Exchange OWA zero-day: OWAReaper long-term access
A Russian-linked group used an Exchange OWA zero-day to deliver OWAReaper via half-click XSS emails. The malware can maintain mailbox access even after clean-up and credential changes.
A Russian-linked group used an Exchange OWA zero-day to deliver OWAReaper via half-click XSS emails. The malware can maintain mailbox access even after clean-up and credential changes.
The NCSC reports that criminals are abusing WordPress sites via a botnet. Visitors see a fake browser update and may unknowingly install malware or lose login credentials.
Unit 42 investigated how malware on a Windows PC can abuse passkey-protected accounts via Google Password Manager in Chrome. The attack is post-compromise: it only starts once the device has already been taken over.
A Chinese-speaking threat actor is using a Leaked DarkSword kit to target iOS devices and deliver GHOSTBLADE. The campaign relies on fake login pages, watering holes, and credential theft.
Researchers warn that hijacked hotel wi-fi can redirect guests to fake browser or OS update pages. These can deliver surveillance malware and token-stealing payloads.