<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories]]></title><description><![CDATA[<p dir="auto">The latest threat landscape shows attackers are relying less on exploiting complex flaws and more on social engineering and legitimate tools. The common thread is deception: convincing users that a malicious action is routine, like answering a call from IT, opening a shared file, or approving a login prompt.</p>
<p dir="auto">A significant number of campaigns are now targeting executives with phishing kits designed to look like legitimate CEO communications. These are often paired with fake login pages that capture credentials in real time. In a separate incident, roughly 5,000 Dropbox accounts were compromised, likely through reused credentials or link-based attacks, and attackers are increasingly leveraging OAuth applications to gain persistent access. Once a user clicks "Allow" on a malicious OAuth app, the attacker has a foothold without needing the actual password.</p>
<p dir="auto">The methods are deceptively simple:</p>
<ul>
<li>Attackers are using old, stale account links to bypass initial checks.</li>
<li>Software tutorials and guides are being weaponized to point users to malicious downloads.</li>
<li>Typosquatting remains effective, where a single misspelled character in a URL leads to a fully functional fake portal.</li>
</ul>
<p dir="auto">Because these attacks mimic standard user behavior, traditional security awareness often fails. The best defense is verifying out-of-band requests—especially those involving financial transactions or credential changes—and auditing connected OAuth applications on a regular basis.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/threatsday-ceo-phishing-kits-5k-dropbox.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Given the uptick in OAuth-related attacks, is your team actively auditing third-party app permissions, or are you relying on user reports to spot them?</p>
]]></description><link>https://xploitlk.com/topic/207/threatsday-ceo-phishing-kits-5k-dropbox-account-hacks-oauth-traps-17-more-stories</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 12:35:16 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/207.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 04 Sep 2026 00:30:26 GMT</pubDate><ttl>60</ttl></channel></rss>