Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Cybersecurity News
  5. ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

Scheduled Pinned Locked Moved Cybersecurity News
1 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    The latest threat landscape shows attackers are relying less on exploiting complex flaws and more on social engineering and legitimate tools. The common thread is deception: convincing users that a malicious action is routine, like answering a call from IT, opening a shared file, or approving a login prompt.

    A significant number of campaigns are now targeting executives with phishing kits designed to look like legitimate CEO communications. These are often paired with fake login pages that capture credentials in real time. In a separate incident, roughly 5,000 Dropbox accounts were compromised, likely through reused credentials or link-based attacks, and attackers are increasingly leveraging OAuth applications to gain persistent access. Once a user clicks "Allow" on a malicious OAuth app, the attacker has a foothold without needing the actual password.

    The methods are deceptively simple:

    • Attackers are using old, stale account links to bypass initial checks.
    • Software tutorials and guides are being weaponized to point users to malicious downloads.
    • Typosquatting remains effective, where a single misspelled character in a URL leads to a fully functional fake portal.

    Because these attacks mimic standard user behavior, traditional security awareness often fails. The best defense is verifying out-of-band requests—especially those involving financial transactions or credential changes—and auditing connected OAuth applications on a regular basis.

    Source: The Hacker News

    Given the uptick in OAuth-related attacks, is your team actively auditing third-party app permissions, or are you relying on user reports to spot them?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World