Huff Data Systems
Business Cybersecurity and Managed IT Services. Helping Businesses Reduce RISK with Cybersecurity. IT that works for you..
Follow for the latest Business Cybersecurity News, Tips and Updates. Started in 2001, ComputerMan Group is a complete technology solution provider. We are 100% committed to making sure business owners have the most reliable and professional IT service in Victoria, TX. Our team of talented IT professionals can solve your IT nightmares once and for all.
09/23/2026
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain."
"While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim's inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed," Steven Masada, associate general counsel and general manager at Microsoft's Digital Crimes Unit, said.
"The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action."
“The stolen tokens are abused for email exfiltration and persistence, often by setting malicious inbox rules that conceal communications. In some cases, the tokens have also been abused to grant new devices access to a victim's inbox, thereby giving attackers an alternative pathway to maintaining long-term access.
The malicious lure, typically delivered via phishing attacks, shows the user a device code for the service that the threat actor wishes to access. The victim is then prompted to enter this code at the legitimate verification URL (e.g., microsoft.com/devicelogin) during the sign-in process.
Once the code is supplied, the authorization server issues access and refresh tokens to the attacker's client, granting them ongoing access under the victim's identity.”
https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises Microsoft disrupted EvilTokens after it was linked to more than 12,000 compromised inboxes across over 10,000 organizations.
09/23/2026
Tech Support Fraud Computer Pop-up Advertisements
Tech support fraud computer pop-up ads are designed to open a new window and switch to browser full screen mode so that they appear to be operating system alerts, instead of just websites. An example is shown in article..
When potential victims call the phone number listed on the pop-up, they are routed to a criminal in India who will attempt to defraud them using various scams.
How to Stop Tech Support Fraud - FVRO Since 2021, criminal groups in India have shifted from making outbound law enforcement impersonation phone calls to distributing call back phone numbers to potential tech support fraud victims via computer pop-up ads and e-mail messages. As a result, tech support fraud has since doubled to become th...
09/22/2026
Alert Number: I-090126-PSA | 01 September 2026
Malicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing
Since late 2025, malicious cyber actors have been targeting prominent victims, their family members, and personal acquaintances by directly messaging personal accounts with malicious links leveraging a technique known as "OAuth consent phishing."
https://www.ic3.gov/PSA/2026/PSA260901?
Internet Crime Complaint Center (IC3) | Malicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing Since late 2025, malicious cyber actors have been targeting prominent victims, their family members, and personal acquaintances by directly messaging personal accounts with malicious links leveraging a technique known as "OAuth consent phishing."
09/21/2026
If your business has EDR installed your covered right? Well Malware and fake versions of popular programs can kill EDR and then exploit systems.. read on
“LastPass and Delphos Labs disclosed on September 17, 2026, that a malware campaign running since at least August 13 uses fake GitHub repositories impersonating LastPass Authenticator and dozens of other brands to install the Rapuncel infostealer. The attack's real weapon is a Microsoft-signed kernel driver that kills 145 antivirus and EDR tools by exploiting a loophole most people have never heard of: renaming a file changes its hash, and hash-based blocklists don't catch what they can't recognize.”
“What Rapuncel actually steals
Once the security tools are dead, Rapuncel gets to work. According to Bleeping Computer and daily.dev, it pulls credentials from 25 browsers, data from 30 cryptocurrency wallets, session tokens from Discord, Steam, and Telegram, the contents of Windows Credential Manager, documents containing words like "password," "seed," "wallet," or "recovery," screenshots from every connected monitor, and detailed system information.”
Fake GitHub Repos for LastPass and 39 Other Brands Are Pushing Malware That Kills 145 Security Tools LastPass and Delphos Labs disclosed on September 17, 2026, that a malware campaign running since at least August 13 uses fake GitHub repositories impersonating LastPass Authenticator and dozens of other brands to install the Rapuncel infostealer. The attack's real weapon is a Microsoft-signed kernel...
Why MFA/2FA is not an end all for cybersecurity and layered approach with Managed SOC monitoring and response like the one HDS has in
place for clients is one of those important layers.
“The operation also exposed a TeamPCP member developing an AI-assisted zero-day capable of bypassing two-factor authentication in widely used login software.”
—
“🚨 Google reveals undercover Mandiant analyst infiltrated TeamPCP during massive supply-chain hacking spree
Google says an undercover Mandiant analyst infiltrated TeamPCP's inner circle as the hacking group compromised open-source software and ultimately breached more than 1,000 companies.
⠀
The analyst gained access to TeamPCP's core "CanisterWorm" chat in March, joining a group of roughly 12 members and watching the operation from the inside.
⠀
The mole also gained access to a server containing credentials stolen from victims, including usernames, passwords, and access tokens.
Google used that visibility to alert cloud and technology providers, revoke compromised credentials, and send hundreds of notifications to affected organizations.
⠀
The operation also exposed a TeamPCP member developing an AI-assisted zero-day capable of bypassing two-factor authentication in widely used login software.
Google obtained the exploit code, verified that it worked after minor modifications, and privately notified the developer so the vulnerability could be patched.
⠀
TeamPCP's campaign compromised hundreds of open-source packages and affected organizations including GitHub, Mistral AI, Mercor, the European Commission, and employee devices at OpenAI.
⠀
Google says operational security mistakes later helped investigators identify an alleged TeamPCP member, with information passed to the FBI.
