Fake Firefox Extension Hijacks Google Accounts Without Stealing Passwords First
A malicious Firefox extension masquerading as a PDF identity-verification utility has been found targeting Google accounts through session-cookie theft and a...
Articles mapped to MITRE ATT&CK techniques. Select a technique to view matching articles.
284 articles found
A malicious Firefox extension masquerading as a PDF identity-verification utility has been found targeting Google accounts through session-cookie theft and a...
Disruptive attacks on public-facing services, financially motivated cybercrime and compromises of shared technology providers are increasing cybersecurity ri...
A firewall is supposed to be the barrier between attackers and the enterprise network, but that barrier can itself become a threat actors’ tool. Check Point ...
Technology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday. The flaw impacts de...
The ShinyHunters cybercriminal organization on Tuesday replaced agency images on the FBIjobs.gov site with a photo of a Pokemon that has become the group’s d...
How many bugs have you missed because you didn’t send quite enough HTTP requests?
Microsoft has warned that the EvilTokens phishing-as-a-service platform has become a major driver of AI-enabled device-code phishing, compromising more than ...
A threat actor linked to the ongoing Graphalgo software supply-chain campaign has expanded beyond npm and PyPI, using malicious Terraform providers and Go mo...
Cisco Duo is the best MFA for most buyers comparing on price and speed published per-user tiers, a free small-team floor, and device trust included while Mic...
RedVDS operated as an online hub selling access to virtual machines (VMs) that were used by cybercriminals to launch a variety of attacks, including phishing...
The popular phishing-as-a-service platform used AI throughout the attack chain, allowing cybercriminals to steal tokens for account takeover and business ema...
EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and ...
AI is letting cybercriminals reach deeper into organizations than a phishing email ever could. 41% of CISOs reported at least one social engineering incident...
When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Finan...
A Google Gemini AI agent broke into three companies in July, guessing the credentials for one and discovering the credentials for the second two in a public ...
Google has been fined 403 million euros ($463 million) for breaching the European Union’s strict privacy rules because it mishandled users’ location data. Th...
AI agents are becoming the new attack surface, exposed to poisoned skills, prompt injection, jailbreaks and attacks through connected tools. I read the AI se...
Forty percent of large companies had an AI-related compliance or governance issue in the past 12 months, according to 1,000 senior IT, operations, and transf...
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial a...
Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity ...