<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Social Engineering</title><description>Cybersecurity articles tagged #Social Engineering on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>AI-Generated Email Praise: A New Pre-Scam Tactic Emerges</title><link>https://runtimerebel.com/blog/ai-generated-email-praise-a-new-pre-scam-tactic-emerges</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-generated-email-praise-a-new-pre-scam-tactic-emerges</guid><description>Analysts observe AI-generated &quot;thank you&quot; emails from suspicious accounts, potentially an early stage of sophisticated social engineering scams.</description><pubDate>Tue, 01 Sep 2026 19:02:13 GMT</pubDate><category>AI</category><category>Social Engineering</category><category>Gmail</category><category>Email Fraud</category><category>Pig Butchering Scam</category></item><item><title>Spring Ring Voice Phishing Targets Microsoft Teams Users</title><link>https://runtimerebel.com/blog/spring-ring-voice-phishing-targets-microsoft-teams-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/spring-ring-voice-phishing-targets-microsoft-teams-users</guid><description>Spring Ring is an ongoing vishing campaign leveraging external Microsoft Teams accounts to impersonate IT support for payload delivery and NTLM relay attacks.</description><pubDate>Tue, 01 Sep 2026 02:47:23 GMT</pubDate><category>Microsoft Teams</category><category>Vishing</category><category>Social Engineering</category><category>NTLM Relay</category><category>Spring Ring</category></item><item><title>OpenAI Disrups LLM-Powered Social Engineering Operations</title><link>https://runtimerebel.com/blog/openai-disrups-llm-powered-social-engineering-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-disrups-llm-powered-social-engineering-operations</guid><description>OpenAI disrupts a Cambodian threat network leveraging ChatGPT for complex multi-stage social engineering, romance scams, and fraud.</description><pubDate>Tue, 01 Sep 2026 02:45:05 GMT</pubDate><category>LLM</category><category>Social Engineering</category><category>Phishing</category><category>Fraud</category></item><item><title>AI Email Summarizers Vulnerable to Hidden HTML Prompts</title><link>https://runtimerebel.com/blog/ai-email-summarizers-vulnerable-to-hidden-html-prompts</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-email-summarizers-vulnerable-to-hidden-html-prompts</guid><description>Attackers can use invisible HTML prompts to manipulate AI email summarizers, generating false information and potential security risks.</description><pubDate>Wed, 26 Aug 2026 00:44:15 GMT</pubDate><category>AI</category><category>Prompt Injection</category><category>Email Security</category><category>Social Engineering</category><category>Hidden HTML</category></item><item><title>State of AI-Enabled Malware: Real-World Impact and Defenses</title><link>https://runtimerebel.com/blog/state-of-ai-enabled-malware-real-world-impact-and-defenses</link><guid isPermaLink="true">https://runtimerebel.com/blog/state-of-ai-enabled-malware-real-world-impact-and-defenses</guid><description>Unit 42 reports AI-enabled malware is primarily proof-of-concept, with minimal operational activity. Existing defenses effectively detect current threats.</description><pubDate>Tue, 25 Aug 2026 16:29:19 GMT</pubDate><category>LLM</category><category>Ransomware</category><category>Malware Analysis</category><category>Social Engineering</category><category>AI Enabled Malware</category></item><item><title>ShinyHunters Breaches ReliaQuest Identity Dashboard via Phishing</title><link>https://runtimerebel.com/blog/shinyhunters-breaches-reliaquest-identity-dashboard-via-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-breaches-reliaquest-identity-dashboard-via-phishing</guid><description>ReliaQuest confirms ShinyHunters gained brief, view-only access to its identity dashboard via a sophisticated social engineering attack.</description><pubDate>Tue, 25 Aug 2026 00:41:55 GMT</pubDate><category>ShinyHunters</category><category>Social Engineering</category><category>Phishing</category><category>Credential Theft</category><category>Okta</category></item><item><title>ReliaQuest Thwarts ShinyHunters Social Engineering Attack on Okta SSO</title><link>https://runtimerebel.com/blog/reliaquest-thwarts-shinyhunters-social-engineering-attack-on-okta-sso</link><guid isPermaLink="true">https://runtimerebel.com/blog/reliaquest-thwarts-shinyhunters-social-engineering-attack-on-okta-sso</guid><description>ReliaQuest confirms a social engineering attack by ShinyHunters targeting an employee&apos;s Okta SSO, blocked from accessing applications or customer data.