# Social engineering

A cybersecurity attack technique that tricks people into revealing information that can be used to attack systems or networks.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## HBO Max's verified Reddit account hijacked to spread malware

DevFeed: [HBO Max's verified Reddit account hijacked to spread malware](<https://devfeed.tech/articles/hbo-max-s-verified-reddit-account-hijacked-to-spread-malware-26612.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/hbo-maxs-verified-reddit-account-hijacked-to-spread-malware>)

Author: Pieter Arntz

Published: 2026-09-15T11:51:03Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>), [Reddit](<https://devfeed.tech/topics/reddit.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [clickfix](<https://devfeed.tech/tags/clickfix.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [hbo-max](<https://devfeed.tech/tags/hbo-max.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [news](<https://devfeed.tech/tags/news.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [pasteswitch](<https://devfeed.tech/tags/pasteswitch.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [reddit](<https://devfeed.tech/tags/reddit.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [terminal](<https://devfeed.tech/tags/terminal.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Cybercriminals hijacked HBO Max's verified Reddit account and used it to run 108 malicious ads over about 48 hours. The ads promoted fake software and used ClickFix-style instructions to distribute infostealers and cryptocurrency clipboard hijackers to macOS and Windows users.

### Source excerpt

Cybercriminals used HBO Max's verified Reddit account to run 108 malicious ads that tricked people into installing information stealers.

## Trezor, BitBox users targeted in newsletter phishing spree

DevFeed: [Trezor, BitBox users targeted in newsletter phishing spree](<https://devfeed.tech/articles/trezor-bitbox-users-targeted-in-newsletter-phishing-spree-8538.md>)

Original publisher: [Read original article](<https://www.theregister.com/cyber-crime/2026/09/10/trezor-bitbox-users-targeted-in-newsletter-phishing-spree/5295496>)

Author: Connor Jones

Published: 2026-09-10T11:30:00Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>)

Tags: [cyber-crime](<https://devfeed.tech/tags/cyber-crime.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Attackers exploit legitimate mailing channels to demand crypto wallet backups from Trezor and BitBox users.

### Source excerpt

Attackers exploit legitimate mailing channels to demand crypto wallet backups

## StreamRat Android malware spreads through Meta and TikTok ads

DevFeed: [StreamRat Android malware spreads through Meta and TikTok ads](<https://devfeed.tech/articles/streamrat-android-malware-spreads-through-meta-and-tiktok-ads-8441.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/streamrat-android-malware-spreads-through-meta-and-tiktok-ads>)

Author: Pieter Arntz

Published: 2026-09-03T16:04:24Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [StreamRAT](<https://devfeed.tech/topics/streamrat.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [ads](<https://devfeed.tech/tags/ads.md>), [advertising](<https://devfeed.tech/tags/advertising.md>), [android](<https://devfeed.tech/tags/android.md>), [browser](<https://devfeed.tech/tags/browser.md>), [malware](<https://devfeed.tech/tags/malware.md>), [meta](<https://devfeed.tech/tags/meta.md>), [news](<https://devfeed.tech/tags/news.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [scam](<https://devfeed.tech/tags/scam.md>), [security](<https://devfeed.tech/tags/security.md>), [social-media](<https://devfeed.tech/tags/social-media.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [streamrat](<https://devfeed.tech/tags/streamrat.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>), [tiktok](<https://devfeed.tech/tags/tiktok.md>)

### AI overview

A malicious ad campaign used fake streaming-service promotions on Meta and TikTok to distribute the StreamRat Android banking Trojan. The campaign directed Android users to a tailored download page that coached them past security warnings and enabled credential theft and remote device control.

### Source excerpt

Social media ads for a free streaming service exposed roughly 570,000 people to StreamRat, a banking Trojan that can take control of infected phones.

## MAST in the Age of Open Source Software |Guardsquare

DevFeed: [MAST in the Age of Open Source Software |Guardsquare](<https://devfeed.tech/articles/mast-in-the-age-of-open-source-software-guardsquare-26310.md>)

Original publisher: [Read original article](<https://www.guardsquare.com/blog/open-source-software-mast>)

Author: Simon Haven - Product Marketing Manager

Published: 2026-09-01T10:59:01Z

Content type: article

Language: en

Sources: [Guardsquare Blog](<https://devfeed.tech/sources/guardsquare-blog.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [Mobile Security](<https://devfeed.tech/topics/mobile-security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [npm](<https://devfeed.tech/topics/npm.md>)

Tags: [app-security-testing](<https://devfeed.tech/tags/app-security-testing.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [appsweep](<https://devfeed.tech/tags/appsweep.md>), [general](<https://devfeed.tech/tags/general.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [mobile-apps](<https://devfeed.tech/tags/mobile-apps.md>), [npm](<https://devfeed.tech/tags/npm.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains why mobile application security testing is important when apps use free and open source software. It describes how vulnerable, deprecated, compromised, and transitive third-party dependencies can expand an app's attack surface, citing a September 2025 npm supply chain attack as an example.

