Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect ...
WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login ...
In einem ausführlichen Blogbeitrag führt ein Sicherheitsforscher von pwn.ai Details zur XSS2Shell-Lücke aus. Der Fehler ...
Laundry Bear exploits security flaw in unpatched Zimbra servers, stealing 90 days of emails and authentication data without victims clicking a link.
China-linked Jewelbug uses XG-Web for espionage and crypto fraud, stealing over 580,000 browser cookies and thousands of ...
An advanced malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with ...
Blocklists were already losing ground before AI entered the picture. Phishing domains have been getting shorter-lived for years, campaigns have been burning infrastructure faster, and the gap between ...
Есть довольно распространенный сценарий, при котором сайт начинает тормозить, и кто-то предлагает подключить CDN. В итоге подключают, переключают DNS, трафик начинает идти через распределенную сеть, с ...
The built-in web fetch was never the bottleneck I thought it was, until I swapped it for a free tool.
Microsoft 365 phishing campaign disclosed by Arctic Wolf Labs abuses Google Meet and Amazon S3 to bypass enterprise email filters. Standard MFA provides no protection as attackers steal session tokens ...
Twenty-four malicious npm packages have been used to turn trusted package mirrors into staging points for ClickFix phishing ...
npmおよびそのミラーを悪用してCloudflare CAPTCHAに見せかけた悪性HTMLページをホストするキャンペーンについて、OX ...