威胁情报|node-ipc 遭供应链入侵投毒攻击分析
本次事件是 npm 公共生态中一起典型的供应链沦陷案例。攻击者通过复用真实项目的合法发布路径,精准在 node-ipc 的 CommonJS 入口文件中注入了恶意投毒逻辑,实现了‘无交互、加载即触发’的强隐蔽、高危攻击效果。
Cybercriminals behind the Tycoon 2FA phishing kit have added a powerful new weapon to their playbook. By combining their well-known phishing infrastructure with OAuth Device Code abuse, they can now steal access to Microsoft 365 accounts without ever capturing a single password. The Tycoon 2FA phishing kit first gained attention as a Phishing-as-a-Service (PhaaS) platform. […]
The post Tycoon 2FA Operators Adopt OAuth Device Code Phishing to Bypass MFA appeared first on Cyber Security News.