home.social

#socialengineering — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #socialengineering, aggregated by home.social.

  1. DATE: May 28, 2026 at 04:59PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    Why are #webportals a favorite target of #hackers? t.co/pUspfjwPY5

    Here are any URLs found in the article text:

    t.co/pUspfjwPY5

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  2. DATE: May 28, 2026 at 04:58PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #Connecticut #Medicaid Portal Hack Affects Thousands: Attackers Attempted to Reroute #Hospital Medicaid Reimbursements t.co/pUspfjwPY5 #GainwellTechnologies @HartfordHealthcare #HIPAA

    Here are any URLs found in the article text:

    t.co/pUspfjwPY5

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  3. A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure

    JINX-0164, a financially motivated threat actor active since mid-2025, has been conducting sophisticated campaigns against cryptocurrency organizations. The actor employs LinkedIn-based social engineering, posing as recruiters or business partners to deliver custom macOS malware including AUDIOFIX (a Python-based infostealer and RAT) and MINIRAT (a lightweight Go backdoor). Their operations focus on compromising developer endpoints to steal cryptocurrency wallet credentials, cloud secrets, and GitHub tokens. The attackers then pivot to CI/CD infrastructure, injecting malicious code into repositories to enable lateral movement. In April 2026, they executed a supply chain attack by trojanizing the npm package @velora-dex/sdk. The group masks activity using VPN services and demonstrates advanced capabilities including credential harvesting from password managers, browser extensions, and development tools.

    Pulse ID: 6a181e409d755171f4ac356c
    Pulse Link: otx.alienvault.com/pulse/6a181
    Pulse Author: AlienVault
    Created: 2026-05-28 10:51:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Cloud #CredentialHarvesting #CyberSecurity #Endpoint #GitHub #InfoSec #InfoStealer #LinkedIn #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #Password #Python #RAT #SocialEngineering #SupplyChain #Trojan #VPN #Word #bot #cryptocurrency #AlienVault

  4. A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure

    JINX-0164, a financially motivated threat actor active since mid-2025, has been conducting sophisticated campaigns against cryptocurrency organizations. The actor employs LinkedIn-based social engineering, posing as recruiters or business partners to deliver custom macOS malware including AUDIOFIX (a Python-based infostealer and RAT) and MINIRAT (a lightweight Go backdoor). Their operations focus on compromising developer endpoints to steal cryptocurrency wallet credentials, cloud secrets, and GitHub tokens. The attackers then pivot to CI/CD infrastructure, injecting malicious code into repositories to enable lateral movement. In April 2026, they executed a supply chain attack by trojanizing the npm package @velora-dex/sdk. The group masks activity using VPN services and demonstrates advanced capabilities including credential harvesting from password managers, browser extensions, and development tools.

    Pulse ID: 6a181e409d755171f4ac356c
    Pulse Link: otx.alienvault.com/pulse/6a181
    Pulse Author: AlienVault
    Created: 2026-05-28 10:51:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Cloud #CredentialHarvesting #CyberSecurity #Endpoint #GitHub #InfoSec #InfoStealer #LinkedIn #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #Password #Python #RAT #SocialEngineering #SupplyChain #Trojan #VPN #Word #bot #cryptocurrency #AlienVault

  5. A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure

    JINX-0164, a financially motivated threat actor active since mid-2025, has been conducting sophisticated campaigns against cryptocurrency organizations. The actor employs LinkedIn-based social engineering, posing as recruiters or business partners to deliver custom macOS malware including AUDIOFIX (a Python-based infostealer and RAT) and MINIRAT (a lightweight Go backdoor). Their operations focus on compromising developer endpoints to steal cryptocurrency wallet credentials, cloud secrets, and GitHub tokens. The attackers then pivot to CI/CD infrastructure, injecting malicious code into repositories to enable lateral movement. In April 2026, they executed a supply chain attack by trojanizing the npm package @velora-dex/sdk. The group masks activity using VPN services and demonstrates advanced capabilities including credential harvesting from password managers, browser extensions, and development tools.

    Pulse ID: 6a181e409d755171f4ac356c
    Pulse Link: otx.alienvault.com/pulse/6a181
    Pulse Author: AlienVault
    Created: 2026-05-28 10:51:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Cloud #CredentialHarvesting #CyberSecurity #Endpoint #GitHub #InfoSec #InfoStealer #LinkedIn #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #Password #Python #RAT #SocialEngineering #SupplyChain #Trojan #VPN #Word #bot #cryptocurrency #AlienVault

  6. A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure

    JINX-0164, a financially motivated threat actor active since mid-2025, has been conducting sophisticated campaigns against cryptocurrency organizations. The actor employs LinkedIn-based social engineering, posing as recruiters or business partners to deliver custom macOS malware including AUDIOFIX (a Python-based infostealer and RAT) and MINIRAT (a lightweight Go backdoor). Their operations focus on compromising developer endpoints to steal cryptocurrency wallet credentials, cloud secrets, and GitHub tokens. The attackers then pivot to CI/CD infrastructure, injecting malicious code into repositories to enable lateral movement. In April 2026, they executed a supply chain attack by trojanizing the npm package @velora-dex/sdk. The group masks activity using VPN services and demonstrates advanced capabilities including credential harvesting from password managers, browser extensions, and development tools.

    Pulse ID: 6a181e409d755171f4ac356c
    Pulse Link: otx.alienvault.com/pulse/6a181
    Pulse Author: AlienVault
    Created: 2026-05-28 10:51:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Cloud #CredentialHarvesting #CyberSecurity #Endpoint #GitHub #InfoSec #InfoStealer #LinkedIn #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #Password #Python #RAT #SocialEngineering #SupplyChain #Trojan #VPN #Word #bot #cryptocurrency #AlienVault

  7. A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure

    JINX-0164, a financially motivated threat actor active since mid-2025, has been conducting sophisticated campaigns against cryptocurrency organizations. The actor employs LinkedIn-based social engineering, posing as recruiters or business partners to deliver custom macOS malware including AUDIOFIX (a Python-based infostealer and RAT) and MINIRAT (a lightweight Go backdoor). Their operations focus on compromising developer endpoints to steal cryptocurrency wallet credentials, cloud secrets, and GitHub tokens. The attackers then pivot to CI/CD infrastructure, injecting malicious code into repositories to enable lateral movement. In April 2026, they executed a supply chain attack by trojanizing the npm package @velora-dex/sdk. The group masks activity using VPN services and demonstrates advanced capabilities including credential harvesting from password managers, browser extensions, and development tools.

