BlackHat conference in giant phishing gaffe
The annual BlackHat conference in Las Vegas prides itself as "the best and biggest event of its kind, unique in its ability to define tomorrow's information security landscape."
But this year's event has kicked off with a giant security boo-boo. (This wasn't the sort of mistake to make at any time, let alone to an international army of geeks - paying geeks, at that! - who are in the process of heading to your event.)
The story started over the weekend as BlackHat 2012 delegates - and only delegates, as quickly became obvious as recipients compared notes - started to get emails like this one:
From: BlackHat 2012 [mailto: gleach @ itn-international.com]
Sent: Sunday, July 22, 2012 8:58am
To: Not Me As Sadly I'm Not Going This Year
Subject: Your admin passwordThis is a note from BlackHat 2012.
_________________________________
You have requested a new password. Here are your details:
Username:
Password:To sign in, please go to this URL:
https://svel1023/BH12/Admin