Thieves Using AirTags to “Follow” Cars

From Ontario and not surprising:

Since September 2021, officers have investigated five incidents where suspects have placed small tracking devices on high-end vehicles so they can later locate and steal them. Brand name “air tags” are placed in out-of-sight areas of the target vehicles when they are parked in public places like malls or parking lots. Thieves then track the targeted vehicles to the victim’s residence, where they are stolen from the driveway.

Thieves typically use tools like screwdrivers to enter the vehicles through the driver or passenger door, while ensuring not to set off alarms. Once inside, an electronic device, typically used by mechanics to reprogram the factory setting, is connected to the onboard diagnostics port below the dashboard and programs the vehicle to accept a key the thieves have brought with them. Once the new key is programmed, the vehicle will start and the thieves drive it away.

I’m not sure if there’s anything that can be done:

When Apple first released AirTags earlier this year, concerns immediately sprung up about nefarious use cases for the covert trackers. Apple responded with a slew of anti-stalking measures, but those are more intended for keeping people safe than cars. An AirTag away from its owner will sound an alarm, letting anyone nearby know that it’s been left behind, but it can take up to 24 hours for that alarm to go off — more than enough time to nab a car in the dead of night.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Before You Download: Steer Clear of Malicious Android Apps

You may have heard the news that more than 300,000 Android users unknowingly downloaded banking trojan apps from the Google Play Store, malicious apps which bypassed the store’s security detections to install malware. 

This news comes from a security report that found these trojans cleverly posed as apps that people commonly search for, such as QR code scanners, fitness apps, and a bevy of other popular types of utilities. In fact, these phony apps contain trojans that are designed to steal banking information, harvest keystrokes as you enter account info, and even grab screenshots of what you’re doing on your phone.  

The trick with this malware is that it only activates after it is installed, which may or may not be apparent to the user. For the malware to activate, it requires an extra step, such as an in-app update (not through the Play Store), which then downloads the payload of malware onto the phone. In many cases, the bogus apps force users to make this update once the app is downloaded.  

So, while the apps that appeared in the Play Store may not have contained malware, they deliver the payload onto the user’s phone post-purchase from other servers, which is a reason why these malicious apps have not been readily flagged.   

All of this is just one more way hackers have found to infect smartphones with malware. 

It’s no wonder that they target smartphones. They’re loaded with personal info and photos, in addition to credentials for banking and payment apps, all of which are valuable to loot or hold for ransom. Add in other powerful smartphone features like cameras, microphones, and GPS, and a compromised phone may allow a hacker to:  

  • Snoop on your current location and everyday travels.  
  • Hijack your passwords to social media, shopping, and financial accounts. 
  • Drain your wallet by racking up app store purchases or tapping into payment apps. 
  • Read your text messages or steal your photos.  

All of that adds up to one thing—a great, big “no thanks!”  

So how do these sorts of malicious apps work? By posing as legitimate apps, they can end up on your phone and gain broad, powerful permissions to files, photos, and functionality—or sneak in code that allows cybercriminals to gather personal info. As a result, that can lead to all kinds of headaches, ranging from a plague of popup ads to costly identity theft.  

Here are a few recent examples of malicious apps in the news:   

  • Fake ad-blocking programs that ironically serve up ads instead.  
  • Phony VPN apps that charge a subscription and offer no protection in return.  
  • Utility apps that hijack system privileges and permissions, which expose users to further attacks.  

Again, “no thanks!” So, let’s see about steering clear of malicious apps like these.  

Seven steps to safer mobile app downloads  

The good news is that there are ways you can spot these imposters. Major app marketplaces like Google Play and Apple’s App Store do their part to keep their virtual shelves free of malware, as reported by Google and Apple themselves. Still, cybercriminals can find ways around these efforts. (That’s what they do, after all!) So, a little extra precaution on your part will help you stay safer. These steps can help:  

1) Keep an eye on app permissions  

Another way cyber criminals weasel their way into your device is by getting permissions to access things like your location, contacts, and photos—and they’ll use sketchy apps to do it. (Consider the long-running free flashlight app scams mentioned above that requested up to more than 70 different permissions, such as the right to record audio, video, and access contacts.) So, pay close attention to what permissions the app is requesting when you’re installing it. If it’s asking for way more than you bargained for, like a simple game wanting access to your camera or microphone, it may be a scam. Delete the app and find a legitimate one that doesn’t ask for invasive permissions like that.   

Additionally, you can check to see what permissions an app may request before downloading the app. In Google Play, scroll down the app listing and find “About this app.” From there, click “App permissions,” which will provide you with an informative list. In the iOS App Store, scroll down to “App Privacy” and tap “See Details” for a similar list. If you’re curious about permissions for apps that are already on your phone, iPhone users can learn how to allow or revoke app permissions here, and Android can do the same here 

2) Be wary of apps that prompt you for an in-app update 

While some apps (like games) rely on downloadable content from within the app, look out for apps that prompt you for an immediate update directly from the app. For the most part, the app you download from the store should be the most recent version and not require an update. Likewise, update your phone through the app store, not the app itself, which can help you avoid malware-based attacks like these.  

