tomspark wrote:
macOS users think they're immune to this stuff and it's wild. Standard defense: don't click sketchy links, use a password manager (not your browser), keep your OS updated. The spoofing domains angle is nasty but that's more social engineering than a technical flaw.