pouet.chapril.org est l'un des nombreux serveurs Mastodon indépendants que vous pouvez utiliser pour participer au fédiverse.
Chapril https://www.chapril.org est un projet de l'April https://www.april.org

Administré par :

Statistiques du serveur :

1,1K
comptes actifs

#email

60 messages50 participants5 messages aujourd’hui

PoisonSeed Campaign Targets CRM and Bulk Email Providers in Supply Chain Spam Operation

A new threat group, dubbed PoisonSeed, is targeting enterprise organizations and individuals outside the cryptocurrency industry. The campaign focuses on phishing CRM and bulk email providers' credentials to export email lists and send bulk spam. The attackers use a cryptocurrency seed phrase poisoning attack, providing security seed phrases to trick victims into compromising their wallets. Similarities have been detected between PoisonSeed, Scattered Spider, and CryptoChameleon, but the campaign is being classified separately due to unique characteristics. The attackers have set up phishing pages for prominent CRM and bulk email companies, including Mailchimp, SendGrid, Hubspot, Mailgun, and Zoho. Once credentials are phished, the process of bulk downloading email lists appears to be automated. The campaign also involves spam sent from compromised accounts, including a notable breach of an Akamai SendGrid account.

Pulse ID: 67f432acbd8d0957264e79a3
Pulse Link: otx.alienvault.com/pulse/67f43
Pulse Author: AlienVault
Created: 2025-04-07 20:16:44

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

If you're using #GMail and you've learned about their latest claim to introduce real end-to-end #encryption: it's a lie.

Google has the control and/or you can't do anything against that Google takes control any time.

Real #E2EE works differently: only the sender and receiver are able to access the protected content.

arstechnica.com/security/2025/

michal.sapka.pl/2025/gmail-e2e

#Meta also defined E2EE such that the message is encrypted from the sender to them, processed in clear text and re-encrypted for the transmission to the receiver.

Don't let them fool you with false claims and wrong definitions.

Ars Technica · Google unveils end-to-end messages for Gmail. Only thing is: It’s not true E2EE.Par Dan Goodin

Grandoreiro Stealer Targeting Spain and Latin America: Malware Analysis and Decryption Insights

A new campaign utilizing the Brazilian stealer Grandoreiro has been detected targeting Spain and Latin American countries. The malware, active since 2017, aims to steal sensitive information, including banking credentials and personal data. It employs advanced evasion techniques such as string encryption and anti-sandbox measures. The campaign distributes Grandoreiro through phishing emails containing VBS files. Once executed, it performs various checks to evade detection and uses legitimate services for geolocation and DNS resolution. The report provides detailed insights into the malware's behavior and explains the string obfuscation and decryption techniques used in this campaign.

Pulse ID: 67f038fac3f02d82df0a9833
Pulse Link: otx.alienvault.com/pulse/67f03
Pulse Author: AlienVault
Created: 2025-04-04 19:54:34

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

Just to be clear: If #Google decides it’s okay to no longer send non-Gmail users the ACTUAL #email, but only a LINK to some bullshit #proprietary service that you must click to “unlock” the TRUE contents, then Gmail ceases to be an email provider but is merely a spam service which bullies unsuspecting users into using their proprietary crap.

While this seems to be limited to (fake) E2E for now, I’m afraid it could get worse if people do not resist.

I know why I don’t use #Gmail.

#eMail #selfHosting gurus: I am looking for the simplest possible way to host myself a mailbox I can add to my email clients (Thunderbird, phone, etc.) as usual, so I can move mails there to free up space on the 3rd party "real" emails, then back them up separately on my server.

I do not want receiving or sending emails to work. Just an IMAP or whatever box I can shove emails in the face by dragging them in Thunderbird or with a script.

Ideally available in :nixos: #NixOS

#dovecot? 🤔

My life is a constant tension between

a. Wanting to be All The Prepared, meet All The #Deadlines, make Everyone Happy, Time All The Management

b. Wanting to # live my life, not #grind it away; to #create, #explore, #love my loved ones; to minimize the % of my life involving #email; to not beat my head against things I don't enjoy

Thus, my life looks like a rolling disaster, sometimes, to some kinds of people.

Working like the 90’s
Yes, we should work like the 90’s and get to disconnected when we leave the office. At my job I don’t ever check my email because I only get around 1 email a month that would involve me and it also involves my boss because he copied me. Thus, he always mentions to me that there is email to deal with. Everything else I do comes in via Github because we’re dealing int
curtismchale.ca/2025/04/06/wor
#LinksOfInterest #burnout #email #overwork