Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale - https://www.redpacketsecurity.com/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/
Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale - https://www.redpacketsecurity.com/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/
DKnife – nowy cyberzagrożenie w routerach zmienia zasady bezpieczeństwa sieci
Czy Twój router to tylko nudne pudełko do Wi-Fi? DKnife pokazuje, że to może być idealna budka podsłuchowa – tuż przy drzwiach Twojej sieci.
Czytaj dalej:
https://pressmind.org/dknife-nowy-cyberzagrozenie-w-routerach-zmienia-zasady-bezpieczenstwa-sieci/
#PressMindLabs #aitm #darknimbus #dknife #routery #shadowpad
Resurgence of a multi‑stage AiTM phishing and BEC campaign abusing SharePoint - https://www.redpacketsecurity.com/resurgence-of-a-multi-stage-aitm-phishing-and-bec-campaign-abusing-sharepoint/
#threatintel
#AiTM phishing
#BEC
#SharePoint abuse
#MFA bypass
#Energy sector security
Phishing actors exploit complex routing and misconfigurations to spoof domains - https://www.redpacketsecurity.com/phishing-actors-exploit-complex-routing-and-misconfigurations-to-spoof-domains/
#threatintel
#phishing
#spoofing
#AiTM
#Tycoon2FA
#email-security
A five-month spearphishing operation discovered by Socket has transformed the npm registry into a durable hosting layer for AiTM credential theft, specifically targeting sales teams in the manufacturing and healthcare industries.
#SecurityLand #Cybersecurity #Research #NPM #Phishing #CriticalInfrastructure #AiTM #Spearphishing #Dev

A five-month spearphishing operation has transformed the npm registry into a durable hosting layer for AiTM credential theft, specifically targeting sales teams in the manufacturing and healthcare industries.
@BleepingComputer : when using untrustworthy networks, use a browser that supports "warn for insecure connections" - and enable it (my advice: do both anyway).
Note that it is near-impossible to redirect an https connection without a certificate error - until said connection has been successfully set up. After that happens, only the target website can redirect the browser.
• Firefox uses a stupid name: "HTTPS-only". That's misleading because it only means that you'll be warned for insecure http connections (which can be enforced and hijacked by an evil twin, when not demanding https).
• Chrome on Android is stupid too: "Always use secure connections" (default: off). Also we'll have to wait one more year for this to become the default: https://security.googleblog.com/2025/10/https-by-default.html.
• Safari on iOS/iPadOS: "Not Secure Connection Warning" (also off by default).
To test: open http://http.badssl.com - your browser should warn you (instead of showing the web page), but allow you to use http.
Important: most browsers will *remember* your choice to allow an insecure connection to a specific website (based on the domain name). The criteria to "forget" such an exception vary per browser.
#AitM #MitM #EvilTwin #HTTPSonly #InsecureConnectionWarning #Firefox #Chrome #Safari
@PerlPlayer : unless it was an extremely boring meeting, that's probably one of the dumbest moments to ask people to change their password.
Regardless, tell your local BOFH's to change their stupid policy which has never improved security.
EXTREMELY long overdue (bad advice from day 1): point 6 in https://pages.nist.gov/800-63-4/sp800-63b.html#passwordver.
P.S.
1️⃣ Use a strong and reliable password manager
2️⃣ Make it use Autofill (offer creds based on domain name)
3️⃣ Let it create a long, complex, UNIQUE pw for EACH account
4️⃣ Make a backup of the database after each change
5️⃣ Make multiple backups, at least one offline
6️⃣ Use a STRONG master password (and never forget it)
7️⃣ Compromised device or account: game over
8️⃣ Enable "warn for insecure connections" in browser(s)
9️⃣ Stay vigilant (oops: https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/).
VoidProxy phishing-as-a-service bypasses MFA & SSO for Microsoft 365/Google accounts. Okta Threat Intelligence reveals sophisticated AitM attacks defeating modern authentication. Enterprise security teams: reassess your defenses NOW.
#SecurityLand #ThreatHorizon #CyberSecurity #PhishingAttack #EnterpriseSecurity #AitM #Phishing #VoidProxy
1) security.nl
2) http:⧸⧸gw.defensie.nl
3) https:⧸⧸gemeente.amsterdam
Nb. in 2 en 3 heb ik ⧸⧸ i.p.v. // gebruikt om te voorkómen dat Mastodon er resp.
http://gw.defensie.nl
en
https://gemeente.amsterdam
van maakt (m.i. zou Mastodon OP Z'N MINST "http://" in link 2 moeten laten zien).
Zie https://www.security.nl/posting/904650/security_nl+-%3E+http%3A__security_nl.
#httpVShttps #AitM #QRcodes #EvilTwin #PublicWifi #InfoSec #httpsVShttp #E2EE #Tunnel #TLS #SSL