Theme:
Light Dark Auto
GeneralPoliticsBusinessEconomyTechnologyEnvironmentScienceSportsHealthEducationEntertainmentLifestyleGeneralNationWorld
TECHNOLOGY

Phishers Exploit Google Sites and DKIM Replay to Send Signed Emails, Steal Credentials

A sophisticated phishing attack leveraged Google's infrastructure to send seemingly legitimate emails from [email protected], bypassing security checks. The emails, mimicking legal subpoenas, directed recipients to fraudulent Google Sites pages designed to steal credentials. The attack exploited a DKIM replay and a legacy Google Sites feature allowing arbitrary scripts. Google has since implemented fixes, urging users to enable two-factor authentication and passkeys for enhanced protection against such attacks. This follows similar recent attacks using Proofpoint vulnerabilities and SVG attachments.

Prepared by Jonathan Pierce and reviewed by editorial team.

Related News

Comments

JQJO App
Get JQJO App
Read news faster on our app
GET