Tech

Hackers found a sneaky new way to steal your login even when it’s encrypted – here’s how they’re pulling it off

Share
Share


  • Bypasses email gateways and security tools by never hitting a real server
  • Blob URIs mean phishing content isn’t hosted online, so filters never see it coming
  • No weird URLs, no dodgy domains, just silent theft from a fake Microsoft login page

Security researchers have uncovered a series of phishing campaigns that use a rarely exploited technique to steal login credentials, even when those credentials are protected by encryption.

New research from Cofense warns the method relies on blob URIs, a browser feature designed to display temporary local content, and cybercriminals are now abusing this feature to deliver phishing pages.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
AI is making phishing emails dangerously convincing with better spelling, grammar and formatting
Tech

AI is making phishing emails dangerously convincing with better spelling, grammar and formatting

Experts warn AI-written phishing emails look polished and bypass traditional email filters...

AI-driven layoffs accelerate as companies push humans aside in favor of automation
Tech

AI-driven layoffs accelerate as companies push humans aside in favor of automation

AI threatens jobs across sectors from routine work to skilled professions CrowdStrike...