home.social

#socialengineering — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #socialengineering, aggregated by home.social.

  1. McDonald's Customer Data Platform Breach Exposes 40M Records

    If you're one of the 28 million McDonald's customers whose data was exposed, you may be at risk of social engineering scams and loyalty fraud due to the breach of sensitive info like names and loyalty point transactions. This massive data leak, which also included 71,000 corporate records, is a stark reminder to stay vigilant…

    osintsights.com/mcdonalds-cust

    #CustomerDataBreach #EmergingThreats #LoyaltyFraud #SocialEngineering #Indonesia

  2. McDonald's Customer Data Platform Breach Exposes 40M Records

    If you're one of the 28 million McDonald's customers whose data was exposed, you may be at risk of social engineering scams and loyalty fraud due to the breach of sensitive info like names and loyalty point transactions. This massive data leak, which also included 71,000 corporate records, is a stark reminder to stay vigilant…

    osintsights.com/mcdonalds-cust

    #CustomerDataBreach #EmergingThreats #LoyaltyFraud #SocialEngineering #Indonesia

  3. Attackers do not just hack passwords. They hack emotions.

    In episode 452 of the Shared Security Podcast, we discuss how AI voice-cloning scams use public information and emotional triggers to create believable pretexts.

    The practical defense: pause, verify independently, and do not let urgency skip the process.

    Full episode: sharedsecurity.net/2026/09/28/ #Cybersecurity #AI #Scams #SocialEngineering

  4. Attackers do not just hack passwords. They hack emotions.

    In episode 452 of the Shared Security Podcast, we discuss how AI voice-cloning scams use public information and emotional triggers to create believable pretexts.

    The practical defense: pause, verify independently, and do not let urgency skip the process.

    Full episode: sharedsecurity.net/2026/09/28/ #Cybersecurity #AI #Scams #SocialEngineering

  5. Attackers do not just hack passwords. They hack emotions.

    In episode 452 of the Shared Security Podcast, we discuss how AI voice-cloning scams use public information and emotional triggers to create believable pretexts.

    The practical defense: pause, verify independently, and do not let urgency skip the process.

    Full episode: sharedsecurity.net/2026/09/28/ #Cybersecurity #AI #Scams #SocialEngineering

  6. Attackers do not just hack passwords. They hack emotions.

    In episode 452 of the Shared Security Podcast, we discuss how AI voice-cloning scams use public information and emotional triggers to create believable pretexts.

    The practical defense: pause, verify independently, and do not let urgency skip the process.

    Full episode: sharedsecurity.net/2026/09/28/ #Cybersecurity #AI #Scams #SocialEngineering

  7. Attackers do not just hack passwords. They hack emotions.

    In episode 452 of the Shared Security Podcast, we discuss how AI voice-cloning scams use public information and emotional triggers to create believable pretexts.

    The practical defense: pause, verify independently, and do not let urgency skip the process.

    Full episode: sharedsecurity.net/2026/09/28/ #Cybersecurity #AI #Scams #SocialEngineering

  8. DATE: September 29, 2026 at 05:24PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    @OpenAI Apologizes for Hacks on #Australian Government Sites: #AI Firm Admits Delayed Disclosure, Details Incidents, Promises New #AIAgent Safeguards t.co/HAbgCmGGKA

    Here are any URLs found in the article text:

    t.co/HAbgCmGGKA

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  9. DATE: September 29, 2026 at 05:24PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    @OpenAI Apologizes for Hacks on #Australian Government Sites: #AI Firm Admits Delayed Disclosure, Details Incidents, Promises New #AIAgent Safeguards t.co/HAbgCmGGKA

    Here are any URLs found in the article text:

    t.co/HAbgCmGGKA

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  10. DATE: September 29, 2026 at 05:24PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    @OpenAI Apologizes for Hacks on #Australian Government Sites: #AI Firm Admits Delayed Disclosure, Details Incidents, Promises New #AIAgent Safeguards t.co/HAbgCmGGKA

    Here are any URLs found in the article text:

    t.co/HAbgCmGGKA

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  11. DATE: September 29, 2026 at 05:24PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    @OpenAI Apologizes for Hacks on #Australian Government Sites: #AI Firm Admits Delayed Disclosure, Details Incidents, Promises New #AIAgent Safeguards t.co/HAbgCmGGKA

    Here are any URLs found in the article text:

    t.co/HAbgCmGGKA

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  12. DATE: September 29, 2026 at 08:59AM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #Estonia Tests #SovereignAI on National #HealthData:
    @OwkinScience 's #AgenticAI Will Support Nation's #Biomed Research While Preserving Data Sovereignty
    t.co/fO39ctKSvO

