gtbarry, to Black_cats
@gtbarry@mastodon.social avatar

US offers $10 million bounty for info on 'Blackcat' hackers who hit UnitedHealth

The U.S. State Department on Wednesday offered up to $10 million for information on the "Blackcat" ransomware gang who hit the UnitedHealth Group's tech unit and snarled insurance payments across America.

https://www.reuters.com/technology/cybersecurity/us-offers-10-million-bounty-info-blackcat-hackers-who-hit-unitedhealth-2024-03-27/

schizanon, to security

ProTip: If a website asks you to hold down a key, something bad is about to happen to you.

(the attacker entices you to hold Enter and then causes some UI to appear where the Enter key activates an unsafe action.)

#gestureJacking #security #malware #web

gcluley, to Cybersecurity
@gcluley@mastodon.green avatar

Ransomware: lessons all companies can learn from the British Library attack.

Read more in my article on the Exponential-e blog: https://www.exponential-e.com/blog/ransomware-lessons-all-companies-can-learn-from-the-british-library-attack

#cybersecurity #malware #ransomware #britishlibrary #databreach

br00t4c, to microsoft
@br00t4c@mastodon.social avatar
br00t4c, (edited ) to Colorado
@br00t4c@mastodon.social avatar
metin, to security
@metin@graphics.social avatar

From the ar(t)chive…

Stylized 3D illustration for the staff magazine of the Dutch police force, accompanying an article about data vulnerability.

garry, to technology
@garry@mstdn.social avatar

Unpatchable security flaw in Apple Silicon Macs breaks encryption

'University researchers have found an unpatchable security flaw in Apple Silicon Macs, which would allow an attacker to break encryption and get access to cryptographic keys.
The flaw is present in M1, M2, and M3 chips, and because the failing is part of the architecture of the chips, there’s no way for Apple to fix it in current devices …'

#technology #tech #security #hacking #malware #encryption

https://9to5mac.com/2024/03/22/unpatchable-security-flaw-mac/

gcluley, to Cybersecurity
@gcluley@mastodon.green avatar

There’s a Bing ding dong, after Microsoft over-enthusiastically encourages Chrome users to stop using Google, and silence hits the British Library as it shares its story of a ransomware attack. Yes, it’s a new “Smashing Security” podcast with me and Carole Theriault.

Thanks to Kolide by 1Password, Vanta, and Kiteworks for supporting this episode!

https://grahamcluley.com/smashing-security-podcast-364/

#cybersecurity #podcast #ransomware #malware #databreach #britishlibrary #microsoft #bing #google #chrome

br00t4c, to random
@br00t4c@mastodon.social avatar

Fujitsu says it found malware on its corporate network, warns of possible data breach

#malware

https://arstechnica.com/?p=2010974

br00t4c, to random
@br00t4c@mastodon.social avatar

Fujitsu reveals malware installed on internal systems, risk of customer data spill

#malware

https://go.theregister.com/feed/www.theregister.com/2024/03/18/fujitsu_malware_data_breach/

remixtures, to Bulgaria Portuguese
@remixtures@tldr.nettime.org avatar

#EU #Cybersecurity #Spyware #Surveillance #Malware #Pegasus: "Now, when push has come to shove, policymakers at the European Union (EU) must act to ban spyware in Europe. Yesterday, the media reported a major attack on EU democracy with members of the European Parliament Defense Committee being the target of phone hacking. Intrusions of this kind pose a threat to democracy by interfering with electoral and decision-making processes and undermining the integrity of the public debate.

But such intrusions into privacy are nothing new. Journalists, human rights defenders and activists have been targeted for years by states with surveillance malware like Pegasus. Our democracies hinge on EU policymakers’ responsibility to create a protective EU-wide framework against spyware. With the 2024 elections approaching, will the EU politicians make the obvious choice of putting the safety of people and the integrity of our democracy first by banning spyware?" https://edri.org/our-work/press-release-brussels-rocked-by-major-spyware-scandal-urgent-call-for-ban/

TechDesk, to Cybersecurity
@TechDesk@flipboard.social avatar

Personal data and customer information may have been stolen from Japanese tech giant Fujitsu after it reported a cyberattack. The company is currently investigating how its network was compromised by malware.

https://flip.it/0yWCd9

KrzysztofKolacz, to AppleInc Polish

Apple chwali się, jak szczelny jest App Store pod kątem niedopuszczania do systemowego sklepu z aplikacjami tych, które służą oszustwom. No nie do końca, co pokazuje przykład scamerskiego portfela bitcoinów.

Na moich oczach z kont zostało pobranych 150 tys. USD po tym, jak wprowadziłem swoją frazę seed do tej fałszywej aplikacji z Apple Store. Nie mogę uwierzyć, że Apple pozwala na takie aplikacje w swoim App Store!d

– pisze jedna z osób, które padły ofiarą aplikacji Bitcoin Wallet – BTC Vault, na łamach Haker News.

https://imagazine.pl/wp-content/uploads/2024/03/BTC-Vault.png

Firma stojąca za nią nimi jest zarejestrowana w Nowej Zelandii, w przypadkowym Airbnb.

Cele atakujących są osoby przesiadające się z Androida na iOS (tzw. switcherzy). Po przeniesieniu wszystkich aplikacji chcą oni przenieść także swoje bitcoiny z androidowego portfela na jakiś odpowiednik w iOS.

Wpisałem frazę „portfel bitcoin” w Apple App Store, zainstalowałem pierwszą aplikację, którą zobaczyłem (wyglądała legalnie), przelałem bitcoiny i natychmiast zostały one wysłane donikąd. Okazuje się, że ta aplikacja została wcześniej zgłoszona co najmniej 12 dni temu jako oszustwo!

– relacjonuje kolejny poszkodowany. Mowa o zgłoszeniu na tym Reddit. Apple przez 12 dni zatem nic z tym zgłoszeniem nie zrobiło, a aplikacja wyświetlana jest (nadal!) jako pierwsza rekomendacja. Wyprzedzając inne, dobrze znane na rynku krypto portfele, jak binance, blockchain.com i coinbase.

Chętnie przeczytałbym komentarz Apple w tej sprawie.

https://imagazine.pl/2024/03/18/apple-dopuscilo-do-app-store-falszywa-aplikacje-okradajaca-ludzi/

#AppStore #malware #scam

image/png

gcluley, to Cybersecurity
@gcluley@mastodon.green avatar
tuneintodetuned, to EldenRing Spanish
@tuneintodetuned@mastodon.social avatar

Confirmado.
No juguéis a nada que use a menos que podáis deshabilitarlo y jugar por LAN como hicimos nosotros en .
Easy Anti-Cheat (en declive desde que fue comprado por ) ha sido demostrado como vulnerable a ejecución de código remoto durante el último torneo de , que ha quedado suspendido. Esto implica que se puede instalar sin vuestro consentimiento al estar jugando en una partida "protegida" por Easy Anti-Cheat.

https://www.ign.com/articles/apex-legends-global-series-tournament-abandoned-after-pros-hacked-mid-match

xro, to ads
@xro@chaos.social avatar

What's the problem with and ?

  • ads are information
  • ads are intentionally incorrect and misleading
  • ads are ubiquitous available information, to the point of being actively PUSHED onto every human reachable.
  • for many people who don't actively seek other sources, it is the main source of information.

That"s not a good basis for a where informed citizens are supposed to make good decisions.

publicvoit,
@publicvoit@graz.social avatar

@xro At least on the web, #malware gets distributed via the #advertisement propagation channels.

Therefore, an #adblocker + #NoScript add-on are mostly not for personal convenience but rather an important security feature.

As a side-effect, the web is faster and easier to consume without ads.

#security #ads

xro,
@xro@chaos.social avatar

@publicvoit

I was actually mainly thinking about TV ads, billboards, analog newspaper ads, mailbox leaflets or whole papers that pretend to be a newspaper but are in reality a big ad, 😅

since thanks to AdBlockers, WebAds have seized to be a problem for me.

But you are right, the WWW without AdBlockers is a dangerous and unusable mess. At least here on the Web we have a technical solution against ads.

gcluley, to Cybersecurity
@gcluley@mastodon.green avatar

LockBit affiliate Mikhail Vasiliev jailed for almost four years after guilty plea.

