Introduction
A supply chain attack, phishing, social engineering, and malware. That's what we're talking about in this week's review. I welcome you all, and I hope that you're all fine.
Let's begin.
Attackers using legitimate services for malicious purposes is not a new thing. By the looks of it, they are not stopping anytime soon.
From the article:
Google Calendar phishing is not new, with Google previously rolling out protections allowing users to block these types of invites more easily.
However, if a Google Workspace administrator does not enable these protections, you will continue to have invites automatically added to your calendars.
To be honest, I am not surprised by these kinds of attacks. Can we even call it an attack? Well, that's debatable. Nonetheless, this further proves that despite the security, malicious apps still find their way into official application platforms.
From the article:
The second malicious action performed by the app is scanning the device to retrieve all installed applications, allowing the attackers to plan their next steps.
Finally, the spyware intercepts and collects SMS messages sent and stored on the device, including one-time passwords (OTPs) and verification codes.
Credits
Cover photo by Debby Hudson on Unsplash.
That's it for this week, and I'll see you next time.
SOCIAL SHARE CARD GENERATOR