LIVE · cybersecurity feed
Live wire
CVE-2026-15409 · Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeterAnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodesCVE-2026-60004 · Hackers now exploit critical Gitea flaw in code injection attacksEmployee benefits platform Paylogix says hackers stole financial and health dataU.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure BreachesCVE-2026-61979 · Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as VulnerableCVE-2024-28224 · A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClawAustralia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attack
phishing

Bogus recruiters go after high-value corporate credentials on mobile

Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium. Attackers are using a technique called browser-in-the-browser, or BitB, which CTM360 documented in earlier research on recruitment phishing. They scrape public profile data and use it to craft convincing scheduling flows designed to get past

zeroday.news ·

A sophisticated phishing campaign is targeting high-value corporate credentials through fake job recruitment schemes, leveraging a technique known as browser-in-the-browser (BitB) to deceive victims. The attackers impersonate human resources staff from well-known companies, crafting convincing interview scheduling flows designed to steal corporate passwords.

Researchers tracking the activity observed that the phishing kit employs strict pre-qualification logic, rejecting personal email addresses and only accepting corporate credentials. This deliberate targeting ensures that threat actors gain access to high-value enterprise accounts, which can then provide immediate access to OAuth tokens, internal communications, and cloud applications, facilitating rapid lateral movement within an organization.

While the BitB technique can mimic an entire browser window, including the address bar, on desktop systems to make a fake login page appear genuine, its application differs on mobile devices. On phones, where there is no visible browser window or address bar to begin with, the kit switches to a full-screen fake login page, removing any visual cues a victim might use to verify authenticity.

The campaign has been active for at least a year, with researchers tracking numerous domains impersonating major brands. These domains often follow patterns such as "[company]-careers.com" or "[company]-global.com." The infrastructure supporting these malicious domains shows less variation than might be expected, frequently utilizing the same hosting and cloud providers. Amazon Web Services and SEDO GmbH were identified as common providers at the Autonomous System Number (ASN) level.

Domain blocklists often struggle to keep pace with the rapid registration of new lookalike domains on these shared networks, creating a window of vulnerability before fake sites are flagged. Researchers have published 46 previously undisclosed indicators of compromise related to this activity.

The impersonated brands span a wide range of industries, including e-commerce, luxury goods, aviation, and retail. Companies whose names have been caught up in the scheme include Amazon, Louis Vuitton, Apple, FIFA, Emirates Group, Boeing, Heineken, Deloitte, Central Network Retail Group, and Lego.

Defending against these targeted campaigns necessitates a shift in security focus beyond traditional desktop-centric web gateways. Securing corporate identities at the mobile touchpoint is crucial to mitigate the risks posed by these evolving phishing tactics.

phishing
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks

The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks. The post CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks appeared first on SecurityWeek.

CVE-2026-60004critical

Hackers now exploit critical Gitea flaw in code injection attacks

Attackers are actively exploiting a critical code injection vulnerability (CVE-2026-60004) in the self-hosted Gitea Git service. The flaw allows authenticated users with write access to execute arbitrary shell commands, and with default open registration, unauthenticated attackers can exploit it by creating an account. Gitea has released version 1.27.1 to address the issue, and CISA has ordered U.S. federal agencies to patch within three days due to active exploitation, with reports indicating cryptocurrency mining malware deployment.

mfa

The MFA Identity Trap: When Authentication Creates a False Sense of Security

Organizations are falling into an 'MFA Identity Trap' by conflating identity verification, authentication, and threat detection. This confusion can lead to a false sense of security, where systems successfully authenticate attackers instead of blocking them. A clear distinction between these processes is crucial for effective security.

security

RightCrowd Pass unifies mobile, physical, and biometric credentials

RightCrowd announced RightCrowd Pass, a credentialing solution that issues and manages mobile, physical and biometric access credentials from a single platform. Many large enterprises and universities rely on badge programs-built years ago. As organizations add mobile and biometric credentials, what began as a single access program can fragment into three separate systems, each with its own issuan

security

Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests

Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was first reported by ABC News on August 10, based on chat logs and screenshots the user supplied. He had asked an

vulnerability

Chrome 152 Patches Over 300 Vulnerabilities

Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities. The post Chrome 152 Patches Over 300 Vulnerabilities appeared first on SecurityWeek.