news.mlab.sh
Back to the feed
threat-intel

Curiouser and Curiouser

High
Image: Cisco Talos
Summary

Cisco Talos has identified "JWR", a new phishing framework and variant of "The Outsider" as a service, used to steal payment data, 2FA codes, and device fingerprints via SMS lures impersonating regional authorities. The framework is operator-driven in real-time, allowing attackers to bypass MFA by prompting for 2FA codes when needed. JWR is particularly effective due to its integration with e-commerce platforms like Shopify. The article also highlights other security news, including a ransomware attack on the Colombian Justice Ministry, a North Korean IT staffer working for a U.S. agency, and a Microsoft SharePoint exploit.

Read the full article at Cisco Talos

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.