ETR-Invspt.ca SMS Scam Leads to Fake Interac Deposit Page
A Canadian smishing campaign sends etr-invspt.ca SMS links that redirect to inc-gdep.com, a fake Interac deposit page impersonating Government of Canada and banks.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
October 4, 2026
A Canadian smishing campaign sends etr-invspt.ca SMS links that redirect to inc-gdep.com, a fake Interac deposit page impersonating Government of Canada and banks.
HiddenLayer says a fake OpenAI-themed Hugging Face repository copied a privacy-filter model card and used loader.py/start.bat to fetch Windows infostealer malware.
JDownloader says attackers changed several official website download links on May 6-7, sending Windows alternative installer and Linux shell installer users to malicious files.
cPanel patched three WHM and WP Squared vulnerabilities affecting server control paths, including arbitrary file read, Perl code injection, and unsafe symlink chmod behavior.
Instructure says a Canvas incident exposed names, emails, student IDs, and user messages at affected organizations, while login pages were later altered during the…
ESET says 28 CallPhantom apps in Google Play sold fake call, SMS, and WhatsApp history reports, turning curiosity into paid subscriptions and harder-to-refund charges.
Trend Micro reports QLNX, a Linux-focused Quasar RAT variant that combines persistence, rootkit-style hiding, PAM backdoor access, and credential theft from developer and cloud…
Elastic reports that TCLBANKER hides inside a fake peripheral-device installer, uses DLL sideloading, and spreads through WhatsApp and Outlook while targeting Brazilian banking users.
Kaspersky reports a suspected OceanLotus campaign that used malicious PyPI packages to deliver ZiChatBot, turning routine Python installs into a cross-platform backdoor risk.