#vishing — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vishing, aggregated by home.social.
-
Questel (IP-Dienstleister) bestätigt einen Sicherheitsvorfall: Über einen Voice-Phishing-Angriff erlangten Angreifer Zugriff auf eine SharePoint-Umgebung in Microsoft 365. ShinyHunters behauptet den Diebstahl von über 21 Mio. Datensätzen und 147 GB Daten.
Kein technischer Exploit, sondern gezielte soziale Manipulation am Telefon. Ein weiterer Beleg dafür, dass Awareness-Maßnahmen gegen Social Engineering mindestens so wichtig sind wie technische Schutzmechanismen.
-
BlackFile Rebrand: Google Links Extortion Group to Redact - https://www.redpacketsecurity.com/google-links-redact-extortion-group-to-blackfile-rebrand/
-
UNC6671 non è mai morta: dietro Redact, Pink, Helix e Falcon c’è sempre BlackFile
Google Threat Intelligence Group svela come il gruppo di estorsione UNC6671, dato per chiuso a maggio con il ritiro del brand BlackFile, sia in realtà proseguito sotto quattro nuove insegne. Vishing mirato, phishing AiTM e furto di dati SaaS colpiscono private equity, hedge fund e big della finanza globale. -
Voci clonate contro Wall Street: il vishing che ha colpito Citadel, Point72 e Two Sigma in un solo giorno
Il 5 agosto una campagna coordinata di vishing basato su sistemi computazionali ha preso di mira Citadel, Point72, Two Sigma e Millennium Management usando voci clonate di dirigenti. L'attacco ha attivato per la prima volta il FINRA Fusion Center e riporta alla ribalta il precedente del cluster UNC3753/Luna Moth. -
#MicrosoftTeams #vishing attacks lead to #Chaos #ransomware attacks
-
📣⚠️📞 Beware: Attackers posing as IT support staff are using Microsoft Teams and Quick Assist to access employee computers and install a new backdoor called #GoGRPC in attacks suspected of supporting ransomware operations.
Listen/Read: https://hackread.com/fake-it-calls-microsoft-teams-gogrpc-backdoor/
#CyberSecurity #Backdoor #Malware #MicrosoftTeams #Vishing #Scam
-
What communities / forums discuss #PhoneSpam?
I'm looking for serious discussion on telemarketing, robocalls, AI calls, and unsolicited voice or text comms generally. Here on the Fediverse or elsewhere.
I'm aware that the #FCC has / has had several recent rulemaking requests for comment. I'm afraid I've missed most such windows.
I'd like to know what's being tried, successfully or otherwise, throughout the world. The problem seems severe in the US presently, but I suspect it's growing elsewhere. AI will all but certainly open new avenues for abuse.
What hashtags are being used for discussion? Are there any Fediverse groups formed on the topic?
Reboosts greatly appreciated.
DM if you prefer, though I'd generally appreciate an open thread.
-
Charter Communications: Sicherheitsvorfall #Datenleck #Datendiebstahl #Vishing #Erpressung #TeamInfoSec #cyberangriff https://www.security-incidents.de/sicherheitsvorfaelle/sicherheitsvorfall-charter-communications-US-12618.php
-
#Entra #passkey enrollment #vishing targets #Microsoft365 users
-
Helix Group Exploits SharePoint with Advanced Vishing Tactics
Helix Group hackers are using clever voice phishing tactics, often impersonating managers, to trick victims into handing over account access. They use a simple yet effective playbook, starting with a convincing phone call that sets the stage for a device-code phishing scheme.
#VoicePhishing #Vishing #DevicecodePhishing #MfaBypass #ThreatActors
-
Luna Moth incassa 20 milioni di dollari da Weil Gotshal & Manges: il gruppo entra fisicamente negli uffici per rubare dati
La prestigiosa law firm americana Weil, Gotshal & Manges ha pagato tra i 18 e i 20 milioni di dollari al gruppo di estorsione Luna Moth (Silent Ransom Group) per impedire la pubblicazione di documenti riservati dei clienti. L'FBI ha emesso un alert FLASH documentando per la prima volta l'escalation tattica del gruppo, che ora invia operativi fisici negli uffici delle vittime quando le tecniche di accesso remoto falliscono. -
📣🚨 Cybersecurity researchers are warning businesses about #Pink Extortion Group, a new cybercrime group that uses voice phishing to bypass multi-factor authentication and steal files from cloud environments.
