Did you know there's a type of phishing attack that defeats MFA completely.
It's called a reverse proxy phishing kit and it's one of the fastest-growing attack techniques in cybersecurity.
Traditional phishing works by using fake login page. you type your password. attacker gets it. if you have MFA enabled, the stolen password alone is useless. attacker gets stopped at the second gate.
reverse proxy is different.
instead of a fake page, the attacker sets up a live proxy server between you and the real website. when you click the phishing link, you connect to the attacker's server. the server connects to the real Microsoft, Google, or Okta on your behalf. it fetches the real login page and serves it directly to you, pixel for pixel in real time.
you're looking at the actual login page. you type your real password. the proxy relays it to Microsoft. Microsoft sends back an MFA prompt. the proxy relays that to you. you approve it. Microsoft sends back a session cookie.
the proxy intercepts the cookie before it reaches your browser.
You're logged in, so is the attacker using the same session.
Tools used: Evilginx, Modlishka, Muraena. all open source. all free. all with pre-built templates for Microsoft 365, Google Workspace, Okta, and PayPal.
commercial versions: EvilProxy, Tycoon 2FA, Mamba 2FA, Starkiller. Sold as subscription services on Telegram.
Reverse proxy phishing surged 139% between September 2025 and March 2026, nearly 1 in 4 phishing links now carries a reverse proxy payload.
18 US universities hit last year. Microsoft 365 campaigns targeting thousands of organizations globally.
The only authentication method that stops this completely: FIDO2 passkeys and hardware security keys. They bind credentials to the real domain. The proxy can't replay them because the credential was never issued for the proxy's domain.
Everything else, SMS codes, authenticator apps, push notifications can all be relayed.
This paper is inaccurate slop. It makes a large number of clearly inaccurate claims about GrapheneOS and presents results which are verifiably false. It's filled with nonsense which appears AI generated. > The Clone Strikes Back: Efficient Vulnerable Code Detection in Custom Android-based Systems
The authors wrongly believe GrapheneOS has diverged from the Android Open Source Project (AOSP). The starting point for GrapheneOS is the latest stable release of AOSP with all of the AOSP security backport commits applied. Our changes to AOSP repositories are maintained as cleanly rebased patches.
Our AOSP changes are reviewed and improved on an ongoing basis. It's not only the code being improved but also commit structure. We're always preparing for porting to the next stable release. It's handled as if our AOSP changes are being prepared for submission to the project for the first time.
We start fresh with each stable release of AOSP. All our changes are ported to the new source tree. There's no merging process but rather porting and submitting the changes to the new source tree. Major changes are often required including entirely rewriting certain features for the new release.
This entire paper is based around a misconception. The authors wrongly believe we need to identify and incorporate all of the upstream changes into GrapheneOS. It's our changes we need to make sure to fully and correctly port to each new release of AOSP, not the other way around as they believe.
The authors should have seen that each of releases has all of our changes to AOSP repositories cleanly rebased on top of the latest stable release. We do make substantial changes to AOSP but it can all be reviewed as a set of patches applied on top of the latest AOSP release with zero merge commits.
Android Security Bulletins are a list privacy and security patches backported to older releases of the OS. These aren't the privacy and security fixes made in the development branch but rather incomplete backports. Far more fixes made in the development branch and the approach is often different.
Android's development branch can do major refactoring and rewrites. It can make privacy and security improvements requiring substantial changes to the code. It can fix weaknesses requiring backwards incompatible changes. The backports don't even attempt to cover Low and Moderate severity patches.
The authors of the paper took the diffs from the Android Security Bulletins and created tooling to look for the changes made by those diffs being missing. They present the findings where they manually confirmed lines of code don't appear to be present as if those are missing patches in GrapheneOS.
They should have easily figured out GrapheneOS releases are based on the latest AOSP release. They should have used their tooling on AOSP itself as a control. They would have gotten the same results for AOSP and GrapheneOS if they used versions from the same date. Instead, they're misleading people.
