National Cyber Warfare Foundation (NCWF)

Deceptive AI Bots Spread Malware, Raise Security Concerns


0 user ratings
2023-08-21 16:32:11
milo
Developers , Blue Team (CND) , Malware , Policy / Governance

 - archive -- 
ESET said Facebook promoted the download of what seemed to be Google’s Bard AI tool

Deceptive AI Bots Spread Malware, Raise Security Concerns
https://www.infosecurity-magazine.com/news/deceptive-ai-bots-spread-malware/
ESET said Facebook promoted the download of what seemed to be Google’s Bard AI tool
Mon, 21 Aug 2023 16:30:00 GMT
https://www.infosecurity-magazine.com/news/deceptive-ai-bots-spread-malware/

Source: InfosecMagazine
Source Link: https://www.infosecurity-magazine.com/news/deceptive-ai-bots-spread-malware/


Comments
new comment
Nobody has commented yet. Will you be the first?
CVE mentions by industry news 
Google Play Early Access Abused to Push Thousands of Deceptive Android Apps 
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 113 
FBI raises alarm over deceptive phishing campaign targeting prominent people 
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations 
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities 
13 Malicious Rabby Firefox Extensions Steal Wallet Keyrings Before They Are Encrypted 
 
Ransom Busters Ransomware Affiliate Targets Victims With Fake Data Recovery Extortion 
Hackers Abuse Thousands of WordPress Sites to Spread StopAndProtect Malware via ClickFix 
Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure 
The NYC Council sent letters to Polymarket, Kalshi, Coinbase, and Gemini Titan to investigate alleged deceptive marketing practices and targeting mino 
The FTC wants to regulate AI for ideological bias 
Don t swing at everything 
Keep going, bro. You ve got this! A data-driven look at how adversaries are weaponizing AI 
222 GitHub Repositories Linked to Fake Go Package Malware Operation 
Telegram-Hosted RedWing Malware Lets Anyone Rent Android Spyware Tools 
Hackers Use Compromised Websites and transcript.pdf.js Lure to Deliver PureLog Stealer 
Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects 
ATF cancels controversial commercial geolocation contract 
New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis 
WhatsApp Malware Campaign Hijacks Trust, Installs Legitimate Admin Tools 
A VBScript campaign distributed through WhatsApp deploying RMM software 
Investigation: Polymarket is paying creators to make deceptive videos about winning bets, targeting users in the US, where its primary crypto platform 
New Rokarolla Android Trojan Targets 217 Banking and Crypto Apps 
Criminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing Cybercrime 
Nimbus Manticore APT Uses Fake Jobs to Deliver Custom Malware 
Florida AG James Uthmeier sues OpenAI and Sam Altman, seeking to hold Altman personally liable for deceptive trade practices, negligence, and public n 
Malicious PDF LNK Files Deploy Cobalt Strike in Operation Dragon Whistle 
Apple Blocks Over 2 Million Apps in 2025 Fraud Crackdown 
Table tennis robot defeats some of world s best players why this has major implications for robotics 
Beyond Acceleration and Automation: How AI + Intelligence Changes Cyber Defense 
Fake TronLink Chrome Extension Steals Crypto Wallet Credentials 
The Different Types of Payment Fraud and How to Prevent Them 
Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware 
Websites with an undefined trust level: avoiding the trap 
Malicious OpenClaw Skill Targets Agentic AI Workflows to Deploy RATs and Stealers 
Microsoft warns of global campaign stealing auth tokens from 35K users 
Fake Notepad++ for Mac Site May Pose Malware Risk for Mac Users 
Malicious TanStack Package Abuses Postinstall Script to Steal Developer Secrets 
AI-powered honeypots: Turning the tables on malicious AI agents 
CVE-2026-42557 
North Korean Fake IT Workers Infiltrate Firms to Dodge Sanctions 
The FTC s AI portfolio is about to get bigger 
Fake Adobe Reader Download Drops ScreenConnect via Fileless Loader 
AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud 
JanelaRAT: a financial threat targeting users in Latin America 
CVE-2026-40153 
The Trojan horse of cybercrime: Weaponizing SaaS notification pipelines 
Tor-Backed ClickFix Campaign Drops Node.js RAT on Windows 
The New Playground for Cybercriminals: Securing the Microsoft Teams Frontier 
Fake Cloudflare CAPTCHA Pages Deliver Infiniti Stealer Malware on macOS 
Baltimore sues xAI, accusing it of violating consumer protection laws and engaging in deceptive trade practices by marketing Grok as generally safe (L 
Mapping Your Defenses to What You Need, Not What You Inherited 
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 88 
Security Affairs newsletter Round 567 by Pierluigi Paganini INTERNATIONAL EDITION 
AI Agents Present Insider Threat as Rogue Behaviors Bypass Cyber Defenses: Study 
New ClickFix Attacks Target macOS Users with MacSync Infostealer 
Massive GitHub malware operation spreads BoryptGrab stealer 
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 87 
Security Affairs newsletter Round 566 by Pierluigi Paganini INTERNATIONAL EDITION 
Malicious Browser Add on Targets imToken Users Private Keys 
What Is Address Poisoning 
Meta Files Lawsuits Against Brazil, China, Vietnam Advertisers Over Celeb-Bait Scams 
‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA 
Los Angeles County sues Roblox, alleging it engaged in deceptive business practices that exposed children to sexual content, exploitation, and online  
Cryptocurrency Scams in Asia Combine Malvertising and Pig Butchering, Causing Losses Up to 10 Million 
SmartLoader hackers clone Oura MCP project to spread StealC malware 
Malicious npm and PyPI packages linked to Lazarus APT fake recruiter campaign 
Snapchat's woes escalate with complaint to FTC 
Botnet Takedowns: Effective or Deceptive? 
