Indeed.Com Open Redirect Flaw Exploited By Phishers To Attack Us Executives
Indeed.com Open Redirect Flaw Exploited by Phishers to Attack US Executives Written by Shipra Sanganeria Cybersecurity & Tech Writer A recent phishing campaign targeting Microsoft365 accounts of senior executives in the US was seen exploiting the open redirection vulnerability in the popular job site, Indeed.com. Discovered by researchers at Menlo Security, the campaign which started in July 2023 was seen using the EvilProxy phishing framework. This reverse proxy service enables phishers to harvest session cookies and to successfully bypass non-phishing resistant multi-factor authentication (MFA)....