If they checked the latest AOSP release at the time, they would have seen there's no actual difference in what their tooling finds between AOSP and GrapheneOS. The code they identified as not present in GrapheneOS wasn't in the latest AOSP release at the time. It also doesn't show anything is wrong.
Many of the security issues fixed by Android for older releases aren't present in recent releases due to rewrites and changes to the code. Fixes in the development branch are often difficult to backport with major changes or entirely different approaches being needed. Backports are their own thing.
It's common for the initial attempt at fixing a privacy and security issue to be incomplete or incorrect. These changes sometimes even introduce new vulnerabilities. There are often multiple rounds of partial fixes. Truly fixing it often requires major changes or rewrites impractical to backport.
This paper is built around an incorrect understanding of how GrapheneOS is based on AOSP and Android's security patches. All of the patches included in Android at the time were shipped by GrapheneOS. If any of what they found was an actual issue, which is doubtful, then it was missing in AOSP too.
Aside from the incorrect premise and methodology, the paper is filled with many other inaccurate claims about GrapheneOS. Look at this example: > For instance, GrapheneOS eliminates unnecessary background processes and applies exploit-hardening techniques to reduce CPU and battery usage.
Did a human truly write that sentence? We aren't aware of any background processes we've eliminated compared to AOSP. Our exploit protections certainly don't reduce CPU, memory or battery usage. We do take great care to minimize the overhead and provide toggles for features with a substantial cost.
The paper is filled with statements which sound reasonable to non-experts but are nonsense. We wouldn't be surprised if most of the paper and code was LLM generated. There are many strong signs of it and it's hard to believe humans wrote all of this. We think it should be investigated further.
There are 4 authors listed for this. The person listed 3rd is a Senior Research Scientist in the Platforms Security and Privacy team at Google. It's published as part of the 2026 IEEE 11th European Symposium on Security and Privacy (EuroS&P). What happened here?
https://t.co/DQMsT0kZWF
Google published Android as an open source project and it succeeded based on it. For years, they've been engaging in illegal anti-competitive tactics to gain control over what was an open platform supposedly governed by a group of companies rather than Google. That includes the Play Integrity API.
Play Integrity API is pushed based on the false premise that it's a security feature. In reality, it's a core pillar of an illegal anti-competitive business model and clearly harms security. It bans GrapheneOS despite it being far more secure than anything they certify including far better patching.
This paper pushes Google's false narrative of alternatives to Google certified Android not providing standard patches and protections. A Google researcher being directly involved as an author is scandalous. The claims made by the paper about GrapheneOS are clearly false and it needs to be retracted.
The paper links to a GitHub repository with code, data and a copy of the paper. It's strange they apparently never thought to run this against the AOSP release which the GrapheneOS release they tested was based on. There are 0 differences in most of the relevant code...
https://t.co/o2bMPi8HvT
Ich habe zu lange auf Katherina Reiches neue Solar-Regeln geschaut.
Bis mir auffiel: Die Wind-Bedingungen werden komplett umgebaut.
Das stellt 6000 genehmigte Projekte infrage – ohne die die Energiewende scheitert.
Ein THREAD 🧵
Wegen diesem Video regen sich die Faschos der AfD auf. Deswegen bitte nicht teilen und verbreiten, wenn ihr Faschisten nicht ärgern möchtet.Ich poste es nur zu Dokumentationszwecken.
#AfDVerbotsverfahrenJETZT
Denmark just passed a law that every person owns a copyright to their own face, voice, and body. In the age of AI, this places more legal control in a person's hands, and there are real, large consequences and fines for breaking this law.
We need to make this worldwide.
Media outlets now cover AI with dramatic images of dark hoodies and sci fi villains, but AI isn't an autonomous entity or a magician. It's software. An AI model can't access the internet, run code, or read a database unless a human developer explicitly grants network permissions and API credentials.
