★   weekly threat intel

Locket Intel

The cyber tea you actually need.

Account Takeovers
High RiskMar 27, 2026

AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion

Threat actors are hijacking TikTok for Business accounts by directing victims to lookalike pages that use Cloudflare Turnstile to block security scanners before stealing credentials. Compromised accounts are then weaponized for malware distribution and malvertising.

via The Hacker NewsRead More →
Platform Updates
Medium RiskMar 13, 2026

Meta to Shut Down Instagram End-to-End Encrypted Chat Support Starting May 2026

Meta is discontinuing end-to-end encryption for Instagram DMs after May 8, 2026, citing low adoption. Users who want encrypted messaging will be directed to WhatsApp instead — leaving Instagram conversations more exposed.

via The Hacker NewsRead More →
Platform Updates
Low RiskJan 23, 2026

TikTok Forms U.S. Joint Venture to Continue Operations Under Executive Order

TikTok established TikTok USDS Joint Venture LLC to comply with President Trump's executive order, allowing the app to stay live in the U.S. ByteDance retains a 19.9% stake while data protections are managed through Oracle's cloud infrastructure.

via The Hacker NewsRead More →
Account Takeovers
High RiskAug 5, 2025

15,000 Fake TikTok Shop Domains Deliver Malware and Steal Crypto

Researchers uncovered FraudOnTok — a campaign using 15,000+ lookalike domains to trick TikTok Shop users into downloading malware. The operation uses AI-generated videos and Meta ads to advertise fake discounts, targeting crypto theft and credential harvesting.

via The Hacker NewsRead More →
Dark Web
High RiskMay 20, 2025

Malicious PyPI Packages Exploit Instagram and TikTok APIs to Validate Stolen Accounts

Three malicious Python packages on PyPI were found sending forged requests to TikTok and Instagram APIs to verify whether stolen email addresses have active accounts — building validated lists for credential stuffing attacks.

via The Hacker NewsRead More →
Platform Updates
Medium RiskJun 5, 2021

TikTok Quietly Updated Its Privacy Policy to Collect Users' Biometric Data

TikTok revised its U.S. privacy policy to permit automatic collection of biometric identifiers including faceprints and voiceprints from user content — without explicit consent in most U.S. states, following a previous $92 million settlement.

via The Hacker NewsRead More →

✦   don't miss a drop

Get the intel, weekly.

Social media threats, influencer alerts, and dark web updates — straight to your inbox.