AI Phishing Ring Busted ⚖️ + 474 GitHub Keys Still Unlocking Doors 🔑
Today's two biggest stories share a theme: attackers don't need to break in when they can simply log in. One shows how AI is supercharging email fraud; the other shows how a single forgotten file can hand over the keys to your code.
🤖 EvilTokens: The Phishing Service That Read Your Inbox With AI
Microsoft and the UK's Metropolitan Police just took down EvilTokens, a "phishing-as-a-service" operation that criminals could rent on Telegram for $1,500 upfront and $500 a month. It tricked people into approving a legitimate-looking Microsoft sign-in code, which quietly handed attackers access to their accounts. Before the takedown, it compromised roughly 12,000 accounts across 10,000 organizations. The scary part: a built-in AI chatbot scanned thousands of stolen emails at once to figure out who approves payments, who they report to, and exactly what fake request would get money wired to criminals. Microsoft seized 50 websites and 150 domains and two men were arrested, but the lesson stands: never enter a sign-in code you didn't request yourself, and always verify payment changes by phone.
🔑 474 Leaked GitHub Keys That Never Expire
Security firm GitGuardian tested 4,802 GitHub App private keys that had leaked online and found 474 of them still worked, giving access to 440 different apps. Forty-four of those apps had full admin rights over an organization, and 207 could change the code stored in repositories. One affected app was installed across roughly 300 organizations. Because these keys don't expire on their own, a file accidentally posted years ago can still be a live skeleton key today. If your business builds software, make sure your team audits and rotates these keys regularly rather than assuming old leaks have gone stale.
Stay ahead of threats with GOCO Security at gocosecurity.com.
.jpg)
Comments
Post a Comment