Criminals build phishing pages on the no-code platform Bubble
Kaspersky reports that cybercriminals are increasingly using the no-code platform Bubble to build convincing phishing pages that mimic legitimate login portals, with corporate accounts as the main target. Because these sites run on a trusted platform, they pass more easily through traditional security filters and are harder both to detect and to block. The trend lowers the technical barrier for attackers and makes credential-stealing campaigns easier to scale.
What this means for your organisation
Blocking based on domain reputation works poorly when the domain belongs to a platform many organisations use for legitimate purposes themselves. Blacklisting the whole platform is rarely a realistic option. The result is that more fake login pages reach employees, and the volume of attempts against corporate accounts rises. At that point the filter is no longer the last line of defence, the sign-in itself is.
Berigo recommends
- Move to phishing-resistant authentication on email, collaboration and other core services.
- Configure conditional access that requires a known device, not just the right password.
- Monitor alerts for new sign-in sessions and unusual locations, and act on them.
- Give staff a fixed routine for how they log in, so a link in an email is never the normal route.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch