home.social

#phishing-prevention โ€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #phishing-prevention, aggregated by home.social.

fetched live
  1. @patrickcmiller : there is nothing sophisticated about this attack; it is business as usual.

    I'm tired of C-Level people with thick wallets who know shit.

    A zoom in of the screenshot at the top of specopssoft.com/blog/phishing- can be seen below.

    The browser's address bar clearly shows that http is used (instead of https) but more importantly, the domain name is:

    tradixyu.cfd

    Instead of complaining and looking for excuses, we need to fix the Internet as I wrote in (among other places) todon.nl/@ErikvanStraten/11565.

    #Phishing #PhishingPrevention #GoogleIsEvil #BigTechIsEvil #CloudflareIsEvil #LetsEncryptIsEvil

  2. @maaikees : unfortunately, no. If such a solution would exist, spammers and phisher-(wo)men would immediately start using it.

    Using an email provider with a good reputation *or* (evil) big tech is your best bet.

    Note: when switching email provider, first make a list of *all* websites where you have an account, either with the old email address as user-ID or another user-ID but where the old email address can be used for password resets.

    It's okay to create a new email address (using another provider and domain name), but do not close your old email account until it has been removed (or replaced by your new address) from all websites where it may be used to authenticate you.

    My advice: use a password manager (*). Apart from other advantages, if you record in it every site where you enter your email address, you'll have a nice overview of sites that know your email address.

    (*) Full list of tips:
    Dutch: security.nl/posting/912904

    English: see the list in todon.nl/@ErikvanStraten/11561

    #PasswordManager #AutoFill #PhishingPrevention #Phishing

  3. ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ง๐—ฟ๐—ฎ๐—ถ๐—ป๐—ถ๐—ป๐—ด: ๐—œ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ณ๐˜†๐—ถ๐—ป๐—ด ๐—ฎ๐—ป๐—ฑ ๐—ฃ๐—ฟ๐—ฒ๐˜ƒ๐—ฒ๐—ป๐˜๐—ถ๐—ป๐—ด ๐— ๐—ผ๐—ฑ๐—ฒ๐—ฟ๐—ป ๐—ง๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜๐˜€

    #CyberSecurity #DataProtection #MalwareAwareness #InformationSecurity #RemoteWorkSafety #CyberTraining #TechSecurity #PhishingPrevention

    youtu.be/HnMBmeyVGlQ

  4. For defending against phishing campaigns, you've got to have sensible security rules in place and a good overall security practice in your organization. You also need to be running EDR tools (EDR/XDR) and edge protection. These practices will all help, though they are not a silver bullet against the problem.

    Be aware as a practitioner if DNS over HTTPS is becoming more present on your network. If you control your own DNS resolver, that's the best way to go.

    DNS is really your friend as a security practitioner.

    Listen to the full episode of the Breaking Badness Cybersecurity Podcast here: domaintools.com/resources/podc

    #DNS #cybersecurity #infosec #infosecurity #phishing #phishingprotection #phishingprevention