Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issuesVolume 342, Issue 2IT Vendor NewsBarracuda Networks

Threat Spotlight: Phishing Pages That Exist Only Inside the Victim's Browser

Barracuda, Wednesday, September 9th, 2026

Attackers use blob URLs so the phishing page is constructed locally, leaving no malicious site to detect or block.

Barracuda researchers analyze attacks using blob URLs to render phishing pages entirely within the victim's browser rather than hosting them on a server.

Victims are routed through legitimate Microsoft services, with the malicious workflow executed via service workers and sandboxed iframes.

The technique defeats URL reputation and web filtering because there is no malicious URL to categorize: the page is constructed locally from content that arrived through trusted infrastructure.

Detection has to move to browser behavior or email content analysis rather than destination filtering.

more →  ·  More from Barracuda Networks →