Government Experts in Last Minute Seasonal Scam Warning

Government Experts in Last Minute Seasonal Scam Warning

The National Cyber Security Centre (NCSC) has made one final plea to consumers ahead of the busiest shopping weekend before Christmas to be alert to fraud and data theft attempts.

The GCHQ agency urged shoppers to protect their devices, be aware of unsolicited messages and minimize the amount of information they input into e-commerce sites.

According to banking body UK Finance, nearly £22bn was spent online on Christmas shopping last year due to COVID-19: over a third (34%) of all card spending in December. With the Omicron variant surging, 2021 will likely witness a repeat show, exposing more consumers to online scams.

These can take many forms, including phishing emails containing fake shipping notifications and warnings about compromised accounts or fake gift cards requiring the recipient to share personal information to ‘redeem’ them.

Consumers may also be approached online via emails and social media messages with “too good to be true” offers for discounted popular gift items, including electronics. If they fall for these, the victims not only lose the money spent on the non-existent item, but their bank or card details will also end up in the hands of the threat actors.

The NCSC said the last-minute rush to buy presents online before the Christmas delivery deadline peaks this Saturday, making many shoppers more vulnerable to such scams.

“The good news is that there are common signs of a scam that people can look for, for example offers that seem too good to be true or claim that particular items are in short supply,” said NCSC director for policy and communications, Nicola Hudson.

“To protect themselves, there are practical steps people can take, from setting a strong password on accounts to researching a brand before buying – much more can be found on this on the NCSC’s website.”

The NCSC urged consumers to use strong, unique passwords and two-factor authentication for all accounts, especially email, banking and payment services.

It advised shoppers to ignore unsolicited messages, especially ones with links to websites, and to pay via credit card as purchases should be protected this way. The agency also recommended that shoppers check out as a “guest” to avoid spending too many personal details with e-commerce firms.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Log4j Looms Large Over Patch Tuesday

Log4j Looms Large Over Patch Tuesday

IT teams knocked for six by a newly disclosed Log4j bug were forced to tackle a new patch load from Microsoft released yesterday, containing 67 new flaws including six zero-days.

The monthly Patch Tuesday release from the computing giant couldn’t have come at a worse time for sysadmins already struggling to find and patch the Apache logging utility instances across their environments.

“Efforts to identify, mitigate, or remediate the Apache Log4j vulnerability continue. In this case it is leaving a lot of teams frustrated, not knowing exactly what they need to do,” argued Ivanti VP of product management, Chris Goettl.

“Apache Log4j is a development library, so you cannot just patch a specific JAR file and call it a day. It falls to your development team or the vendors whose products you may be using.”

He singled out zero-day bug CVE-2021-43890, a spoofing vulnerability in Windows AppX Installer, as the most important for organizations to fix this month. The flaw has apparently been exploited in the wild alongside malware from the Emotet/Trickbot/BazarLoader family.

The five other zero-days have yet to be exploited, but as they’ve been made public, the clock will be ticking.

They can be found in the Encrypting File System (CVE-2021-43893), Windows Installer (CVE-2021-43883), Windows Mobile Device Management (CVE-2021-43880), Windows Print Spooler (CVE-2021-41333) and NTFS Set Short Name (CVE-2021-43240).

“The disclosures include a functional example in the case of the Print Spooler, proof-of-concept for the NTFS and Windows Installer vulnerabilities, so there is some cause to put urgency on the OS updates this month,” said Goettl.

Kev Breen, director of cyber threat research at Immersive Labs, called out CVE-2021-43215, an iSNS Server Memory Corruption vulnerability which can lead to remote code execution and has a CVSS score of 9.8.

However, the good news is that not all organizations run iSNS by default.

“It is a client-server protocol that allows clients to query an iSNS database. To exploit this vulnerability, an attacker only needs to be able to send a specially crafted request to the target server to gain code execution,” said Breen.

“As this protocol is used to facilitate data storage over the network, it would be a high priority target for attackers looking to damage an organization’s ability to recover from attacks like ransomware. These services are also typically trusted from a network perspective – which is another reason attackers would choose this kind of target.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Quizzes and Other Identity Theft Schemes to Avoid on Social Media

Before you take the fun-looking quiz that popped up in your social media feed, think twice. The person holding the answers may be a hacker. 

