Visualização de leitura

Free streaming boxes may be routing criminal traffic through your home

“Free” movies and TV could cost you your privacy, bandwidth, and control of your home network.

We’ve warned about illegal streaming and modded Amazon Fire TV Sticks in the past. Now, researchers have found that certain SuperBox devices and apps could quietly enroll a household connection into a proxy network, allowing third parties to route traffic through it.

An earlier report identified CyberFlix TV, available through SuperBox’s custom app store, as containing Popanet proxy functionality that registers the device with a server controlled by the proxy operator.

Law enforcement agencies have warned that “foreign entities” are using residential proxies to conceal their identities and make their activity appear to come from someone else’s home network.

The FBI defines a residential proxy as follows:

“A residential proxy is an intermediary server between individuals and websites they visit to make their connections appear to originate elsewhere. Legitimate IP addresses assigned by an Internet Service Provider (ISP) to consumers’ Internet of Things (IoT) devices, such as TV streaming devices, digital picture frames, smartphones, tablets, and routers are used to route traffic. Once an internet-connected device is compromised, the device’s IP address can be used by threat actors to mask their online illegal activity, making the consumer appear responsible.”

Residential proxy networks rent out ordinary home IP addresses to customers. That makes their traffic appear as if it originates from a legitimate consumer connection rather than a data center, helping cybercriminals evade IP-based fraud controls and reputation systems.

Besides affecting connectivity, this can mean that a household’s public IP address becomes associated with activity it did not initiate, ranging from credential stuffing and account abuse to attempts to bypass enterprise security controls.

Plume’s more recent research warns that these proxy networks can also function as malware-delivery platforms. In other words, attackers may not only use a compromised streaming box as an exit node. They may use the proxy connection to reach the box itself and install additional malicious software.

The reported SuperBox configuration is especially troubling because it disables or weakens multiple Android safeguards. Researchers found exposed Android Debug Bridge (ADB) access, root-level privileges without authentication, and the removal of protections that would normally restrict untrusted app installation or prompt users to approve risky actions.

Many people assume that placing a streaming device behind a home router prevents outside access. Normally, network address translation and a firewall do make unsolicited inbound connections more difficult. But proxy-enabled devices can maintain an encrypted outbound connection to a remote server, creating a channel that the home router treats as legitimate traffic initiated from inside the network.

How to stay safe

The safest option is not to connect devices or install apps that promise unauthorized access to free movies and TV. You could be bringing a proverbial Trojan horse into your home.

If you own a SuperBox device or have installed CyberFlix TV, disconnect the device from your network. A factory reset may not be enough to make it safe to use again, so you should replace it.

When a device’s business model depends on monetizing your connection, its security choices can put your IP address, bandwidth, privacy, and local network at risk.

Network segmentation can reduce exposure for ordinary Internet of Things (IoT) devices, but it is not a complete answer here. A product that intentionally establishes a persistent proxy channel and offers weak device-level protection should not be trusted on a household network, even on a separate guest network.


From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Project ORBITAL

Introduction

The modern cyber threat landscape has seen a fundamental shift in how threat actors manage and deploy their infrastructure. Advanced persistent threats (APTs) have almost completely moved away from static command-and-control (C2) servers, opting instead to build complex, multi-layered botnets known as Operational Relay Box (ORB) networks. 

Project ORBITAL (which stands for Operational Relay Box Intelligence, Tracking, & Analysis Lexicon) was established as a centralised intelligence matrix to track, analyse, and ultimately help defenders disrupt this highly evasive infrastructure.

To construct these networks, adversaries systematically compromise unpatched, end-of-life devices. By targeting legacy, unpatched Small Office/Home Office (SOHO) router and Internet-of-Things (IoT) devices attackers can create a sprawling, decentralised mesh of proxy nodes. By routing their operations through layers of compromised devices, adversaries mask their true origins, making malicious activity blend seamlessly with legitimate regional traffic.

Blogs by my colleagues at Team Cymru as well as Google offer detailed explanations as to why and how these ORBs have grown over many years and continue to expand.

