A recruiter messages you on LinkedIn with a coding test. Open it, and you've handed someone remote control of your machine. Four minutes. Let's go.

🚨 THE BIG STORY

Fake LinkedIn recruiters are shipping malware as coding tests

Attackers posing as recruiters are sending developers take-home technical assessments that install remote-access malware on Windows, Linux and macOS. Researchers at PolySwarm attribute the campaign to the Iran-linked group Mirage Kitten, with victims across fintech, aviation and aerospace.

🧠 Why It Matters

Developers open and run unfamiliar code constantly — it's the job, not a red flag. That's what makes this work. A compromised developer laptop usually means source code, stored credentials and live sessions to company systems. If your team interviews engineers, set a rule now: assessments run in an isolated environment, never the main work machine.

⚡ CYBER IN 60 SECONDS

  • A breach at learning platform Mathspace hit over a million students, parents and teachers across New Zealand and Australia — one of three back-to-back incidents there, alongside a health research firm and a payroll provider. Researchers say the likelihood calculation has shifted for small organizations. [Mathspace Breach Hits 1 Million Students and Teachers]

  • Ontario courts breach update: C-Track Canada has confirmed that confidential, redacted or sealed information may have been affected, and says it has no evidence of fraud so far. A dedicated notification site is now live for anyone concerned. [Ontario Court Records Exposed in Thomson Reuters Breach]

  • Worth your weekend: the young hacker behind the PowerSchool breach — which put 60 million children's records at risk — gave his first interview before reporting to prison. The FBI agent who ran the case says victims will be dealing with it for life. [PowerSchool Hacker, 20, Gets 4 Years in Federal Prison]

💼 THE BUSINESS OF SECURITY

  • Nvidia's Jensen Huang says cybersecurity is AI's next big market. His argument: AI now writes code faster than anyone can review it, so flaws have to be found and fixed at machine speed. Worth noting he sells the hardware that would run those tools. [Nvidia CEO: Cybersecurity Is AI's Next Big Market]

🎭 SCAM TO WATCH

After a payroll or tax-related breach, expect a message that knows too much about you. A cybersecurity researcher at Victoria University described the pattern following this week's New Zealand payroll breach: criminals use your real name, address and tax number to send a convincing note claiming you underpaid tax on a specific pay period, with a link to "log in and fix it." The accurate details are what sell it. The tell: tax agencies — the CRA in Canada, the IRS in the US — don't send payment links by email or text. Go to the agency's website directly or call the number on an official notice.

🛡️ TODAY'S SECURE MINDSET

Before you act on any recruiter message, verify the person exists at the company they claim — check the company's own careers page or call the main line. Two things should stop you cold regardless: a tight deadline, and instructions not to modify a specific file or use AI tools. Both exist to rush you past the part where you'd notice something wrong. [Fake LinkedIn Job Offers Hide Malware in Coding Tests]

See you Monday. — SecureMindset