The attack begins with users receiving a fake CDC email. In order to make it less suspicious, the email is distributed under the subject line of ‘Flu Pandemic Warning’. The infamous GandCrab is back in a new phishing campaign. Here, the attackers are using fake Center for Disease Control (CDC) warning to distribute the GandCrab 5.2 ransomware onto the victims’ ...
Read More »Monthly Archives: March 2019
Sizmek reviews account breach that enable attackers to modify existing ads and offers
The credential of the affected user account is being sold on the dark web for a price starting from $800. Following the discovery, Sizmek has forced a password reset on all internal employee accounts. Sizmek, an American online advertising platform is investigating a security incident in which hackers have gained access to one of the firm’s user account. The credential ...
Read More »Attackers compromised Pakistani government website to deliver Scanbox Framework payload
Researchers detected a compromised Pakistani government website that delivers Scanbox Framework payload whenever anyone visits the site. Trustwave notified the Pakistani government website about the infection, however, the site still remains compromised. What is the issue – Researchers from Trustwave detected a compromised Pakistani government website that delivers Scanbox Framework payload whenever anyone visits the site. Worth noting – The compromised Pakistani ...
Read More »Man drives 3,300 miles to talk to YouTube about deleted video
On Sunday, police in Mountain View, California, where Google is headquartered, arrested a man who drove more than 3,300 miles from Maine to discuss what he thought was the company’s removal of his YouTube account and the one video he’d posted – one about getting rich quick. It was not, in fact, deleted by YouTube. It turns out, his wife ...
Read More »7 uncomfortable truths of Endpoint Security: A Sophos report
A report released today by Sophos reveals that IT managers are more likely to catch cybercriminals on their organization’s servers and networks than anywhere else. The study, 7 Uncomfortable Truths of Endpoint Security, surveyed over 3,100 IT managers in 12 different countries across industry verticals and organization sizes, and was conducted by the independent research specialist Vanson Bourne. The report reveals ...
Read More »SECURITY & FRAUDIndia Lender Warns Of WhatsApp Scam That Steals Bank Details
State Bank of India (SBI), the country’s biggest lender, has issued a warning that account holders are being tricked into offering up personal banking details. According to a report in BGR, SBI said messages from WhatsApp and other social media platforms are tricking customers into sharing details of their accounts. The hackers are tricking the users by first sending a message in an effort ...
Read More »Stolen email credentials being used to pry into cloud accounts
Malicious actors are using the massive supply of previously stolen login credentials to help brute force their way into high-profile cloud-based business systems that cannot easily use two-factor authentication for security. Proofpoint researchers found the availability of these tools has powered a massive increase in the number of cloud attacks taking place which in turn enable the attackers to possibly ...
Read More »RSAC 2019: For Domestic Abuse, IoT Devices Pose New Threat
When it comes to domestic abuse, smart products around the house are turning into new threats, a panel of experts said at RSA. SAN FRANCISCO – The influx of connected products in the home – from smart thermometers to connected locks – presents a disturbing new threat surface for victims of domestic abuse. That’s what Lisa Green, senior director of ...
Read More »Software maker Citrix hacked, business documents removed
Acting on a tip from the FBI, Citrix has investigated and confirmed that its network has been penetrated and data had been exfiltrated by an outside force. Neither the extent of nor the specifics of what has been removed has been determined, but in a statement Citrix said business documents have been accessed and downloaded by malicious actors. The FBI contacted Citrix ...
Read More »Another Windows zero-day vulnerability revealed by Google
The security vulnerability is said to affect Windows 7 systems particularly those with the 32-bit version. This flaw leads to a privilege escalation in the Windows kernel driver allowing malicious components to evade security sandbox. Right after a Chrome security flaw was fixed by Google, another vulnerability existing in Microsoft’s Windows was disclosed by the tech giant. According to Google’s ...
Read More »