home.social

#bitb — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #bitb, aggregated by home.social.

fetched live
  1. Waarschuwing voor "Browser in the Browser" aanvallen

    Bij een BitB-aanval toont een nepwebsite een nep pop-up-venster dat eruit ziet als een (deels of geheel) nieuw browser-venster. Gesuggereerd wordt dat u uw inloggegevens moet invoeren op bijvoorbeeld:

    https:⧸⧸accounts.google.com/signin/v3/

    maar dat is allemaal fake: door u ingevoerde nloggegevens vallen zo in handen van de eigenaar van de onderliggende website, die daarmee als u kan inloggen en uw account kan kapen.

    Mijn bron: bleepingcomputer.com/news/secu

    Onderin gist.github.com/BushidoUK/57c3 ziet u een lijst van criminele domeinnamen waar deze techniek op werd of nog wordt toegepast.

    De hieronder getoonde website is gehost bij Amazon (zie het RELATIONS tabblad van virustotal.com/gui/domain/marr). Als u zou openen (dat raad ik af):

    https:⧸⧸marriott-hiring․com

    moet u eerst een vinkje zetten, zogenaamd om te bevestigen dat u een mens bent. Daarna verschijnt het beeld dat linksonder te zien is.

    De feitelijke BitB-aanval ziet u in het 2e plaatje (meer info onder ALT).

    Nb. met een passkey is deze aanval niet mogelijk omdat de domeinnaam niet klopt. Zwakke 2FA (SMS, TOTP of Number Matching) voorkómt *niet* dat u slachtoffer wordt.

    #AmazonIsEvil #BigTechIsEvil #LetsEncryptIsEvil #BitB #Phishing #NepWebSites #ATO #AccountTakeOver #AitM #MitM

  2. Waarschuwing voor "Browser in the Browser" aanvallen

    Bij een BitB-aanval toont een nepwebsite een nep pop-up-venster dat eruit ziet als een (deels of geheel) nieuw browser-venster. Gesuggereerd wordt dat u uw inloggegevens moet invoeren op bijvoorbeeld:

    https:⧸⧸accounts.google.com/signin/v3/

    maar dat is allemaal fake: door u ingevoerde nloggegevens vallen zo in handen van de eigenaar van de onderliggende website, die daarmee als u kan inloggen en uw account kan kapen.

    Mijn bron: bleepingcomputer.com/news/secu

    Onderin gist.github.com/BushidoUK/57c3 ziet u een lijst van criminele domeinnamen waar deze techniek op werd of nog wordt toegepast.

    De hieronder getoonde website is gehost bij Amazon (zie het RELATIONS tabblad van virustotal.com/gui/domain/marr). Als u zou openen (dat raad ik af):

    https:⧸⧸marriott-hiring․com

    moet u eerst een vinkje zetten, zogenaand om te bevestigen dat u een mens bent. Daarna verschijnt het beeld dat linksonder te zien is.

    De feitelijke BitB-aanval ziet u in het 2e plaatje (meer info onder ALT).

    Nb. met een passkey is deze aanval niet mogelijk omdat de domeinnaam niet klopt. Zwakke 2FA (SMS, TOTP of Number Matching) voorkómt *niet* dat u slachtoffer wordt.

    #AmazonIsEvil #BigTechIsEvil #LetsEncryptIsEvil #BitB #Phishing #NepWebSites #ATO #AccountTakeOver #AitM #MitM

  3. Waarschuwing voor "Browser in the Browser" aanvallen

    Bij een BitB-aanval toont een nepwebsite een nep pop-up-venster dat eruit ziet als een (deels of geheel) nieuw browser-venster. Gesuggereerd wordt dat u uw inloggegevens moet invoeren op bijvoorbeeld:

    https:⧸⧸accounts.google.com/signin/v3/

    maar dat is allemaal fake: door u ingevoerde nloggegevens vallen zo in handen van de eigenaar van de onderliggende website, die daarmee als u kan inloggen en uw account kan kapen.

