Topic: account takeover
-
Account Takeover Threats Are Rising: Key Prevention Tips
Account takeover attacks are surging as attackers exploit the complexity of managing identities across cloud services, BYOD policies, and remote environments, often by compromising legitimate accounts rather than infrastructure. Attackers bypass traditional defenses like MFA through sophisticated...
Read More » -
Mirage2FA phishing kit steals Microsoft 365 credentials via HTML smuggling
The Mirage2FA phishing kit targets Microsoft 365 users by using HTML smuggling and obfuscated JavaScript to steal credentials, bypassing multi-factor authentication through fake prompts for authenticator apps and number matching. The attack begins with business-themed email lures containing HTML ...
Read More » -
How Fraudsters Use Bots to Hijack Accounts
Modern digital fraud operates as a coordinated chain, using specialized tools for automated account creation and human-driven sessions to evade detection by single-point security checks. Relying on isolated risk signals like IP reputation or email domains leads to false positives and is easily by...
Read More » -
Inside the Market for Stolen Login Credentials
Cybercriminals have evolved from selling bulk credential dumps to offering targeted "search-your-target" services, where buyers can request credentials for specific companies, platforms, or regions from massive infostealer databases. Analysis of 470 underground forum posts reveals a dedicated ser...
Read More » -
Major PS5 Security Flaw Puts All Users at Risk
A critical PSN security vulnerability has been uncovered that relies on social engineering, not hacking, where customer support agents can be persuaded to grant account access using easily obtained details like a username, email, and a purchase date or transaction ID. Attackers can infer purchase...
Read More » -
Beyond Credentials: Why Device Trust Matters in the AI Era
AI has accelerated identity-based attacks by making phishing, credential theft, and MFA bypass faster and more scalable, while traditional trust signals like IP reputation and geolocation are now easily spoofed by attackers using residential proxies and rotating identities. Device trust is emergi...
Read More » -
State-Backed Phishing Targets Military, Journalists on Signal
German authorities warn of a state-backed phishing campaign targeting European elites, exploiting the Signal app to compromise high-profile individuals for espionage, with techniques adaptable for criminal use. Attackers use two primary methods: impersonating Signal support to trick victims into ...
Read More » -
Critical SimpleHelp RMM bug CVE-2026-48558 exposes endpoints to takeover
A critical unauthenticated vulnerability (CVE-2026-48558) in the SimpleHelp RMM platform allows attackers to remotely create a "Technician" account, enabling full control over managed networks and endpoints. The flaw requires no authentication or user interaction, and due to SimpleHelp's deep sys...
Read More » -
Email Breaches: The Silent Threat to Your Business Growth
78% of organizations experienced an email security breach in the past year, primarily through phishing, impersonation, and account takeover, which often lead to ransomware and data loss. The consequences of breaches include reputational damage, operational downtime, and lost business, with smalle...
Read More » -
Microsoft 365 Accounts Hijacked in 3 Seconds via ConsentFix & ClickFix
A new attack variant called ConsentFix targets Microsoft 365 by tricking users into dragging a localhost callback link into their browser, which surrenders OAuth tokens and bypasses passwords and multi-factor authentication. These attacks succeed by exploiting trained user habits, such as clickin...
Read More » -
The Hidden Vulnerabilities in Email Security
Email is the primary cyberattack vector, with malware, scams, and phishing attempts surging by over 130%, 30%, and 20% respectively, causing widespread operational disruptions. Over 78% of organizations experienced an email breach last year, with phishing and impersonation being the most common m...
Read More » -
Microsoft Warns of "Payroll Pirate" Scam Targeting Employee Paychecks
A phishing campaign called "Payroll Pirate" targets corporate HR accounts to redirect employee paychecks into criminal-controlled bank accounts by manipulating platforms like Workday. Attackers use adversary-in-the-middle techniques to intercept login credentials and multi-factor authentication c...
Read More » -
Google Workspace gets unified email, file & OAuth security
Modern cyber threats are unified: attacks combine phishing, data exposure, and OAuth abuse, but traditional siloed security tools fail to connect these signals, leaving breaches undetected for an average of 241 days. Material Security consolidates email security, sensitive data protection (PHI/PI...
Read More » -
Beware: New Phishing Scam Steals Dropbox Passwords
A sophisticated phishing campaign targets corporate cloud storage credentials by using urgent, professional-looking emails that evade standard security protocols like SPF and DKIM. The attack employs a PDF attachment with a malicious link, hosted on legitimate cloud infrastructure to bypass autom...
Read More » -
Bank of America scams use ScreenConnect to hijack PCs
A phishing campaign targets Bank of America customers, primarily on Windows PCs, by tricking them into installing the remote access tool ScreenConnect, which grants attackers full control and is configured to resist removal. Mac users face a separate phishing variant that lures them to a fake BoA...
Read More » -
US offers $10M reward for info on Signal and WhatsApp hackers
The U.S. government has placed a $10 million bounty for information leading to the capture of a Russian state-sponsored cyber group that hacked thousands of Signal and WhatsApp accounts, targeting journalists and U.S. government employees. The hacking operation, active since at least March, invol...
Read More » -
Malicious Chrome Extensions Steal HR Platform Credentials
Malicious Chrome extensions disguised as legitimate tools were discovered stealing login credentials and sabotaging security functions on major enterprise HR and ERP platforms. The extensions enabled persistent account access through continuous cookie theft and actively blocked critical security ...
Read More » -
Microsoft Blames North Korea for Mastra AI Supply Chain Attack
North Korean state-sponsored group Sapphire Sleet (also known as APT38 and BlueNoroff) conducted a sophisticated supply chain attack on the Mastra npm framework by compromising a maintainer account and injecting malicious code. The attack affected over 140 packages and delivered a cross-platform ...
Read More » -
MSP Security Webinar: Rethinking Protection and Recovery
AI-powered phishing and sophisticated ransomware are now primary threats that evade conventional security tools, demanding a fundamental shift in defense strategies. The webinar argues that security alone is insufficient, advocating for an integrated strategy that combines prevention, detection, ...
Read More » -
AMOS Infostealer Targets macOS via Popular AI App
The cybercrime economy is increasingly fueled by sophisticated infostealer malware like AMOS, which harvests and sells stolen credentials, financial data, and session cookies to enable further fraud and network intrusions. Attackers distribute this malware through highly adaptive social engineeri...
Read More »