<?xml version="1.0"?>
<rss version="2.0"><channel><title><![CDATA[News: Security & Privacy News]]></title><link>https://nsaneforums.com/news/security-privacy-news/page/35/?d=2</link><description><![CDATA[News: Security & Privacy News]]></description><language>en</language><item><title>The UK could follow Australia's footsteps in banning social media for those under 16</title><link>https://nsaneforums.com/news/security-privacy-news/the-uk-could-follow-australias-footsteps-in-banning-social-media-for-those-under-16-r26627/</link><description><![CDATA[<p>
	Australia is making waves with its bold move to ban social media for kids under 16, and the UK seems to be eyeing the playbook. The Aussies have proposed legislation that would block under-16s from platforms like TikTok, Instagram, and X. With this legislation, they hope to keep kids safe from the ugly side of the internet (cyberbullying and harmful content). Prime Minister Anthony Albanese summed it up: parents are "worried sick" about what their kids might run into online.
</p>

<p>
	 
</p>

<p>
	If this law passes, it’s not an instant switch. Platforms would have a year to adjust and start proving they’re enforcing the rules. But not everyone’s cheering for it. Critics, including digital industry groups like DIGI, think it could do more harm than good. Their argument? Banning kids might cut them off from online communities that are actually helpful, and maybe teaching digital literacy would be a smarter move.
</p>

<p>
	 
</p>

<p>
	Now, the UK hasn’t officially jumped on this bandwagon yet, but it’s not hard to picture. The country has been wrestling with its own tech regulation challenges. Its Online Safety Bill has already stirred up serious conversations about protecting young people online. If Australia’s plan works out, the UK might just follow suit, especially since the concerns—mental health, online predators, and so on—are pretty universal.
</p>

<p>
	 
</p>

<p>
	The back-and-forth between social media companies, kids, and governments is getting intense. Authorities are clamping down hard, with fines and even jail time being proposed for social media execs who fail to protect kids. For example, the <a href="https://www.neowin.net/news/uk-online-safety-bill-threatens-social-media-companies-ad-revenue-and-user-numbers/" rel="external nofollow">UK’s Online Safety Bill</a> could impose serious penalties if platforms don’t keep younger users safe. These companies are now scrambling to keep up.
</p>

<p>
	 
</p>

<p>
	Social media platforms like Instagram have <a href="https://www.neowin.net/news/instagram-introduces-video-selfie-and-social-vouching-as-new-options-to-verify-age/" rel="external nofollow">rolled out features to protect kids</a>, such as age-verification tools and better privacy controls. But, as usual, these changes are coming pretty late, mostly after governments start pushing for more action. Some companies are even considering creating independent oversight groups to help make sure the rules are followed.
</p>

<p>
	 
</p>

<p>
	At the same time, governments are tightening their grip, forcing platforms to do more. They want to see things like tougher age restrictions and better transparency on how social media companies are dealing with underage users. But it’s not an easy fix. Kids are still finding ways around age checks, and companies still rely heavily on their revenue from younger users.
</p>

<p>
	 
</p>

<p>
	Source: <a href="https://www.bbc.com/news/articles/ce9gpdrx829o" rel="external nofollow">BBC</a>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/the-uk-could-follow-australias-footsteps-in-banning-social-media-for-those-under-16/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26627</guid><pubDate>Wed, 20 Nov 2024 16:47:16 +0000</pubDate></item><item><title>Microsoft Edge is getting scareware blocker and secure password deployment option</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-edge-is-getting-scareware-blocker-and-secure-password-deployment-option-r26608/</link><description><![CDATA[<p>
	At Ignite 2024, Microsoft announced new security and management features, including a new scareware blocker, that make it better for enterprises and users.
</p>

<p>
	 
</p>

<p>
	IT admins can manage the Edge browser within their network using the Microsoft Edge management service in the Microsoft 365 admin center. In some cases within an enterprise, passwords for certain websites are shared among a set of users. Users generally share credentials via email or chats. To prevent such insecure sharing of passwords, the Microsoft Edge management service will soon allow IT admins to deploy an encrypted, shared password to a specific set of users.
</p>

<p>
	 
</p>

<p>
	This will allow those specific users to sign in to websites without knowing the actual passwords. Through this new method, only the users designated by IT admins can access the common webpage or resource, preventing password misuse. Microsoft mentioned that the secure password deployment feature will be available in preview in the coming months for Microsoft 365 Business Premium, E3, and E5 license customers.
</p>

<p>
	 
</p>

<p>
	Based on IT admin feedback, Microsoft is now enabling the <a href="https://www.neowin.net/news/microsoft-edge-123-is-now-available-in-the-stable-channel/" rel="external nofollow">Edge management service</a> to deploy both browser policies in the cloud and Intune. The Edge management service will be the place for browser-first management, and this new Edge management experience is now available in preview.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/windows-defender-will-soon-scareware-apps-like-cleaners-and-optimizers/" rel="external nofollow">Scareware</a> is already on the rise among online scams. Most online users have encountered messages like, “Your computer is infected, click here.” The new scareware blocker in Microsoft Edge will help protect users from such online scams. When a user comes across a website with a warning such as, “Your computer is infected, click here,” the new scareware blocker in Edge will alert the user that it is illegitimate information.
</p>

<p>
	 
</p>

<p>
	Microsoft mentioned that the scareware blocker is AI-powered and will continuously improve its detection capabilities based on user feedback. The new scareware blocker feature is expected to be available in preview for both consumer and commercial customers in the coming months.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/microsoft-edge-is-getting-scareware-blocker-and-secure-password-deployment-option/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26608</guid><pubDate>Tue, 19 Nov 2024 18:02:34 +0000</pubDate></item><item><title>Huge leak reveals what iPhones and Androids the secretive tech tool Graykey can unlock</title><link>https://nsaneforums.com/news/security-privacy-news/huge-leak-reveals-what-iphones-and-androids-the-secretive-tech-tool-graykey-can-unlock-r26607/</link><description><![CDATA[<p>
	A massive leak has revealed the inner workings of Graykey, a powerful phone unlocking tool widely used by law enforcement for digital forensics. For the first time, detailed insights have been shared about its capabilities—particularly concerning newer iPhones running iOS 18.
</p>

<p>
	 
</p>

<p>
	The leaked documents, <a href="https://www.404media.co/leaked-documents-show-what-phones-secretive-tech-graykey-can-unlock-2/" rel="external nofollow">initially shared by 404 Media</a>, show that while Graykey can still unlock many iPhones, there are limits. It works on devices from the iPhone 12 to the iPhone 16 series, but it can only access partial data from those running iOS 18 and the smaller update, iOS 18.0.1. For users hoping to retrieve everything from their devices, Graykey doesn't quite deliver—there’s still plenty it can’t get to.
</p>

<p>
	 
</p>

<figure class="image image--expandable">
	<img alt="A screenshot of one of the documents showing Graykey capabilities against iPhones running iOS 180 an" class="ipsImage" height="459" width="720" src="https://cdn.neowin.com/news/images/uploaded/2024/11/1732034695_iphones-recent.jpg">
	<figcaption>
		<em>Image: 404 Media</em>
	</figcaption>
</figure>

<p>
	A significant twist in this leak is that it doesn’t clearly explain what Graykey can do with iPhones running iOS 18.1, <a href="https://www.neowin.net/news/apple-intelligence-launches-with-ios-181-ipados-181-and-macos-sequoia-151/" rel="external nofollow">which was released just last month</a>. It seems Graykey hasn't caught up to this version yet, and phones are running the beta versions of iOS 18. Forget it—Graykey can’t unlock them at all. 404 Media has provided full versions of the leak <a href="https://docs.google.com/spreadsheets/d/1gf1F8U7VFweBmOc9u10dfvkAWl3KKxZv/edit?gid=1779629987#gid=1779629987" rel="external nofollow">here</a> and <a href="https://docs.google.com/spreadsheets/d/1qZESd9Zj5HkMZnIjLStSNWEyKvs8Drk5/edit?gid=1587154452#gid=1587154452" rel="external nofollow">here</a>.
</p>

<p>
	 
</p>

<p>
	While Graykey’s work on iPhones is increasingly tricky due to Apple's constant security updates, its performance with Android devices isn’t much better. It can unlock partial data from Google Pixel devices—up to the Pixel 9—but only if the phone is in an “After First Unlock” state, meaning the device must have been unlocked at least once since booting up.
</p>

<p>
	 
</p>

<p>
	This leak is a big deal because it gives us a rare look into what Graykey can actually do and what it can’t. Before this, its capabilities were shrouded in secrecy. Forensic experts now have a much clearer picture of its strengths and weaknesses when it comes to cracking iPhones.
</p>

<p>
	 
</p>

<p>
	However, just because Graykey can’t unlock every piece of data doesn’t mean its battle with Apple and Google is over. In fact, it's all part of a long-running cat-and-mouse game. While Apple and Google push updates to protect user data, forensic companies like Grayshift and Cellebrite work tirelessly to stay ahead, trying to overcome obstacles like the USB Restricted Mode, <a href="https://www.neowin.net/news/experts-reveal-why-iphones-are-suddenly-rebooting-themselves-leaving-police-stumped/" rel="external nofollow">Inactivity Reboot</a>, and other security measures Apple has introduced in recent years.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/huge-leak-reveals-what-iphones-and-androids-the-secretive-tech-tool-graykey-can-unlock/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26607</guid><pubDate>Tue, 19 Nov 2024 18:01:41 +0000</pubDate></item><item><title>Spotify abused to promote pirated software and game cheats</title><link>https://nsaneforums.com/news/security-privacy-news/spotify-abused-to-promote-pirated-software-and-game-cheats-r26606/</link><description><![CDATA[<p>
	Spotify playlists and podcasts are being abused to push pirated software, game cheat codes, spam links, and "warez" sites.
</p>

<p>
	 
</p>

<p>
	By injecting targeted keywords and links in playlist names and podcast descriptions, threat actors may benefit from boosting SEO for their dubious online properties, since Spotify's web player results appear in search engines like Google.
</p>

<h2>
	Spotify playlists pushing <em>warez</em>
</h2>

<p>
	When abusing platforms, spammers and scammers leave no stone unturned to promote their agenda.
</p>

<p>
	 
</p>

<p>
	Most recently, a Spotify playlist with the title "Sony Vegas Pro 13 Crack..." appeared to drive traffic to one or more "free" software sites listed in the playlist title and description.
</p>

<p>
	 
</p>

<p>
	Cybersecurity ethusiast Karol Paciorek who <a href="https://twitter.com/karol_paciorek/status/1858477716456005923" rel="external nofollow" target="_blank">spotted</a> the playlist said, "cybercriminals exploit Spotify for malware distribution. Why? Spotify has a strong reputation and its pages are easily indexed by search engines, making it an effective platform to promote malicious links."
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Spotify playlist promoting Sony Vegas Pro pirated software" class="ipsImage" height="515" width="720" src="https://www.bleepstatic.com/images/news/u/1164866/2024/Nov/spotify-abused-spam/1731934401334.jpeg">
		<figcaption>
			<em>Spotify playlist promoting Sony Vegas Pro "crack"<br>
			(Karol Paciorek)</em>
		</figcaption>
	</figure>
</div>

<p>
	The terms "warez" or "crack" are frequently used in the computing culture to refer to bootleg or pirated software circulating on the internet, often on untrustworthy websites.
</p>

<p>
	 
</p>

<p>
	There's no guarantee, ever, that attempting to download counterfeit software products from such websites, or "torrents" will be risk-free, as these could be malware, or lead users to bogus "survey" sites which are scams.
</p>

<p>
	 
</p>

<p>
	Users who download such "warez" may indeed, on occasion, receive the software program advertised on the suspicious websites without coughing up a fee, but may unknowingly end up with viruses, adware, or other unwanted programs hidden in the "cracked" version of the software.
</p>

<h2>
	Added benefit: SEO for spam sites
</h2>

<p>
	We observed that a side effect of polluting trustworthy and vastly popular platforms like Spotify with spam, for threat actors, is the added boost to the search engine rankings of their shady websites.
</p>

<p>
	 
</p>

<p>
	Those searching for keywords like "free download" combined with "Sony Vegas Pro 13" or other software products may be presented with the following Google results:
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Spotify podcasts and playlists appear in search results" class="ipsImage" height="370" width="720" src="https://www.bleepstatic.com/images/news/u/1164866/2024/Nov/spotify-abused-spam/spotify-google-results.jpg">
		<figcaption>
			<em>Spotify playlists and podcasts appear in search results<br>
			(BleepingComputer)</em>
		</figcaption>
	</figure>
</div>

<p>
	This is made possible because, in addition to mobile and desktop apps, Spotify offers a web player version at <em>open.spotify.com.</em> Playlists and podcasts available on the web player are, as with any website, crawled by search engines like Google.
</p>

<p>
	 
</p>

<p>
	This means, the illicit "free" software websites now have greater visibility and a higher chance of driving traffic to their servers—which are often riddled with ads, spam content, bogus "surveys," and crypto giveaways that one would have to navigate through to<em>, </em>perhaps<em>,</em> be able to finally download a cracked software product, which is once again bound to be risky.
</p>

<p>
	 
</p>

<p>
	We asked Spotify if it had any controls or automated technologies in place to catch and prevent spam, and if any third-party Spotify apps or services were being abused to sneak in spam content on the platform.
</p>

<p>
	 
</p>

<p>
	Spotify deleted the "Sony Vegas Pro" playlist and podcast and their spokesperson responded:
</p>

<p>
	 
</p>

<p>
	"The playlist title in question has been removed," Spotify informed BleepingComputer.<br>
	<br>
	"Spotify's <a href="https://www.spotify.com/us/safetyandprivacy/platform-rules" rel="external nofollow" target="_blank">Platform Rules</a> prohibit posting, sharing, or providing instructions on implementing malware or related malicious practices that seek to harm or gain unauthorized access to computers, networks, systems, or other technologies."
</p>

<p>
	 
</p>

<p>
	We did not get an answer to our other questions.
</p>

<h2>
	Podcast 'episodes' use synthesized speech
</h2>

<p>
	BleepingComputer discovered Spotify's spam problem was not limited to playlists promoting links to pirated software but bootleg digital content in general, including eBooks.
</p>

<p>
	 
</p>

<p>
	Compared to playlists, we observed much greater instances of spurious podcasts, each with several "episodes," published with the apparent intention of promoting spam links, "torrents," and Telegram channels that seem to be scams.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Several Spotify podcasts and playlists promoting pirated digital eBooks" class="ipsImage" height="278" style="height: auto;" width="600" src="https://www.bleepstatic.com/images/news/u/1164866/2024/Nov/spotify-abused-spam/more-epub-spam.jpg">
		<figcaption>
			<em>Several Spotify podcasts and playlists promoting ePubs and eBook PDFs<br>
			(BleepingComputer)</em>
		</figcaption>
	</figure>
</div>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Spurious Spotify podcasts promoting ebooks and torrents" class="ipsImage" height="363" style="height: auto;" width="600" src="https://www.bleepstatic.com/images/news/u/1164866/2024/Nov/spotify-abused-spam/podcast-ebooks.jpg">
		<figcaption>
			<em>eBook and "torrent" podcasts on Spotify<br>
			(BleepingComputer)</em>
		</figcaption>
	</figure>
</div>

<p>
	These "episodes" are about ten to twenty seconds long, and comprise synthesized speech audio that directs users to visit the "link in the description." One such episode is transcribed below:
</p>

<p>
	 
</p>

<p>
	"Hello viewers, welcome to my channel, there is good news from me, if you want to download or listen to audiobooks from this channel, please click the link in the description and sign up there then you will get unlimited book access, please follow me I am looking for several ebook and audiobook options. Thank you for coming to my channel, warm greetings from me."
</p>

