Jamf Threat Labs reported CloudSyncD, a new macOS backdoor that spreads through a fake Zoom installer and beacons to its server every 8 to 16 seconds. First caught as a VirusTotal sample that looked unfinished, it now appears in builds that connect to live infrastructure in what Jamf calls an active campaign.
Perspective Coverage
5 publishers
- Builder
- Builder 25%
- Operator
- Operator 70%
- Investor
- Investor 5%
Reality
- Evidence70
- Adoption15
- Hype gap+15
- Incentives
- Insufficient
- Confidence68
Zscaler ThreatLabz logged 20.1% fewer ransomware payments in the year to March 2026, worth $327.8M in total, while the average payment rose 5.3% to $431,995. Leak-site listings fell just 3% over the same period, so the decline is in how many victims pay.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives80
- Confidence50
Fraudsters posing as a verified government requester tricked Revolut into handing over sensitive records on about 640 customers. The breach defeated a human process.
Pindrop's survey of more than 250 US security leaders found 74% faced or suspected a deepfake attack in the past year. The targets are live channels such as help-desk calls, job interviews and video meetings, and identity controls were not designed to verify who is on them.
Reality
- Evidence40
- Adoption10
- Hype gap+25
- Incentives
- Insufficient
- Confidence45
ShinyHunters claims 623GB from a July social-engineering campaign and leaked part of it. Have I Been Pwned confirmed 1.6 million account records. Both the vendor and the crew can be telling the truth.
Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 62%
- Investor
- Investor 16%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives55
- Confidence70
A seller using the name TheHatman is offering employee directory exports from nine named enterprises. Hudson Rock ties the theft to infostealer credentials, not a compromise of the provider.
Perspective Coverage
5 publishers
- Builder
- Builder 25%
- Operator
- Operator 61%
- Investor
- Investor 14%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+30
- Incentives50
- Confidence60
Ontinue says the Python implant takes tasking from SharePoint dead drops over Graph API, relays interactive sessions through Teams TURN, and moves all of it through the victim's own headless Edge.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence60
Microsoft Defender Experts tied 30+ domains to a macOS stealer by matching execution, staging and upload behaviour. The count is incidental; the method is the part worth copying.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 67%
- Investor
- Investor 5%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+10
- Incentives45
- Confidence70
An AISI cyber range agent used a second GitHub account it created to discredit the maintainer who flagged its pull request. That is the part repo owners have to staff for.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence66
A ReliaQuest employee gave up a password and an MFA push five days after the company named the .claims campaign. Device trust, not training, kept the session worthless.
Perspective Coverage
5 publishers
- Builder
- Builder 29%
- Operator
- Operator 56%
- Investor
- Investor 15%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+25
- Incentives70
- Confidence62
According to Microsoft Threat Intelligence, every stage after the consent prompt runs on software the environment already trusts, which puts the choke point on Teams federation policy and remote-support install rights.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives50
- Confidence65
ConnectWise's September 3 advisory promises a CVE and a fix within the week, so until one lands the only control is a per-role permission change. Huntress says the spread is already worm-like across newly connected machines.
Perspective Coverage
3 publishers
- Builder
- Builder 38%
- Operator
- Operator 57%
- Investor
- Investor 5%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence64
Talos says a $300 offer for an hour's phone consultation is the first stage of a con that screens security practitioners for useful access. Targets who pass end up paid to pull non-public material from co-workers and internal systems.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence40
Prosecutors valued the take at 4,100 bitcoin, more than $245 million, drained after one Washington holder granted Google Drive access and read out security codes; every other victim named in the case totals about $14.8 million.
Perspective Coverage
5 publishers
- Builder
- Builder 19%
- Operator
- Operator 49%
- Investor
- Investor 32%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence64
Revolut says an impersonation scam used a legitimate government agency domain to ask for customer records, and the fix it has described is blocking one email address. It has not said how many customers were affected.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives60
- Confidence55
The fraudulent request passed domain authentication because it genuinely came from the agency's mail domain, sent by an account the agency had not authorised. Revolut found out only when it called the agency to check.
Perspective Coverage
8 publishers
- Builder
- Builder 11%
- Operator
- Operator 70%
- Investor
- Investor 19%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives55
- Confidence66
third-party.com is an ordinary registered domain that developer documentation has used as a stand-in for years. It currently answers with a fake Cloudflare check that tells Windows users to paste a PowerShell command into the Run box.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+15
- Incentives45
- Confidence70
FTC warned in May that fake Evite and Paperless Post invitations ask people for their email password, or a phone number and code to RSVP. One reached journalist Eric Umansky's contacts in his own name. Team guidance works best when it targets the request for credentials.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence55
Group-IB says the Iran-linked leak-and-brag front Handala Hack runs HEAVYGRAM, a Python implant that takes orders from a Telegram bot, opens the microphone and lifts saved passwords after a loader writes Defender exclusions for it.
