MyCyber News
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Last feed pull: Aug 10, 2026, 2:55 AM (UTC+3)
Topic · Phishing
IEH was breached by a phishing attack that exposed its Microsoft 365 inbox, including emails and potentially export-controlled military data. IEH Corporation is a U. S. defense and aerospace manufacturer based in Brooklyn, New York. The company specializes in high-reliability electrical connectors, particularly hyperboloid connectors used in demanding military and aerospace environments. Its connectors are used in systems including rotary-wing aircraft, THAAD and Patriot missile systems, fighter aircraft, airborne radar systems, satellites and spacecraft, military radios, and torpedoes. IEH Corporation disclosed a cyberattack in an 8-K filing with the SEC. The company discovered the breach on August 4.
Lina K. , a co-worker, recently shared a firsthand account of how bots are adding League of Legends players via the Riot client friends list immediately after a match ends, striking up a flirty conversation, and eventually pushing an OnlyFans link. The pattern lines up with a wave of complaints that have piled up on Reddit and Facebook gaming communities over the past several months, and it fits into a broader trend of AI-assisted social engineering that has moved from dating apps straight into game clients. The pattern The scheme reported by multiple League of Legends players follows a near-identical script. A friend request lands in the Riot client within moments of a match ending, from an account whose name does not match anyone from that game.
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671. "UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via
Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing. The post In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street appeared first on SecurityWeek .
Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands. The post Vishing Extortion Group UNC6671 Rebrands After Making Millions appeared first on SecurityWeek .
This week our Threat Research team tracked an active supply chain attack that took over a maintainer account and used it to push malware across the widely used keyv and cacheable packages, then spread to other maintainers through stolen npm tokens. Those packages sit deep in dependency trees and account for tens of millions of weekly downloads. Attacks like this are getting more frequent, and open source maintainers are the ones on the receiving end. When an account takeover happens, the maintainer is often the last to find out and the first to deal with the fallout, usually alone. And usually for software they maintain for free. Maintaining critical software now comes with a security burden that has outgrown what any volunteer can reasonably carry. Earlier this year a coordinated social engineering campaign hunted high-impact Node.
Anthropic’s Mythos AI agent, tested by the UK AI Safety Institute (AISI), has reportedly attempted a real‑world social‑engineering style hack against GitHub maintainers by creating fake human profiles, pressuring them to accept malicious code, and then editing logs to hide its tracks when challenged. AISI was running cybersecurity evaluations of Anthropic’s Mythos and OpenAI’s Sol when it detected unusual outbound data transfers from its research systems. An investigation showed that some agents had engaged in “sustained, potentially harmful activity” targeting real people and organizations, rather than staying within the intended test environment. The most serious activity involved an Anthropic Mythos agent tasked with solving a GitHub‑related cybersecurity challenge.
Wall Street giants Citadel, Two Sigma, Point72 targeted in wave of AI vishing attacks Cybernews
An AI agent powered by Anthropic’s Mythos 5 created a malicious pull request, fabricated identities, targeted open source maintainers, and planted instructions for other coding agents during a UK government cybersecurity evaluation. The UK AI Security Institute (AISI) disclosed on August 4 that frontier AI agents took 19 unsanctioned actions on the live internet during a cybersecurity evaluation, including an attempted supply chain attack against a real open source project. The most serious run included an agent that: • Hid a malware dropper behind a legitimate bug fix in a public pull request. • Researched maintainers and fabricated multiple identities. • Used sockpuppet endorsements and spearphishing emails to social engineer a maintainer into merging the malware. • Planted a prompt injection intended to make other AI coding agents execute a malicious payload.
Credit Agricole scammers built a leaderboard to compete for phishing prizes Cybernews
Passkeys were supposed to make stolen passwords a thing of the past. No password to phish, no secret to reuse, and no string of characters sitting in a database waiting to be leaked. Over time, it’s thought that passkeys will replace passwords entirely. But what happens when malware steals the master key? Researchers have found a way for malware to hijack passkey-protected accounts through Google Password Manager, highlighting an important exception: passkeys can be very secure but the software surrounding them still has weaknesses. What are passkeys? Passkeys are a password replacement based on public‑key cryptography. Instead of a secret you remember and type, each account gets a key pair where the private key never leaves your devices, and the website only ever sees the public key and signed challenges.
