Cybersecurity intelligence

Know what changed.
Trace why it matters.

A daily, source-linked briefing for security practitioners. Every record carries its publication context, evidence links, and known limitations.

Get Security Weekly by email

Latest security briefing

Security Daily

Read latest edition
Latest signal

High-signal changes

View full briefing →
Security Daily

Incident · Malwarebytes Labs

What happened

Researchers at Manifold Security found third-party[.]com, an ordinary domain often used in documentation for an external website, API, or service, serving a fake Cloudflare-style verification page to Windows visitors. The page urged visitors to open the Windows Run box and paste a clipboard-copied command designed to download and execute a PowerShell script; the script-hosting domain was not resolving at the time of writing.

Why it matters

ClickFix is described as social engineering that convinces victims to run commands themselves, often using legitimate operating-system tools and the permissions of the persuaded user; consequences can range from information theft to more serious company-network compromise.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

AI & Agents · Krebs On Security

What happened

Cameron John Wagenius, a U.S. Army soldier stationed in South Korea, pleaded guilty to hacking telecommunications companies and stealing mobile call and text metadata from more than 100 million AT&T customers; he was sentenced to 70 months in federal prison and ordered to pay $294,978 in restitution. The intrusions involved Snowflake customers with exposed credentials and no enforced multi-factor authentication; Snowflake has since mandated MFA on all accounts.

Why it matters

Federal investigators characterized the case as a serious insider-threat investigation because Wagenius was an active-duty soldier with secret clearance allegedly creating hacking tools and trafficking in data.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

AI & Agents · Malwarebytes Labs

What happened

LinkedIn is adding verification features intended to make fabricated professional identities, work histories, and company impersonation harder, in response to generative AI lowering the cost of creating convincing profiles and outreach. The features include colleague or classmate confirmations of work or study affiliations; these confirm an affiliation but do not assess ability or recommend the person.

Why it matters

The checks may help establish whether a recruiter is affiliated with a recognized company, but may be less useful when scammers invent the employer itself or operate a fraudulent company Page.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Curated context

Selected historical incidents

View library →

This is a curated historical collection, not a measure of global incident prevalence.

Build practical skill

Learn from the same evidence discipline

Open learning hub →
Trust through limits

Evidence is visible. Uncertainty stays visible too.

Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.

Read methodology and limitations →
Your Monday security briefing

BaitaPhish Security Weekly

Get the week's most important security developments by email, with links to the evidence and the narrated edition.

Monday mornings, when a new edition is published.

We’ll email you a link to confirm your subscription. Previously unsubscribed? Use this form to request a fresh confirmation link.

Explore Security Weekly