Read: https://hackread.com/pink-extortion-microsoft-365-cloud-data-vishing-scams/
-
Měla povědomí o podvodech po telefonu (takzvanému vishingu) a znala i možné varovné signály, podle kterých lze podvod rozeznat. Přesto šejdíři ženu z Prahy 6 během 24 hodin připravili o 600 000 korun, než si uvědomila, že se stala obětí rafinované psychologické manipulace.
Tón: : mírně negativní
#česko #gdelt #podvod #podvodníci #vishing(voicePhishing)
-
Ojo con el código 21: así funciona la estafa telefónica que desvía llamadas para cometer fraudes bancarios | vía #MalaEspinaCheck
-
📢🪝⚠️ A Romanian national accused of running #VOIP vishing scams and using fake debit cards to drain bank accounts now faces up to 30 years in a US prison after extradition from #Romania.
Read: https://hackread.com/romanian-man-30-years-us-prison-vishing-scams/
-
Four grand. That's what it costs a random kid with a laptop to run a voice phishing operation that used to require a call center, a phisher, and a developer. ATHR packages all of it into one dashboard, tosses in AI voice agents that can ad-lib when a victim gets suspicious, and ships with ready-made lures for Google, Microsoft, Coinbase, Binance, and a few more.
CyberCrime has a SaaS model now, complete with commission splits (10% of profits back to the vendor). The barrier to running a convincing vishing campaign just collapsed, and your awareness training still says "watch for typos in the email."
🎙️ AI agents handle objections live, so the "support rep" sounds real because they are, functionally, reasoning
📧 Lure emails are customized per target with accurate IPs, dates, locations, and pass authentication checks
🏦 Eight brands supported out of the box, crypto exchanges heavily represented for obvious reasons
🛡️ Stop looking at email indicators, start modeling normal communication patterns and flag the anomaliesIf your vishing defense is a 20-minute annual training video and a phish-report button, you're bringing a knife to a drone fight. The humans on the other end of the phone aren't humans anymore, and they don't get tired, rattled, or bored on calls.
#Cybersecurity #Vishing #AI #security #privacy #cloud #infosec #cybersecurity
-
Here's the thing, there may be more people (if not 99% of the people) on other social networks, but at the end the day, I still need to actually *do something* with my projects or it is all just idle entertainment under the guise of not or I have no idea.
I just want to nerd out on things that are cool to nerd out on and be able to talk about it with people that get it. That is all here.
Here are all the hashtags of things I'm working on and will be posting about, what I'm interested in from others, and whatever adjacent from folks in those spheres bubble up (I want a clubhouse).
#Malware #RedTeaming #PurpleTeaming #SocialEngineering #Vishing #ReverseEngineering
-
Vaya, parece que hoy me ha salido un "hijo" espontáneo al que se le ha ahogado el móvil.
Qué detalle que, en medio de su tragedia tecnológica, haya tenido tiempo de memorizar mi número, conseguir otro teléfono y escribirme con esa urgencia tan enternecedora (y tan falsa).Lo de "mamá" ya es de nivel avanzado de ciencia ficción, sobre todo porque no recordaba haber pasado por un paritorio últimamente.
En fin, otro que se va directo a la lista de bloqueados antes de que me pida los datos de la tarjeta para "el arroz".Cuidado con estos "accidentes acuáticos", que lo único que quieren limpiar es vuestra cuenta corriente.
╰┈ ─ ─ ─ ─ ─ ─ ┈╯
-
Heute ist die Polizei anwesend und warnt vor Trickbetrügern. Die Betrüger rufen gezielt ältere Menschen an und es gibt aktuell eine Häufung von Fällen in der Umgebung der Milbertshofener Straße.
-
Sicherheitslücke bei Optimizely #Sicherheitslücke #Datendiebstahl #Vishing #menschliches Versagen #TeamInfoSec #cyberangriff https://www.security-incidents.de/sicherheitsvorfaelle/sicherheitsluecke_bei_optimizely-11988.php
-
So, I have a loose rule of thumb that says if a podcaster is advertising something, that thing is probably a scam. (Not all podcasters, not all products.) Most of the “identity protection services“ are exactly that. Most of them are owned by data brokers, so...?
Anyway, I tell you that story to tell you this one: Aura has been breached, exposing almost a million records.
https://gizmodo.com/the-company-paid-to-protect-your-identity-just-got-hacked-2000735410
You can check Troy Hunt’s Have I Been Pwned here to see if you’ve been caught up in any of the hundreds of data breaches recently: