Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
CSS: The Hidden Threat Lurking in Your Inbox
1+ hour, 16+ min ago (779+ words) CSS was once just about design. Now researchers warn it's powerful enough to exfiltrate data from webmail — and some vendors aren't prepared. Black Hat USA 2026 – Las Vegas – Using email platforms to target users is nothing new in the world of…...
Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS
1+ mon, 4+ day ago (641+ words) Threat actors are moving away from spray-n-pray phishing attacks in favor of campaigns that can automatically adapt to a target's device and operating system. "One method of detection that is appearing more often is the use of Cloudflare user-agent blocking,…...
FBI-Flagged Phishing Kit Kali365 Expands Its Reach
2+ mon, 2+ day ago (355+ words) Once targeting just Microsoft 365, the phishing-as-a-service platform now aims at AWS, Okta, and Russian platforms, while relying on device code phishing. The operators of Kali365, a phishing-as-a-service platform that drew considerable attention for helping attackers bypass multifactor authentication (MFA) on Microsoft…...
Microsoft Exchange Zero-Day Under Attack, No Patch Available
2+ mon, 2+ week ago (623+ words) CVE-2026-42897 stems from a cross-site scripting (XSS) vulnerability and can allow an attacker to compromise Outlook Web Access (OWA) mailboxes. Microsoft on Thursday disclosed a zero-day vulnerability in Exchange that's under active exploitation, but four days later customers are still…...
Google News
3+ mon, 2+ week ago (12+ words) Serial-to-IP Devices Hide Thousands of Old and New Bugs Dark Reading...
Why 'Call This Number' TOAD Emails Beat Gateways
5+ mon, 1+ week ago (753+ words) Attackers are bypassing email gateways through telephone-oriented attack delivery (TOAD), in which the only email payload is a phone number. While much of the conversation surrounding phishing concerns not clicking a suspicious link or downloading a malicious attachment, there's an…...