The use of open redirects from legitimate domains makes phishing emails that much more believable and credible, obfuscating the dangerous nature of these attacks.

In the ongoing saga of attacks on Microsoft 365 users, security analysts at Microsoft recently announced a widespread attack that utilises open redirects – a technique used in web development to point to the URL visitors of a website should be taken to once the initially-visited page is done processing the visit. A simple example of an open redirect is the following: [https://]example[DOT]com/redirect[DOT]php?url=[http://]attacker[DOT]com.

According to Microsoft, attackers will use a bit more trickery to fool those that choose to hover over links in emails before clicking on them, embedding a malicious URL within what appears to be a trusted URL. In many cases, redirects to malicious URLs first take visitors to Google reCAPTCHA pages to further obfuscate the nature of the final destination from security solutions designed to evaluate email links.

While evaluating destination URLs via hovering over links in an email is definitely a good security practice, threat actors are becoming wise to this and are taking steps such as those mentioned above to make it even more difficult to spot a malicious link. Users should be taught via Security Awareness Training to be more mindful of the actual message being sent – if unsolicited, it should be treated with at least a bit of distrust and scrutiny, being certain it is legitimate before engaging with links – benign or malicious.

Contact us to organise a Staff IT Training Session, in your offices, by an IT Security Expert.

Call Back

Preferred Time for Call ?
:

This will close in 0 seconds

Have A Question ?

Get In Touch

Your Name(Required)

This will close in 0 seconds

Hi, I will lodge a ticket for you and someone from support team will get back to you as soon as possible.

If they say no, its urgent and needs to be done quick say following

Our system shows that you are an Ad-Hoc client in our system. Unfortunately, we do not provide phone call support for our unmanaged client. However,

I can lodge a ticket for you, and someone will get back to you via email within the next 24 hours.

Or alternatively,

We can organize our technician to come out. There may be someone available in next couple of hours. Our call out service is charged $199 per hr with minimum 1 hr call out fee. This is payable on completion of session either via cash, Mastercard or Visa. If yes, from what time to what time are you available today? I will need to check with our call out technician for his availability and I will get back to you shortly.

Note: After the first hour, we charge in 15 minutes blocks.

This will close in 0 seconds

Hi, Could you please connect to your mobile hotspot and make sure the mobile is not connected to Office Wi-Fi.

This will close in 0 seconds