Glossary
Spoofing
The act of disguising a communication or identity — an email sender, an IP address, a phone number, or a website — to appear as though it comes from a trusted source, in order to deceive a victim or bypass a security control. It underlies many other attack techniques, including phishing, DNS spoofing, and ARP spoofing.
Recent coverage mentioning Spoofing
39 Methods Compromise Passkey Authentication: Threat Analysis
Discover 39 published methods compromising passkey authentication, focusing on ecosystem flaws, UI manipulation, and enrollment abuse.
"Phantom Deal" M&A Scams Target Large Enterprises: Averting Financial Fraud
"Phantom Deal" M&A scams target large enterprises, leveraging detailed research and social engineering to trick employees into initiating fraudulent financial transfers.
Russian Threat Clusters Abuse OAuth and WhatsApp for Espionage
Google Threat Intelligence reports three suspected Russian groups using OAuth phishing, Google app passwords, and WhatsApp device linking to hijack accounts.
Russian Threat Clusters Target Academia and Government via Auth Abuse
Google Threat Intelligence Group tracks three Russian cyber espionage clusters abusing legitimate authentication flows and app passwords.
UNC6671 Targets Financial Sector via Vishing and AiTM Phishing
UNC6671, linked to BlackFile, exploits vishing and AiTM phishing against financial firms for cloud data theft and extortion.
Microsoft & Apple Patch Critical RCEs and Auth Bypass Flaws
Microsoft released patches for critical-severity RCE and EoP flaws across Active Directory, Azure, and Teams. Apple fixed a Screen Sharing authentication bypass.
Advertisement