App Leaks Thousands of Baby Photos and Videos Online

App Leaks Thousands of Baby Photos and Videos Online

An app designed to record and share milestones in a child’s development has leaked thousands of images and videos of babies online.

Bithouse Inc., the developer of the Peekaboo Moments app, failed to secure a 100 GB Elasticsearch database containing more than 70 million log files dating from March 2019. As a result, information including email addresses, geographic location data, detailed device data, and links to photos and videos has been exposed.

The breach was discovered by Dan Ehrlich, who operates Texas-based computer security consulting firm Twelve Security.

Ehrlich estimates that at least 800,000 email addresses are in the exposed data, which is stored on servers hosted by Singapore-based Alibaba Cloud.

“I’ve never seen a server so blatantly open,” Ehrlich told Information Security Media Group. “Everything about the server, the company’s website and the iOS/Android app was both bizarrely done and grossly insecure.”

Peekaboo Moments, which appears to be run by a company based in China, allows parents to record their baby’s birth date and track the infant’s length and weight. Now parents will be able to use it to record an unexpected milestone—their baby’s first ever data breach.

The free app claims to take the security of users’ data seriously and to offer users a “secured space” in which to record their child’s precious moments. The company makes money by offering additional storage, with subscription plans starting at $8.99 per quarter.

On its Google Play app profile page, it states: “Data privacy and security come as our priority. Every Baby’s photos, audios & videos or diaries will be stored in secured space. Only families & friends can have access to baby’s moments at your control.”

The length of time the Elasticsearch server has been unsecured or who may have accessed its contents are unclear. 

Information Security Media Group said that repeated efforts to contact Peekaboo Moments CEO Jason Liu—based in San Francisco, according to his LinkedIn profile—have drawn a blank. 

Attempts to contact the company and other Peekaboo employees have also proved unsuccessful.

According to Google Play, the Peekaboo Moments app has been downloaded 1 million times since launching in 2012.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Play Store Still Peppered with Fleeceware Apps

Play Store Still Peppered with Fleeceware Apps

Four months after fleeceware’s initial exposure, Android users who purchase “subscriptions” to apps from the Google Play Store are still at risk of being ripped off.

Fleeceware hit the news in September 2019, when researchers at SophosLabs showed how some app publishers were using a sneaky business model to drastically overcharge Android users for basic services. 

On the Google Play Store, researchers found multiple instances of app publishers operating a system where users could be charged excessive amounts of money for apps if they didn’t cancel a “subscription” before the short free trial window closed.

New research published today by SophosLabs reveals that fleeceware has not been shorn from the store. 

“While the company did take down all the apps we had previously reported to them, fleeceware remains a big problem on Google Play,” wrote researchers.

“Since our September post, we’ve seen many more Fleeceware apps appear on the official Android app store.”

New fleeceware flagged by SophosLabs includes entertainment or utility apps, fortune-telling apps, instant messengers, video editors, and beauty apps. 

Some apps, offering basic services such as a reverse-image search, which Google does for free, charge over $200 for an annual subscription. 

Researchers said that the total number of installations of these apps totals nearly 600 million across fewer than 25 apps. Some of the individual apps on the store appear to have been installed on more than 100 million devices.

One popular keyboard app investigated by researchers allegedly transmits the full text of whatever its users type back to China. 

Clues to the fleeceware apps’ financial chicanery can be found in customers’ reviews.

“User reviews reveal serious complaints about overcharging, and that many of these apps are substandard, and don’t work as expected,” wrote researchers. 

Some users claim to have been charged an annual subscription fee despite unsubscribing by a certain date as per the app’s instructions. 

Researchers noted apps offering weekly and monthly subscription payment options in an attempt to make their product seem more budget friendly. 

“In one case, we found an app displaying subscription fees of €8.99 per week, or €23.99 per month, which works out annually to €467.48 (if you pay the weekly amount for 52 weeks) or €287.88 (if you pay the monthly amount for 12 months),” wrote researchers. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Texan Arrested for Cyber-stalking Realtors and Threatening Their Kids

Texan Arrested for Cyber-stalking Realtors and Threatening Their Kids

A Texas man has been arrested on suspicion of sending perverse and threatening text messages to real estate agents across America.

