Over 100 Organizations Targeted in ShinyHunters Phishing Campaign
A ShinyHunters-linked campaign used fake domains, vishing, and phishing kits to target SSO accounts across 100+ major organizations aiming to bypass MFA.
ShinyHunters group opens new dark web leak site, claims responsibility for OKTA vishing campaign - DataBreaches.Net
ShinyHunters claimed responsibility for an Okta SSO vishing campaign and published alleged data from Crunchbase, SoundCloud, and Betterment, promising more victims.
ShinyHunters claim to be behind SSO-account data theft attacks - DataBreaches.Net
Voice phishing targeting Okta, Microsoft, and Google SSO lets attackers bypass MFA, access corporate SaaS platforms, and steal company data for extortion.
PDFSider is a stealthy Windows backdoor deployed via social engineering and DLL side-loading to provide persistent, encrypted access and data exfiltration over DNS.
Why Google is really warning 2.5 billion Gmail users to stop using their passwords
Google advises abandoning passwords in favor of stronger protections after Salesforce-sourced data boosted targeted phishing and impersonation attacks.
Teen charged with Las Vegas casino cyber heist | Computer Weekly
A teenage suspect surrendered and faces multiple charges for Scattered Spider cyberattacks that disrupted MGM and Caesars, causing major losses and data theft.
Google Says Claims of Mass Gmail Security Breach Are "Entirely False"
Google denied issuing mass Gmail security alerts, confirmed a UNC6040 vishing incident exposed basic business contact data but said Gmail accounts were not broadly compromised.
Mother of all Google breaches puts all 2.5b Gmail users at risk
A breach of a Google Salesforce-managed database exposed contact data for 2.5 billion Gmail users, enabling scammers to attempt account hijacking through vishing and phishing.