Latest updates for Account-Centric Abuse

Fresh curated links around account-centric abuse are collected here so marketers can spot useful updates and turn timely ideas into posts faster.

Recent items include:

  • Attackers Distribute Password Attacks Across Fictional OAuth Apps to Evade SOC Alerts
  • OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
  • NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

Post angles to try

Share the most useful takeaway for your audience.
Turn one article into a quick practical checklist.
Ask your audience how this shift affects their work.
Turn angles into scheduled posts

Fresh articles and ideas

Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.

gbhackers.com /1 month ago

Attackers Distribute Password Attacks Across Fictional OAuth Apps to Evade SOC Alerts

Attackers are increasingly abusing spoofed OAuth application identifiers to enumerate Microsoft Entra ID accounts, test credentials, and fragment authentication activity across hun...

Read source
thehackernews.com /1 month ago

OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The activity allow...

Read source
thehackernews.com /2 weeks ago

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-i...

Read source
cybersecuritynews.com /1 month ago

Hackers Spoof 3.7 Million OAuth Client IDs to Stealthily Enumerate 2 Million Entra ID Users

Threat actors are increasingly exploiting spoofed OAuth client IDs to enumerate Microsoft Entra ID accounts and identify potentially valid credentials while evading traditional det...

Read source
blog.knowbe4.com /3 weeks ago

Report: Scams Are Surging as Attackers Abuse Trusted Workflows

Threat actors are increasingly abusing trusted workflows to carry out attacks, according to a new report from Gen Digital.

Read source
venturebeat.com /1 week ago

Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke

Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards.The accounts Anthropic flagged were car...

Read source
schneier.com /1 month ago

First-Person Identity Theft Story

Harrowing story of an identity theft victim. Yes, the person made a mistake—they gave the scammer a two-factor authentication code that allowed the scammer to take over their email...

Read source
thecitizen.co.tz /1 month ago

Rogue SIM agents exploit user registrations to fuel cybercrime

Weak enforcement of SIM card registration rules and the misuse of customers' personal information by rogue mobile phone agents are fuelling online fraud, raising concerns over the...

Read source
thehackernews.com /2 weeks ago

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerosp...

Read source
thehackernews.com /1 month ago

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. "UNC6671 continues...

Read source
gbhackers.com /2 days ago

Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials

A large-scale phishing operation is abusing trusted Google services as a multi-stage redirect network to bypass email security controls, deliver highly personalized credential-harv...

Read source
cybersecuritynews.com /1 month ago

Hackers Abuse FaceTime Calls to Impersonate Banks and Hijack Victims’ Accounts

Apple has issued a security advisory warning iPhone and iPad users to treat unexpected FaceTime calls with the same scrutiny as standard phishing emails. A newly tracked wave of so...

Read source
broadbandbreakfast.com /1 week ago

Scams in the U.S. Are at a Record High, Yet Most Victims Get No Help

Although both the Trump administration and Congress are pursuing new options, victims still have little recourse.

Read source
fintechnews.sg /3 weeks ago

Webinar: When Account Takeover Moves Past Onboarding

Account takeover shows why fraud risk cannot be treated as an onboarding problem. Fraudsters are using stolen credentials, phishing and social engineering to get into real customer...

Read source
cofense.com /2 weeks ago

Understanding Browser Trust Abuse: Exploiting Enterprise’s Most Trusted Interface

By: Marie Mamaril, Intelligence TeamThe biggest change in browser-related threats is not a new flaw in browser software. It is a shift in how threat actors operate. Instead of brea...

Read source
fintechnews.hk /3 weeks ago

Webinar: When Account Takeover Moves Past Onboarding

Account takeover shows why fraud risk cannot be treated as an onboarding problem. Fraudsters are using stolen credentials, phishing and social engineering to get into real customer...

Read source
gbhackers.com /2 weeks ago

EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords

EvilTokens is pushing phishing-as-a-service beyond credential theft by abusing Microsoft’s device authorization flow to obtain valid Microsoft 365 tokens. Victims can complete a le...

Read source
devops.com /1 month ago

GitHub API Abuse, ‘Ghost’ Accounts Part of Malicious Efforts to Map Organizations

Datadog researchers uncover months-long overlapping campaigns to scrape data about companies and their developers.

Read source
finextra.com /2 weeks ago

When fraud controls start working against you (Ben O'Brien)

UK Finance data puts total payment fraud losses at £1.28bn, up 4% year on year, with APP fraud alone...

Read source
thehackernews.com /1 month ago

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing m...

Read source
blog.knowbe4.com /1 week ago

Attackers Abuse Enterprise Collaboration Tools to Avoid Detection

Threat actors’ abuse of enterprise collaboration tools increased fourfold over the past twelve months, according to researchers at Palo Alto Networks’ Unit 42.

Read source
chicatphilsplace.blogspot.com /3 weeks ago

Abuse Reports in Second Life

There is a very long and detailed article on how to report abuses  --- this just out on Techie Tuesday or whatever the new catch phrase actually is.  Now many of you already know h...

Read source
cybersecuritynews.com /2 days ago

Hackers Abuse Trusted Google Services to Hide Credential-Stealing Phishing Attacks

Criminals are using trusted Google services as cover for a wide phishing campaign that steals corporate credentials and, in some cases, installs remote-access software. The malicio...

Read source
fintechnews.sg /1 month ago

Asia’s Biggest Fraud Threat Is the Customer Who Passes Every Check

Somewhere in Asia right now, a payment is clearing every security check a bank has in place. The login is legitimate, the device is the one the customer uses, and the person tappin...

Read source

Turn fresh research into a full content calendar

Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.

Sources covering Account-Centric Abuse

feeds.feedburner.com

Recent coverage from public sources
Public source

blog.knowbe4.com

Recent coverage from public sources
Public source

broadbandbreakfast.com

Recent coverage from public sources
Public source

cofense.com

Recent coverage from public sources
Public source

cybersecuritynews.com

Recent coverage from public sources
Public source

devops.com

Recent coverage from public sources
Public source