Hackers found a sneaky new way to steal your login even when it’s encrypted – here’s how they’re pulling it off

zeeforce
4 Min Read




  • Bypasses email gateways and security tools by never hitting a real server
  • Blob URIs mean phishing content isn’t hosted online, so filters never see it coming
  • No weird URLs, no dodgy domains, just silent theft from a fake Microsoft login page

Security researchers have uncovered a series of phishing campaigns that use a rarely exploited technique to steal login credentials, even when those credentials are protected by encryption.

New research from Cofense warns the method relies on blob URIs, a browser feature designed to display temporary local content, and cybercriminals are now abusing this feature to deliver phishing pages.



Source link

Share This Article
Leave a comment
Optimized by Optimole
Verified by MonsterInsights