GMAIL phishing attack saga

imagensecforcepost.png

It all started a week ago. Some news hinted that some attackers were stealing domains taking advance of a Gmail vulnerability. Even when it was not confirmed, the story was Digged and generated quite a lot of buzz in the security community.

It all seemed that a new version of an old GMail hijack technique

On Tuesday Google confirmed that no known vulnerabilities were affecting Gmail and that the incidents were phishing attacks whereby attackers set up fake websites asking for Gmail username and password.

This is very interesting because it reinforces the theory that simple attacks targeting human security awareness are still very effective. At SECFORCE we work with our clients to increase security awareness and prevent this kind of attacks form happening.

You may also be interested in...

imagensecforcepost.png
July 15, 2011

Penetration testing - GUI Manipulation

GUI manipulation during a penetration testing exercise. The penetration test required modification of disabled fields in the target GUI

See more
imagensecforcepost.png
Jan. 18, 2019

Your Voice Is My Password

In the current technological landscape, A.I. is playing a major role in trying to provide user-friendly and more secure bio-metrics authentication schemes including but not limited to Face and Voice authentication.

See more