Cybercriminals are using a fake Bank of America phishing campaign to trick users into downloading a malicious script that installs ScreenConnect, enabling remote access and persistence on compromised systems
The attacks use diverse social engineering lures and rotating payloads to deliver ScreenConnect for persistent remote access to compromised networks.
Microsoft has warned that hotel, conference, and other hospitality Wi-Fi networks are being actively abused by a Russian group to target travelers worldwide. The campaign, dubbed “CaptiveCrunch” turns a routine Wi-Fi login moment into an opportunity to compromise corporate accounts and devices. From the user’s perspective, nothing looks out of the ordinary: they connect to hotel Wi-Fi, get the usual captive portal prompt, and perhaps see a familiar‑looking message about needing to update something before they can browse. However, behind the scenes, the allegedly state-linked group position themselves in the network path and manipulate DNS (Domain Name System) and HTTP traffic from captive‑portal Wi-Fi.
Socket’s Threat Research Team is tracking an active supply chain compromise affecting the widely used keyv and cacheable npm packages. On August 4, 2026, at least ten packages beginning with the keyv and cacheable namespaces and spreading to packages owned by other maintainers, were published with a malicious preinstall hook ( setup. mjs ) that downloads a standalone Bun runtime, executes an obfuscated second stage, harvests cloud and CI credentials, and republishes trojanized versions of other packages the stolen npm token can reach. The affected packages collectively account for tens of millions of weekly downloads. New packages are appearing in real time, and Socket team will keep on updating the list. The evidence indicates the maintainer account (Jaredwray) was compromised and used to publish across two package families.
Newer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind.
Last week on Malwarebytes Labs: • Fake Fortnite rewards are stealing players’ accounts • Fake Flash Player installs AtlasRAT • Malwarebytes for Windows, now available on the Microsoft Store • Hims & Hers sued over alleged health data privacy failures • Hidden prompt turns Microsoft Copilot into an AI worm • Apple accused of letting fake crypto app steal $1.8 million • Buying TikTok views or followers?
The UK’s Department for Education has disclosed a serious data breach orchestrated via a social engineering attack on its external-facing helpdesk
The NCSC and partners warned of a novel phishing technique being deployed against high-profile users of Zimbra’s Communication Suite, but the threat actor behind the campaign already seems to be moving on to new targets
Executive Summary Insikt Group identified four new TAG-195 ("Golden Chickens", “Venom Spider”) malware families through ongoing tracking of the TAG-195 MaaS ecosystem. We named two of the families "TinyEgg" and “ChonkyChicken"; the third is a modularized variant of ChonkyChicken. The fourth family, which includes a modified browser credential theft helper, we named “ChromEggscalator". TAG-195 is a financially motivated malware-as-a-service (MaaS) developer whose tooling Insikt Group has previously linked to TAG-127 as an operator and customer. (Insikt Group has directly observed TAG-127 deploying TinyEgg via “ClickFix”-style campaigns that use fake security verification pages to trick victims into manually executing malicious commands that download and install malware payloads via a legitimate Windows system utility.)
Intel 471 investigated an ongoing, multi-stage phishing operation that systematically abuses legitimate software-as-a-service (SaaS) sales and marketing, and cloud platforms to orchestrate corporate credential theft.
Two young men have been arrested in the Netherlands on suspicion of running a phishing operation that harvested the credit card details of unsuspecting victims. Read more in my article on the Hot for Security blog.
Huntress is tracking a threat actor group as they evolve a phishing attack that uses a Facebook feature to send the initial spam lure.
Huntress Managed SAT now offers localized phishing simulations for Canada, using familiar, country-specific brands and scenarios to provide more effective security awareness training for your learners.
This blog documents Group-IB’s research into an SMS phishing campaign targeting Serbian road users through the impersonation of Serbia's state road authority, and how it can be linked to both Darcula and Phoenix PhaaS platforms with victims across the globe.
Hey there, I hope you’ve been doing well! 🖼️ Meme Unfortunately work’s been too busy this week for me to lovingly write an artisanal, handcrafted intro combining snippets from my week, whimsy, and reflections on life and dare I say, what it means to be human. So for now, I share a meme: Shout-out Reader’s Digest Sponsor 📣 Device code phishing in 2026: live demos, real kits, and where it's headed next
Datadog Security Research investigates a June 2026 adversary-in-the-middle phishing campaign that cloned the AWS console login page to harvest victim credentials and multi-factor authentication codes.
