Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Top tips: How to spot a scammer pretending to be your boss

Top tips is a weekly column where we highlight what's trending in the tech world and share practical ways to navigate these shifts. This week, we're looking at spear-phishing: how cybercriminals weaponize social engineering, why your natural instinct can act as a security blind spot, and practical steps to verify suspicious requests before you take action. I would like to make a confession: I’m a well-versed tech expert, but I almost fell for a phishing scam.

Report: Scams Are Surging as Attackers Abuse Trusted Workflows

Threat actors are increasingly abusing trusted workflows to carry out attacks, according to a new report from Gen Digital. “ are not only sending malicious links or dropping malware,” the report says. “They are abusing context, sessions, workflows, brands, update systems, advertising platforms and delegated authority.

Your Invoice Fraud Controls Probably Never Look at the Signature

Business email compromise took $3 billion in reported losses during 2025, the second-largest category in the FBI's Internet Crime Complaint Center annual report after investment fraud. The same report logged 1,008,597 complaints and $20.877 billion in total losses, up 26% on the year before. The control most organisations built in response is a callback procedure. Payment details changed? Phone the supplier on a number you already had. That control works, and it's worth having.

Report: Employees Are Overconfident in Their Ability to Spot Scams

A survey from Trustmi found that most employees believe they’d be able to spot a social engineering attack, but those same employees still rely primarily on outdated guidance to spot red flags. Generative AI has given attackers the ability to craft extremely convincing, error-free phishing emails.

How to Identify Users Exposed to Brand Impersonation Attacks

Most organizations have become better at finding brand impersonation attacks. They can detect fake domains, identify cloned websites, report phishing pages, initiate takedowns, and warn customers when an impersonation campaign becomes visible. That work matters. But it does not answer the question that often matters most once the attack is live: Which users were exposed? Finding fake sites is only half the problem. Understanding who encountered them is where effective protection begins.

Apple Warns Users to be Wary of Unsolicited FaceTime Calls

Apple is warning users to be wary of unsolicited FaceTime calls amidst a wave of scams impersonating Apple Support, Malwarebytes reports. The scammers inform the user that there’s been fraudulent activity or a technical problem associated with their account, and trick the victim into handing over payment card details, banking credentials or Apple ID logins.

Evil Twin Attack: What It Is, How It Works, and Why Your Customers Are the Target

An evil twin attack is a man-in-the-middle attack in which an attacker creates a rogue wireless access point that impersonates a legitimate network. Victims connect believing the network is genuine, allowing the attacker to intercept traffic or present fraudulent login experiences designed to capture credentials. Evil twin attacks have traditionally been treated as wireless-security incidents. For enterprises with large customer bases, however, the consequences extend well beyond the network layer.

The Fuyao Enterprise: Building an Ad-Fraud Empire with AI and Kids' Coding Blocks

In this post, we will uncover the “Fuyao Enterprise,” a previously unknown, sophisticated and highly modular botnet operating within Android TV boxes. This operation marks a shift in modern ad-fraud, where automated bots fake both clicks and views to defraud advertisers and ad-networks. While deploying novel tactics and techniques, Fuyao managed to escape public research for several years. Now, its operators openly advertise their network of over 120,000 “AI digital humans.".