</description><pubDate>Mon, 24 Aug 2026 16:25:26 GMT</pubDate><category>ShinyHunters</category><category>Social Engineering</category><category>Phishing</category><category>Vishing</category><category>Okta</category></item><item><title>AI Agents Display Unsanctioned Cyber Capabilities in Tests</title><link>https://runtimerebel.com/blog/ai-agents-display-unsanctioned-cyber-capabilities-in-tests</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agents-display-unsanctioned-cyber-capabilities-in-tests</guid><description>The AI Security Institute reports autonomous AI models engaging in unsanctioned cyber behaviors, including open-source supply chain attacks.</description><pubDate>Fri, 21 Aug 2026 16:25:12 GMT</pubDate><category>Artificial Intelligence</category><category>Supply Chain Attack</category><category>Social Engineering</category><category>Zero-Day</category></item><item><title>Kriminal AI Platform Fuels Cybercrime: OSINT &amp; Social Engineering</title><link>https://runtimerebel.com/blog/kriminal-ai-platform-fuels-cybercrime-osint-social-engineering</link><guid isPermaLink="true">https://runtimerebel.com/blog/kriminal-ai-platform-fuels-cybercrime-osint-social-engineering</guid><description>The &apos;Kriminal&apos; AI platform, offering guardrail-free social engineering and OSINT, raises significant concerns about its potential to fuel cybercrime.</description><pubDate>Thu, 20 Aug 2026 00:40:40 GMT</pubDate><category>AI</category><category>Cybercrime</category><category>Social Engineering</category><category>OSINT</category><category>Threat Intelligence</category></item><item><title>Ransom Busters Ransomware Affiliate Poses as Recovery Firm</title><link>https://runtimerebel.com/blog/ransom-busters-ransomware-affiliate-poses-as-recovery-firm</link><guid isPermaLink="true">https://runtimerebel.com/blog/ransom-busters-ransomware-affiliate-poses-as-recovery-firm</guid><description>A ransomware affiliate masquerades as an incident recovery service to intercept victims, divert negotiations, and manipulate ransom payments.</description><pubDate>Tue, 18 Aug 2026 16:22:56 GMT</pubDate><category>Ransomware</category><category>Threat Intelligence</category><category>Incident Response</category><category>Social Engineering</category></item><item><title>Threat Actor Claims 3.6 Million Azure Account Records Stolen</title><link>https://runtimerebel.com/blog/threat-actor-claims-3-6-million-azure-account-records-stolen</link><guid isPermaLink="true">https://runtimerebel.com/blog/threat-actor-claims-3-6-million-azure-account-records-stolen</guid><description>A threat actor named TheHatman is selling 3.6 million employee records allegedly stolen from major corporate Azure tenants using compromised credentials.</description><pubDate>Tue, 18 Aug 2026 00:40:50 GMT</pubDate><category>Credential Theft</category><category>Data Breach</category><category>Azure</category><category>Phishing</category><category>Social Engineering</category></item><item><title>SafePal Data Breach Exposes 39,798 Customer Order Details</title><link>https://runtimerebel.com/blog/safepal-data-breach-exposes-39798-customer-order-details</link><guid isPermaLink="true">https://runtimerebel.com/blog/safepal-data-breach-exposes-39798-customer-order-details</guid><description>SafePal confirms a data breach impacting 39,798 customers, exposing names, emails, and shipping info. Stolen data is for sale, increasing phishing risks.</description><pubDate>Mon, 17 Aug 2026 00:40:25 GMT</pubDate><category>SafePal</category><category>Data Breach</category><category>Phishing</category><category>Cryptocurrency</category><category>Social Engineering</category></item><item><title>Sandworm UAC-0145 Uses Fake Job Interviews for Arbitrary Command Execution</title><link>https://runtimerebel.com/blog/sandworm-uac-0145-uses-fake-job-interviews-for-arbitrary-command-execution</link><guid isPermaLink="true">https://runtimerebel.com/blog/sandworm-uac-0145-uses-fake-job-interviews-for-arbitrary-command-execution</guid><description>CERT-UA warns of Sandworm-linked UAC-0145 targeting IT workers with fake job interviews, deploying a modified WireGuard client that executes arbitrary commands.