Visualização de leitura

WhatsApp Just Added 3 New Ways to Protect Your Account

WhatsApp is adding stronger two-step verification, multiple passkeys and more context for unknown callers as it expands protections against scams.

The post WhatsApp Just Added 3 New Ways to Protect Your Account appeared first on TechRepublic.

The Password Notebook Is Back — but Is It Actually Safer?

Password notebooks are making an unexpected comeback as infostealers and browser attacks revive debate over the safest way to store credentials.

The post The Password Notebook Is Back — but Is It Actually Safer? appeared first on TechRepublic.

Hackers Target Social Media Accounts to Steal Explicit Content, FBI Warns

sexual exploitation actors

The FBI is warning the public about sexual exploitation actors illegally accessing social media and personal accounts to steal explicit images and videos from adult and underage victims. The stolen material, also known as non-consensual intimate images (NCII), is being posted or sold on criminal marketplaces, often without the victim's knowledge.

According to the FBI, these actors use social engineering and cyber intrusion tactics to target specific individuals or general targets of opportunity. After gaining access to accounts, they steal explicit content and share it through community forums or illicit marketplaces.

The FBI said personally identifiable information, including a victim's name, date of birth, email address, phone number and social media username, is often posted alongside the stolen material. This can expose victims to continued harassment and re-victimization.

How Sexual Exploitation Actors Access Accounts

The FBI has identified several methods used by sexual exploitation actors to gain access to victims' accounts.

Password and PIN Targeting

In password/PIN targeting, actors use high-volume password and PIN attempts against social media and personal accounts. The information used in these attempts can come from data leak sites, social media and open-source information.

When victims are known to the actors, curated lists may include personal details such as names, date of birth or variations of those details.

Social Media Customer Service Impersonation

Another tactic involves social media customer service impersonation through text messages. Victims may receive messages claiming their account is being disabled or locked unless they provide a verification code.

The actor then requests a password reset, causing a code to be sent to the victim. If the victim shares the code, the actor can reset the password and access the account.

Phishing Emails

The FBI also warns about phishing campaigns using look-alike domains and email accounts designed to appear as social media customer support.

These messages may claim there has been a new login and contain an embedded link asking the victim to change their password. Clicking the malicious link can give the actor access to the account.

Stolen Content Can Lead to Further Attacks

Once explicit content is stolen, sexual exploitation actors may post or sell it while including personal information about the victim. The FBI said victims can subsequently face harassment, sextortion, stalking or other targeted attacks.

The actors may also advertise stolen content through a victim's own social media page, increasing the potential for further exposure.

FBI Shares Steps to Protect Accounts

The FBI advises people to avoid storing sensitive images or videos on social media platforms or other internet-accessible sites.

It recommends using unique, complex passphrases and PINs along with multi-factor authentication (MFA). Password information directly associated with a person's identity, including names or birthdays, should be avoided.

Users should also be cautious with links received through emails and text messages. The FBI recommends going directly to the relevant website to address account concerns and checking URLs before clicking.

Unrequested temporary passwords, PIN resets or access codes should also be treated with caution. The FBI advises users not to share login information, even when someone claims to represent a platform or service.

People who believe their explicit content was stolen or leaked can provide information through the FBI's NCII reporting site. The FBI also advises the public to continue reporting fraud, scams and cyber threats to the Internet Crime Complaint Center or a local FBI Field Office.

Talos: Attackers Refine Phishing Playbook To Target Critical Infrastructure

Phishing played a part in more than half of all incident response engagements undertaken by Talos, Cisco's threat research organization, during the second quarter of 2026, with healthcare organizations and manufacturing firms among the top targets.

The post Talos: Attackers Refine Phishing Playbook To Target Critical Infrastructure appeared first on The Security Ledger with Paul F. Roberts.

Google Adds Selfie Video Sign-In to Help Users Recover Locked Accounts

Google added selfie video recovery for eligible accounts, using encrypted videos and liveness checks to help users regain access when locked out.

The post Google Adds Selfie Video Sign-In to Help Users Recover Locked Accounts appeared first on TechRepublic.

