Scammers posing as Hollyland, Nike and Spotify lure YouTube creators to fake brand-deal portals that take Google passwords and one-time codes, ESET found. One sign-in hands over Gmail, Drive and the channel itself.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence60
Scammers posing as Hollyland are sending YouTube creators tailored sponsorship offers that end at a fake Google login, WeLiveSecurity reported. That page takes the password and the one-time code, and with them the account that owns the channel.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Nikkei said attackers used hijacked staff Microsoft 365 accounts to send about 9,000 malicious-link emails on September 30, many to outside sources. The company believes recipients' names and addresses were exposed and expects more mail impersonating its staff.
Perspective Coverage
6 publishers
- Builder
- Builder 19%
- Operator
- Operator 60%
- Investor
- Investor 21%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence65
BlueKit, a phishing-as-a-service kit Malwarebytes has tracked since April, runs lures for 97 brands in 176 variants from one dashboard. Its targets include corporate SSO gateways, Salesforce and GitHub, so buyers with little skill can aim polished lures at work accounts.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives
- Insufficient
- Confidence50
Domino's has reset a "very small number" of customer accounts that attackers opened with passwords leaked in breaches at other sites. The company says its own systems held, but a correct stolen password was all an attacker needed to get in.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+5
- Incentives55
- Confidence50
Meta's on-device model flags likely scams from non-contacts in a limited beta. It carries no enforcement, no admin visibility, and no view of the vector that works best.
Reality
- Evidence55
- Adoption10
- Hype gap+15
- Incentives50
- Confidence60
CVE-2026-18963 lets an unauthenticated request skip the emailed reset token entirely. Upstream 26.7.2 and four Red Hat errata are out, and the stopgap has to be set realm by realm.
Publishers:access.redhat.com · github.com · keycloak.org · thehackernews.com Perspective Coverage
4 publishers
- Builder
- Builder 43%
- Operator
- Operator 51%
- Investor
- Investor 6%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+8
- Incentives30
- Confidence72
The two-step secret becomes a full alphanumeric password, and an account can now hold one passkey per platform. Both remain opt-in settings inside the app.
Perspective Coverage
7 publishers
- Builder
- Builder 33%
- Operator
- Operator 55%
- Investor
- Investor 12%
Reality
- Evidence68
- Adoption35
- Hype gap+10
- Incentives40
- Confidence72
buildOne report1 publisher The add-on shipped to Mozilla's store as a dispatcher and took its instructions afterwards from a page it opened itself, on a domain built to resemble googleusercontent.com.
Reality
- Evidence62
- Adoption10
- Hype gap−10
- Incentives55
- Confidence58
Automated traffic is now aimed at the screens where customers sign in and pay, and DataDome's year of request data shows how concentrated that pressure has become. Filtering it means deciding which humans get let in too.
Reality
- Evidence45
- Adoption60
- Hype gap+25
- Incentives80
- Confidence50
According to the Wall Street Journal, nearly 500 Polymarket US accounts were entered by people who typed in someone else's Social Security number. The flow's duplicate-identity check opened the account it matched instead of blocking the attempt.
Reality
- Evidence55
- Adoption72
- Hype gap−15
- Incentives70
- Confidence55
The notifications describe logins with valid passwords, data down to partial payment card numbers, and service changes made without the customer's consent. Telus did not say how many accounts were affected.
Reality
- Evidence55
- Adoption30
- Hype gap+10
- Incentives65
- Confidence55
buildOne report1 publisher A pool created with the defaults treats a password as the whole authentication factor and scores no risk on the sign-in. In the HackerOne chain a dev.to writeup walks through, either setting turned on would have stopped the takeover.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives68
- Confidence52
Rapid7's read of the fraud economy names Xleet, Blackpass, Infodig and Styx as the venues doing the trade, and points teams at MITRE's Fraud Fighting Framework, introduced in early 2026, to order what they watch.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+28
- Incentives68
- Confidence55
The 4,100 coins left a Washington wallet after two callers talked their way into the holder's Google Drive, and the arrests followed an exchange signup made from a home IP plus a month of spending loud enough to advertise itself.
Reality
- Evidence62
- Adoption68
- Hype gap−6
- Incentives45
- Confidence58
City of London Police recorded a 417% rise in account-hack losses to £6.3m in the year to March. The arithmetic underneath it shows the average loss per victim halving as small cases got recorded for the first time.
Reality
- Evidence62
- Adoption74
- Hype gap+14
- Incentives58
- Confidence66
buildOne report1 publisher CVE-2026-18963 lets an unauthenticated request skip the emailed token and reset any account on the server. Red Hat rates it 9.1. The stopgap costs you self-service recovery in every realm.
Reality
- Evidence62
- Adoption30
- Hype gap+14
- Incentives45
- Confidence56