    Pulse ID: 6a181e409d755171f4ac356c
    Pulse Link: otx.alienvault.com/pulse/6a181
    Pulse Author: AlienVault
    Created: 2026-05-28 10:51:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Cloud #CredentialHarvesting #CyberSecurity #Endpoint #GitHub #InfoSec #InfoStealer #LinkedIn #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #Password #Python #RAT #SocialEngineering #SupplyChain #Trojan #VPN #Word #bot #cryptocurrency #AlienVault

  8. Carnival Cruise Data Breach Exposes 6 Million Customers

    A recent data breach at Carnival Cruise, affecting 6 million customers, highlights the vulnerability of traditional security controls to social engineering tactics, where a single compromised employee device can lead to devastating consequences. This incident serves as a stark reminder of the human factor in cybersecurity, where threat…

    osintsights.com/carnival-cruis

    #CarnivalCruise #DataBreach #SocialEngineering #Ransomware #Shinyhunters

  9. Carnival Cruise Breach Exposes 6 Million in Data Heist

    Millions of Carnival Cruise customers are reeling after a massive data breach exposed sensitive information, with 5.9 million individuals affected by the shocking incident. The breach, which occurred over a 12-day period, was sparked by a clever social engineering scam that duped an employee into handing over access to the company's IT…

    osintsights.com/carnival-cruis

    #DataBreach #CarnivalCruise #CustomerData #SocialEngineering #EmergingThreats

  10. DATE: May 27, 2026 at 04:57PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #AgenticAI in #Healthcare Is a Risky Proposition: @HealthISAC Report Warns About Weak Governance, Credential Misuse and Other Concerns t.co/Ion6CSxfnx

    Here are any URLs found in the article text:

    t.co/Ion6CSxfnx

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  11. DATE: May 27, 2026 at 04:57PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #AgenticAI in #Healthcare Is a Risky Proposition: @HealthISAC Report Warns About Weak Governance, Credential Misuse and Other Concerns t.co/Ion6CSxfnx

    Here are any URLs found in the article text:

    t.co/Ion6CSxfnx

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  12. DATE: May 27, 2026 at 04:57PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #AgenticAI in #Healthcare Is a Risky Proposition: @HealthISAC Report Warns About Weak Governance, Credential Misuse and Other Concerns t.co/Ion6CSxfnx

    Here are any URLs found in the article text:

    t.co/Ion6CSxfnx

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  13. DATE: May 27, 2026 at 04:57PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #AgenticAI in #Healthcare Is a Risky Proposition: @HealthISAC Report Warns About Weak Governance, Credential Misuse and Other Concerns t.co/Ion6CSxfnx

    Here are any URLs found in the article text:

    t.co/Ion6CSxfnx

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  14. Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet

    Threat actors exploited the EtherHiding technique to store ClearFake payload routing instructions within smart contracts on the BNB Smart Chain testnet, creating an immutable command-and-control infrastructure that cannot be taken down. The attack began with injected JavaScript on a compromised Swiss website that queried blockchain contracts to deliver malicious payloads. Victims passing anti-analysis checks were fingerprinted by operating system and routed to platform-specific ClickFix social engineering overlays. The campaign simultaneously deployed SectopRAT, a .NET-based remote access trojan capable of browser session hijacking, and ACRStealer, a C++ infostealer targeting credentials and cryptocurrency wallets. An on-chain execution tracker confirmed each compromise in real time. Four smart contracts shared a single deployer wallet, with the oldest deployed nearly a year before analysis, indicating a long-running, actively maintained operation.

    Pulse ID: 6a15ba2632bd7e246e9c1250
    Pulse Link: otx.alienvault.com/pulse/6a15b
    Pulse Author: AlienVault
    Created: 2026-05-26 15:20:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #CandC #ClearFake #CyberSecurity #EtherHiding #InfoSec #InfoStealer #Java #JavaScript #NET #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #SocialEngineering #Trojan #bot #cryptocurrency #AlienVault

  15. Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet

    Threat actors exploited the EtherHiding technique to store ClearFake payload routing instructions within smart contracts on the BNB Smart Chain testnet, creating an immutable command-and-control infrastructure that cannot be taken down. The attack began with injected JavaScript on a compromised Swiss website that queried blockchain contracts to deliver malicious payloads. Victims passing anti-analysis checks were fingerprinted by operating system and routed to platform-specific ClickFix social engineering overlays. The campaign simultaneously deployed SectopRAT, a .NET-based remote access trojan capable of browser session hijacking, and ACRStealer, a C++ infostealer targeting credentials and cryptocurrency wallets. An on-chain execution tracker confirmed each compromise in real time. Four smart contracts shared a single deployer wallet, with the oldest deployed nearly a year before analysis, indicating a long-running, actively maintained operation.

    Pulse ID: 6a15ba2632bd7e246e9c1250
    Pulse Link: otx.alienvault.com/pulse/6a15b
    Pulse Author: AlienVault
    Created: 2026-05-26 15:20:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #CandC #ClearFake #CyberSecurity #EtherHiding #InfoSec #InfoStealer #Java #JavaScript #NET #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #SocialEngineering #Trojan #bot #cryptocurrency #AlienVault

  16. Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet

    Threat actors exploited the EtherHiding technique to store ClearFake payload routing instructions within smart contracts on the BNB Smart Chain testnet, creating an immutable command-and-control infrastructure that cannot be taken down. The attack began with injected JavaScript on a compromised Swiss website that queried blockchain contracts to deliver malicious payloads. Victims passing anti-analysis checks were fingerprinted by operating system and routed to platform-specific ClickFix social engineering overlays. The campaign simultaneously deployed SectopRAT, a .NET-based remote access trojan capable of browser session hijacking, and ACRStealer, a C++ infostealer targeting credentials and cryptocurrency wallets. An on-chain execution tracker confirmed each compromise in real time. Four smart contracts shared a single deployer wallet, with the oldest deployed nearly a year before analysis, indicating a long-running, actively maintained operation.

