inglés
Actualidad y política
$99 / mes después de la prueba.Cancela cuando quieras.
Acerca de Hacking Humans
Deception, influence, and social engineering in the world of cyber crime.
770 episodios
Who is winning the scam game?
This week, hosts of N2K CyberWire Maria Varmazis [https://www.linkedin.com/in/varmazis/] and [https://www.linkedin.com/in/dave-bittner-27231a4/] Dave Bittner [https://www.linkedin.com/in/dave-bittner-27231a4/] alongside Joe Carrigan [https://www.linkedin.com/in/joecarrigan/] are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. If you thought you could escape chicken talk, you we're wrong, this week Joe shares some more updates on his chickens. Joe’s got two stories this week, one on a New Jersey man arrested while attempting to collect $800,000 in gold as part of a widespread scam targeting elderly victims, and the second is on a new Google-tracked threat group using social engineering and phishing tactics to infiltrate BPOs and steal corporate data for extortion. Maria’s story is on a conversation she had with Sean Colicchio [https://www.linkedin.com/in/seanslinked/], highlighting how trusting human instincts, slowing down, and balancing security training can help individuals and organizations better defend against social engineering attacks. Dave’s got the story on a surge in traffic violation scams now using QR codes in phishing texts to trick victims, alongside ten hard-stop rules emphasizing verification, avoiding links or inbound requests, and slowing down to prevent falling for increasingly sophisticated scams. Our Catch of the Day comes from Reddit, where a user questioned a supposed “Google Play Console partnership” email, and the community quickly flagged it as a likely scam—citing red flags. Resources and links to stories: * Indian in New Jersey on work visa arrested in gold scam, nabbed when he was going to collect $800,000 in gold [https://timesofindia.indiatimes.com/world/us/indian-in-new-jersey-on-work-visa-arrested-in-gold-scam-nabbed-when-he-was-going-to-collect-800000-in-gold/articleshow/130143807.cms] * Google Warns of New Threat Group Targeting BPOs and Helpdesks [https://www.infosecurity-magazine.com/news/google-warns-group-targeting-bpos/] * Traffic violation scams switch to QR codes in new phishing texts [https://www.bleepingcomputer.com/news/security/traffic-violation-scams-switch-to-qr-codes-in-new-phishing-texts/] * [Nepal] Is this “Google Play Console partnership” email a scam? [https://www.reddit.com/r/Scams/comments/1sggme7/nepal_is_this_google_play_console_partnership/] [https://www.ghanaweb.com/GhanaHomePage/business/Inside-the-alleged-2-5-million-Dubai-Crown-Prince-romance-scam-2020297]Have a Catch of the Day you'd like to share? Email it to us at [https://therecord.media/fin6-recruitment-scam-malware-campaign]hackinghumans@n2k.com [hackinghumans@n2k.com].
Service Set Identifier (SSID) (noun) [Word Notes]
Please enjoy this encore of Word Notes. The name of a wireless access point. CyberWire Glossary link [https://thecyberwire.com/glossary/service-set-identifier-ssid]. Audio reference link: SSID Management - CompTIA Security+ SY0-401: 1.5 [https://www.youtube.com/watch?v=wlg4VaEXbrg], Professor Messer, uploaded August 3rd, 2014.
When “opportunity” knocks, don’t answer.
