Reading view

There are new articles available, click to refresh the page.

FBI Alert: OAuth Consent Phishing is Targeting Users of Messaging Apps

The U.S. Federal Bureau of Investigation (FBI) has issued an advisory warning of a wave of OAuth consent phishing attacks targeting “prominent victims, their family members, and personal acquaintances.”

OAuth phishing is an increasingly popular social engineering tactic that tricks users into granting access to their accounts without handing over their passwords.

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out of attacker-controlled web infrastructure and into the victim’s browser. Unlike ordinary phishing kits, which host cloned login portals on domains that can eventually be detected and disrupted, this campaign delivers malicious content assembled only after a user follows the attack chain. A blob URL is a […]

The post New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

When it comes to Beatles references, scientists can't let it be

Scientists have an indisputable playful side, evidenced by frequent allusions to popular culture in their research publications. That includes popular song lyrics. And the most popular musical group, in terms of how frequently their songs and lyrics appear in the scientific literature, is The Beatles, according to a new paper published in the journal PLoS ONE.

“Some of these are genuinely brilliant," said co-author Gabriel Budel of Delft University of Technology in the Netherlands of the more than 3,000 references they found to The Beatles. "'The lung and winding road' is a paper on Long COVID that changes one vowel. 'Here comes the SU(N)' turns 'Here Comes the Sun' into a quantum computing paper about mathematical groups. Someone was having a very good day at their desk.”

Back in 2014, scientists at the Karolinska Institute in Sweden revealed that they had been deliberately inserting Bob Dylan lyrics into their papers as part of a long-running bet, starting with a 1997 Nature review entitled "Nitric Oxide and inflammation: The answer is blowing in the wind." That resulted in a 2015 study on whether Dylan lyrics appeared elsewhere in the biomedical literature; the most frequently referenced were "The Times They Are A'Changin'" and "Blowing in the Wind."

Read full article

Comments

© Ramon Dorenbos, CC-BY 4.0

Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools

Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote management software to establish persistent access to victims’ devices.

Both incidents, observed in August, began with phishing messages directing victims to attacker-controlled websites. The attackers then used a browser-in-the-browser (BiTB) technique to create what appeared to be a legitimate Adobe webpage, before convincing victims to download malicious software disguised as an Adobe Reader update.

Rather than deploying conventional malware, the attackers installed rogue instances of ScreenConnect, legitimate remote monitoring and management (RMM) software, giving them continued remote access to compromised endpoints.

Fake browser makes phishing harder to spot

BiTB attacks create a fake browser window inside a webpage using HTML, CSS and JavaScript. The window can replicate familiar features including an address bar, padlock and legitimate-looking URL, making traditional advice such as checking the web address less effective.

In the first attack, detected on 25 August, a victim clicked a link in a phishing email and was taken to a fake CAPTCHA page. They were subsequently presented with blurred documents and told they needed to download Adobe PDF Reader to view them.

The fake browser page appeared to show Adobe’s legitimate get.adobe.com address. However, the supposed Reader installer was actually ScreenConnect.

Once installed, the attackers deployed two rogue ScreenConnect clients, providing redundant routes for maintaining access. They then executed HideCursor.exe, a defence-evasion tool designed to conceal on-screen activity. Huntress intervened before the attack could progress further.

Second attack follows same playbook

Huntress identified another incident on 31 August involving the same Adobe Reader lure.

This time, the victim interacted with a malicious link delivered through AT&T Office@Hand, a legitimate communications service powered by RingCentral. The attackers again disguised ScreenConnect as an Adobe Reader update and installed two unauthorised instances.

The second ScreenConnect session was used to execute another defence-evasion binary, HideUL.exe. Microsoft Defender detected part of the activity, but the rogue ScreenConnect client still completed its installation before Huntress shut down the attack.

Legitimate tools remain attractive to attackers

The attacks demonstrate how threat actors can combine familiar phishing techniques with trusted software to make malicious activity harder to identify.

RMM abuse is a growing problem. Huntress’ 2026 Cyber Threat Report found RMM abuse increased 277% year on year and appeared in nearly a quarter of the incidents investigated by the company.

Huntress recommends organisations restrict who can install remote management tools, maintain an approved inventory of RMM software and monitor for new or unauthorised ScreenConnect clients. Employees should also be wary of unexpected software updates or file-viewing prompts, even when a webpage appears to display a legitimate address.

Read the full research here. 

The post Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools appeared first on IT Security Guru.

Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials

A large-scale phishing operation is abusing trusted Google services as a multi-stage redirect network to bypass email security controls, deliver highly personalized credential-harvesting pages, and, in some cases, install ScreenConnect remote-access software. The campaign’s central advantage is that it presents trusted Google-owned domains at nearly every point a gateway, proxy, or analyst is likely to […]

The post Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackaday Links: September 6, 2026

Hackaday Links Column Banner

Yesterday, Isar Aerospace secured its place in the history books when the upper stage of their Spectrum rocket put a payload of CubeSats into low Earth orbit (LEO). Not only does this make them the first European company to achieve such a feat, but it also marks the first time a booster departing from continental Europe has reached orbit. Not bad for a second attempt.

Standing 28 meters (92 feet) tall, the two-stage Spectrum rocket is just shy of half the size of the SpaceX Falcon 9 and designed to put a maximum of 1,000 kilograms (2,200 pounds) into LEO and 700 kg (1,500 lb) into the Sun-synchronous orbits used by Earth observation satellites. That puts its performance considerably ahead of other commercial launchers such as Rocket Lab’s Electron. Although the booster is not reusable, Isar Aerospace has stated they’re targeting a respectable launch cost of €10,000 ($11,700) per kilogram. The German company notes there are several more Spectrum vehicles currently in production, and when their new factory is operational, they’ll have the capacity to produce up to 40 of them each year.

In other European space news, BepiColombo has now entered what the European Space Agency (ESA) is calling the “arrival phase” of its nearly decade-long journey to Mercury. On Thursday, the spacecraft jettisoned its ion propulsion module as it had achieved the necessary trajectory and velocity to be captured by the planet’s gravitational field when it swoops by in November.

Launched in 2018, the BepiColombo mission is actually carrying two separate craft: the ESA’s Mercury Planetary Orbiter and the Mercury Magnetospheric Orbiter from Japan. After the two separate from each other in December, they will operate independently to study their respective aspects of the solar system’s innermost planet for the next year, although, as is often the case for missions like this, an extension is always possible if things are still going well at that point.

On the subject of hardware outliving its original design lifetime, an active community of hackers has done a fantastic job of keeping the Spotify Car Thing up and running after the company officially pulled the plug on it just two years after its 2022 release. They’ve got a full Linux distribution running on it featuring a slick UI that can launch apps, check the weather, tap into Home Assistant, and of course, play music. The community is currently running a contest with cash prizes to spur on development of new open source software for the liberated Car Thing, and we’re eager to see what comes of it.

The Car Thing, back when Spotify still cared.

Speaking of keeping things open, the Free Software Foundation (FSF) has joined Bluesky — but they aren’t exactly thrilled with it. Being federated and largely comprised of free and open-source software, the FSF admits that Bluesky is the lesser evil when compared to something like X or Facebook. But they still can’t recommend others join the service, as the actual signup process requires your browser to run non-free JavaScript code.

One may wonder why the FSF would join Bluesky if they can’t recommend the service to others, and the answer is simply because they want to get the word out to a wider audience. While the FSF already operates an account on Mastodon, there’s a good chance that anyone who’s willingly regularly using said platform doesn’t need any additional convincing when it comes to the evils of proprietary software.

This is as good a time as any to point out that Hackaday is on Bluesky and Mastodon as well, and unlike the FSF, we’re also on Facebook, although the automatic sharing of new posts hasn’t worked for quite some time and honestly we can’t be bothered to figure out why. For our readers with a particular aversion to grass, we’ve even got an official IRC channel on libera.chat where you and nearly 50 others can feel superior to the thousands of immoral heathens that have joined our Discord server.

Finally, it’s been 50 years since the introduction of the ColorChecker — that little card with 24 blocks of colors that’s placed in the frame of a picture or video to provide a visual reference point. In honor of the milestone, Calibrite has put together a timeline that walks you through its history, starting with its inception in the 1976 paper “A Color-Rendition Chart” by C.S. McCamy, H. Marcus, and J.G. Davidson and running up to how the handy tool evolved for the digital age.

There are plenty of facts and trivia about the ColorChecker that you can bring up the next time you want to impress a photographer, and we especially appreciated the breakdown of what each of the original 24 colors was meant to represent.


See something interesting that you think would be a good fit for our weekly Links column? Drop us a line; we’d love to hear about it.

Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud

Microsoft is developing a new security feature for Teams messaging that will obscure QR codes sent by external users. This measure aims to help organizations reduce phishing and fraud risks associated with malicious QR code campaigns. Listed under Microsoft 365 Roadmap ID 570439, this feature is currently in development and is scheduled for rollout in […]

The post Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes

QR code phishing, widely known as “quishing,” has reached record levels as threat actors increasingly conceal malicious URLs within scannable images rather than placing clickable links directly in emails. The shift is helping attackers bypass traditional secure email gateways and move victims from managed corporate devices to less-protected smartphones. The company recorded an average of […]

The post QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