All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Zendesk Security Flaw Enables Mass Email Bombing Attacks

By

todsacerdoti

7mo ago· 3 min readenNews

Summary

Cybercriminals are exploiting a security vulnerability in Zendesk's customer service platform that allows them to send massive volumes of threatening emails to targeted individuals. The attack leverages Zendesk's lack of authentication requirements, enabling attackers to flood inboxes with messages that appear to come from hundreds of legitimate corporate customers simultaneously, including companies like CapCom, CompTIA, and Discord.

Key quotes

· 4 pulled
Cybercriminals are abusing a widespread lack of authentication in the customer service platform Zendesk to flood targeted email inboxes with menacing messages
Zendesk is an automated help desk service designed to make it simple for people to contact companies for customer support issues
KrebsOnSecurity started receiving thousands of ticket creation notification messages through Zendesk in rapid succession
each bearing the name of different Zendesk customers, such as CapCom, CompTIA, Discord
Snippet from the RSS feed
Cybercriminals are abusing a widespread lack of authentication in the customer service platform Zendesk to flood targeted email inboxes with menacing messages that come from hundreds of Zendesk corporate customers simultaneously.

You might also wanna read