N0va Phishing Kit Hijacks Real Microsoft Logins to Steal Session Tokens
A new phishing kit called N0va abuses legitimate device-code authentication flows for Microsoft, Google, and other trusted services to steal access and refresh tokens rather than passwords. The...
Lenovo ID Trust Flaw Opened About 5,000 Dropbox Accounts to Takeover
Dropbox says attackers compromised roughly 5,000 accounts by creating Lenovo IDs with victims’ email addresses and abusing a federated-login integration. The incident demonstrates why matching email claims cannot...
New ‘Pass-ta-key’ Attacks Show How Malware Can Silently Hijack Google’s Synced Passkeys
Unit 42 researchers have detailed three escalating attack techniques that let malware already on a Windows PC take over Google-synced passkeys without ever triggering a password, PIN, or...
Meta AI Flaw Lets Attackers Hijack Instagram Accounts Without Verification — Premium Handles Worth $1M+ Stolen
A critical flaw in Meta's AI account recovery tool allowed attackers to trick the chatbot into sending password reset codes with no identity verification, enabling theft of premium...
Google Chrome’s Device-Bound Session Credentials Go GA — Cryptographically Kills Cookie-Theft Attacks
Google has moved Device Bound Session Credentials (DBSC) to general availability in Chrome on Windows, cryptographically binding session cookies to the originating device via TPM. Enabled by default...