Category: ➽News
-

Brand Protection Software: What Click2Shell Means for WordPress
Brand protection software can help organizations maintain visibility into phishing and impersonation risks, but the newly disclosed WordPress Click2Shell vulnerability highlights a different part of the attack surface: the website itself. The flaw can allow an attacker to achieve server-side PHP execution through a chain involving a logged-in administrator, a maliciously crafted link, and WordPress…
-

Brand Protection Software: WaterPlum’s 30,000-Device Campaign
Brand protection software is not a substitute for endpoint security, but it can provide another layer of visibility when threat actors use trusted identities, recruiting platforms, and online infrastructure to reach victims. The latest WaterPlum campaign shows why that broader view matters. A joint advisory from authorities in Japan, the United States, Australia, and Germany…
-

Domain Spoofing Protection After Parallels Desktop Flaw
Domain spoofing protection is normally discussed in the context of phishing, fake websites, and brand impersonation, but the latest Parallels Desktop vulnerability highlights a different part of the security chain. Researchers have disclosed a local privilege-escalation flaw that can allow an unprivileged macOS user to execute code with root privileges on affected installations of Parallels…
-

Threat Intelligence Platform: Chrome Zero-Day Attack
Threat intelligence platform visibility is becoming increasingly important as attackers combine browser exploits, phishing, and operating-system vulnerabilities in a single intrusion chain. A campaign recently documented by Volexity shows how a Chrome zero-day could be paired with a Windows kernel vulnerability to move from an initial phishing interaction toward deeper control of a targeted system.…
-

Threat Intelligence Platform: Claude and 1.8M Android Apps
Threat intelligence platform capabilities are becoming increasingly relevant as attackers use AI to automate security research at a scale that would previously have required substantial manual effort. Anthropic reported in September 2026 that multiple threat groups abused Claude during malicious cyber operations, including an operation in which 1.8 million Android application packages were downloaded and…
-

Spoofing Detection: CAPTCHA and WebDAV Malware Abuse
Spoofing detection is becoming increasingly important as attackers combine familiar brands, compromised websites, legitimate cloud services and unconventional delivery infrastructure to distribute malware. A campaign analyzed by Cisco Talos and reported by GBHackers uses a fake Google CAPTCHA, ClickFix social engineering, WebDAV, Cloudflare Workers and BNB Smart Chain smart contracts to deliver the Amatera information…
-

Domain Spoofing Protection: BigBear MFA Phishing Explained
Domain spoofing protection has become increasingly relevant as phishing operations move beyond simple fake login pages. On September 7, 2026, BleepingComputer reported that a phishing-as-a-service framework called BigBear 2.0 had been used to bypass MFA at 258 organizations and capture more than 5,000 Microsoft 365 credential records, based on research by CloudSEK. The incident demonstrates…
-

Domain Spoofing Protection: Detect Invisible Unicode Phishing
Domain spoofing protection is increasingly relevant as attackers use invisible Unicode characters to conceal phishing lures from automated security controls. Microsoft reported in September 2026 that researchers observed a high-volume phishing campaign using invisible Unicode tag characters to split words and interfere with content detection. The technique is not entirely new, but the campaign demonstrates…
-

Phishing Detection: Mirage Kitten’s Fake Coding Tests
Phishing detection has taken on a new dimension as Mirage Kitten has been linked to a campaign that disguises malware as legitimate software-development assessments. According to research published by Kaspersky on September 1, 2026, the activity uses fake recruiter personas, trojanized coding challenges, and two previously undocumented cross-platform remote access trojans (RATs), NodeRabbit and PollCat.…
-

Domain Spoofing Protection After the TanStack npm Attack
Domain spoofing protection is becoming increasingly relevant to software supply-chain incidents because stolen developer credentials can create risks that extend beyond the original compromised workstation. In August 2026, security researchers reported a supply-chain worm affecting multiple releases of @7nohe/openapi-react-query-codegen, a package that generates TanStack Query hooks from OpenAPI schemas. The incident involved credential theft and…