#socialengineering — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #socialengineering, aggregated by home.social.
-
McDonald's Customer Data Platform Breach Exposes 40M Records
If you're one of the 28 million McDonald's customers whose data was exposed, you may be at risk of social engineering scams and loyalty fraud due to the breach of sensitive info like names and loyalty point transactions. This massive data leak, which also included 71,000 corporate records, is a stark reminder to stay vigilant…
#CustomerDataBreach #EmergingThreats #LoyaltyFraud #SocialEngineering #Indonesia
-
McDonald's Customer Data Platform Breach Exposes 40M Records
If you're one of the 28 million McDonald's customers whose data was exposed, you may be at risk of social engineering scams and loyalty fraud due to the breach of sensitive info like names and loyalty point transactions. This massive data leak, which also included 71,000 corporate records, is a stark reminder to stay vigilant…
#CustomerDataBreach #EmergingThreats #LoyaltyFraud #SocialEngineering #Indonesia
-
Attackers do not just hack passwords. They hack emotions.
In episode 452 of the Shared Security Podcast, we discuss how AI voice-cloning scams use public information and emotional triggers to create believable pretexts.
The practical defense: pause, verify independently, and do not let urgency skip the process.
Full episode: https://sharedsecurity.net/2026/09/28/when-familiar-voices-become-scam-calls/ #Cybersecurity #AI #Scams #SocialEngineering
-
Attackers do not just hack passwords. They hack emotions.
In episode 452 of the Shared Security Podcast, we discuss how AI voice-cloning scams use public information and emotional triggers to create believable pretexts.
The practical defense: pause, verify independently, and do not let urgency skip the process.
Full episode: https://sharedsecurity.net/2026/09/28/when-familiar-voices-become-scam-calls/ #Cybersecurity #AI #Scams #SocialEngineering
-
Attackers do not just hack passwords. They hack emotions.
In episode 452 of the Shared Security Podcast, we discuss how AI voice-cloning scams use public information and emotional triggers to create believable pretexts.
The practical defense: pause, verify independently, and do not let urgency skip the process.
Full episode: https://sharedsecurity.net/2026/09/28/when-familiar-voices-become-scam-calls/ #Cybersecurity #AI #Scams #SocialEngineering
-
Attackers do not just hack passwords. They hack emotions.
In episode 452 of the Shared Security Podcast, we discuss how AI voice-cloning scams use public information and emotional triggers to create believable pretexts.
The practical defense: pause, verify independently, and do not let urgency skip the process.
Full episode: https://sharedsecurity.net/2026/09/28/when-familiar-voices-become-scam-calls/ #Cybersecurity #AI #Scams #SocialEngineering
-
Attackers do not just hack passwords. They hack emotions.
In episode 452 of the Shared Security Podcast, we discuss how AI voice-cloning scams use public information and emotional triggers to create believable pretexts.
The practical defense: pause, verify independently, and do not let urgency skip the process.
