REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2333 reports · page 55 of 59
ars_security · tlp:amber · 4/22/2026, 7:32:56 PM
Microsoft issues emergency update for macOS and Linux ASP.NET threat When authentication fails, things can go very, very wrong. Microsoft released an emergency patch for its ASP.NET Core to fix a high-severity vulnerability that allows unauthenticated attackers to gain SYSTEM privileges on devices that use the Web development framework to run Linux or macOS apps. The software maker said Tuesday evening that the vulnerability, tracked as CVE-2026-40372, affects versions 10.0…
Read original ↗https://arstechnica.com/security/2026/04/microsoft-issues-emergency-update-for-macos-and-linux-asp-net-threattalos · tlp:amber · 4/22/2026, 10:00:34 AM
IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist Phishing reemerged as the most observed means of gaining initial access, accounting for over a third of the engagements where initial access could be determined. Phishing has not been the top vertical for initial access since Q2 2025. Phishing reemerged as the most observed means of gaining initial access, accounting for over a third of the engagements wher…
unit42 · tlp:amber · 4/22/2026, 10:00:22 AM
When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks Unit 42 research reveals AirSnitch attacks bypass WPA2/3 Wi-Fi encryption and client isolation, exposing critical infrastructure vulnerabilities. The post When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks appeared first on Unit 42 . When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks Menu Tools ATOMs Security Consulting About Us Under Attack…
Read original ↗https://unit42.paloaltonetworks.com/air-snitch-enterprise-wireless-attacksars_security · tlp:amber · 4/21/2026, 9:40:41 PM
Mozilla: Anthropic's Mythos found 271 security vulnerabilities in Firefox 150 CTO says new AI model is "every bit as capable" as world's best security researchers. Earlier this month, Anthropic said its Mythos Preview model was so good at finding cybersecurity vulnerabilities that the company was limiting its initial release to "a limited group of critical industry partners." Since then, debate has raged over whether the model presages an era of turbocharged AI-aided hackin…
Read original ↗https://arstechnica.com/ai/2026/04/mozilla-anthropics-mythos-found-271-zero-day-vulnerabilities-in-firefox-150ars_security · tlp:amber · 4/21/2026, 12:35:20 PM
Contrary to popular superstition, AES 128 is just fine in a post-quantum world A stubborn misconception is hampering the already hard work of quantum readiness. With growing focus on the existential threat quantum computing poses to some of the most crucial and widely used forms of encryption, cryptography engineer Filippo Valsorda wants to make one thing absolutely clear: Contrary to popular mythology that refuses to die, AES 128 is perfectly fine in a post-quantum world. …
Read original ↗https://arstechnica.com/security/2026/04/contrary-to-popular-superstition-aes-128-is-just-fine-in-a-post-quantum-worldtalos · tlp:amber · 4/21/2026, 12:29:49 PM
[Podcast] It's not you, it's your printer: State-sponsored and phishing threats in 2025 In this episode of Talos Takes, Amy and Martin Lee unpack state-sponsored and phishing trends from the 2025 Talos Year in Review. In this episode, we unpack state-sponsored and phishing trends from the 2025 Talos Year in Review. Amy and Martin Lee explore the alarming rise of internal phishing campaigns that bypass traditional perimeter defenses, including the widespread weaponization of…
Read original ↗https://blog.talosintelligence.com/podcast-its-not-you-its-your-printer-state-sponsored-and-phishing-threats-in-2025talos · tlp:amber · 4/21/2026, 12:00:08 PM
Phishing and MFA exploitation: Targeting the keys to the kingdom In 2025, attackers increasingly targeted weaknesses in multi-factor authentication (MFA) workflows, and phishing attacks leveraged valid, compromised credentials to launch lures from trusted accounts. The trends focused entirely on trust, or the lack thereof, in everyday business operations. In 2025, attackers increasingly targeted weaknesses in multi-factor authentication (MFA) workflows, and phishing attacks…
Read original ↗https://blog.talosintelligence.com/phishing-and-mfa-exploitation-targeting-the-keys-to-the-kingdomhuggingface_blog · tlp:amber · 4/21/2026, 10:09:58 AM
