Sophos researchers are warning of a spam campaign that asks recipients to click on a link in order to update their UPS accounts.
"The link ... leads to a compromised website in the Seychelles," writes Sophos' Chester Wisniewski. "It appears the attackers have exploited a vulnerability in the Joomla CMS installed on the host."
"It is unlikely the phishers are really trying to access your UPS account, but rather are counting on the fact that most users reuse their usernames and passwords for multiple sites," Wisniewski writes.
Go to "UPS phishing email wants your shipping credentials" to read the details.https://o1.qnsr.com/log/p.gif?;n=203;c=204660766;s=9477;x=7936;f=201812281312070;u=j;z=TIMESTAMP;a=20392931;e=i
For regular security news updates, follow eSecurityPlanet on Twitter: @eSecurityP.