Tag: Password Reset

Malware Using Google MultiLogin Exploit to Maintain Access Despite Password Reset
News

Malware Using Google MultiLogin Exploit to Maintain Access Despite Password Reset

Malware that steals information is currently using MultiLogin, an undocumented Google OAuth API, to take over user sessions and grant persistent access to Google services even after a password reset. As per CloudSEK, the crucial vulnerability enables threat actors to sustain access to a legitimate session in an unauthorized way by facilitating cookie formation and session persistence. On October 20, 2023, a threat actor going by the handle PRISMA initially disclosed the method on their Telegram channel. Since then, it has been included in several malware-as-a-service (MaaS) stealer families, including RisePro, Lumma, Rhadamanthys, Stealc, Meduza, and Whitesnake. When users sign in to their accounts in the Chrome web browser, the MultiLogin authentication endpoint is primarily int...
Password Reset Hack Exposed in Honda E-Commerce Platform Dealers Data at Risk
News

Password Reset Hack Exposed in Honda E-Commerce Platform Dealers Data at Risk

Honda's e-commerce platform has security flaws that may have been used to get uncontrolled access to private dealer data. In a study released last week, security researcher Eaton Zveare said that "broken/missing access controls made it possible to access all data on the platform, even when logged in as a test account." The platform is made for firms selling lawn & garden, marine, and power equipment. The Japanese company's vehicle division is unaffected. In essence, the hack uses a password reset feature on one of Honda's websites, Power Equipment Tech Express (PETE), to reset any account's password and gain complete admin access read more Password Reset Hack Exposed in Honda E-Commerce Platform, Dealers Data at Risk. Stay one step ahead of cyber threats with ReconBee.com....