Sophisticated Phishing Attacks Outsmarting Savvy Users

  Рет қаралды 1,570

Kathy Zant

Kathy Zant

2 ай бұрын

A recent attack targeting LastPass users used email, SMS, and voice calls to trick targets into divulging their password vault master passwords. A deeper look at these attacks shows how sophisticated phishing kits have become. Not only are attackers using phishing via email, but they're also corroborating false information with phone calls and text messages.
Lookout, a data-centric cloud security company, investigated this kit in action to see how threat actors were leveraging new tools to trick users.
More about the LastPass campaign:
arstechnica.com/security/2024...
Previous videos about LastPass:
• LastPass Password Vaul...
• The LastPass Hack Has ...
• New Information on the...
Lookout's threat research:
www.lookout.com/threat-intell...
===========================
Get Private Internet Access, the best VPN available:
zant.fyi/piavpn
Get CyberGhost for privacy:
zant.fyi/cyberghostvpn
===========================
Sign up at Proton Mail for secure mail:
zant.fyi/Proton
Remember to set up 2-factor authentication using a reputable 2FA application!
===========================
Get the WordPress Security Mini-Course:
zant.fyi/mini-course-yt
===========================
Connect with me!
===========================
Tik Tok: ➡︎ / kathyzant
X: ➡︎ x.com/@kathyzant
Instagram: ➡︎ / kathyzant
Facebook: ➡︎ / kathyzant
LinkedIn: ➡︎ / kathyzant
Website: ➡︎ www.zant.com/
#cellphonesecurity #emailprivacy #cellphoneprivacy

