Security Is Hard, Y'all

A security researcher details a potential phishing attempt involving a suspicious Cloudflare-branded domain. The author highlights the dangers of top-level domains like .pay and the lack of clear reporting mechanisms for suspicious authorization requests.
Why it matters
It illustrates the evolving sophistication of social engineering and the risks associated with new, less-vetted top-level domains.
Neat! I clicked through to the site and there it is:
And huzzah !, my preferred handle, @ericlaw is still available. I’d better hurry to claim it before someone else gets it!
Since I’m already a long-time Cloudflare user, I just need to sign in. That makes sense, how else will they bind the handle to my account?
Easy peasy. I’m in. Looks like there’s just one more step, I gotta authorize the new feature?
This looks exactly like one of those Consent Phishing attacks that have been so popular over the last few years!
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in