The company's 13-million-follower account was hijacked and used to boost a token tied to an old Office mascot.
GhostCode abuses Microsoft's device authorization flow to obtain tokens and register attacker hardware inside a victim tenant.
Canada's Telus says attackers used stolen credentials to reach customer records over more than a year.
The FBI warns OAuth consent phishing has been seizing prominent people's accounts since late 2025, and password resets do not…
Red Hat patches a critical Keycloak flaw that lets unauthenticated attackers seize any account, including admins.
A new phishing kit enrolls attacker passkeys to keep access after password resets.
Sansec blocked the first exploits of CVE-2026-71362, an unauthenticated account takeover in Adobe Commerce rated 9.1.
Chick-fil-A disclosed a credential stuffing attack that compromised customer accounts in the Chick-fil-A One loyalty program.