<p>
	 
</p>

<p>
	These links lead to a page that does have "download" or "read online" buttons featured next to the advertised book's digital cover image. Clicking either button, however, attempts to either launch a survey or worse, directs users to <a href="https://chromewebstore.google.com/detail/adblock-popup-ads/mdbglkdbdommcbnepklehgbhceaejkph/reviews?an=at&amp;cid=460f66f1e9b4ef2efd53ee975e4d3e8b&amp;sid=24934902" rel="external nofollow" target="_blank">flimsy "ad block" Chrome extensions</a> which may be instead be collecting your data:
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Adblock extension ads" class="ipsImage" height="320" style="height: auto;" width="600" src="https://www.bleepstatic.com/images/news/u/1164866/2024/Nov/spotify-abused-spam/adblock-ad.jpg">
		<figcaption>
			<strong>Dubious "adblock" Chrome extension ads </strong>(BleepingComputer)
		</figcaption>
	</figure>
</div>

<h2>
	Next up: Game cheats and "GTA V" mods
</h2>

<p>
	Similarly, some <a href="http://archive.is/XyAXu" rel="external nofollow" target="_blank">podcasts we discovered</a> claimed to offer game cheat codes for hit titles like Apex Legends, Fortnite hacks, Roblox scripts, "GTA V mods," and trainers.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="cheat codes" class="ipsImage" height="285" style="height: auto;" width="400" src="https://www.bleepstatic.com/images/news/u/1164866/2024/Nov/spotify-abused-spam/podcast-game-cheats.jpg">
		<figcaption>
			<em>Podcast description contains keywords for game cheats and hacks<br>
			(BleepingComputer)</em>
		</figcaption>
	</figure>
</div>

<p>
	The "Free Cheat Codes" text in the description of this example episode was clickable and led to a <em>cheater.ninja</em> website:
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Cheater ninja website pushed via podcasts" class="ipsImage" height="349" style="height: auto;" width="600" src="https://www.bleepstatic.com/images/news/u/1164866/2024/Nov/spotify-abused-spam/cheater-ninja.jpg">
		<figcaption>
			<em>A "Cheater.ninja" game cheats website pushed via podcasts (BleepingComputer)</em>
		</figcaption>
	</figure>
</div>

<p>
	In August, security researcher <em>@g0njxa</em> shared examples of "Fortnite" spammers abusing the platform too:
</p>

<p>
	 
</p>

<div class="ipsEmbeddedOther" contenteditable="false">
	<iframe allowfullscreen="" class="ipsEmbed_finishedLoading" data-controller="core.front.core.autosizeiframe" data-embedid="embed4305022643" src="https://nsaneforums.com/index.php?app=core&amp;module=system&amp;controller=embed&amp;url=https://twitter.com/g0njxa/status/1826270148556189762?ref_src=twsrc%255Etfw%257Ctwcamp%255Etweetembed%257Ctwterm%255E1826270148556189762%257Ctwgr%255E26f9f7a94aee7ae245c2745b3060851712fbc19b%257Ctwcon%255Es1_%26ref_url=https://www.bleepingcomputer.com/news/security/spotify-abused-to-promote-pirated-software-and-game-cheats/" style="overflow: hidden; height: 681px;"></iframe>
</div>

<h2>
	Published via third-party podcast distribution services
</h2>

<p>
	Interestingly, while platforms like Spotify could have their automated technologies and barriers restricting invalid playlist names or descriptions, third-party apps and services are another vector threat actors tap into to get their foot in.
</p>

<p>
	 
</p>

<p>
	A common denominator among many, though not all such "podcasts" was the use of such third-party services that provide hosting, publication, and distribution services to podcast producers across streaming platforms including Spotify.
</p>

<p>
	 
</p>

<p>
	We noticed a "<a href="https://archive.is/wip/Lw25u" rel="external nofollow" target="_blank">Powered by Firstory Hosting</a>" banner appended to the description area of these podcasts.
</p>

<p>
	 
</p>

<p>
	Launched in 2019, <a href="https://firstory.me/" rel="external nofollow" target="_blank">Firstory</a> is an online service designed to "empower podcasters in the world to distribute everywhere and start to connect with audiences!"
</p>

<p>
	 
</p>

<p>
	One can use Firstory to publish podcasts on Spotify, but the platform acknowledges that spam is an ongoing problem that it is focusing on curtailing.
</p>

<p>
	 
</p>

<p>
	"Spam accounts and content are ongoing challenges, and it's something we continue to focus on improving," wrote Firstory co-founder Stanley Yu to BleepingComputer in response to our questions.
</p>

<p>
	 
</p>

<p>
	"Anyone can use our platform to publish podcasts on Spotify. However, we do have certain filters in place to prevent accounts using specific fraudulent domains or email addresses containing variations such as account+[numbers]@gmail.com or '.' in emails."
</p>

<p>
	 
</p>

<p>
	"These spam accounts not only violate the rights of the creators we value most, but they also drive up our operational costs."
</p>

<p>
	 
</p>

<p>
	"We've dedicated considerable resources to addressing this issue."
</p>

<p>
	 
</p>

<p>
	Yu shared that the security measures in place include email verification and blocking; that is, conducting "a series of checks to block suspicious or fraudulent email addresses during the account registration process."
</p>

<p>
	 
</p>

<p>
	Further, the platform works closely with Spotify and, according to Yu, promptly reviews and reports any infringing content detected.
</p>

<p>
	 
</p>

<p>
	"We also have API integration with Spotify to remove any flagged content."
</p>

<p>
	 
</p>

<p>
	"We scan podcast titles and show notes for specific keywords like EPUB, PDF, etc., to prevent the hosting of spammy content. A challenge here is that some episodes use variations such as "E.P.U.B." or contain terms like "epub" in unrelated contexts (e.g., "republic"). These cases require extra attention during our review process," Yu concluded.
</p>

<p>
	 
</p>

<p>
	From sneaking in <a href="https://www.bleepingcomputer.com/news/technology/tinder-spam-campaign-hides-handwritten-links-in-profile-images/" target="_blank" rel="external nofollow">"handwritten" links in dating profiles</a> to hijacking <a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-14-year-old-cms-editor-on-govt-edu-sites-for-seo-poisoning/" target="_blank" rel="external nofollow">government</a> and <a href="https://www.bleepingcomputer.com/news/security/university-websites-using-mediawiki-twiki-hacked-to-serve-fortnite-spam/" target="_blank" rel="external nofollow">university websites</a>, unscrupulous actors have repeatedly employed novel tactics to push unwanted content to the masses. And, now they won't leave you in peace with your favorite music either.
</p>

<p>
	 
</p>

<p>
	<em>Update, November 19th, 07:54 AM ET: Added quote from expert, Karol Paciorek.</em>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/spotify-abused-to-promote-pirated-software-and-game-cheats/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26606</guid><pubDate>Tue, 19 Nov 2024 18:00:03 +0000</pubDate></item><item><title>No, Microsoft doesn't have dirt on you, it's just a sextortion scam</title><link>https://nsaneforums.com/news/security-privacy-news/no-microsoft-doesnt-have-dirt-on-you-its-just-a-sextortion-scam-r26588/</link><description><![CDATA[<p>
	Hackers are pulling a clever trick with the Microsoft 365 Admin Portal to send sextortion emails that sneak past spam filters and land directly in your inbox. These scams use the Microsoft 365 Message Center—a tool designed for legitimate updates about services and features. Instead of sending real updates, cybercriminals are abusing its "Share" feature to push their scam messages, making them look like they came straight from Microsoft.
</p>

<p>
	 
</p>

<p>
	Here’s the deal: these emails claim your device was hacked and that they’ve got dirt on you—like videos or images of you in compromising situations. The scammers then demand payment in Bitcoin, threatening to share the supposed material if you don’t pay up. It’s a bold move, and the use of a legitimate Microsoft email address makes it seem even more real.
</p>

<p>
	 
</p>

<p>
	What makes these emails especially dangerous is how they manage to bypass email security systems. Normally, these scams would be flagged by filters, but because they are sent from a trusted Microsoft address, "o365mc@microsoft.com," they get through unnoticed.
</p>

<p>
	 
</p>

<p>
	Apparently, these scammers are abusing the "Personal Message" field in the Microsoft 365 Message Center’s "Share" option, which is designed to add a short note when sharing an advisory. Normally, this field is capped at 1,000 characters, but attackers have figured out a way around it. By using browser developer tools, they tweak the <strong>maxlength</strong> attribute in the HTML <strong>textarea</strong> element to allow longer messages. This lets them include their full sextortion text in the email without truncation.
</p>

<p>
	 
</p>

<figure class="image image--expandable">
	<img alt="a screenshot of the textarea element being edited to increase the maximum length" class="ipsImage" height="112" width="720" src="https://cdn.neowin.com/news/images/uploaded/2024/11/1731941488_changing-maxlength.jpg">
	<figcaption>
		<em>Image: Bleeping Computer</em>
	</figcaption>
</figure>

<p>
	It’s downright embarrassing for Microsoft that this works because the first rule in cybersecurity is "Never trust user input." This principle, often phrased as "Never trust what comes from the browser," emphasizes that client-side validations (like the character limit) are unreliable. Without server-side checks to enforce these restrictions, the email system blindly processes and sends the altered message.
</p>

<p>
	 
</p>

<p>
	Although this technique has allowed scammers to bypass filters, it is important for users to recognize these emails for what they are: scams. <a href="https://www.bleepingcomputer.com/news/security/microsoft-365-admin-portal-abused-to-send-sextortion-emails/" rel="external nofollow">Bleeping Computer says</a> that Microsoft has acknowledged the issue and is investigating the abuse, but as of now, the server-side checks to prevent such messages haven't been added.
</p>

<p>
	 
</p>

<p>
	A <a href="https://answers.microsoft.com/en-us/msoffice/forum/all/i-have-an-email-that-purports-to-be-from-microsoft/d8d68580-ee1f-40a6-b022-f74f1794e1ee" rel="external nofollow">copy of one such scam email</a> was posted on the Microsoft Answers forum, where a user shared the disturbing content. The email included bizarre arrow symbols and detailed information about the recipient, including their birthdate, to make it seem more authentic. It threatened to share compromising footage unless a Bitcoin payment was made within 48 hours.
</p>

<p>
	 
</p>

<p>
	Sextortion emails are nothing new, but they're getting way nastier and more advanced. A big chunk of these scams is <a href="https://www.neowin.net/news/increase-in-cyber-sextortion-largely-being-driven-by-one-african-cybercriminal-group/" rel="external nofollow">driven by groups like the infamous "Yahoo Boys" from West Africa</a>, who’ve turned this into a full-blown operation. They’ve been sharing how-to guides on platforms like TikTok and YouTube, targeting teens and young adults on apps like Instagram and Snapchat.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/no-microsoft-doesnt-have-dirt-on-you-its-just-a-sextortion-scam/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26588</guid><pubDate>Mon, 18 Nov 2024 18:51:32 +0000</pubDate></item><item><title>Fake Bitwarden ads on Facebook push info-stealing Chrome extension</title><link>https://nsaneforums.com/news/security-privacy-news/fake-bitwarden-ads-on-facebook-push-info-stealing-chrome-extension-r26587/</link><description><![CDATA[<p>
	Fake Bitwarden password manager advertisements on Facebook are pushing a malicious Google Chrome extension that collects and steals sensitive user data from the browser.
</p>

<p>
	 
</p>

<p>
	Bitwarden is a popular password manager app with a "free" tier featuring end-to-end encryption, cross-platform support, MFA integration, and a user-friendly interface.
</p>

<p>
	 
</p>

<p>
	Its user base has been growing steadily in the past couple of years, especially following <a href="https://www.bleepingcomputer.com/news/security/lastpass-hackers-stole-customer-vault-data-in-cloud-storage-breach/" target="_blank" rel="external nofollow">security breaches of competitors</a> that led many to look for alternatives.
</p>

<p>
	 
</p>

<p>
	A new malvertising campaign impersonating Bitwarden was <a href="https://www.bitdefender.com/en-us/blog/labs/inside-bitdefender-labs-investigation-of-a-malicious-facebook-ad-campaign-targeting-bitwarden-users" rel="external nofollow" target="_blank">spotted by Bitdefender Labs</a>, whose researchers report that the operation launched on November 3, 2024.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Multiple ads of the same campaign" class="ipsImage" height="290" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2024/Phishing/25/ads.jpg">
		<figcaption>
			<em>Multiple ads of the same campaign<br>
			Source: Bitdefender</em>
		</figcaption>
	</figure>
</div>

<h2>
	Malicious Facebook advertisements
</h2>

<p>
	The Facebook advertising campaign warns users that they're "using an outdated version of Bitwarden," and need to update the program immediately to secure their passwords.
</p>

<p>
	 
</p>

<p>
	The link included in the ad is 'chromewebstoredownload[.]com,' which pretends to be Google's official Chrome Web Store at 'chromewebstore.google.com.'
</p>

<p>
	 
</p>

<p>
	The landing page also features a design closely resembling the Chrome Web Store, including an 'Add to Chrome' button.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Malicious website mimicking the real Google web store" class="ipsImage" height="423" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2024/Phishing/25/site.jpg">
		<figcaption>
			<em>Malicious website mimicking the real Google web store<br>
			Source: Bitdefender</em>
		</figcaption>
	</figure>
</div>

<p>
	However, instead of the extension automatically installing when you click the link, visitors are prompted to download a ZIP file from a Google Drive folder.
</p>

<p>
	 
</p>

<p>
	Though this should be a clear sign of danger, users unfamiliar with the Chrome Web Store may proceed with the manual installation, following the instructions on the webpage.
</p>

<p>
	 
</p>

<p>
	The installation requires enabling 'Developer Mode' on Chrome and manually sideloading the extension on the program, so essentially, security checks are bypassed.
</p>

<p>
	 
</p>

<p>
	Once installed, the extension registers as 'Bitwarden Password Manager' version 0.0.1 and secures permissions that enable it to intercept and manipulate user activities.
</p>

<p>
	 
</p>

<p>
	Its main functions are the following:
</p>

<p>
	 
</p>

<ul>
	<li>
		Collect Facebook cookies, particularly the 'c_user' cookie containing the user ID.
	</li>
	<li>
		Gather IP and geolocation data using public APIs
	</li>
	<li>
		Collect Facebook user details, account information, and billing data through Facebook's Graph API
	</li>
	<li>
		Manipulates browser DOM to display fake loading messages for legitimacy or deception.
	</li>
	<li>
		Encodes sensitive data and transmits it to a Google Script URL under the attackers' control.
	</li>
</ul>

<p>
	 
</p>

<p>
	To mitigate this risk, Bitwarden users are advised to ignore ads prompting extension updates, as Chrome extensions are automatically updated when the vendor releases a new version.
</p>

<p>
	 
</p>

<p>
	Extensions should only be installed via Google's official web store or by following links from the project's official website, in this case, bitwarden.com.
</p>

<p>
	 
</p>

<p>
	When installing a new extension, always check the requested permissions and treat overly aggressive requests involving access to cookies, network requests, and website data with high suspicion.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/fake-bitwarden-ads-on-facebook-push-info-stealing-chrome-extension/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26587</guid><pubDate>Mon, 18 Nov 2024 18:50:45 +0000</pubDate></item><item><title>Security plugin flaw in millions of WordPress sites gives admin access</title><link>https://nsaneforums.com/news/security-privacy-news/security-plugin-flaw-in-millions-of-wordpress-sites-gives-admin-access-r26575/</link><description><![CDATA[<p>
	A critical authentication bypass vulnerability has been discovered impacting the WordPress plugin 'Really Simple Security' (formerly 'Really Simple SSL'), including both free and Pro versions.
</p>

<p>
	 
</p>

<p>
	Really Simple Security is a security plugin for the WordPress platform, offering SSL configuration, login protection, a two-factor authentication layer, and real-time vulnerability detection. Its free version alone is used in over four million websites.
</p>

<p>
	 
</p>

<p>
	Wordfence, which publicly disclosed the flaw, calls it one of the most severe vulnerabilities reported in its 12-year history, <a href="https://www.wordfence.com/blog/2024/11/really-simple-security-vulnerability/" rel="external nofollow" target="_blank">warning</a> that it allows remote attackers to gain full administrative access to impacted sites.
</p>

<p>
	 
</p>

<p>
	To make matters worse, the flaw can be exploited en masse using automated scripts, potentially leading to large-scale website takeover campaigns.
</p>

