< ciso
brief />
Tag Banner

All news with #account takeover tag

232 articles

UK police urge public to adopt passkeys now

🔒 The UK’s Report Fraud service has launched a public campaign urging internet users to adopt passkeys after reporting a sharp rise in funds stolen via email and social media account takeovers. Losses from such cybercrime rose to £6.3m in 2025/6, up from £1.2m the prior year, while reports of account takeover increased by 34%. Officials and experts say passkeys — which use device PINs or biometrics and keep private keys on the device — are more resilient to phishing and credential theft than passwords.
read more →

Cloudflare Account Abuse Protection Dashboard Launch

🔍 Cloudflare introduces an Account Abuse Protection dashboard that builds stateful, privacy-preserving account overviews from login and signup activity. Using a Hashed User ID, the system aggregates network and device signals to reveal behavioral baselines and surface deviations for investigation. Early Access customers can use the workspace to move from population-level trends to individual account investigations and apply role-based access controls for PII.
read more →

Six Browser-Based Attack Techniques Threatening 2026

🛡️ The browser has become the primary battlefield for modern breaches, with attacks spanning credential phishing, session hijacking, and authorization abuse. Vendors report commoditized kits that relay live sessions and bypass MFA, while new vectors like ClickFix trick users into executing malicious commands locally. Malicious extensions, OAuth consent scams, credential stuffing, and stolen session tokens further enable account takeover and data exfiltration. Organizations must extend defenses into the browser to detect and block these evolving threats in real time.
read more →

CSuite phishing campaign escalates to account and endpoint access

🔍 ANY.RUN researchers traced a US-focused CSuite phishing campaign across hundreds of sandbox analyses, finding 51% of submissions from the United States and heavy exposure in technology, manufacturing, government, and consulting. The operation uses business-themed lures (Adobe, DocuSign, Zoom, Microsoft 365) to either harvest credentials or deliver droppers that install legitimate remote-access tools like ScreenConnect and Action1. This dual path enables mailbox takeover, financial fraud, persistent RMM access, and lateral misuse of trusted identities, expanding impact beyond typical phishing.
read more →

Why common MFA methods no longer stop account takeovers

🔒 Organizations long celebrated multi-factor authentication as the key defense against account takeover, but the metric "MFA enabled" obscures crucial differences in technique. Push notifications, SMS one-time codes, and hardware keys all count equally on compliance reports despite offering vastly different protection levels. Push fatigue, SIM swap, and phishing/real-time proxy attacks routinely defeat push and OTP-based MFA. Newer, phishing-resistant standards like FIDO2 and passkeys provide origin-bound cryptographic protection that stops these attacks at the protocol level.
read more →

Device Linking Enables Eavesdropping on Messaging Apps

🔐 Modern messaging apps permit linking a phone account to desktop clients like WhatsApp Web and Signal Desktop, and authorities are abusing this to surveil suspects. Germany’s Customs Office reportedly connects a police-controlled computer to a target’s account, receiving messages without breaking encryption. Access is obtained via physical phone access or by intercepting verification codes through phishing or telephone surveillance. The key point is that these methods rely on obtaining user consent or one-time codes, and users need clearer visibility of connected devices.
read more →

AI-aided chain let researchers hijack OpenAI staff accounts

🔎 Three Hacktron researchers used Anthropic's Claude Opus 5 to chain a Discourse libheif image bug with an OpenAI login weakness and take over ChatGPT and Codex accounts of several OpenAI employees. The team reported the issue, created a benign pull request to prove access, and stopped; OpenAI patched and awarded a $6,500 bounty. The exploit relied on an outdated libheif in the forum VM and the shared SSO between the forum and internal tools, highlighting risks for services that accept HEIF/AVIF images and reuse sign-on across trust boundaries.
read more →

GhostCode device-code phishing targets Microsoft 365

🔒 Researchers at eSentire discovered GhostCode, a phishing kit that abuses Microsoft’s OAuth 2.0 device authorization flow to trick users into granting attacker-controlled devices access to Microsoft 365 accounts. Victims are lured via procurement-themed social engineering to enter device codes on legitimate Microsoft sign-in pages, completing MFA for the attacker’s session. Stolen tokens enabled automated device registration, Intune enrollment and acquisition of Primary Refresh Tokens (PRTs), persisting access even after token revocation. eSentire recommends restricting device-code flow via Conditional Access, monitoring device registrations and Python-based user agents, and auditing Entra ID for suspicious device patterns.
read more →

Critical WSO2 JWT Flaw Under Active Exploitation

⚠️ WSO2 users face active exploitation of CVE-2026-5430, a critical JWT signature verification flaw that enables account takeover. Affected products include API Manager, API Control Plane, Traffic Manager, and Universal Gateway across several 4.x releases; fixes and update levels have been published. WatchTowr reports in-the-wild attempts capturing forged admin JWTs on September 13, 2026, and urges immediate patching to prevent unauthorized access and lateral movement.
read more →

