Skip to content
Latest
GitHub Enterprise SSRF Shows Why Secret Scanning Needs Network GuardrailsBlinder Tunnel Shows How Developer Trust Becomes Critical Infrastructure RiskBrowser Detection and Response Shows Why the Browser Is Now a Security Blind SpotApache Struts REST Plugin Flaws Show Why Legacy Java Apps Need Exposure ReviewClingSTUN Shows Why IoT Edge Devices Need Real Egress MonitoringApache Thrift 61-CVE Patch Shows Why RPC Frameworks Need InventoryNIST OT Zero Trust Guidance Shows Segmentation Must Reach Below Level 3Milk Dragon Shows Social Commerce Phishing Needs Identity and Payment ControlsCisco SD-WAN Auth Bypass Shows Edge Control Planes Need Emergency ReviewRansomware Data Theft Surge Shows Why Exfiltration Defense Comes FirstLive Exposed Credentials Show Why Secret Scanning Must End in RevocationAntino Backdoor Shows Why Microsoft 365 C2 Needs Cloud-Aware DetectionSession Cookie Bypass Shows Why SSO Is Not the Whole Trust BoundaryWarlock Ransomware Shows SharePoint Is Still Critical Infrastructure Risk

Category Archive

Social Engineering

28 reports·All intelligence

Bulwark Black cyber threat intelligence filed under Social Engineering.

General CTI
RMM Phishing Turns Trusted Admin Tools Into Persistent Access
General CTI·

RMM Phishing Turns Trusted Admin Tools Into Persistent Access

Microsoft observed phishing campaigns abusing legitimate MSP360 RMM and ScreenConnect to create redundant remote access. Here is what SMB and government-contractor defenders should monitor.

General CTI
Custom GPT ClickFix Shows Why AI Trust Needs Browser-to-Shell Controls
General CTI·

Custom GPT ClickFix Shows Why AI Trust Needs Browser-to-Shell Controls

Attackers abused ChatGPT Custom GPT pages and fake verification prompts to push victims into a ClickFix-to-RAT chain. Here is what SMB and government-contractor defenders should monitor.

General CTI
ClickFix Shows Why Brand Impersonation Needs Workflow-Based Defense
General CTI·

ClickFix Shows Why Brand Impersonation Needs Workflow-Based Defense

Recorded Future’s ClickFix research shows how trusted logos and verification prompts can turn users into the delivery mechanism. Here is how SMBs and government contractors should defend the workflow, not just the payload.

General CTI
EvilTokens Shows Why Device Code Phishing Needs Identity Controls
General CTI·

EvilTokens Shows Why Device Code Phishing Needs Identity Controls

Microsoft says EvilTokens helped compromise more than 12,000 inboxes by abusing device code authentication. Here is what SMBs and government contractors should lock down now.

Cyber Security Blog
Passkey Phishing Shows Why Microsoft 365 Needs Enrollment Guardrails
Cyber Security Blog·

Passkey Phishing Shows Why Microsoft 365 Needs Enrollment Guardrails

Microsoft is tracking passkey-themed social engineering that turns MFA enrollment trust into Microsoft 365 cloud compromise. Here is what SMBs and government contractors should monitor and lock down.

Cyber Security Blog
Revolut Breach Shows Why Data Requests Need Verification Controls
Cyber Security Blog·

Revolut Breach Shows Why Data Requests Need Verification Controls

Revolut confirmed sensitive customer data was disclosed after fraudulent requests appeared to come from a legitimate government agency email domain. Here is what SMBs and government contractors should tighten now.

General CTI
AI Invoice Fraud Shows Why Finance Needs Verification Controls
General CTI·

AI Invoice Fraud Shows Why Finance Needs Verification Controls

Microsoft observed a million-email AI-assisted executive impersonation campaign pushing fabricated invoices and ACH payment requests. For SMBs and government contractors, the fix is not just better spam filtering — it is finance workflow verification.

Social Engineering
Teams Helpdesk Impersonation Shows Why Remote Support Needs Guardrails
Social Engineering·

Teams Helpdesk Impersonation Shows Why Remote Support Needs Guardrails

Microsoft’s Teams helpdesk impersonation case shows why remote support sessions need verification, tool control, user-writable execution limits, and WinRM monitoring.

