ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
Threat actors are sending legitimate OpenAI organization invitations that impersonate companies to trick employees into submitting sensitive data. Push Security discovered the "Poisoned Tenant" campaign after employees received invites to a fake "Push Security Inc." tenant created by attackers using Gmail addresses. The invitations came from OpenAI's official notification address and passed email authentication checks.
Tap to vote and see what everyone thinks.
Summary by ByteBrief
Order-tracking app Shop abused to push callback phishing attacks