Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Threat actors leverage document publishing sites for ongoing credential and session token theft

released on 2024-03-14 @ 04:31:34 PM
Cisco Talos Incident Response has observed threat actors using legitimate digital document publishing sites to host phishing documents and steal credentials. The sites' reputation, customization options, and transient nature create advantages for attackers trying to bypass defenses. Security teams should block these sites if possible, update phishing protections to detect them, and train users to identify and report suspicious documents from unfamiliar sources.