Cybercriminals are building phishing pages that exist only inside victims’ browsers
A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside their own browser, according to researchers at Barracuda. “Instead of delivering a phishing page from a web server, the malicious content is assembled inside the victim’s browser using a blob URL — a temporary browser-generated URL that points to content stored locally in memory rather than on a website,” researchers explained. The attack … More → The post Cybercriminals are building phishing pages that exist only inside victims’ browsers appeared first on Help Net Security .
We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what CyberBrief adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.
Coverage
One outlet has carried this so far.
2026-09-10 05:00 UTC
Related stories
- Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
The Hacker News · 2026-09-16
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine · 2026-09-16
- N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
The Hacker News · 2026-09-16
- Spain gets its first taste of AI-aided cyber attack
The Register · 2026-09-16
- Threat Intelligence Alone Won't Close the Exploitation Gap
The Hacker News · 2026-09-16