Seguridad Mania.com - España y América Latina
Portal sobre tecnologías para la seguridad física
- Destacamos »
- software Anti Blanqueo
PR Newswire
CHARLOTTESVILLE, Va., April 11, 2022
CHARLOTTESVILLE, Va. , April 11, 2022 /PRNewswire/ -- A clever new credential phishing attack known as "Browser-in-the-Browser" (BitB) has recently emerged which could catch many employees off-guard, leading to dangerous account takeover attacks that impact corporations.
The BitB attack, which is now being used by the Ghostwriter hacking group, is nearly invisible to its victims since it deftly exploits the single sign-on (SSO) authentication method common on websites. The attack imitates a legitimate SSO popup window, such as "Sign in with Google" or "Sign in with Facebook," and is even able to spoof a real URL address, which makes it difficult to tell if the login window is fake.
SafeGuard Cyber is warning companies to expect more targeted BitB attacks, since this credential phishing tactic is extremely convincing and easy for criminal hackers to implement. As the world's leading provider of security and compliance solutions for today's communications-based threats, SafeGuard Cyber has created a helpful online explainer of the BitB attack method, along with key security advice for companies to follow.
"BitB is a new social engineering tactic that only recently came to light, but it is likely to become a popular tactic among many criminal and nation-state groups due to its effectiveness and ease of use," said Chris Lehman, CEO of SafeGuard Cyber. "This is part of a larger strategy shift we are seeing among threat actors to target companies through the periphery, such as employees' personal accounts, where there is less security monitoring in place. By attacking an employee's personal email or social media account, the threat actor can more easily harvest a credential that may be reused on a corporate account. But they can also utilize these personal email and social media accounts as a staging ground for secondary social engineering attacks on other employees within the company."
Here are several security tips about BitB:
For more information about the BitB attack and how to defend against it, read SafeGuard Cyber's online explainer: "New BitB Attacks Show Credential Phishing Isn't Just an Email Problem."
About SafeGuard Cyber
SafeGuard Cyber provides security and compliance for human connections so enterprises can trust modern communications. With patented Natural Language Understanding technology, our security solutions deliver comprehensive visibility, detection and response to threats across the disparate communication methods used by today's digitally enabled businesses. In addition, cloud-based machine learning provides compliance solutions for governance and policy enforcement that empower customers to communicate through modern apps and social networking. Learn more at www.safeguardcyber.com.
View original content to download multimedia:https://www.prnewswire.com/news-releases/safeguard-cyber-provides-security-advice-for-defending-against-browser-in-the-browser-bitb-attacks-301522908.html
SOURCE SafeGuard Cyber
Publicamos interesante Informe de más de 48 págs y varios videos demostrativos sobre los posibles ataques a los robots de montaje de las fábricas. ... Leer más ►
Publicado el 22-Jun-2017 • 10.48hs
Publicado el 20-Jun-2017 • 20.22hs
Dirigido tanto a los principiantes, como a los expertos en seguridad informática y sistemas de control industrial (ICS), este libro ayudará a los lectores a comprender mejor la protección de normas de control interno de las amenazas electrónicas. ... Leer más ►
Publicado el 3-Ene-2012 • 20.16hs
Publicado el 25-Set-2009 • 01.26hs
Publicado el 17-Dic-2008 • 08.32hs