Browser-Based Phishing: Critical New Threat
ID: 807edadc-e8d3-5f3d-968f-1005b698671b
STIX ID: report--807edadc-e8d3-5f3d-968f-1005b698671b
Feed Name: CyberNexora News
This report describes a phishing campaign that delivers DocuSign-themed lures which route victims through legitimate Microsoft infrastructure (login.microsoftonline.com and Microsoft Teams) and then assembles a fake login interface locally in the browser using blob URLs, service workers, and sandboxed iframes, making conventional URL- or domain-based defenses less effective. It highlights affected credentials, detection challenges, observed infrastructure (cdn.bloom.io), and recommended mitigations including passkeys/FIDO2, comprehensive redirect analysis, endpoint/browser monitoring, and user awareness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