<p>
	 
</p>

<p>
	Such is the risk that Wordfence proposes that hosting providers force-update the plugin on customer sites and scan their databases to ensure nobody runs a vulnerable version.
</p>

<h2>
	2FA leading to weaker security
</h2>

<p>
	The critical severity flaw in question is <a href="https://www.wordfence.com/threat-intel/vulnerabilities/detail/really-simple-security-free-pro-and-pro-multisite-900-9111-authentication-bypass" rel="external nofollow" target="_blank">CVE-2024-10924</a>, discovered by Wordfence's researcher István Márton on November 6, 2024.
</p>

<p>
	 
</p>

<p>
	It is caused by improper handling of user authentication in the plugin's two-factor REST API actions, enabling unauthorized access to any user account, including administrators.
</p>

<p>
	 
</p>

<p>
	Specifically, the problem lies in the 'check_login_and_get_user()' function that verifies user identities by checking the 'user_id' and 'login_nonce' parameters.
</p>

<p>
	 
</p>

<p>
	When 'login_nonce' is invalid, the request isn't rejected, as it should, but instead invokes 'authenticate_and_redirect(),' which authenticates the user based on the 'user_id' alone, effectively allowing authentication bypass.
</p>

<p>
	 
</p>

<p>
	The flaw is exploitable when two-factor authentication (2FA) is enabled, and even though it's disabled by default, many administrators will allow it for stronger account security.
</p>

<p>
	 
</p>

<p>
	CVE-2024-10924 impacts plugin versions from 9.0.0 and up to 9.1.1.1 of the "free," "Pro," and "Pro Multisite" releases.
</p>

<p>
	 
</p>

<p>
	The developer addressed the flaw by ensuring that the code now correctly handles 'login_nonce' verification fails, exiting the 'check_login_and_get_user()' function immediately.
</p>

<p>
	 
</p>

<p>
	The fixes were applied to version 9.1.2 of the plugin, released on November 12 for the Pro version and November 14 for free users.
</p>

<p>
	 
</p>

<p>
	The vendor coordinated with WordPress.org to perform force security updates on users of the plugin, but website administrators still need to check and ensure they're running the latest version (9.1.2).
</p>

<p>
	 
</p>

<p>
	Users of the Pro version have their auto-updates disabled when the license expires, so they must manually update 9.1.2.
</p>

<p>
	 
</p>

<p>
	As of yesterday, the <a href="https://wordpress.org/plugins/really-simple-ssl/advanced/" rel="external nofollow" target="_blank">WordPress.org stats</a> site, which monitors installs of the free version of the plugin, showed approximately 450,000 downloads, leaving 3,500,000 sites potentially exposed to the flaw.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/security-plugin-flaw-in-millions-of-wordpress-sites-gives-admin-access/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26575</guid><pubDate>Sun, 17 Nov 2024 17:16:27 +0000</pubDate></item><item><title>T-Mobile confirms it was hacked in recent wave of telecom breaches</title><link>https://nsaneforums.com/news/security-privacy-news/t-mobile-confirms-it-was-hacked-in-recent-wave-of-telecom-breaches-r26571/</link><description><![CDATA[<p>
	T-Mobile confirms it was hacked in the wave of recently reported telecom breaches conducted by Chinese threat actors to gain access to private communications, call records, and law enforcement information requests.
</p>

<p>
	 
</p>

<p>
	"T-Mobile is closely monitoring this industry-wide attack, and at this time, T-Mobile systems and data have not been impacted in any significant way, and we have no evidence of impacts to customer information," T-Mobile told the <a href="https://www.wsj.com/politics/national-security/t-mobile-hacked-in-massive-chinese-breach-of-telecom-networks-4b2d7f92?st=ZyDoU4&amp;reflink=desktopwebshare_permalink" rel="external nofollow" target="_blank">Wall Street Journal</a>, which first reported about the breach.
</p>

<p>
	 
</p>

<p>
	"We will continue to monitor this closely, working with industry peers and the relevant authorities."
</p>

<p>
	 
</p>

<p>
	T-Mobile shared a similar statement with BleepingComputer, stating it has found no evidence of any customer data being accessed or exfiltrated.
</p>

<p>
	 
</p>

<p>
	"Due to our security controls, network structure and diligent monitoring and response we have seen no significant impacts to T-Mobile systems or data," T-Mobile told BleepingComputer after the publishing of this story.
</p>

<p>
	 
</p>

<p>
	"We have no evidence of access or exfiltration of any customer or other sensitive information as other companies may have experienced."
</p>

<p>
	 
</p>

<p>
	Last month, The Wall Street Journal reported that Chinese state-sponsored threat actors known as Salt Typhoon had <a href="https://www.bleepingcomputer.com/news/security/atandt-verizon-reportedly-hacked-to-target-us-govt-wiretapping-platform/" target="_blank" rel="external nofollow">breached multiple U.S. telecommunication companies</a>, including AT&amp;T, Verizon, and Lumen.
</p>

<p>
	 
</p>

<p>
	Salt Typhoon (aka Earth Estries, FamousSparrow, Ghost Emperor, and UNC2286) is a sophisticated Chinese state-sponsored hacking group active since at least 2019 and typically focuses on breaching government entities and telecommunications companies in Southeast Asia.
</p>

<p>
	 
</p>

<p>
	WSJ reports that the hacking campaign allowed the threat actors to target the cellphone lines of senior U.S. national security and policy officials across the U.S. government to steal call logs, text messages, and some audio.
</p>

<p>
	 
</p>

<p>
	In a joint statement from the FBI and CISA earlier this week, the <a href="https://www.bleepingcomputer.com/news/security/chinese-hackers-compromised-us-government-officials-private-communications-in-recent-telecom-breach/" target="_blank" rel="external nofollow">U.S. government confirmed</a> that the threat actors stole call data, communications from targeted people, and information about law enforcement requests submitted to telecommunication companies.
</p>

<p>
	 
</p>

<p>
	"Specifically, we have identified that PRC-affiliated actors have compromised networks at multiple telecommunications companies to enable the theft of customer call records data, the compromise of private communications of a limited number of individuals who are primarily involved in government or political activity, and the copying of certain information that was subject to U.S. law enforcement requests pursuant to court orders,," reads the <a href="https://content.govdelivery.com/accounts/USDHSCISA/bulletins/3c1b400" rel="external nofollow" target="_blank">joint statement</a>.
</p>

<p>
	 
</p>

<p>
	"We expect our understanding of these compromises to grow as the investigation continues."
</p>

<p>
	 
</p>

<p>
	These attacks were reportedly conducted through vulnerabilities in Cisco routers responsible for routing internet traffic. However, Cisco previously stated there were no indications that their equipment was breached during these attacks.
</p>

<p>
	 
</p>

<p>
	This breach is the ninth T-Mobile suffered since 2019, with the other incidents being:
</p>

<p>
	 
</p>

<ul style="list-style-type:square">
	<li>
		In 2019, T-Mobile <a href="https://www.bleepingcomputer.com/news/security/t-mobile-discloses-data-breach-impacting-prepaid-customers/" target="_blank" rel="external nofollow">exposed the account information</a> of an undisclosed number of prepaid customers.
	</li>
	<li>
		In March 2020, T-Mobile employees were affected by a data breach <a href="https://www.bleepingcomputer.com/news/security/t-mobile-data-breach-exposes-customer-personal-financial-info/" target="_blank" rel="external nofollow">exposing their personal and financial information</a>.
	</li>
	<li>
		In December 2020, threat actors accessed <a href="https://www.bleepingcomputer.com/news/security/t-mobile-data-breach-exposed-phone-numbers-call-records/" target="_blank" rel="external nofollow">customer proprietary network information (phone numbers, call records)</a>.
	</li>
	<li>
		In February 2021, <a href="https://www.bleepingcomputer.com/news/security/t-mobile-discloses-data-breach-after-sim-swapping-attacks/" target="_blank" rel="external nofollow">an internal T-Mobile application</a> was accessed by unknown attackers without authorization.
	</li>
	<li>
		In August 2021, hackers <a href="https://www.bleepingcomputer.com/news/security/t-mobile-ceo-hacker-brute-forced-his-way-through-our-network/" target="_blank" rel="external nofollow">brute-forced their way through the carrier's network</a> following a <a href="https://www.bleepingcomputer.com/news/security/t-mobile-confirms-servers-were-hacked-investigates-data-breach/" target="_blank" rel="external nofollow">breach of a T-Mobile testing environment</a>.
	</li>
	<li>
		In April 2022, the Lapsus$ extortion gang <a href="https://www.bleepingcomputer.com/news/security/t-mobile-confirms-lapsus-hackers-breached-internal-systems/" target="_blank" rel="external nofollow">breached T-Mobile's network</a> using stolen credentials.
	</li>
	<li>
		In January 2023, T-Mobile confirmed attackers <a href="https://www.bleepingcomputer.com/news/security/t-mobile-hacked-to-steal-data-of-37-million-accounts-in-api-data-breach/" target="_blank" rel="external nofollow">stole the personal information of 37 million customers</a> by abusing a vulnerable Application Programming Interface (API) in November 2022.
	</li>
	<li>
		In May 2023, T-Mobile <a href="https://www.bleepingcomputer.com/news/security/t-mobile-discloses-second-data-breach-since-the-start-of-2023/" target="_blank" rel="external nofollow">disclosed a breach</a> impacting only 836 customers, but that exposed sensitive information.
	</li>
</ul>

<p>
	 
</p>

<p>
	<em>Update 11/16/24: Added statement from T-Mobile.</em>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/t-mobile-confirms-it-was-hacked-in-recent-wave-of-telecom-breaches/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26571</guid><pubDate>Sun, 17 Nov 2024 01:58:12 +0000</pubDate></item><item><title>Frustrated by phone scammers? Let AI-generated grandma 'Daisy' handle them</title><link>https://nsaneforums.com/news/security-privacy-news/frustrated-by-phone-scammers-let-ai-generated-grandma-daisy-handle-them-r26558/</link><description><![CDATA[<p>
	Phone scammers should now be worried as 'Daisy,' an AI-generated granny, is here to the rescue. Scammers have evolved, and some now even use artificial intelligence to con their victims by impersonating others. Since scammers use AI to lure victims into traps, the UK network provider has come up with an AI-based defense mechanism.
</p>

<p>
	 
</p>

<p>
	Developed by Virgin Media O2, 'Daisy' is an AI-generated tool that has the voice of a grandmother. Its purpose is to engage fraudsters in conversation, wasting their time as much as possible. O2 <a href="https://news.virginmediao2.co.uk/o2-unveils-daisy-the-ai-granny-wasting-scammers-time/" rel="external nofollow">notes</a>,
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		O2 has today unveiled the newest member of its fraud prevention team, ‘Daisy’. As ‘Head of Scammer Relations’, this state-of-the-art AI Granny’s mission is to talk with fraudsters and waste as much of their time as possible with human-like rambling chat to keep them away from real people, while highlighting the need for consumers to stay vigilant as the UK faces a fraud epidemic.
	</p>
</blockquote>

<p>
	Daisy can keep talking to a scammer for up to 40 minutes at a time. It keeps the scammers engaged by talking about her passion for knitting and providing fraudsters with fake details such as fabricated bank details, addresses, etc.
</p>

<p>
	 
</p>

<div class="ipsEmbeddedVideo" contenteditable="false">
	<div>
		<iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen="" frameborder="0" height="113" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube-nocookie.com/embed/RV_SdCfZ-0s?feature=oembed" title="AI Scambaiters: O2 creates AI Granny to waste scammers’ time" width="200"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	The AI-generated tool is developed using a custom-trained large language model with the help of one of YouTube's best scam baiters, <a href="https://www.youtube.com/JimBrowning" rel="external nofollow">Jim Browning</a>. Daisy is trained to respond to any questions from the scammers without needing any input from her creators. It listens to the caller, transcribes the text, sends it to LLM, and sends the generated response using text-to-speech.
</p>

<p>
	 
</p>

<p>
	Murray Mackenzie, Director of Fraud at Virgin Media O2, said, "We’re committed to playing our part in stopping the scammers, investing in everything from firewall technology to block out scam texts to AI-powered spam call detection to keep our customers safe." He further recommended that anyone in the UK worried about fraud can forward any call or messages they suspect from being a scammer to 7726 for free so that it can be investigated.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/frustrated-by-phone-scammers-let-ai-generated-grandma-daisy-handle-them/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26558</guid><pubDate>Fri, 15 Nov 2024 18:45:29 +0000</pubDate></item><item><title>New Glove infostealer malware bypasses Chrome&#x2019;s cookie encryption</title><link>https://nsaneforums.com/news/security-privacy-news/new-glove-infostealer-malware-bypasses-chrome%E2%80%99s-cookie-encryption-r26549/</link><description><![CDATA[<p>
	New Glove Stealer malware can bypass Google Chrome's Application-Bound (App-Bound) encryption to steal browser cookies.
</p>

<p>
	 
</p>

<p>
	As Gen Digital security researchers who first spotted it while investigating a recent phishing campaign said, this information-stealing malware is "relatively simple and contains minimal obfuscation or protection mechanisms," indicating that it's very likely in its early development stages.
</p>

<p>
	 
</p>

<p>
	During their attacks, the threat actors used social engineering tactics similar to those used in the <a href="https://www.bleepingcomputer.com/news/security/fake-google-chrome-errors-trick-you-into-running-malicious-powershell-scripts/" target="_blank" rel="external nofollow">ClickFix infection chain</a>, where potential victims get tricked into installing malware using fake error windows displayed within HTML files attached to the phishing emails.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="ClickFix attachment sample" class="ipsImage" height="312" width="720" src="https://www.bleepstatic.com/images/news/u/1109292/2024/clickfix_attachment_sample.webp">
		<figcaption>
			<em>ClickFix HTML attachment sample (Gen Digital)</em>
		</figcaption>
	</figure>
</div>

<p>
	The Glove Stealer .NET malware can extract and exfiltrate cookies from Firefox and Chromium-based browsers (e.g., Chrome, Edge, Brave, Yandex, Opera).
</p>

<p>
	 
</p>

<p>
	It's also capable of stealing cryptocurrency wallets from browser extensions, 2FA session tokens from Google, Microsoft, Aegis, and LastPass authenticator apps, password data from Bitwarden, LastPass, and KeePass, as well as emails from mail clients like Thunderbird.
</p>

<p>
	 
</p>

<p>
	"Other than stealing private data from browsers, it also tries to exfiltrate sensitive information from a list of 280 browser extensions and more than 80 locally installed applications," <a href="https://www.gendigital.com/blog/news/innovation/glove-stealer" rel="external nofollow" target="_blank">said malware researcher Jan Rubín</a>.
</p>

<p>
	 
</p>

<p>
	"These extensions and applications typically involve cryptocurrency wallets, 2FA authenticators, password managers, email clients and others."
</p>

<h2>
	Basic App-Bound encryption bypass capabilities
</h2>

<p>
	<span style="box-sizing:border-box; margin:0px; padding:0px">To steal credentials from Chromium web browsers, Glove Stealer bypasses Google's App-Bound encryption cookie-theft defenses, which were <a href="https://www.bleepingcomputer.com/news/security/google-chrome-adds-app-bound-encryption-to-block-infostealer-malware/" target="_blank" rel="external nofollow">introduced by Chrome 127</a> in July.</span>
</p>

<p>
	 
</p>

<p>
	To do that, it follows <a href="https://www.bleepingcomputer.com/news/security/new-tool-bypasses-google-chromes-new-cookie-encryption-system/" target="_blank" rel="external nofollow">the method</a> described by <a href="https://x.com/xaitax/status/1850500705074700298" rel="external nofollow" target="_blank">security researcher Alexander Hagenah</a> last month, using a supporting module that uses Chrome's own COM-based IElevator Windows service (running with SYSTEM privileges) to decrypt and retrieve App-Bound encrypted keys.
</p>

<p>
	 
</p>

<p>
	It's important to note that the malware first needs to get local admin privileges on the compromised systems to place this module in Google Chrome's Program Files directory and use it to retrieve encrypted keys.
</p>