Full episode: https://sharedsecurity.net/2026/09/28/when-familiar-voices-become-scam-calls/ #Cybersecurity #AI #Scams #SocialEngineering
-
DATE: September 29, 2026 at 05:24PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
@OpenAI Apologizes for Hacks on #Australian Government Sites: #AI Firm Admits Delayed Disclosure, Details Incidents, Promises New #AIAgent Safeguards https://t.co/HAbgCmGGKA
Here are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
DATE: September 29, 2026 at 05:24PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
@OpenAI Apologizes for Hacks on #Australian Government Sites: #AI Firm Admits Delayed Disclosure, Details Incidents, Promises New #AIAgent Safeguards https://t.co/HAbgCmGGKA
Here are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
DATE: September 29, 2026 at 05:24PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
@OpenAI Apologizes for Hacks on #Australian Government Sites: #AI Firm Admits Delayed Disclosure, Details Incidents, Promises New #AIAgent Safeguards https://t.co/HAbgCmGGKA
Here are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
DATE: September 29, 2026 at 05:24PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
@OpenAI Apologizes for Hacks on #Australian Government Sites: #AI Firm Admits Delayed Disclosure, Details Incidents, Promises New #AIAgent Safeguards https://t.co/HAbgCmGGKA
Here are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
DATE: September 29, 2026 at 08:59AM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
#Estonia Tests #SovereignAI on National #HealthData:
@OwkinScience 's #AgenticAI Will Support Nation's #Biomed Research While Preserving Data Sovereignty
https://t.co/fO39ctKSvOHere are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
DATE: September 29, 2026 at 08:59AM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
#Estonia Tests #SovereignAI on National #HealthData:
@OwkinScience 's #AgenticAI Will Support Nation's #Biomed Research While Preserving Data Sovereignty
https://t.co/fO39ctKSvOHere are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
DATE: September 29, 2026 at 08:59AM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
#Estonia Tests #SovereignAI on National #HealthData:
@OwkinScience 's #AgenticAI Will Support Nation's #Biomed Research While Preserving Data Sovereignty
https://t.co/fO39ctKSvOHere are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
DATE: September 29, 2026 at 08:59AM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
#Estonia Tests #SovereignAI on National #HealthData:
@OwkinScience 's #AgenticAI Will Support Nation's #Biomed Research While Preserving Data Sovereignty
https://t.co/fO39ctKSvOHere are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
The attack isn't rocket science but from an attacker perspective quite neat.
The MSI is quite small and contains, appart from the hostnames little "suspicious" code.
The random readme prevents signature based detection.
As the code is retrieved and directly executed in memory, file based detections can't detect it.
Furthermore, attackers can modify it anytime and the next execution uses the updated code.And, last but not least there is less forensic evidence left on the infected system.
As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴
-
The attack isn't rocket science but from an attacker perspective quite neat.
The MSI is quite small and contains, appart from the hostnames little "suspicious" code.
The random readme prevents signature based detection.
As the code is retrieved and directly executed in memory, file based detections can't detect it.
Furthermore, attackers can modify it anytime and the next execution uses the updated code.And, last but not least there is less forensic evidence left on the infected system.
As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴
-
The attack isn't rocket science but from an attacker perspective quite neat.
The MSI is quite small and contains, appart from the hostnames little "suspicious" code.
The random readme prevents signature based detection.
As the code is retrieved and directly executed in memory, file based detections can't detect it.
Furthermore, attackers can modify it anytime and the next execution uses the updated code.And, last but not least there is less forensic evidence left on the infected system.
As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴
-
The attack isn't rocket science but from an attacker perspective quite neat.
The MSI is quite small and contains, appart from the hostnames little "suspicious" code.
The random readme prevents signature based detection.
As the code is retrieved and directly executed in memory, file based detections can't detect it.
Furthermore, attackers can modify it anytime and the next execution uses the updated code.And, last but not least there is less forensic evidence left on the infected system.
As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴
-
The attack isn't rocket science but from an attacker perspective quite neat.
The MSI is quite small and contains, appart from the hostnames little "suspicious" code.
The random readme prevents signature based detection.
As the code is retrieved and directly executed in memory, file based detections can't detect it.
Furthermore, attackers can modify it anytime and the next execution uses the updated code.And, last but not least there is less forensic evidence left on the infected system.
As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴
-
As I managed to get my hands on the malicious MSI file I can provide some more details.
You can unpack the MSI file with 7zip.
This reveals a PowerShell script.This script downloads a standalone Python interpreter, installs pip and some packages (
pythonnet,pywin32,pywinpty, andwebsockets).It than creates a README.md with random ASCII content
And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at
/cl/flash/c?v=17and executes the codeSadly, I failed to retrive the code from any of the above-mentioned hosts.
So again, if someone has more success, let me know.
-
As I managed to get my hands on the malicious MSI file I can provide some more details.
You can unpack the MSI file with 7zip.
This reveals a PowerShell script.This script downloads a standalone Python interpreter, installs pip and some packages (
pythonnet,pywin32,pywinpty, andwebsockets).It than creates a README.md with random ASCII content
And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at
/cl/flash/c?v=17and executes the codeSadly, I failed to retrive the code from any of the above-mentioned hosts.
So again, if someone has more success, let me know.