    Pulse ID: 6a15ba2632bd7e246e9c1250
    Pulse Link: otx.alienvault.com/pulse/6a15b
    Pulse Author: AlienVault
    Created: 2026-05-26 15:20:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #CandC #ClearFake #CyberSecurity #EtherHiding #InfoSec #InfoStealer #Java #JavaScript #NET #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #SocialEngineering #Trojan #bot #cryptocurrency #AlienVault

  17. Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet

    Threat actors exploited the EtherHiding technique to store ClearFake payload routing instructions within smart contracts on the BNB Smart Chain testnet, creating an immutable command-and-control infrastructure that cannot be taken down. The attack began with injected JavaScript on a compromised Swiss website that queried blockchain contracts to deliver malicious payloads. Victims passing anti-analysis checks were fingerprinted by operating system and routed to platform-specific ClickFix social engineering overlays. The campaign simultaneously deployed SectopRAT, a .NET-based remote access trojan capable of browser session hijacking, and ACRStealer, a C++ infostealer targeting credentials and cryptocurrency wallets. An on-chain execution tracker confirmed each compromise in real time. Four smart contracts shared a single deployer wallet, with the oldest deployed nearly a year before analysis, indicating a long-running, actively maintained operation.

    Pulse ID: 6a15ba2632bd7e246e9c1250
    Pulse Link: otx.alienvault.com/pulse/6a15b
    Pulse Author: AlienVault
    Created: 2026-05-26 15:20:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #CandC #ClearFake #CyberSecurity #EtherHiding #InfoSec #InfoStealer #Java #JavaScript #NET #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #SocialEngineering #Trojan #bot #cryptocurrency #AlienVault

  18. Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet

    Threat actors exploited the EtherHiding technique to store ClearFake payload routing instructions within smart contracts on the BNB Smart Chain testnet, creating an immutable command-and-control infrastructure that cannot be taken down. The attack began with injected JavaScript on a compromised Swiss website that queried blockchain contracts to deliver malicious payloads. Victims passing anti-analysis checks were fingerprinted by operating system and routed to platform-specific ClickFix social engineering overlays. The campaign simultaneously deployed SectopRAT, a .NET-based remote access trojan capable of browser session hijacking, and ACRStealer, a C++ infostealer targeting credentials and cryptocurrency wallets. An on-chain execution tracker confirmed each compromise in real time. Four smart contracts shared a single deployer wallet, with the oldest deployed nearly a year before analysis, indicating a long-running, actively maintained operation.

    Pulse ID: 6a15ba2632bd7e246e9c1250
    Pulse Link: otx.alienvault.com/pulse/6a15b
    Pulse Author: AlienVault
    Created: 2026-05-26 15:20:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #CandC #ClearFake #CyberSecurity #EtherHiding #InfoSec #InfoStealer #Java #JavaScript #NET #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #SocialEngineering #Trojan #bot #cryptocurrency #AlienVault

  19. DATE: May 26, 2026 at 05:29PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #Oncology Firm Says Billing Vendor Hack Compromised Patient Data t.co/6kEmD6KWi9 #TheOncologyInstitute #TOI

    Here are any URLs found in the article text:

    t.co/6kEmD6KWi9

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  20. DATE: May 26, 2026 at 05:29PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #Oncology Firm Says Billing Vendor Hack Compromised Patient Data t.co/6kEmD6KWi9 #TheOncologyInstitute #TOI

    Here are any URLs found in the article text:

    t.co/6kEmD6KWi9

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  21. DATE: May 26, 2026 at 05:29PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #Oncology Firm Says Billing Vendor Hack Compromised Patient Data t.co/6kEmD6KWi9 #TheOncologyInstitute #TOI

    Here are any URLs found in the article text:

    t.co/6kEmD6KWi9

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  22. DATE: May 26, 2026 at 05:29PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #Oncology Firm Says Billing Vendor Hack Compromised Patient Data t.co/6kEmD6KWi9 #TheOncologyInstitute #TOI

    Here are any URLs found in the article text:

    t.co/6kEmD6KWi9

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  23. Hook, Line, and Sinker: Why People Still Fall for “Official” Emails

    3,206 words, 17 minutes read time.

    The digital landscape is a cold, relentless stretch of asphalt where the rain never stops and the shadows are always reaching for your throat. It is an environment built on the fundamental architecture of trust, yet it is that very trust that serves as the primary vector for the modern grift. When we look at the evolution of the phishing landscape, we aren’t just looking at a series of technical failures or a lack of robust filtering; we are looking at the exploitation of the human operating system. Most analysts want to talk about SPF, DKIM, and DMARC as if they are the ultimate shields against the storm, but they often ignore the fact that the most sophisticated code in the world cannot patch a moment of panic. The “Official” email is the modern equivalent of a knock at the door at three in the morning; it carries an inherent authority that bypasses the logical gates of the brain and targets the raw, unrefined nerves of social obligation and fear of consequence.

    Analyzing the recent waves of business email compromise and high-stakes credential harvesting, I see a clear pattern that suggests we are losing the war of attrition because we refuse to acknowledge the psychological heavy lifting being done by the adversary. The craft has moved far beyond the broken syntax and desperate pleas of a decade ago, evolving into a surgical instrument that mirrors the exact cadence of corporate bureaucracy. These attackers are not just hackers anymore; they are student of institutional behavior who understand that a well-placed “Urgent Action Required” notice from a spoofed human resources alias is more effective than any brute-force attack. By the time the target realizes the landing page is a mirror of a Microsoft 365 login, the credentials have already been spirited away into a database in a jurisdiction where the law doesn’t have a name.

    The Psychological Mechanics of the Digital Ambush

    The success of a phishing campaign relies on the deliberate manipulation of cognitive load and the exploitation of ingrained social hierarchies. When an individual receives an email that appears to originate from a high-level executive or a government entity like the Internal Revenue Service, the brain undergoes a shift from analytical processing to a reactive survival mode. This is not a matter of intelligence or technical savvy, as even seasoned administrators have been known to trip over a well-constructed lure when the timing is right. The adversary waits for the moment of highest friction—the end of a quarter, the middle of a migration, or the chaos of a public holiday—to drop a message that demands immediate attention. This creates a sense of urgency that effectively narrows the victim’s field of vision, making them ignore the subtle discrepancies in the sender’s address or the slightly off-kilter phrasing of the call to action.

    Furthermore, the concept of social proof is weaponized within these emails to provide a false sense of security that lulls the victim into a state of compliance. Many of these “official” messages are designed to look like a small part of a larger, ongoing process, such as a mandatory security update or a routine document review. By framing the malicious link as a necessary step in a boring, everyday task, the attacker sidesteps the natural skepticism that usually accompanies an unexpected request. Consequently, the victim views the interaction not as a potential threat, but as a minor hurdle to be cleared so they can return to their actual work. This mundane nature of the attack is its greatest strength, allowing it to slip through the cracks of human intuition while the technical defenses are busy looking for more overt signs of intrusion.