3) Review with a critical eye 

As with so many attacks, cybercriminals rely on people clicking links or tapping “download” without a second thought. Before you download, take time to do some quick research, which may uncover a few signs that the app is malicious. Check out the developer—have they published several other apps with many downloads and good reviews? A legit app typically has quite a few reviews, whereas malicious apps may have only a handful of (phony) five-star reviews. Lastly, look for typos and poor grammar in both the app description and screenshots. They could be a sign that a hacker slapped the app together and quickly deployed it.  

4) Go with a strong recommendation  

Even better than combing through user reviews yourself is getting a recommendation from a trusted source, like a well-known publication or from app store editors. In this case, much of the vetting work has been done for you by an established reviewer. A quick online search like “best fitness apps” or “best apps for travelers” should turn up articles from legitimate sites that can suggest good options and describe them in detail before you download.  

5) Avoid third-party app stores 

Unlike Google Play and Apple’s App Store, which have measures in place to review and vet apps to help ensure that they are safe and secure, third-party sites may not have that process in place. In fact, some third-party sites may intentionally host malicious apps as part of a broader scam. Granted, cybercriminals have found ways to work around Google and Apple’s review process, yet the chances of downloading a safe app from them are far greater than anywhere else. Furthermore, both Google and Apple are quick to remove malicious apps once discovered, making their stores that much safer.  

6) Protect your smartphone with security software  

With all that we do on our phones, it’s important to get security software installed on them, just like we do on our computers and laptops. Whether you go with comprehensive security software that protects all of your devices or pick up an app in Google Play or Apple’s iOS App Store, you’ll have malware, web, and device security that’ll help you stay safe on your phone.   

7) Update your phone’s operating system  

Hand-in-hand with installing security software is keeping your phone’s operating system up to date. Updates can fix vulnerabilities that cybercriminals rely on to pull off their malware-based attacks—it’s another tried and true method of keeping yourself safe and your phone running in tip-top shape.  

Stay on guard against mobile malware  

Here are a few more things you can do:   

Lastly, you can always ask yourself, “Do I really need this app?” One way to avoid malicious mobile apps is to download fewer apps overall. If you’re unsure if that free game is on the up-and-up or if the offer for that productivity app sounds a little too good, skip it. Look for a better option or pass on the idea altogether. As said earlier, cybercriminals really rely on us clicking and downloading without thinking. Staying on guard against mobile malware will cost you a few moments of your time, which is minimal compared to the potential costs of a hacked phone. 

The post Before You Download: Steer Clear of Malicious Android Apps appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Ex Ubiquiti Developer Arrested for Data Theft

Ex Ubiquiti Developer Arrested for Data Theft

A man from Oregon has been charged with stealing confidential data from his employer and secretly extorting the company for a $2m ransom while purporting to be working on remediating the theft. 

Portland resident Nickolas Sharp allegedly stole gigabytes of data from Ubiquiti Inc., a technology company headquartered in New York, where Sharp was employed from August 2018 to around April 1, 2021. 

According to an indictment unsealed on Wednesday in Manhattan Federal Court, Sharp’s senior developer role gave him access to credentials for the company’s Amazon Web Services (AWS) and GitHub servers.

Around this time last year, Sharp allegedly repeatedly disguised his IP address through virtual private network service (VPN) Surfshark, then abused his administrative access to exfiltrate his employer’s confidential data. 

While he was anonymously inside his employer’s network, Sharp allegedly altered log retention policies and other files to hide his intrusion. 

In January 2021, while working as part of a team tasked to remediate the theft of the data, Sharp allegedly posed as an anonymous hacker and sent his employer a digital ransom note. In the note, Sharp demanded 50 Bitcoin (worth around $1.9m at the time) to return the stolen data and identify a supposed “backdoor” in the company’s network. 

After his employer refused to pay up, Sharp allegedly published some of the stolen files online in a public forum. 

In March, when FBI agents searched Sharp’s residence and showed the defendant records of his Surfshark service purchase in July 2020, Sharp claimed it had been bought by someone else through his PayPal account.

Following the search, Sharp allegedly posed as an anonymous Ubiquiti whistleblower and caused false news stories to be published in which it was claimed that an unknown cybercriminal had maliciously acquired root administrator access to the company’s accounts to steal the confidential data prosecutors say was taken by Sharp. 

Following the publication of these articles, between March 30, 2021, and March 31, 2021, Ubiquiti experienced a 20% drop in stock price.

