A reported flaw in ChatGPT Workspace Agents shows how one click can become an agent-launch event, not just a browser detour.
A phishing campaign built around fake job interviews and brand impersonation shows how a simple login prompt can become the endgame of a carefully staged social-engineering chain.
A fake FIFA World Cup 2026 merchandise offer shows how personalized branding and trusted web infrastructure can turn an inbox novelty into a malware delivery path.
A seven-week campaign tied to Dropping Elephant mixed trusted web services with fast-changing infrastructure, showing how attackers can turn ordinary publishing and chat-link features into malware delivery paths.
WhatsApp’s move against an NSO-linked campaign shows how modern spyware defense now blends platform telemetry, account controls, and courtroom pressure.
A Windows Search URI-handler flaw is being linked to NTLMv2 material leaking to attacker-controlled servers after a single click, showing how built-in convenience features can become authentication boundaries.
A public sharing feature built for convenience is being recast as a lure, with fake outage pages and alleged malware delivery at the center of the abuse.