Social Engineering Leveled Up. Has Your Security Program?

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Modern social engineering has evolved beyond detectable attacks into techniques that blend seamlessly into trusted workflows, legitimate platforms, and everyday tools. Key threats include device code phishing (EvilTokens/Railway campaign) that bypasses MFA by stealing OAuth session tokens, AI-powered deepfakes impersonating executives and candidates, malicious search results mimicking legitimate software installers, and calendar/SaaS workflow abuse. Only 8.9% of security teams identify phishing as their biggest gap, yet 26.5% feel least prepared for identity-based attacks and 32% lack ITDR capabilities. The core argument is that prevention-first security models are failing because attackers now operate inside trusted infrastructure. Resilient teams are shifting toward speed over volume, behavioral detection over static indicators, clear ownership of incident response, and cross-tenant identity visibility to limit damage and recover quickly.

10m read timeFrom huntress.com
Post cover image
Table of contents
Trust in identities: When "real" isn't real anymoreTrust in information sources: When answers become the attackTrust in third parties: Phishing infrastructure hiding in plain sightTrust in everyday workflows: When normal behavior is the targetPrevention alone doesn't cut itThe shift: Resilience over assumptionSee it in action