Back to Feed

Tag

Identity & Access

IAM, MFA bypass, credential theft, authentication

50 items tagged #identity-access

Articles

Deleted Google API Keys Remain Active up to 23 Minutes, Study Finds

Deleted Google API keys remain active for up to 23 minutes due to eventual consistency delays.

Hackers bypass SonicWall VPN MFA due to incomplete patching

SonicWall Gen6 SSL-VPN devices remain vulnerable to MFA bypass despite patching without manual LDAP reconfiguration.

Uruguay DNIC allegedly leaked: 5.8M citizen database records exposed

Uruguay DNIC citizen database with 5.8M records allegedly leaked on underground forum

Lul... CISA Admin Leaked AWS GovCloud Keys on GitHub https://t.co/V8j07muRXS

CISA administrator accidentally exposed AWS GovCloud credentials on GitHub.

Grafana says stolen GitHub token let hackers steal codebase

Grafana Labs' GitHub environment breached via stolen token; source code stolen by CoinbaseCartel extortion gang.

Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing

Tycoon2FA phishing kit adds device-code attacks to hijack Microsoft 365 accounts via Trustifi URLs.

Scammers Send Physical Phishing Letters to Steal Ledger Wallet Seed Phrases

Scammers mail fake Ledger phishing letters with QR codes to steal crypto wallet seed phrases from Italian users.

Critical ‘Claw Chain’ Vulnerabilities Put Thousands of OpenClaw AI Servers at Risk

Four critical vulnerabilities in OpenClaw AI servers enable data theft, backdoors, and admin-level compromise.

The Next Cybersecurity Challenge May Be Verifying AI Agents

Industry develops verification standards for autonomous AI agents operating in enterprise systems.

Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution

REMUS infostealer malware evolves into MaaS platform targeting session tokens and password managers.

1/2‼️🇧🇷 Nuvidio allegedly breached: 40K files including KYC records, biometrics, private keys,...

Brazilian identity verification provider Nuvidio allegedly breached; 40K files with KYC, biometrics, private keys

1/2‼️🇬🇹 Guatemalan Ministry of Finance allegedly breached: 130,000 RGAE registrations and 235,0...

Guatemalan Ministry of Finance allegedly breached; 130K RGAE registrations and 235K PDFs exposed via IDOR.

Cyber-Enabled Cargo Crime: How Cybercrime Tradecraft is Used to Steal Freight

Cyber-enabled cargo crime uses phishing and stolen credentials to redirect freight shipments to criminal warehouses.

mutreasury Allegedly Breached: Admin Credentials and API Keys Exposed From the Egyptian University Payment Gateway Covering 28+ Universities, Sold With a Zero-Day Vulnerability

mutreasury payment gateway breach exposes admin credentials, API keys, and student data from 28+ Egyptian universities;

Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike

Ghostwriter targets Ukrainian government with geofenced PDF phishing delivering Cobalt Strike.

KongTuke hackers now use Microsoft Teams for corporate breaches

KongTuke IAB now exploits Microsoft Teams for social engineering, delivering ModeloRAT in under five minutes.

Siemens Opcenter RDnL

Siemens Opcenter RDnL affected by missing authentication in ActiveMQ Artemis (CVE-2026-27446)

How AI Hallucinations Are Creating Real Security Risks

AI hallucinations pose critical security risks in infrastructure decision-making through confident but inaccurate

Your iPhone Gets Stolen. Then the Hacking Begins

Underground ecosystem sells iPhone unlocking tools and phishing kits to criminals targeting stolen devices.

Iranian hackers targeted major South Korean electronics maker

Iran-linked MuddyWater targets South Korean electronics maker and 8+ orgs in espionage campaign.

Packagist Urges Immediate Composer Update After GitHub Actions Token Leak

Composer vulnerability exposed GitHub Actions tokens in CI logs due to token format validation regex mismatch.

Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises

Microsoft patches critical zero-click Outlook RCE vulnerability CVE-2026-40361 affecting enterprises.

Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator

Fortinet patches critical RCE flaws in FortiSandbox and FortiAuthenticator.

FutureShop Egypt Allegedly Breached Exposing Thousands of Customer, Order, and Delivery Records From the Egyptian Grocery Delivery Platform

FutureShop Egypt breached via unauthenticated API exposure, leaking 3,893 customer profiles and 5,181 orders.

