BleepingComputer is partnering with Material Security for a live webinar on September 23 examining documented Google Workspace breaches. Speakers Rajan Kapoor of Material Security and Rick Fitzgerald of Fireside Consulting will dissect two incidents where attackers used social engineering and rogue OAuth apps to gain access, then walk through the response decisions that followed.
bleepingcomputer.com
· 2026-09-22
BleepingComputer and Material Security are hosting a live webinar on September 23, 2026, examining real, publicly documented breaches of Google Workspace environments. Speakers Rajan Kapoor of Material Security and Rick Fitzgerald of Fireside Consulting LLC will dissect incidents involving social engineering and malicious OAuth apps to identify which defenses failed and which security controls actually matter.
bleepingcomputer.com
· 2026-09-18
iOS 27 includes a new privacy feature called Impersonation Risk Detection, designed to flag social engineering scams where attackers pose as banks or trusted contacts to pressure victims into transferring money or changing account details. The feature is disabled by default and must be turned on manually through Settings > Privacy & Security > Impersonation Risk Detection. It works by analyzing device and Apple Account signals to generate a risk score that participating apps can use to add warnings, delays, or identity checks.
9to5mac.com
· 2026-09-16
BleepingComputer is hosting a live webinar on September 23, 2026, featuring Material Security's Rajan Kapoor and Fireside Consulting's Rick Fitzgerald, who will dissect real, publicly documented Google Workspace breaches. The session focuses on the critical early hours after a breach is discovered, including cases where attackers used social engineering paired with malicious OAuth apps to gain entry.
bleepingcomputer.com
· 2026-09-16
BleepingComputer is hosting a live webinar on September 23, 2026, with Material Security's Rajan Kapoor and Fireside Consulting's Rick Fitzgerald, who will dissect two real breaches of Google Workspace environments carried out through malicious OAuth applications and social engineering rather than stolen passwords. The session will walk through how the attacks unfolded, the security gaps that let them succeed, and the response decisions made in the early hours of each incident.
bleepingcomputer.com
· 2026-09-14
New research indicates that scammers using AI-generated voices that mimic a target's own accent are more effective at deceiving victims than generic synthetic voices. The findings suggest that accent-matching adds a layer of perceived familiarity and trust that makes fraudulent calls more convincing.
wsj.com
· 2026-09-13
At Black Hat USA 2026, security researcher Fred Heiding and former US National Cyber Director Chris Inglis presented findings showing AI's growing role in social engineering scams, which the FBI says cost Americans nearly $21 billion last year. Heiding argued that while AI can be used to defend against AI-driven technical attacks, it cannot easily counter AI's ability to psychologically manipulate humans.
darkreading.com
· 2026-09-11
Malone Lam, a 22-year-old Singaporean living in Miami, has pleaded guilty to racketeering charges tied to a cybercrime ring that allegedly stole and laundered hundreds of millions in cryptocurrency. Prosecutors say the 12-member group, which reportedly first connected through Minecraft before meeting in person in 2023, targeted wealthy crypto holders using social engineering, with individual thefts ranging from $800,000 to a single $245 million heist. Lam now faces up to 20 years in prison, with sentencing still pending.
tomshardware.com
· 2026-09-10
AdaptHealth has confirmed that a cyberattack discovered in July, linked to the ShinyHunters group, exposed personal and health data belonging to about 4.1 million patients. The company says attackers gained access on June 5 through a social engineering attack that compromised a third-party contractor's privileged account, reaching cloud-based patient management and record systems. Exposed data includes names, contact and demographic details, health insurance information, and health records.
bleepingcomputer.com
· 2026-09-09
Cisco Talos researchers identified two separate ClickFix-style social engineering campaigns that trick victims into executing malicious code themselves, one aimed at stealing cryptocurrency and another designed to gain persistent enterprise network access. One campaign uses a publicly shared Google Sheet to distribute malicious browser code that hijacks Chrome transaction interfaces, while both operations abuse legitimate cloud services and trusted software to disguise malicious activity as normal user behavior.
darkreading.com
· 2026-09-08
A joint alert from the US State Department, Japan, Canada and the UK warns that North Korean operatives are using falsified identity documents to get hired as remote IT workers at foreign companies, letting them enter corporate networks with legitimate-looking access. Separately, groups like Scattered Spider have used social engineering against help desks to trick staff into resetting passwords or MFA for accounts they don't own, bypassing strong authentication entirely.
bleepingcomputer.com
· 2026-08-25