ZeroTokens gives phishing operators live control of victim sessions targeting 53 financial brands

A new phishing platform known as ZeroTokens allows attackers to monitor victim sessions in real time and dynamically alter the prompts displayed, enabling adaptive attacks aimed at harvesting credentials and financial data. The platform provides operators with live visibility into information entered by victims, allowing them to steer individual phishing interactions while simultaneously using the collected data against legitimate institutions.
Abnormal AI published its analysis of the campaign on August 25, indicating that over 45,000 messages were distributed to more than 24,000 recipients across over 700 organizations. On a single peak day, approximately 24,000 messages were sent.
The campaign utilized ten sender domains and exploited nine SendGrid accounts. The phishing messages successfully passed SPF, DKIM, and DMARC authentication checks. The attackers employed a W-8BEN tax documentation review as a convincing pretext, targeting recipients with US securities holdings.
The phishing sites meticulously replicated the interfaces of targeted financial institutions, capable of presenting up to eight stages mirroring genuine verification processes. As victims input information, ZeroTokens relayed the session state to its platform, allowing an operator to choose the next screen to be displayed. The observed data collection flow included login credentials, driver’s license details, credit card information, SMS verification codes, app-based approvals, and a separate trading password.
A persistent WebSocket connection facilitated the relay of victim inputs to the operator console, simultaneously granting the operator control over the session. This capability also allowed operators to respond to failed verification attempts by presenting alternative prompts, thereby sustaining the phishing interaction instead of letting it terminate. Once data collection was complete, victims could be redirected to the legitimate institution's website.
ZeroTokens supports templates for 53 financial institutions and 36 card issuers, encompassing banks and brokerages across multiple regions. Abnormal AI's examination of the tool's console revealed distinct super-admin and operator roles. This structural design led researchers to conclude with high confidence that ZeroTokens is likely an in-house tool developed for a single criminal group, rather than a phishing-as-a-service (PaaS) offering available for rent.
The platform itself does not offer functionalities for withdrawals, transfers, payee changes, or trading orders. Consequently, Abnormal AI assessed that any financial theft or payment redirection would most likely occur outside the ZeroTokens platform, utilizing the information gathered during the phishing interaction, rather than through the platform directly.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.