GKRootWire
Gadgets Fairphone 6 Plus and Framework 12 Push the Case for Repairable TechSecurity Windows Named Pipes Are a Quiet Privilege-Escalation Risk, Security Firm WarnsGadgets Pixel 11 Pro XL Review: Faster Cameras, Familiar PhoneGadgets Amazon Raises Prices on Echo, Kindle, and Fire TV Devices by Up to 60 PercentSecurity Malware Hijacks Android Car Head Units to Build Proxy BotnetDev Tools Model Context Protocol Team Charts Next Phase With New RoadmapGadgets Fairphone 6 Plus and Framework 12 Push the Case for Repairable TechSecurity Windows Named Pipes Are a Quiet Privilege-Escalation Risk, Security Firm WarnsGadgets Pixel 11 Pro XL Review: Faster Cameras, Familiar PhoneGadgets Amazon Raises Prices on Echo, Kindle, and Fire TV Devices by Up to 60 PercentSecurity Malware Hijacks Android Car Head Units to Build Proxy BotnetDev Tools Model Context Protocol Team Charts Next Phase With New Roadmap
Security

Fake Crypto Conference Invite Used to Target Security Researchers

An attacker posing as a well-known crypto news outlet used a bogus conference pitch and Google Docs to try to plant malware on researchers' machines.

A threat actor impersonating staff from a prominent cryptocurrency news website has been reaching out to cybersecurity researchers with invitations to a fake industry conference. Instead of a normal PDF or website, the lure relied on Google Docs links, likely chosen because they feel trustworthy and can slip past email security filters.

Once a target opened the shared document, the attacker attempted to deliver malware, apparently hoping to compromise the researcher's system or steal credentials. The campaign appears narrowly targeted at people who work in security, rather than the general public, suggesting the attacker wanted access to sensitive research, contacts, or client data.

This is a variation on a familiar playbook: using a topic (crypto, conferences, recruiting) that a specific professional audience finds credible, then hiding malicious payloads inside seemingly benign cloud documents rather than traditional attachments.

Why it matters: Security researchers are high-value targets because they often have access to unpublished vulnerabilities, client networks, and threat intel. Using Google Docs as a delivery vector is notable because it exploits the implicit trust users place in legitimate cloud platforms, a technique that's harder to block with traditional email security tools.

Sources: TechCrunch