<p>
	 
</p>

<p>
	However, although impressive on paper, this still points to Glove Stealer being in early development since it's a basic method that most other info stealers have already surpassed to steal cookies from all Google Chrome versions, as researcher <a href="https://x.com/g0njxa" rel="external nofollow" target="_blank">g0njxa</a> told BleepingComputer in October.
</p>

<p>
	 
</p>

<p>
	Malware analyst <a data-sk="tooltip_parent" data-stringify-link="https://x.com/RussianPanda9xx" delay="150" href="https://x.com/RussianPanda9xx" rel="external nofollow" target="_blank">Russian Panda</a> previously said to BleepingComputer that Hagenah's method looks similar to early bypass approaches other malware took after Google first implemented Chrome App-Bound encryption.
</p>

<p>
	 
</p>

<p>
	Multiple infostealer malware operations are now capable of bypassing <a href="https://www.bleepingcomputer.com/news/security/infostealer-malware-bypasses-chromes-new-cookie-theft-defenses/" target="_blank" rel="external nofollow">the new security feature</a> to allow their "customers" to steal and decrypt Google Chrome cookies.
</p>

<p>
	 
</p>

<p>
	"This code [xaitax's] requires admin privileges, which shows that we've successfully elevated the amount of access required to successfully pull off this type of attack," Google told BleepingComputer last month.
</p>

<p>
	 
</p>

<p>
	Unfortunately, even though admin privileges are required to bypass App-Bound encryption, this has yet to put a noticeable dent in the number of ongoing information-stealing malware campaigns.
</p>

<p>
	 
</p>

<p>
	<span style="box-sizing:border-box; margin:0px; padding:0px">Attacks have only increased since July when Google first implemented App-Bound encryption, targeting potential victims via <a href="https://www.bleepingcomputer.com/news/security/new-steelfox-malware-hijacks-windows-pcs-using-vulnerable-driver/" target="_blank" rel="external nofollow">vulnerable drivers</a>, <a href="https://www.bleepingcomputer.com/news/security/cisa-warns-of-windows-flaw-used-in-infostealer-malware-attacks/" target="_blank" rel="external nofollow">zero-day vulnerabilities</a>, <a href="https://www.bleepingcomputer.com/news/security/global-infostealer-malware-operation-targets-crypto-users-gamers/" target="_blank" rel="external nofollow">malvertising, spearphishing</a>, <a href="https://www.bleepingcomputer.com/news/security/cybercriminals-pose-as-helpful-stack-overflow-users-to-push-malware/" target="_blank" rel="external nofollow">StackOverflow answers</a>, and <a href="https://www.bleepingcomputer.com/news/security/clever-github-scanner-campaign-abusing-repos-to-push-malware/" target="_blank" rel="external nofollow">fake fixes to GitHub issues</a>.</span>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/new-glove-infostealer-malware-bypasses-google-chromes-cookie-encryption/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26549</guid><pubDate>Fri, 15 Nov 2024 01:51:58 +0000</pubDate></item><item><title>DNA-testing firm vanishes with highly sensitive customer genetic data</title><link>https://nsaneforums.com/news/security-privacy-news/dna-testing-firm-vanishes-with-highly-sensitive-customer-genetic-data-r26547/</link><description><![CDATA[<p>
	<strong><em>In yet another blow to the DNA-testing industry, Atlas Biomed, a London-based genetic firm with links to Russia, has disappeared without any warning. The BBC reports that customers’ sensitive data extracted from biological samples is now in limbo.</em></strong>
</p>

<p>
	 
</p>

<p>
	“From ordering the kit, to receiving your results online, your personal data is kept protected during each stage,” Atlas Biomed claimed on the now-defunct website.
</p>

<p>
	 
</p>

<p>
	“User Data are securely stored on certified servers located within the European Union. SHA-256 with RSA Encryption. Full UK GDPR and EU GDPR compliance. Registered with the Information Commissioner's Office.”
</p>

<p>
	 
</p>

<p>
	The clients can no longer access their accounts or retrieve reports, and the firm itself appears to have ‘vanished.’
</p>

<p>
	 
</p>

<p>
	“I have a history of 16 tests I can't now access, hundreds of pounds invested, but the data wasn't downloadable, so relying on the website,” a Facebook user commented on the company’s post nine months ago.
</p>

<p>
	 
</p>

<p>
	Other customers reported paying for subscriptions or tests without receiving services. Soma labeled the company a scam. Atlas Biomed hasn’t posted anything on any of its social media accounts for more than a year now.
</p>

<p>
	 
</p>

<p>
	The BBC was the first to <a href="https://www.bbc.com/news/articles/cz7wl7rpndjo" rel="external nofollow" target="_blank">report</a> the mystery surrounding the DNA-testing firm. The company has not responded to the BBC’s request for comment, but the Information Commissioner’s Office has received complaints about it. The firm’s financial accounts are now overdue, but it is still listed as active with the UK’s Companies House.
</p>

<p>
	 
</p>

<p>
	Cybernews attempted to reach out to the CEO, Sergei Musienko, to no avail.
</p>

<h2 class="content__heading " id="the-most-sensitive-information-in-limbo">
	The most sensitive information in limbo
</h2>

<p>
	The firm’s clients now have no clue what happened to their personal information.
</p>

<p>
	 
</p>

<p>
	Atlas Biomed collected a vast trove of sensitive data, including phone numbers, emails, addresses, cookies and website usage, health and lifestyle information, and biological samples. It also derived genetic data and interpretation results.
</p>

<p>
	 
</p>

<p>
	“These include health, nutrition, sports, ancestry, and personal traits data which are derived from interpretation of your health and lifestyle information and raw data and which we display to you in your personal account,” the privacy policy reads.
</p>

<p>
	 
</p>

<p>
	Malwarebytes Labs <a href="https://www.malwarebytes.com/blog/news/2024/11/dna-testing-company-vanishes-along-with-its-customers-genetic-data" rel="external nofollow" target="_blank">found</a> no evidence that any of the data has been misused but noted that “it is worrying to not know who now has access to the data, especially now that the investigation shows that there might be ties to Russia.”
</p>

<p>
	 
</p>

<p>
	Four out of eight company officers have resigned, and the two remaining are listed at the same address in Moscow. The address is linked to a Russian billionaire who previously resigned as director.
</p>

<p>
	 
</p>

<p>
	“DNA testing has become so commonplace that many people have blindly participated without truly understanding the implications. It has always been a problem to figure out who you could trust with your genetic data. For some people, it’s their cheapest chance of finding out whether they are affected by some genetic disorder,” Malwarebytes Labs said.
</p>

<p>
	 
</p>

<p>
	This mystery adds to the uncertainty surrounding genetic data security. In 2018, an incident at MyHeritage exposed 92 million users’ emails and hashed passwords. In 2020, the investment firm Blackstone's acquisition of Ancestry raised concerns about the potential commercialization and data transfers.
</p>

<p>
	 
</p>

<p>
	Last year started the ongoing saga surrounding 23andMe, which experienced a data <a href="https://cybernews.com/privacy/dna-testing-service-23andme-investigates-leak-claims/" rel="external nofollow">breach</a> affecting about 6.9 million users. This week, 23andMe <a href="https://cybernews.com/news/23andme-announces-major-layoffs/" rel="external nofollow">announced</a> major layoffs and financial struggles.
</p>

<p>
	 
</p>

<p>
	The security firm recommends researching the genetic companies you want to trust with your most sensitive data before submitting biological samples. Lying is also an option.
</p>

<p>
	 
</p>

<p>
	“Only share the personal information you absolutely have to provide with the genetic testing company. Lie if you must and create a separate free email account so the information can’t be tied to your main account,” Malwarebytes said.
</p>

<p>
	 
</p>

<p>
	There are worries that DNA testing, while offering valuable personal discoveries, also creates permanent digital records that can be misused for insurance discrimination, targeted marketing, such as Alzheimer’s or cancer preventative nutrition, racial profiling by police officers or employers, identity theft, and others.
</p>

<p>
	 
</p>

<p>
	<a href="https://cybernews.com/security/dna-testing-firm-vanishes-with-highly-sensitive-data/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26547</guid><pubDate>Thu, 14 Nov 2024 20:27:35 +0000</pubDate></item><item><title>Threads may start displaying ads as early as January 2025</title><link>https://nsaneforums.com/news/security-privacy-news/threads-may-start-displaying-ads-as-early-as-january-2025-r26543/</link><description><![CDATA[<p>
	Meta introduced Threads as an alternative to the micro-blogging site Twitter, now called "X" after <a href="https://www.neowin.net/news/elon-musk-officially-takes-over-twitter-sacks-ceo-parag-agrawal-and-cfo-ned-segal/" rel="external nofollow">Elon Musk's takeover</a>. Ads are the backbone and also a major revenue source for social media platforms, and it appears that Threads will soon join the bandwagon. According to a report by <a href="https://www.theinformation.com/articles/meta-to-launch-ads-on-threads-in-early-2025" rel="external nofollow">The Information</a>, ads will start appearing on Threads from next year.
</p>

<p>
	 
</p>

<p>
	Threads is one of the alternatives to X, but the platform hasn't been able to gain as much limelight as X. It is expected that the upcoming change could shift the vibe a bit. There are plenty of companies that use Threads to promote their businesses. However, one thing that is still missing from Threads is sponsored content, a staple on X and other platforms.
</p>

<p>
	 
</p>

<p>
	Reportedly, Threads is expected to start showing ads as soon as January 2025, though with a different approach. Initially, Threads will work with a limited group of advertisers and, based on that experience, will tailor its approach to broaden its advertiser base.
</p>

<p>
	 
</p>

<p>
	Back in October, Instagram head <a href="https://www.threads.net/@mosseri/post/C5erGYZPShe" rel="external nofollow">Adam Mosseri</a>, also confirmed that Meta is planning to bring ads to Threads. He said, "I get why people have concerns, but at the end of the day we're a business and Threads needs to make enough money to pay for the people and servers that it takes to run the service and provide it to people for free."
</p>

<p>
	 
</p>

<p>
	The introduction of ads on Threads will require a bit of adjusting for regular users, but it shouldn't be a big concern, because other social media platforms have included ads for years. Meta's other properties, such as Facebook and Instagram, are no strangers to ads, and the company may want to bring Threads to the same dais.
</p>

<p>
	 
</p>

<p>
	For now, you can enjoy Threads without ads. But do share your thoughts are ads simply ruining the communication experience or are they a part of the modern social media landscape?
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/threads-may-start-displaying-ads-as-early-as-january-2025/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26543</guid><pubDate>Thu, 14 Nov 2024 17:59:35 +0000</pubDate></item><item><title>New ShrinkLocker ransomware decryptor recovers BitLocker password</title><link>https://nsaneforums.com/news/security-privacy-news/new-shrinklocker-ransomware-decryptor-recovers-bitlocker-password-r26521/</link><description><![CDATA[<p>
	Bitdefender has released a decryptor for the 'ShrinkLocker' ransomware strain, which uses Windows' built-in BitLocker drive encryption tool to lock victim's files.
</p>

<p>
	 
</p>

<p>
	Discovered in May 2024 by researchers at cybersecurity company Kaspersky, <a href="https://www.bleepingcomputer.com/news/security/new-shrinklocker-ransomware-uses-bitlocker-to-encrypt-your-files/" target="_blank" rel="external nofollow">ShrinkLocker</a> lacks the sophistication of other ransomware families but integrates features that can maximize the damage of an attack.
</p>

<p>
	 
</p>

<p>
	According to Bitdefender's analysis, the malware appears to have been repurposed from benign ten-year-old code, using VBScript, and leverages generally outdated techniques.
</p>

<p>
	 
</p>

<p>
	The researchers note that ShrinkLocker's operators seem to be low-skilled, using redundant code and typos, leaving behind reconnaissance logs in the form of text files, and rely on readily available tools.
</p>

<p>
	 
</p>

<p>
	However, the threat actor has had successful attacks on corporate targets.
</p>

<p>
	 
</p>

<p>
	In a report today, Bitdefender highlights a ShrinkLocker attack against a healthcare organization where attackers encrypted Windows 10, Windows 11, and Windows Server devices across the network, including backups.
</p>

<p>
	 
</p>

<p>
	The encryption process finished in 2.5 hours and the organization lost access to critical systems, potentially facing difficulties in providing patient care.
</p>

<p>
	 
</p>

<p>
	Bitdefender is releasing a free decryption tool that can help ShrinkLocker victims recover their files.
</p>

<h2>
	ShrinkLocker attacks
</h2>

<p>
	Instead of using custom encryption implementations like traditional ransomware, ShrinkLocker uses Windows BitLocker with a randomly generated password that is sent to the attacker.
</p>

<p>
	 
</p>

<p>
	The malware first runs a Windows Management Instrumentation (WMI) query to checks if BitLocker is available on the target system, and installs the tool if not present.
</p>

<p>
	 
</p>

<p>
	Next, it removes all default protections that keep the drive from being encrypted by accident. For speed, it uses the '-UsedSpaceOnly' flag to have BitLocker only encrypt occupied space on the disk.
</p>

<p>
	 
</p>

<p>
	The random password is generated using network traffic and memory usage data, so there are no patterns to make brute-forcing feasible.
</p>

<p>
	 
</p>

<p>
	The ShrinkLocker script will also delete and reconfigure all BitLocker protectors, to make more difficult the recovery of the encryption keys.
</p>

<p>
	 
</p>

<p>
	"Protectors are mechanisms used by BitLocker to protect the encryption key. They can include hardware protectors like TPMs or software protectors like passwords or recovery keys. By deleting all protectors, the script aims to make it impossible for the victim to recover their data or decrypt the drive," Bitdefender explains.
</p>

<p>
	 
</p>

<p>
	For propagation, ShrinkLocker uses Group Policy Objects (GPOs) and scheduled tasks, modifies Group Policy settings on Active Directory domain controllers, and creates tasks for all domain-joined machines to ensure the encryption of all drives on the compromised network.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="The ShrinkLocker attack chain" class="ipsImage" height="317" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2024/Ransomware/31/attack-chain.jpg">
		<figcaption>
			<em>The ShrinkLocker attack chain<br>
			Source: Bitdefender</em>
		</figcaption>
	</figure>
</div>

<p>
	After reboot, victims see a BitLocker password screen that also includes the threat actor's contact details.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="BitLocker screen served to the victim" class="ipsImage" height="345" width="657" src="https://www.bleepstatic.com/images/news/u/1220909/2024/Ransomware/31/bitlocker-screen.jpg">
		<figcaption>
			<em>BitLocker screen served to the victim<br>
			Source: Bitdefender</em>
		</figcaption>
	</figure>
</div>

<h2>
	Bitdefender releases decryptor
</h2>

<p>
	Bitdefender created and <a href="http://download.bitdefender.com/am/malware_removal/BDShrinkLockerUnlocker.exe" rel="external nofollow" target="_blank">released a decryptor</a> that reverses the sequence in which ShrinkLocker deletes and reconfigures BitLocker's protectors.
</p>

<p>
	 
</p>

<p>
	The researchers say that they identified "a specific window of opportunity for data recovery immediately after the removal of protectors from BitLocker-encrypted disks," which allows them to decrypt and recover the password set by the attacker.
</p>

<p>
	 
</p>

<p>
	This makes it possible to reverse the encryption process and bring the drives back to their previous, unencrypted state.
</p>

<p>
	 
</p>

<p>
	ShrinkLocker victims can download the tool and use it from a USB drive connected to the impacted systems. When the BitLocker recovery screen shows, users should enter BitLocker Recovery Mode and skip all the steps to get to Advanced options, which provides a command prompt that allows launching the decryption tool.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="BitLocker password recovery screen" class="ipsImage" height="334" style="height: auto;" width="800" src="https://www.bleepstatic.com/images/news/u/1100723/2024/BitLocker_pass-rec_ShrinkLocker.png">
		<figcaption>
			<em>Decryptor successfully recovers ShrinkLocker's BitLocker password<br>
			Source: Bitdefender</em>
		</figcaption>
	</figure>
</div>

<p>
	The researchers warn that the time to decrypt the data depends on the system's hardware and the complexity of the encryption and could take some time.
</p>

<p>
	 
</p>

<p>
	When done, the decryptor will unlock the drive and disable smart card-based authentication.
</p>

<p>
	 
</p>

<p>
	Bitdefender notes that the decryptor only works on Windows 10, Windows 11, and recent Windows Server versions and is most effective when used shortly after the ransomware attack, when BitLocker's configurations are not fully overridden yet and can be recovered.
</p>

<p>
	 
</p>

<p>
	Unfortunately, this method will not work to recover BitLocker passwords created using other methods.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/new-shrinklocker-ransomware-decryptor-recovers-bitlocker-password/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26521</guid><pubDate>Wed, 13 Nov 2024 18:46:47 +0000</pubDate></item><item><title>D-Link won&#x2019;t fix critical bug in 60,000 exposed EoL modems</title><link>https://nsaneforums.com/news/security-privacy-news/d-link-won%E2%80%99t-fix-critical-bug-in-60000-exposed-eol-modems-r26512/</link><description><![CDATA[<p>
	Tens of thousands of exposed D-Link routers that have reached their end-of-life are vulnerable to a critical security issue that allows an unauthenticated remote attacker to change any user's password and take complete control of the device.
</p>

<p>
	 
</p>

<p>
	The vulnerability was discovered in the D-Link DSL6740C modem by security researcher Chaio-Lin Yu (Steven Meow), who reported it to Taiwan’s computer and response center (TWCERTCC).
</p>

<p>
	 
</p>

<p>
	It is worth noting that the device was not available in the U.S. and reached end-of-service (EoS) phase at the beginning of the year.
</p>

<p>
	 
</p>

<p>
	In an <a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10414" rel="external nofollow" target="_blank">advisory</a> today, D-Link announced that it won't fix the issue and recommends "retiring and replacing D-Link devices that have reached EOL/EOS."
</p>

<p>
	 
</p>

<p>
	Chaio-Lin Yu reported to TWCERTCC two other vulnerabilities, an OS command injection and a path traversal issue:
</p>

<p>
	 
</p>

<p>
	The three flaws issues are summarized as follows:
</p>

<p>
	 
</p>

<ul>
	<li>
		<a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11068" rel="external nofollow" target="_blank"><strong>CVE-2024-11068</strong></a>: Flaw that allows unauthenticated attackers to modify any user’s password through privileged API access, granting them access to the modem’s Web, SSH, and Telnet services. (CVSS v3 score: 9.8 “critical”).
	</li>
	<li>
		<a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11067" rel="external nofollow" target="_blank"><strong>CVE-2024-11067</strong></a>: Path traversal vulnerability allowing unauthenticated attackers to read arbitrary system files, retrieve the device’s MAC address, and attempt login using the default credentials. (CVSS v3 score: 7.5 “high”)
	</li>
	<li>
		<a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11066" rel="external nofollow" target="_blank"><strong>CVE-2024-11066</strong></a>: Bug enabling attackers with admin privileges to execute arbitrary commands on the host operating system through a specific web page. (CVSS v3 score: 7.2 “high”)
	</li>
</ul>

<p>
	 
</p>

<p>
	A quick search on the FOFA search engine for publicly exposed devices and software shows that there are close to 60,000 D-Link DSL6740C modems reachable over the internet, most of them in Taiwan.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="FOFA scan results" class="ipsImage" height="385" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2024/Phishing/24/Fofa-BC.png">
		<figcaption>
			<em>FOFA scan results<br>
			Source: BleepingComputer</em>
		</figcaption>
	</figure>
</div>

<p>
	TWCERTCC has published advisories for four more high-severity OS command injection vulnerabilities that impact the same D-Link device. The bugs are tracked as <a href="https://www.twcert.org.tw/tw/cp-132-8221-601c3-1.html" rel="external nofollow" target="_blank">CVE-2024-11062</a>, <a href="https://www.twcert.org.tw/tw/cp-132-8222-eb5bb-1.html" rel="external nofollow" target="_blank">CVE-2024-11063</a>, <a href="https://www.twcert.org.tw/tw/cp-132-8223-f6da0-1.html" rel="external nofollow" target="_blank">CVE-2024-11064</a>, and <a href="https://www.twcert.org.tw/tw/cp-132-8224-d939e-1.html" rel="external nofollow" target="_blank">CVE-2024-11065</a>.
</p>

<p>
	 
</p>

<p>
	Although the number of vulnerable devices exposed on the public web is significant, D-Link has made it clear in the past [<a href="https://www.bleepingcomputer.com/news/security/d-link-wont-fix-critical-flaw-affecting-60-000-older-nas-devices/" target="_blank" rel="external nofollow">1</a>, <a href="https://www.bleepingcomputer.com/news/security/over-92-000-exposed-d-link-nas-devices-have-a-backdoor-account/" target="_blank" rel="external nofollow">2</a>] that end-of-life (EoL) devices are not covered by updates, even when critical bugs are concerned.
</p>

<p>
	 
</p>

<p>
	If users can't replace the affected device with a variant that the vendor still supports, they should at least restrict remote access and set secure access passwords.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/d-link-wont-fix-critical-bug-in-60-000-exposed-eol-modems/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26512</guid><pubDate>Tue, 12 Nov 2024 22:22:17 +0000</pubDate></item><item><title>FBI, CISA, and NSA reveal most exploited vulnerabilities of 2023</title><link>https://nsaneforums.com/news/security-privacy-news/fbi-cisa-and-nsa-reveal-most-exploited-vulnerabilities-of-2023-r26498/</link><description><![CDATA[<p>
	The FBI, the NSA, and cybersecurity authorities of the Five Eyes intelligence alliance have released today a list of the top 15 routinely exploited vulnerabilities throughout last year.
</p>

<p>
	 
</p>

<p>
	A joint advisory published on Tuesday calls for organizations worldwide to immediately patch these security flaws and deploy patch management systems to minimize their networks' exposure to potential attacks.
</p>

<p>
	 
</p>

<p>
	"In 2023, malicious cyber actors exploited more zero-day vulnerabilities to compromise enterprise networks compared to 2022, allowing them to conduct cyber operations against higher-priority targets," <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a" rel="external nofollow" target="_blank">the cybersecurity agencies warned</a>.
</p>

<p>
	 
</p>

<p>
	"In 2023, the majority of the most frequently exploited vulnerabilities were initially exploited as a zero-day, which is an increase from 2022, when less than half of the top exploited vulnerabilities were exploited as a zero-day."
</p>

<p>
	 
</p>

<p>
	As they also revealed, 12 out of the top 15 vulnerabilities routinely abused in the wild were addressed last year, lining up with the agencies warning that threat actors focused their attacks on zero-days (security flaws that have been disclosed but are yet to be patched).
</p>

<p>
	 
</p>

<p>
	Here is the complete list of last year's most exploited vulnerabilities and relevant links to the National Vulnerability Database entries.
</p>

<p>
	 
</p>

<table border="1px solid black;">
	<tbody>
		<tr>
			<td>
				<strong>CVE</strong>
			</td>
			<td>
				<strong>Vendor</strong>
			</td>
			<td>
				<strong>Product</strong>
			</td>
			<td>
				<strong>Type</strong>
			</td>
		</tr>
		<tr>
			<td>
				<a data-extlink="" href="https://www.cve.org/CVERecord?id=CVE-2023-3519" rel="external nofollow" title="CVE-2023-3519 - Critical (opens in a new window)">CVE-2023-3519</a>
			</td>
			<td>
				Citrix
			</td>
			<td>
				NetScaler ADC/Gateway
			</td>
			<td>
				Code Injection
			</td>
		</tr>
		<tr>
			<td>
				<a data-extlink="" href="https://www.cve.org/CVERecord?id=CVE-2023-4966" rel="external nofollow" title="CVE-2023-4966 - Critical (opens in a new window)">CVE-2023-4966</a>
			</td>
			<td>
				Citrix
			</td>
			<td>
				NetScaler ADC/Gateway
			</td>
			<td>
				Buffer Overflow
			</td>
		</tr>
		<tr>
			<td>
				<a data-extlink="" href="https://www.cve.org/CVERecord?id=CVE-2023-20198" rel="external nofollow" title="CVE-2023-20198 - Critical (opens in a new window)">CVE-2023-20198</a>
			</td>
			<td>
				Cisco
			</td>
			<td>
				IOS XE Web UI
			</td>
			<td>
				Privilege Escalation
			</td>
		</tr>
		<tr>
			<td>
				<a data-extlink="" href="https://www.cve.org/CVERecord?id=CVE-2023-20273" rel="external nofollow" title="CVE-2023-20273 - High (opens in a new window)">CVE-2023-20273</a>
			</td>
			<td>
				Cisco
			</td>
			<td>
				IOS XE
			</td>
			<td>
				Web UI Command Injection
			</td>
		</tr>
		<tr>
			<td>
				<a data-extlink="" href="https://www.cve.org/CVERecord?id=CVE-2023-27997" rel="external nofollow" title="CVE-2023-27997 - Critical (opens in a new window)">CVE-2023-27997</a>
			</td>
			<td>
				Fortinet
			</td>
			<td>
				FortiOS and iPadOS/FortiProxy SSL-VPN
			</td>
			<td>
				Heap-Based Buffer Overflow
			</td>
		</tr>
		<tr>
			<td>
				<a data-extlink="" href="https://www.cve.org/CVERecord?id=CVE-2023-34362" rel="external nofollow" title="CVE-2023-34362 - Critical (opens in a new window)">CVE-2023-34362</a>
			</td>
			<td>
				Progress
			</td>
			<td>
				MOVEit Transfer
			</td>
			<td>
				SQL Injection
			</td>
		</tr>
		<tr>
			<td>
				<a data-extlink="" href="https://www.cve.org/CVERecord?id=CVE-2023-22515" rel="external nofollow" title="CVE-2023-22515 - Critical (opens in a new window)">CVE-2023-22515</a>
			</td>
			<td>
				Atlassian
			</td>
			<td>
				Confluence Data Center/Server
			</td>
			<td>
				Broken Access Control
			</td>
		</tr>
		<tr>
			<td>
				<a data-extlink="" href="https://www.cve.org/CVERecord?id=CVE-2021-44228" rel="external nofollow" title="CVE-2021-44228 - Critical (opens in a new window)">CVE-2021- 44228</a> (Log4Shell)
			</td>
			<td>
				Apache
			</td>
			<td>
				Log4j2
			</td>
			<td>
				Remote Code Execution
			</td>
		</tr>
		<tr>
			<td>
				<a data-extlink="" href="https://www.cve.org/CVERecord?id=CVE-2023-2868" rel="external nofollow" title="CVE-2023-2868 - Critical (opens in a new window)">CVE-2023-2868</a>
			</td>
			<td>
				Barracuda Networks
			</td>
			<td>
				ESG Appliance
			</td>
			<td>
				Improper Input Validation
			</td>
		</tr>
		<tr>
			<td>
				<a data-extlink="" href="https://www.cve.org/CVERecord?id=CVE-2022-47966" rel="external nofollow" title="CVE-2022-47966 - Critical (opens in a new window)">CVE-2022-47966</a>
			</td>
			<td>
				Zoho
			</td>
			<td>
				ManageEngine Multiple Products
			</td>
			<td>
				Remote Code Execution
			</td>
		</tr>
		<tr>
			<td>
				<a data-extlink="" href="https://www.cve.org/CVERecord?id=CVE-2023-27350" rel="external nofollow" title="CVE-2023-27350 - Critical (opens in a new window)">CVE-2023-27350</a>
			</td>
			<td>
				PaperCut
			</td>
			<td>
				MF/NG
			</td>
			<td>
				Improper Access Control
			</td>
		</tr>
		<tr>
			<td>
				<a data-extlink="" href="https://www.cve.org/CVERecord?id=CVE-2020-1472" rel="external nofollow" title="CVE-2020-1472 - Medium (opens in a new window)">CVE-2020-1472</a>
			</td>
			<td>
				Microsoft
			</td>
			<td>
				Netlogon
			</td>
			<td>
				Privilege Escalation
			</td>
		</tr>
		<tr>
			<td>
				<a data-extlink="" href="https://www.cve.org/CVERecord?id=CVE-2023-42793" rel="external nofollow" title="CVE-2023-42793 - Critical (opens in a new window)">CVE-2023-42793</a>
			</td>
			<td>
				JetBrains
			</td>
			<td>
				TeamCity
			</td>
			<td>
				Authentication Bypass
			</td>
		</tr>
		<tr>
			<td>
				<a data-extlink="" href="https://www.cve.org/CVERecord?id=CVE-2023-23397" rel="external nofollow" title="CVE-2023-23397 - Critical (opens in a new window)">CVE-2023-23397</a>
			</td>
			<td>
				Microsoft
			</td>
			<td>
				Office Outlook
			</td>
			<td>
				Privilege Escalation
			</td>
		</tr>
		<tr>
			<td>
				<a data-extlink="" href="https://www.cve.org/CVERecord?id=CVE-2023-49103" rel="external nofollow" title="CVE-2023-49103 - Critical (opens in a new window)">CVE-2023-49103</a>
			</td>
			<td>
				ownCloud
			</td>
			<td>
				graphapi
			</td>
			<td>
				Information Disclosure
			</td>
		</tr>
	</tbody>
</table>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/tag/cve-2023-3519/" target="_blank" rel="external nofollow">CVE-2023-3519</a>, a code injection vulnerability in NetScaler ADC / Gateway that enables attackers to gain remote code execution on unpatched servers, took the first spot after state hackers abused it to <a href="https://www.bleepingcomputer.com/news/security/netscaler-adc-bug-exploited-to-breach-us-critical-infrastructure-org/" target="_blank" rel="external nofollow">breach U.S. critical infrastructure organizations</a>.
</p>

<p>
	 
</p>

<p>
	By early August 2023, this security flaw had been leveraged to backdoor at least <a href="https://www.bleepingcomputer.com/news/security/over-640-citrix-servers-backdoored-with-web-shells-in-ongoing-attacks/" target="_blank" rel="external nofollow">640 Citrix servers</a> worldwide and over <a href="https://www.bleepingcomputer.com/news/security/almost-2-000-citrix-netscaler-servers-backdoored-in-hacking-campaign/" target="_blank" rel="external nofollow">2,000 by mid-August</a>.
</p>

<p>
	 
</p>

<p>
	Today's advisory highlights 32 other vulnerabilities often exploited last year to compromise organizations and provides information on how defenders can decrease their exposure to attacks abusing them in the wild.
</p>

<p>
	 
</p>

<p>
	This June, MITRE also unveiled the <a href="https://www.bleepingcomputer.com/news/security/mitre-releases-new-list-of-top-25-most-dangerous-software-bugs/" target="_blank" rel="external nofollow">25 most dangerous software weaknesses</a> for the previous two calendar years and, in November 2021, a list of the <a href="https://www.bleepingcomputer.com/news/security/mitre-shares-list-of-most-dangerous-hardware-weaknesses/" target="_blank" rel="external nofollow">most important hardware weaknesses</a>.
</p>

<p>
	 
</p>

<p>
	"All of these vulnerabilities are publicly known, but many are in the top 15 list for the first time," <a href="https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3961769/cisa-nsa-and-partners-issue-annual-report-on-top-exploited-vulnerabilities/" rel="external nofollow" target="_blank">said</a> Jeffrey Dickerson, NSA's cybersecurity technical director, on Tuesday.
</p>

<p>
	 
</p>

<p>
	"Network defenders should pay careful attention to trends and take immediate action to ensure vulnerabilities are patched and mitigated. Exploitation will likely continue in 2024 and 2025."
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/fbi-cisa-and-nsa-reveal-most-exploited-vulnerabilities-of-2023/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26498</guid><pubDate>Tue, 12 Nov 2024 18:02:42 +0000</pubDate></item><item><title>"Browser extensions are a blind spot for EDR/XDR, and SWGs have no way to infer their presence": Google Chrome's new Manifest V3 framework, touted as private and secure, might be a breeding ground for phishing scams</title><link>https://nsaneforums.com/news/security-privacy-news/browser-extensions-are-a-blind-spot-for-edrxdr-and-swgs-have-no-way-to-infer-their-presence-google-chromes-new-manifest-v3-framework-touted-as-private-and-secure-might-be-a-breeding-ground-for-phishing-scams-r26482/</link><description><![CDATA[<h3>
	Google Chrome's Manifest V3 framework poses a major security threat.
</h3>

