brunty, to random
@brunty@brunty.social avatar

Remember to do your security upgradations...

EricIndiana, to random
@EricIndiana@mastodon.social avatar

The original "African email scams" predated email, and I just came across one that for some reason I saved in a box for 30 years...

#phishing #emailscams #nigerianscammers

jik, to privacy
@jik@federate.social avatar

A company I consulted for emailed me asking for info for my 1099.
The email was sent by a 3rd-party service claiming to be acting on their behalf.
I started filling out the form, but when I got to the SSN field, it occurred to me, "How do I know this is legit? Also, didn't I give them my SSN already?"
I closed the form and emailed my contact there asking him to confirm the request.
A few days later I got my 1099 from the 3rd-party service. They indeed had my SSN already.
#privacy #phishing

rcpierce, to internet_funeral
@rcpierce@mastodon.online avatar

Spam or genuine wrong number? FYI I am certainly not Erin.

odr_k4tana, to random

Because I read something along those lines often: the fact that some legitimate emails look like phishing is caused by phishers mimicking real emails, not the other way round. The problem are garbage phishing detection rules, not the legitimate emails phishers try to mimic.

Phishing detection rules cannot be set in stone but depend highly on the environment and "email culture" you inhabit. If you filter out legitimate stuff because of your rules, your rules suck.

Example: "Don't open attachments" is stupid advice if you have to open email attachments every day for your regular job. Rather tell people to upload files sent with automated emails or unknown senders to either virus total or let them get checked by local antivirus. Or implement encryption policies where unencrypted files are suspicious by default.

Bottom line: setting the same standards for everyone won't work. Consider your environment and act accordingly.

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

📢Watch out for malicious QR Codes🚨 QR Code Phishing Soars 587% - Check Point's Live Cyber Threat Map identified 20,000 instances of QR code attacks within two weeks.

https://hackread.com/qr-code-phishing-social-engineering-scams/

#CyberAttack #CyberSecurity #QR #Phishing #Malware

That_One_Guy, to Cybersecurity
@That_One_Guy@mastodon.world avatar

No matter how many meetings we have about email and cyber security some idiot still clicks on every link they are sent.🙄🤦🤬

This dumbass will lose access to his account for a whole day even though this wasn't real. Hopefully he has his #2 pencil sharp. ✏️

#cybersecurity #phishing #IT

steveroy, to random
@steveroy@mstdn.ca avatar

Someone sent an email at my workplace today, impersonating me to change the banking info used for my pay.

I’m amazed that people try stunts like that. But then maybe I shouldn’t be surprised.

knitcode, to random

what's the word for when: the phishers who are stealing from the organized crime phishers that you are researching realize that you know they are fake (organized crime) and take down their entire infrastructure and social media presence in a few hours? i was going with "wow" but it doesn't seem quite the right word. i also tried "bummer".

simsus, to random German
@simsus@social.tchncs.de avatar

#Phishing-Welle von Zentralstelle Cybercrime Bayern beobachtet | Security https://www.heise.de/news/Zentralstelle-Cybercrime-warnt-vor-Phishing-Welle-9604611.html

stiefkind, to random German
@stiefkind@mastodon.social avatar

"Ihre Sendung hat den Weg gefunden: Infos innen". Absender ist ein "ZustellHelden Logistik".

Es werd's ma so Helden sei ey … #phishing

InfobloxThreatIntel, to Cybersecurity

We just released the results of collaborative research with @rmceoin on the kingpin of cybercrime traffic distribution: VexTrio. The longest lived, most pervasive threat we see in the wild. VexTrio has over 60 affiliates feeding them victims, including the famous SocGohlish and ClearFake actors. Not just middlemen, they compromise WP sites and run their own campaigns as well. end-to-end criminal gang. https://blogs.infoblox.com/cyber-threat-intelligence/cybercrime-central-vextrio-operates-massive-criminal-affiliate-program/

DFN, to random German

🛡️ Aktive #Cyberabwehr in #DFNSecurity: Die DNS-Firewall startet Ende Januar in den Pilotbetrieb. Ziel: techn. Validierung u. Prüfen der Onboarding- & Dokumentationsprozesse. Sie dient u.a. der Abwehr von 🎣 #Phishing Angriffen. @dfncert #switch_ch Infos: https://www.dfn.de/dfn-security-dns-firewall-startet-in-den-pilotbetrieb/

jsrailton, to SEC
@jsrailton@mastodon.social avatar

deleted_by_author

  • Loading...
  • publicvoit,
    @publicvoit@graz.social avatar

    @jsrailton Only FIDO2 and Passkeys are protecting against #phishing attacks.

    Caution: #Passkeys might copy your secret into the service provider's cloud for convenience and backup purposes.

    IMHO, #FIDO2 hardware tokens are the only non plus ultra for authentication security since they protect your secrets in hardware without the possibility of "backups" to the cloud.

    #TOTP #2FA #U2F

    luppano, to random French
    @luppano@lou.lt avatar

    J'ai trop de temps libre

    luppano,
    @luppano@lou.lt avatar

    Vous pensez qu'ils vont discuter ?