    Why Technical Defense Perimeters Often Fail the Human Test

    We have spent billions of dollars on secure email gateways and advanced threat protection, yet the “official” email remains the most successful entry point for ransomware and data exfiltration. This failure is rooted in the inherent tension between usability and security, where the need for seamless communication often creates gaps that an attacker can drive a truck through. A secure email gateway is essentially a filter designed to catch known bad patterns, but the modern phisher is an expert at staying just beneath the threshold of detection. They use legitimate infrastructure, such as compromised Small Business Server accounts or reputable cloud hosting providers, to launch their campaigns. When a malicious email originates from a trusted IP address with valid cryptographic signatures, the technical gates swing wide open, leaving only the human at the keyboard to make the final call.

    In addition to the subversion of trust, the rapid pace of digital transformation has outstripped the ability of the average user to verify the authenticity of their communications. As organizations move their operations to various third-party SaaS platforms, the number of “official” domains that a user interacts with on a daily basis has skyrocketed. It is no longer enough to look for a single corporate domain; employees are now expected to recognize notifications from payroll systems, project management tools, and cloud storage providers, all of which use different naming conventions and email templates. This fragmentation creates a smokescreen for the attacker, who can easily hide a malicious domain amidst the noise of a dozen legitimate ones. As a result, the mental fatigue of constantly verifying these sources leads to a state of “security nihilism,” where the user eventually stops checking altogether and simply clicks through to stay productive.

    The anatomy of a modern credential harvest is a masterclass in deceptive minimalism, designed to exploit the very tools we use to stay organized and secure. Looking at the mechanics of the “Official” document lure, I see a devastatingly effective strategy that leverages the ubiquity of shared drives and collaborative platforms like SharePoint or DocuSign. The attacker doesn’t need to attach a piece of malware that might trigger an endpoint detection system; they simply provide a link to a legitimate-looking landing page that asks for a login to “view the protected file.” This transition from a trusted email environment to a browser-based authentication prompt is where the logic breaks down for most users. Because the initial email looked like a standard notification—complete with the correct legal disclaimers and corporate branding—the user’s brain has already cleared the transaction for takeoff. By the time they land on the spoofed login page, they aren’t looking for a scam; they are looking for their document, and they will hand over their credentials to get it.

    The danger is compounded by the rise of “Living off the Land” techniques in the phishing world, where attackers use the victim’s own tools against them. When an adversary compromises a legitimate account within a supply chain, they can send “official” emails from a truly valid source to that person’s entire contact list. This lateral movement within a trusted ecosystem is the nightmare scenario for any security operations center because the traditional red flags simply do not exist. There is no mismatched “From” header to inspect, and the link often points to a real file hosted on a real corporate server that happens to contain a malicious redirect. In this context, the victim isn’t falling for a fake; they are being misled by a compromised reality. This level of deception makes it nearly impossible for the average employee to distinguish between a routine request and a high-stakes heist, especially when the message arrives in the middle of a high-pressure workday.

    The Institutional Cost of Authority-Based Exploitation

    When we break down the damage, we see that the financial toll of these “official” phishes is often eclipsed by the erosion of internal culture and institutional trust. Every time a successful campaign rips through a department, the aftermath involves a heavy-handed response from IT that usually includes more restrictive policies and mandatory, often condescending, training modules. This creates a friction-filled environment where employees start to view their own security team as an adversary or a hurdle to their productivity. Furthermore, the psychological impact on the individual who clicked the link can be profound, leading to a loss of confidence that hampers their work performance and makes them less likely to report future suspicious activity for fear of further embarrassment. Consequently, the organization becomes more brittle, hiding its vulnerabilities behind a facade of compliance while the actual risk remains unaddressed and festering in the shadows.

    Looking at the broader economic landscape, the industrialization of phishing kits has lowered the barrier to entry for low-level criminals, allowing them to masquerade as sophisticated entities with the click of a button. These kits come pre-loaded with high-fidelity templates for every major bank, government agency, and tech giant, ensuring that even a novice operator can launch an “official” campaign that looks professional. This democratization of high-end social engineering means that the volume of attacks is constantly increasing, creating a background radiation of fraud that everyone must navigate daily. The sheer frequency of these encounters leads to a desensitization of the workforce, where the warning signs that used to trigger an alarm are now ignored as part of the digital noise. This saturation of the communication channel is exactly what the adversary wants, as it ensures that eventually, someone, somewhere, will be tired or distracted enough to swallow the hook.

    The Illusion of Multi-Factor Authentication as a Total Shield

    One of the most dangerous myths in the current security climate is the idea that Multi-Factor Authentication is an unhackable barrier that renders phishing obsolete. While MFA is a critical layer of defense, the “official” email has evolved to bypass it through sophisticated techniques like adversary-in-the-middle attacks and session hijacking. In a standard MFA-bypass scenario, the malicious email leads the victim to a proxy server that mimics the real login page in real-time. As the victim enters their username, password, and the subsequent one-time code from their phone, the attacker’s server passes those credentials to the actual service and steals the resulting session cookie. To the user, the experience is seamless and appears entirely “official,” but behind the scenes, the attacker now has a persistent foothold that bypasses the need for a password entirely. This proves that even our most robust technical solutions can be undermined by a well-executed social engineering play that targets the moment of authentication.

    Moreover, the phenomenon of “MFA Fatigue” has become a potent weapon in the attacker’s arsenal, turning a security feature into a vulnerability. After sending a series of “official” emails claiming there is a problem with an account, the attacker will trigger a barrage of push notifications to the victim’s mobile device. The goal is to wear the person down until they hit “Approve” just to make the buzzing stop, assuming it’s a glitch in the “official” system. This exploit doesn’t require technical brilliance; it requires an understanding of human frustration and the tendency to take the path of least resistance. It demonstrates that as long as there is a human in the loop, the adversary will find a way to manipulate that person into opening the door, no matter how many locks we put on it. The “official” email is merely the first step in a psychological siege designed to break the victim’s resolve.

    The strategy of the modern phisher has moved beyond the simple theft of credentials and into the territory of high-stakes narrative control. When we analyze the rise of Business Email Compromise, it becomes clear that the “Official” email is often just the opening act in a long-form con that can last for weeks. The attacker doesn’t just want a password; they want to insert themselves into the financial workflow of an organization. By mimicking the tone, the signature blocks, and the specific jargon of a vendor or a high-level partner, the adversary creates a secondary reality where a change in banking details or a diverted wire transfer seems like a routine administrative adjustment. The horror of this approach lies in its banality. There are no flashing red lights or “Access Denied” screens; there is only a quiet, professional-looking email that follows every established rule of corporate etiquette while it drains the company’s accounts.

