ZeroHour

Search: “brand monitoring”

40 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Cyble Introduces Major Upgrade to its Executive Monitoring Module

Cyble upgraded Executive Monitoring in Cyble Vision, unifying impersonation, exposure, and mention findings with AI scoring and multi-channel alerting.

Cyble released a major upgrade to Executive Monitoring within its Cyble Vision platform, consolidating Mentions, Impersonations, Exposures, and a new Surface Mentions source (blog and news coverage) into a single findings stream. The release adds AI-generated verdicts and recommendations, per-executive Risk and Reputation scoring for board reporting, and richer onboarding with aliases, reference images, and addresses to cut same-name false positives. Alerting now supports data residency, bulk import, delivery via email, WhatsApp, and SMS, an Access API, and branded executive PDF reports; the upgrade is live with no customer action required.

Cyble · 6d agoTools

Recorded Future Launches Impact and Metrics Dashboard

Recorded Future releases an Impact and Metrics Dashboard aggregating risk-reduction, detection, and analyst-efficiency metrics for customer leadership reporting.

The dashboard pulls data from a customer's environment, alerts, integrations, threat detections, and analyst activity into six metric areas: platform-wide security value, threat prioritization, threat detection, digital risk protection, account and credential monitoring, and Recorded Future AI and Insikt Group research usage. It is available now to all Recorded Future customers, who are advised to configure Priority Intelligence Requirements in Settings so reporting maps to their intelligence program. The vendor cites its 2025 ROI Report across nearly 300 customers reporting 351.3% annual ROI and says customers aligning alerting to PIRs identified new threats 65% faster.

Recorded Future · 23d agoTools

Bitsight connects threat intelligence and exposure monitoring across the supply chain

Bitsight made Beacon generally available, combining supply-chain exposure monitoring with MCP support to feed threat intelligence into AI workflows.

Bitsight announced general availability of Beacon, which continuously monitors critical vendors for exposure, vulnerabilities, malicious activity, intrusion, stolen credentials and compromise. New Model Context Protocol (MCP) and agentic capabilities push Bitsight intelligence into AI-enabled workflows, with over 400 customers signing up for early access in one month. The company cites data that third parties now account for almost half of enterprise breaches, up over 60% year over year.

Help Net Security · 2d agoTools

Recorded Future Launches Digital Risk Protection, Unifying Brand and Identity Monitoring

Recorded Future launched Digital Risk Protection, unifying brand and identity monitoring across five external threat surfaces in one workflow.

Recorded Future announced Digital Risk Protection, combining brand threat monitoring and identity exposure monitoring across five use cases: malicious site, impersonation, code repository, dark web brand, and identity exposure monitoring. The platform includes an AI Triage Agent that automates alert evaluation with explicit verdicts and context, expanding social media analysis, OCR, full Telegram coverage, and infostealer log ingestion. Gartner's 2026 Magic Quadrant folded digital risk protection into cyber threat intelligence technologies, and the launch cites $15.9 billion in 2025 US fraud/scam losses, up 28% year over year.

Recorded Future · 7d agoTools

Smishing Triad Hackers Use JWR Phishing Kit to Steal Cards, OTPs and Bank Credentials

Group-IB attributes large-scale smishing using the JWR real-time phishing kit to the Smishing Triad's Outsider cluster, harvesting card data, OTPs, and bank credentials.

Group-IB attributes a large-scale SMS phishing campaign to Outsider, an operator sub-cluster within the Smishing Triad phishing-as-a-service ecosystem, using a kit dubbed JWR. The Vue 2-based platform maintains real-time WebSocket communication with operators, enabling them to adapt pages live and harvest roughly 70 PII fields, card data, PINs, OTPs, identity document images, and digital wallet credentials via a dedicated PayPal sub-funnel. Unit 42 previously tied 194,345 malicious domains across 136,933 root domains to the broader operation since January 2024. Defenders can hunt for /api/open/ endpoints, /webSocket/QT/ paths, JWR-prefixed storage artifacts, and a hard-coded WebSocket token.

