Advisory
Published 2026-09-09
Verified 2026-09-19

Barracuda: DocuSign/Teams redirect phishing renders blob-URL pages inside the browser

SecurityWeek (9 September 2026) summarises Barracuda research on a phishing campaign that avoids hosting a static phishing site. Flow: DocuSign-themed email with a calendar invite, crafted redirect into Microsoft Teams, then an external resource on cdn.bloom[.]io that the browser turns into a blob URL so the phishing page exists only inside the victim browser. Service workers, iframes, and backend controls drive the session; Barracuda notes a managed platform with hidden C2 configuration. Defenders lose traditional blocklists of phishing domains — detection shifts to blob-URL browser behaviour, OAuth destination checks, and full click-path email analysis. Treat as an advisory on technique, not a named AU incident.

Product
Browser phishing / Microsoft Teams redirect abuse
Exploited in Australia?
unknown
Patch to
Monitor blob-URL browser activity; inspect OAuth destinations; email controls that follow full click paths

Primary: SecurityWeek — blob-URL phishing (9 Sep 2026; Barracuda) · Vendor: SecurityWeek (Barracuda research)

tech identity cloud