← BACK TO FEED
TAG

account security3 articles

Infostealer Malware Is Draining Claude Accounts While Users Sleep

Anthropic has warned some Claude users that their computers were infected with infostealer malware — including Vidar, Lumma, and Atomic Stealer — which allowed attackers to steal browser cookies and hijack login sessions to exploit their accounts. The company detected the activity, signed out compromised sessions, removed saved payment methods, and refunded any unauthorized charges. Affected users have been advised to remove all malware from their devices before re-adding payment information.

1 Sept 2026

£8K Phishing Kit Promises to Plant Fake Passkeys and Haunt Compromised Accounts Long After You've Changed Your Password

A $10,000 phishing kit called iAuthFlow v2, advertised on Russian-language cybercrime forums, uses a browser-in-the-middle technique to hijack authentication sessions and secretly enroll attacker-controlled passkeys on compromised accounts — allowing persistent access even after victims change their passwords. The kit relays the victim's login interaction through an attacker-controlled browser, then exploits the authenticated session to register a rogue passkey, reportedly completing the process within seconds. Security researchers warn that incident response must go beyond password resets and session revocation, requiring a thorough audit of all post-compromise account changes, including newly enrolled passkeys, OAuth grants, and recovery methods.

23 Aug 2026

Meta's AI Support Tool Had a Bug. Hackers Found It First.

Meta disclosed that approximately 20,000 Instagram accounts were compromised through a bug in its High Touch Support (HTS) account recovery tool, which failed to verify that the email address provided during a password reset request matched the one associated with the targeted account. This allowed attackers to redirect password reset links to their own email addresses and take over accounts that lacked two-factor authentication (2FA). Meta has since disabled the vulnerable tool, invalidated the exploited reset links, reset affected account passwords, and plans to notify impacted users.

8 Jun 2026