Gone are the days when phishing was a numbers game with modest returns. Traditional phishing campaigns saw a 12% success rate, requiring significant manual effort for each attempt. But artificial intelligence (GenAI, and sometimes other ML/DL tricks) has rewritten these rules entirely. In a controlled study of 101 participants, AI-generated phishing emails matched human experts with a 54% success rate. Even more remarkably, when humans and AI collaborated, the success rate nudged up to 56%. This wasn't just better emails – the AI system demonstrated an uncanny ability to gather accurate target information from the web (OSINT), with an 88% success rate in building accurate profiles from public data. Perhaps the most striking finding is the dramatic reduction in effort required. Traditional targeted attacks required: ➖ 23.5 minutes of research per target ➖ 10.2 minutes crafting each email ➖ Total time: 34 minutes per attempt The AI system collapsed this to just one minute total. Even with human oversight, the process took only 2.7 minutes – a 92% reduction in time invested. This efficiency creates a troubling economic reality. With a typical conversion rate of 2.35% (the percentage of clicked links that lead to successful exploitation), AI automation reduces costs by up to 50 times. The mathematics become profitable at surprisingly low numbers – just 2,859 targets for high-success scenarios. Even with minimal conversion rates of 0.6%, the economics work at scale. The same Gen AI technologies have potential for defence: ➖ Claude 3.5 Sonnet achieved a 97.25% detection rate ➖ Zero false positives in legitimate email detection ➖ Successfully caught sophisticated attacks that fooled human reviewers We're entering an era where AI will dominate both attack and defence, be cheap and plentiful for attackers while defenders with AI skillsets will become gold. Machine speed cybersecurity through cognitive, network and identity layers will become standard. Welcome to the brave new world.
Cybersecurity Exploit Techniques
Explore top LinkedIn content from expert professionals.
-
-
Microsoft warns of new “Payroll Pirate” scam stealing employees’ direct deposits - ArsTechnica Dan Goodin Among other things, the scammers bypass multi-factor authentication. Microsoft is warning of an active scam that diverts employees' paycheck payments to attacker-controlled accounts after first taking over their profiles on Workday or other cloud-based HR services. Payroll Pirate, as Microsoft says the campaign has been dubbed, gains access to victims’ HR portals by sending them phishing emails that trick the recipients into providing their credentials for logging in to the cloud account. The scammers are able to recover multi-factor authentication codes by using adversary-in-the-middle tactics, which work by sitting between the victims and the site they think they’re logging in to, which is, in fact, a fake site operated by the attackers. Not all MFA is created equal The attackers then enter the intercepted credentials, including the MFA code, into the real site. This tactic, which has grown increasingly common in recent years, underscores the importance of adopting FIDO-compliant forms of MFA, which are immune to such attacks. Once inside the employees’ accounts, the scammers make changes to payroll configurations within Workday. The changes cause direct-deposit payments to be diverted from accounts originally chosen by the employee and instead flow to an account controlled by the attackers. #cybersecurity #Workday #Payroll #PayChecks #MFA #FIDO
-
Cyber attacks rarely begin with sophisticated malware. They begin with someone understanding their target better than we expect. Today it is Thailand's healthcare sector. Tomorrow it could be any critical sector, anywhere. Last month our researchers at Seqrite Labs recently identified and analysed an active malware campaign targeting healthcare organisations in Thailand. The attackers used carefully crafted healthcare themed phishing emails, multi stage malware, GitHub hosted payloads and attempted data exfiltration through Telegram. What caught my attention was not just the malware. It was the level of planning behind it. The lures were designed specifically for healthcare procurement teams, hospital administrators, radiology departments and Ministry of Health personnel. That tells us the attackers understood how the sector works before launching the campaign. Modern cyber attacks are becoming far more patient and precise. They are no longer built to infect everyone. They are built to reach the right people. This is why threat intelligence matters. Every campaign we analyse helps us better understand attacker behaviour, improve detection capabilities and share actionable intelligence with the broader cybersecurity community. I want to congratulate Vaibhav Billade and the Seqrite Labs research team for their work on this investigation. It is encouraging to see the research being referenced by respected global cybersecurity communities and threat intelligence platforms. Cybersecurity is a global challenge. Every meaningful piece of research shared responsibly strengthens the collective defence of organisations everywhere. For those interested in the complete technical analysis, the detailed research blog is available in the comments. Seqrite #CyberSecurity #Seqrite #ThreatResearch #HealthcareSecurity #APT #SeqriteLabs #CyberDefense
