🕵️ SicherheitslückenWeb Application Firewall Rule Bypass in Jetpack WAF Runtime(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenCross-Site Request Forgery in WooCommerce Product and Term Ordering(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenUnescaped Output in Enable Media Replace Error View(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenStored Cross-Site Scripting in WooCommerce Order Notes REST API v4(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenUnescaped Attribute Output in Enable Media Replace Upsell View(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenWeb Application Firewall Rule Bypass in Jetpack WAF Runtime(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenCross-Site Request Forgery in WooCommerce Product and Term Ordering(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenUnescaped Output in Enable Media Replace Error View(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenStored Cross-Site Scripting in WooCommerce Order Notes REST API v4(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenUnescaped Attribute Output in Enable Media Replace Upsell View(17.09.2026 um 16:34 Uhr)
🎥 IT Security Video 🕛 vor 1 Jahr 2 Min Lesezeit SECURITY-FEED
0

Youtube virusbtn: BEC and phishing targets local election candidate me! - Andrew Brandt (Sophos)

↗ Quelle (YouTube)
🗣️ Stimme:
📺
YouTube
80 YouTube-Aufrufe

Author: Virus Bulletin - Bewertung: 0x - Views:0

Presented at the VB2024 conference in Dublin, 2 - 4 October 2024.

↓ Slides: N/A

↓ Paper: N/A

→ Details: https://www.virusbulletin.com/conference/vb2024/abstracts/bec-and-phishing-targets-local-election-candidate-me/



✪ PRESENTED BY ✪



• Andrew Brandt (Sophos)



✪ ABSTRACT ✪



During the so-called "off-year" 2023 election cycle in the United States, I ran for elected office in my hometown. In the month prior to the election – about one year to the date prior to this conference – my election campaign was targeted with a very unsophisticated BEC attack, followed by a quite sophisticated phishing attack. Other candidates who were running in the same election also received BEC emails, but fortunately, none were victimized.



So, of course, I began an investigation into the attacks against my own campaign.



This presentation will focus on both attacks as examples of the kinds of phishing that target election campaigns at all levels. BEC attacks targeting election campaigns have resulted in dramatic losses – according to Defending Digital Campaigns, one candidate for office in 2022 had more than $300,000 stolen from their accounts as a result of a BEC attack.



In many ways, political campaign operations are akin to small startup businesses: they move fast, and often have to communicate with a variety of outside organizations for the first time. Campaigns move quickly, and few candidates have cybersecurity chops, so urgent calls for action that would set off a red flag in a large enterprise might elude a candidate or campaign staffer's Spidey Sense.



I will dissect the attacks in order to determine a set of general principles that candidates everywhere should apply to protect themselves and their campaigns from phishing attacks. The phishing campaign, in particular, used some sophisticated new tools that made the attack quite convincing. I will drill down into how that attack worked, and what I did to prevent the attackers from leveraging the same tools in future phishing attacks.

Vollständiges Original-Advisory
Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Microsoft Office Ohne Abonnement? Jetzt kostet es ein paar Hundert - Jablíčkář
1 Quelle
Windows Defender: Falsche Warnung täuscht Sicherheitslücke vor - ad-hoc-news.de
1 Quelle
DFN-CERT-2026-4930 FFmpeg: Mehrere Schwachstellen ermöglichen u. a. das Ausführen ...
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten BEC and phishing targets local election candidate me! - Andrew Brandt (Sophos)

Thematisch verwandte Begriffe: phishing, targets, local, election · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...