Hackers' New Phishing Tactic: Leveraging Fake Popup Login Pages, with Apple Safari Most Vulnerable
1 week ago / Read about 0 minute
Author:小编   

Recently, the security firm SquareX has unveiled a novel phishing technique dubbed "Browser in the Middle." In this method, cybercriminals craft deceptive popup login pages and exploit the browser's Fullscreen API to conceal the URL, thereby tricking users into disclosing sensitive information, including account passwords. Apple's Safari browser stands out as the most susceptible to this attack due to its absence of notifications during fullscreen transitions. In contrast, Chromium-based browsers (like Chrome and Edge) do provide brief prompts, but these are frequently overlooked by users. This sophisticated phishing method poses a grave threat to the security of user information.