Saturday 08 August 2026 11:56:23 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#account hijacking


How Malware Can Aim at Synced Passkeys Without Breaking the Math

Published: 05 August 2026 17:27Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

Researchers demonstrated attack paths against Google’s synced passkey setup, showing that the weak point may be the device, browser, or recovery layer around the credential rather than WebAuthn itself.

Inbox AI Turns Every Message Into a Possible Attack Path

Published: 04 August 2026 16:13Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

Built-in email assistants can make work faster, but a poisoned message may also steer summaries, drafts, or trust decisions in ways attackers can exploit.

Passkeys Were Supposed to Kill Password Theft. Malware Found the Device Instead.

Published: 04 August 2026 08:16Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: PATCHVIPER

The risk is no longer just phishing: on a compromised Windows machine, synced passkeys can become part of the attacker’s path to account takeover.

Insurance Phishing Has Learned to Move at the Speed of a Login

Published: 25 July 2026 14:08Category: Security Awareness & Social EngineeringGeo: Middle East / BahrainAuthor: NEURALSHIELD

CTM360-linked research points to a shift from delayed credential theft to real-time account hijacking, a change that shrinks the defender’s window from hours to seconds.

When a Mailbox Becomes an API Problem

Published: 09 July 2026 11:34Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A targeted campaign tied to ToddyCat shows how malware, installer lures, and cloud authorization abuse can turn Gmail from an inbox into an identity-risk surface.

When a Phone Number Turns Into a Crypto Break-In Tool

Published: 26 June 2026 02:10Category: CybercrimeGeo: Europe / PolandAuthor: CIPHERWARDEN

A Polish arrests case shows how SIM-swapping can move through telecom trust, email access, and identity recovery.

When the Login Becomes the Breach: Tchap Shows How Identity Can Outrun Encryption

Published: 09 June 2026 14:36Category: Breaches & Data LeaksGeo: Europe / FranceAuthor: SECURERECLAIMER

France’s government messenger was tied to a hijacked account, a reminder that secure chat can still bend if the person behind the screen is no longer trusted.

Weedhack Turns Minecraft Curiosity Into a Credential-Grabging Business

Published: 09 June 2026 10:27Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A subscription-style malware operation tied to Minecraft lures shows how fake mod sites, search poisoning, and social promotion can be turned into a repeatable theft pipeline.

When Recovery Becomes the Prize: Instagram’s Support Flow Lands in the Attackers’ Crosshairs

Published: 03 June 2026 10:13Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A reported Instagram takeover tied to Meta’s AI-assisted support tools shows how account recovery can become a high-value security boundary, not just a convenience feature.

When the Help Desk Becomes the Lockpick

Published: 02 June 2026 18:06Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

Multiple Instagram users lost account access after attackers abused AI-driven support and identity checks, showing how recovery flows can turn into a takeover path.

Avatar Uploads, Full Trust: The Open WebUI Flaw That Turned a Profile Feature Into a Security Fault Line

Published: 12 May 2026 13:57Category: Vulnerabilities & Patch ManagementAuthor: NEONPALADIN

A reported stored XSS issue in Open WebUI’s upload path shows how a routine profile-image workflow can become a persistent browser-side attack surface, with a claimed route to account hijacking and even deeper compromise in chained scenarios.

When a Trusted Installer Turns Into a Message Relay

Published: 09 May 2026 19:23Category: Malware & BotnetsGeo: South America / BrazilAuthor: NEXUSGUARDIAN

Reported activity around TCLBANKER shows how a banking trojan can borrow the credibility of a signed installer and the reach of hijacked accounts to spread further.

WhatsApp Hijacks: How Cybercriminals Are Turning Trusted Chats into Cash Traps

Published: 14 January 2026 11:32Category: Security Awareness & Social EngineeringGeo: EuropeAuthor: LOGICFALCON

A wave of WhatsApp account takeovers is fueling a new breed of convincing scams-here’s how to spot and stop them.