Hackers have taken advantage of compromised hotel Wi-Fi gateways to trick users into entering their Microsoft 365 credentials on fake login pages. According to research from ReliaQuest's threat team, attackers have targeted hotels and conference centers, redirecting guests without their knowledge. This method avoids traditional phishing tactics like emails or attachments, making it particularly sneaky. Anyone using hotel Wi-Fi could be at risk, especially business travelers who often access sensitive accounts. This incident serves as a reminder for users to be cautious when logging into accounts over public networks and to verify the authenticity of login pages.
Articles tagged "Phishing"
Found 415 articles
The Hacker News
Recent research from CTM360 reveals a troubling shift in phishing tactics targeting the insurance sector. Traditionally, attackers would trick victims into providing their login credentials, then use this information to compromise accounts later. However, the new approach involves real-time account hijacking, where attackers act immediately upon obtaining credentials. This evolution poses a significant risk not only to individuals but also to insurance companies, as it allows for quicker financial exploitation and potentially greater losses. Users must remain vigilant against these sophisticated phishing schemes, which are becoming increasingly effective at bypassing security measures.
SCM feed for Latest
The Vatican's 'Click to Pray' app, which is used by many for daily prayer, has been found to be leaking personal information, including names and email addresses, of hundreds of thousands of its users. This data breach raises significant concerns about user privacy and data security, particularly given the sensitive nature of the app's purpose. Users of the app are now at risk of spam and potential phishing attacks that exploit this leaked information. The incident underscores the need for organizations, especially those handling personal data, to implement stronger security measures to protect user information. This situation serves as a reminder of the importance of vigilance in safeguarding personal data, especially in religious and non-profit contexts where trust is paramount.
BleepingComputer
OnTrac, a parcel delivery company, has reported a data breach after hackers gained access to its corporate network. The company is notifying customers that their personal information may have been compromised during the incident. While details about the specific data accessed have not been disclosed, the breach raises concerns about the security of customer data in the logistics industry. This incident serves as a reminder of the ongoing risks that businesses face from cyberattacks and the importance of robust security measures to protect sensitive information. Customers are advised to monitor their accounts for any unusual activity and remain vigilant against potential phishing attempts that may arise from the breach.
A serious data leak has been discovered involving the Vatican's official prayer app, which has exposed the personal information of over 700,000 users worldwide. The leak stems from a vulnerable API endpoint that allowed anyone with a web browser to access sensitive data, including names, email addresses, countries, and user statuses. This incident raises significant privacy concerns, especially given the sensitive nature of the app and its connection to a major religious institution. Users of the app may be at risk of spam, phishing attacks, or other malicious activities due to their exposed personal information. This breach emphasizes the need for robust security measures in applications handling personal data, particularly those associated with trusted organizations like the Vatican.
The Hacker News
Researchers at Zenity Labs have identified a serious vulnerability in OpenAI's ChatGPT Workspace Agents, which they have named AgentForger. This flaw could potentially allow an attacker to use a single phishing link to create, authorize, and deploy a rogue AI agent within an organization's environment. This means that if a user clicks the link, it could lead to unauthorized actions taken by the AI, posing significant security risks. OpenAI has addressed this issue with a fix released on June 8, 2023. Organizations using ChatGPT Workspace Agents should ensure they update their systems to safeguard against this vulnerability.
Infosecurity Magazine
OpenAI's ChatGPT has made its debut in the list of the top 10 most impersonated brands in phishing attacks, according to research from Check Point. This marks a significant shift as attackers are increasingly using the chatbot's name to deceive users into revealing personal information. Phishing scams typically involve creating fake websites or emails that look like legitimate services, and in this case, scammers are leveraging the popularity of ChatGPT. This is concerning for both users and organizations, as it indicates that bad actors are targeting well-known brands to exploit their trustworthiness. Users need to be vigilant and verify the authenticity of any communication claiming to be from ChatGPT or related services to avoid falling victim to these scams.
