A New Kind of Phishing Attack - ThreatWire

Поділитися
Вставка
  • Опубліковано 8 чер 2024
  • ⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️
    Support ThreatWire → / threatwire
    @endingwithali →
    Twitch: / endingwithali
    Twitter: / endingwithali
    UA-cam: / @endingwithali
    Everywhere else: links.ali.dev
    If you want to help Ali with her research project email her at endingwithaliresearch@gmail.com
    → Please include (1️⃣) the size of your company and (2️⃣) what your company does.
    [❗] Join the book club on Patreon→ / threatwire
    0:00 Intro
    0:08 - New Kind of Phishing Attack
    1:01 - Latrodectus
    3:24 - Discord DOS
    3:53 - Unsupported NAS devices left Vulnerable
    6:03 - OUTRO
    LINKS
    🔗 Story 1: New Kind of Phishing Attack
    - lutrasecurity.com/en/articles...
    🔗 Story 2: Latrodectus
    - www.darkreading.com/threat-in...
    - www.darkreading.com/cyber-ris...
    - www.proofpoint.com/us/blog/th...
    - thehackernews.com/2024/04/wat...
    🔗 Story 3: Discord DOS
    - / 1777199692184498257
    🔗 Story 4: Unsupported NAS devices left Vulnerable
    - supportannouncement.us.dlink....
    - github.com/netsecfish/dlink
    - www.computerworld.com/article...
    - www.neowin.net/news/ten-years...
    ____________________________________________
    Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community - where all hackers belong.
  • Наука та технологія

КОМЕНТАРІ • 165

  • @Jack-qj2pr
    @Jack-qj2pr Місяць тому +25

    You've grown into your role really well. You certainly come across as much more confident compared to when you started Threatwire. You're doing great!

    • @JohnPeter-yf5jf
      @JohnPeter-yf5jf Місяць тому

      Haven’t watched since she started, still a little tough but this one was important today.

    • @xxxxzzzzz5943
      @xxxxzzzzz5943 Місяць тому

      All women are QUEENS

    • @annnooon8455
      @annnooon8455 Місяць тому

      @@JohnPeter-yf5jfwhat happened to Shannon?

    • @HyperMakes
      @HyperMakes Місяць тому

      ​@@annnooon8455That's what i was wondering too. Looks like Shannon has parted away from Hak5.

    • @WhyOOWhenCanOOIIO
      @WhyOOWhenCanOOIIO Місяць тому

      @@annnooon8455 Shannon left due to health issues.
      She still posts on her channel.
      You can find her final episode where she discusses her departure in the Nov 7 2023 ThreatWire.

  • @zephyfoxy
    @zephyfoxy Місяць тому +14

    Of course Micro$hit just marks a bug as resolved without actually taking action.

    • @KDR911KO
      @KDR911KO Місяць тому

      Why? The only thing shitty is it's flaws like viruses it can get. Best option? Buy a client oem and ask network administrator with ISP to do that dual boot if you're phone is compatible with. Client OEM devices sound alot like Motorola or Verizon or metro would do

    • @secinject814
      @secinject814 Місяць тому +1

      Yeah that was the weirdest line like, okay that technique for a device compromise is "solved" as in we know how it works (yay microsoft wowee) but we ajn't doing anything.
      My rule is I never click anything in an email unless it's a password reset I know I just initiated.

  • @AQDuck
    @AQDuck Місяць тому +37

    I think if your IOT product holds important customer data it should absolutely be patched regardless of how long it's been.
    Or at the very least, when support is ended it should be cut off from the manufacturer's cloud and only work locally.

    • @ishmaelmusgrave
      @ishmaelmusgrave Місяць тому +4

      I agree.. like Fail Secure / Fail Closed

    • @billmiller4800
      @billmiller4800 Місяць тому +2

      Maybe open sourcing the software so someone else will fix it would make sense?

