Kevin Karhan :verified: · @kkarhan
1441 followers · 102814 posts · Server mstdn.social

@b33fpebble @jnbhlr @yassie_j personally, I think that tools like enpass.io work well as that they offer only on legitimate or rather known domains, so -based doesn't work.

Plus they don't do fully-automatic auto-filling but rather expect the user to choose the credentials in an overlay offered by the extension.

So it's not as if one can provoke logins just with an HTTP(S) request.

Even then still demands one to enter a Password or PIN.

#Enpass #Phishing #typosquatting #autofill

Last updated 1 year ago

Marcel SIneM(S)US · @simsus
205 followers · 4655 posts · Server social.tchncs.de

Tippfehler: Mails fürs US-Militär gingen an Mali-Domain | heise online heise.de/news/Tippfehler-Mails

#typosquatting

Last updated 1 year ago

Patrick Borsoi · @patrickborsoi
5 followers · 117 posts · Server mastodon.nl

Security (b)log: Alphabets
look very much alike, but is a more realistic threat.

News from the big bad world: much cryptocurrency stolen | different kinds of 2FA | criminals love Telegram | lots more

securityblogpatrick-english.bl

#typosquatting #homoglyphs

Last updated 1 year ago

Patrick Borsoi · @patrickborsoi
5 followers · 117 posts · Server mastodon.nl

Security (b)log: Alfabetten
Twee druppels water lijken sterk op elkaar, maar toch kunnen ze van elkaar verschillen. Met letters is dat net zo, bijvoorbeeld als ze uit verschillende alfabetten komen. De Security (b)log legt en uit.

In de grote boze buitenwereld wordt veel cryptogeld gestolen, zijn er diverse smaken 2FA en zweren criminelen bij Telegram.

securityblogpatrick.blogspot.c

#typosquatting #homogliefen

Last updated 1 year ago

ffranz · @ffranz
0 followers · 1 posts · Server ioc.exchange

A few months ago @ggdaniel wrote about an easy way to generate regular expressions from a word list using Trieregex library. I've decided to put together a couple of examples where this approach fits really good: and link.medium.com/1DIHrNr8Yyb

#typosquatting #dataleaks

Last updated 1 year ago

GeekProjects News · @news
4 followers · 3116 posts · Server geekprojects.com
IT News · @itnewsbot
3030 followers · 253848 posts · Server schleuss.online

This Week in Security: USB Boom! Acropalypse, and a Bitcoin Heist - We’ve covered a lot of sketchy USB devices over the years. And surely you know by ... - hackaday.com/2023/03/24/this-w

#usb #news #acropalypse #typosquatting #securityhacks #hackadaycolumns #thisweekinsecurity

Last updated 1 year ago

Sven Ruppert · @svenruppert
401 followers · 161 posts · Server mastodon.social
Marcel SIneM(S)US ☑️ · @simsus
164 followers · 2187 posts · Server social.tchncs.de
IT News · @itnewsbot
2892 followers · 249868 posts · Server schleuss.online

Latest attack on PyPI users shows crooks are only getting better - Enlarge (credit: Getty Images)

More than 400 malicious package... - arstechnica.com/?p=1917705

#pypi #biz #typosquatting #coderepositories

Last updated 1 year ago

Tech news from Canada · @TechNews
269 followers · 6792 posts · Server mastodon.roitsystems.ca
Chris Partridge · @tweedge
708 followers · 675 posts · Server cybersecurity.theater

FYI: There's a massive campaign targeting PyPI. Someone's clearly reached the automation section of "Black Hat Python" 🙄

This is the same actor as highlighted by Phylum yesterday - currently they're pushing a cryptostealer everywhere they can, but who knows what's next.

Recently, they've started typosquatting the following packages (& showing example typosquat):
* xlsxwriter (ex. xlsxwwriter)
* urllib3 (rllib3)
* simplejson (simplejsn)
* requests-toolbelt (requests-toollbelt)
* discord-webhook (disocrd-webhook)
* discord-py (discod-py)
* websocket-client (weebsocket-client)
* openpyxl (oepnpyxl)
* pillow (pilloow)
* click (clickk)
* pysocks (ysocks)
* psutil (psuil)
* gitpython (gitpythn)
* pycodestyle (pycodestye)
* prompt-toolkit (prompt-toolkiit)
* beautifulsoup (baeutifulsoup)

Reports headed out to PyPI soon.

If your company uses your own PyPI mirror, I'd recommend disallowing new packages released within the past ~week (as a general precaution, tbh).

#infosec #typosquatting

Last updated 1 year ago

Tarnkappe.info · @tarnkappeinfo
1881 followers · 4117 posts · Server social.tchncs.de
Sai · @akaSAI
0 followers · 7 posts · Server infosec.exchange

Weekly

"This week Dr. Doug discusses: Empathy, back, , , Lexmark, Exchange, Russians, Iranians, Dragonbridge, Derek Johnson talks about Hive and more on the Security Weekly News."

Empathy, Bitwarden, Lexmark, Exchange, Dragonbridge, & Derek Johnson Talks About Hive - SWN #269

youtube.com/watch?v=M7D7UOyQv3

#security #news #hacking #typosquatting #bitwarden

Last updated 2 years ago

Sven Ruppert · @svenruppert
379 followers · 103 posts · Server mastodon.social
manhack · @manhack
2388 followers · 10739 posts · Server social.tcit.fr

RT @hpsecurity@twitter.com

🚨We’ve spotted several convincing campaigns using paid adverts and to trick users into downloading and – read more in our latest blog: ow.ly/iKov50MtK47

🐦🔗: twitter.com/hpsecurity/status/

#malvertising #typosquatting #vidarstealer #IcedID

Last updated 2 years ago

TOPECAX · @Topecax
24 followers · 3804 posts · Server mastodon.social

Seguro que alguna vez te has equivocado introduciendo la url en el navegador...

#typosquatting

Last updated 2 years ago

TOPECAX · @topecax
33 followers · 3539 posts · Server mastodon.cloud

Seguro que alguna vez te has equivocado introduciendo la url en el navegador...

#typosquatting

Last updated 2 years ago

ELHACKERETICO · @elhackeretico
52 followers · 9 posts · Server infosec.exchange

Nueva entrada en el Blog. En este caso, explicamos en que consiste la técnica de , qué variaciones nos podemos encontrar, como detectarlo y que herramientas usar para ello.

elhackeretico.com/typosquattin

#typosquatting

Last updated 2 years ago

Louis Lang · @louislang
70 followers · 106 posts · Server fosstodon.org

phylum.io identified possible campaign gearing up on . 17 packages published, but currently seem to be benign. Includes things like asyncoi, twien and pynalc

#typosquatting #pypi #python #infosec #tech #malware

Last updated 2 years ago