Securing the digital realm, one tip at a time! 🌐 | Empowering netizens with daily #CyberSecurity insights. Be aware, stay safe. 💡 #OnlineSafety#InfoSecTip
⚠️ ALERT: Exploit alert for Magento users!
A critical flaw, CVE-2024-20720, allows threat actors to sneak a persistent backdoor into e-commerce sites and deploy skimmers to steal financial data.
Learn more: https://t.co/RZmpVgJZ7Y
#hacking#cybersecurity
The #Indian government said it has rescued and repatriated about 250 citizens in Cambodia who were held captive and coerced into running #cyber scams.
The Indian nationals "were lured with employment opportunities to that country but were forced to undertake illegal #cyber work," the Ministry of External Affairs (#MEA) said in a statement, adding it had rescued 75 people in the past three months.
It also said it's working with "with Cambodian authorities and with agencies in #India to crack down on those responsible for these fraudulent schemes."
The development comes in the wake of a report from the Indian Express that said more than 5,000 Indians stuck in #Cambodia were forced into "#cyber slavery" by organized #crime rackets to #scam people in India and extort #money by masquerading as law enforcement authorities in some cases.
The #Android banking #trojan known as Vultur has resurfaced with a suite of new features and improved anti-analysis and detection evasion techniques, enabling its operators to remotely interact with a mobile device and harvest sensitive data.
"Vultur has also started masquerading more of its #malicious activity by encrypting its C2 communication, using multiple #encrypted payloads that are decrypted on the fly, and using the guise of legitimate applications to carry out its malicious actions," NCC Group researcher Joshua Kamp said in a report published last week.
Vultur was first disclosed in early 2021, with the malware capable of leveraging Android's accessibility services APIs to execute its malicious actions.
The malware has been observed to be distributed via trojanized dropper apps on the #Google Play Store, masquerading as authenticator and productivity apps to trick unwitting users into installing them. These dropper apps are offered as part of a dropper-as-a-service (DaaS) operation called Brunhilda.
Other #attack chains, as observed by NCC Group, involve the droppers being spread using a combination of SMS messages and phone calls – a technique called telephone-oriented attack delivery (TOAD) – to ultimately serve an updated version of the #malware.
Apple ID “push bombing” Attack Targeting #Apple Users to Steal passwords
Apple users are falling prey to a sophisticated phishing campaign designed to hijack their Apple IDs through what’s known as a “push bombing” or “MFA fatigue” attack.
This method exploits the #multi-factor authentication (MFA) system, bombarding users with incessant notifications to approve password changes or logins, ultimately aiming to steal passwords and gain unauthorized access to personal information and devices.
The Mechanics of the #Attack
Entrepreneur Parth Patel recently became a target of this phishing scheme, experiencing firsthand the relentless flood of system notifications across all his Apple devices, urging him to approve a #password reset.
This deluge of prompts is not just annoying but strategically designed to wear down the victim’s resistance or catch them off guard, leading to an accidental approval of the #malicious request.
Adding a layer of sophistication to the attack, #phishers follow up with phone calls masquerading as #Apple #Support, using caller ID spoofing to display Apple’s legitimate customer support number.
In Patel’s case, the caller provided accurate personal information, except for his real name, sourced from a people-search website known for inaccurately listing personal details.
This tactic lends credibility to the phishing attempt and aims to manipulate victims into providing a one-time password sent to their device, enabling attackers to reset the Apple ID password and lock out the user.
#Krebs on #Security, a well-known security #blog, recently reported a series of attacks targeting #Apple users, known as “MFA Bombing.”
#GitLab Security Flaw Let #Attackers Inject #Malicious Scripts: Patch Now
GitLab has announced the release of updated versions for both its Community Edition (#CE) and Enterprise Edition (#EE), addressing critical vulnerabilities that could potentially allow attackers to inject malicious scripts and cause denial of service (#DoS) attacks.
The versions released—16.10.1, 16.9.3, and 16.8.5—come as a part of GitLab’s ongoing efforts to maintain the highest security standards and protect its users from emerging #cyber threats.
CVE-2023-6371: Stored XSS #Vulnerability in Wiki Pages
One of the most critical issues addressed in this update is a Stored Cross-Site Scripting (XSS) vulnerability identified as CVE-2023-6371.
Password spraying is a technique #hackers often take advantage of because it enables them to gain unauthorized access to many accounts or systems.
They can potentially compromise many targets with little difficulty by using the same passwords for several accounts.
