Threat actors are combining social engineering with malicious OAuth applications to bypass password-based security and access sensitive Google Workspace data.
Fintech firm Revolut has confirmed a data breach caused by a sophisticated impersonation scam involving fraudulent requests sent via legitimate government domains.
Over 4.1 million people have been affected by a data breach at AdaptHealth, where hackers stole names, contact details, and health insurance information.
Attackers are increasingly bypassing multi-factor authentication (MFA) by targeting the processes used to recover lost or compromised accounts via service desks.
Threat actors are increasingly exploiting account recovery workflows to circumvent MFA, turning service desk support into a primary target for identity theft.