Project Background

Project ORBITAL represents a centralised Open Source Intelligence (OSINT) collection driven by public reporting from advanced research teams across the cybersecurity and technology sectors. This initiative aggregates telemetry and findings from top-tier vendors including Cisco Talos, CrowdStrike, Google, GreyNoise Labs, Lumen Black Lotus Labs, Microsoft, SecurityScorecard, Sekoia, SentinelLabs, Sygnia, and Team Cymru. Furthermore, it incorporates critical alerts and intelligence shared publicly by United States government agencies, specifically the Federal Bureau of Investigation (FBI), the Cyber National Mission Force (CNMF), and the National Security Agency (NSA).

This repository builds on the methodology of my previous OSINT tracking initiatives. It is heavily inspired by the structure and community success of my earlier matrix projects, specifically the Ransomware Tool Matrix (RTM) (here), the Ransomware Vulnerability Matrix (RVM) (here), and the Russian APT Tool Matrix (RUTM) (here). By applying a similar, structured approach to mapping Operational Relay Box (ORB) networks, this project aims to provide defenders with a clear, actionable lexicon for hunting and tracking evasive edge-device botnets.

Graph Visualisation

Once Project ORBITAL was initially assembled, it was then possible to use a GitHub Action automation with NetworkX and PyVis to create a Graph Visualisation using the data collected. Once in this view, some interesting patterns could be observed.

Analysis of the extracted data uncovered that ASUS devices were the most targeted out of all of the targeted devices by ORBs from the public reports.

Another interesting point the graph highlighted is that the LapDogs ORB network had the highest number of reported targeted devices.  

In most reported scenarios, a singular threat group used a dedicated ORB network. However, from extracting the details from the Google and SentinelLabs reports, an adversary like APT15, reportedly leverages both SPACEHOP and PurpleHaze ORB networks, alongside two other separate adversaries UNC2630 and UNC5174.

The overlap in ORB usage suggests these APTs aren't all building their own botnets from scratch. These overlaps likely indicate there are provisioning teams, such as specialised contractors, like Beijing Integrity Tech, who build and maintain these ORB networks and then lease access to the broader Chinese intelligence community in the Ministry of State Security (MSS) and People’s Liberation Army (PLA).

Panda-monium

Below is the list of well-known China-nexus APTs listed using CrowdStrike’s naming scheme and their Google or Microsoft aliases that are all mentioned in Project ORBITAL.

  1. CAULDRON PANDA (aka UNC3886)
  2. ETHEREAL PANDA (aka Flax Typhoon)
  3. JUDGMENT PANDA (APT31, Violet Typhoon)
  4. KEYHOLE PANDA (aka UNC2630, APT5)
  5. MURKY PANDA (aka Silk Typhoon)
  6. VANGUARD PANDA (aka Volt Typhoon)
  7. VIXEN PANDA (aka APT15, Nylon Typhoon) 

The most notable aspect about this list is that it contains APTs with wildly different mandates. VANGUARD PANDA (Volt Typhoon) is famous for pre-positioning within critical infrastructure with the potential disruptive attacks, while KEYHOLE PANDA (APT5) and JUDGMENT PANDA (APT31) are long-running cyber-espionage and IP theft operators. The fact that both the saboteurs and the spies have all adopted ORB networks goes to show that this tactic is not niche but instead is the baseline standard for Chinese APT operational security (OPSEC).

How to Access

You can find Project ORBITAL on my GitHub repository below:


Residential Proxy Risks: Understanding Google’s Latest Action Against 2 Million Strong NetNut

Google announced that it helped take down NetNut, a 2 million strong malicious residential proxy network. The incident highlights the growing risks posed by residential proxy networks that quietly conscript consumer devices into services used by cybercriminals and nation-state actors alike.

The post Residential Proxy Risks: Understanding Google’s Latest Action Against 2 Million Strong NetNut appeared first on The Security Ledger with Paul F. Roberts.

NetNut botnet takes a hit. Don’t be part of the next one.

In a joint operation, Google, the FBI, and other partners have dealt a significant blow to the residential proxy ecosystem by disrupting the NetNut (also tracked as Popa) botnet.

NetNut is a malicious service built on millions of hijacked consumer devices. NetNut marketed itself as a high-quality residential proxy provider, selling access to “real” home IP addresses for web data collection and other benign-sounding use cases.