GBHackersupdated · 8h agofirst · 10h agoPhishing & fraud in the wild 2 sources

Generative Marketing Mix Modeling: A Causal Inference Framework Linking GEO and GEM to Business Impact

Paper proposes Generative Marketing Mix Modeling to causally estimate Generative Engine Optimization and Marketing effects on business outcomes.

The authors develop GMMM, a causal inference framework for measuring how often users see and notice a firm's name in generated answers, which standard marketing data ignore. For GEO it combines repeated generated answers with question counts, shares of generative-system usage and notice probabilities; for GEM it uses sponsored placement records with notice probabilities. The framework compares expected business responses under alternative treatment sequences, establishes identification conditions, and is evaluated on simulated product-recommendation answers in English and Japanese.

arXiv cs.AI / cs.LG / cs.CL · 6d agoAI research

The 12 Best Antivirus Software for Mac, Compared and Priced

GBHackers ranks 12 Mac antivirus products, naming Bitdefender best overall and noting Gen Digital owns Norton, Avast, and Avira.

GBHackers scored twelve Mac antivirus products, ranking Bitdefender first at 8.8/10, followed by Intego, Malwarebytes, and ESET. The piece highlights that Gen Digital owns Norton, Avast, and Avira following the NortonLifeLock-Avast merger, so three of the twelve options share one corporate owner. It advises comparing year-two renewal prices rather than discounted first-year pricing and notes macOS already ships XProtect, Gatekeeper, and automatic malware removal. The 2026 Mac threat model described is infostealers harvesting passwords, cookies, and wallets via cracked software, fake installers, and malicious search ads.

GBHackers · 7d agoIndustry 2 sources

Brand Impersonation Takedown: From Whack-a-Mole to Managed Response

Mandiant-tracked group UNC3753 impersonated US professional services firms' brands in 2026; Cyble urges managed takedowns over manual abuse reports.

Cyble describes how Google Mandiant-tracked group UNC3753 targeted US professional services firms between January and May 2026 using brand impersonation, spoofed domains, and fake executive profiles. Manual takedowns fail because phishing pages damage brands within hours while removal takes days. A managed takedown program with continuous monitoring and pre-authorized removal cuts the exposure window from days to hours.

Cyble · Aug 17, 2026Phishing & fraud in the wild

HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures

A custom HVNC backdoor is targeting Latin American financial organizations via fake DocuSign and NFe tax-document lures, giving attackers hidden persistent remote access.

ANY.RUN researchers analyzed a multi-stage phishing campaign delivering a custom HVNC backdoor to banking and financial organizations in Latin America. The chain starts with fake DocuSign and NFe tax-document pages that serve per-visitor ZIP archives, followed by an LNK dropper, an NSIS loader, and a 64-bit backdoor masquerading as Windows Update Assistant. The implant provides hidden remote desktop control, keystroke monitoring, Firefox data theft, Startup-folder persistence, and EDR-aware behavior, communicating over TCP/27015.

ANY.RUN · 8d agoMalware in the wild

Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates

ANY.RUN August release adds TI Lookup connections view, 81 behavior signatures, 16 YARA rules, 559 Suricata rules, and three new threat intelligence reports.

ANY.RUN released August product updates expanding its Threat Intelligence Lookup with a Connections block for pivoting between related observables (domains, IPs, URLs), JSON export for retrohunting and SIEM/NDR integration, and hidden whitelisted data by default. Detection coverage grew with 81 new behavior signatures, 16 YARA rules, and 559 Suricata rules covering malware execution, phishing, and C2 traffic. Three new Threat Intelligence Reports cover a US-focused RMM phishing campaign across 46 countries, the Mirage2FA phishing-as-a-service targeting Microsoft 365 (1,249 sandbox sessions, 9,332 potential compromise events), and a threat brief on OVERLORD RAT, CRPX0, and TRIBACK loader.