Google to Label Malware Sites with 30-Day Full Page Alerts 
US Bank Slammed for "Vague and Deceptive" Breach Disclosure 
New Family of Deceptive Gaming Apps Discovered 
Spam Campaign Distributes Fake PDFs, Deploys Remote Monitoring Tools for Ongoing Access 
Cybersecurity Alert: Fake Traffic Ticket Portals Target Personal, Credit Card Data 
Cyberattackers Exploit DNS TXT Records in ClickFix Script to Execute Malicious PowerShell Commands 
Fake Party Invites Lure Victims Into Installing Malicious Remote Access Tools 
Malicious Google Play App With 50K+ Downloads Spreads Anatsa Banking Trojan 
Helpdesk Impersonation: A High-Risk Social Engineering Attack 
The staggering cybersecurity weakness that isn t getting enough focus, according to a top Secret Service official 
Google targets IPIDEA in crackdown on global residential proxy networks 
Fake Mac Cleaner Campaign Uses Google Ads to Redirect Users to Malware 
MacSync macOS Infostealer Exploits ClickFix-style Attack to Trick Users with Single Terminal Command 
Threat Actors Exploit LNK Files to Deploy MoonPeak Malware on Windows Systems 
Fake Captcha Exploits Trusted Web Infrastructure to Distribute Malware 
Google Gemini Flaw Let Attackers Access Private Calendar Data 
CVE-2026-23731 
HoneyTrap: Outsmarting Jailbreak Attacks on Large Language Models 
Fake Booking.com lures and BSoD scams spread DCRat in European hospitality sector 
Russia-linked APT UAC-0184 uses Viber to spy on Ukrainian military in 2025 
McDonald s McRib Under Fire in Lawsuit Claiming No Rib Meat 
Amazon to Issue Refund Checks After Record $2.5 Billion Prime Settlement 
Transparent Tribe Launches New RAT Attacks Against Indian Government and Academia 
Google Tasks Feature Exploited in New Sophisticated Phishing Campaign 
APT36 Targets Indian Government Systems Using Malicious Windows LNK Files 
New Cybercrime Tool ErrTraffic Enables Automated ClickFix Attacks 
WebRAT Malware Campaign Leveraging GitHub-Hosted Proof-of-Concept Code 
Targeted Phishing Attack Strikes HubSpot Users 
Instacart will pay $60M to settle FTC allegations that it used deceptive tactics in its subscription signup and "satisfaction guarantee" adv 
California's DMV says a California administrative law judge recently ruled that Tesla engaged in deceptive marketing around its Autopilot and FSD 
California DMV says a California administrative law judge recently ruled Tesla engaged in deceptive marketing around its Autopilot and Full Self-Drivi 
Most Parked Domains Now Serving Malicious Content 
The US FTC, along with 21 states and DC, files an amended complaint against Uber, alleging deceptive billing and cancellation practices related to Ube 
Frogblight Android Malware Spoofs Government Sites to Collect SMS and Device Details 
The EU fines X 120M for breaching online content rules, the first fine under the DSA, citing issues like its deceptive blue checkmarks, after a two 
Hackers Abuse Microsoft Teams Notifications to Launch Callback Phishing Attacks 
The EU fines X 120M for breaching online content rules, the first fine under the DSA, citing issues including the deceptive design of its blue chec 
Chrome Extension Malware Secretly Adds Hidden SOL Fees to Solana Swap Transactions 
Unraveling the Web of Russian Disinformation Campaigns 
ClickFix Attack Uses Steganography to Hide Malware in Fake Windows Security Update 
Attackers Swap m with rn in Microsoft.com to Trick Users 
To buy or not to buy: How cybercriminals capitalize on Black Friday 
Operation DreamJob Attacks on Manufacturing via WhatsApp Web 
CTM360 Exposes a Global WhatsApp Hijacking Campaign: HackOnChat 
New npm Malware Campaign Checks If Visitor Is a Victim or Researcher Before Initiating Infection 
WhatsApp Screen-Sharing Scam: How Attackers Are Deceiving Users to Expose Sensitive Information 
