<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Account Takeover</title><description>Cybersecurity articles tagged #Account Takeover on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Modern Google Workspace Attack Chain: OAuth &amp; AI Agent Risks</title><link>https://runtimerebel.com/blog/modern-google-workspace-attack-chain-oauth-ai-agent-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/modern-google-workspace-attack-chain-oauth-ai-agent-risks</guid><description>The modern Google Workspace attack chain exploits OAuth grants, not just email. Understand how attackers and AI agents compromise accounts and secure your environment.</description><pubDate>Sat, 15 Aug 2026 08:16:26 GMT</pubDate><category>Google Workspace</category><category>OAuth</category><category>AI Agents</category><category>Account Takeover</category><category>Cloud Security</category></item><item><title>CVE-2026-71362: Adobe Commerce Account Takeover — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-71362-adobe-commerce-account-takeover-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-71362-adobe-commerce-account-takeover-patch-now</guid><description>Hackers are immediately exploiting CVE-2026-71362, a critical authorization flaw in Adobe Commerce, to take over customer accounts. Patch urgently.</description><pubDate>Fri, 14 Aug 2026 01:07:52 GMT</pubDate><category>Privilege Escalation</category><category>Account Takeover</category><category>CVE-2026-71362</category><category>Adobe Commerce</category><category>Magento Open Source</category></item><item><title>Chick-fil-A Data Breach: Over 13K Accounts Compromised via Credential Stuffing</title><link>https://runtimerebel.com/blog/chick-fil-a-data-breach-over-13k-accounts-compromised-via-credential-stuffing</link><guid isPermaLink="true">https://runtimerebel.com/blog/chick-fil-a-data-breach-over-13k-accounts-compromised-via-credential-stuffing</guid><description>Chick-fil-A confirms a data breach affecting over 13,000 customer accounts through credential stuffing, leading to drained rewards and gift cards.</description><pubDate>Fri, 24 Jul 2026 17:41:55 GMT</pubDate><category>Chick Fil a</category><category>Data Breach</category><category>Credential Stuffing</category><category>Account Takeover</category><category>Customer Data</category></item><item><title>Email Account Takeover via 2FA Compromise: Mitigating Identity Theft Risk</title><link>https://runtimerebel.com/blog/email-account-takeover-via-2fa-compromise-mitigating-identity-theft-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/email-account-takeover-via-2fa-compromise-mitigating-identity-theft-risk</guid><description>An identity theft incident highlights how easily email account takeover via compromised 2FA can lead to broader security breaches. Learn to protect your digital identity.</description><pubDate>Wed, 22 Jul 2026 17:24:17 GMT</pubDate><category>Identity Theft</category><category>Account Takeover</category><category>2FA Bypass</category><category>Email Security</category><category>Phishing</category><category>Social Engineering</category></item><item><title>Zoom CVE-2026-53412: Critical Windows Client Account Takeover Fix</title><link>https://runtimerebel.com/blog/zoom-cve-2026-53412-critical-windows-client-account-takeover-fix</link><guid isPermaLink="true">https://runtimerebel.com/blog/zoom-cve-2026-53412-critical-windows-client-account-takeover-fix</guid><description>Zoom releases critical security updates for CVE-2026-53412, a high-severity input validation flaw in Windows clients allowing unauthenticated account takeover.</description><pubDate>Thu, 16 Jul 2026 10:12:19 GMT</pubDate><category>Zoom</category><category>CVE-2026-53412</category><category>Windows</category><category>Account Takeover</category><category>Input Validation</category></item><item><title>CVE-2024-24691: Zoom Windows Client Account Takeover - Patch Now</title><link>https://runtimerebel.com/blog/cve-2024-24691-zoom-windows-client-account-takeover-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-24691-zoom-windows-client-account-takeover-patch-now</guid><description>Zoom has addressed CVE-2024-24691, a critical 9.6 CVSS vulnerability in Windows clients allowing unauthenticated account takeover. Learn how to patch and defend.