Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
US CERT Warns of Potential Hurricane Harvey Phishing Scams
Newest First  |  Oldest First  |  Threaded View
HowardE668
50%
50%
HowardE668,
User Rank: Apprentice
9/4/2017 | 1:18:25 PM
Remember emails are easily read on the web
Almost every time I order something on Ebay, within an hour or two I will get an email purporting to be from Ebay asking to 'confirm' my personal data - username, email address, login and password.  'For security reasons'.  The IP address is easily traced, they don't even try to mask it.  Comes back to a server in Prague, the Czech Republic.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
8/30/2017 | 7:31:24 AM
Re: Other Phishing scams
The part of me that has faith in mankind would like to agree with you.  The part of me that still watches endless armies of dummies open up a PDF or DOC file with a refund from the Liberty Wine company ....... 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
8/29/2017 | 1:30:43 PM
Re: Other Phishing scams
"Never had anybody alive IN Nigeria to start with" That true and there is nobody left in Nigeria since they have all been dead based on the number of emails we receive. :--))
Dr.T
100%
0%
Dr.T,
User Rank: Ninja
8/29/2017 | 1:28:55 PM
Re: Other Phishing scams
"Bank of Nigeria through a dead relative!" I agree, most people are aware of Nigeria scams, no need to fall into it anymore.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
8/29/2017 | 1:26:52 PM
Re: Other Phishing scams
"True enough but there are always phishing and phone scams running without cause or reason. " That is true. People are more vulnerable when there is a disaster, most try to help.
Dr.T
100%
0%
Dr.T,
User Rank: Ninja
8/29/2017 | 1:25:12 PM
Re: Other Phishing scams
"It's not just Harvey that's being used to scam. " That is true. I agree, after any disaster these types of scams have been increasing.
Dr.T
100%
0%
Dr.T,
User Rank: Ninja
8/29/2017 | 1:23:15 PM
Harvey
It is quite common that some people try to exploit vulnerable people, that is sad but reality that after a disaster these things jump high.
REISEN1955
100%
0%
REISEN1955,
User Rank: Ninja
8/29/2017 | 1:17:58 PM
Re: Other Phishing scams
True enough but there are always phishing and phone scams running without cause or reason.  Whenever I receive a call form a Police benefit org, I hang up ..... and never respond to those infamous $7,203,232 waiting fr me in the Bank of Nigeria through a dead relative!!!  (Never had anybody alive IN Nigeria to start wit)
jenshadus
50%
50%
jenshadus,
User Rank: Strategist
8/29/2017 | 9:48:54 AM
Other Phishing scams
It's not just Harvey that's being used to scam.  Beware of text messages with links asking for your user ID and password.  I've gotten two in as many weeks.  I immediately called the company affected only to be told these were phishing scams. 


Commentary
Ransomware Is Not the Problem
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  6/9/2021
Edge-DRsplash-11-edge-ask-the-experts
How Can I Test the Security of My Home-Office Employees' Routers?
John Bock, Senior Research Scientist,  6/7/2021
News
New Ransomware Group Claiming Connection to REvil Gang Surfaces
Jai Vijayan, Contributing Writer,  6/10/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: Zero Trust doesn't have to break your budget!
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-27479
PUBLISHED: 2021-06-16
ZOLL Defibrillator Dashboard, v prior to 2.2,The affected product’s web application could allow a low privilege user to inject parameters to contain malicious scripts to be executed by higher privilege users.
CVE-2021-27483
PUBLISHED: 2021-06-16
ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could allow a lower privilege user to escalate privileges to an administrative level user.
CVE-2021-27485
PUBLISHED: 2021-06-16
ZOLL Defibrillator Dashboard, v prior to 2.2,The application allows users to store their passwords in a recoverable format, which could allow an attacker to retrieve the credentials from the web browser.
CVE-2021-31159
PUBLISHED: 2021-06-16
Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.
CVE-2021-31857
PUBLISHED: 2021-06-16
In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a browser extension for non-website resource types.