Friday, February 13, 2026
Home Blog Page 46

ShinyHunters declare to be behind SSO-account information theft assaults

0


The ShinyHunters extortion gang claims it’s behind a wave of ongoing voice phishing assaults focusing on single sign-on (SSO) accounts at Okta, Microsoft, and Google, enabling menace actors to breach company SaaS platforms and steal firm information for extortion.

In these assaults, menace actors impersonate IT assist and name staff, tricking them into coming into their credentials and multi-factor authentication (MFA) codes on phishing websites that impersonate firm login portals.

As soon as compromised, the attackers acquire entry to the sufferer’s SSO account, which might present entry to different related enterprise functions and companies.

Wiz

SSO companies from Okta, Microsoft Entra, and Google allow corporations to hyperlink third-party functions right into a single authentication move, giving staff entry to cloud companies, inside instruments, and enterprise platforms with a single login. 

These SSO dashboards usually listing all related companies, making a compromised account a gateway into company programs and information.

Platforms generally related by SSO embrace Salesforce, Microsoft 365, Google Workspace, Dropbox, Adobe, SAP, Slack, Zendesk, Atlassian, and plenty of others.

Microsoft Entra single sign-on (SSO) dashboard
Microsoft Entra single sign-on (SSO) dashboard
Supply: Microsoft

Vishing assaults used for information theft

As first reported by BleepingComputer, menace actors have been finishing up these assaults by calling staff and posing as IT employees, utilizing social engineering to persuade them to log into phishing pages and full MFA challenges in actual time.

After having access to a sufferer’s SSO account, the attackers browse the listing of related functions and start harvesting information from the platforms out there to that consumer.

BleepingComputer is conscious of a number of corporations focused in these assaults which have since obtained extortion calls for signed by ShinyHunters, indicating that the group was behind the intrusions.

BleepingComputer contacted Okta earlier this week in regards to the breaches, however the firm declined to touch upon the information theft assaults.

Nevertheless, Okta launched a report yesterday describing the phishing kits utilized in these voice-based assaults, which match what BleepingComputer has been advised.

In response to Okta, the phishing kits embrace a web-based management panel that permits attackers to dynamically change what a sufferer sees on a phishing website whereas talking to them on the telephone. This permits menace actors to information victims by every step of the login and MFA authentication course of.

If the attackers enter stolen credentials into the actual service and are prompted for MFA, they’ll show new dialog containers on the phishing website in actual time to instruct a sufferer to approve a push notification, enter a TOTP code, or carry out different authentication steps.

Phishing kit letting attackers display different dialogs while calling victims
A phishing package lets attackers show totally different dialogs whereas calling victims
Supply: Okta

ShinyHunters declare accountability

Whereas ShinyHunters declined to touch upon the assaults final evening, the group confirmed to BleepingComputer this morning that it’s accountable for a number of the social engineering assaults.

“We affirm we’re behind the assaults,” ShinyHunters advised BleepingComputer. “We’re unable to share additional particulars at the moment, moreover the truth that Salesforce stays our main curiosity and goal, the remainder are benefactors.”

The group additionally confirmed different elements of BleepingComputer’s reporting, together with particulars in regards to the phishing infrastructure and domains used within the marketing campaign. Nevertheless, it disputed {that a} screenshot of a phishing package command-and-control server shared by Okta was for its platform, claiming as an alternative that theirs was constructed in-house.

ShinyHunters claimed it’s focusing on not solely Okta but additionally Microsoft Entra and Google SSO platforms.

Microsoft stated it has nothing to share at the moment, and Google stated it had no proof its merchandise have been being abused within the marketing campaign.

“Right now, now we have no indication that Google itself or its merchandise are affected by this marketing campaign,” a Google spokesperson advised BleepingComputer.

ShinyHunters claims to be utilizing information stolen in earlier breaches, such because the widespread Salesforce information theft assaults, to establish and phone staff. This information contains telephone numbers, job titles, names, and different particulars used to make the social-engineering calls extra convincing.

Final evening, the group relaunched its Tor information leak website, which at the moment lists breaches at SoundCloud, Betterment, and Crunchbase.

SoundCloud beforehand disclosed an information breach in December 2025, whereas Betterment confirmed this month that its electronic mail platform had been abused to ship cryptocurrency scams and that information was stolen.

Crunchbase, which had not beforehand disclosed a breach, confirmed right this moment that information was stolen from its company community.

“Crunchbase detected a cybersecurity incident the place a menace actor exfiltrated sure paperwork from our company community,” an organization spokesperson advised BleepingComputer. “No enterprise operations have been disrupted by this incident. We now have contained the incident and our programs are safe.”

“Upon detecting the incident we engaged cybersecurity consultants and contacted federal legislation enforcement. We’re reviewing the impacted data to find out if any notifications are required in line with relevant authorized necessities.”

Whether or not you are cleansing up outdated keys or setting guardrails for AI-generated code, this information helps your staff construct securely from the beginning.

Get the cheat sheet and take the guesswork out of secrets and techniques administration.

