CISA warns Windows users of new spear-phishing threats and security measures
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned Windows users about new email threats, particularly a large-scale spear-phishing campaign targeting various sectors, including government and IT. CISA advises against using SMS-based multifactor authentication (MFA) due to its vulnerability to attacks. Spear-phishing is a more targeted form of phishing that can be harder to detect. CISA reports that attackers are using emails with malicious remote desktop protocol (RDP) files to gain access to networks, increasing the risk of data breaches. CISA has released a top-ten list of security measures for organizations, emphasizing the importance of enabling MFA while avoiding SMS options. Stronger alternatives, such as software authenticators or passkeys, are recommended for better protection against cyber threats.