苹果测试工程师的日常
14:15 · 2025年4月17日 · 周四
用 Google 漏洞发带 Google DKIM 签名的钓鱼邮件
https://nitter.net/nicksdjohnson/status/1912439023982834120
https://easydmarc.com/blog/google-spoofed-via-dkim-replay-attack-a-technical-breakdown/
Nitter
nick.eth (@nicksdjohnson)
Recently I was targeted by an extremely sophisticated phishing attack, and I want to highlight it here. It exploits a vulnerability in Google's infrastructure, and given their refusal to fix it, we're likely to see it a lot more. Here's the email I got:
Home
Powered by
BroadcastChannel
&
Sepia