A spearphishing email targeting Sitting Duck support engineers successfully exploited an XSS/CSRF in NetMon. For more detailed information on the attack, see the Attack Narrative in .
Not applicable.
Awareness training (DON'T CLICK!) combined with back-up technical solutions (detection of newly registered domains, sandboxing the email client, etc..).