    Mijn bron: bleepingcomputer.com/news/secu

    Onderin gist.github.com/BushidoUK/57c3 ziet u een lijst van criminele domeinnamen waar deze techniek op werd of nog wordt toegepast.

    De hieronder getoonde website is gehost bij Amazon (zie het RELATIONS tabblad van virustotal.com/gui/domain/marr). Als u zou openen (dat raad ik af):

    https:⧸⧸marriott-hiring․com

    moet u eerst een vinkje zetten, zogenaand om te bevestigen dat u een mens bent. Daarna verschijnt het beeld dat linksonder te zien is.

    De feitelijke BitB-aanval ziet u in het 2e plaatje (meer info onder ALT).

    Nb. met een passkey is deze aanval niet mogelijk omdat de domeinnaam niet klopt. Zwakke 2FA (SMS, TOTP of Number Matching) voorkómt *niet* dat u slachtoffer wordt.

    #AmazonIsEvil #BigTechIsEvil #LetsEncryptIsEvil #BitB #Phishing #NepWebSites #ATO #AccountTakeOver #AitM #MitM

  4. Waarschuwing voor "Browser in the Browser" aanvallen

    Bij een BitB-aanval toont een nepwebsite een nep pop-up-venster dat eruit ziet als een (deels of geheel) nieuw browser-venster. Gesuggereerd wordt dat u uw inloggegevens moet invoeren op bijvoorbeeld:

    https:⧸⧸accounts.google.com/signin/v3/

    maar dat is allemaal fake: door u ingevoerde nloggegevens vallen zo in handen van de eigenaar van de onderliggende website, die daarmee als u kan inloggen en uw account kan kapen.

    Mijn bron: bleepingcomputer.com/news/secu

    Onderin gist.github.com/BushidoUK/57c3 ziet u een lijst van criminele domeinnamen waar deze techniek op werd of nog wordt toegepast.

    De hieronder getoonde website is gehost bij Amazon (zie het RELATIONS tabblad van virustotal.com/gui/domain/marr). Als u zou openen (dat raad ik af):

    https:⧸⧸marriott-hiring․com

    moet u eerst een vinkje zetten, zogenaamd om te bevestigen dat u een mens bent. Daarna verschijnt het beeld dat linksonder te zien is.

    De feitelijke BitB-aanval ziet u in het 2e plaatje (meer info onder ALT).

    Nb. met een passkey is deze aanval niet mogelijk omdat de domeinnaam niet klopt. Zwakke 2FA (SMS, TOTP of Number Matching) voorkómt *niet* dat u slachtoffer wordt.

    #AmazonIsEvil #BigTechIsEvil #LetsEncryptIsEvil #BitB #Phishing #NepWebSites #ATO #AccountTakeOver #AitM #MitM

  5. 📰 New Phishing Wave Uses Fake Browser Windows to Target Microsoft 365 Users

    ⚠️ New phishing attack targets Microsoft 365 users with 'Browser-in-the-Browser' (BitB) fakes. Attackers use realistic but fake login pop-ups to steal credentials. Stay vigilant! #Phishing #BitB #Microsoft365 #CyberSecurity

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/br

  6. Browser-in-the-Browser (BitB): Najczęstsza metoda ataku na użytkowników Facebooka w drugim półroczu 2025

    Portale społecznościowe są często wybierane przez atakujących jako źródło dystrybucji malware. Cyberprzestępcy korzystając z reklam rozsyłają treści, które pod pozorem darmowych narzędzi, sensacyjnych materiałów wideo czy też zaskakujących promocji nakłaniają użytkowników do kliknięcia w link.  Dalszy scenariusz ataku możemy sobie łatwo wyobrazić. Przejęcie konta, masowe wyłudzanie “na Blika”, utrata dostępu...

    #WBiegu #Awareness #Bitb #Facebook #Meta #Phishing

    sekurak.pl/browser-in-the-brow

  7. Browser-in-the-Browser (BitB): Najczęstsza metoda ataku na użytkowników Facebooka w drugim półroczu 2025

    Portale społecznościowe są często wybierane przez atakujących jako źródło dystrybucji malware. Cyberprzestępcy korzystając z reklam rozsyłają treści, które pod pozorem darmowych narzędzi, sensacyjnych materiałów wideo czy też zaskakujących promocji nakłaniają użytkowników do kliknięcia w link.  Dalszy scenariusz ataku możemy sobie łatwo wyobrazić. Przejęcie konta, masowe wyłudzanie “na Blika”, utrata dostępu...

