itnewsbot, to security

How China gets free intel on tech companies’ vulnerabilities - Enlarge (credit: Wired staff; Getty Images)

For state-sponsore... - https://arstechnica.com/?p=1966082 #securitydisclosures #uncategorized #syndication #security #phishing #hacking #biz#china

ankit_anubhav, to Cybersecurity

#AITM #MITM phishing hosted on notion. If you have kept notion in some whitelist do reconsider.

hxxps[://]vigorous-harbor-449[.]notion[.]site/CONFIDENTIAL-DOCUMENT-b6e34d5a4532410598073a639f23fec3

#phishing #cybersecurity #infosec

cc @da_667 @GossiTheDog

image/png

avoidthehack, to Cybersecurity

Why is .US Being Used to Phish So Many of Us?

From @briankrebs

"As far back as 2018, Interisle found .US domains were the worst in the world for #spam, botnet (attack infrastructure for DDOS etc.) and illicit or harmful content"

Looks like a systemic problem to me.

#phishing #cybersecurity #infosec #security

https://krebsonsecurity.com/2023/09/why-is-us-being-used-to-phish-so-many-of-us/

maxleibman, to infosec
@maxleibman@mastodon.social avatar

Where does a phisherman buy his links?

At the clickbait shop.

#phishing #DadJoke #infosec

remixtures, to Cybersecurity Portuguese
@remixtures@tldr.nettime.org avatar

#Cybersecurity #Phishing #Scams #Montenegro: "“Howdy Joseph,” the July email I got from Zdravko Krivokapić, who was the Prime Minister of Montenegro until last year, read.

Obviously, this wasn’t actually Krivokapić emailing me. Instead, it was a hacker who had gained access to what seemed to be Krivokapić’s personal Gmail account. The hackers proceeded to send me a mass of alleged documents from the government of Montenegro, including some related to the country’s Ministry of Finance. Alongside those, the hacker also sent photos of cash, flashy watches, and weapons, which appear to be from the hacker’s own collection and not the former Prime Minister’s.

Beyond wanting to flex their access to Krivokapić’s account, the hacker said they might use the compromised email to then target other services, using the former Prime Minster’s identity as a cover."

https://www.404media.co/buying-and-selling-hacked-government-emails-edrs-discord-snapchat-facebook-tiktok/

DefectiveWings, to CrystalsHashtags

Well this is new to me:

#phishing email that arrives initially encrypted, but once decrypted, is a legitimate link to #adobe document online storage. That document contains a link to a phishing domain that is typosquatting the previous victim's domain.

Normal "checks" fail to catch this:

  • Email has the legitimate headers and such of the sender (who has been previously compromised).
  • The initial document link uses correct language and theming from Adobe's document site
  • The Adobe URL is an actual "adobe.com" link.

It wasn't until you get a few layers deep that you encounter something odd.

Stay safe, friends.

#infosec #security

nitpicking, to random
@nitpicking@mstdn.party avatar

1/2

Pretty bad #phishing scam in my email today. The letter claims to be from #Youporn and asserts that my image has been used in porn on their site, and that they won't remove it unless I pay them significant money in Bitcoin to the wallet linked. I happen to be fairly alert to these #scams, but this could fool someone who has sexted with an ex who they now are on bad terms with. I tried to report it to Youporn, but their contact form is thoroughly broken.

sharedsecurity, to Podcast

🔐 Exciting News! Get ready for an all new podcast episode that dives into the world of cybersecurity and online safety!🌐 Here's what's on this week's episode:

🔒 Back-to-School Cybersecurity Tips
As schools gear up for a new year, digital security takes center stage. We discuss crucial cybersecurity tips that educational institutions and students must know to safeguard sensitive data and protect against cyber threats.

💡 Avoiding Malicious Links & Phishing Scams
Phishing attacks are on the rise, and it's essential to be proactive. Learn 4 key strategies to outsmart malicious links and avoid falling into the traps of scams.🛡️

🚫 The X Update: Changes to Blocking Content
X (formerly Twitter) users will experience a significant change in blocking users. Tune in to our podcast episode to explore the safety implications and its impact on the platform's safety features.

🎙️ Tune in this week for an insightful discussion, packed with practical tips to keep you secure in today's digital age!