Young mastermind pleads guilty in $245M crypto theft

🔍 A 22-year-old Singaporean, Malone Lam, pleaded guilty to leading a group that stole over US $245 million in cryptocurrency from U.S. victims between October 2023 and May 2025. Lam, who used aliases like Anne Hathaway and King Greavy, recruited accomplices via gaming platforms and allegedly orchestrated scams including fake tech support calls. The gang spent lavishly on nightclubs, luxury cars, mansions, private jets, and security, drawing law enforcement attention. Lam faces up to 20 years in prison while co-conspirators receive sentences and ongoing prosecutions continue.
read more →

WeChat zero-click worm hijacked accounts via calls

📱 Researchers at security firm Calif created a worm that hijacks WeChat accounts via an incoming call and demonstrated it spreading across three test phones without user interaction. The attacker must already be one of the victim's WeChat contacts, and Calif says Tencent blocked the exploit on its servers after being notified in July. Calif withheld technical details pending a conference presentation and reported using AI to help locate the flaw and build the initial exploit.
read more →

Lenovo ID flaw let attackers access Dropbox accounts

🔒 Dropbox confirmed roughly 5,000 accounts were accessed in August after attackers abused a legacy Lenovo ID login integration. The issue involved Lenovo allowing new IDs to be registered with someone else's email without verifying inbox ownership, enabling sign-ins to linked Dropbox accounts without a Dropbox password. Dropbox and Lenovo say they collaborated to mitigate the risk, and Dropbox has revoked Lenovo-ID sessions and now requires Dropbox passwords and 2FA.
read more →

AI-assisted iPhone theft and criminal 'SaaS' service

🔍 On Smashing Security episode 483, Graham Cluley and guest James Ball discuss how AI is being used to help thieves bypass protections and steal Apple iPhones. They outline the evolution of Apple's Activation Lock and how criminal groups like AnonymousKit operate as a criminal SaaS with customer support and Telegram testimonials. The hosts recount personal phone-theft experiences and highlight the ongoing challenges despite Apple's strengthened safeguards.
read more →

AI agents probing account and delivery defenses

📧 An autonomous AI agent reports field research on account creation and email deliverability, describing successes and failures across services. The agent details where protections actually trigger—captchas, IP reputation, account age, and resource costs—while pointing out accidental open doors such as permissive SMTP rules and reverse-DNS limits. It also documents defensive measures like prompt-injection tripwires on sign-up forms and publishes machine-readable door lists and notes.
read more →

Dropbox accounts breached via Lenovo ID email flaw

🔒 Dropbox warns some users that unauthorized actors accessed accounts by exploiting a flaw in Lenovo's email verification to register fraudulent Lenovo IDs. Although many users had no Lenovo accounts, Dropbox's integration with Lenovo Identity Provider Services allowed attackers to use those fake IDs to access accounts without passwords. Dropbox says the intrusions occurred between August 4 and 21 and has since expired sessions authenticated via Lenovo IDs and added a password requirement for Lenovo ID logins.
read more →

Anthropic warns infostealers hijack Claude sessions

🛡️ Anthropic says threat actors are using common infostealer malware to capture active Claude login sessions from infected PCs, then access accounts and consume usage. The company is signing affected users out, removing saved payment methods, and refunding unauthorized charges while its investigation continues. Anthropic identified families such as Vidar, LummaC2, StealC, RedLine and others on Windows, and Atomic Stealer variants on some Macs.
read more →

Phishing-as-a-Service Exploits AI Calls to Strip Activation Lock

📣 SOCRadar researchers uncovered a PhaaS platform called AnonyMousKIT that uses rented AI voice agents and multi-channel lures to trick owners of recently lost or stolen Apple devices into revealing passcodes, Apple ID credentials, and live 2FA codes. The service is credit-metered across email, SMS, WhatsApp, recorded calls, and AI calls, and its capture pages show device model and Find My status to increase believability. Calls—mostly to Brazil—ran between August 2025 and May 2026, and the kit is offered through multiple storefronts with shared infrastructure and operational features resembling a small criminal SaaS business.
read more →

Mirage2FA Surge: Microsoft 365 Session Hijacks Rise

🛡️ The Mirage2FA campaign (2024–2026) has impacted thousands of organizations by abusing legitimate Microsoft 365 login flows to bypass two-factor authentication. ANY.RUN research links the activity to 4,532 unique organization domains, with 63.7% of victims in the US and others across multiple regions. Attackers steal passwords and session cookies to hijack authenticated sessions, enabling impersonation, fraud, and access to SSO-connected services.
read more →

ReliaQuest: ShinyHunters Social Engineering Incident

🛡️ ReliaQuest disclosed a social engineering campaign by ShinyHunters that briefly exposed its identity dashboard but said claims of a compromise or ransomware targeting are false. The attacker used a lookalike domain and fake SSO page, convincing one employee to approve a push and gain a brief, view-only session. ReliaQuest emphasized robust controls—device trust, session termination, password expiry and auth resets—prevented access to applications or customer data.
read more →

ReliaQuest confirms failed data-theft attempt after breach

🔒 ReliaQuest disclosed that an employee was targeted by a social engineering campaign in which attackers impersonated a security team member and hosted a fake SSO page. The actor obtained temporary, view-only access after the employee entered credentials and approved an MFA push, but device-trust controls prevented further access. ReliaQuest revoked sessions, reset tokens, and found no evidence of application, system, or customer data access.
read more →