-
🚨 New Cyber Threat Alert: “Quishing” Attacks Are Weaponizing QR Codes! 🚨 In today’s digital-first world, QR codes have become a part of our daily lives — from restaurant menus to payment gateways and quick access to online forms. But as convenience grows, so does the creativity of cybercriminals. A new wave of phishing attacks, known as “Quishing” (QR code phishing), is now on the rise — and it’s catching both individuals and organizations off guard. 🔍 What is Quishing? Quishing attacks exploit the trust users have in QR codes. Cybercriminals embed malicious links within QR codes, which when scanned, can: Redirect users to fake login pages that mimic Microsoft, Google, or company portals to steal credentials. Trigger automatic downloads of malware or spyware onto the victim’s device. Bypass traditional email security filters, since QR codes can conceal malicious URLs that scanners can’t easily detects. 🎯 Why It’s So Effective You can’t see where a QR code leads until you scan it. Email filters often miss image-based threats like QR codes. Mobile devices, commonly used for scanning, are less protected than workstations. Employees might unknowingly scan a QR code placed in an office, parking lot, or event venue — thinking it’s legitimate. 🛡️ How to Protect Yourself & Your Organization ✅ Be skeptical of unsolicited QR codes, whether online, in emails, or on printed materials. ✅ Use QR scanner apps that preview the URL before opening it. ✅ Educate employees about emerging phishing methods, including QR-based threats. ✅ Verify before you scan — if a QR code is on a poster or email, confirm its legitimacy. ✅ Enable Multi-Factor Authentication (MFA) — it’s your last line of defense even if credentials are compromised. ✅ Keep devices updated with the latest security patches and antivirus protection. 💡 Emerging Trends to Watch Attackers are embedding malicious QR codes in PDFs and business emails, disguised as invoice links or IT login requests. Some campaigns are geo-targeted, adapting fake login pages based on the user’s company or region. There’s an increasing use of AI-generated corporate phishing pages, making them nearly indistinguishable from real ones. 🔐 Takeaway As technology evolves, so do the tactics of attackers. Awareness and vigilance are the first steps in defending against modern cyber threats like Quishing. Organizations must continuously update their security training, test phishing resilience, and educate employees about this new threat vector. Let’s stay ahead — because in cybersecurity, prevention is always better than recovery. 💪 #CyberSecurity #InfoSec #Phishing #Quishing #QRcodeSecurity #CyberAwareness #ThreatIntelligence #DataProtection #MFA #SecurityTraining #ZeroTrust
-
Credential relay phishing has quietly become one of the most effective attack techniques. Attackers don't just steal passwords anymore. They proxy the entire M365 login flow in real time, capture session cookies and tokens, satisfy MFA, and hijack a fully authenticated session. Once they own the session, they own the workspace. Email. SharePoint. OneDrive. Teams. Identity. This is why adding another point solution isn't the answer. The bad guys don't think in silos. They think in identities, sessions, and attack paths. MSPs need a new perspective - understanding the attack before the attacker reaches their objective. The only way to stop modern attacks is to correlate signals across the entire workspace - identities, email, endpoints, browsers, and data—into a single operational context. The modern security architecture is built around agents that continuously correlate signals, investigate autonomously, understand attacker behavior, and orchestrate response in seconds.
-
AI supply chain risk now includes prompt injection through metadata. On Feb 3, Noma Security Labs Lead Threat Researcher Sasi Levi disclosed DockerDash, a vulnerability pattern involving Docker’s Ask Gordon (beta) AI assistant where untrusted Docker image metadata can be interpreted as instructions and, in environments with tool integration, can influence MCP-driven tool invocation. The Exploit * An attacker publishes a Docker image or repo with malicious instructions embedded in “informational” metadata, such as Dockerfile LABEL text. * A developer pulls it and asks the AI assistant a normal question like: “Describe this image” or “What does this container do?” * The AI assistant includes that metadata in the context sent to the LLM. If the LLM parses the injected text as an instruction (the way the attacker intended), it will generate an output that effectively becomes a tool-use plan (for example: “run X, then run Y, then return Z”). * If the system is wired to execute tool calls from the model’s output (via MCP tools, a gateway, or other agent tooling), those model-generated instructions can trigger tool invocation and drive real actions or data access and exfiltration, depending on permissions. Read the full report here: https://lnkd.in/gyAEEmFB The Architectural Lesson If you cannot trust what gets stuffed into the model context window, you cannot trust what an agent will do next. I call this the “cram hole” problem. Docker’s Mitigation (Docker Desktop 4.50.0, upgrade now) To address this specific exposure, Docker Desktop implemented two meaningful guardrails: * Ask Gordon no longer displays images with user-provided URLs. * Ask Gordon prompts for explicit confirmation before running built-in or user-added MCP tools (Human-in-the-Loop). HITL helps, but it doesn’t eliminate risk. Attackers can still pressure users into approving actions. So defense in depth still matters: Treat retrieved metadata as untrusted input, enforce instruction hierarchy, apply least privilege to tools, add monitoring for policy violations, maintain an active inventory of AI assistants, and require approvals for sensitive operations. #AIsecurity #SupplyChainSecurity #Docker #AppSec #PromptInjection #AgenticAI #ZeroTrust
