Tag: Credential theft
Cybersecurity Threat Advisory: TrustSink attack targets Microsoft Entra ID
Cybersecurity Threat Advisory: TrustSink attack targets Microsoft Entra ID
TrustSink is an attack technique that abuses Microsoft Entra ID’s federated trust model. It uses a rogue MFA provider to intercept user credentials during legitimate login attempts. The attack captures plaintext passwords in real time without the user’s knowledge. Attackers...
Cybersecurity Threat Advisory: Credential-stealing RAT
Cybersecurity Threat Advisory: Credential-stealing RAT
Researchers have identified a new remote access trojan (RAT) called ChonkyChicken, which threat actors use to steal browser credentials, hijack active browser sessions, and move laterally across Windows networks. Barracuda advises organizations to focus on detection, monitoring, and security hardening,...
