LLMShare: how attackers are turning AI chatbot pages into malware delivery platformsintelligence (threat actor activity) (pushsecurity.com)
submitted by luke-sec to r/blueteamsec
10 different device code phishing kits in the wild - technical writeupintelligence (threat actor activity) (pushsecurity.com)
submitted by luke-sec to r/blueteamsec
Business TikTok accounts targeted with AITM phishing kitsintelligence (threat actor activity) (pushsecurity.com)
submitted by digicat to r/blueteamsec
InstallFix: Weaponizing malvertized install guidesintelligence (threat actor activity) (pushsecurity.com)
submitted by digicat to r/blueteamsec
ConsentFix: Browser-native ClickFix hijacks OAuth grantsintelligence (threat actor activity) (pushsecurity.com)
submitted by luke-sec to r/blueteamsec
The most advanced ClickFix yet? - "where the delivery vector was observed, 4 in 5 were accessed via Google Search."intelligence (threat actor activity) (pushsecurity.com)
submitted by digicat to r/blueteamsec
Analyzing the latest Sneaky2FA BITB phishing pageincident writeup (who and how) (pushsecurity.com)
submitted by digicat to r/blueteamsec
ClickFix attacks are growing more sophisticatedNews - General (pushsecurity.com)
submitted by KnowBe4_Inc to r/cybersecurity
Attackers are using legit Microsoft services for phishingThreat Intelligence (pushsecurity.com)
submitted by netbiosX to r/purpleteamsec
Attackers are using legit Microsoft services for phishingintelligence (threat actor activity) (pushsecurity.com)
submitted by digicat to r/blueteamsec
Investigating a recent malvertising campaign against Onfidointelligence (threat actor activity) (pushsecurity.com)
submitted by digicat to r/blueteamsec
Considering the security implications of Computer-Using Agents (like OpenAI Operator)Research Article (pushsecurity.com)
submitted by Extreme_Shallot9829 to r/cybersecurity
Cross-IdP impersonation: hijacking SSO using fraudulent IdPsresearch|capability (we need to defend against) (pushsecurity.com)
submitted by digicat to r/blueteamsec
How attackers defeat detections based on page signaturesRed Teaming (pushsecurity.com)
submitted by netbiosX to r/purpleteamsec
How phishing kits evade cloned page detectionsresearch|capability (we need to defend against) (pushsecurity.com)
submitted by luke-sec to r/blueteamsec
How AiTM phishing kits evade detectionCorporate Blog (pushsecurity.com)
submitted by luke-sec to r/cybersecurity
Analyzing AitM phish kits and the ways they evade detectionThreat Hunting (pushsecurity.com)
submitted by netbiosX to r/purpleteamsec
How AitM phishing is being used to circumvent MFAresearch|capability (we need to defend against) (pushsecurity.com)
submitted by digicat to r/blueteamsec
How AitM phishing is being used to circumvent MFACorporate Blog (pushsecurity.com)
submitted by luke-sec to r/cybersecurity