4 posts

News

Diagram of an adversary-in-the-middle phishing attack: a user enters credentials on a fake website, which passes them to the attacker, who uses them on the real website

Anatomy of a LinkedIn Job Scam

Carlos Finos ―

From the first message to the fake login page, a step by step look at how scammers turn career aspirations into phishing attacks. An InMail offering a BlackRock advisory seat. An InMail arrived on LinkedIn at 1:03 PM offering a Strategic Advisor seat on BlackRock’s Executive Committee. Four to six hours a month. An annual retainer between $190,000 and $275,000. The sender introduced herself as a

News opsec Scam rekt social engineering 1password
Trezor Brevo breach blog cover — fake 'Critical Security Alert: STM32 Entropy Bug' phishing email that passed SPF, DKIM, and DMARC

Trezor: 347,000 Users Phished After Attackers Breached Its Email Provider.

Carlos Finos ―

On September 9th, attackers compromised Brevo (the email platform behind Trezor's newsletter) and sent a fake security alert to roughly 347,000 subscribers. Trezor wasn't the only one hit: BitBox and CoinTracking got caught in the same net. The email looked legitimate to subscribers. It came from the official help@trezor.io address, with headers referring to mailing.trezor.io, and it passed standard SPF, DKIM,

News opsec password manager rekt Scam social engineering 1password infostealers
Opsek graphic on a YubiKey 5C reading "A synced passkey no longer qualifies," announcing OpenAI's physical security key requirement for Trusted Access for Cyber accounts and how to enroll in

OpenAI now requires security keys for TAC members: how to enroll in Advanced Account Security

Carlos Finos ―

If you are part of OpenAI's Trusted Access for Cyber (TAC) program, there is a new requirement to act on. From October 1st, 2026 (previously Sept 1st), individual TAC members must turn on Advanced Account Security (AAS) and sign in with a physical security key. A passkey synced through a password manager will not qualify. This guide covers what TAC is, what AAS changes on your account, which

1password credentials News password manager
Signal Secure Backups: how to set them up and where to store the recovery key

Signal Secure Backups: how to set them up and where to store the recovery key

Carlos Finos ―

Signal used to have one hard rule: your messages lived on your device and nowhere else. Lose the phone, lose the history. That changed. Signal Secure Backups are now live on Android and iOS. They are end-to-end encrypted, opt-in, and Signal cannot read them. If your Signal threads touch treasury approvals, deployment coordination or incident response, this is worth ten minutes of your attention. Setup takes five.

News Scam rekt 1password

Stay in the loop

Subscribe to get the latest updates, straight to your inbox.