    Here are any URLs found in the article text:

    t.co/fO39ctKSvO

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  13. DATE: September 29, 2026 at 08:59AM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #Estonia Tests #SovereignAI on National #HealthData:
    @OwkinScience 's #AgenticAI Will Support Nation's #Biomed Research While Preserving Data Sovereignty
    t.co/fO39ctKSvO

    Here are any URLs found in the article text:

    t.co/fO39ctKSvO

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  14. DATE: September 29, 2026 at 08:59AM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #Estonia Tests #SovereignAI on National #HealthData:
    @OwkinScience 's #AgenticAI Will Support Nation's #Biomed Research While Preserving Data Sovereignty
    t.co/fO39ctKSvO

    Here are any URLs found in the article text:

    t.co/fO39ctKSvO

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  15. DATE: September 29, 2026 at 08:59AM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #Estonia Tests #SovereignAI on National #HealthData:
    @OwkinScience 's #AgenticAI Will Support Nation's #Biomed Research While Preserving Data Sovereignty
    t.co/fO39ctKSvO

    Here are any URLs found in the article text:

    t.co/fO39ctKSvO

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  16. The attack isn't rocket science but from an attacker perspective quite neat.

    The MSI is quite small and contains, appart from the hostnames little "suspicious" code.

    The random readme prevents signature based detection.

    As the code is retrieved and directly executed in memory, file based detections can't detect it.
    Furthermore, attackers can modify it anytime and the next execution uses the updated code.

    And, last but not least there is less forensic evidence left on the infected system.

    As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴

    #Malware #SocialEngineering #Cybersecurity

  17. The attack isn't rocket science but from an attacker perspective quite neat.

    The MSI is quite small and contains, appart from the hostnames little "suspicious" code.

    The random readme prevents signature based detection.

    As the code is retrieved and directly executed in memory, file based detections can't detect it.
    Furthermore, attackers can modify it anytime and the next execution uses the updated code.

    And, last but not least there is less forensic evidence left on the infected system.

    As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴

    #Malware #SocialEngineering #Cybersecurity

  18. The attack isn't rocket science but from an attacker perspective quite neat.

    The MSI is quite small and contains, appart from the hostnames little "suspicious" code.

    The random readme prevents signature based detection.

    As the code is retrieved and directly executed in memory, file based detections can't detect it.
    Furthermore, attackers can modify it anytime and the next execution uses the updated code.

    And, last but not least there is less forensic evidence left on the infected system.

    As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴

    #Malware #SocialEngineering #Cybersecurity

  19. The attack isn't rocket science but from an attacker perspective quite neat.

    The MSI is quite small and contains, appart from the hostnames little "suspicious" code.

    The random readme prevents signature based detection.

    As the code is retrieved and directly executed in memory, file based detections can't detect it.
    Furthermore, attackers can modify it anytime and the next execution uses the updated code.

    And, last but not least there is less forensic evidence left on the infected system.

    As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴

    #Malware #SocialEngineering #Cybersecurity

  20. The attack isn't rocket science but from an attacker perspective quite neat.

    The MSI is quite small and contains, appart from the hostnames little "suspicious" code.

    The random readme prevents signature based detection.

    As the code is retrieved and directly executed in memory, file based detections can't detect it.
    Furthermore, attackers can modify it anytime and the next execution uses the updated code.

    And, last but not least there is less forensic evidence left on the infected system.

    As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴

    #Malware #SocialEngineering #Cybersecurity

  21. As I managed to get my hands on the malicious MSI file I can provide some more details.

    You can unpack the MSI file with 7zip.
    This reveals a PowerShell script.

    This script downloads a standalone Python interpreter, installs pip and some packages (pythonnet, pywin32, pywinpty, and websockets).

    It than creates a README.md with random ASCII content

    And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at /cl/flash/c?v=17 and executes the code

    Sadly, I failed to retrive the code from any of the above-mentioned hosts.

    So again, if someone has more success, let me know.

    #Malware #SocialEngineering #Cybersecurity

  22. As I managed to get my hands on the malicious MSI file I can provide some more details.

    You can unpack the MSI file with 7zip.
    This reveals a PowerShell script.

    This script downloads a standalone Python interpreter, installs pip and some packages (pythonnet, pywin32, pywinpty, and websockets).

    It than creates a README.md with random ASCII content

    And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at /cl/flash/c?v=17 and executes the code

    Sadly, I failed to retrive the code from any of the above-mentioned hosts.

    So again, if someone has more success, let me know.

    #Malware #SocialEngineering #Cybersecurity

  23. As I managed to get my hands on the malicious MSI file I can provide some more details.

    You can unpack the MSI file with 7zip.
    This reveals a PowerShell script.