It is a low-risk and high-reward attack method that the threat actors use while trying to get into networks or steal private information as password spraying defeats account lockout mechanisms.
Recently, cybersecurity researchers at #Cisco warned of password-spraying attacks that are actively targeting #VPN services.
Business email compromise (or #BEC) is a form of #phishing attack where a criminal attempts to trick a senior executive (or budget holder) into transferring funds, or revealing sensitive #information.
The #criminals behind BEC send convincing-looking emails that might request unusual #payments, or contain links to 'dodgy' #websites.
Some emails may contain viruses disguised as harmless attachments, which are activated when opened.
Unlike standard phishing emails that are sent out indiscriminately to millions of people, #BEC attacks are crafted to appeal to specific individuals, and can be even harder to detect.
BEC is a threat to all organisations of all sizes and across all sectors, including non-profit organisations and #government.
If you think you've been a victim of a phishing attack, tell your #IT department as soon as you can. The earlier you tell then, the more likely they'll be able to help.
Hackers Target #macOS Users with Malicious Ads Spreading Stealer #Malware
Malicious ads and bogus websites are acting as a conduit to deliver two different stealer malware, including Atomic Stealer, targeting #Apple macOS users.
The ongoing infostealer attacks targeting macOS users may have adopted different methods to compromise victims' Macs, but operate with the end goal of stealing sensitive data, Jamf Threat Labs said in a report published Friday.
One such attack chain targets users searching for Arc Browser on search engines like #Google to serve bogus ads that redirect users to look-alike sites ("airci[.]net") that serve the malware.
The #Golden Age of Automated #Penetration Testing is Here
#Network penetration testing plays a vital role in detecting vulnerabilities that can be #exploited. The current method of performing pen testing is pricey, leading many #companies to undertake it only when necessary, usually once a year for their compliance requirements.
This manual approach often misses opportunities to find and fix security issues early on, leaving businesses vulnerable to expensive #cyberattacks and potential breaches.
However, new technologies using automation and #AI have revolutionized the process, making regular network pentesting easy and affordable.
We're now in the golden era of pentesting, where every company can assess the #security of their networks without breaking the bank.
More details at : https://t.co/peDKf1HAem
#Ukraine Arrests Trio for #Hijacking Over 100 Million #Email and #Instagram Accounts
The #Cyber Police of #Ukraine has arrested three individuals on suspicion of #hijacking more than 100 million emails and #Instagram accounts from users across the #world.
The suspects, aged between 20 and 40, are said to be part of an organized criminal group living in different parts of the country. If convicted, they face up to 15 years in prison.
The accounts, authorities said, were taken over by carrying out brute-force attacks, which employ trial-and-error methods to guess login credentials. The group operated under the direction of a leader, who distributed the #hacking tasks to other members.
The #cybercrime group subsequently monetized their ill-gotten credentials by putting them up for sale on #darkweb forums.
Other threat actors who purchased the information used the compromised accounts to conduct a variety of fraudulent schemes, including those in which scammers reach out to the victim's friends to urgently transfer #money to their #bank account.
"You can protect your account from this method of #hacking by setting up two-factor authentication and using strong #passwords," the #agency said.
As part of the operation, officials conducted seven searches in Kyiv, Odesa, Vinnytsia, Ivano-Frankivsk, Donetsk, and Kirovohrad, confiscating 70 computers, 14 phones, #bank cards, and #cash worth more than $3,000.
The development comes as a #US. national pleaded guilty to breaching over a dozen entities in the U.S., including a medical clinic in Griffin, and exfiltrating the personal information of more than 132,000 individuals. He is scheduled for sentencing on June 18, 2024.
Robert Purbeck (aka #Lifelock or #Studmaster) "aggravated his crimes by weaponizing sensitive data in an egregious attempt to extort his #victims," U.S. Attorney Ryan K. Buchanan said.
New 'Loop DoS' Attack Impacts Hundreds of Thousands of Systems
A novel denial-of-service (#DoS) #attack vector has been found to target application-layer protocols based on User Datagram Protocol (#UDP), putting hundreds of thousands of hosts likely at risk.
Called Loop DoS attacks, the approach pairs "servers of these protocols in such a way that they communicate with each other indefinitely," researchers from the #CISPA Helmholtz-Center for Information #Security said.
UDP, by design, is a connectionless protocol that does not validate source IP addresses, making it susceptible to IP spoofing.
Thus, when #attackers forge several UDP packets to include a victim IP address, the destination #server responds to the victim (as opposed to the threat actor), creating a reflected denial-of-service (DoS) attack.