-
Everyone panicked about the wrong thing last summer. When the "16 billion passwords" story broke, the advice was instant: change your passwords, turn on MFA. But that trove was mostly infostealer logs, and the crown jewels inside weren't passwords. They were session cookies. Here's what most people still miss. MFA protects the login. The second you authenticate, the app hands you a session token that says "this person already passed MFA." Steal that token and you walk straight in. No password. No second factor. A full browser cookie dump sells for $15 to $50. Now put an AI agent in the picture. A human session dies when you close the laptop. An agent's session is built to never log out. It holds long-lived tokens across many systems, runs unattended, and acts with authority. Steal a person's session and you get one app for a few hours. Steal an agent's session and you inherit a trusted, tireless foothold that nobody is watching. We spent a decade telling people MFA was the answer. Against session theft, it secures the door and ignores the key. When did your organization last check how long an agent's session stays alive? #Cybersecurity #SessionHijacking #AgenticAI #Infostealers #IdentitySecurity
-
🚨 My New PDF Playbook: Prompt Injection Attacks on LLMs, Threats & Mitigation (Aug 2025) LLMs are the new attack surface. I pulled together a multi-page, practitioner-ready guide for AI researchers, security engineers, product teams, and tech leaders. 📄 What’s inside: 🧨 Real-world attacks (direct/indirect, emoji/Unicode smuggling, link-/markdown exfil, RAG poisoning, agent/MCP abuse) 🧭 Full attacker taxonomy 🛡️ Up-to-date defenses & architectural countermeasures 🗺️ 30/60/90-day rollout plan 🔁 Technique → countermeasure tables 🧩 Visuals: attack chains & layered defenses 📚 References: OWASP, MITRE ATLAS, arXiv, CISA, NIST 👉 Grab the PDF (attached) and share with your AI & security teams. Let’s ship safer AI, together. 💪 #LLMSecurity #PromptInjection #GenAI #AITrustAndSafety #AppSec #RedTeam #BlueTeam #RAG #Agents #MCP #OWASP #MITRE #CISA #NIST #arXiv #AI #CyberSecurity
-
📛 CVE 2025 32711 is a turning point Last week, we saw the first confirmed zero click prompt injection breach against a production AI assistant. No malware. No links to click. No user interaction. Just a cleverly crafted email quietly triggering Microsoft 365 Copilot to leak sensitive org data as part of its intended behavior. Here’s how it worked: • The attacker sent a benign-looking email or calendar invite • Copilot ingested it automatically as background context • Hidden inside was markdown-crafted prompt injection • Copilot responded by appending internal data into an external URL owned by the attacker • All of this happened without the user ever opening the email This is CVE 2025 32711 (EchoLeak). Severity 9.3 Let that sink in. The AI assistant did exactly what it was designed to do. It read context, summarized, assisted. But with no guardrails on trust boundaries, it blended attacker inputs with internal memory. This wasn’t a user mistake. It wasn’t a phishing scam. It was a design flaw in the AI data pipeline itself. 🧠 The Novelty What makes this different from prior prompt injection? 1. Zero click. No action by the user. Sitting in the inbox was enough 2. Silent execution. No visible output or alerts. Invisible to the user and the SOC 3. Trusted context abuse. The assistant couldn’t distinguish between hostile inputs and safe memory 4. No sandboxing. Context ingestion, generation, and network response occurred in the same flow This wasn’t just bad prompt filtering. It was the AI behaving correctly in a poorly defined system. 🔐 Implications For CISOs, architects, and Copilot owners - read this twice. → You must assume all inputs are hostile, including passive ones → Enforce strict context segmentation. Copilot shouldn’t ingest emails, chats, docs in the same pass → Treat prompt handling as a security boundary, not just UX → Monitor agent output channels like you would outbound APIs → Require your vendors to disclose what their AI sees and what triggers it 🧭 Final Thought The next wave of breaches won’t look like malware or phishing. They will look like AI tools doing exactly what they were trained to do but in systems that never imagined a threat could come from within a calendar invite. Patch if you must. But fix your AI architecture before the next CVE hits.
Explore categories
- Hospitality & Tourism
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Healthcare
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Career
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development