7th May 2018

Week in security (April 30 – May 6)

Last week on Labs, we examined the Spartacus ransomware, reported about a new tactic used by the Necurs malspam campaign, informed you about the recommended Twitter password change, and discussed engaging students to start considering careers in cybersecurity. Other news NTML credentials can be stolen via malicious Portable Document Format (PDF) files without any user interaction. (Source: SecurityWeek) Twitter sold data access to a Cambridge Analytica-linked researcher. (Source: Bloomberg) FacexWorm targets cryptocurrency users by spreading through Facebook Messenger. (Source: Security Affairs) New DNS encryption tools accelerate privacy online. (Source: HelpNetSecurity) IoT security: Is cryptocurrency-mining malware your next big headache? (Source: ZDNet) Companies from across the tech spectrum are lining up to protest the measure that would allow them to “hack back” with offensive initiatives in the face of a cyberattack. (Source: ThreatPost) Drive-by Rowhammer attack uses GPU to c..
4th May 2018

Cambridge Analytica shuts down and ransomware victims pay up | Avast

MA school district pays $10,000 ransom On April 14, the Leominster school district in Massachusetts was hit with a ransomware attack that took the education sector’s computer system hostage, locking all administrators and teachers out of their email. Authorities believe the attack was intended only as a money-making scheme and not to mine sensitive data.
27th April 2018

Please don’t buy this: smart toys

Smart toys attempt to offer what a lot of us imagined as kids—a toy that we can not only play with, but one that plays back. Many models offer voice recognition, facial expressions, hundreds of words and phrases, reaction to touch and impact, and even the ability to learn and retain new information. These features provide an obvious thrill for many children, whose imaginary friend just became a lot more real. At the low end, smart toys can be as simple as a motion-activated rattle designed with features intended to help with developmental milestones. Higher-end toys can be as engaging as a real-life R2-D2 that will watch Star Wars with you and offer commentary. But much like other Internet of Things products, smart toys don’t have a great track record of protecting personal information, designing software according to industry best practices, and updating in a timely manner. And we’re in fairly new territory when it comes to young children and the Internet. Suddenly, we have to worry..
27th April 2018

Amazon hacked for Ethereum heist and new security laws affect UK | Avast

Amazon Web Services (AWS) hijacked for 2-hour heist For two hours on Tuesday, the website MyEtherWallet.com, a cryptocurrency wallet where thousands of users store their Ethereum, was leeched of roughly $150,000. Cybercriminals hacked into the site by posing as a legitimate Amazon Web Service (AWS) IP space. AWS hosts the website, and to the casual user, everything looked normal.
23rd April 2018

A week in security (April 16 – April 22)

Last week, we took a stroll down memory lane talking about Facebook and MySpace, noticed a change in the Magnitude exploit kit—wherein it started adopting the GandCrab ransomware, took a good look at a new form of adware that is based on Python, chatted a bit about Russian hacking with a journalist, encouraged retailers to ask the right questions to protect their business, and weighed in on a way to speed up Internet bandwidth and increase privacy via Cloudflare’s new DNS service. Other news Cryptocurrency is all the rave these days—and so are cryptominers. Security researchers recently discovered one that doesn’t rely on an open browser session. (Source: HackRead) Tax fraud is no longer for the clueless, it seems. Experts noticed that scammers are also targeting tax professionals—those filing taxes on behalf of their clients. (Source: CNBC) To date, adware, spyware, and malware have lurked inside the Google Play Store. But surveillanceware? That’s definitely something new. (Source: L..