5 ms·
PSA: I just received a github phishing request that was not detected by Gmail. I almost fell for it. Phishing email looks like a "review your suspicious activi
by spir 7y ago
PSA: I just received a github phishing request that was not detected by Gmail. I almost fell for it.
Phishing email looks like a "review your suspicious activity" alert, but the alert is the suspicious activity.
https://imgur.com/a/zdtWmuN https://imgur.com/a/zdtWmuN
- RMPR 7y agoJust received a repository vulnerability notification as well, in the Pillow dependency but it seems legit.
- meowface 7y agoDid the odd capitalization, "April 01th", and unrelated sending address not tip you off?
- johnghanks 7y agoYeah I gotta agree with you. How is this any different from the other 10s of thousands of variations of phishing attempts? If it's not signed and it's not from github.com or a registered subdomain, or if the URL of the action isn't _explicitly_ github.com... it's not legit. It doesn't matter if it slipped through GMail's filter or not...
- meowface 7y agoI don't mean to shame people for falling for phishing. I fell for a convincing Steam phish once when I was a young teenager after a friend's account was compromised and messaged me with a link to a perfect clone of the login page and a similar domain. But as far as phishes go, this one just seems not too convincing.
- justinhj 7y agoIn the case of the github phishing it does have a valid certificate and the host name is something that looks legit enough it will probably fool a lot of people
- ksec 7y agoSaw many similar request on twitter as well. Hopefully the two things ( Being Down and Phishing ) are coincidence.