Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect ...
Mirage2FA uses AiTM phishing to steal Microsoft 365 credentials and authenticated sessions, bypassing conventional MFA and ...
BdThemes supply chain attack poisons JSON feed to create rogue WordPress admins and deploy web shells without code changes.
The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. Although the threat actor has targeted government ...
Fortnite can stop before the lobby with "An error occurred while connecting to Epic servers. Please try again later. ESP-DIST ...
Microsoft 365 phishing campaign disclosed by Arctic Wolf Labs abuses Google Meet and Amazon S3 to bypass enterprise email filters. Standard MFA provides no protection as attackers steal session tokens ...
Malware is abusing car infotainment updates to install proxy software, turning Android head units into nodes for the BADBOX ...
Spread the loveIf you’ve spent any significant time wrestling with APIs, you know the drill: repetitive setup, token ...
Google tracks 3 Russian-linked espionage clusters using legitimate authentication tools to target researchers, diplomats and ...
Spread the loveWhen you’re building modern applications, APIs are the backbone. They’re how different software components ...
A newly disclosed critical vulnerabilities across several open-source SAML implementations through an AI-assisted research pipeline using Anthropic’s Claude Opus.