Transcript
Dave Buettner (0:02)
You're listening to the Cyberwire Network powered by N2K. Do you know the status of your compliance controls right now? Like right now? We know that real time visibility is critical for security, but when it comes to our GRC programs, we rely on.
Adam Kahn (0:25)
Point in time checks.
Dave Buettner (0:27)
But get this, more than 8,000 companies like Atlassian and Quora have continuous visibility into their controls with Vanta. Here's the gist. Vanta brings automation to evidence collection across 30 frameworks like SoC2 and ISO 27001. They also centralize key workflows like policies, access reviews and reporting and helps you get security questionnaires done five times faster with AI. Now that's a new way to GRC. Get $1,000 off Vanta when you go to vanta.com cyber that's vanta.com cyber for $1,000 off.
Unknown Speaker (1:23)
We don't see QR codes being attached or shared but but it is becoming more prevalent in our day to day lives. When we are going to even certain restaurants, they don't even have a menu anymore, they give you a QR code. And when it comes to emails, more and more companies are trying to use QR codes, but it's a fast way to engage.
Dave Buettner (1:51)
That's Adam Khan, VP of Security Operations at Barracuda. The research we're discussing today is titled the evolving use of QR Codes in Phishing Attacks.
Unknown Speaker (2:08)
You know, as tactics are evolving when it comes to phishing and our researchers are always digging into how cybercriminals are advancing and utilizing new tactics and techniques. And the data that proves over, as you saw in the article, over half a million emails that were analyzed that had PDF documents and even the emails themselves had QR codes included in them. Impersonating legitimate brands such as Microsoft, including the tools within Microsoft such as SharePoint or OneDrive and even companies like DocuSign or Adobe are being utilized by these cybercriminals to execute QR phishing attacks. So obviously it's not very commonly known and it was really the data kind of resonated overall how it's kind of growing over time.
Adam Kahn (3:06)
Well, before we dig into some of the specifics from the report, for folks who may not be familiar with this particular kind of phishing, it's often called quishing QR code phishing. I think most folks are familiar with.
Dave Buettner (3:21)
What a QR code is at this.
Adam Kahn (3:23)
![Quishing for trouble. [Research Saturday] - CyberWire Daily cover](/_next/image?url=https%3A%2F%2Fmegaphone.imgix.net%2Fpodcasts%2F5f5c6976-beff-11ef-a8bd-67b02091c6d0%2Fimage%2F95b72a93c2ffaf8ff900d662a9bd3735.png%3Fixlib%3Drails-4.3.1%26max-w%3D3000%26max-h%3D3000%26fit%3Dcrop%26auto%3Dformat%2Ccompress&w=1920&q=75)