A modular malware campaign tied to ClickFix lures shows how a single user action can become the start of a much larger compromise.
A trust signal built to block bots can be repurposed into a social-engineering step that nudges Windows users toward running PowerShell commands.
A cross-border police action against an alleged investment scam network shows how modern crypto fraud depends on persuasion, speed, and payment flows more than on malware.
Dutch police and Europol moved against an alleged investment-fraud network after arrests in multiple European countries, underscoring how scam operations can grow across borders and industrialize trust abuse.
The malware case shows how one hostile workflow can move from fake software delivery to browser abuse and wallet-app surveillance, all aimed at crypto credentials.
A macOS malware campaign used Google Ads and Claude shared-chat links as delivery channels, showing how attackers can turn familiar services into a credential-harvesting lure.
A ClickFix-style campaign is reportedly using shared Claude chats as bait, showing how a normal collaboration feature can be repurposed into a trust channel for macOS credential theft.
A campaign using spoofed security notices against LastPass and Bitwarden users shows how attackers can weaponize the very language of account protection to lure victims onto fraudulent websites.
The strongest cryptography can still be undermined if an attacker goes after the account, the phone number, or the person holding the device.
A suspected espionage effort aimed at a narrow circle of Italian figures shows how encrypted messaging can still be pressured through identity checks, linked devices, and account control.
Greenhat’s announced appearance at Web Summit Vancouver 2026 is not a breach story, but it does underline how public-facing tech events can increase the need for verification and identity discipline.
A courier-themed phishing campaign uses a fake failed-delivery notice to push recipients toward a form that asks for personal details and payment-card data.
ScamBuster shows how defenders are starting to answer email fraud with their own scripted identities, turning attacker conversation into a potential intelligence source.
A reported spear-phishing campaign borrowed real event details, then used an ISO container and process injection to move RokRAT onto Windows systems.
A panel-driven phishing operation is using fake security calls to pressure Microsoft 365 users into registering a new passkey, showing how identity attacks can target the enrollment process instead of the login itself.
A vishing campaign is steering Microsoft 365 users toward counterfeit Microsoft Entra ID login pages, showing how social engineering now targets the identity layer itself.
A macOS infostealer campaign is blending social engineering, AppleScript, and LaunchDaemons to collect credentials and push fake crypto-wallet software onto infected Macs.
A callback-phishing lure uses fake account sign-in alerts to pull targets off the inbox and into a live voice scam, where trust is easier to exploit and harder to automate away.
A callback-phishing campaign uses fake sign-in warnings to push recipients away from inbox checks and into attacker-controlled voice channels.
A new ransomware snapshot points to a crowded criminal economy shaped by concentration at the top and by AI that appears to speed up familiar social-engineering work rather than invent a new kind of attack.