/* ---- Google Analytics Code Below */
Showing posts with label Phishing. Show all posts
Showing posts with label Phishing. Show all posts

Saturday, January 28, 2023

Guide to Phishing

 Been Phished? I have.   Schneier sends along a nice piece from TidBits on the topic.   A useful guide, history and much more.   Schneier's piece has lots of comments on experiences    . 

An Annotated Field Guide to Identifying Phish   in TidBits  and VentureBeat.

Do you like phish? Not the band, not tasty seafood dishes, and not the pretty tropical variety. I refer instead to the intellectual challenge of identifying phishing emails that attempt to get you to reveal personal information, often including login credentials or financial details, or entice you to call a phone number where trained operators will attempt to separate you from your money.

Phishing is a big deal, with a State of Phishing report  from security firm SlashNext claiming that there were more than 255 million phishing attacks in 2022, a 61% increase from the year before. The Verizon Data Breach Investigations Report for 2022 says that only 2.9% of employees click through from phishing emails, but with billions of email addresses available to target, the raw numbers are still high.   ... ' 

Sunday, October 30, 2022

Microsoft: Hackers are Using Open Source Software, Fake Jobs in Phishing Attacks

 Not very new, except in the details. seen this before.  

ACM NEWS

Microsoft: Hackers are Using Open Source Software, Fake Jobs in Phishing Attacks

By ZDNet

September 30, 2022

Microsoft is warning that hackers are using open source software and bogus social media accounts to dupe software engineers and IT support staff with fake job offers that in reality lead to malware attacks.

A phishing-happy hacking crew linked to North Korea's armed forces has been using trojanized open-source apps and LinkedIn recruitment bait to hit tech industry employees, according to threat analysts from Microsoft's advanced persistent threat (APT) research group.

The Microsoft Threat Intelligence Center (MSTIC, pronounced 'Mystic') has seen the group using PuTTY, KiTTY, TightVNC, Sumatra PDF Reader, and the muPDF/Subliminal Recording software installer for these attack since late April, according to MSTIC's blogpost....

A security team at Microsoft-owned LinkedIn said the same actors created fake profiles to impersonate recruiters from companies in the technology, defense, and media entertainment sectors.

From ZDNet

View Full Article  

Wednesday, April 20, 2022

Linkedin is Most Spoofed for Phishing

Not surprised, it has an element of respectability. 

Linkedin is most spoofed brand with Phishing  By Bill Toulas  in Bleeping Computer

Security researchers are warning that LinkedIn has become the most spoofed brand in phishing attacks, accounting for more than 52% of all such incidents at a global level.

The data comes from cybersecurity company Check Point, who recorded a dramatic uptick in LinkedIn brand abuse in phishing incidents in the first quarter of this year.

The second most mimicked brand is German package delivery DHL, which previously was at the top of the list. A contributing factor for this was the increased shopping during the holiday season. .... ' 

Friday, April 15, 2022

Novel Password Phishing

 Security issue.

A password phishing site that can trick even savvy users      in ArsTechnca

Just when you thought you'd seen every phishing trick out there, BitB comes along.

DAN GOODIN - 3/21/2022, 2:47 PM

Behold, a password phishing site that can trick even savvy users

When we teach people how to avoid falling victim to phishing sites, we usually advise closely inspecting the address bar to make sure it does contain HTTPS and that it doesn’t contain suspicious domains such as google.evildomain.com or substitute letters such as g00gle.com. But what if someone found a way to phish passwords using a malicious site that didn’t contain these telltale signs?

One researcher has devised a technique to do just that. He calls it a BitB, short for "browser in the browser." It uses a fake browser window inside a real browser window to spoof an OAuth page. Hundreds of thousands of sites use the OAuth protocol to let visitors login using their existing accounts with companies like Google, Facebook, or Apple. Instead of having to create an account on the new site, visitors can use an account that they already have—and the magic of OAuth does the rest.

Exploiting trust

The photo editing site Canva, for instance, gives visitors the option to login using any of three common accounts. The images below show what a user sees after clicking the "sign in" button; following that, the image show what appears after choosing to sign in with a Google password. After the user chooses Google, a new browser window with a legitimate address opens in front of the existing Canva window. ... '

Monday, January 10, 2022

The End of Car Keys, Payments and More

 Have recently been involved in some significant and phishing attempts on me, so am taking a deeper look at how funds are used with in consumer payment systems. Continuing talks on how this occurs in online banking.  With additional input of complex human  interaction. This piece looks at the broader issue. Will follow this up as is possible .

The End of Car Keys, Passwords, Fumbling with Phones at Checkout

By The Wall Street Journal, January 10, 2022

Ultra-wideband (UWB) technology being developed by the nonprofit FiRa Consortium could revolutionize interaction with devices, if privacy and other issues can be addressed.

UWB adds a centimeter-level sense of location to three-dimensional space by triangulating objects' positions through radio waves' travel times between devices and beacons.

Companies like Apple, luxury automaker BMW, and others have used UWB to allow users to unlock and start cars via handheld devices.

University of California, San Diego researchers demonstrated that a new type of beacon could speed UWB about 10-fold and reduce power consumption commensurately.

FiRa's Ardavan Tehrani said overcoming privacy concerns about objects and devices constantly broadcasting locations would remove a key hurdle to augmenting awareness through smart glasses and other interfaces.

From The Wall Street Journal

View Full Article - May Require Paid Subscription  ... 

Monday, October 25, 2021

MFA is Phishable

Multi factor authentication (MFA) is seen as a strong means of security, but can be less so, here some reasons why.

Why Is the Majority of Our MFA So Phishable?

Published on October 20, 2021

By Roger Grimes in Linkedin,   Data-Driven Defense Evangelist at KnowBe4

The huge push to multifactor authentication (MFA) is ostensibly to help people avoid getting so easily phished. But are we making the same mistake with MFA and making too much of it too easily phishable? Will we be pushing our organizations and end-users to MFA only to repeat many of the same mistakes? The US government is worried about it. You should be worried as well.

The U.S. government has been pushing people to avoid SMS- and voice call-based multifactor authentication (MFA) for years, but their most recent warning is to avoid any MFA that is overly susceptible to phishing. That is only commonsense (since most data breaches involve social engineering), but what MFA types do they mean and what does that mean for you? Read on.   ... '