Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale - RedPacket Security

Following its emergence in August 2023, Tycoon2FA rapidly became one of the most widespread phishing-as-a-service (PhaaS) platforms, enabling campaigns

RedPacket Security

DKnife – nowy cyberzagrożenie w routerach zmienia zasady bezpieczeństwa sieci

Czy Twój router to tylko nudne pudełko do Wi-Fi? DKnife pokazuje, że to może być idealna budka podsłuchowa – tuż przy drzwiach Twojej sieci.

Czytaj dalej:
https://pressmind.org/dknife-nowy-cyberzagrozenie-w-routerach-zmienia-zasady-bezpieczenstwa-sieci/

#PressMindLabs #aitm #darknimbus #dknife #routery #shadowpad

Resurgence of a multi‑stage AiTM phishing and BEC campaign abusing SharePoint - https://www.redpacketsecurity.com/resurgence-of-a-multi-stage-aitm-phishing-and-bec-campaign-abusing-sharepoint/

#threatintel
#AiTM phishing
#BEC
#SharePoint abuse
#MFA bypass
#Energy sector security

Resurgence of a multi‑stage AiTM phishing and BEC campaign abusing SharePoint - RedPacket Security

Microsoft Defender Researchers uncovered a multi‑stage adversary‑in‑the‑middle (AiTM) phishing and business email compromise (BEC) campaign targeting multiple

RedPacket Security
Phishing actors exploit complex routing and misconfigurations to spoof domains - RedPacket Security

Phishing actors are exploiting complex routing scenarios and misconfigured spoof protections to effectively spoof organizations’ domains and deliver phishing

RedPacket Security

A five-month spearphishing operation discovered by Socket has transformed the npm registry into a durable hosting layer for AiTM credential theft, specifically targeting sales teams in the manufacturing and healthcare industries.

Read More: https://www.security.land/npm-registry-weaponized-in-spearphishing-campaign-against-critical-infrastructure/

#SecurityLand #Cybersecurity #Research #NPM #Phishing #CriticalInfrastructure #AiTM #Spearphishing #Dev

npm Registry Abused for Targeted Spearphishing Campaign

A five-month spearphishing operation has transformed the npm registry into a durable hosting layer for AiTM credential theft, specifically targeting sales teams in the manufacturing and healthcare industries.

Security Land | Decoding the Cyber Threat Landscape
TokenFlare y la nueva generación de AiTM serverless: cuando el phishing se convierte en infraestructura #aitm #herramientas #red_team #windows
https://www.hackplayers.com/2025/12/tokenflare-y-la-nueva-generacion-de-AiTM.html
TokenFlare y la nueva generación de AiTM serverless: cuando el phishing se convierte en infraestructura

Durante años, el phishing ha sido tratado como un problema “humano”: concienciación, banners, simulaciones internas y poco más. Sin embargo,...

@BleepingComputer : when using untrustworthy networks, use a browser that supports "warn for insecure connections" - and enable it (my advice: do both anyway).

Note that it is near-impossible to redirect an https connection without a certificate error - until said connection has been successfully set up. After that happens, only the target website can redirect the browser.

• Firefox uses a stupid name: "HTTPS-only". That's misleading because it only means that you'll be warned for insecure http connections (which can be enforced and hijacked by an evil twin, when not demanding https).

• Chrome on Android is stupid too: "Always use secure connections" (default: off). Also we'll have to wait one more year for this to become the default: https://security.googleblog.com/2025/10/https-by-default.html.

• Safari on iOS/iPadOS: "Not Secure Connection Warning" (also off by default).

To test: open http://http.badssl.com - your browser should warn you (instead of showing the web page), but allow you to use http.

Important: most browsers will *remember* your choice to allow an insecure connection to a specific website (based on the domain name). The criteria to "forget" such an exception vary per browser.

#AitM #MitM #EvilTwin #HTTPSonly #InsecureConnectionWarning #Firefox #Chrome #Safari

@PerlPlayer : unless it was an extremely boring meeting, that's probably one of the dumbest moments to ask people to change their password.

Regardless, tell your local BOFH's to change their stupid policy which has never improved security.

EXTREMELY long overdue (bad advice from day 1): point 6 in https://pages.nist.gov/800-63-4/sp800-63b.html#passwordver.

P.S.
1️⃣ Use a strong and reliable password manager
2️⃣ Make it use Autofill (offer creds based on domain name)
3️⃣ Let it create a long, complex, UNIQUE pw for EACH account
4️⃣ Make a backup of the database after each change
5️⃣ Make multiple backups, at least one offline
6️⃣ Use a STRONG master password (and never forget it)
7️⃣ Compromised device or account: game over
8️⃣ Enable "warn for insecure connections" in browser(s)
9️⃣ Stay vigilant (oops: https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/).

@sundogplanets

#Passwords #PasswordManager #Phishing #TroyHunt #AitM #MitM

VoidProxy phishing-as-a-service bypasses MFA & SSO for Microsoft 365/Google accounts. Okta Threat Intelligence reveals sophisticated AitM attacks defeating modern authentication. Enterprise security teams: reassess your defenses NOW.

#SecurityLand #ThreatHorizon #CyberSecurity #PhishingAttack #EnterpriseSecurity #AitM #Phishing #VoidProxy

Read More: https://www.security.land/voidproxy-emerges-as-advanced-phishing-as-a-service-platform-targeting-enterprise-authentication-systems/

VoidProxy Emerges as Advanced Phishing-as-a-Service Platform Targeting Enterprise Authentication Systems | Security Land

VoidProxy phishing platform bypasses MFA and SSO security, targeting Microsoft 365 and Google accounts through sophisticated AitM attacks.

Security Land

1) security.nl
2) http:⧸⧸gw.defensie.nl
3) https:⧸⧸gemeente.amsterdam

Nb. in 2 en 3 heb ik ⧸⧸ i.p.v. // gebruikt om te voorkómen dat Mastodon er resp.
http://gw.defensie.nl
en
https://gemeente.amsterdam
van maakt (m.i. zou Mastodon OP Z'N MINST "http://" in link 2 moeten laten zien).

Zie https://www.security.nl/posting/904650/security_nl+-%3E+http%3A__security_nl.

#httpVShttps #AitM #QRcodes #EvilTwin #PublicWifi #InfoSec #httpsVShttp #E2EE #Tunnel #TLS #SSL