< ciso
brief />
Tag Banner

All news with #account takeover tag

213 articles · page 7 of 11

OfferUp scams surge: common frauds and protection guidance

🔒 OfferUp users face a range of scams — from counterfeit goods and overpayment ruses to account takeovers, phishing links and empty-box deliveries. The platform provides 48-hour Purchase Protection for qualified on-app purchases but excludes off‑app and cash transactions. Follow advised safeguards: stay in-app, avoid third-party payments, meet at Community Meetup Spots and protect verification codes and personal data.
read more →

Coinbase Confirms Contractor Insider Breach of Support Data

🔒 Coinbase confirmed that a contractor improperly accessed data for approximately 30 customers in a December incident, and the individual no longer performs services for the company. Impacted users were notified, provided identity theft protection services, and Coinbase disclosed the incident to relevant regulators. Screenshots of an internal support panel briefly appeared on Telegram and were associated with the 'Shiny Lapsus Hunters' posts, showing customer PII, KYC details, and wallet balances, though attribution remains unclear.
read more →

Multi-stage PDF phishing uses Dropbox to harvest logins

📄 Forcepoint researchers describe a multi-stage phishing campaign that uses attached PDFs to redirect victims through cloud-hosted content to a fake Dropbox sign-in page. Attackers exploit spoofed or compromised senders and trusted services to bypass filters and authentication checks like SPF, DKIM, and DMARC. If credentials are entered they’re exfiltrated to attacker-controlled infrastructure for account takeover and fraud. The campaign succeeds because each step appears legitimate in isolation, exploiting habitual trust in PDFs and mainstream cloud services.
read more →

Panera Bread breach affects 5.1M accounts, not 14M customers

🔒 Have I Been Pwned reports that a January 2026 data breach at Panera Bread exposed roughly 5.1 million unique email addresses and associated contact information, rather than 14 million distinct customers as initially claimed. The files, totaling about 760 MB, were published by the ShinyHunters extortion group after an alleged failed ransom attempt. ShinyHunters says it gained access via a Microsoft Entra SSO code as part of a broader vishing campaign targeting SSO providers. Panera has confirmed the incident to authorities and said the data is contact information.
read more →

Google Disrupts IPIDEA Residential Proxy Network at Scale

🔒 Google Threat Intelligence Group, working with industry partners, disrupted the IPIDEA residential proxy network by taking down domains, infected-device management systems, and proxy-traffic routing infrastructure. The operation targeted SDKs embedded in at least 600 trojanized Android apps and over 3,000 malicious Windows binaries, which collectively enrolled about 6.7 million devices worldwide. GTIG reported that more than 550 distinct threat groups abused IPIDEA for account takeovers, credential theft, botnet control, and DDoS support; users should avoid untrusted VPNs and apps that pay for bandwidth.
read more →

Six Okta Security Settings You May Have Overlooked

🔐 Identity providers like Okta are central to modern SaaS security, and subtle configuration gaps can create serious exposure. This article highlights six fundamental settings—password policies, phishing‑resistant MFA, ThreatInsight, admin session ASN binding, session lifetimes, and behavior rules—that reduce the risk of account takeovers and session hijacking. Complementing these controls with continuous monitoring from Nudge Security helps detect drift and remediate misconfigurations before they’re exploited.
read more →

Appsmith authentication flaw enables account takeovers

🔒 A critical authentication vulnerability (CVE-2026-22794) in the Appsmith low-code platform allowed attackers to manipulate password reset links by supplying a malicious HTTP Origin header, causing reset tokens to be redirected to attacker-controlled infrastructure. Exploitation can lead to full account takeover, including administrator access. The flaw affects Appsmith 1.92 and earlier and was corrected in 1.93; internet scans identified 1,666 publicly accessible instances.
read more →

PcComponentes denies 16M breach, cites credential stuffing

🔒 PcComponentes says it found no evidence of unauthorized access after investigating claims that a threat actor leaked a 16.3 million‑record customer dataset, but confirmed its platform was targeted in a credential stuffing campaign. The actor posted a 500,000‑record sample and offered the remainder for sale. The company asserts no payment details or passwords are stored and that only a small number of accounts showed exposure of personal data. PcComponentes has deployed CAPTCHA, mandated two‑factor authentication and invalidated active sessions.
read more →

Old Habits Die Hard: 2025’s Most Common Passwords Worldwide

🔐 Two 2025 analyses by NordPass and Comparitech show that simple numeric strings like '123456' continue to dominate leaked password lists worldwide. Across 44 countries, 25% of the top 1,000 passwords are purely numeric, while predictable entries such as 'admin', '12345678' and '12345' remain widespread, including in the US and UK. Security advice is clear: change weak or reused passwords, use a reputable password manager, and enable two‑factor authentication or passkeys to reduce account takeover risk. Organizations should combine technical controls with user training to mitigate large‑scale exposure.
read more →

Hacker Pleads Guilty After Leaking Supreme Court Data

🔓 Nicholas Moore, 24, pleaded guilty to hacking the U.S. Supreme Court's restricted electronic filing system and breaching AmeriCorps and VA accounts. Prosecutors say Moore used stolen credentials to access the Court's system at least 25 times between August and October 2023, sometimes logging in multiple times per day, and posted screenshots and victims' data to an Instagram account, @ihackedthegovernment. He also accessed an AmeriCorps account seven times and a VA My HealtheVet account five times, viewing sensitive personal and health information. Moore admitted to one count of computer fraud.
read more →