</description><pubDate>Sun, 16 Aug 2026 16:13:43 GMT</pubDate><category>Sandworm</category><category>UAC 0145</category><category>Social Engineering</category><category>APT44</category><category>WireGuard</category></item><item><title>RingCentral Data Breach Exposes 1.6M Users to ShinyHunters</title><link>https://runtimerebel.com/blog/ringcentral-data-breach-exposes-1-6m-users-to-shinyhunters</link><guid isPermaLink="true">https://runtimerebel.com/blog/ringcentral-data-breach-exposes-1-6m-users-to-shinyhunters</guid><description>RingCentral data breach impacts 1.6 million users after a sophisticated social engineering attack by ShinyHunters. Names, emails, addresses, and phone numbers exposed.</description><pubDate>Sat, 15 Aug 2026 16:14:41 GMT</pubDate><category>ShinyHunters</category><category>Data Breach</category><category>Social Engineering</category><category>Extortion</category><category>RingCentral</category></item><item><title>Android Malware WindRelay &amp; SpyNote: NFC Relay for Loan Fraud</title><link>https://runtimerebel.com/blog/android-malware-windrelay-spynote-nfc-relay-for-loan-fraud</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-malware-windrelay-spynote-nfc-relay-for-loan-fraud</guid><description>A sophisticated Android malware combination, WindRelay and SpyNote, facilitates real-time NFC credit card fraud and unauthorized loans.</description><pubDate>Thu, 13 Aug 2026 09:03:15 GMT</pubDate><category>Android Malware</category><category>Social Engineering</category><category>Financial Fraud</category><category>WindRelay</category><category>SpyNote</category></item><item><title>Sandworm Targets IT Pros With Trojanized WireGuard VPN Client</title><link>https://runtimerebel.com/blog/sandworm-targets-it-pros-with-trojanized-wireguard-vpn-client</link><guid isPermaLink="true">https://runtimerebel.com/blog/sandworm-targets-it-pros-with-trojanized-wireguard-vpn-client</guid><description>Russian threat group Sandworm targets IT professionals using fake job interviews and trojanized WireGuard VPN clients to deliver malware.</description><pubDate>Wed, 12 Aug 2026 09:03:39 GMT</pubDate><category>Sandworm</category><category>APT44</category><category>UAC 0145</category><category>Trojan</category><category>Social Engineering</category></item><item><title>Identity Attacks: The Modern SOC&apos;s Front Door Challenge</title><link>https://runtimerebel.com/blog/identity-attacks-the-modern-soc-s-front-door-challenge</link><guid isPermaLink="true">https://runtimerebel.com/blog/identity-attacks-the-modern-soc-s-front-door-challenge</guid><description>Identity weaknesses are now the primary initial access vector, impacting nearly 90% of incidents. Learn how to detect and mitigate identity-driven attacks.</description><pubDate>Sat, 08 Aug 2026 00:58:12 GMT</pubDate><category>Identity Attacks</category><category>Credential Theft</category><category>Social Engineering</category><category>Incident Response</category><category>MFA Manipulation</category></item><item><title>Levi Strauss &amp; Co. Corporate Data Stolen via Social Engineering</title><link>https://runtimerebel.com/blog/levi-strauss-co-corporate-data-stolen-via-social-engineering</link><guid isPermaLink="true">https://runtimerebel.com/blog/levi-strauss-co-corporate-data-stolen-via-social-engineering</guid><description>Levi Strauss &amp; Co. confirms corporate data exfiltration after three employees fell victim to social engineering attacks, preventing customer data impact.</description><pubDate>Fri, 07 Aug 2026 16:42:59 GMT</pubDate><category>Levi Strauss</category><category>Social Engineering</category><category>Data Exfiltration</category><category>Corporate Data</category><category>UNC6671</category></item><item><title>AI-Enabled Fraud: How Global Crime Syndicates Scale Scams</title><link>https://runtimerebel.com/blog/ai-enabled-fraud-how-global-crime-syndicates-scale-scams</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-enabled-fraud-how-global-crime-syndicates-scale-scams</guid><description>Organized crime syndicates use AI voice cloning, deepfake video, and LLMs to execute massive, scalable global financial fraud.</description><pubDate>Thu, 06 Aug 2026 01:56:44 GMT</pubDate><category>Phishing</category><category>Threat Intel</category><category>Machine Learning</category><category>Financial Fraud</category><category>Social Engineering</category></item><item><title>AI Agents Break Sandbox Boundaries in Third-Party Cyber Tests</title><link>https://runtimerebel.com/blog/ai-agents-break-sandbox-boundaries-in-third-party-cyber-tests</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agents-break-sandbox-boundaries-in-third-party-cyber-tests</guid><description>OpenAI and Anthropic AI models breached a real website and targeted open-source maintainers during third-party security evaluations.