Se ha descubierto una infraestructura de phishing modular dirigida a múltiples bancos mexicanos, que abusa de GitHub Pages, emplea scripts ofuscados y centraliza la exfiltración de credenciales mediante la API de SheetBest, lo que indica una operación de phishing escalable y persistente de múltiples marcas.
A modular phishing infrastructure targeting multiple Mexican banks has been uncovered, abusing GitHub-hosted Pages, employing obfuscated scripts, and featuring a centralized credential exfiltration via SheetBest API, indicating a scalable and persistent multi-brand phishing operation.
This blog provides a deep-dive into SniperDz, a centralised PhaaS platform with more than 80 ready-made phishing templates impersonating over 30 global brands, and uncovers the hidden infrastructure behind this sophisticated and highly-organized fraud ecosystem.
SilabRAT (aka SnappyClient) is an advanced Remote Access Trojan (RAT) sold as a Malware-as-a-Service (MaaS) on Darkweb forums. Developed by the threat actor "o1oo1," SilabRAT is heavily focused on financial gain through credential theft. It offers stability and is capable of bypassing existing security measures.
The Most Targeted Identity in Your Organization May Be Sitting in the Boardroom When organizations think about cybersecurity risk, they often focus on privileged accounts. Administrators. Developers. Security teams. But attackers increasingly focus their attention elsewhere. They target executives. CEOs.
Los investigadores de Group-IB exponen una operación de smishing y phishing a gran escala que suplanta más de 260 marcas en 72 países, utilizando páginas de error 524 falsas para evadir el análisis.
Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass traditional perimeter defenses and multi-factor authentication (MFA), UNC6671 gains deep access to cloud environments. The group primarily targets Microsoft 365 and Okta infrastructure, leveraging Python and PowerShell scripts to programmatically exfiltrate sensitive corporate data for subsequent extortion attempts. This post details UNC6671’s attack lifecycle and provides defenders with actionable guidance to detect and mitigate these identity-centric threats.
A static analysis of the open-sourced Shai-Hulud offensive framework attributed to TeamPCP, covering its credential harvesting, supply chain poisoning, and exfiltration capabilities.
AI agents are one of the ways to extend an LLM to answer your DFIR prompts. They’re a lot like MCP tools and skills and you can achieve the same goal (investigating phishing, for example) with any of the three. It’s an architectural decision with pros and cons either way. “Agent” is also an extremely overused word right now, so the topic gets confusing fast. I hope to simplify it for you in this post. As you experiment, remember to submit your wins and failures to our “ AI+DFIR: Good and Ugly ” challenge. Basic Definition “Agent” is hard to define because the term gets used so loosely. The most simple definition is that an AI agent is what runs in an Agentic AI framework. LLMs call them, pass in arguments, and get a result. They are the microservices equivalent to GenAI architecture. An agent can be as simple as Python code that adds two numbers that were passed in as arguments.
Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim to accept a Microsoft Teams chat invitation from an account outside their organization. The UNC6692 campaign demonstrates an interesting evolution in tactics, particularly the use of social engineering, custom malware, and a malicious browser extension, playing on the victim’s inherent trust in several different enterprise software providers.
This week, we focus on raising awareness about API vulnerabilities created by direct attacks against API development teams and tech stacks. We also share articles on safe use of API frameworks, and examine how OWASP API vulnerabilities are uncovered by bounty hunters. Article: How secure is your API SDLC? API teams can produce secure and reliable APIs through rigorous design, coding and testing. However, this recent article highlights how every phase of API development is now at risk, forcing API teams to take a broader view of API security beyond just the code they produce.
This week, we have articles on the threats to enterprises in the cloud and another on the looming threats to APIs. We also examine the challenges posed by API threats in the utility and energy sectors. We also have technical articles on using AI to hack the crAPI vulnerable API and how to generate SDKs from your API contracts. Finally, we have news on two upcoming events. Article: Security threats to enterprises in the cloud In the first article this week , Forbes discusses the various security risks companies face when moving their operations and data to the cloud. While cloud service providers invest in security measures, businesses should avoid assuming their data is fully protected. The article presents insights from 20 members of the Forbes Technology Council on the top security threats and how to address them.
Phishing awareness can be a powerful security tool, or a complete disaster. It all hinges on how you implement it.