Fake Microsoft Login Popup Campaign Uses Deceptive Browser in Browser Trick

Attackers use a fake browser popup that mimics Microsoft's OAuth login screen to steal credentials from unsuspecting users.

The Latest

Breaking News and Alerts

EDRChoker Exploits Windows QoS to Quietly Disable EDR Agents

The open source tool uses Windows' policy based quality of service to throttle EDR agent bandwidth to 8 bps, sidestepping detection methods used for traditional firewall blocking.

Spotlight

Cybersecurity Profiles and Stories

LiteLLM Vulnerability Actively Exploited in Attacks Leading to Full System Takeover

Attackers are chaining a LiteLLM command injection flaw with a Starlette authentication bypass to compromise AI gateway deployments without needing any credentials.

Meta Thwarts NSO Group’s Latest WhatsApp Phishing Campaign and Seeks Contempt Ruling

Meta uncovered NSO Group's attempt to bypass a permanent court order by launching a fresh phishing campaign on WhatsApp using malicious domains and test accounts.

Websites Can Now Spy on Your Apps and Browsing Activity Through SSD Timing Flaw

A new side channel technique called FROST uses browser storage APIs and SSD timing measurements to identify which other applications and websites a user has open.

Single Character Error in Linux Kernel Opens Door to Full System Takeover

A single character error in the Linux kernel's nf_tables subsystem enables unprivileged users to gain root access and escape containers, with multiple working exploits now publicly available.

Features

Research and Thought Leadership