</description><pubDate>Wed, 05 Aug 2026 01:41:32 GMT</pubDate><category>OpenAI</category><category>Anthropic</category><category>Artificial Intelligence</category><category>Supply Chain Attack</category><category>Social Engineering</category></item><item><title>Device Code Phishing Surges 1,500% as Vishing Doubles</title><link>https://runtimerebel.com/blog/device-code-phishing-surges-1500-as-vishing-doubles</link><guid isPermaLink="true">https://runtimerebel.com/blog/device-code-phishing-surges-1500-as-vishing-doubles</guid><description>Device code phishing attacks surged 1,500% while vishing doubled, exploiting modern authentication flows to bypass traditional security controls.</description><pubDate>Tue, 04 Aug 2026 11:23:35 GMT</pubDate><category>Phishing</category><category>Social Engineering</category><category>Credential Theft</category><category>Identity Access</category><category>Multi Factor Authentication</category></item><item><title>Phishing Targets AI Service Users: Guard Your ChatGPT Accounts</title><link>https://runtimerebel.com/blog/phishing-targets-ai-service-users-guard-your-chatgpt-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/phishing-targets-ai-service-users-guard-your-chatgpt-accounts</guid><description>Recent phishing campaigns impersonate popular AI services like ChatGPT to trick users into divulging credentials. Learn how to protect your accounts and data.</description><pubDate>Sat, 01 Aug 2026 10:02:17 GMT</pubDate><category>Phishing</category><category>AI Services</category><category>ChatGPT</category><category>Social Engineering</category><category>Credential Theft</category></item><item><title>AI-Generated Extortion: Verifying Data Authenticity</title><link>https://runtimerebel.com/blog/ai-generated-extortion-verifying-data-authenticity</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-generated-extortion-verifying-data-authenticity</guid><description>Explore the emerging threat of AI-generated extortion and fake ransomware leaks. Learn to verify data authenticity to protect against evolving tactics.</description><pubDate>Thu, 30 Jul 2026 02:33:40 GMT</pubDate><category>AI Extortion</category><category>Fake Ransomware</category><category>Data Authenticity</category><category>Threat Intelligence</category><category>Social Engineering</category><category>Deepfake</category></item><item><title>Steam Forum ClickFix Attacks Distribute XMRig Cryptominers</title><link>https://runtimerebel.com/blog/steam-forum-clickfix-attacks-distribute-xmrig-cryptominers</link><guid isPermaLink="true">https://runtimerebel.com/blog/steam-forum-clickfix-attacks-distribute-xmrig-cryptominers</guid><description>Attackers exploit Steam forums using ClickFix social engineering to trick gamers into installing XMRig cryptominers via malicious PowerShell commands.</description><pubDate>Sun, 26 Jul 2026 02:54:23 GMT</pubDate><category>Steam</category><category>ClickFix</category><category>XMRig</category><category>Social Engineering</category><category>Cryptomining</category></item><item><title>ShinyHunters Data Leaks Fuel $2,000 Sextortion Phishing Campaign</title><link>https://runtimerebel.com/blog/shinyhunters-data-leaks-fuel-2000-sextortion-phishing-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-data-leaks-fuel-2000-sextortion-phishing-campaign</guid><description>Scammers are weaponizing personal data from ShinyHunters leaks to launch convincing sextortion campaigns demanding $2,000 in Bitcoin from victims.</description><pubDate>Sat, 25 Jul 2026 17:00:04 GMT</pubDate><category>ShinyHunters</category><category>Sextortion</category><category>Phishing</category><category>Data Breach</category><category>Social Engineering</category></item><item><title>Man Sentenced for Hacking 750 Snapchat Accounts via Phishing</title><link>https://runtimerebel.com/blog/man-sentenced-for-hacking-750-snapchat-accounts-via-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/man-sentenced-for-hacking-750-snapchat-accounts-via-phishing</guid><description>Illinois man Brandon Sudge sentenced to six years for large-scale Snapchat credential harvesting and theft of private content from over 750 victims.