LIVE · cybersecurity feed
Live wire
Cisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEV
breach

98% of fraudulent hires have company credentials by the time they’re caught

A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. “Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic credentials directly from IT,” said Bojan Simic, CEO of HYPR. “Human intuition is not a security control. Sceptics might po

zeroday.news ·

A new report from HYPR indicates that 98% of fraudulent hires obtain company credentials before their deception is detected. This finding highlights a significant vulnerability in enterprise identity security, particularly a "blind spot" during the 90-day period between hiring and onboarding.

The report suggests that adversaries are increasingly bypassing traditional network breaches by successfully navigating remote interviews and receiving legitimate credentials directly from IT departments. This method allows fraudulent individuals to gain internal network access before their true identities are discovered.

While 98% of HR leaders surveyed reported direct experience with candidate fraud, 96% expressed confidence in their organization's ability to detect it. This discrepancy points to a potential overestimation of current defense capabilities. Detection often occurs through fragmented checkpoints such as screenings, interviews, onboarding, active employment, and technical assessments, averaging 2.2 detection points per incident. This fragmented approach suggests a lack of a consistent, primary barrier against fraud.

Identity verification tools are frequently limited to specific events like account creation, sensitive transactions, or account recovery. Outside these defined checks, fraudulent hires can remain undetected, leaving organizations reliant on manual processes and employee vigilance to identify suspicious behavior. Although recruitment platforms and applicant tracking systems are beginning to integrate identity verification and anti-fraud features, particularly targeting AI-generated candidates and synthetic agents during application and screening stages, third-party security tools only detect 53% of identity-based and AI-driven attacks. The remaining cases are discovered manually through employee reports, internal audits, or external alerts.

A notable "confidence gap" was observed among leaders responsible for identity and hiring technology, who generally expressed less assurance in their organizations' fraud detection capabilities. The IT and telecommunications sector, despite being the most technically equipped, reported a higher reliance on manual observation than any other group. Education showed the largest disparity between concern about hiring fraud and confidence in existing defenses. Conversely, manufacturing and utilities reported high levels of both concern and confidence, which HYPR attributes to their prevalence of in-person hiring and face-to-face identity checks. Sales, media, and marketing was the only sector where confidence exceeded concern, heavily depending on employees to identify and report suspected fraud.

The report also identifies an "identity risk handoff" problem. While HR typically manages recruitment and IT/security takes over once a new hire receives access, the period between these stages often lacks a clearly defined owner. Attackers exploit this transition to infiltrate organizations while responsibility is shifting between teams. This exposure can persist even after hiring, especially if fraud is only discovered after credentials have been issued.

Resolving a hiring fraud incident typically takes one to three weeks, incurring financial and operational costs through delayed hiring, backfilling, lost productivity, security exposure, compliance risks, and team disruption. In response to such incidents, companies have implemented an average of 2.52 actions, including identity verification technologies. However, investment in identity security tends to be reactive, with approximately 60% of identity verification and multi-factor authentication (MFA) spending being triggered by a security breach rather than proactive measures.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hardcoded MCP credentials found in public GitHub files

Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security Gaps report. The company analyzed around 82,000 configuration files and found that 12% of credential slots contained a hardcoded credential literal,

breach

Most WordPress pros still lack a breach recovery plan

Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The respondents build and run WordPress sites for a living: agency staff, developers, designers, site owners and administrators. Across the whole group, fewer than three in ten have a breach recovery plan. A recovery plan settles in advance

ai

The End of Point-in-Time Compliance: Why Continuous Audit Readiness Matters to You in the AI Era

AI-driven threats are outpacing traditional audits. Discover how continuous monitoring, automated evidence collection, and risk-based remediation help security teams close compliance gaps and maintain audit readiness as environments change daily.

vulnerability

AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom

Plugin4Shell attack affects all the major coding agents, researchers say

malware

New RatHat Android malware uses AI to automate device control

A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. [...]

vulnerabilityhigh

Cisco alerts customers to second actively exploited zero-day in as many days

The latest zero-day has a maximum-severity rating and affects Cisco Identity Services Engine, a product hit with three actively exploited vulnerabilities since June 2025. The post Cisco alerts customers to second actively exploited zero-day in as many days appeared first on CyberScoop.