Phishers Padding URLs with Hyphens to Target Facebook Users

Phishers are sending Facebook users fake login pages with URLs they’ve padded with hyphens, a trick which makes the sites look legitimate on mobile devices. The attack works by sending a real, legitimate domain within a larger URL that’s fake. For instance, the following link redirects users to a phishing site: hxxp://m.facebook.com—————-validate—-step1.rickytaylk[dot]com/sign_in.html. The genuine path […]… Read More

The post Phishers Padding URLs with Hyphens to Target Facebook Users appeared first on The State of Security.

Continue reading Phishers Padding URLs with Hyphens to Target Facebook Users

20 Percent of Users Still Don’t Know about Phishing or Ransomware, Reveals Survey

Digital security threats like ransomware and phishing attacks frequently make headlines these days. One would hope this publicity translates into heightened awareness and more secure behavior online by web users. To test this theory, Wombat Security surveyed more than 2,000 working adults (1,000 in the United States and 1,000 in the United Kingdom) in early […]… Read More

The post 20 Percent of Users Still Don’t Know about Phishing or Ransomware, Reveals Survey appeared first on The State of Security.

Continue reading 20 Percent of Users Still Don’t Know about Phishing or Ransomware, Reveals Survey

Hacker Admits to Stealing Military Data from U.S. Department of Defense

A hacker has admitted to stealing hundreds of user accounts from a U.S. military communications system operated by the U.S. Department of Defense (DoD). Sean Caffrey, 25, of Sutton Coldfield, pleaded guilty to the theft of U.S. military data at the Birmingham Crown Court on 15 June. His crimes amount to an offense under the […]… Read More

The post Hacker Admits to Stealing Military Data from U.S. Department of Defense appeared first on The State of Security.

Continue reading Hacker Admits to Stealing Military Data from U.S. Department of Defense

Survey: 99% of Attachment-Based Email Attacks Required User Clicks by December 2016

In May 2017, an updated version of WannaCry ransomware struck a minimum of 200,000 organizations in over 150 countries. It did so by abusing a Windows SMB vulnerability (MS17-010) using exploit code developed by the NSA and leaked online by The Shadow Brokers. As we all know, however, not all attack campaigns automatically exploit vulnerable […]… Read More

The post Survey: 99% of Attachment-Based Email Attacks Required User Clicks by December 2016 appeared first on The State of Security.

Continue reading Survey: 99% of Attachment-Based Email Attacks Required User Clicks by December 2016

Phishing Campaign Stealing Money and Data from Industrial Companies

An ongoing targeted phishing campaign is making off with industrial companies’ money and sensitive corporate information. In October 2016, Kaspersky Lab identified a spike in the number of malware infection attempts received by customers with industrial control systems (ICS) installed. The malware arrives via well crafted phishing messages that exploit a Windows vulnerability dating back […]… Read More

The post Phishing Campaign Stealing Money and Data from Industrial Companies appeared first on The State of Security.

Continue reading Phishing Campaign Stealing Money and Data from Industrial Companies