Every story tagged Account Security, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
138 stories · open in the command center
Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization.
Plane is an open-source project management tool. Prior to 1.4.0, a user whose account has been deactivated by setting is_active=False can still log in with existing credentials. Successful authentication silently changes is_active back to True, reactivating the account without notifying the administrator. This issue is fixed in 1.4.0.
This article highlights a gray market in China where resellers use harvested identities, prepaid/USDT-funded cards, and proxy networks to buy and resell Claude access, bypassing platform controls and geographic restrictions. For CIOs and technology leaders, the key implication is that AI services are becoming an identity-, payment-, and network-security problem as much as a software procurement issue, increasing exposure to fraud, policy violations, and supply-chain risk. IT organizations should assume that unauthorized AI access and account sharing can evade standard controls, so governance must extend to vendor verification, usage monitoring, and enforcement of regional and payment restrictions.
The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts.
The article argues that while browser-based password saving is convenient and reasonably well protected, it concentrates risk: if a device, browser profile, or synced account is compromised, attackers can harvest many credentials and session cookies at once. For CIOs and technology leaders, the strategic takeaway is to reduce credential blast radius by separating password storage from the browser, accelerating adoption of dedicated password managers, and prioritizing passkeys where supported to improve security and lower phishing exposure.
The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by the cookie rather than on the actual requester via `current_user_can()`, while the switch-back form and a valid session-bound nonce are emitted publicly via `wp_footer` to any visitor — including unauthenticated users — whenever that cookie is present. This makes it possible for unauthenticated attackers to set the `original_user_id` cookie to any administrator's user ID, collect the rendered nonce, and POST it back to the `revert_switch` handler, causing `wp_set_auth_cookie()` to be called with the administrator's ID and granting the attacker a full administrator-level authenticated sessio...
Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change. Attackers with a stolen session cookie can maintain access to user accounts even after the associated user changes their password.
Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user to submit content that, when later viewed by another user, executes arbitrary JavaScript in that user's authenticated session. This could be used to perform actions on the victim's behalf and may have permitted account takeover, including of higher-privileged users. Exploitation requires the victim to view the attacker-supplied content.
In Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4, an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC handler, silently downgrades the administrator password to the default value and corrupts the in-memory authentication state until the device reloads. The handler does not verify the session's privilege level, so any authenticated user can trigger it.
This article is a cautionary tale about the operational and legal risk of over-trusting automated decision systems: a false ALPR alert led to a driver being ticketed despite presenting valid proof of insurance. For CIOs and technology leaders, the business implication is clear—AI and automation tools used in high-stakes workflows need rigorous validation, human override paths, and auditability, or they can erode trust, increase liability, and create costly process failures.
The FBI’s reported breach of its job application portal underscores how legacy, internet-facing systems can expose highly sensitive employee data at scale, including SSNs and medical information. For CIOs and technology leaders, the strategic takeaway is that HR and recruiting platforms are now high-value targets that can create operational, legal, and reputational risk, while also enabling phishing, coercion, and broader insider-threat exposure. IT organizations should treat employee-facing systems as critical assets, with the same rigor applied to identity, segmentation, patching, and incident disclosure workflows.
This high-severity Froxlor vulnerability means that changing a user password does not fully revoke existing panel sessions, API keys, or trusted 2FA cookies, leaving previously authenticated access paths alive. For CIOs and technology leaders, the business risk is persistent unauthorized access to hosting/control-panel functions even after a credential reset, so IT teams should treat this as an urgent identity and access control gap with potential account takeover and compliance implications.
Froxlor 2.0.0 through 2.3.10 contains a high-severity stored cross-site scripting flaw that can be triggered by a low-privilege customer account, creating a path to session hijacking, credential theft, and unauthorized actions in the hosting control plane. For CIOs and technology leaders, this is a reminder that admin consoles and multi-tenant infrastructure tools are high-value targets; a compromise here can cascade across customers and services, so timely remediation and hardening are business-critical.