Two Australians accused of being principal participants in TeamPCP were arrested last month.”
09/17/2026
Reminder to talk to your family about this.. tell them to hang up and call you or only the official police sherifs office phone number.
I normally just advise people to have their parents call them then their kids can help. Reason is this may just be part of the scam and this is just one type of scam.
Some of these scams also involve sending packages or people to homes via uber etc to collect.
Scammers impersonating Victoria County Sheriff's Office target residents A local victim lost more than $1,200 after scammers posing as sheriff's office officials threatened arrest and demanded payment
09/15/2026
Share with your parents and grandparents..
Help protect your loved ones from tech support scammers, who frequently target older Americans. They want you to pay them to fix a problem that does not exist. Each year, these scams are responsible for over $1 billion in losses.
Learn more: https://www.fbi.gov/video-repository/elder-fraud-impersonation-scams-092524.mp4/view
09/14/2026
A familiar website does not mean every ad on it is safe.
An employee browses Reddit or another popular website during lunch. A malicious ad leads to a convincing pop-up claiming something is broken and offering instructions to “fix” it.
The employee follows the instructions, copies a command, and runs it on their work computer.
They think they are helping. Instead, they could be giving a cybercriminal remote access and a starting point to reach company systems, files, and sensitive data.
Would your current cybersecurity stop that? And if it did not, who would notice?
Would someone investigate the suspicious activity immediately? Or could an attacker spend three months inside your network without anyone realizing something was wrong?
A computer that appears to be working normally does not necessarily mean it is secure. And “we haven’t noticed anything” is not the same as “we have verified that nothing is wrong.”
This is why IT management and cybersecurity cannot be treated as a set-it-and-forget-it service. Employee education matters, but your protection also needs to account for someone making a mistake.
Prevention, ongoing monitoring, testing, and a clear response plan all matter.
Ask your current provider: “If an employee followed a malicious pop-up’s instructions today, what would block it, how would you detect it, and who would respond?”
The answer should be more specific than “You have antivirus.”
Not sure? In about 20 min we’ll show you with a simple yes/no.
Source:
HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation | Hudson Rock HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation…
09/10/2026
Approximately $52 million of cryptocurrency involved in scam money laundering was restrained in one day, bringing the total restrained by the Scam Center Strike Force to approximately $938 million.
WASHINGTON – U.S. Attorney Jeanine Ferris Pirro, together with major federal law enforcement and interagency partners, announced actions taken by the Department of Justice’s Scam Center Strike Force to secure America against Southeast Asian cryptocurrency-related fraud and scams. The Strike Force and the Department of the Treasury took coordinated actions against Xinbi Guarantee (“Xinbi”), an illicit marketplace for scam services, and the Strike Force deployed to Madagascar to assist in the taking down of 13 Chinese-run scam compounds.
Approximately $52 million of cryptocurrency involved in scam money laundering was restrained in one day, bringing the total restrained by the Scam Center Strike Force to approximately $938 million.
Scam Center Strike Force Conducts Seizures of Chinese-Run Illicit Scammer Marketplace, and Restrains $52 Million in Laundered Crypto Scammer Funds In One Day U.S. Attorney Jeanine Ferris Pirro, together with major federal law enforcement and interagency partners, announced actions taken by the Department of Justice’s Scam Center Strike Force to secure America against Southeast Asian cryptocurrency-related fraud and scams. The Strike Force and the Depar...
09/09/2026
Former ATT employe sentenced for selling access for SIM Swapping attacks to victims cell phone numbers, then criminals could use txt based 2FA codes reset passwords gain access to crypto, bank and other accounts.
For reasons such as this Microsoft is ending support for txt bases two factor codes, App Based MFA with number matching is more secure and resistant to these types of cyber crimes.
“SIM swapping” is a technique in which a criminal fraudulently induces a mobile carrier to reassign a cell phone number from the legitimate subscriber’s Subscriber Identity Module (SIM) card to a SIM card controlled by another without the legitimate subscriber’s authorization or knowledge. This process allows a criminal to intercept two-factor authentication codes sent to the victim via phone call or text message, and to gain access to the victim’s various accounts.
A former Oregon-based AT&T Store employee was sentenced today to 16 months in federal prison for selling his access to his employer’s network to a hacker by “SIM swapping” customers – fraudulently reassigning customers’ cell phone numbers – so the hacker could take control of the victims’ bank accounts and steal their money, causing nearly $600,000 in intended losses.
Kenneth Carter, 44, of Portland, Oregon, was sentenced by United States District Judge Stanley Blumenfeld, Jr., who also ordered him to pay $99,528 in restitution. Carter pleaded guilty on March 24 to one count of conspiracy to commit wire fraud and bank fraud.
“SIM swapping” is a technique in which a criminal fraudulently induces a mobile carrier to reassign a cell phone number from the legitimate subscriber’s Subscriber Identity Module (SIM) card to a SIM card controlled by another without the legitimate subscriber’s authorization or knowledge. This process allows a criminal to intercept two-factor authentication codes sent to the victim via phone call or text message, and to gain access to the victim’s various accounts.
Additional details: https://www.justice.gov/usao-cdca/pr/oregon-man-sentenced-16-months-federal-prison-abusing-his-role-mobile-phone-store-give
Click here to claim your Sponsored Listing.
Category
Contact the business
Telephone
Website
Address
101 W. Goodwin Avenue #1118
Victoria, TX
77901