KCS Information Technology Inc.
10/21/2025
Watch Out for Fake Google Job Offer Emails
We want to alert you about a new credential phishing scam that is targeting Google Workspace and Microsoft 365 users with fake job offers impersonating Google Careers.
According to researchers at Sublime Security, attackers are sending emails that appear to come from Google recruiters or departments such as “GG Careers”, using addresses like [email protected].
These scammers are constantly changing email addresses, domains, languages, and web pages to bypass spam filters and trick even cautious users. They also use hidden formatting techniques to disguise keywords like “Google Careers” from email security filters.
How the Scam Works?
1. The user receives an email invite with a link or button “Book a Call” or “Apply” for a position.
2. Clicking the link redirects users through several fake pages. Starts with a fake Cloudflare verification page, followed by a fake Google Careers scheduling form.
3. Finally, victims are sent to a spoofed Google login page designed to steal usernames and passwords.
Recommendations to Stay Protected:
1. Be skeptical of unexpected job offers, even if they appear to come from trusted companies like Google.
2. Check the sender’s email address carefully. Legitimate emails from Google will end with .com.
3. Do not click on links or download attachments from unsolicited job-related emails.
4. Verify through official channels before clicking. Visit careers.google.com or the company’s verified LinkedIn page instead of following email links.
5. Report suspicious emails to any of our KCS technicians and right-click on the email to report it as phishing or spam.
6. Enable multi-factor authentication (MFA) on your accounts to increase security.
We recommend you to read more about this topic on the following article(s):
https://support.google.com/faqs/answer/10122524?sjid=11968685626366774464-NC
https://hackread.com/fake-google-job-offer-email-scam-workspace-microsoft-365/
Fake Google Job Offer Email Scam Targets Workspace and Microsoft 365 Users – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More A new report from the leading cybersecurity firm Sublime Security has revealed an ongoing email scam that uses fake job offers from Google to trick people using Google Workspace and Microsoft 365 into giving away their private login details.
10/07/2025
Dear KCS Clients,
We would like to inform you of a new cybersecurity threat involving a malicious software tool called MatrixPDF, which allows attackers to implant regular PDFs with site re-directions and malware.
About the Threat
Researchers from Varonis, a known cybersecurity platform, have identified that cybercriminals are using MatrixPDF to convert legitimate-looking PDF files into interactive files designed to bypass traditional email security. These PDFs often appear as secure or confidential documents but contain fake “Open Secure Document” buttons or links that redirect users to credential-stealing sites or malware downloads.
Since files generated through MatrixPDF do not initially contain malicious code, they can slip past antivirus and spam filters, only becoming dangerous once a user interacts with them.
How to Protect Yourself and Others?
•Be cautious with any PDF attachments, especially if they ask you to click a button or “unlock” secure content.
•Verify the sender’s email address and intent before opening attachments.
•Hover over links or buttons in PDFs to preview the destination URL—do not click if it looks unfamiliar.
•Report any suspicious emails or attachments to [email protected] immediately.
•DO NOT enter login credentials, payment details, or personal information via links from PDF files.
•DO NOT ignore email or browser warnings about external content, unrecognized senders, or unsafe sites.
•DO NOT forward suspicious messages to colleagues. Report them to us first.
If you have any questions or believe you may have interacted with a suspicious PDF, please email us at [email protected] or contact any of our technicians.
We recommend you to read more about this topic on the following article(s):
• https://www.bleepingcomputer.com/news/security/new-matrixpdf-toolkit-turns-pdfs-into-phishing-and-malware-lures/
• https://cyberpress.org/matrixpdf-exploit/
MatrixPDF Exploit Evades Gmail’s Email Filters, Fetches Malicious Payload MatrixPDF exploit - MatrixPDF is a new phishing and malware toolkit turning benign PDFs into weaponized attack vectors. Using overlays.
09/04/2025
Watch Out for Caller ID Spoofing Scams
We want to make you aware of an ongoing phishing campaign involving caller ID spoofing. Users have reported seeing scammers impersonating trusted contacts, businesses, or even government agencies by manipulating the phone number and name that appear on their caller ID. These calls look legitimate by showing the exact number of a friend, family member, your bank, or a well-known company. The goal is to trick you into sharing sensitive information such as login credentials, bank details, or making urgent money transfers.
How Caller ID Spoofing Works?.
Scammers use apps and tools to make their phone calls appear to come from a familiar source. For example:
• A scammer may impersonate Google and claim there is suspicious activity on your account.
• Fraudsters may pose as government officials demanding immediate payment.
• Criminals may impersonate family members in distress to pressure you into sending money.
How to Prevent Falling for This?
• Be cautious of urgent requests for money, passwords, or personal information.
• Hang up immediately if something feels off, and call the person or company back using a verified number. Only use phone numbers from their official website.
• Enable spam/scam call filtering features on your smartphone.
• Do not share passwords, multi-factor authentication codes, or financial details over the phone.
• Do not press buttons, click links in texts, or engage with suspicious prompts during a call.
• Do not assume a familiar name or number on caller ID means the call is safe.
Legitimate organizations, including Google, the IRS, and your bank, will not call you unexpectedly to demand money, login credentials, or verification codes.
