Phishing sites again ? The Heartbleed bug – the OpenSSL vulnerability that exposed the private keys, passwords and other information of most Internet users – has been making headlines in recent days. So it was only natural that it would also attract the attention of cybercriminals.
The first to warn about the new phishing scams using Heartbleed was Australian security expert Troy Hunt. Below is the first tweet warning.
[tweet_embed id=454199866588028928]
Rob VandenBrink's SANS Institute also reported that it has already received fake emails asking for password changes. The notifications contain links that lead to malware or phishing websites.
So, since you are readers of iGuRu.gr, we shouldn't have to mention how careful we should be when receiving emails from services we don't use, or even from those we do use.
Rather than clicking on a link in an email, it's much better to open the website in a separate tab of your browser and type in the address yourself. It may seem tedious, but it's not dangerous. If you want to change your Gmail password, you can type in gmail.com, which is much safer.
It would be good to think a little logically before panicking. Changing passwords on services that are still vulnerable is pointless. You should wait and make sure that the website has patched the version of OpenSSL it uses before changing your password.
To check for any vulnerabilities on websites you use, you can use LastPass' Heartbleed checker.

