I. Vishing away domain ownership
GoDaddy Employees Used in Attacks on Multiple Cryptocurrency Services
GoDaddy employees were targeted with voice phishing or ‘Vishing’ attacks to obtain ownership of cryptocurrency domains.
In CyberInsights #8, we wrote of vishing attacks gaining prominence due to work from home.
CISO Check:
Is your team involved in the security of contact center processes at the design stage? Do you include contact center security testing as a part of your red teaming exercises?
Can your security operations detect changes in your domain accounts with your registrar?
II. The Pope’s Insta account likes bikini models
The Vatican Wants to Know How the Pope's Instagram Account Liked a Model's Photo
Pope Francis’ Instagram account liked a Brazilian model’s photo. The account is managed by a team of people. Investigations are still under way.
There seems to be a dearth of social media management tools that can securely handle multiple users managing a single account. Write to us if you know of one.
CISO Check:
How do you manage the legitimate business requirement of multiple user access to a single social media account?
III. Quote of the week
Security is better when it is built in, not bolted on. - Stephen Yu
Have an original interesting cybersecurity quote? Let us know in the comments and we will publish it along with your name in our quotes section.