Showing posts with the label spoofing
Bleeping Computer’s Sergiu Gatlan reports on a dire DMARC warning from the US National Security Agency (NSA): It seems that North Korea loves to send phishing emails, and they seem to be finding success by picking domains with weak DMARC policies , when looking for whom to target. I have to wonder – have they learned, possibly through that rush for everyone to implement DMARC so that everyon…
The Register's Thomas Claburn details a recently shared research paper exposing troubling examples of loopholes in email authentication , allowing bad guys to spoof messages via email forwarding. Thankfully, some of the potential loopholes reported have already been address…
Katherine Skiba for AARP reports how in just one particular month in 2021, five hundred (!) different consumer brands were hit by phishing attacks -- not just Sam's Club! And phishing attacks and email scams are big money. "Though in third place, [the FTC says that] i…
From Infosecurity Magazine: "New research from Barracuda Networks has revealed that cyber-criminals are increasingly using official reCAPTCHA walls to disguise malicious content from email security systems and trick unsuspecting users."   Read more here . Meaning, i…
Over on the Word to the Wise blog, Laura Atkins raises the concern that in response to the recent "prank" email scandal , email technologists are likely to say that this couldn't have happened if the White House had implemented DMARC. She's correct in that DM…
Somebody asked me recently, what is phishing? Instead of re-inventing the wheel, allow me to link to a few of the resources already out there that explain what phishing is and why it is a problem. What is phishing? From Wikipedia : "Phishing is the attempt to acquire sensi…