Technology Today

A new phishing campaign designed to harvest Cisco WebEx credentials through a security warning for the application has been discovered by the Cofense Phishing Defense Center (PDC).Surprisingly, Cisco's own Secure Email Gateway failed to catch this new campaign which was launched at a time when millions of people are working from home using a variety of online platforms and software.
Cybercriminals are well aware of this and have begun to exploit trusted brands like WebEx to deliver malicious emails to users.Video conferencing software has been targeted by attackers in the past but the rapid influx of remote workers during the global pandemic makes for easy prey for hackers.
Cofense anticipates that there will continue to be an increase in remote work phishing in the months to come.This latest phishing campaign begins with potential victims receiving an email with subject lines such as Critical Update or Alert from the spoofed address meetings@webex.com.
The body of the email explains that there is a vulnerability that the user must patch or risk allowing an unauthenticated user to install a Docker container with high privileges on the system.This quite clever on the part of the hackers as they have spoofed a legitimate business service and have even included links to a write-up for a legitimate vulnerability tracked as CVE-2016-9223.
To make their email more compelling, the linked article uses the same wording as the email.The attackers have also created a fake URL (https://globalpagee-prod-webex.com/signin) which, at first glance, appears quite similar to the actual Cisco WebEx URL (https://globalpage-prod.webex.com/sigin).
However, upon further inspection, it is clear that the spoofed URL contains an extra "e" and uses a dash instead of a period at the end.To carry out this attack, the hackers registered a fraudulent domain through Public Domain Registry just a few days before sending out their credential phishing email.
They even went as far as to obtain a SSL certificate for their fraudulent domain to make it appear more legitimate.
Once again though there is a discrepancy though, as the official Cisco certificate is verified by HydrantID while the attacker's certificate is through Sectigo Limited.The phishing page then redirects users to a fake Cisco WebEx login page that is visually identical to the real thing.
Once a user logs in, the attackers then have their WebEx credentials which could be sold on the dark web or used to launch additional attacks against them or their organization.Working from home certainly has its perks but remote workers must remain vigilant to avoid falling victim to this and the many other scams making their way around the internet at the moment.





Unlimited Portal Access + Monthly Magazine - 12 issues


Contribute US to Start Broadcasting - It's Voluntary!


ADVERTISE


Merchandise (Peace Series)

 


5 ways you can turn old phones, TVs and computers into useful gadgets


Apple iPhone 16e costs and when UK fans can get their hands on it


Back-to-basics gadget guarantees to help you write without interruptions


Virgin Media will give you a free 4K television or ₤ 200 if you switch this month


Brand new smartwatch launches with embarrassing typo software updates can't fix


Apple launches smart new iPhone 16e today and you'll be very surprised by its price


Researchers discover the science behind eBay bidding - it's all in the timing


Amazon shoppers swap Fitbit for 'impressive' smart watch that's 20% off and 'does it all'


'I'm a computer professional &-- this is the reason your keyboard has a Shift secret'


Amazon axes TikTok-style shopping feature after simply 3 years


Changes to Chrome suggest Google can now track you throughout all your gadgets


New Apple iPhone: The Sky, O2, and Vodafone pages to save before expected SE launch


Facebook users will see one significant modification in brand-new Meta update


Tech influencer makes iPhone 17 predictions and says 'fresh' upgrades are needed


Gaming expert swears by this £17 Amazon gadget that's a 'must' for PS5 players


Urgent UK Wi-Fi risk confirmed - check your broadband router right away


Oxford scientists achieve teleportation in major quantum supercomputer breakthrough


Tech specialist's four reasons not to update your mobile phone every year


Substantial complimentary Sky upgrade launched today - inspect your TV now for 'boosted' brand-new features


Less than half of Brits are open to purchasing a reconditioned phone regardless of savings advantages


Are you 'a mug' for purchasing NFTs Everything you need to know about the new digital frontier


Try 5-second trick to protect iPhone after cops seize 1,000 stolen devices in week


Ex-Apple employee exposes five things you didn't know your iPhone might do


UK iPhone and Android users issued 'crucial' advice and urged to text this number now


Fly me to the Moon: When will we be able to go on holiday to space


Apple product launch: What to expect at this week's event


Star Trek's warp drive could become a reality - but there's a big problem


Community Fibre down: Huge internet outage leaves thousands without broadband


How did Elon Musk become the richest man on the planet


Time to ditch your meal Sky validates cheaper method to see TV is coming soon


You could be sitting on a fortune - how to check if you have any bitcoins


Why Gen Z and Millennials don't want to answer their phones


3 iPhone and Android apps looking to rival Meta and X with one clear difference


Fans state the best Star Wars movie is made with AI and just took 14 days to finish


Is online dating doomed Concerns swirl around Tinder’s new AI matchmaking tools


All Gmail users placed on red alert and not following advice could be 'devastating'


Finest television bundles to pair with Sky Glass gen 2 as one gets big ₤ 144 price cut


Nearly half of teens are falling prey to text scams and these are the ones to watch out for


Provide your broken Android phone to Samsung and get Galaxy S25 for an unexpected rate


Top Tech: Get the Galaxy S25 with £500 worth of freebies in deal Samsung can't beat


EE issues 'important' text warning and puts phone users on red alert today


Apple confirms something new is coming next week in very surprising announcement


WhatsApp upgrade fans have 'asked for' launches today - check your settings now


This ₤ 3 AirTag rival will have you dumping Apple and Samsung with Argos deal stack


Leading 5 clever rings to shop in 2025 to track health and wellness, according to a tech editor


Tech editor shares the 5 secret functions on your Apple Watch you may not be utilizing


Britain’s ‘worst’ broadband officially confirmed - is it time you switched


Social media users say 'hate is winning' as Google Calendar removes key feature


Necessary Freeview update finally provides TV function Sky users have loved for many years