LinkedIn Phishing Scam Uses Fake Notifications to Hijack Accounts
2026-04-01T20:51:46Z•589e5b6a2f0feb9f3fb0ef02617de14a0ca3ac0ff1ab5cf2ccbc6408e9ea4257
CVE-2025-53521F5-BIG-IPIObit-UnlockerImageMagickLinuxWordPressaccount-takeoveraxioscode-exposurecredential-theftdata-leakdependency-managementdual-use-toolskernel-observabilitylookalike-domainsnpmpatchingphishingpost-quantum-cryptographyransomwareremote-code-executionsecrets-managementsupply-chainvulnerability-exploitationzero-day
What happened
Multiple high-impact threats reported: a LinkedIn phishing campaign using fake notifications and lookalike domains to steal credentials and hijack professional accounts; a human-error data leak at Anthropic exposing ~512,000 lines of Claude AI code and internal secrets; ransomware actors abusing legitimate IT/admin tools (the "dual-use" dilemma) to bypass AV; a critical ImageMagick zero-day enabling remote code execution via image uploads affecting Linux distributions and WordPress deployments; a high-profile npm supply-chain compromise of the axios package; and an actively-exploited, upgraded
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 589e5b6a2f0feb9f3fb0ef02617de14a0ca3ac0ff1ab5cf2ccbc6408e9ea4257
- Enrichment time
- 2026-04-01T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.