social.coop is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Fediverse instance for people interested in cooperative and collective projects. If you are interested in joining our community, please apply at https://join.social.coop/registration-form.html.

Administered by:

Server stats:

487
active users

#sendgrid

1 post1 participant0 posts today

If you recently registered for an account and did not receive the expected confirmation email, my apologies. The site's outbound email setup failed; frankly, it just wasn't very robust.

As of an hour ago I've switched to #Sendgrid, which I expect will greatly improve things.

I see more and more phishing campaigns using compromised sendgrid accounts to send their phishing payloads to potential victims. This makes it harder to detect, as both SPF and DKIM records may authenticate the message, and any phishing links are obfuscated by the sendgrid link tracking feature.

This again means that the payload is more likely to slip through spam and email verification filters.

This is not a new phenomenon, but it seems to have become more common lately.

Here are some sendgrid domains that I have recorded sending phishing emails to one of my honeypot emails. Including a count of how many instances from each:

     1 u14316059.ct.sendgrid
     3 u1745908.ct.sendgrid
     4 u2135035.ct.sendgrid
     2 u22130470.ct.sendgrid
     1 u25891187.ct.sendgrid
     2 u26465819.ct.sendgrid
     6 u33170455.ct.sendgrid
     1 u34750922.ct.sendgrid
     8 u34933879.ct.sendgrid
     4 u39338181.ct.sendgrid
     4 u39840881.ct.sendgrid
     2 u40053292.ct.sendgrid
     2 u40053620.ct.sendgrid
     4 u47546984.ct.sendgrid
     3 u7351105.ct.sendgrid
     2 u8325676.ct.sendgrid

This is most likely incomplete, as I have not been specifically looking for this pattern before lately.

#phishing #infosec #ioc #spam #sendgrid
hub.volse.noVolse Hubzilla

Just received a #phishing Email that I almost fell for.
I’ve had a #Sendgrid account for a while that I used to use for a project, this account has now been inactive for quite a long time. Today I received an Email from „SendGrid“, informing me that I needed to click a link to verify my account. Thing is, said Email originated from SendGrid’s own SMTP servers, and the URL I was supposed to click does link to ct.sendgrid.net, making this look extremely legit.

#Sendgrid lets customers use custom domains for click tracking in transactional emails, but don't provide SSL certs and use `http://` on all links. It’s 2024; `https://` should be ubiquitous. 🤷‍♂️

If you enforce `https://` for all urls like me, you'll get `NET::ERR_CERT_COMMON_NAME_INVALID` errors. This happened with two emails I received today.

Don't use vanity domains with a SaaS unless they provide SSL certs for it.

Plunk: The #OpenSource #Email #Platform

Plunk is an open-source email platform built on top of #AWS #SES. It allows you to easily send emails from your applications. It can be considered as a self-hosted alternative to services like #SendGrid, #Resend or #Mailgun.

Features
- Transactional Emails: Send emails straight from your API
- Automations: Create automations based on user actions
- Broadcasts: Send newsletters and product updates to big audiences

github.com/useplunk/plunk

Achtung, #Phishing! SendGrid, die Email Marketing Plattform, bekommt den Spam-Missbrauch nach wie vor nicht in den Griff. Aktuell werden über #SendGrid Phishing Mails, die vortäuschen von der LBB Landesbank Berlin zu sein, massenweise an potentielle Phishing-Opfer versendet. Diese Phishing Mails landen nicht im Spam-Ordner, sondern im normalen Posteingang! LBB- Kunden sollten #Emails von der #LBB am besten gar nicht erst öffnen und sofort löschen.
#spam #cybersecurity #scam

The official sendgrid-java module at github.com/sendgrid/sendgrid-j has a dependency on log4j 1.2.17 which is flagged as 'critical security issue' in Sonatype.
Anyone got an idea how I can convince maven to just... not include that dependency? Needs to work with a gitlab ci/cd service.

GitHubGitHub - sendgrid/sendgrid-java: The Official Twilio SendGrid Led, Community Driven Java API LibraryThe Official Twilio SendGrid Led, Community Driven Java API Library - GitHub - sendgrid/sendgrid-java: The Official Twilio SendGrid Led, Community Driven Java API Library