Skip to content
tag — social-engineering

grep -rl "social-engineering" ./articles

#social-engineering

18 articles

The call is about your passkey. The break-in uses routes a passkey alone does not close

2026-09-15Security

Microsoft says extortion groups tied to ShinyHunters and Helix are phoning staff about urgent passkey or single sign-on updates, then steering them into relayed sign-ins or device-code approvals. Once in, they register an MFA method of their own, map the tenant through Microsoft Graph and take files at under 1,000 an hour to stay unremarkable.

The only thing they changed was telling you to open Terminal instead of Run

2026-08-31Security

TerminalFix is ClickFix with one substitution. A fake Cloudflare CAPTCHA asks you to paste a command, and instead of the Run dialog it sends you to Windows Terminal or PowerShell — where long multi-line scripts actually work. The end of the chain is a Python reverse tunnel that lets the operator reach anything your machine can see.

The fake GTA VI download is 113GB of nothing wrapped around a 50KB payload

2026-08-26Security

Days after the leak, an ISO began circulating claiming to be the leaked build. Testers report it is 99.99% empty zeroes padded around roughly 50KB of malware, and that the installer whitelists the entire C: drive in Windows Defender before it runs. The file size was the disguise: 113GB is what a real game looks like.

They phoned a security company, used real employees' names, and got in

2026-08-25Security

ShinyHunters registered a fake ReliaQuest SSO page and rang staff one by one, each time impersonating a named colleague from the security team. One person typed their password and approved the push. ReliaQuest says the attackers got view-only access to an Okta dashboard and nothing else — and the interesting part is which controls held.

3.6 million staff directory records are on sale from nine large companies — and the two that answered say nothing was breached

2026-08-19Security

Hudson Rock reported on 16 August that a seller calling himself TheHatman is offering Entra directory exports from McDonald's, TCS, Vodafone, HCL and five others. TCS says it found no credible evidence and the data is at least four years old. Gap says the same. Nobody has independently authenticated any of it — and the records would still be useful to an attacker if every word of the denials is true.