    #WBiegu #Awareness #Bitb #Facebook #Meta #Phishing

    sekurak.pl/browser-in-the-brow

  8. Browser-in-the-Browser (BitB): Najczęstsza metoda ataku na użytkowników Facebooka w drugim półroczu 2025

    Portale społecznościowe są często wybierane przez atakujących jako źródło dystrybucji malware. Cyberprzestępcy korzystając z reklam rozsyłają treści, które pod pozorem darmowych narzędzi, sensacyjnych materiałów wideo czy też zaskakujących promocji nakłaniają użytkowników do kliknięcia w link.  Dalszy scenariusz ataku możemy sobie łatwo wyobrazić. Przejęcie konta, masowe wyłudzanie “na Blika”, utrata dostępu...

    #WBiegu #Awareness #Bitb #Facebook #Meta #Phishing

    sekurak.pl/browser-in-the-brow

  9. Browser-in-the-Browser (BitB): Najczęstsza metoda ataku na użytkowników Facebooka w drugim półroczu 2025

    Portale społecznościowe są często wybierane przez atakujących jako źródło dystrybucji malware. Cyberprzestępcy korzystając z reklam rozsyłają treści, które pod pozorem darmowych narzędzi, sensacyjnych materiałów wideo czy też zaskakujących promocji nakłaniają użytkowników do kliknięcia w link.  Dalszy scenariusz ataku możemy sobie łatwo wyobrazić. Przejęcie konta, masowe wyłudzanie “na Blika”, utrata dostępu...

    #WBiegu #Awareness #Bitb #Facebook #Meta #Phishing

    sekurak.pl/browser-in-the-brow

  10. Browser-in-the-Browser (BitB): Najczęstsza metoda ataku na użytkowników Facebooka w drugim półroczu 2025

    Portale społecznościowe są często wybierane przez atakujących jako źródło dystrybucji malware. Cyberprzestępcy korzystając z reklam rozsyłają treści, które pod pozorem darmowych narzędzi, sensacyjnych materiałów wideo czy też zaskakujących promocji nakłaniają użytkowników do kliknięcia w link.  Dalszy scenariusz ataku możemy sobie łatwo wyobrazić. Przejęcie konta, masowe wyłudzanie “na Blika”, utrata dostępu...

    #WBiegu #Awareness #Bitb #Facebook #Meta #Phishing

    sekurak.pl/browser-in-the-brow

  11. Sneaky2FA has added Browser-in-the-Browser (BITB) capabilities to display fake Microsoft login windows that match the victim’s OS and browser environment.

    Highlights:
    • Cloudflare Turnstile evasion
    • Conditional loading → redirects scanners
    • W3LL Panel OV6 code components
    • Heavy HTML/JS obfuscation
    • Domain rotation + URL masking

    Full breakdown: technadu.com/sneaky2fa-phishin

    Follow for more threat intel updates.

    #CyberSecurity #Phishing #BITB #Sneaky2FA #ThreatIntel #Microsoft365

  12. Sneaky2FA has added Browser-in-the-Browser (BITB) capabilities to display fake Microsoft login windows that match the victim’s OS and browser environment.

    Highlights:
    • Cloudflare Turnstile evasion
    • Conditional loading → redirects scanners
    • W3LL Panel OV6 code components
    • Heavy HTML/JS obfuscation
    • Domain rotation + URL masking

    Full breakdown: technadu.com/sneaky2fa-phishin

    Follow for more threat intel updates.

    #CyberSecurity #Phishing #BITB #Sneaky2FA #ThreatIntel #Microsoft365

  13. Sneaky2FA has added Browser-in-the-Browser (BITB) capabilities to display fake Microsoft login windows that match the victim’s OS and browser environment.

