Identity & Access

When an Employee's Password Shows Up in a Stealer Log, the Session Cookie Is the Real Problem
Infostealer malware grabs more than passwords. It grabs live logins, and that is what lets attackers walk past multi-factor prompts.

Shai-Hulud Worm Now Hunts 469 Places for Developer Secrets
A self-spreading credential thief has more than doubled the hiding spots it checks on developer machines, from 189 to 469.

Criminals Pose as IT Support Inside Microsoft Teams to Take Over Company Networks
A hacking campaign called Spring Ring tricked more than 150 employees at ten-plus companies into handing over remote control of their computers, all through a fake Teams call from a fake help desk.

Ransomware Gangs Are Now Paying Insiders to Unlock the Front Door
Criminal groups are bribing employees to hand over company access rather than hacking their way in. It is cheaper, faster, and harder to detect, and the insider threat problem is getting worse.

Dropbox accounts hijacked after attacker abused a Lenovo signup flaw
A weakness in how Lenovo verified email addresses let an attacker create fake Lenovo IDs and walk straight into around 5,000 Dropbox accounts, no password needed.

Why Edge Security Alone Misses the Riskiest Logins
Attackers now hide behind home internet connections and privacy tools that make their sessions look ordinary. Session enrichment aims to fix that blind spot.

Microsoft Makes Passkeys the Default Login for Business Accounts. Passwords Aren't Dead Yet.
From September 2025, Microsoft's business identity system defaults to passkeys instead of passwords. But experts say the shift will take years to complete, and most companies will run both systems side by side for a long time.

Five habits that keep file server access from spiralling out of control
A practical guide to least-privilege permissions, drawn from vendor guidance aimed at overworked IT teams.

Bank Impersonation Scams: How One Target Wasted the Fraudsters' Time for Hours
A reader who received a fake Barclays automated call decided not to hang up. What followed is a useful case study in how these scams work, and what you can do when one lands in your lap.

Phone thief raided victim's Sharesies investment account and moved $50,000 in three transfers
A Hamilton man is behind bars after a stolen cellphone gave criminals a direct route into an investment app, netting tens of thousands of dollars. The case also exposed a separate scheme to help scammers cheat an elderly victim out of $24,000.

Anthropic warns Claude accounts are being hijacked by password-stealing malware
The AI company says common infostealer malware on customer PCs has been lifting active Claude login sessions, letting criminals sign in without a password and burn through usage limits.

Brave Rolls Out Email Aliases to Cut Off a Common Path to Phishing
Version 1.94 of the Brave browser lets users mask their real inbox behind disposable addresses, aiming to blunt data-broker resale and post-breach phishing.

Why 'Identity Fabric' Is the Phrase Every Security Team Will Hear in 2026
As passwords fade and machine accounts outnumber humans, a new architecture promises to watch every login, token and API call in one place. Here's what it actually means.

Dark-web card data, 98 Bunnings items, and one PowerPass account: how a South Australian man was caught
Aijaypal Tim Sanghera used stolen credit card numbers, almost certainly bought on the dark web, to order $15,899 worth of goods from Bunnings stores across South Australia. A loyalty account tied every transaction to his name.

Android 17 hides which websites you visit from your Wi-Fi and mobile provider
Google's next Android release turns on Encrypted Client Hello by default, blocks silent local network scans, and lets carriers switch off the ageing 2G network that fraudsters abuse.