The FBI’s definition of a residential proxy:

“A residential proxy is an intermediary server between individuals and websites they visit to make their connections appear to originate elsewhere. Legitimate IP addresses assigned by an Internet Service Provider (ISP) to consumers’ Internet of Things (IoT) devices, such as TV streaming devices, digital picture frames, smartphones, tablets, and routers are used to route traffic. Once an internet-connected device is compromised, the device’s IP address can be used by threat actors to mask their online illegal activity, making the consumer appear responsible.”

The most common method used to add devices to the NetNut network was to  trick users into installing “bandwidth sharing” or proxyware apps that promised payouts for “sharing your unused internet” but buried the true risks in fine print or skipped meaningful consent altogether. Less commonly, devices are sold pre-compromised through grey-market supply chains and shipped with malicious firmware or side-loaded apps.

Once enrolled, these devices could be used to relay password-spraying attacks, account takeover attempts, advertising fraud, and even Mirai-variant DDoS attacks.

The disruption focused on three levers: disabling Google accounts used for NetNut’s command-and-control (C2), sharing detailed indicators on NetNut’s SDKs and infrastructure with platforms and law enforcement, and using Google Play Protect to warn users and automatically disable apps that included NetNut code.

Reportedly, this has significantly disrupted the NetNut botnet, reducing the available pool of devices for the proxy operator by millions.

How to stay safe

A typical home user is unlikely to notice that their devices are part of the NetNut botnet, although they may experience slower performance, reduced internet speeds, faster battery drain, and additional wear and tear on affected devices.

After this blow, the botnet’s operators will likely try to rebuild their network by compromising new devices, or another botnet may take its place. So it’s important to stay vigilant. Some basic tips:

  • Be extremely wary of apps that pay you for unused bandwidth.
  • Stick to official app stores.
  • Check VPN and proxy permissions on your devices.
  • Favor reputable, Play Protect–certified vendors for connected devices.
  • Use an up-to-date, real-time anti-malware solution on devices that are eligible.
Malwarebytes blocks netnut.com
Malwarebytes blocks netnut.com

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

Peter Thiel ‘s Secret Society Leak Creates a Perfect Target List for Espionage, Influence Operations, and Blackmail

A simple website flaw exposed members, political profiles, login tokens, and dating data from Peter Thiel ‘s secretive Dialog network.

Dialog, a private invitation-only organization cofounded in 2006 by billionaire tech investor Peter Thiel, has spent two decades refusing to disclose its membership. That position became harder to maintain last week when Swiss hacktivist maia arson crimew, known for exposing the US government’s No Fly List, found an open directory embedded in the source code of dialog.org that was visible to anyone who viewed the page. WIRED independently verified the contents and obtained the registration list for Dialog’s 2026 retreat, scheduled for August 12-16 near Dublin, Ireland.

“A trove of internal records from a secret society for powerful figures in US politics, finance, and tech was left exposed online, WIRED has confirmed, naming participants in its events and revealing sensitive personal details they were assured would stay private.” reported Wired. “The group, called Dialog, is a private, invitation-only organization cofounded in 2006 by the billionaire tech investor Peter Thiel. It convenes US officials, foreign government figures, and Silicon Valley executives at off-the-record annual retreats.”

The 2026 list names 222 registrants, 87 of them first-time attendees. Others have histories stretching back more than a decade, a handful to the founding itself. None used a government email address, placing their attendance outside public records laws.

The roster is not a list of adjacent power. It’s power in direct regulatory relationship with itself. Treasury Secretary Scott Bessent appears alongside Auren Hoffman, Dialog’s chairman, who founded location-data broker SafeGraph and identity-resolution firm LiveRamp. Senator Ted Cruz, who chairs the committee overseeing the FTC and its data-privacy authority, is listed in the same directory. Palantir cofounder Joe Lonsdale, whose software runs case management for ICE and data fusion for the Pentagon, appears alongside Army Secretary Dan Driscoll and Representative Jim Himes, ranking member of the House Intelligence Committee, which oversees agencies Palantir contracts with.

Forbes confirmed additional members including investor Marc Andreessen and investor and former Facebook board member Jim Breyer.

General Alexus Grynkewich, NATO’s supreme allied commander Europe and head of US European Command, is recorded as having attended Dialog gatherings since 2021.

The session agenda for the 2026 retreat includes “Navigating WWIII,” “Battlefield Technologies,” “Bring Back Nuclear,” and “Build-a-Cult,” the last moderated by the founder of the Christian networking site Pray.com. There’s also “How’s Your Sex Life?” which presumably has a different moderator.

