Wednesday 29 July 2026 00:13:35 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

Security Awareness & Social Engineering / North America


The Kit Was Burned, Not the Playbook: Kratos and the Afterlife of Phishing Infrastructure

Published: 28 July 2026 19:21Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A July 2026 disruption did not end the threat around Kratos - it appears to have pushed its methods into fresh Microsoft 365 phishing campaigns.

Search Ads, Fake Installers, and the Mac Trust Trap

Published: 28 July 2026 19:05Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A malvertising campaign is using Google Ads and a fake Claude Code installer to reach macOS users, showing how cybercrime now leans on trust instead of obvious exploits.

One Phishing Kit Fell, but Microsoft 365 Attackers Kept the Blueprint

Published: 28 July 2026 14:46Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

The disruption of Kratos may have removed one criminal service, but the deeper problem is the reusable playbook behind modern Microsoft 365 account-takeover campaigns.

Support Calls, Remote Access, and a Hidden Backdoor: A Quiet Path Into Employee PCs

Published: 28 July 2026 14:25Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A reported social-engineering intrusion used fake IT contact, Microsoft Teams, and Quick Assist to reach employee computers before the GoGRPC backdoor was installed, with ransomware ties still unconfirmed.

Fake Teams Update, Real Remote Access: The BlueDash Playbook

Published: 27 July 2026 16:46Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A counterfeit Microsoft Teams update flow is being used to push legitimate remote management tools onto victim systems, blurring the line between phishing and admin software abuse.

More Than 70 Look-Alike Windows Download Sites Turn Software Search Into a Trap

Published: 27 July 2026 14:17Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A cluster of impersonation domains shows how attackers can abuse search traffic, brand trust, and download reputation before any file ever reaches the desktop.

Fake Download Traps Turn Windows Search Into a Malware Magnet

Published: 27 July 2026 12:04Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A large impersonation campaign used clone domains, copied branding, and AI-written pages to make bogus Windows app sites look routine and trustworthy.

Trusted Labels, Hidden Payloads: How a Fake Logistics Email Became a Malware Delivery Trap

Published: 25 July 2026 08:04Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A phishing run dressed up as shipping notices and tax-audit mail shows how attackers can turn everyday business trust into a credential-theft pipeline.

When a Login Prompt Becomes a Crime Scene

Published: 24 July 2026 18:52Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A guilty plea tied to a Snapchat phishing case shows how account takeover can turn routine social engineering into intimate privacy loss.

When a Login Code Becomes the Key: Snapchat Phishing Case Exposes the Weak Spot in MFA

Published: 24 July 2026 18:47Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A guilty plea tied to Snapchat code theft shows how one-time codes can fail when attackers aim at the user, not the platform.

When the Helpdesk Arrives in Chat: Microsoft Teams as the New Social-Engineering Front

Published: 24 July 2026 10:54Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

Attackers are using Microsoft Teams conversations to pose as internal IT support, turning a trusted workplace channel into a path for credentials, remote access, and account takeover attempts.

When the Inbox Is No Longer Enough: Phishing Moves Into Chat and Calls

Published: 24 July 2026 10:51Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

Microsoft’s warning points to a harder problem for defenders: attackers are increasingly exploiting the trust built into workplace communication tools, with Teams emerging as a prime social-engineering surface.

When Reused Passwords Open the Door: The Chick-fil-A One Account Takeover Problem

Published: 23 July 2026 19:13Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A credential-stuffing incident against Chick-fil-A One shows how stolen logins can turn a consumer rewards account into a fraud target without any need for a software exploit.

The Help Desk Trap: Fake IC3 Sites and AI Voices Are Turning Recovery Into a Second Scam

Published: 22 July 2026 14:58Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A new FBI warning shows how criminals are blending impersonation, synthetic media, and lookalike complaint portals to catch fraud victims at their most vulnerable.

AI Faces, Fake Help Desks, and the New Scam Layer Built for Repeat Victims

Published: 22 July 2026 14:55Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A federal warning points to a sharper fraud pattern: synthetic media and spoofed complaint portals are being used to squeeze people who have already lost money once.

The Fake Microsoft Page That Chases the Session, Not Just the Password

Published: 22 July 2026 12:06Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

AiTM phishing turns a trusted login screen into a relay point for credentials, MFA output, and live session tokens, which can make account takeover look like a normal sign-in.

Procurement Emails Became the Bait in a Session-Theft Campaign Against Microsoft 365

Published: 22 July 2026 10:37Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

AiTM phishing can turn a routine vendor request into a live browser hijack, letting attackers reuse an authenticated Microsoft 365 session even after MFA is completed.

Fake Authority, Real Loss: How Impersonation Scams Are Reusing the FBI Name

Published: 21 July 2026 16:55Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A fraud pattern built on deepfake video, spoofed complaint pages, and false recovery promises shows how criminals can turn trust in institutions into a second attack.

FaceTime Scams Turn Live Video Into a New Trust Trap

Published: 17 July 2026 12:35Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

Fraudsters are using FaceTime calls to impersonate banks, tech support, and government officials, making old social engineering tactics feel more immediate and harder to question.

Paid Search, Shared AI Links, and a Mac Stealer: The New Trust Trap

Published: 16 July 2026 10:43Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A macOS malware campaign used Google Ads and Claude shared-chat links as delivery channels, showing how attackers can turn familiar services into a credential-harvesting lure.