    Highlights:
    • Cloudflare Turnstile evasion
    • Conditional loading → redirects scanners
    • W3LL Panel OV6 code components
    • Heavy HTML/JS obfuscation
    • Domain rotation + URL masking

    Full breakdown: technadu.com/sneaky2fa-phishin

    Follow for more threat intel updates.

    #CyberSecurity #Phishing #BITB #Sneaky2FA #ThreatIntel #Microsoft365

  14. Sneaky2FA has added Browser-in-the-Browser (BITB) capabilities to display fake Microsoft login windows that match the victim’s OS and browser environment.

    Highlights:
    • Cloudflare Turnstile evasion
    • Conditional loading → redirects scanners
    • W3LL Panel OV6 code components
    • Heavy HTML/JS obfuscation
    • Domain rotation + URL masking

    Full breakdown: technadu.com/sneaky2fa-phishin

    Follow for more threat intel updates.

    #CyberSecurity #Phishing #BITB #Sneaky2FA #ThreatIntel #Microsoft365

  15. Sneaky2FA has added Browser-in-the-Browser (BITB) capabilities to display fake Microsoft login windows that match the victim’s OS and browser environment.

    Highlights:
    • Cloudflare Turnstile evasion
    • Conditional loading → redirects scanners
    • W3LL Panel OV6 code components
    • Heavy HTML/JS obfuscation
    • Domain rotation + URL masking

    Full breakdown: technadu.com/sneaky2fa-phishin

    Follow for more threat intel updates.

    #CyberSecurity #Phishing #BITB #Sneaky2FA #ThreatIntel #Microsoft365

  16. Cyberprzestępcy kradną konta Steam graczy CS2 za pomocą techniki Browser-in-the-Browser (BitB)

    Kilka dni temu zespół Silent Push poinformował o namierzeniu kampanii phishingowej targetującej graczy Counter-Strike 2 na Steam z wykorzystaniem techniki Browser-in-the-Browser (BitB). Technika BitB została stworzona w 2022 roku przez eksperta security mr. d0xa (na githubie wciąż udostępnia template ataku). Na czym polega? Na niektórych stronach mamy możliwość zalogowania za...

    #WBiegu #Bitb #BrowserInTheBrowser #Cyberawareness #KradzieżDanych #OSINT #Phishing #Steam

    sekurak.pl/cyberprzestepcy-kra

  17. Cyberprzestępcy kradną konta Steam graczy CS2 za pomocą techniki Browser-in-the-Browser (BitB)

    Kilka dni temu zespół Silent Push poinformował o namierzeniu kampanii phishingowej targetującej graczy Counter-Strike 2 na Steam z wykorzystaniem techniki Browser-in-the-Browser (BitB). Technika BitB została stworzona w 2022 roku przez eksperta security mr. d0xa (na githubie wciąż udostępnia template ataku). Na czym polega? Na niektórych stronach mamy możliwość zalogowania za...

    #WBiegu #Bitb #BrowserInTheBrowser #Cyberawareness #KradzieżDanych #OSINT #Phishing #Steam

    sekurak.pl/cyberprzestepcy-kra

  18. Cyberprzestępcy kradną konta Steam graczy CS2 za pomocą techniki Browser-in-the-Browser (BitB)

    Kilka dni temu zespół Silent Push poinformował o namierzeniu kampanii phishingowej targetującej graczy Counter-Strike 2 na Steam z wykorzystaniem techniki Browser-in-the-Browser (BitB). Technika BitB została stworzona w 2022 roku przez eksperta security mr. d0xa (na githubie wciąż udostępnia template ataku). Na czym polega? Na niektórych stronach mamy możliwość zalogowania za...

    #WBiegu #Bitb #BrowserInTheBrowser #Cyberawareness #KradzieżDanych #OSINT #Phishing #Steam

    sekurak.pl/cyberprzestepcy-kra

  19. Cyberprzestępcy kradną konta Steam graczy CS2 za pomocą techniki Browser-in-the-Browser (BitB)

    Kilka dni temu zespół Silent Push poinformował o namierzeniu kampanii phishingowej targetującej graczy Counter-Strike 2 na Steam z wykorzystaniem techniki Browser-in-the-Browser (BitB). Technika BitB została stworzona w 2022 roku przez eksperta security mr. d0xa (na githubie wciąż udostępnia template ataku). Na czym polega? Na niektórych stronach mamy możliwość zalogowania za...