### Source excerpt

Building with free and open source software (FOSS) has become common practice for app developers. In 2022, it was estimated that between 70% and 90% of any given software codebase was made up of open source components. Leveraging open source projects presents many advantages:

## Defending against AI-fueled social engineering

DevFeed: [Defending against AI-fueled social engineering](<https://devfeed.tech/articles/defending-against-ai-fueled-social-engineering-4794.md>)

Original publisher: [Read original article](<https://www.elastic.co/blog/defending-against-ai-fueled-social-engineering>)

Author: Joe DeFever

Published: 2026-09-01T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Blog - Elasticsearch, Kibana, and ELK Stack](<https://devfeed.tech/sources/elastic-blog-elasticsearch-kibana-and-elk-stack.md>)

Topics: [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>)

Tags: [agentic-ai-alerting-security-analytics](<https://devfeed.tech/tags/agentic-ai-alerting-security-analytics.md>), [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>)

### AI overview

The article describes how AI enables personalized spear phishing, smishing, and deepfake-based impersonation at greater scale. It argues that defenders should detect behavioral signals rather than rely solely on static signatures and known patterns.

### Source excerpt

AI is supercharging social engineering. Learn how SOC teams can detect deepfakes, spear phishing, and smishing before they cause real damage.

## Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

DevFeed: [Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](<https://devfeed.tech/articles/spring-ring-an-inside-look-at-voice-phishing-campaigns-in-microsoft-teams-7760.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/>)

Author: Noam Sala

Published: 2026-08-31T10:00:36Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [remote access software](<https://devfeed.tech/topics/remote-access-software.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Cloaked Ursa](<https://devfeed.tech/topics/cloaked-ursa.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [cloaked-ursa](<https://devfeed.tech/tags/cloaked-ursa.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [microsoft-teams](<https://devfeed.tech/tags/microsoft-teams.md>), [payload](<https://devfeed.tech/tags/payload.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [spoof](<https://devfeed.tech/tags/spoof.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>), [vishing](<https://devfeed.tech/tags/vishing.md>), [voice](<https://devfeed.tech/tags/voice.md>)

### AI overview

Spring Ring is a coordinated social engineering campaign that used external Microsoft Teams accounts and voice phishing to impersonate IT help desk staff. The operation targeted more than 150 employees across at least 10 companies and attempted to deliver remote monitoring and management tools or custom malware. A more advanced variant escalated to an NTLM relay attack against an organization's domain controller.

### Source excerpt

Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42.

## AI-driven OSINT in the wrong hands - and why everyone could be a target for fraud

DevFeed: [AI-driven OSINT in the wrong hands - and why everyone could be a target for fraud](<https://devfeed.tech/articles/ai-driven-osint-in-the-wrong-hands-and-why-everyone-could-be-a-target-for-fraud-8392.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/privacy/ai-powered-osint-why-everyone-viable-target-fraud/>)

Author: Phil Muncaster

Published: 2026-08-27T09:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Web](<https://devfeed.tech/topics/web.md>), [Malware](<https://devfeed.tech/topics/malware.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [malware](<https://devfeed.tech/tags/malware.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [research](<https://devfeed.tech/tags/research.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

AI-powered OSINT is making it faster and easier for cybercriminals to gather publicly available information about potential victims. By linking accounts, relationships, images, and videos at machine speed, these tools can make fraud and social engineering more convincing and scalable, lowering the barrier to entry for attackers.

### Source excerpt

It's getting cheaper and easier for cybercriminals to research potential victims. Here's what's still in your control.

