#AccountHijacking
IF you still have any META accounts (Instagram, FB, Threads), go check right now to see if META made you FOLLOW the accounts of the current administration.

Discovered that META (IG) did this TO ME! I'm FURIOUS

#META #AccountHijacking #noconsent #NoMorePrivacy #MyDecisionsNotTheirs
January 22, 2025 at 8:57 AM
Massive gambling network doubles as hidden C2 and anonymity infrastructure, researchers say

📖 Read more: www.helpnetsecurity.com/2025/12/03/i...

#cybersecurity #cybersecuritynews #accounthijacking
Massive gambling network doubles as hidden C2 and anonymity infrastructure, researchers say - Help Net Security
A sprawling online gambling network is likely also being used to provide threat actors command and control (C2) and anonymity services.
www.helpnetsecurity.com
December 3, 2025 at 1:24 PM
One WeChat Call Was Enough to Hijack Accounts Across iPhone and Android #AccountHijacking #Android #AppleZeroDayVulnerabilities
One WeChat Call Was Enough to Hijack Accounts Across iPhone and Android
  A new wave of WeChat vulnerability can turn an incoming voice call into a zero-click account takeover, enabling a compromised account to target another contact without requiring the recipient to answer the call or interact with the device. Security researchers at Calif developed the exploit and demonstrated its worm-like propagation across an iPhone and two Android devices. In the test, an Android phone called an iPhone and compromised its WeChat account while the incoming call was still ringing. The compromised iPhone then called a second Android phone, allowing the researchers to repeat the takeover. The attack depends on the caller already being listed as a WeChat contact of the target. Calif said this is not necessarily a strong protection because compromising one account can give an attacker access to that user's trusted contacts, creating opportunities to propagate the attack through existing relationships. The recipient does not need to answer the call. Calif said answering it also does not prevent exploitation, with the victim hearing nothing while the attack continues. Rejecting the call stops that individual attempt, but an attacker can simply place another call later. This could allow repeated attempts when a target is unavailable, including while the person is asleep. According to Calif, the vulnerability affects WeChat's VoIP functionality and involves memory corruption. Successful exploitation provides control over the victim's WeChat account, allowing an attacker to read and send messages, make calls and operate the account as its owner. The researchers stressed that the vulnerability by itself does not provide control of the entire smartphone. Chaining it with separate device vulnerabilities could, however, potentially extend an attack beyond the application. Calif has not released the exploit's technical details and plans to present its full research at a security conference. The company said its researchers used an AI-assisted system designed to explore attack surfaces in messaging applications to identify the vulnerability. Calif said its engineering team identified the bug on July 23, completed an Android exploit on July 30 and demonstrated the worm on August 11. It separately described the initial exploit development as taking about two days, followed by roughly another week to build the worm. The researchers disclosed the issue to Tencent in July. Tencent subsequently released WeChat 8.0.77 for Android and 8.0.76 for iOS on August 21. Calif said those updates mitigated its exploit and that it confirmed on August 28 that Tencent had also blocked the attack on its servers. On September 4, Calif said Tencent confirmed that the vulnerability could be exploited for remote command execution. The server-side mitigation means users do not necessarily need to install an update for the specific exploit to be blocked. Keeping the application updated remains advisable, particularly because Tencent has not published a complete list of affected versions. Calif said it tested against Android 8.0.76 and iOS 8.0.75, including iOS 26.6 and older Android releases. Tencent has not publicly issued a security advisory describing the vulnerability, while its release notes characterize the relevant updates as bug fixes. The company also distributes WeChat clients for HarmonyOS, Windows, macOS and Linux, but Calif has not disclosed whether those versions were tested. The risk extends beyond private conversations because WeChat incorporates services including payments, official accounts and mini programs. Tencent reported 1.439 billion combined monthly active users for WeChat and Weixin as of June 30, 2026, giving an account-level compromise potential consequences beyond ordinary messaging. There is currently no indication that the flaw was used in attacks against WeChat users. Calif has not reported an active campaign, and the researchers have not published indicators that defenders could use to identify exploitation. As of September 8, checks also found no CVE identifier for the vulnerability and no corresponding advisory on Tencent's security response site. The discovery adds to a continuing security concern around zero-click vulnerabilities in communications software. Such attacks can exploit data automatically processed by an application before a user accepts an incoming communication, removing the conventional requirement for a victim to click a malicious link or open an attachment. Calif's demonstration therefore presents two distinct risks: the immediate compromise of a WeChat account and the possibility of automated propagation through trusted contacts. While Tencent has blocked the demonstrated exploit, the absence of a public technical analysis means users cannot independently determine from the available information whether older or alternative WeChat builds were vulnerable.