    #WBiegu #Bitb #BrowserInTheBrowser #Cyberawareness #KradzieżDanych #OSINT #Phishing #Steam

    sekurak.pl/cyberprzestepcy-kra

  20. Cyberprzestępcy kradną konta Steam graczy CS2 za pomocą techniki Browser-in-the-Browser (BitB)

    Kilka dni temu zespół Silent Push poinformował o namierzeniu kampanii phishingowej targetującej graczy Counter-Strike 2 na Steam z wykorzystaniem techniki Browser-in-the-Browser (BitB). Technika BitB została stworzona w 2022 roku przez eksperta security mr. d0xa (na githubie wciąż udostępnia template ataku). Na czym polega? Na niektórych stronach mamy możliwość zalogowania za...

    #WBiegu #Bitb #BrowserInTheBrowser #Cyberawareness #KradzieżDanych #OSINT #Phishing #Steam

    sekurak.pl/cyberprzestepcy-kra

  21. The Boys are LIVE on this Thursday with a proper UFC London preview 🇬🇧 #BitB

    @[email protected] @[email protected]

    Come hang 🤝
    x.com/i/broadcasts/1…

  22. The Boys are LIVE on this Thursday with a proper UFC London preview 🇬🇧 #BitB

    @[email protected] @[email protected]

    Come hang 🤝
    x.com/i/broadcasts/1…

  23. US Bitcoin ETFs See Fourth Day of Outflows, Totaling $152M - U.S. spot bitcoin exchange-traded funds (ETFs) experienced another day of outflows... - news.bitcoin.com/us-bitcoin-et #u.s.spotbitcoinetfs #tradevolume #arkinvest #fidelity #outflows #finance #bitcoin #bitwise #vaneck #arkb #bitb #etfs #fbtc #hodl

  24. US Bitcoin ETFs See Fourth Day of Outflows, Totaling $152M - U.S. spot bitcoin exchange-traded funds (ETFs) experienced another day of outflows... - news.bitcoin.com/us-bitcoin-et #u.s.spotbitcoinetfs #tradevolume #arkinvest #fidelity #outflows #finance #bitcoin #bitwise #vaneck #arkb #bitb #etfs #fbtc #hodl

  25. US Bitcoin ETFs See Fourth Day of Outflows, Totaling $152M - U.S. spot bitcoin exchange-traded funds (ETFs) experienced another day of outflows... - news.bitcoin.com/us-bitcoin-et #u.s.spotbitcoinetfs #tradevolume #arkinvest #fidelity #outflows #finance #bitcoin #bitwise #vaneck #arkb #bitb #etfs #fbtc #hodl

  26. US Bitcoin ETFs See Fourth Day of Outflows, Totaling $152M - U.S. spot bitcoin exchange-traded funds (ETFs) experienced another day of outflows... - news.bitcoin.com/us-bitcoin-et #u.s.spotbitcoinetfs #tradevolume #arkinvest #fidelity #outflows #finance #bitcoin #bitwise #vaneck #arkb #bitb #etfs #fbtc #hodl

  27. US Spot Bitcoin ETFs Face Third Day of Outflows, $145 Million Drained on Monday - U.S. spot bitcoin exchange-traded funds (ETFs) experienced their third consecutive... - news.bitcoin.com/us-spot-bitco #u.s.spotbitcoinetfs #tradevolume #arkinvest #fidelity #outflows #finance #bitcoin #bitwise #vaneck #arkb #bitb #etfs #fbtc #hodl