## Identity Abuse Through Trusted Communication Channels

DevFeed: [Identity Abuse Through Trusted Communication Channels](<https://devfeed.tech/articles/identity-abuse-through-trusted-communication-channels-7750.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/communication-channel-identity-risks/>)

Author: Bill Batchelor

Published: 2026-08-20T10:00:25Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [identity](<https://devfeed.tech/tags/identity.md>), [identity-theft](<https://devfeed.tech/tags/identity-theft.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [remote-access-software](<https://devfeed.tech/tags/remote-access-software.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>)

### AI overview

Unit 42 examines how attackers abuse trusted enterprise communication and collaboration platforms for identity phishing, impersonation, credential theft, malware delivery and social engineering. The article describes how compromised identities can make malicious activity appear legitimate within authenticated collaboration sessions and offers recommendations for detecting and defending against these attacks.

### Source excerpt

Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.

## How QR-code phishing can slip past corporate security measures

DevFeed: [How QR-code phishing can slip past corporate security measures](<https://devfeed.tech/articles/how-qr-code-phishing-can-slip-past-corporate-security-measures-8339.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/qr-code-phishing-slip-past-corporate-security-measures/>)

Author: Phil Muncaster

Published: 2026-08-17T09:00:00Z

Content type: article

Language: eng

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [QR Code](<https://devfeed.tech/topics/qrcode.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>)

Tags: [business-security](<https://devfeed.tech/tags/business-security.md>), [corporate](<https://devfeed.tech/tags/corporate.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article explains how QR-code phishing ("quishing") can evade corporate defenses by hiding malicious URLs and directing employees to less-protected mobile devices.

### Source excerpt

Quishing has become a popular alternative to traditional phishing. Here's how businesses can close the gap.

## Before the first prompt: Code execution paths in trusted coding-agent projects

DevFeed: [Before the first prompt: Code execution paths in trusted coding-agent projects](<https://devfeed.tech/articles/before-the-first-prompt-code-execution-paths-in-trusted-coding-agent-projects-8281.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/coding-agent-project-trust-code-execution-before-first-prompt/>)

Author: Nick Frichette

Published: 2026-08-03T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Claude Code](<https://devfeed.tech/topics/claude-code.md>), [codex](<https://devfeed.tech/topics/codex.md>), [Model Context Protocol (MCP)](<https://devfeed.tech/topics/model-context-protocol-mcp.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Visual Studio Code](<https://devfeed.tech/topics/visual-studio-code.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [claude-code](<https://devfeed.tech/tags/claude-code.md>), [code](<https://devfeed.tech/tags/code.md>), [codex](<https://devfeed.tech/tags/codex.md>), [debugging](<https://devfeed.tech/tags/debugging.md>), [developers](<https://devfeed.tech/tags/developers.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>)

### AI overview

This security article examines how trusted coding-agent projects can execute repository-controlled code before a user sends the first prompt. It describes execution paths involving project-scoped MCP configuration in Codex and project-controlled environment settings and Git probes in Claude Code, without requiring a model response or shell-command approval.

### Source excerpt

Learn how trusted coding-agent projects can execute repository-controlled code before the first prompt through Codex MCP configuration and Claude Code environment settings.

## ESET Threat Report H1 2026

DevFeed: [ESET Threat Report H1 2026](<https://devfeed.tech/articles/eset-threat-report-h1-2026-8365.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/>)

Author: Jiří Kropáč

Published: 2026-07-08T08:45:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Generative AI](<https://devfeed.tech/topics/generative-ai.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Android](<https://devfeed.tech/topics/android.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>), [QR Code](<https://devfeed.tech/topics/qrcode.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [android](<https://devfeed.tech/tags/android.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [code](<https://devfeed.tech/tags/code.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [malware](<https://devfeed.tech/tags/malware.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [threat-report](<https://devfeed.tech/tags/threat-report.md>)

### AI overview

ESET's H1 2026 threat report describes attackers adapting established techniques across new platforms and behaviors. It highlights the expanding abuse of AI skills, PromptSpy Android malware using Google Gemini, the spread of ClickFix and QR-code phishing, and continued ransomware activity involving EDR killers.

### Source excerpt

A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.

## Inside the inbox: Why cybercriminals want to break into your email account

DevFeed: [Inside the inbox: Why cybercriminals want to break into your email account](<https://devfeed.tech/articles/inside-the-inbox-why-cybercriminals-want-to-break-into-your-email-account-8354.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/cybersecurity/inside-inbox-cybercriminals-want-break-email-account/>)

Author: Phil Muncaster

Published: 2026-06-29T08:50:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [Security](<https://devfeed.tech/topics/security.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [data](<https://devfeed.tech/topics/data.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [data](<https://devfeed.tech/tags/data.md>), [digital-security](<https://devfeed.tech/tags/digital-security.md>), [identity](<https://devfeed.tech/tags/identity.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article explains why email inboxes are high-value targets for cybercriminals. Access can enable password resets, interception of one-time passcodes, persistent forwarding rules, misuse of connected sessions and apps, phishing, identity fraud, blackmail, and access to corporate systems and customer data.

