Storm-2755 Uses AiTM Hijacking to Divert Employee Salaries
Hackers are abusing adversary-in-the-middle (AiTM) session hijacking to steal employee salaries in a new “payroll pirate” campaign tracked by Microsoft as Storm-2755 and targeting Canadian users. By h...
Related Vulnerabilities
- CVE-2026-35664: OpenClaw before 2026.3.25 contains an authentication bypass vulnerability in raw card send surface t MEDIUM
- CVE-2026-6031: A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. This affects an unkn MEDIUM
- CVE-2026-3446: When calling base64.b64decode() or related functions the decoding process would stop after encounter N/A
- CVE-2025-62718: Axios has a NO_PROXY Hostname Normalization Bypass Leads to SSRF MEDIUM
- CVE-2026-34479: The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden b MEDIUM
Related Coverage
Threat Actors