الثلاثاء 28 يوليو 2026 17:16:39 GMT+02:00

Netcrook

الرئيسيةالبيان
الأخبار
Techcrook
Geocrook
WikicrookالفريقAppاتصالتسجيل الدخول
EnglishItaliano

#passkeys


One Phishing Kit Fell, but Microsoft 365 Attackers Kept the Blueprint

Published: 28 July 2026 14:46Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

The disruption of Kratos may have removed one criminal service, but the deeper problem is the reusable playbook behind modern Microsoft 365 account-takeover campaigns.

The QR Trap: How Quishing Turns Email Into a Mobile Ambush

Published: 26 July 2026 10:04Category: Security Awareness & Social EngineeringAuthor: PATCHKNIGHT

QR-code phishing is growing fast because it moves the scam out of text filters and into the scan step, where a personal phone may become the attacker’s real launchpad.

When a Login Prompt Becomes a Crime Scene

Published: 24 July 2026 18:52Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A guilty plea tied to a Snapchat phishing case shows how account takeover can turn routine social engineering into intimate privacy loss.

When Reused Passwords Turn a Restaurant App Into an Attack Surface

Published: 24 July 2026 18:32Category: Breaches & Data LeaksGeo: North America / USAAuthor: BYTEHERMIT

More than 13,000 Chick-fil-A customer accounts were caught in a credential-stuffing campaign, a reminder that the weakest link in many consumer platforms is often the login box itself.

When Reused Passwords Open the Door: The Loyalty Account Breach That Exposes a Familiar Weak Point

Published: 23 July 2026 12:37Category: Breaches & Data LeaksGeo: North America / USAAuthor: BYTESHIELD

A confirmed incident affecting Chick-fil-A One accounts shows how credential stuffing can turn ordinary password reuse into a serious account-security and payment-risk problem.

When Checkout Depends on Shared Secrets, Passkeys Become the Security Upgrade Payments Need

Published: 16 July 2026 13:05Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

Credential-sharing habits make password-based checkout brittle, and the shift to passkeys changes the risk model for Click to Pay without making identity security automatic.

Microsoft’s Entra Identity Turns Toward Passkeys, and the Fallback Problem Gets Real

Published: 14 July 2026 16:32Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

Microsoft has set passkeys to become the default authentication method for Entra ID in September 2026, a change that shifts the security conversation from passwords to enrollment, recovery, and policy design.

Fake Passkey Enrollment Is Becoming the New Front Door for Microsoft 365 Intrusions

Published: 09 July 2026 10:17Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A vishing-led campaign is abusing the trust users place in passkey onboarding, showing that phishing resistance can still be undermined at the enrollment step.

Passkeys Shift the Battle Line: Attackers Move From Password Dumps to Verification Flaws

Published: 08 July 2026 16:49Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

As password replay loses value in well-implemented passkey environments, account takeover pressure is migrating toward verification, recovery, and fallback paths that still decide who gets in.

Passkeys Move Enterprise Logins Off the Password Trapdoor

Published: 06 July 2026 14:38Category: Security Awareness & Social EngineeringGeo: Europe / LithuaniaAuthor: NEURALSHIELD

A NordPass discount may be the headline hook, but the deeper story is the shift from reusable passwords to phishing-resistant authentication that can shrink the value of stolen credentials.

When the Password Dies, the Real Battle Moves to Devices and Checkout Rules

Published: 29 June 2026 14:39Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

Passkeys are pushing authentication away from reusable secrets, while Click to Pay and emerging agent-led commerce are turning payments into a tighter trust problem with new security choke points.

Ghostwriter’s Login Trap: Why a Familiar Mailbox Can Become a High-Value Target

Published: 29 June 2026 10:08Category: Cyber Warfare & Nation-State OperationsGeo: Europe / BelarusAuthor: AGONY

A reported UNC1151 phishing push aimed at Gmail and a Ukrainian email portal shows how credential theft now leans on trusted identity services rather than loud malware.

Fake AWS Logins, Real-Time Theft: The Cloud Phish That Turns MFA Into a Relay

Published: 25 June 2026 10:10Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A small, targeted campaign against AWS users shows how cloned console pages and live interception can make typed MFA codes part of the attack, not the defense.

Fake Gmail Panels Put Passwords and One-Time Codes in the Same Trap

Published: 16 June 2026 15:22Category: Security Awareness & Social EngineeringGeo: Europe / PolandAuthor: PATCHKNIGHT

A phishing operation attributed to Ghostwriter, also tracked as UNC1151, shows how attackers can turn a normal sign-in flow into a credential-grab that reaches beyond the password field.

A Gmail Phish That Hunts for the Second Factor, Not Just the Password

Published: 16 June 2026 12:42Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A reported UNC1151 Ghostwriter campaign puts a familiar weak point back under the microscope: code-based 2FA can still be trapped by a convincing fake login flow.

When an Extortion Claim Points at GitHub, the Real Target Is Identity

Published: 13 June 2026 14:23Category: Ransomware & ExtortionGeo: North America / USAAuthor: NEBULASCOUT

A Lapsus$-attributed claim tied to github.com is unverified, but it highlights why developer platforms are prized for secrets, access tokens, and account control.

BitB Phishing Pushes Microsoft 365 Users Into a Dangerous Login Illusion

Published: 09 June 2026 14:44Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A phishing campaign is using Browser-in-the-Browser styling to target Microsoft 365 credentials, turning ordinary sign-in habits into the attacker’s main entry point.

OpenAI Adds New Locks to ChatGPT as Account Security Becomes the Real Battleground

Published: 08 June 2026 12:48Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

Active Sessions and Lockdown Mode are being expanded, turning ChatGPT into a tighter-controlled workspace where visibility and restriction matter as much as convenience.

The Passkey Trap: Why One PIN Can Become the Weakest Link in a Synced Vault

Published: 28 May 2026 14:30Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A reported phishing technique puts the spotlight on the recovery layer behind Google Password Manager, where convenience features can become high-value targets.

Why Tycoon 2FA Still Matters: The Cloud Login Trap That Can Beat Weak MFA

Published: 27 May 2026 12:06Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

Tycoon 2FA is a reminder that identity attacks do not need to break passwords if they can relay a live login and harvest the session behind it.