Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AINorth Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels
Cybersecurity researchers at Proofpoint have identified two malicious campaigns linked to the North Korean threat group Contagious Interview, which is targeting developers through fake recruitment and code review schemes. The threat actor is weaponizing developer tools and processes to deliver malware via sophisticated phishing operations. This represents an evolution in North Korean cyber tactics
AIGoogle Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing
Google has filed a lawsuit against a Chinese cybercrime network for allegedly weaponizing its Gemini AI to facilitate SMS phishing (smishing) attacks targeting Americans. The network reportedly operates a phishing-as-a-service (PhaaS) platform called Outsider, demonstrating how threat actors are exploiting generative AI tools for malicious purposes.
AIPhishing Attack Volume Down 20%, but Risk Still Rising
Despite a 20% decrease in overall phishing attack volume, the threat landscape remains increasingly dangerous as cybercriminals shift their strategy from mass campaigns to more sophisticated, targeted attacks. Hackers are leveraging AI technologies to enhance the quality and effectiveness of their phishing attempts, making them harder to detect and more likely to succeed. This evolution represents
Cybersecurity Incidents Reported by Multiple Dental Practices
Multiple dental practices across the U.S. have reported cybersecurity incidents affecting thousands of patients, with breaches ranging from ransomware attacks to phishing-based email compromises. The incidents exposed sensitive patient data including Social Security numbers, medical records, and insurance information, with Bayside Dental's breach affecting over 10,000 patients and involving a rans
AIMeta Blocks NSO Group's New WhatsApp Phishing Attack, Files Contempt Order
Meta has detected and blocked spear-phishing attacks attributed to Israeli spyware vendor NSO Group targeting WhatsApp users. The company is filing a federal contempt order against NSO Group for violating a permanent injunction that prohibited the vendor from targeting WhatsApp and its users, with the attacks attempting to redirect victims to malicious external websites through deceptive links.
AIAI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload
AI-powered phishing campaigns are generating unprecedented volumes of sophisticated attacks, overwhelming Security Operations Center (SOC) Tier 1 analysts with alert fatigue. Attackers leverage AI to rapidly produce convincing phishing emails and fake login pages at scale, creating massive review queues that increase the risk of critical threats slipping through undetected. Organizations must adop
AIFIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins
Security researchers and the FBI have issued warnings about a surge in FIFA World Cup 2026-related cybersecurity threats targeting fans ahead of the tournament. Attackers are deploying thousands of fraudulent FIFA domains, banking malware embedded in illegal streaming applications, and sophisticated phishing pages designed to steal legitimate user credentials. These scams exploit the massive globa
Onsite Women’s Health $2.5M Data Breach Settlement
Onsite Women's Health reached a $2.525 million settlement following a phishing-enabled email breach that exposed protected health information of 357,265 individuals, including Social Security numbers, financial data, and medical records. The consolidated class action lawsuit alleged inadequate security measures failed to prevent or quickly detect the October 2024 breach, though the company denies
AIChina-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa
China-linked threat actor TA4922 has expanded its phishing campaign operations from initial targets to include organizations in the UK, Germany, Italy, and South Africa. The group demonstrates a rapid operational tempo and employs an evolving malware toolkit that includes ValleyRAT (Winos 4.0) and Atlas RAT (AtlasCross RAT) among other tools.
AIChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
Cybersecurity researchers at Permiso Security have identified a vulnerability dubbed 'ChatGPhish' in OpenAI's ChatGPT that exploits the platform's trust in Markdown links and images. The flaw enables attackers to execute prompt injection attacks and conduct phishing campaigns by manipulating how ChatGPT's web interface renders Markdown content. This vulnerability highlights emerging security risks
