Phishing Campaign Hides Lua Loader as TrueType Font File

2026-07-16T20:52:20Z70623983d9288b621bc353555356f95f086efbd6c0490e37dd4f7c94e7b1aacf
AI-misuseCVE-volumeClickLockCrashStealerEntra-IDEvilginxGPT-5.5GodDamnMFA-bypassMicrosoft-patch-tuesdayPoisonXRATRMMUEFIagentic-AI','AI-governance','supply-chain','cloud-exposure','CISeCardinfostealerlua-loadermacOS-malwareoauth-spoofingphishingransomwaresecure-boot-bypasstruetype-fontvulnerabilities

What happened

A broad set of Infosecurity Magazine reports covering active campaigns, high-impact vulnerabilities and policy shifts. Notable items include innovative phishing (a Lua loader hidden as a TrueType font, seasonal eCard lures deploying RMM, Evilginx operators exposed), new macOS malware/stealers (ClickLock, CrashStealer) and Windows threats (GodDamn ransomware dropping the PoisonX kernel driver, GigaWiper). Security research highlights AI misuse risks (single-prompt GPT-5.5 enabling full attack chains, agentic AI accelerating cloud compromise, GhostApproval symlink flaw in AI coding assistants) и

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
70623983d9288b621bc353555356f95f086efbd6c0490e37dd4f7c94e7b1aacf
Enrichment time
2026-07-16T20:52:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.