Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Toshiba and Muji warn of fake login screens from polyfill.io

The threat involves a compromised third-party service, polyfill.io, which served malicious scripts to display fake login screens on websites like Toshiba and Muji, creating a credential harvesting attack vector. The article does not provide a CVSS score, specific affected software versions, a fixed version, or a technical workaround. The primary remediation action taken by the affected companies was to suspend the use of the polyfill.io service.
Read Full Article →

Identity Toshiba and Muji warn of fake login screens from polyfill.io June 8, 2026 Share By SC Staff (Adobe Stock) Tech giants Toshiba and Muji have alerted visitors to their websites about suspicious sign-in screens that could potentially harvest user credentials. Both companies advised users who may have entered their login information on these fraudulent screens to change their passwords immediately, as reported by Bleeping Computer. The deceptive login prompts were generated by an external service hosted at polyfill[.]io. This service had previously introduced malicious code in 2024, impacting numerous websites that relied on its scripts. Toshiba and Muji, along with other Japanese companies like Zojirushi and FiNC Technologies, have since resolved the issue by suspending the use of the polyfill[.]io service. While there is no current evidence of unauthorized access or data breaches, users are urged to remain vigilant and change passwords if they interacted with the fake login screens. The polyfill[.]io domain, which was not owned by the original project creator, became active again in late May 2026, leading to these authentication requests being misinterpreted by browsers as legitimate login prompts. Source: Bleeping Computer SC Staff Related Identity Silent Ransom Group moves to in-person method if vishing attempt fails Steve Zurier June 8, 2026 Mandiant warns Silent Ransom Group uses vishing and even in-person visits to steal data. Identity How managing digital identities has become critical to agentic AI projects Ellen Boehm June 8, 2026 Teams need identity systems that have access control, the ability to limit and revoke privileges, and auditability. AI/ML Guardrails for agents: How to secure AI at runtime Paul Wagenseil June 8, 2026 Here's how identity security is becoming the enforcement layer for agentic AI. Related Events Cybercast IAM for MSSPs: Real-World Deployments On-Demand Event Cybercast Privilege risk is in the lifecycle: A CISO discussion on modernizing identity control On-Demand Event Cybercast The industrialization of identity compromise On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Basic Authentication Biometrics Certificate-Based Authentication Challenge-Handshake Authentication Protocol (CHAP) Digest Authentication Digital Certificate Discretionary Access Control (DAC) You can skip this ad in 5 seconds

Share this article