Sharp was arrested on December 1. He is charged with wire fraud, transmitting a program to a protected computer that intentionally caused damage, the transmission of an interstate threat and making false statements to the FBI.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

UK Government Fined Over Honors List Data Breach

UK Government Fined Over Honors List Data Breach

The UK’s data watchdog has slapped the British government with a hefty fine for exposing the addresses of individuals chosen to receive honors. 

The Information Commissioner’s Office (ICO) said that the safety of hundreds of 2020 New Year Honors recipients had been placed in jeopardy after their personal data was published online.

“On 27 December 2019 the Cabinet Office published a file on GOV.UK containing the names and unredacted addresses of more than 1,000 people announced in the New Year Honors list,” said the ICO in a statement released Thursday. 

Among the figures impacted by the unauthorized disclosure of personal information were musician Elton John, TV chef Nadiya Hussain, former NHS England chief executive Simon Stevens, former director of public prosecutions Alison Saunders, and cricketer Ben Stokes. 

The addresses of the honorees were available online for two hours and 21 minutes. During that period, the information was accessed 3,872 times. 

“After becoming aware of the data breach, the Cabinet Office removed the weblink to the file. However, the file was still cached and accessible online to people who had the exact webpage address,” said the ICO.

Three complaints were received from the ICO by individuals whose data was exposed in the incident. A further 27 people contacted the Cabinet Office to raise concerns over the personal safety of the honorees following the breach. 

The ICO found that officials at the Cabinet Office had breached UK data protection laws by failing to put in place “appropriate technical and organizational measures” to prevent the publication of the addresses.

On Thursday the ICO fined the Cabinet Office £500,000 (approximately $661K) over the data debacle. 

“The Cabinet Office’s complacency and failure to mitigate the risk of a data breach meant that hundreds of people were potentially exposed to the risk of identity fraud and threats to their personal safety,” said the ICO’s director of investigations, Steve Eckersley.

“The fine issued today sends a message to other organizations that looking after people’s information safely, as well as regularly checking that appropriate measures are in place, must be at the top of their agenda.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US Issues Cybersecurity Directive for Airlines and Railroads

US Issues Cybersecurity Directive for Airlines and Railroads

Nearly all railroads and airlines in the United States have been ordered to report cybersecurity breaches to the federal government. 

Under the new Transportation Security Administration–issued mandate, rail operators, airport operators and airline operators will be required to report cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency within 24 hours of detection.

All three types of operators will also have to designate a cybersecurity coordinator. The mandate applies to both passenger and freight railroads.

Other requirements included in the mandates are that railroad operators must complete a vulnerability review to determine how susceptible they are to cyber-attacks. They must also create and implement a cybersecurity incident response plan.

The fresh security regulations were announced by senior officials at the US Department of Homeland Security (DHS) on Thursday and will come into force on the last day of this month. 

“Cybersecurity incidents affecting transportation are a growing, evolving and persistent threat,” Victoria Newhouse, TSA’s deputy assistant administrator, told the House Transportation Committee on Thursday. 

“Across US critical infrastructure, cyber threat actors have demonstrated their willingness and ability to conduct malicious cyber activities targeting critical infrastructure by exploiting the vulnerability of operational technology and information technology systems.”

Several cyber-attacks targeting the rail sector have been reported over the past twelve months. They include a ransomware strike on Toronto’s transit agency, a breach of New York’s Metropolitan Transportation Authority’s computer systems and an attack on the Transportation Authority in Ann Arbor, Michigan. 

The new rules echo similar mandates directed at improving the security of America’s pipelines, which the Biden administration issued in the wake of the cyber-attack on Colonial Pipeline.

“These new cybersecurity requirements and recommendations will help keep the traveling public safe and protect our critical infrastructure from evolving threats,” Department of Homeland Security Secretary Alejandro Mayorkas said.

“DHS will continue working with our partners across every level of government and in the private sector to increase the resilience of our critical infrastructure nationwide.”

The Wall Street Journal reports that the new mandates will affect roughly 90% of passenger rail systems in the US and 80% of freight railways.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Twitter and Meta Tackle Anti-Vaxxers and Chinese Disinformation

Twitter and Meta Tackle Anti-Vaxxers and Chinese Disinformation

Social media giants Twitter and Meta have been forced to remove thousands of “inauthentic” accounts linked to state-backed disinformation campaigns and anti-vaxxer rhetoric.

China loomed large over much of the activity. Twitter revealed that it removed over 3400 accounts – around 2000 of which were being used to amplify Communist Party narratives related to the treatment of the Uyghur population in Xinjiang.

Meanwhile, Meta removed four Coordinated Inauthentic Behavior (CIB) operations. These included a Chinese effort to spread false news about the US putting pressure on the World Health Organisation (WHO) to blame China for the pandemic.

