#accounttakeover

5 posts · Last used 7d

Back to Timeline
dilshad @dilshad@infosec.exchange · Aug 07, 2026
NPM account takeovers via expired maintainer domains You don't need to exploit npm to poison it. Buy the expired email domain behind a maintainer's account, reset the password, and the package is yours. We scanned 2.1 million packages, extracted 6.7 million maintainer emails, and found 675 expired domains leaving 2,843 packages open to takeover. Those packages sit under 257,000+ dependent repos and 93,000 downstream packages. One lapsed domain renewal, a supply chain full of blast radius. https://laburity.com/research-npm-account-takeovers/ #SupplyChainSecurity #npm #AccountTakeover #AppSec #Laburity
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Aug 03, 2026
CVE-2026-18577 is being exploited in the wild for N-central account takeover. An incomplete patch let attackers gain admin access. Update to 2026.3.1.7. #Nable #Ncentral #CVE202618577 #AccountTakeover #RMM #CyberSecurity https://securityonline.info/cve-2026-18577-n-central-account-takeover/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 20, 2026
Kimai vulnerability CVE-2026-52824 (CVSS 9.1) lets attackers forge cookies for account takeover via a default Docker APP_SECRET. Update to 2.58.0 now. #Kimai #AccountTakeover #Docker #CVE202652824 #OpenSource https://securityonline.info/kimai-account-takeover/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 15, 2026
🤖 Zoom warns of critical Windows account takeover vulnerability. Unauthenticated attackers can exploit the desktop client and SDK to hijack accounts. Patch now. 🔗 https://www.bleepingcomputer.com/news/security/zoom-warns-of-critical-account-takeover-vulnerability/ #CVE #AccountTakeover #Zoom #CyberSec
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 15, 2026
Zoom vulnerability CVE-2026-53412 (CVSS 9.8) allows unauthenticated account takeover over the network. Update Zoom Workplace for Windows to 7.0.0 now. #Zoom #CVE202653412 #AccountTakeover #Windows #CyberSecurity https://securityonline.info/zoom-account-takeover-flaw/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0

You've seen all posts