< ciso
brief />
Tag Banner

All news with #account takeover tag

212 articles

Doubloon Dredger abuses Notion to harvest tokens

📄 Sublime's Threat Intelligence team identified a financially motivated actor, tracked as Doubloon Dredger, abusing free Notion accounts and malicious PDFs in July 2026 to harvest authentication tokens. Fake notifications from compromised Notion accounts bypassed DKIM/SPF/DMARC checks and steered victims to intermediary PDFs that redirected to an EvilTokens device-code phishing page. If users entered the provided code on Microsoft's legitimate device-code entry, attackers obtained authorization tokens and could access accounts and inboxes via tools like MailVault.
read more →

Distinct Russian-linked clusters targeting individuals

🛡️ Google Threat Intelligence Group (GTIG) reports three suspected Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—targeting academia, aerospace and defense, governments, and think tanks across Europe and the US. These groups abuse legitimate authentication flows, including app passwords, OAuth prompts, and device linking, and use persistent, adaptive phishing with sophisticated social engineering. UNC7005 employs website templates, fingerprinting, analysis-evasion scripts, and malicious JavaScript to record audio/video or deliver further compromise.
read more →

UK Sees Record Rise in Fraud and Identity Crime

📈 Over 220,000 cases were filed with the UK’s National Fraud Database in H1 2026, the highest first-half total on record, according to Cifas. Identity fraud rose 9% YoY to nearly 130,000 incidents, driven by bank account and card scams which made up 68% of cases, while account takeovers and SIM-swap attacks also surged. Young adults feature prominently as both victims and perpetrators, with money muling cases up 69% and mule activity accounting for 30% of misuse filings.
read more →

North Korean remote hires evade standard security checks

🛡️ Researchers investigated suspected North Korean IT operatives who applied for and secured remote developer roles, revealing forged identities, VPN/VPS infrastructure, and AI-assisted workflows. The FBI is probing a case where a suspected DPRK worker reportedly accessed a U.S. federal agency. The report highlights hiring-stage inconsistencies—document anomalies, interview behavior, and location mismatches—as key warning signs requiring deeper verification and sandboxed validation.
read more →

FBI warns of hackers stealing explicit images online

🔔 The FBI warns cybercriminals are compromising adults' and children's social media and other online accounts to steal sexually explicit photos and videos for blackmail or sale. Victims risk re-victimization through sextortion, harassment, stalking, and public exposure when attackers post or trade stolen content alongside personal details. Authorities advise not sharing verification codes, avoiding internet-accessible storage for explicit material, using complex passwords, and enabling multi-factor authentication.
read more →

How Google Cloud detects and contains emerging threats

🔒 Google Cloud outlines its proactive, shared-fate approach to detect and contain emerging threats across AI workloads, cryptomining, credential exposure, supply chain attacks, and account takeover. The post describes detection signals, tailored containment actions like granular throttling and localized identity isolation, and escalation paths including targeted suspensions. It highlights integrations such as GitHub Secret Scanning and details observability tools like Cloud Abuse Event Logging, Cloud Audit Logging, and billing alerts.
read more →

Snowflake breach actor pleads guilty in US court

🔒 Connor Riley Moucka pleaded guilty in Seattle federal court to charges including computer fraud, wire fraud and aggravated identity theft for his role in the 2024 Snowflake customer account intrusions that affected at least 165 organizations and exposed data tied to over 100 million people. Prosecutors say attackers used old credentials harvested by infostealer malware and exploited accounts with MFA disabled, resulting in more than $9.5 million in direct victim losses and at least $495,000 personally taken by Moucka.
read more →

Report: Passkey weaknesses expose account takeover risks

🔒 A Palo Alto Networks Unit 42 report details how attackers can exploit onboarding, recovery and device-trust workflows to bypass passkey protections after compromising an endpoint. Analysts stress the underlying cryptography remains intact but warn implementations, synced passkeys and support processes create practical risks. Experts advise enforcing user verification, preferring device-bound authenticators and improving incident response.
read more →

Enterprise passkey risks from malware and weak processes

🔒 A Palo Alto Networks Unit 42 report details how malware on compromised endpoints can abuse onboarding, recovery and device-trust workflows to defeat passkey protections. The research outlines three attack categories—Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key—that enable account takeover or mass extraction of synced passkeys. Experts emphasize these are post-compromise attacks that exploit implementation and procedural weaknesses rather than breaking the underlying cryptography. CISOs are advised to enforce user verification, prefer device-bound authenticators for sensitive accounts and tighten enrollment, recovery and sync policies.
read more →

Kali365 Device-Code Phishing Threat to M365

🔒 Kali365 is a device-code phishing kit that abuses Microsoft's legitimate device login to gain persistent access to Microsoft 365 resources. The campaign primarily targets US organizations using SharePoint- and OneDrive-themed lures that redirect victims to Microsoft's real authentication portal where they enter attacker-supplied codes. Once access and refresh tokens are issued, attackers can maintain access to email, documents, and cloud assets, increasing risks of fraud, data exposure, and operational disruption. ANY.RUN telemetry links dozens of weekly sessions to this campaign and emphasizes rapid detection and contextual intelligence to contain token abuse.
read more →