Lubbock resident Andy Castillo allegedly used multiple phone numbers and an app to mask his identity when cyber-stalking as many as 100 realtors in up to 22 different states. 

The 56-year-old is accused of sending pornographic images to agents along with sexually explicit text messages soliciting sex. It is further alleged that Castillo attempted to solicit sex from some agents’ children. 

Castillo is accused of downloading photographs of agents’ kids from social media and sending the pictures to the agents, along with chilling descriptions of his desire to sexually assault their children.

All the real estate agents targeted in this particularly disturbing cyber-stalking case are women. 

Detective Joseph Scaramucci said Castillo “was searching the top 10 realtors in different cities” and “saving female realtors’ photographs right off the internet with their contact information.”

Castillo was arrested in his apartment last week and taken into custody by McLennan County Sheriff’s Office (MCSO). Authorities seized two cellphones and an electronic tablet belonging to Castillo.

Deputies allege that just five minutes prior to his arrest, Castillo sent lewd and threatening messages to people in San Francisco and New Orleans.

McLennan County sheriff Parnell McNamara said the MCSO began investigating Castillo in late December 2019 after receiving complaints from seven Waco-based realtors about pornographic images and messages that they had received from unknown numbers.

The results of the investigation suggest Castillo sent sexually explicit and threatening messages to women in at least twenty cities in ten different states. However, McNamara said Castillo could have stalked hundreds of women in up to 22 states and that he is expecting further victims to come forward.

Currently, Castillo is accused of cyber-stalking agents throughout Texas, including in Amarillo, El Paso, Lubbock, San Antonio, and Waco. The Texan is facing a second-degree felony charge of criminal solicitation with intent to commit aggravated sexual assault of a child.

Police are investigating reports of similar cyber-stalking behavior that have been filed in Tucson, Arizona; Anaheim, Berkeley, Irvine, San Jose, and Santa Clara, California; Broward County and Daytona Beach, Florida; New Orleans, Louisiana; Reno, Nevada; Albany and Manhattan, New York; Belfort, South Carolina; Seattle, Washington; and Washington, D.C.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Most Firms Still on Windows 7 as Support Deadline Arrives

Most Firms Still on Windows 7 as Support Deadline Arrives

Two-thirds of UK businesses and two-fifths of US firms are still running Windows 7, according to new research released on the day the operating system, and Windows Server 2008, reach their end-of-support deadline.

Organizations that fail to upgrade their operating systems or invest in costly extended support from Microsoft will no longer receive patches from the vendor, exposing themselves to unnecessary cyber risk, according to Kollective, which issued the research.

“It took many businesses up to three years to move from XP to Windows 7 and we can expect a similar timeline for the move to Windows 10. While a lot of companies have migrated the majority of their systems away from Windows 7, being “almost there” isn’t good enough,” argued Jon O’Connor, solution architect at Kollective.

“It only takes a handful of unsecured devices to launch a full-scale cyber-attack, so having even one or two Windows 7 PCs on your network could pose a serious risk. IT teams need to know for certain that every single device on their networks is off of Windows 7 — but the reality is that most simply don’t know.”

As if to emphasize the potential risks of staying on unsupported operating system versions, news emerged this week that Microsoft is shipping a fix today for a critical flaw in a core Windows component, which could have wide-ranging consequences if left unpatched. The bug is so bad that reports suggest Redmond has already secretly supplied the patch to high-value customers.

Carl Wearn, head of e-crime at Mimecast, urged organizations to ensure they have third-party security tools in place to help shield any exposure to threats.

“As organization’s move their operations to the cloud, legacy support issues like this will likely become a thing of the past in the next 10 to 15 years, but as Windows 7 remains in use across many organisations at present people should be aware of the increased vulnerability which this OS will now experience as it is no longer supported,” he continued.

“Ensuring good cyber hygiene and the use of fallback facilities, as-well as ensuring the updating of a good antivirus solution, becomes even more critical to an organization if it continues to use an unsupported OS.”

Trend Micro argued that “virtual patching,” or intrusion prevention technology, can also help in these circumstances, by protecting unsupported and unpatched operating systems.

