logo

Browser-Based Phishing: Critical New Threat

ID: 807edadc-e8d3-5f3d-968f-1005b698671b

STIX ID: report--807edadc-e8d3-5f3d-968f-1005b698671b

Feed Name: CyberNexora News

Threat Score
65/100

Date Published: 2026-09-10

Date Updated: 2026-09-11

Author: Debolina Barik

...
...

This report describes a phishing campaign that delivers DocuSign-themed lures which route victims through legitimate Microsoft infrastructure (login.microsoftonline.com and Microsoft Teams) and then assembles a fake login interface locally in the browser using blob URLs, service workers, and sandboxed iframes, making conventional URL- or domain-based defenses less effective. It highlights affected credentials, detection challenges, observed infrastructure (cdn.bloom.io), and recommended mitigations including passkeys/FIDO2, comprehensive redirect analysis, endpoint/browser monitoring, and user awareness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.