The post LinkedIn DM Attack Warning — What Users Need To Know appeared on BitcoinEthereumNews.com. Beware the latest LinkedIn attack, security experts warn. NurPhoto via Getty Images Gmail passwords leaked, PayPal users warned of attacks, even Twitter, sorry X, issuing an account lockdown warning, are all, sadly, par for the cybersecurity news headlines course these days. What isn’t is attacks that focus on LinkedIn, the professional and business networking platform that boasts more than a billion users. If you are one of them, then I apologize, but you need to be aware of just such an occurrence. ForbesWhatsApp Confirms Sudden Backup Passkey Security Move For BillionsBy Davey Winder LinkedIn Users Warned To Beware This New Direct Message Attack The last time I wrote a LinkedIn-specific news story was way back in February, when I warned of a Lazarus attack that targeted the wrong user. That LinkedIn doesn’t feature more in security news reports is a good thing; it means the platform is doing something right. This latest warning, however, is worth taking seriously, as the attackers are targeting the right users — at least in terms of potentially profitable outcomes. Push Security researcher Dan Green has confirmed that business executives on the networking platform are vulnerable to a “high-risk LinkedIn phishing attack,” via the LinkedIn direct messaging resource. ​​This is particularly worrying because LinkedIn itself, “while often used for work and commonly accessed from corporate devices,” Green warned, “sits outside the purview of enterprise security tools, exploiting a visibility and control blind spot.” In the case detailed by Green, in technical glory for those who like such things, the victim received a malicious LinkedIn direct message which redirected them a total of three times, through Google Search, a supposed payroll site and ultimately to a custom landing page hosting various documents. “Upon clicking on one of the document links on the page, the victim is… The post LinkedIn DM Attack Warning — What Users Need To Know appeared on BitcoinEthereumNews.com. Beware the latest LinkedIn attack, security experts warn. NurPhoto via Getty Images Gmail passwords leaked, PayPal users warned of attacks, even Twitter, sorry X, issuing an account lockdown warning, are all, sadly, par for the cybersecurity news headlines course these days. What isn’t is attacks that focus on LinkedIn, the professional and business networking platform that boasts more than a billion users. If you are one of them, then I apologize, but you need to be aware of just such an occurrence. ForbesWhatsApp Confirms Sudden Backup Passkey Security Move For BillionsBy Davey Winder LinkedIn Users Warned To Beware This New Direct Message Attack The last time I wrote a LinkedIn-specific news story was way back in February, when I warned of a Lazarus attack that targeted the wrong user. That LinkedIn doesn’t feature more in security news reports is a good thing; it means the platform is doing something right. This latest warning, however, is worth taking seriously, as the attackers are targeting the right users — at least in terms of potentially profitable outcomes. Push Security researcher Dan Green has confirmed that business executives on the networking platform are vulnerable to a “high-risk LinkedIn phishing attack,” via the LinkedIn direct messaging resource. ​​This is particularly worrying because LinkedIn itself, “while often used for work and commonly accessed from corporate devices,” Green warned, “sits outside the purview of enterprise security tools, exploiting a visibility and control blind spot.” In the case detailed by Green, in technical glory for those who like such things, the victim received a malicious LinkedIn direct message which redirected them a total of three times, through Google Search, a supposed payroll site and ultimately to a custom landing page hosting various documents. “Upon clicking on one of the document links on the page, the victim is…

LinkedIn DM Attack Warning — What Users Need To Know

2025/10/31 21:21

Beware the latest LinkedIn attack, security experts warn.

NurPhoto via Getty Images

Gmail passwords leaked, PayPal users warned of attacks, even Twitter, sorry X, issuing an account lockdown warning, are all, sadly, par for the cybersecurity news headlines course these days. What isn’t is attacks that focus on LinkedIn, the professional and business networking platform that boasts more than a billion users. If you are one of them, then I apologize, but you need to be aware of just such an occurrence.

ForbesWhatsApp Confirms Sudden Backup Passkey Security Move For Billions

LinkedIn Users Warned To Beware This New Direct Message Attack

The last time I wrote a LinkedIn-specific news story was way back in February, when I warned of a Lazarus attack that targeted the wrong user. That LinkedIn doesn’t feature more in security news reports is a good thing; it means the platform is doing something right. This latest warning, however, is worth taking seriously, as the attackers are targeting the right users — at least in terms of potentially profitable outcomes. Push Security researcher Dan Green has confirmed that business executives on the networking platform are vulnerable to a “high-risk LinkedIn phishing attack,” via the LinkedIn direct messaging resource.