    Furthermore, the integration of generative AI into the attacker’s toolkit has eliminated the last remaining red flags that used to give these “Official” lures away. Gone are the days when a sharp-eyed employee could spot a phishing attempt by its poor grammar or awkward phrasing. Today’s lures are syntactically perfect, culturally nuanced, and tailored to the specific industry of the target. An attacker can now feed a few public interviews or LinkedIn posts from an executive into a model and generate an email that captures that individual’s unique “voice” with terrifying precision. This makes the “Official” email even more dangerous because it appeals to the victim’s sense of familiarity. Consequently, the gap between a legitimate internal communication and a fraudulent one has narrowed to the point of invisibility, leaving the human target to navigate a minefield where every step looks like solid ground.

    The Weaponization of Compliance and Legal Fear

    A significant portion of why people still fall for these lures is the strategic use of “regulatory theater” to induce a state of compliance-driven panic. Attackers have realized that the modern professional is terrified of three things: HR violations, tax audits, and data breaches. By framing a phishing lure as a “Mandatory Data Privacy Attestation” or an “Immediate Tax Compliance Notice,” the attacker leverages the weight of the law to bypass the user’s skepticism. These emails often include realistic references to actual legislation, such as GDPR or the CCPA, which adds a layer of superficial credibility that is hard to ignore. The victim isn’t just clicking a link; they are attempting to protect themselves or their company from a perceived legal threat. This flip of the script—making the scam look like a security measure—is a calculated move that turns a person’s best intentions into their greatest vulnerability.

    In addition to legal threats, the “Official” lure often exploits the internal power dynamics of the modern workplace. In a high-pressure environment where “performance” is everything, the fear of failing to respond to a superior is a powerful motivator. I see this play out in “Urgent Request” scenarios where the email appears to come from a CEO or a Board Member who is “stuck in a meeting” and needs a quick favor. The victim is often so focused on the social reward of being helpful or the fear of appearing incompetent that they fail to perform even basic due diligence. The adversary knows that in a hierarchy, authority flows downward with a force that can flatten common sense. By the time the employee thinks to call the executive to verify the request, the gift cards have been drained or the sensitive spreadsheet has been uploaded to a command-and-control server.

    Rebuilding the Perimeter on a Foundation of Radical Skepticism

    If we are going to survive in this environment, we have to move past the idea that we can train the human element out of the equation. The “Official” email works because it is designed to work on humans, and humans are fundamentally social, cooperative, and prone to pressure. The solution isn’t another hour of boring slide decks; it’s a fundamental shift toward an “Assume Breach” mentality at the individual level. This means moving away from a culture of blind trust and toward one of verified communication, where no request involving data or money is ever handled through a single, unverified channel. We need to normalize the “Double-Check”—the idea that calling a coworker to verify an unusual email is not a sign of paranoia, but a standard operating procedure. This cultural shift is far harder to implement than a new firewall, but it is the only thing that can stand against the psychological precision of the modern phisher.

    Moreover, organizations must stop relying on the visual “polish” of an email as a proxy for its legitimacy. We need to strip away the corporate logos and the fancy signatures in our minds and look at the raw intent of the message. If an email creates a sense of urgency, demands a bypass of standard procedures, or directs you to an external site to enter credentials, it should be treated as hostile until proven otherwise. The “Official” email is a mask, and the only way to beat it is to stop being impressed by the mask. We have to start valuing the friction in our systems—the extra steps, the out-of-band verifications, and the healthy skepticism—because that friction is the only thing that slows the attacker down long enough for us to see the hook beneath the bait. The rain is still falling on the digital asphalt, and the shadows are still reaching, but they only win when we let them lead us where they want us to go.

    The persistence of the “Official” email as a top-tier threat vector is ultimately a testament to the fact that technical solutions are being applied to a non-technical problem. We are trying to use cryptographic signatures and automated filters to solve for the human desire to be helpful, the fear of authority, and the exhaustion of the modern workday. It is a mismatch of resources that the adversary exploits with predatory efficiency. When I look at the wreckage left behind by these campaigns, it is rarely the result of a single catastrophic failure; rather, it is a series of small, logical concessions made by a tired person just trying to get through their inbox. The attacker doesn’t need to be a digital ghost or a coding prodigy; they just need to be a better actor than you are a skeptic. They understand that if they can control the narrative, they can control the network, and they use the “Official” branding as the stage on which they perform their heist.

    To break this cycle, we have to stop treating phishing as a “user error” and start treating it as an inevitable environmental hazard. This requires a defensive architecture that doesn’t just look for bad files, but looks for suspicious behaviors and anomalies in the flow of authority. If an executive who never handles wire transfers suddenly sends an “Official” urgent request for one, the system should be smart enough to flag the deviation, regardless of how clean the email headers look. We need to build systems that protect people from their own instinct to comply, creating hard stops and out-of-band verification requirements for any high-value transaction. The goal is to move the burden of defense off the shoulders of the individual and into the design of the workflow itself. Until we accept that the “Official” email is the most dangerous weapon in the digital world, we will continue to find ourselves staring at the empty accounts and compromised servers that are the hallmark of a successful hook, line, and sinker.

    Call to Action

    The time for treating phishing as a minor IT nuisance is over; it is a predatory psychological war, and you are currently the primary target. If you are a leader, you need to stop hiding behind automated filters and start building a culture where a healthy “no” is valued more than a rushed “yes.” Stop the assembly line long enough to verify the source, pick up the phone when an email feels even slightly off-kilter, and demand that your organization implements out-of-band verification for every high-stakes transaction. Don’t wait for the post-mortem report to realize your “official” communication was a ghost in the machine. Audit your workflows today, tighten your authentication protocols, and train your eyes to see the hook beneath the polish—because the next “urgent” email in your inbox isn’t looking to help you, it’s looking to gut you.

    SUPPORTSUBSCRIBECONTACT ME

    D. Bryan King

    Sources

    Disclaimer:

    The views and opinions expressed in this post are solely those of the author. The information provided is based on personal research, experience, and understanding of the subject matter at the time of writing. Readers should consult relevant experts or authorities for specific guidance related to their unique situations.