“The website directory names sitting Trump administration officials, two US senators, six members of the Paypal Mafia, a former Middle East chief of intelligence, and a sitting ambassador to the United States, along with the founders and directors of many of the country’s largest surveillance, data-broker, and advertising-data companies.” Wired continues.

The leaked registration list adds names not in the public directory of 113: Randy Kroszner, former Federal Reserve governor now on the Bank of England’s Financial Policy Committee; Jonathan Greenblatt, CEO of the Anti-Defamation League; Ryan Stowers, executive director of the Charles Koch Foundation; Roger Myerson, Nobel laureate economist; and a cluster of Google and Google DeepMind executives including Tom Lue, who leads global affairs for the frontier AI division.

The data breach is structurally embarrassing because it was entirely avoidable. The directory was served to any visitor who viewed the page’s source code. A separate Dialog page at app.dialog.org presents a sign-in screen with no terms of service, no indication the application is restricted, and no invitation requirement. The records sat in Airtable, a commercial database, and included for each participant their membership status, every retreat attended, biography, home city, and a private access token functioning as a login credential.

Dialog also runs a matchmaking service. Its registration form asks whether participants are “looking for love” and offers to include single respondents in “future matchmaking.” A separate site at dating.dialog.org hosts an app pitched as “meaningful connections for exceptional people.” The form also collects each registrant’s political leaning, which Dialog promised would never be shared.

“That data, and the matchmaking responses, were exposed in the leak.” concludes Wired.

The data collected by Dialog could be valuable for criminals or intelligence agencies because it reveals personal vulnerabilities, relationship status, political views, and access to influential networks. Such information can support targeted phishing, social engineering, honey-trap operations, blackmail, or influence campaigns. The risk is amplified because participants are often members of the global elite, making them attractive intelligence targets. Many may be highly accomplished in their fields but still willing to share sensitive personal details in trusted environments, creating opportunities for manipulation and exploitation.

An internal guide for event moderators, also found in the exposed directory, instructs them to remind participants that everything is off the record, keep comments concise and “nonobvious,” and model brief introductions to “avoid status signaling” in a room full of senators, dignitaries, and tycoons. The discipline imposed on members apparently didn’t extend to basic website security.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Peter Thiel)

Hackers Exploit Butter Network Bridge to Mint Massive MAPO Supply

MAPO token

The cryptocurrency market witnessed another major security breach this week after the MAPO token collapsed by 96% following an exploit tied to the Butter Network cross-chain bridge. The incident resulted in the unauthorized minting of a quadrillion MAPO tokens, flooding the market with a supply vastly larger than the legitimate circulating amount and causing severe disruption across decentralized finance ecosystems connected to ETH and other blockchains.  According to blockchain security researchers, the exploit enabled the attacker to generate tens of thousands of times more MAPO tokens than the official supply. As panic selling intensified, the price of the Map Protocol token dropped from nearly $0.003 to around $0.0001 within hours, based on market tracking data from CoinGecko. 

Attacker Drains ETH From Liquidity Pools 

The attack primarily targeted the Butter Network bridge infrastructure, a cross-chain protocol associated with Map Protocol. Security platform Blockaid reported that the exploiter used a newly created externally-owned account (EOA) to offload approximately one billion MAPO tokens into decentralized exchanges.  During the process, the attacker reportedly drained nearly 52 ETH from Uniswap liquidity pools, an amount valued at roughly $180,000 at the time of the incident. Despite the liquidation of a portion of tokens, blockchain analysts noted that the attacker still retained close to a trillion MAPO tokens.  Those remaining holdings continue to create risks for additional liquidity pools and potential exchange listings linked to the Map Protocol token ecosystem. The sudden flood of tokens severely impacted market confidence and highlighted ongoing vulnerabilities within cross-chain bridge infrastructure. 

MAPO Exploit Adds to Growing List of DeFi Attacks 

The exploit comes during an already damaging month for decentralized finance projects. Reports indicate that at least 18 DeFi and blockchain protocols have been compromised in recent weeks. Among the affected projects are THORChain, Verus Protocol, Transit Finance, TrustedVolumes, Ekubo, Echo Protocol, and RetoSwap.  The repeated attacks have intensified concerns surrounding interoperability protocols, especially those handling assets across ETH, Bitcoin, and other blockchain ecosystems. Cross-chain bridges remain frequent targets because of the complexity involved in validating transactions between multiple networks. 

Map Protocol Pauses Mainnet Operations 

In response to the breach, Map Protocol confirmed that the vulnerability originated in the Solidity contract layer. The project announced that it had paused its mainnet and initiated a migration process while the investigation continues. Butter Network also suspended ButterSwap operations, although the team stated that user funds were not directly at risk. In its latest statement, the Map Protocol team said it would announce a new contract address and later conduct an asset snapshot. The project added that “any remaining tokens held by attacker-controlled addresses will be fully invalidated and will not be included in any future snapshot or conversion process.” Blockchain data further revealed that approximately one billion MAPO tokens were transferred to Uniswap shortly after the quadrillion-token mint occurred.

How the MAPO Mint Exploit Happened 

Security researchers later outlined how the attack unfolded. According to Blockaid, the attacker initially submitted a legitimate oracle multisig-signed message before deploying a malicious smart contract at a carefully chosen address. The exploiter then resent a modified “retry” message that appeared identical in transaction hash but had actually been manipulated. Because the cross-chain bridge incorrectly verified the altered message as authentic, the system approved the minting of the massive MAPO supply. Researchers stressed that no private keys were stolen and no light clients were compromised during the attack. Instead, the incident was described as a “classic Solidity vulnerability involving multiple dynamic fields.”  The exploit once again demonstrated how weaknesses in smart contract validation can place both MAPO and ETH liquidity ecosystems at risk.

Introducing Wallarm Middle East Cloud: Built for Data Residency Compliance

As API and AI adoption grows across the Middle East, so do the expectations around how data is handled. For many organizations operating in this region, it’s not just about securing applications. It’s about doing it in a way that keeps data in-country and aligned with local requirements. Today, we’re introducing the Wallarm Middle East [...]

The post Introducing Wallarm Middle East Cloud: Built for Data Residency Compliance appeared first on Wallarm.

The post Introducing Wallarm Middle East Cloud: Built for Data Residency Compliance appeared first on Security Boulevard.

Sandhills Medical Foundation Ransomware Breach Draws Class Action Investigation Nearly a Year Later

What happened A ransomware attack on Sandhills Medical Foundation, a Federally Qualified Community Health Center in McBee, South Carolina, is now the subject of a class action investigation, nearly a year after the incident was first discovered. Sandhills Medical discovered the ransomware attack on May 8, 2025. A forensic investigation determined that an unauthorized third […]

The post Sandhills Medical Foundation Ransomware Breach Draws Class Action Investigation Nearly a Year Later appeared first on CISO Whisperer.

The post Sandhills Medical Foundation Ransomware Breach Draws Class Action Investigation Nearly a Year Later appeared first on Security Boulevard.

Telegram Mini Apps Abused for Crypto Scams and Android Malware Delivery

What happened CTM360 researchers have uncovered a large-scale fraud operation using Telegram’s Mini App feature to run cryptocurrency scams, impersonate major brands, and distribute Android malware. The platform behind the operation, dubbed FEMITBOT based on a string found in API responses, uses Telegram bots and embedded Mini Apps to create convincing app-like experiences within the […]

The post Telegram Mini Apps Abused for Crypto Scams and Android Malware Delivery appeared first on CISO Whisperer.

The post Telegram Mini Apps Abused for Crypto Scams and Android Malware Delivery appeared first on Security Boulevard.

Frost Bank Hit With Class-Action Lawsuits Over Data Breach Affecting More Than 100,000 Customers

What happened Frost Bank, San Antonio’s largest bank, is facing two proposed class-action lawsuits following a cyberattack attributed to the Everest ransomware group that allegedly exposed the sensitive personal data of an estimated 109,000 customers. The bank has not publicly confirmed the scope of the breach or reported it to the Texas Attorney General’s Office, […]

The post Frost Bank Hit With Class-Action Lawsuits Over Data Breach Affecting More Than 100,000 Customers appeared first on CISO Whisperer.

The post Frost Bank Hit With Class-Action Lawsuits Over Data Breach Affecting More Than 100,000 Customers appeared first on Security Boulevard.

