Mirage2FA uses AiTM phishing to steal Microsoft 365 credentials and authenticated sessions, bypassing conventional MFA and ...
An advanced malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with ...
A phishing campaign targeting cybersecurity conference attendees has been using Google Docs and other familiar online services to deliver malware, including a Windows payload that can install its own ...
NemoClaw vulnerability CVE-2026-65105 lets a single malicious webpage permanently rewrite a local AI agent's chat template ...
Malware is abusing car infotainment updates to install proxy software, turning Android head units into nodes for the BADBOX ...
CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities Catalog more than six months after its initial disclosure.
A phishing-as-a-service (PhaaS) toolkit tracked as Mirage2FA has been linked to the potential compromise of 4,532 Microsoft ...
Kaspersky uncovers first-ever malware targeting Android car head units, linked to the BADBOX botnet, enabling ad fraud and ...
Android malware is spreading through the built-in firmware update mechanism of automotive head units for the first time.
Twenty-four malicious npm packages have been used to turn trusted package mirrors into staging points for ClickFix phishing ...
A Huntress researcher was contacted by an X account with the handle "@HartmansDoeke," who claimed to be the vice president ...
China’s hacking campaign targeted NASA, the Federal Reserve, the US Senate, the Justice Department, and more, according to ...