
Cybersecurity experts are warning about a widespread phishing campaign that exploits Google Calendar and other trusted tools to steal user credentials. Cybercriminals are sending spoofed invites that appear legitimate, tricking users into clicking malicious links. This campaign has reportedly targeted thousands of users, particularly in Europe, with tools like HubSpot's Free Form Builder being used to create fake DocuSign alerts. The phishing attempts are designed to bypass spam filters, making them particularly effective. In addition, vulnerabilities in various software products have been identified, including a critical flaw in BeyondTrust's Privileged Remote Access and Remote Support products, which has a CVSS score of 9.8, indicating its severity. Organizations are urged to remain vigilant and implement security measures to protect against these threats.


CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities List: https://t.co/TWyD4dW4CN by The Hacker News #infosec #cybersecurity #technology #news
🚨 CISA warns of an actively exploited critical flaw (CVE-2024-12356, CVSS: 9.8) in BeyondTrust's Privileged Remote Access (PRA) and Remote Support (RS) products. Read: https://t.co/cBZleiNIeh
Episode title is also how everyone names their Zoom calendar invites with me https://t.co/laJlEEQZCY