threat-intel Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes A sophisticated phishing-as-a-service platform, dubbed AnonyMousKIT, is being used to target stolen Apple devices and trick owners into providing their passcodes and 2FA codes, enabling Activation Lock removal. Operated by a commercial voice platform, the operation leverages AI-powered voice agents impersonating Apple… The Hacker News · 4d ago High ZABRUSphishingactivation lock2fa
supply-chain npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk GitHub has released npm 12, significantly bolstering supply chain security by disabling install scripts and deprecating granular access tokens (GATs). These changes restrict automated script execution and limit the abili… The Hacker News · Jul 9, 2026 Medium npmsupply chainsecurity
threat-intel EvilTokens: A phishing attack that doesn’t steal your password EvilTokens is a sophisticated phishing-as-a-service (PaaS) kit that bypasses traditional phishing defenses by leveraging the OAuth 2.0 device authorization grant flow. Attackers use convincing lures – often mimicking leg… WeLiveSecurity · Jun 15, 2026 High phishingoath2device-code
threat-intel Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse Meta has reported that approximately 20,000 Instagram accounts were compromised due to abuse of its AI-powered account recovery tool, High Touch Support (HTS). Hackers exploited a vulnerability in the tool to reset passw… SecurityWeek · Jun 8, 2026 High aiaccount recoverypassword reset
phishing Instagram users locked out after Meta AI abused to steal accounts Instagram accounts were compromised due to attackers exploiting Meta’s AI-powered support tools to impersonate legitimate owners. Users were tricked into verifying their identities via AI-generated selfies, bypassing tra… BleepingComputer · Jun 2, 2026 High USaisocial mediaaccount takeover
supply-chain npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks npm has implemented a new staged publishing feature to bolster the security of its software supply chain, addressing concerns about malicious package releases. This system requires maintainers to verify releases with a t… The Hacker News · May 23, 2026 High supply-chain2fasecurity
threat-intel Move fast and save things: A quick guide to recovering a hacked account This article provides a practical guide for individuals whose online accounts have been compromised. It emphasizes the importance of immediate action to limit the attacker's control and recover the account. The guide out… WeLiveSecurity · Mar 20, 2026 Medium WOaccount recoveryphishingpassword security