Experts share their insights on protecting against cyber threats and staying ahead of evolving security risks.
Recently active
August 29, 2022 By Ian Barker Your friends may not be willing to tell you that you're looking older, but facial recognition systems have no such reservations.Face-recognition algorithms might struggle to identify you as the same person after just five years, according to the New Scientist.As we increasingly turn to biometrics to secure our systems, the team at Ping Identity has been looking in more detail at the pros and cons of facial recognition systems. >> Full Article <<
By Ionut Arghire on August 29, 2022 Researchers at Georgia Institute of Technology have identified malicious plugins on tens of thousands of WordPress websites.An analysis of nightly backups of more than 400,000 unique web servers has revealed the existence of more than 47,000 malicious plugins installed on nearly 25,000 unique WordPress websites. More than 94% of these plugins (over 44,000) continue to be in use today. >> Full Article <<
August 26, 2022 By Pierluigi Paganini The North Korea-linked Kimsuky APT is behind a new campaign, tracked as GoldDragon, targeting political and diplomatic entities in South Korea in early 2022.Researchers from Kaspersky attribute a series of attacks, tracked as GoldDragon, against political and diplomatic entities located in South Korea in early 2022 to the North Korea-linked group Kimsuky.Kimsuky cyberespiona group (aka Black Banshee, Thallium, Velvet Chollima) was first spotted by Kaspersky researcher in 2013. At the end of October 2020, the US-CERT published a report on Kimusky’s recent activities that provided information on their TTPs and infrastructure. >> Full Article <<
By Ryan Naraine on August 26, 2022 Atlassian’s security response team has issued an urgent advisory to warn of a critical command injection flaw in its Bitbucket Server and Data Center product.The vulnerability carries a CVSS severity score of 9.9 out of 10 and can be exploited remotely to launch code execution attacks, Atlassian said.Atlassian said the security defect, tracked as CVE-2022-36804, was introduced in version 7.0.0 of Bitbucket Server and Data Center. >> Full Article <<
But the "30TB" disk does at least try to fool users in clever ways.ANDREW CUNNINGHAM - 8/26/2022 It feels like high-capacity SSDs are getting cheaper all the time, but in the words of a security researcher known as Ray Redacted on Twitter, there are still some deals that are too good to be true. In the spirit of discovery, he bought a "30TB" external SSD from AliExpress for $31.40, which also happens to be listed on Walmart's website for $39 (I am linking it for educational and entertainment value, please do not buy it). >> Full Article <<
August 26, 2022 By Nathan Collier A PDF reader found on Google Play with over one million downloads is aggressively displaying full screen ads, even when the app is not in use. More specifically, the reader is known as PDF reader - documents viewer, package name com.document.pdf.viewer. As a result, this aggressive behavior lands it in the realm of adware. Or as we call it, Android/Adware.HiddenAds.PPMA.Catching the adwareCatching this adware in real time is a game of install and wait. It takes a couple of hours before the PDF app will display ads. This long delay is in order to make it harder to track down which app is causing the ads. For example, full screen ads displaying immediately after install would likely result in quick a uninstall. With this in mind, I plugged my test phone into my laptop with Android Device Monitor running. Among other tools, Android Device Monitor includes LogCat which logs all activity on an Android mobile device. I then installed PDF reader - documents
August 26, 2022 By Pierluigi Paganini An Iran-linked Mercury APT group exploited the Log4Shell vulnerability in SysAid applications for initial access to the targeted organizations.The Log4Shell flaw (CVE-2021-44228) made the headlines in December after Chinese security researcher p0rz9 publicly disclosed a Proof-of-concept exploit for the critical remote code execution zero-day vulnerability (aka Log4Shell) that affects the Apache Log4j Java-based logging library. >> Full Article <<
By Eduard Kovacs on August 26, 2022 Food delivery company DoorDash revealed on Thursday that customer and employee data has been exposed as a result of a recent breach at a third-party vendor.DoorDash said hackers abused a third-party vendor’s access to its systems. The attacker abused DoorDash’s internal tools and gained access to the information of ‘a small percentage of individuals’. >> Full Article <<
Toronto woman scammed of $25K after being contacted by fake Amazon rep A Toronto senior lost about $25,000 after being contacted by someone pretending to be an Amazon representative.Linda Dyment said that she thought the call she got asking to update her Amazon Prime account sounded legitimate.“They said they needed my credit card information and I said, well why do you need it when you already have it?”According to Dyment, the caller said Amazon wanted to make sure they had the proper information and also asked to check her bank account as well.Dyment agreed and thought she was processing a $39 payment to continue her Prime account.Dyment said days after the July 16 call she never gave it much thought, until she tried to use her credit card."It was declined" said Dyment.Dyment became concerned and contacted her bank, Bank of Montreal, and that’s when she was told someone had used her information to do cash withdrawals over four days totalling $25,000."With all that happening in my acc
