1. X
  2. Arsen Security
Log inSign up
Arsen Security
297 posts
Arsen Security profile banner
user avatar

Arsen Security

@arsen
πŸ›‘οΈ Security Awareness for the age of AI β€” ✨ AI-driven vishing, smishing, and phishing β€” 🌐 arsen.co
πŸ‡ΊπŸ‡Έ USA πŸ‡¬πŸ‡§ UK πŸ‡«πŸ‡· France
arsen.co/en
Joined March 2020
203
Following
363
Followers
RepliesRepliesMediaMedia
  • user avatar
    Arsen Security
    @arsen
    Aug 7
    Citadel, Two Sigma, Point72 and Millennium were targeted in a coordinated voice phishing campaign. No malware. No zero-day. Attackers called employees and asked for access. Read the full breakdown πŸ‘‡
    Hedge Funds Hit by AI Vishing Attacks: What CISOs Must Do
    Hedge Funds Hit by AI Vishing Attacks: What CISOs Must Do
    From arsen.co
  • user avatar
    Arsen Security
    @arsen
    Aug 3
    πŸ”₯ This week in the news: - @binance's CSO: employees who repeatedly fail phishing tests will be fired! - @CrowdStrike flags surge in vishing - @okta shares a full BTS of a vishing operation - @ChatGPT joins the top 10 most impersonated brands in phishing
    Weekly Cyber Digest - Week of August 3, 2026
    From linkedin.com
  • user avatar
    Arsen Security
    @arsen
    Jul 20
    ClickFix and vishing attacks are evolving fast, making social engineering an ever growing threat. See the latest campaigns uncovered by @msftsecurity, @GroupIB & @kaspersky; and how @arsen helps train your team. πŸ‘‡
    Weekly Cyber Digest - Week of July 20, 2026
    From linkedin.com
  • user avatar
    Arsen Security
    @arsen
    Jul 10
    🚨 @okta details a vishing campaign where @Microsoft365 users are tricked into enrolling attacker-controlled Entra passkeys. Time to test these workflows with company-scale vishing simulations. πŸ‘‡
    okta.com
    Vishing actors target Entra passkey enrollment | Okta Threat Intelligence
  • user avatar
    Arsen Security
    @arsen
    Jul 8
    πŸ’‘ClickFix is a type of social engineering attack that makes people run malware on their own without the attacker needing to use an exploit. Learn more: arsen.co/en/resources/c…
    user avatar
    Unit 42
    @Unit42_Intel
    Jul 6
    We are tracking a MaaS #ClickFix operation using Polygon #blockchain as a resilient C2 config store. So far, 130+ compromised sites with 15 rotating C2s. Victim telemetry is periodically exfiltrated and stage 3 execution drops an infostealer. Details at bit.ly/4fmKZ8g
    Code snippets from left to right: "Blockchain for C2 fetching" shows JavaScript code for obtaining servers and fetching data from a blockchain. "Screenshot Exfiltration" includes code for capturing and sending screenshots to a server. "Dynamic Clipboard Payload Injection" demonstrates code for injecting and executing clipboard content. Each section is annotated to highlight its purpose.
    The image displays a screenshot of computer code with annotations. It includes highlighted text pointing to the "Rotating C2 domains," "ClickFix Lure," and "Clipboard payloads."
    The image shows a screenshot of the JokerStat operator login page. It features fields for email address and password and a human verification challenge. Text annotations note "One of the 15 C2 domains," "Every C2 domain runs the same clone," and "Support for MaaS kit." A smaller overlay mentions Telegram support.

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
TermsΒ·PrivacyΒ·CookiesΒ·AccessibilityΒ·Ads InfoΒ·Β© 2026 X Corp.