Writing
phishing
2 articles on this subject.
The URL bar is not lying to you. The window around it is.
Browser-in-the-browser phishing draws a convincing fake popup inside the attacker's page. Why checking the URL does not protect users, and what does.
11 min read
MFA succeeded and the account still fell: adversary-in-the-middle phishing and session cookie theft
The phishing chain that still works against companies with MFA switched on. A reverse proxy sits in front of the real login page, the victim authenticates for real, and the attacker keeps the session cookie.
7 min read