The UK CMA opens probes into StubHub, Viagogo, and others over allegedly deceptive online pricing practices; the UK plans to ban above face value tick 
Microsoft Entra Invitations Hijacked in Surge of TOAD Phishing Attacks 
Phishing Emails Alert: How Spam Filters Can Steal Your Email Logins in an Instant 
SmartApeSG Uses ClickFix to Deploy NetSupport RAT 
Beware of Security Alert-Themed Malicious Emails that Steal Your Email Logins 
Malicious PuTTY Ads Deliver OysterLoader, Allowing Attackers Full Device and Network Access 
Beware of Fake ChatGPT Apps That Spy on Users and Steal Sensitive Data 
Crypto wasted: BlueNoroff’s ghost mirage of funding and jobs 
North Korean Chollima Actors Added BeaverTail and OtterCookie to its Arsenal 
Apple and Google challenged by parents rights coalition on youth privacy protections 
Clickbait Scams: The Misleading Method of Phishing 
New Tech Support Scam Exploits Microsoft Logo to Steal User Credentials 
BeaverTail and OtterCookie evolve with a new Javascript module 
Hackers Mimic as OpenAI and Sora Services to Steal Login Credentials 
Unverified COTS hardware enables persistent attacks in small satellites via SpyChain 
Cybercrime ring GXC Team dismantled in Spain, 25-year-old leader detained 
ClayRat Android Malware Masquerades as WhatsApp & Google Photos 
Anthropic's open-source safety tool found AI models whisteblowing - in all the wrong places 
New Android Spyware Targeting Users by Imitating Signal and ToTok Apps 
Threat Actors Imitate Popular Brands in New Malware Distribution Campaigns 
Alert: Malicious PyPI Package soopsocks Infects 2,653 Systems Before Takedown 
Anthropic touts safety, security improvements in Claude Sonnet 4.5 
Malicious Code in Fake Postmark MCP Server Steals Thousands of Emails 
Amazon owes Prime customers up to $51 each - how to get your share 
Amazon to pay $2.5B settlement over tricking Prime subscribers - how to get your share 
Amazon reaches a $2.5B settlement with the FTC over deceptive Prime practices, with a $1B civil penalty and $1.5B in consumer redress, three days into 
Hackers Deploy Stealthy Malware on WordPress Sites to Gain Admin Access 
Inboxfuscation Tool Bypasses Exchange Inbox Rules and Evades Detection 
Trojan Horse Virus: Understanding, Detecting, and Defending with Seceon 
AI-Driven Phishing Attacks: Deceptive Tactics to Bypass Security Systems 
Put together an IR playbook for your personal mental health and wellbeing 
Hackers Abuse RTL LTR Text Tricks and Browser Flaws to Mask Malicious Links 
Attorney Generals go after Bitcoin ATMs for supporting Fraud 
These popular free VPNs all share the same shady security practices - here's why 
Chrome Extension Scam Exposed: Hackers Stealing Meta Accounts 
Meta Verified Scam Ads on Facebook Steal User Account Details 
Supreme Court blocks FTC commissioner Slaughter s reinstatement 
U.S. Officials Investigating Cyber Threat Aimed at China Trade Talks 
GOP Cries Censorship Over Spam Filters That Work 
New Scam Targets PayPal Users During Account Profile Setup 
XWorm Malware Adopts New Infection Chain to Bypass Security Detection 
TinyLoader Malware Spreads via Network Shares and Malicious Shortcut Files on Windows 
New WhatsApp Scam Poses Serious Risk: Hackers Can Hijack Your Chats 
Affiliates Flock to ‘Soulless’ Scam Gambling Machine 
Weaponized ScreenConnect RMM Tool Deceives Users into Installing Xworm RAT 
H1 2025 Malware and Vulnerability Trends 
ShadowCaptcha Exploit: Massive WordPress Site Compromise Used to Execute Malicious Commands on Victims 
Beware! Fake Google Play Store Sites Used to Spread Android Malware 
Beware! Google Ads Promote Fake Tesla Websites Soliciting Fraudulent Deposits 
Rogue Go Module Doubles as Fast SSH Brute-Forcer, Sends Stolen Passwords via Telegram 