QIMMA قِمّة ⛰: A Quality-First Arabic LLM Leaderboard QIMMA قِمّة ⛰: A Quality-First Arabic LLM Leaderboard Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles QIMMA قِمّة ⛰: A Quality-First Arabic LLM Leaderboard Community Article Published April 21, 2026 Upvote 12 +6 Leen AlQadi LeenAlQadi Follow tiiuae Ahmed Alzubaidi amztheory Follow tiiuae Mohammed Alyafeai Alyafeai Follow tiiuae Maitha Alhammadi MaithaAlhammadi Follow…
Read original ↗https://huggingface.co/blog/tiiuae/qimma-arabic-leaderboardtalos · tlp:amber · 4/21/2026, 10:00:29 AM
Bad Apples: Weaponizing native macOS primitives for movement and execution Cisco Talos documents several macOS living-off-the-land (LOTL) techniques, demonstrating that native pathways for movement and execution remain accessible to those who understand the underlying architecture. As macOS adoption grows among developers and DevOps, it has become a high value target; however, native "living-off-the-land" (LOTL) techniques for the platform remain significantl…
Read original ↗https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-executioneset · tlp:amber · 4/21/2026, 8:55:00 AM
New NGate variant hides in a trojanized NFC payment app ESET researchers discover another iteration of NGate malware, this time possibly developed with the assistance of AI New NGate variant hides in a trojanized NFC payment app Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat reports WeLiveScience FEA…
Read original ↗https://www.welivesecurity.com/en/eset-research/new-ngate-variant-hides-in-a-trojanized-nfc-payment-apptrend_micro · tlp:amber · 4/21/2026, 12:00:00 AM
Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories Our research on Void Dokkaebi’s operations uncovered a campaign that turns infected developer repositories into malware delivery channels. By spreading through trusted workflows, organizational codebases, and open-source projects, the threat can scale from a single compromise to a broader supply chain risk. Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories | T…
Read original ↗https://www.trendmicro.com/en_us/research/26/d/void-dokkaebi-uses-fake-job-interview-lure-to-spread-malware-via-code-repositories.htmlhuggingface_blog · tlp:amber · 4/21/2026, 12:00:00 AM
AI and the Future of Cybersecurity: Why Openness Matters AI and the Future of Cybersecurity: Why Openness Matters Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles AI and the Future of Cybersecurity: Why Openness Matters Published April 21, 2026 Update on GitHub Upvote 37 +31 Margaret Mitchell meg Follow Yacine Jernite yjernite Follow Clem 🤗 clem Follow What is Mythos? How Openness Can Be a Structural Advantage Building D…
Read original ↗https://huggingface.co/blog/cybersecurity-opennesscheckpoint_research · tlp:amber · 4/20/2026, 2:24:24 PM
20th April – Threat Intelligence Report For the latest discoveries in cyber research for the week of 20th April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Booking.com, the Amsterdam-based travel platform, has confirmed a data breach after unauthorized parties accessed reservation data linked to some customers. Exposed information included names, email addresses, phone numbers, physical addresses, and booking […] The post 20th April – Th…
Read original ↗https://research.checkpoint.com/2026/20th-april-threat-intelligence-reportcheckpoint_research · tlp:amber · 4/20/2026, 12:55:53 PM
DFIR Report – The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy Key Points The Gentlemen RaaS The Gentlemen ransomware‑as‑a‑service (RaaS) operation is a relatively new group that emerged around mid‑2025. The operators advertise their services across multiple underground forums, promoting their ransomware platform and inviting penetration testers (and other technically skilled actors) to join as affiliates. The RaaS provides affiliates with multi‑OS lockers for Windows…
Read original ↗https://research.checkpoint.com/2026/dfir-report-the-gentlemenunit42 · tlp:amber · 4/20/2026, 10:00:14 AM
Fracturing Software Security With Frontier AI Models Unit 42 finds frontier AI models enhance vulnerability discovery, acting as full-spectrum security researchers. They enable autonomous zero-day discovery and faster N-day patching. The post Fracturing Software Security With Frontier AI Models appeared first on Unit 42 . Fracturing Software Security With Frontier AI Models Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Insights General G…
Read original ↗https://unit42.paloaltonetworks.com/ai-software-security-riskseset · tlp:amber · 4/20/2026, 9:00:00 AM