### Source excerpt

Your inbox is an identity system all of its own: whoever owns it may own a lot more

## BTMOB: A stealthy RAT burrowing deep into Android devices

DevFeed: [BTMOB: A stealthy RAT burrowing deep into Android devices](<https://devfeed.tech/articles/btmob-a-stealthy-rat-burrowing-deep-into-android-devices-8390.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/>)

Author: Daniel Cunha Barbosa

Published: 2026-05-26T08:50:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [Android](<https://devfeed.tech/topics/android.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [APK](<https://devfeed.tech/topics/apk.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [Accessibility](<https://devfeed.tech/topics/accessibility.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [code](<https://devfeed.tech/tags/code.md>), [malware](<https://devfeed.tech/tags/malware.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [tool](<https://devfeed.tech/tags/tool.md>)

### AI overview

BTMOB is an Android remote access trojan that spreads through phishing websites, fake app stores, and malicious APKs. It can exfiltrate sensitive data, capture screenshots, record device activity, and enable remote control. Its APK builder and malware-as-a-service model make customized campaigns easier to launch.

### Source excerpt

The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise

## What's New in Android Security and Privacy in 2026

DevFeed: [What's New in Android Security and Privacy in 2026](<https://devfeed.tech/articles/what-s-new-in-android-security-and-privacy-in-2026-7635.md>)

Original publisher: [Read original article](<https://blog.google/security/whats-new-in-android-security-privacy-2026/>)

Author: Eugene Liderman

Published: 2026-05-12T17:00:00Z

Content type: article

Language: en

Sources: [Security](<https://devfeed.tech/sources/security.md>)

Topics: [Android](<https://devfeed.tech/topics/android.md>), [Android Security](<https://devfeed.tech/topics/android-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [On-device AI](<https://devfeed.tech/topics/on-device-ai.md>), [Chrome](<https://devfeed.tech/topics/chrome.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [android](<https://devfeed.tech/tags/android.md>), [android-security](<https://devfeed.tech/tags/android-security.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [none](<https://devfeed.tech/tags/none.md>), [on-device-ai](<https://devfeed.tech/tags/on-device-ai.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

The article describes planned Android security and privacy enhancements for 2026, including verified financial calls to combat spoofed banking scams. Android can verify incoming calls through participating financial apps and automatically end calls that are not genuine. It also highlights expanded Live Threat Detection, which uses on-device AI to analyze app behavior and warn about suspicious activity.

### Source excerpt

New Android security and privacy features

## New NGate variant hides in a trojanized NFC payment app

DevFeed: [New NGate variant hides in a trojanized NFC payment app](<https://devfeed.tech/articles/new-ngate-variant-hides-in-a-trojanized-nfc-payment-app-8377.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/new-ngate-variant-hides-in-a-trojanized-nfc-payment-app/>)

Author: Lukas Stefanko

Published: 2026-04-21T08:55:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Android](<https://devfeed.tech/topics/android.md>), [ESET research](<https://devfeed.tech/topics/eset-research.md>), [genai](<https://devfeed.tech/topics/genai.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [App](<https://devfeed.tech/topics/app.md>), [servers](<https://devfeed.tech/topics/servers.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [brazil](<https://devfeed.tech/tags/brazil.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [genai](<https://devfeed.tech/tags/genai.md>), [malware](<https://devfeed.tech/tags/malware.md>), [payment](<https://devfeed.tech/tags/payment.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [threat-report](<https://devfeed.tech/tags/threat-report.md>)

### AI overview

ESET Research reports a new NGate malware variant hidden in a trojanized Android NFC payment app called HandyPay. The malware relays payment-card NFC data, steals card PINs, and exfiltrates them to an operator-controlled server. The active campaign, targeting users in Brazil since around November 2025, distributes the app through fake lottery and Google Play websites; the code may have been assisted by GenAI.

