social engineering
-
FBI warns Silent Ransom Group is targeting US law firms in in-person data theft attacks
The FBI warned that Silent Ransom Group is targeting U.S. law firms with phishing, callback scams and, if needed, in-person access to steal data. The gang may use remote tools or connect external drives to victim computers.
-
French government agency confirms data breach after hacker claims 19 million records
France Titres, the French agency that issues identity and registration documents, said a security incident may have exposed account data. A hacker later claimed to be selling up to 19 million records.
-
Apple adds macOS Terminal warning to block ClickFix attacks
Apple has added a macOS Tahoe 26.4 warning in Terminal that pauses risky pasted commands and alerts users to possible ClickFix attacks. The feature is aimed at stopping social engineering lures that trick people into running harmful instructions.
-
ClickFix campaigns used search ads and ChatGPT lures to deliver MacSync macOS stealer
Sophos found three ClickFix campaigns that tricked users into pasting Terminal commands to install MacSync, a macOS infostealer that steals credentials, keychain data and wallet seed phrases. Campaigns ran from November 2025 to February 2026.
-
Researchers expose North Korean scheme to rent engineer identities for remote jobs
Security researchers say North Korean recruiters tied to Famous Chollima have been soliciting software engineers to rent their identities, using stolen identities, deepfakes and remote access to secure jobs at Western firms and route activity through compromised machines.
-
FBI says cybercriminals stole $262 million in account-takeover schemes since January
The FBI said cybercriminals impersonating banks have stolen more than $262 million in account-takeover attacks since January, with the IC3 receiving over 5,100 complaints; attackers use phishing, social engineering and fraudulent websites to capture credentials and move funds to cryptocurrency wallets.
-
Researchers: network published more than 3,000 malicious YouTube videos to distribute malware
Security researchers say a network of compromised YouTube accounts published more than 3,000 videos since 2021 to promote links that lead to malware downloads; Check Point labelled the operation the YouTube Ghost Network and said Google removed most of the videos.
-
Google says North Korean hackers used smart-contract “EtherHiding” to deliver malware
Google Threat Intelligence Group says a North Korean actor known as UNC5342 used an “EtherHiding” smart-contract technique to host and deliver JavaScript malware via fake job interviews, enabling stealthy payload updates and theft of credentials and cryptocurrency.
-
Microsoft tightens Edge’s Internet Explorer mode after reports of exploit chain
Microsoft said it has tightened Internet Explorer mode in Edge after reports that attackers used social engineering and unpatched Chakra 0-day exploits to gain remote code execution and escalate privileges, and the company removed easier IE mode launch options and now requires explicit enabling.
-
Insight Partners notifies thousands after ransomware breach, exposing personal and investor data
New York-based Insight Partners said thousands of individuals were affected by a ransomware breach that involved data exfiltration and subsequent server encryption, with notification letters and identity monitoring offered to impacted individuals and a Sept. 2025 deadline for confirming exposure.








