Geekmaster 👽:system76: · @Geekmaster
165 followers · 1242 posts · Server ioc.exchange
Anonymous :anarchism: 🏴 · @YourAnonRiots
5563 followers · 34560 posts · Server mstdn.social

🚨 ALERT: Financially motivated cyber attackers are leveraging Azure Serial Console to gain full administrative access to virtual machines!

thehackernews.com/2023/05/thre

#informationsecurity #CyberSecurity #Microsoft #unc3944

Last updated 1 year ago

Opalsec :verified: · @Opalsec
124 followers · 65 posts · Server infosec.exchange

Cryptocurrency exchange operator Coinbase have disclosed an attempted intrusion by /#ScatteredSpider from early February.

The attack used SMS Phishing () to deliver a malicious URL that pointed to a credential harvesting campaign, but thankfully despite an employee falling for the fake login page, they hesitated when the attackers attempted to socially engineer their way past MFA protections.

UNC3944 is a highly capable actor that has only been growing in sophistication since their debut in the 0ktapus campaign of 2022, and one that every organisation should be wary of.

We've summarised the key TTP overlaps between these intrusions and provided some tips on how to enhance the resistance of your MFA solutions against social engineering and MFA fatigue attacks: opalsec.substack.com/p/return-

#unc3944 #smishing

Last updated 1 year ago