FBI and CISA warn of an ongoing voice phishing campaign targeting remote workers in the US aimed at stealing login credentials for corporate networks/VPNs
Corporate VPNs should not be using passwords for external access. Full stop. Certificates are free to generate and deploying them to corp devices provides unphishable auth. Security keys allow cross-device use and provide nearly unphishable auth. https://krebsonsecurity.com/ ...
I've rarely heard threat intelligence people sound as urgent in their warnings about an ongoing hacking campaign as the ones who spoke to me for this story. I hope companies take this threat seriously. https://twitter.com/...
The FBI and CISA are warning about the growing threat from voice phishing or “vishing” targeting companies. Their alert comes <24h after my report on a particularly aggressive gang that's marketing a service to steal VPN credentials from company employees https://krebsonsecurity.…
The same “phone spear phishing” playbook used to hack Twitter in July has since been used against dozens of other companies, including banks, cryptocurrency exchanges and hosting providers, according to investigators tracking the new wave of attacks: https://www.wired.com/...