Domain registrar Namecheap handed over a customer's account to an unverified third party after a password reset request, raising security concerns for a 13-year customer.
A long-time Namecheap customer discovered the registrar transferred domain control to an unauthorized user following a password reset initiated by someone else.
The customer had registered a .com domain under their own credentials for a college club they helped manage. During a leadership transition, an incoming club officer found the domain parked at Namecheap and initiated a password reset using only the domain name.
Namecheap sent a reset email to the account owner, but the customer claims the registrar ultimately granted access to the unverified third party without proper verification.
The incident highlights potential gaps in Namecheap's account security protocols. Password reset procedures typically require additional verification steps beyond email confirmation when sensitive assets like domain registrations are at stake.
The customer filed a support ticket to address the unauthorized access. The situation underscores the importance of registrars implementing multi-factor authentication and stricter identity verification for account transfers and sensitive changes.
AegisAI, a security startup founded by former Google executives, secured $36 million in funding to deploy AI agents that detect sophisticated spear phishing attacks.
The US government issued an updated advisory warning that Iranian hackers are actively disrupting critical infrastructure systems used by American water and energy providers.
Apple has published SOC 3 audit reports for its Private Cloud Compute infrastructure, providing third-party verification of security controls for on-device AI processing that routes some tasks to Apple servers.
A developer discovered their coding interview assignment included hidden malware designed to execute via Git hooks. The sophisticated setup raised questions about interview practices and candidate vetting.