A high-severity SAML validation flaw in Siemens Mendix SAML shows how a single trust-check failure can turn federated login into an account-hijack risk.
A hijacked HBO Max Reddit identity was used to push ClickFix-style malicious ads, showing how trust signals can be repurposed into an execution path for Windows and macOS users.
The dangerous part is not the passkey itself, but the human workflow around identity recovery, where urgency and trust can be turned into account takeover.
A credential-stealing campaign aimed at Claude accounts shows why modern account security is no longer just about passwords - it is about revoking live sessions before an attacker can replay them.
A critical flaw tied to the WordPress plugin TranslatePress shows how one weak privilege check in a widely deployed extension can become a path to full site control.
Suspected Russia-linked clusters are reportedly turning ordinary sign-in flows into access brokers, using legitimate authentication steps to reach high-value accounts.
CTM360-linked research points to a shift from delayed credential theft to real-time account hijacking, a change that shrinks the defender’s window from hours to seconds.
A targeted campaign tied to ToddyCat shows how malware, installer lures, and cloud authorization abuse can turn Gmail from an inbox into an identity-risk surface.
A Polish arrests case shows how SIM-swapping can move through telecom trust, email access, and identity recovery.
France’s government messenger was tied to a hijacked account, a reminder that secure chat can still bend if the person behind the screen is no longer trusted.
A subscription-style malware operation tied to Minecraft lures shows how fake mod sites, search poisoning, and social promotion can be turned into a repeatable theft pipeline.
A reported Instagram hijack case points to a larger security lesson: when AI can influence recovery workflows, the trust boundary moves from login screens to support logic.
A cross-site scripting flaw in pretalx was patched in v2026.1.0, and the technical lesson is bigger than one event tool: privileged browser sessions remain a high-value target.
A reported stored XSS issue in Open WebUI’s upload path shows how a routine profile-image workflow can become a persistent browser-side attack surface, with a claimed route to account hijacking and even deeper compromise in chained scenarios.
Reported activity around TCLBANKER shows how a banking trojan can borrow the credibility of a signed installer and the reach of hijacked accounts to spread further.
A quietly devastating vulnerability in LangSmith exposed critical enterprise data to stealthy account hijacks-without a single password phished.