</description><pubDate>Wed, 15 Jul 2026 21:05:22 GMT</pubDate><category>CVE-2024-24691</category><category>Zoom</category><category>Account Takeover</category><category>Windows</category><category>Remote Code Execution</category></item><item><title>Microsoft 365 Entra Passkey Vishing Targets: Account Takeover Risk</title><link>https://runtimerebel.com/blog/microsoft-365-entra-passkey-vishing-targets-account-takeover-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-365-entra-passkey-vishing-targets-account-takeover-risk</guid><description>A sophisticated vishing campaign targets Microsoft 365 users, tricking them into enrolling malicious Entra passkeys for account takeover. Learn detection and prevention.</description><pubDate>Wed, 08 Jul 2026 17:39:23 GMT</pubDate><category>Microsoft 365</category><category>Entra</category><category>Passkey</category><category>Vishing</category><category>Social Engineering</category><category>Account Takeover</category></item><item><title>FBI Warns: Russian APTs Target Signal Backup Keys via Phishing</title><link>https://runtimerebel.com/blog/fbi-warns-russian-apts-target-signal-backup-keys-via-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-warns-russian-apts-target-signal-backup-keys-via-phishing</guid><description>FBI and CISA warn of Russian intelligence targeting Signal users. Attackers phish for backup recovery keys, enabling full account takeover and message history access.</description><pubDate>Fri, 26 Jun 2026 20:38:49 GMT</pubDate><category>Russian Intelligence</category><category>Signal</category><category>Phishing</category><category>Account Takeover</category><category>Data Theft</category></item><item><title>SIM-Swapping Ring Busted: Millions in Crypto Theft via Telecom Hacks</title><link>https://runtimerebel.com/blog/sim-swapping-ring-busted-millions-in-crypto-theft-via-telecom-hacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/sim-swapping-ring-busted-millions-in-crypto-theft-via-telecom-hacks</guid><description>Polish authorities dismantle a sophisticated SIM-swapping ring that hijacked telecom partners and email accounts to steal millions in cryptocurrency.</description><pubDate>Fri, 26 Jun 2026 01:02:30 GMT</pubDate><category>SIM Swapping</category><category>Cryptocurrency Theft</category><category>Telecommunications Security</category><category>Account Takeover</category><category>Cybercrime</category><category>Poland</category></item><item><title>Nathaniel Saavedra Sentenced for 2022 DraftKings Account Takeover</title><link>https://runtimerebel.com/blog/nathaniel-saavedra-sentenced-for-2022-draftkings-account-takeover</link><guid isPermaLink="true">https://runtimerebel.com/blog/nathaniel-saavedra-sentenced-for-2022-draftkings-account-takeover</guid><description>21-year-old hacker &apos;Snoopy&apos; sentenced to 18 months in prison for the DraftKings cyberattack that compromised 60,000 accounts via credential stuffing in 2022.</description><pubDate>Thu, 25 Jun 2026 00:59:20 GMT</pubDate><category>DraftKings</category><category>Credential Stuffing</category><category>Account Takeover</category><category>Cybercrime Sentencing</category><category>Snoopy</category></item><item><title>Rise of &apos;Search Your Target&apos; Markets for Stolen Credentials</title><link>https://runtimerebel.com/blog/rise-of-search-your-target-markets-for-stolen-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/rise-of-search-your-target-markets-for-stolen-credentials</guid><description>Explores the emerging underground market where attackers pay to precisely search stolen credential databases for specific target organizations and accounts.</description><pubDate>Mon, 22 Jun 2026 17:37:29 GMT</pubDate><category>Stolen Credentials</category><category>Credential Stuffing</category><category>Account Takeover</category><category>Dark Web</category><category>Underground Market</category><category>Threat Intelligence</category></item><item><title>Iowa School District Hack: Sentencing Highlights Insider Threat Risks</title><link>https://runtimerebel.com/blog/iowa-school-district-hack-sentencing-highlights-insider-threat-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/iowa-school-district-hack-sentencing-highlights-insider-threat-risks</guid><description>Former Iowa school IT employee sentenced to 21 months for malicious infrastructure disruption and data tampering against his former employer.