circatee, to random

Does anyone here use iCloud email? Worth it?
Spam growth on Outlook Dot Com, is a serious pain. Hence, my question, time to move I think...

#iCloud #Email #Spam #Phishing #Junk

factcheck, to random Italian
@factcheck@mastodon.uno avatar
AAKL, to Cybersecurity
blog, to random
@blog@shkspr.mobi avatar

Scammers registering date-based domain names
https://shkspr.mobi/blog/2020/01/scammers-registering-date-based-domain-names/

Yesterday, January 2nd, my wife received a billing alert from her phone provider.
An SMS saying there's a problem with your phone bill.

Luckily, she's not with EE - because it's a pretty convincing text. That domain name is specifically designed to include the day's date.

If you're stood up on a crowded train, with your phone screen cracked, would you notice that a . is where a / should be? A quick look at the URl shows a trusted domain at the start - followed by today's date.

It starts with https:// - that means it's secure, right? Is .info even recognisable as Top Level Domain?

Scammers know these domains get blocked pretty quickly - so there's no point registering a generic name like billing-pdf.biz only to have it burned within a day. By the time I'd fired up a VM to inspect it, major browsers were already blocking the site as suspicious.

Is there any way to stop this? No, not really. Domain names are cheap - you can buy a new .info for a couple of quid. The https:// certificate was freely provided by Let's Encrypt. The site was probably hosted somewhere cheap, and whose support staff are asleep when abuse reports come in from the UK.

And that's the price we pay for anyone being able to buy their own domain and run their own secure site.

Money and technical expertise used to be strong barriers to prevent people from registering scam domains. But those days are long gone. There are no technical gatekeepers to keep us safe. We have to rely on our own wits.

https://shkspr.mobi/blog/2020/01/scammers-registering-date-based-domain-names/

#phishing #scam #spam

1HommeAzerty, to random French
@1HommeAzerty@mamot.fr avatar

Ah oui, le fameux code par défaut. #phishing

protonmail, to ai
@protonmail@mastodon.social avatar

With billions of phishing emails sent daily and making social engineering easier, is the most critical you and your team must be able to recognize.

Take the @frameworkcomputer as a sign to learn these steps: https://proton.me/blog/what-is-phishing

sanjaymenon, to infosec
@sanjaymenon@mastodon.social avatar
ge0rg, to random German
@ge0rg@chaos.social avatar

PSA: Spear-Phishing bei #DKB - Angreifer haben Name, Konto- & Telefonnummer

  1. Angeblicher IT-Support der DKB ruft von der Nummer der DKB-Hotline an
  2. Bittet um Bestätigung der Identität in der DKB-App (1. Schritt vom Passwort-Reset, die App sagt das aber nicht!)
  3. Fragt nach CVV2 der Debitkarte (2. Schritt)
  4. Setzt ein neues Passwort und loggt sich ein
  5. Bittet um Bestätigung einer "Test-Transaktion", mit der dann effektiv das Konto abgeräumt wird.

#phishing #BoostWelcome

oetgrunnen, to random
@oetgrunnen@mstdn.social avatar

@belastingdienst ze blijven het proberen #Phishing

deflockcom, to security
@deflockcom@mastodon.social avatar

We had the solution since the beginning!! :)

Troll, to Signal French
@Troll@maly.io avatar

J'avais pas ce genre de #spam / #phishing avant l'introduction des noms d'utilisateur sur #signal et vous ?

Coïncidence ou corrélation ?

stefan, to internet_funeral
@stefan@gardenstate.social avatar

Current text spam/phishing I'm getting over and over again.

Morishima, to security
@Morishima@ieji.de avatar

⚠️These are most likely phishing sites posing as Microsoft.
Please use caution when accessing these sites.

s8k47.moraspu.ru/02b3/
874pf.eaver1.com/h538/
1w7g1.unisa0.com/6d19/
82nxtirnj1.q1uad.com/CRA1rix15f/
qzptx.choncisev.ru/u72y3t68q/
zwdsmgmoec.alftoneh.ru/f62kx2ju8z/
c12ir5.equityinvestorconnections.com/5e97jY912/
25sgilg2.gtp94.com/Gjz2oVK7l/

linuxine, to random

Salut Masto !

