ai6yr, to Cybersecurity
@ai6yr@m.ai6yr.org avatar

Interesting, heard about someone who almost had their work direct deposit changed... Someone set up a gmail account with their name and emailed HR of their employer and asked them to change their direct deposit to an account (that was NOT THEIRS). Worth keeping an eye on that one. #cybersecurity #phishing #scam

thenewoil, to Cybersecurity
nbwpuk, to wordpress

Important Security Notice: WordPress administrators being actively targeted with phishing campaign

It has come to our attention that a fraudulent phishing campaign is actively targeting administrators of WordPress websites.

The attackers are sending emails with the subject line "URGENT: Vulnerability found - Your website [DOMAIN] is at risk!" The email claims to be from the WordPress Security Team and insists on addressing a critical Remote Code Execution (RCE) vulnerability affecting your website. It urges users to download a plugin labelled as "CVE-2024-46188 Patch" to mitigate the alleged threat.

READ MORE: https://encode.host/announcements/64/Important-Security-Notice-WordPress-administrators-being-actively-targeted-with-phishing-campaign.html

#WordPress #security #malware #phishing

omeraltundal, to Cybersecurity

Everyone thinks that they are the chosen one, but believe me, none of us are Neo

#cybersecurity #phishing #awareness

BishopFox, to random

Organizations on average experience 700+ social engineering attacks a year.

Dardan Prebreza is your host as we explore #socialengineering stages from planning to execution, common #phishing techniques, and the necessity of ongoing vigilance and proactive strategies to combat this pervasive issue. Don't miss out!

https://bfx.social/3SbtRHe

Champagne, to random

I keep receiving emails from an employee that reads;

"I want to update my new banking information before the next payroll is completed. What details do you need ?"

It is signed by the employee and looks fairly convincing. I'm pretty certain the email is spoofed, however...

You see the person in question is deceased. So, my reply is simple:

"Send me your new account information along with proof of resurrection."

#phishing #SpoofAccounts

gtbarry, to security
@gtbarry@mastodon.social avatar

The growing abuse of QR codes in malware and payment scams prompts FTC warning

The US Federal Trade Commission has become the latest organization to warn against the growing use of QR codes in scams that attempt to take control of smartphones, make fraudulent charges, or obtain personal information.

#FTC #QR #QRcode #quiching #phishing #security #cybersecurity #infosec #hackers #hacking

https://arstechnica.com/security/2023/12/ftc-warns-consumers-to-beware-of-qr-codes-used-in-malware-and-payment-scams/

0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2024 is out! It includes the following and much more:

➝ 🇺🇸 🖼️ MAJOR US SUFFER FALLOUT
➝ 🇪🇸 📡 A “ridiculously weak“ password causes disaster for ’s No. 2 mobile carrier
➝ 🔓 🧬 tells victims it’s their fault that their data was breached
➝ 🔓 💸 loses $86 million in the last hack of 2023
➝ 🔓 🅿️ Europe’s Largest Parking App Provider Informs Customers of Data Breach
➝ 💸 🙊 wallet founder loses $125,000 to fake airdrop website
➝ 🇺🇸 ⚖️ US Says 19 People Charged Following 2019 Takedown of Cybercrime Marketplace
➝ 🇵🇸 🇮🇱 Palestinian Hackers Hit 100 Israeli Organizations in Destructive Attacks
➝ 🔓 ❌ Hacked X Account Abused for Theft
➝ 🇳🇬 🇺🇸 ⚖️ Nigerian hacker arrested for stealing $7.5M from charities
➝ 🇦🇱 📡 Albanian Parliament and One Albania Telecom Hit by Cyber Attacks
➝ 🇺🇸 The FBI is adding more cyber-focused agents to U.S. embassies
➝ 🇺🇸 ⚖️ Former admin to be jailed until Jan. 19 sentencing
➝ 🇺🇸 💰 DOJ Slams with $10 Million Fine Over Massive Illegal Robocall Operation
➝ 📷 🥸 Contractor Pays Parents $50 to Scan Their Childrens' Faces
➝ 💰 🥸 Google Settles $5 Billion Lawsuit Over Tracking Users in 'Incognito Mode'
➝ 🇨🇳 🗳️ to reveal Chinese election interference after Saturday’s vote
➝ 🦠 💰 Settles Insurance Claim, Leaving Definition Unresolved
➝ 🦠 🇰🇵 SpectralBlur: New Backdoor Threat from North Korean Hackers
➝ 🦠 🐍 3 Malicious Packages Found Targeting with Crypto Miners
➝ 🦠 🎠 New Bandook Variant Resurfaces, Targeting Machines
➝ 🦠 🎠 UAC-0050 Group Using New Tactics to Distribute Remcos RAT
➝ 🦠 🇺🇦 CERT-UA Uncovers New Wave Distributing OCEANMAP, MASEPIE, STEELHOOK
➝ 🔓 🦠 Free Decryptor Released for Ransomware
➝ 🐛 📨 Smuggling: New Flaw Lets Attackers Bypass Security and Spoof
➝ 🩹 warns critical EPM lets hackers hijack enrolled devices
➝ 🩹 Google Patches Six Vulnerabilities With First Update of 2024
➝ 🩹 🐡 Millions still haven’t patched SSH protocol

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-012024

Frieren, to security

⚠️This is most likely phishing site posing as @protonmail .
Please use caution when accessing this site.
#security #privacy #phishing #proton #protonmail #degoogle

proton-mail-109261.square.site/

Frieren, to security

⚠️These are most likely phishing sites posing as @protonmail .
Please use caution when accessing these sites.
#security #privacy #phishing #proton #protonmail #degoogle

protonmail-101446.square.site/
pronmail-103119.square.site

Frieren, to security

⚠️This is most likely phishing site posing as @protonmail .
Please use caution when accessing this site.

panel.cyrusvpn.com

Frieren, to security

⚠️These are most likely phishing sites posing as @protonmail .
Please use caution when accessing these sites.
#security #privacy #phishing #proton

sevano.betako.fun/
tune-1.alijenabkhan.site/
kart-3.kilips.cfd/
fd-gfgff-fdfer-fvdv-gb.highweb.sbs/

knitcode, to infosec

Last year’s highlights…my team started to come out of our shell with a commitment to publishing high end original research on topics related to DNS threats
that were not covered by others…we’ve got big plans for 2024!

