This week in cyber threats: unauthorized token spending hits Claude Max subscribers, hackers use invisible Unicode to dodge phishing filters, a network of 119,000 fake online stores is stealing credit cards, and there's a backdoor in the Skullcandy Dime 3 earbuds.
Claude Max Users Lose Token Limits Without Warning
Subscribers with premium Claude accounts are reporting their token limits being drained—sometimes with zero activity on their end. Hackers are burning through Claude Max users' token quotas without permission.
Invisible Unicode Characters Slip Past Phishing Filters
Attackers are sneaking invisible Unicode characters into their messages to get around anti-phishing filters, making it tough for automated systems to spot malicious emails.
119,000 Fake Online Stores Stealing Card Data
A massive network of 119,000 fake e-commerce sites has been set up to steal credit card info. The scale of this scam is a reminder of the risk shoppers face every time they pay online.
Skullcandy Dime 3 Backdoor Hijacks Audio
The Skullcandy Dime 3 earbuds have been found to contain a backdoor that can intercept audio. This means users could be at risk of unauthorized access to their audio streams and a serious privacy breach.
