A new phishing-as-a-service (PhaaS) operation called Forg365 is targeting Microsoft 365 accounts using device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, AI-assisted…
Nyasher is a phishing framework used to target Google accounts through fake bid proposal workflows, incorporating press-and-hold verification to evade scanners.
Security researcher Chinmohan Nayak has detailed a WhatsApp-to-host attack chain leveraging three now-patched vulnerabilities in the OpenClaw personal AI assistant. The flaws,…
Microsoft has dismantled a destructive Windows backdoor named GigaWiper, which combines three older malicious tools into a single platform. The malware, written…
The cybersecurity landscape is witnessing a surge in vulnerability clearinghouse announcements, but according to this analysis, most will fail because they focus…
Cybersecurity researchers at Infoblox have uncovered a threat actor tracked as Lurking Lizard, operating an end-to-end malicious residential proxy business since at…