Phishing Campaign Hides Lua Loader as TrueType Font File
2026-07-16T20:52:20Z•70623983d9288b621bc353555356f95f086efbd6c0490e37dd4f7c94e7b1aacf
AI-misuseCVE-volumeClickLockCrashStealerEntra-IDEvilginxGPT-5.5GodDamnMFA-bypassMicrosoft-patch-tuesdayPoisonXRATRMMUEFIagentic-AI','AI-governance','supply-chain','cloud-exposure','CISeCardinfostealerlua-loadermacOS-malwareoauth-spoofingphishingransomwaresecure-boot-bypasstruetype-fontvulnerabilities
What happened
A broad set of Infosecurity Magazine reports covering active campaigns, high-impact vulnerabilities and policy shifts. Notable items include innovative phishing (a Lua loader hidden as a TrueType font, seasonal eCard lures deploying RMM, Evilginx operators exposed), new macOS malware/stealers (ClickLock, CrashStealer) and Windows threats (GodDamn ransomware dropping the PoisonX kernel driver, GigaWiper). Security research highlights AI misuse risks (single-prompt GPT-5.5 enabling full attack chains, agentic AI accelerating cloud compromise, GhostApproval symlink flaw in AI coding assistants) и
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 70623983d9288b621bc353555356f95f086efbd6c0490e37dd4f7c94e7b1aacf
- Enrichment time
- 2026-07-16T20:52:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.