-
As I managed to get my hands on the malicious MSI file I can provide some more details.
You can unpack the MSI file with 7zip.
This reveals a PowerShell script.This script downloads a standalone Python interpreter, installs pip and some packages (
pythonnet,pywin32,pywinpty, andwebsockets).It than creates a README.md with random ASCII content
And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at
/cl/flash/c?v=17and executes the codeSadly, I failed to retrive the code from any of the above-mentioned hosts.
So again, if someone has more success, let me know.
-
As I managed to get my hands on the malicious MSI file I can provide some more details.
You can unpack the MSI file with 7zip.
This reveals a PowerShell script.This script downloads a standalone Python interpreter, installs pip and some packages (
pythonnet,pywin32,pywinpty, andwebsockets).It than creates a README.md with random ASCII content
And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at
/cl/flash/c?v=17and executes the codeSadly, I failed to retrive the code from any of the above-mentioned hosts.
So again, if someone has more success, let me know.
-
As I managed to get my hands on the malicious MSI file I can provide some more details.
You can unpack the MSI file with 7zip.
This reveals a PowerShell script.This script downloads a standalone Python interpreter, installs pip and some packages (
pythonnet,pywin32,pywinpty, andwebsockets).It than creates a README.md with random ASCII content
And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at
/cl/flash/c?v=17and executes the codeSadly, I failed to retrive the code from any of the above-mentioned hosts.
So again, if someone has more success, let me know.
-
DATE: September 28, 2026 at 03:28PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
#AstranaHealth Tells SEC Hack Exposed Sensitive Data https://t.co/vaKPH3lzVO
Here are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
DATE: September 28, 2026 at 03:28PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
#AstranaHealth Tells SEC Hack Exposed Sensitive Data https://t.co/vaKPH3lzVO
Here are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
DATE: September 28, 2026 at 03:28PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
#AstranaHealth Tells SEC Hack Exposed Sensitive Data https://t.co/vaKPH3lzVO
Here are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
DATE: September 28, 2026 at 03:28PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
#AstranaHealth Tells SEC Hack Exposed Sensitive Data https://t.co/vaKPH3lzVO
Here are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
95 milioni di euro con un vocale WhatsApp: dentro il deepfake che ha colpito Fideuram
Un messaggio WhatsApp e una telefonata con voce clonata dall'AI sono bastati a far sparire 95 milioni di euro dai conti di Fideuram (Intesa Sanpaolo). Come funziona il nuovo BEC potenziato dal voice cloning e cosa cambiare nelle procedure anti-frode. -
95 milioni di euro con un vocale WhatsApp: dentro il deepfake che ha colpito Fideuram
Un messaggio WhatsApp e una telefonata con voce clonata dall'AI sono bastati a far sparire 95 milioni di euro dai conti di Fideuram (Intesa Sanpaolo). Come funziona il nuovo BEC potenziato dal voice cloning e cosa cambiare nelle procedure anti-frode. -
95 milioni di euro con un vocale WhatsApp: dentro il deepfake che ha colpito Fideuram
Un messaggio WhatsApp e una telefonata con voce clonata dall'AI sono bastati a far sparire 95 milioni di euro dai conti di Fideuram (Intesa Sanpaolo). Come funziona il nuovo BEC potenziato dal voice cloning e cosa cambiare nelle procedure anti-frode. -
95 milioni di euro con un vocale WhatsApp: dentro il deepfake che ha colpito Fideuram
Un messaggio WhatsApp e una telefonata con voce clonata dall'AI sono bastati a far sparire 95 milioni di euro dai conti di Fideuram (Intesa Sanpaolo). Come funziona il nuovo BEC potenziato dal voice cloning e cosa cambiare nelle procedure anti-frode. -
95 milioni di euro con un vocale WhatsApp: dentro il deepfake che ha colpito Fideuram
Un messaggio WhatsApp e una telefonata con voce clonata dall'AI sono bastati a far sparire 95 milioni di euro dai conti di Fideuram (Intesa Sanpaolo). Come funziona il nuovo BEC potenziato dal voice cloning e cosa cambiare nelle procedure anti-frode.