Threat actors are exploiting CVE-2026-58138, a critical-severity remote code execution vulnerability in Orkes Conductor.
FedEx Corp. recently announced its new premium delivery option for residential and commercial shipments. The Memphis-based ...
JSCeal can steal browser credentials, replay Google sessions using stolen cookies, and modify traffic for cryptocurrency ...
Microsoft 365 phishing MFA bypass platform BigBear 2.0 compromised 258 organizations across 40+ countries by using custom JavaScript to disable FIDO2 hardware key authentication before stealing ...
CrowdStrike says PhantomRaven was likely LLM-generated and spread through malicious npm packages that collect developer credentials and CI/CD secrets.
Sentire uncovers the GhostCode phishing kit abusing Microsoft OAuth to steal tokens, register attacker devices and access ...
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations ...
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites ...
BigBear 2.0 compromised 258 organizations and stole over 5,000 Microsoft 365 credentials using MFA-bypass phishing techniques ...
A Microsoft 365 phishing operation targeting hundreds of organizations captured thousands of passwords and session cookies, ...
Introduction to Modern SSO Challenges Isn't it annoying how many passwords we need these days? Single Sign-On (SSO) was supposed to fix that, but sometimes it feels like it just moved the problem ...
Researchers found a phishing service relaying live Google sign-in sessions to intercept passwords, 2FA codes, and active ...