    Related Posts

    Rate this:

    #adversaryInTheMiddle #AiTM #AuthorityBias #BEC #businessEmailCompromise #CEOFraud #CognitiveLoad #corporateEspionage #corporateSecurity #credentialHarvesting #cyberDefense #cyberResilience #cyberRiskManagement #cyberThreats #cybercrime #cybersecurityBlog #cybersecurityTraining #dataBreach #DigitalAmbush #DKIM #DMARC #DocuSignScams #emailSecurity #financialFraud #HumanError #identityTheft #incidentResponse #informationSecurity #IRSPhishing #LivingOffTheLand #MalwareFreeAttacks #MFABypass #MFAFatigue #Microsoft365Security #OfficialEmailScams #phishing #PsychologicalExploitation #RegulatoryPhishing #secureEmailGateway #securityAwareness #SecurityNihilism #sessionHijacking #SharePointPhishing #socialEngineering #spearPhishing #SPF #threatIntelligence #TrustArchitecture #UrgencyTactics #vendorImpersonation #zeroTrust
  24. Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns

    Unit 42 researchers identified six new remote access Trojan variants deployed by Iran-nexus APT group Screening Serpens between February and April 2026, coinciding with a regional conflict starting February 28, 2026. The group targeted entities in the U.S., Israel, UAE, and other Middle Eastern locations, primarily focusing on technology sector professionals through highly tailored social engineering using personalized recruitment lures. Two new malware families, MiniUpdate and MiniJunk V2, were discovered featuring advanced techniques including AppDomainManager hijacking that manipulates .NET application initialization to disable security mechanisms. The campaigns demonstrated increased technical capabilities and operational resilience, with each variant using dedicated C2 infrastructure hosted on Azure. The attacks leveraged DLL sideloading, scheduled tasks for persistence, and sophisticated evasion techniques to maintain long-term access for espionage purposes.

    Pulse ID: 6a109360ffcb2c8229a150c7
    Pulse Link: otx.alienvault.com/pulse/6a109
    Pulse Author: AlienVault
    Created: 2026-05-22 17:33:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Azure #CyberSecurity #Espionage #InfoSec #Iran #Israel #Malware #MiddleEast #NET #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #SMS #SideLoading #SocialEngineering #Trojan #UAE #Unit42 #bot #AlienVault

  25. Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns

    Unit 42 researchers identified six new remote access Trojan variants deployed by Iran-nexus APT group Screening Serpens between February and April 2026, coinciding with a regional conflict starting February 28, 2026. The group targeted entities in the U.S., Israel, UAE, and other Middle Eastern locations, primarily focusing on technology sector professionals through highly tailored social engineering using personalized recruitment lures. Two new malware families, MiniUpdate and MiniJunk V2, were discovered featuring advanced techniques including AppDomainManager hijacking that manipulates .NET application initialization to disable security mechanisms. The campaigns demonstrated increased technical capabilities and operational resilience, with each variant using dedicated C2 infrastructure hosted on Azure. The attacks leveraged DLL sideloading, scheduled tasks for persistence, and sophisticated evasion techniques to maintain long-term access for espionage purposes.

    Pulse ID: 6a109360ffcb2c8229a150c7
    Pulse Link: otx.alienvault.com/pulse/6a109
    Pulse Author: AlienVault
    Created: 2026-05-22 17:33:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Azure #CyberSecurity #Espionage #InfoSec #Iran #Israel #Malware #MiddleEast #NET #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #SMS #SideLoading #SocialEngineering #Trojan #UAE #Unit42 #bot #AlienVault

  26. Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns

    Unit 42 researchers identified six new remote access Trojan variants deployed by Iran-nexus APT group Screening Serpens between February and April 2026, coinciding with a regional conflict starting February 28, 2026. The group targeted entities in the U.S., Israel, UAE, and other Middle Eastern locations, primarily focusing on technology sector professionals through highly tailored social engineering using personalized recruitment lures. Two new malware families, MiniUpdate and MiniJunk V2, were discovered featuring advanced techniques including AppDomainManager hijacking that manipulates .NET application initialization to disable security mechanisms. The campaigns demonstrated increased technical capabilities and operational resilience, with each variant using dedicated C2 infrastructure hosted on Azure. The attacks leveraged DLL sideloading, scheduled tasks for persistence, and sophisticated evasion techniques to maintain long-term access for espionage purposes.

    Pulse ID: 6a109360ffcb2c8229a150c7
    Pulse Link: otx.alienvault.com/pulse/6a109
    Pulse Author: AlienVault
    Created: 2026-05-22 17:33:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Azure #CyberSecurity #Espionage #InfoSec #Iran #Israel #Malware #MiddleEast #NET #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #SMS #SideLoading #SocialEngineering #Trojan #UAE #Unit42 #bot #AlienVault

  27. Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns

    Unit 42 researchers identified six new remote access Trojan variants deployed by Iran-nexus APT group Screening Serpens between February and April 2026, coinciding with a regional conflict starting February 28, 2026. The group targeted entities in the U.S., Israel, UAE, and other Middle Eastern locations, primarily focusing on technology sector professionals through highly tailored social engineering using personalized recruitment lures. Two new malware families, MiniUpdate and MiniJunk V2, were discovered featuring advanced techniques including AppDomainManager hijacking that manipulates .NET application initialization to disable security mechanisms. The campaigns demonstrated increased technical capabilities and operational resilience, with each variant using dedicated C2 infrastructure hosted on Azure. The attacks leveraged DLL sideloading, scheduled tasks for persistence, and sophisticated evasion techniques to maintain long-term access for espionage purposes.

    Pulse ID: 6a109360ffcb2c8229a150c7
    Pulse Link: otx.alienvault.com/pulse/6a109
    Pulse Author: AlienVault
    Created: 2026-05-22 17:33:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Azure #CyberSecurity #Espionage #InfoSec #Iran #Israel #Malware #MiddleEast #NET #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #SMS #SideLoading #SocialEngineering #Trojan #UAE #Unit42 #bot #AlienVault

  28. Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns

    Unit 42 researchers identified six new remote access Trojan variants deployed by Iran-nexus APT group Screening Serpens between February and April 2026, coinciding with a regional conflict starting February 28, 2026. The group targeted entities in the U.S., Israel, UAE, and other Middle Eastern locations, primarily focusing on technology sector professionals through highly tailored social engineering using personalized recruitment lures. Two new malware families, MiniUpdate and MiniJunk V2, were discovered featuring advanced techniques including AppDomainManager hijacking that manipulates .NET application initialization to disable security mechanisms. The campaigns demonstrated increased technical capabilities and operational resilience, with each variant using dedicated C2 infrastructure hosted on Azure. The attacks leveraged DLL sideloading, scheduled tasks for persistence, and sophisticated evasion techniques to maintain long-term access for espionage purposes.