Salt Typhoon Suspected in Breach of IBM Italy Subsidiary Managing Public Infrastructure

What happened A cybersecurity incident in late April 2026 targeted Sistemi Informativi, an Italian company wholly owned by IBM Italy that provides IT infrastructure management for public agencies and key private sector organizations. IBM confirmed the breach through an official statement, acknowledging it had identified and contained a cybersecurity incident and activated incident response protocols […]

The post Salt Typhoon Suspected in Breach of IBM Italy Subsidiary Managing Public Infrastructure appeared first on CISO Whisperer.

The post Salt Typhoon Suspected in Breach of IBM Italy Subsidiary Managing Public Infrastructure appeared first on Security Boulevard.

Threat Actors Use AI to Automate Zero-Day Discovery and Exploitation at Machine Speed

What happened Cyberthint analysts have documented a structural shift in how cyberattacks are conducted, with threat actors now using artificial intelligence to discover and exploit zero-day vulnerabilities in minutes rather than months. The firm identified this transition in late 2024, noting that AI is operating not just as a research assistant but as an active […]

The post Threat Actors Use AI to Automate Zero-Day Discovery and Exploitation at Machine Speed appeared first on CISO Whisperer.

The post Threat Actors Use AI to Automate Zero-Day Discovery and Exploitation at Machine Speed appeared first on Security Boulevard.

Microsoft Defender Mistakenly Flags DigiCert Root Certificates as Malware

What happened A faulty Microsoft Defender antimalware signature update released around April 30, 2026, caused widespread false positive alerts by incorrectly flagging two legitimate DigiCert root certificates as high-severity malware. The detection, labeled Trojan:Win32/Cerdigent.A!dha, identified registry entries belonging to DigiCert Assured ID Root CA and DigiCert Trusted Root G4 as threats and automatically quarantined them […]

The post Microsoft Defender Mistakenly Flags DigiCert Root Certificates as Malware appeared first on CISO Whisperer.

The post Microsoft Defender Mistakenly Flags DigiCert Root Certificates as Malware appeared first on Security Boulevard.

CISO Diaries: Victor-Andrei Nicolae on Practical Security, Patience, and AI-Driven Defense

Security leadership is often associated with emerging threats and advanced technologies, but much of the role comes down to disciplined execution, thoughtful decision-making, and balancing protection with business continuity. In CISO Diaries, we speak with leading CISOs around the world to understand what the role actually looks like beyond frameworks and incident headlines, how security […]

The post CISO Diaries: Victor-Andrei Nicolae on Practical Security, Patience, and AI-Driven Defense appeared first on CISO Whisperer.

The post CISO Diaries: Victor-Andrei Nicolae on Practical Security, Patience, and AI-Driven Defense appeared first on Security Boulevard.

1,800 Developers Hit in Mini Shai-Hulud Supply Chain Attack Across PyPI, NPM, and PHP

What happened A supply chain attack campaign attributed to TeamPCP, dubbed Mini Shai-Hulud, has compromised packages across the PyPI, NPM, and PHP ecosystems over a two-day period, affecting over 1,800 developer repositories containing stolen credentials. The campaign was first identified on April 29 when malicious versions of four SAP NPM packages were caught delivering information-stealing […]

The post 1,800 Developers Hit in Mini Shai-Hulud Supply Chain Attack Across PyPI, NPM, and PHP appeared first on CISO Whisperer.

The post 1,800 Developers Hit in Mini Shai-Hulud Supply Chain Attack Across PyPI, NPM, and PHP appeared first on Security Boulevard.

ConsentFix v3 Automates OAuth Abuse to Bypass MFA and Hijack Azure Accounts

What happened A third iteration of the ConsentFix attack technique has been circulating on hacker forums, introducing automation and scalability to a method that abuses Microsoft Azure’s OAuth2 authorization code flow to hijack accounts without passwords and despite multi-factor authentication being enabled. The original ConsentFix was documented by Push Security in December 2025 as an […]

The post ConsentFix v3 Automates OAuth Abuse to Bypass MFA and Hijack Azure Accounts appeared first on CISO Whisperer.

The post ConsentFix v3 Automates OAuth Abuse to Bypass MFA and Hijack Azure Accounts appeared first on Security Boulevard.

❌