30,000 Facebook Accounts Hacked via Google AppSheet Phishing Campaign
A Vietnamese-linked operation uses Google AppSheet for phishing, compromising around 30,000 Facebook accounts to sell them back through an illicit storefront.
Russian crims phish way into Signal and WhatsApp accounts
Russian-linked hackers target Signal and WhatsApp accounts by tricking users into sharing security codes rather than breaking encryption, successfully compromising government officials, journalists, and military personnel globally.
New phishing campaign tricks employees into bypassing Microsoft 365 MFA
Attackers trick employees into registering a hacker-controlled device via OAuth device authorization, granting persistent access to Microsoft accounts and bypassing MFA.
Epstein Files Leak Sensitive Data, Victim Information, and Credentials
Government-retracted Epstein records exposed PII of about 100 victims, leaked financial data, passwords, and account credentials, leading to threats and alleged account compromises.
Google and Check Point nuke massive YouTube malware network
Malicious YouTube videos posing as cracked software and game cheats distributed infostealers by using fake or compromised accounts and manipulated engagement to deceive users.
DraftKings Warns Users of Credential Stuffing Attacks
DraftKings detected a credential stuffing attack using externally harvested credentials that may have exposed user account data and is enforcing password resets and MFA.
Battered by cyberattacks, is Salesforce facing a trust problem?
ZDNET's key takeaways
The FBI warned about the alarming trend of compromised accounts.
The success rate of threat actors could tarnish Salesforce's reputation.
The most recent wave of attacks was likely preventable.