- Services
- Products
-
-
- Online Training
- Information Security Awareness Training Course
- PCI DSS Compliance Bundle
- GLBA Awareness Training Course
- CMMC Training Course
- HIPAA Awareness Training Course
- Data Privacy Training Course
- Payments Security Training Course
- Phishing Awareness Training Course
- GDPR Training Course
- FERPA Training Course
- FACTA Training Course
- Online Training
-
- Compliance
- Markets
- Insights
- About
Threat Intel Update
Cybercriminals are blending social engineering, identity abuse, and AI exploitation to compromise accounts. Enterprise impersonation scams, including fake IT calls and fraudulent M&A schemes, continue targeting credentials and financial transfers.
AI ecosystems face new risks: stolen session tokens bypassing MFA, black markets for premium AI access, and a ChatGPT prompt-injection flaw leaking connected-app data. Separately, DoppelCart’s 119,000+ fake shopping sites show fraud operations scaling fast.
Bottom line: stronger identity controls, tighter verification, and vigilance against social engineering are critical.
Cybersecurity News
- AI Login Tokens Found Exposed in Massive Infostealer Leak – Okta found 1,843 valid JWTs and 24 active API keys for AI services (Gemini, OpenAI, Groq, OpenRouter) in a 7GB infostealer dump posted to Telegram. The data, pulled from 5,871 infected machines in 162 countries, also included tokens for Anthropic, Microsoft, Amazon, Cursor, and Character.ai. The Hacker News
- ChatGPT Flaw Let Attackers Secretly Exfiltrate Gmail Data – Check Point showed a planted prompt could make ChatGPT quietly read a user’s Gmail and leak it to an attacker’s account via a shared internal Artifactory instance. OpenAI has taken the service offline; no user action needed. The Hacker News
- DoppelCart Scam Network Runs 119,000 Fake Online Stores – Nebty uncovered DoppelCart, a fraud network running 119,000+ fake shop domains (105,000+ still live) impersonating 44,182 brands, the largest known fake-shop cluster by domain count. BleepingComputer
- Attackers Pose as IT Staff to Hijack Microsoft 365 Accounts – Since May 2026, attackers have been calling/texting employees’ personal phones posing as IT staff, using AiTM phishing or device-code flows to steal M365 credentials, then registering their own MFA to maintain access and exfiltrate SharePoint, OneDrive, and Exchange data. Help Net Security
- Fake M&A Deals Used to Con Employees Into Wiring Millions – The ‘Phantom Deal’ campaign impersonates executives and advisory firms to pressure employees into wiring large sums under cover of confidential M&A deals. Targets include Gen (Norton/Avast) and at least four other firms across PE, industrial finance, sales, mining, and energy. Dark Reading
Sign Up
To receive Threat Briefings by email.