CISA Adds N‑able N‑central Flaw to KEV Catalog

🔒 CISA added a high‑severity vulnerability affecting N‑able N‑central to its Known Exploited Vulnerabilities (KEV) list after reports of active exploitation. Tracked as CVE-2026-18577, the flaw is an incomplete patch for CVE-2026-18556 and permits authentication bypass and account takeover; it is fixed in version 2026.3 HF1. N‑able and researchers note indicators such as a malicious "svchost.exe" in user documents, a service named "Cloudflared," and inbound connections from several VPN exit node IPs linked to Mullvad and NordVPN.
read more →

Insurance Phishing Evolves into Real-Time Account Hijacks

🔍 Recent research shows insurance-targeted phishing has shifted from credential harvesting to real-time session hijacking. Attackers use paid Google Ads and disposable hosting to lure victims to realistic portals and then relay OTPs and credentials to authenticate on the legitimate service while the victim is logged in. CTM360 identified a bespoke kit, InsureOTP Kit, and exposed backend infrastructure revealing live session management and operator workflows. Defenders must expand detection beyond malicious pages to include ad monitoring, infrastructure analysis, and attacker workflow intelligence.
read more →

Chick‑fil‑A reports credential stuffing breach

🔐 Chick‑fil‑A confirmed that more than 13,000 customers were impacted by credential stuffing attacks targeting its website and mobile app between June 17 and June 19. The attackers used credentials obtained from a third‑party source and accessed names, emails, membership numbers, Chick‑fil‑A credit amounts, mobile pay numbers, and card last four digits; some accounts may have also exposed birth dates, phone numbers, and addresses. The company logged out affected accounts, removed payment methods, restored balances, added rewards, and urged users to change passwords.
read more →

Man sentenced for mass Snapchat account hacks

🔒 An Illinois man received a 76-month prison sentence and three years supervised release after admitting to social engineering attacks that compromised over 750 women's Snapchat accounts to steal and trade nude photos. Between May 2020 and February 2021, he targeted thousands of users while impersonating Snap Inc., accessed at least 517 accounts to download explicit images, and enabled two-factor authentication to lock victims out. Investigators also found hundreds of CSAM files in his cloud storage, and he advertised hacking services online, using Kik to communicate with clients including a former coach who was separately convicted for hiring hacks.
read more →

First-person identity theft and email risk

🛡️ Harrowing first-person account of identity theft highlights how a single mistake—sharing a two-factor authentication code—enabled a scammer to seize the victim's email. The piece underscores that many online accounts are effectively secured by email access, making email compromise catastrophic. It emphasizes practical lessons about account recovery, 2FA methods, and attacker behaviors.
read more →

ConsentFix: OAuth-based Microsoft 365 account hijacking

🛡️Researchers uncovered a new ClickFix variant called ConsentFix that tricks users into granting OAuth tokens, enabling attackers to access Microsoft 365 accounts without stealing passwords. Attackers use deceptive pages and social engineering—often via phishing emails imitating file-sharing services—to induce victims to drag a tokenized URL onto an attacker-controlled page. Once obtained, the OAuth token can expose Outlook, Teams, OneDrive, SharePoint and other services depending on the organization’s license and privileges, enabling data exfiltration, BEC and lateral movement. The technique is widely shared on cybercrime forums with tutorials and turnkey tools, increasing its prevalence and lowering the barrier for novice threat actors.
read more →

Post-Breakup Digital Security Steps to Take Now

🔒 After a breakup, shared digital ties like accounts, subscriptions, and devices can leave you vulnerable if not properly separated. Review active sessions, update passwords and recovery options, and remove your ex from trusted devices and family-sharing settings. Revoke access to smart home devices, unlink payment methods, and cancel or recreate shared subscriptions. Use password managers, privacy tools, and support services to reclaim control and protect your safety.
read more →

Zoom fixes critical account-takeover vulnerability

🔒 Zoom disclosed and patched a critical vulnerability that could allow an unauthenticated attacker to perform an account takeover via network access, affecting several Windows clients and VDI branches. The company also fixed three privilege-escalation bugs across Zoom Workplace, Zoom Rooms, and related VDI plugins. Security experts warned the flaw is highly dangerous due to low complexity and no user interaction required, while praising Zoom for discovering and patching the issues.
read more →

Zoom issues urgent Windows security updates

🔒 Zoom released updates to patch a critical account-takeover vulnerability affecting several Windows clients and SDKs. The flaw, tracked as CVE-2026-53412 (CVSS 9.8), impacts Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows and could allow unauthenticated remote takeover. The advisory also fixes three high-severity escalation-of-privilege and TOCTOU bugs in various Workplace, VDI, plugin, Rooms, and Remote Control components; no active exploitation has been reported.
read more →

Zoom warns of critical Windows account takeover flaw

🛡️ Zoom has disclosed a critical vulnerability in its Windows desktop client and Meeting SDK that could allow an unauthenticated attacker to hijack accounts. Tracked as CVE-2026-53412 with a 9.8 severity score, the flaw affects several Windows releases including Zoom Workplace and VDI clients prior to the listed patched versions. The vendor described the issue as an improper input validation vulnerability and urged users to apply the latest updates to mitigate risk.
read more →