NEW INFOSTEALER 'STORM' BYPASSES MFA WITH SERVER-SIDE DECRYPTION
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
A new infostealer called Storm steals encrypted browser data and decrypts it on attacker-controlled servers, enabling session hijacking and password bypass. Security researchers at Varonis revealed the technique sidesteps traditional local decryption detection.
■ MORE FROM THE SECURITY DESK
Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.
Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.
Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.
Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.