Social Engineering Campaign Uses Phony NDAs to Avoid Detection
Researchers at Gen Digital are tracking a sophisticated social engineering campaign that’s using phony NDA documents to trick employees into moving the conversation to WhatsApp and ...
Researchers at Gen Digital are tracking a sophisticated social engineering campaign that’s using phony NDA documents to trick employees into moving the conversation to WhatsApp and ...
Threat actors are increasingly leveraging AI hallucinations to plant phishing links and other malicious content in AI output, IEEE Spectrum reports. Large language models (LLMs) sometimes ...
Lead Analysts: Prabhakaran Ravichandhiran, Jeewan Singh Jalal
Cloaked SEO poisoning attacks surged by 40% in the second quarter of 2026, according to researchers at Fortra. This tactic, also known as “Chameleon SEO poisoning,” uses cloaked search ...
Lead Analysts: Prabhakaran Ravichandhiran, Jeewan Singh Jalal, Karthikeyan Dharmaraj and Sripathi Kumar
A new phishing platform called “JWR” gives attackers real-time control over social engineering attacks, according to researchers at Cisco Talos. The kit livestreams the phishing page to ...
Google’s Threat Intelligence Group (GTIG) is tracking a voice phishing (vishing) campaign that’s targeting hedge funds and financial firms. The researchers attribute the attacks to ...
Criminals are now selling malicious AI tools for use in cyberattacks, according to researchers at Trellix. These tools dramatically lower the barrier for unskilled crooks to launch ...
Phishing is still the top initial access vector, accounting for more than half of cyberattacks observed during Q2 2026, according to a new report from Cisco Talos.
Social engineering remains a central part of modern cyberattacks, according to a new report from CrowdStrike. Attackers are increasingly turning to voice phishing because it bypasses ...