English-speaking audiences in the US and UK and Chinese-speaking audiences in Taiwan, Hong Kong, and Tibet were reportedly the targets of this campaign.

Dismantling the operation required Meta to take down 524 Facebook accounts, 20 Pages, four Groups, and 86 Instagram accounts.

Other CIBs were focused around networks in Palestine, Poland and Belarus.

Meta also revealed two new policy violation categories: “mass reporting” and “brigading.”

The former works when a network of accounts mass-report an account or content in order to get it incorrectly removed by Meta.

The firm described one such network it took action on in Vietnam

“They coordinated the targeting of activists and other people who publicly criticized the Vietnamese government and used false reports of various violations in an attempt to have these users removed from our platform,” it explained.

“The people behind this activity relied primarily on authentic and duplicate accounts to submit hundreds – in some cases, thousands – of complaints against their targets through our abuse reporting flows.”

Meanwhile, brigading is where Facebook users work together to engage en masse in repetitive behaviors to harass or silence individuals.

This was the case with a network of anti-vaxxers belonging to the conspiracy movement “V_V” which Meta recently removed. It originated in Italy and France and targeted medical professionals, journalists and elected officials with mass harassment.

“The people behind this operation relied on a combination of authentic, duplicate and fake accounts to mass comment on posts from Pages, including news entities, and individuals to intimidate them and suppress their views,” it said.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Misconfigured Database Leaks Info on 150K E-commerce Buyers

Misconfigured Database Leaks Info on 150K E-commerce Buyers

Security researchers have found a misconfigured cloud-hosted database leaking over 300,000 records, including sensitive personal information on e-commerce buyers.

A team at Safety Detectives found the leaky Elasticsearch database on July 25 this year but claimed the content had been exposed without any password protection or encryption since November 2020.

Its efforts to close the leak have so far proven unsuccessful, after hosting firm Alibaba did not reply to the team’s outreach, and the identity of the database owner remains a mystery.

All Safety Detectives has been able to ascertain from the 500MB data leak is that the owner is a Chinese ERP provider serving businesses that sell goods on platforms like Amazon and Shopify.

Around half of the 329,000 exposed records contained buyers’ names, phone numbers, email, billing and delivery addresses, according to the report. In some cases, seller names, email addresses and billing information were also leaked.

German, French and Danish e-commerce customers featured among the haul, with as many as 150,000 potentially exposed, the report claimed.

The leaked data would be a goldmine for scammers, who are past masters at reusing personal information in follow-on phishing and identity fraud attempts designed to elicit more sensitive financial info.

“Home addresses are available on the database too. This makes home invasion/burglary a real possibility if personally identifiable information (PII) is sold on to other criminals. Thieves may target users who make high-value orders in the hope the victim’s house is full of expensive goods,” the report claimed.

“Theft of ordered goods is another risk associated with leaked order details. Tracking links, shipment times, courier information, delivery addresses and order information provide criminals with enough data to intercept and steal a user’s ordered goods.”

If the database owner is finally tracked down, they could face investigation from regulators of both the GDPR and China’s new equivalent legislation, the Personal Information Protection Law (PIPL).

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Omicron Phishing Campaign Hits User Inboxes

Omicron Phishing Campaign Hits User Inboxes

Online fraudsters have reacted quickly to news of a potentially new severe COVID-19 variant, with a carefully crafted phishing email campaign, according to observers.

Consumer rights group Which? spotted the email, which is designed to appear as if sent from the NHS, and urges recipients to get a new PCR test for the Omicron variant.

Two separate versions of the same email feature a link and a legitimate-looking “get it now” button.

“The fake email was also sent to a Which? member from ‘NHS Customer Service’ using the email address ‘contact-nhs[AT]nhscontact.com.’ This email address may seem authentic, but it has nothing to do with the genuine NHS,” Which? explained.

“As well as falsely claiming that the new COVID variant requires new test kits, the email invites readers to visit the site shown in the above image. But clicking the link takes you to the true web address – ‘healt-service-nh.com’ — which is a copycat of the NHS website set up just days ago.”

The phishing site then asks users to enter their full name, date of birth, address, mobile number, and email address, as well as their mother’s maiden name – which scammers could use to craft follow-on identity fraud attacks.

It also asks for a small payment of £1.24 for ‘delivery’ – presumably, if users proceed with this they will also have their bank card details stolen.

Which? reported the scam to the National Cyber Security Centre’s Suspicious Email Reporting Service, which has been incredibly popular during the pandemic.

According to the NCSC, it accrued 5.9 million reports over the past year, leading to the removal of more than 53,000 scams and 96,500 malicious URLs.

At the height of the first wave of the pandemic, in April 2020, Google claimed to be blocking over 240 million COVID-themed spam messages each day and 18 million malware and phishing emails. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains