Tag Archives: Cybersecurity
Device Code Phishing: FBI Issues Alert on Kali365 PhaaS Platform
The FBI warns that the Kali365 PhaaS platform is using device code phishing to bypass 2FA. Learn how this attack works and how to protect your organization. Continue reading
Kali365 Phishing: FBI Warns of Microsoft 365 Token Hijacking
The FBI has issued an alert regarding the Kali365 phishing toolkit, which bypasses MFA by hijacking Microsoft 365 tokens via legitimate device code flows. Continue reading
Mullvad VPN vulnerability Disclosed: Exit IP Fingerprinting Flaw Patched
Mullvad VPN has disclosed and initiated a patch for an exit IP fingerprinting vulnerability that threatened user anonymity during server-to-server connections. Continue reading
GitHub Codebase Breach: Internal Repositories Stolen via VS Code Extension
Microsoft’s GitHub is investigating a major GitHub codebase breach after hackers exfiltrated thousands of internal repositories using a poisoned VS Code extension. Continue reading
Mini Shai-Hulud Worm: TeamPCP Targets GitHub and npm
The Mini Shai-Hulud worm has launched a massive software supply chain campaign, targeting GitHub and npm registries to harvest credentials and exfiltrate corporate data. Continue reading
GitHub Code Breach: TeamPCP and the Shai-Hulud Worm Explained
Discover how the sophisticated Shai-Hulud worm enabled the TeamPCP group to execute a massive GitHub code breach, compromising internal repositories in mere minutes. Continue reading
Tycoon 2FA Phishing: New OAuth Tactics Target Microsoft 365
The evolved Tycoon 2FA phishing kit has returned with sophisticated OAuth-based exploits specifically engineered to bypass Microsoft 365 security protocols. Continue reading
Communications Cybersecurity ISAC Launched by Major US Telecom Giants
The launch of the Communications Cybersecurity ISAC marks a pivotal shift in industry security, enabling real-time threat intelligence sharing among the nation’s largest telecommunications providers. Continue reading