ANY.RUN · 13d agoTools1

Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach

Heights Finance breach of a third-party cloud platform exposed SSNs and banking data of 734,828 loan customers across 11 states.

Attackers breached a third-party cloud platform used by Heights Finance in May, exposing data on 734,828 customers, according to the company's filing with Texas regulators. Stolen data includes contact details, bank account and routing numbers, Social Security numbers, tax IDs and driver's license numbers. The breach, discovered on May 7, was limited to the cloud platform and did not affect loan management systems. No group has claimed the attack and dark web monitoring has found no evidence of the data being leaked.

The Record · Aug 17, 2026Data breach

German Manufacturer Shrinks Security Alert Response While Protecting 10,000 Endpoints

Vendor case study: a German manufacturer's five-person SOC cut alert triage time using ANY.RUN's cloud sandbox across 10,000 endpoints.

ANY.RUN published a case study in which a five-person security team at an unnamed German manufacturer replaced an air-gapped forensic laptop with its cloud-managed interactive sandbox, protecting roughly 10,000 endpoints and 10,000 users. The vendor claims a median 15 minutes saved per alert, 20-40 daily tasks processed, a 2.5-minute alert-to-isolation target, and a 95% agreement rate between analyst and sandbox verdicts; all figures are vendor-supplied with the customer identity withheld. The writeup also describes detonating a multi-stage phishing chain from a PDF link to a password-protected ZIP to malware execution.

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

Google and Mandiant attribute vishing-based SaaS data extortion attacks to UNC6671, now operating under the Redact, Pink, Helix, and Falcon brands.

Google Threat Intelligence Group and Mandiant track extortion group UNC6671, which uses vishing calls impersonating IT help desks to lure employees to adversary-in-the-middle phishing pages that capture credentials, MFA tokens, and session tokens. The group then registers adversary-controlled MFA devices, pivots through identity providers into Microsoft 365, Okta, and other SaaS applications, and runs automated Python and PowerShell exfiltration scripts. UNC6671 has rotated through extortion brands including BlackFile, Redact, Pink, Helix, and Falcon, and Google tracked over $10.6 million in Bitcoin payments between January 7 and May 12, 2026, with initial demands exceeding $3 million. The actor has hit dozens of organizations in North America, Australia, and the UK, shifting toward high-value financial and legal firms in July 2026.

The Hacker Newsupdated · 9d agofirst · 9d agoThreat actor in the wild 2 sources1

US Finance Under Phishing Pressure: What the SOC Data Reveals?

ANY.RUN SOC telemetry shows escalating phishing campaigns against US finance, including Vercel-hosted RMM attacks abusing legitimate services.

ANY.RUN analyzed SOC telemetry data on phishing targeting the US financial sector, concluding that the scale and security impact should not be understated. The analysis highlights modern campaigns such as Vercel-hosted attacks that deliver remote monitoring and management (RMM) tools. It notes that attackers increasingly abuse legitimate services and everyday workflow tools to deliver phishing, making detection harder for SOC teams.

ANY.RUN · 21d agoPhishing & fraud in the wild

Intelligence-Driven SOC: Modernizing Threat Monitoring and Detection Engineering for Ultimate MTTR Reduction

ANY.RUN urges SOC teams and MSSPs to adopt intelligence-driven threat monitoring to reduce mean time to respond.

ANY.RUN published a vendor blog post arguing that threat monitoring is the connective tissue of modern security operations and that SOC teams and MSSPs must move from simple log collection to a proactive, intelligence-driven framework. The piece promotes ANY.RUN's Threat Intelligence offering as the solution for detection engineering and MTTR reduction. It is promotional content rather than a threat disclosure or research finding.

ANY.RUN · Aug 12, 2026Industry

LastPass enhancements improve visibility, governance, and control

LastPass releases SaaS monitoring enhancements, Mobile Smart Scanner, and auto-enrolled dark web monitoring across its password management products.

