“Cybercriminals are gaining access to email accounts,” the FBI warned this week, even when accounts are protected by multifactor authentication (MFA). Attacks begin when users are lured into “visiting suspicious websites or click on phishing links that download malicious software onto their computer.”
pull down to refresh
related posts
I'd love some description of how these "suspicious websites" are managing to get cookies from other domains. If I had to guess they are poisoning DNS caches as it's the main attack that companies like google can't fully defend against.
Good question, I was wondering about the commonality of the source folks are getting these. Are they all targeted or broad sweeping?
If you're going through the trouble of poisoning a dns cache, seems like you ought to have more than one target, but maybe not