Barracuda: DocuSign/Teams redirect phishing renders blob-URL pages inside the browser
SecurityWeek (9 September 2026) summarises Barracuda research on a phishing campaign that avoids hosting a static phishing site. Flow: DocuSign-themed email with a calendar invite, crafted redirect into Microsoft Teams, then an external resource on cdn.bloom[.]io that the browser turns into a blob URL so the phishing page exists only inside the victim browser. Service workers, iframes, and backend controls drive the session; Barracuda notes a managed platform with hidden C2 configuration. Defenders lose traditional blocklists of phishing domains — detection shifts to blob-URL browser behaviour, OAuth destination checks, and full click-path email analysis. Treat as an advisory on technique, not a named AU incident.
- Product
- Browser phishing / Microsoft Teams redirect abuse
- Exploited in Australia?
- unknown
- Patch to
- Monitor blob-URL browser activity; inspect OAuth destinations; email controls that follow full click paths
Primary: SecurityWeek — blob-URL phishing (9 Sep 2026; Barracuda) · Vendor: SecurityWeek (Barracuda research)
