ZeroHour

Search: “eBay”

29 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Google Password Manager Attacks Could Let Malware Hijack Passkey

Unit 42 details three attack paths letting Windows malware silently sign into passkey-protected accounts via Chrome's Google Password Manager without user verification.

Palo Alto Networks Unit 42 described three post-compromise attack paths—Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key—against Chrome's Google Password Manager cloud authenticator on TPM-equipped Windows systems. The attacks can silently obtain valid authentication assertions, install attacker-controlled user-verification keys, or extract the 32-byte Security Domain Secret used to decrypt synced passkey private keys, enabling reusable access from the attacker's own environment. No CVE was assigned and no exploitation in the wild was reported; demonstrations were validated against Chrome 142 and parts of the architecture are corroborated by Chromium source. GitHub enforced the User Verified flag check, while eBay accepted a test assertion lacking it before fixing its validation gap after disclosure.

The Hacker News · Aug 11, 2026Research

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing

Three research teams showed passkey bypasses: WebAuthn assertion replay in Microsoft Entra ID, synced-passkey key recovery in Google Password Manager, and Windows Hello key reuse.

SpecterOps' Pass-the-Passkey research showed Windows stored past YubiKey signatures in cleartext and chained this with Microsoft Entra ID passkey validation weaknesses to impersonate privileged users despite phishing-resistant MFA; the Windows Event Logging Service issue is tracked as CVE-2026-34348 (CVSS 6.5) and fixed in July 2026 updates. Unit 42's Golden Pass-ta-key attack recovered the 32-byte Security Domain Secret protecting Google Password Manager synced passkeys from Chrome on Windows via pre-existing malware. Dirk-jan Mollema showed in-session malware can use a hardware-bound Windows Hello for Business key without a fresh PIN or biometric check. Microsoft applied Entra-side mitigations for the relay assertion issue; no real-world exploitation has been reported.

The Hacker News · Aug 11, 2026VulnerabilityCVE-2026-34348

Panic builds over bankrupt Spirit’s looming data sale to Google

Startups object to Google's bankruptcy-auction purchase of Spirit Airlines operational data, claiming proprietary IP is being sold without consent.

Google won an auction to acquire a large enterprise dataset from bankrupt Spirit Airlines, which it says will help improve its products and AI models, with no personal information included. Springshot, whose airline logistics platform powered Spirit's stack, filed a limited objection arguing the vaguely defined data categories could transfer third-party IP and trade secrets it owns; International Aero Engines filed a similar objection. The EFF called it the first public bankruptcy proceeding over selling company and employee data as an asset, and objectors warn of a precedent letting large companies acquire startup IP through bankruptcy courts.

Ars Technica · AI · 6d agoAI industry

Proofpoint Strengthens Executive Leadership Team with Appointment of Chief Legal Officer and Chief People Officer

Proofpoint appointed Brian Levey as Chief Legal Officer and Puja Jaspal as Chief People Officer, strengthening its executive leadership team.

Proofpoint announced on September 8, 2026 the appointments of Brian Levey as Chief Legal Officer and Puja Jaspal as Chief People Officer. Levey previously served as Chief Business Affairs & Chief Legal Officer at Upwork and spent 13 years at eBay; Jaspal was Chief People Officer at Fastly with prior senior roles at Cisco, Visa, and Google. The hires support Proofpoint's stated expansion around human and AI-agent security.

Proofpoint Threat Insight · 8d agoIndustry

Driver’s License Data for Sale

Schneier on Security highlights that driver's license data is being sold, underscoring concerns over monetization of driver records and surveillance.

A post on Bruce Schneier's blog is titled 'Driver's License Data for Sale.' The available excerpt contains no article body, so the specifics of the reported data sales are not detailed. The topic concerns the commercial availability of driver's license records, a recurring data-privacy and surveillance theme on the blog.

Schneier on Security · 7d agoData breach

Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware

Attackers with Brevo DNS access injected malicious scripts serving ClickFix malware and WordPress backdoors to over 100,000 customer sites on 14 September 2026.

Brevo (formerly Sendinblue), an email marketing platform whose clients include eBay, Louis Vuitton, Michelin and Amnesty International, served injected JavaScript from sendibt1.com domains between 16:05 and 20:12 UTC on 14 September 2026, reaching over 100,000 customer sites and mailing lists. The f.js malware secretly installed a WordPress backdoor plugin from cdn10.sendibt1.com/p/wm.zip using logged-in admins' sessions and showed ClickFix overlays urging visitors to copy-paste and run commands. An SSL certificate for cdn.sendibt1.com created August 25 and attacker-created cdn* DNS records indicate write access to Brevo's Cloudflare DNS, likely via a single Cloudflare account compromise. Sansec recorded 2,549 CSP violation reports across 12 monitored sites; all malicious hosts stopped resolving on 15 September and Brevo's status page lists no incident.