    • @AQDuck
      @AQDuck Місяць тому

      @@billmiller4800 Open sourcing abandonware would be an absolute dream

    • @KDR911KO
      @KDR911KO Місяць тому

      Data can be traced but can be removed from your iot devices, iasae devices. Etc he who can think like a hacker can prevent one from attack another person. 😮😅😉 Just remember that each motif can have a long term affect or effect or both? You be the judge of the that.

    • @user-ew9cf1fv4l
      @user-ew9cf1fv4l Місяць тому

      When you're a one man NOC, sometimes you gotta play for both the teams. (No homo)

  • @stevenpugh5412
    @stevenpugh5412 Місяць тому +4

    Thanks for all the work putting this together.

  • @ducodarling
    @ducodarling Місяць тому +15

    Where's the rest of the info on the phishing attack?
    How does hiding elements result in a phishing attack anyway?
    Is there a CVE?
    Suggestions for the laymen?

    • @garicrewsen1128
      @garicrewsen1128 Місяць тому +1

      Definitely the last request! TIA😊

    • @gabethedog4043
      @gabethedog4043 Місяць тому +13

      The CSS can change what the email says after it detects that it has been forwarded because an email that has been forwarded has been offset. It could be programmed to notice that, then change what the text says based on that. The scheme was to trick the first recipient to forward the email. Next, the email changes the text to something "malicious" like sending money as the article used as an example. In the long run, it appears that the email was forwarded from your boss (because it was) and says to send money. You ask your boss to confirm he sent you an email, and he says that he has indeed sent an email. He did not know you meant an email to send money. He thought you meant the innocent email which may have only said "forward this to (person 2) because I do not know his email address" but the text was changed by the CSS after detecting the format change due to being forwarded. Hopefully you understand now, and this isn't too long.

    • @OneWildTurkey
      @OneWildTurkey Місяць тому

      @@gabethedog4043 Thanks!

    • @squarefpvsmind
      @squarefpvsmind Місяць тому

      00ppLl. DQzpq v

    • @MyEyeOnAi
      @MyEyeOnAi Місяць тому

      Thank you

  • @wilgarcia1
    @wilgarcia1 Місяць тому +11

    ooff. If I ever have hardware bricked by an update. I will never buy that brand again.

  • @dunce_cap
    @dunce_cap Місяць тому +2

    Informative as always, thanks!

  • @BobCollins42
    @BobCollins42 Місяць тому +12

    D-Link says FU to its customers. I say FU to D-Link.

    • @SimonGreen85
      @SimonGreen85 Місяць тому

      Fu dlink are words to live by

    • @DinoNucci
      @DinoNucci Місяць тому +1

      Who buys D Link?

    • @BobCollins42
      @BobCollins42 Місяць тому

      @@DinoNucci Obviously, many people do, as per Ali's report.

    • @DinoNucci
      @DinoNucci Місяць тому +1

      @@BobCollins42 why

    • @Ottomanmint
      @Ottomanmint Місяць тому

      D-Link & WD Security patches either don't work as claimed or don't manifest lately...

  • @spirit.canada
    @spirit.canada Місяць тому

    You and your team are doing great! Thank you for this valuable info

  • @RidinWithMyLocsOn
    @RidinWithMyLocsOn Місяць тому +1

    Always interesting and informative, thank you! Stay safe!

  • @solarwind907
    @solarwind907 Місяць тому +1

    Good job! Thanks for the helpful content!

  • @stuxed
    @stuxed Місяць тому +1

    Shared! Thank you!

  • @briianhebert
    @briianhebert Місяць тому +3

    Thanks for the video

  • @zainuddinbrahim4625
    @zainuddinbrahim4625 Місяць тому +1

    Appreciate the info

  • @pehden
    @pehden Місяць тому

    Okay, so this is my favorite video so far, 100% at every point of it. Ready for the next one.

  • @jamescarroll6954
    @jamescarroll6954 Місяць тому

    Interesting name. Latrodectus is a genus of spiders, including Black Widow. (L. Mactans)

  • @MatthewCallier
    @MatthewCallier Місяць тому +2

    Another great episode.

  • @justforyounl7388
    @justforyounl7388 Місяць тому +2

    For the nas exploit they could just release there firmware to the public, so the open source community can do something about it!

