#login,


Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

Aug 25, 2026 // 14:58

Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate […]

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

Jul 28, 2026 // 17:51

Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to […]

New ClickLock macOS malware traps users into revealing login password

Jul 17, 2026 // 00:56

A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. The malware is designed to […]

PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords

Jul 3, 2026 // 11:27

Cybersecurity researchers have flagged a new macOS information stealer called PamStealer that employs a series of clever tricks to infect systems and siphon sensitive data. […]

Hackers target Microsoft 365 accounts with 81 million login attempts

Jul 1, 2026 // 19:58

An aggressive password-spraying campaign targeting Microsoft 365 environments generated more than 81 million login attempts over a two-week period. The threat actor tried to authenticate […]

Bluekit phishing kit adopts browser-in-the-middle for login theft

Jun 25, 2026 // 23:37

The Bluekit phishing-as-a-service platform continues to evolve with nearly 70 new hostnames identified over the past week, and by adding browser-in-the-middle (BitM) capabilities for improved […]

China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade

Jun 12, 2026 // 21:27

Instead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the Linux login […]

Suspicious Polyfill login prompts pop up on Toshiba, Muji websites

Jun 6, 2026 // 00:56

Tech giant Toshiba and mega-retailer Muji warned visitors that suspicious sign-in screens popping up on their websites could collect credentials. Both Japanese companies advised users […]

Canvas login portals hacked in mass ShinyHunters extortion campaign

May 8, 2026 // 11:57

The ShinyHunters extortion gang has breached education technology giant Instructure again, this time exploiting a vulnerability to deface Canvas login portals for hundreds of colleges […]

Hackers abuse Google ads for GoDaddy ManageWP login phishing

May 7, 2026 // 00:37

A phishing campaign delivered through Google sponsored search results is targeting credentials for ManageWP, GoDaddy’s platform for managing fleets of WordPress websites. The threat actor […]

1 2 Next