Skip to content
iSec News
  • News
  • Cybercrime
  • Risk
  • Policy
  • Privacy
  • Research
  • Cloud
  • Insurance
  • LinkedIn
  • Facebook
  • Mirage2FA phishing kit uses HTML smuggling to target Microsoft 365 users

    Cloud, Cybercrime, Research, Risk
    June 26, 2026

    Fortra identified Mirage2FA, a phishing kit that uses HTML smuggling and obfuscated JavaScript to mimic Microsoft 365 sign-in pages and steal credentials during MFA prompts in an email campaign tied to cheacker[.]store.

    Mirage2FA phishing kit uses HTML smuggling to target Microsoft 365 users

Latest NEWS

  • Microsoft flags photo ZIP phishing campaign targeting hotels in Europe and Asia

    June 26, 2026
    Microsoft flags photo ZIP phishing campaign targeting hotels in Europe and Asia

  • Xsolis says phishing attack exposed data of 1.4 million people

    June 26, 2026
    Xsolis says phishing attack exposed data of 1.4 million people

  • DraftKings hacker ‘Snoopy’ gets 18 months in prison

    June 26, 2026
    DraftKings hacker ‘Snoopy’ gets 18 months in prison

  • Fake GTA 6 early access sites push crypto scam and malware, reports say

    June 26, 2026
    Fake GTA 6 early access sites push crypto scam and malware, reports say

  • Malwarebytes warns of parcel mule job scams posing as remote work

    June 26, 2026
    Malwarebytes warns of parcel mule job scams posing as remote work

  • ownCloud urges users to enable MFA after credential theft reports

    Cloud, Cybercrime, News, Vendors

    ·

    January 8, 2026
    ownCloud urges users to enable MFA after credential theft reports
  • Phishing actors spoof internal addresses by abusing complex email routing, Microsoft warns

    Cloud, Cybercrime, News, Vendors

    ·

    January 7, 2026
    Phishing actors spoof internal addresses by abusing complex email routing, Microsoft warns
  • Command injection in legacy D-Link DSL routers tracked as CVE-2026-0625 and actively exploited

    News, Vendors, Vulnerabilities

    ·

    January 7, 2026
    Command injection in legacy D-Link DSL routers tracked as CVE-2026-0625 and actively exploited
  • Two Chrome extensions exfiltrated ChatGPT and DeepSeek conversations from 900,000 users

    Cybercrime, News, Privacy, Research

    ·

    January 7, 2026
    Two Chrome extensions exfiltrated ChatGPT and DeepSeek conversations from 900,000 users
  • Unpatched TOTOLINK EX200 firmware flaw can start unauthenticated root telnet

    News, Vendors, Vulnerabilities

    ·

    January 7, 2026
    Unpatched TOTOLINK EX200 firmware flaw can start unauthenticated root telnet
Loading…Load More
iSec News
  • LinkedIn
  • Facebook
  • About
  • Editorial Policy
  • Privacy
  • Contact