### Source excerpt

ESET researchers discover another iteration of NGate malware, this time possibly developed with the assistance of AI

## That data breach alert might be a trap

DevFeed: [That data breach alert might be a trap](<https://devfeed.tech/articles/that-data-breach-alert-might-be-a-trap-8403.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/scams/data-breach-alert-might-be-trap/>)

Author: Phil Muncaster

Published: 2026-04-17T09:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-tools](<https://devfeed.tech/tags/ai-tools.md>), [breach](<https://devfeed.tech/tags/breach.md>), [data](<https://devfeed.tech/tags/data.md>), [incident](<https://devfeed.tech/tags/incident.md>), [malware](<https://devfeed.tech/tags/malware.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [scam](<https://devfeed.tech/tags/scam.md>), [scams](<https://devfeed.tech/tags/scams.md>)

### AI overview

Fake data breach notifications exploit recipients' expectations after real or fabricated incidents. The article explains how scammers use phishing kits, AI tools, copied branding, and realistic language to create convincing lures that may lead to malware infections or theft of personal, financial, and password information.

### Source excerpt

Ignoring a real breach notification invites risk, but falling for a bogus one could be even worse. Stop reacting on autopilot.

## PCI DSS Compliance: What Digital Businesses Need to Know

DevFeed: [PCI DSS Compliance: What Digital Businesses Need to Know](<https://devfeed.tech/articles/pci-dss-compliance-what-digital-businesses-need-to-know-10274.md>)

Original publisher: [Read original article](<https://dodopayments.com/blogs/pci-dss-compliance-digital-business/>)

Author: Ayush Agarwal

Published: 2026-04-15T00:00:00Z

Content type: tutorial

Language: en

Sources: [Dodo Payments Blog](<https://devfeed.tech/sources/dodo-payments-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Network Segmentation](<https://devfeed.tech/topics/network-segmentation.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [tokenization](<https://devfeed.tech/topics/tokenization.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [digital-products](<https://devfeed.tech/tags/digital-products.md>), [firewalls](<https://devfeed.tech/tags/firewalls.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [network-segmentation](<https://devfeed.tech/tags/network-segmentation.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [saas](<https://devfeed.tech/tags/saas.md>), [scope](<https://devfeed.tech/tags/scope.md>), [security](<https://devfeed.tech/tags/security.md>), [siem](<https://devfeed.tech/tags/siem.md>), [tls](<https://devfeed.tech/tags/tls.md>), [tokenization](<https://devfeed.tech/tags/tokenization.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This guide explains how PCI DSS applies to digital businesses that accept card payments, including SaaS companies and sellers of digital products. It outlines the standard's 12 requirements and discusses controls for networks, account data, vulnerabilities, access, monitoring, and information security. It also covers card-not-present transactions, recurring billing, and tokenization.

### Source excerpt

PCI DSS compliance explained for digital businesses. Understand the 12 requirements, compliance levels, and how to reduce your scope when selling digital products online.

## As breakout time accelerates, prevention-first cybersecurity takes center stage

DevFeed: [As breakout time accelerates, prevention-first cybersecurity takes center stage](<https://devfeed.tech/articles/as-breakout-time-accelerates-prevention-first-cybersecurity-takes-center-stage-8326.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/breakout-time-accelerates-prevention-first-cybersecurity-center-stage/>)

Author: Phil Muncaster

Published: 2026-04-07T09:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-automation](<https://devfeed.tech/tags/ai-automation.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [automation](<https://devfeed.tech/tags/automation.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [tools](<https://devfeed.tech/tags/tools.md>)

### AI overview

Threat actors are using AI, automation, credential theft, phishing, zero-day exploits, reconnaissance, and AI-powered scripts to accelerate attacks. The article argues that shrinking breakout times require defenders to adopt a prevention-first cybersecurity strategy.

### Source excerpt

Threat actors are using AI to supercharge tried-and-tested TTPs. When attacks move this fast, cyber-defenders need to rethink their own strategy.

## A cunning predator: How Silver Fox preys on Japanese firms this tax season

DevFeed: [A cunning predator: How Silver Fox preys on Japanese firms this tax season](<https://devfeed.tech/articles/a-cunning-predator-how-silver-fox-preys-on-japanese-firms-this-tax-season-8328.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/cunning-predator-how-silver-fox-preys-japanese-firms-tax-season/>)

Author: Dominik Breitenbacher Takahiro Sajima

Published: 2026-03-27T07:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [business](<https://devfeed.tech/tags/business.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [finance](<https://devfeed.tech/tags/finance.md>), [government](<https://devfeed.tech/tags/government.md>), [japan](<https://devfeed.tech/tags/japan.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

Silver Fox is conducting a targeted spearphishing campaign against Japanese manufacturers and other businesses during tax-filing and organizational-change season. The attackers use convincing tax- and HR-themed emails, links, and attachments to exploit expected business communications and increase the likelihood of compromise.