Read more in my article on the Tripwire blog: https://www.tripwire.com/state-of-security/lockbit-affiliate-jailed-almost-four-years-after-guilty-plea

#cybersecurity #ransomware #malware #lockbit

YourAnonRiots, to github Japanese

🚨 Alert: A new phishing campaign uses a Java-based downloader to distribute VCURMS & STRRAT RATs, leveraging public services like AWS & #GitHub for #malware hosting.

https://thehackernews.com/2024/03/alert-cybercriminals-deploying-vcurms.html

#hacking #cybersecurity

YourAnonRiots, to random Japanese

Tools of the Trade: Anti- scanning, WAFs, and sandboxing alone aren't sufficient for protecting against malicious uploads.

https://thehackernews.com/2024/03/demystifying-common-cybersecurity-myth.html

YourAnonRiots, to Cybersecurity Japanese

⚠️ Hackers are getting faster! Magnet Goblin, a threat group known for fast exploitation of 1-day vulnerabilities, targets edge devices & public servers to deploy #malware like Nerbian RAT.

https://thehackernews.com/2024/03/magnet-goblin-hacker-group-leveraging-1.html

#cybersecurity #hacking

YourAnonRiots, to Cybersecurity Japanese

🔒Alert: Cybercriminals weaponizing vulnerabilities in JetBrains TeamCity software to deploy BianLian #ransomware for extortion attacks.

https://thehackernews.com/2024/03/bianlian-threat-actors-exploiting.html

#malware #cybersecurity

YourAnonRiots, to infosec Japanese

⚠️ Beware of fake DocuSign emails – they're designed to trick you into downloading the New CHAVECLOAK Android banking #malware.

What it does:

  • Hijacks your screen
  • Logs your keystrokes
  • Uses fake pop-ups to capture your banking logins

https://thehackernews.com/2024/03/new-banking-trojan-chavecloak-targets.html

#infosec

blogdiva, to tv
@blogdiva@mastodon.social avatar

ok, so my sons bought a heavily discounted "smart" last xmas. a TCL with Roku plastered all over the box.

is there a way to root these tvs and wipe their OS?

https://www.wired.com/story/roku-terms-of-service-update-locks-tv/

rooting and changing the OS of smart anything, especially phones, need to be at the center of the right to repair movement, not just getting access to software drivers or hardware.

PS: i have avoided activating the Roku nonsense exactly for what the article describes.

btaroli,
@btaroli@federate.social avatar

@blogdiva This all #marketing and #profit bullshit. These huge “smart” TVs are so cheap, but that’s only because they’re burdened with #malware and #spyware. Try pricing a “dumb” display at that size.

Then you realize this is like an ISP renting you their hardware at a discount or charging you four times more every month to bring your own. There’s a reason they want their device in your home and it’s not a benefit to you. So they create financial #incentive give to make you do it. #RESIST!

kubikpixel, (edited ) to internet German
@kubikpixel@chaos.social avatar

Jetzt wo ihr alle auf eine und offene Plattform für gewechselt seid, das , könnt ihr z.B. bei den weiter machen.

🔎 @MetaGer
🔎 @Mojeek
🔎 @monocles
🔎 https://gruble.de

Ne du, so was wie , & liefern Daten ihrer Crawler wie (M$) und/oder . Pseudonymisiert ist nicht anonym, denn die sind vertraglich dazu verpflichtet.

kubikpixel,
@kubikpixel@chaos.social avatar

🧵…siehe in den obigen Toots/Posts weshalb ich Google schon länger nicht mehr nutze und deswegen welche Alternativen ich im #Internet gebrauche und empfehle.

«Googles neue KI-Suchergebnisse promoten Scam und Malware:
Google ergänzt seine #Suche'rgebnisse jüngst mit #KI-generierten Inhalten wie Zusammenfassungen. Jetzt mehren sich die Warnungen, dass über dieses System auch #Scam und #Malware beworben werden. Der KI-Suchalgorithmen von #Google scheinen unterwandert.»

🤖 https://winfuture.de/news/141915

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • GTA5RPClips
  • tacticalgear
  • normalnudes
  • tester
  • osvaldo12
  • everett
  • cubers
  • ethstaker
  • anitta
  • provamag3
  • Leos
  • cisconetworking
  • lostlight
  • All magazines