Sign in to baba News

One account across the web, iPhone and Android — your subscription follows it.

or use an email code

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories (in the app)
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the monthly limit

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Search stories

Type at least two characters. Results come from every newsroom baba reads.

to move · to open · esc to close

Live Terminal

Sign in to baba News

Sign in to keep asking. News Plus removes the daily limit.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories (in the app)
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the monthly limit

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Security13:04 · 1h ago

Cyber Experts Warn of New QR Code Phishing Scams

Translated & summarized from Ice by baba
The story · English

Cybersecurity firm ESET is alerting users to the growing threat of "Quishing," a phishing technique that exploits QR codes. These codes, now ubiquitous in daily life from restaurant menus to digital payments, are used by attackers because people tend to scan them without suspicion. Unlike traditional phishing, which uses links or files, Quishing hides malicious web addresses within QR codes, making them harder for both users and security systems to detect. The address is not visible as readable text, and standard email filters struggle to identify and inspect it. Sometimes, these codes are embedded within PDF or JPEG files.

Or Isaac, support manager at Comsecure, the exclusive distributor of ESET in Israel, explained that the danger escalates when an employee scans the code with a smartphone. This action moves the user from a secured corporate network to a mobile device, which is often less protected and may not be managed by the organization. This allows a successful email attack to quickly transfer to a more vulnerable environment, enabling the attacker to act more easily.

Quishing goes beyond simple password theft. ESET reports that attackers use this method to steal authentication codes, direct users to download unofficial applications, attempt account takeovers, and even redirect them to legitimate payment apps with pre-filled recipient details. Attackers can leverage regular services and apps as part of the scam, not relying solely on suspicious-looking fake websites. They also use URL shorteners to further obscure the destination and can incorporate links or contact information that lead to phishing sites later. This technique blends well with social engineering tactics, as messages impersonating service updates, signature requests, or account verification can create a sense of urgency, making the QR code appear as part of a legitimate process.

State-sponsored groups are also employing Quishing. In January 2026, the FBI warned that the North Korean hacking group Kimsuky used QR codes in targeted spear-phishing messages sent to research institutions, academic bodies, and government entities in the US and other countries. In some instances, attackers tried to trick recipients into believing that scanning the code would lead to a questionnaire, registration page, or secure drive, thereby prompting them to initiate the attack themselves.

Isaac advises organizations to incorporate QR code attacks into employee phishing training and drills. He recommends avoiding scanning codes from unexpected messages and verifying unusual requests with the sender through independently found contact information. Additionally, he suggests using security solutions for mobile devices, enabling phishing-resistant multi-factor authentication, and keeping operating systems and security tools updated.

Read the original at Ice
Open the live terminal