Malicious Google Chrome Extensions Hijack Workday and Netsuite

🔒 Security researchers at Socket have identified a set of malicious Google Chrome extensions that targeted major HR and ERP platforms including Workday, Netsuite and SAP SuccessFactors. The extensions, which masqueraded as productivity tools, stole authentication cookies and session tokens, uploading them to a command-and-control server and revisiting targets every 60 seconds. More than 2,300 users downloaded the extensions from the Chrome Web Store before they were removed. Socket recommends using Chrome Enterprise extension allowlists and monitoring for extensions with similar platform targeting and permission requests.
read more →

Malicious Chrome extensions hijack enterprise sessions

🔒 A cluster of five malicious Chrome extensions posed as productivity tools but exfiltrated session cookies to attacker-controlled infrastructure, enabling account takeover. Researchers from Socket.dev identified variants such as DataByCloud Access, Data By Cloud 1/2, Software Access and Tool Access 11 targeting HR and ERP platforms like Workday, NetSuite and SuccessFactors. Some extensions stole cookies as often as every 60 seconds and used cookie injection (e.g., chrome.cookies.set()) while others blocked admin security pages, hampering incident response.
read more →

Chrome Extensions Impersonating Workday and NetSuite

⚠ Security researchers uncovered five malicious Chrome extensions that impersonate HR and ERP platforms, including Workday and NetSuite, to harvest authentication tokens and facilitate session takeovers. The add-ons exfiltrate cookies to attacker-controlled APIs, manipulate DOM content to block administrative pages, and can inject stolen cookies to hijack sessions. Most were removed from the Chrome Web Store but remain available on third-party download sites; affected users should remove the extensions, reset credentials, and audit for unauthorized access.
read more →

Account Compromise Soars 389% in 2025: eSentire Report

🔐 eSentire's 2025 Year in Review (published 15 Jan 2026) documents a 389% year‑over‑year surge in account compromises, which accounted for 55% of observed attacks. Credential access comprised 75% of malicious activity, with Microsoft 365 accounts heavily targeted and two‑thirds of compromises used for account takeovers. Phishing‑as‑a‑service (PhaaS) kits — including Tycoon2FA, FlowerStorm and EvilProxy — fueled many Business Email Compromise operations, while malware represented 25% of threats, down slightly from 2024.
read more →

When Your Personal Data Appears on the Dark Web - What to Do

🔒 If you learn your personal or financial data is on the dark web, act quickly: cybercriminals use stolen PII, credentials, session cookies and payment details to commit account takeover, identity theft and fraud. Immediately change compromised passwords, enable MFA (prefer authenticator apps or hardware keys), sign out of all devices, scan for infostealer malware and contact your bank to freeze or reissue cards. For longer-term protection, freeze credit, tighten privacy settings, use email aliasing and a password manager, and enroll in monitoring services such as HaveIBeenPwned.
read more →

Apex Legends players hit by in-match character hijacks

🎮 Players of Apex Legends faced in-match disruptions over the weekend as external actors reportedly took control of characters, forced disconnects, and changed player nicknames. Respawn acknowledged "an active security incident" but said initial investigation found no evidence of an RCE or malware infection. The publisher reported the issue was resolved within hours and suggested cheating tools were involved while the investigation continues.
read more →

Credential stuffing: risks and protection advice today

🔐 Credential stuffing exploits reused login credentials harvested from breaches or captured by infostealer malware, then systematically automates login attempts across services. Attackers increasingly use bots, IP rotation and AI-assisted scripts to mimic human behavior and evade basic defenses, enabling stealthier and larger-scale attacks. Because it uses valid credentials, it often bypasses alarms that detect brute-force failures. Protect yourself with a password manager, enable 2FA/MFA, and monitor for exposed credentials.
read more →

Open WebUI Direct Connections flaw risks account takeover

⚠️ A high-severity vulnerability (CVE-2025-64496) affecting Open WebUI versions 0.6.34 and earlier can enable account takeover when the Direct Connections feature is enabled. A malicious OpenAI-compatible model server can send a crafted server-sent events message that executes JavaScript in a connected user's browser and steals authentication tokens from localStorage. Open WebUI 0.6.35 and later block the malicious execute events; administrators should upgrade immediately, restrict Direct Connections to trusted endpoints, and strengthen authentication and sandboxing.
read more →

Former Coinbase Support Agent Arrested in India After Breach

🔒 A former Coinbase customer support agent was arrested in Hyderabad after investigators linked the individual to a scheme that helped hackers access a company database earlier this year. Coinbase CEO Brian Armstrong said additional arrests are expected. The incident, tied to outsourced agents at TaskUs, affected about 69,500 customers and involved a $20 million ransom demand.
read more →

Massive Rainbow Six Siege breach grants billions of credits

🚨 Ubisoft's Rainbow Six Siege suffered an in‑game abuse incident that allowed attackers to ban and unban players, display fake ban messages, and grant approximately 2 billion R6 Credits and Renown to accounts worldwide. Ubisoft confirmed the issue at 9:10 AM Saturday, intentionally shut down Siege and its Marketplace while teams investigated, and said transactions since 11:00 UTC will be rolled back. The company stated players will not be punished for spending the granted credits.
read more →