Пікірлер: 19
@D.von.N
@D.von.N 2 ай бұрын
Sandboxing (so far) is a safe way to open risky attachments or other files. Virustotal is good at eliminating potential threats. One antivirus can fail spotting malware, but over 70 different vendors have better chance against malware.
@bwgosselin
@bwgosselin 2 ай бұрын
Use temp email to give out. Use virtual machines
@David-zp8rx
@David-zp8rx 2 ай бұрын
Thanks to Microsoft for their ridiculous URLs people are so used to constantly typing microsoft credentials in these random (legitimate) hard to read URLs, it makes it hard for average users to discern. Thanks MS..
@KathyZant
@KathyZant 2 ай бұрын
MS security concerns are the gifts that keep on giving. 😩
@octonoozle
@octonoozle 2 ай бұрын
I don't use the internet.
@KathyZant
@KathyZant 2 ай бұрын
Perfect. The solution to everything.
@MacS7n
@MacS7n 2 ай бұрын
Which password manager do you use? I need to start using a password manager. Great video btw
@KathyZant
@KathyZant 2 ай бұрын
There are quite a few password managers that are quite good. Bitwarden free is the easiest to get started with; the paid version is only $10/yr. NordPass is good, as is 1Password. I have friends who love Keeper. Given the problems LastPass has had, I'd avoid that one.
@MicroOrbit
@MicroOrbit 2 ай бұрын
Hi Kathy, great video! I use a unique email, yubi key, never click on links or give info over the phone (even if it is the "IRS"). If one wanted a career in cyber without college, how would you go about it? Video idea?
@KathyZant
@KathyZant 2 ай бұрын
Great idea for a video. I didn't study cybersecurity in college as it wasn't a thing back then. I'll put together some thoughts and post a video. Thanks for watching and for the suggestion!
@RCohle452
@RCohle452 2 ай бұрын
The change some of the letters to cyrillic characters that look similar to the alphabet characters.
@D.von.N
@D.von.N 2 ай бұрын
And that is a growing problem. People cannot trust their eyes these days.
@KathyZant
@KathyZant 2 ай бұрын
Yep, that and homoglyph swapping are used frequently.
@datajake1999
@datajake1999 2 ай бұрын
@@D.von.N When a screen reader encounters these strange characters, the URL is read out in an unusual way. For example, a character that visually looks like a slash is read as divided by, and this will most likely tip off the user letting them know that something phishy is going on (pun intended).
@BrianWoodruff-Jr
@BrianWoodruff-Jr 2 ай бұрын
So what are sites like Amazon supposed to do, not send "update on your package" emails? If everyone is sus, then what's the point? I chose to trust >0 emails, which videos like this make me feel ashamed of.
@KathyZant
@KathyZant 2 ай бұрын
Don’t feel ashamed, at all. Just be aware of what attackers are up to. Hopefully you feel more empowerment through knowledge than anything else. They’re getting more sophisticated, which means we have to be more aware.
@D.von.N
@D.von.N 2 ай бұрын
Hmmm if they click on anyhing sent to them out of blue, even if a follow up, they aren't that savvy then. Always don't trust any links in mobile media where you cannot hover over them or inspect the link in detail independently. This is why I hate smartphones as supposed computers. You have your hands tied in some aspects as an average user. All that advice for the use on PC doesn't quite work in mobile devices. Always search the website of the company and log into it by yourself. Just beware of sponsored links. Those might be phishing sites, too.
@KathyZant
@KathyZant 2 ай бұрын
This phishing campaign definitely targets the limited mobile experience. And yes, ads can be malicious, too. Good advice.
@D.von.N
@D.von.N 2 ай бұрын
@@KathyZant There was a warning somewhere, when people look for a contact number to call usual companies, they just search it and use anything that appears in the first searches, the company name and their number, not knowing they can be fraudulent pages pushed to the top by skilled scammers. Always look for a proper website and use their proper number under 'about us' section.
Info Stealers: The Latest Threat to Your Assets
17:14
Kathy Zant
Рет қаралды 770
SIM Swap Attacks More Common: How to Protect Yourself
17:47
Kathy Zant
Рет қаралды 12 М.
Llegó al techo 😱
00:37
Juan De Dios Pantoja
Рет қаралды 56 МЛН
No empty
00:35
Mamasoboliha
Рет қаралды 6 МЛН
Best KFC Homemade For My Son #cooking #shorts
00:58
BANKII
Рет қаралды 65 МЛН
39kgのガリガリが踊る絵文字ダンス/39kg boney emoji dance#dance #ダンス #にんげんっていいな
00:16
💀Skeleton Ninja🥷【にんげんっていいなチャンネル】
Рет қаралды 8 МЛН
NEVER install these programs on your PC... EVER!!!
19:26
JayzTwoCents
Рет қаралды 3 МЛН
Phishing Resistant MFA How it Works!
15:26
Andy Malone MVP
Рет қаралды 12 М.
Under the Hood | Episode 3: Building apps with Claude in minutes
27:53
Incredible Dangers in Browsers (Affects all of them)
21:02
Rob Braxman Tech
Рет қаралды 289 М.
How to Get a Verified Email Badge (Extremely Rare)
26:24
ThioJoe
Рет қаралды 500 М.
When Did Raspberry Pi become the villain?
21:54
Jeff Geerling
Рет қаралды 1,5 МЛН
10 WordPress security mistakes you're probably making
17:24
Kathy Zant
Рет қаралды 1,1 М.
BEST Password Manager 2024 | TOP provider revealed!
15:08
CyberNews
Рет қаралды 41 М.
The Cellular Network is Way Too Easy to Hack
12:43
Kathy Zant
Рет қаралды 472
Мировой Рекорд по Засыпанию (@DazByron )
0:30
Голову Сломал
Рет қаралды 6 МЛН
КАРОЧЕ НЕУДОБНАЯ СИТУАЦИЯ😱🔥 #shorts
0:45
ПОПОВИЧИ
Рет қаралды 7 МЛН
Они не знали, почему он так поступил, пока
0:39
КАРОЧЕ НЕУДОБНАЯ СИТУАЦИЯ😱🔥 #shorts
0:45
ПОПОВИЧИ
Рет қаралды 7 МЛН