    Codeberg, to random
    @Codeberg@social.anoxinon.de avatar

    We saw #malware uploads to Codeberg increase in the past weeks. Although our users are likely not the target audience of these files, we still want to remind you:

    Watch out and stay secured. Do not run files from untrusted authors.
    On Codeberg, double-check the project's legitimacy (e.g. user age, stars / issues / activity) or the source code itself.
    Visit the project's homepage and use official download sources.
    Never let emails panic you, consider if it's part of a #phishing campaign.

    YourAnonRiots, to microsoft Japanese
    @YourAnonRiots@mstdn.social avatar

    📢🚨 has warned of an Israel-Hamas-themed phishing scam, accompanied by the use of a custom backdoor called , carried out by the Iranian Mint APT.

    https://hackread.com/iran-mint-sandstorm-hamas-israel-phishing-scam/

    PogoWasRight, to Cybersecurity

    @itpro reports:

    Research from cyber security firm Egress found that 94% of organizations globally have experienced a serious email security incident in the past 12 months, and 4 out of 10 employees responsible for email security breaches over the last year have been sacked.

    Egress report link: https://pages.egress.com/whitepaper-email-risk-report-01-24.html

    So.... my comment:

    If four in ten are being fired for email security breaches, then maybe it's not the employees who should be fired but those at the top who haven't invested in solutions that do not rely on or require human beings to be perfect detectors of phishing attempts, BEC, or other social engineering attacks involving email? Or who haven't just accepted that shit will happen? And now that AI is making such attacks even more convincing or difficult to detect, firing employees for falling prey is even less justifiable or effective.

    Your thoughts, folks?

    #cybersecurity #responsibility #email #phishing #BEC

    otter, to infosec

    More or less every company has guidance that users shouldn't click links in emails to prevent phishing and other email based attacks. So why do all email clients enable clickable links? There doesn't even seem to be an option to disable such links from incoming emails. 🤔
    #infosec #email #phishing #security

    shawnhooper, to Facebook
    @shawnhooper@fosstodon.org avatar

    How to disable the ability for "Guest 1234" accounts to message your Facebook Business page.

    https://nileflores.com/how-to-disable-messages-from-guest-1234-on-facebook-pages-messenger/

    #facebook #phishing

    teksquisite, to security

    Peacock ongoing #phishing messages to my #icloud email account.
    ———-
    Small print = “After signing up, you have to insert your credit card details for validation of your Peacock ID. We will not withdraw any amount.”
    ———
    OMG! Seriously, my ribs are hurting!

    #security #cybersecurity #infosec #technology

    Screenshot of a phishing email message for Peacock streaming TV.

    euroinfosec, to web3

    Crypto-seeking drainer scam-as-a-service operations are thriving, with $295 million in digital assets lost just last year to wallet drainers, researchers warn
    https://www.databreachtoday.com/crypto-seeking-drainer-scam-as-a-service-operations-thrive-a-24107

    villares, to random Portuguese
    @villares@ciberlandia.pt avatar

    Um lembrete: cuidado com #SMS dizendo que é dos #Correios e que houve algo com a sua entrega e você precisa preencher dados em um link, é #phishing (um tipo de fraude que tenta "pescar" dados sigilosos das vítimas, originalmente por email).

    Maltego, to blackfriday

    How to investigate a suspect #phishing domain in #Maltego? We divided the workflow into 5 steps:

    Step 1: Starting with a Phishing Domain
    Step 2: Map out Infrastructure & Threats
    Step 3: Dive into Relevant Data
    Step 4: Explore Threat Network
    Step 5: Uncover Internet Relationships

    Our guest author, @MarioRojas, detected and mapped out the network of the phishing sites that flourished during #BlackFriday and #CyberMonday using Maltego, @DomainTools, urlscan.io, and WhoisXML.

    Hunt down the fraudulent domains with Maltego NOW: https://www.maltego.com/blog/hunting-phishing-sites-in-the-festive-season-with-maltego/?utm_source=mastodon&utm_medium=social&utm_campaign=CSO&utm_content=maltego.com

    redstarfish, to email

    I received this mail today from <postmaster@disroot.org> which says my password is about to expire. I'd have considered it phishing email except from the address it came. So when I clicked on the link it took me to https://bonusrnp.com/eky/index.html#abhiseckpaira@disroot.org which is not https://disroot.org.

    So I guess it is a phishing attack after all?! #phishing #Email #disroot

    Screenshot of the email I received

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • everett
  • rosin
  • Youngstown
  • ngwrru68w68
  • khanakhh
  • slotface
  • InstantRegret
  • mdbf
  • osvaldo12
  • kavyap
  • cisconetworking
  • DreamBathrooms
  • ethstaker
  • Leos
  • magazineikmin
  • thenastyranch
  • modclub
  • GTA5RPClips
  • tacticalgear
  • provamag3
  • normalnudes
  • cubers
  • Durango
  • tester
  • megavids
  • anitta
  • lostlight
  • All magazines