Mirage2FA uses AiTM phishing to steal Microsoft 365 credentials and authenticated sessions, bypassing conventional MFA and ...
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect ...
WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login ...
Uh-oh, e-commerce giant AliExpress has been caught running hidden, silent audio processes inside visitors' browsers to generate unique device tracking profiles without user consent.
In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 ...
A developer noticed that AliExpress uses the Web Audio API to identify devices via inaudible audio signals. The question is: ...
China-linked Jewelbug uses XG-Web for espionage and crypto fraud, stealing over 580,000 browser cookies and thousands of ...
For most defenders, a phishing alert ends with a forced password change. Mirage2FA is built to make that response useless.
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion monthly downloads. The Wave Six payload hid inside AI agent config files ...
A phishing-as-a-service (PhaaS) toolkit tracked as Mirage2FA has been linked to the potential compromise of 4,532 Microsoft ...
Cybersecurity researchers have uncovered 24 malicious npm packages that abuse package mirror services to host obfuscated ...
McKinsey’s latest State of AI report revealed that 62% of organizations have started experimenting with AI agents in some form. However, Gartner expects over 40% of these projects to be scrapped by ...