    Pulse ID: 6a109360ffcb2c8229a150c7
    Pulse Link: otx.alienvault.com/pulse/6a109
    Pulse Author: AlienVault
    Created: 2026-05-22 17:33:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Azure #CyberSecurity #Espionage #InfoSec #Iran #Israel #Malware #MiddleEast #NET #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #SMS #SideLoading #SocialEngineering #Trojan #UAE #Unit42 #bot #AlienVault

  29. DATE: May 22, 2026 at 06:03PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    @HHSGov Launches ##AI-Powered Effort to Identify Fraud, Waste: Tools Will Analyze Audits of States, Grantees That Receive Federal Funding t.co/Z0OpNpAoEA

    Here are any URLs found in the article text:

    t.co/Z0OpNpAoEA

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  30. Der Fall von C.A. Cloud Attribution zeigt deutlich, wie professionell und international organisierte Tech-Support-Betrugsnetzwerke heute operieren. Cybercrime ist längst kein Einzelfall von Hackern mehr, sondern umfasst komplexe Geschäftsmodelle mit globalen Callcentern, Telemarketing-Systemen und digitaler Infrastruktur. 👇

    #cybercrime #datenbetrug #malware #telefonbetrug #scamnetzwerk #onlinebetrug #digitalesicherheit #callcenterbetrug #socialengineering #identitätsdiebstahl #thirdpartyrisk #cybersecuritytips #itsicherheit

    teufelswerk.net/cybercrime-im-

  31. Der Fall von C.A. Cloud Attribution zeigt deutlich, wie professionell und international organisierte Tech-Support-Betrugsnetzwerke heute operieren. Cybercrime ist längst kein Einzelfall von Hackern mehr, sondern umfasst komplexe Geschäftsmodelle mit globalen Callcentern, Telemarketing-Systemen und digitaler Infrastruktur. 👇

    #cybercrime #datenbetrug #malware #telefonbetrug #scamnetzwerk #onlinebetrug #digitalesicherheit #callcenterbetrug #socialengineering #identitätsdiebstahl #thirdpartyrisk #cybersecuritytips #itsicherheit

    teufelswerk.net/cybercrime-im-

  32. Der Fall von C.A. Cloud Attribution zeigt deutlich, wie professionell und international organisierte Tech-Support-Betrugsnetzwerke heute operieren. Cybercrime ist längst kein Einzelfall von Hackern mehr, sondern umfasst komplexe Geschäftsmodelle mit globalen Callcentern, Telemarketing-Systemen und digitaler Infrastruktur. 👇

    #cybercrime #datenbetrug #malware #telefonbetrug #scamnetzwerk #onlinebetrug #digitalesicherheit #callcenterbetrug #socialengineering #identitätsdiebstahl #thirdpartyrisk #cybersecuritytips #itsicherheit

    teufelswerk.net/cybercrime-im-

  33. Der Fall von C.A. Cloud Attribution zeigt deutlich, wie professionell und international organisierte Tech-Support-Betrugsnetzwerke heute operieren. Cybercrime ist längst kein Einzelfall von Hackern mehr, sondern umfasst komplexe Geschäftsmodelle mit globalen Callcentern, Telemarketing-Systemen und digitaler Infrastruktur. 👇

    #cybercrime #datenbetrug #malware #telefonbetrug #scamnetzwerk #onlinebetrug #digitalesicherheit #callcenterbetrug #socialengineering #identitätsdiebstahl #thirdpartyrisk #cybersecuritytips #itsicherheit

    teufelswerk.net/cybercrime-im-

  34. Der Fall von C.A. Cloud Attribution zeigt deutlich, wie professionell und international organisierte Tech-Support-Betrugsnetzwerke heute operieren. Cybercrime ist längst kein Einzelfall von Hackern mehr, sondern umfasst komplexe Geschäftsmodelle mit globalen Callcentern, Telemarketing-Systemen und digitaler Infrastruktur. 👇

    #cybercrime #datenbetrug #malware #telefonbetrug #scamnetzwerk #onlinebetrug #digitalesicherheit #callcenterbetrug #socialengineering #identitätsdiebstahl #thirdpartyrisk #cybersecuritytips #itsicherheit

    teufelswerk.net/cybercrime-im-

  35. DATE: May 21, 2026 at 05:28PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #LibertyMutual Sued Over Alleged #Everest Group #DataTheft: Incident Comes Months After #NYS Fined @LibertyMutual $2M in Other Hacks t.co/6yJITEPDPq

    Here are any URLs found in the article text:

    t.co/6yJITEPDPq

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  36. DATE: May 21, 2026 at 05:28PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #LibertyMutual Sued Over Alleged #Everest Group #DataTheft: Incident Comes Months After #NYS Fined @LibertyMutual $2M in Other Hacks t.co/6yJITEPDPq

    Here are any URLs found in the article text:

    t.co/6yJITEPDPq

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  37. DATE: May 21, 2026 at 05:28PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #LibertyMutual Sued Over Alleged #Everest Group #DataTheft: Incident Comes Months After #NYS Fined @LibertyMutual $2M in Other Hacks t.co/6yJITEPDPq

    Here are any URLs found in the article text:

    t.co/6yJITEPDPq

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  38. DATE: May 21, 2026 at 05:28PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #LibertyMutual Sued Over Alleged #Everest Group #DataTheft: Incident Comes Months After #NYS Fined @LibertyMutual $2M in Other Hacks t.co/6yJITEPDPq

    Here are any URLs found in the article text:

    t.co/6yJITEPDPq

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  39. Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks

    Attackers exploited CVE-2026-26980, a critical SQL injection vulnerability in Ghost CMS, to obtain Admin API Keys without authorization and conduct mass website poisoning campaigns. Over 700 domains across multiple industries including universities, blockchain, AI, security research, and media were compromised. The attack chain involves CMS takeover, page poisoning with malicious JavaScript loaders, two-stage cloaking scripts, and FakeCaptcha social engineering to trick users into executing malicious commands. Two distinct threat groups are actively exploiting unpatched Ghost CMS installations, delivering information stealers and remote access tools. Compromised sites include Harvard University, Oxford University, and Auburn University. The attacks leverage users' trust in legitimate websites to increase success rates of ClickFix-type attacks, with payloads being dynamically distributed through Cloudflare-proxied domains.

