The CyberDiplomat’s Daily Report
This report outlines various global cybersecurity incidents, including sophisticated spyware targeting Tibetan and Taiwanese communities, scrutiny over Bangladesh’s Cyber Security Act, a DDoS attack on Indonesia’s Tempo.co, and breaches in Australia’s superannuation sector. Other highlights include malware threats in various regions and ongoing efforts to enhance cybersecurity across nations.…
Read More
Lovable AI Found Most Vulnerable to VibeScamming — Enabling Anyone to Build Live Scam Pages
Summary: Lovable, a generative AI platform for creating web applications, has been identified as highly vulnerable to jailbreak attacks, enabling users to create fake credential harvesting pages effortlessly. This vulnerability is part of a broader trend where AI tools are misused in cybercrime, through methods like VibeScamming and Immersive World which facilitate the creation of convincing phishing campaigns.…
Read More
VibeScamming — From Prompt to Phish: Benchmarking Popular AI Agents’ Resistance to the Dark Side
This article discusses the dangers posed by generative AI in facilitating phishing scams, highlighting the results of the VibeScamming Benchmark v1.0. Guardio Labs evaluated how well popular AI platforms handle scam-related prompts, revealing significant vulnerabilities across different models. The findings urge AI developers to prioritize safety measures in their technologies to protect individuals from fraud.…
Read More
Summary: A cybercriminal group known as the Smishing Triad is intensifying smishing activities targeting consumers in the US and UK with fraudulent texts related to toll payment services. This campaign involves the use of deceptive messages that impersonate legitimate toll agencies, demanding payments for fictitious unpaid tolls and soliciting sensitive personal information.…
Read More
Six arrested for AI-powered investment scams that stole  million
Summary: Spanish police have arrested six individuals involved in a sophisticated cryptocurrency investment scam that employed AI-generated deepfake ads featuring renowned public figures to deceive victims. The scam successfully defrauded 19 million Euros from over 200 victims worldwide. Operations included the use of shell companies and various aliases by the perpetrators to launder funds and maintain their illicit activities.…
Read More
Everest ransomware group’s darknet site offline following defacement
Summary: The darknet leak site used by the ransomware group Everest was taken offline and defaced with an anti-crime message. The incident raises questions about its legitimacy and potential involvement of law enforcement, as authorities intensify disruption operations against ransomware activities. In the wake of recent disruptions, including operations against other ransomware groups, there is a noticeable decline in extortion payments in the cybercrime ecosystem.…
Read More
⚡ Weekly Recap: VPN Exploits, Oracle’s Silent Breach, ClickFix Surge and More
Summary: The cybersecurity landscape is plagued by persistent threats stemming from unpatched systems, oversights, and social engineering tactics that facilitate breaches. This report highlights significant vulnerabilities and recent breaches linked to well-known organizations and emerging threat actors. The trends illustrate a critical need for companies to prioritize security measures against increasingly sophisticated attacks.…
Read More
AI Turned My Face Into a Cartoon—Hackers Turned It Into a Weapon
Summary: AI technology, initially used for creative endeavors, is now being exploited for identity theft and scams, particularly in India. Fraudsters are using AI tools to generate realistic fake IDs and documents, leading to widespread digital scams and misinformation. This alarming trend points to a need for better regulation and public awareness regarding the use of AI in identity verification and privacy management.…
Read More
Social Media Flooded with Ghibli AI Images—But What Are We Really Feeding the Algorithms?
Summary: The viral trend of AI-generated art, particularly Ghibli-style portraits, raises significant privacy concerns as users unknowingly share sensitive biometric data. While the transformation of selfies into whimsical anime characters captivates audiences, it also poses risks of data misuse, identity theft, and exploitation by AI algorithms.…
Read More
E-ZPass toll payment texts return in massive phishing wave
Summary: A surge in phishing campaigns impersonating E-ZPass and other toll authorities aims to steal personal and credit card information through deceptive iMessages and SMS texts. The messages create urgency by warning recipients of impending fines and payment deadlines. Users are advised to avoid responding to these messages and to check balances directly through official toll authority websites instead.…
Read More
Threat actors leverage tax season to deploy tax-themed phishing campaigns
As the tax season approaches in the U.S., Microsoft has noted an increase in phishing campaigns using tax-related themes to steal sensitive information and deploy malware. These campaigns exploit various techniques, including URL shorteners, QR codes, and legitimate file-hosting services to evade detection. The reported threats include credential theft linked to platforms like RaccoonO365 and various malware types such as Remcos and Latrodectus.…
Read More

Summary: The video discusses a security warning regarding a fake version of GitHub that leads users to an authorization page for a security app OAuth request. It highlights the alarming permissions that this app can request, such as the ability to delete repositories, raising concerns about user data safety.…
Read More