WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login ...
Mirage2FA uses AiTM phishing to steal Microsoft 365 credentials and authenticated sessions, bypassing conventional MFA and ...
Laundry Bear exploits security flaw in unpatched Zimbra servers, stealing 90 days of emails and authentication data without victims clicking a link.
Three suspected Russian cyber-espionage clusters are abusing legitimate authentication features to compromise personal ...
BdThemes supply chain attack poisoned JSON API exploiting XSS vulnerability to create rogue WordPress admin accounts and install webshells.
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect ...
An advanced malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with ...
A developer noticed that AliExpress uses the Web Audio API to identify devices via inaudible audio signals. The question is: ...
A financially motivated threat actor has been observed abusing free Notion accounts, malicious PDFs and device code phishing ...
The built-in web fetch was never the bottleneck I thought it was, until I swapped it for a free tool.
On Thursday, Google’s Threat Intelligence Group (GTIG) said it's now tracking two other suspected Russian groups, UNC7005 and ...
ThreatDown, the business security arm of Malwarebytes Inc., said in new research published today that Kriminal, one of the ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results