Show more

House Votes to Extend—and Expand—a Major US Spy Program

The US House of Representatives voted on Friday to extend the Section 702 spy program. It passed without an amendment that would have required the FBI to obtain a warrant to access Americans’ information. - Section 702 permits the US government to wiretap communications between Americans and foreigners overseas.

wired.com/story/house-section-

Cybersecurity researchers have discovered a credit card skimmer that's concealed within a fake Meta Pixel tracker script in an attempt to evade detection.

Sucuri said that the malware is injected into websites through tools that allow for custom code, such as WordPress plugins like Simple Custom CSS and JS or the "Miscellaneous Scripts" section of the Magento admin panel.

Credit card skimmer hidden in fake Facebook pixel tracker report:

blog.sucuri.net/2024/04/credit

The right pentesting approach can provide valuable insights and direction to help organizations strengthen their security posture and navigate the complex threat landscape with increased confidence and peace of mind.

Exploring How Penetration Tests Are Classified – Pentesting Aspirant Guide 2024

gbhackers.com/penetration-test

"SSH is a vital tool for the safe operation of a networked world – anything that undermines it is really bad news"

In discovering malicious code that endangered global networks in open-source software, Andres Freund exposed our reliance on insecure, volunteer-maintained tech

One engineer’s curiosity may have saved us from a devastating cyber-attack

theguardian.com/commentisfree/

Hackers have successfully manipulated a default plugin within the Notepad++ package, potentially compromising the security of countless systems.

The plugin in question, “mimeTools.dll,” is a standard component of Notepad++ that provides encoding functionalities

asec.ahnlab.com/ko/63738/

ASEC has provided the following indicators of compromise (IoCs) for users to check their systems:

ICYMI

posted about this a while back

Detect when your installed Chrome extensions have changed owners.

github.com/classvsoftware/unde

Intermittently checks your installed extensions to see if the developer information listed on the Chrome Web Store has changed. If anything is different, the extension icon will display a red badge, alerting you to the change.

more here:

counter.social/@ecksmc/1120689

Because Facebook collects data even when you’re logged off, you should be aware of what information is getting tracked. Facebook uses tracking cookies that are stored on your computer or mobile device. These cookies are files that contain logged information about your online activity.

How To Stop Facebook From Tracking You [2024 Guide]

allaboutcookies.org/how-to-tur

Free VPN Apps on Google Play Turn Phones into Proxies

Several free Android VPN apps have been found to support a malicious residential proxy operation named ‘Proxylib.’

restoreprivacy.com/free-vpn-ap

Some of us would be happy being rated 7.5 out of 10, just sayin'

Two DNSSEC vulnerabilities were disclosed last month with similar descriptions and the same severity score, but they are not the same issue

theregister.com/2024/03/26/sof

'Mass surveillance' fears over law change plans in UK

The UK tech industry has deep concerns over government plans to amend a law dubbed a "snooper's charter".

Ministers insist their changes to the Investigatory Powers Act is intended to keep UK citizens safe.

But, in a statement, trade body techUK said the changes were neither balanced nor proportionate.

German authorities took down the Nemesis Market, a major online marketplace for drugs, cybercrime services and stolen credit card data.

Investigators seized the Nemesis Market platform’s server infrastructure in Germany and Lithuania on Wednesday

Press release from the Frankfurt am Main Public Prosecutor's Office - ZIT - and the Federal Criminal Police Office

bka.de/DE/Presse/Listenseite_P

new variant of the wiper malware AcidRain, known as AcidPour, has been discovered by SentinelOne’s threat intelligence team, SentinelLabs.

threadreaderapp.com/thread/176

AcidRain and AcidPour have a similar reboot mechanism.

sentinelone.com/labs/acidrain-

More here:

infosecurity-magazine.com/news

The International Monetary Fund (IMF) recently detected a cybersecurity incident that involved nearly a dozen email accounts getting hacked.

In a statement issued last week, the United Nations financial institution said it detected the security breach on February 16, 2024.

imf.org/en/News/Articles/2024/

The IMF told Reuters that the list of hacked accounts did not include the ones of Managing Director Kristalina Georgieva or other top officials.

reuters.com/technology/cyberse

New research has shed light on the profound impact of ransomware attacks on the IT and construction sectors these industries bore the brunt of nearly half of all incidents in 23

ontinue.com/resource/deep-dive

the report forecasts continued challenges in 2024, with artificial intelligence (AI) exploitation, IoT vulnerabilities and evolving ransomware operations expected to remain key concerns. the rise of hacktivism and the proliferation of hack-for-hire services sound additional alarm bells

new phishing campaign is targeting U.S. organizations with the intent to deploy a remote access trojan called NetSupport RAT.

Israeli cybersecurity company Perception Point is tracking the activity under the moniker Operation PhantomBlu.

perception-point.io/blog/opera

The starting point is a Salary-themed phishing email that purports to be from the accounting department and urges recipients to open the attached Microsoft Word document to view the "monthly salary report."

BTW ProtonVPN free version now won't let you pick what server you want or country it auto-picks the nearest country from the free countries available and the nearest server inside that country

bummer before you could pick between Japan, Netherlands, Poland, Romania or the US and all had more than ten servers one in different regions in each country

guess the free version was getting too popular

Google has an interesting game you can play called odd one out, where you're presented with 4 images, one of which is AI generated.

It's scary how hard it is to get right

artsandculture.google.com/expe

eSIM Vulnerabilities: SIM Swappers Exploit Flaws, Hijack Phone Numbers

According to a new report, SIM-swapping crimes are rising worldwide, mainly committed by eSIM (Embedded Subscriber Identity Modules) users.

cysecurity.news/2024/03/esim-v

ICYMI

Sim-swap fraud: How your bank account can be emptied ...

theguardian.com/money/2024/feb

Show more

⇄ Σ = Mᄃ² ⇆

CounterSocial is the first Social Network Platform to take a zero-tolerance stance to hostile nations, bot accounts and trolls who are weaponizing OUR social media platforms and freedoms to engage in influence operations against us. And we're here to counter it.