Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The Greatness phishing-as-a-service toolkit now uses device code phishing to exploit OAuth 2.0 Device Authorization Grant, bypassing MFA and hijacking accounts.
Tag
12 results in the archive.
The Greatness phishing-as-a-service toolkit now uses device code phishing to exploit OAuth 2.0 Device Authorization Grant, bypassing MFA and hijacking accounts.
Amgen reported a cloud data breach involving unauthorized access to patient health data and proprietary corporate information via third-party cloud systems.
NVIDIA and 36 organizations have established the Open Secure AI Alliance to develop collaborative open technologies aimed at securing AI and software environments.
A critical pre-authentication remote code execution vulnerability in vBulletin forum software has been patched following the public release of an exploit, enabling unauthenticated attackers to execute arbitrary PHP code.
Attackers manipulate DNS settings on hotel and conference center Wi-Fi to redirect users to fraudulent Microsoft 365 login pages, targeting credential theft from business travelers.
A zero-day vulnerability named LegacyHive enables privilege escalation on fully updated Windows systems, allowing attackers to gain admin-level access.
Abbott Laboratories is investigating unauthorized access incidents affecting Exact Sciences legacy systems and its LabCentral portal, with allegations of stolen company data linked to extortion.
ClickLock is a new macOS information-stealing malware that tricks users into revealing their system login password by terminating visible processes.
Two hackers were sentenced for their 2024 attack on Transport for London, which disrupted 148 systems and forced a password reset for 27,000 employees, causing significant operational and financial impact.
Zoom has disclosed a critical vulnerability in its Windows desktop client and SDK that enables unauthenticated attackers to hijack user accounts, posing a significant security risk.
Spanish Police arrested four individuals and dismantled a cybercrime network responsible for €140 million in losses through investment fraud and business email compromise attacks.
Google and Microsoft removed the ModHeader browser extension from their stores due to a dormant hidden browsing-history collector found in the official version, with no evidence of active data transmission.