Magecart Credit Card Skimmer Avoids VMs to Fly Under the Radar

The Magecart threat actor uses a browser script to evade detection by researchers and sandboxes so it targets only victims’ machines to steal credentials and personal info.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US Blacklists NSO Group

The Israeli cyberweapons arms manufacturer — and human rights violator, and probably war criminal — NSO Group has been added to the US Department of Commerce’s trade blacklist. US companies and individuals cannot sell to them. Aside from the obvious difficulties this causes, it’ll make it harder for them to buy zero-day vulnerabilities on the open market.

This is another step in the ongoing US actions against the company.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

‘Tis the Season for the Wayward Package Phish

The holiday shopping season always means big business for phishers, who tend to find increased success this time of year with a lure about a wayward package that needs redelivery. Here’s a look at a fairly elaborate SMS-based phishing scam that spoofs FedEx in a bid to extract personal and financial information from unwary recipients.

One of dozens of FedEx-themed phishing sites currently being advertised via SMS spam.

Louis Morton, a security professional based in Fort Worth, Texas, forwarded an SMS phishing or “smishing” message sent to his wife’s mobile device that indicated a package couldn’t be delivered.

“It is a nearly perfect attack vector at this time of year,” Morton said. “A link was included, implying that the recipient could reschedule delivery.”

Attempting to visit the domain in the phishing link — o001cfedeex[.]com — from a desktop web browser redirects the visitor to a harmless page with ads for car insurance quotes. But by loading it in a mobile device (or by mimicking one using developer tools), we can see the intended landing page pictured in the screenshot to the right — returns-fedex[.]com.

Blocking non-mobile users from visiting the domain can help minimize scrutiny of the site from non-potential victims, such as security researchers, and thus potentially keep the scam site online longer.

Clicking “Schedule new delivery” brings up a page that requests your name, address, phone number and date of birth. Those who click “Next Step” after providing that information are asked to add a payment card to cover the $2.20 “redelivery fee.”

After clicking “Pay Now,” the visitor is prompted to verify their identity by providing their Social Security number, driver’s license number, email address and email password. Scrolling down on the page revealed more than a half dozen working links to real fedex.com resources online, including the company’s security and privacy policies.

While every fiber of my being hopes that most people would freak out at this page and go away, scams like these would hardly exist if they didn’t work at least some of the time.

After clicking “Verify,” anyone anxious enough over a wayward package to provide all that information is redirected to the real FedEx at Fedex.com.

It appears that sometime in the past 12 hours, the domain that gets loaded when one clicks the link in the SMS phishing message — returns-fedex[.]com — stopped resolving. But I doubt we’ve seen the last of these phishers.

The true Internet address of the link included in the FedEx SMS phishing campaign is hidden behind content distribution network Cloudflare, but a review of its domain name system (DNS) records shows it resolves to 23.92.29[.]42. There are currently more than three dozen other newly-registered FedEx phishing domains tied to that address, all with a similar naming convention, e.g., f001bfedeex[.]com, g001bfedeex[.]com, and so on.

Now is a great time to remind family and friends about the best advice to sidestep phishing scams: Avoid clicking on links or attachments that arrive unbidden in emails, text messages and other mediums. Most phishing scams invoke a temporal element that warns of negative consequences should you fail to respond or act quickly.

If you’re unsure whether the message is legitimate, take a deep breath and visit the site or service in question manually — ideally, using a browser bookmark so as to avoid potential typosquatting sites.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Cyber-Incident Impacts UK Labour Party

Cyber-Incident Impacts UK Labour Party

A company that handles the membership data of Britain’s Labour Party has been affected by a “cyber-incident.”

Labour said that the event at the third-party firm has rendered “a significant quantity” of party data “inaccessible on their systems.”

The incident has been reported to the UK’s National Cyber Security Centre (NCSC), National Crime Agency (NCA), and the Information Commissioner’s Office (ICO), which are investigating what transpired. 

Data impacted by the incident includes information provided to the Labour Party by its “members, registered and affiliated supporters, and other individuals,” according to a statement by the opposition party. 

Labour said that they were informed of the cyber-incident by the third party on October 29. They did not reveal the name of the company. 