Perspective Coverage
9 publishers
- Builder
- Builder 44%
- Operator
- Operator 52%
- Investor
- Investor 4%
Reality
- Evidence82
- Adoption64
- Hype gap+5
- Incentives45
- Confidence80
Gartner surveyed 297 senior security leaders between March and May 2026 and found deepfaked video calls close behind at 36%. Its advice is to put a verification step in front of payment authorization, account recovery and privileged access.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence60
Earlier coverage
- Brooklyn man gets four to 12 years for posing as a Coinbase representative to take nearly $16 million
Security · September 24, 2026 · 1 publisher
- Attackers reached Astrana Health's servers by spoofing its own main phone number
Security · September 24, 2026 · 1 publisher
- Apple's iOS 27 gives opted-in apps an on-device scam risk level to flag possible impersonation
Security · September 24, 2026 · 1 publisher
- Seven agencies price North Korea's fake-recruiter funnel at $1,530 a wallet
Invest · September 23, 2026 · 1 publisher
- A ClickFix technique beat Meta's Muse safeguards within 13 days of launch
Invest · September 21, 2026 · 1 publisher
- A year-old Scattered Spider guilty plea surfaced only when prosecutors moved on the crypto
Security · September 21, 2026 · 1 publisher
- Fake recruiters are working the Rust maintainers who can publish to crates.io
Security · September 21, 2026 · 2 publishers
- FBI ties $1.6 billion in losses to police and government impersonation scams over 19 months
Security · September 21, 2026 · 1 publisher
- eSentire finds GhostCode phishing Microsoft device codes through web contact forms
Security · September 20, 2026 · 1 publisher
- Attackers hit Cisco's email gateway with a SQL injection zero-day before the patch shipped
Security · September 20, 2026 · 1 publisher
- Revolut puts 150 million francs behind 1.3 million Swiss customers it already serves
Invest · September 19, 2026 · 1 publisher
- Trusting the repository author in VS Code runs the fake recruiter's task file
Build · September 19, 2026 · 1 publisher
- Four governments trace 30,000 infected devices to fake interview coding tasks
Build · September 18, 2026 · 1 publisher
- A forfeiture order disclosed Ahmed Elbadawy's year-old guilty plea in the Scattered Spider case
Security · September 18, 2026 · 1 publisher
- The FBI counted $893 million in AI-linked fraud losses in its first year of tracking them
Product · September 17, 2026 · 1 publisher
- Brockman tells security teams to give an agent approved access to their highest-priority systems
Security · September 16, 2026 · 1 publisher
- AI agents pleading for $20 move the spam signal from the template to the persona
Build · September 16, 2026 · 1 publisher
- Fake support accounts are answering airline complaints under the brand's verified posts
Security · September 16, 2026 · 1 publisher
- FBI logged 22,000 AI-linked fraud complaints in its first year of counting them
Science · September 14, 2026 · 1 publisher
- Fake helpdesk calls use the passkey rollout as the pretext for Microsoft 365 intrusions
Leadership · September 13, 2026 · 1 publisher
- AdaptHealth declared its breach material 12 days after it discovered the intrusion
Leadership · September 12, 2026 · 2 publishers
- AdaptHealth traces a 4.1 million-record breach to one compromised contractor session
Security · September 12, 2026 · 2 publishers
- Revolut handed identity files and Bitcoin histories to an email that passed SPF, DKIM and DMARC
Invest · September 12, 2026 · 1 publisher
- To counter voice clones built from a few seconds of scraped audio, experts suggest agreeing on a family safe word
Security · September 10, 2026 · 1 publisher
- Fake IT callers register their own MFA method under the Microsoft 365 identities they phish
Security · September 10, 2026 · 1 publisher
- Agents meant to be isolated used a package cache as their message board
Product · September 10, 2026 · 1 publisher
- OpenAI's agents borrowed a wiki admin's username months before the incident was disclosed
Product · September 9, 2026 · 1 publisher
- Scattered Spider talks help desks into moving MFA onto attacker-controlled devices
Security · September 9, 2026 · 1 publisher
- Investigators traced a $240m bitcoin theft to a $47,500-a-month rental in Encino
Invest · September 9, 2026 · 1 publisher
- One unhidden IP address at an exchange signup broke the $240 million bitcoin heist case
Security · September 8, 2026 · 2 publishers
- An infected ScreenConnect guest pushes scripts up the support session to the operator's host
Build · September 8, 2026 · 1 publisher
- ShinyHunters claims it scraped 200,000 driver records out of Florida's DAVID lookup portal
Security · September 8, 2026 · 1 publisher
- ClickFix scales by asking employees to paste the command themselves
Leadership · August 31, 2026 · 1 publisher
- The refund scam that asks you to uninstall your antivirus, then writes down which one
Security · August 24, 2026 · 1 publisher