Subscribe on Apple Podcasts, Spotify, or your favorite podcast platform:
https://sharedsecurity.net/subscribe

Watch on YouTube:
https://youtu.be/wPO9gZwP214

Listen on our website:
https://sharedsecurity.net/2023/08/28/back-to-school-cybersecurity-phishing-pitfalls-and-strategies-xs-twitter-blocking-overhaul/

#podcast #cybersecurity #backtoschoolsafety #twitter #x #blocking #phishing

dustinfinn, to random

Happy Good Day Monday !
All Of the @pancakescon @pancakescon Videos from #PancakesCon4 are live and available.

The Entire Two Track Day is up and available on YouTube.

Here is the link -https://www.youtube.com/@PancakesCon

Thank you to @hacks4pancakes for spending the time to organize this with volunteers and GREAT GIGANTIC THANK YOU to the Speakers and the patience while these vidoes were processed and posted.

Go Watch the double track day !

eingfoan,

@dustinfinn @pancakescon @pancakescon @hacks4pancakes @catsalad

#fishing session of @infobex is online

Knitting sims

https://www.youtube.com/@PancakesCon

#Phishing #security #email #simulation

Yaaaayyyyy

ericonidentity, to infosec

For anyone at @BlueTeamCon who wants to understand why many forms of MFA are not phishing-resistant and why passkeys/FIDO2 are, tomorrow at 12:20pm during lunch in the #unconference room I’ll be delivering an impromptu session on #phishing resistant authentication, including a live demo of #evilginx.

#BlueTeamCon #BlueTeam #blueteamcon2023 #mvpbuzz #infosec

heiseonline, to Cybersecurity German

Neue Webinare zum Schutz vor Cyberangriffen

In fünf Webinaren vom 23.10. bis 27.11.2023 lernen IT-Verantwortliche und Admins von den Profis der SySS GmbH, Hackern stets einen Schritt voraus zu sein.

https://www.heise.de/news/Neue-Webinare-zum-Schutz-vor-Cyberangriffen-9282616.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#Cybercrime #Cybersecurity #Datenschutz #Security #Phishing #news

fitheach, to email
@fitheach@mstdn.io avatar

I've received a phishing email with this subject line:

New fax message 08-25-2023

Attached to the message was a zip file (of course).

Wow!

I haven't even thought about fax in twenty years. The phishing email must be targetting a select breed.

knitcode, to infosec

One of the daily stories of how DNS detects threats before they are known or used. I'm always keen to collaborate with the folks downstream in the malware world... if you know more about the malware or campaigns themselves let me know. (here or any time) We detect 30k+ registered DGAs a day and correlate them together. Never good news. #infosec #threatintel #dns #infoblox #malware #phishing https://blogs.infoblox.com/cyber-threat-intelligence/suspicious-dga-domains-discovered-in-dns-turn-up-in-malware-campaigns/

mcmahoniel, to steam
dnkrupinski, to random German
@dnkrupinski@hannover.town avatar

Achtung #Servicehinweis für alle Nutzenden von #tutanota @Tutanota :
Aktuell sind #Phishing-#EMails mit offenen Rechnungsposten unterwegs. Dabei stammt die angezeigte Absenderadresse aus AT (Österreich).

0x58, to Cybersecurity

📨 Latest issue of my curated #cybersecurity and #infosec list of resources for week #33/2023 is out! It includes the following and much more:

