account-takeover

Tag

Cards List
#account-takeover

Chrome adopts what may be the best protection yet against account takeovers

Ars Technica · 2026-08-11 Cached

Chrome begins rolling out Device Bound Session Credentials (DBSCs), a new protection that binds session cookies to a device's TPM or Secure Enclave, making stolen cookies useless for account takeovers.

0 favorites 0 likes
#account-takeover

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

Hacker News Top · 2026-08-04 Cached

This Unit 42 research discloses three novel attacks against passwordless authentication using Google's synced passkey ecosystem, showing how malware can take over passkey-protected accounts, bypass user verification, and extract private keys.

0 favorites 0 likes
#account-takeover

Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles

Lobsters Hottest · 2026-07-27 Cached

A security researcher discovered a vulnerability in Volvo/Eicher's My Eicher fleet management platform that allowed unauthenticated access to internal APIs, enabling account takeover and control over all users and vehicles, exposing data of 748k customers and 676k vehicles.

0 favorites 0 likes
#account-takeover

AI support bots and account recovery: where should the line be?

Reddit r/ArtificialInteligence · 2026-06-10

Attackers bypassed Instagram 2FA by using Meta's AI support assistant to change recovery email via prompt injection, raising questions about AI agent privileges in account recovery.

0 favorites 0 likes
#account-takeover

Another 1-click admin account takeover in pewdiepie's AI tool (language in video nsfw)

Reddit r/LocalLLaMA · 2026-06-06

A security vulnerability allowing 1-click admin account takeover has been discovered in PewDiePie's AI tool.

0 favorites 0 likes
#account-takeover

Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked

Simon Willison's Blog · 2026-06-01 Cached

Hackers exploited Meta's AI support chatbot to take over high-profile Instagram accounts by simply asking it to change the account's email address, bypassing normal verification and account recovery procedures.

0 favorites 0 likes
#account-takeover

The Newest Instagram "Exploit" Is the Goofiest I've Seen

Hacker News Top · 2026-06-01 Cached

A newly discovered Instagram exploit allows attackers to take over accounts by faking location and using Meta's support AI to reset email verification, bypassing 2FA. The vulnerability, which affected high-profile accounts, has been patched but was active for weeks.

0 favorites 0 likes
#account-takeover

Exposing Critical Vulnerabilities in CBSE's On-Screen Marking Portal

Hacker News Top · 2026-05-26 Cached

A security researcher discovered critical vulnerabilities in CBSE's On-Screen Marking portal, including a hardcoded master password and authentication bypass, which could allow full account takeover and tampering with exam evaluations.

0 favorites 0 likes
#account-takeover

XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None

Lobsters Hottest · 2026-05-20 Cached

The article explains how a single XSS vulnerability can defeat the phishing-resistance of passkeys when attestation is set to 'none', allowing attackers to register their own passkeys and achieve persistent account takeover. It calls for attention to this overlooked threat and suggests defenses.

0 favorites 0 likes
#account-takeover

Cheap smart doorbell allows fleet-wide account takeover and call hijacking

Lobsters Hottest · 2026-05-16 Cached

Security researcher discloses multiple serious vulnerabilities in a cheap Temu smart doorbell, including fleet-wide account takeover, live call hijacking, and WiFi password exfiltration, affecting the Naxclow IoT platform.

0 favorites 0 likes
← Back to home

Submit Feedback