Vive l'IA, un de mes contacts a reçu un faux mail de l'ANTAI lui demandant de payer une contravention super bien fait, complètement identique aux vrais, avec zéro faute... Heureusement ils se sont plantés dans le délais pour payer ce qui l'a incité à ne pas cliquer.

J'ai demandé à voir le mail. Le nom de domaine de l'expediteur et du faux site pour payer sont enregistrés en France, chez OVH. Est ce que vous savez si j'ai moyen de contacter directement OVH pour leur signaler ?

#phishing #OVH #signalement

aeveltstra, to cisco
@aeveltstra@mastodon.social avatar
PieterJJ, to random Dutch
@PieterJJ@mastodon.nl avatar

Pap is gek 😜

kohelet, to microsoft
@kohelet@mstdn.social avatar

I like how there's so many products and so much money spent on endpoint defense,
malware detection, incident response, scanning of files, behavioral changes and signals
and all that shit...

but then companies end up losing millions to a simple phishing attack.

I'm doing the SC-200 by Microsoft, and I barely see things that talk about this

#Phishing
#Microsoft #InfoSec #CyberSecurity

tofuknacker, to random German
@tofuknacker@norden.social avatar

Achtung!

Habe heute eine #Phishing Mail erhalten, die angeblich von der #ING kommt.

Es wird dazu aufgefordert, wegen AGB Änderungen innerhalb 14 Tagen die Kontodaten zu bestätigen, da sonst das Konto kostenpflichtig gesperrt werde.

Prüft bitte in solchen Fällen immer, von wo diese E-Mail kommt und ob das an die richtige E-Mail-Adresse gesendet wurde.

(Bei mir ging es an eine komplett falsche Adresse, die ich aus historischen Gründen noch habe)

lau, to Belgium French
@lau@eldritch.cafe avatar

Je viens de recevoir un appel d'un numéro belge, une voix robotique s'annonce comme étant PayPal et m'informant que je viens de faire une transaction de 582€.
J'ai raccroché direct, signalé et bloqué le numéro.

#phishing #belgium #paypal

frehi, to infosec

My employer lets a private company send fake phishing mails to all staff in order to train them. Now that company, which most personnel do not know, sends an e-mail in its own name to all our staff, asking them to click on a link to follow an anti-phishing training. So it looks like the message they are giving to all our staff is: it's OK to click on links from unknown companies, as long as they tell you that it's anti-phishing training. 🤦‍♂️ #phishing #infosec

fifonetworks, to email

The PDF file attached to this email is malicious. You don’t even have to open it to know it should be deleted immediately. Outlook shows the “from” information, and this email didn’t come from Intuit.

The criminal who sent this email is an amateur. Be aware that the “from” information can be much more deceptive than we see in this email example. Sometimes you have to know how to examine the email header to see where the email is really from.

There are a lot of malicious emails that are of poor quality and easy to identify, like this one. By being informed and on guard, you can save yourself from a lot of trouble.

#callmeifyouneedme #fifonetworks

#spam #email #phishing #cybersecurity

silentlyeating, to random

Phishing scammers now helpfully include the steps you need to take to click on their risky link in their texts. I’m sure ‘tuanosali1981@mailbox.org’ has my best interests in mind and is definitely from “the US Postal team.” I definitely shouldn’t question where they got my phone number from and why USPS wouldn’t just return a package to its sender. #scam #phishing #TrustNoOne

stiefkind, to random German
@stiefkind@mastodon.social avatar

"Ihre Sendung hat den Weg gefunden: Infos innen". Absender ist ein "ZustellHelden Logistik".

Es werd's ma so Helden sei ey … #phishing

ThinkingSapien, to random
@ThinkingSapien@mstdn.social avatar

I don't know my own work phone number. I don't share it. I just got a phone call from someone presenting as wanting to send me a publication. They had my phone number, name, and title. Who the hell is leaking my data!?

#Phishing #DataPrivacy #Spam

otter, to infosec

More or less every company has guidance that users shouldn't click links in emails to prevent phishing and other email based attacks. So why do all email clients enable clickable links? There doesn't even seem to be an option to disable such links from incoming emails. 🤔

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • tester
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • tacticalgear
  • osvaldo12
  • normalnudes
  • cubers
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • modclub
  • lostlight
  • All magazines