North Korean Cyber Threat Intelligence
Nisos DPRK Investigation Shows Why Remote Hiring Is a Security Control
North Korean Cyber Threat Intelligence·

Nisos DPRK Investigation Shows Why Remote Hiring Is a Security Control

Nisos’ DPRK employment-fraud investigation shows why remote hiring, contractor onboarding, identity verification, and access control now belong in the same security conversation.

Malware
Fake Claude Opus 5 App Shows Why AI Tooling Needs Software Control
Malware·

Fake Claude Opus 5 App Shows Why AI Tooling Needs Software Control

A fake Claude Opus 5 GitHub desktop app delivering RevStealer shows why AI experimentation needs approved software paths, endpoint controls, and credential-theft triage.

Malware
TerminalFix Shows Why Fake CAPTCHA Lures Are Network Access Problems
Malware·

TerminalFix Shows Why Fake CAPTCHA Lures Are Network Access Problems

Microsoft’s TerminalFix campaign turns fake CAPTCHA social engineering into DLL sideloading, persistence, Active Directory reconnaissance, and reverse-tunnel access. The lesson for SMBs and government contractors: compromised workstations can become internal proxy nodes.

General CTI
Signed ClickOnce Lures Show Why Hiring Workflows Need Endpoint Guardrails
General CTI·

Signed ClickOnce Lures Show Why Hiring Workflows Need Endpoint Guardrails

A fake Web3 interview chain used signed ClickOnce delivery to deploy credential stealers and a Go hVNC RAT. Here is what SMBs and government contractors should tighten now.

Cyber Security Blog
StopAndProtect Shows Why WordPress Sites Are Attack Infrastructure
Cyber Security Blog·

StopAndProtect Shows Why WordPress Sites Are Attack Infrastructure

Check Point Research exposed StopAndProtect, an operation abusing thousands of compromised WordPress sites for ClickFix delivery, malware staging, command routing, victim logging, data theft, and ransomware. The practical lesson: public websites need the same ownership, telemetry, and incident-response discipline as other production infrastructure.

Cyber Security Blog
PurpleDelta Shows Why Remote Hiring Is Now an Insider-Risk Control
Cyber Security Blog·

PurpleDelta Shows Why Remote Hiring Is Now an Insider-Risk Control

Recorded Future’s PurpleDelta research shows North Korean IT worker operations using fabricated personas, AI-assisted interviews, remote desktop tooling, and facilitators to enter legitimate remote technical roles. Defenders should treat hiring, identity proofing, endpoint onboarding, and contractor access as one security workflow.

Cyber Security Blog
Signed ClickOnce Shows Fake Interviews Are Now a Credential-Theft Delivery System
Cyber Security Blog·

Signed ClickOnce Shows Fake Interviews Are Now a Credential-Theft Delivery System

A fake Web3 interview chain used a signed ClickOnce app to deliver stealers and a RAT. Here is what SMBs and government contractors should change in endpoint, identity, and hiring-workflow defenses.

Cyber Security Blog
Ghost Phishing Shows Why Email Security Must Follow the Browser
Cyber Security Blog·

Ghost Phishing Shows Why Email Security Must Follow the Browser

Ghost phishing hides the real lure until the browser renders it. Here is what SMBs and government contractors should do to defend Microsoft 365 identities.

Cyber Security Blog
ARToken Shows Microsoft 365 Tokens Are the New BEC Control Plane
Cyber Security Blog·

ARToken Shows Microsoft 365 Tokens Are the New BEC Control Plane

Cisco Talos uncovered ARToken, an EvilTokens-linked phishing-as-a-service panel built around Microsoft 365 token theft, device-code phishing, mailbox access, SharePoint operations, and BEC automation. The practical lesson: treat identity tokens, inbox rules, and cloud collaborati

Cyber Security Blog
SmartApeSG Okendo Compromise Shows Third-Party Widgets Are Supply-Chain Risk
Cyber Security Blog·

SmartApeSG Okendo Compromise Shows Third-Party Widgets Are Supply-Chain Risk

Zscaler ThreatLabz reported that SmartApeSG injected malicious JavaScript into the Okendo Reviews widget, creating downstream exposure across e-commerce sites. Here is what SMBs and government contractors should do about third-party browser code risk.

