Hackers Are Turning Plain CSS Into Keyloggers Hidden Inside Everyday Emails
Security researcher Gareth Heyes has demonstrated that ordinary CSS styling code, not JavaScript or malware, can be weaponized to hijack webmail interfaces and capture passwords keystroke by keystroke....
Greatness Phishing Service Lets Attackers Slide Past MFA Into Microsoft 365 Inboxes
A phishing-as-a-service platform called Greatness is stealing live authentication tokens rather than passwords, letting attackers walk past multi-factor authentication and into Microsoft 365 mailboxes. A recent campaign hid...
LokiBot Returns: Multi-Stage JScript Campaign Uses Process Injection to Steal Credentials
LokiBot, the decade-old credential stealer, has resurfaced with a sophisticated multi-stage attack chain: a JScript email dropper, in-memory .NET injection, and process hollowing inside aspnet_compiler.exe to silently harvest...
AWS AiTM Phishing Kit Bypasses MFA to Hijack Cloud Console Sessions in Real Time
A real-time adversary-in-the-middle phishing kit has been targeting AWS engineers, stealing credentials and MFA codes simultaneously to hijack cloud sessions before they expire. Standard MFA provides zero protection...
JS.MonoGlyphRAT: Stealthy New Malware Hidden in Fake Purchase Orders Targets US Enterprises
A previously unknown remote access trojan called JS.MonoGlyphRAT is spreading through US businesses disguised as routine purchase orders and business quotes. It evades all major antivirus tools by...
Grandoreiro Banking Trojan Returns: Targeting Portuguese Banks and Latin American Companies With Dual Campaigns
The long-running Grandoreiro banking trojan has resurfaced with two active campaigns — one using DLL Side-Loading via cloud infrastructure and another via obfuscated VBS scripts — targeting over...
CORDIAL SPIDER and SNARKY SPIDER Deploy AiTM Pages to Breach SharePoint, HubSpot, and Google Workspace
Two threat groups are deploying adversary-in-the-middle phishing pages combined with voice phishing to bypass MFA and hijack enterprise SaaS sessions. Operating entirely within trusted cloud environments, the campaigns...
Microsoft’s April 2026 Update Adds New RDP Security Warnings to Protect Against Phishing via .rdp Files
Microsoft's April 2026 Patch Tuesday introduces new multi-layer warning dialogs in Windows Remote Desktop Connection, designed to protect users from phishing attacks that weaponize .rdp files — a...