CISA Advisories

The Email Address Leaking Your Secrets 📧 & a Fake PDF That Hijacks Your Bank 🏦

Two stories from today's security headlines prove the same uncomfortable point: the systems we trust most — our email and our banking logins — can betray us in ways almost nobody sees coming. Here's what happened and why it matters to you.

📧 That "noreply" Address Might Be Handing Your Secrets to a Stranger

Every business fires off automated emails from addresses like noreply or deleteduser — the kind you're told never to reply to. Security researchers just discovered that many of those messages are quietly bouncing to generic domains anyone can buy, like noreply[.]net. Whoever owns the domain gets the mail.

The numbers are staggering: WIRED reported that a single one of these domains collected more than 400,000 messages over roughly a year and a half, including over 28,000 attachments — invoices, password resets, internal documents and more. The "so what" is simple: sensitive corporate information could be flowing straight to a total stranger, and the companies leaking it have no idea. It's a reminder that a tiny misconfiguration in something as boring as an outbound email can quietly expose a business for months.

Read more

🏦 A Booby-Trapped PDF That Could Empty Belgian Bank Accounts

Researchers found critical flaws in the eID signing software used by most Belgian banks and government agencies — the tool people use to prove who they are online with their national ID card. Because the software didn't properly check which website was talking to it, a malicious site could silently pull data off someone's smart card and even recover their secret eID PIN.

Worse, opening a file disguised as a harmless PDF could trick the software into running attacker code on the victim's computer — a "drive-by" takeover with no obvious warning signs. The vendor has since patched the holes (as of July 22), but the lesson is universal: the trusted little browser add-ons and login helpers we rarely think about can become a direct path into our bank accounts and identities. If your organization relies on eID software, make sure every client is updated.

Read more

Stay ahead of threats with GOCO Security at gocosecurity.com.

Comments

Popular Posts