  • @David_998
    @David_998 Місяць тому +1

    Love the smile and dimples 😊 thanks for the info

  • @MrPir84free
    @MrPir84free Місяць тому

    Imagine a car company telling their customers that their vehicles are designed to last 5 years, because that's when the warranty expires; at the end of 5 years, customers should take their vehicles to the junkyard and sell it as scrap. Then the customer should return to buy the next round of vehicles, also with a 5 year lifespan. This is what D-Link is telling their customers.
    Worse, the manufacturer created the issue by including default logins and passwords, which is an industry norm to AVOID at all costs. Yet, D-Link says to their customer base - toss it in the trash, and come buy something new instead. Folks, it's time to NEVER buy a D-Link device, even to include a unmanaged switch, or a cable ; vote with your money and send it anywhere but D-Link.

  • @zer0r00t
    @zer0r00t Місяць тому +5

    Wait Sonos never did that iirc. They simply split the systems into v1 and v2 so newer devices could only be grouped with newer devices and vice versa

    • @oxoboo
      @oxoboo Місяць тому

      I believe she was referring to Sonos's "Recycle Mode" that bricked old speakers and was required to enable for Sonos's trade-up program to get a discount.
      Edit: clarification

    • @zer0r00t
      @zer0r00t Місяць тому

      @@oxoboo hmm yea. True that. But that was opt-in. It was basically a trade-in, but without actually sending the hardware to them. So essentially it's the same thing. You 'trade-in' aka disable your old hardware and get the discount

    • @DinoNucci
      @DinoNucci Місяць тому +1

      Wrong

  • @niallflynn1833
    @niallflynn1833 Місяць тому +9

    After eol/eos, release the source code and schematics....

    • @MrPir84free
      @MrPir84free Місяць тому

      In D-Link's case, it would have meant that hackers would have gained access to the devices much earlier; default logins and passwords are always a bad thing; usually a sign of a company that does not give a crap about security, just selling product, abandoning it when it stops making money, then selling more new product just as long as they can make a dime.
      People should steer clear of D-Link products. Their approach to security and how it sees its customer base is abhorrent.

  • @mrmiyagi5
    @mrmiyagi5 Місяць тому +9

    HTML in EMAIL was a mistake bros.

  • @innerfire369
    @innerfire369 Місяць тому +1

    I just have one question about the oldest episodes of the threatwire. Where are they?

  • @Stephanie3XL
    @Stephanie3XL Місяць тому +9

    heavy going with lots of big words. simple layman's terms with what to do/not to do would help my seriously cluttered mind. happy saturday

    • @secinject814
      @secinject814 Місяць тому

      It's a balance because there's technical folk who want some details and more layman level of knowledge who just want to know what to do for protection.

  • @adonaiblackwood7172
    @adonaiblackwood7172 Місяць тому

    This is interesting! Stay aware!

  • @jordanyoung1836
    @jordanyoung1836 27 днів тому

    Always keep your emails safe

  • @DNETREAPER
    @DNETREAPER Місяць тому

    Thanks for another good video!

  • @KDR911KO
    @KDR911KO Місяць тому

    Just remember that awareness of these things matter so you can prevent another attack.

  • @infinitivez
    @infinitivez Місяць тому +3

    Grow with you, no problemo. Occasionally late, we'll eagerly wait for you all.
    But no PUPPY?!?! HOW COULD YOU DO THIS TO US?!?! 😜

    • @KDR911KO
      @KDR911KO Місяць тому

      The puppy thing is a great attachment like a call of duty attachment lol 😂 anywho she should hired by metro

    • @KDR911KO
      @KDR911KO Місяць тому

      I'm not sorry but Will be a better pet next time 😂

    • @DinoNucci
      @DinoNucci Місяць тому +1

      WAT!?