A Hashish Customary Measure, Weird Lifeforms, And Extra! : ScienceAlert

0


This week in science: Scientists suggest new commonplace measures for hashish use; mysterious historical lifeforms do not comfortably match on the tree of life; the world’s oldest rock artwork found; and rather more!

Scientists Figured Out a Customary Measure For Hashish Use

(Terrance Barksdale/Canva)

UK scientists have calculated a normal measure for hashish as THC models, which will help customers and docs monitor consumption.

A 0.45-gram joint of sturdy natural hashish would possibly comprise 12.78 commonplace THC models, whereas weaker, seeded natural hashish can comprise simply 3.78 THC models, in response to the brand new estimates.

Learn the total story right here.

Mysterious Giants May Be a Entire New Type of Life That No Longer Exists

Mysterious Giants Could Be a Whole New Kind of Life That No Longer Exists
Prototaxites does not examine with another life kind we all know of. (Loron et al., Science, 2025)

Prototaxites – 8-m (26-ft) tall organisms that lived 400 million years in the past – does not belong to any recognized class of life at the moment, a brand new examine finds.

By a evaluate of microscopic anatomy and chemical evaluation of its tubular constructions, the workforce of researchers systematically eradicated every candidate group, leaving no trendy organism with which it would share some type of ancestral relationship.

Fungi? Rejected due to the distinctive manner its anatomy connects.

A plant or algae? Not going given its chemical composition.

A mixture of the 2, resembling a lichen? Not with that anatomy.

Some weird animal? Cell partitions say no likelihood.

Learn the total story right here.

Research Confirms Why Some Individuals Get Drunk With out Touching Alcohol

Study Confirms Why Some People Get Drunk Without Touching Alcohol
Klebsiella pneumoniae, one in every of two bacterial species implicated. (Callista Photos/Getty Photos)

E. coli and Ok. pneumoniae have been recognized as the 2 principal micro organism behind a uncommon syndrome the place alcohol brews within the intestine after consuming.

Audition now for ScienceAlert's Casting Call

The findings counsel reduction for sufferers would possibly lie in selling or introducing, by means of dietary adjustments, stool transplants or probiotics, different strains of intestine micro organism that readily metabolize ethanol.

Learn the total story right here.

World’s Oldest Rock Artwork Found in Indonesian Cave

World's Oldest Rock Art Discovered in Indonesian Cave
The information of the fingers had been pointed, a mode solely seen in Sulawesi, and which can have been associated to animals. (Ahdi Agus Oktaviana)

The world’s oldest recognized rock artwork has been found in a collapse Indonesia, dated to a minimum of 67,800 years in the past.

“What we’re seeing in Indonesia might be not a sequence of remoted surprises, however the gradual revealing of a a lot deeper and older cultural custom that has merely been invisible to us till lately,” archaeologist Maxime Aubert of Griffith College in Australia, who co-led the analysis, instructed ScienceAlert.

Learn the total story right here.

Scientists Discovered a Sugar That is Candy, Low-Calorie, And Would not Spike Insulin

Scientists Found a Sugar That's Sweet, Low-Calorie, And Doesn't Spike Insulin
(Uma Shankar sharma/Getty Photos)

Scientists have discovered a easy technique to produce a pure sugar known as tagatose, 92% as candy as sucrose however with solely 30% of the energy.

What’s notably thrilling about it’s that it doesn’t spike insulin ranges like sucrose or high-intensity synthetic sweeteners – making it a doubtlessly engaging possibility for these with diabetes or blood glucose points.

Learn the total story right here.

Shingles Vaccine Linked to Slower Organic Growing older, Research Finds

A reddish colored virus particle seen under a microscope
Transmission electron microscope picture of the varicella zoster virus, which causes shingles. (Science Photograph Library – HEATHER DAVIES/Getty Photos)

The shingles vaccine has been linked to slower growing old and fewer irritation, in a examine of three,800 folks over the age of 70.

The findings counsel that the vaccine could have “broad” and lingering results on “aging-related processes”, in response to the authors, gerontologists Jung Ki Kim and Eileen Crimmins from the College of Southern California.

Learn the total story right here.

jQuery 4.0.0 JavaScript library options trusted varieties

0

Model 4.0.0 of the still-widely-used jQuery JavaScript library is now accessible. Celebrated as the primary main launch in almost 10 years, jQuery 4.0.0 options help for trusted varieties and a brand new, slimmer construct.

Introduced January 17, the most recent model of the jQuery JavaScript library might be downloaded from jquery.com.  Trusted varieties in jQuery 4.0.0 be certain that HTML within the TrustedHTML interface might be enter to jQuery manipulation strategies in compliance with a browser’s Content material Safety Coverage (CSP) required-trusted-types-for directive. As well as, whereas some AJAX requests already had been utilizing to keep away from any CSP errors brought on by inline scripts. There nonetheless are just a few instances the place XHR is used for asynchronous script requests, corresponding to when the "headers" possibility is handed, however