➝ 🇬🇧 👮🏻‍♂️ #Norfolk and #Suffolk police: Victims and witnesses hit by #databreach
➝ 💬 🔓 #Discord.io confirms breach after hacker steals data of 760K users
➝ 🇺🇸 🏥 #Health plan provider PH TECH joins MOVEit victim list, 1.7 million exposed
➝ 🌍 👮🏻‍♂️ #Interpol arrests 14 suspected cybercriminals for stealing $40 million
➝ 🇮🇷 #Iran and the Rise of Cyber-Enabled Influence Operations
➝ 🎣 📨 Major U.S. energy org targeted in QR code #phishing attack
➝ 🦠 💸 Jon DiMaggio’s demystifying #LockBit’s Secrets in his latest Ransomware Diaries Vol. 3
➝ 🔓 🎠 Approximately 2000 #Citrix NetScalers backdoored in mass-exploitation campaign
➝ 🇮🇷 Charming Kitten Targets Iranian Dissidents with Advanced Cyber Attacks
➝ 🇺🇸 💸 #FBI warns of increasing #cryptocurrency recovery scams
➝ 🇵🇱 👮🏻‍♂️ #LOLEKHosted admin arrested for aiding Netwalker ransomware gang
➝ 🇷🇺 👨🏻‍⚖️ #Russia slaps #Reddit, #Wikipedia with fines
➝ 🇨🇳 ⚡️ #Tesla reassures Chinese users on #datasecurity amid spying concerns
➝ 🇮🇱 🇺🇸 #Israel, US to Invest $4 Million in Critical Infrastructure Security Projects
➝ 💸 🐈‍⬛ New #BlackCat Ransomware Variant Adopts Advanced Impacket and RemCom Tools
➝ 🦠 🦝 Raccoon Stealer #malware returns with new stealthier version
➝ 💸 🐧 Monti #Ransomware Returns with New #Linux Variant and Enhanced Evasion Tactics
➝ 🏴‍☠️ 💻 Over 120,000 Computers Compromised by Info Stealers Linked to Users of #Cybercrime Forums
➝ 🤖 🌪️ Google Brings AI Magic to Fuzz Testing With Eye-Opening Results
➝ 🔑 #Google Introduces First #Quantum Resilient #FIDO2 Security Key Implementation
➝ 🐮 👀 Cult of the Dead Cow releases #Veilid: A secure open-source Peer-to-Peer network for apps that flips off the surveillance economy
➝ 📱 Threat actors use beta apps to bypass mobile app store security
➝ 🛰️ ☠️ How a hacking crew overtook a #satellite from inside a Las Vegas convention center and won $50,000
➝ 🃏 🔓 How to hack #casino card-shuffling machines
➝ 🇫🇷 🏧 Iagona ScrutisWeb Vulnerabilities Could Expose #ATM's to Remote Hacking

📚 This week's recommended reading is: "The Cuckoo's Egg: Tracking a Spy Through the Maze of Computer Espionage" by Clifford Paul "Cliff" Stoll

Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-332023

HistoPol, (edited ) to VintageOSes
@HistoPol@mastodon.social avatar

ATTENTION - important fake #ZOOM #phishing attempt.

Citing EU #GDPDR rules and looking like a standard notification of ToS, the #cybercriminal has invested a lot of work in the quite authentic looking website.
Block the domain and inform your IT security.
Good luck!

noreply@email.zoominformation.com

Also; ZOOM changed its Terms of Service on 04/01/2023. - You have now agreed that they may use all your data generated while using their app, including the training of LLMs. Check the ToS, Sect.10

heisec, to security German

LKA warnt vor Betrugsmasche mit Bezug auf Steuer-Bescheid und-Betrug

E-Mails mit Bezug auf Steuerbescheid, -betrug oder Einkommenssteuer, vorgeblich etwa von "Steuerbehörden", machen die Runde, warnt das LKA Niedersachsen.

https://www.heise.de/news/LKA-warnt-vor-Betrugsmasche-mit-Bezug-auf-Steuer-Bescheid-und-Betrug-9269903.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#Phishing #Security #news

reginagrogan, to DEFCON
@reginagrogan@mastodon.social avatar

I do not want to be a hater, but…

Sees guys promo after the event

“I hacked all the atms in vegas and took everyones money!” Lolololol (guy 1)
“I hacked the pacemakers and all the boomers!” Lolololol (guy 2)
“I caused horrible chaos to everyone in vegas by sending millions of texts!” lololol (guy 3)
“I took my cab drivers money lololol i have a tiny dick!” (Guy 4)

“why do people have a bad rep?”

Geeee i wonder…

protectprivacy, to privacy

🐟 How to Prevent Phishing Attacks? Your Ultimate Guide to Staying Safe Online

#privacy #cybersecurity #phishing

https://protectprivacy.eu/privacy/how-to-prevent-phishing-attacks/

tagesschau, to random German
@tagesschau@ard.social avatar

Zahl der Cyberangriffe in Deutschland weiterhin auf hohem Niveau

Was die BKA-Statistik erfasst, ist nur "die Spitze des Eisbergs" - doch auch die ist schon beachtlich: 136.865 Fälle von Cyberkriminalität registrierte das BKA 2022. Gerade Erpressung mit Ransomware könne "existenzbedrohend" sein.