</description><pubDate>Sun, 14 Jun 2026 01:05:13 GMT</pubDate><category>Insider Threat</category><category>Identity Management</category><category>Account Takeover</category><category>School Security</category></item><item><title>Meta AI Chatbot Exploited for Instagram Account Takeover</title><link>https://runtimerebel.com/blog/meta-ai-chatbot-exploited-for-instagram-account-takeover</link><guid isPermaLink="true">https://runtimerebel.com/blog/meta-ai-chatbot-exploited-for-instagram-account-takeover</guid><description>Attackers manipulate Meta&apos;s AI support chatbot to reset Instagram passwords and hijack accounts via unauthorized email updates and location spoofing.</description><pubDate>Thu, 04 Jun 2026 13:17:29 GMT</pubDate><category>Meta AI</category><category>Instagram</category><category>Account Takeover</category><category>Social Engineering</category><category>AI Security</category></item><item><title>Meta AI Support Abuse Leads to Instagram Account Hijacking</title><link>https://runtimerebel.com/blog/meta-ai-support-abuse-leads-to-instagram-account-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/meta-ai-support-abuse-leads-to-instagram-account-hijacking</guid><description>Attackers exploit Meta AI support tools to bypass traditional security and hijack Instagram profiles, leaving legitimate users locked out of their accounts.</description><pubDate>Tue, 02 Jun 2026 17:38:52 GMT</pubDate><category>Meta AI</category><category>Instagram</category><category>Social Engineering</category><category>Account Takeover</category><category>AI Abuse</category></item><item><title>Meta AI Support Bot Exploited for Instagram Account Takeovers</title><link>https://runtimerebel.com/blog/meta-ai-support-bot-exploited-for-instagram-account-takeovers</link><guid isPermaLink="true">https://runtimerebel.com/blog/meta-ai-support-bot-exploited-for-instagram-account-takeovers</guid><description>Hackers manipulated Meta&apos;s AI support assistant to bypass authentication and seize high-profile Instagram accounts, including government entities.</description><pubDate>Mon, 01 Jun 2026 18:08:48 GMT</pubDate><category>Instagram</category><category>Meta AI</category><category>Account Takeover</category><category>Prompt Injection</category><category>Social Engineering</category></item><item><title>WP Maps Pro Flaw Exploited for Admin Account Creation — Patch Now</title><link>https://runtimerebel.com/blog/wp-maps-pro-flaw-exploited-for-admin-account-creation-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/wp-maps-pro-flaw-exploited-for-admin-account-creation-patch-now</guid><description>Attackers are actively exploiting a critical vulnerability in the WP Maps Pro WordPress plugin to create unauthorized administrator accounts on affected sites.</description><pubDate>Mon, 01 Jun 2026 09:57:24 GMT</pubDate><category>WP Maps Pro</category><category>WordPress Security</category><category>Unauthorized Access</category><category>Account Takeover</category><category>Plugin Vulnerability</category></item><item><title>CVE-2024-45404: Pretalx Logic Flaw Enables Full Account Takeover</title><link>https://runtimerebel.com/blog/cve-2024-45404-pretalx-logic-flaw-enables-full-account-takeover</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-45404-pretalx-logic-flaw-enables-full-account-takeover</guid><description>Researchers discover a critical logic flaw in Pretalx versions prior to 2024.1.0 that allows attackers to hijack organizer accounts and manipulate events.</description><pubDate>Wed, 27 May 2026 17:13:17 GMT</pubDate><category>Pretalx</category><category>CVE-2024-45404</category><category>Account Takeover</category><category>Conference Security</category><category>Logic Flaw</category></item><item><title>Roblox Account Hijacking: 610,000 Accounts Compromised and Sold</title><link>https://runtimerebel.com/blog/roblox-account-hijacking-610000-accounts-compromised-and-sold</link><guid isPermaLink="true">https://runtimerebel.com/blog/roblox-account-hijacking-610000-accounts-compromised-and-sold</guid><description>Ukrainian police arrested a group for hijacking 610,000 Roblox accounts and generating $225,000 in profits through illegal sales of user data.