### Source excerpt

Silver Fox is back in Japan, spoofing tax and HR emails timed to the one season when no one thinks twice about opening them

## How a Malicious Google Skill on ClawHub Tricks Users Into Installing Malware

DevFeed: [How a Malicious Google Skill on ClawHub Tricks Users Into Installing Malware](<https://devfeed.tech/articles/how-a-malicious-google-skill-on-clawhub-tricks-users-into-installing-malware-7863.md>)

Original publisher: [Read original article](<https://snyk.io/blog/clawhub-malicious-google-skill-openclaw-malware/>)

Author: Liran Tal

Published: 2026-02-10T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Agent Skills](<https://devfeed.tech/topics/agent-skills.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Google](<https://devfeed.tech/topics/google.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [agent-skills](<https://devfeed.tech/tags/agent-skills.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [interest](<https://devfeed.tech/tags/interest.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [security](<https://devfeed.tech/tags/security.md>), [security-labs](<https://devfeed.tech/tags/security-labs.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-security-intel](<https://devfeed.tech/tags/snyk-security-intel.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Snyk researchers describe an active supply chain attack targeting OpenClaw users through a malicious Google integration skill distributed on ClawHub. The skill uses instructions in SKILL.md to fabricate a prerequisite, persuade users to run an installer, and deploy malware across Windows and macOS/Linux systems.

### Source excerpt

Breaking: Snyk researchers uncover a malicious "Google" skill on ClawHub that tricks users into installing malware via a fake OpenClaw dependency. Learn how the attack works and how to protect your AI agents.

## Silver lining playbook: Likely China-origin activity targeting US persons

DevFeed: [Silver lining playbook: Likely China-origin activity targeting US persons](<https://devfeed.tech/articles/silver-lining-playbook-likely-china-origin-activity-targeting-us-persons-41324.md>)

Original publisher: [Read original article](<https://openai.com/index/disrupting-malicious-uses-of-ai-silver-lining-playbook>)

Published: 2026-02-01T00:00:00Z

Content type: article

Language: en

Sources: [OpenAI News](<https://devfeed.tech/sources/openai-news.md>)

Topics: [OpenAI](<https://devfeed.tech/topics/openai.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [email](<https://devfeed.tech/topics/email.md>), [information retrieval](<https://devfeed.tech/topics/information-retrieval.md>)

Tags: [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [china](<https://devfeed.tech/tags/china.md>), [email](<https://devfeed.tech/tags/email.md>), [information-retrieval](<https://devfeed.tech/tags/information-retrieval.md>), [openai](<https://devfeed.tech/tags/openai.md>), [report](<https://devfeed.tech/tags/report.md>), [research](<https://devfeed.tech/tags/research.md>), [safety](<https://devfeed.tech/tags/safety.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [us](<https://devfeed.tech/tags/us.md>)

### AI overview

OpenAI describes banning a small set of likely China-origin ChatGPT accounts that used its models to research US persons and federal locations, draft social-engineering emails, and request guidance related to face-manipulation software. The activity was named "Silver Lining Playbook."

### Source excerpt

OpenAI banned likely China-origin accounts using AI to research US persons, locations, and social-engineering tactics.

## The big catch: How whaling attacks target top executives

DevFeed: [The big catch: How whaling attacks target top executives](<https://devfeed.tech/articles/the-big-catch-how-whaling-attacks-target-top-executives-8321.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/big-catch-how-whaling-attacks-target-top-executives/>)

Author: Phil Muncaster

Published: 2025-12-09T10:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Vishing](<https://devfeed.tech/topics/vishing.md>), [MFA](<https://devfeed.tech/topics/mfa.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [business](<https://devfeed.tech/tags/business.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [corporate](<https://devfeed.tech/tags/corporate.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [vishing](<https://devfeed.tech/tags/vishing.md>)

### AI overview

This article explains whaling attacks, a form of targeted phishing, vishing, smishing, or business email compromise aimed at senior corporate executives. It describes how attackers exploit executives' limited time, public visibility, and access to sensitive information and financial authority, including through malware-laced Zoom invitations and detailed reconnaissance.

