A large-scale phishing campaign used fake voicemail SVG attachments to bypass email defenses, targeting 5527 organizations ...
A phishing page designed to evade security tools accidentally broke its own credential-stealing operation after a coding ...
Mirage2FA uses AiTM phishing to steal Microsoft 365 credentials and authenticated sessions, bypassing conventional MFA and ...
A phishing-as-a-service (PhaaS) toolkit tracked as Mirage2FA has been linked to the potential compromise of 4,532 Microsoft ...
For most defenders, a phishing alert ends with a forced password change. Mirage2FA is built to make that response useless.
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login ...
A developer noticed that AliExpress uses the Web Audio API to identify devices via inaudible audio signals. The question is: ...
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect ...
Uh-oh, e-commerce giant AliExpress has been caught running hidden, silent audio processes inside visitors' browsers to generate unique device tracking profiles without user consent.
In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 ...
Five layers of a 2026 phish, two studies three years apart, and the tells that replaced the ones you were taught. In October 2022, Osterman Research published a study we commissioned, The Business ...