Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium. Attackers are using a technique called browser-in-the-browser, or BitB, which CTM360 documented in earlier research on recruitment phishing. They scrape public profile data and use it to craft convincing scheduling flows designed to get past

A sophisticated phishing campaign is targeting high-value corporate credentials through fake job recruitment schemes, leveraging a technique known as browser-in-the-browser (BitB) to deceive victims. The attackers impersonate human resources staff from well-known companies, crafting convincing interview scheduling flows designed to steal corporate passwords.
Researchers tracking the activity observed that the phishing kit employs strict pre-qualification logic, rejecting personal email addresses and only accepting corporate credentials. This deliberate targeting ensures that threat actors gain access to high-value enterprise accounts, which can then provide immediate access to OAuth tokens, internal communications, and cloud applications, facilitating rapid lateral movement within an organization.
While the BitB technique can mimic an entire browser window, including the address bar, on desktop systems to make a fake login page appear genuine, its application differs on mobile devices. On phones, where there is no visible browser window or address bar to begin with, the kit switches to a full-screen fake login page, removing any visual cues a victim might use to verify authenticity.
The campaign has been active for at least a year, with researchers tracking numerous domains impersonating major brands. These domains often follow patterns such as "[company]-careers.com" or "[company]-global.com." The infrastructure supporting these malicious domains shows less variation than might be expected, frequently utilizing the same hosting and cloud providers. Amazon Web Services and SEDO GmbH were identified as common providers at the Autonomous System Number (ASN) level.
Domain blocklists often struggle to keep pace with the rapid registration of new lookalike domains on these shared networks, creating a window of vulnerability before fake sites are flagged. Researchers have published 46 previously undisclosed indicators of compromise related to this activity.
The impersonated brands span a wide range of industries, including e-commerce, luxury goods, aviation, and retail. Companies whose names have been caught up in the scheme include Amazon, Louis Vuitton, Apple, FIFA, Emirates Group, Boeing, Heineken, Deloitte, Central Network Retail Group, and Lego.
Defending against these targeted campaigns necessitates a shift in security focus beyond traditional desktop-centric web gateways. Securing corporate identities at the mobile touchpoint is crucial to mitigate the risks posed by these evolving phishing tactics.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets