Cyber-Criminals Target Naked Zoom Users

Cyber-Criminals Target Naked Zoom Users

Cyber-criminals have launched a new sextortion scam aimed at people who use the video-conferencing app Zoom while in a state of undress. 

The scam, detected by Bitdefender Antispam Lab, appears to have originated on October 20, just after high-profile reporter and TV analyst Jeffrey Toobin was caught masturbating during a Zoom video chat with members of the New Yorker and WNYC radio.

Bitdefender reported that a quarter of a million people, mostly in the United States, received an email informing them that they have been filmed engaging in a sexual act while using Zoom. Victims were then threatened with exposure of the footage if they didn’t pay a ransom.

The email, titled “Regarding Zoom Conference call,” claims that the attacker exploited a zero-day vulnerability to access the victim’s private data. 

“You have used Zoom recently, like most of us during these bad COVID times. And I have very unfortunate news for you,” reads the email.

“There was a zero-day security vulnerability on Zoom app that allowed me a full time access to your camera and some other metadata on your account.”

The attacker then claims that while making recordings “just for fun,” they “have made a recording, where you work on yourself.”

Bitdefender’s Alina Bizga noted: “The extortionist has clearly done his homework. Multiple zero-day vulnerabilities have been reported this year, including some that even allow a full takeover of devices.”

After claiming to be in possession of compromising images of their victim, the attacker then presents themself as a victim of the impact of COVID-19.

“I got very sick, lost my job, about to be evicted and have no money to survive. All of this because of the stupid virus,” writes the attacker.

“I’m sorry. I have no other choice.”

The scammer then demands a $2,000 ransom in Bitcoin to be paid within three days if the victim doesn’t want the footage to be made public. 

“I do not want you to be the next Jeffrey Toobin,” writes the attacker. “I’m sure you don’t want to be embarrassed.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ping Identity Acquires Symphonic to Boost API and Data Security Offering

Ping Identity Acquires Symphonic to Boost API and Data Security Offering

Ping Identity has announced the acquisition of Symphonic Software, a provider of dynamic authorization for protecting APIs, data, apps and resources through identity.

After partnering for two years, a partnership which paired Symphonic’s authorization platform with Ping’s data privacy and consent products, the combining of the companies will allow users to centralize administration and enforcement to critical resources and data for all types of users, applications and devices.

This will also permit IT team flexibility to control what users can see and do, enabling better fraud prevention and overall compliance.

“With increasing data privacy regulations, users are demanding that enterprises give them better digital experiences with more transparency and control,” said Andre Durand, CEO and founder of Ping Identity. “The acquisition of Symphonic accelerates our vision for enterprises to not only maintain security and compliance with confidence, but to easily deliver personalized, trustworthy experiences.”

Symphonic said that when integrated with the broader Ping Intelligent Identity Platform, enterprise customers can cover advanced authorization scenarios that go beyond typical user roles and entitlements, as dynamic authorization extends their identity platform with policies that leverage context, risk and consent, allowing enterprises to deliver more secure experiences with faster time-to-market.

“For the past two years Symphonic has worked alongside Ping to make policy management easy for enterprises,” said Derick James, CEO of Symphonic. “Ping Identity’s dedication to customers aligns well with Symphonic’s values, and we are thrilled to continue our journey together as one.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Truata and Mastercard Launch Privacy-Enhanced Portal for Financial Institutions

Truata and Mastercard Launch Privacy-Enhanced Portal for Financial Institutions

Truata has announced the launch of a new privacy-enhanced self-service analytical portal for financial institutions in partnership with Mastercard.

The agreement will enable Mastercard customers to analyze customer data in a way that is fully anonymized and compliant with data protection regulations.

The Privacy Enhanced Analytics Platform utilizes business intelligence KPI dashboards and machine learning models, which track measurement and performance on consumer clearing data, thereby offering end user insights such as spending attrition, card usage, travel payments and details on recurring payments. It is built on the actions of past and present customers, whether they consented or not, but who are kept anonymous.

Truata’s solution aims to balance the desire of banks to modernize and enhance their services through data analytics with customers’ privacy.

Felix Marx, chief executive officer at Truata, commented: “For banks and financial services to grow and prosper in today’s highly competitive climate, they need to generate insights from their customer data. However, it is paramount that this is done in a way that is ethical, preserves consumer privacy and adheres to data protection regulations.