Hackers Weaponize QR Codes With Malicious Links to Steal Sensitive Data 
Cybercriminals Deploy CORNFLAKE.V3 Backdoor via ClickFix Tactic and Fake CAPTCHA Pages 
New Research Reveals Security Vulnerabilities Linked to Popular VPN Apps 
US-China AI Gap: 2025 Analysis of Model Performance, Investment, and Innovation 
Smarter Cybersecurity with IPv6: How Drip Architecture Defeats Spray-and-Pray Attacks 
Proxyware Campaign Piggybacks on Popular YouTube Video Download Services 
Emerging AI-Driven Phishing Trends Reshape Cybercrime Tactics 
CastleLoader Malware Hits 400+ Devices via Cloudflare-Themed ClickFix Phishing Attack 
SocGholish Uses Parrot and Keitaro TDS to Spread Malware via Fake Updates 
A US federal judge strikes down a California law blocking large platforms from hosting deceptive AI-generated content related to elections, citing Sec 
A federal judge struck down a California law blocking large platforms from hosting deceptive AI-generated content related to elections, citing Section 
Over 10,000 Malicious TikTok Shop Domains Target Users with Malware and Credential Theft 
Cloudflare Accuses Perplexity AI of Bypassing Firewalls with User-Agent Spoofing 
Silver Fox Hackers Exploit Weaponized Google Translate Tools to Deliver Windows Malware 
Scammers Unleash Flood of Slick Online Gaming Sites 
PyPI Alerts Developers to New Phishing Attack Using Fake PyPI Site 
Got a suspicious Amazon refund text? Don't click the link - it's a scam 
Scattered Spider targets VMware ESXi in using social engineering 
Malicious ISO File Used in Romance Scam Targeting German Speakers 
Rogue CAPTCHAs: Look out for phony verification pages spreading malware 
Hackers Exploit Google Forms to Trick Victims into Stealing Cryptocurrency 
Fake Indian Banking Apps on Android Steal Login Credentials from Users 
DSPM & AI Are Booming: $17.87B and $4.8T Markets by 2033 
New Web3 Phishing Scam Uses Fake AI Platforms to Steal Credentials 
BaitTrap Reveals Global Web of 17,000+ Fraud-Promoting Fake News Sites 
Iranian group Pay2Key.I2P ramps Up ransomware attacks against Israel and US with incentives for affiliates 
Anatsa Android Banking Trojan Hits 90,000 Users with Fake PDF App on Google Play 
North Korea-linked threat actors spread macOS NimDoor malware via fake Zoom updates 
Cybercriminals Use Malicious PDFs to Impersonate Microsoft, DocuSign, and Dropbox in Targeted Phishing Attacks 
CVE-2025-7021 
Trump's big, revised bill will slash AI funding for states that regulate AI 
Glasgow City Warns of Parking Fine Scam Amid Ongoing Cybersecurity Incident 
Cybercriminals Exploit CapCut Popularity to Steal Apple ID Credentials and Credit Card Data 
Malicious Passlib Python Package Triggers Windows Shutdowns with Invalid Inputs 
Threat Actors Use Clickfix Tactics to Deploy Malicious AppleScripts for Stealing Login Credentials 
N. Korean Group BlueNoroff Uses Deepfake Zoom Calls in Crypto Scams 
IPv6 Drip Drowns Spray-and-Pray 
Threat Actors Manipulate Search Results, Exploit ChatGPT and Luma AI Popularity to Deliver Malicious Payloads 
Black Hat SEO Poisoning Search Engine Results For AI to Distribute Malware 
OpenAI Used Globally for Attacks – FireTail Blog 
APT36 Hackers Target Indian Defense Personnel with Sophisticated Phishing Campaign 
Beware of Weaponized MSI Installer Masquerading as WhatsApp to Deliver XWorm RAT 
Mocha Manakin Uses Paste-and-Run Technique to Deceive Users into Downloading Malware 
Threat Actors Manipulate Google Search Results to Display Scammer’s Phone Number Instead of Real Number 
Threat Actors Exploit Vercel Hosting Platform to Distribute Remote Access Malware 
North Korean Hackers Deploy Malware Using Weaponized Calendly and Google Meet Links 
BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with MacOS Backdoor Malware 
Beware: Fake CAPTCHA Windows Stealthily Install LightPerlGirl Malware 
Cybercriminals Leverage ClickFix Strategy to Deploy RATs and Data-Stealing Malware 
Hackers Use Fake Verification Prompt and Clickfix Technique to Deploy Fileless AsyncRAT 
CVE-2025-52449 
Cybersecurity Snapshot: NIST Offers Zero Trust Implementation Advice, While OpenAI Shares ChatGPT Misuse Incidents 
Inside a Dark Adtech Empire Fed by Fake CAPTCHAs 
Beware of Instagram Growth Tools Stealing Login Credentials and Sending Them to Attackers 
New SharePoint Phishing Campaigns Employing Deceptive Lick Techniques 
Malicious Actors Exploit SoraAI’s Popularity & GitHub to Distribute Malware 
DOJ moves to seize $7.74M in crypto linked to North Korean IT worker scam 
New Blitz Malware Targets Windows Servers to Deploy Monero Miner 
OpenAI bans ChatGPT accounts linked to Russian, Chinese cyber ops 
Report on the Malicious Uses of AI 
Hackers Leverage New ClickFix Tactic to Exploit Human Error with Deceptive Prompts 
Beware: Fake AI Business Tools Spreading Hidden Ransomware 
Hackers Exploit New HTML Trick to Deceive Outlook Users into Clicking Malicious Links 
Threat Actors Abuse ‘Prove You Are Human’ System to Distribute Malware 
Fake DocuSign, Gitcode Sites Spread NetSupport RAT via Multi-Stage PowerShell Attack 
Threat Actors Leverage ClickFix Technique to Deploy EddieStealer Malware 
Threat Actors Exploit Google Apps Script to Host Phishing Sites 
New EDDIESTEALER Malware Bypasses Chrome's App-Bound Encryption to Steal Browser Data 
Parties behind 2024 Biden AI robocall reach deal in lawsuit 
A new author has appeared 
Dark Partner Hackers Leverage Fake AI, VPN, and Crypto Sites to Target macOS and Windows Users 
Malicious WordPress Plugin Disguised as Java Update Infects Site Visitors 
India asks e-commerce platforms and retailers to remove "dark patterns" or deceptive actions that manipulate customers into making unintende 
Threat Actors Weaponize Fake AI-Themed Websites to Deliver Python-based infostealers 
App Store Security: Apple stops $2B in fraud in 2024 alone, $9B over 5 years 
VenomRAT Malware Introduces New Tools for Password Theft and Stealthy Access 
Zanubis in motion: Tracing the active evolution of the Android banking malware 
Crooks use a fake antivirus site to spread Venom RAT and a mix of malware 
Apple Blocks $9 Billion in Fraud Over 5 Years Amid Rising App Store Threats 
The EU says Shein's practices breach its rules against false discounts, deceptive product labels, and more, and warn Shein could face fines if it 
Fake DigiYatra Apps Target Indian Users to Steal Financial Data 
The EU says Shein's practices breach rules against false discounts, deceptive product labels, and more, and warn that it could face fines if it d 
Researchers Warn of Smiao Network Cyber Threat Against Taiwan s Federal Staff 
NSIS Abuse and sRDI Shellcode: Anatomy of the Winos 4.0 Campaign 
Protecting Against Brand Impersonation Attacks with Browser Detection and Response 
Hackers Masquerade as Organizations to Steal Payroll Logins and Redirect Payments from Employees 
DPRK IT Workers Impersonate Polish and US Nationals to Secure Full-Stack Developer Positions 
New Phishing Attack Poses as Zoom Meeting Invites to Steal Login Credentials 
New Ransomware Attack Targets Elon Musk Supporters Using PowerShell to Deploy Payloads 
FTC wants a new, segregated software system to police deepfake porn 
Weaponized Google Calendar Invites Deliver Malicious Payload Using a Single Character 
5 BCDR Essentials for Effective Ransomware Defense 
Threat actors use fake AI tools to deliver the information stealer Noodlophile 
LLM Prompt Injection - What's the Business Risk, and What to Do About It 
