
Experts flag Bank of America phishing scam that hands your device over to hackers
THE SO WHAT
A phishing flow that convinces users to install ScreenConnect is a reminder that endpoint takeover still starts with basic social engineering, not zero-days. If your org uses remote support tools, tighten policies this week — whitelist vendors, lock install rights, and train staff that banks do not ask for remote access.
READ THE SOURCE
MORE FROM THE WIRE
Deep & Emerging TechThe Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one
A credential-stealing worm shipped through a library served ~127 million times a week shows that “trusted maintainer” is now a prime attack surface. If you ship on Node or similar ecosystems, lock down your dependency tree and treat maintainer account security as part of your own security posture.
Deep & Emerging TechHackers use fake Adobe and Zoom updates to load malware onto victim devices — here's what to look out for
SMOKE#SCREEN leaning on fake Adobe and Zoom updates is another reminder that user trust in familiar brands is the real exploit. Tighten update policies — centralize software distribution and train teams to treat unsolicited “urgent updates” as phishing until proven otherwise.
Deep & Emerging TechThe RAM Crisis Is Forcing PC Makers to Team Up With a Company the U.S. Hates
When RAM shortages push OEMs toward politically sensitive suppliers, supply chain risk becomes a board topic, not a procurement detail. If your products depend on high-density memory, map your exposure now — geopolitics may hit your BOM before prices normalize.
Deep & Emerging TechNvidia’s stock is basking in the glow of a high-profile endorsement
A public commitment from SpaceX to use only Nvidia chips for its AI stack reinforces Nvidia as the default for high-stakes, vertically integrated deployments. If you’re betting on alternative accelerators, your pitch now has to overcome not just perf-per-dollar but ecosystem gravity and perceived execution risk.