Hackers found a sneaky new way to steal your login even when it’s encrypted – here’s how they’re pulling it off




  • Bypasses email gateways and security tools by never hitting a real server
  • Blob URIs mean phishing content isn’t hosted online, so filters never see it coming
  • No weird URLs, no dodgy domains, just silent theft from a fake Microsoft login page

Security researchers have uncovered a series of phishing campaigns that use a rarely exploited technique to steal login credentials, even when those credentials are protected by encryption.

New research from Cofense warns the method relies on blob URIs, a browser feature designed to display temporary local content, and cybercriminals are now abusing this feature to deliver phishing pages.

https://cdn.mos.cms.futurecdn.net/LqY7HKu9U9Ey8QoKMdnSzX.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img