TOSHIBA, MUJI SITES HIT BY FAKE LOGIN PROMPTS
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
Toshiba and Muji have alerted users to suspicious sign-in screens appearing on their websites designed to steal login credentials. The fake prompts exploit a compromised polyfill library.
■ MORE FROM THE SECURITY DESK
QBittorrent, the popular open-source torrent client, has been found capable of breaking out of sandbox environments to execute unauthorized operations. Security researchers identified the vulnerability, raising concerns about the application's access to system resources.
Threat actors are deploying invisible Unicode characters in phishing campaigns to evade email security systems. The ASCII smuggling technique allows attackers to conceal malicious content from detection tools.
A Unicode block invisible to human readers has transitioned from an academic curiosity used to test AI systems into an active tool for spammers. The technique exploits characters that machines process but humans cannot see.
A study found that 86% of licensed British gambling websites violate GDPR privacy requirements, using deceptive cookie banners to track users before obtaining consent.