Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Tron (TRX) Sees 10% Price Surge Following Bittorrent Bridge Launch

    June 4, 2023

    Apple’s Reality Pro headset could make augmented reality cool

    June 4, 2023

    Girl killed, dozens injured in Dnipro blast – DW – 06/04/2023

    June 4, 2023
    Facebook Twitter Instagram
    • About Us
    • Contact Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Facebook Twitter Instagram Pinterest Vimeo
    Weis
    • Home
    • Crypto
      1. Cryptocurrency Live Price
      2. View All

      Tron (TRX) Sees 10% Price Surge Following Bittorrent Bridge Launch

      June 4, 2023

      Apple’s Reality Pro headset could make augmented reality cool

      June 4, 2023

      Girl killed, dozens injured in Dnipro blast – DW – 06/04/2023

      June 4, 2023

      NHTSA to Require Auto Braking on New Vehicles and Set Tougher Standards

      June 4, 2023

      Tron (TRX) Sees 10% Price Surge Following Bittorrent Bridge Launch

      June 4, 2023

      Crypto Rug Pull Losses Outpaced DeFi Exploits in May: Report

      June 4, 2023

      Three Reasons Behind Bitcoin's 2023 Resurgence

      June 4, 2023

      5 free ChatGPT and generative AI courses

      June 4, 2023
    • Insurance

      NHTSA to Require Auto Braking on New Vehicles and Set Tougher Standards

      June 4, 2023

      ANALYSIS – Breakup of Insurers’ Climate Coalition Driven by U.S. Regulation Fears

      June 4, 2023

      Judge Dismisses Criminal Charges Against PG&E Energy in Fatal California Wildfire

      June 4, 2023

      Reinsurers Maintain Their ‘Heightened Risk Aversion’ During June 1 Renewals: Report

      June 4, 2023

      Former Arizona County Official Who Said Election Deniers Made Work ‘Toxic’ Gets $130K

      June 4, 2023
    • International News

      Girl killed, dozens injured in Dnipro blast – DW – 06/04/2023

      June 4, 2023

      Lech Walesa joins hundreds of thousands of Poles in anti-govt march in Warsaw

      June 4, 2023

      Migrants flown from Texas to California and left outside church were ‘lied to’ | US immigration

      June 4, 2023

      Most Victims Unidentified as Relatives Struggle to Reach India Train Crash Site

      June 4, 2023

      Brazil’s Lula is right on global politics and wrong on Ukraine | Opinions

      June 4, 2023
    • Politics

      ‘Anti-woke’ GOP presidential candidate says he wouldn’t ban transgender service in military

      June 4, 2023

      Search of Nicola Sturgeon’s home ‘proportionate and necessary’, says police chief | Scotland

      June 4, 2023

      Chuck Todd stepping down from NBC’s ‘Meet The Press’

      June 4, 2023

      Signalling system error led to deadly train crash: India minister | News

      June 4, 2023

      California officials investigating migrant arrivals in Sacramento: ‘Without any advance warning’

      June 4, 2023
    • Sports

      The Ashes: Jack Leach ruled out of series with back stress fracture | Cricket News

      June 4, 2023

      French Open 2023 results: Novak Djokovic beats Juan Pablo Varillas at Roland Garros

      June 4, 2023

      Man charged after wearing shirt appearing to reference Hillsborough disaster

      June 4, 2023

      Latest from the French Open fourth round

      June 4, 2023

      Never-Ending Line for Caitlin Clark Autograph Session Shows Immense Star Power of Iowa Standout

      June 4, 2023
    • Tech

      Apple’s Reality Pro headset could make augmented reality cool

      June 4, 2023

      After investing $28B in Slack, Salesforce bets on one of its own as new CEO

      June 4, 2023

      This new Steam update will show you the lowest price a game has sold for in the last 30 days

      June 4, 2023

      What could Apple’s VR headset possibly do to justify its $3,000 price tag?

      June 4, 2023

      What Would AI Regulation Look Like?

      June 4, 2023
    • Shop
    Subscribe
    Weis
    Home»Tech»More Microsoft 365 phishing attacks are using this dangerous new method – here’s what you need to know
    Tech

    More Microsoft 365 phishing attacks are using this dangerous new method – here’s what you need to know

    AuthorBy AuthorMay 26, 2023No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Modern-day phishing methods involve abusing legitimate cloud services to bypass email security solutions and place a malicious email right into the victim’s inbox.

    In this latest example, cybersecurity researchers from Trustwave found a threat actor abusing Microsoft’s Rights Management Services (RMS) to provide links to fake landing pages to their victims. The attacks are highly targeted and difficult to mitigate, researchers said.

    In the attack, threat actors use a previously stolen email account to send a message to their victim. The message contains an attachment created using the RSM service, meaning it will be encrypted and will carry the .RPMSG extension. Microsoft designed RSM to offer an additional layer of protection for sensitive files, by forcing readers to authenticate first.

    Theft of sensitive data

    Authentication can be done using a Microsoft account, or through a one-time passcode.

    Once users are authenticated and given the ability to read the message, they are redirected to a fake SharePoint document hosted by Adobe’s InDesign service. The document contains a call-to-action “Click Here to View Document”, which takes users to an empty page with a “Loading” message. It’s just a distraction, while a malicious script siphons sensitive data in the background.

    The data includes visitor ID, connect token and hash, video card renderer information, system language, device memory, hardware concurrency, installed browser plugins, browser window details, and OS architecture. Once this process is complete, the page will be reloaded with a fake Microsoft 365 login form that will steal the visitor’s login credentials and send them to the attackers.

    “Educate your users on the nature of the threat, and not try to decrypt or open unexpected messages from external sources,” Trustwave said in its report.

    “To help prevent Microsoft 365 accounts from being compromised, enable Multi-Factor Authentication (MFA).”

    Multi-factor authentication is not foolproof but makes threat actors work harder to gain access to their target endpoints. Because it’s simple to set up, MFA is praised by the cybersecurity community and considered the industry standard.

    Via: Bleeping Computer

    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleAllianz’ PIMCO Weighs Joining Investors Suing Over Credit Suisse AT1 Bonds
    Next Article Premier League finishing positions – how much is each spot worth?
    Author
    • Website

    Related Posts

    Tech

    Apple’s Reality Pro headset could make augmented reality cool

    June 4, 2023
    Tech

    After investing $28B in Slack, Salesforce bets on one of its own as new CEO

    June 4, 2023
    Tech

    This new Steam update will show you the lowest price a game has sold for in the last 30 days

    June 4, 2023
    Add A Comment

    Leave A Reply Cancel Reply

    Top Posts

    Tron (TRX) Sees 10% Price Surge Following Bittorrent Bridge Launch

    June 4, 2023

    Tablet PC Market to Witness Exponential Growth by 2028, Sources Say

    January 11, 2020

    Save $25 on Philips Wired Headphone For A Great Sounding Over-Ear Headphone

    January 12, 2020
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Crypto

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    AuthorJanuary 15, 2021
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    AuthorJanuary 15, 2021
    8.9
    Uncategorized

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    AuthorJanuary 15, 2021

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Tron (TRX) Sees 10% Price Surge Following Bittorrent Bridge Launch

    June 4, 2023

    Tablet PC Market to Witness Exponential Growth by 2028, Sources Say

    January 11, 2020

    Save $25 on Philips Wired Headphone For A Great Sounding Over-Ear Headphone

    January 12, 2020
    Our Picks

    Tron (TRX) Sees 10% Price Surge Following Bittorrent Bridge Launch

    June 4, 2023

    Apple’s Reality Pro headset could make augmented reality cool

    June 4, 2023

    Girl killed, dozens injured in Dnipro blast – DW – 06/04/2023

    June 4, 2023

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.