wolfSSH Patches 5 Security Vulnerabilities, Including Critical SSH Authentication Bypass
wolfSSL has released wolfSSH version 1.6.
Articles mapped to MITRE ATT&CK techniques. Select a technique to view matching articles.
24 articles found
wolfSSL has released wolfSSH version 1.6.
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) e...
A China-linked threat actor known as TA419 has targeted U.S.
Every identity-compromise runbook I have written, read or inherited has the same step near the top: revoke the tokens. Reset the password, kill the sessions,...
Attackers are using passkey-themed social engineering to trick employees into giving them access to their Microsoft accounts. Microsoft Security Research sai...
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service ...
View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory ...
Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redire...
Threat actors are increasingly abusing Microsoft 365 identity sessions rather than deploying malware, as shown in a cloud-only business email compromise (BEC...
A critical vulnerability in the Apache HttpComponents Client can allow man-in-the-middle attackers to impersonate trusted servers when applications use the a...
The new AKV feature is designed to combat man-in-the-middle attacks, where an adversary could intercept messages by corrupting Signal's centralized directory...
A Chrome Web Store operation that turns “free VPN” extensions into browser-wide traffic relays controlled by a single proxy provider. The campaign comprises ...
Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted...
A widespread phishing operation that compromises Microsoft 365 accounts through adversary-in-the-middle (AiTM) infrastructure, then uses Microsoft Graph to i...
Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniqu...
Stolen Greatness authentication tokens are providing sustained, MFA‑approved access to victim Microsoft 365 tenants for more than two weeks after the initial...
The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing target...
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a r...
We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms lik...
A new report from eSentire reveals that AiTM attacks accounted for 28.57% of all initial access events in the legal sector, with a 20% year-over-year increas...