Topic: push security research
-
Device Code Phishing Attacks Jump 37x with New Kits
A massive 37.5x surge in device code phishing attacks has occurred this year, exploiting a legitimate OAuth feature designed for hardware to hijack accounts and bypass multi-factor authentication. The primary driver is the EvilTokens phishing-as-a-service kit, with at least 11 distinct kits now a...
Read More » -
Beware Fake Claude Code Pages: "InstallFix" Attacks Surge
A sophisticated malware campaign uses fake installation pages, promoted via paid Google ads, to trick developers searching for the Claude Code AI tool into downloading information-stealing malware instead of the legitimate software. The attack, dubbed "InstallFix," is effective because users init...
Read More »