Normal view
-
/r/netsec - Information Security News & Discussion
- Malicious Coding Agent Skills and the Risk of Dynamic Context | Datadog Security Labs
-
/r/netsec - Information Security News & Discussion
- AI Vulnerability Research and the Fuzzer Era Dรฉjร Vu
-
/r/netsec - Information Security News & Discussion
- I spent a weekend trying to get OpenClaw to leak my own personal data and it caught me immediately...
The New Gradโs Guide to Job and Recruitment Scams
Graduation season should be about launching your career, not dodging scams.
But for many new grads, the job search now comes with a hidden risk: fake recruiters, fraudulent job offers, and convincing messages designed to steal money, personal information, or both.
The threat is larger than many people realize. According to McAfeeโs 2026 State of the Scamiverse report, 76% of Americans have encountered a scam, and the average person receives 14 scam messages every day through text, email, and social media. Americans now spend an estimated 114 hours each year trying to figure out what is real online and what is not.
Young adults are among the most heavily targeted groups. Nearly 3 in 10 people ages 18 to 24 (28%) report receiving conversational scams that begin with casual outreach such as โHey, how are you?โ or a โwrong numberโ text. Those same tactics increasingly appear in fake recruiter messages, LinkedIn outreach, and texts promoting remote job opportunities.
Todayโs job scams can look highly professional. Scammers build polished LinkedIn profiles, clone legitimate company websites, and even use AI-generated interviews to appear credible. Many scams unfold quickly, with nearly half completed in less than an hour, creating pressure to act before candidates have time to verify what is real.
Thatโsย where tools likeย McAfeeโs Scam Detectorย come inโflagging suspicious emails, texts, links, and messages before you engage, so you can tellย whatโsย real before you click.ย
Hereโsย how to avoid jobย scamsย and stay safe with McAfee:ย
How Job Scams Actually Work
|
Step |
What Happens |
Red Flags |
What Scammers Want |
|
1. The Outreach |
Youโre contacted via email, text, or social media about a job |
Unsolicited offer, vague role, overly enthusiastic recruiter |
Your attention |
|
2. The Build-Up |
They walk you through interviews or onboarding steps |
No video calls, inconsistent details, fast timeline |
Your trust |
|
3. The Ask |
They request personal info or payment |
SSN requests, bank info, โtraining feesโ |
Identity + money |
|
4. The Trap |
They escalate the situation or disappear |
More payment requests or sudden silence |
Continued financial gain |
A Real Example: How People Get Pulled In
Even experienced professionals fall for these scams.
In one case, a tech expert with decades of experience lost $13,000 after accepting what looked like a legitimate part-time role reviewing products.
The opportunity seemed real:
- A polished website
- Structured onboarding
- A small initial payout
Then came the shift. He was told he needed to deposit money to continue working and kept paying more to โunlockโ earnings that never came.
This type of advance fee scam is increasingly common in job fraud, and it works because it builds trust first.
What the Data Says
Recent graduates are entering the workforce at a time when scams are more sophisticated, more personalized, and harder to spot than ever before. McAfeeโs 2026 State of the Scamiverse report highlights why younger job seekers should be especially cautious.
Young Adults Face Higher Risk
- Younger adults report the highest rates of repeat scam victimization. McAfeeโs research found that scam victims under 35 are more likely than older adults to be targeted again, suggesting that early-career professionals may be especially vulnerable as they navigate job searches, salaries, and onboarding for the first time.
Scam Messages Are Constant
- Americans receive 14 scam messages per day on average.
- 76% of Americans say they have encountered an online scam.
- People spend 114 hours per year, nearly three full workweeks, trying to determine what is real and what is fake online.
Professional Platforms Are Not Immune
- 7% of respondents reported encountering scams on LinkedIn.
- 44% have replied to suspicious messages that contained no link at all.
Many modern scams begin with a simple message such as โI came across your profileโ or โWeโd like to discuss an opportunity,โ rather than an obviously suspicious URL.
Job Scams Move Fast
- The average scam unfolds in just 38 minutes.
Scammers often create urgency by claiming a role is limited, an offer will expire quickly, or onboarding must begin immediately.
AI Makes Fake Recruiters More Convincing
- 35% of Americans are not confident they can spot deepfake scams.
- McAfee predicts job scams will become increasingly personalized as scammers use AI to create tailored outreach, onboarding documents, and contracts that closely match a candidateโs background.
Job Scams Are a Growing Financial Threat
- FTC-reported job scam losses rose nearly 40% year over year, increasing from $543 million in 2024 to $752 million in 2025.
For new graduates eager to land their first job, the lesson is simple: if an opportunity seems rushed, asks for money, or feels too good to be true, take a step back and verify before you respond.
Where McAfee Comes In
Job scams donโt just happen in one moment. They unfold in stagesโfirst a message, then a conversation, then a request for information or money.
Thatโs why protection needs to work the same way: across the entire experience. McAfeeโs comprehensive protection helps you stay ahead of job scams at every step:
McAfee+ Advanced gives you multiple layers working together so you are not left figuring it out after the damage is done:
- Identity Monitoring alerts you if your personal info shows up where it should not, so you can act fast
- Personal Data Cleanup helps remove your information from data broker sites, making you harder to target in the first place
- Scam Detector flags suspicious texts, emails, links, and even deepfake videos before you engage
- Safe Browsing helps block risky sites if you do click
- Device Security helps detect malicious apps or downloads
- Secure VPN keeps your data private, especially on public Wi-Fiย ย
The Biggest Red Flags to Watch For
These patterns show up again and again in job scams:
|
Red Flag |
What It Looks Like |
Why Itโs a Problem |
What to Do Instead |
|
Requests for Sensitive Information Too Early |
Asked for your Social Security number, banking info, or ID details early in the process |
Scammers use this to steal your identity or access your accounts |
Only share sensitive info after accepting a verified jobโand through secure onboarding systems |
|
Youโre Asked to Pay to Work |
Fees for training, equipment, onboarding, or background checks |
Legitimate employers donโt charge candidates to get hired |
Walk away immediatelyโthis is one of the clearest signs of a scam |
|
The Job Sounds Too Good to Be True |
High pay, low hours, minimal experience required, vague responsibilities |
Designed to hook attention and lower your guard |
Research typical salaries and ask detailed questions about the role |
|
The Hiring Process Moves Too Fast |
Immediate job offers or rushed decisions without interviews |
Real hiring processes involve multiple steps and evaluations |
Be cautious of offers that skip standard hiring steps |
|
No Real Interaction |
Communication only via email or chat, refusal to do video or phone calls |
Scammers avoid real-time interaction to stay anonymous |
Request a video call or verify the recruiter through official company channels |
How to Protect Yourself
You donโt need to overcomplicate it. Stick to a few grounded habits:
- Verify the company independently: Search the company, check official sites, confirm recruiter identities
- Keep communication on trusted platforms: Be cautious with offers coming from unexpected channels
- Never pay upfront for a job: Thatโs a dealbreaker
- Pause before sharing personal information: Especially early in the process
- Use tools that flag risks automatically: Scam Detector helps catch what looks legitimate, but isnโt
What to Do If You Think Itโs a Scam
If something feels off:
- Stop communication immediately
- Do not send money or personal information
- Report the scam to the FTC
- Monitor your accounts for suspicious activity
If youโve already shared sensitive information, act quickly to secure your accounts.
With McAfeeโs comprehensive protection, youโre not left to figure it out on your own.
From blocking risky links to monitoring your identity and helping you respond quickly, itโs designed to help you stay one step ahead, and recover faster if needed. Because job searching is stressful enough without scammers, and you deserve to land your next job with confidence.
The post The New Gradโs Guide to Job and Recruitment Scams appeared first on McAfee Blog.
-
/r/netsec - Information Security News & Discussion
- Curl lead developer Daniel Stenberg provides insightful feedbacks from Mythos analysis results
New ipTIME Pre-Auth RCE in CWMP
A pre-auth remote code execution vulnerability was found in the CWMP implementation of ipTIME routers, allowing unauthenticated attackers to execute arbitrary code remotely.
[link] [comments]
Postmortem: TanStack npm supply-chain compromise
Welcoming the Bangladesh Government to Have I Been Pwned
Today, we welcome the 43rd government onboarded to Have I Been Pwned's free gov service, Bangladesh. The BGD e-GOV CIRT department now has full access to query all their government domains via API, and monitor them against future breaches.

Bangladesh joins a growing list of national governments using HIBP to help protect their public sector digital assets, and we look forward to supporting their efforts to identify exposure of government email addresses in data breaches and respond quickly when new incidents appear.
Eyes wide open: How to mitigate the security and privacy risks of smart glasses
-
/r/netsec - Information Security News & Discussion
- OpenAI announces Daybreak, "frontier AI for defenders"
OpenAI announces Daybreak, "frontier AI for defenders"
I think the bigger point here is that AI has clearly been accelerating attackers, so it makes sense that frontier models are now being packaged more directly for defenders too.