Old-school payment fraud is still a material business risk: even as AI amplifies phishing and digital scams, attackers continue to profit from physical credit card skimmers, forged replacement cards, and mail-based social engineering. For CIOs and technology leaders, the key implication is that legacy payment channels—especially magnetic stripe workflows and any customer-facing or benefits-related systems that still rely on them—remain a real exposure that can drive direct financial loss, operational disruption, and reputational damage. IT organizations should treat fraud prevention as a cross-channel control problem, combining endpoint inspection, terminal hardening, payment modernization, and user awareness across both digital and physical touchpoints.
This article highlights how voice-phishing operations are becoming more organized, scalable, and deceptive, even when the criminals themselves make mistakes. For CIOs and technology leaders, the business impact is clear: social engineering remains a top initial-access vector, especially for cloud environments, so IT organizations need stronger identity verification, layered access controls, and more realistic employee training to reduce the risk of account takeover and fraud.
North Korean fake IT worker schemes are becoming a material enterprise risk, enabling credential theft, malware placement, and long-term access through remote hiring pipelines and contractor relationships. For CIOs and technology leaders, the strategic implication is that hiring security is now part of cyber defense: IT, HR, legal, and security teams must jointly strengthen screening, identity verification, and device control to reduce the chance of a fraudulent worker gaining access to corporate systems. Organizations that rely on distributed technical talent should treat recruiting as an attack surface and add both human review and automated fraud detection to preserve productivity without opening the door to persistent insider-style threats.
Google’s new Credential Transfer API removes a major barrier to passkey adoption by making credentials portable between password managers on Android, reducing vendor lock-in and making it easier for employees and customers to move to stronger, phishing-resistant authentication. For IT leaders, this is strategically important because it lowers migration friction, strengthens the business case for passkeys over passwords, and gives organizations more flexibility in selecting or changing identity and credential management platforms. It also signals a maturing ecosystem where authentication strategy can be based more on security and user experience than on the risk of trapping credentials in one vendor’s vault.
A flaw in SourceHut’s build log rendering (ansi2html) allowed malicious ANSI/OSC sequences to become executable HTML/JavaScript, turning a routine log view into a path for account takeover and potentially broader platform compromise. For CIOs and technology leaders, the business risk is that CI/CD and developer tooling can become an attack surface for identity theft, unauthorized code access, and exposure of sensitive deploy keys; this underscores the need to treat log viewers and text-to-HTML converters as security-critical components in the software supply chain.
This article highlights a phishing technique that uses one carefully crafted URL to confuse different security tools: browsers, email filters, and URL scanners can each interpret it differently, allowing malicious links to slip past controls. For CIOs and technology leaders, the business risk is reduced effectiveness of layered defenses and increased likelihood of credential theft, which means IT organizations need stronger URL parsing, normalization, and detection logic across email, web, and security platforms.
Microsoft and partners disrupted EvilTokens, a phishing-as-a-service operation that used AI and device code phishing to compromise more than 12,000 inboxes across over 10,000 organizations worldwide, underscoring how quickly identity attacks can scale into broad business email compromise risk. For CIOs and IT leaders, the incident reinforces that Microsoft 365 and identity controls are a front-line business resilience issue: organizations need stronger phishing-resistant authentication, tighter session/token monitoring, and faster detection of anomalous inbox and Graph API activity to limit financial fraud and lateral exposure.
The article shows that attackers can bypass strong employee account defenses by exploiting forgotten Microsoft 365 service accounts, leading to rapid compromise of email, Teams, OneDrive, SharePoint, and even cloud admin portals. For CIOs and technology leaders, the strategic lesson is that identity security must extend beyond human users to include every nonhuman account, or a small set of overlooked credentials can become a major data-loss and operational-risk event. IT organizations should treat service-account governance as a core control domain, with clear ownership, least privilege, MFA, and continuous lifecycle management.
LinkedIn is introducing stronger verification and brand-control tools to counter the growing risk of fake profiles, impersonation, and bogus employment claims amplified by AI. For CIOs and technology leaders, this signals that professional identity verification is becoming a core trust layer for talent brand protection, recruiting integrity, and enterprise reputation management across digital platforms. IT organizations should expect tighter expectations around identity assurance, governance of employee-facing profiles, and integration with third-party verification ecosystems as authentication becomes a competitive and security requirement.