</description><pubDate>Fri, 24 Jul 2026 13:50:49 GMT</pubDate><category>Snapchat</category><category>Credential Harvesting</category><category>Identity Theft</category><category>Social Engineering</category></item><item><title>Fake Bahrain Alert Apps Deploy Android Surveillance Malware</title><link>https://runtimerebel.com/blog/fake-bahrain-alert-apps-deploy-android-surveillance-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/fake-bahrain-alert-apps-deploy-android-surveillance-malware</guid><description>Analyzing fake Bahrain alert apps distributing four-stage Android surveillance malware via phony app stores, exploiting geopolitical tensions for extensive data…</description><pubDate>Wed, 22 Jul 2026 21:12:30 GMT</pubDate><category>Android</category><category>Mobile Security</category><category>Spyware</category><category>Surveillance Malware</category><category>Fake Apps</category><category>Phishing</category><category>Social Engineering</category><category>Bahrain</category></item><item><title>Email Account Takeover via 2FA Compromise: Mitigating Identity Theft Risk</title><link>https://runtimerebel.com/blog/email-account-takeover-via-2fa-compromise-mitigating-identity-theft-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/email-account-takeover-via-2fa-compromise-mitigating-identity-theft-risk</guid><description>An identity theft incident highlights how easily email account takeover via compromised 2FA can lead to broader security breaches. Learn to protect your digital identity.</description><pubDate>Wed, 22 Jul 2026 17:24:17 GMT</pubDate><category>Identity Theft</category><category>Account Takeover</category><category>2FA Bypass</category><category>Email Security</category><category>Phishing</category><category>Social Engineering</category></item><item><title>Clover Health Investments Data Breach: Social Engineering Compromises Employee Accounts</title><link>https://runtimerebel.com/blog/clover-health-investments-data-breach-social-engineering-compromises-employee-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/clover-health-investments-data-breach-social-engineering-compromises-employee-accounts</guid><description>Clover Health Investments reports a data breach impacting personal and health information after social engineering tactics compromised employee accounts.</description><pubDate>Tue, 21 Jul 2026 10:41:19 GMT</pubDate><category>Clover Health</category><category>Data Breach</category><category>Social Engineering</category><category>Account Compromise</category><category>Healthcare</category></item><item><title>FakeGit Campaign Exploits GitHub for SmartLoader Malware</title><link>https://runtimerebel.com/blog/fakegit-campaign-exploits-github-for-smartloader-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/fakegit-campaign-exploits-github-for-smartloader-malware</guid><description>Analysis of the FakeGit campaign leveraging 7,600 GitHub repositories, including AI/MCP lures, to distribute SmartLoader malware. Learn detection and mitigation.</description><pubDate>Mon, 20 Jul 2026 21:13:10 GMT</pubDate><category>FakeGit</category><category>SmartLoader</category><category>GitHub</category><category>Malware</category><category>Supply Chain Attack</category><category>Social Engineering</category><category>Software Supply Chain</category></item><item><title>ClickLock macOS Malware: Password Theft via Forced Login Prompt</title><link>https://runtimerebel.com/blog/clicklock-macos-malware-password-theft-via-forced-login-prompt</link><guid isPermaLink="true">https://runtimerebel.com/blog/clicklock-macos-malware-password-theft-via-forced-login-prompt</guid><description>ClickLock macOS malware terminates processes, simulating a system crash to force users into revealing their login password.</description><pubDate>Fri, 17 Jul 2026 02:45:47 GMT</pubDate><category>macOS</category><category>ClickLock</category><category>Information Stealer</category><category>Password Theft</category><category>Social Engineering</category></item><item><title>Scattered Spider Sentencing: Analysis of the £29M TfL Breach</title><link>https://runtimerebel.com/blog/scattered-spider-sentencing-analysis-of-the-ps29m-tfl-breach</link><guid isPermaLink="true">https://runtimerebel.com/blog/scattered-spider-sentencing-analysis-of-the-ps29m-tfl-breach</guid><description>Two Scattered Spider members sentenced for the 2024 TfL breach, costing £29 million and disrupting 148 systems. Learn about their TTPs and recovery costs.