This week, hosts of N2K CyberWire Maria Varmazis [https://www.linkedin.com/in/varmazis/] and [https://www.linkedin.com/in/dave-bittner-27231a4/] Dave Bittner [https://www.linkedin.com/in/dave-bittner-27231a4/] alongside Joe Carrigan [https://www.linkedin.com/in/joecarrigan/] are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. Your favorite follow up story is back, this time Sue from Australia discusses why Joe’s hen is losing feathers. Dave’s story is on a sophisticated LinkedIn phishing scam that tricks professionals with fake notifications and counterfeit login pages to steal credentials. Joe discusses a bizarre Everest scam where climbers and Sherpas were targeted with fake rescue schemes, highlighting the surprisingly high number of visitors versus summiters. Maria has the story of IRS and tax-related scams warning taxpayers about ghost preparers, urgent payment demands, and fraudulent contact attempts, with Proofpoint noting the use of remote monitoring tools in 40% of 2026 cases. Our catch of the day comes from Reddit, where a likely “stranded in the woods” scam involving a man named Michael begins to unfold but quickly unravels after he overwhelms the interaction with constant ChatGPT-style questioning. Resources and links to stories: * [https://attack.mitre.org/techniques/T1667/]LinkedIn Phishing Scam Uses Fake Notifications to Hijack Accounts [https://hackread.com/linkedin-phishing-scam-fake-notificatioms-hijack-accounts/] * Everest guides accused of poisoning foreign climbers to force fake rescues in $20m scam [https://www.independent.co.uk/travel/news-and-advice/mount-everest-climb-nepal-insurance-scam-sherpa-poisoning-b2952027.html] * Surge in sophisticated tax scams reported by BBB ahead of deadline [https://www.newsnationnow.com/us-news/recalls/tax-scams-april-15-deadline-bbb-warning/] * Security brief: tax scams aim to steal funds from taxpayers [https://www.proofpoint.com/us/blog/threat-insight/security-brief-tax-scams-aim-steal-funds-taxpayers] * The Guy in the Woods - Seduction on Scrabble - Part 1 [https://www.reddit.com/r/scambait/comments/1s8p1jj/the_guy_in_the_woods_seduction_on_scrabble_part_1/?solution=d9ec8e59cd30cbd8d9ec8e59cd30cbd8&js_challenge=1&token=bbbe4bf1c9a2b5160829c4be34da58619d8cfe58c234fe2d6d3629d61c58b5ef] [https://www.ghanaweb.com/GhanaHomePage/business/Inside-the-alleged-2-5-million-Dubai-Crown-Prince-romance-scam-2020297]Have a Catch of the Day you'd like to share? Email it to us at [https://therecord.media/fin6-recruitment-scam-malware-campaign]hackinghumans@n2k.com [hackinghumans@n2k.com].
Advanced Encryption Standard (AES) (noun) [Word Notes]
Please enjoy this encore of Word Notes. A U.S. Government specification for data encryption using an asymmetric key algorithm. CyberWire Glossary link: https://thecyberwire.com/glossary/advanced-encryption-standard [https://thecyberwire.com/glossary/advanced-encryption-standard] Audio reference link: papadoc73. “Claude Debussy: Clair De Lune.” [https://www.youtube.com/watch?v=CvFH_6DNRCY] YouTube, YouTube, 6 Oct. 2008.
Who’s logging in? [OMITB]
Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is Selena Larson [https://www.linkedin.com/in/selenalarson/], Proofpoint [https://www.proofpoint.com/] intelligence analyst and host of their podcast DISCARDED [https://www.proofpoint.com/us/podcasts/discarded]. Inspired by the residents of a building in New York’s exclusive upper west side, Selena is joined by her co-hosts N2K Networks [https://www.n2k.com/] Dave Bittner [https://www.linkedin.com/in/dave-bittner-27231a4/] and Keith Mularski [https://www.linkedin.com/in/keith-mularski-b737551/], former FBI cybercrime investigator and now Chief Global Ambassador at Qintel [https://www.linkedin.com/company/qintel/]. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. On this episode, we discuss findings from the Sophos Active Adversary Report 2026 by Sophos, highlighting how identity-related weaknesses like compromised credentials and gaps in MFA continue to drive a majority of security incidents. The conversation explores how attackers are moving faster, often operating after hours, and how a growing number of threat groups is adding to the complexity.
Elige tu suscripción
Más populares
Premium
20 horas de audiolibros
Podcasts solo en Podimo
Disfruta los shows de Podimo sin anuncios
Cancela cuando quieras
Empieza 7 días de prueba
Después $99 / mes
Empieza 7 días de prueba. $99 / mes después de la prueba. Cancela cuando quieras.