Where people go, hackers are sure to follow. So it’s no surprise hackers have set up shop on social media. This has been the case for years, yet now social media-based crime is on the rise. In 2019, total reported losses to this type of fraud reached $134 million. But reported losses hit $117 million in just the first six months of 2020, according to the U.S. Federal Trade Commission (FTC). 

Among these losses are cases of identity theft, where criminals use social media to gather personal information and build profiles of potential victims they can target. Just as we discussed in our recent blog, “Can thieves steal identities with only a name and address?” these bits of information are important pieces in the larger jigsaw puzzle that is your overall identity. 

Let’s uncover these scams these crooks use so that you can steer clear and stay safe. 

A quick look at some common social media scams 

Quizzes and surveys 

“What’s your spooky Halloween name?” or “What’s your professional wrestler name?” You’ve probably seen a few of those and similar quizzes in your feed where you use the street you grew up on, your birthdate, your favorite song, and maybe the name of a beloved first pet to cook up a silly name or some other result. Of course, these are pieces of personal information, sometimes the answer to commonly used security questions by banks and other financial institutions. (Like, what was the model of your first car?) With this info in hand, a hacker could attempt to gain access to your accounts.  

Similarly, scammers will also post surveys with the offer of a gift card to a popular retailer. All you have to do is fork over your personal info. Of course, there’s no gift card coming. Meanwhile, that scammer now has some choice pieces of personal info that they can potentially use against you. 

How to avoid them: Simply put, don’t take those quizzes and surveys online. 

Bogus benefits and get-rich-quick schemes  

The list here is long. These include posts and direct messages about phony relief fundsgrants, and giveaways—along with bogus business opportunities that run the gamut from thinly-veiled pyramid schemes and gifting circles to mystery shopper jobs. What they all have in common is that they’re run by scammers who want your information, money or both. If this sounds familiar, like those old emails about transferring funds for a prince in some faraway nation, it is. Many of these scams simply made the jump from email to social media platforms. 

How to avoid them: Research any offer, business opportunity, or organization that reaches out to you. A good trick is to do a search of the organization’s name plus the term “scam” or “review” or “complaint” to see if anything sketchy comes up. 

Government imposter scams 

If there’s one government official that scammers like use to put a scare in you, it’s the tax collector. These scammers will use social media messaging (and other mediums like emails, texts, and phone calls) to pose as an official that’s either demanding back taxes or offering a refund or credit—all of which are bogus and all of which involve you handing over your personal info, money, or both.  

How to avoid them: Delete the message. In the U.S., the IRS and other government agencies will never reach out to you in this way or ask you for your personal information. Likewise, they won’t demand payment via wire transfer, gift cards, or cryptocurrency like bitcoin. Only scammers will. 

Friends and family imposter scams 

These are far more targeted than the scams listed above, because they’re targeted and often rely upon specific information about you and your family. Thanks to social media, scammers can gain access to that info and use it against you. One example is the “grandkid scam” where a hacker impersonates a grandchild and asks a grandparent for money. Similarly, there are family emergency scams where a bad actor sends a message that a family member was in an accident or arrested and needs money quickly. In all, they rely on a phony story that often involves someone close to you who’s in need or in trouble. 

How to avoid them: Take a deep breath and confirm the situation. Reach out to the person in question or another friend or family member to see if there really is a concern. Don’t jump to pay right away. 

The romance con  

This is one of the most targeted attacks of all—the con artist who strikes up an online relationship to bilk a victim out of money. Found everywhere from social media sites to dating apps to online forums, this scam involves creating a phony profile and a phony story to go with it. From there, the scammer will communicate several times a day, perhaps talking about their exotic job in some exotic location. They’ll build trust along the way and eventually ask the victim to wire money or purchase gift cards.  

How to avoid them: Bottom line, if someone you’ve never met in person asks you for money online, it’s a good bet that it’s a scam. Don’t do it. 

