jik, to firefox
@jik@federate.social avatar

This is one of the most convincing #phishing messages I've seen in a long time.
The email is clean and professional, the web site it links to doesn't get flagged by either #Firefox or #Chrome (I've reported it), and the web site (https:// apple-coin.io/, screenshot included below in case it gets taken down) is REALLY smooth.
Please give any #iPhone+#crypto users in your life a heads-up about this, because it's likely to fool a lot of people.
Please boost for visibility.
#infosec #cybersecurity

[Screenshot of https://cdn.masto.host/federatesocial/media_attachments/files/111/955/080/664/996/368/original/93f3ea22e1c8956e.pngatesocial/media_attachments/files/111/955/080/664/996/368/original/93f3ea22e1c8956e.png)

Morishima, to security
@Morishima@ieji.de avatar

⚠️These are most likely phishing sites posing as Netflix.
Please use caution when accessing these sites.
#security #cybersecurity #privacy #phishing #netflix #streaming #tech #video #movie #hacking

shrxysharma.github.io/netflix/
nileshmuleva.github.io/netflix.github.io/
jayaji.github.io/Netflix-clone/
midhun4059.github.io/netflixwebsite1/

tbroyer, to random
@tbroyer@piaille.fr avatar

Ha ha, this is a fun (sic) phishing attempt:

  • mail posing as an UAE bank
  • but sent from an indian investment firm (with valid SPF, DKIM and DMARC, so probably a vulnerable/misconfigured SMTP server on their end);
  • call-to-action links to the canadian "bikers against pedophiles"' (‽) staging website (a page under wp-includes, so probably leveraging a WordPress vulnerability)
  • that redirects to a page on the czech Pandora website
  • that mimics the UAE bank, asking for credit card details (phishing page has already been removed and I forgot taking a screenshot a few hours ago)

#phishing #spam

itnewsbot, to azure
@itnewsbot@schleuss.online avatar

Ongoing campaign compromises senior execs’ Azure accounts, locks them using MFA - Enlarge (credit: Getty Images)

Hundreds of Microsoft Azure acc... - https://arstechnica.com/?p=2002911 &it

jos1264, to Cybersecurity
@jos1264@social.skynetcloud.site avatar
squishymage42, to tech
@squishymage42@dice.camp avatar

https://pluralistic.net/2024/02/05/cyber-dunning-kruger/

Fun reading about how even @pluralistic falls for phishing sometimes thanks to all the enshittification of getting in touch with necessary services making us less likely to catch the red flags.

I've clicked on a few of my office's "phishing tests" which at least gets me more "watch this social engineering info video" even if the videos are so bad that you can't help zone out.

linuxmagazine, (edited ) to linux
@linuxmagazine@fosstodon.org avatar

Issue is available now! This month we take a look at the Plasma 6 release. On the DVD: @linuxmint 21.3 MATE and 17 Core. See what else we're talking about this month https://mailchi.mp/linux-magazine.com/linux-magazine-preview-issue-280-march-2024

ThinkingSapien, to random
@ThinkingSapien@mstdn.social avatar

I don't know my own work phone number. I don't share it. I just got a phone call from someone presenting as wanting to send me a publication. They had my phone number, name, and title. Who the hell is leaking my data!?

#Phishing #DataPrivacy #Spam

crowgirl, to infosec
@crowgirl@hachyderm.io avatar

I just posted this cybersecurity warning on LinkedIn. But I should share it here too. Full alt text is provided. Please share! #infosec #phishing

silentlyeating, to random

Phishing scammers now helpfully include the steps you need to take to click on their risky link in their texts. I’m sure ‘tuanosali1981@mailbox.org’ has my best interests in mind and is definitely from “the US Postal team.” I definitely shouldn’t question where they got my phone number from and why USPS wouldn’t just return a package to its sender.

frehi, to infosec
@frehi@fosstodon.org avatar

My employer lets a private company send fake phishing mails to all staff in order to train them. Now that company, which most personnel do not know, sends an e-mail in its own name to all our staff, asking them to click on a link to follow an anti-phishing training. So it looks like the message they are giving to all our staff is: it's OK to click on links from unknown companies, as long as they tell you that it's anti-phishing training. 🤦‍♂️ #phishing #infosec

BNetzA, to random German
@BNetzA@social.bund.de avatar

Achtung, #Phishing: Aktuell sind E-Mails mit falscher #BNetzA-Mailadresse und Grußformel des #BZSt im Umlauf. Die E-Mails sind nicht echt. Öffnen Sie keine Links und geben Sie bitte keine persönlichen Daten wie beispielsweise Ihre IBAN preis.

Aufforderung zum Anklicken eines Links.
Falsche E-Mail-Kontaktadresse für Rückfragen.

tofuknacker, to random German
@tofuknacker@norden.social avatar

Achtung!

Habe heute eine #Phishing Mail erhalten, die angeblich von der #ING kommt.

Es wird dazu aufgefordert, wegen AGB Änderungen innerhalb 14 Tagen die Kontodaten zu bestätigen, da sonst das Konto kostenpflichtig gesperrt werde.

Prüft bitte in solchen Fällen immer, von wo diese E-Mail kommt und ob das an die richtige E-Mail-Adresse gesendet wurde.

(Bei mir ging es an eine komplett falsche Adresse, die ich aus historischen Gründen noch habe)

funcrunch, to random
@funcrunch@me.dm avatar

Reading about always depresses me. I know there are far greater problems in the world, but I wish the people who put so much effort into scamming others would redirect those efforts into doing something positive for society.

Regardless, good article in @medium by @pluralistic about a targeting users of :

https://doctorow.medium.com/how-i-got-scammed-0ae9bd453490

InfobloxThreatIntel, to Cybersecurity

We're going to be talking about VexTrio, the single most pervasive and persistent cybercriminal group we've encountered on Wed Feb 7th 8am PT. Boosts appreciated. Link here to register, its free https://www.infoblox.com/registration-traffic-distribution-systems-at-the-heart-of-cybercrime/

tiamat271, to random
@tiamat271@mastodon.online avatar

Think you can’t be tricked by a fraudster? If it can happen to @pluralistic, it can happen to you. Long thread, but worth the read.

https://mamot.fr/@pluralistic/111879255100026834

itnewsbot, to machinelearning
@itnewsbot@schleuss.online avatar

Deepfake scammer walks off with $25 million in first-of-its-kind AI heist - Enlarge (credit: Getty Images / Benj Edwards)

On Sunday, a rep... - https://arstechnica.com/?p=2000988

pluralistic, to random
@pluralistic@mamot.fr avatar

I wuz robbed.

More specifically, I was tricked by a phone-phisher pretending to be from my bank, and he convinced me to hand over my credit-card number, then did $8,000+ worth of fraud with it before I figured out what happened. And then he tried to do it again, a week later!

--

If you'd like an essay-formatted version of this thread to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:

https://pluralistic.net/2024/02/05/cyber-dunning-kruger/#swiss-cheese-security

1/

angusm,
@angusm@mastodon.social avatar

@pluralistic “There's a leak somewhere in the CU systems' supply chain”

I absolutely believe it.

I received a plausible #phishing mail, sent to an address I use only for one specific CU, with my correct name, purporting to be from the CU's president.

The payload link used in the phish contained the email address of the CTO of a different CU; I think the scammer just re-used a link without fine-tuning it for my CU.

The scammers clearly have access to CU client DBs & are targeting many CUs.

nono2357, to web French
Frieren, to security

⚠️These are most likely phishing sites posing as Microsoft.
Please use caution when accessing these sites.

7in7ko48.fkade.ru/Cc3F9pJ7PtQ/
melody.lincelryou.com/y48633m/
jy35gym.tnjxb.com/0ViPep1/
925kbwi4.jxfav.ru/925kBwi4/
a6534.hioa13.com/e615/aHR0cHM6Ly9hNjUzNC5oa9hMTMuY29tL/
team.ndivente.ru/4gmgk8s8/

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

Artificial Intelligence is revolutionizing not just industries but also cybercrime.

Isla Sibanda explores how AI is changing the phishing landscape and what measures you can take to protect your organization.⤵️

https://hubs.la/Q02hngRr0

#Cybersecurity #AI #Phishing

kpwn, to random

I don’t understand how people can fall for #phishing! All you have to do is check whether the domain is valid.

Like the following example obviously is phishing because…

Oh, it's the actual website of a German ministry?

🤦‍♂️

InfobloxThreatIntel, to Cybersecurity

A few of the MFA lookalike domains we've detected recently. These target a large bank in the Czech Republic (csob[.]sk):
csob-sso-sk[.]net, online-csob-sso-sk-moja[.]com, csob-sso-sk[.]com

To learn more about MFA smishing check out this blog https://blogs.infoblox.com/cyber-threat-intelligence/how-bad-guys-are-undermining-trust-in-multi-factor-authentication-mfa/

#dns #infoblox #threatintel #cybersecurity #infosec #lookalike #phishing #mfa #smishing

PieterJJ, to random Dutch
@PieterJJ@mastodon.nl avatar

Pap is gek 😜 #phishing

fifonetworks, to email

The PDF file attached to this email is malicious. You don’t even have to open it to know it should be deleted immediately. Outlook shows the “from” information, and this email didn’t come from Intuit.

The criminal who sent this email is an amateur. Be aware that the “from” information can be much more deceptive than we see in this email example. Sometimes you have to know how to examine the email header to see where the email is really from.

There are a lot of malicious emails that are of poor quality and easy to identify, like this one. By being informed and on guard, you can save yourself from a lot of trouble.

#callmeifyouneedme #fifonetworks

#spam #email #phishing #cybersecurity

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • InstantRegret
  • rosin
  • modclub
  • Youngstown
  • khanakhh
  • Durango
  • slotface
  • mdbf
  • cubers
  • GTA5RPClips
  • kavyap
  • DreamBathrooms
  • ngwrru68w68
  • provamag3
  • magazineikmin
  • osvaldo12
  • tester
  • tacticalgear
  • ethstaker
  • Leos
  • thenastyranch
  • everett
  • normalnudes
  • anitta
  • megavids
  • cisconetworking
  • lostlight
  • All magazines