<h2 id="what-you-need-to-know-3">
	What you need to know
</h2>

<ul>
	<li>
		Google recently transitioned Google Chrome's extension support from the Manifest V2 framework to V3.
	</li>
	<li>
		The company indicated the Manifest V3 framework provides better privacy and security for users.
	</li>
	<li>
		New research shows malicious browser extensions can bypass the new framework's security measures, leaving users susceptible to phishing scams.
	</li>
</ul>

<p>
	 
</p>

<hr>
<p>
	 
</p>

<p>
	Extensions are essential and provide an enhanced and seamless browsing experience for users. As you may know, Google <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/software-apps/browsing/google-pulls-the-plug-on-ublock-origin" href="https://www.windowscentral.com/software-apps/browsing/google-pulls-the-plug-on-ublock-origin" rel="external nofollow">transitioned Google Chrome's extension support</a> from the Manifest V2 framework to the Manifest V3 framework.
</p>

<p>
	 
</p>

<p>
	The drastic change impacted many browser extensions, including uBlock Origin, potentially <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/software-apps/browsing/google-warns-it-will-end-support-for-ublock-origin-soon" href="https://www.windowscentral.com/software-apps/browsing/google-warns-it-will-end-support-for-ublock-origin-soon" rel="external nofollow">leaving over 30 million Chrome users susceptible to intrusive ads</a>. Google attributed the drastic change to privacy and security concerns with the Manifest V2 framework. According to Google, the Manifest V2 framework "presents security risks by allowing unreviewed code to be executed in extensions."<strong> </strong>
</p>

<p>
	 
</p>

<p>
	Google touts Manifest V3 as a better and safer option since it only allows an extension to execute JavaScript as part of its package, ultimately mitigating the risk. However, new research by SquareX shows some browser extensions can still circumvent the Manifest V3 framework's security measures (via <a data-analytics-id="inline-link" data-hl-processed="none" data-url="https://www.techradar.com/pro/google-chrome-extensions-remain-a-security-risk-as-manifest-v3-fails-to-prevent-data-theft-and-malware-exploitation" href="https://www.techradar.com/pro/google-chrome-extensions-remain-a-security-risk-as-manifest-v3-fails-to-prevent-data-theft-and-malware-exploitation" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">TechRadar Pro</a>). The report further suggests that this loophole places users at risk, potentially giving bad actors access to personal and sensitive information.
</p>

<p>
	 
</p>

<p>
	According to the research team's findings, malicious browser extensions can bypass the Manifest V3 framework's security, granting them unauthorized access to live video streams, including Google Meet and Zoom Web. Google faced similar issues with the Manifest V2 framework, potentially influencing the transition to V3.
</p>

<p>
	 
</p>

<p>
	The malicious extensions reportedly allow bad actors to add unauthorized collaborators to private GitHub repositories. Even worse, they can be leveraged to lure unsuspecting users into phishing scams fronted as password managers. This way, the extensions access your browsing and download history, cookies, bookmarks, and more.
</p>

<p>
	 
</p>

<p>
	As you may know, security solutions like Secure Access Service Edge (SASE) or endpoint protection can't assess browser extensions, leaving users susceptible to security risks. However, the researchers have highlighted several solutions to mitigate these issues, including fine-tuning policies that allow admins to control extension access based on reviews, ratings, extension permissions, and update history.
</p>

<p>
	 
</p>

<p>
	According to SquareX Founder &amp; CEO Vivek Ramachandran:
</p>

<p>
	 
</p>

<div id="slice-container-newsletterForm-articleInbodyContent-HdBSJzSjsvLHLHDDVR4Sph">
	<div data-hydrate="true">
		<p class="QuoteNewsStyle">
			<em>“Browser extensions are a blind spot for EDR/XDR, and SWGs have no way to infer their presence. This has made browser extensions a very effective and potent technique to silently be installed and monitor enterprise users, and attackers are leveraging them to monitor communication over web calls, act on the victim’s behalf to give permissions to external parties, steal cookies and other site data and so on.”</em>
		</p>

		<p>
			SquareX claims the solution will block network requests by extensions in real time based on policies, machine learning insights, and heuristic analysis.
		</p>

		<p>
			 
		</p>

		<p>
			<a href="https://www.windowscentral.com/software-apps/browsing/browser-extensions-are-a-blind-spot-for-edr-xdr-and-swgs-have-no-way-to-infer-their-presence-google-chromes-new-manifest-v3-framework-touted-as-private-and-secure-might-be-a-breeding-ground-for-phishing-scams" rel="external nofollow">Source</a>
		</p>

		<hr class="ipsHr">
		<p>
			<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
		</p>

		<p>
			<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
		</p>

		<p>
			<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
		</p>

		<p>
			<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
		</p>
	</div>
</div>
]]></description><guid isPermaLink="false">26482</guid><pubDate>Mon, 11 Nov 2024 18:47:34 +0000</pubDate></item><item><title>D-Link won&#x2019;t fix critical flaw affecting 60,000 older NAS devices</title><link>https://nsaneforums.com/news/security-privacy-news/d-link-won%E2%80%99t-fix-critical-flaw-affecting-60000-older-nas-devices-r26449/</link><description><![CDATA[<p>
	More than 60,000 D-Link network-attached storage devices that have reached end-of-life are vulnerable to a command injection vulnerability with a publicly available exploit.
</p>

<p>
	 
</p>

<p>
	The flaw, tracked as <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10914" rel="external nofollow" target="_blank">CVE-2024-10914</a>, has a critical 9.2 severity score and is present in the ‘cgi_user_add’ command where the name parameter is insufficiently sanitized.
</p>

<p>
	 
</p>

<p>
	An unauthenticated attacker could exploit it to inject arbitrary shell commands by sending specially crafted HTTP GET requests to the devices.
</p>

<p>
	 
</p>

<p>
	The flaw impacts multiple models of D-Link network-attached storage (NAS) devices that are commonly used by small businesses:
</p>

<p>
	 
</p>

<ul>
	<li>
		DNS-320 Version 1.00
	</li>
	<li>
		DNS-320LW Version 1.01.0914.2012
	</li>
	<li>
		DNS-325 Version 1.01,  Version 1.02
	</li>
	<li>
		DNS-340L Version 1.08
	</li>
</ul>

<p>
	 
</p>

<p>
	In a technical write-up that provides exploit details, security researcher Netsecfish says that leveraging the vulnerability requires sending "a crafted HTTP GET request to the NAS device with malicious input in the name parameter.”
</p>

<p>
	 
</p>

<p>
	<code>curl "http://[Target-IP]/cgi-bin/account_mgr.cgi cmd=cgi_user_add&amp;name=%27;&lt;INJECTED_SHELL_COMMAND&gt;;%27" </code>
</p>

<p>
	 
</p>

<p>
	“This curl request constructs a URL that triggers the cgi_user_add command with a name parameter that includes an injected shell command,” the researcher explains.
</p>

<p>
	 
</p>

<p>
	A search that Netsecfish conducted on the FOFA platform returned 61,147 results at 41,097 unique IP addresses for D-Link devices vulnerable to CVE-2024-10914.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="FOFA scan results for exposed D-Link NAS devices" class="ipsImage" height="195" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2024/Crypto/12/FOFA.jpg">
		<figcaption>
			<em>FOFA scan results for exposed D-Link NAS devices<br>
			Source: Netsecfish</em>
		</figcaption>
	</figure>
</div>

<p>
	In a <a href="http://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10413" rel="external nofollow" target="_blank">security bulletin</a> today, D-Link has confirmed that a fix for CVE-2024-10914 is not coming and the vendor recommends that users retire vulnerable products.
</p>

<p>
	 
</p>

<p>
	If that is not possible at the moment, users should at least isolate them from the public internet or place them under stricter access conditions.
</p>

<p>
	 
</p>

<p>
	The same researcher discovered in April this year an arbitrary command injection and hardcoded backdoor flaw, tracked as CVE-2024-3273, impacting mostly the same D-Link NAS models as the latest flaw.
</p>

<p>
	 
</p>

<p>
	Back then, FOFA internet scans <a href="https://www.bleepingcomputer.com/news/security/over-92-000-exposed-d-link-nas-devices-have-a-backdoor-account/" target="_blank" rel="external nofollow">returned 92,589 results</a>.
</p>

<p>
	 
</p>

<p>
	Responding to the situation at the time, a D-Link spokesperson told BleepingComputer that the networking firm no longer makes NAS devices, and the impacted products had reached EoL and will not be receiving security updates.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/d-link-wont-fix-critical-flaw-affecting-60-000-older-nas-devices/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26449</guid><pubDate>Sat, 09 Nov 2024 04:28:09 +0000</pubDate></item><item><title>Microsoft releases free Windows Server 2025 security advice book for download</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-releases-free-windows-server-2025-security-advice-book-for-download-r26424/</link><description><![CDATA[<p>
	Earlier this month, Microsoft announced the <a href="https://www.neowin.net/news/microsoft-windows-server-2025-now-generally-available-alongside-system-center-2025/" rel="external nofollow">general availability</a> of Windows Server 2025. It introduces a suite of new and enhanced security features to deal with modern threats against on-premises, hybrid, and cloud environments. To accompany the launch, Microsoft has released the Windows Server 2025 Security Advice book for free.
</p>

<figure class="image image--expandable">
	<img alt="Image from Windows Server 2025 security book" class="ipsImage" height="405" width="720" src="https://cdn.neowin.com/news/images/uploaded/2024/11/1730960643_security-book.jpg">
</figure>

<p>
	The free book is designed for those responsible for Windows Server security in enterprise environments. It helps you get a better understanding of the protections now embedded in Windows Server. Best of all, the PDF document is just 19 pages long, so if you hate reading, it won't take long to get through it.
</p>

<p>
	 
</p>

<p>
	The book is split up into eight chapters and covers system hardening and baselines, credential protection and application control, silicon-assisted security innovations, operational security and continuous monitoring, workload security for virtual machines and containers, enhanced network security with micro-segregation, and advanced compliance and threat detection.
</p>

<p>
	 
</p>

<p>
	With increasing digitalization and heightened geopolitical tensions, <a href="https://www.imf.org/en/Blogs/Articles/2024/04/09/rising-cyber-threats-pose-serious-concerns-for-financial-stability" rel="external nofollow">the International Monetary Fund warns that cyberattacks has risen in recent years</a>. For this reasons, administrators of Windows Server 2025 need to be on their toes now more than ever and by reading this book from Microsoft they can be better prepared to fend off attacks.
</p>

<p>
	 
</p>

<p>
	The information packed into this book will benefit readers for the next decade with mainstream support ending in October 2029 and extended support lasting until October 2034, so it's definitely worth the time to read it if you're an administrator.
</p>

<p>
	 
</p>

<p>
	To get the new book, just head over to <a href="https://aka.ms/ws2025securitybook" rel="external nofollow">this link</a> to get the PDF.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/microsoft-releases-free-windows-server-2025-security-advice-book-for-download/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26424</guid><pubDate>Thu, 07 Nov 2024 09:06:41 +0000</pubDate></item><item><title>New SteelFox malware hijacks Windows PCs using vulnerable driver</title><link>https://nsaneforums.com/news/security-privacy-news/new-steelfox-malware-hijacks-windows-pcs-using-vulnerable-driver-r26418/</link><description><![CDATA[<p>
	A new malicious package called 'SteelFox' mines for cryptocurrency and steals credit card data by using the “bring your own vulnerable driver” technique to get SYSTEM privileges on Windows machines.
</p>

<p>
	 
</p>

<p>
	The malware bundle dropper is distributed through forums and torrent trackers as a crack tool that activates legitimate versions of various software like Foxit PDF Editor, JetBrains and AutoCAD.
</p>

<p>
	 
</p>

<p>
	Using a vulnerable driver for privilege escalation is common for <a href="https://www.bleepingcomputer.com/news/microsoft/windows-driver-zero-day-exploited-by-lazarus-hackers-to-install-rootkit/" target="_blank" rel="external nofollow">state-sponsored threat actors</a> and <a href="https://www.bleepingcomputer.com/news/security/ransomware-gang-deploys-new-malware-to-kill-security-software/" target="_blank" rel="external nofollow">ransomware groups</a>. However, the technique now appears to extend to info-stealing malware attacks.
</p>

<p>
	 
</p>

<p>
	Kaspersky researchers discovered the SteelFox campaign in August but say that the malware has been around since February 2023 and increased distribution lately using multiple channels (e.g. torrents, blogs, and posts on forums).
</p>

<p>
	 
</p>

<p>
	According to the company, its products detected and blocked SteelFox attacks 11,000 times.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="SteelFox's operational timeline" class="ipsImage" height="149" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2024/InfoStealers/06/timeline.jpg">
		<figcaption>
			<em>SteelFox's operational timeline<br>
			Source: Kaspersky</em>
		</figcaption>
	</figure>
</div>

<h2>
	SteelFox infection and privilege escalation
</h2>

<p>
	Kaspersky <a href="https://securelist.com/steelfox-trojan-drops-stealer-and-miner/114414/" rel="external nofollow" target="_blank">reports</a> that malicious posts promoting the SteelFox malware dropper come with complete instructions on how to illegally activate the software. Below is a sample of such a post providing directions on how to activate JetBrains:
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Instructions to victims" class="ipsImage" height="337" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2024/InfoStealers/06/instructions(1).jpg">
		<figcaption>
			<em>Instructions to victims<br>
			Source: Kaspersky</em>
		</figcaption>
	</figure>
</div>

<p>
	The researchers say that while the dropper does have the advertised functionality, users also infect their systems with malware.
</p>

<p>
	 
</p>

<p>
	Since the software targeted for illegal activation is typically installed in the Program Files, adding the crack requires administrator access, a permission that the malware uses later in the attack.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="The dropper application" class="ipsImage" height="192" style="height: auto;" width="677" src="https://www.bleepstatic.com/images/news/u/1220909/2024/InfoStealers/06/dropper.jpg">
		<figcaption>
			<em>The dropper application<br>
			Source: Kaspersky</em>
		</figcaption>
	</figure>
</div>

<p>
	Kaspersky researchers say that "the execution chain looks legitimate until the moment the files are unpacked." They explain that a malicious function is added during the process, which drops on the machine code that loads SteelFox.
</p>

<p>
	 
</p>

<p>
	Having secured admin rights, SteelFox creates a service that runs <em>WinRing0.sys</em> inside, a driver vulnerable to CVE-2020-14979 and CVE-2021-41285, which can be exploited to obtain privilege escalation to NT/SYSTEM level.
</p>

<p>
	 
</p>

<p>
	Such permissions are the highest on a local system, more powerful than an administrator's, and allow unrestricted access to any resource and process.
</p>

<p>
	 
</p>

<p>
	The WinRing0.sys driver is also used for cryptocurrency mining, as it is part of the XMRig program for mining Monero cryptocurrency. Kaspersky researchers say that the threat actor uses a modified version of the miner executable that connects to a mining pool with hardcoded credentials.
</p>

<p>
	 
</p>

<p>
	The malware then establishes a connection with its command-and-control (C2) server using SSL pinning and TLS v1.3, which protects the communication from being intercepted.
</p>

<p>
	 
</p>

<p>
	It also activates the info-stealer component that extracts data from 13 web browsers, information about the system, network, and RDP connection.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Data targeted by SteelFox" class="ipsImage" height="532" style="height: auto;" width="676" src="https://www.bleepstatic.com/images/news/u/1220909/2024/InfoStealers/06/datatheft.jpg">
		<figcaption>
			<em>Data targeted by SteelFox<br>
			Source: Kaspersky</em>
		</figcaption>
	</figure>
</div>

