Threat Brief — 2026-08-12 — New intel on fake hires and threat actors
Executive summary. Today's fresh feed brings limited genuinely new material — most findings are duplicates of stories already captured earlier today. What is new: a profile of the REvil-linked actor "Quake3," a technique paper on fake remote-worker infiltration of organisations, Google's own researchers demonstrating their AI hiring filter can be bypassed, and an FBI alert on account-takeover campaigns aimed at stealing explicit photos. The dozen MSRC entries are all informational acknowledgement updates with no new patch or exploit details.
Top items
- REvil coder and XSS forum moderator "Quake3" identified. A Ukrainian hacker allegedly wrote code for REvil ransomware, moderated the XSS underground forum, and evaded German police. The profile adds actionable attribution detail to one of the most destructive ransomware families. (src: SecurityLab)
- Fake remote workers exploit gaps between hiring checks and device delivery. Specops outlines how attackers slip into organisations under false identities during the window between background verification, device shipping, and account provisioning — recommending document verification and biometric liveness checks as mitigations. Relevant to any team running remote-first hiring. (src: BleepingComputer)
- DeepMind researchers show Google's AI hiring filter is unreliable. Google is selling AI for candidate screening, but its own researchers told candidates the corporate resume filters can be bypassed — undercutting the product's security claims and raising questions about adversarial prompt resistance in HR pipelines. (src: SecurityLab)
- FBI warns: hackers target online accounts to steal nude photos. Cybercriminals are compromising adults' and children's social media and other online accounts specifically to obtain sexually explicit images or videos — likely for sextortion or doxxing. User-facing awareness and MFA enforcement are the primary mitigations. (src: BleepingComputer)
Themes
Hiring-process attack surface is expanding. Two of today's items — fake remote workers and the DeepMind hiring-filter bypass — converge on the same risk: adversaries are targeting the hiring lifecycle itself, whether through social-engineered fake identities or by defeating automated screening tools. Combined with the earlier "fake crypto startup catches North Korean IT workers" story from this morning, the hiring pipeline is clearly an active battlefield.
===
THREAT-TOPICS===
[{"slug":"quake3-revil-identity-profile","headline":"Quake3 identified as REvil coder and XSS forum moderator","findingIds":[7440],"status":"new","development":""},{"slug":"fake-remote-workers-hiring-infiltration","headline":"Fake remote workers exploit gaps in hiring and onboarding checks","findingIds":[7422],"status":"new","development":""},{"slug":"google-ai-hiring-filter-bypass","headline":"DeepMind researchers show Google AI hiring filter can be bypassed","findingIds":[7449],"status":"new","development":""},{"slug":"fbi-nude-photo-account-takeover-warning","headline":"FBI warns hackers target online accounts to steal explicit photos","findingIds":[7421],"status":"new","development":""}]
