Threat actors are increasingly leveraging AI hallucinations to plant phishing links and other malicious content in AI output, IEEE Spectrum reports. Large language models (LLMs) sometimes fabricate information, including web domains, when answering users’ questions. Attackers are registering these hallucinated web domains to host phishing pages.
The U.S. Federal Bureau of Investigation (FBI) has issued an advisory warning of a wave of OAuth consent phishing attacks targeting “prominent victims, their family members, and personal acquaintances.”
OAuth phishing is an increasingly popular social engineering tactic that tricks users into granting access to their accounts without handing over their passwords.
A recent survey from Experian found that 60% of companies report fraud losses that are “somewhat or significantly higher” than in previous years, with a majority of respondents citing AI-generated phishing attacks as their top AI-related fraud concern.
Researchers at INKY observed a major phishing campaign that used SVG (Scalable Vector Graphics) image files to deliver malicious JavaScript. While abuse of SVG files isn’t new, INKY says their use in phishing campaigns has exploded over the past year.
Researchers at Zimperium are tracking widespread phishing campaigns that use Browser-in-the-Browser (BitB) attacks to trick users into handing over their enterprise credentials. The attackers impersonate real HR employees at major companies and target job seekers with extremely realistic interview processes.
Attackers are using “wrong-number” texts to identify potential targets for scams, according to researchers at Malwarebytes.
These texts appear to be harmless messages meant for another person, such as “Are we still on for dinner tomorrow?” or “Where’s the PowerPoint?” Recipients often try to be helpful by replying to let the person know they’ve got the wrong number. This reply, however, informs the threat actor that the phone number is active and marks it for future scams.
A new phishing platform called “JWR” gives attackers real-time control over social engineering attacks, according to researchers at Cisco Talos. The kit livestreams the phishing page to the attacker as the victim is entering information, allowing the attacker to steer the victim’s experience and maximize the damage.
Google’s Threat Intelligence Group (GTIG) is tracking a voice phishing (vishing) campaign that’s targeting hedge funds and financial firms. The researchers attribute the attacks to “UNC6671,” an extortion group formerly known as “BlackFile.” The attackers pose as IT staff informing employees of urgent, mandatory migrations.
Criminals are now selling malicious AI tools for use in cyberattacks, according to researchers at Trellix. These tools dramatically lower the barrier for unskilled crooks to launch sophisticated attacks.
Attackers are distributing a new Android malware called “WindRelay” via phone-based social engineering attacks, according to researchers at Group-IB. The attackers call the victims, impersonating bank employees and instruct them to install a malicious app. In one instance observed by Group-IB, the scammers carried out the entire attack in just thirteen minutes.
A study has found that AI chatbots can be more effective at social engineering than human scammers, WIRED reports. The researchers looked at a form of romance scam commonly known as “pig butchering,” in which scammers spend weeks or months building a relationship with the victim before tricking them into sending money for a phony investment scheme.
AI is making social engineering attacks significantly more effective, according to a new report from cyber insurance firm Resilience. These attacks were behind more than 85% of losses in the first half of 2026, compared to less than 20% during H1 2024.
Earlier, we wrote an article on the issues that cars have. These issues are still common and car ransomware might soon emerge, hitting not just individual cars but entire fleets as vehicles get more autonomous and packed with different features.
In light of that, we want to show you a tool that makes car hacking more approachable. It’s GearGoat. The tool was built to simulate a car’s internal network so you can play with it.
GearGoat
GearGoat is a car simulator developed by INE Labs. It lets you work with the internal communication network used by most modern vehicles (CAN bus). Every action generates CAN packets on a virtual interface. You can use cansniffer, candump and UDS scanners with GearGoat, just like with any vehicle.
In a real car, you’d connect a CAN adapter (CANable or Macchina M2) into the OBD-II port, located under the dashboard. This port is basically a gateway into the vehicle’s internal network. Your system will treat the adapter as a network interface (can0) and you can start capturing and sending CAN messages. When someone presses the brake or turns on the indicators, it generates messages that travel across the network.
Setting Up
GearGoat runs inside a Docker container, so it’s easy to deploy. Clone the repository and run the script:
kali > git clone https://github.com/ine-labs/GearGoat.git
kali > cd GearGoat
kali > sudo chmod +x initial_setup.sh
kali > sudo ./initial_setup.sh
Then you need to configure the virtual CAN interface (vcan0):
kali > sudo chmod +x vcan_setup.sh
kali > sudo ./vcan_setup.sh
On certain distros you might be missing kernel modules. Here’s how you install them:
kali > sudo apt-get install -y linux-modules-extra-$(uname -r)
It doesn’t always work on Kali Linux though. You can manually load the required modules and create the interface yourself:
kali > sudo modprobe vcan
kali > sudo ip link add dev vcan0 type vcan
kali > sudo ip link set up vcan0
kali > ip link show vcan0
Now everything should be ready. You can start GearGoat:
kali > sudo docker run --network="host" --privileged geargoat
The simulator will be hosted on http://localhost. There you’ll see different car functions. Each button on the interface generates CAN traffic.
Intercepting Traffic
While the simulator’s running, it continuously generates CAN traffic. To see this traffic, use cansniffer.
kali > cansniffer -c vcan0
The output can feel overwhelming. The tool keeps highlighting changing bytes dynamically. It’s very noisy when you’re trying to establish a baseline. You need a way to tell the tool what normal looks like. Press Shift + 3 + Enter multiple times and cansniffer will treat the current state as the baseline. It won’t highlight the background noise anymore, so you’ll only see the changes you make.
Once the baseline is set, you can start playing with the simulator. Click the Left Indicator button and you’ll notice a change in the CAN data.
The first byte of a frame changes and it’s tied to 0x188. That means this identifier controls the indicator state.
When you play with the speedometer, you’ll see a different pattern. The changes happen in the 4th and 5th bytes are associated with 0x244. The speed climbs gradually.
Repeat this with other controls and you’ll see how functions map on the CAN bus.
Sending Input
Now we know which messages control specific functions, so we can interact with them.
To control the indicators, we’ll send CAN frames using cansend:
kali > cansend vcan0 188#0100000000000000 # left
kali > cansend vcan0 188#0200000000000000 # right
These commands will turn on the left and right indicators. The CAN bus runs at high speed, so these changes can be hard to catch. We used the watch command to make it more visible:
kali > watch -n 0.1 "cansend vcan0 188#0200000000000000"
Working with speed gets slightly more complex. Earlier, we found the address (0x244) and that specific bytes that control the value. To set a speed, we need to convert miles per hour into the format the CAN message expects.
To simulate a speed of 50 miles per hour you send:
kali > cansend vcan0 244#0000001F6F
You can see the simulator accelerating. Use the formula V = round(mph / 0.6213751 * 100) to calculate the value, then convert it into hexadecimal using big-endian.
Capturing and Replaying Traffic
You can also capture and replay traffic. That way you can record a sequence of actions and reproduce them.
To capture traffic, you use candump with logging:
kali > candump -l vcan0
It’ll record the CAN messages into a log file. Once captured, you can replay it:
kali > canplayer -I <log_file_name>.log
Summary
GearGoat can get you started with car hacking. You work with a simulated CAN bus to understand the communication patterns and message structure. It’s easy to set up and it’s not resource intensive, so it’ll run on pretty much any computer.
We also have our three-day Car Hacking training, showing you real attacks. It includes CAN protocol exploitation and the use of Software Defined Radio (SDR). There we show you how modern vehicles are actually compromised.
Americans are now losing an estimated $148 billion each year to online scams, a 22% increase compared to 2024, according to a new report from the Consumer Federation of America (CFA). The FBI’s Internet Crime Complaint Center (IC3) tracked $20.8 billion in losses last year, but the CFA notes that the actual losses are much higher.
Social engineering remains a central part of modern cyberattacks, according to a new report from CrowdStrike. Attackers are increasingly turning to voice phishing because it bypasses traditional security controls and leaves little forensic evidence, since the social engineering takes place over the phone.