LastPass announced enhancements to SaaS Monitoring and SaaS Protect in its Business Max offering, including Persistent Monitoring that keeps visibility active through the browser extension even when users are signed out, fully released as of July. It launched Mobile Smart Scanner to convert printed, handwritten, or screenshot passwords into vault credentials, and began phasing in automatic enrollment of all consumer accounts in dark web monitoring. The company also completed its transition to a Unified Admin Console, added company-wide onboarding links, and passed SOC 2 and ISO 27001/27701 audits with zero findings for the second consecutive year.

Help Net Security · 15d agoTools

Product showcase: AI Paper Trail shows the privacy cost of talking to AI

Proton launched AI Paper Trail, a free tool that analyzes ChatGPT or Claude exports and reports what personal data can be inferred from AI conversations.

Proton released AI Paper Trail, a free web tool that analyzes the 200 most recent prompts from exported ChatGPT or Claude conversation histories and generates a privacy report with an AI Exposure Score, inferred personal data categories, and an estimated advertising value. In a hands-on test it identified 47 data points, returned a 58/100 exposure score, estimated $185 in advertising value, and flagged five red flags spanning location, interests, finances, and relationships. Proton states that uploaded data is deleted after analysis and is not stored on its Lumo servers.

Help Net Security · 23d agoAI industry

AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn

NSA, CISA, FBI, DOE and EPA warn hackers are using AI-generated scripts to actively attack Siemens S7 PLCs across critical-infrastructure sectors.

A joint cybersecurity advisory from the NSA, CISA, FBI, Department of Energy and EPA warns of an active threat campaign targeting water, food, energy, chemical, manufacturing and commercial facilities via Siemens S7 Series programmable logic controllers. The actors use internet scanning to find exposed or poorly protected PLCs, then deploy AI-generated exploitation scripts disguised as legitimate monitoring tools, an OT first that dramatically lowers the expertise required for ICS attacks. Siemens says no new S7 vulnerabilities are involved, only exploitation of misconfigurations, and it is coordinating with CISA's ProductCERT. The warning follows a joint FBI-EPA advisory confirming attacks at water and wastewater utilities in at least 12 states since July 27.

CyberScoop · 27d agoAdvisory in the wild1

The New Face of Financial Fraud: AI-Powered Brand Abuse

Akamai reports AI-powered brand abuse is driving financial fraud against banks and promotes its Brand Guardian defense.

Akamai describes AI-powered brand abuse as a growing driver of financial fraud against banks. The post outlines the threats and the business impact for financial institutions. It also promotes Akamai Brand Guardian as a mitigation for financial institutions.

Akamai Blog · 22d agoPhishing & fraud

11 Best CSPM Tools Compared (2026): Features & Pricing

CSPM comparison ranks Wiz first for agentless attack-path analysis; notes Ermetic absorbed into Tenable and Lacework into Fortinet FortiCNAPP.

An editorial comparison of eleven CSPM tools ranks Wiz as the agentless attack-path momentum leader, Prisma Cloud as the breadth benchmark, and Orca as the agentless SideScanning pioneer. It highlights consolidation: Ermetic now powers Tenable Cloud Security and Lacework became Fortinet's FortiCNAPP. The guide recommends starting with free tiers from Defender for Cloud, Prowler, and native cloud tools before buying.

GBHackers · 1d agoIndustry1

Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites

Infoblox links China-aligned APT PeckBirdy C2 infrastructure hidden in casino and adult websites targeting Asian government, finance, IT, and education sectors.

Infoblox researchers report that China-aligned APT groups have used casino and adult websites as cover for PeckBirdy, a JavaScript command-and-control framework active since 2023. The sites embed C2 servers, register service workers for persistence, and serve fake browser-update prompts delivering backdoors capable of running commands, stealing credentials, and providing remote access. Targeted sectors across Asia include education, IT, banking, financial services, and government. Just over 3% of Infoblox enterprise customers resolved at least one PeckBirdy C2 domain, with detection coverage on VirusTotal ranging from 13 detections to none.

Distill Globally, Adapt Locally: Reasoning Distillation and Product-Type Test-Time Training for Scalable Trade-Up Recommendation

A distillation framework compresses LLM reasoning into a 15.5M-parameter trade-up recommendation model reaching AUC 0.941 with product-type test-time training.

The paper targets trade-up recommendation, which identifies higher-quality alternatives that preserve customer purchase intent. A retrieval-augmented few-shot LLM teacher generates labels and rationales that supervise a compact embedding-pair classifier; at inference the 15.5M-parameter student uses only two precomputed 768-dimensional embeddings with no LLM calls. On 8,352 annotated pairs, label-only training scored AUC 0.912, reasoning distillation reached 0.924, and product-type test-time training lifted it to 0.941 with average precision 0.940. The distilled student is roughly 5,000x faster and 10,000x cheaper than direct LLM inference on a 100K-pair proxy catalog.

arXiv cs.AI / cs.LG / cs.CL · 12d agoAI research

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Google tracked three suspected Russian espionage clusters abusing OAuth flows, app passwords, and WhatsApp linking to hijack accounts of diplomats and defense targets.

Google Threat Intelligence Group detailed three suspected Russian espionage clusters, UNC6293, UNC7005 (Storm-2945), and UNC5976, targeting academia, aerospace, defense, governments, and think tanks in Europe, the US, Ukraine, and Armenia. UNC6293, assessed as a sub-cluster of APT29/Ice Relic, conducted OAuth and application-specific password phishing while impersonating State Department officials. UNC5976 registered file-sharing-themed domains hosting fake OAuth login pages and deployed a malicious Excel plugin codenamed HEADRUSH, while UNC7005 abused WhatsApp device linking to hijack accounts and record victims' audio and video.

The Hacker News · 26d agoThreat actor in the wild

Citrix adds AI-powered browser activity analysis to SecurAccess

Citrix launched Session Insights for SecurAccess with Chrome Enterprise, using AI to record and analyze browser activity from users and autonomous agents.

Citrix Session Insights adds automatic session recording and AI-powered risk detection for browser activity by human users and autonomous AI agents within Citrix SecurAccess with Chrome Enterprise. The capability creates visual forensic records, highlights risky behavior for faster investigations, and recommends policy adjustments or changes to agent authority levels. It is designed to support audits and governance as enterprise AI agent workflows expand.

Help Net Security · 12h agoTools

Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown

McAfee says WeedHack infostealer MaaS still spreads via ten fake Minecraft client sites and SEO poisoning despite C2 takedown, with 116,464 infections logged.

McAfee Labs' follow-up on the WeedHack Malware-as-a-Service operation, first documented in June 2026, found ten active fake Minecraft client sites and multiple file-hosting accounts still distributing the infostealer even after its C2 server went dark; over 6,300 user attempts were blocked in the past month. The campaign, running since January with 116,464 infected systems and 2,000-3,000 daily new victims, offered a free Discord-gated tier and a $5/month premium tier with webcam surveillance, and stole session cookies, passwords, browser data, and cryptocurrency wallets. Distribution relies on SEO poisoning that ranked fake sites such as nova-client.com above genuine GitHub repositories, with most malicious links coming via Discord (49.6%) and MediaFire (23.4%), and one fake site built with the AI website builder lovable.app.

Security Affairs · 22d agoMalware

Hunt Malware & Phishing Threats with ANY.RUN for Proactive Enterprise Security

ANY.RUN promotes its Threat Intelligence platform for turning scattered malware and phishing indicators into proactive enterprise threat hunting workflows.

ANY.RUN published a vendor blog post describing how its Threat Intelligence product helps analysts consolidate endless alerts, indicators, behavioral evidence and infrastructure context. The post frames threat intelligence as a way to move from raw data collection to proactive protection against malware and phishing. No new threat activity, malware family or vulnerability is disclosed.

ANY.RUN · 28d agoTools

CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the

CTM360's RecruitTrap report documents 3,000+ recruitment phishing URLs using BitB windows to steal credentials and relay MFA.

