—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Author: admin
Massive Zero-Day Hole Found in Palo Alto Security Appliances
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
New Android Spyware Poses Pegasus-Like Threat
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Hacking the Sony Playstation 5
I just don’t think it’s possible to create a hack-proof computer system, especially when the system is physically in the hands of the hackers. The Sony Playstation 5 is the latest example:
Hackers may have just made some big strides towards possibly jailbreaking the PlayStation 5 over the weekend, with the hacking group Fail0verflow claiming to have managed to obtain PS5 root keys allowing them to decrypt the console’s firmware.
[…]
The two exploits are particularly notable due to the level of access they theoretically give to the PS5’s software. Decrypted firmware which is possible through Fail0verflow’s keys would potentially allow for hackers to further reverse engineer the PS5 software and potentially develop the sorts of hacks that allowed for things like installing Linux, emulators, or even pirated games on past Sony consoles.
In 1999, Adam Shostack and I wrote a paper discussing the security challenges of giving people devices that included embedded secrets that needed to be kept from those people. We were writing about smart cards, but our lessons were general. And they’re no less applicable today.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
The Newest Malicious Actor: “Squirrelwaffle” Malicious Doc.
Authored By Kiran Raj
Due to their widespread use, Office Documents are commonly used by Malicious actors as a way to distribute their malware. McAfee Labs have observed a new threat “Squirrelwaffle” which is one such emerging malware that was observed using office documents in mid-September that infects systems with CobaltStrike.
In this Blog, we will have a quick look at the SquirrelWaffle malicious doc and understand the Initial infection vector.
Geolocation based stats of Squirrelwaffle malicious doc observed by McAfee from September 2021
Infection Chain
- The initial attack vector is a phishing email with a malicious link hosting malicious docs
- On clicking the URL, a ZIP archived malicious doc is downloaded
- The malicious doc is weaponized with AutoOpen VBA function. Upon opening the malicious doc, it drops a VBS file containing obfuscated powershell
- The dropped VBS script is invoked via exe to download malicious DLLs
- Thedownloaded DLLs are executed via exe with an argument of export function “ldr”
Malicious Doc Analysis
Here is how the face of the document looks when we open the document (figure 3). Normally, the macros are disabled to run by default by Microsoft Office. The malware authors are aware of this and hence present a lure image to trick the victims guiding them into enabling the macros.
UserForms and VBA
The VBA Userform Label components present in the Word document (Figure-4) is used to store all the content required for the VBS file. In Figure-3, we can see the userform’s Labelbox “t2” has VBS code in its caption.
Sub routine “eFile()” retrieves the LabelBox captions and writes it to a C:ProgramdataPin.vbs and executes it using cscript.exe
Cmd line: cmd /c cscript.exe C:ProgramdataPin.vbs
VBS Script Analysis
The dropped VBS Script is obfuscated (Figure-5) and contains 5 URLs that host payloads. The script runs in a loop to download payloads using powershell and writes to C:Programdata location in the format /www-[1-5].dll/. Once the payloads are downloaded, it is executed using rundll32.exe with export function name as parameter “ldr”
De-obfuscated VBS script
VBS script after de-obfuscating (Figure-6)
MITRE ATT&CK
Different techniques & tactics are used by the malware and we mapped these with the MITRE ATT&CK platform.
- Command and Scripting Interpreter (T-1059)
Malicious doc VBA drops and invokes VBS script.
