Researchers say the highly effective social engineering technique is no longer the exception for malware attacks — it's now the rule.

A sophisticated social engineering tactic, previously considered an outlier, has become a prevalent method for delivering malware, according to security researchers. This technique, which leverages user interaction to facilitate malicious payloads, is now frequently employed in cyberattacks.
The effectiveness of this approach stems from its ability to bypass traditional security measures by tricking users into inadvertently executing malware. Instead of relying solely on technical exploits, attackers now prioritize manipulating human behavior.
This shift signifies a growing trend where the human element is increasingly targeted as the weakest link in security defenses. Attackers are investing more effort into crafting convincing lures that exploit user trust or curiosity.
While the specifics of the technique are not detailed, its widespread adoption suggests attackers have found it to be a reliable and scalable method for infecting systems. This implies a high success rate in tricking individuals into performing actions that lead to malware infection.
The implications for cybersecurity are significant, as it necessitates a stronger focus on user education and awareness alongside technical security solutions. Organizations and individuals alike must be vigilant against deceptive communications and requests.
This trend underscores the evolving landscape of cyber threats, where social engineering is no longer a fringe tactic but a core component of many malware delivery strategies. The success of such methods highlights the ongoing need for robust security awareness training programs.
As attackers refine their social engineering tactics, the defense must adapt by strengthening both technological defenses and human vigilance. The reliance on user interaction for malware delivery means that user awareness is a critical line of defense.
The widespread use of this technique suggests a need for continuous adaptation of security strategies to counter evolving attacker methodologies. This includes not only technical patching but also ongoing efforts to educate users about the risks of social engineering.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.