CTM360 identified over 3,000 phishing URLs impersonating recruiters from more than 50 organizations across 14 sectors in the RecruitTrap campaign. Attacks use Browser-in-the-Browser popups with spoofed address bars to harvest Google and Facebook credentials and relay MFA prompts in real time. About 96% of pages used a Calendly theme, with infrastructure concentrated on AWS EC2 and hidden behind Cloudflare.

The Hacker News · Aug 15, 2026Phishing & fraud in the wild

Teams calls are about to get a lot harder to fake

Microsoft will roll out Brand Impersonation Protection in Teams Calling from mid-May 2026, warning users about suspicious inbound VoIP calls impersonating trusted brands.

Microsoft Teams Calling is gaining Brand Impersonation Protection, which evaluates inbound VoIP calls from first-time external callers for signs of brand impersonation and displays warnings before users answer high-risk calls. The feature rolls out from mid-May 2026 with completion expected by late May 2026, is enabled by default, and requires no administrative action. Users can accept, block, or end flagged calls, and alerts may continue throughout a call if suspicious activity persists. Microsoft recommends preparing helpdesk teams and updating security awareness materials ahead of deployment.

Help Net Security · 12d agoTools

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

GuidePoint reports a ransomware affiliate posing as 'Ransom Busters' charges victims $20,000-$60,000 to delete stolen data, and details UNC6671's $8M AitM extortion wave.

GuidePoint's GRIT team reports that 'Ransom Busters', likely a ransomware affiliate active across multiple RaaS operations including DragonForce, Settra and Anubis, proactively emails victims claiming it deleted their stolen data and backups for a $20,000-$60,000 fee, citing claimed access to RaaS administrative panels for over three years. Two analyzed intrusions shared tooling: SoftPerfect Network Scanner for reconnaissance, s5cmd-based exfiltration to AWS cloud storage, an RMM tool installed via PowerShell, a backdoor account with password 'Numlock!123' and the same attacker hostname DESKTOP-BBETH6K. Separately, GRIT detailed UNC6671's (Cordial Spider) adversary-in-the-middle vishing operation running since April under five extortion brands, with more than $8 million across 15 Bitcoin wallets, an average of $600,000 per payment, and 78 phishing sub-domains across 76 organizations, 40% in financial services.

The Hacker News · 29d agoThreat actor in the wild1

ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories

A weekly bulletin aggregating short security updates, including the City-Forum data-theft campaign, a ShipMonk breach, a Cursor CLI flaw, and GhostJacking AI attacks.

The Hacker News ThreatsDay Bulletin bundles roughly 20 short updates across cloud services, AI tools, malware, breaches, and scams. Highlights include the City-Forum campaign pulling data from unauthenticated guest access in Salesforce Experience Cloud and ServiceNow Service Portals since March 2025, and a ShipMonk breach exposing Trezor customer order data for orders in seven countries between May 10 and August 8, 2026. Other items cover a patched Cursor CLI flaw that let cloned repositories run commands before the workspace-trust prompt, Okta's analysis of the Work Panel vishing console used by actors like UNC6671, and GhostJacking AI agent hijacking via a patched Claude Desktop sandbox escape. Meta also launched an on-device WhatsApp Scam Alert machine learning model that keeps message content on the device.

The Hacker News · 29d agoIndustry

How to connect AI usage to business value

OpenAI explained how ChatGPT Admin Console analytics link AI usage, spend, and Codex contributions to business outcomes.

OpenAI published guidance describing analytics features in the ChatGPT Admin Console that combine usage, credit, and token data across ChatGPT Work and Codex. The Insights task classifier groups messages into use cases such as software engineering and sales research, while an Outcomes view tracks Codex contributions to merged commits and lines of code. An Admin plugin and Admin API let teams automate reporting and combine AI analytics with business metrics like ticket resolution time or revenue.

OpenAI News · 10h agoAI industry

How we monitor internal coding agents for misalignment

OpenAI published its approach for monitoring internal coding agents for misalignment behaviors, detailing oversight methodology rather than a specific incident.