Hackers Exploit Fake Chrome Error Pages to Deploy Malicious Scripts on Windows Users 
Hackers Target HR Departments With Fake Resumes to Spread More_eggs Malware 
RomCom RAT Targets UK Organizations Through Compromised Customer Feedback Portals 
Threat Actors Attacking U.S. Citizens Via Social Engineering Attack 
Sneaky WordPress Malware Disguised as Anti-Malware Plugin 
Nitrogen Ransomware Uses Cobalt Strike and Log Wiping in Targeted Attacks on Organizations 
Advanced Multi-Stage Carding Attack Hits Magento Site Using Fake GIFs and Reverse Proxy Malware 
Deel sues Rippling for alleged defamation, libel, and deceptive trade practices, says Rippling placed an insider within Deel, is not tax compliant, an 
“Power Parasites” Phishing Campaign Targets Energy Firms and Major Brands 
Ransomware Actors Ramp Up Attacks Organizations with Emerging Extortion Trends 
Lumma Stealer Tracking distribution channels 
Phishing attacks leveraging HTML code inside SVG files 
Hackers Exploit Node.js to Spread Malware and Exfiltrate Data 
Trump Revenge Tour Targets Cyber Leaders, Elections 
Slow Pisces Group Targets Developers Using Coding Challenges Laced with Python Malware 
Hackers Imitate Google Chrome Install Page on Google Play to Distribute Android Malware 
SpyNote, BadBazaar, MOONSHINE Malware Target Android and iOS Users via Fake Apps 
Malicious mParivahan App Circulates on WhatsApp, Skimming Sensitive Mobile Data 
Vidar Stealer Uses New Deception Technique to Hijack Browser Cookies and Stored Credentials 
Threat Actors Exploit Fake CAPTCHAs and Cloudflare Turnstile to Distribute LegionLoader 
Beware of Clickfix: ‘Fix Now’ and ‘Bot Verification’ Lures Deliver and Execute Malware 
New Credit Card Skimming Campaign Uses Browser Extensions to Steal Financial Data 
CVE-2025-32323 
CVE-2025-32345 
North Korea IT Workers Expand Their Employment Across Europe To Infiltrate the Company Networks 
New Surge of IRS-Themed Attacks Targets Taxpayers Mobile Devices 
ClickFix: Social Engineering That Bypasses EDRs, SWGs and Humans 
Rules File Backdoor: AI Code Editors exploited for silent supply chain attacks 
Fake Coinbase Migration Messages Target Users to Steal Wallet Credentials 
CVE-2025-26435 
Scammers Exploit California Wildfires, Posing as Fire Relief Services 
Fastrak Text Phishing Scam In California: How To Spot Deceptive Messages From Hackers? - Times Now 
Dark web threats and dark market predictions for 2025 
OpenAI's o1 lies more than any major AI model. Why that matters 
15 SpyLoan Android apps found on Google Play had over 8 million installs 
Beware Of SpyLoan Apps Exploits Social Engineering To Steal User Data 
Scammer Black Friday offers: Online shopping threats and dark web sales 
Scammer Black Friday offers: Online shopping threats and dark web 
X sues to block California's AB 2655, aimed at curbing AI-generated deceptive election content on social media, claiming it impinges on free spee 
The Deceptive Media Era: Moving Beyond "Real vs. Fake" 
ClickFix Exploits GMeet & Zoom Pages to Deliver Sophisticated Malware 
Georgia Secretary of State: Haitian immigrant voting video is likely Russian disinformation 
An investigation finds eight deceptive operations on Meta's platforms that collectively controlled 340+ Pages and placed 160K+ ads to collect use 
An investigation finds eight deceptive operations on Meta's platforms that collectively controlled 340+ Pages and placed 160K ads to collect user 
Security Affairs newsletter Round 495 by Pierluigi Paganini INTERNATIONAL EDITION 
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 17 
Operation Overload Impersonates Media to Influence 2024 US Election 
Researchers Reveal 'Deceptive Delight' Method to Jailbreak AI Models 
Stealer here, stealer there, stealers everywhere! 
