ZeroHour

Search: “Direct Send”

3 stories in the last 24h

GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds

eSentire identified GhostCode, a phishing kit abusing Microsoft 365 OAuth device-code sign-in to steal tokens and take over accounts in seconds.

eSentire analysts identified GhostCode in late August, a phishing kit that uses business contact-form messages and an NDA pretext to deliver a password-protected HTML attachment leading victims to a Microsoft device-code sign-in. Victims authenticate on legitimate Microsoft pages, letting the kit obtain a Primary Refresh Token in 32 seconds and register three devices in 78 seconds, with residential proxies matching the victim's location. The kit hides its redirect with encrypted addresses, junk data, and scanner-filtering challenges, and uses GHOSTnet-linked infrastructure during device enrolment. eSentire recommends blocking device-code authentication via Conditional Access, invalidating tokens, and reviewing newly enrolled devices.

Cyber Security News · 23h agoPhishing & fraud in the wild 2 sources5

The sexy AI-powered dating app scams are here

Anthropic exposed a network of roughly 28 AI-driven dating apps using autonomous personas and gig workers to defraud paying users.

Anthropic threat intelligence uncovered a fraud network of around 28 dating apps after a prepaid account sent over 100,000 Claude API requests daily, with most chats run by autonomous AI personas and no human agent. Researchers Matthew Gore-Kormanik and Anthropic's Chris Cronbaugh documented apps including Dora, Romi, and Doni, which monetize conversations via coins; gig workers were hired only to pass liveness checks and select pregenerated replies. An operations manual written in Chinese was found inside the Doni app, and Anthropic published findings in its September 2026 AI misuse report.

The Verge · AI · 23h agoPhishing & fraud in the wild

I Hijacked a Real Artist's Spotify with AI Music. It Was Disturbingly Easynew

A journalist used DistroKid's loophole to publish an Udio-generated song on Lathe of Heaven's verified Spotify page, exposing a widespread AI music royalty scam.

A 404 Media reporter generated a punk song with Udio and, via a $3.75-per-month DistroKid account, released it under the name of Brooklyn punk band Lathe of Heaven without any identity verification by the distributor or streaming platforms. The AI-generated track appeared a day later on the band's Spotify, Apple Music, Tidal, Amazon Music and Deezer pages, with royalties flowing to the uploader. Similar abuse has hit deceased musicians such as Blaze Foley, and Spotify says artist profiles that are not actively managed are especially vulnerable.

404 Media · 22m agoPhishing & fraud in the wild