Protecting yourself from identity theft and scams on social media 

Now with an idea of the bad actors are up to out there, here’s a quick rundown of things you can do to protect yourself further from the social media scams they’re trying to pull. 

  1. Use strict privacy settings. First up, set your social media profile to private so that only approved friends and family members can access it. This will circulate less of your personal information in public. However, consider anything you do or post on social media as public information. (Plenty of people can still see it, copy it, and pass it along.) Likewise, pare back the information you provide in your profile, like your birthday, the high school you attended, and so on. The less you put out there, the less a scammer can use against you. 
  2. Be a skeptic. You could argue that this applies to staying safe online in general. So many scams rely on our innate willingness to share stories, help others, or simply talk about what’s going on in our lives. This willingness could lower your guard when a scammer comes calling. Instead, try to look at the messages you receive beyond face value. Does something seem unusual about the language or request? What could be the motivation behind it? Pausing and considering questions like these could spare some headaches. 
  3. Know your friends. How well do you know everyone in your list of friends and followers? Even with your privacy settings set to the max, these people will see what you’re posting online. Being selective about who you invite into that private circle of yours can limit the amount of personal information people have immediate access to via your posts, tweets, and updates. However, if you like having a larger list of friends and followers, be aware that any personal info you share is effectively being broadcast on a small scale—potentially to people you don’t really know well at all. 
  4. Follow up. Get a message from a “friend” that seems a little spammy or just plain weird? Or maybe you get something that sounds like an imposter scam, like the ones we outlined above? Follow up with them using another means of communication other than the social media account that sent the message. See what’s really going on.  
  5. Look out for each other. Much like following up, looking out for each other means letting friends know about that strange message you received or a friend request from a potentially duplicate account. By speaking up, you may be giving them the first sign that their account (and thus a portion of their identity) has been compromised. Likewise, it also means talking about that online flame with each other, how it’s going, and, importantly, if that “special someone” has stooped to asking for money. 

Stay steps ahead of the scams on social media 

Above and beyond what we’ve covered so far, some online protection basics can keep you safer still. Comprehensive online protection software will help you create strong, unique passwords for all your accounts, help you keep from clicking links to malicious sites, and prevent you from downloading malware. Moreover, it can provide you with identity protection services like ours, which keep your personal info private with around-the-clock monitoring of your email addresses and bank accounts with up to $1M of ID theft insurance. 

Together, with some good protection and a sharp eye, you can avoid those identity theft scams floating around on social media—and get back to enjoying time spent online with your true family and friends. 

The post Quizzes and Other Identity Theft Schemes to Avoid on Social Media appeared first on McAfee Blogs.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Cyber-attack on Financial Apps

Cyber-attack on Financial Apps

Hundreds of financial applications are being targeted by a threat campaign featuring a new strain of the Anubis Android banking trojan malware.

The malicious campaign was detected by researchers at cybersecurity company and integrated endpoint-to-cloud provider Lookout.

Researchers observed the banking malware masquerading as an account management application created by France’s largest telecommunications company, Orange S.A., to target customers of nearly 400 financial institutions, virtual payment platforms, and crypto-currency wallets.

Victims of Anubis suffer their personal data’s being exfiltrated from their mobile device then exploited for financial gain. The malware accesses victims’ information by intercepting SMSs, keylogging, GPS data collection, file exfiltration, screen monitoring, and abusing the accessibility services of a device.

This latest distribution of Anubis can record a device’s screen activity and sound from its microphone, capture screenshots, retrieve contacts and send mass SMS messages to specified recipients, and submit USSD code requests to query bank balances. It can also lock the screen of a device and cause a ransom note to be displayed.

The malicious app, with a package name of ‘fr.orange.serviceapp’, landed in the Google Play store at the end of July 2021. Lookout’s researchers believe its creators sought to test Google’s antivirus capabilities. 

To disguise the criminal nature of the malicious app, the cyber-criminals have perfectly mimicked its “Orange et Moi France” app icon, which shows a user and their device drawn in white against an orange background. 

However, eagle-eyed app users will notice that the resolution of the fake image used by the cyber-criminals is lower than that used in the real icon, giving it a slightly fuzzy appearance.

Explaining how Anubis initiates attacks, researchers wrote: “As a trojanized malware, users assume that the app they have downloaded is legitimate. Pretending to be ‘Orange Service,’ the malware begins its attack by asking for accessibility services.”

Once the user selects “OK,” the app initiates covert communications with its C2, sending details about the victim’s device. Next, it exploits accessibility services to grant itself additional extensive permissions.

“This process occurs so quickly that most users probably wouldn’t see the device selecting ‘agree’ to the permission request prompts,” said researchers. 

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

LastPass to Become Standalone Company

LastPass to Become Standalone Company

Cloud-based password manager LastPass is going to emerge from under the wing of LogMeIn and become a standalone business once again.

Plans to set up LastPass as an independent company were announced today by LogMeIn, which acquired the password manager back in October 2015 for $125m. 

A new chief executive will be hired in 2022 to run LastPass. Until then, LogMeIn chief executive officer and president Bill Wagner and his management team will continue to run the company. 

“The substantial scale of LastPass, its tremendous growth, and its market-leading position and brand makes it a perfect candidate to seize new opportunities as its own standalone company,” said Wagner.

He added: “We believe that LogMeIn is well positioned to continue to deliver strong results and capitalize on the tremendous opportunity in today’s virtual environment.”

LastPass is currently used by more than 30 million people and 85,000 businesses around the world. LogMeIn shared plans to improve their interaction with the password manager by increasing investment in the customer experience.

Money will also be siloed into leveling up LastPass’ go-to-market functions and engineering. LogMeIn said it believed such investment would speed up the company’s natural growth in single sign-on (SSO) and multi-factor authentication (MFA). 

While not giving any specific details, LogMeIn said in a statement released earlier today that LastPass customers can expect to experience “planned enhancements on an accelerated timeline in 2022” along with “additional dedicated LastPass resources.”

“The success we’ve seen across the entire LogMeIn portfolio over the last 18 months proves there is a vast growth opportunity ahead for both LastPass and LogMeIn,” said Andrew Kowal, partner at American private equity firm Francisco Partners. 

“We assessed our portfolio with a laser focus on unlocking the full potential of our business and identifying how we could best serve customers and accelerate growth across very different markets.”

LastPass uses a zero-knowledge security model that allows users to generate, secure, and share credentials, as well as monitor personal information on the dark web. Over the past three years, the company has achieved more than 50% revenue CAGR (compound annual growth rate).

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

TAG to Open New Global Headquarters

TAG to Open New Global Headquarters

A cybersecurity research and advisory company has announced plans to open a new global headquarters in New York City.

TAG Cyber said relocation to the famous spot in the Big Apple was necessary as the firm is expanding its operations to support a growing need for research as a service (RaaS) among enterprise clients, commercial vendors, and government clients.

Sited in the Battery Park section of Manhattan at 45 Broadway, TAG Cyber’s new operational base will feature a video production studio. The company’s current clutch of original video content was filmed in its studios on Fulton Street, New York City.

TAG Cyber was established in 2016 to help cybersecurity teams access guidance and analysis that could help them to protect their infrastructure from cyber-attacks. When the company started out, it was a one-man operation staffed by Dr. Ed Amoroso.

“It’s been an exciting journey from our first hot desk at WeWork five years ago to this exciting new office,” said Amoroso, TAG Cyber’s founder and CEO. 

“As a former senior executive at AT&T, I always took for granted the privilege to serve customers in a lovely space. As a reinvented entrepreneur, however, I now understand the intense effort it takes to get here. We are just so proud of our new headquarters.” 

TAG Cyber provides customers with industry research and advisory services on-demand through a SaaS-style subscription portal that is accessible around the clock every day of the year. 

A team of expert practitioners, most of whom joined the company after holding CISO positions, are on hand to give research assistance in over 140 different areas of information and data protection, including vendor selection and technology support. The team also answers customers’ tough cybersecurity-related questions.

“Our new headquarters in New York City will provide us with a spacious facility that can help us achieve our main business objective, which is to equip and enable the cyber defender,” said Amoroso. 

“I hope all enterprise, government, and vendor teams will take time on their next visit to New York City to stop by and say hello.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains