Effective, fast, and unrecoverable: Wiper malware is popping up everywhere
Over the past year, a flurry of destructive wiper malware from no fewer than nine families has appeared. In the past week, researchers cataloged at least two more, both exhibiting advanced codebases designed to inflict maximum damage
Privacy advocates are aghast at UK’s anti-encryption plans
Their prime concern involves the threat to end-to-end encrypted (E2EE) messenger apps. Under the mooted measures, telecoms regulators could force platforms to scan through private messages for illegal content.
The proposals are part of the controversial Online Safety Bill
The bill provides for technology notices requiring communication providers to take away end-to-end encryption — to break it
https://thenextweb.com/news/privacy-advocates-slam-uk-anti-encryption-plans-whatsapp
Twitter confirmed today that the recent leak of millions of members' profiles, including private phone numbers and email addresses, resulted from the same data breach the company disclosed in August 2022.
"In November 2022, some press reports published that Twitter users' data had been allegedly leaked online," reads the update.
The weirdest security stories of 2022
https://www.malwarebytes.com/blog/news/2022/12/the-weirdest-stories-of-2022
“In The Box” marketplace may now proudly be called the largest and most significant catalyst for banking theft and fraud involving mobile devices
According to the experts from Resecurity
https://resecurity.com/blog/article/in-the-box-mobile-malware-webinjects-marketplace
Security News This Week: Attackers Keep Targeting the US Electric Grid
Plus: Chinese hackers stealing US Covid relief funds, a cyberattack on the Met Opera website, and more
https://www.wired.com/story/attacks-us-electrical-grid-security-roundup/
50 GB of Israeli Firms’ Data on Sale
A group of hackers has posted a trove of approximately 50GB of data for sale on two online forums and a Telegram group. The data was posted on 26 and 27th November 2022. This was revealed to Hackread.com by researchers at VPNMentor.
Google warns stolen Android keys used to sign info-stealing malware
OEMs including Samsung, LG and Mediatek named and shamed
Also in the alert, Google listed 10 malware samples and related SHA256 hashes, and recommended all affected smart-device vendors rotate their platform certificates.
https://www.theregister.com/2022/12/05/compromised_android_keys/
Sneaky hackers reverse defense mitigations when detected
A financially motivated threat actor is hacking telecommunication service providers and business process outsourcing firms, actively reversing defensive mitigations applied when the breach is detected.
Lil heads up for google one users with a pixel 7* & pixel 7 pro*
As of December 2022, Pixel 7* and Pixel 7 Pro* consumers can access VPN by Google One at no extra cost on those devices through the Google One app without a Google One subscription
If you have one of they devices install the google one app to benefit
Thats if you wanna trust a VPN service by google
So far i can't find anything to suggest google are using another VPN service to use for their VPN
Google Accuses Spanish Spyware Vendor of Exploiting Chrome, Firefox, & Windows Zero-Days
https://thehackernews.com/2022/12/google-accuses-spanish-spyware-vendor.html
WhatsApp Files on Dark Web Show Millions of Records For Sale
Check Point Research (CPR) has published a new advisory analyzing the exposed files and confirming the leak includes 360 million phone numbers from 108 countries.
(Nov release)
https://www.infosecurity-magazine.com/next-gen-infosec/whatsapp-attack-mobile-phishing/
(latest relaese)
According to the document, the whole list went on sale for four days and is now being distributed for free among dark web users.
https://www.infosecurity-magazine.com/news/dark-web-show-millions-of-whatsapp/
The hackers leaking stolen Australian health records to the dark web on Thursday appeared to end their extortion attempt by dumping a final batch of data online and declaring:"Case closed."
or as the Australian government call them "rolled gold mongrels"
🤣
https://www.securityweek.com/hackers-dump-australian-health-data-online-declare-case-closed
Heads up WhatsApp users: #CoSoSec
hacker has allegedly posted a dataset to the dark web containing the personal information of almost 500 million WhatsApp users
which was uploaded to hacking forum BreachForums on November 16, the hacker claimed to be selling up-to-date personal information of 487 million WhatsApp users from 84 countries no official statement from WhatsApp or its parent company
A screenshot of the alleged hacker's post on BreachedForums
This virtual event will focus on some of the new threats posed by cybercriminals and nation-states.
Cybersecurity Outlook 2023 | This free, all-day virtual event hosted by Dark Reading
https://twitter.com/DarkReading
And
@BlackHatEvents
https://twitter.com/BlackHatEvents
and @OmdiaCyber
https://twitter.com/OmdiaCyber
will offer expert insight on the cyber-threats and technology trends enterprises will face in the coming year
https://vts.informaengage.com/dark-reading-cybersecurity-outlook-2023/
This privacy breach has taken the U.S. by storm, as Meta Pixel is used by many hospitals in the country, exposing millions of people to third parties
Meta Pixel is a JavaScript tracker that helps website operators understand how visitors interact with the site, helping them make targeted improvements.
However, the tracker also sends sensitive data to Meta (Facebook) and is then shared with a massive network of marketers
The Microsoft Detection and Response Team (DART) recently warned that attackers are increasingly using token theft to circumvent multi-factor authentication (MFA).
“By compromising and replaying a token issued to an identity that has already completed multifactor authentication, the threat actor satisfies the validation of MFA and access is granted to organizational resources accordingly,”
Microsoft Warns of Surge in Token Theft, Bypassing MFA
https://www.esecurityplanet.com/threats/token-theft-bypassing-mfa/
Ben Lovejoy
- Nov. 25th 2022 6:36 am
security specialist who yesterday tweeted about the issue had their Twitter account suspended the same day. Internationally recognized computer security expert Chad Loder predicted Twitter’s reaction, and was confirmed right within minutes
A massive Twitter data breach last year, exposing more than five million phone numbers and email addresses, was worse than initially reported
Google Releases Chrome Patch to Fix New Zero-Day Vulnerability
Writing in a security bulletin, the tech giant described the high-severity vulnerability (tracked CVE-2022-4135) as a heap buffer overflow in the graphics processing unit (GPU) component
https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.html
users should upgrade to version 107.0.5304.121/.122 for Windows and 107.0.5304.121 for Mac and Linux. Chromium-based browsers like Microsoft Edge, Brave, Opera and Vivaldi should also be updated
As the Data Marketplace Matures, Prices Decline
In the past year, the Dark Web data market grew larger in total volume and product variety. Predictably, as supply grew, most prices plummeted.
Here’s a review of the Dark Web data market by the numbers:
E = Mc2 - Energy Milk Coffee
Fáilte Abhaile 🏴 “a nod’s as guid as a wink tae a blind horse”
ta be aff yer heid helps