Cybersecurity Roundup: Claude Max token theft, Skullcandy backdoor, and more
This week's cybersecurity report highlights several incidents, including unauthorized token usage on Claude Max accounts, the use of invisible Unicode characters to bypass phishing filters, and a network of 119,000 fake online stores targeting credit card data. Additionally, a backdoor was discovered in Skullcandy Dime 3 headphones capable of intercepting audio. Regarding the Claude Max incident, users reported unauthorized token depletion. Anthropic investigated and found that a compromised session key was used to issue unauthorized OAuth tokens, likely by a third-party service. The company has since revoked sessions and provided partial refunds to affected users.
Summaries are written by AI from the original article. Not investment advice.