    Pulse ID: 6a0f06676dfe8431915ed38a
    Pulse Link: otx.alienvault.com/pulse/6a0f0
    Pulse Author: AlienVault
    Created: 2026-05-21 13:19:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #CAPTCHA #Cloud #CyberSecurity #InfoSec #Java #JavaScript #OTX #OpenThreatExchange #RAT #Rust #SQL #SocialEngineering #Vulnerability #bot #AlienVault

  40. Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks

    Attackers exploited CVE-2026-26980, a critical SQL injection vulnerability in Ghost CMS, to obtain Admin API Keys without authorization and conduct mass website poisoning campaigns. Over 700 domains across multiple industries including universities, blockchain, AI, security research, and media were compromised. The attack chain involves CMS takeover, page poisoning with malicious JavaScript loaders, two-stage cloaking scripts, and FakeCaptcha social engineering to trick users into executing malicious commands. Two distinct threat groups are actively exploiting unpatched Ghost CMS installations, delivering information stealers and remote access tools. Compromised sites include Harvard University, Oxford University, and Auburn University. The attacks leverage users' trust in legitimate websites to increase success rates of ClickFix-type attacks, with payloads being dynamically distributed through Cloudflare-proxied domains.

    Pulse ID: 6a0f06676dfe8431915ed38a
    Pulse Link: otx.alienvault.com/pulse/6a0f0
    Pulse Author: AlienVault
    Created: 2026-05-21 13:19:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #CAPTCHA #Cloud #CyberSecurity #InfoSec #Java #JavaScript #OTX #OpenThreatExchange #RAT #Rust #SQL #SocialEngineering #Vulnerability #bot #AlienVault

  41. Beyond Tax Returns: How Shared Malware Infrastructure Scales Brand Abuse In Indonesia

    A sophisticated fraud campaign exploiting Indonesia's tax season targeted 67 million residents through fake Coretax applications distributed via phishing websites and WhatsApp social engineering. The GoldFactory threat cluster orchestrated operations using Gigabud.RAT and MMRat malware families with shared infrastructure abusing over 16 trusted brands across government and financial sectors. The attack chain combines vishing, screen recording, and remote access capabilities to achieve device compromise and unauthorized financial transfers. Estimated financial impact reaches USD 1.5-2 million nationwide, with global implications extending to USD 6 million annually across multiple countries. The industrialized malware-as-a-service infrastructure enables horizontal scaling across Thailand, Vietnam, Philippines, and South Africa, demonstrating a shift toward unified cross-border operations that systematically undermine trust in digital government services.

    Pulse ID: 6a0daa32ac6609fbd06d30ae
    Pulse Link: otx.alienvault.com/pulse/6a0da
    Pulse Author: AlienVault
    Created: 2026-05-20 12:33:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #CyberSecurity #Government #Indonesia #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #Philippines #Phishing #RAT #Rust #SocialEngineering #Thailand #Vietnam #WhatsApp #bot #AlienVault

  42. Operation Dragon Whistle: UNG002 Targets Chinese Academia via Weaponized Institutional Lure

    A sophisticated spear-phishing campaign designated Operation Dragon Whistle has been identified targeting Changzhou University in China. The threat actor UNG002 leveraged highly contextual social engineering by impersonating official university communications regarding mandatory 2026 National Student Physical Fitness and Health Standards testing, which directly impacts graduation eligibility. The attack chain begins with a weaponized ZIP file containing a malicious LNK file disguised as a PDF document. Upon execution, it triggers a VBScript that simultaneously displays a legitimate-looking decoy document while deploying a multi-stage infection chain involving DLL sideloading via Bandizip.exe, anti-debugging techniques, and ultimately delivering a Cobalt Strike Beacon payload entirely in memory. The campaign demonstrates advanced evasion capabilities and utilizes Chinese cloud infrastructure hosted on Alibaba Cloud for command and control operations.

    Pulse ID: 6a0db1f45208b8cf1b2b1571
    Pulse Link: otx.alienvault.com/pulse/6a0db
    Pulse Author: AlienVault
    Created: 2026-05-20 13:07:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #China #Chinese #Cloud #CobaltStrike #CyberSecurity #InfoSec #LNK #OTX #OpenThreatExchange #PDF #Phishing #RAT #SideLoading #SocialEngineering #SpearPhishing #VBS #ZIP #bot #AlienVault

  43. DATE: May 21, 2026 at 08:52AM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    Why Are Smaller #Healthcare Providers Such Easy Targets for #Hackers? t.co/Ip71icBdNc

    Here are any URLs found in the article text:

    t.co/Ip71icBdNc

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  44. DATE: May 21, 2026 at 08:52AM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    Why Are Smaller #Healthcare Providers Such Easy Targets for #Hackers? t.co/Ip71icBdNc

    Here are any URLs found in the article text:

    t.co/Ip71icBdNc

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  45. DATE: May 21, 2026 at 08:52AM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    Why Are Smaller #Healthcare Providers Such Easy Targets for #Hackers? t.co/Ip71icBdNc

    Here are any URLs found in the article text:

    t.co/Ip71icBdNc

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  46. DATE: May 21, 2026 at 08:52AM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    Why Are Smaller #Healthcare Providers Such Easy Targets for #Hackers? t.co/Ip71icBdNc

    Here are any URLs found in the article text:

    t.co/Ip71icBdNc

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  47. DATE: May 20, 2026 at 05:51PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    Why Smaller #Healthcare Providers Remain Easy Targets: Recent #Hacks Underscore Persistent and Growing Threats to Smaller Organizations t.co/Ip71icAFXE
    #HIPAA #Verizon #VerizonDBIR #databreach #healthdatabreach

    Here are any URLs found in the article text:

    t.co/Ip71icAFXE

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  48. DATE: May 20, 2026 at 05:51PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    Why Smaller #Healthcare Providers Remain Easy Targets: Recent #Hacks Underscore Persistent and Growing Threats to Smaller Organizations t.co/Ip71icAFXE
    #HIPAA #Verizon #VerizonDBIR #databreach #healthdatabreach

    Here are any URLs found in the article text:

    t.co/Ip71icAFXE

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  49. DATE: May 20, 2026 at 05:51PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    Why Smaller #Healthcare Providers Remain Easy Targets: Recent #Hacks Underscore Persistent and Growing Threats to Smaller Organizations t.co/Ip71icAFXE
    #HIPAA #Verizon #VerizonDBIR #databreach #healthdatabreach

    Here are any URLs found in the article text:

    t.co/Ip71icAFXE

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  50. DATE: May 20, 2026 at 05:51PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    Why Smaller #Healthcare Providers Remain Easy Targets: Recent #Hacks Underscore Persistent and Growing Threats to Smaller Organizations t.co/Ip71icAFXE
    #HIPAA #Verizon #VerizonDBIR #databreach #healthdatabreach

    Here are any URLs found in the article text:

    t.co/Ip71icAFXE

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering