Phishing attacks using generative AI are grammatically perfect and contextually calibrated, causing traditional rule-based filters to fail — Amazon Bedrock instead relies on behavior analysis and anomaly detection.
Attackers create fraudulent OpenAI organizations under real company names and send invitations from OpenAI’s infrastructure to trick authorized employees into using them and intercept sensitive data they enter.
A malicious Edge extension exploits the native messaging protocol to bypass browser sandbox and establish full remote access backdoor at operating system level.
A new ClickFix campaign automates malware downloads on macOS entirely through terminal commands, with Atomic macOS Stealer stealing passwords, browser data, and cryptocurrency wallet holdings.
Service desks are popular vectors for social engineering attacks because controls are weak and operational pressure on staff is high — a combination that demands training, process improvements, and technical controls.
ScarCruft uses fake Microsoft security alerts to distribute NarwhalRAT, a Python-based malware that operates in memory and communicates with command-and-control servers via compromised websites and pCloud APIs.
Three new malware loaders (BabaDeda, Lorem Ipsum, Potemkin) distribute via ClickFix social engineering and compromised WordPress sites to enable data theft, ransomware, and remote control.