內 容
|
- 1. Microsoft 365 Phishing Can Bypass MFA
- Summary: BigBear 2.0 uses fake Microsoft 365 sign-in pages and AiTM techniques to steal session cookies, allowing account takeover even after MFA. More than 461 organizations in 40+ countries were targeted, with 258 confirmed compromised.
- Action: Do not trust login links just because MFA is enabled. Open Microsoft 365 from the official site or a saved bookmark instead of email links.
- Reference: iThome
- 2. AI Helps Impersonate Executives and Fake Invoices
- Summary: Microsoft reported scams using generative AI to imitate executives, create fake invoices, signatures, and realistic email threads, then pressure finance staff to make payments.
- Action: Verify payment, account-change, procurement, or urgent requests through a second channel such as phone or an internal extension.
- Reference: iThome
- 3. Attackers Impersonate Students in Internship and Meeting Emails
- Summary: BlueMoon campaigns impersonated university students seeking internships or meetings. Victims were lured to malicious links exploiting browser or Windows flaws; some extensions even posed as Google Gemini tools.
- Action: Verify unfamiliar student, internship, conference, or academic emails before opening links or installing browser extensions or software.
- Reference: iThome
- 4. Chrome Zero-Day Exploited in the Wild
- Summary: Google released Chrome 153 in September with fixes for 230 security flaws, including a zero-day already exploited in attacks. Other Chromium-based browsers may also be affected.
- Action: Keep Chrome, Edge, and other browsers updated and restart promptly when an update requires it.
- Reference: iThome
- 5. Fake Giveaways and Payment Pages Remain Widespread
- Summary: Taiwan is Ministry of Digital Affairs confirmed over 22,000 scam messages in one week in early September. Common lures included free phones, prize draws, celebrity merchandise, and fake payment pages.
- Action: Be cautious with giveaways, urgent offers, and payment requests. Do not enter account, card, or personal information through unfamiliar links.
- Reference: MODA
|
|