Mirage2FA uses AiTM phishing to steal Microsoft 365 credentials and authenticated sessions, bypassing conventional MFA and ...
WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login ...
A developer noticed that AliExpress uses the Web Audio API to identify devices via inaudible audio signals. The question is: ...
China-linked Jewelbug uses XG-Web for espionage and crypto fraud, stealing over 580,000 browser cookies and thousands of ...
The WordPress developers have closed a malicious code security vulnerability known as XSS2Shell. In a detailed blog post, a security researcher from pwn.ai explains details about the XSS2Shell ...
An advanced malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with ...
Ein Angreifer kompromittierte die Infrastruktur des Plugin-Anbieters BdThemes und legte darüber unbemerkt Admin-Konten auf über 350.000 WordPress-Seiten an.
Three suspected Russian cyber-espionage clusters are abusing legitimate authentication features to compromise personal ...
Laundry Bear exploits security flaw in unpatched Zimbra servers, stealing 90 days of emails and authentication data without victims clicking a link.
BdThemes supply chain attack poisoned JSON API exploiting XSS vulnerability to create rogue WordPress admin accounts and install webshells.
A financially motivated threat actor has been observed abusing free Notion accounts, malicious PDFs and device code phishing ...
The built-in web fetch was never the bottleneck I thought it was, until I swapped it for a free tool.