Microsoft disrupted an AI-assisted scam platform that compromised 12,000 accounts across 10,000 organizations, showing how attackers are using automation to scale email compromise and fraud faster than traditional defenses can react. The key strategic shift is that once an inbox is breached, AI can rapidly map relationships, identify payment authorities, and craft convincing follow-up lures—compressing attacker analysis from days to minutes and increasing business risk for finance, operations, and customer trust. For IT organizations, this elevates identity hardening, OAuth/device-code controls, and behavioral monitoring from technical hygiene to core business protection measures.
Google is testing an Android 17 feature that would let users recover access to a device with their linked Google account if they forget their PIN or password, potentially avoiding factory resets and the loss of unmanaged data. For CIOs and technology leaders, this could reduce user downtime and helpdesk friction while improving endpoint resilience, but it also raises identity assurance and policy-governance considerations that IT will need to evaluate before broad adoption. Because the capability is optional and disabled by default, it may become another controllable recovery path for enterprise Android fleets without weakening security if paired with strong account protections and approval workflows.
A reported flaw in Meta’s Muse Mac app could allow any local app or terminal command to access the authentication token for a user’s Muse account, creating a serious account-takeover and data-exposure risk. For CIOs and IT leaders, this underscores that AI assistants and productivity apps can introduce new identity and token-security vulnerabilities that bypass traditional perimeter controls, making endpoint hardening, app trust validation, and AI usage governance increasingly important. The business impact is potential leakage of sensitive prompts, outputs, and connected account data, along with reputational and compliance risk if such tools are deployed broadly without proper controls.
Amazon’s blocking of Meta’s Muse AI agent underscores a growing conflict between agentic AI tools and digital platform owners over access, identity, privacy, and control of customer interactions. For businesses, this can disrupt automated commerce experiences and create legal, security, and partnership risks as vendors increasingly restrict unsanctioned AI traffic. CIOs and IT leaders should expect tighter platform defenses and should treat third-party AI agents as a governance issue requiring clear approval, authentication, and data-handling standards.
Polymarket’s reported handling of a $10M+ fraud and money-laundering attempt highlights how rapidly growing digital platforms can face material financial, compliance, and reputational risk if controls do not keep pace with product growth. For CIOs and technology leaders, the story underscores the need for stronger identity verification, transaction monitoring, fraud detection, and governance as companies prepare for scale, regulatory scrutiny, and potential public-market readiness.
Dashlane’s new Vault Enforcement feature highlights a persistent enterprise security problem: password tools and passkeys are only effective if employees actually use them, and many organizations still face an adoption gap after initial rollout. By allowing IT to require vault-based logins on specific domains through policy-managed browser extensions, the feature shifts credential protection from optional training to enforceable control—an important move for reducing shadow password use across the many apps that still fall outside SSO coverage. For CIOs and technology leaders, the strategic takeaway is that identity security must be designed around user behavior and operational enforcement, not just education and tooling availability.
Security researchers demonstrated that AI tools can materially accelerate offensive security work, using Claude to compromise OpenAI employee accounts through a third-party forum vulnerability and reach internal systems tied to sensitive code repositories. For CIOs and technology leaders, the key implication is that enterprise risk now extends beyond core applications to the entire digital ecosystem, including SaaS providers, content-processing pipelines, and AI-enabled attack workflows that can turn low-cost tooling into high-impact breaches. IT organizations should expect faster, more scalable exploitation attempts and respond with stronger third-party risk management, tighter identity/access controls, and more rigorous monitoring of externally hosted collaboration platforms.
A security research team used Anthropic’s Claude tooling to breach an OpenAI employee account, exposing internal code and underscoring how AI platforms, third-party services, and identity controls can become high-value attack paths. For CIOs and technology leaders, the incident reinforces that AI adoption expands the enterprise threat surface and that governance, access management, and supply-chain security must be built into AI programs from the start. The article also highlights a broader strategic shift: AI is increasingly being used to build AI, which raises both productivity potential and oversight risks for IT organizations.