WhatsApp Usernames: A Privacy Win That Opens a New Impersonation Surface
WhatsApp usernames reduce phone-number exposure, but they also create a new global namespace where brands, public bodies, and lookalike handles can become fraud infrastructure.
8 articles
WhatsApp usernames reduce phone-number exposure, but they also create a new global namespace where brands, public bodies, and lookalike handles can become fraud infrastructure.
A June 2026 password spray from LSHIY LLC's IPv6 range compromised 78 Microsoft accounts across 64 organizations by abusing Azure CLI ROPC sign-ins that MFA policies did not cover.
Attackers no longer need malware on every endpoint. With one valid identity, token, or integration, they can move through Microsoft 365, Google Workspace, Salesforce, Slack, GitHub, and other SaaS platforms like an internal network.
Attackers do not always need your password. A single OAuth consent grant can give a malicious or compromised app durable access to mail, files, calendars, and SaaS data.
Adversary-in-the-Middle phishing silently proxies real login pages and steals session tokens — making MFA useless. Here's how it works and how to detect it.
How attackers escalate from a low-privilege AWS IAM credential to full S3 data theft — and the CloudTrail events, GuardDuty findings, and Sigma rules that expose them.
Service accounts, API keys, OAuth tokens and machine credentials now outnumber human identities 144 to 1. Most organizations have zero visibility into them. Attackers do.
How passkeys and FIDO2 work, why they defeat phishing and credential stuffing, and how attackers are already adapting with downgrade attacks and fallback abuse.