​​This is particularly worrying because LinkedIn itself, “while often used for work and commonly accessed from corporate devices,” Green warned, “sits outside the purview of enterprise security tools, exploiting a visibility and control blind spot.”

In the case detailed by Green, in technical glory for those who like such things, the victim received a malicious LinkedIn direct message which redirected them a total of three times, through Google Search, a supposed payroll site and ultimately to a custom landing page hosting various documents. “Upon clicking on one of the document links on the page, the victim is prompted to view with Microsoft,” and, well, you can probably guess the rest. A cloned Microsoft page requires credentials to be entered and 2FA authentication to be completed, at which point the attacker has that Microsoft session stolen.

ForbesGoogle Chrome Crash Warning For 3 Billion — No Fix Available

LinkedIn As An Attack Platform Is A Clever Move By Scammers

Using LinkedIn to launch such attacks is a clever move by threat actors, not least as many users will be expecting contacts from outside of their organization to talk about work. By not using email, this also adds to the detection-evasion toolkit. The attackers then used a chain of legitimate sites to avoid being flagged as suspicious and to cloak the ultimate URL destination..

“Just because the attack happens over LinkedIn doesn’t lessen the impact,” Green said, “these are corporate credentials and accounts being targeted, even if it is nominally a ‘personal’ application.”

I reached out to LinkedIn, and a spokesperson provided the following statement: “Sophisticated phishing scams are a problem across the internet, and our teams use a variety of automated technology and trained investigation experts to detect and stop harmful behavior. Our free verification features enable members to make more informed decisions on who they’re interacting with. We also proactively share safety tips including how to report any suspicious messages to us, and how to enable the optional advanced safety feature which can help identify potentially harmful or fraudulent content.”

ForbesGoogle Security Gets Game As Inoculation Theory Put To The Test

Source: https://www.forbes.com/sites/daveywinder/2025/10/31/linkedin-dm-attack-warning—what-users-need-to-know/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Another Nasdaq-Listed Company Announces Massive Bitcoin (BTC) Purchase! Becomes 14th Largest Company! – They’ll Also Invest in Trump-Linked Altcoin!

Another Nasdaq-Listed Company Announces Massive Bitcoin (BTC) Purchase! Becomes 14th Largest Company! – They’ll Also Invest in Trump-Linked Altcoin!

The post Another Nasdaq-Listed Company Announces Massive Bitcoin (BTC) Purchase! Becomes 14th Largest Company! – They’ll Also Invest in Trump-Linked Altcoin! appeared on BitcoinEthereumNews.com. While the number of Bitcoin (BTC) treasury companies continues to increase day by day, another Nasdaq-listed company has announced its purchase of BTC. Accordingly, live broadcast and e-commerce company GD Culture Group announced a $787.5 million Bitcoin purchase agreement. According to the official statement, GD Culture Group announced that they have entered into an equity agreement to acquire assets worth $875 million, including 7,500 Bitcoins, from Pallas Capital Holding, a company registered in the British Virgin Islands. GD Culture will issue approximately 39.2 million shares of common stock in exchange for all of Pallas Capital’s assets, including $875.4 million worth of Bitcoin. GD Culture CEO Xiaojian Wang said the acquisition deal will directly support the company’s plan to build a strong and diversified crypto asset reserve while capitalizing on the growing institutional acceptance of Bitcoin as a reserve asset and store of value. With this acquisition, GD Culture is expected to become the 14th largest publicly traded Bitcoin holding company. The number of companies adopting Bitcoin treasury strategies has increased significantly, exceeding 190 by 2025. Immediately after the deal was announced, GD Culture shares fell 28.16% to $6.99, their biggest drop in a year. As you may also recall, GD Culture announced in May that it would create a cryptocurrency reserve. At this point, the company announced that they plan to invest in Bitcoin and President Donald Trump’s official meme coin, TRUMP token, through the issuance of up to $300 million in stock. *This is not investment advice. Follow our Telegram and Twitter account now for exclusive news, analytics and on-chain data! Source: https://en.bitcoinsistemi.com/another-nasdaq-listed-company-announces-massive-bitcoin-btc-purchase-becomes-14th-largest-company-theyll-also-invest-in-trump-linked-altcoin/
Share
BitcoinEthereumNews2025/09/18 04:06