OpenAI Blocks 20 Global Malicious Campaigns Using AI for Cybercrime and Disinformation 
OpenAI says it has disrupted 20+ operations and deceptive networks in 2024 so far that tried to use its models, including four that had election-relat 
New Perfctl Malware targets Linux servers in cryptomining campaign 
We can try to bridge the cybersecurity skills gap, but that doesn t necessarily mean more jobs for defenders 
DragonRank, a Chinese-speaking SEO manipulator service provider 
Phishing Via Typosquatting and Brand Impersonation: Trends and Tactics 
U.S. CISA adds Draytek VigorConnect and Kingsoft WPS Office bugs to its Known Exploited Vulnerabilities catalog 
Disinfo group Spamouflage more aggressively targeting U.S. elections, candidates 
Deceptive AI: A New Wave of Cyber Threats 
Cthulhu Stealer Malware Targets macOS With Deceptive Tactics 
GreenCharlie Infrastructure Targeting US Political Entities with Advanced Phishing and Malware 
GreenCharlie Infrastructure Linked to US Political Campaign Targeting 
Vulnerability Summary for the Week of August 12, 2024 
BlindEagle flying high in Latin America 
Telegram Bot Selling Phishing Tools to Bypass 2FA & Hack Microsoft 365 Accounts 
North Korean Kimusky Group Attacking University Professors 
Hackers Exploit iOS Settings to Trigger Fake iOS Updates on Hijacked Devices 
Chameleon Device-Takeover Malware Attacking IT Employees 
Hackers Abused StackExchange Platform To Deliuver Malicious Python Package 
Security Affairs Malware Newsletter – Round 5 
Meta paid a $1.4 Billion Settlement for the Unauthorized Capture of Personal Biometric Data 
CVE-2024-7262 
Threat Actots Leveraging ChatGPT To Craft Sophisticated Attacks 
Storm-0835 
Mozilla and AI Forensics: TikTok Lite, launched in 2018 and aimed at poorer markets, leaves AI-generated content unlabeled and lacks other similar saf 
Beware! of New Phishing Tactics Mimic as HR Attacking Employees 
ViperSoftX Weaponizing AutoIt & CLR For Stealthy PowerShell Execution 
New FishXProxy Phishing Kit Making Phishing Accessible to Script Kiddies 
New FishXProxy Phishing Kit Lowers Barriers for Cybercriminals 
How do cryptocurrency drainer phishing scams work? 
APT42 
Cybersecurity regulations face uphill battle after Chevron ruling 
CVE-2024-6429 
Harnessing Email Data to Stop Phishing Attacks with Falcon Next-Gen SIEM 
Seeing the Unseen: Preventing Breaches by Spotting Malicious Browser Extensions 
Experts observed approximately 120 malicious campaigns using the Rafel RAT 
How to Identify and Protect Against Phishing Emails Leveraging Data Broker Information 
Smishing Triad Is Targeting Pakistan To Defraud Banking Customers At Scale 
The Techno Rebels 
BRONZE BUTLER 
ScarCruft 
Sticky Werewolf Weaponizing LNK Files Group Attacking To Attack Organizations 
Short Version: The Belt and Road Initiative and Human Trafficking (April 2024) 
Long Version: The Belt and Road Initiative and Human Trafficking (April 2024) 
North Korean Hackers Abusing Facebook & MS Management Console 
SocGholish Attacks Enterprises Via Fake Browser Updates 
State of ransomware in 2024 
Beware of Phishing Attacks Targeting AmericanExpress Card Users 
The EU opens a DSA investigation into Meta over deceptive Facebook and Instagram ad and political content; sources say the probe is about a pro-Kremli 
The EU opens a DSA investigation into Facebook and Instagram over deceptive ad and political content; sources say the move relates to a pro-Kremlin ca 
Congressional privacy bill looks to rein in data brokers 
Hackers Manipulate GitHub Search To Deliver Clipboard-Hijacking Malware 
Notepad++ Wants Your Help to Take Down the Parasite Website 
China is using generative AI to carry out influence operations 
Indian Govt Rescues 250 Citizens Trapped In Cambodia Forced Into Cyber-Slavery 
HYAS Threat Intel Report April 1 2024 
Beware of New HelloFire Ransomware Actor Mimic as a Pentester 
Beware Of Free wedding Invite WhatsApp Scam That Steal Sensitive Data 
GBHackers Weekly Round-Up: Cyber Attacks, Vulnerabilities, Threats & New Cyber Stories 
Hackers Trick Users to Install Malware Via Weaponized PDF 
Beware Of New Malicious PyPI Packages That Steal Wallet Passwords 
Tweaks Stealer Targets Roblox Users Through YouTube and Discord 
Security Affairs newsletter Round 462 by Pierluigi Paganini INTERNATIONAL EDITION 
New CHAVECLOAK Banking Trojan Targets Brazilians via Malicious PDFs 
New Linux variant of BIFROSE RAT uses deceptive domain strategies 
Deceptive AI content and 2024 elections Week in security with Tony Anscombe 
RisePro Stealer Attacks Windows Users Steals Sensitive Data 
New BIFROSE Linux Malware Variant Using Deceptive VMware Domain for Evasion 
Unmasking 2024’s Email Security Landscape 
Meta outlines its strategy to combat generative AI misuse ahead of the European elections in June 2024, including setting up an EU-specific operations 
Avast Fined Millions for Selling User Browsing Data 
Meta outlines its strategy to combat the misuse of generative AI ahead of the European elections in June, including setting up an EU-specific operatio 
Deepfake Threat: $2 Deceptive Content Undermines Election Integrity 
TEGWAR, AI and the FTC – Gov’t Agency Warns of Deceptive AI Contract Language 
Google DeepMind announces AI Safety and Alignment, an organization that includes a new team focused on AGI safety alongside existing teams working on  
How BRICS Got “Rug Pulled” Cryptocurrency Counterfeiting is on the Rise 
Nation-state actors are using AI services and LLMs for cyberattacks 
Abusing the Ubuntu ‘command-not-found’ utility to install malicious packages 
U.S. Internet Leaked Years of Internal, Customer Emails 
PikaBot Resurfaces with Streamlined Code and Deceptive Tactics 
Uncovering the Deceptive Tactics of Chinese Websites Mimic as Local News 
New Hampshire authorities trace Biden AI robocall to Texas-based telecom 
ApateWeb: Hackers Using 130,000+ Domains to Launch Cyber Attacks 
Hundreds of network operators credentials found circulating in Dark Web 
That new X cryptocurrency? It’s a scam. 
