Help Net Security newsletters: Daily and weekly news, cybersecurity jobs, open source projects, breaking news – subscribe here!

Please turn on your JavaScript for this page to function normally.
danger
Fake OpenAI Codex download tricks macOS users into installing malware

A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has been uncovered by …

social engineering
ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack

Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief window into the …

online fraud
Banks look for fraud signals in customer behavior

Banks are dealing with more fraud in which customers authorize payments after being manipulated by criminals. ThreatMark’s Fraud Readiness Benchmark 2026 describes a banking …

Android
New Android malware relays bank cards to fraudsters while victims still hold them

Group-IB researchers discovered WindRelay, a new Android malware built to capture live payment card data over NFC (Near Field Communication) and relay it to attackers in real …

crypto scams
Fake IRS letters direct crypto holders to bogus compliance portal

Scammers are sending physical letters to cryptocurrency holders that copy the look of official IRS notices. The letters tell recipients they must enroll in something called a …

phishing
The best-funded companies open the most phishing attachments

An employee gets an email dressed as a password reset. She clicks the link, types her credentials into a page built to copy her company’s login screen, and moves on with …

FaceTime
Scammers weaponize FaceTime to drain bank accounts

Apple is warning iPhone and iPad users that scammers are using FaceTime calls to trick them into handing over money and account details. According to Apple, scammers pose as …

Transport for London
Scattered Spider members jailed over Transport for London hack that cost £29 million

Two members of the notorious “Scattered Spider” hacking collective have been sentenced to five years and six months in prison each for a cyberattack on Transport …

ClickFix
ClickFix is changing the economics of social engineering

ClickFix has moved from a one-off social engineering trick into an industrialized attack ecosystem that is outpacing conventional antivirus and endpoint defenses, according to …

AI
AI used to help plan the break-in, now it’s doing the break-in

Over the past twelve months, researchers documented intrusions in which AI ran exploitation workflows autonomously, generating thousands of commands across dozens of sessions …

data request
Most data brokers won’t tell you what happened to your deletion request

Data brokers collect personal details on most adults in the United States and sell them to buyers that include employers, landlords, insurance companies, and government …

Microsoft 365 phishing
Extortion crew hijacks Microsoft 365 accounts via fake passkey setup

The Pink cyber extortion crew is tricking employees into giving them access to their Microsoft 365 accounts by faking Entra passkey enrollment requests. The attack The attack …

Don't miss

Cybersecurity news
Daily newsletter sent Monday-Friday
Weekly newsletter sent on Mondays
Editor's choice newsletter sent twice a month
Periodical newsletter released for important security events and breaking news
Weekly newsletter listing new cybersecurity job positions
Monthly newsletter focusing on open source cybersecurity tools