What the ransom note won’t say An attack is what you see, but a business operation is what you’re up against Ransomware’s back office: What the ransom note won’t say Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat reports WeLiveScience FEATURED Ukraine crisis – Digital security resource center WeLiveP…
Read original ↗https://www.welivesecurity.com/en/ransomware/what-ransom-note-doesnt-saytrend_micro · tlp:amber · 4/20/2026, 12:00:00 AM
The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment Variables An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defenses and amplify blast radius. This article examines the attack chain, underlying design tradeoffs, and what it reveals about modern PaaS and software supply chain risk. The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden…
Read original ↗https://www.trendmicro.com/en_us/research/26/d/vercel-breach-oauth-supply-chain.htmlunit42 · tlp:amber · 4/17/2026, 10:35:07 PM
Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17) Unit 42 details recent Iranian cyberattack activity, sharing direct observations of phishing, hacktivist activity and cybercrime. We include recommendations for defenders. The post Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17) appeared first on Unit 42 . Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17) Menu Tools ATOMs Security Consulting About Us U…
Read original ↗https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026ars_security · tlp:amber · 4/17/2026, 9:28:35 PM
US-sanctioned currency exchange says $15 million heist done by "unfriendly states" Grinex says needed hacking resources "available exclusively to... unfriendly states." Grinex, a US-sanctioned cryptocurrency exchange registered in Kyrgyzstan, said it’s halting operations after experiencing a $13 million heist carried out by “western special services” hackers. Researchers from TRM, which has confirmed the theft, put the value of stolen assets at $15 million after discovering…
Read original ↗https://arstechnica.com/security/2026/04/russia-friendly-exchange-says-western-special-service-behind-15-million-cyberattackchainalysis · tlp:amber · 4/17/2026, 9:14:02 PM
Sanctioned Russia-Linked Exchange Grinex Suspends Operations Following Alleged Cyberattack TL;DR Grinex, the sanctioned successor to the Russian exchange Garantex, suspended operations yesterday following a claimed 1 billion ruble ($13.7… The post Sanctioned Russia-Linked Exchange Grinex Suspends Operations Following Alleged Cyberattack appeared first on Chainalysis . Sanctioned Russia-Linked Exchange Grinex Suspends Operations Chainalysis Products Crypto Investigatio…
Read original ↗https://www.chainalysis.com/blog/sanctioned-grinex-exchange-suspends-operationsars_security · tlp:amber · 4/17/2026, 11:00:50 AM
Recent advances push Big Tech closer to the Q-Day danger zone Here's which players are winning the race to transition to post-quantum crypto. Sometime around 2010, sophisticated malware known as Flame hijacked the mechanism that Microsoft used to distribute updates to millions of Windows computers around the world. The malware—reportedly jointly developed by the US and Israel—pushed a malicious update throughout an infected network belonging to the Iranian government. The l…
Read original ↗https://arstechnica.com/security/2026/04/while-some-big-tech-players-accelerate-pqc-readiness-others-stay-the-coursetrail_of_bits · tlp:amber · 4/17/2026, 11:00:00 AM
We beat Google’s zero-knowledge proof of quantum cryptanalysis Two weeks ago, Google’s Quantum AI group published a zero-knowledge proof of a quantum circuit so optimized, they concluded that first-generation quantum computers will break elliptic curve cryptography keys in as little as 9 minutes. Today, Trail of Bits is publishing our own zero-knowledge proof that significantly improves Google’s on all metrics. Our result is not due to some quantum breakthrough, but rather t…
Read original ↗https://blog.trailofbits.com/2026/04/17/we-beat-googles-zero-knowledge-proof-of-quantum-cryptanalysiseset · tlp:amber · 4/17/2026, 9:00:00 AM
That data breach alert might be a trap Ignoring a real breach notification invites risk, but falling for a bogus one could be even worse. Stop reacting on autopilot. Why that next data breach alert could be a trap Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat reports WeLiveScience FEATURED Ukraine c…
Read original ↗https://www.welivesecurity.com/en/scams/data-breach-alert-might-be-trapunit42 · tlp:amber · 4/16/2026, 10:00:13 PM
