LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
cyber espionagehigh

China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

A China-aligned cyber espionage group, designated TA419, has reportedly been observed targeting U.S. AI policy experts through sophisticated phishing campaigns. These operations are characterized by the impersonation of prominent individuals and the deployment of a technique known as Frameless Browser-in-the-Browser (BitB) to construct highly convincing fake Microsoft login pages. The primary…

ZeroDay News ·

Source: The Hacker News

A China-aligned cyber espionage group, designated TA419, has reportedly been observed targeting U.S. AI policy experts through sophisticated phishing campaigns. These operations are characterized by the impersonation of prominent individuals and the deployment of a technique known as Frameless Browser-in-the-Browser (BitB) to construct highly convincing fake Microsoft login pages. The primary objective of these attacks is believed to be the theft of user credentials.

The core mechanism behind these attacks involves the Frameless BitB technique. This method exploits the visual rendering capabilities of web browsers to create a simulated browser window within the legitimate browser tab. Attackers craft a malicious webpage that displays what appears to be a separate, authentic login pop-up, complete with a URL bar and browser controls, but which is entirely controlled by the attacker. This allows them to present a seemingly legitimate Microsoft login page, complete with familiar branding and interface elements, within the user's current browsing session, making it difficult for targets to discern its fraudulent nature.

Upon interacting with the fake login page, victims are prompted to enter their Microsoft credentials. Because the entire "browser window" is a fabrication, any information entered into the fields is immediately transmitted to the attackers rather than to Microsoft's legitimate authentication servers. This allows TA419 to harvest usernames and passwords, which can then be used for unauthorized access to email accounts, cloud services, and other sensitive systems.

The targeting of U.S. AI policy experts suggests a strategic intelligence gathering objective. Individuals in these roles often have access to discussions, drafts, and analyses related to emerging AI regulations, ethical frameworks, and national strategies. Gaining insight into these areas could provide a foreign adversary with a significant advantage in understanding and potentially influencing the future landscape of artificial intelligence.

Products and services from major vendors like Microsoft are frequently leveraged in such attacks due to their widespread adoption in enterprise and government environments. The ubiquity of Microsoft 365 and Azure Active Directory makes these platforms a prime target for credential theft, as compromise can grant access to a broad spectrum of organizational data and communications.

Mitigation strategies for this class of attack typically involve a multi-layered approach. User education is paramount, focusing on the dangers of unsolicited emails, the importance of scrutinizing URLs, and the visual cues of legitimate login pages versus fakes. Technical controls such as multi-factor authentication (MFA) are critical, as they significantly reduce the impact of stolen credentials by requiring a second verification factor. Additionally, robust email filtering, endpoint detection and response (EDR) solutions, and continuous security awareness training are essential in defending against advanced phishing techniques like Frameless BitB.

This incident underscores the persistent threat posed by state-sponsored cyber espionage groups and their evolving tactics. The focus on AI policy experts highlights the increasing strategic importance of artificial intelligence as a domain for intelligence collection. As nations continue to develop their AI capabilities and regulatory frameworks, it is likely that such targeted campaigns will continue to evolve in sophistication and frequency, necessitating ongoing vigilance and adaptation in cybersecurity defenses.

cyber espionagephishingta419ai policyadversary-in-the-middle
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…

nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.