FBI Flags Kali365 as New Phishing Threat Targeting Microsoft 365 Users

Kali365 Phishing Kit

The FBI has issued a fresh warning about a growing cybercrime service known as Kali365, a new Phishing-as-a-Service (PhaaS) platform that enables attackers to hijack Microsoft 365 accounts without stealing passwords directly. According to the FBI, the Kali365 phishing kit allows even low-skilled cybercriminals to bypass multi-factor authentication (MFA) protections by abusing Microsoft’s legitimate device authentication workflow. The platform, which surfaced in April 2026, is being distributed primarily through Telegram channels and is already being linked to hundreds of phishing campaigns targeting organizations and individuals worldwide. Instead of collecting usernames and passwords, attackers steal OAuth access tokens that provide long-term access to Microsoft 365 environments, including Outlook, Teams, and OneDrive.

How the Kali365 Phishing Kit Works

The FBI explained that the platform relies on a deceptive but technically simple attack chain designed to exploit user trust. The process typically begins with a phishing email impersonating trusted productivity or document-sharing services. The email contains a device authentication code and instructions asking the victim to visit a legitimate Microsoft verification page. Because the webpage itself is genuine, many users assume the request is safe. Once the targeted user enters the provided code, they unknowingly authorize the attacker’s device to access their Microsoft 365 account. The attacker then captures OAuth access and refresh tokens, enabling persistent access without requiring the victim’s password or additional MFA verification. This technique is particularly dangerous because it does not rely on traditional credential theft. Instead, it abuses Microsoft’s authentication framework to gain legitimate session access. The FBI noted that after successful token capture, attackers can continue accessing services such as Outlook email accounts, Teams communications, and OneDrive files without triggering additional login prompts.

Why OAuth Token Theft Is Becoming a Growing Threat

Security researchers say OAuth token theft is becoming increasingly popular among cybercriminals because it allows attackers to bypass many traditional security controls. Unlike passwords, OAuth tokens are designed to maintain authenticated sessions across services. If stolen, they can provide attackers with ongoing access until revoked or expired. The FBI warned that Kali365 significantly lowers the barrier to entry for cybercrime operations by offering built-in phishing templates, AI-generated phishing lures, automated campaign tools, and real-time dashboards that track victims and stolen tokens. This means attackers no longer need advanced technical expertise to launch phishing campaigns against businesses using Microsoft 365 environments. The platform’s availability on Telegram also makes it easier for threat actors to distribute and monetize phishing infrastructure at scale.

FBI Shares Protection Measures Against Kali365 Attacks

To reduce exposure to these attacks, the FBI advised organizations to restrict or block device code authentication flows wherever possible. One of the key recommendations includes implementing conditional access policies that block device code flow for most users while allowing limited exceptions for essential business operations. Organizations are also encouraged to audit existing device authentication workflows to identify legitimate dependencies before enforcing restrictions. The FBI further recommended blocking authentication transfer policies that allow authentication to move between computers and mobile devices, as these workflows can potentially be abused during phishing attacks. For organizations unable to fully disable device code flow, the agency suggested excluding emergency access accounts from restrictions to avoid accidental lockouts during critical situations.

FBI Urges Victims to Report Incidents

The FBI is urging anyone impacted by the Kali365 phishing campaign to report incidents through the Internet Crime Complaint Center (IC3). Victims are encouraged to preserve and submit phishing emails, suspicious login activity, unauthorized devices, IP addresses, and active session information that could assist investigators. The agency also pointed users toward phishing mitigation guidance published by the Cybersecurity and Infrastructure Security Agency, which outlines defensive measures organizations can take to reduce phishing risks. The rise of Kali365 Phishing-as-a-Service highlights how cybercriminals are increasingly shifting toward token-based attacks that exploit trusted authentication systems instead of relying solely on password theft. As phishing platforms continue evolving, security experts warn that organizations using cloud productivity platforms like Microsoft 365 will need stronger identity protection measures and closer monitoring of authentication activity to reduce the risk of account compromise.

SAML vs OIDC vs OAuth: The 60-Second B2B Playbook

Confused by auth protocols? We break down the core differences between SAML, OIDC, and OAuth so you can choose the right standard for your B2B app. Read now.

The post SAML vs OIDC vs OAuth: The 60-Second B2B Playbook appeared first on Security Boulevard.

Russian GRU Cyber Campaign Targets Western Logistics Firms Supporting Ukraine

Russian GRU cyber campaign

A new joint cybersecurity advisory has revealed an ongoing Russian GRU cyber campaign targeting Western logistics entities and technology companies, particularly those involved in coordinating and delivering aid to Ukraine. The activity has been linked to the Russian General Staff Main Intelligence Directorate’s Unit 26165, widely tracked in the cybersecurity community as APT28 or Fancy Bear. According to the advisory, the Russian GRU cyber campaign has been active since early 2022 and continues to evolve, posing a sustained risk to organizations across multiple sectors. Security agencies warn that companies involved in transportation, IT services, and defense supply chains should assume they are potential targets and strengthen monitoring and threat detection efforts.

GRU Unit 26165 Expands Logistics Cyber Targeting

The campaign, attributed to GRU Unit 26165, has focused on entities supporting Ukraine through logistics and infrastructure. This includes companies operating across air, sea, and rail transport, as well as IT service providers connected to these operations. Targets span multiple countries, including the United States, Germany, Poland, France, and Ukraine. The attackers have also exploited trust relationships between organizations, moving from one compromised entity to another to expand access. [caption id="attachment_111431" align="aligncenter" width="600"]Russian GRU Cyber Campaign Image source: https://www.cyber.gov.au/[/caption] Officials noted that the Russian GRU cyber campaign is not limited to direct targets. Organizations with business ties to logistics providers have also been drawn into the attack chain, increasing the overall risk surface.

APT28 Attacks Use Known but Effective Techniques

The advisory highlights that APT28 attacks rely heavily on established tactics, techniques, and procedures. These include credential guessing, brute-force attacks, and spearphishing campaigns designed to steal login details or deploy malware. Spearphishing remains a key component of the Russian GRU cyber campaign, with emails crafted in the target’s native language and often impersonating government or trusted services. Many of these emails direct victims to fake login pages hosted on compromised devices or free web platforms. The attackers have also used multi-stage redirect systems to filter victims based on location and device characteristics, making detection more difficult.

CVE Exploitation and Malware Deployment Observed

A significant aspect of the campaign involves the exploitation of known vulnerabilities. The actors have weaponized multiple CVEs, including:
  • CVE-2023-23397 in Microsoft Outlook to harvest credentials
  • Roundcube vulnerabilities for email server access
  • CVE-2023-38831 in WinRAR for remote code execution
These vulnerabilities have enabled attackers to gain initial access and move deeper into targeted networks. The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.

Post-Compromise Activity Focuses on Sensitive Data

Once inside a network, attackers conduct extensive reconnaissance to identify high-value targets, including employees managing transport operations and cybersecurity teams. The Russian GRU cyber campaign places particular emphasis on accessing sensitive logistics data. This includes shipment details such as routes, cargo contents, sender and recipient information, and transport schedules. Attackers use tools like Remote Desktop Protocol and open-source frameworks to move laterally within networks. They also manipulate email permissions to maintain long-term access and collect communications from compromised accounts.

IP Cameras Targeted to Track Aid Movement

In addition to corporate networks, the campaign has extended to internet-connected cameras. The advisory reports that GRU actors have targeted IP cameras located near border crossings, rail stations, and military facilities. By exploiting weak credentials and unsecured Real Time Streaming Protocol servers, attackers have been able to access live feeds and monitor the movement of aid into Ukraine. A large portion of these attempts has focused on cameras in Ukraine and neighboring countries. This tactic adds a physical surveillance dimension to the Russian GRU cyber campaign, enabling real-time tracking of logistics operations.

Organizations Urged to Strengthen Defenses

Cybersecurity agencies are urging organizations to take immediate steps to mitigate risks associated with the Russian GRU cyber campaign. Recommended measures include:
  • Enforcing multi-factor authentication and strong access controls
  • Monitoring for unusual login activity and lateral movement
  • Patching known vulnerabilities and securing internet-facing systems
  • Limiting access to critical infrastructure and sensitive data
  • Auditing logs and deploying endpoint detection tools
Companies are also advised to review their relationships with partners and suppliers, as attackers frequently exploit these connections to expand their reach.

Persistent Threat Expected to Continue

The advisory concludes that the Russian GRU cyber campaign is likely to persist, with continued use of similar tactics and targeting patterns. As geopolitical tensions remain high, logistics and technology sectors are expected to stay at the forefront of cyber espionage activity. Organizations operating in these sectors are being encouraged to adopt a proactive security posture, recognizing that the threat is ongoing and highly targeted.

API Keys vs. JWTs: Choosing the Right Auth Method for Your API

5 min readA developer needs to connect a service to an API. The documentation says to generate an API key, store it in an environment variable and pass it in a header. Five minutes later, the integration works.

The post API Keys vs. JWTs: Choosing the Right Auth Method for Your API appeared first on Aembit.

The post API Keys vs. JWTs: Choosing the Right Auth Method for Your API appeared first on Security Boulevard.

❌