  • @KDR911KO
    @KDR911KO Місяць тому

    Kingphisher is a compaign awareness like what a ciso does

  • @FunkCakes
    @FunkCakes Місяць тому +1

    Its very annoying these situations exist. Although the public can't top this we can more careful in the selection of products we choose to use. We need to strive to not choose products that are D-Link to a bad experience. 😅

  • @SloppyPastrami
    @SloppyPastrami Місяць тому

    if a company is going to EOL/EOS a hardware product, then they should release the software and firmware so owners at least have the option to maintain them on their own.

  • @ch1pnd413
    @ch1pnd413 Місяць тому

    ❤ excellent content 👍🏻

  • @robotron1236
    @robotron1236 Місяць тому +3

    Why would people make fun of the name Ally Diamond? That's not even a weird name...

  • @hcfdewet1
    @hcfdewet1 Місяць тому

    Why does D-Link not make the EOL/EOS firmware available to the Open Source community?

  • @Rochester92G
    @Rochester92G Місяць тому

    Smart company. Gets attractive women to present technical information.

  • @debugin1227
    @debugin1227 Місяць тому +17

    dlink attitude to security is the reason I won't buy any more of their products. hard coded reds warrants and update if out of support because of the stupidity of the vendor to include one
    Mr Potato Head... Mr Potato Head back doors are not secret and they should know it

    • @xXDarthBagginsXx
      @xXDarthBagginsXx Місяць тому +2

      In the end, just build your own NAS.

    • @CanadaHasFallen
      @CanadaHasFallen Місяць тому +4

      Dlink has had a horrible reputation since....forever? at least 2005?

    • @hak5
      @hak5  Місяць тому +2

      2 points for the War Games quote ~Darren

    • @secinject814
      @secinject814 Місяць тому

      Yeah hardcoded creds are an invite for compromise. And they're usually unbelievably easy, short and predictable. Probably didnt even need to bruteforce it with a program lol

  • @woritsez
    @woritsez Місяць тому

    never trust ppl that forward email

  • @gaptastic
    @gaptastic Місяць тому +2

    You're kicking ass. I'm glad Hak5 is continuing with Threatwire and I'm glad you're taking it over. Wish you the best in this role. Ignore the haters, for haters will only hate.

  • @cesar3422
    @cesar3422 Місяць тому +1

    Nice tablecloth

  • @sandsquid
    @sandsquid Місяць тому

    You go grrl!

  • @UNcommonSenseAUS
    @UNcommonSenseAUS Місяць тому

    6:21 please validate me

  • @user-lg4le8xr4s
    @user-lg4le8xr4s Місяць тому

    Honestly, even if D-link released a patch, the type of person who is exposing an EoL device's management interface (or ANY device really) directly to the internet isn't going to update it anyways, and probably will never even hear about this CVE.

  • @IndyAdvant
    @IndyAdvant Місяць тому

    Lutra link is broken

  • @ZeNex74
    @ZeNex74 Місяць тому

    Noob now subbed and hit the bell

  • @ShinitaiKokii
    @ShinitaiKokii Місяць тому +1

    🔗 Story 1: New Kind of Phishing Attack
    link does not work!

    • @hak5
      @hak5  Місяць тому

      fixed - ali

  • @userou-ig1ze
    @userou-ig1ze Місяць тому

    2:00 have them install JavaScript?

    • @RCBMW
      @RCBMW Місяць тому

      What is she even talking about? I'm lost!!

  • @KDR911KO
    @KDR911KO Місяць тому

    I'm cool with threatwire

  • @imca_b_5517
    @imca_b_5517 Місяць тому

    It was major issue in the world 🌍 "email attack"

  • @ultranadax6852
    @ultranadax6852 Місяць тому

    Sub’d- great info and delivery!

  • @ScriptureFirst
    @ScriptureFirst Місяць тому

    🙋🏻‍♂️ startup 💎 2 man team 1️⃣ customer 😏 but he’s paying all the bills 🙌🏼

  • @vectoralphaAI
    @vectoralphaAI Місяць тому +2

    Its always hard when doing something new so its ok. You will get more comfortable with news delivery as time goes by.

  • @marks0117
    @marks0117 Місяць тому +2

    Keep up the good work, guys.

  • @ReligionAndMaterialismDebunked
    @ReligionAndMaterialismDebunked Місяць тому

    Shalom.