</description><pubDate>Wed, 29 Apr 2026 20:30:38 GMT</pubDate><category>Roblox</category><category>Account Takeover</category><category>Credential Stuffing</category><category>Cybercrime</category><category>Identity Theft</category></item><item><title>Malicious PyPI Package elementary-data Hijacked for Infostealer</title><link>https://runtimerebel.com/blog/malicious-pypi-package-elementary-data-hijacked-for-infostealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-pypi-package-elementary-data-hijacked-for-infostealer</guid><description>High-profile supply chain attack on the elementary-data PyPI package compromises developer credentials and crypto wallets via account takeover. Patch now.</description><pubDate>Mon, 27 Apr 2026 16:40:27 GMT</pubDate><category>PyPI</category><category>Elementary Data</category><category>Infostealer</category><category>Python Security</category><category>Account Takeover</category></item><item><title>Multi-Signal Fraud Prevention for the Customer Journey</title><link>https://runtimerebel.com/blog/multi-signal-fraud-prevention-for-the-customer-journey</link><guid isPermaLink="true">https://runtimerebel.com/blog/multi-signal-fraud-prevention-for-the-customer-journey</guid><description>Protect digital platforms from account takeover and payment fraud. This guide covers how identity, device, and network signals improve security without friction.</description><pubDate>Tue, 21 Apr 2026 16:30:40 GMT</pubDate><category>Fraud Prevention</category><category>Account Takeover</category><category>Device Fingerprinting</category><category>Identity Validation</category><category>Bot Detection</category></item><item><title>Tycoon Phishers Adopt Device Code Attacks to Bypass 2FA</title><link>https://runtimerebel.com/blog/tycoon-phishers-adopt-device-code-attacks-to-bypass-2fa</link><guid isPermaLink="true">https://runtimerebel.com/blog/tycoon-phishers-adopt-device-code-attacks-to-bypass-2fa</guid><description>Tycoon 2FA Phishers are now leveraging device code phishing to bypass multi-factor authentication, granting them unauthorized account access.</description><pubDate>Sat, 18 Apr 2026 00:42:05 GMT</pubDate><category>Phishing</category><category>2FA Bypass</category><category>Tycoon Phishing</category><category>Account Takeover</category><category>Device Code Phishing</category><category>OAuth</category></item><item><title>DraftKings Hacker Sentenced: Lessons in Credential Stuffing Defense</title><link>https://runtimerebel.com/blog/draftkings-hacker-sentenced-lessons-in-credential-stuffing-defense</link><guid isPermaLink="true">https://runtimerebel.com/blog/draftkings-hacker-sentenced-lessons-in-credential-stuffing-defense</guid><description>Analysis of the sentencing of Kamerin Stokes following the 2022 DraftKings breach, detailing credential stuffing TTPs and account takeover prevention strategies.</description><pubDate>Fri, 17 Apr 2026 12:29:34 GMT</pubDate><category>DraftKings</category><category>Credential Stuffing</category><category>Account Takeover</category><category>Insider Threat</category><category>Identity Theft</category></item><item><title>DraftKings Credential Stuffing: Memphis Man Sentenced to 30 Months</title><link>https://runtimerebel.com/blog/draftkings-credential-stuffing-memphis-man-sentenced-to-30-months</link><guid isPermaLink="true">https://runtimerebel.com/blog/draftkings-credential-stuffing-memphis-man-sentenced-to-30-months</guid><description>Kamerin Stokes sentenced to 30 months for selling 60,000+ hacked DraftKings accounts. Technical analysis of the 2022 credential stuffing attack and mitigations.</description><pubDate>Fri, 17 Apr 2026 08:43:09 GMT</pubDate><category>DraftKings</category><category>Credential Stuffing</category><category>Account Takeover</category><category>Fraud</category><category>Cybercrime Sentencing</category></item><item><title>VIP Credential Monitoring: Defending High-Value Targets</title><link>https://runtimerebel.com/blog/vip-credential-monitoring-defending-high-value-targets</link><guid isPermaLink="true">https://runtimerebel.com/blog/vip-credential-monitoring-defending-high-value-targets</guid><description>Learn how VIP credential monitoring protects high-privilege users from account takeover by tracking exposures across personal and corporate email domains.