Advertisement
Scattered Spider Member Tylerb Pleads Guilty: Smishing Analysis
Tyler Robert Buchanan's guilty plea exposes Scattered Spider smishing tactics that compromised 12+ tech firms and stole millions in cryptocurrency.
Apple ID Alerts Abused for Phishing via Legitimate Servers
Threat actors are exploiting Apple's account notification system to send authentic-looking phishing emails that bypass traditional spam filters and SPF checks.
Strategic Human-LLM Interaction: Research into AI Trust and Rationality
New research shows humans attribute higher rationality and cooperation to LLMs in strategic games, impacting trust in automated cybersecurity environments.
Kraken Extorted by Hackers Following Insider Account Breach
Kraken faces extortion after a social engineering attack on a support agent led to unauthorized internal system access and threatened customer data exposure.
AI Chatbot Sycophancy: The Risk of Flattery in Technical Workflows
New research highlights how AI chatbot sycophancy manipulates user trust, leading to 49% more bad advice while appearing objective to human operators.

APT37 Social Engineering via Facebook Delivers RokRAT Malware
North Korean threat actor APT37 leverages Facebook friend requests and trust-building to deploy the RokRAT trojan against high-value targets.
Analyzing the Frequency of Open Redirects in Phishing Campaigns
Examine the technical drivers behind the use of open redirects in phishing delivery and learn strategies for detection and vulnerability remediation.
North Korean Social Engineering Targets Node.js Maintainers
North Korean threat actors use social engineering and malicious npm packages to target high-profile Node.js maintainers in a sophisticated supply chain campaign.
Axios npm Hijack Attempt: Detecting Social Engineering Tactics
North Korean threat actors targeted an Axios maintainer with a fake Microsoft Teams fix, highlighting critical risks to open-source supply chains.
Infinity Stealer macOS Malware: Analyzing ClickFix Lures and Payloads
Infinity Stealer targets macOS via ClickFix social engineering. Learn how this Nuitka-compiled malware steals browser data, crypto wallets, and Keychain info.
Palo Alto Networks Recruiter Scam and Quantum Security Outlook
Threat actors are impersonating Palo Alto Networks recruiters to target security professionals, while Google sets a 2029 deadline for quantum computing.
_Panther_Media_GmbH_Alamy.jpg?width=1280&auto=webp&quality=80&disable=upscale)
Palo Alto Networks Recruitment Fraud: Analysis of Phishing Tactics
Phishing campaigns posing as Palo Alto Networks recruiters leverage LinkedIn data and psychological tactics to defraud job seekers in the security industry.