The Hacker News·21h ago highElementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link#elementor#wordpress#csrf 3 sources 2 min
oss-security·1d ago highCVE-2026-82378: Apache Roller: OAuth authorization endpoint trusts request-supplied identity#apache-roller#oauth#cve-2026-82378CVE-2026-82378 17 sources
Lobsters · security·1d agoSourceHut account takeover via build logs (XSS in ansi2html.py)#sourcehut#xss#ansi2htmlVulnerability 3 sources 12 min
Cyber Security News·2d agoMalicious Firefox Extension Disguised as PDF Tool Steals Google Account Sessions#firefox#malicious-extension#session-theft 2 sources in the wild 5 min
SecurityWeek·3d ago highAI-Powered Phishing Platform EvilTokens Disrupted by Microsoft#account-takeover#ai#device-code-phishing 14 sources in the wild 2 min1
Cyber Security News·4d agoGHAPPIER Supply Chain Attack Compromises 65 GitHub Repositories and Poisons npm Package#npm#github#supply-chain 3 sources in the wild 4 min
Cyber Security News·4d agoZTE SmartLife Flaws Let Attackers Hijack Accounts by Resetting Passwords Without Verification#zte#smartlife#account-takeover 4 min
Security Affairs·7d agoAI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum#account-takeover#ai-driven-exploitation#discourse 5 min
The Hacker News·7d agoClaude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws#account-takeover#anthropic#claude-opus-5 6 min
The Decoder·8d ago highSecurity researchers used Anthropic's Claude to hack OpenAI's internal systems in under 72 hours#account-takeover#anthropic#claude-opus-5 3 sources 3 min
SecurityWeek·8d ago highAI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code#account-takeover#ai-built-exploit#bug-bounty in the wild 3 min1
GBHackers·8d agoChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts#account-takeover#chatgpt#cofense in the wild 4 min
Cyber Security News·9d agoResearchers Use Claude Opus 5 to Hack OpenAI Forum and Reach Internal Repositories#account-takeover#ai-assisted-hacking#claude-opus-5 in the wild 4 min
Hacker News · security·9d ago highA heap overflow and SSO misconfiguration to compromise OpenAI internal repos#account-takeover#bug-bounty#discourse in the wild 9 min1
SecurityWeek·10d ago criticalEnterprises Warned of Attacks Exploiting WSO2 Vulnerability#account-takeover#api-security#authentication-bypass in the wild 2 min2
The Hacker News·11d ago highActive Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens#account-takeover#api-manager#authentication-bypass in the wild 2 min1
Help Net Security·11d agoThe modern attack chain: Rethinking Google Workspace security in the age of AI#account-takeover#ai-agents#attack-chain in the wild 8 min
Cyber Security News·12d agoMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users#account-takeover#browser-extension#infostealer in the wild 6 min
SecurityWeek·12d ago highTelus Warns Customers of Account Breaches#account-takeover#breach#canada in the wild 2 min1
Rapid7 Blog·15d agoThe Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment#account-takeover#bec#dark-web 13 min
DataBreaches.net·17d agoRussian suspect in bank account takeovers is extradited to US#account-takeover#doj#extraditionPolicy & legal1
TechCrunch · AI·18d agoHackers are stealing Claude tokens from subscribers#account-takeover#anthropic#claude in the wild 4 min1
CyberScoop·18d agoRussian national extradited to US for alleged involvement in bank-account takeover scheme#account-takeover#bank-fraud#doj 3 min
The Record·18d agoRussian suspect in bank account takeovers is extradited to US#account-takeover#bank-fraud#credential-phishingPolicy & legal 2 min