Welcome to the 130th edition of HX Weekly. If you feel like phishing attempts are becoming impossible to avoid, you are right—the “phish” is truly everywhere, from fake eCards and cloned ticket websites to sophisticated credential-spoofing campaigns.
As our recent warnings anticipated, the threat landscape has reached a new level of volatility. We are currently navigating a “Patchapalooza” of critical vulnerabilities and emerging Ai-driven risks that demand a shift in how we approach our digital hygiene.
The Week in Threats: Why Vigilance is Non-Negotiable
This week highlighted just how diverse and persistent these attacks have become:
- Phishing Evolution: Attackers are now abusing simple eCards to deploy Remote Monitoring and Management (RMM) tools. We also saw fake Céline Dion tickets being sold on convincing Facebook and Ticketmaster clones.
- Credential Attacks: A new OAuth client ID spoofing technique is allowing attackers to validate stolen Microsoft Entra credentials, while LastPass and Bitwarden users are being targeted with fake security alerts.
- Ai-Driven Deception: A new technique called “Ghostcommit” hides prompt injection attacks within images, designed to fool Ai agents and steal sensitive secrets.
- MacOS Risks: A new modular macOS stealer has been spotted using “kill loops” to force users into entering their passwords.
The Bigger Picture
Beyond individual scams, the structural security of our digital world is being tested:
- Infrastructure Stress: Security teams are scrambling to address a flood of vulnerabilities across major platforms like Windows, SharePoint, Fortinet, and Cisco.
- State-Sponsored Activity: Global alliances are currently responding to state-sponsored Russian cyber activity targeting critical military and utility networks.
- Data Accountability: We are seeing the consequences of past failures, such as 23andMe’s $18 million settlement following their massive breach. Conversely, there is a push for privacy, with over 322,000 Californians signing up to have data brokers delete their personal information.
What Now? The Zero Trust Mindset
In an environment where threats are rampant and Ai is being weaponized, “just being careful” isn’t enough.
- Adopt Zero Trust: Always practice zero trust—verify every request, assume every device or identity is a potential risk, and never trust a link or prompt just because it arrives in a familiar format.
- Stay Apprised: The warnings we issued regarding Ai-driven risks and infrastructure patches have already materialized in this week’s headlines. Make our TWA (Tips, Warnings, Alerts) section a mandatory part of your weekly routine.
Inside Hexagon: Help Us Spread the Message
We are doubling down on our commitment to public education. We are currently expanding our HexagonPSA campaign to reach even more social media platforms.
You can now find our educational videos dropping every 5 hours on your favorite social channels, with entirely new content continuing to release every 7 hours on our YouTube channel. We want these messages to be fun, engaging, and highly shareable—if you have suggestions on how we can improve, please let us know.
Stay vigilant, stay protected, and join us in making the internet a safer place. Subscribe at hexagoncenter.org.
— The Hexagon Center Team
