Cybersecuritynews iconCybersecuritynewsSep 10, 2026

Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers

Rather than sending people to a malicious website, its operators use browser-generated blob URLs to assemble the page in local memory, leaving less for security tools to inspect before it appears. The operation starts with a DocuSign-themed email carrying a calendar invitation.

Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers

Share this story

Send the public story page.

Useful takeaways from this story.

Rather than sending people to a malicious website, its operators use browser-generated blob URLs to assemble the page in local memory, leaving less for security tools to inspect before it appears.

The operation starts with a DocuSign-themed email carrying a calendar invitation.

A new phishing campaign is moving fake login pages into victims' browsers.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

Rather than sending people to a malicious website, its operators use browser-generated blob URLs to assemble the page in local memory, leaving less for security tools to inspect before it appears. The operation starts with a DocuSign-themed email carrying a calendar invitation. A new phishing campaign is moving fake login pages into victims' browsers.

What to take from it

A new phishing campaign is moving fake login pages into victims' browsers.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app