Skip to content
category — security

ls ./category/security

Security

Breaches, vulnerabilities, malware and the patches that matter.

176 articles

The call is about your passkey. The break-in uses routes a passkey alone does not close

2026-09-15

Microsoft says extortion groups tied to ShinyHunters and Helix are phoning staff about urgent passkey or single sign-on updates, then steering them into relayed sign-ins or device-code approvals. Once in, they register an MFA method of their own, map the tenant through Microsoft Graph and take files at under 1,000 an hour to stay unremarkable.

The Trezor phishing needed no stolen password. Brevo's SSO let the attacker sign in as the people they invited

2026-09-15

Phishing that reached 347,000 Trezor newsletter subscribers came from Trezor's genuine Brevo account, so it passed every sender check. Brevo's post-mortem says the attacker created an account, switched on single sign-on, invited real Brevo users into it, and was then let into every organisation those users could reach. Early coverage spoke of stolen login details. Brevo's account involves none.

A terabyte left over four days, and nothing in the chain was a vulnerability

2026-09-10

McKesson's 8-K describes roughly one terabyte exfiltrated between 21 and 25 August 2026, detected on the last day. The chain was vishing to Okta SSO to Salesforce and Snowflake — no CVE, no exploit, no patch. And the claimed 284 million records are database rows, by the attackers' own account.

974 flaws, and the two that matter are both privilege escalation

2026-09-09

Microsoft patched 974 vulnerabilities in September, a 70% jump over the previous record, with 723 of them in Windows and more than 110 rated critical. Two are being exploited. Both are CVSS 7.8 local privilege escalation, which means the attacker is already on the machine — and that is the whole triage.