Fake Claude Code Installer Targets Developers With Browser Credential Stealer

Fake Claude Code installer malware targets developers to steal browser credentials and encryption keys.

Android 17 to expand banking scam call and privacy protections

Android 17 introduces banking scam call detection, device theft protection, and expanded threat detection features.

Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise

Microsoft incident response reveals stealthy third-party compromise exploiting trusted HPE operations agent.

When Responder forces a NetBIOS election and wins https://t.co/wihk8U3OKM

Responder tool exploits NetBIOS election mechanism to intercept network traffic.

OLG Stuttgart - 4 U 353/24

German appeals court partially upholds GDPR data subject rights against social media company tracking via third-party

ABB WebPro SNMP Card PowerValue Multiple Vulnerabilities

ABB WebPro SNMP Card PowerValue contains three critical vulnerabilities enabling authentication bypass and DoS attacks.

Customer data exposure at CB Financial Services (CBFV) prompts material cybersecurity filing

CB Financial Services discloses material breach exposing customer names, SSNs, birthdates via unauthorized AI app.

1/2‼️🇮🇳 BLS International allegedly breached exposing 29 million records, source code, and SSH...

BLS International breach exposes 29M records, source code, SSH keys from Indian visa services provider

Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation

Google discloses first known zero-day 2FA bypass likely developed using AI by unknown threat actors.

Why Changing Passwords Doesn’t End an Active Directory Breach

Password resets alone don't remove attackers from AD; cached credentials and Kerberos tickets enable persistence.

Google Detects First AI-Generated Zero-Day Exploit

Google identifies first AI-generated zero-day exploit designed to bypass 2FA on web administration tool.

Hackers Exploit Vercel GenAI to Mass-Produce Convincing Phishing Sites

Hackers abuse Vercel GenAI to mass-produce convincing phishing sites mimicking Microsoft, Adidas, Nike.

Over 500 Organizations Hit in Years-Long Phishing Campaign

Operation HookedWing phishing campaign steals 2,000+ credentials from 500+ organizations over four years.

Hackers Trick DigiCert Into Issuing Certificates Used to Sign Malware

DigiCert revokes 60 code signing certificates after attackers breach support systems to issue malware signatures.

‼️9,500 passport and national ID card scans allegedly being sold mainly from France and Turkey A...

Threat actor selling 9,542 passport and ID card scans from France, Turkey, and other nations.

We observed a phishing campaign pivot to evade static analysis, shifting from credential theft to...

Phishing campaign pivots to OAuth device code attacks using runtime-fetched landing pages.

Ransomware negotiator tied to $56M in attacks was sentenced, DPRK-linked fraudulent IT worker sch...

Ransomware negotiator sentenced for $56M attacks; DPRK IT fraud disrupted; PCPJack targets cloud credentials; Palo Alto

‼️🇦🇺 1,169 Australian websites allegedly being sold as full panel access by a single threat act...

Threat actor claims to be selling full admin access to 1,169 Australian websites.

Security Incident Update & FAQs

Instructure Canvas LMS suffers unauthorized access via Free-For-Teacher account vulnerability; personal data of

Community Choice Credit Union Allegedly Breached Exposing 1M+ Premium Credit Client Records

Community Choice Credit Union allegedly breached; 1M+ premium client records with full card numbers exposed.

‼️🇺🇸 Community Choice Credit Union Allegedly Breached Exposing 1M+ Premium Credit Client Record...

Community Choice Credit Union allegedly breached, exposing 1M+ premium client records.

Former govt contractor convicted for wiping dozens of federal databases

Former federal contractor convicted for destroying 96 government databases after termination.

ShinyHunters got access to Canvas infrastructure from ... "Vishing". Social engineering. WHY IS...

ShinyHunters breach Canvas infrastructure via vishing social engineering attack.

Vulnerability in Claude Extension for Chrome Exposes AI Agent to Takeover

ClaudeBleed vulnerability in Claude Chrome extension allows attackers to hijack AI agent via prompt injection.

Instructure Status

Instructure Canvas suffers confirmed security breach; names, emails, student IDs, and messages compromised.

Canvas login portals hacked in mass ShinyHunters extortion campaign

ShinyHunters defaced Canvas login portals for 330 schools in extortion campaign.