<p>
	The researchers note that SteelFox collects from the browsers data like credit cards, browsing history, and cookies.
</p>

<p>
	 
</p>

<p>
	Kaspersky says that although the C2 domain SteelFox uses is hardcoded, the threat actor manages to hide it by switching its IP addresses and resolving them through Google Public DNS and DNS over HTTPS (DoH).
</p>

<p>
	 
</p>

<p>
	SteelFox attacks do not have specific targets but appear to focus on users of AutoCAD, JetBrains, and Foxit PDF Editor. Based on Kaspersky's visibility, the malware compromises systems in Brazil, China, Russia, Mexico, UAE, Egypt, Algeria, Vietnam, India, and Sri Lanka.
</p>

<p>
	 
</p>

<p>
	Although SteelFox is fairly new, "it is a full-featured crimeware bundle," the researchers say. Analysis of the malware indicates that it's developer is skilled in C++ programming and they managed to create formidable malware by integrating external libraries.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/new-steelfox-malware-hijacks-windows-pcs-using-vulnerable-driver/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26418</guid><pubDate>Thu, 07 Nov 2024 01:53:56 +0000</pubDate></item><item><title>Mozilla is eliminating its advocacy division, which fought for a free and open web</title><link>https://nsaneforums.com/news/security-privacy-news/mozilla-is-eliminating-its-advocacy-division-which-fought-for-a-free-and-open-web-r26400/</link><description><![CDATA[<h3>
	The Mozilla Foundation laid off 30 percent of its workforce in late October.
</h3>

<div>
	<div>
		<div>
			<div>
				<p>
					The Mozilla Foundation laid off 30 percent of its workforce and completely eliminated its advocacy and global programs divisions, <a href="https://techcrunch.com/2024/11/05/mozilla-foundation-lays-off-30-staff-drops-advocacy-division/" rel="external nofollow"><em>TechCrunch </em>reports</a>. 
				</p>

				<p>
					 
				</p>
			</div>

			<div>
				<p>
					While Mozilla is best known for its Firefox web browser, the Mozilla Foundation — the parent of the Mozilla Corporation — describes itself as standing up “for the health of the internet.” With its advocacy and global programs divisions gone, its impact may be lessened going forward.
				</p>

				<p>
					 
				</p>
			</div>

			<div>
				<p>
					“Fighting for a free and open internet will always be core to our mission, and advocacy continues to be a critical tool in that work. We’re revisiting how we pursue that work, not stopping it,” Brandon Borrman, the Mozilla Foundation’s communications chief, said in an email to <em>The Verge. </em>Borrman declined to confirm exactly how many people were laid off, but said it was about “30% of the current team.”
				</p>

				<p>
					 
				</p>
			</div>

			<div>
				<p>
					This is Mozilla’s <a href="https://www.theverge.com/2024/2/13/24072184/mozilla-is-laying-off-around-60-workers-and-scaling-back-its-mastodon-instance" rel="external nofollow">second round of layoffs this year</a>. In February, the Mozilla Corporation laid off around 60 workers said it would be making a “strategic correction” that would involve involve cutting back its work on a Mastodon instance. Mozilla shut down its virtual 3D platform and refocused its efforts on Firefox and AI. The Mozilla Foundation had around 120 employees before this more recent round of layoffs, according to <em>TechCrunch</em>.
				</p>

				<p>
					 
				</p>
			</div>

			<div>
				<p>
					In an email sent to all employees on October 30th, Nabhia Syed, the foundation’s executive director, said that the advocacy and global programs divisions “are no longer part of our structure.”
				</p>

				<p>
					 
				</p>
			</div>

			<div>
				<p>
					“Navigating this topsy-turvy, distracting time requires laser focus — and sometimes saying goodbye to the excellent work that has gotten us this far because it won’t get us to the next peak,” wrote Syed, who previously worked as the chief executive of <em>The Markup</em>, an investigative news site. “Lofty goals demand hard choices.”
				</p>
			</div>
		</div>
	</div>

	<div data-concert="btf_medium_rectangle_variable_feature_extended_sticky">
		 
	</div>
</div>

<p>
	<a href="https://www.theverge.com/2024/11/5/24289124/mozilla-foundation-layoffs-advocacy-global-programs" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26400</guid><pubDate>Wed, 06 Nov 2024 02:37:15 +0000</pubDate></item><item><title>Suspect arrested in Snowflake data-theft attacks affecting millions</title><link>https://nsaneforums.com/news/security-privacy-news/suspect-arrested-in-snowflake-data-theft-attacks-affecting-millions-r26399/</link><description><![CDATA[<h3>
	Threat actor exploited account credentials swept up by infostealers years earlier.
</h3>

<p>
	Canadian authorities have arrested a man on suspicion he breached hundreds of accounts belonging to users of cloud storage provider Snowflake and used that access to steal personal data belonging to millions of people, authorities said Tuesday.
</p>

<p>
	 
</p>

<p>
	“Following a request by the United States, Alexander Moucka (aka Connor Moucka) was arrested on a provisional arrest warrant on Wednesday, October 30, 2024,” an official with the Canada Department of Justice wrote in an email Tuesday. “He appeared in court later that afternoon, and his case was adjourned to Tuesday, November 5, 2024. As extradition requests are considered confidential state-to-state communications, we cannot comment further on this case.”
</p>

<p>
	 
</p>

<p>
	Word of the arrest first came from <a href="https://www.bloomberg.com/news/articles/2024-11-05/hacker-said-to-be-behind-breach-of-snowflake-customers-arrested" rel="external nofollow">Bloomberg News</a> and was later confirmed by <a href="https://www.404media.co/suspected-snowflake-hacker-arrested-in-canada/" rel="external nofollow">404 Media</a>.
</p>

<h2>
	Scourge of the infostealers
</h2>

<p>
	The Snowflake compromise came to light in late May, following the <a href="https://arstechnica.com/security/2024/06/ticketmaster-and-several-other-snowflake-customers-hacked/" rel="external nofollow">disclosure</a> by Live Nation that data held by its Ticketmaster group had been stolen and put up for sale online. The data included the full names, addresses, phone numbers, and partial credit card numbers for 560 million Ticketmaster customers. Live Nation <a href="https://techcrunch.com/2024/05/31/live-nation-confirms-ticketmaster-was-hacked-says-personal-information-stolen-in-data-breach/" rel="external nofollow">later told</a> TechCrunch the data had been stored in an account on Snowflake.
</p>

<p>
	 
</p>

<p>
	Mandiant, a Google-owned security firm Snowflake retained to investigate the breach <a href="https://arstechnica.com/information-technology/2024/06/hackers-steal-significant-volume-of-data-from-hundreds-of-snowflake-customers/" rel="external nofollow">has said</a> that 165 customers of the cloud storage provider may have had data stolen during that spree. Data purporting to be taken from many customers was later put up for auction online, creating major risks for the breached companies and the individual holders of that personal data.
</p>

<p>
	 
</p>

<p>
	Mandiant went on to say that all the compromises it had tracked were the result of login credentials for Snowflake accounts being stolen by infostealer malware and stored in vast logs, sometimes for years at a time, before eventually making their way into the hands of the threat actors who used them in the individual breaches.
</p>

<p>
	 
</p>

<figure class="ars-img-shortcode id-2030620 align-center">
	<div>
		<div class="ars-lightbox">
			<div class="ars-lightbox-item">
				<img alt="snowflake-attack-path-980x815.jpg" class="ipsImage" decoding="async" height="720" width="720" src="https://cdn.arstechnica.net/wp-content/uploads/2024/06/snowflake-attack-path-980x815.jpg">
				<div class="pswp-caption-content" id="caption-2030620">
					<em>Attack Path UNC5537 has used in attacks against as many as 165 Snowflake customers. </em>

					<div class="ars-gallery-caption-credit">
						<em><em>Credit: Mandiant </em></em>
					</div>
				</div>
			</div>
		</div>
	</div>
</figure>

<p>
	None of the affected accounts used multifactor authentication, which requires users to provide a one-time password or additional means of authentication besides a password. After that revelation, Snowflake <a href="https://www.snowflake.com/en/blog/multi-factor-identification-default/" rel="external nofollow">enforced</a> mandatory MFA for accounts and required that passwords be at least 14 characters long.
</p>

<p>
	 
</p>

<p>
	Mandiant had identified the threat group behind the breaches as UNC5537. The group has referred to itself ShinyHunters. Snowflake offers its services under a model known as SaaS (software as a service).
</p>

<p>
	 
</p>

<p>
	“UNC5537 aka Alexander ‘Connor’ Moucka has proven to be one of the most consequential threat actors of 2024,” Mandiant wrote in an emailed statement. “In April 2024, UNC5537 launched a campaign, systematically compromising misconfigured SaaS instances across over a hundred organizations. The operation, which left organizations reeling from significant data loss and extortion attempts, highlighted the alarming scale of harm an individual can cause using off-the-shelf tools.”
</p>

<p>
	 
</p>

<p>
	Mandiant said a co-conspirator, John Binns, was <a href="https://www.tmonews.com/2024/06/man-behind-2021-t-mobile-data-breach-finally-arrested/%22" rel="external nofollow">arrested</a> in June. The status of that case wasn’t immediately known.
</p>

<p>
	 
</p>

<p>
	Besides Ticketmaster, other customers known to have been breached include AT&amp;T and Spain-based bank Santander. In July, AT&amp;T <a href="https://www.sec.gov/Archives/edgar/data/732717/000073271724000046/t-20240506.htm" rel="external nofollow">said</a> that personal information and phone and text message records for roughly 110 million customers were stolen. WIRED <a href="https://www.wired.com/story/atandt-paid-hacker-300000-to-delete-stolen-call-records/" rel="external nofollow">later reported</a> that AT&amp;T paid $370,000 in return for a promise the data would be deleted.
</p>

<p>
	 
</p>

<p>
	Other Snowflake customers reported by various news outlets as breached are Pure Storage, Advance Auto Parts, Los Angeles Unified School District, QuoteWizard/LendingTree, Neiman Marcus, Anheuser-Busch, Allstate, Mitsubishi, and State Farm.
</p>

<p>
	 
</p>

<p>
	KrebsOnSecurity <a href="https://krebsonsecurity.com/2024/11/canadian-man-arrested-in-snowflake-data-extortions/" rel="external nofollow">reported Tuesday</a> that Moucka has been named in multiple charging documents filed by US federal prosecutors. Reporter Brian Krebs said specific charges and allegations are unknown because the cases remain sealed.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2024/11/suspect-arrested-in-snowflake-data-theft-attacks-affecting-millions/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26399</guid><pubDate>Wed, 06 Nov 2024 02:36:42 +0000</pubDate></item><item><title>Google fixes two Android zero-days used in targeted attacks</title><link>https://nsaneforums.com/news/security-privacy-news/google-fixes-two-android-zero-days-used-in-targeted-attacks-r26388/</link><description><![CDATA[<p>
	Google fixed two actively exploited Android zero-day flaws as part of its November security updates, addressing a total of 51 vulnerabilities.
</p>

<p>
	 
</p>

<p>
	Tracked as CVE-2024-43047 and CVE-2024-43093, the two issues are marked as exploited in limited, targeted attacks.
</p>

<p>
	 
</p>

<p>
	"There are indications that the following may be under limited, targeted exploitation," says <a href="https://source.android.com/docs/security/bulletin/2024-11-01" rel="external nofollow" target="_blank">Google's advisory</a>.
</p>

<p>
	 
</p>

<p>
	The CVE-2024-43047 flaw is a high-severity use-after-free issue in closed-source Qualcomm components within the Android kernel that elevates privileges.
</p>

<p>
	 
</p>

<p>
	The flaw was <a href="https://www.bleepingcomputer.com/news/security/qualcomm-patches-high-severity-zero-day-exploited-in-attacks/" target="_blank" rel="external nofollow">first disclosed</a> in early October 2024 by Qualcomm as a problem in its Digital Signal Processor (DSP) service.
</p>

<p>
	 
</p>

<p>
	CVE-2024-43093 is also a high-severity elevation of privilege flaw, this time impacting the Android Framework component and Google Play system updates, specifically in the Documents UI.
</p>

<p>
	 
</p>

<p>
	Google did not disclose who discovered the CVE-2024-43093 vulnerability.
</p>

<p>
	 
</p>

<p>
	While Google did not share any details on how the vulnerabilities were exploited, as researchers at Amnesty International discovered CVE-2024-43047, it could indicate that the flaw was used in targeted spyware attacks.
</p>

<p>
	 
</p>

<p>
	Out of the remaining 49 flaws fixed this time, only one, CVE-2024-38408, is classified as critical, also impacting Qualcomm's proprietary components.
</p>

<p>
	 
</p>

<p>
	The security issues fixed this month impact Android versions between 12 and 15, with some being limited to specific versions of the mobile operating system.
</p>

<p>
	 
</p>

<p>
	Google issues two patch levels each month, in this case, November 1 (2024-11-01 Patch Level) and November 5 (2024-11-05 Patch Level).
</p>

<p>
	 
</p>

<p>
	The first level addresses core Android vulnerabilities, with 17 issues this time, while the second patch level encompasses those plus vendor-specific fixes (Qualcomm, MediaTek, etc.), counting an additional 34 fixes this month.
</p>

<p>
	 
</p>

<p>
	To apply the latest update, head to <strong>Settings &gt; System &gt; Software updates &gt; System update</strong>. Alternatively, go to <strong>Settings &gt; Security &amp; privacy &gt; System &amp; updates &gt; Security update</strong>. A restart will be required to apply the update.
</p>

<p>
	 
</p>

<p>
	Android 11 and older are no longer supported but may receive security updates to critical issues for actively exploited flaws through <a href="https://support.google.com/android/answer/7680439" rel="external nofollow" target="_blank">Google Play system updates</a>, though that's not guaranteed.
</p>

<p>
	 
</p>

<p>
	The best course of action for devices still running those older releases should be either to replace them with newer models or use a third-party Android distribution that incorporates the latest security fixes.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/google-fixes-two-android-zero-days-used-in-targeted-attacks/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26388</guid><pubDate>Tue, 05 Nov 2024 17:53:01 +0000</pubDate></item><item><title>Meet Interlock &#x2014; The new ransomware targeting FreeBSD servers</title><link>https://nsaneforums.com/news/security-privacy-news/meet-interlock-%E2%80%94-the-new-ransomware-targeting-freebsd-servers-r26368/</link><description><![CDATA[<p>
	A relatively new ransomware operation named Interlock attacks organizations worldwide, taking the unusual approach of creating an encryptor to target FreeBSD servers.
</p>

<p>
	 
</p>

<p>
	Launched at the end of September 2024, Interlock has since claimed attacks on six organizations, publishing stolen data on their data leak site after a ransom was not paid. One of the victims is Wayne County, Michigan, which <a href="http://www.wxyz.com/news/local-news/investigations/cyberattack-hits-wayne-county-government-services-affected-as-hacker-demands-ransom" rel="external nofollow" target="_blank">suffered a cyberattack at the beginning of October</a>.
</p>

<p>
	 
</p>

<p>
	Not much is known about the ransomware operation, with some of the first information coming from incident responder Simo in early October, <a href="https://x.com/nembo81pr/status/1841390890167775551" rel="external nofollow" target="_blank">who found</a> a new backdoor [<a href="https://www.virustotal.com/gui/file/e9ff4d40aeec2ff9d2886c7e7aea7634d8997a14ca3740645fd3101808cc187b/detection" rel="external nofollow" target="_blank">VirusTotal</a>] deployed in an Interlock ransomware incident.
</p>

<p>
	 
</p>

<p>
	Soon after, cybersecurity researcher <a href="https://x.com/malwrhunterteam/status/1844016110821368277" rel="external nofollow" target="_blank">MalwareHuntTeam found</a> what was believed to be a Linux ELF encryptor [<a href="https://www.virustotal.com/gui/file/e86bb8361c436be94b0901e5b39db9b6666134f23cce1e5581421c2981405cb1" rel="external nofollow" target="_blank">VirusTotal</a>] for the Interlock operation. Sharing the sample with BleepingComputer, we attempted to test it on a virtual machine, where it immediately crashed.
</p>