A Deep Dive Into Attempted Exploitation of CVE-2023-33538 CVE-2023-33538 allows for command injection in TP-Link routers. We discuss exploitation attempts with payloads characteristic of Mirai botnet malware. The post A Deep Dive Into Attempted Exploitation of CVE-2023-33538 appeared first on Unit 42 . A Deep Dive Into Attempted Exploitation of CVE-2023-33538 Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Vulnerabilities V…
Read original ↗https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538talos · tlp:amber · 4/16/2026, 7:00:24 PM
Foxit, LibRaw vulnerabilities Cisco Talos’ Vulnerability Discovery & Research team recently disclosed one Foxit Reader vulnerability, and six LibRaw file reader vulnerabilities. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy . For Cisco Talos’ Vulnerability Discovery & Research team recently disclosed on…
Read original ↗https://blog.talosintelligence.com/foxit-libraw-vulnerabilitiestalos · tlp:amber · 4/16/2026, 6:00:31 PM
The Q1 vulnerability pulse Thor provides an overview of the Q1 2026 vulnerability statistics, highlighting key trends in legacy CVEs and the evolving impact of AI on the threat landscape. Welcome to this week’s edition of the Threat Source newsletter. The first quarter of 2026 passed faster than a misconfigured firewall rule gets exploited — and the last few weeks have been firmly stamped with the "software supply chain compromise" la…
Read original ↗https://blog.talosintelligence.com/the-q1-vulnerability-pulsemandiant · tlp:amber · 4/16/2026, 2:00:00 PM
Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/defending-enterprise-ai-vulnerabilitieseset · tlp:amber · 4/16/2026, 12:00:00 PM
Supply chain dependencies: Have you checked your blind spot? Your biggest risk may be a vendor you trust. How can SMBs map their third-party blind spots and build operational resilience? Supply chain dependencies: Have you checked your blind spot? Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat report…
Read original ↗https://www.welivesecurity.com/en/business-security/supply-chain-dependencies-have-you-checked-your-blind-spothuggingface_blog · tlp:amber · 4/16/2026, 12:00:00 AM
Training and Finetuning Multimodal Embedding & Reranker Models with Sentence Transformers Training and Finetuning Multimodal Embedding & Reranker Models with Sentence Transformers Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles Training and Finetuning Multimodal Embedding & Reranker Models with Sentence Transformers Published April 16, 2026 Update on GitHub Upvote 70 +64 Tom Aarsen tomaarsen Follow Table of Cont…
Read original ↗https://huggingface.co/blog/train-multimodal-sentence-transformershuggingface_blog · tlp:amber · 4/16/2026, 12:00:00 AM
Ecom-RLVE: Adaptive Verifiable Environments for E-Commerce Conversational Agents Ecom-RLVE: Adaptive Verifiable Environments for E-Commerce Conversational Agents Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles Ecom-RLVE: Adaptive Verifiable Environments for E-Commerce Conversational Agents Published April 16, 2026 Update on GitHub Upvote 17 +11 Rahul Bajaj thebajajra Follow owlgebra-ai Jaya Nupur ai-queen Follow owlgebr…
Read original ↗https://huggingface.co/blog/ecom-rlvehuggingface_blog · tlp:amber · 4/16/2026, 12:00:00 AM
The PR you would have opened yourself The PR you would have opened yourself Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles The PR you would have opened yourself Published April 16, 2026 Update on GitHub Upvote 68 +62 Pedro Cuenca pcuenq Follow Awni Hannun awni Follow mlx-community TL;DR The advent of code agents What does this have to do with MLX? What we did How we did it Test harness How to use the Skill Next steps a…
Read original ↗https://huggingface.co/blog/transformers-to-mlxars_security · tlp:amber · 4/15/2026, 8:36:28 PM
"TotalRecall Reloaded" tool finds a side entrance to Windows 11's Recall database "The vault is solid. The delivery truck is not." Two years ago, Microsoft launched its first wave of “Copilot+” Windows PCs with a handful of exclusive features that could take advantage of the neural processing unit (NPU) hardware being built into newer laptop processors. These NPUs could enable AI and machine learning features that could run locally rather than in someone’s cloud, theoretica…
Read original ↗https://arstechnica.com/gadgets/2026/04/totalrecall-reloaded-tool-finds-a-side-entrance-to-windows-11s-recall-databasemandiant · tlp:amber · 4/15/2026, 2:00:00 PM