Dark web threats and dark market predictions for 2024 
Anthropic researchers: AI models can be trained to deceive and the most commonly used AI safety techniques had little to no effect on the deceptive be 
3 New Malicious PyPI Packages Found Installing CoinMiner on Linux Devices 
Cybercriminals Implemented Artificial Intelligence (AI) for Invoice Fraud 
Cybersecurity Post-Incident Cleanup What You re Probably Not Doing 
Android Malware Actively Infecting Devices to Take Full Control 
Rogue WordPress Plugin Exposes E-Commerce Sites to Credit Card Theft 
Law enforcement Operation HAECHI IV led to the seizure of $300 Million 
Sidewinder Hacker Group Using Weaponized Documents to Deliver Malware 
Researchers Uncovered an Active Directory DNS spoofing exploit 
Surge in deceptive loan apps Week in security with Tony Anscombe 
New Krasue Linux RAT targets telecom companies in Thailand 
Doppelg nger: Hackers Employ AI to Launch Highly sophistication Attacks 
Beware of predatory fin(tech): Loan sharks use Android apps to reach new depths 
SpyLoan Scams Target Android Users With Deceptive Apps 
Obfuscation and AI Content in the Russian Influence Network Doppelg nger Signals Evolving Tactics 
A New Telekopye Bots That Tricks Users to Steal Payment Details 
North Korea-linked APT Diamond Sleet supply chain attack relies on CyberLink software 
Consumer cyberthreats: predictions for 2024 
Experts warn of a surge in NetSupport RAT attacks against education and government sectors 
The dark side of Black Friday: decoding cyberthreats around the year’s biggest shopping season 
Improving Automation and Accessibility Drive $100 Billion in Projected Ad Fraud Losses 
Uncovering Prolific Puma, Massive Domain Generator & URL Shortener 
Are Corporate VPNs Secure? 
StripedFly: Perennially flying under the radar 
Android Malware Masquerades as Chrome Browser Reads SMS & Intercepts Emails 
US DoJ seized domains used by North Korean IT workers to defraud businesses worldwide 
Digital Identification: The Cornerstone for Confidence Online 
Hackers are Abusing Dropbox to Steal Microsoft SharePoint Credentials 
Your next online dating match might actually be ChatGPT 
Rogue npm Package Deploys Open-Source Rootkit in New Supply Chain Attack 
FortiGuard Uncovers Deceptive Install Scripts in npm Packages 
New SMS Phishing Campaign Impersonating The US Postal Service 
Is My Boss Spying on Me, Instagram Painting Scam, Kia and Hyundai TikTok Challenge 
Microsoft s Bing AI Faces Malware Threat From Deceptive Ads 
More than 30 US Banks Targeted in New Xenomorph Malware Campaign 
FTC nominees urge Congress to pass federal data privacy law 
Russian APT28 Hacking Group Attacking Critical Power Infrastructure 
“Smishing Triad” Targeted USPS and US Citizens for Data Theft 
Publicly available Evil_MinIO exploit used in attacks on MinIO Storage Systems 
Deceptive Links, Brand Impersonation, and Identity Deception Top the List of Phishing Attack Tactics 
US tech firms offer data protections for Europeans to comply with EU big tech rules 
GUEST ESSAY: Lessons to be learned from the waves of BofA phone number spoofing scams 
SolarMarker Malware Uses Novel Techniques to Persist on Hacked Systems 
The rise of AI-powered criminals: Identifying threats and opportunities 
Top Malware Delivery Tactics to Watch Out for in 2023 
Online influence operators continue fine-tuning use of AI to deceive their targets, researchers say 
CVE-2021-21303 
CVE-2019-16681 
 
Forum
Developers
Blue Team (CND)
Malware
Policy / Governance



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.