Posts

Showing posts with the label Google Workspace

Russian state hackers swap malware with cloud-based attacks

By Vilius Petkauskas,  Cybernews Russian adversaries increasingly focus on targeting the cloud environment, Crowdstrike’s Global Threat Report on Cloud Security revealed. Fancy Bear, a Russian adversary associated with Russia’s Main Intelligence Directorate (GRU), used to rely on malware-based spear-phishing attacks, the report claims. However, with their tactics exposed by the US Department of Justice (DoJ), hackers have refocused their attention on cloud service providers. Since Fancy Bear’s primary source of intelligence comes from various credential harvesting practices that allow penetrating target organizations and individuals, it’s no surprise that the main targets are cloud-based email providers. According to the report, Fancy Bear focused their attention on service providers such as Microsoft 365, Google’s GSuite, as well as webmail providers that individuals usually use. Meanwhile, Cozy Bear, Russia’s state-sponsored hacker group controlled by the Federal Security service...

Google Chat Adds Warning Banners To Protect Against Phishing Attacks

Image
By Kavita Iyer, Tech Worm In its latest attempt to prevent phishing, Google has expanded its warning banner feature to Google Chat to help protect users against malicious users and keep their data safe. These warning banners, which are already available in Gmail and Google Drive, would warn users against potential phishing and malware messages coming from users with personal Google Accounts. “In Gmail, warning banners are displayed when responding to emails sent from outside of your organisation. Now, Android warning banners are also displayed as you add new external recipients. Admins can turn these specific warning labels on or off for their organisation,” Google announced in a blog post on Thursday. The new ‘red warning’ banner will appear at the bottom of the mobile and desktop web app with the invites from users with personal Google Accounts. The message displayed will be, “This invite is suspicious. This conversation contains links to known phishing sites that may try to steal yo...

Google SMTP relay service abused for sending phishing emails

By Bill Toulas, Bleeping Computer Phishing actors abuse Google's SMTP relay service to bypass email security products and successfully deliver malicious emails to targeted users. According to a report from email security firm Avanan, there has been a sudden uptick in threat actors abusing Google's SMTP relay service starting in April 2022. The company has detected at least 30,000 emails in the first two weeks of April being distributed through this method. Attack details Google offers an SMTP (Simple Mail Transfer Protocol) relay service that can be used by Gmail and Google Workspace users to route outgoing emails. Businesses use this service for various reasons, ranging from not having to manage an external mail server to using it for marketing emails, so their mail server does not get added to a block list. Avanan states that threat actors can utilize Google's SMTP relay service to spoof other Gmail tenants without being detected, as long as those domains do not have a DM...