A recent study has revealed that employees at well-funded companies are more likely to open phishing emails and attachments. In a simulation involving 13.9 million phishing messages, only 10% of recipients reported suspicious emails to their security teams. This leaves the other 90% potentially vulnerable, as attackers only need one unsuspecting employee to compromise a system. The research emphasizes the importance of employee training and awareness in cybersecurity, particularly in high-stakes environments where sensitive information is at risk. Organizations must prioritize educating their staff to recognize and report phishing attempts to reduce the chances of successful attacks.
MZ Automation's lib60870 software, used in critical infrastructure sectors like chemical, energy, and water management, has a serious vulnerability that could lead to denial of service. Specifically, versions 2.4.0 and earlier are affected by an out-of-bounds read issue, which can crash the parsing process. This flaw has a CVSS score of 8.2, indicating high severity. Users are urged to update to version 2.4.1 or later to mitigate the risk. Organizations should also follow CISA's recommendations to secure their control systems, including limiting network exposure and using VPNs for remote access. Currently, there are no reports of this vulnerability being actively exploited in the wild.
Weintek's cMT3092X human-machine interface (HMI) has several security vulnerabilities that could allow unauthorized users to escalate their privileges or access sensitive user credentials. The affected firmware versions include those below 20210218 and EasyWeb versions prior to 2.1.20. Notably, vulnerabilities include reliance on unvalidated cookies, incorrect permission assignments, and the storage of passwords in plaintext. Weintek has issued a patch, cmt_typeB_20260316_007, which upgrades EasyWeb to version 2.3.17 to address these issues. Users are urged to apply this patch immediately to protect their systems.
Recent vulnerabilities in MZ Automation's libIEC61850 could allow unauthorized attackers on the same network to crash vital IEC 61850 services or run arbitrary code. This affects all versions of libIEC61850 from 1.0.0 to 1.6.1. With these weaknesses, critical control and protection functions could be significantly disrupted, posing a serious risk to industrial control systems. MZ Automation recommends that users update to the latest version of the software to mitigate these vulnerabilities. Although no known exploitations have been reported, organizations should take immediate action to secure their systems by minimizing network exposure and using secure remote access methods like VPNs.
Rockwell Automation's ThinManager software has a significant vulnerability that allows authenticated attackers to write files to restricted directories outside the intended application area. This issue affects several versions, specifically ThinManager versions 13.0.0 through 14.0.2. Users who cannot upgrade to the patched versions—13.1.6, 13.2.5, and 14.0.3—are advised to follow security best practices provided by Rockwell. The vulnerability, classified as a path traversal issue, has a high severity score of 8.1. Although no known active exploitation of this vulnerability has been reported, organizations should remain vigilant and implement defensive measures to protect their control systems.
Johnson Controls has reported significant vulnerabilities in its C-CURE 9000 and Victor application server software that could allow attackers to execute arbitrary code remotely. Specifically, versions of the C-CURE 9000 and Victor applications up to v2.90_v3.0 and Victor Web versions up to v7.1 are impacted. An attacker on an adjacent network could exploit these flaws to compromise physical security controls and access sensitive information. The vulnerabilities have been assigned high to critical severity scores, highlighting the urgency for affected users to take action. Johnson Controls recommends upgrading to the latest versions and implementing various security measures to mitigate risks.
Recent vulnerabilities have been discovered in Panduit's IntraVUE software, affecting versions 3.2.1a14 and earlier. These security flaws could allow attackers to manipulate industrial control devices remotely without needing physical access or specialized tools. Notably, one vulnerability involves the storage of passwords in plaintext, which could expose sensitive credentials via the API. Users are urged to upgrade to version 3.2.1a16 or later to mitigate these risks. With potential impacts on critical infrastructure sectors including manufacturing, energy, and water systems, the urgency for organizations to update their software is high to prevent exploitation.
The article recounts the experience of an individual who fell victim to identity theft after inadvertently providing a two-factor authentication code to a scammer. This mistake allowed the attacker to gain control of the victim's email account, leading to a cascade of security issues. The story illustrates a critical vulnerability many people face: the security of their online accounts often hinges on the protection of their email. When scammers compromise an email account, they can reset passwords and access sensitive information across various platforms. This incident serves as a cautionary tale about the importance of safeguarding personal information and being vigilant against phishing attempts.