Hackers found a sneaky new way to steal your login even when it’s encrypted – here’s how they’re pulling it off

Estimated read time 3 min read




  • Bypasses email gateways and security tools by never hitting a real server
  • Blob URIs mean phishing content isn’t hosted online, so filters never see it coming
  • No weird URLs, no dodgy domains, just silent theft from a fake Microsoft login page

Security researchers have uncovered a series of phishing campaigns that use a rarely exploited technique to steal login credentials, even when those credentials are protected by encryption.

New research from Cofense warns the method relies on blob URIs, a browser feature designed to display temporary local content, and cybercriminals are now abusing this feature to deliver phishing pages.



Source link

You May Also Like

More From Author

+ There are no comments

Add yours