“The third party told us that the incident had resulted in a significant quantity of Party data being rendered inaccessible on their systems,” said Labour in a data incident notification.

“As soon as the Party was notified of these matters, we engaged third-party experts and the incident was immediately reported to the relevant authorities, including the National Crime Agency (NCA), National Cyber Security Centre (NCSC) and the Information Commissioner’s Office (ICO).”

Labour said its new data systems were not affected by the incident; the full scope of which is still being investigated.

“The Party is also working closely and on an urgent basis with the third party in order to understand the full nature, circumstances and impact of the incident,” said Labour. 

A spokesman for the NCSC said: “We are aware of this issue and are working with the Labour Party to fully investigate and mitigate any potential impact.

“We would urge anyone who thinks they may have been the victim of a data breach to be especially vigilant against suspicious emails, phone calls or text messages and to follow the steps set out in our data breaches guidance.”

Labour advised its members to be vigilant against suspicious activity, including suspicious emails, phone calls or text messages, and to forward suspicious emails to report@phishing.gov.uk.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US House Passes Acts to Help SMBs with Cybersecurity

US House Passes Acts to Help SMBs with Cybersecurity

The United States House of Representatives has passed two bills to strengthen the cybersecurity of small businesses. 

The Small Business Development Center Cyber Training Act of 2021 attracted strong support among House members of all political persuasions and was passed on Tuesday with a vote of 409 in favor to 14 against. 

Representative Andrew Garbarino, who is both a member of the Small Business Committee and a ranking member of the Committee on Homeland Security’s Subcommittee on Cybersecurity, Infrastructure Protection, and Innovation, introduced the bill back in July. 

Speaking on the House floor yesterday in support of the legislation, Garbarino said: “Cyberattacks are on the rise, and small businesses are increasingly vulnerable. 

“Nearly 50% of cyberattacks are directed at small businesses, which can result in devastating financial, intellectual property, and reputational loss.”

Explaining why cyber-criminals may choose to victimize smaller companies over larger companies, Garbarino said: “Small businesses are targeted because they often lack the resources or technical knowledge needed to implement and maintain cybersecurity defenses.”

Garbarino said he had personally witnessed the difficulties small businesses experience when trying to defend themselves against cyber-attacks. 

The Small Business Development Center Cyber Training Act would establish a cyber counseling certification program at Small Business Development Centers (SBDCs) so that they can better assist small businesses with their cybersecurity and cyber-strategy needs.

If enacted into law, the legislation would authorize the Small Business Administration (SBA) to reimburse SBDCs for employee certification costs up to $350,000 per fiscal year. These costs would be covered by existing federal resources.

“This bill provides much needed resources to help small businesses improve their cyber preparedness in the face of rising threats,” said Garbarino.

On Tuesday, the House also approved the Small Business Administration (SBA) Cyber Awareness Act, which would require the SBA to generate a report about its cybersecurity capabilities and inform Congress if a cybersecurity breach occurred that could potentially compromise sensitive information.

Representative Jason Crow, who co-sponsored the legislation, said: “This bill would ensure we are doing everything we can to protect the millions of small businesses that the SBA serves and prepare them for 21st-century threats.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

CISA Orders Federal Agencies to Patch Flaws

CISA Orders Federal Agencies to Patch Flaws

The United States Cybersecurity and Infrastructure Security Agency (CISA) today issued an order mandating most federal agencies to patch hundreds of known cybersecurity vulnerabilities it says are being “actively exploited by adversaries.”

Binding Operational Directive (BOD) 22-01, Reducing the Significant Risk of Known Exploited Vulnerabilities, establishes a CISA-managed public catalog of known exploited vulnerabilities and gives federal civilian agencies a specific timeframe within which they must remediate such vulnerabilities.

The directive applies to all hardware and software located on federal information systems, including resources that are managed on agency premises or hosted by third parties for an agency.

BOD 22-01 marks CISA’s first government-wide requirement to remediate flaws impacting both internet-facing and non-internet-facing assets. 

CISA urged private businesses and state, local, tribal, and territorial (SLTT) governments to give precedence to remediating vulnerabilities listed in CISA’s catalog.

