#informationsecurity

2026-02-05

To follow up on the earlier thread, the impersonation of AECOM HR part 2 continues with the malicious actors respond to my reply.

I had responded to the threat actor, providing availability for a conversation. The threat actor responded with the questions below at 0331 AM PT 2026-02-04. This should have been a big tell for me as the spoofed HR persona is located in Portland, OR and not likely working in the middle of the night.
Then when I had not responded, they replied to the same email thread with the same content at 1737 PM PT 2026-02-04. This is what triggered my further analysis and recognized the miscreant at work.
I posted the IOCs and details on my Github:
github.com/obrientg/Analysis/b

#jobsearch #fraud #impersonation #informationsecurity #abuse #risk #riskmanagement #gethired #hiring #threatintel #IOC #IOCs #gethired #hiring #threatlandscape #getFediHired #threatInteligence #cybersecurity #phishing

2026-02-05

Impersonation of AECOM HR - The malicious actors continue to target individuals on the search for their next job.

Yesterday I spent the afternoon writing up a response to (what I thought) a reach out by AECOM for potential roles with the company. Having crafted thoughtful responses to the questions, I went to reply –

And realized this was fake. This is a scammer.

The tell-tale signs I missed at first:
· The name not matching the email address
· Weird subject line
· The email coming from GMail rather than their aecom.com domain
· The work signature block including a LinkedIn profile URL
· Email interaction tracking URL

This sample was specifically targeted as they pulled background from LinkedIn regarding my background and experience, hence my blocking the other telltale signs.

These threat actors are using mailsuite [DOT] com a Gmail plugin to track their targeted individuals (aka the u.list-opt-center [DOT] com URL). This appears to be a legit service being used for malicious activities. I have reached out to Mailsuite but have not received a response.

They are impersonating a pamlevesque [AT] aecom.com; I have reached out on LinkedIn Pam Levesque to warn them & connect with their abuse team but have not received a response. I also reached out to multiple other individuals in InfoSec/Risk/Abuse roles at AECOM with no response.

#jobsearch #fraud #impersonation #informationsecurity #abuse #risk #riskmanagement #gethired #hiring #threatlandscape #getFediHired #threatIntel #threatInteligence #cybersecurity #phishing

The full documentation of the initial interaction is on my Github:
github.com/obrientg/Analysis/b

and my #Linkedin posting:
linkedin.com/posts/activity-74
#stinkedin

Astra Global Consultingastraglobalco
2026-02-05

Compliance ensures you meet regulations. Security ensures you survive real-world threats.

Too many organizations treat them as the same—and pay the price when audits pass but breaches happen.

Smart leaders integrate compliance + security into a single, risk-driven strategy focused on resilience, not just checklists.

But downtime, data loss, and lost trust can end a business.

Edwin G. :mapleleafroundel:EdwinG@mstdn.moimeme.ca
2026-02-05

Canada Computers now says around 1,300 customers were affected by the data breach

cbc.ca/news/business/canada-co
- - -
Ordinateurs Canada dit désormais que 1300 clients ont été touchés par la brèche de données

// Article en anglais //

#Canada #CanadaComputers #OrdinateursCanada #InfoSec #InformationSecurity #Cybersécurité

Brian Anderson (He/Him)btanderson@infosec.exchange
2026-02-04

If you do not acknowledge risk, you increase risk.
#InfoSec
#InformationSecurity

Brian Anderson (He/Him)btanderson@infosec.exchange
2026-02-04

If your customer support people/bots aren’t trained to answer basic questions about your service’s cybersecurity and privacy, please don’t bother me with your “we take your security and privacy seriously” letter.

#InfoSec
#InformationSecurity

Juliet (Ryel), Rollerskating Elf 🏳️‍⚧️julie@merida.hair
2026-02-03

Kaspersky dropped a bunch of IOCs for the Notepad++ compromise today. Worth checking out if you're a thrunter or incident responder.

https://securelist.com/notepad-supply-chain-attack/118708/

#CyberSecurity #InformationSecurity

BSides Saskatoon - 2026-09-26bsidesyxe@infosec.exchange
2026-02-02

Save the date!

Monday, September 28, 2026 - BSides Saskatoon is coming back for its 3rd year!

Keep your eyes peeled for more information coming soon on tickets, Call for Papers, and venue information.

Can't wait to see you there!

#BSides #BSidesYXE #Saskatoon #InformationSecurity #infosec #cybersecurity

Juliet (Ryel), Rollerskating Elf 🏳️‍⚧️julie@merida.hair
2026-02-02

Notepad++ confirms it was compromised by state-sponsored hackers.

You might want to update and do some threat hunting.

https://notepad-plus-plus.org/news/hijacked-incident-info-update/

Bonus: Here's a great writeup from December from
@GossiTheDog@cyberplace.social
https://doublepulsar.com/small-numbers-of-notepad-users-reporting-security-woes-371d7a3fd2d9

#CyberSecurity #InformationSecurity

That scene in Contact (1997) where they suddenly realize the code transmitted by the alien civilization doesn't form a 2D document, but a 3D one, and suddenly it's readable.

But in this version, it starts "Dear friend, I have encrypted your files...".

#Contact #CISO #security #InformationSecurity #aliens #ransomware

Edwin G. :mapleleafroundel:EdwinG@mstdn.moimeme.ca
2026-01-29

Private AI Chat conversations leaked because the database was not secured properly

404media.co/massive-ai-chat-ap
- - -
Des conversations privées avec une IA ont été divulguées à cause d’une base de données incorrectement sécurisée

moncarnet.com/2026/01/29/fuite

#AI #IA #ArtificialIntelligence #IntelligenceArtificielle #InfoSec #InformationSecurity #Cybersécurité

Edwin G. :mapleleafroundel:EdwinG@mstdn.moimeme.ca
2026-01-29

France 🇫🇷 fines France Travail, the country’s public employment service, €5M over failures to protect job seekers’ data

bleepingcomputer.com/news/secu
- - -
La France 🇫🇷 met France Travail, le service d’emploi public du pays, à l’amende de 5M€ pour avoir failli à protéger les données des personnes en recherche d’emploi

lemonde.fr/pixels/article/2026

#France #FranceTravail #InfoSec #InformationSecurity #Cybersécurité

Edwin G. :mapleleafroundel:EdwinG@mstdn.moimeme.ca
2026-01-29

The Canadian Centre for Cyber Security warns that more criminals are using AI for ransomware attacks

cbc.ca/news/politics/ai-ransom
- - -
Le Centre canadien pour la cybersécurité met en garde que davantage de criminels•elles utilisent l’IA pour les attaques par rançongiciel

lactualite.com/actualites/les-

#Canada #Ransomware #Rançongiciel #InfoSec #InformationSecurity #Cybersécurité #AI #IA #ArtificialIntelligence #IntelligenceArtificielle

Yonhap Infomax Newsinfomaxkorea
2026-01-28

The South Korean government will expand user protection by introducing dispute mediation for damages beyond personal data leaks, strengthening AI and digital product security, and aligning with EU cybersecurity regulations.

en.infomaxai.com/news/articleV

Edwin G. :mapleleafroundel:EdwinG@mstdn.moimeme.ca
2026-01-27

Canada Computers starts emailing customers about data breach

mobilesyrup.com/2026/01/27/can
- - -
Ordinateurs Canada commence à informer les clients au sujet d’une brèche de données

// Article en anglais //

#Canada #CanadaComputers #OrdinateursCanada #InfoSec #InformationSecurity #Cybersécurité

Endoacusticacellularispia
2026-01-27

🔐 How Audio Sensors Are Changing Professional Bug Sweeping Services

As workplaces evolve, so do the risks around sensitive conversations and confidential information. Traditional bug sweeping is no longer enough for modern offices, shared spaces, and remote collaboration environments.

📊 Learn why physical information security matters more than ever in today’s connected world.


prlog.org/13123966-how-audio-s

How Audio Sensors Are Changing Professional Bug Sweeping Services

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst