Cybercriminals are building phishing pages that exist only inside victims’ browsers

LowHelp Net Security · Sinisa Markovic·

At a glance

Severity
Low
Used in attacks
No flaws named
Vendors and products
MicrosoftBarracuda
Reported by
1 outlet

A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside their own browser, according to researchers at Barracuda. “Instead of delivering a phishing page from a web server, the malicious content is assembled inside the victim’s browser using a blob URL — a temporary browser-generated URL that points to content stored locally in memory rather than on a website,” researchers explained. The attack … More → The post Cybercriminals are building phishing pages that exist only inside victims’ browsers appeared first on Help Net Security .

We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what CyberBrief adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.

Coverage

One outlet has carried this so far.

  1. Help Net SecurityEstablished SourceFirst reported

    2026-09-10 05:00 UTC

Related stories