The German Cyber Criminal Überfall: Shifts in Europe's Data Leak Landscape Written by: Jamie Collier, Robin Grunewald Germany has reclaimed its position as a primary focus for cyber extortion in Europe. While data leak site (DLS) posts rose almost 50% globally in 2025, Google Threat Intelligence (GTI) data shows that the surge is hitting German infrastructure harder and faster than its regional neighbors, marking a significant return to the high-pressure levels previously ob…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/europe-data-leak-landscapehuggingface_blog · tlp:amber · 4/15/2026, 12:07:25 PM
Inside VAKRA: Reasoning, Tool Use, and Failure Modes of Agents Inside VAKRA: Reasoning, Tool Use, and Failure Modes of Agents Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles Inside VAKRA: Reasoning, Tool Use, and Failure Modes of Agents Enterprise Article Published April 15, 2026 Upvote 28 +22 Ankita Naik ankita-naik Follow ibm-research danish danish Follow ibm-research Ben Ben871 Follow ibm-research Anupama Murthi anup…
Read original ↗https://huggingface.co/blog/ibm-research/vakra-benchmark-analysishuggingface_blog · tlp:amber · 4/15/2026, 9:25:20 AM
Meet HoloTab by HCompany. Your AI browser companion. Meet HoloTab by HCompany. Your AI browser companion. Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles Meet HoloTab by HCompany. Your AI browser companion. Team Article Published April 15, 2026 Upvote 23 +17 Marc Thibault marc-thibault-h Follow Hcompany Pierre-Louis Cedoz plcedoz38 Follow Hcompany Hamza Benchekroun hamza-hcompany Follow Hcompany Kai Yuan h-kaiy Follow H…
Read original ↗https://huggingface.co/blog/Hcompany/holotabars_security · tlp:amber · 4/14/2026, 7:11:25 PM
UK gov's Mythos AI tests help separate cybersecurity threat from hype New model is the first AI system to complete a difficult multistep infiltration challenge. Last week, Anthropic announced it was restricting the initial release of its Mythos Preview model to "a limited group of critical industry partners," giving them time to prepare for a model that it said is "strikingly capable at computer security tasks." Now, the UK government's AI Security Institute (AISI) has publ…
Read original ↗https://arstechnica.com/ai/2026/04/uk-govs-mythos-ai-tests-help-separate-cybersecurity-threat-from-hypecheckpoint_research · tlp:amber · 4/13/2026, 1:11:17 PM
13th April – Threat Intelligence Report For the latest discoveries in cyber research for the week of 13th April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The Los Angeles Police Department has reported a data breach involving a digital storage system used by the L.A. City Attorney’s Office. The exposure included 7.7 terabytes and more than 337,000 files, […] The post 13th April – Threat Intelligence Report appeared first on Check Point …
Read original ↗https://research.checkpoint.com/2026/13th-april-threat-intelligence-reporttrend_micro · tlp:amber · 4/13/2026, 12:00:00 AM
Identity Protection in the AI Era Enterprises aiming to predict and mitigate human, machine, and AI‑agent risks at scale demand AI‑powered identity‑first security without compromise. Identity Protection in the AI Era | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping organizations navigate and thrive through a focused portfolio of cybersecurity businesses Learn more Leadership Team Le…
Read original ↗https://www.trendmicro.com/en_us/research/26/d/ai-era-identity-production.htmlchainalysis · tlp:amber · 4/10/2026, 4:46:24 PM
Iran’s Strait of Hormuz Crypto Toll: An Evolution of Tehran’s Expanding Use of Digital Assets TL;DR Bloomberg reported on April 1, 2026 that Iran’s Islamic Revolutionary Guard Corps (IRGC) was already extracting transit tolls from… The post Iran’s Strait of Hormuz Crypto Toll: An Evolution of Tehran’s Expanding Use of Digital Assets appeared first on Chainalysis . Iran's Strait of Hormuz Crypto Toll Chainalysis Products Crypto Investigations Investiga…
Read original ↗https://www.chainalysis.com/blog/iran-strait-of-hormuz-crypto-tolleset · tlp:amber · 4/10/2026, 9:00:00 AM
Recovery scammers hit you when you’re down: Here’s how to avoid a second strike If you’ve been a victim of fraud, you’re likely already a lead on a ‘sucker list’ – and if you’re not careful, your ordeal may be about to get worse. Recovery scammers hit you when you’re down: Here’s how to avoid a ‘second strike’ Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH A…
Read original ↗https://www.welivesecurity.com/en/scams/recovery-scammers-hit-when-down-avoid-second-strike