Over 10 years we help companies reach their financial and branding goals. Engitech is a values-driven technology agency dedicated.

Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

Threat actors are exploiting Bubble.io, a legitimate no-code application platform, to host Microsoft 365 credential-harvesting pages that bypass standard email security controls. Because Bubble.io holds trusted domain reputation, phishing links evade URL reputation filters and email gateway allow-lists that would block dedicated attacker infrastructure. Kaspersky researchers (as reported by BleepingComputer) warn the technique is likely to be integrated into Phishing-as-a-Service kits, which would significantly expand the volume and reach of these attacks against any organization using Microsoft 365.

Author

Tech Jacks Solutions