“Placing the individual at the center of everything it does, Mastercard’s commitment to privacy by design is reflected in the way it embeds privacy and individuals’ rights, needs and interests into the design and operation of all its products, services and technologies. We’re honored to provide our data anonymization services to Mastercard’s customers.”

Gurpreet Atwal, Mastercard’s senior VP, data and services, added: “We know how important data is to our issuing banks, but we also know the importance of privacy to individuals. That’s why we’ve worked closely with Truata, drawing upon its proprietary technology and expertise in data anonymization and analytics, to bring the Privacy Enhanced Analytics Platform to the market.

“This move is part of our commitment to promoting the responsible use of data. Working with Truata enables our customers to close their analytical gaps in a GDPR-compliant way.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

The BBC Experiences Over 250,000 Malicious Email Attacks Per Day

The BBC Experiences Over 250,000 Malicious Email Attacks Per Day

The British Broadcasting Corporation (BBC), the UK’s public service broadcaster, faces in excess of a quarter of a million malicious email attacks every day, according to data obtained by Parliament Street following a Freedom of Information (FoI) request.

The think tank revealed that the corporation blocked an average of 283,597 malicious emails per day during the first eight months of 2020.

According to the data, every month the BBC receives an average of 6,704,188 emails that are classified as scam or spam as well as 18,662 malware attacks such as viruses, ransomware and spyware. In total, 51,898,393 infected emails were blocked in the period from January to August 2020.

The month which contained the highest amount of recorded incidents was July, when the BBC received 6,787,635 spam and 13,592 malware attempts. The next highest was March, when the COVID-19 first struck the UK, with 6,768,632 spam emails and 14,089 malware attacks.

In March, an analysis by Barracuda Networks found that phishing emails went up by 667% as a result of the pandemic, as cyber-criminals looked to capitalize on the fear and uncertainty brought about by the crisis.

The BBC has been on the receiving end of numerous cyber-attacks in the past. This includes in 2013 when sympathizers of Syrian President Bashar Assad took control of several of its Twitter accounts to post messages and send phishing emails around its staff.

Tim Sadler, CEO of Tessian, commented: “The global pandemic has become a ripe opportunity for phishing scams, and we can clearly see that in reflected in the spike of malicious attacks on the BBC. In the wake of the outbreak, journalists and employees would have been busier and more distracted than usual.

“Using clever social engineering techniques, cyber-criminals prey on people’s desire for information during uncertain times, and bank on the fact that busy, distracted and stressed employees may miss the signs of a phishing email and fall for their scams. Organizations, therefore, must have security measures in place to automatically predict such email threats and warn people before they click or download an attachment.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Security Pros Have Role in Combatting Disinformation

Security Pros Have Role in Combatting Disinformation

The COVID-19 pandemic has provided much greater opportunities for the use of disinformation to trick people into making bad decisions, according to a panel speaking on a recent webinar entitled Duped, Deluded, Deceived: How Disinformation Defrauds You.

The panellists firstly highlighted how the definition of ‘disinformation’ encompasses many common tactics used by cyber-criminals, including phishing, in which victims are duped by information that is designed to mislead.

The surge in these types of attacks this year has partly been as a result of businesses and individuals operating in new environments, in particular the shift to home working in which people are less protected by corporate networks. Niamh Muldoon, EMEA senior director in trust and cybersecurity at One Login said: “During times of uncertainty people are taken out of their comfort zone, they’re using new technologies to keep their businesses moving forward, and accessing systems and data in new ways and therefore it increases the risks and threats around uncertainty around how to operate from a security perspective.”

Another issue is that people are far more distracted by worries and fears in this period, and therefore more susceptible to clicking on bad URLs or being tricked into handing over personal details. Malicious actors have stayed abreast of new trends to effectively play on people’s emotions, with Theresa Lanowitz, head of communications at AT&T Cybersecurity, observing that the focus has continually shifted, covering areas such as the health impact, government stimulus packages, social unrest and vaccines. “Cyber-criminals, in this very well co-ordinated business model they have, follow current events,” she noted.

