
Habdul HazeezLearn about the top cybersecurity news between September 25, 2026, and October 2, 2026. Read now and increase your cybersecurity knowledge.
Phishing is still a thing. When you go online, malicious websites are among the threats that you should steer clear of—that's if you know that they are malicious. Also, AI is here to stay while it is increasing the productivity of defenders and attackers. Finally, not every ad is worthy of your click and I just learned that scammers can hijack social media accounts of a Big Tech company.
The lesson that I want you to take away from this article is this: email is still a vector that attackers use to deliver phishing links. But, gone are the days when you can catch them by looking for typos or bad grammar; AI has changed all that. Also, it drives home that awareness can help, employees should not be quick to delete a phishing email because it could be part of a larger campaign. Finally, never stop learning how attackers are planning to take over your employee's account.
For the latter, here is one of those ways:
As neither seeing nor hearing is believing these days, a recognizable face or voice doesn’t always provide conclusive evidence of who’s behind the request. Employees who encounter lifelike but fake audio and video in the middle of work often lack the opportunity to examine every frame or to listen or watch for possible synthetic tells revealed by older deepfake creations.
The seven defensive tips highlighted in the article are what you can do to prevent yourself from getting scammed. Undoubtedly, the list includes showing the full URL and blocking potentially unwanted sites. If you still doubt why you should go through these processes, read the excerpt below.
Malicious websites pose a threat to all of us who use the web regularly. They let attackers infect your PC with viruses and spyware, steal your personal data, take over your system, and hijack your accounts. But you don't have to be a victim
The basics can go a long way to secure the systems of your organization. That's the message.
From the article:
Not surprisingly, good security hygiene and good security fundamentals go a long way toward preventing security incidents and securing applications, even in the age of “Frontier AI.”
This is another wake-up call to think twice before clicking on ads that appear in your search results. Anyone who follows these fake ChatGPT ads will encounter a ClickFix attack that can lead to the installation of malware.
From the article:
The combination of malware and advertising — also known as malvertising — has a long, storied history, which means you should always be careful when clicking on any advertisement online. To stay safe, you could try using one of the best ad blockers, since Google's "sponsored" links are still technically ads; most blockers will hide them.
There are no surprises in this one. AI is making its users protective, attackers included.
Here is an example of what's going on:
AI lets attackers personalize every phishing message, turning spear phishing into a mass operation, and helps them get past language and skill barriers.
Fraudsters faking an identity used to slip up with a forged ID that looked off, writing that read like a second language, an accent that came through during an interview, and barely any trace online. “AI fixes all four simultaneously,” Microsoft stated.
Currently, the mystery surrounding this event is: How did it happen? For now, we don't know. Will we ever find out? Time will tell.
A glimpse of what happened:
The account behind the reposted message, @clippymsftcto, posed as Clippy and has since been suspended. A second account involved in the incident kept pushing a $Clippy token, saying its liquidity pool was paired with $MSFT.
The posts were eventually taken down. According to The Verge, an apology appeared on the Microsoft account roughly 30 minutes later and was deleted soon after
Cover photo by Debby Hudson on Unsplash.
That's it for this week, and I'll see you next time.