Namecheap/SendGrid Hijack: Phishing With Perfect DMARC
Phishers compromised a SendGrid supplier account and sent MetaMask-themed mail through Namecheap's legitimate pipeline — SPF, DKIM, and DMARC all passed.
Phishers compromised a SendGrid supplier account and sent MetaMask-themed mail through Namecheap's legitimate pipeline — SPF, DKIM, and DMARC all passed.
A cloned intranet page harvested an employee's password and MFA code, opening hours of internal access. Phishing-resistant MFA and self-report lessons.
GoDaddy's 2023 filing admitted intermittent intruder access since 2020, malware in cPanel servers, and email interception affecting ~6.95M customers.
ESXiArgs hit thousands of unpatched VMware ESXi hosts via old OpenSLP bugs in February 2023. Hypervisor ransomware and recovery-script lessons.