“As the operational lead for federal cybersecurity, we are using our directive authority to drive cybersecurity efforts toward mitigation of those specific vulnerabilities that we know to be actively used by malicious cyber actors,” said CISA director Jen Easterly. 

She continued: “The Directive lays out clear requirements for federal civilian agencies to take immediate action to improve their vulnerability management practices and dramatically reduce their exposure to cyber-attacks.”

Commenting on the new directive, Greg Fitzgerald, co-founder of Sevco Security, told Infosecurity Magazine: “This mandate is a good first step that will let a lot of companies reduce their attack surface. Unfortunately, the 300 or so vulnerabilities that this order addresses are only a drop in the bucket, and it will fall far short of solving the issue of unpatched vulnerabilities.”

Fitzgerald said a more pressing issue that CISA should be tackling was patching vulnerabilities on assets that IT teams have abandoned or forgotten about. 

“Most organizations are unable to create an accurate IT asset inventory that reflects the entirety of their attack surface, which in modern enterprises extends beyond the network to include cloud, personal devices, remote workers as well as all things on premises,” he said. 

“This puts them at the mercy of attackers who know where to look for forgotten IT assets that contain exploitable vulnerabilities.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

#SecTorCa: Jeff Moss Defines the Role of Hacking

#SecTorCa: Jeff Moss Defines the Role of Hacking

Jeff Moss, also known as The Dark Tangent, is a well-known figure in the security community, as the founder of Defcon and Black Hat security conferences. Moss is also a hacker, a moniker that everyone doesn’t understand well.

In a keynote session at the SecTor security conference on November 3, Moss detailed the evolution of the hacking movement from the 1970s through to the modern era. He started his talk by declaring that people fear what they do not understand and historically people do not understand hacking.

“They don’t understand complex computer systems and information security and because of that, it’s kind of a voodoo, and if they can’t easily understand, it’s like magic,” Moss said: “So a lot of the problems we’ve had is communicating with people what it is we do and how we do it.”

Defining Hacking

Part of the fear of the term ‘hacker’ is also because the word is not well defined either.

Moss defined hacking as a combination of curiosity and skills. It’s about having an innate curiosity, seeking knowledge and getting pleasure out of novel results. He added that individuals could use hacking skills for both good and evil.

There is also a difference between information security, commonly referred to as infosec and hacking. In Moss’ view, one of the big problems is that people treat all infosec as hacking and all hacking as infosec.

“Hacking can provide a lot of joy and absolutely no income,” Moss said: “With InfoSec, the goal is to produce income. It’s a job; you have to do the thing, solve the problem, write the report.”

There are multiple groups at play in the security world in the modern era, each with different IT security goals. The first group listed by Moss are nation-states that generally are looking to find secrets and are involved in espionage-type activities. Nation-state threat actors primarily are not looking for money.

On the other hand, organized cybercriminals are motivated by money and are another active threat actor in the modern internet. Finally, hacktivists represent another group that is sometimes identified as hackers. Moss explained that hacktivism is about protesters that want some form of change and use hacking skills to try and advance their goals.

The other key group is one that Moss referred to simply as hackers and researchers. This group is mainly concerned about the pursuit of knowledge, and it’s the group where Moss places himself.

“This is my sweet spot,” Moss said: ”I believe that hackers and researchers really lead the way in a number of areas as we discover new classes of vulnerabilities, we expose poor product security, and we spur public debate.”

The Positive Role of Hackers in Society

The innate curiosity and skills that hackers bring to the table fill a critical role in society.

As an example, Moss noted that if there is a new high-security lock available, the manufacturer will not tell you how to bypass it, and neither is the government. If criminals figure out how to bypass the lock, they are unlikely to say to the public how to do it either. Moss said that researchers and hackers are acting as the sort of public disclosure of the risks of technology.

“The better you understand the risks, the better informed your decisions will be,” Moss said. “If you’re getting that risk information from hackers and researchers and not from the manufacturers, it tells you that there’s a really important civil society role for us for hackers to speak truth to power into reveal what’s really going on.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains