Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect ...
Laundry Bear exploits security flaw in unpatched Zimbra servers, stealing 90 days of emails and authentication data without victims clicking a link.
A developer noticed that AliExpress uses the Web Audio API to identify devices via inaudible audio signals. The question is: ...
An advanced malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with ...
A phishing page designed to evade security tools accidentally broke its own credential-stealing operation after a coding ...
The built-in web fetch was never the bottleneck I thought it was, until I swapped it for a free tool.
Twenty-four malicious npm packages have been used to turn trusted package mirrors into staging points for ClickFix phishing ...
Cybersecurity researchers have uncovered 24 malicious npm packages that abuse package mirror services to host obfuscated ...
Microsoft 365 phishing campaign disclosed by Arctic Wolf Labs abuses Google Meet and Amazon S3 to bypass enterprise email filters. Standard MFA provides no protection as attackers steal session tokens ...
Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations
A phishing-as-a-service (PhaaS) toolkit tracked as Mirage2FA has been linked to the potential compromise of 4,532 Microsoft ...
Alleged Chinese-speaking actor breached Philippine nuclear and naval targets by exploiting known flaws, stealing sensitive ...
Malware is abusing car infotainment updates to install proxy software, turning Android head units into nodes for the BADBOX ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results