Archive for October 5, 2026

Guest Post – Flirt as an attack vector: The most expensive date you’ll never go on

Posted in Commentary with tags on October 5, 2026 by itnerd

If you think seduction as a tool for data gathering belongs solely in James Bond movies, think again. Cybercriminals are actively using flirtation and romance as attack vectors.

The FBI recently issued a public warning: Scammers are hijacking accounts to steal intimate content and sell it on criminal marketplaces or to blackmail victims, both adults and minors. The perpetrators pose as romantic interests to manipulate targets into revealing credentials, clicking malicious links, or sharing sensitive material.

A calculated emotional investment

“For an attacker, technical breaches are usually costly. Emotional ones are nearly free — they require only patience. Instead of investing in tools and code, criminals spend a week or two on conversations and compliments, creating the illusion of mutual understanding. When the trust or attraction is established, things can quickly go downhill,” says Deividas Ambrazevicius, an engineering manager at NordPass.

Ambrazevicius shared the story of a man who recently met a woman on vacation. They had a great time, and by day four, he received a link with a note: “Here’s our photo album, just for you.” Ten minutes later, his own personal photos, videos, sensitive files, and everything from active login sessions to internal documents were in someone else’s hands. No password was stolen — trust was. The victim clicked on the alleged link to a photo album and installed the malware himself, blindsided by emotions and a vacation romance.

Common romantic attack vectors include:

  • Flirtation as an opener. Emotional closeness dulls critical thinking. A link from a romantic interest gets scrutinized far less than one from your bank.
  • Fake relationships. Long-term emotional investment makes a single request — for money, photos, or credentials — feel natural.

“The weakest link isn’t the password — it’s the desire to be noticed. It’s also a risk for organizations. They must train employees to recognize emotional manipulation, not just fake banking emails. A romantic scam targeting an employee can become a gateway into corporate infrastructure. The most sophisticated firewall won’t help if an employee hands over credentials to someone they trust because of an emotional attachment,” says Ambrazevicius.

Park Place Technologies Booking Interviews at Gartner IT Symposium / Xpo 2026

Posted in Commentary with tags on October 5, 2026 by itnerd
WhoPark Place Technologies, a leading global IT infrastructure services firm
WhatThe company will showcase solutions designed to help organizations scale AI infrastructure more efficiently
WhereGartner IT Symposium / Xpo 2026 in Orlando, booth #449
WhenOctober 19 – 22, 2026 during exhibition hours
DetailsVisitors to booth #449 will experience a live liquid cooling demonstration and connect with experts on GPU-powered infrastructure, data center optimization and strategies for supporting AI growth without increasing IT spend.
RSVPEditorial briefings, as well as demos of the company’s liquid cooling solutions, are being scheduled for reporters attending the conference. Please contact Henry Feintuch (914-548-6924) or Liz Savery (917-805-4581) or parkplacetech@feintuchpr.com via email to reserve an interview slot.

:

:           

:         

:           

:        

:          

Hacker claims live access to SMS data linked to Airbnb, Uber, PayPal, Booking.com and Google

Posted in Commentary with tags on October 5, 2026 by itnerd

A hacker is selling 54 million records allegedly linked to Airbnb, Uber, PayPal, Booking.com, and Google.

The threat actor, known as Marx, claims to have live access to the source of the data, potentially allowing them to intercept sensitive communications, including authentication codes, as they reach users.

Cybernews researchers looked at the claims, here’s what they found:

  • The samples of data appear to originate from a single third-party SMS service.
  • The samples contain phone numbers and mobile carrier information, while the alleged Uber data also includes names of people who booked rides. The message contents seem to be heavily stripped.
  • The samples examined appear geographically limited to India and Oman, and researchers could not determine the full scope of the alleged breach.

If proven to be legitimate, such exposed data could result in increased risks of phishing attacks and, in some cases, account takeovers.

Here’s the full investigation:

https://cybernews.com/security/airbnb-uber-google-data-breach-claims