</description><pubDate>Mon, 13 Apr 2026 16:36:02 GMT</pubDate><category>Credential Theft</category><category>Identity Intelligence</category><category>Account Takeover</category><category>Executive Protection</category><category>Infostealers</category></item><item><title>OAuth 2.0 Device Code Phishing Surge: Protecting M365 and Google</title><link>https://runtimerebel.com/blog/oauth-2-0-device-code-phishing-surge-protecting-m365-and-google</link><guid isPermaLink="true">https://runtimerebel.com/blog/oauth-2-0-device-code-phishing-surge-protecting-m365-and-google</guid><description>Device code phishing attacks have surged 37x this year. Learn how adversaries abuse the OAuth 2.0 Device Authorization Grant to bypass MFA and hijack accounts.</description><pubDate>Sat, 04 Apr 2026 16:14:53 GMT</pubDate><category>OAuth 2 0</category><category>Phishing</category><category>Microsoft 365</category><category>MFA Bypass</category><category>Account Takeover</category></item><item><title>Residential Proxies Bypass 78% of IP Reputation Checks</title><link>https://runtimerebel.com/blog/residential-proxies-bypass-78-of-ip-reputation-checks</link><guid isPermaLink="true">https://runtimerebel.com/blog/residential-proxies-bypass-78-of-ip-reputation-checks</guid><description>Residential proxies effectively bypass IP reputation systems in 78% of sessions, enabling widespread bot attacks like credential stuffing and account takeovers.</description><pubDate>Thu, 02 Apr 2026 16:26:17 GMT</pubDate><category>Residential Proxies</category><category>IP Reputation</category><category>Bot Attacks</category><category>Credential Stuffing</category><category>Account Takeover</category><category>Netacea</category><category>Cybercrime</category></item><item><title>EvilTokens Fuels Microsoft Device Code Phishing &amp; BEC</title><link>https://runtimerebel.com/blog/eviltokens-fuels-microsoft-device-code-phishing-bec</link><guid isPermaLink="true">https://runtimerebel.com/blog/eviltokens-fuels-microsoft-device-code-phishing-bec</guid><description>New EvilTokens service automates Microsoft device code phishing, enabling account takeover and sophisticated business email compromise (BEC) attacks. Learn how to defend.</description><pubDate>Wed, 01 Apr 2026 20:19:20 GMT</pubDate><category>EvilTokens</category><category>Microsoft</category><category>Device Code Phishing</category><category>BEC</category><category>Account Takeover</category><category>Phishing</category><category>MFA Bypass</category></item><item><title>Credential Theft Surge: Understanding Infostealer &amp; AI Social Engineering</title><link>https://runtimerebel.com/blog/credential-theft-surge-understanding-infostealer-ai-social-engineering</link><guid isPermaLink="true">https://runtimerebel.com/blog/credential-theft-surge-understanding-infostealer-ai-social-engineering</guid><description>Credential theft surged in late 2025, driven by sophisticated infostealer malware and AI-enhanced social engineering.</description><pubDate>Wed, 18 Mar 2026 00:37:14 GMT</pubDate><category>Credential Theft</category><category>Infostealer</category><category>AI Social Engineering</category><category>Identity Security</category><category>Account Takeover</category><category>Social Engineering</category></item><item><title>Loblaw Data Breach: Analyzing the PC Optimum Account Resets</title><link>https://runtimerebel.com/blog/loblaw-data-breach-analyzing-the-pc-optimum-account-resets</link><guid isPermaLink="true">https://runtimerebel.com/blog/loblaw-data-breach-analyzing-the-pc-optimum-account-resets</guid><description>Canadian retail giant Loblaw notifies customers of a security breach affecting PC Optimum accounts, prompting a mandatory session reset for all users.</description><pubDate>Fri, 13 Mar 2026 00:34:33 GMT</pubDate><category>Loblaw</category><category>Credential Stuffing</category><category>Retail Security</category><category>Pc Optimum</category><category>Account Takeover</category></item><item><title>Phishing Campaign Leverages Fake Google PWA to Steal Credentials, MFA</title><link>https://runtimerebel.com/blog/phishing-campaign-leverages-fake-google-pwa-to-steal-credentials-mfa</link><guid isPermaLink="true">https://runtimerebel.com/blog/phishing-campaign-leverages-fake-google-pwa-to-steal-credentials-mfa</guid><description>A sophisticated phishing campaign uses a fake Google Security PWA to compromise accounts, steal MFA codes, and proxy traffic. Learn how to protect.</description><pubDate>Tue, 03 Mar 2026 00:36:21 GMT</pubDate><category>Phishing</category><category>PWA</category><category>MFA Bypass</category><category>Credential Theft</category><category>Google Accounts</category><category>Account Takeover</category></item></channel></rss>