### Source excerpt

Is your organization's senior leadership vulnerable to a cyber-harpooning? Learn how to keep them safe.

## Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture

DevFeed: [Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture](<https://devfeed.tech/articles/phishing-privileges-and-passwords-why-identity-is-critical-to-improving-cybersecurity-posture-8337.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/phishing-privileges-passwords-identity-cybersecurity-posture/>)

Author: Phil Muncaster

Published: 2025-12-04T10:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Vishing](<https://devfeed.tech/topics/vishing.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [breach](<https://devfeed.tech/tags/breach.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [identity](<https://devfeed.tech/tags/identity.md>), [password-spraying](<https://devfeed.tech/tags/password-spraying.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article explains why identity has become the new network perimeter and why protecting credentials is central to cybersecurity. It examines ransomware incidents involving M&S and Co-op Group, credential theft through vishing, phishing, infostealer malware, password database breaches, brute-force attacks, credential stuffing, and password spraying.

### Source excerpt

Identity is effectively the new network boundary. It must be protected at all costs.

## Android expands pilot for in-call scam protection for financial apps

DevFeed: [Android expands pilot for in-call scam protection for financial apps](<https://devfeed.tech/articles/android-expands-pilot-for-in-call-scam-protection-for-financial-apps-19807.md>)

Original publisher: [Read original article](<http://security.googleblog.com/2025/12/android-expands-pilot-in-call-scam-protection-financial-apps.html>)

Author: Edward Fernandez (noreply@blogger.com)

Published: 2025-12-03T16:59:00Z

Content type: release

Language: en

Sources: [Google Online Security](<https://devfeed.tech/sources/google-online-security.md>)

Topics: [Android](<https://devfeed.tech/topics/android.md>), [Security](<https://devfeed.tech/topics/security.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Mobile](<https://devfeed.tech/topics/mobile.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [android-security](<https://devfeed.tech/tags/android-security.md>), [google](<https://devfeed.tech/tags/google.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [none](<https://devfeed.tech/tags/none.md>), [safety](<https://devfeed.tech/tags/safety.md>), [scams](<https://devfeed.tech/tags/scams.md>), [screen-sharing](<https://devfeed.tech/tags/screen-sharing.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>)

### AI overview

Google is expanding Android's pilot for in-call scam protection to the United States with selected fintechs and banks, following pilots in the UK, Brazil, and India. The feature warns users when they open participating financial apps while screen sharing during a call from an unknown number, and provides a one-tap option to end the call and stop screen sharing.

### Source excerpt

Posted by Aden Haussmann, Associate Product Manager and Sumeet Sharma, Play Partnerships Trust & Safety Lead Android uses the best of Google AI and our advanced security expertise to tackle mobile scams from every angle. Over the last few years, we've launched industry-leading features to detect scams and protect users across phone calls, text messages and messaging app chat notifications. These efforts are making a real difference in the lives of Android users. According to a recent YouGov survey1 commissioned by Google, Android users were 58% more likely than iOS users to report they had not received any scam texts in the prior week2. But our work doesn't stop there. Scammers are continuously evolving, using more sophisticated social engineering tactics to trick users into sharing their phone screen while on the phone to visit malicious websites, reveal sensitive information, send funds or download harmful apps. One popular scam involves criminals impersonating banks or other trusted institutions on the phone to try to manipulate victims into sharing their screen in order to reveal banking information or make a financial transfer. To help combat these types of financial scams, we launched a pilot earlier this year in the UK focused on in-call protections for financial apps. How the in-call scam protection works on Android When you launch a participating financial app while screen sharing and on a phone call with a number that is not saved in your contacts, your Android device3 will automatically warn you about the potential dangers and give you the option to end the call and to stop screen sharing with just one tap. The warning includes a 30-second pause period before you're able to continue, which helps break the 'spell' of the scammer's social engineering, disrupting the false sense of urgency and panic commonly used to manipulate you into a scam. Bringing in-call scam protections to more users on Android The UK pilot of Android's in-call scam protections has al

[Next page](<https://devfeed.tech/topics/social-engineering.md?cursor=WyIyMDI1LTEyLTAzVDE2OjU5OjAwKzAwOjAwIiwgIjdmOGE4ZDVmLWFiZWEtNGIzNS1iZTU2LTczNjQ1NWIwNjQyOCJd>)