@cirriustech @GossiTheDog Thanks for the info! From their site: “The Logo API is offered as a free, legacy product and is unsupported at this time”. Good chance that means it’s not monitored for abuse! Hopefully they’ll EOL it before December 1st.
Notices by Fellows (fellows@cyberplace.social)
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Saturday, 22-Feb-2025 09:14:46 JST Fellows
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Saturday, 22-Feb-2025 08:41:56 JST Fellows
Recently I’ve seen a number of good looking malicious emails pretending to be from various orgs, all with included company logos.
Looking over the HTML of the emails I noticed an image URL common to all of them, logo.clearbit[.]com. It was in the image tag for logo.
It’s a company logo API that uses logo.clearbit[.]com/“domain.whatever” for logo creation.
Might be a domain you want to start filtering for, as the API is clearly being abused thanks to it being absolutely free.
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Saturday, 22-Feb-2025 07:24:37 JST Fellows
@GossiTheDog I have to watch the entire season again. Too much times passed since it originally came out that I need a refresher.
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Thursday, 20-Feb-2025 04:31:45 JST Fellows
@GossiTheDog that doesn’t seem very humane
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Wednesday, 19-Feb-2025 09:21:39 JST Fellows
@GossiTheDog it had a good run
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Saturday, 15-Feb-2025 00:50:11 JST Fellows
Over the past few days, I’ve noticed a variety of malicious emails with different styles. All of these emails use the lure URL link.shoppermeet[.]net.
Link attempts to redirect users to a Microsoft 365 phishing page for credential harvesting. The threat actor even tries to include company images and logos to make the email appear more legitimate.
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Friday, 07-Feb-2025 16:03:15 JST Fellows
If you still haven’t applied Microsoft Office patches since January 2024, now might be a good time to
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Friday, 07-Feb-2025 08:07:50 JST Fellows
@GossiTheDog I guess it’s no Starfield
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Wednesday, 05-Feb-2025 03:26:28 JST Fellows
@GossiTheDog aside from graphics, is the gameplay any good?
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Sunday, 02-Feb-2025 12:22:43 JST Fellows
@GossiTheDog I think this fits the quintessential definition of “first world problem”
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Wednesday, 29-Jan-2025 04:56:07 JST Fellows
Not sure if you’ve heard of Pixpa[.]com. They label themselves as “an easy, all-in-one portfolio website builder for photographers & creators…”
I’ve recently seen threat actors use Pixpa as a trusted domain within links in malicious email campaigns. Watch out as the service isn’t always photography.
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Saturday, 25-Jan-2025 06:05:56 JST Fellows
@GossiTheDog I cracked out my Nintendo Switch the other day after seeing your post about the Switch 2. As a guy born in the first half of the 1980s, maybe it’s the nostalgia, but I like the gameplay of stuff like Mario Wonder. I bet the Switch 2 outsells everything - I’m in for one.
The fact that the X/S is trailing the One in sales doesn’t seem too surprising
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Saturday, 25-Jan-2025 05:43:30 JST Fellows
@GossiTheDog wow that’s neat, and kinda terrifying.
I wonder what my neighbours would think if I started flying that over their homes. I had to write a test and get licensed just to be able to fly my drone here!
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Saturday, 25-Jan-2025 05:08:25 JST Fellows
@GossiTheDog is that vehicle something that exists in the physical world?
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Wednesday, 22-Jan-2025 04:34:58 JST Fellows
@GossiTheDog I gave it a try, didn’t like it, added no value. The bar was low but they didn’t make it over.
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Wednesday, 22-Jan-2025 04:22:51 JST Fellows
If you’re not blocking SVG (Scalable Vector Graphic) attachments in email messages you might want to.
I have observed something I haven’t yet seen. Malicious email messages where the attachment the threat actor wants the target to open is a to SVG file pretending to be an agreement.
The SVG file when loaded makes a HTTP call to load a remote image, it also contains a transparent layer which links to the malicious website.
Looks to be an attempt at evading detection.
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Monday, 20-Jan-2025 03:59:29 JST Fellows
@GossiTheDog no need to go to the theater with events so expertly scripted.
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Friday, 17-Jan-2025 01:58:06 JST Fellows
@GossiTheDog He must be playing TMNT
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Thursday, 16-Jan-2025 10:24:48 JST Fellows
@GossiTheDog thanks for this Kevin, I have passed the info around to some MSPs I have friends working at.
-
Embed this notice
Fellows (fellows@cyberplace.social)'s status on Sunday, 05-Jan-2025 03:15:05 JST Fellows
@GossiTheDog Those graphics look pretty amazing. Is this game like WWII Online? (If you’ve ever played that one) I used to play WWII Online as a teen on my old Power Mac G4 and Power Mac G5.