Cyber Security Blog
Maine Breach Portal Hoax Shows Disclosure Systems Need Verification Controls
Cyber Security Blog·

Maine Breach Portal Hoax Shows Disclosure Systems Need Verification Controls

Maine took its public breach notification database offline after fake disclosures were published. The lesson for SMBs and government contractors: public trust workflows need verification, moderation, and correction controls.

Cyber Security Blog
Pink Extortion Shows Microsoft 365 Defense Starts With Vishing Controls
Cyber Security Blog·

Pink Extortion Shows Microsoft 365 Defense Starts With Vishing Controls

Unit 42 is tracking Pink / CL-CRI-1147, a Com-affiliated extortion brand using vishing, credential theft, and Microsoft 365 data exfiltration. Here is what SMBs and government contractors should lock down now.

Cyber Security Blog
Error 524 Smishing Shows Why Fraud Infrastructure Needs CTI
Cyber Security Blog·

Error 524 Smishing Shows Why Fraud Infrastructure Needs CTI

Group-IB documented a global smishing operation using fake error pages, geofencing, and encrypted WebSocket exfiltration. Here is what SMBs and government contractors should take from it.

Cyber Security Blog
Chinese-Language PhaaS Shows MFA Bypass Is Becoming Real-Time Fraud
Cyber Security Blog·

Chinese-Language PhaaS Shows MFA Bypass Is Becoming Real-Time Fraud

Google’s reporting on Chinese-language phishing-as-a-service shows why MFA bypass, real-time OTP interception, and digital wallet fraud require phishing-resistant authentication and session monitoring.

AI (General)
Fake OpenAI Hugging Face Repo Shows AI Supply Chain Risk Is Already Here
AI (General)·

Fake OpenAI Hugging Face Repo Shows AI Supply Chain Risk Is Already Here

A fake OpenAI Privacy Filter repository on Hugging Face delivered Windows infostealer malware. Here is what SMB and gov-contractor defenders should take from it.

AI (General)
DeepLoad Malware: AI-Generated Evasion Meets ClickFix Delivery in Enterprise Credential Theft Campaign
AI (General)·

DeepLoad Malware: AI-Generated Evasion Meets ClickFix Delivery in Enterprise Credential Theft Campaign

A sophisticated new malware campaign dubbed “DeepLoad” has emerged targeting enterprise environments, combining ClickFix social engineering delivery with AI-generated obfuscation techniques that defeat traditional security controls. ReliaQuest researchers discovered the threat af

Malware
LeakNet Ransomware Scales Operations with ClickFix Lures and Stealthy Deno-Based Fileless Loader
Malware·

LeakNet Ransomware Scales Operations with ClickFix Lures and Stealthy Deno-Based Fileless Loader

The LeakNet ransomware group is rapidly scaling its operations with two dangerous innovations: a social engineering technique called ClickFix and a previously unreported fileless loader built on the legitimate Deno JavaScript runtime. According to ReliaQuest research, LeakNet has

Social Engineering
Physical Mail Phishing Targets Trezor and Ledger Users: Attackers Use QR Codes to Steal Recovery Phrases
Social Engineering·

Physical Mail Phishing Targets Trezor and Ledger Users: Attackers Use QR Codes to Steal Recovery Phrases

A new phishing campaign is targeting cryptocurrency hardware wallet users through an unusual vector: physical mail. Threat actors are sending fake letters impersonating Trezor and Ledger security teams, attempting to trick users into surrendering their wallet recovery phrases. Th

Social Engineering
Betterment Data Breach Exposes 1.4 Million Customers Following Sophisticated Social Engineering Attack
Social Engineering·

Betterment Data Breach Exposes 1.4 Million Customers Following Sophisticated Social Engineering Attack

Automated investment platform Betterment has disclosed a significant data breach affecting approximately 1.4 million customers, following a sophisticated social engineering campaign that targeted company employees in January 2026. Attack Overview According to Betterment’s officia

Red Teaming
I Got In Without A Badge Easy!? Social Engineering Strategies.
Red Teaming·

I Got In Without A Badge Easy!? Social Engineering Strategies.

People assume social engineering is all charm and quick thinking. But real operators know the truth:Preparation is the payload.Execution is just the final click. This is how I walked into a secured corporate building twice without a badge, without clearance, and without triggerin

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.