← Back
PhishingCisco Talos·1 week ago

Dissecting the JWR phishing framework

Cisco Talos has identified an undocumented phishing framework called JWR that is designed to impersonate checkout and login pages for major payment and shopping platforms. The framework, named internally by its developer, enables convincing phishing attacks targeting users during payment and authentication workflows. This discovery highlights an emerging threat to e-commerce users relying on legitimate-appearing payment interfaces.

Read full article at Cisco Talos

Related Articles

PhishingThe Hacker News·10 hours ago

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based. Mirage2FA Campaign

PhishingThe Hacker News·10 hours ago

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the

PhishingHelp Net Security·13 hours ago

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack

ReliaQuest confirmed that one of its employees fell victim to a social engineering attack that provided attackers with a password and temporary access to the company's identity system. Extortion group ShinyHunters subsequently posted screenshots on its leak site, claiming responsibility and taunting the cybersecurity firm over the breach. The incident followed an earlier exchange between ShinyHunters and ReliaQuest's threat research team on social media.