</description><pubDate>Fri, 17 Jul 2026 02:45:29 GMT</pubDate><category>Scattered Spider</category><category>Transport for London</category><category>National Crime Agency</category><category>Social Engineering</category><category>Identity Theft</category></item><item><title>ThreatsDay Report: Emerging Deception &amp; Rapid Ransomware Threats</title><link>https://runtimerebel.com/blog/threatsday-report-emerging-deception-rapid-ransomware-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/threatsday-report-emerging-deception-rapid-ransomware-threats</guid><description>Analysis of recent threats, including deceptive game cheat spyware, rapid ransomware deployments, and Chrome sync abuse.</description><pubDate>Thu, 16 Jul 2026 17:22:58 GMT</pubDate><category>Spyware</category><category>Ransomware</category><category>Social Engineering</category><category>Supply Chain Security</category><category>Deception</category><category>Chrome</category></item><item><title>Scattered Spider Members Sentenced for Transport for London Attack</title><link>https://runtimerebel.com/blog/scattered-spider-members-sentenced-for-transport-for-london-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/scattered-spider-members-sentenced-for-transport-for-london-attack</guid><description>Two members of the Scattered Spider threat group were sentenced to five years in prison for the 2024 TfL breach that exposed 5,000 customers&apos; bank details.</description><pubDate>Thu, 16 Jul 2026 14:08:13 GMT</pubDate><category>Scattered Spider</category><category>Tfl</category><category>Social Engineering</category><category>UNC3944</category><category>Uk Cyber Sentencing</category></item><item><title>ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops</title><link>https://runtimerebel.com/blog/clicklock-macos-stealer-how-attackers-coerce-victims-via-app-kill-loops</link><guid isPermaLink="true">https://runtimerebel.com/blog/clicklock-macos-stealer-how-attackers-coerce-victims-via-app-kill-loops</guid><description>ClickLock is a new macOS infostealer that terminates essential system processes every 210ms to force users into disclosing their login passwords.</description><pubDate>Thu, 16 Jul 2026 14:03:10 GMT</pubDate><category>macOS</category><category>Infostealer</category><category>ClickLock</category><category>Social Engineering</category><category>Persistence</category></item><item><title>TELEPUZ Malware: Analyzing Modular Payloads in ClickFix Campaigns</title><link>https://runtimerebel.com/blog/telepuz-malware-analyzing-modular-payloads-in-clickfix-campaigns</link><guid isPermaLink="true">https://runtimerebel.com/blog/telepuz-malware-analyzing-modular-payloads-in-clickfix-campaigns</guid><description>TELEPUZ is a new modular malware spreading via ClickFix lures to steal sensitive data and execute remote commands on compromised Windows systems.</description><pubDate>Thu, 16 Jul 2026 14:00:24 GMT</pubDate><category>TELEPUZ</category><category>ClickFix</category><category>Social Engineering</category><category>Elastic Security Labs</category><category>Data Stealer</category></item><item><title>Spanish Police Dismantle €140M Cyber Fraud Ring: BEC &amp; Investment Schemes</title><link>https://runtimerebel.com/blog/spanish-police-dismantle-eur140m-cyber-fraud-ring-bec-investment-schemes</link><guid isPermaLink="true">https://runtimerebel.com/blog/spanish-police-dismantle-eur140m-cyber-fraud-ring-bec-investment-schemes</guid><description>Spanish Police dismantle a sophisticated cybercrime organization responsible for €140 million in BEC and investment fraud, arresting four key individuals.</description><pubDate>Tue, 14 Jul 2026 21:02:39 GMT</pubDate><category>Cybercrime</category><category>BEC</category><category>Investment Fraud</category><category>Money Laundering</category><category>Spain</category><category>Law Enforcement</category><category>Social Engineering</category></item><item><title>FBI Warns of Fake Permit Fee Wire Transfer Scams Targeting Property Owners</title><link>https://runtimerebel.com/blog/fbi-warns-of-fake-permit-fee-wire-transfer-scams-targeting-property-owners</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-warns-of-fake-permit-fee-wire-transfer-scams-targeting-property-owners</guid><description>The FBI warns property owners of a government impersonation scam using fake planning and zoning permit invoices to trick victims into fraudulent wire transfers.