As well as using disinformation to commit cybercrime, this method is increasingly being utilized as a tool to spread misinformation online, something that has been highlighted during the current US election cycle. This has been brought about by the growing reliance on the internet and social media for information, which has been exacerbated by the COVID-19 pandemic, as well as celebrity culture.

Raj Samani, chief scientist and research fellow, McAfee, commented: “Today with the advent of social media, the construct of who we see as authoritative has fundamentally changed. We’ve seen alternative authoritative figures pushing miseducation which we’ve now categorized as misinformation.” He highlighted the conspiracy theory that 5G was causing the coronavirus, which was endorsed by certain public figures.

This problem of misinformation has been worsened by the growing division and tribalism in countries like the US over recent years, leading to much greater confirmation bias. “We need to have more education for the public on verifying information,” stated Tim Helming, security evangelist at DomainTools. This includes double checking sources and the stories themselves.

Combatting the fake news phenomenon is therefore part of the job of cybersecurity professionals, according to Muldoon. “We do have a role in the technology platforms that provide that information and validating the identity of the person that is sharing it. That’s where I believe our role comes in and making sure the controls are in place within platforms to validate the integrity of the data being shared.”

To effectively tackle the overall issue of disinformation, education and understanding is the key. Organizations can help in this regard by building a security first mindset throughout their staff, with these learnings and habits spilling out into their home lives as well. “You can tie security to business outcomes and objectives,” explained Lanowitz. “You want to set that culture at the top and have that shared responsibility model where the C-suite is leading by example and showing people what to do.”

To achieve this, first and foremost, establishing an environment which encourages people to come forward when they see anything suspicious or even when they have been tricked is critical. Helming added: “If you create a culture that intimidates and shames people for doing something like that, they’re not going to want to come forward.”  

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

CERT/CC Aims to Tackle FUD with New CVE-Naming Bot

CERT/CC Aims to Tackle FUD with New CVE-Naming Bot

Security experts at the CERT Coordination Center (CERT/CC) have begun a new initiative designed to tackle the rise in sensationalist naming of vulnerabilities.

Its “vulnonym” project will publish to Twitter neutral names associated with CVEs as they are issued.

CERT researcher, Leigh Metcalf, argued that although humans find it easier to relate to and remember names rather than numbers, threat researchers and their marketing teams often go too far with names like “Spectre” and “Heartbleed.

“Not every named vulnerability is a severe vulnerability despite what some researchers want you to think. Sensational names are often the tool of the discoverers to create more visibility for their work,” she added.

“This is an area of concern for the CERT/CC as we attempt to reduce any fear, uncertainty, and doubt for vendors, researchers, and the general public.”

As a result, CERT/CC will create what it hopes to be the de facto name for each CVE that is published.

“Our goal is to create neutral names that provides a means for people to remember vulnerabilities without implying how scary (or not scary) the particular vulnerability in question is. Our neutral names are generated from the CVE IDs to provide a nice mapping between name and number,” said Metcalf.

“The CERT/CC decided that if we can come up with a solution to this problem, we can help with discussions about vulnerabilities as well as mitigate the fear that can be spread by a vulnerability with a scary name. We plan to name the vulnerabilities with a phrase of adjective noun, for example, Arbitrary Albatross.”

Vulnonym is effectively a bot generating names from various lists of animals, plants, objects in space and other categories, and using the “Cantor Depairing Function” to map them to the relevant CVE IDs.

It remains to be seen whether these names actually stick. Already the bot has come up with some curious-sounding monikers including “Bottomless Whistler,” “Foamy Waka,” “Guarded Puffer” and “Pelleted Quetzal.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Banks Face Consumer Frustration Over Digital Identity Management

UK Banks Face Consumer Frustration Over Digital Identity Management

UK banks are facing consumer frustration over customer identity management, according to a new study from global analytics software provider FICO.

The survey of 172 banks across eight countries – conducted by independent research firm OMDIA – discovered that consistency of identity validation across digital channels is a challenge for 54% of UK banks.

For example, whilst 72% of UK banks use digital methods to capture identity for personal bank accounts, only 36% said they capture customer identities and verify them in the same channel, the study claimed. Such lack of integration – which often forces users to download further apps or scan and email documents to verify details – leaves clients much more likely to abandon an application and highlights that current identity verification methods are not fit for purpose in the digital age, FICO said.