Sansec (Magento / e-commerce security) · 19h agoMalware in the wild

“Zlibrary my beloved”: Anthropic staff chats extolling piracy cited in Sony suit

Sony's copyright lawsuit against Anthropic now cites internal staff chats praising Z-Library piracy as evidence in the AI training-data dispute.

Sony's lawsuit against Anthropic cites internal staff chats in which employees extolled pirating books from Z-Library, according to Ars Technica. The suit forms part of the broader copyright dispute over torrented works used to train AI models. The article also notes AI-generated songs reaching the top of music charts, raising stakes for songwriters in the case.

Ars Technica · AI · 16d agoAI policy

Scammers are getting smarter about where they target you

Malwarebytes data shows scammers tailor fraud by platform: 90% of toll scams arrive via email/SMS and MrBeast is now the most impersonated person.

Malwarebytes threat research analyzed global scam data from April 15 to July 14, 2026, across more than 20 scam types, finding each type favors a specific channel such as email, SMS, phone, or social media. Roughly nine in ten toll scams arrive by email or text, about half of IRS scams come by phone, and MrBeast is impersonated in about 30% of impersonation scams. The most impersonated brands are Google, Microsoft, Apple, Roblox, and Amazon, and Malwarebytes blocks around 500,000 phishing websites daily. Gaming scams on Roblox, Steam, Discord, and Minecraft increasingly carry losses of $1,000 or more, with 15-19% activity spikes in mid-2026.

Malwarebytes Labs · 14d agoPhishing & fraud

Ready-made $500 kit puts a crypto scam within anyone's reach

A $500 ready-made scam kit sold on a cybercrime forum builds fake Tesla $TSLA presale pages that harvest wallet recovery phrases and cryptocurrency deposits.

Malwarebytes found a $500 scam-in-a-box kit by seller xrep on a cybercrime forum, bundling a fake Tesla-style $TSLA presale site, a victim-tracking admin panel, and controls to inflate fake balances. The kit harvests 12-word wallet recovery phrases via wallet-connection prompts or accepts direct transfers in Bitcoin, Ethereum, USDT, or Dogecoin. The admin panel lets operators check stolen wallets' value before draining them, raise displayed balances to encourage further deposits, and send follow-up messages demanding fake network fees.

Help Net Security · Aug 12, 2026Phishing & fraud

[webapps] CubeCart 6.7.4 - Stored XSS

A proof-of-concept stored cross-site scripting exploit targeting CubeCart 6.7.4 was published on Exploit-DB.

Exploit-DB lists a proof-of-concept exploit for a stored cross-site scripting (XSS) vulnerability in CubeCart 6.7.4, a PHP-based e-commerce web application. The listing demonstrates injection of attacker-controlled script that persists in the application, but no exploitation in the wild or CVE assignment is reported in the provided text.

Exploit-DB · 16d agoExploit / PoC1

Meme Coin Factories: Uncovering Large-Scale Manipulations on pump.fun

Large-scale pump.fun study of 15 million meme coins identifies five manipulation classes including wash trading and a Market-Manipulation-as-a-Service ecosystem.

Researchers analyzed all 15 million coins launched on pump.fun over the last two years plus large random samples of transaction data, identifying five manipulation classes: wash trading, creator address obfuscation, coordinated sells, copycat coins, and social media manipulation. Strategic actors bypass the platform interface and implement strategies in a highly automated, low-latency way by interacting directly with the blockchain. The study also uncovers Market-Manipulation-as-a-Service (MMaaS) third-party tools that let non-technical users run these manipulations, and proposes mitigations for traders, pump.fun, and regulators.

arXiv cs.CR · 7d agoResearch

Scammers have figured out the best time to text you

Malwarebytes threat data shows scammers tailor platforms per scam, with the web as top channel, Friday midday peaks, and MrBeast the most impersonated person.

Malwarebytes analyzed its threat data from April 15 to July 14, 2026 across more than 20 scam categories, finding scammers match platforms to scam types: job scams via email, romance scams via social media, and tech support scams via phone. The web is the top delivery channel ahead of email and SMS, and Malwarebytes says it blocks about 500,000 phishing sites a day. Scam texts peak at 12:00 pm ET, roughly 874% above the quietest hour, with volume peaking on Fridays about 50% higher than the start of the week. MrBeast (Jimmy Donaldson) appears in about 30% of impersonation scams, and the most impersonated brands are Google, Microsoft, Apple, Roblox and Amazon.

Help Net Security · 12d agoPhishing & fraud in the wild

ICE Wants to Know Everyone Who Bought a Certain Green Beanie From REI in the Last 2 Years

DHS subpoenaed REI for all Minneapolis-area customers who bought a specific green beanie since 2024, part of an investigation into 39 ICE protest defendants.

Court filings allege Homeland Security Investigations agents subpoenaed REI in March for transaction records of all persons in the greater Minneapolis–St. Paul area who purchased a specific dark green beanie since 2024. The subpoena was one of 92 sent in a federal case against 39 people, including journalists, who attended an ICE protest at a church. Companies responded differently: T-Mobile handed over six months of a defendant's call and text logs, Google refused a request for YouTube viewers, Reddit withdrew after a First Amendment objection, and Meta pushed back on at least one summons. The 1509 customs summonses require no judicial oversight, and the total number issued under the Trump administration is unknown.

WIRED · Security · 12d agoPolicy & legal

Merchants of Insecurity

Opinion essay titled Merchants of Insecurity, apparently critiquing security industry practices; no article body was included in the feed.

The feed provides only the title and a comments link for this Lobsters-shared post from blog.happyfellow.dev; no article text was available. Based on the title, it appears to be an opinion piece about incentives in the security industry, possibly arguing vendors profit from perpetuating insecurity.

Lobsters · security · 21d agoIndustry

Google Search Makes It Harder to See Where a Link Really Goes Before You Click

Google now routes some Search results through opaque google.com/goto redirects, weakening hover-to-verify anti-phishing checks.

Google has begun serving some organic search results as opaque google.com/goto?url= redirects whose destinations can only be resolved server-side by Google, likely to raise scraping costs for rank trackers and archival services. The change removes the pre-click hover preview of the true destination URL, undermining a long-standing anti-phishing habit for spotting lookalike, typosquatted, or search-optimized phishing domains. Security teams are advised to rely on layered defenses such as domain reputation, DNS and web filtering, browser isolation, and user training rather than hover text.

GBHackers · 1d agoIndustry

Chinese Routers Sold Worldwide Contain Backdoors

Manufacturer-built backdoor implants were found in ZBT white-label routers sold worldwide, exposing affected devices to potential unauthorized access.

An untold number of ZBT routers distributed globally as white-label products contain multiple backdoor implants built into the devices by the manufacturer. The implants are pre-installed through the hardware and firmware supply chain rather than injected by attackers after deployment. The scale of affected deployments and whether the implants have been actively abused have not been disclosed.

Dark Reading · 19d agoVulnerability

From Infostealer Log to Marketplace Listing: A Technical Walkthrough of the Credential Theft Pipeline

Cyble walkthrough maps how infostealer logs move from endpoint infection through aggregation and enrichment to dark web credential marketplace sales.

Cyble breaks the credential theft pipeline into stages: infostealer execution harvesting browser credential stores, cookies, session tokens, crypto wallets, and FTP configurations; aggregation of stealer logs via C2 panels into bundled archives; parsing and enrichment against previously leaked datasets; and final listing on dark web marketplaces. Enrichment adds employer and role context that raises prices and enables credential stuffing across reused passwords. The report advises SOC teams to monitor stealer logs and marketplace chatter early rather than waiting for breach alerts.

Cyble · 6d agoMalware1

Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs

Rapid7 research uncovered dark web marketplaces trading executive Social Security numbers, fueling synthetic identity fraud and unauthorized lines of credit.

Rapid7 threat research documents dark web marketplaces where stolen executive Social Security numbers are bought and sold, a tier of the cybercrime ecosystem more durable than stolen payment cards because SSNs cannot be deactivated. Exposed SSNs enable unauthorized credit lines, synthetic identity fraud, and long-term impersonation. The article cites FTC statistics of over 1 million identity theft reports annually, with related fraud and imposter scams causing billions in losses each year.

Rapid7 Blog · 20d agoResearch

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

Check Point identifies Chinese-speaking group Gambling Goblin hijacking Brazilian government domains via malicious Apache modules for SEO-manipulated gambling phishing.

Check Point Research tracks a sustained campaign since mid-2025 against Brazilian government and educational organizations by Gambling Goblin, a Chinese-speaking cybercrime cluster linked to Earth Berberoka. Attackers compile and install malicious Apache modules that silently reverse-proxy visitors to phishing pages impersonating Google Play, Microsoft Store, and Amazon, chaining compromised high-reputation domains to inflate search rankings. The group deploys a heavily obfuscated Linux toolkit including DownPro, AlphaAgent, oRAT, a 3snake-based credential stealer, and SSH brute-forcers, with parallel phishing networks localized for Vietnamese, Spanish, and English victims.

Check Point Research · 14d agoThreat actor

Podcast: We Spoke to an Amazon Worker Destroying Books for AI

404 Media podcast covers Amazon destroying scanned books for AI training, recurring AI names in academic papers, and ICE voter-data spending.

404 Media's podcast follows up on its investigation of an Amazon warehouse where books are scanned and destroyed for AI training data, including an interview with a warehouse worker. The hosts also discuss how the same few names repeatedly surface in LLM outputs and AI-generated academic papers. The episode additionally covers ICE's plans to spend millions on voter fraud data and Boston Dynamics robot dogs.

404 Media · 14d agoAI industry

What the AI Warning Letter Completely Missed

Opinion piece argues the recent AI warning letter identifies a risk window but omits which actors pose risks and who can mitigate.

This Dark Reading commentary critiques a recent AI warning letter for correctly identifying an approaching risk window while failing to name who is coming through it or who will close it. The piece is brief opinion commentary on AI risk discourse rather than a technical report.

Dark Reading · 13d agoAI safety & security

The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

Rapid7 analyzes how fraud marketplaces are fragmenting into specialized shops after larger marketplaces were dismantled, aided by new MITRE F3 framework

Rapid7 reports a shift from large known fraud marketplaces to a fragmented environment of smaller specialized storefronts such as Xleet, Blackpass, Infodig, and Styx, operating across dark web channels, Telegram, and P2P options. These Fraud-as-a-Service shops sell stolen accounts, PII, synthetic identity generation, infrastructure, and money laundering support, supporting schemes like business email compromise. MITRE's Fraud Fighting Framework (F3), introduced in early 2026, aims to help security teams prioritize monitoring of fraud TTPs, particularly account takeover techniques. Fraud damages are anticipated to approach hundreds of billions of USD.

Rapid7 Blog · 5d agoPhishing & fraud

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

Hacker News ThreatsDay digest: malicious browser extensions, AI-agent intrusions, NCSC shadow AI warning, M&A wire fraud, and 119,000-domain fake shops.

Socket found four malicious Chrome and Firefox extensions (J7Tracker, VREO, Orbit Tracker) stealing session tokens and wallet data from Axiom Trade and Padre users via attacker-controlled Vercel deployments. Hunt.io reported a Chinese-speaking operator using Claude Code, Alibaba Qwen, and DeepSeek with the SecFlow orchestration framework to automate intrusions against government and financial targets in Afghanistan, Thailand, Taiwan, and the US. The UK NCSC warned shadow AI use risks breaches and regulatory failure, Microsoft announced privacy-preserving Windows Age APIs, and Gen Digital described fake M&A wire-fraud scams. A 119,000-domain fake-shop operation called DoppelCart was also highlighted.

The Hacker News · 6d agoIndustry in the wild

MFA's Weakest Link: Account Recovery Is the New Attack Path

Help desk account recovery is increasingly the weakest link in MFA-protected identities, as Scattered Spider's impersonation-driven Marks & Spencer attack demonstrated.

As MFA, conditional access, and phishing-resistant factors raise the cost of direct account takeover, attackers increasingly target the recovery process, convincing service desk staff to reset passwords or re-register MFA on attacker-controlled devices. CISA, FBI, and partner advisories describe Scattered Spider posing as employees to trigger such resets; the 2025 Marks & Spencer attack began this way and led to ransomware with an estimated £300 million profit impact. Microsoft now describes Entra ID account recovery as a high-assurance process, and the article promotes Specops Secure Service Desk for verified identity workflows.

BleepingComputer · 7d agoPhishing & fraud

Attackers conceal phishing lures using invisible Unicode characters

Threat actors use invisible Unicode characters (ASCII smuggling) to hide phishing lures and evade email security filters.

Threat actors have adopted the ASCII smuggling technique in phishing campaigns, embedding invisible Unicode characters in emails to conceal malicious lures. The approach is designed to evade email security filters that scan for visible phishing indicators. The report gives no victim counts or named campaigns.

BleepingComputer · 10d agoPhishing & fraud in the wild