<p>
	 
</p>

<p>
	Examining the strings within the executable indicated that it was compiled specifically for FreeBSD, with the Linux "File" command further confirming it was compiled on FreeBSD 10.4.
</p>

<pre><code>interlock.elf: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, BuildID[sha1]=c7f876806bf4d3ccafbf2252e77c2a7546c301e6, for FreeBSD 10.4, FreeBSD-style, not stripped</code></pre>

<p>
	However, even when testing the sample on a FreeBSD virtual machine, BleepingComputer was unable to get the sample to properly execute.
</p>

<p>
	 
</p>

<p>
	While it is common to see Linux encryptors created to target VMware ESXi servers and virtual machines, it is rare to see ones created for FreeBSD. The only other ransomware operation known to have created FreeBSD encryptors is the <a href="https://www.bleepingcomputer.com/news/security/hive-ransomware-now-encrypts-linux-and-freebsd-systems/" target="_blank" rel="external nofollow">now-defunct Hive ransomware operation</a>, which was <a href="https://www.bleepingcomputer.com/news/security/hive-ransomware-disrupted-after-fbi-hacks-gangs-systems/" target="_blank" rel="external nofollow">disrupted by the FBI in 2023</a>.
</p>

<p>
	 
</p>

<p>
	This week, researchers from cybersecurity firm Trend Micro shared on X that they found an additional sample of the FreeBSD ELF encryptor [<a href="https://www.virustotal.com/gui/file/28c3c50d115d2b8ffc7ba0a8de9572fbe307907aaae3a486aabd8c0266e9426f" rel="external nofollow" target="_blank">VirusTotal</a>] and a sample of the operation's Windows encryptor [<a href="http://1cb6a93e6d2d86d3479a1ea59f7d5b258f1c5c53" rel="external nofollow" target="_blank">VirusTotal</a>].
</p>

<p>
	 
</p>

<p>
	Trend Micro further said that the threat actors likely created a FreeBSD encryptor as the operating system is commonly used in critical infrastructure, where attacks can cause widespread disruption.
</p>

<p>
	 
</p>

<p>
	"Interlock targets FreeBSD as it's widely utilized in servers and critical infrastructure. Attackers can disrupt vital services, demand hefty ransoms, and coerce victims into paying," explains Trend Micro.
</p>

<h2>
	The Interlock ransomware
</h2>

<p>
	While BleepingComputer could not get the FreeBSD encryptor working, the Windows version ran without a problem on our virtual machine.
</p>

<p>
	 
</p>

<p>
	According to Trend Micro, the Windows encryptor will clear Windows event logs, and if self-deletion is enabled, will use a DLL to delete the main binary using rundll32.exe. 
</p>

<p>
	 
</p>

<p>
	When encrypting files, the ransomware will append the <strong>.interlock</strong> extension to all encrypted file names, and create a ransom note in each folder.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Files encrypted by Interlock" class="ipsImage" height="446" width="720" src="https://www.bleepstatic.com/images/news/ransomware/i/interlock/encrypted-files.jpg">
		<figcaption>
			<em>Files encrypted by Interlock<br>
			Source: BleepingComputer</em>
		</figcaption>
	</figure>
</div>

<p>
	This ransom note is named <strong>!__README__!.txt</strong> and briefly describes what happened to the victim's files, makes threats, and links to the Tor negotiation and data leak sites.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Interlock ransom note" class="ipsImage" height="465" width="720" src="https://www.bleepstatic.com/images/news/ransomware/i/interlock/ransom-note.jpg">
		<figcaption>
			<em>Interlock ransom note<br>
			Source: BleepingComputer</em>
		</figcaption>
	</figure>
</div>

<p>
	Each victim has a unique "Company ID" that is used along with an email address to register on the threat actor's Tor negotiation site. Like many other recent ransomware operations, the victim-facing negotiation site just includes a chat system that can be used to communicate with the threat actors.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Interlock dark web negotiation site" class="ipsImage" height="600" style="height: auto;" width="874" src="https://www.bleepstatic.com/images/news/ransomware/i/interlock/interlock-negoration-site.jpg">
		<figcaption>
			Interlock dark web negotiation site<br>
			Source: BleepingComputer
		</figcaption>
	</figure>
</div>

<p>
	When conducting attacks, Interlock will breach a corporate network and steal data from servers while spreading laterally to other devices. When done, the threat actors deploy the ransomware to encrypt all of the files on the network.
</p>

<p>
	 
</p>

<p>
	The stolen data is used as part of a double-extortion attack, where the threat actors threaten to publicly leak it if a ransom is not paid.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Interlock data leak site" class="ipsImage" height="600" style="height: auto;" width="847" src="https://www.bleepstatic.com/images/news/ransomware/i/interlock/data-leak-site.jpg">
		<figcaption>
			<em>Interlock data leak site<br>
			Source: BleepingComputer</em>
		</figcaption>
	</figure>
</div>

<p>
	BleepingComputer has learned that the ransomware operation demands ransoms ranging from hundreds of thousands of dollars to millions, depending on the size of the organization.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/meet-interlock-the-new-ransomware-targeting-freebsd-servers/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26368</guid><pubDate>Mon, 04 Nov 2024 06:07:51 +0000</pubDate></item><item><title>You can now try Microsoft&#x2019;s more modern Windows Hello UI</title><link>https://nsaneforums.com/news/security-privacy-news/you-can-now-try-microsoft%E2%80%99s-more-modern-windows-hello-ui-r26336/</link><description><![CDATA[<h3>
	Windows 11 is getting a sign-in and authentication overhaul, and it’s now in beta testing.
</h3>

<div>
	<div>
		<div>
			<div>
				<p>
					Microsoft is modernizing how its Windows Hello authentication, which includes facial and fingerprint recognition, works in Windows 11. The revamp to the Windows Hello experience is now in beta testing with Windows Insiders, and includes visual changes, new iconography, and improvements to passkeys.
				</p>

				<p>
					 
				</p>
			</div>

			<div>
				<p>
					Not only will this new UI appear on the Windows 11 login screen, but also when you’re using passkeys to sign into websites and apps. “We redesigned Windows security credential user experiences for passkey creating a cleaner experience that supports secured and quick authentication,” <a href="https://blogs.windows.com/windows-insider/2024/11/01/announcing-windows-11-insider-preview-build-22635-4440-beta-channel/" rel="external nofollow">explains the Windows team</a>. “Users will now be able to switch between authentication options and select passkey / devices more intuitively.”
				</p>

				<p>
					 
				</p>
			</div>

			<div>
				<div>
					<div>
						<div aria-label="Zoom" role="button" tabindex="0">
							<div>
								<div>
									<div>
										<span><img alt="The new Windows Hello UI on the login screen of Windows 11." class="ipsImage" data-nimg="fill" decoding="async" height="720" width="720" src="https://duet-cdn.vox-cdn.com/thumbor/0x0:1920x1080/1080x608/filters:focal(960x540:961x541):format(webp)/cdn.vox-cdn.com/uploads/chorus_asset/file/25710242/lockScreen_darkThemeOct.png"></span>
									</div>
								</div>
							</div>
						</div>
					</div>

					<div>
						<div>
							<em>The new Windows Hello UI on the login screen of Windows 11.</em>
						</div>
						<cite class="duet--article--dangerously-set-cms-markup inline not-italic text-gray-63 dark:text-gray-bd [&amp;&gt;a:hover]:text-gray-63 [&amp;&gt;a:hover]:shadow-underline-black dark:[&amp;&gt;a:hover]:text-gray-bd dark:[&amp;&gt;a:hover]:shadow-underline-gray [&amp;&gt;a]:shadow-underline-gray-63 dark:[&amp;&gt;a]:text-gray-bd dark:[&amp;&gt;a]:shadow-underline-gray">Image: Microsoft</cite>
					</div>
				</div>
			</div>

			<div>
				<p>
					 
				</p>

				<p>
					Microsoft currently supports passkeys in Windows 11, but the experience of using one from a mobile device involves scanning QR codes and an outdated UI. A new sign-in UI for passkeys and Microsoft account authentication will improve this greatly, as part of this Windows Hello UI overhaul.
				</p>

				<p>
					 
				</p>
			</div>

			<div>
				<p>
					<a href="https://www.theverge.com/2024/10/10/24266780/microsoft-windows-11-passkey-redesign-windows-hello" rel="external nofollow">Microsoft has also built</a> a new API for third-party password and passkey managers that can let developers plug directly into this modern Windows Hello experience. It will also allow Windows 11 users to use passkey from a mobile device to authenticate with apps and websites on a PC. This new passkeys experience will also support saving passkeys to third-party apps or syncing them to your Microsoft account.
				</p>

				<p>
					 
				</p>
			</div>

			<div>
				<div>
					<div>
						<div aria-label="Zoom" role="button" tabindex="0">
							<div>
								<div>
									<div>
										<span><img alt="The new passkey sign-in process." class="ipsImage" data-nimg="fill" decoding="async" height="720" width="720" src="https://duet-cdn.vox-cdn.com/thumbor/0x0:2742x1256/1080x495/filters:focal(1371x628:1372x629):format(webp)/cdn.vox-cdn.com/uploads/chorus_asset/file/25710262/Passkey_Sign_in_CredUIRejuv.png"></span>
									</div>
								</div>
							</div>
						</div>
					</div>

					<div>
						<div>
							<em>The new passkey sign-in process.</em>
						</div>
						<cite class="duet--article--dangerously-set-cms-markup inline not-italic text-gray-63 dark:text-gray-bd [&amp;&gt;a:hover]:text-gray-63 [&amp;&gt;a:hover]:shadow-underline-black dark:[&amp;&gt;a:hover]:text-gray-bd dark:[&amp;&gt;a:hover]:shadow-underline-gray [&amp;&gt;a]:shadow-underline-gray-63 dark:[&amp;&gt;a]:text-gray-bd dark:[&amp;&gt;a]:shadow-underline-gray">Image: Microsoft</cite>
					</div>
				</div>
			</div>

			<div>
				<p>
					 
				</p>

				<p>
					Microsoft has started testing this new Windows Hello experience for the beta channel (23H2), and it should also appear in the dev channel (which is based on 24H2) once <a href="https://twitter.com/windowsinsider/status/1852398059382251582" rel="external nofollow">builds resume soon</a>. I’d expect we’ll see this new Windows Hello UI appear for all Windows 11 users in the coming months.
				</p>
			</div>
		</div>
	</div>

	<div data-concert="btf_medium_rectangle_variable_feature_extended_sticky">
		 
	</div>
</div>

<p>
	<a href="https://www.theverge.com/2024/11/1/24285558/microsoft-windows-hello-ui-passkeys-beta-testing" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26336</guid><pubDate>Fri, 01 Nov 2024 19:20:19 +0000</pubDate></item><item><title>LastPass warns of fake support centers trying to steal customer data</title><link>https://nsaneforums.com/news/security-privacy-news/lastpass-warns-of-fake-support-centers-trying-to-steal-customer-data-r26323/</link><description><![CDATA[<p>
	LastPass is warning about an ongoing campaign where scammers are writing reviews for its Chrome extension to promote a fake customer support phone number. However, this phone number is part of a much larger campaign to trick callers into giving scammers remote access to their computers, as discovered by BleepingComputer.
</p>

<p>
	 
</p>

<p>
	LastPass is a popular password manager that utilizes a <a href="https://www.bleepingcomputer.com/news/security/lastpass-says-12-hour-outage-caused-by-bad-chrome-extension-update/" target="_blank" rel="external nofollow">LastPass Chrome extension</a> to generate, save, manage, and autofill website passwords.
</p>

<p>
	 
</p>

<p>
	Threat actors are attempting to target a large swath of the company's user base by leaving 5-star reviews with a fake LastPass customer support number.
</p>

<p>
	 
</p>

<p>
	These reviews urge users facing any problems with the app to contact the LastPass online customer service at 805-206-2892, which is not associated with the vendor.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Fraudulent reviews on Chrome Web Store" class="ipsImage" height="604" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2024/Campaigns/31/reviews.jpg">
		<figcaption>
			<em>Fraudulent reviews on Chrome Web Store<br>
			Source: LastPass</em>
		</figcaption>
	</figure>
</div>

<p>
	Instead, a scammer answering the phone will impersonate LastPass and direct individuals to a site at 'dghelp[.]top' where they must enter a code to download a remote support program.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Fake support site" class="ipsImage" height="347" width="720" src="https://www.bleepstatic.com/images/news/security/l/lastpass/fake-support-site/fake-lastpass-support-site.jpg">
		<figcaption>
			<em>Fake support site<br>
			Source: BleepingComputer</em>
		</figcaption>
	</figure>
</div>

<p>
	"Individuals calling this fake support number will be greeted by an individual asking what product they are having issues with and then a series of questions regarding whether they are attempting to access LastPass via a computer or a mobile device and what operating system they are using," <a href="https://blog.lastpass.com/posts/fake-web-store-reviews-attempting-to-steal-customer-data" rel="external nofollow" target="_blank">explains LastPass</a>.
</p>

<p>
	 
</p>

<p>
	"They will then be directed to the site dghelp[.]top while the threat actor remains on the line and attempts to get the potential victim to engage with the site, exposing their data."
</p>

<p>
	 
</p>

<p>
	BleepingComputer has discovered that entering the code on this page will download a ConnectWise ScreenConnect agent [<a href="https://www.virustotal.com/gui/file/696572c679a9936be682231796f36cd2d71f4eed419bd7ab16bbd457f427f3b4" rel="external nofollow" target="_blank">VirusTotal</a>] that will give the scammer full access to a person's computer.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Support agent signed by ConnectWise" class="ipsImage" height="400" width="352" src="https://www.bleepstatic.com/images/news/security/l/lastpass/fake-support-site/screenconnect-properties.jpg">
		<figcaption>
			<em>Support agent signed by ConnectWise<br>
			Source: BleepingComputer</em>
		</figcaption>
	</figure>
</div>

<p>
	From there, one threat actor can keep the caller engaged with questions. At the same time, another scammer uses ScreenConnect in the background to install other programs for unattended remote access, steal data, or steal data from the computer.
</p>

<p>
	 
</p>

<p>
	BleepingComputer found that the ScreenConnect client will make connections to attacker-controlled servers at molatorimax[.]icu and n9back366[.]stream. Both of these sites have previously been associated with an IP address in Ukraine before being hidden behind Cloudflare.
</p>

<p>
	 
</p>

<p>
	LastPass users are reminded never to share their master password with anyone, not even legitimate customer support, as this would private access to all of the passwords and data stored in LastPass vaults.
</p>

<h2>
	Linked to a larger scam campaign 
</h2>

<p>
	BleepingComputer has learned that the phone number associated with the fake LastPass support center is linked to a much larger campaign.
</p>

<p>
	 
</p>

<p>
	The phone number, 805-206-2892, was also found promoted as a support number for numerous other companies, including Amazon, Adobe, Facebook, Hulu, YouTube TV, Peakcock TV, Verizon, Netflix, Roku, PayPal, Squarespace, Grammarly, iCloud, Ticketmaster, and Capital One.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Promoted as PayPal and iCloud support numbers" class="ipsImage" height="208" width="720" src="https://www.bleepstatic.com/images/news/security/l/lastpass/fake-support-site/extension-reviews.jpg">
		<figcaption>
			<em>Promoted as PayPal and iCloud support numbers<br>
			Source: BleepingComputer</em>
		</figcaption>
	</figure>
</div>

<p>
	These fake support numbers are posted not only to Chrome extension reviews but also to sites that allow anyone to create content, such as company forums and Reddit.
</p>

<p>
	 
</p>

<p>
	While many of these posts are taken down as they are created, others are still available, with new ones created throughout the day.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/lastpass-warns-of-fake-support-centers-trying-to-steal-customer-data/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of October): 4,832 news posts</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">26323</guid><pubDate>Fri, 01 Nov 2024 19:02:49 +0000</pubDate></item></channel></rss>