  • @VincentGroenewold
    @VincentGroenewold Місяць тому +14

    Great work! Ignore bad comments, embrace useful criticism and focus on the positive ones, tough for us humans to do but it helped me quite a bit. Keep on rocking!

    • @garicrewsen1128
      @garicrewsen1128 Місяць тому +1

      Many creators suggest not reading the comments. Kinda defeats the purpose of commenting, though. Maybe hire someone to proof the comments, remove the negative, overly critical and childish ones? Although you've no need to worry about them. You're doing great. Thx and keep it up! 😊

  • @scentilatingone2148
    @scentilatingone2148 Місяць тому

    Those dimples

  • @KDR911KO
    @KDR911KO Місяць тому

    Still permission denied because of passkeys

  • @blookolla
    @blookolla Місяць тому

    Where's Shannon?

  • @yanasitta
    @yanasitta Місяць тому

    Burberry, how decadent.

  • @nicolasferrari7146
    @nicolasferrari7146 Місяць тому +1

    It's kind of scary nearly 1 mil people subscribe to hak5.

    • @blookolla
      @blookolla Місяць тому

      It started off well.

    • @miproduction6196
      @miproduction6196 Місяць тому

      @@blookollawhat what is she declining or something

  • @seb_gibbs
    @seb_gibbs Місяць тому

    D-Link needs to pull their socks up; do they really like to be supporting hackers? I've always used TP-Link.anyhow

  • @Starfire42
    @Starfire42 Місяць тому +1

    Dlink is horrible as usual. Great work Ali!

  • @qkb3128
    @qkb3128 Місяць тому +2

    That’s ridiculous that forces people to upgrade all their hardware. Sounds like you don’t want to buy D-link…lol just Dlink there product.

  • @0Buddhaspot0
    @0Buddhaspot0 Місяць тому

    👽☠️👾

  • @redslashed
    @redslashed Місяць тому +2

    No Ali Diamond sound so cool

  • @Kyus2001
    @Kyus2001 Місяць тому

    Cicada3301 good actors

  • @user-uz4ti5zs8z
    @user-uz4ti5zs8z Місяць тому

    thumbs up on that dress
    thumbs up! like the beerrrrrrr beerrry

  • @tommyboy3164
    @tommyboy3164 Місяць тому

    …..I can’t….

  • @agritech802
    @agritech802 Місяць тому

    4 years is a joke for eol, it should be 15 years at least

  • @russell28533
    @russell28533 Місяць тому

    Good work Ali

  • @gravelguitar9443
    @gravelguitar9443 Місяць тому

    HTTP, OR HTTPS?

  • @electricsushi
    @electricsushi Місяць тому

    Something is off with the transcoding. Not complaining about the 720P choice, but should not have this may artifacts.

  • @astrogatorjones
    @astrogatorjones Місяць тому +2

    You’re doing fine.

  • @blckwaterpark
    @blckwaterpark Місяць тому +2

    Lesson to learn here, never buying any D-Link devices knowing how insecure they are just after a few years..

  • @KDR911KO
    @KDR911KO Місяць тому

    Try and catch and patch your services

  • @sigmamale6143
    @sigmamale6143 Місяць тому

    I'm not even in cyber security stuff but I'm here for her cute dimples
    God made so beautiful people

  • @AnonMedic
    @AnonMedic Місяць тому +3

    The fact D-Link won't just release a patch makes me never want to buy another D-Link product again.
    Also I just noticed you got the cutest dimples ever.

  • @lossless4129
    @lossless4129 Місяць тому

    You’re great! Keep it up

  • @Human_Shrek
    @Human_Shrek Місяць тому +4

    she's so adorable and informative. thank you, threat-wire as always.

  • @secinject814
    @secinject814 Місяць тому

    I think you're a good presenter, no complaints!