➡️ https://www.tagesschau.de/inland/cyberangriffe-deutschland-bka-100.html?at_medium=mastodon&at_campaign=tagesschau.de

Uwe_B,

@tagesschau Diese elenden #Kleptokraten von der #Tagesschau! Geld kassieren, das im #Schutzgeldverfahren eingezogen wird, aber gar nicht daran denken, eine entsprechende Gegenleistung zu erbringen. Das Mindeste wäre, sich schlau zu machen, was #Phishing wirklich bedeutet. Aber das würde ja ein Mindestmaß an Kompetenz in Sachen #Cybersicherheit bedeuten, und die ist in der Redaktion der Tagesschau offensichtlich unerwünscht. Kein Wunder, dass die #Cyberkriminalität hoch bleibt.

heiseonline, to finanzen German

S-ID-Check: Sparkasse warnt vor Phishing-Attacke

Phishing-Versuche zielen mit einer neuen Masche auf die Sparkasse ab. Angeblich sei eine Aktivierung des S-ID-Checks erforderlich.

https://www.heise.de/news/S-ID-Check-Sparkasse-warnt-vor-Phishing-Attacke-9246002.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#Datenschutz #Finanzen #Phishing #news

nuke, to random Italian

Legge anti pirateria 📣 di @quinta per LaRepubblica

Un piccolo passo avanti verso un nuovo Internet, forse.
Un po’ come facciamo da sempre contro il #phishing e ne parlavo proprio alcuni mesi fa.

image/png

petersuber, (edited ) to random

I don't use #Paypal. But I use the <phishing@paypal.com> email address several times a week. If you receive Paypal-related #phishing attempts, forward them to that address.

Odd mixed feelings: I shun Paypal, partly because of the nonstop phishing and partly because of the #ElonMusk connection. But I appreciate the phishing alert email address.

autonomysolidarity, (edited ) to random German
@autonomysolidarity@todon.eu avatar

Dass die EU-Kommission die Totalüberwachung und digitale
Kontrolle im Internet genauso wie im Alltag, an ihren Außengrenzen zur Bekämpfung von fliehenden Menschen und im Inneren u.a. für den Datenkapitalismus weiter ausbaut, ist nichts Neues. Nicht nur besteht sie aus stramm neoliberalen, autoritären Politiker*innen, die schon zuvor immer wieder mit repressiven Vorhaben angekommen sind, es geht allgemein mit dem Überwachungs- und Krisenkapitalismus auch eine autoritäre Transformation einher.

Als Antiautoritäre stellen wir uns diesen Entwicklungen und Allen, die sie voranbringen wollen, entschlossen entgegen!

--> https://enough-is-enough14.org/2022/05/15/statement-zum-eu-verschluesselungsverbot-chatdurchleuchtungspflicht/

autonomysolidarity,
@autonomysolidarity@todon.eu avatar

Gefährlicher Präzedenzfall: Neues Gesetz in will zur verpflichten

"Die französische Regierung will Zensurmechanismen auf Browser-Ebene einführen. , bekannt für seinen Firefox-Browser, fürchtet eine dystopische Technik, die autoritären Regimen die Zensur erleichtert.
(...)
„Dass eine Regierung anordnen kann, dass eine bestimmte Website in einem Browser/System überhaupt nicht geöffnet wird, ist Neuland, und selbst die repressivsten Regime der Welt ziehen es bisher vor, Websites weiter oben im Netz (Internetanbieter usw.) zu blockieren“, schreibt Mozilla.
Auch wenn die Technik heute in Frankreich vielleicht nur für und genutzt werden würde, entstünde ein Präzedenzfall und die technische Voraussetzung in Browsern für Zensur. „Eine Welt, in der Browser gezwungen werden können, eine Liste verbotener Websites auf Software-Ebene zu integrieren, die sich weder in einer Region noch weltweit öffnen lassen, ist eine beunruhigende Aussicht, die ernste Bedenken hinsichtlich der Meinungsfreiheit aufwirft“, schreibt Udbhav Tiwari. Mozilla fürchtet, dass das Gesetz es dann in Zukunft Browsern schwer machen würde, solche Anfragen von anderen Regierungen abzulehnen."
https://netzpolitik.org/2023/gefaehrlicher-praezedenzfall-neues-gesetz-in-frankreich-will-browser-zur-zensur-verpflichten/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • tester
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • tacticalgear
  • osvaldo12
  • normalnudes
  • cubers
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • modclub
  • lostlight
  • All magazines