A reported attempt to hide malicious code in a real repository, paired with a fake account, shows how software trust can be strained long before any payload is confirmed to have landed.
A callback-phishing lure uses fake account sign-in alerts to pull targets off the inbox and into a live voice scam, where trust is easier to exploit and harder to automate away.
AI is being used to make influence accounts look more believable, shifting some campaigns away from blunt flooding and toward quieter persona manipulation.