  28. US Spot Bitcoin ETFs Face Third Day of Outflows, $145 Million Drained on Monday - U.S. spot bitcoin exchange-traded funds (ETFs) experienced their third consecutive... - news.bitcoin.com/us-spot-bitco #u.s.spotbitcoinetfs #tradevolume #arkinvest #fidelity #outflows #finance #bitcoin #bitwise #vaneck #arkb #bitb #etfs #fbtc #hodl

  29. US Spot Bitcoin ETFs Face Third Day of Outflows, $145 Million Drained on Monday - U.S. spot bitcoin exchange-traded funds (ETFs) experienced their third consecutive... - news.bitcoin.com/us-spot-bitco #u.s.spotbitcoinetfs #tradevolume #arkinvest #fidelity #outflows #finance #bitcoin #bitwise #vaneck #arkb #bitb #etfs #fbtc #hodl

  30. US Spot Bitcoin ETFs Face Third Day of Outflows, $145 Million Drained on Monday - U.S. spot bitcoin exchange-traded funds (ETFs) experienced their third consecutive... - news.bitcoin.com/us-spot-bitco #u.s.spotbitcoinetfs #tradevolume #arkinvest #fidelity #outflows #finance #bitcoin #bitwise #vaneck #arkb #bitb #etfs #fbtc #hodl

  31. Grayscale’s GBTC stops bleeding: First inflow since launch - Grayscale Investments' GBTC has seen its first day of inflows, following... - cointelegraph.com/news/graysca #franklintempleton #fbtc #bitb

  32. Grayscale’s GBTC stops bleeding: First inflow since launch - Grayscale Investments' GBTC has seen its first day of inflows, following... - cointelegraph.com/news/graysca #franklintempleton #fbtc #bitb

  33. Grayscale’s GBTC stops bleeding: First inflow since launch - Grayscale Investments' GBTC has seen its first day of inflows, following... - cointelegraph.com/news/graysca #franklintempleton #fbtc #bitb

  34. Grayscale’s GBTC stops bleeding: First inflow since launch - Grayscale Investments' GBTC has seen its first day of inflows, following... - cointelegraph.com/news/graysca #franklintempleton #fbtc #bitb

  35. ❌ Nowa scam-kampania w Polsce wykorzystująca sprytną technikę BITB. Zobacz szczegóły żeby nie dać się nabrać

    Czy widzisz w adresie na zdjęciu poniżej coś podejrzanego? …wygląda on zupełnie dobrze ✅ a mimo tego ta strona 🔴 wykrada dane. Jak to możliwe? To sprytna technika ataku o nazwie Browser In The Browser („przeglądarka w przeglądarce”). Świeżą kampanię, która wykorzystuje BITB, opisuje właśnie KNF. 1️⃣ Najpierw do ofiary...

    #Aktualności #Awareness #Bitb

    sekurak.pl/nowa-scam-kampania-

  36. ❌ Nowa scam-kampania w Polsce wykorzystująca sprytną technikę BITB. Zobacz szczegóły żeby nie dać się nabrać

    Czy widzisz w adresie na zdjęciu poniżej coś podejrzanego? …wygląda on zupełnie dobrze ✅ a mimo tego ta strona 🔴 wykrada dane. Jak to możliwe? To sprytna technika ataku o nazwie Browser In The Browser („przeglądarka w przeglądarce”). Świeżą kampanię, która wykorzystuje BITB, opisuje właśnie KNF. 1️⃣ Najpierw do ofiary...

    #Aktualności #Awareness #Bitb

    sekurak.pl/nowa-scam-kampania-

  37. ❌ Nowa scam-kampania w Polsce wykorzystująca sprytną technikę BITB. Zobacz szczegóły żeby nie dać się nabrać

    Czy widzisz w adresie na zdjęciu poniżej coś podejrzanego? …wygląda on zupełnie dobrze ✅ a mimo tego ta strona 🔴 wykrada dane. Jak to możliwe? To sprytna technika ataku o nazwie Browser In The Browser („przeglądarka w przeglądarce”). Świeżą kampanię, która wykorzystuje BITB, opisuje właśnie KNF. 1️⃣ Najpierw do ofiary...

    #Aktualności #Awareness #Bitb

    sekurak.pl/nowa-scam-kampania-