📰 Abnormal Security News
Page 29 - Abnormal Security News Today
Fast, Ad-Free News Updates
Stay updated with breaking news from Abnormal Security. Real-time updates on events, politics, business and more.
February 17, 2021
SolarWinds-style email compromise attacks go mainstream The supply chain attack involving SolarWinds software last year has caused ripples throughout the cybersecurity industry, not least because it went undetected for nine months. The attack was able to bypass traditional email security by exploiting trusted communications routes between vendors and customers. A worrying new report from Abnormal Security shows that this technique is becoming a mainstream attack vector. Between the third quarte...
January 29, 2021
Two new phishing tactics use the platform’s automated responses to evade email filters. Two fresh business email compromise (BEC) tactics have emerged onto the phishing scene, involving the manipulation of Microsoft 365 automated email responses in order to evade email security filters. In one case, scammers are targeting victims by redirecting legitimate out-of-office (OOO) replies from an employee to them; and in the other, read receipts are being manipulated. Both styles were seen being us...
January 27, 2021
Building 92 at Microsofts headquarters in Redmond, Washington. (Coolcaesar via CC BY-SA 4.0)(Coolcaesar via CC BY-SA 4.0) Researchers have discovered two business email compromise (BEC) attack techniques that exploit Microsoft 365 âread receiptâ and âout of officeâ message loopholes to evade auto-remediation of a malicious email. In a blog posted Tuesday, Abnormal Security reported that in using these techniques, scammers target victims with BEC extortion notes by redirectin...
January 26, 2021
BEC Scammers Find New Ways to Navigate Microsoft 365 Their techniques made use of out-of-office replies and automatic responses during the 2020 holiday season, researchers report. Business email compromise (BEC) scammers targeted victims out-of-office replies and read receipts during the 2020 holiday season, when many took time off work and automatic replies were more prevalent, researchers report. Related Content: Attackers targeted victims by redirecting their own Microsoft 365 out-of-office ...
January 13, 2021
Drata raises $3.2M for its compliance audit platform Drata, a startup that helps businesses get their SOC 2 compliance, today announced that it has raised a $3.2 million seed round led by Cowboy Ventures and that it is coming out of stealth. Other investors include Leaders Fund, SV Angel and a group of angel investors. Like similar services, Drata helps businesses automate a lot of the evidence collection as they prepare for a SOC 2 audit. The focus of the service is obviously on running tests ...
January 6, 2021
Get Permission The Australian Cyber Security Center is warning that fraudsters have recently started sending phishing emails that spoof the agency and contain malware designed to steal banking credentials. In an alert, the agency notes hackers posing as ACSC employees are sending emails requesting that recipients download antivirus software. When the victim clicks on a link, malicious code that can steal banking credentials is downloaded onto the compromised device. The fraudsters also are usi...
December 24, 2020
A small United States Postal Service truck seen in Carson City, Nevada. (John Phelan/CC BY 3.0) Abnormal Security reported Wednesday that its email security platform blocked a credential phishing attack impersonating the U.S. Postal Service that sought to get victims to give up their credit card credentials and pay a special delivery fee within three days to ensure package delivered. In a blog post today, Abnormal Security said the attackers sought to take advant...
December 24, 2020
Get Permission The FBI is warning that fraudsters are exploiting the recent news surrounding the availability of COVID-19 vaccines to launch schemes to steal personal information and money. The warning issued this week included input from the U.S. Department of Health and Human Services Office of Inspector General and the Centers for Medicare and Medicaid Services. The alert notes that scams may involve offers for early access to vaccines by paying in advance, requests for cash to receive a va...
December 23, 2020
Get Permission Phishing email designed to look like a message from the New York State Department of Labor (Source: Abnormal Security) A recently uncovered phishing campaign is spoofing messages from the New York State Department of Labor, claiming to offer $600 as part of a COVID-19 relief program, according to researchers at Abnormal Security. The goal is to harvest personally identifiable information. This phishing campaign, which appears to have started earlier this month, may have targeted...
December 22, 2020
Phishers Spoof New York Department of Labor Scammers are impersonating New York States Department of Labor to steal personal information from state residents seeking to claim money from a COVID relief fund. Targets are sent an email bearing the state logo that appears to come from “noreply@labor.ny.gov.” The email states that by activating their account, the recipient will receive $600 in pandemic aid. It reads: "Dear Citizen, Due to Covid-19 related issues...