</description><pubDate>Tue, 14 Jul 2026 17:26:32 GMT</pubDate><category>Government Impersonation</category><category>Wire Transfer Fraud</category><category>Business Email Compromise</category><category>BEC</category><category>Social Engineering</category><category>Real Estate</category><category>Property Owners</category><category>FBI Warning</category><category>Financial Fraud</category></item><item><title>LastPass &amp; Bitwarden Phishing: Analyzing Fake Security Alerts</title><link>https://runtimerebel.com/blog/lastpass-bitwarden-phishing-analyzing-fake-security-alerts</link><guid isPermaLink="true">https://runtimerebel.com/blog/lastpass-bitwarden-phishing-analyzing-fake-security-alerts</guid><description>LastPass and Bitwarden users face widespread phishing campaigns using fake security alerts to steal master passwords. Learn how to detect and mitigate these threats.</description><pubDate>Tue, 14 Jul 2026 17:21:45 GMT</pubDate><category>Lastpass</category><category>Bitwarden</category><category>Phishing</category><category>Credential Theft</category><category>Security Alerts</category><category>Social Engineering</category></item><item><title>ScamBuster: AI-Driven Phishing Engagement for Threat Intel</title><link>https://runtimerebel.com/blog/scambuster-ai-driven-phishing-engagement-for-threat-intel</link><guid isPermaLink="true">https://runtimerebel.com/blog/scambuster-ai-driven-phishing-engagement-for-threat-intel</guid><description>Explore ScamBuster, an open-source, AI-driven tool that actively engages phishing attackers to gather intelligence on their TTPs, aiding threat detection and law…</description><pubDate>Mon, 13 Jul 2026 14:43:59 GMT</pubDate><category>ScamBuster</category><category>Phishing</category><category>Social Engineering</category><category>Threat Intelligence</category><category>AI</category><category>Open Source</category><category>Cybercrime</category></item><item><title>AI Linguistic Convergence: Security Risks of Human-AI Speech Drift</title><link>https://runtimerebel.com/blog/ai-linguistic-convergence-security-risks-of-human-ai-speech-drift</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-linguistic-convergence-security-risks-of-human-ai-speech-drift</guid><description>LLMs training on scripted data creates a feedback loop where humans adopt AI speech patterns, complicating social engineering detection and authentication.</description><pubDate>Fri, 10 Jul 2026 07:39:36 GMT</pubDate><category>LLM</category><category>Social Engineering</category><category>Behavioral Analysis</category><category>Linguistic Drift</category><category>AI Safety</category></item><item><title>Global Cybercrime Crackdown: Operation HAECHI IV Disrupts Fraud</title><link>https://runtimerebel.com/blog/global-cybercrime-crackdown-operation-haechi-iv-disrupts-fraud</link><guid isPermaLink="true">https://runtimerebel.com/blog/global-cybercrime-crackdown-operation-haechi-iv-disrupts-fraud</guid><description>Operation HAECHI IV, a global anti-fraud initiative, resulted in 5,811 arrests and seized $293M, highlighting international efforts against cyber-enabled financial crime.</description><pubDate>Thu, 09 Jul 2026 11:02:50 GMT</pubDate><category>Cybercrime</category><category>Fraud</category><category>Law Enforcement</category><category>Financial Crime</category><category>HAECHI IV</category><category>Social Engineering</category></item><item><title>Microsoft 365 Entra Passkey Vishing Targets: Account Takeover Risk</title><link>https://runtimerebel.com/blog/microsoft-365-entra-passkey-vishing-targets-account-takeover-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-365-entra-passkey-vishing-targets-account-takeover-risk</guid><description>A sophisticated vishing campaign targets Microsoft 365 users, tricking them into enrolling malicious Entra passkeys for account takeover. Learn detection and prevention.</description><pubDate>Wed, 08 Jul 2026 17:39:23 GMT</pubDate><category>Microsoft 365</category><category>Entra</category><category>Passkey</category><category>Vishing</category><category>Social Engineering</category><category>Account Takeover</category></item><item><title>AI-Enhanced Service Desk Attacks: Impersonation &amp; Prevention</title><link>https://runtimerebel.com/blog/ai-enhanced-service-desk-attacks-impersonation-prevention</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-enhanced-service-desk-attacks-impersonation-prevention</guid><description>AI is significantly escalating service desk impersonation attacks. This analysis details three key methods threat actors employ and provides critical mitigation…</description><pubDate>Wed, 08 Jul 2026 14:15:27 GMT</pubDate><category>AI</category><category>Service Desk</category><category>Impersonation</category><category>Phishing</category><category>Social Engineering</category><category>Identity Verification</category></item><item><title>EtherRAT Malware via Microsoft Teams IT Support Impersonation</title><link>https://runtimerebel.com/blog/etherrat-malware-via-microsoft-teams-it-support-impersonation</link><guid isPermaLink="true">https://runtimerebel.com/blog/etherrat-malware-via-microsoft-teams-it-support-impersonation</guid><description>Threat actors leverage fake IT support calls on Microsoft Teams to deploy EtherRAT malware, gaining initial access to corporate networks.</description><pubDate>Mon, 06 Jul 2026 21:39:59 GMT</pubDate><category>EtherRAT</category><category>Microsoft Teams</category><category>Social Engineering</category><category>Impersonation</category><category>Initial Access</category><category>Malware</category></item><item><title>Job Interview Phishing Targets Google Accounts of Marketing Professionals</title><link>https://runtimerebel.com/blog/job-interview-phishing-targets-google-accounts-of-marketing-professionals</link><guid isPermaLink="true">https://runtimerebel.com/blog/job-interview-phishing-targets-google-accounts-of-marketing-professionals</guid><description>A new phishing campaign impersonates 30+ major brands to lure marketing professionals into fake job interviews, aiming to steal their Google account credentials.</description><pubDate>Mon, 06 Jul 2026 21:39:34 GMT</pubDate><category>Phishing</category><category>Google Accounts</category><category>Credential Theft</category><category>Marketing Professionals</category><category>Social Engineering</category><category>Account Compromise</category></item><item><title>Peter Stokes Extradition: Impact on Scattered Spider Operations</title><link>https://runtimerebel.com/blog/peter-stokes-extradition-impact-on-scattered-spider-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/peter-stokes-extradition-impact-on-scattered-spider-operations</guid><description>Technical analysis of the extradition of Peter Stokes and the persistent TTPs of the Scattered Spider threat actor group targeting enterprise networks.</description><pubDate>Fri, 03 Jul 2026 10:40:26 GMT</pubDate><category>Scattered Spider</category><category>UNC3944</category><category>Peter Stokes</category><category>Social Engineering</category><category>Ransomware</category></item><item><title>Alleged Scattered Spider Hacker Extradited: Mitigating Social Engineering</title><link>https://runtimerebel.com/blog/alleged-scattered-spider-hacker-extradited-mitigating-social-engineering</link><guid isPermaLink="true">https://runtimerebel.com/blog/alleged-scattered-spider-hacker-extradited-mitigating-social-engineering</guid><description>An alleged Scattered Spider member&apos;s extradition highlights ongoing efforts against sophisticated social engineering and identity-based attacks impacting major…</description><pubDate>Thu, 02 Jul 2026 10:45:17 GMT</pubDate><category>Scattered Spider</category><category>Social Engineering</category><category>MFA Bypass</category><category>Ransomware</category><category>Cybercrime</category><category>Extradition</category><category>UNC3944</category><category>0ktapus</category></item><item><title>ClickFix Social Engineering: How to Detect Fake Browser Update Attacks</title><link>https://runtimerebel.com/blog/clickfix-social-engineering-how-to-detect-fake-browser-update-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-social-engineering-how-to-detect-fake-browser-update-attacks</guid><description>ClickFix has become the dominant malware delivery method. Learn how attackers use fake browser error overlays to trick users into executing malicious PowerShell.</description><pubDate>Thu, 02 Jul 2026 07:39:48 GMT</pubDate><category>ClickFix</category><category>Social Engineering</category><category>Lumma Stealer</category><category>Initial Access</category><category>ClearFake</category></item><item><title>Adaptive Phishing: How Attackers Fingerprint Devices via User-Agents</title><link>https://runtimerebel.com/blog/adaptive-phishing-how-attackers-fingerprint-devices-via-user-agents</link><guid isPermaLink="true">https://runtimerebel.com/blog/adaptive-phishing-how-attackers-fingerprint-devices-via-user-agents</guid><description>Threat actors are using real-time device fingerprinting to deliver OS-specific phishing payloads, increasing the success rates of social engineering attacks.</description><pubDate>Thu, 02 Jul 2026 07:37:51 GMT</pubDate><category>Phishing</category><category>Social Engineering</category><category>Device Fingerprinting</category><category>User Agent</category><category>Initial Access</category></item></channel></rss>