KLUE BREACH TRACED TO UNREVOKED 2022 CREDENTIAL
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
Klue disclosed that hackers exploited a credential left active since 2022 to breach customer data systems. The company failed to revoke the access key after completing a limited pilot program.
■ MORE FROM THE SECURITY DESK
The FBI's Atlanta office is investigating a suspected fake Wi-Fi hotspot attack targeting a Delta flight, with DEF CON attendees under suspicion. No arrests have been made.
Google Chrome is implementing device-bound session credentials, a security feature designed to block account takeovers by tying login sessions to specific devices. The technology addresses a growing threat where attackers steal credentials to gain unauthorized access.
The DeadLock ransomware operation is leveraging decentralized blockchain infrastructure to protect its communications with victims and data-leak operations. The approach makes traditional law enforcement takedowns significantly more difficult.
Russian threat group Sandworm is targeting IT professionals with trojanized WireGuard VPN clients distributed through fraudulent job offers. The campaign has been active since at least May.