ZeroHour

Search: “vulnerability reporting”

5 stories in the last 3d

North Korean IT Workers Pay People to Sit Through Job Interviews While They Control the Computer

Silent Push found North Korean IT workers recruiting on-camera proxies for job interviews while remotely controlling the computer, defeating identity and location checks.

Silent Push researchers engaged the "Tec Guru" persona via Discord and Telegram and assessed with moderate-to-high confidence that the operator is a North Korean IT worker recruiting on-camera proxies in the US, Europe, and Latin America for a 35/65 revenue split. During Google Meet interviews, the proxy stays on camera while the real worker supplies answers via ChatGPT-generated prompts, real-time messaging, or remote-control tools such as AnyDesk and TeamViewer. Successfully placed workers can access source code, cloud tenants, and CI/CD systems, and payments create sanctions exposure; the US, Japan, South Korea, and eight other governments issued a joint identity-verification alert on July 31, 2026.

GBHackers · 1h agoPhishing & fraud in the wild 2 sources

GhostCode Abuses Microsoft Entra Device Enrollment to Maintain Access After Token Revocation

eSentire exposes GhostCode, a device-code phishing kit that abuses Microsoft Entra device enrollment to persist even after stolen tokens are revoked.

eSentire's Threat Response Unit observed GhostCode campaigns in late August 2026, using BEC-style social engineering that impersonated procurement staff, including BJ's Wholesale Club, via Salesforce contact forms. Victims received password-protected HTML lures disguised as a FlipBook document portal, with junk-data padding, HTML comment injection, and AES-256-GCM encrypted redirects gated by anti-bot checks. The kit exploits the OAuth 2.0 device authorization grant, prompting victims to approve real Microsoft device-code sign-ins with MFA. Within 78 seconds of approval, attackers registered three Entra devices and obtained a Primary Refresh Token, so rogue device registrations persist even after session token revocation.

GBHackersupdated · 23h agofirst · 1d agoPhishing & fraud in the wild 2 sources2

Smishing Triad Hackers Use JWR Phishing Kit to Steal Cards, OTPs and Bank Credentials

Group-IB attributes large-scale smishing using the JWR real-time phishing kit to the Smishing Triad's Outsider cluster, harvesting card data, OTPs, and bank credentials.

Group-IB attributes a large-scale SMS phishing campaign to Outsider, an operator sub-cluster within the Smishing Triad phishing-as-a-service ecosystem, using a kit dubbed JWR. The Vue 2-based platform maintains real-time WebSocket communication with operators, enabling them to adapt pages live and harvest roughly 70 PII fields, card data, PINs, OTPs, identity document images, and digital wallet credentials via a dedicated PayPal sub-funnel. Unit 42 previously tied 194,345 malicious domains across 136,933 root domains to the broader operation since January 2024. Defenders can hunt for /api/open/ endpoints, /webSocket/QT/ paths, JWR-prefixed storage artifacts, and a hard-coded WebSocket token.

GBHackersupdated · 1d agofirst · 1d agoPhishing & fraud in the wild 2 sources

Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters

VBSpam Q3 2026 test shows phishers abusing DKIM-aligned domains, Amazon SES, and multi-stage URL cloaking to defeat email filters.

Virus Bulletin's Q3 2026 VBSpam test (AMTSO-LS1-TP207) found phishing campaigns moving payloads past the email itself via browser-fingerprinting gates, redirect chains, and hidden POST requests. Examples include a Dutch McAfee/TotalAV scareware renewal scam, a German overdue-payment Web3 fraud delivered via Amazon SES from DKIM-aligned moolaah.com, and Romanian BCR PSD2 credential phishing embedding IPv6-mapped URLs resolving to 103.193.179.223. Net at Work NoSpamProxy ranked first with a 99.995 score while open-source Rspamd caught only 62.55% of phishing mail.

GBHackers · 2d agoPhishing & fraud in the wild 2 sources

I Hijacked a Real Artist's Spotify with AI Music. It Was Disturbingly Easynew

A journalist used DistroKid's loophole to publish an Udio-generated song on Lathe of Heaven's verified Spotify page, exposing a widespread AI music royalty scam.

A 404 Media reporter generated a punk song with Udio and, via a $3.75-per-month DistroKid account, released it under the name of Brooklyn punk band Lathe of Heaven without any identity verification by the distributor or streaming platforms. The AI-generated track appeared a day later on the band's Spotify, Apple Music, Tidal, Amazon Music and Deezer pages, with royalties flowing to the uploader. Similar abuse has hit deceased musicians such as Blaze Foley, and Spotify says artist profiles that are not actively managed are especially vulnerable.

404 Media · 22m agoPhishing & fraud in the wild