Topic
scam
E-Commerce & Marketplaces TikTok Bans iPhones and Gift Cards From Surprise Sets After Bidder Complaints
TikTok's Surprise Set auctions let users bid on mystery prizes, but bidders complained of receiving cheap items like teddy bears instead of advertised iPhones. TikTok responded by banning high-value items such as iPhones, iPads, and gift cards from the feature, and reaffirmed that sellers must accurately present offerings or face account suspension.
Technology Incogni Report Reveals Job-Search Platforms Selling User Data Without Awareness
A new report from Incogni reveals that leading job-search platforms are selling users' sensitive data to third parties, often without users' awareness. ZipRecruiter, LinkedIn, and Monster rank highest for data collection and sharing. Only 7% of surveyed job seekers expressed concern about privacy risks.
Technology Hackers Use TikTok Videos Promising Free Spotify Premium to Deploy Malware
A report from ReversingLabs reveals hackers are using TikTok and Instagram Reels videos offering fake free subscriptions to Spotify Premium, Windows, Office, and Adobe to trick victims into running malicious PowerShell commands. The attack installs the Vidar infostealer, which steals passwords, cookies, session tokens, and cryptocurrency wallet data. This marks a shift from email phishing to social engineering on short-form video platforms.
Technology Phishing campaign exploiting Google Cloud links reaches 12,000 servers worldwide
An investigation by Comparitech revealed a coordinated phishing and spam network spanning 12,704 servers across 55 countries. Attackers use Google Cloud Storage links to evade detection, with fake New York Times pages as decoys. 99.8% of servers run end-of-life software, and 89% had no prior abuse history, indicating a rapidly rotating infrastructure aimed at bypassing traditional security tools.
Technology North Korean Phishing Scheme Targets Developers for Crypto Theft
A North Korean phishing campaign, led by the group UNK_DeadDrop, targets developers with fake job offers to steal cryptocurrency. This operation mirrors tactics used by Lazarus but employs email-based lures and new payloads.