ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

Cyberattackers are getting creative, using a combination of old and new tactics to infiltrate even the most secure systems. One particularly insidious technique involves exploiting identity exposure to unlock active attack paths, essentially giving hackers a free pass into an organization’s inner sanctum. According to recent reports, at least 11 high-profile cases have emerged where this tactic has been used with devastating effect.

At its core, this method relies on cross-domain privilege escalation – a complex-sounding term that refers to the ability of attackers to move laterally within an organization by exploiting differences in permission levels across different systems. This allows hackers to jump from one network segment to another, often undetected, and create a kind of digital “backdoor” into sensitive areas.

Take, for example, the recent case where five thousand Dropbox accounts were compromised using this exact tactic. It’s not clear how the attackers initially gained access to these accounts, but once inside, they used cross-domain privilege escalation to move laterally within the platform and steal sensitive information from users who had linked their Dropbox accounts to other services.

Another worrying trend is the increasing use of OAuth traps – a type of phishing attack that exploits vulnerabilities in online authentication protocols. When an attacker sets up an OAuth trap, it appears as though the user has authorized access to their own account, but in reality, they’ve just handed over their login credentials to the hacker. This can be devastating for businesses, which often rely on cloud services like Google or Amazon to host critical infrastructure.

The use of CEO phishing kits is another disturbing trend – pre-packaged software that allows attackers to launch highly targeted spear-phishing campaigns against executives and other high-value targets. These kits are often sold on the dark web, making it easier than ever for even novice hackers to launch sophisticated attacks against unsuspecting organizations.

But what’s perhaps most alarming about these tactics is their relatively low barrier to entry. With the rise of cloud-based services and the proliferation of connected devices, attackers have more opportunities than ever before to exploit vulnerabilities in an organization’s security posture. This makes it essential for businesses to stay vigilant and regularly review their defenses – no matter how secure they may feel.

To protect yourself from these types of attacks, it’s crucial to keep your software up-to-date, use strong passwords and two-factor authentication, and be extremely cautious when clicking on links or opening attachments from unknown senders. Even small vulnerabilities can have major consequences if exploited by determined attackers – so stay vigilant, and stay informed.


Source: The Hacker News — 2026-09-03