Skip to content
Hmmnm brand header logo displayed prominently across the top of the webpage
  • Home
  • Blog
  • About Us
  • Contact
  • Toggle website search
Press Escape to close the search panel.
Menu Close
  • Home
  • Blog
  • About Us
  • Contact
  • Toggle website search
Search this website

Identity & Phishing

  1. Home>
  2. Blog>
  3. Security>
  4. Identity & Phishing>
  5. Page 5
Read more about the article LastPass 2022: The Dev-Environment Breach That Came Back

LastPass 2022: The Dev-Environment Breach That Came Back

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Identity & Phishing/Security

August’s ‘contained’ developer-account compromise returned in December as stolen vault backups. Inside the two-act breach.

Continue ReadingLastPass 2022: The Dev-Environment Breach That Came Back
Read more about the article Plex’s 15M Credential Leak: When Your Forum Post Becomes a Combo List

Plex’s 15M Credential Leak: When Your Forum Post Becomes a Combo List

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Identity & Phishing/Security

A forums database with bcrypt hashes and salts hit a criminal forum. The real blast radius was everywhere else users reused passwords.

Continue ReadingPlex’s 15M Credential Leak: When Your Forum Post Becomes a Combo List
Read more about the article Solana’s 9,000-Wallet Drain: Who Logged the Seed Phrases?

Solana’s 9,000-Wallet Drain: Who Logged the Seed Phrases?

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cryptography & PKI/Identity & Phishing/Security

Slope’s telemetry backend held plaintext seed phrases, and attackers harvested them. The chain saw only valid signatures — and that is the whole lesson.

Continue ReadingSolana’s 9,000-Wallet Drain: Who Logged the Seed Phrases?
Read more about the article 0ktapus: The SMS Phishing Wave That Hit 130+ Companies

0ktapus: The SMS Phishing Wave That Hit 130+ Companies

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:AI & Agent Security/Identity & Phishing/Security

Fake Okta pages, real-time MFA relay, and one crew harvesting 10,000 identities. Why Cloudflare walked away clean and Twilio didn’t.

Continue Reading0ktapus: The SMS Phishing Wave That Hit 130+ Companies
Read more about the article Twitter’s 5.4M Scrape: When an API Becomes a Breach Oracle

Twitter’s 5.4M Scrape: When an API Becomes a Breach Oracle

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Identity & Phishing/Security/Web & API Security

A patched OAuth endpoint answered one question too honestly: which phone belongs to which handle. The dataset sold for $30k — the class lesson is still with us.

Continue ReadingTwitter’s 5.4M Scrape: When an API Becomes a Breach Oracle
Read more about the article Your Phone Is a Beacon: BLE Location Tracking Goes Mainstream

Your Phone Is a Beacon: BLE Location Tracking Goes Mainstream

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Identity & Phishing/Security

Rotating MAC addresses were supposed to make Bluetooth anonymous. May 2022’s synthesis of research, stalker hardware, and detection tools proved they never did.

Continue ReadingYour Phone Is a Beacon: BLE Location Tracking Goes Mainstream
Read more about the article Heroku Held the Keys: Anatomy of a Vendor-Token Breach

Heroku Held the Keys: Anatomy of a Vendor-Token Breach

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Identity & Phishing/Security/Supply Chain Security

GitHub’s OAuth tokens lived in Heroku’s infrastructure. One compromised CI cache later, an ecosystem learned where vendor tokens really live.

Continue ReadingHeroku Held the Keys: Anatomy of a Vendor-Token Breach
Read more about the article GitHub’s OAuth supply chain: the Heroku Token Heist That Reached npm

GitHub’s OAuth supply chain: the Heroku Token Heist That Reached npm

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Identity & Phishing/Security/Supply Chain Security

Attackers stole GitHub integration tokens from Heroku and Travis CI, pivoted into npm, and downloaded ~109,000 publishing credentials.

Continue ReadingGitHub’s OAuth supply chain: the Heroku Token Heist That Reached npm
Read more about the article Lapsus$ vs Microsoft: When Teen Hackers Beat a Hyperscaler’s Odds

Lapsus$ vs Microsoft: When Teen Hackers Beat a Hyperscaler’s Odds

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Identity & Phishing/Security/Supply Chain Security

37GB claimed, one account compromised, no customer data lost — and a DEV-0536 profile that taught the industry how social engineering beats MFA.

