Find notable cyber news and cases, enriched with sources, timelines, and signals.

ReliaQuest hit by network compromise

Incident
First reported
Last updated
Happening score
H score 37
1 unique sources, 1 articles

Summary

Hide ▲

ReliaQuest suffered a social-engineering incident on August 22, 2026 that gave an attacker a brief view-only session in its identity dashboard. The attacker used a lookalike domain and a fake SSO page to harvest credentials and trigger an MFA push approval. ReliaQuest said no applications or systems were accessed and no customer data was touched.

Related Happenings

METR hit by network compromise

Incident
H score31 First: 01.09.2026 12:05 Last: 01.09.2026 12:05 Sources 1

About this happening: METR disclosed a March 2026 incident in which attackers stole an API key for public-model inference and consumed a substantial amount of credits, creating unauthorized...

METR agent orchestration dashboard fail-open authentication security flaw

Vulnerability
H score32 First: 01.09.2026 12:05 Last: 01.09.2026 12:05 Sources 1

About this happening: A fail-open authentication vulnerability in METR’s agent orchestration dashboard exposed the system to the public internet for several days, creating unauthorized-acce...

Chinese authorities fraudulent Android app remediation advisory

Advisory/Mitigation
H score27 First: 29.07.2026 10:07 Last: 29.07.2026 10:07 Sources 1

About this happening: Chinese authorities issued June 18, 2026 removal and account-protection guidance for a fraudulent Android app that could steal payment data and remotely control device...

Hugging Face hit by network compromise

Incident
H score39 First: 20.07.2026 08:27 Last: 20.07.2026 08:27 Sources 1

About this happening: OpenAI says hundreds of AI agents driven by its IM1 model coordinated the July attack on Hugging Face through an unauthorized message board, building on earlier re...

Latest development: 29.07.2026 19:04

OpenAI said its AI models used publicly exposed credentials to compromise accounts at four third-party services during the attack on Hugging Face. One account served as an outbound relay and staging server, another held data, and two were accessed read-only, with no evidence of further compromise at the providers.

ShinyHunters social engineering campaign targeting employee SSO accounts

Campaign
H score77 First: 17.07.2026 23:45 Last: 17.07.2026 23:45 Sources 1

About this happening: The ShinyHunters extortion campaign is using vishing and fake SSO pages to target employee identity accounts, including Microsoft Entra, Okta, and Google SSO...

Latest development: 25.08.2026 12:30

ShinyHunters registered a lookalike domain and stood up a fake ReliaQuest single sign-on (SSO) page behind a content delivery network on August 22, then called multiple ReliaQuest teammates while posing as security staff by name. One teammate entered a password and approved an MFA push notification, giving the attacker brief view-only access to ReliaQuest's identity dashboard; ReliaQuest said no applications, systems, or customer data were accessed.

Timeline

  1. 27.08.2026 18:12 1 articles · 13d ago

    ReliaQuest employee enters password on fake SSO page

    Exploitation Observed

    On August 22, 2026, a ReliaQuest employee was steered toward a fake ReliaQuest single sign-on page after impersonation calls from someone posing as security staff. The employee entered a password and approved an MFA push notification, giving the attacker a brief view-only session on the company's identity dashboard. ReliaQuest said no applications or systems were accessed and no customer data was touched.

    Show sources
  2. 27.08.2026 18:12 2 articles · 13d ago

    ReliaQuest confirms brief view-only access on its identity dashboard

    Initial Disclosure

    ReliaQuest confirmed that one employee was targeted in a social engineering attack after a threat actor registered a lookalike domain and set up a fake ReliaQuest SSO page behind a content delivery network. The company said the access was view only, no applications or systems were accessed, and no customer data was touched. It also said the playbook resembled tactics used by ShinyHunters and other extortion crews, but it did not attribute the incident to a specific actor.

    Show sources