>They click and land on a genuine login.microsoftonline.com page: no spoofed URL, no red flags, nothing employees were ever trained to spot.>Then it asks them to “approve” an app. One crucial click later, attackers have a foothold in that person’s email, Teams, SharePoint, OneDrive, and calendar – all without ever stealing a password.>Researchers have identified more than 200 unique phishing emails that targeted users across approximately 120 organizations in two weeks, spanning a wide range of industries and countries worldwide. And it’s not a one-off.>“This technique is already common and becoming increasingly widespread. It is a named and tracked technique in the MITRE ATT&CK framework, and in 2026, it evolved from a targeted, manually built attack into a service that virtually anyone can rent,”
>>109416003>now
>>109416003>Why is windows so easy to exploit now?
My nigger, everything is easy to exploit now thanks to AI
Doesn't their community bug reporting and bug bounty system basically fuck people over constantly? I'd imagine that + Jeet code.
>>109416003>phishing You don't even have to be a hacker to pull this off.
>>109416003>windows>“approve” an appTrain Karen in HR better, Rajesh.
Meanwhile Linux users get exploited by curling random scripts and getting malicious dependencies pulled in. Mac users get the same because they need homebrew for any serious software outside the app store.
exploit my system right now if its so easy.
>>109417152No examples? That's what I thought kid
>>109417163https://www.truesec.com/hub/blog/supply-chain-attack-compromising-arch-linux-aur-packages-infostealer-rootkit
>>109417174nooooo I dont use any of those so they dont count nooooooooooooo
>>109416465Yeah, if you report a bug, you're often not allowed to make any disclosure, including a CVE report.That's why microsoft has so little reported CVEs. And also it's poor incentives for researchers who create CVE reports for their career.
>>109417174>>109417178the most popular and active packages wouldn't have been affected since to even insert the malware into an existing package it would have to have been orphaned first
>>109416003>phishing emailswhy is linux so easy to exploit? Why is everything so easy to exploit?
>>109417199Didn't know this was an ESL thread
>>109417182Microsoft pays which is mpre than can be said for opensource shit.
>>109417208i accept your concession
>>109417217Are you that weed smoking multi-paragraph C defender guy?
>>109417209Open source rarely pays researchers, but institutions do. Here's there's a state institute that gives money when you report vulns, I heard the EU is doing something similar.The problem about these institutions is that they're not the original project developer, so people try to max out the CVE score otherwise it's not worth it.Also some companies will offer you money if you find a vuln in an open source software they use
>>109417174>BlogYour anecdotes are fake and gay kid
>>109417267It's literally from TrueSec.You asked for example, you got one and you are still complaining.
>>109417208Learn to read sukhdeep
>>109417273My dad also works for Nintendo
>>109417278>cant write>tells other people to learn to read
>>109417283Both you and your dad have natal irreversible brain damage
>>109417174>>109417206>>109417209LDS Linux derangement syndrome
>Then it asks them to “approve” an app.lmaoI suppose people aren't trained for this but apps literally read your environment's data and should be trusted about as much as installing random software on your computer.
>>109417287Learn to read sukhdeep
>>109416003Oh no no no no, wangjeet-xirsters, our response?