A new attack technique named ConsentFix v3 has emerged, automating the hijacking of Microsoft Azure accounts through sophisticated phishing methods. This attack builds on previous versions by enhancing automation and…
Cybercriminals are exploiting two attack methods, ConsentFix and ClickFix, to hijack Microsoft 365 accounts in as little as three seconds. These attacks leverage users' habitual online behaviors, such as dragging links…
A ClickFix-style malware campaign was detected spreading through a sponsored ad on X, originating from a verified account. The ad masqueraded as the legitimate Mac app DynamicLake, leading users to a malicious domain,…