Phishing Attacks Using Passkeys, Anthropic’s Major Report, Airline Cybersecurity Vulnerabilities

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.
https://www.linkedin.com/embeds/publishingEmbed.html?articleId=8006072531196306549

Today on CISO Series…

https://www.linkedin.com/embeds/publishingEmbed.html?articleId=7001590132939224183

In today’s cybersecurity news…

Attackers exploit passkey phishing to commandeer Microsoft cloud accounts

Microsoft characterizes this nefarious tactic, witnessed since May 2026, as rooted in identity-targeted social engineering.

“The perpetrators call or message a user’s personal device, masquerading as the organization’s IT help desk, and pressure them to promptly update their passkey, multi-factor authentication (MFA), or single sign-on (SSO) settings to avert access interruptions.”

Victims are directed to fraudulent sites imitating the authentic Microsoft sign-in process via SMS messages dispatched to their mobile phones.

Microsoft highlighted that these malicious actors conduct meticulous reconnaissance, amassing insights regarding personnel and organizational frameworks from publicly accessible sources, including social and professional networking platforms.

In some cases, they even engage with victims through Microsoft Teams and have registered convincingly legitimate domains incorporating the company’s name.

Anthropic identifies Russia-linked operatives harnessing Claude for cyber incursions

In a revealing threat assessment detailing activities between December 2025 and August 2026, Anthropic announced it “detected and thwarted a Russia-linked cyber-espionage faction that leveraged its AI tool Claude in a hacking expedition targeting over 20 governmental, intelligence, diplomatic, and defense agencies.”

Anthropic disclosed that this activity was consistent with that of Midnight Blizzard, formerly recognized as Cozy Bear, a group attributed to the Russian Foreign Intelligence Service (SVR).

In a particular case, the group “focused on members of the Ukrainian government, military, and diplomatic personnel as well as organizations involved in the drone supply network.

They successfully purloined an entire proprietary software development kit for a drone vision system, subsequently using Claude to reverse-engineer the drone’s vision architecture, recovering its product design, hardware bill of materials, supplier dependencies, and details of an undisclosed product.”

ShinyHunters exploited Claude to extract sensitive data from 1.8 million Android applications

This same Anthropic threat assessment also divulged operations coordinated by the ShinyHunters collective, which involved a credential-harvesting pipeline utilizing ten Amazon Web Services (AWS) EC2 nodes that “downloaded from various repositories and subsequently scanned for secrets across 1.8 million Android APKs. ..

The same perpetrators deployed a distinct automated mechanism to compile GitHub organizational email addresses and utilized them to acquire GitHub Personal Access Tokens (PATs).”

One of these initiatives enabled the offenders to impersonate the French national police to market purloined payment-card information, complete cardholder details, and an interactive interface mapping victim addresses.

A link to this extensive report, which encompasses numerous other narratives and revelations, is referenced in the show notes for this episode.

Airlines’ adherence to new cybersecurity mandates means diminished passenger comforts

Commencing next month, airlines whose flights face cancellations or delays attributable to a cyber intrusion will no longer be obliged to provide meal vouchers or accommodation to affected passengers.

This change follows a recent directive from the Transportation Department that introduces a new “cause of delay” category, thereby alleviating air carriers from liability for 10 specific types of events, including: “cybersecurity attacks (assuming the air carrier complies with applicable cybersecurity regulations).”

Dutch authorities alert to imminent Check Point VPN vulnerabilities

The Dutch National Cyber Security Centrum (NCSC) issued a caution regarding two critical vulnerabilities in Check Point VPN, identified as CVE-2026-85102 and CVE-2026-85103.

While no public proof-of-concept exploit has been disclosed, the agency warns of the high likelihood of exploitation and potentially severe consequences.

Check Point VPN serves as an enterprise solution, enabling remote employees to securely access their company’s internal networks through encrypted channels.

Florida officials link motor vehicle data breach to officer’s personal device

In a brief follow-up to a previous story we reported on Wednesday, Florida officials now indicate that the data breach affecting the state Department of Motor Vehicles resulted from the ShinyHunters extortion group acquiring login credentials from a police officer who had stored this sensitive information on a personal device.

Conti malware developer sentenced to four years for ransomware offenses

In a continuation of a narrative we have been monitoring for several months, former attorney-turned-malware developer Oleksii Oleksiyovych Lytvynenko received a four-year prison sentence this week for conspiracy to engage in wire fraud.

His involvement with the Conti gang led to the infection of over 1,000 organizations globally between 2020 and 2022, resulting in victim payouts exceeding $150 million prior to the cessation of the operation.

CISA incorporates five actively exploited flaws into KEV

The five security vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS have been officially added to the Known Exploited Vulnerabilities (KEV) catalog, following evidence of active exploitation.

A glass wall with a red CISA logo in front of server racks in a data center.

Federal Civilian Executive Branch (FCEB) agencies were mandated to rectify the RouterOS vulnerabilities by the deadline of yesterday, September 13, 2026, with the ScreenConnect flaw slated for correction by September 14, 2026, and the Artifactory vulnerabilities by September 25, 2026.

A link providing a summary of these five vulnerabilities and their corresponding CVE identifiers is included in the show notes of this episode.

Source link: Linkedin.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Neil Hemmings

I'm Neil Hemmings from Anaheim, CA, with an Associate of Science in Computer Science from Diablo Valley College. As Senior Tech Associate and Content Manager at RS Web Solutions, I write about AI, gadgets, cybersecurity, and apps – sharing hands-on reviews, tutorials, and practical tech insights.
Share the Love
Related News Worth Reading