A new phishing campaign targeting US healthcare and cryptocurrency sectors is exploiting vulnerabilities in remote support tool, ConnectWise ScreenConnect. Researchers found fraudulent websites that mimic cryptocurrency platforms and healthcare organizations, which, when interacted with, initiate the download of ScreenConnect client files, creating a potential entry point for hackers. Despite no detected active communication between servers and clients, the potential for data extraction or malware deployment remains high.
Startup necromancy: Dead Google Apps domains can be compromised by new owners
Many businesses are not properly closing their Google accounts when they fail or are sold, posing significant risks, as the accounts often still give access