Security News

Cybersecurity news aggregator

⚔️
HIGH Attacks Help Net Security

New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials

A new Browser-in-the-Browser (BitB) phishing campaign targets Microsoft 365 users by embedding a fake browser window within a webpage to display a highly convincing, spoofed Microsoft OAuth login popup. This attack vector relies on social engineering to steal credentials directly from the rendered page. The article does not specify a software vulnerability, CVSS score, affected versions, or a patch, but advises vigilance against deceptive authentication prompts.
Read Full Article →

A new Browser-in-the-Browser (BitB) phishing campaign is targeting Microsoft 365 users with fake login popups designed to closely mimic legitimate browser authentication windows, according to Palo Alto Networks Unit 42. The attack relies on a fake browser window embedded within a webpage. Victims who click a Microsoft sign-in button are presented with what appears to be a standard authentication prompt, complete with a spoofed Microsoft OAuth URL and a login form. Phishing page displaying a … More → The post New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials appeared first on Help Net Security .

Share this article