Security News

OAuth Consent Phishing Ramps Up with Microsoft Office 365 Attacks
2020-09-30 21:29

According to researchers from Proofpoint, targets receive a well-crafted lures asking them to click a link which carries them to the legitimate Microsoft third-party apps consent page. "The ability to perform reconnaissance on an O365 account supplies an actor with valuable information that can later be weaponized in business email compromise attacks or account takeoversThe minimal [read-only] permissions requested by these apps also likely help them appear inconspicuous if an organization's O365 administrator audits connected apps for their users' accounts."

Officials: Washington Being Targeted by Phishing Campaign
2020-09-25 12:26

Washington state is among those being targeted by a "Large-scale, highly sophisticated" nationwide phishing campaign, the office of Gov. Jay Inslee said Thursday. At a press conference Thursday, Inslee said that the state is taking proactive measures to protect state systems, but he said that no ransomware activity has occurred among the agencies targeted, and no state services have been impacted.

SMS phishing scam pretends to be Apple “chatbot” – don’t fall for it!
2020-09-24 18:59

Sadly what works for legitimate businesses almost always works for cybercriminals too, so there are plenty of crooks still using SMSes for phishing - an attack that's wryly known as smishing. Your phone's operating system will happily recognise when the text in an SMS looks like a URL and automatically make it clickable for you.

Mozilla Discontinues Firefox Feature Abused in Malware, Phishing Attacks
2020-09-21 11:44

Mozilla is decommissioning Firefox Send and Firefox Notes, two legacy services that emerged out of the Firefox Test Pilot program. Firefox Send, the browser maker reveals, is being discontinued because it has been abused for delivering malware and phishing attacks.

Phish Scale: New method helps organizations better train their employees to avoid phishing
2020-09-21 04:30

Researchers at the National Institute of Standards and Technology have developed a new method called the Phish Scale that could help organizations better train their employees to avoid phishing. Many organizations have phishing training programs in which employees receive fake phishing emails generated by the employees' own organization to teach them to be vigilant and to recognize the characteristics of actual phishing emails.

You have to be very on-trend as a cybercrook – hence why coronavirus-themed phishing is this year's must-have look
2020-09-17 08:30

Coronavirus-themed malicious emails were the standout feature of online naughtiness in the first half of 2020, according to infosec firm F-Secure - though overall volumes of phishing did decrease a touch. Observed attack attempts included an Emotet banking trojan campaign targeting Japan in January after the nation confirmed its first coronavirus infection.

Two Russians Charged in $17M Cryptocurrency Phishing Spree
2020-09-16 20:53

U.S. authorities today announced criminal charges and financial sanctions against two Russian men accused of stealing nearly $17 million worth of virtual currencies in a series of phishing attacks throughout 2017 and 2018 that spoofed websites for some of the most popular cryptocurrency exchanges. Prosecutors say the men then laundered the stolen funds through an array of intermediary cryptocurrency accounts - including compromised and fictitiously created accounts - on the targeted cryptocurrency exchange platforms.

What are the most vulnerable departments and sectors to phishing attacks?
2020-09-16 04:30

Keepnet Labs has revealed the most vulnerable departments and sectors against phishing attacks, based on a data set of 410 thousand phishing emails, covering a period of one year. Accordingly, 90% of successful cyber attacks occur through email-based attacks.

How to run a phishing attack simulation with GoPhish
2020-09-15 15:58

Jack Wallen shows you how to run a phishing simulation on your employees to test their understanding of how this type of attack works. How do you test those end users? One way is with the GoPhish phishing toolkit.

Office 365 Phishing Attack Leverages Real-Time Active Directory Validation
2020-09-11 20:28

Researchers have uncovered a phishing attack using a new technique: Attackers are making use of authentication APIs to validate victims' Office 365 credentials - in real time - as they enter them into the landing page. Office 365 requires app registrations to use APIs - but registrations require only an email address, making them seamless for attackers to leverage.