⤷ Title: Account Takeover Attacks: The Most Popular Sport in Cybercrime
════════════════════════
𐀪 Author: Wes Young
════════════════════════
ⴵ Time: Tue, 11 Feb 2025 14:28:15 GMT
════════════════════════
⌗ Tags: #phishing #threat_intelligence #ato #cybersecurity #alpha_hunt
════════════════════════
𐀪 Author: Wes Young
════════════════════════
ⴵ Time: Tue, 11 Feb 2025 14:28:15 GMT
════════════════════════
⌗ Tags: #phishing #threat_intelligence #ato #cybersecurity #alpha_hunt
Medium
🥷 Account Takeover Attacks: The Most Popular Sport in Cybercrime 🎾
When you think ATOs, think of threat actors running a well-oiled operation — only in finance, retail, and tech, they play by different…
⤷ Title: Day 16: Massive Users Account Takeovers (Chaining Vulnerabilities to IDOR)
════════════════════════
𐀪 Author: dani3l
════════════════════════
ⴵ Time: Fri, 21 Feb 2025 16:52:41 GMT
════════════════════════
⌗ Tags: #ethical_hacking #pen_testing_tool #bug_bounty #ato
════════════════════════
𐀪 Author: dani3l
════════════════════════
ⴵ Time: Fri, 21 Feb 2025 16:52:41 GMT
════════════════════════
⌗ Tags: #ethical_hacking #pen_testing_tool #bug_bounty #ato
Medium
Day 16: Massive Users Account Takeovers (Chaining Vulnerabilities to IDOR)
By Anurag Verma
⤷ Title: Day 17: [$5K] Misconfigured Reset Password Leads to Account Takeover (No User Interaction ATO)
════════════════════════
𐀪 Author: dani3l
════════════════════════
ⴵ Time: Sat, 22 Feb 2025 18:06:02 GMT
════════════════════════
⌗ Tags: #account_takeover #ato #bug_bounty
════════════════════════
𐀪 Author: dani3l
════════════════════════
ⴵ Time: Sat, 22 Feb 2025 18:06:02 GMT
════════════════════════
⌗ Tags: #account_takeover #ato #bug_bounty
Medium
Day 17: [$5K] Misconfigured Reset Password Leads to Account Takeover (No User Interaction ATO)
By Aditya Sharma
Published on Aug 24, 2021–4 min read
Published on Aug 24, 2021–4 min read
⤷ Title: Day 18: How a Researcher Hacked One of the Biggest Airlines Group in the World
════════════════════════
𐀪 Author: dani3l
════════════════════════
ⴵ Time: Sun, 23 Feb 2025 17:39:05 GMT
════════════════════════
⌗ Tags: #ethical_hacking #account_takeover #ato #bug_bounty
════════════════════════
𐀪 Author: dani3l
════════════════════════
ⴵ Time: Sun, 23 Feb 2025 17:39:05 GMT
════════════════════════
⌗ Tags: #ethical_hacking #account_takeover #ato #bug_bounty
Medium
Day 18: How a Researcher Hacked One of the Biggest Airlines Group in the World
About a year ago, when the researcher started exploring HackerOne, they discovered one of the most impactful bugs ever. they received a…
⤷ Title: Legacy SDK Flaws Cause Stored XSS and Account Takeover (ATO)
════════════════════════
𐀪 Author: MindPatch
════════════════════════
ⴵ Time: Fri, 14 Mar 2025 00:54:48 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #pentesting #ato #xss_attack
════════════════════════
𐀪 Author: MindPatch
════════════════════════
ⴵ Time: Fri, 14 Mar 2025 00:54:48 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #pentesting #ato #xss_attack
Medium
Legacy SDK Flaws Cause Stored XSS and Account Takeover (ATO)
Before we dive in, let’s quickly mention that I know writing Medium articles about XSS are common and cringy, but this one has something…
⤷ Title: The story of XSS that leads to ATO
════════════════════════
𐀪 Author: SahandAmi
════════════════════════
ⴵ Time: Mon, 24 Mar 2025 10:59:09 GMT
════════════════════════
⌗ Tags: #ato #account_takeover #csrf_token #bug_bounty #xs
════════════════════════
𐀪 Author: SahandAmi
════════════════════════
ⴵ Time: Mon, 24 Mar 2025 10:59:09 GMT
════════════════════════
⌗ Tags: #ato #account_takeover #csrf_token #bug_bounty #xs
Medium
The story of XSS that leads to ATO
One day, while reviewing the output of my recon machine (which uses various techniques to collect subdomains), I found a subdomain that…
⤷ Title: Day 29 — CSRF Bypass Using Domain Confusion Leads To Account Takeover (ATO)
════════════════════════
𐀪 Author: dani3l
════════════════════════
ⴵ Time: Sat, 05 Apr 2025 09:48:00 GMT
════════════════════════
⌗ Tags: #bug_bounty #ato #account_takeover #cybersecurity
════════════════════════
𐀪 Author: dani3l
════════════════════════
ⴵ Time: Sat, 05 Apr 2025 09:48:00 GMT
════════════════════════
⌗ Tags: #bug_bounty #ato #account_takeover #cybersecurity
Medium
Day 29 — CSRF Bypass Using Domain Confusion Leads To Account Takeover (ATO)
Part of my #100DaysOfATO Challenge Original Finding: Osama Aly (@w4lT3R) Reward: $4000
⤷ Title: Bug Bounty | Istifadəçi hesablarının oğurlanmasına səbəb ola biləcək bir boşluq tapdım (Account…
════════════════════════
𐀪 Author: Zeynalxan Quliyev
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 12:04:41 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty #ato #account_takeover #hacker
════════════════════════
𐀪 Author: Zeynalxan Quliyev
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 12:04:41 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty #ato #account_takeover #hacker
Medium
Bug Bounty | Istifadəçi hesablarının oğurlanmasına səbəb ola biləcək bir boşluq tapdım (Account…
Ağıllı ev platformasında login boşluğu tapdım. Bu boşluq hesabların ələ keçirilməsinə yol aça bilər. Texniki analiz və təhlükənin izahı yazıda.
⤷ Title: Sensitive Data Exposure + Public Recon = Instant Account Takeover
════════════════════════
𐀪 Author: Aya Ayman(GERR4Y)
════════════════════════
ⴵ Time: Tue, 22 Apr 2025 16:20:58 GMT
════════════════════════
⌗ Tags: #bug_bounty #ato #osint
════════════════════════
𐀪 Author: Aya Ayman(GERR4Y)
════════════════════════
ⴵ Time: Tue, 22 Apr 2025 16:20:58 GMT
════════════════════════
⌗ Tags: #bug_bounty #ato #osint
Medium
Sensitive Data Exposure + Public Recon = Instant Account Takeover🔻
“بسم الله و الصلاة و السلام على رسول الله الحمد لله الذي علم بالقلم علم الإنسان ما لم يعلم و الصلاة و السلام على خير معلم الناس الخير محمد”
⤷ Title: TeamFiltration Weaponized: UNK_SneakyStrike Campaign Targets 80,000+ Microsoft Entra ID Accounts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:30:01 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #ATO #AWS #cyberattack #cybersecurity #Microsoft 365 #Microsoft Entra ID #OAuth #Password Spraying #Proofpoint #TeamFiltration
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:30:01 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #ATO #AWS #cyberattack #cybersecurity #Microsoft 365 #Microsoft Entra ID #OAuth #Password Spraying #Proofpoint #TeamFiltration
Daily CyberSecurity
TeamFiltration Weaponized: UNK_SneakyStrike Campaign Targets 80,000+ Microsoft Entra ID Accounts
TeamFiltration is being actively exploited in UNK_SneakyStrike, targeting over 80,000 Microsoft Entra ID accounts with password spraying and data exfiltration.
⤷ Title: CVE-2025–56676 | Critical Vulnerability in Zender Gateway Allows Account Takeover
════════════════════════
𐀪 Author: DarkLotus
════════════════════════
ⴵ Time: Sat, 27 Sep 2025 03:42:36 GMT
════════════════════════
⌗ Tags: #bug_bounty #cve #cwe_639 #ato #cve_2025
════════════════════════
𐀪 Author: DarkLotus
════════════════════════
ⴵ Time: Sat, 27 Sep 2025 03:42:36 GMT
════════════════════════
⌗ Tags: #bug_bounty #cve #cwe_639 #ato #cve_2025
Medium
CVE-2025–56676 | Critical Vulnerability in Zender Gateway Allows Account Takeover
Summary