WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login ...
An advanced malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with ...
Mirage2FA uses AiTM phishing to steal Microsoft 365 credentials and authenticated sessions, bypassing conventional MFA and ...
Threat actors are increasingly turning legitimate software into part of their attack chains. Instead of deploying an obviously malicious executable, attackers can abuse trusted tools that already have ...
A phishing campaign targeting cybersecurity conference attendees has been using Google Docs and other familiar online services to deliver malware, including a Windows payload that can install its own ...
Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations
A phishing-as-a-service (PhaaS) toolkit tracked as Mirage2FA has been linked to the potential compromise of 4,532 Microsoft ...
Hackers hide Agent Tesla malware in Unicode emojis inside fake bank emails, tricking finance teams into opening malicious ...
MuddyWater-linked threat actors are using a backdoor named Dindoor that abuses the legitimate Deno runtime to execute ...
The campaign, observed in late July 2026, begins with compromised WordPress websites injected with obfuscated ErrTraffic ...
Malware is abusing car infotainment updates to install proxy software, turning Android head units into nodes for the BADBOX ...
A Huntress researcher was contacted by an X account with the handle "@HartmansDoeke," who claimed to be the vice president ...
Android malware is spreading through the built-in firmware update mechanism of automotive head units for the first time.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results