Twilio smished – SMS is the new achilles heel

Twilio was recently compromised after a couple of employees handed over their credentials to an attacker.  The unsuspecting employees were targeted by a Smishing attack in which they received a text message on their phone saying their passwords had expired and they needed to re-authenticate. A useful link was provided which took the employees to … Continue reading Twilio smished – SMS is the new achilles heel

Get rich in Europe for €250 (or lose it all and your personal data)

Group-IB have published a very well researched report on fake investment scams in Europe  The scam follows a well-established set of steps:1. The bogus come-on is published on social media.2. The victim is taken to a phony investment website.3. The victim enters personal information in a form on the scam site.4. A call center contacts … Continue reading Get rich in Europe for €250 (or lose it all and your personal data)

Verified Twitter accounts phished via hate speech!

Some interesting research from Malwarebytes Labs. The first was around verified Twitter accounts receiving direct messages apparently from Twitter which claimed their accounts had been flagged for hate speech. They would then be redirected to a fake Twitter help centre to input their login credentials.  The second was a Discord phishing campaign where people would recieve … Continue reading Verified Twitter accounts phished via hate speech!

Smart thermostats, Rabbits, and TV Pickup

In a paper titled Unintended consequences of smart thermostats in the transition to electrified heating, researchers discovered that most people don't bother changing the default heating times on these thermostats. As a result at 6am, the strain on the electricity grid peaks as every thermostat clicks on. Akin to launching an inadvertent DDoS attack. Of … Continue reading Smart thermostats, Rabbits, and TV Pickup