[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fZe8rSHO2X1Q5ANB2dNpGLXijbVQ4nED2tSSxBLClg84":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"4f340846-655c-4cac-b65d-e806660cad14","sophisticated-resume-phishing-campaign-exploits-human-trust","3ac00f94-e45a-44c0-aab6-14dee76544cf","Sophisticated Resume Phishing Campaign Exploits Human Trust","The FAUX#ELEVATE campaign demonstrates how attackers exploit human psychology by disguising malware as legitimate resume documents to bypass technical security controls. Employees opened what appeared to be job applications, unknowingly executing obfuscated VBScript that established persistent access within 25 seconds. The attack's success relied on social engineering rather than technical vulnerabilities, highlighting that humans remain the weakest link in cybersecurity. By abusing trusted services like Dropbox and compromised WordPress sites, the attackers evaded detection while stealing credentials and deploying cryptocurrency miners.","**Immediate actions:**\n- Organizations should implement strict email security policies that block or sandbox executable file types, including VBScript files, regardless of their apparent source\n\n**Long-term improvements:**\n- This attack could have been prevented through comprehensive security awareness training focusing on email attachment risks and social engineering tactics\n- Regular phishing simulation exercises specifically targeting HR and recruiting staff would help build resistance to resume-based social engineering attacks\n\n**Detection measures:**\n- Application whitelisting and endpoint detection systems could prevent unauthorized script execution, while network segmentation would limit lateral movement if initial compromise occurs",[12,13,14,15,16,17],"CIS Control 14","CIS Control 7","CIS Control 2","NIST SP 800-53 AT-2","NIST SP 800-53 AC-6","NIST CSF PR.AT-1","published","2026-03-25T03:06:47.602204+00:00","2026-03-25T03:06:47.511+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F03\u002Fhackers-use-fake-resumes-to-steal.html","hackers-use-fake-resumes-to-steal-enterprise-credentials-and-deploy-crypto-miner","Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":33,"name":34,"slug":35,"description":36,"color":37},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]