LIVE · cybersecurity feed
Live wire
CISA’s logging guidance works beyond governmentCISA orders urgent patching of actively exploited Zimbra flawZero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainHow an Emerging Industrial Protocol Family Could Put OT at Risk14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accounts
security

Doubloon Dredger Abuses Notion to Harvest Authentication Tokens

Doubloon Dredger abused Notion and malicious PDFs to harvest Microsoft authentication tokens

zeroday.news ·

A financially motivated threat actor, tracked as Doubloon Dredger, has been observed leveraging free Notion accounts, malicious PDFs, and device code phishing to compromise organizational accounts and harvest authentication tokens. The activity, identified in July 2026 by Sublime's Threat Intelligence & Research team, began after a customer reported Notion abuse, leading to the discovery of similar attacks against another organization.

The campaigns involve sending document-sharing notifications from legitimate Notion infrastructure using fake accounts that impersonate senior executives. These emails, generated through compromised Notion accounts, successfully pass DKIM, SPF, and DMARC checks, lending them an air of legitimacy.

Recipients who click on the notification are first directed to an intermediary PDF. Within this PDF, a "Review and Sign" button then redirects the victim to a device code harvesting page. This page is designed to mimic an Adobe Acrobat document-sharing authentication screen, providing a verification code and instructions to enter it on Microsoft's legitimate login or device code entry page. If the victim follows these instructions and enters the code, the attacker gains an authorization token, enabling access to the compromised account.

The phishing-as-a-service (PaaS) platform used for this, known as EvilTokens, has been available since at least February 2026, with access sold through a private Telegram channel. EvilTokens also offers MailVault, a webmail client that allows attackers to interact with compromised inboxes.

Sublime's research uncovered 14 additional PDFs with identical metadata and overlapping link structures. These PDFs contained multiple links overlaid on the same button, which could lead to different destinations depending on the PDF reader used. Researchers speculate this might serve as infrastructure redundancy or a method to complicate defensive analysis. These PDFs targeted organizations across various sectors, including manufacturing, telecommunications, retail, health, and logistics. Some samples from these campaigns linked to Kratos phishing pages instead of EvilTokens.

While Sublime could not definitively determine if the PDF builder was shared among different threat actors or exclusively used by Doubloon Dredger, similarities were noted between the campaign's first-stage JavaScript and activity associated with the Tycoon2FA device code harvesting platform. Analysis identified 603 related scripts, with 416 decoding to EvilTokens and 187 to Tycoon2FA. Researchers assess with moderate confidence that Doubloon Dredger is a customer of both PaaS platforms. This activity follows a global operation that disrupted Tycoon2FA months prior, though the platform quickly resumed operations.

Organizations are advised to disable device code authentication where feasible or to restrict device code token generation to trusted devices to mitigate such threats.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts

Dutch Data Protection Authority said it is imposing a fine of 825 million euros because Uber violated the EU’s General Data Protection Regulation. The post Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts appeared first on SecurityWeek.

patch

Microsoft: August updates break printing, PDF export in WPF apps

Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in WPF applications. [...]

security

Venezuelan Gets Record Federal Prison Term for ATM Jackpotting

Juan Manuel Gouveia-Aguilera has been sentenced to 8 years in prison for his role in an ATM jackpotting scheme that caused millions in losses. The post Venezuelan Gets Record Federal Prison Term for ATM Jackpotting appeared first on SecurityWeek.

securitycritical

CISA’s logging guidance works beyond government

The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you’ve collected to catch it and reconstruct what happened afterward? The Logging Reference Architecture (LRA), released in August 2026, is meant to help US federal civilian agencies meet the logging requir

vulnerabilityhigh

CISA orders urgent patching of actively exploited Zimbra flaw

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. [...]

nation-state

Criminal Deception in Silicon Valley

Interesting paper: Abstract: With entrepreneurial fraud cases on the rise, we investigate how entrepreneurs carry out criminal deception, employing deceptive means to defraud audiences. Analyzing court data from Silicon Valley ventures and their founders prosecuted for fraud between 2000 and 2023, our findings reveal that entrepreneurs carry out criminal deception through a process of façading: En