Banks in the UK also noted challenges around authentication of existing customers, including complying with legislation, with a lack of up-to-date customer information such as mobile numbers noted as further inhibiting streamlined customer and payment verification.

“Historically, identity solutions were developed for face-to-face interactions and have since been adapted to the needs of new channels and products,” explained Sarah Rutherford, senior director of identity fraud marketing at FICO. “As digital interaction is accelerated by the impact of COVID-19, it exposes the weaknesses inherent in using identity verification processes that were not intended for digital channels.”

Banks therefore need to move fast to work out how identity fits into their digital on boarding and authentication strategies, Rutherford added.

“The fragmented approach is impacting the customer experience. The benefits of moving to a single identity infrastructure across all channels and product lines should be assessed as a matter of priority. This approach reduces unnecessary friction and confusion for customers, avoids multiple copies of documents being held across the institution and facilitates faster on-boarding of cross-sell opportunities.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

North Korean Malware Helps Hackers Target #COVID19 Vaccines

North Korean Malware Helps Hackers Target #COVID19 Vaccines

Security researchers have discovered new North Korean malware being used to drive information-stealing attacks against COVID-19 vaccine makers and other targets.

Cybereason Nocturnus said it had been able to track new attack infrastructure linked to the prolific Kimsuky group via BabyShark and AppleSeed malware previously attributed to it.

The new domains created as part of this push were all registered to the same IP address responsible for BabyShark attacks, the vendor said.

Whilst investigating, it uncovered a new malware suite dubbed “KGH” spread via weaponized Word documents in phishing emails and containing multiple spyware modules. Recipients are encouraged to open the attachment, which purports to contain either an interview with a North Korean defector or a letter addressed to former Japanese Prime Minister, Shinzo Abe.

KGH’s infostealer module, which remained undetected by AV tools at the time of writing, harvests data from browsers, Windows Credential Manager, WINSCP and mail clients.

Separately, Cybereason detected a new downloader, “CSPY,” which it said “is packed with robust evasion techniques meant to ensure that the ‘coast is clear’ and that the malware does not run in a context of a virtual machine or analysis tools before it continues to download secondary payloads.”

After payloads are downloaded they are removed and renamed, the main payload masquerades as a legitimate Windows service, and exploits a known UAC bypass technique using the SilentCleanup task to execute the binary with elevated privileges.

Cybereason uncovered additional efforts designed to confound white hat researchers, including the manipulation of timestamps and file compilation data to thwart forensics. In this case, most files were falsely backdated to 2016.

Alongside COVID-19 vaccine makers, the group has apparently targeted the UN Security Council, South Korean government, research institutes, think tanks, journalists and the military.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Gold Bullion Seller Hit by Magecart Attack

Gold Bullion Seller Hit by Magecart Attack

A leading online gold retailer has revealed to customers that its website was hit by a Magecart-style data breach several months ago.

Dallas-headquartered JM Bullion describes itself as one of the largest sellers of precious metals in the world, with sales exceeding $3bn over the past eight years.

However, according to a breach notification letter sent to customers which was posted to Reddit, the card details used to make some of those sales may have been skimmed by attackers earlier this year.

“On July 6, 2020, JM Bullion was alerted to suspicious activity on its website. JM Bullion immediately began an investigation, with the assistance of a third-party forensic specialist, to assess the nature and scope of the incident,” the notice read.

“Through an investigation, it was determined that malicious code was present on the website from February 18, 2020 to July 17, 2020, which had the ability to capture customer information entered into the website in limited scenarios while making a purchase.”

JM Bullion confirmed that the unspecified malicious code was removed from its website on July 17, but question marks will remain over why it took the firm five months to discover the presence of malware on its systems and then several more months to notify customers.

Although it claimed that only “a small portion of the transactions processed on JM Bullion’s website during the impacted time frame” were taken, the stolen details included names, addresses, account numbers, expiry dates and security codes.

That’s enough to carry out e-commerce fraud which would be difficult for many merchants’ filters to spot.

There appears to have been a surge in digital skimming attacks in 2020 as global COVID-19 lockdowns forced more consumers online. In September the largest ever Magecart campaign was spotted after 2000 e-commerce stores running Magento software were attacked in a single weekend.

There appears to be no confirmation of the incident on the JM Bullion site.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk