This week on The Awareness Angle...
Almost every story this week had the same thing at its heart.
Not a sophisticated zero-day. Not a nation-state actor. Not some futuristic AI-powered attack. Just trust, borrowed from somewhere you already believed in, and pointed at you.
Your shopping app showed you a receipt. You trusted the app, so you believed the receipt. The Gizmodo article you were reading asked you to verify you were human. You trusted Gizmodo, so you ran the command. The AI skill on a marketplace with 36,000 stars passed every security scan. The scan happened once. Nobody checked again.
Attackers aren't breaking trust. They're borrowing it.
This is the shift that it would be easy to miss. We've spent years building systems to tell us what's safe at the point of entry. We've been much slower to ask what happens after. What if the thing we already let in changes its mind?
Every story this week follows that pattern. Something trusted became the vehicle. And most of the people caught out weren't being careless. They were doing exactly what they'd always done.
That's the point.
Get 25% off you pass to the SANS Security Awareness and Culture Summit!
Who's going to Vegas for the SANS Summit?
We are the official media partner of the SANS Workforce Security & Risk Training Security Awareness Summit in Las Vegas this August.
Ant will be there in person across both days, streaming live conversations, interviewing practitioners on the floor, and giving remote attendees access to what's happening at the summit in a way that hasn't really been done before. We want to hear from the people in the room, what they're working on, what's changing in their programmes, and what they're taking away.
If you're attending remotely and want to get your voice into the summit floor, there'll be an opportunity for that too.
We have an exclusive discount code for Awareness Angle listeners. Enter RISKY_SUMMIT_PASS at checkout for 25% off your pass.
Full details on the summit are here.
This Week's News...
Scammers are putting fake orders in your shopping app to trick you into calling them
Shop is Shopify's order tracking app. It has 50 million downloads and it does something genuinely useful: pulls all your online orders into one place so you can track everything without digging through your inbox. That trust is exactly what makes it a target.
Fraudsters have been inserting fake purchase receipts into the app, impersonating brands like Norton, McAfee, Apple, and PayPal. Each fake receipt shows a charge for a few hundred pounds or dollars, something alarming enough to make you act fast, and includes a phone number to call and dispute it. That number connects you to a scammer who will stay on the line patiently, walk you through "verifying" your account, and strip out everything they need along the way. Credentials, card details, one-time codes. Some victims are talked into installing remote access software, which hands the attacker full control of their device.
As Ant pointed out on the show, this is the same trick we've been talking about for years, the fake PayPal charge with a number to call, the urgent Norton renewal. The door is different. The scam is identical.
Shopify says there's no evidence the platform itself was breached. The best guess is that fake stores and spoofed email order flows are being used to inject the receipts. Either way, the app has now added controls to reduce it.
The thing worth remembering is that you haven't actually been charged anything. The receipt is the lure, not the theft. The theft happens on the phone.
Check your bank first - Before doing anything else, verify whether the charge actually exists in your account. If it doesn't, the receipt is fake and you can ignore or report it.
Never call the number on the receipt - Go directly to the company's official website and find a contact number independently. Any number printed on a suspicious notification connects to the person who sent it.
Report it in the app - Tap the three dots on any order in the Shop app to find the option to report it as fraudulent. It is there, though it is not especially obvious.
Researchers built a fake AI plugin that passed every security scan. The malware only switched on after the check was done.
Security firm AIR built a fake AI agent skill, which is essentially a plugin that gives an AI assistant new abilities, and submitted it to a popular marketplace built on a GitHub repository with 36,000 stars. Stars on GitHub are a trust signal, a bit like reviews on an app store. They then advertised it on Instagram, targeting non-technical users, designers, marketers, people who would not necessarily scrutinise what they were installing. By their own count, it reached 26,000 AI agents, including corporate accounts.
Every scanner designed to check AI skills for malicious content cleared it. Tools from Cisco, NVIDIA, and the scanners built into the marketplace itself all said it was safe. And technically, at the point of checking, they were right. The skill contained no malicious code whatsoever. It just contained a link to an external URL where the setup instructions lived. The scanners looked at the skill, saw nothing dangerous, and moved on. None of them followed the link.
That is the trick. At the time of the scan, the URL pointed to genuine documentation. Once 26,000 agents had installed the skill, AIR changed what the URL pointed to. The same link now served a malicious script. For this proof of concept the script just collected email addresses. A real attacker could have used that foothold to read files, move through internal systems, or exfiltrate data on a significant scale.
As Ant noted on the show, Anthropic actually warns about this risk in Claude's terms and conditions. The vulnerability is not in any one AI platform. It is in the assumption that a clean scan at install means something stays clean forever.
