Security researchers from CloudSEK have discovered cybercriminals using Zendesk to run brand impersonation scams, known as pig butchering scams. Hackers create fake subdomains mimicking legitimate companies to send phishing emails, tricking people into investing in fake platforms. The researchers noted that Zendesk’s vetting system is not thorough enough, allowing attackers to target individuals with phishing attempts disguised as legitimate ticket assignments. CloudSEK has informed Zendesk of the flaw and is waiting for a response.
Full Article
CISA Adds PaperCut NG/MF CSRF Vulnerability to KEV Catalog Amid Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability in PaperCutNG/MF print management software, tracked as CVE-2023-2533 (CVSS score: 8.4), to its Known Exploited Vulnerabilities catalog due to evidence of active exploitation. This cross-site request forgery (CSRF) bug poses significant security risks to users. Want More Context? 🔎
Read more