Technology Today

A new phishing campaign designed to harvest Cisco WebEx credentials through a security warning for the application has been discovered by the Cofense Phishing Defense Center (PDC).Surprisingly, Cisco's own Secure Email Gateway failed to catch this new campaign which was launched at a time when millions of people are working from home using a variety of online platforms and software.

Cybercriminals are well aware of this and have begun to exploit trusted brands like WebEx to deliver malicious emails to users.Video conferencing software has been targeted by attackers in the past but the rapid influx of remote workers during the global pandemic makes for easy prey for hackers.

Cofense anticipates that there will continue to be an increase in remote work phishing in the months to come.This latest phishing campaign begins with potential victims receiving an email with subject lines such as “Critical Update” or “Alert” from the spoofed address “This email address is being protected from spambots.

You need JavaScript enabled to view it. document.getElementById('cloakec4f9f6d0497325d4b8a60b2058fd91c').innerHTML = ''; var prefix = 'ma' + 'il' + 'to'; var path = 'hr' + 'ef' + '='; var addyec4f9f6d0497325d4b8a60b2058fd91c = 'meetings' + '@'; addyec4f9f6d0497325d4b8a60b2058fd91c = addyec4f9f6d0497325d4b8a60b2058fd91c + 'webex' + '.' + 'com'; var addy_textec4f9f6d0497325d4b8a60b2058fd91c = 'meetings' + '@' + 'webex' + '.' + 'com';document.getElementById('cloakec4f9f6d0497325d4b8a60b2058fd91c').innerHTML += ''+addy_textec4f9f6d0497325d4b8a60b2058fd91c+''; ”.

The body of the email explains that there is a vulnerability that the user must patch or risk allowing an unauthenticated user to install a “Docker container with high privileges on the system”.This quite clever on the part of the hackers as they have spoofed a legitimate business service and have even included links to a write-up for a legitimate vulnerability tracked as CVE-2016-9223.

To make their email more compelling, the linked article uses the same wording as the email.The attackers have also created a fake URL (https://globalpagee-prod-webex.com/signin) which, at first glance, appears quite similar to the actual Cisco WebEx URL (https://globalpage-prod.webex.com/sigin).

However, upon further inspection, it is clear that the spoofed URL contains an extra "e" and uses a dash instead of a period at the end.To carry out this attack, the hackers registered a fraudulent domain through Public Domain Registry just a few days before sending out their credential phishing email.

They even went as far as to obtain a SSL certificate for their fraudulent domain to make it appear more legitimate.

Once again though there is a discrepancy though, as the official Cisco certificate is verified by HydrantID while the attacker's certificate is through Sectigo Limited.The phishing page then redirects users to a fake Cisco WebEx login page that is visually identical to the real thing.

Once a user logs in, the attackers then have their WebEx credentials which could be sold on the dark web or used to launch additional attacks against them or their organization.Working from home certainly has its perks but remote workers must remain vigilant to avoid falling victim to this and the many other scams making their way around the internet at the moment.





Unlimited Portal Access + Monthly Magazine - 12 issues-Publication from Jan 2021


Buy Our Merchandise (Peace Series)

 


Contribute US to Start Broadcasting



It's Voluntary! Take care of your Family, Friends and People around You First and later think about us. Its Fine if you dont wish to contribute and if you wish to contribute then think about the Homeless first and Feed them. We can survive with your wishes too :-). You can Buy our Merchandise too which are of the finest quality.


STRIPE


Amazon's Philips deal has saved me from splashing hundreds at Joe and the Juice


Inspect your Wi-Fi now or you might be at 'threat' - stressing alert issued to UK homes


Spotify down: Thousands left frustrated as music service stops working


Your Freeview TV gets a free channel boost that matches Sky and Virgin Media


Virgin Media problems cautioning to millions who break 'golden rule' of good Wi-Fi


O2 issues alert to UK iPhone and Android users, neglecting 3 rules will be costly


Leading Tech: Best smartwatches we rate from Amazon, FitBit and ? 17 Samsung Galaxy deal


Spending plan friendly £& pound; 20 broadband beats Sky, Virgin, EE and more on cost while using 'quick speeds'


'I tested latest Ring Video doorbell and it's brand-new significant features may persuade you to upgrade'


AD FEATURE: Sky confirms totally free television upgrade for UK homes with 10 new things to attempt today


Surprise new Galaxy S24 confirmed that makes owning Samsung's flagship more affordable


Workplace employees swamped by tech as hybrid work increases gadget reliance


Millions of Android users placed on red alert and told to follow 3 crucial rules


Argos buyers dash to utilize new TV code that provides extremely inexpensive option to Sky


Wowcher's 'better than Black Friday' sale offers HP Chromebook laptops from £49


New Samsung Galaxy S24 could launch next month with a very surprising price


New UK Fire TV Stick rival that is 'suggested' by professionals goes on sale this week


Spending plan Garmin option will only set you back ? 60 - and it tracks your physical fitness objectives


TikTok issues urgent alerting to anybody who has actually gotten specific text


Disney+ using least expensive £& pound; 1.99 deal however it ends this week - here's how to get it


Freeview and Sky television competitor lastly gets big totally free channel boost - is it time to change


Argos is using Samsung and LG television fans ? 100 free of charge - how to claim yours


Virgin Media concerns 24-hour countdown to declare a complimentary 4K TELEVISION, act today or lose out


Countless UK homes told to follow Wi-Fi 'principle' or run the risk of broken broadband


'My wife and I left our jobs to make a fake AI-generated influencer - now she pays our wage'


Your Sky TV box may be blocked from ITV next month, simple check to avoid channel loss


Sky says 'sorry' as UK homes suffer severe TV problem, you must follow essential advice


Who still uses pagers and why did they explode in Lebanon


Amazon Big Deals Day: Samsung S24+ and Galaxy Watch6 get early cost drop





54