Not sure how to start using it yet or get access
[link] [comments]
-
/r/netsec - Information Security News & Discussion
- GhostLock: SMB Deny-Share Handles as a Zero-Privilege Availability Weapon
GhostLock: SMB Deny-Share Handles as a Zero-Privilege Availability Weapon
-
/r/netsec - Information Security News & Discussion
- How I Defeat Passkeys Nearly Every Time in Phishing Assessments
How I Defeat Passkeys Nearly Every Time in Phishing Assessments
-
/r/netsec - Information Security News & Discussion
- MyAudi app:Security issues in Audi Connected Vehicle experience
MyAudi app:Security issues in Audi Connected Vehicle experience
I recently published a security research post on the myAudi connected vehicle platform. I found that anyone with a VIN can access a sensitive informations about car and ownership
I think the topic is useful beyond Audi itself, because many vendors now rely on these โconnected vehicleโ platforms and mobile apps, often with very similar architectures and assumptions
[link] [comments]
-
/r/netsec - Information Security News & Discussion
- Giving Claude Code Full Control of a Hardware Fault Injection Setup to Bypass Secure Boot
Autonomous Vulnerability Hunting with MCP
-
/r/netsec - Information Security News & Discussion
- ShinyHunters / AT&T ransom payment traced on-chain โ paper draft, seeking arXiv cs.CR endorsement
ShinyHunters / AT&T ransom payment traced on-chain โ paper draft, seeking arXiv cs.CR endorsement
Across all major ShinyHunters campaigns (AT&T/Snowflake, Salesforce, Canvas/Instructure), only one event has both a publicly stated payment amount and a known approximate settlement date: the May 2024 AT&T payment of ~5.7 BTC (~$370K), confirmed by Wired but never published with a transaction hash. I use that as the analytical anchor for an end-to-end on-chain analysis using only free public data.
Pipeline (5 stages):
- BigQuery bulk filter on amount and time window โ 500 candidates.
- Recipient profiling via Blockstream Esplora (lifetime tx count, spend shape).
- Sender-side cluster analysis using common-input ownership; looking for broker-aggregation patterns.
- Depth-12 concurrent forward trace, top-K=4 fan-out.
- Terminal attribution via OKLink, BitInfoCharts, WalletExplorer.
Result:
A single highest-fit candidate: 5.71997804 BTC paid 2024-05-17 22:04 UTC to a fresh recipient, spent in 6 min, laundered through a 6-cycle automated peel chain, terminating at an exchange deposit cluster. Funding side shows broker-aggregation fingerprint (4ร 1.147 BTC peels in a 90-min window pre-payout). Upstream hub addresses appear reused across multiple victims of the same laundering service, active through 2025. Paper closes with the legal pathway from chain endpoint to indictment and a scoped compliance-request template.
Limitations (explicit in ยง5):
Ranking under a scoring scheme, not positive ID. No off-chain ground truth. Documented OKLink vs. Arkham label conflict on the dominant terminal, resolved via behavioural audit. No formal null-distribution analysis yet. Score weights are author judgements.
Asking for:
- Technical feedback / methodology critique.
arXiv cs.CR endorsement โ endorsement code: ZQXBSQ
github.com/tr4m0ryp/shinyhunters-gotta-catch-em-all/blob/main/Gotta_Catch_Em_All_ShinyHunters.pdf
Tooling and dataset released for reuse
[link] [comments]
-
/r/netsec - Information Security News & Discussion
- Data in Use Protection: How MPC Keeps Inputs Hidden from the Cloud - Stoffel - MPC Made Simple
-
/r/netsec - Information Security News & Discussion
- The compression of the exploit timeline: Why n-day gaps and 90-day embargoes are failing in practice.
The compression of the exploit timeline: Why n-day gaps and 90-day embargoes are failing in practice.
The traditional vulnerability disclosure timeline relies on a fundamental assumption: exploit development and vulnerability discovery take time. Over the last 12 months the integration of LLMs into offensive tooling has demonstrably broken this assumption.
I recently published a technical write-up arguing that the 90-day disclosure window is effectively dead backed by three specific observations from recent incidents:
- Automated Diff Analysis (30-minute n-days) : The safety net between a patch release and an in-the-wild exploit is gone. Taking a recent React security patch (CVE-2026-23870), I used an LLM to analyze the diff, identify the vulnerable path, and write a working DoS PoC in roughly 30 minutes. The human reverse-engineering bottleneck has been bypassed.
- Vulnerability Convergence : I recently reported a critical P0 to a vendor and was told I was the 11th reporter in 6 weeks. LLM assisted scanners are causing independent researchers to converge on the same bugs simultaneously. An embargo no longer contains the vulnerability; it simply provides a head start to whichever threat actor also found it.
- The Linux Kernel (Copy Fail & Dirty Frag) : The recent kernel exploits highlight this perfectly. Copy Fail (CVE-2026-31431) went from an automated AI scan to a public PoC to nation state weaponization in days. Shortly after the embargo for Dirty Frag (CVE-2026-43284 / CVE-2026-43500) was broken in hours because an unrelated third party independently discovered the same bug class using similar tooling.
The defense cannot operate on monthly cycles when the offense is operating in hours. The focus needs to shift to real-time, PR-level AI scanning to match the pace.
can read the full technical breakdown and case studies on my blog:https://blog.himanshuanand.com/2026/05/the-90-day-disclosure-policy-is-dead/
I am curious if the researchers here are experiencing similar convergence rates or if you view this as a temporary anomaly while legacy codebases are scanned with new tools.
[link] [comments]
Outrunning SHA256 with Physics
-
/r/netsec - Information Security News & Discussion
- Defence in Depth: A Practical Secure Corporate Network Topology
Defence in Depth: A Practical Secure Corporate Network Topology
I built a realistic enterprise security architecture guide covering SPOFs, insider threats, and budget implementation
[link] [comments]