CMD: cscript.exe C:ProgramDatapin.vbs
- Signed Binary Proxy Execution (T1218)
Rundll32.exe is used to execute the dropped payload
CMD: rundll32.exe C:ProgramDatawww1.dll,ldr
IOC
| Type | Value | Scanner | Detection Name |
| Main Word Document | 195eba46828b9dfde47ffecdf61d9672db1a8bf13cd9ff03b71074db458b6cdf | ENS,
WSS
|
W97M/Downloader.dsl
|
| Downloaded DLL
|
85d0b72fe822fd6c22827b4da1917d2c1f2d9faa838e003e78e533384ea80939 | ENS,
WSS |
RDN/Squirrelwaffle |
| URLs to download DLL | · priyacareers.com
· bussiness-z.ml · cablingpoint.com · bonus.corporatebusinessmachines.co.in · perfectdemos.com |
WebAdvisor | Blocked |
The post The Newest Malicious Actor: “Squirrelwaffle” Malicious Doc. appeared first on McAfee Blogs.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Legendary Entertainment Relies on MVISION CNAPP Across Its Multicloud Environment
Becoming a cloud first company is an exciting and rewarding journey, but it’s also fraught with difficulties when it comes to securing an entire cloud estate. Many forwarding-thinking companies that have made massive investments in migrating their infrastructure to the cloud are facing challenges with respect to their cloud-native applications. These range from inconsistent security across cloud properties to lack of visibility into the public cloud infrastructure where cloud-native applications are hosted—and more. All of these issues can create vulnerabilities in a sprawling attack surface that can be potentially exploited by cybercriminals.
Legendary Entertainment is a global media company with multiple divisions including film, television, digital studios, and comics. Under the guidance of Dan Meacham, VP of Global Security and Corporate Operations and CSO/CISO, the multi-billion dollar organization transitioned from on-premises data centers to the cloud in 2012.
Meacham points out that it’s been a source of great pride for his security and IT teams to always be “on top of the latest and greatest” technology trends—and migration to the cloud is no exception. That’s why his interest was sparked when he learned about the rollout of the MVISION security product line early in the migration process. Its cloud-native, open architecture was exactly the right fit for Legendary Entertainment’s environment.
The challenges of securing a multi-cloud environment
As a cloud-first organization, Legendary Entertainment encountered challenges that are common to many companies that have migrated their workloads, applications, and data assets to the cloud. At first, the organization attempted to rely on security services natively provided by the individual cloud service providers: Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), and Wasabi for cloud storage. As Meacham notes, “The security from one vendor doesn’t trickle over to the others. They all have different security controls, so our cloud security was not uniform, and security management was complicated.”
Lack of visibility
In their disparate multicloud environment spanning several cloud service providers, it became time-consuming and difficult to monitor and assess the security posture of applications and workloads, such as which systems needed patching or contained critical vulnerabilities.
Inconsistent security policies
With multiple management consoles required for its many cloud environments, applying and enforcing uniform security policy across their cloud estate was nearly impossible without investing a lot of time, effort, and resources.
Risky Shadow IT
Another problem in Legendary Entertainment’s early adoption of cloud-first was shadow IT, where employees or contractors enrolled in cloud collaboration platforms that were not authorized by IT. Although the shadow IT platforms were not connected to core systems, they made it more difficult to tightly monitor data which sometimes caused cloud-enabled applications to violate security policies. It is understandable that teams with a cloud-first mindset would embrace innovation and new collaborative experiences to accomplish goals faster. However, some of the shadow IT application has weak or no security controls – resulting the opportunities for external collaborator accounts to be compromised or have mis-managed privileges.
Unacceptable levels of risk
With high-profile data breaches in the entertainment industry in recent headlines, Legendary Entertainment was concerned about its level of risk and exposure, especially since it has valuable intellectual property such as scripts and marketing strategy plans for film releases among its holdings. The requirement for stronger security has been a boardroom-level conversation at digital media companies since the Sony Pictures hack and other vendor supply chain and workflow hacks. Attacks now extend beyond data leaks and can have far reaching business disruptions across an entire supply chain.
How MVISION CNAPP creates a consistent, compliant cloud security posture
By deploying MVISION
Cloud Native Application Protection Platform (MVISION CNAPP), Legendary Entertainment addressed all of these challenges at once. This unique solution prioritizes alerts and defends against the latest cloud threats and vulnerabilities. MVISION CNAPP combines granular application and data context with cloud security posture management and cloud workload protection in a single-console solution.
Unparalleled visibility
MVISION CNAPP provides Legendary Entertainment with broad and deep visibility across its entire infrastructure. It discovers all their cloud assets, including compute resources, containers, and storage and provides continuous visibility into vulnerabilities and security posture for applications and workloads running across multiple clouds.
Thanks to MVISION CNAPP, Meacham’s team can write, apply, and enforce security policies in a consistent fashion for the entire cloud estate. As Meacham points out, policy is continually checked so his team can correct any misconfigurations, disable services, or remove escalated privileges until corrections are made in alignment with internal compliance rules. And in many cases, the remediation can be automated internally in MVISION CNAPP or through workflow initiations.
“MVISION CNAPP gives me manageability and security uniformity for all our cloud platforms so that I can elevate the level of security and make it consistent across the board. Now that I have visibility into all our cloud assets from a high level, I can look at how current controls and configurations compare to our best practices, industry best practices, and to the best practices of peers who are using the same product. Without MVISION CNAPP, management is one to one, whereas with MVISION CNAPP, it’s one to many,” explains Meacham.
The Cloud Security Posture Management (CSPM) component of MVISION CNAPP provides Legendary Entertainment with on-demand scanning, which looks at all services used in the public cloud and checks their security settings against internal benchmarks. “This gives us a security posture score and provides feedback on what we can do to bring ourselves back into compliance,” observes Meacham. “If someone changes a configuration, we get an alert right away. And if it’s not in alignment with policy, we can roll it back to the previous settings. MVISION CNAPP also helps us remediate policy exceptions by clearly stating the risks, instances impacted, and the necessary step by step actions needed for resolution.”
Banishing Shadow IT
MVISION CNAPP also ensures that Legendary Entertainment’s developers operate in a secure environment by alerting the security team when their actions violate security policies or increase the risk of a data breach. This effectively puts a halt to Shadow IT.
“MVISION CNAPP helps me keep my system administrators and developers accountable for what they are doing. We can make sure that they are consistent in how they execute, deploy, and build things. Configuration policies, on-demand scans, and different types of checks in MVISION CNAPP can help force that compliance. I am able to keep tabs on my developers to make sure they are operating according to these guidelines in any platform,” remarks Meacham.
Risk reduction through contextual entitlements
MVISION CNAPP reduces risk associated with operating in the cloud, enabling Legendary Entertainment to run mission-critical applications and develop blockbuster movies such as “The Dark Knight Rises” and “Dune” securely across a heterogenous multicloud environment. The solution also enables contextual entitlements so that users can be identified and assigned selective access to and permissions for applications and resources based on the security profile of the devices they are using at any given time.
Data protection with user and entity behavior analytics (UEBA)
Legendary Entertainment leverages MVISION CNAPP’s data loss prevention (DLP) capabilities to monitor activity in cloud data stores in order to help prevent data breaches. Unusual or suspicious activity or unauthorized movement of data transit is tracked and flagged immediately by leveraging built-in UEBA capabilities.
“If I see 2,000 files change in 30 seconds, that’s a huge red flag indicating ransomware or some other type of attack. The solution’s monitoring tool detects suspicious behavior and immediately brings that to our awareness. If we see something like that happening on multiple platforms, we know that immediate action is required. The UEBA capability is invaluable for identifying external collaborators who may have compromised accounts, which we find on a regular basis.”
Learn more
If you are looking for a simple-to-manage, high-visibility solution to secure your multicloud environment against the latest threats and vulnerabilities such as ChaosDB, take a look at MVISION CNAPP. For more information, visit: https://www.mcafee.com/enterprise/en-us/solutions/mvision-cnapp.html.
The post Legendary Entertainment Relies on MVISION CNAPP Across Its Multicloud Environment appeared first on McAfee Blogs.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
SMS About Bank Fraud as a Pretext for Voice Phishing
Most of us have probably heard the term “smishing” — which is a portmanteau for traditional phishing scams sent through SMS text messages. Smishing messages usually include a link to a site that spoofs a popular bank and tries to siphon personal information. But increasingly, phishers are turning to a hybrid form of smishing — blasting out linkless text messages about suspicious bank transfers as a pretext for immediately calling and scamming anyone who responds via text.
KrebsOnSecurity recently heard from a reader who said his daughter received an SMS that said it was from her bank, and inquired whether she’d authorized a $5,000 payment from her account. The message said she should reply “Yes” or “No,” or 1 to decline future fraud alerts.
Since this seemed like a reasonable and simple request — and she indeed had an account at the bank in question — she responded, “NO.”

Seconds later, her mobile phone rang.
“When she replied ‘no,’ someone called immediately, and the caller ID said ‘JP Morgan Chase’,” reader Kris Stevens told KrebsOnSecurity. “The person on the phone said they were from the fraud department and they needed to help her secure her account but needed information from her to make sure they were talking to the account owner and not the scammer.”
Thankfully, Stevens said his daughter had honored the gold rule regarding incoming phone calls about fraud: When In Doubt, Hang up, Look up, and Call Back.
“She knows the drill so she hung up and called Chase, who confirmed they had not called her,” he said. “What was different about this was it was all very smooth. No foreign accents, the pairing of the call with the text message, and the fact that she does have a Chase account.”
The remarkable aspect of these phone-based phishing scams is typically the attackers never even try to log in to the victim’s bank account. The entirety of the scam takes place over the phone.
We don’t know what the fraudsters behind this clever hybrid SMS/voice phishing scam intended to do with the information they might have coaxed from Stevens’ daughter. But in previous stories and reporting on voice phishing schemes, the fraudsters used the phished information to set up new financial accounts in the victim’s name, which they then used to receive and forward large wire transfers of stolen funds.
Even many security-conscious people tend to focus on protecting their online selves, while perhaps discounting the threat from less technically sophisticated phone-based scams. In 2020 I told the story of “Mitch” — the tech-savvy Silicon Valley executive who got voice phished after he thought he’d turned the tables on the scammers.
Unlike Stevens’ daughter, Mitch didn’t hang up with the suspected scammers. Rather, he put them on hold. Then Mitch called his bank on the other line and asked if their customer support people were in fact engaged in a separate conversation with him over the phone.
The bank replied that they were indeed speaking to the same customer on a different line at that very moment. Feeling better, Mitch got back on the line with the scammers. What Mitch couldn’t have known at that point was that a member of the fraudster’s team simultaneously was impersonating him on the phone with the bank’s customer service people.
So don’t be Mitch. Don’t try to outsmart the crooks. Just remember this anti-fraud mantra, and maybe repeat it a few times in front of your friends and family: When in doubt, hang up, look up, and call back. If you believe the call might be legitimate, look up the number of the organization supposedly calling you, and call them back.
And I suppose the same time-honored advice about not replying to spam email goes doubly for unsolicited text messages: When in doubt, it’s best not to respond.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Free Cybersecurity Training for SMBs
Free Cybersecurity Training for SMBs

Small and mid-sized businesses (SMBs) were today granted free access to a virtual security awareness training program.
The program was put together by six-year-old security awareness training company Curricula, which is based in Atlanta, Georgia.
In a statement released Tuesday, Curricula said: “Our team at Curricula is proud to announce a free security awareness training program designed to help protect organizations with up to 1,000 employees build a security culture at no cost.”
Under the training project, any organization with up to 1,000 or fewer employees can access the resources needed to launch an employee security awareness program. Curricula Free includes cybersecurity training content, an integrated phishing simulator, simple compliance reporting, and an easy-to-use custom content creator.
Curricula said its decision to make the training available at no cost was made in response to the “constantly growing threat of phishing and ransomware attacks targeting businesses of all sizes” coupled with a realization that SMBs could do with some help.
“After working with thousands of businesses, we noticed a big gap in the industry. No one is focused on helping SMBs with security training,” said Curricula’s CEO, Nick Santora. “While there are other free tools available, Curricula’s training has demonstrated to be effective because employees actually resonate with the content and embrace building a security culture together.”
Santora said that with its free training program, Curricula is aiming to eliminate the barrier to entry for every business that wants to proactively improve its cybersecurity posture.
“Security awareness shouldn’t be a compliance-focused activity, or a reactive, knee-jerk decision caused by a data breach,” he added.
Commenting on the launch of the free training project, Brad Thies, founder and president, BARR Advisory, told Infosecurity Magazine: “Curricula’s decision to create a free security awareness program allows more organizations access to this critical component of an information security program. Security tools, processes, and systems can only go so far if your people aren’t trained.
“We’re excited to see organizations like Curricula moving the needle toward empowering companies to build cultures with strong security, not just checking the security box.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
DomainTools Acquires Farsight Security
DomainTools Acquires Farsight Security

Farsight Security has been acquired by a domain name and DNS-based cyber threat intelligence company based in Seattle, Washington.
DomainTools announced its acquisition on Tuesday, describing the deal as “a natural extension of both companies’ long-standing partnership to deliver the market-leading DNS intelligence and real-time security telemetry needed to assess risk, map attacker infrastructure, and rapidly increase visibility and context on threats.”
Farsight Security is a DNS intelligence and passive DNS cybersecurity data solutions provider based in San Mateo, California. The company uses proprietary technology to manage data and carry out real-time analysis.
Led by DNS inventor Dr. Paul Mockapetris and by Internet Systems Consortium (ISC) founder Dr. Paul Vixie, the company’s tech observes over 300,000 DNS resolutions per second to provide real-time actionable threat intelligence on how the internet is changing.
DomainTools and Farsight have been working together since 2017 to deliver Farsight’s passive DNS data via DomainTools’ Iris investigation platform.
“Over the years, DomainTools and Farsight have consistently delivered market-leading DNS intelligence and real-time security telemetry needed to defend against today’s cyberattacks,” said Vixie, chairman, co-founder, and CEO of Farsight Security.
“We recognize the immense opportunity this acquisition presents not only for both companies, but also for our global customers. We are thrilled to join DomainTools at this next stage of the company’s growth and, together, help to make the internet safer for everyone.”
In a joint statement, the companies said that combining DNS observation data with DomainTools’ active DNS data will benefit customers by giving them the earliest and most comprehensive look into threats emerging outside their network.
“DomainTools and Farsight have proven the value of our combined data sets and integrated intelligence solutions over many years. Our unified solution is used by some of the most sophisticated security organizations worldwide to increase the effectiveness of their threat intelligence and incident response capabilities,” said Tim Chen, CEO, DomainTools.
“This acquisition enhances our ability to drive security-forward detection, investigation, enrichment and mitigation outcomes for our joint customers while accelerating our data science advancements for predictive risk scoring of domain names, hostnames, IP addresses, nameservers and other DNS indicators.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Micro-Segmentation Used by 83% of Cybersecurity Leaders
Micro-Segmentation Used by 83% of Cybersecurity Leaders

Four out of five cybersecurity leaders now use micro-segmentation to protect corporate networks, according to a new study by cybersecurity company Byos.
Micro-segmentation is the creation of zones in data centers and cloud environments. It allows workloads to be isolated from one another and secured individually.
Byos surveyed 100 cybersecurity leaders in the third quarter of 2021 about their use of micro-segmentation strategies. The company’s findings – published in the report State of Microsegmentation in Network Security – indicate that micro-segmentation is being widely employed in addition to traditional perimeter-based security.
Researchers found that 83% of cybersecurity leaders currently augment their corporate network’s security with some form of micro-segmentation. Of the 17% of cybersecurity leaders who aren’t using micro-segmentation right now, nearly two-thirds (65%) say that they intend to use it at some point in the future.
Over a third (35%) of cybersecurity professionals who have yet to implement micro-segmentation said that they currently lack the people necessary to enact the strategy. Almost as many said that they lacked the budget to implement micro-segmentation (29%), or that they didn’t have enough time to set micro-segmentation up (29%).
For those who have already made the shift to micro-segmentation, 88% of cybersecurity leaders said that they believe micro-segmentation is essential to achieving zero trust network security. Even more leaders – 92% – said that they believe micro-segmentation “is more practical and efficient than its alternatives.”
Explaining what features were important when choosing a micro-segmentation solution, 76% of cybersecurity leaders said real-time threat management. Secure remote access and a ransomware kill switch were listed as major draws by 67% and 62%, respectively.
“When Gartner first identified micro-segmentation as a key emerging technology for information security in 2016, many security experts were unfamiliar with the concept, but here we are just five years later, and we see that it has been widely recognized as a crucial component of any security infrastructure,” said Matias Katz, Byos founder and CEO.
“Today, there is little doubt that micro-segmentation is an important method for stopping attackers from moving laterally to other systems once they have compromised a network. Our solution takes the complexity out of micro-segmentation, making it easier for IT teams to implement.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains