Tag
Chrome begins rolling out Device Bound Session Credentials (DBSCs), a new protection that binds session cookies to a device's TPM or Secure Enclave, making stolen cookies useless for account takeovers.
This Unit 42 research discloses three novel attacks against passwordless authentication using Google's synced passkey ecosystem, showing how malware can take over passkey-protected accounts, bypass user verification, and extract private keys.
A security researcher discovered a vulnerability in Volvo/Eicher's My Eicher fleet management platform that allowed unauthenticated access to internal APIs, enabling account takeover and control over all users and vehicles, exposing data of 748k customers and 676k vehicles.
Attackers bypassed Instagram 2FA by using Meta's AI support assistant to change recovery email via prompt injection, raising questions about AI agent privileges in account recovery.
A security vulnerability allowing 1-click admin account takeover has been discovered in PewDiePie's AI tool.
Hackers exploited Meta's AI support chatbot to take over high-profile Instagram accounts by simply asking it to change the account's email address, bypassing normal verification and account recovery procedures.
A newly discovered Instagram exploit allows attackers to take over accounts by faking location and using Meta's support AI to reset email verification, bypassing 2FA. The vulnerability, which affected high-profile accounts, has been patched but was active for weeks.
A security researcher discovered critical vulnerabilities in CBSE's On-Screen Marking portal, including a hardcoded master password and authentication bypass, which could allow full account takeover and tampering with exam evaluations.
The article explains how a single XSS vulnerability can defeat the phishing-resistance of passkeys when attestation is set to 'none', allowing attackers to register their own passkeys and achieve persistent account takeover. It calls for attention to this overlooked threat and suggests defenses.
Security researcher discloses multiple serious vulnerabilities in a cheap Temu smart doorbell, including fleet-wide account takeover, live call hijacking, and WiFi password exfiltration, affecting the Naxclow IoT platform.