  • Decoy Dog was the first time an APT DNS malware was detected and reverse engineered from DNS query-response data…we got the actors to respond to us, and picked up some file samples later but this was a DNS story through and through

  • Open Tangle was the first publication of a dedicated lookalikes phishing DNS threat actor operating for over 4 years

  • We introduced the DNS threat actor technique of registered domain generation algorithms (RDGA) to evade detection

  • Prolific Puma was the first report of a malicious link shortener (and they use RDGA)

  • and we discovered that they had circumvented of the usTLD privacy regulations to boot…

We don’t publish the most, but we try to make every time count.
#dns #threatintel #infoblox #cybercrime #infosec #cybersecurity #malware #phishing

YourAnonRiots, to Cybersecurity Japanese

🚨 ALERT: Ukraine's CERT warns of a new #phishing campaign by Russia-linked #APT28.

They're deploying stealthy #malware like MASEPIE and STEELHOOK to target government entities.

https://thehackernews.com/2023/12/cert-ua-uncovers-new-malware-wave.html

#cybersecurity #hacking

sanjay_ankur, to random

Just received a text that took me to https://royalmail.myparcel-gb.com

Enter any post code, and it'll then say that one needs to pay to reschedule a delivery---I assume to get ones credit/debit card details. Please beware of this website.

Natanox, to random German
@Natanox@chaos.social avatar

Uh, das ist ja mal eine richtig gut gemachte #Phishing Mail. Wäre jetzt noch die Sendeadresse ordentlich gespoofed worden wäre das echt überzeugend gewesen - der Button zeigt offenkundig natürlich mal wieder sonstwo hin.
Wobei das Spoofing wiederrum wohl den Spamfilter getriggered hätte, ohne erreichen sie vmtl. mehr Leute. 🤔

mattotcha, to ai
@mattotcha@mastodon.social avatar
ai6yr, to Cybersecurity
@ai6yr@m.ai6yr.org avatar

Most definitely is the "Your Subscription Is Expiring! Click Here To Renew!" phishing season. #phishing #cybersecurity

Freemind, to Cybersecurity
@Freemind@mastodon.online avatar

While the malware is capable of collecting files of interest and system information, it lacks some features found in advanced stealer malware in the cybercrime underground.

#Cybersecurity #India #Malware #Phishing #Rust #RusticWeb #Stealthy #Government

https://cybersec84.wordpress.com/2023/12/23/unveiling-the-stealthy-malware-aimed-at-indian-government-operation-rusticweb-decoded/

kurtseifried, to random

Did anyone else get this #phishing email claiming to be from Okta? csid.com, they redirect it to Experian to make it look legitimate? Looks like I'm not the only one https://news.ycombinator.com/item?id=38714897 also @briankrebs for visibility.

linuxandyarn, to random

The shit I get mailed sometimes.

<quote>
Your website or a website that your company hosts is infringing on a copyright-protected images owned by our company (mailchimp Inc.).

Take a look at this document with the links to our images you utilized at [domain] and our previous publication to find the proof of our copyrights.

Download it right now and check this out for yourself:

(Link to a domain registered in April 2023 in Bogota)
</quote>

Hahahaha, no.

#spam #phishing #sysadminning

weddige, to random
@weddige@gruene.social avatar

Etsy has a huge phishing problem and they know it. But their countermeasures are completely inadequate. The picture shows just some of the phishing messages my wife has received in the last days, and with Etsy in the name and avatar they could easily be detected and automatically blocked.

1/4

#etsy #phishing

realhackhistory, to Youtube
@realhackhistory@chaos.social avatar

I put together a short #YouTube video on the #history of #Christmas related or themed computer viruses, #malware and #hacker #phishing campaigns over the years.

If you enjoy it, please share it and happy holidays.
#hacking #histodons
https://youtu.be/4ZPjZFgsCp0

phishing_radar, to random German
@phishing_radar@verbraucherzentrale.social avatar

#Phishing: Vermeintliche Zustimmung zu Vertragsanpassungen bei der #ING notwendig: https://www.verbraucherzentrale.nrw/phishing

avoidthehack, to wordpress

#WordPress hosting service Kinsta targeted by #Google phishing ads

Threat actors using Google Ads to lure people to fake Kinsta pages in an effort to steal hosting credentials. Be careful of where you click, even on "trusted" pages like Google search results.

Generally, it's best to avoid clicking on sites in the sponsored results of Google (or any search engine, really).

Using an adblocker prevents this section from loading in most cases.

#cybersecurity #phishing #security #googleads #malvertising

https://www.bleepingcomputer.com/news/security/wordpress-hosting-service-kinsta-targeted-by-google-phishing-ads/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • tester
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • tacticalgear
  • osvaldo12
  • normalnudes
  • cubers
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • modclub
  • lostlight
  • All magazines