Just like a software sandbox operates within a controlled test environment, AI operates strictly within human built boundaries. It just happens to be an exceedingly intelligent piece of software that can find vulnerabilities left exposed by humans. Fix the sandbox vulnerabilities and AI won’t be able to “break out”.
This dangerous narrative stems from 2 clear market plays.
First, the top 2 US AI companies want the public and politicians to view AI as so inherently dangerous that the government steps in with heavy regulatory capture. Licensing frameworks and compliance costs block open source competition, leaving the market controlled by 2 tech monopolies.
Second, vendors use manufactured panic to create a new cybersecurity category. They pitch the threat as so advanced that companies must buy additional AI protection just to defend against the original AI, even though their security reports don't read like professional security reports.
AI brings real security risks like automated phishing and data leaks, but software only does what permission structures allow. Panic sells subscriptions. Let’s be real and stop falling for these PR campaigns.
Revolut recently banned using GrapheneOS without any justification. They're falsely claiming to do be doing it for security reasons. In reality, they're enforcing licensing Google Play. Revolut doesn't enforce security standards. It runs on Android 9 with no patches since 2018.
@twidderix@Helmut_Lehmeyer Fast alles ist richtig, aber die AfD ist eben nicht rechts, sie ist auch nicht nur rechtsradikal (alles noch im Rahmen der FDGO). Die AfD ist extremistisch und damit außerhalb der FDGO. Die Wähler sollten das wissen, denn Sie setzen sich mit Ihrem ❌ gegen Deutschland ein.
🚨 BREAKING:
Francesca Albanese, UN Special Rapporteur:
"My credit card doesn't work, I can't pay bills or transfers; my health insurance was cancelled. I feel like Pablo Escobar—all because I said, 'Israel is committing genocide in Gaza.'"
La carta de Sánchez es realmente incómoda para los gobiernos europeos que han querido sacar rédito político de lo ocurrido en Ceuta.
Si España recupera el control de la situación en menos de 48 horas, devuelve a prácticamente todos los que entraron irregularmente y evita cualquier efecto sobre el resto de la UE, ¿con qué fundamento se pedía expulsarla de Schengen cuando Ceuta ni siquiera forma parte de ese espacio?
La crisis de Ceuta ha dejado al descubierto algo aún más grave. Y es que algunos “socios” europeos estaban más interesados en explotar políticamente la situación que en responder con rigor, legalidad y una mínima solidaridad común.
Interessant, was der ukrainische Außenministers Andrij Sybiha hier beschreibt: Russische Propagandanetzwerke hätten innerhalb kürzester Zeit mehr als 1.500 Beiträge über Ceuta verbreitet, um die Bilder europaweit maximal auszuschlachten.
Das ist ein bemerkenswert, denn Sybiha behauptet nicht etwa, Russland habe die Ereignisse in Ceuta verursacht. Er beschreibt vielmehr genau den Mechanismus hybrider Einflussnahme, um den es mir heute ging:
Krisen müssen nicht selbst geschaffen werden. Es genügt, vorhandene Krisen propagandistisch zu verstärken und gesellschaftliche Konflikte weiter anzuheizen, um sie für die eigenen Zwecke zu nutzen.
Letter from the Spanish Prime Minister to Ursula von der Leyen, sent today and seen by me. The three-page letter is strongly worded. Spanish premier laments what he describes as a lack of European solidarity and denounces "attacks, misinformation and prejudice" weaponised for political gain.
He lists illegal entries via Frontex showing Spain vs Italy and argues that anyone familiar with EU law would have known that Ceuta is not part of the Schengen area in the same way as mainland Spain. He says there was therefore no "technical" justification for neighbouring countries to restrict movement or reinforce border controls — that’s a reference to Italy, the Nordic countries and France.
The letter ends with an appeal to VDL and Costa to restore a common position.