Sentire's Threat Response Unit (TRU) has uncovered a previously undocumented device-code phishing kit, dubbed "GhostCode," that abuses Microsoft's OAuth 2.0 device authorization grant flow to hijack ...
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel.
Microsoft warns attackers are using passkey and MFA update requests to phish employees, hijack sessions, and access Microsoft 365 data.
A threat actor exploited a pre-authentication remote code execution flaw in marimo to harvest AWS credentials, retrieve an ...