The latest study found that certain implementations of the UDP protocol, such as #DNS, #NTP, #TFTP, Active Users, Daytime, Echo, Chargen, #QOTD, and Time, can be weaponized to create a self-perpetuating attack loop.
TeamCity Flaw Leads to Surge in #Ransomware, #Cryptomining, and #RAT Attacks
Multiple threat actors are exploiting the recently disclosed security flaws in #JetBrains TeamCity software to deploy ransomware, #cryptocurrency miners, Cobalt Strike beacons, and a Golang-based remote access trojan called Spark RAT.
The #attacks entail the exploitation of CVE-2024-27198 (CVSS score: 9.8) that enables an adversary to bypass authentication measures and gain administrative control over affected servers.
"The #attackers are then able to install #malware that can reach out to its command-and-control (C&C) server and perform additional commands such as deploying Cobalt Strike beacons and remote access trojans (RATs)," Trend Micro said in a new report.
"#Ransomware can then be installed as a final payload to encrypt files and demand ransom #payments from victims."
Following public disclosure of the flaw earlier this month, it has been weaponized by threat actors associated with BianLian and Jasmin ransomware families, as well as to drop the XMRig cryptocurrency miner and Spark RAT.
Organizations relying on TeamCity for their CI/CD processes are recommended to update their #software as soon as possible to #safeguard against potential threats.
More on https://t.co/Kx3iwPlFDt
From #Deepfakes to #Malware: #AI's Expanding Role in #cyberattacks
Large language models (LLMs) powering artificial intelligence (#AI ) tools today could be exploited to develop self-augmenting malware capable of bypassing YARA rules.
"Generative #AI can be used to evade string-based YARA rules by augmenting the source code of small malware variants, effectively lowering detection rates," Recorded Future said in a new report shared with The #Hacker #News.
The findings are part of a red teaming exercise designed to uncover malicious use cases for AI technologies, which are already being experimented with by threat actors to create malware code snippets, generate #phishing emails, and conduct reconnaissance on potential targets.
The #cybersecurity firm said it submitted to an LLM a known piece of malware called #STEELHOOK that's associated with the APT28 #hacking group, alongside its YARA rules, asking it to modify the source code to sidestep detection such the original functionality remained intact and the generated source code was syntactically free of errors.
Suspected #Russian Data-Wiping 'AcidPour' #Malware Targeting #Linux x86 Devices
A new variant of a data wiping malware called #AcidRain has been detected in the wild that's specifically designed for targeting #Linux x86 devices.
The malware, dubbed AcidPour, is compiled for Linux x86 devices, SentinelOne's Juan Andres Guerrero-Saade said in a series of posts on @X .
"The new variant [...] is an ELF binary compiled for x86 (not MIPS) and while it refers to similar devices/strings, it's a largely different codebase," Guerrero-Saade noted.
AcidRain first came to light in the early days of the #Russo-#Ukrainian war, with the malware deployed against KA-SAT modems from #USA . satellite company #Viasat.
An ELF binary compiled for MIPS architectures is capable of wiping the filesystem and different known storage device files by recursively iterating over common directories for most Linux distributions.
New #Phishing Attack Uses Clever #Microsoft Office Trick to Deploy NetSupport #RAT
A new phishing campaign is targeting #US organizations with the intent to deploy a remote access trojan called NetSupport RAT.
#Israeli#cybersecurity company Perception Point is tracking the activity under the moniker Operation PhantomBlu.
"The PhantomBlu operation introduces a nuanced exploitation method, diverging from NetSupport RAT's typical delivery mechanism by leveraging OLE (Object Linking and Embedding) template manipulation, exploiting #Microsoft Office document templates to execute malicious code while evading detection," security researcher Ariel Davidpur said.
NetSupport #RAT is a malicious offshoot of a legitimate remote desktop tool known as NetSupport Manager, allowing threat actors to conduct a spectrum of data gathering actions on a compromised endpoint.
A #vulnerability classified as improper input validation was found in #Zoom Desktop, Zoom VDI & #zoommeeting for #Windows that could potentially allow an authenticated #attacker to gain access to sensitive information on the system through the network.
https://t.co/qyBliX1dP6
The #Russia -linked threat actor known as #APT28 has been linked to multiple ongoing #phishing campaigns that employ lure documents imitating #government and non-governmental organizations (#NGOs) in #Europe, #Central#Asia, and North and South #America.
https://t.co/cRsuM738cz