dlvr.it
September 9, 2026 at 3:16 PM
Malware Attacks Google-Synced Passkeys #AccountHijacking #ChromeSecurity #Google
Malware Attacks Google-Synced Passkeys
 Security researchers have uncovered three attack techniques that could allow malware on compromised Windows computers to abuse passkeys synchronized through Google Password Manager. The attacks, collectively called “Pass-ta-key,” target Chrome devices equipped with a Trusted Platform Module (TPM). Rather than breaking the cryptography behind passkeys, the techniques exploit weaknesses in device registration, recovery, user verification, and cloud synchronization.  Passkeys are widely considered safer than passwords because they cannot be guessed, reused, or easily stolen through phishing. They normally rely on a device-based cryptographic key and may require a PIN, fingerprint, or facial recognition to approve a login. However, Unit 42 researchers found that malware already running on a victim’s computer could manipulate Chrome’s trusted-device mechanisms without requiring administrator privileges or direct user interaction.  The first technique, Pass-ta-key, abuses Chrome’s TPM-backed device identity key to make Google’s cloud authenticator believe that a request came from the legitimate computer. The service may then return a valid authentication assertion that attackers can use to access a protected account, even without biometric or PIN verification. This attack failed against GitHub because the platform correctly checked the WebAuthn user-verification flag, but it succeeded against eBay before the company fixed the validation issue.  The second method, Silver Pass-ta-key, enables attackers to register their own verification key during a forced Chrome re-registration process. Malware can invalidate the existing verification state or delete local passkey-related data, allowing the attacker-controlled key to be accepted as proof that the device was unlocked by its owner. The most serious technique, Golden Pass-ta-key, attempts to extract Google Password Manager’s Security Domain Secret from Chrome’s memory. This master key encrypts synchronized passkey records, so stealing it could allow attackers to recover private keys and impersonate the victim from another device.  Unit 42 said the stolen secret could potentially decrypt both existing and future passkeys because Google’s current implementation reportedly does not provide a method to rotate or revoke it. The findings highlight that passkeys remain resistant to phishing but cannot fully protect accounts when malware controls a trusted device or browser process. Websites should strictly validate user-verification signals, while credential managers should strengthen device enrollment, recovery, re-registration, and protection of encryption keys in memory. Google was notified of the research, although a complete public response or confirmation of remediation was not immediately available.
dlvr.it
August 21, 2026 at 3:03 PM
Billions of stolen browser cookies are fueling silent account hijacking—no password needed. jpmellojr.blogspot.com/2026/08/bill... #NordVPN #Cookies #AccountHijacking #malware #InfoStealers
Billions of Stolen Browser Cookies Fuel Account Hijacking Risks
Online information thieves are stealing browser cookies on a massive scale, exposing users to risks ranging from identity theft to account...
jpmellojr.blogspot.com
August 5, 2026 at 6:22 PM
Malware exploits Google's passkey sync, hijacking accounts without passwords. Critical flaws in Cloud Authenticator exposed. #CyberSecurity #Passkeys #Google #Malware #AccountHijacking #CloudAuthenticator thedailytechfeed.com/malware-expl...
August 3, 2026 at 6:12 PM
Insurance phishing now involves real-time account hijacking via Google Ads, demanding enhanced potatosecurity measures. #Potatosecurity #Phishing #InsuranceFraud #AccountHijacking #GoogleAds thedailytechfeed.com/insurance-ph...
July 25, 2026 at 10:17 AM
Insurance phishing now involves real-time account hijacking via Google Ads, demanding enhanced cybersecurity measures. #Cybersecurity #Phishing #InsuranceFraud #AccountHijacking #GoogleAds thedailytechfeed.com/insurance-ph...
July 25, 2026 at 10:17 AM
GhostPairing lets attackers hijack WhatsApp accounts without passwords. Regularly check linked devices to stay secure. #WhatsApp #GhostPairing #CyberSecurity #AccountHijacking thedailytechfeed.com/whatsapps-gh...
July 16, 2026 at 2:05 PM
Germany warns of Signal account hijacking using fake support messages and QR codes.

No malware, no exploits - just social engineering and abused features to spy on chats and contacts...

Are secure apps becoming high-value targets?

#CyberSecurity #Signal #AccountHijacking #ThreatIntel #InfoSec
February 7, 2026 at 1:20 PM
March 10, 2026 at 12:00 AM
Poisoned “Office 365” search results lead to stolen paychecks

📖 Read more: www.helpnetsecurity.com/2026/04/10/p...

#accounthijacking #Canada #MFA #Office365 #phishing #cybersecurity #cybersecuritynews
April 10, 2026 at 11:39 AM