    This script downloads a standalone Python interpreter, installs pip and some packages (pythonnet, pywin32, pywinpty, and websockets).

    It than creates a README.md with random ASCII content

    And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at /cl/flash/c?v=17 and executes the code

    Sadly, I failed to retrive the code from any of the above-mentioned hosts.

    So again, if someone has more success, let me know.

    #Malware #SocialEngineering #Cybersecurity

  24. As I managed to get my hands on the malicious MSI file I can provide some more details.

    You can unpack the MSI file with 7zip.
    This reveals a PowerShell script.

    This script downloads a standalone Python interpreter, installs pip and some packages (pythonnet, pywin32, pywinpty, and websockets).

    It than creates a README.md with random ASCII content

    And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at /cl/flash/c?v=17 and executes the code

    Sadly, I failed to retrive the code from any of the above-mentioned hosts.

    So again, if someone has more success, let me know.

    #Malware #SocialEngineering #Cybersecurity

  25. As I managed to get my hands on the malicious MSI file I can provide some more details.

    You can unpack the MSI file with 7zip.
    This reveals a PowerShell script.

    This script downloads a standalone Python interpreter, installs pip and some packages (pythonnet, pywin32, pywinpty, and websockets).

    It than creates a README.md with random ASCII content

    And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at /cl/flash/c?v=17 and executes the code

    Sadly, I failed to retrive the code from any of the above-mentioned hosts.

    So again, if someone has more success, let me know.

    #Malware #SocialEngineering #Cybersecurity

  26. DATE: September 28, 2026 at 03:28PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #AstranaHealth Tells SEC Hack Exposed Sensitive Data t.co/vaKPH3lzVO

    Here are any URLs found in the article text:

    t.co/vaKPH3lzVO

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  27. DATE: September 28, 2026 at 03:28PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #AstranaHealth Tells SEC Hack Exposed Sensitive Data t.co/vaKPH3lzVO

    Here are any URLs found in the article text:

    t.co/vaKPH3lzVO

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  28. DATE: September 28, 2026 at 03:28PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #AstranaHealth Tells SEC Hack Exposed Sensitive Data t.co/vaKPH3lzVO

    Here are any URLs found in the article text:

    t.co/vaKPH3lzVO

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  29. DATE: September 28, 2026 at 03:28PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #AstranaHealth Tells SEC Hack Exposed Sensitive Data t.co/vaKPH3lzVO

    Here are any URLs found in the article text:

    t.co/vaKPH3lzVO

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  30. 95 milioni di euro con un vocale WhatsApp: dentro il deepfake che ha colpito Fideuram

    Un messaggio WhatsApp e una telefonata con voce clonata dall'AI sono bastati a far sparire 95 milioni di euro dai conti di Fideuram (Intesa Sanpaolo). Come funziona il nuovo BEC potenziato dal voice cloning e cosa cambiare nelle procedure anti-frode.

    insicurezzadigitale.com/95-mil

  31. 95 milioni di euro con un vocale WhatsApp: dentro il deepfake che ha colpito Fideuram

    Un messaggio WhatsApp e una telefonata con voce clonata dall'AI sono bastati a far sparire 95 milioni di euro dai conti di Fideuram (Intesa Sanpaolo). Come funziona il nuovo BEC potenziato dal voice cloning e cosa cambiare nelle procedure anti-frode.

    insicurezzadigitale.com/95-mil

  32. 95 milioni di euro con un vocale WhatsApp: dentro il deepfake che ha colpito Fideuram

    Un messaggio WhatsApp e una telefonata con voce clonata dall'AI sono bastati a far sparire 95 milioni di euro dai conti di Fideuram (Intesa Sanpaolo). Come funziona il nuovo BEC potenziato dal voice cloning e cosa cambiare nelle procedure anti-frode.

    insicurezzadigitale.com/95-mil

  33. 95 milioni di euro con un vocale WhatsApp: dentro il deepfake che ha colpito Fideuram

    Un messaggio WhatsApp e una telefonata con voce clonata dall'AI sono bastati a far sparire 95 milioni di euro dai conti di Fideuram (Intesa Sanpaolo). Come funziona il nuovo BEC potenziato dal voice cloning e cosa cambiare nelle procedure anti-frode.

    insicurezzadigitale.com/95-mil

  34. 95 milioni di euro con un vocale WhatsApp: dentro il deepfake che ha colpito Fideuram

    Un messaggio WhatsApp e una telefonata con voce clonata dall'AI sono bastati a far sparire 95 milioni di euro dai conti di Fideuram (Intesa Sanpaolo). Come funziona il nuovo BEC potenziato dal voice cloning e cosa cambiare nelle procedure anti-frode.

    insicurezzadigitale.com/95-mil