Daily NCSC-FI news followup 2020-02-22

Slickwraps Data Breach Exposes Financial and Customer Info

www.bleepingcomputer.com/news/security/slickwraps-data-breach-exposes-financial-and-customer-info/ Slickwraps has suffered a data breach after a security researcher was able to access their systems and after receiving no response to emails, publicly disclosed how they gained access to the site and the data that was exposed.. Slickwraps is a mobile device case retailer who sells a large assortment of premade cases and custom cases from images uploaded by customers.

Android Malware: Joker Still Fools Google’s Defense, New Clicker Found

www.bleepingcomputer.com/news/security/android-malware-joker-still-fools-googles-defense-new-clicker-found/ Joker malware that subscribes Android users to premium services without consent is giving Google a hard time as new samples constantly bypass scrutiny and end up in Play Store.

WhatsApp Phishing URLs Skyrocket With Over 13,000% Surge

www.bleepingcomputer.com/news/security/whatsapp-phishing-urls-skyrocket-with-over-13-000-percent-surge/

Apple drops a bomb on long-life HTTPS certificates: Safari to snub new security certs valid for more than 13 months

www.theregister.co.uk/2020/02/20/apple_shorter_cert_lifetime/

The Linux Foundation identifies most important open-source software components and their problems

www.zdnet.com/article/the-linux-foundation-identifies-the-most-important-open-source-software-components-and-their-problems/ In its latest study, the Linux Foundation’s Core Infrastructure Initiative discovered just how prevalent open-source components are in all software and their shared problems and vulnerabilities.

Threat spotlight: RobbinHood ransomware takes the drivers seat

blog.malwarebytes.com/threat-spotlight/2020/02/threat-spotlight-robbinhood-ransomware-takes-the-drivers-seat/ Despite their name, the RobbinHood cybercriminal gang is not stealing from the rich to give to the poor. Instead, these ransomware developers are more like big game huntersattacking enterprise organizations and critical infrastructure and keeping all the spoils for themselves.

Google to put a muzzle on Android apps accessing location data in the background

www.zdnet.com/article/google-to-put-a-muzzle-on-android-apps-accessing-location-data-in-the-background/ Google has announced this week plans to crack down on Android apps that abuse the OS permissions system and request access to user geo-location data when the app is not in use.. Starting with May, the OS maker plans to show warnings in the Play Store backend to all Android app developers about the need to update their apps.

ObliqueRAT linked to threat group launching attacks against government targets

www.zdnet.com/article/new-obliquerat-malware-linked-to-crimsonrat-group-striking-government-targets/ The new Trojan is attacking organizations across Southeast Asia.

You might be interested in …

Daily NCSC-FI news followup 2021-10-13

How Coinbase Phishers Steal One-Time Passwords krebsonsecurity.com/2021/10/how-coinbase-phishers-steal-one-time-passwords A recent phishing campaign targeting Coinbase users shows thieves are getting smarter about phishing one-time passwords (OTPs) needed to complete the login process. It also shows that phishers are attempting to sign up for new Coinbase accounts by the millions as part of an effort to identify email […]

Read More

Daily NCSC-FI news followup 2020-03-05

Attackers Taking Advantage of the Coronavirus/COVID-19 Media Frenzy www.fortinet.com/blog/threat-research/attackers-taking-advantage-of-the-coronavirus-covid-19-media-frenzy.html Over the past several weeks, FortiGuard Labs has been observing a significant increase in both legitimate and malicious activity surrounding the Coronavirus.. Threat findings via OSINT channels have yielded multiple themes, such as those appearing to be reports from trusted sources, such as governmental agencies, news […]

Read More

Daily NCSC-FI news followup 2021-05-02

Ransomware Reality Shock: 92% Who Pay Don’t Get Their Data Back www.forbes.com/sites/daveywinder/2021/05/02/ransomware-reality-shock-92-who-pay-dont-get-their-data-back/ According to the Sophos State of Ransomware 2021 report, the number of organizations deciding to pay a ransom has risen to 32% in 2021 compared to 26% last year. That same global survey discovered that only 8% of them got all their data […]

Read More

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.