VNVũ Nhật Lâminblog.fiscybersec.com·Sep 16 · 17 min readPhantom Deal: When the NDA Is the PayloadSummary It started with an innocuous WhatsApp message: "Hi David, I hope you are well. Are you at the office?" The sender claimed to be a real Gen executive based in Dublin. The profile used his nam00
LTLưu Tuấn Anhinblog.fiscybersec.com·Sep 16 · 13 min readTerminalFix Campaign Analysis: Risk of Active Directory Hijacking from Risky Terminal OperationsExecutive Summary Recently, Microsoft Threat Intelligence published analysis of a wide-area attack campaign called TerminalFix — a dangerous evolution from the social engineering technique ClickFix. I00
LDLakshay Dhoundiyalinlakshaydhoundiyal.hashnode.dev·Aug 26 · 10 min readBrowser-in-the-Browser Attack: How Fake Login Windows Steal Real PasswordsImagine you're browsing a website. You click “Sign in with Google.” A familiar login window appears. The logo looks right. The colors look right. The layout looks right. Even the little browser frame 20
ĐVĐinh Văn Mạnhinblog.fiscybersec.com·Aug 25 · 17 min readFake Microsoft "SysScan": Bogus Security Scanner Invents Problems, Tricks Victims Into Uninstalling Their Antivirus, Then Funnels Them Into a Refund ScamOverview On August 24, 2026, Malwarebytes disclosed a wave of websites calling themselves "SysScan," carrying Microsoft branding, claiming to check whether your antivirus (AV) software is working. Eve10
JAJoyce Abijaincybersage.hashnode.dev·Aug 20 · 6 min readYou don't have to be important to be Hacked"I’m just an ordinary person, I don't work for the government or FBI. Why would anyone want to hack me?” This question reflects one of the biggest misconceptions people have about cybersecurity: the b00
SMScott McMahaninaitransformeronline.hashnode.dev·Aug 13 · 1 min readAI-Powered Phishing in 2026Phishing attacks are becoming more difficult to detect as cybercriminals use AI to create polished messages, personalize fraudulent requests, and automate campaigns at scale. Traditional Warning Signs00
SSaguninsagunwrites.hashnode.dev·Aug 5 · 7 min readILOVEYOUOn May 4, 2000, millions of people around the world opened their email and saw a message with an unusually personal subject: ILOVEYOU For many recipients, it looked like a message from someone they kn00
LTLưu Tuấn Anhinblog.fiscybersec.com·Jul 28 · 11 min readRedHook Android RAT: A new step in Android device hijacking techniquesCampaign Summary A report from Group-IB Threat Intelligence published on July 9, 2026 confirms the re-emergence of RedHook malware — a remote access Trojan (RAT) on Android with breakthrough improveme00
JDJustine Devs (Official)injstn.hashnode.dev·Jul 1 · 8 min readThe malware was not in the app. It was in .git/hooks.My first job hunt taught me to inspect the repo before trusting the task I am currently looking for my first job So when a recruiter messaged me on LinkedIn and sent over a take-home repository, I tre00
AFAeon Flex / Splicer Scorninchaincoder.hashnode.dev·Jun 17 · 8 min readDeepfakes Are Free Now. Your Company’s Phone System Is Not. And that’s the whole problem. Let me set the scene for you. It’s 2:47 PM on a Tuesday. Your CFO gets a call. It’s the CEO’s voice. Same cadence. Same little pause before numbers. Same “hey, can you ru00