“Speaking to numerous businesses over recent weeks, a worryingly high number are prepared to adopt a wait-and-see policy following the end of Server 2008 support on 14 January 2020,” argued VP of sales, Ross Baker.

“This amounts to an extreme hedging of bets and something we would definitely not recommend.”

Some organizations may not be able to upgrade to new OS versions if they have compatibility issues with business-critical legacy applications, or, for example, if Windows has been embedded in OT systems by a manufacturer, added VP of security research, Rik Ferguson.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Texas School District Loses $2.3m in Phishing Raid

Texas School District Loses $2.3m in Phishing Raid

A Texas school district has found out the hard way that phishing attacks remain a serious financial threat to organizations of all shapes and sizes, losing an estimated $2.3m in a recent scam.

Manor Independent School District took to Twitter to post official confirmation that the FBI is currently investigating the incident.

“This investigation is still ongoing and although there are strong leads in the case we are still encouraging anyone with information to contact Detective Lopez at the Manor Police Department,” it added.

According to reports, three separate fraudulent transactions took place in November last year following the phishing attack, although there are few other details to go on.

The news comes as school districts in the US battle against a growing threat from ransomware.

Data released by Armor in December 2019 revealed that 72 districts had been impacted during the year, affecting an estimated 1039 schools nationwide. Separate findings from Emisoft released at the end of the year claimed as many as 1224 schools may have been affected.

Javvad Malik, security awareness advocate at KnowBe4, argued that employee error needs to be addressed more effectively by organizations at risk of phishing attacks.

“Cyber-criminals will attack organizations with the intention of getting the highest return on investment. Usually this translates into social engineering attacks, which are in essence cons against people to do things against the interest of the company,” he added.

“This usually occurs in the form of phishing emails, but can also be SMS messages or phone calls. Therefore, organizations should take time to invest in security awareness and training so that they can be better-prepared to identify and report any suspicious activity.”

Ed Macnair, CEO of Censornet, argued that in failing to mitigate the risk of phishing, the Texas school district also potentially exposed its 10,000 pupils to data theft.

“There is no doubt about the importance of training employees to recognize these modern phishing techniques. Unfortunately, emotions often take over from reason in these situations and no amount of training can account for this,” he added.

“Employee awareness therefore needs to be combined with a robust, multi-layered approach to email security. Traditional pattern matching technologies are useless against modern techniques and organizations need to combine algorithmic analysis, threat intelligence and executive name checking to efficiently protect themselves.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Aussie Bushfires Donation Site Hit by Magecart Thieves

Aussie Bushfires Donation Site Hit by Magecart Thieves

A website set-up to accept donations for victims of the devastating Australian bushfires has become a victim itself — of digital skimming code designed to harvest card details.

Security researchers at Malwarebytes took to Twitter to reveal the problems that hit the unnamed donations site, which was raising money for those affected by fires in Lake Conjola that have destroyed scores of homes.

In such Magecart-style attacks, hackers typically inject malicious JavaScript into payment pages to harvest card and personal data as it is entered in by shoppers, or in this case, donators to a worthy cause. It is then exfiltrated to an external domain under the attackers’ control.

It’s a tried-and-tested method for data theft that lands the attackers with a complete set of information for each victim, worth more on the dark web than individual components.

In this incident, the malicious script in question was identified as “ATMZOW” and the known bad domain it exfiltrated data to was spotted as vamberlo[.]com.

Replying to the post on Twitter, Troy Mursch of security firm Bad Packets claimed that the same malicious script had been identified targeting an additional 39 separate websites.

Deepak Patel, security evangelist at PerimeterX, argued that Magecart attackers have hit new lows with this latest raid.

“Given the lack of visibility into such client-side attacks, the website owners often find out about the data breach days or weeks after the code injection. This extended time allows skimmers to monetize the stolen cards to the fullest extent,” he explained.

“Any site that processes user PII and accepts payments should take steps to shore up their application security by tracking and monitoring first- and third-party code execution on their sites in real time.”

RiskIQ last year claimed to have identified over two million Magecart detections in the wild — a sign of its growing popularity among black hat data thieves.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk