LIVE · cybersecurity feed
Live wire
ransomware

Smashing Security podcast #487: Clippy’s crypto comeback

Microsoft's official Twitter account, which boasts 13 million followers, was reportedly compromised by an attacker who used the platform to promote a cryptocurrency scam. The incident, which occurred on October 8, 2026, involved the attacker posting an image of Clippy, Microsoft's former animated assistant, alongside a promotion for a "dodgy crypto coin."

ZeroDay News ·

Source: Graham Cluley

Microsoft's official Twitter account, which boasts 13 million followers, was reportedly compromised by an attacker who used the platform to promote a cryptocurrency scam. The incident, which occurred on October 8, 2026, involved the attacker posting an image of Clippy, Microsoft's former animated assistant, alongside a promotion for a "dodgy crypto coin."

The compromise did not involve ransomware or data theft, according to reports. Instead, the focus of the attack was solely on leveraging Microsoft's prominent social media presence to push the cryptocurrency scheme. Following the incident, a corporate apology was issued, though it was noted that the apology itself did not originate directly from Microsoft.

This event highlights a broader trend in cybersecurity, as losses from hacked email and social media accounts in the UK have seen a significant increase of 417%. Scammers are increasingly impersonating friends or trusted entities to promote fraudulent schemes, such as non-existent event tickets.

The incident also draws attention to the evolving landscape of cybersecurity threats, including those that exploit social engineering and brand impersonation. While the Microsoft Twitter account compromise was relatively benign in terms of direct data impact, it underscores the potential for widespread disinformation and financial fraud when high-profile accounts are breached.

Cybersecurity experts emphasize the importance of robust account security measures, including multi-factor authentication, and continuous monitoring of social media channels to detect and respond to unauthorized activity promptly. The use of AI agents in security teams is also being explored as a potential solution for enhancing threat detection and response capabilities, though questions remain about their performance evaluation and integration into existing security frameworks.

ransomwareai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Ransomware recovery CEO charged over secret ransom payments

The owner of MonsterCloud, a ransomware remediation company, has been charged with allegedly defrauding clients by secretly paying ransoms to cybercriminals while claiming to use proprietary technology for data recovery. Zohar Pinhasi, 50, also known as "Zack Silver" and "Zack Green," was indicted by a federal grand jury in the Eastern District of New York on September 23, 2026, and arraigned…

security

Cisco quantum network controller lets apps order entanglement on demand

Cisco has unveiled a Quantum Network Controller, a research prototype designed to enable applications to request entanglement on demand from a quantum network, abstracting away the underlying hardware complexities. This controller manages the distribution of entanglement, a linked quantum state shared between distant points, which is a critical resource for quantum networks.

breach

Evolution of Web3 in Cloud Supply Chain Attacks

Threat actors are increasingly leveraging Web3 technologies, including smart contracts and blockchain networks, to enhance their command-and-control (C2) infrastructure in cloud supply chain attacks. This evolution allows for dynamic updates to botnets and worm networks through single smart contract transactions, bypassing traditional Web 2.0-style network monitoring and making C2…

ai

Australian Gov't Weighs Mandatory AI Incident Reporting

The Australian government is reportedly considering the implementation of mandatory incident reporting requirements for companies developing and deploying frontier artificial intelligence systems. This move comes after an incident involving an "agentic attack" against the nation's Medicare systems, prompting a re-evaluation of regulatory frameworks for advanced AI.

security

Shaq Got Hacked. Now He’s Pitching for a VPN

NBA legend Shaquille O'Neal has disclosed that he was targeted in a cyberattack, an experience that prompted him to become a brand ambassador for the security firm NordVPN. O'Neal shared details of the incident at a promotional event in Times Square on Wednesday, emphasizing the importance of digital security for the general public.

breach

US posts $10 million reward for accused Chinese ‘Hafnium’ hacker

The U.S. State Department has announced a reward of up to $10 million for information leading to the arrest or conviction of Zhang Yu, a Chinese national accused of involvement in the Hafnium hacking campaign. Zhang is alleged to be a central figure in a series of cyberattacks that compromised thousands of computers globally and stole sensitive data, including COVID-19 research.