They're totally cool with you giving their emails out to spammy companies.Kevin Purdy - 8/25/2022, 11:50 AM DuckDuckGo's tracker-removing email service, which has been available in private beta for a year, is now open to anyone who uses a DuckDuckGo mobile app, browser extension, or Mac browser. It has also added a few more privacy tools.The service provides you a duck.com email address, one intended to be given out for the kind of "Subscribe to our newsletter for 20 percent off" emails you know exist only to harvest data and target you for ads. Email sent to your duck.com address forwards to your chosen primary email—but with trackers removed.Email Protection now also fixes up links, strips them of tracking modifiers, upgrades unencrypted HTTP URLs to HTTPS where possible, and, for the rare necessary reply, allows you to send directly from your duck address instead of exposing your primary email. During their closed beta, DuckDuckGo claims that 85 percent of the emails it processed co
August 24, 2022 By Ax Sharma Google Chrome extension 'Internet Download Manager' installed by more than 200,000 users is adware.The extension has been sitting on the Chrome Web Store since at least June 2019, according to the earliest reviews posted by users.Although the extension may install a known and legitimate download manager program, BleepingComputer observed unwanted behavior exhibited by the extension—such as opening links to spammy sites, changing the default browser search engine, and further hounding the user with pop-ups asking them to download more "patches" and unwanted programs. >> Full Article <<
Mike Peterson | Aug 25, 2022 A new version of the O.MG hacking tool, which looks like an unassuming Lightning cable, can compromise a range of devices and inject commands, log keystrokes, and more.The O.MG Elite was recently showed off at the DEFCON cybersecurity conference in Las Vegas, and The Verge recently took a look into the nefarious accessory's capabilities."It's a cable that looks identical to the other cables you already have," creator MG said. "But inside each cable, I put an implant that's got a web server, USB communications, and Wi-Fi access. So it plugs in, powers up, and you can connect to it." >> Full Article <<
August 25, 2022 By Bill Toulas Hackers are abusing an anti-cheat system driver for the immensely popular Genshin Impact game to disable antivirus software while conducting ransomware attacks.The driver/module, "mhypro2.sys," doesn't need the target system to have the game installed, and it can operate independently or even embedded in malware, offering the threat actors a powerful vulnerability that can disable security software. >> Full Article <<
August 24, 2022 By Christopher Boyd Deepfakes are back, and causing major problems for people involved in financial circles. Scammers have been targeting people in the cryptocurrency community for some time now. There’s huge money to be made via the act of ripping folks off. Some of it is phishing, other attacks focus on breaking into currency exchanges. A few of these have dabbled in (very poorly done) Elon Musk deepfakes. The clips are bad, the voice an overt mashup of clipped and broken dialogue. All in all: not very convincing.Well, scammers are back for another go. >> Full Article <<
By Eduard Kovacs on August 25, 2022 Leaked documents appear to show a little-known spyware company offering services that include Android and iOS device exploits for €8 million (roughly $8 million).Exploit brokers and mercenary spyware providers have been in the spotlight recently, mainly due to revelations surrounding the use of the controversial Pegasus solution of Israeli company NSO Group. >> Full Article <<
August 25, 2022 By Pierluigi Paganini Threat actors are using the Tox peer-to-peer instant messaging service as a command-and-control server, Uptycs researchers reported.Tox is a peer-to-peer serverless instant messaging services that uses NaCl for encryption and decryption.Uptycs researchers reported that threat actors have started using the Tox peer-to-peer instant messaging service as a command-and-control server. Tox has been used in the last months by threat actors as a communication channel between ransomware gangs and their victims. >> Full Article <<
By Ionut Arghire on August 25, 2022 Cisco this week announced patches for two vulnerabilities impacting the NX-OS software that powers its Nexus-series business switches.Impacting the OSPF version 3 (OSPFv3) feature of NX-OS, the first of these issues is tracked as CVE-2022-20823 and could be exploited remotely, without authentication, to cause a denial-of-service (DoS) condition.The flaw exists due to incomplete input validation of specific OSPFv3 packets, allowing an attacker to send a malicious OSPFv3 link-state advertisement (LSA) to a vulnerable device in order to trigger the bug. >> Full Article <<
August 24, 2022 By Karen Hoffman A Comparitech researcher suggests cryptocurrency and NFT scams accounted for $25 trillion in losses. (Photo by Marco Bello/Getty Images)In the wake of recent hyperactive fluctuations, the market for cryptocurrency and non-fungible tokens is believed to have exploded to more than $3 trillion held by over 300 million people worldwide.However, the current size of the market represents only a fraction of how much has been lost over recent years, according to at least one noted industry analyst. Recent findings suggest that “a whopping $25 trillion and counting has been lost to cryptocurrency and NFT rug pulls and scams to date,” according to a recent posting by Rebecca Moody, head of data research for Comparitech. >> Full Article <<
August 24, 2022 By Fionna Agomuoh Iranian state-sponsored hackers have discovered ways to infiltrate the Gmail, Yahoo, and Outlook inboxes of at least two dozen high-profile users and download their content, according to a report from the Google Threat Analysis Group (TAG).The government-backed group known as Charming Kitten originally developed a hacking tool called Hyperscape in 2020 and has used it to orchestrate the recent cyberattacks. TAG was able to get a hold of a version of this tool for analysis, TechRadar reported. >> Full Article <<
The Russia-backed Nobelium APT has pioneered a post-exploitation tool allowing attackers to authenticate as any user. August 24, 2022 By Dark Reading Staff The attackers responsible for the SolarWinds supply chain attack have added a new arrow to their quiver of misery: A post-compromise capability dubbed MagicWeb, which is used to maintain persistent access to compromised environments and move laterally.Researchers at Microsoft observed the Russia-backed Nobelium APT using the backdoor after gaining administrative privileges to an Active Directory Federated Services (AD FS) server. With that privileged access, the attackers replace a legitimate DLL with the MagicWeb malicious DLL, so that the malware is loaded by AD FS as if it were legitimate. >> Full Article <<
August 23, 2022 By Christopher Boyd Microsoft recently released a report about a ChromeOS remote memory corruption vulnerability. The issue has already been fixed. In fact, it was reported to Google in April. The fix was applied shortly after, and released on June 15. The resulting deep-dive from Microsoft is a fascinating look at how one technology giant addresses another’s bugs and issues.A critical issueThe problem, known as CVE-2022-2587 on the Common Vulnerabilities and Exposures (CVE) list, caused big headaches for Chrome. It also racked up a Common Vulnerability Score (CVSS) of 9.8, which results in it being tagged as “Critical”. As per the description: >> Full Article <<
August 24, 2022 By Pierluigi Paganini The threat actors behind a large-scale adversary-in-the-middle (AiTM) phishing campaign now target Google G Suite usersThe threat actors behind a large-scale adversary-in-the-middle (AiTM) phishing campaign targeting enterprise users of Microsoft email services were spotted targeting Google G Suite users.In AiTM phishing, threat actors set up a proxy server between a target user and the website the user wishes to visit, which is the phishing site under the control of the attackers. The proxy server allows attackers to access the traffic and capture the target’s password and the session cookie. >> Full Article <<
Intruders access personal information for the majority of its 30 million users.DAN GOODIN - 8/24/2022 Streaming media platform Plex on Wednesday said it was hacked by intruders who managed to access a proprietary database and make off with password data, usernames, and emails belonging to at least half of its 30 million customers.“Yesterday, we discovered suspicious activity on one of our databases,” company officials wrote in an email sent to customers. “We immediately began an investigation and it does appear that a third-party was able to access a limited subset of data that includes emails, usernames, and encrypted passwords.” >> Full Article <<
By Eduard Kovacs on August 24, 2022 A researcher from the Ben-Gurion University of the Negev in Israel has shown how a threat actor could stealthily exfiltrate data from air-gapped computers using ultrasonic tones and smartphone gyroscopes.The attack method, named GAIROSCOPE, assumes that the attacker has somehow managed to plant malware on the air-gapped computer from which they want to steal data, as well as on a smartphone that is likely to go near the isolated device. >> Full Article <<
August 23, 2022 By Pierluigi Paganini LockBit ransomware gang claims to have hacked the IT giant Entrust and started leaking the stolen files.Entrust Corp., provides software and hardware used to issue financial cards, e-passport production, user authentication for those looking to access secure networks or conduct financial transactions, trust certificated for websites, mobile credentials, and connected devices.The Lockbit ransomware gang claimed to have hacked the company and is threatening to leak the stolen files. The name of the company has been added to the LockBit 3.0 Tor leak site. >> Full Article <<
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.