OpenAI describes how it monitors its internal coding agents for signs of misalignment. The post focuses on detection methods and infrastructure for catching agent behaviors that deviate from intended goals. No concrete misalignment incident is reported; the piece is primarily about methodology.

Spyware for Babies

AI-powered baby monitors like Nanit, which raised $50 million, collect extensive infant data, raising privacy and surveillance concerns.

A New York Times report covered by Schneier on Security describes how baby-monitoring companies such as Nanit are expanding AI-based 24/7 health tracking of infants. Nanit recently raised $50 million to add tracking of speech and language development and motor skills via its camera, while extending its bedroom presence into early adolescence. The post highlights the already extensive level of baby data collection and its expected growth.

Schneier on Security · 21d agoIndustry

Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads

Hijacked verified HBO Max Reddit account ran 108 ClickFix malvertising ads delivering AMOS infostealers, Windows loaders, and crypto clipboard hijackers.

HudsonRock and ADAMnetworks identified a cross-platform ClickFix operation dubbed PasteSwitch that abused the compromised verified Reddit account u/hbomax to publish 108 malicious ads over 48 hours, using domains like hbomaxx[.]us and codex-craft[.]com. macOS victims run curl/zsh commands delivering AMOS-related stealers and fake wallets, while Windows users get an InstallFix route using mshta and PowerShell that loads Amatera in memory and disables AMSI. The operation's AnimateClipper and ZigClipper families hijack clipboards to swap cryptocurrency addresses, with C2 domains rotated via Binance Smart Chain contracts. Reddit paused the ads and is investigating.

Cyber Security Newsupdated · 1d agofirst · 1d agoMalware in the wild 7 sources

AgenticGen: Reward-Guided Agentic Video Generation for Advertising

AgenticGen applies DPO and GRPO reward-guided reasoning to ad video generation, improving TikTok CTR 2.72%, CVR 2.63%, and Advv 9.61%.

AgenticGen decomposes advertising video generation into two trainable reasoning stages, strategy selection and draft generation, supervised by online business feedback. It learns a performance-based reward from accumulated online feedback plus a rubric-based reward aligned with human quality standards, then optimizes policies with DPO followed by GRPO using process and outcome rewards. Online A/B experiments in the TikTok advertising system show CTR up 2.72%, CVR up 2.63%, and Advv up 9.61% over an SFT baseline.

Hugging Face daily papers · 17d agoAI research

Reimagining advertising with AI

OpenAI launches ChatGPT advertising features including Sponsored Agents, AI ad creation in Ads Manager, and integrations with HubSpot and Shopify.

OpenAI is testing Sponsored Agents in the United States, letting users converse with clearly labeled business-sponsored agents after clicking ads in ChatGPT. Advertisers can create, update, and analyze campaigns via natural-language prompts in ChatGPT with an Ads Manager plugin, plus AI-suggested copy and imagery in Ads Manager. HubSpot becomes the first CRM partner and Shopify the first ecommerce partner, with the Shopify app expanding internationally on September 23.

OpenAI News · 9h agoAI industry

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

GTIG's Q2 2026 tracker shows adversaries adopting agentic AI workflows, including credential harvesting in under six hours and supply chain attacks by UNC6780.

Google Threat Intelligence Group's Q2 2026 report documents adversaries moving from basic prompting to agentic AI workflows and automation, including a cloud compromise followed by agent-enabled mass credential harvesting executed in under six hours. It tracks financially motivated actor UNC6780 (TeamPCP) conducting large-scale open source supply chain compromises across PyPI, npm, and Docker Hub since March 2026, deploying credential stealers. The report also highlights growing targeting of proprietary AI models, source code, prompts, and API credentials, plus LLMJacking practices where adversaries steal developer credentials or hijack cloud infrastructure to run unauthorized AI workloads.

Google Threat Intelligence · 8d agoThreat actor in the wild1