Huff Data Systems

Huff Data Systems Business Cybersecurity and Managed IT Services. Helping Businesses Reduce RISK with Cybersecurity. IT that works for you..

Follow for the latest Business Cybersecurity News, Tips and Updates. Started in 2001, ComputerMan Group is a complete technology solution provider. We are 100% committed to making sure business owners have the most reliable and professional IT service in Victoria, TX. Our team of talented IT professionals can solve your IT nightmares once and for all.

09/05/2026

Attackers Can Gain Access Without Stealing Your Password — And MFA May Not Stop Them

The FBI issued a new cybersecurity warning this week about a growing technique called OAuth Consent Phishing.

This attack is important for every business using cloud services such as Microsoft 365 or Google Workspace.

Doing a another post on this to break down how this works in plain terms.

Here’s what makes it different:

An attacker sends a convincing email, text, or message containing a link to what appears to be a legitimate application or service.

The victim may even be taken to a real Microsoft or Google login page.

They successfully authenticate.

MFA works.

But then comes the dangerous part:

“Allow this application to access your account?”

If the user clicks Allow, they may unknowingly authorize a malicious application to access their email, files, and other company data.

The attacker doesn’t necessarily need the user’s password.

They don’t necessarily need to defeat MFA.

Instead, the user has authorized the attacker’s application.

Even worse, simply changing the user’s password may not remove the attacker’s access because the malicious application can retain an authorization token. The application and its permissions must be identified and revoked.

This is why cybersecurity can no longer rely on:

❌ Strong passwords alone
❌ MFA alone
❌ Antivirus alone
❌ Employee awareness alone

Businesses need layers of protection that include identity monitoring, application controls, OAuth permission management, conditional access, endpoint security, and continuous monitoring.

One of the most important lessons from this FBI warning:

A successful login does not necessarily mean a secure login.

Cybersecurity has moved beyond protecting passwords. Businesses must now protect identities, applications, devices, permissions, and access tokens.

Source: FBI Internet Crime Complaint Center (IC3), September 1, 2026.



Read more:

https://www.ic3.gov/PSA/2026/PSA260901?

09/04/2026

⚠️Cyber criminals are impersonating government officials, media, and other publicly known personalities on a commercial messaging application and soliciting the targeted individual to access a malicious link.

Learn more about this phishing attempt and how to avoid becoming a victim: https://www.ic3.gov/PSA/2026/PSA260901

08/29/2026

We are aware that scammers are spoofing City of Victoria phone numbers to conceal their identities. These scammers may be claiming to call from unrelated agencies such as Medicare or insurance companies.

Remember: The number that appears on your caller ID can be manipulated. If you receive a suspicious call from a City of Victoria phone number (or any unknown number), do not provide personal or financial information.

If you suspect a call is being spoofed, hang up and call the number back directly.

Carhartt data breach exposes information of 12.9 million accounts“The ShinyHunters extortion group has published sensiti...
08/28/2026

Carhartt data breach exposes information of 12.9 million accounts

“The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned.

Founded in 1889, Carhartt is an American apparel company with workwear and streetwear manufacturing facilities in Kentucky and Tennessee and more than 3,000 employees in the United States and Europe.

While Carhartt has yet to confirm the extortion group's claims or issue a statement about the breach, ShinyHunters claimed the attack on August 13 and said they allegedly stole more than 50GB of documents containing a wide range of customer, employee, and corporate data.”

The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned.

Massive security flaws plague Ubiquiti’s UniFi ecosystem: 22 vulnerabilities, 21 criticalUbiquiti's latest UniFi patch f...
08/26/2026

Massive security flaws plague Ubiquiti’s UniFi ecosystem: 22 vulnerabilities, 21 critical
Ubiquiti's latest UniFi patch fixes 22 bugs, and several of them bypass authentication entirely.

21 Ubiquiti UniFi vulnerabilities let network attackers bypass login, escalate access, or run commands. See which devices need updates.

“HOUSTON, Texas (KTRK) -- Three Houston postal carriers are among five people federally charged in an alleged check-thef...
08/24/2026

“HOUSTON, Texas (KTRK) -- Three Houston postal carriers are among five people federally charged in an alleged check-theft scheme that investigators said generated more than $23 million over nearly six years.

According to the indictment, postal carriers were recruited to steal checks from the mail and then sell them to buyers through an encrypted communications group on Telegram.

Investigators said the scheme was allegedly orchestrated by Tryston Vaughn, who recruited postal carriers to remove checks from the mail stream. The stolen checks were then allegedly advertised and sold through a Telegram group called "Slips and Chips."

The three postal carriers charged in the case are Catherine Kilpatrick, Drakkor Alexander and Malcolm Joubert, according to court records.

The indictment alleges the stolen checks included some made out for $16,000, $25,000 and $80,000.”

Three Houston postal carriers are among five people federally charged in an alleged check-theft scheme that investigators say generated more than $23 million over nearly six years.

“One of America’s largest financial institutions, US Bank, has been claimed by the notorious LockBit hacker gang. The cy...
08/21/2026

“One of America’s largest financial institutions, US Bank, has been claimed by the notorious LockBit hacker gang. The cybercrooks gave the bank until early September before leaking the data.
LockBit claimed the bank earlier this week, uploading US Bank onto its dark web forum used to showcase the gang’s latest victims. At the same time, the attackers put a countdown clock on the post, indicating that the time runs out on September 4th.
LockBit and other ransomware gangs typically use deadlines as a scare tactic, threatening to leak victims' data if they don’t pay up.
However, the attacker did not include a data sample, making it impossible to know what types of details LockBit may have accessed. We have reached out to US Bank for comment and will update this article once we receive a reply.”

September 4 deadline puts the alleged US Bank data breach under scrutiny as LockBit offers no data sample. Read what the claims show.

Reminder IP Cameras have onboard computers and often Internet connectivity. Keeping these devices behind a firewall and ...
08/20/2026

Reminder IP Cameras have onboard computers and often Internet connectivity. Keeping these devices behind a firewall and on a segmented/isolated network is crucial to help prevent camera attacks like this. Of course along with patching and using custom set passwords.

“Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique.

The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files across 234 subdirectories, including tooling, logs, shell history, and campaign records, with the researchers saying confirmed compromises were concentrated in Ukraine and Russia.

The researchers said 1,923 cameras were configured with a persistent account during the operation and 283 were reached through the P2P path.

Users of affected Dahua products are advised to install the corresponding fix software or newer firmware, while ITRES Labs recommends disabling P2P where it is not required and checking firmware against the vendor's download site.

"The relay establishes the route without prior authentication, leaving login checks to the device's web application," ITRES Labs said in an analysis published in October 2025.”

Researchers say Operation CameraSwarm compromised 14,530+ Dahua devices using credential attacks, auth bypass flaws, and P2P relays.

Credit Card Skimmers installed in stores.Reminder use tap to pay at credit card terminals, ideally your phones tap to pa...
08/19/2026

Credit Card Skimmers installed in stores.
Reminder use tap to pay at credit card terminals, ideally your phones tap to pay.

“Scams involving credit card skimmers are on the rise, according to the U.S. Secret Service, costing consumers more than $1 billion each year. Since 2024, the Secret Service has removed what it says is just a fraction of the devices nationwide. Carter Evans reports.

Each weekday morning, "CBS Mornings" co-hosts Gayle King and Nate Burleson bring you the latest breaking news, smart conversation and in-depth feature reporting.”

Scams involving credit card skimmers are on the rise, according to ...

Hackers breached IEH Corporation's Microsoft 365 mailbox using a phishing link disguised as a legitimate document-sharin...
08/15/2026

Hackers breached IEH Corporation's Microsoft 365 mailbox using a phishing link disguised as a legitimate document-sharing invite.

IEH Corporation supplies connectors for satellites, fighter jets, radars, and missile systems including THAAD and Patriot programs.

The breach may have exposed export-controlled technical data, engineering documents, purchase orders, and customer communications.

IEH found no evidence of data exfiltration but disclosed the incident to the SEC via an 8-K filing.

“Attackers penetrated IEH Corporation, a US defense and airspace company, via a malicious link that impersonated a legitimate Microsoft sharing link. The hackers accessed an employee’s mailbox, which was full of sensitive information.
IEH Corporation disclosed the security incident in an 8-K form filed with the Securities and Exchange Commission (SEC). According to the company, a threat actor stole access to an employee’s Microsoft 365 mailbox.
IEH Corporation makes connectors used in satellites, fighter jets, ground radars, torpedoes, and airborne radars. Some of its produce is used in precision-guided missile systems such as THAAD and Patriot.
According to the 8-K form, attackers managed to access the IEH Corporation employee’s mailbox after impersonating a “prospective business contact.” The fraudster sent a hyperlink disguised as a Microsoft document-sharing link.”

A fake Microsoft link tricked a defense supplier's employee, exposing IEH Corporation's mailbox and possibly export-controlled military tech data.

Address

101 W. Goodwin Avenue #1118
Victoria, TX
77901

Alerts

Be the first to know and let us send you an email when Huff Data Systems posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Huff Data Systems:

Shortcuts

Share