Dear McMaster Community,
We want to make you aware of a potential phishing vulnerability involving malicious OneNote files that may be circulating via email or shared links.
Cybersecurity teams have identified that attackers are using embedded content in OneNote files (such as executable links or scripts) to trick users into clicking harmful elements. The following images provide examples of how attackers embed malicious content within OneNote files.
Initial Phishing Email Inviting Recipients to Edit a File:
OneNote Invitation Containing ‘VIEW DOCUMENT’ Button Leading to Credential Theft or Malware Installation:
These files may appear legitimate but can lead to credential theft or malware installation.
We’re actively monitoring the situation and will provide updates as needed. Your vigilance helps protect our entire McMaster community.
Thank you for your attention and cooperation.
Phish Bowl