logo

Smashing Security podcast #465: This developer wanted to cheat at Roblox. It cost millions

ID: 29da9b48-a137-5843-8324-cf198b6e4ce7

STIX ID: report--29da9b48-a137-5843-8324-cf198b6e4ce7

Feed Name: Graham Cluley

Threat Score
84/100

Date Published: 2026-04-29

Date Updated: 2026-04-30

Author: Graham Cluley

...
...

This episode details multiple active cybersecurity incidents: a Vercel breach caused by an employee-infected Lumma infostealer that stole OAuth tokens and customer secrets which are now being offered for sale; systemic mobile-network vulnerabilities (SS7 and 2G/3G fallbacks) and clandestine operators enabling location tracking of targets; and Iranian-linked threat actors conducting campaigns against critical infrastructure and Microsoft 365 environments (including password spraying and abuse of Intune to wipe devices). The discussion highlights attacker TTPs, high-impact consequences for victims, and the difficulty of remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.