Continue ReadingLapsus$ vs Microsoft: When Teen Hackers Beat a Hyperscaler’s Odds
Read more about the article Okta’s Weak Link: When Your IdP’s Vendor Gets Pwned

Okta’s Weak Link: When Your IdP’s Vendor Gets Pwned

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Identity & Phishing/Security/Supply Chain Security

One contractor’s stolen credentials reached super-admin support tooling across 366 Okta tenants. The identity supply chain’s hardest lesson.

Continue ReadingOkta’s Weak Link: When Your IdP’s Vendor Gets Pwned
Read more about the article OpenSea’s $1.7M Phish: The Signature Trap

OpenSea’s $1.7M Phish: The Signature Trap

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cryptography & PKI/Identity & Phishing/Security

Seventeen users, one fake migration flow, and $1.7M in Apes gone — the phishing heist that made signature UX a security discipline.

Continue ReadingOpenSea’s $1.7M Phish: The Signature Trap
Read more about the article Lapsus$ Rising: Identity-Driven Extortion’s Breakout

Lapsus$ Rising: Identity-Driven Extortion’s Breakout

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Identity & Phishing/Security/Supply Chain Security

No zero-days, no malware — just MFA fatigue, SIM swaps, and help-desk social engineering. How Lapsus$ broke every assumption.

Continue ReadingLapsus$ Rising: Identity-Driven Extortion’s Breakout
  • Go to the previous page
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • Go to the next page
Press Escape to close the search panel.

Categories

  • AI Security (1)
  • Aviation and Aerospace Security (9)
  • Beyond Security (2)
  • Security (357)
  • Technology (63)

Recent Posts

  • Alert Fatigue Is a Design Problem: Building a Detection Engineering Lifecycle That Survives Contact
  • Write Sigma Rules That Actually Fire: A Detection-as-Code Lab with SigmaCLI and splunk-react
  • Why Planes Don’t Get Hacked — And Where the Next Aviation Cyber Risk Really Is
  • What Is Prompt Injection and How to Prevent It: A Complete Exam Prep Guide
  • Pyramid of Pain to Production: How Detection Engineers Prioritize What to Hunt
  • Build a Free Elastic Security SOC: Ingest Sysmon, Create Dashboards and Triage Alerts
  • Testing JWT Security with jwt-cli and Caido: Alg Confusion, Weak Secrets, and Expired Claims
  • Weekly Threat Intel: 30 September 2026 — npm Malware, Typosquat Waves and Autumn CVEs
  • Evilginx3 Lab: Build a Safe AiTM Phishing Lab to Understand Session Cookie Theft (and Why FIDO2 Stops It)
  • MFA Fatigue and Push Bombing: How Attackers Wear Down Your Users
  • Shodan and Censys for Attack Surface Recon: A Hands-On OSINT Lab with Ethics Guardrails
  • Weekly Threat Intel: 27 September 2026 — Agentic Supply Chain Abuse and CVE Trades
  • Abusing GraphQL Introspection and Batching: A Hands-On API Attack Lab with Defenses
  • SQLite Runs the World: Inside the Most Deployed Database Ever
  • SSRF Lab: Exploit and Block Server-Side Request Forgery with Real Targets and Defenses

Archives

  • October 2026 (8)
  • September 2026 (272)
  • August 2026 (98)

Newsletter

Get all latest content delivered to your email a few times a month. Updates and news about all categories will send to you.
Email is required Email is not valid
This field is required
Thanks for your subscription.
Failed to subscribe, please contact admin.
Hmmnm

Our Other Sites

  • Hmmnm.in
  • Odia.hmmnm.in

Quick Links

  • Security Services
  • Learning Paths
  • About Us
  • Contact
  • Blog
  • Privacy Policy
  • Disclaimer
  • Security Products
  • Terms of Service

Contact Info

  • 📧 contact@hmmnm.com
  • 🌐 hmmnm.com
in
© 2026 @Hmmnm

We use cookies to understand how the site is used and to improve your experience. You can accept analytics cookies or continue with essential cookies only. Privacy Policy

  • Home
  • Blog
  • Security
  • Experience
  • About Us
  • Services
  • Contact