217: $137k Job Scam Exposed, Iran Hacking US Water Grid, OpenAI Security Breach
Key Takeaways
- A sophisticated cyber security job scam is currently targeting unsuspecting tech applicants on LinkedIn with fake $137k entry-level roles, utilizing deceptive PDF assessments and newly stood-up domains.
- State-sponsored Iranian hackers have been actively targeting critical infrastructure, including US water and energy grids, highlighting the growing threat to national security.
- Malicious actors are increasingly exploiting AI tools, such as spreading SectopRAT malware via fake Claude AI apps on Bing ads and utilizing 'slopsquatting' attacks to target AI hallucinations.
- Major organizations and everyday users face rising security challenges, ranging from the recent OpenAI breach and Chick-fil-A credential stuffing to hotel Wi-Fi DNS hijacking aimed at Microsoft 365 logins.
- Aspiring professionals navigating the tech industry can leverage strategic advice on breaking into Managed Service Providers (MSPs), understanding SOC L1 job realities, and avoiding job hunt burnout.
Go to our sponsor https://app.techtualconsulting.tech/bundles/ to get help with your cyber career
------------------------------------------------------------------------------------
Why are fake $137k entry-level cyber jobs taking over LinkedIn? In this episode of The TechTual Talk, HD exposes a live job scam targeting tech applicants with fake PDF assessments and stood-up domains. Plus, we break down Iranian hackers targeting US water and energy grids, the OpenAI breach fallout and Hugging Face's call for radical AI transparency, fake Claude AI apps spreading SectopRAT malware via Bing ads, "Slopsquatting" attacks targeting AI hallucinations, hidden car devices open to remote hacking, Chick-fil-A's customer data breach, and why hotel Wi-Fi DNS hijacking is coming for your Microsoft 365 login
------------------------------------------------------------------------------------
Get your It pro career packages here : https://app.techtualconsulting.tech/bundles/
Book a call: https://calendly.com/techtuaulconsulting
join the discord here: https://discord.gg/8jryx9CUxw
ask your pod questions here: techtualquestions@thetechtualtalk.com
--------------------------------------------------------------------------------------
➡️ Follow us on social media:
Instagram: https://www.instagram.com/techtualchatter/
TIkTok: https://www.tiktok.com/@techtualchatter
Twitter: https://twitter.com/TechtualChatter
LinkedIn: https://www.linkedin.com/in/henri-davis/
Follow Cybershortieee
Youtube: @Cybershortieee
Instagram: https://www.instagram.com/cybershortieee/
Tiktok: https://www.tiktok.com/@cybershortieee
Follow the Pod:
https://www.instagram.com/techtualtalk/
-----------------------------------------------------------------------------------------------------
00:00:00 Intro
04:37 Today’s Cyber Topics Lineup
05:48 Iran Targeting Water and Energy
09:00 OpenAI Hack and Transparency Fight
12:50 Fake Claude App RAT Campaign
18:55 LinkedIn Job Scam Breakdown
27:20 Reddit Takes on Help Desk
29:57 Starting Over at 30 Advice
31:34 Breaking Into MSPs Strategy
33:26 Reality Check on SOC L1 Jobs
39:04 Slop Squatting and AI Hallucinations
41:55 Cars Hacked by Dongles
43:42 Chick-fil-A Credential Stuffing
46:55 Sextortion Email Bluff
49:22 Hotel Wi-Fi DNS Hijacks
51:14 AI Monitoring and Hiring Rants
54:32 Catching AI Cheaters
57:06 Cubicles vs Open Offices
59:47 Fast Track Into Cyber
01:04:45 Job Hunt Burnout Tips
01:05:58 Workplace Reality Checks
01:10:32 Nine to Five Debate
Frequently Asked Questions
What is the cyber security job scam spreading on LinkedIn?
The cyber security job scam involves fraudulent $137k entry-level job postings designed to trick applicants using fake PDF assessments and custom-built malicious domains.
How are hackers using AI apps to spread malware?
Hackers are distributing fake Claude AI applications through Bing ads that contain SectopRAT malware, compromising users who think they are downloading legitimate software.
What infrastructure threats are discussed in this episode?
The episode highlights state-sponsored threats, specifically detailing how Iranian hackers have been targeting critical US water and energy grids.
How can hotel Wi-Fi be exploited to steal login credentials?
Attackers use hotel Wi-Fi DNS hijacking techniques to intercept user traffic and target sensitive credentials like Microsoft 365 logins.