Staying alert and cautious is the best way to protect yourself from these scams. If you notice anything suspicious, no matter how small it is, please let us know as soon as possible.
We recommend you to read more about this topic on the following article(s):
https://lifehacker.com/tech/that-phone-call-from-google-is-probably-a-scam
https://us.norton.com/blog/online-scams/caller-id-spoofing
Caller ID spoofing: How to spot and avoid spoofed calls - Norton Thanks to caller ID spoofing, scammers can place phone calls under different names and numbers. To learn more about this scamming technique, follow this guide.
08/21/2025
Password Manager Autofill Vulnerabilities in Clickjacking Attacks
Dear KCS Clients,
We want to bring to your attention a newly disclosed security issue affecting several major password managers, which could expose sensitive information such as login credentials, two-factor authentication (2FA) codes, and credit card details.
What Happened?
Independent security researcher Marek Tóth, along with Socket Security, identified vulnerabilities in browser-based password managers that make them susceptible to clickjacking attacks. In these attacks, malicious websites or compromised pages can overlay invisible elements on top of password manager controls. When users believe they are clicking on harmless elements (such as popups or banners), they may unknowingly trigger their password manager’s autofill function—leaking sensitive data to attackers.
Affected Password Managers
The following products are currently vulnerable in specific versions:
- 1Password 8.11.4.27
- Bitwarden 2025.7.0
- Enpass 6.11.6
- iCloud Passwords 3.1.25
- LastPass 4.146.3
- LogMeOnce 7.12.4
Dashlane, NordPass, ProtonPass, RoboForm, and Keeper have already released fixes. Others, including LastPass, LogMeOnce, and 1Password, have acknowledged the issue and are working on updates.
LastPass and 1Password have implemented certain clickjacking safeguards, including pop-up notifications that require user confirmation that appear before auto-filling credit cards and personal details on all sites.
Recommendations
Until fixes are fully released and confirmed safe, we recommend the following precautions:
1. Disable Autofill: Turn off the autofill feature in your password manager and instead use copy-and-paste for credentials.
2. Update Regularly: Ensure your password manager is always running the latest version, as fixes are actively being released.
3. Be Vigilant Online: Avoid clicking on suspicious popups, banners, or overlays—especially on unfamiliar websites.
4. Use MFA Apps When Possible: For two-factor authentication, prefer using standalone authenticator apps instead of storing 2FA codes in password managers.
5. Stay Informed: Follow vendor announcements for updates and apply patches as soon as they are available.
We will continue monitoring this situation. If you need assistance reviewing your password manager settings or applying security updates, please reach out to the KCS team.
We recommend you to read more about this topic on the following article(s):
• https://cybernews.com/security/password-managers-autofill-credentials-for-attackers/
• https://thecyberexpress.com/dom%E2%80%91based-extension-clickjacking/
• https://thehackernews.com/2025/08/dom-based-extension-clickjacking.html
DOM-Based Extension Clickjacking Exposes Popular Password Managers to Credential and Data Theft DOM-Based Extension Clickjacking Exposes Popular Password Managers to Credential and Data Theft | Read more hacking news on The Hacker News cybersecurity news website and learn how to protect against cyberattacks and software vulnerabilities.
06/16/2025
Watch Out for Malicious "Unsubscribe" Links in Emails
We want to alert you of a rising cybersecurity risk involving "unsubscribe" links in emails. While it may seem harmless to click these links to clean up your inbox, doing so can expose you to phishing attempts or confirm your email address to spammers.
What’s the risk?
* Malicious unsubscribe links may lead to phishing websites that try to steal your login credentials.
* Clicking unsubscribe buttons or links in spam emails confirms your email is active—encouraging more spam.
* According to DNSFilter, 1 in 644 unsubscribe link clicks leads to a malicious site.
Safe ways to manage unwanted emails:
1. Use built-in unsubscribe tools (safer than in-email links):
* Gmail:
Go to More > Manage subscriptions or click Unsubscribe next to the sender’s name.
* Outlook:
Go to Settings > Mail > Subscriptions or use the three dots menu > Block or Unsubscribe.
2. Set up filters or rules to manage emails:
Automatically move messages from unwanted senders to folders or spam.
* In Gmail: More > Filter messages like these
* In Outlook: Right-click > Rules > Create rule
3. Use a disposable or alias email address
For newsletters or sign-ups, consider using a separate or temporary email address to isolate and easily manage promotional emails.
Quick Reminders:
* Never enter your password on a site you reached via an unsubscribe link.
* If you don’t recognize the sender, don’t click any links.
* Mark suspicious messages as spam or phishing instead.
As your IT support, KCS is happy to assist you with the implementation any of these recommendations or answering any questions regarding this issue.
We recommend you to read more about this topic on the following article(s):
*
Watch Out for Malicious Unsubscribe Links Like the flood of spam texts, your email inbox is likely filled with newsletters, promotions, and other messages that you don't care to read and perhaps don't know why you receive. But you shouldn't just start clicking unsubscribe links, which may open you up to certain cybersecurity risks.
Click here to claim your Sponsored Listing.
Category
Contact the business
Telephone
Website
Address
9524 Franklin Avenue
Franklin Park, IL
60131