Key takeaways “Endpoint” is industry shorthand for a device someone actually uses: a phone, a laptop, a tablet, a desktop. Attacks on personal devices now mostly aim to quietly copy what is already signed in, not to break anything you would notice. Most of the protection you need is already built into your device and […]
Read MoreKey takeaways An active phishing campaign is taking over Microsoft 365 accounts by relaying the genuine sign-in page, so multi-factor authentication is completed correctly and the resulting session is stolen anyway. Hundreds of organisations were targeted by email in July across healthcare, education, manufacturing, government and professional services in the United States, Canada and Europe. […]
Read MoreAttackers have been taking administrative control of the Wi-Fi gateways that hotels and conference centres use to run their guest networks, then quietly rewriting DNS so that travelling employees who try to reach Microsoft 365 land on a page the attacker controls instead. The activity was documented by ReliaQuest Threat Research and has been running […]
Read MoreKey takeaways: HackOnChat is a global scam, uncovered by security firm CTM360, that hijacks WhatsApp accounts using fake login pages. It works two ways: hijacking your WhatsApp Web session, or tricking you into handing over a verification code. The scam spreads through trust. Once an account is taken over, it messages that person’s contacts asking […]
Read More