Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Voice Phishing Attacks Target Hedge Fund Employees

Google’s Threat Intelligence Group (GTIG) is tracking a voice phishing (vishing) campaign that’s targeting hedge funds and financial firms. The researchers attribute the attacks to “UNC6671,” an extortion group formerly known as “BlackFile.” The attackers pose as IT staff informing employees of urgent, mandatory migrations.

Warning: Malicious AI Tools Are Spreading in the Criminal Underground

Criminals are now selling malicious AI tools for use in cyberattacks, according to researchers at Trellix. These tools dramatically lower the barrier for unskilled crooks to launch sophisticated attacks. “In the first half of 2026, the Trellix research team identified multiple distinct AI-related offerings across major underground forums,” the researchers write.

Attackers Use Vishing Attacks to Distribute New Android Malware

Attackers are distributing a new Android malware called “WindRelay” via phone-based social engineering attacks, according to researchers at Group-IB. The attackers call the victims, impersonating bank employees and instruct them to install a malicious app. In one instance observed by Group-IB, the scammers carried out the entire attack in just thirteen minutes.

Report: AI Chatbots Are More Effective at Building Trust Than Human Scammers

A study has found that AI chatbots can be more effective at social engineering than human scammers, WIRED reports. The researchers looked at a form of romance scam commonly known as “pig butchering,” in which scammers spend weeks or months building a relationship with the victim before tricking them into sending money for a phony investment scheme.

Human Error Remains at the Core of AI-Enabled Social Engineering

AI is making social engineering attacks significantly more effective, according to a new report from cyber insurance firm Resilience. These attacks were behind more than 85% of losses in the first half of 2026, compared to less than 20% during H1 2024. “Losses tied to phishing, social engineering, and transfer fraud have climbed from 17.7% of incurred losses in H1 2024 to 85.3% in H1 2026, the single largest increase in the report’s five half-year comparison,” Resilience says.

Securing the Tip of the Spear: Guam's Path to Human and AI Resilience

As the Asia-Pacific and Japan (APJ) region continues its rapid digital acceleration, Guam stands at a unique strategic intersection. Serving as a critical hub for telecommunications, government services and regional defense, the island’s cybersecurity posture is no longer just a local concern, it is a cornerstone of regional stability. I have observed a proactive shift toward onboarding various agencies to a unified security framework.

Report: Vishing and Device Code Phishing Are Surging

Social engineering remains a central part of modern cyberattacks, according to a new report from CrowdStrike. Attackers are increasingly turning to voice phishing because it bypasses traditional security controls and leaves little forensic evidence, since the social engineering takes place over the phone.

Report: Americans Lose an Estimated $148 Billion to Scams Each Year

Americans are now losing an estimated $148 billion each year to online scams, a 22% increase compared to 2024, according to a new report from the Consumer Federation of America (CFA). The FBI’s Internet Crime Complaint Center (IC3) tracked $20.8 billion in losses last year, but the CFA notes that the actual losses are much higher.

The Rise of the 'Non-Human Insider': When AI Agents Become the Threat

For years, cybersecurity has had a familiar villain: the external attacker. The hacker breaking through the firewall, stealing credentials or exploiting an unpatched vulnerability. It is the scenario we have trained for, built defenses around and spent decades trying to prevent. But the next major breach may not begin with someone breaking into your environment at all, it may begin with an AI agent that already has access.