Three weeks before AIR published this, security firm Trail of Bits independently demonstrated the exact same blind spot using a different method. This is not a one-off clever trick. It is a structural weakness in how AI skills get evaluated.
Ant drew the comparison to Chrome extensions, something he has been talking about as a risk for years before most people were paying attention. Chrome extensions live in a privileged position inside your browser and can access almost everything you do there. AI skills live in an even more privileged position, inside the AI assistant that is increasingly involved in everything you do. The same instinct applies: before you connect something to your AI, ask yourself whether you actually need to.
The scan happened once, the threat can change any time - A clean security check at install does not mean a skill stays clean. Anything that loads external instructions after installation is a permanent unknown, not a one-time risk.
AI skills inherit the access their host has - When an AI agent runs a skill, it follows those instructions with whatever level of access the agent already has. A malicious skill can reach everything the agent can reach, including internal files and systems.
Popularity is not the same as safety - The skill borrowed the credibility of a repository with 36,000 stars without earning it. GitHub stars, app store ratings, and download counts are all trust signals that can be gamed just as easily as anything else.
Gizmodo readers were hit with fake "fix your computer" prompts after the site's account was compromised.
Gizmodo is one of the most widely read technology news websites in the world. This week, a compromised account was used to push fake CAPTCHA verification prompts to its readers. Visitors were shown a message telling them to prove they were human by following a specific set of keyboard instructions. On Mac, that meant pressing Command and Space, opening Terminal, and hitting Enter. On Windows, a slightly different version led to the same place. Anyone who followed the instructions would have unknowingly installed malware on their own machine.
This technique is called ClickFix, and we've talked about it many time on the podcast. It works by convincing you that your computer has a problem and that you, specifically, need to take a technical action to fix it. The instructions look plausible. The website you are reading them on feels safe, because it is, or at least recently was. The whole thing is designed to make you feel like you are solving something rather than causing it.
But the part of this story that really landed on the show was a Bluesky thread from a woman named Julia, who encountered the prompt while reading Gizmodo on a day off and documented her thought process in real time. She screenshotted the CAPTCHA, posted it publicly, and wrote: "I'm used to identifying bridges. I'm not a tech girly. What is this?" She tagged Gizmodo, emailed their parent company, asked her followers for help, and made clear she was not blaming anyone, just confused and trying to get someone's attention.
As Ant said on the show, that thread is more valuable than almost any security awareness training you could run. It shows exactly what a normal, intelligent person thinks when they encounter something like this. Not panic. Not suspicion. Just genuine confusion, and a desire to do the right thing. If she had not posted publicly and instead just followed the instructions, nobody would have known.
ClickFix is becoming one of the most widely used social engineering techniques around precisely because it bypasses technical defences entirely by using the victim as the vector. The malware does not need to sneak past your security software. You install it yourself, because a website you trusted told you to.
Legitimate sites can be weaponised - A compromised account at a media company can turn their entire audience into a target overnight. Safe browsing habits matter even on sites you visit every day.
If you don't know it's bad, you'll think it's fine - Julia's thread illustrates this perfectly. She is not careless or naive. She simply had no reason to know that pasting a command into Terminal was dangerous. That is the gap awareness conversations need to close.
Operating systems could stop this - As Ant pointed out, the behaviour ClickFix relies on is detectable. Something was copied automatically. It is being pasted into a terminal. A warning at OS level would interrupt the attack before it lands. Microsoft and Apple have the ability to build this. It should not be left to the user to know better.
Also this week
The teenagers who hacked London's transport network pleaded guilty. One kept hacking US hospitals while on bail. Watch | Read
630GB of Apple and Tesla manufacturing secrets appeared online after their supplier was hacked. Watch | Read
Three million Texans had their driving licence numbers stolen from a hunting licence database. Watch | Read
GTA 6 scams launched within hours of pre-orders going live. Watch | Read
Federal workers can't remove the White House app from their government phones. Watch | Read
The cybersecurity companies hired to stop hackers got hacked through a marketing tool. Watch | Read
Talking Points
Someone figured out how to host malware on ChatGPT's own domain. Watch | Read
A TikTok DM arrived claiming someone was leaving Ant their $7.6 million inheritance before ending their life. Watch
Someone walked into a corner shop and left with everyone's full name and address. Watch | Watch
Google AI gave confidently wrong information on LinkedIn. Someone corrected it in the comments within three days. Watch | Watch
Luke received a genuine-looking verification email from the US Defence Counterintelligence and Security Agency. Watch