  • @DinoNucci
    @DinoNucci Місяць тому +1

    PizzA

    • @RCBMW
      @RCBMW Місяць тому

      Hey, looking good, love your golf vids

  • @SHAZAMYOUNGORDER
    @SHAZAMYOUNGORDER Місяць тому

    🪥

  • @adrift4days
    @adrift4days Місяць тому

    RIP SOPHIE

  • @canlelola
    @canlelola Місяць тому

    Why on earth do people forget or have never come across w3c or w3school?

    • @secinject814
      @secinject814 Місяць тому

      While im still looking for a job atm, throughout my learning on Tryhackme, Hackthebox, portswigger(so far), some books and studying for my Sec+ exam I don't think it has ever been mentioned.
      Perhaps once but not in enough detail to remember. Ive heard of the IEEE and IANA, but not w3c, there's sooooo much info in learning the fundamentals of the web/software/different OS'/networking/Active Dir/cloud/back-end & front-end, cyber- security, coding...
      Obvs I know you don't need to be proficient in all these areas, but the amount of information is mind boggling. It's so easy to miss stuff that more experienced people assume you would run across.

  • @jasonybarra8277
    @jasonybarra8277 Місяць тому

    Your cool new snubs remember the old phrase "trust your techno lust" and my favorite " drink all the booze hack all the things"🖖🖖🤘🤘🤘🤟

  • @juriendejong5201
    @juriendejong5201 Місяць тому

    You cool, please continue

  • @JoeyFun
    @JoeyFun Місяць тому

    Ignore the haters, idk why anyone would make fun of your name. My driving instructor's last name was Diamond and it was pretty kewl! Anywho, keep up the great work.

  • @Chris558576
    @Chris558576 Місяць тому

    I'm done with D-Link. Clearly they are not on the side of consumers.

  • @kjetilhvalstrand1009
    @kjetilhvalstrand1009 Місяць тому

    they always done this crap, they used type words with mispelling as well.

  • @bfrancis9898
    @bfrancis9898 Місяць тому

    D-fective link

  • @bigboldsale
    @bigboldsale Місяць тому +5

    What happened to Shanon?

    • @w3w3w3
      @w3w3w3 Місяць тому

      im interested to know myself, just out of curiosity

  • @KDR911KO
    @KDR911KO Місяць тому

    Cloud C2 rem fix eol nas server cve

  • @MajesticBlueFalcon
    @MajesticBlueFalcon Місяць тому +2

    I miss Snubs 😢

    • @DJMerck
      @DJMerck Місяць тому +2

      We all do a lil.
      What happened? I quit paying attention for a lil over a year, maybe 2 and now everyone is gone.

  • @asishreddy7729
    @asishreddy7729 Місяць тому

    Nothing ruins a beautiful girl like fake body parts. That lip filler….

  • @Akshun82
    @Akshun82 Місяць тому +1

    _No dog with me this week_ *Unsubscribes*

  • @jamescooper4649
    @jamescooper4649 Місяць тому +1

    show us ur linux skills

  • @JohnPeter-yf5jf
    @JohnPeter-yf5jf Місяць тому

    lol 4yr out of date while windows xp still running on a network somewhere

  • @Hat_Uncle
    @Hat_Uncle Місяць тому

    takeaway, once again, Don't Install Java on your machine. LOL

  • @thewelder3538
    @thewelder3538 Місяць тому

    I came to this video with an open mind, but your delivery of pertinent information is REALLY bad. This I think, is down to some terrible writing. Now I'm not entirely sure what you're aiming for, but it sounds like some like some sort of badly written news segment with various quotes from whatever sources you can find. There's nothing here about what people should look for in detail, or how they can avoid these threats. This video is actually hard to watch because of the way things are delivered, to the point I couldn't make it all the way through. If I feel this way and I'm trying to be as constructive as I can, I'm sure others will have a similar opinion.
    However, the worst thing here are the comments. All the supportive ones with no real reason for the support other than the "you go girl" perspective. Sure, there's are trolls, but a lot of the comments are bad because of the reasons I mentioned above. With other commenters saying "ignore the haters" and other moronic things without trying to understand why the haters are saying what they're saying.
    As someone who works in this field, I found this incredibly difficult to watch and I think you have a lot of work to do in order to maintain engagement.