Researchers demonstrated attack paths against Google’s synced passkey setup, showing that the weak point may be the device, browser, or recovery layer around the credential rather than WebAuthn itself.
Built-in email assistants can make work faster, but a poisoned message may also steer summaries, drafts, or trust decisions in ways attackers can exploit.
The risk is no longer just phishing: on a compromised Windows machine, synced passkeys can become part of the attacker’s path to account takeover.
CTM360-linked research points to a shift from delayed credential theft to real-time account hijacking, a change that shrinks the defender’s window from hours to seconds.
A targeted campaign tied to ToddyCat shows how malware, installer lures, and cloud authorization abuse can turn Gmail from an inbox into an identity-risk surface.
A Polish arrests case shows how SIM-swapping can move through telecom trust, email access, and identity recovery.
France’s government messenger was tied to a hijacked account, a reminder that secure chat can still bend if the person behind the screen is no longer trusted.
A subscription-style malware operation tied to Minecraft lures shows how fake mod sites, search poisoning, and social promotion can be turned into a repeatable theft pipeline.
A reported Instagram takeover tied to Meta’s AI-assisted support tools shows how account recovery can become a high-value security boundary, not just a convenience feature.
Multiple Instagram users lost account access after attackers abused AI-driven support and identity checks, showing how recovery flows can turn into a takeover path.
A reported stored XSS issue in Open WebUI’s upload path shows how a routine profile-image workflow can become a persistent browser-side attack surface, with a claimed route to account hijacking and even deeper compromise in chained scenarios.
Reported activity around TCLBANKER shows how a banking trojan can borrow the credibility of a signed installer and the reach of hijacked accounts to spread further.
A wave of WhatsApp account takeovers is fueling a new breed of convincing scams-here’s how to spot and stop them.