Investment scams are on the rise

Credit to Author: Pieter Arntz| Date: Fri, 04 Feb 2022 12:50:38 +0000

Investment scams are on the rise. What types are there and how can you recognize them?

Categories: Scams

Tags:

(Read more…)

The post Investment scams are on the rise appeared first on Malwarebytes Labs.

Read more

Q&A: CISO sees 'enterprise' browser as easier way to monitor employee web use

Credit to Author: Lucas Mearian| Date: Fri, 04 Feb 2022 03:00:00 -0800

Over the past several years, Ashland Specialty Chemicals, a global specialty materials and chemical company with about 4,200 employees, has been downsizing. It shuttered its physical datacenter and adopted more of a software-as-a-service strategy for business apps such as Salesforce and Workday. With the shift to the cloud, the company also had to address keeping web traffic secure as its hybrid workforce accessed sensitive data online.

While the company continues to use more traditional, and costly, firewalls such as Cloud Access Security Brokers (CASB) and Secure Access Service Edge (SASE) to secure web gateways, it has also been testing an enterprise-specific browser from a start-up company named Island

To read this article in full, please click here

Read more

A worrying Etsy listing reveals the stalking potential of Apple’s AirTags

Credit to Author: Thomas Reed| Date: Thu, 03 Feb 2022 21:41:51 +0000

A “silent” AirTag listed for sale on Etsy reveals, once again, how Apple’s tracking devices could potentially be used for stalking.

Categories: Malwarebytes news

(Read more…)

The post A worrying Etsy listing reveals the stalking potential of Apple’s AirTags appeared first on Malwarebytes Labs.

Read more

IaC: Azure Resource Manager Templates vs. Terraform

Credit to Author: Melanie Tafelski| Date: Thu, 03 Feb 2022 00:00:00 +0000

Dive into a hands-on comparison of Azure Resource Manager templates and Terraform. This article highlights the primary features of each solution, comparing and contrasting their capabilities and performance.

Read more

How Phishers Are Slinking Their Links Into LinkedIn

Credit to Author: BrianKrebs| Date: Thu, 03 Feb 2022 18:49:38 +0000

If you received a link to LinkedIn.com via email, SMS or instant message, would you click it? Spammers, phishers and other ne’er-do-wells are hoping you will, because they’ve long taken advantage of a marketing feature on the business networking site which lets them create a LinkedIn.com link that bounces your browser to other websites, such as phishing pages that mimic top online brands (but chiefly Linkedin’s parent firm Microsoft).

Read more

Second Israeli firm accused of undermining iPhones, like NSO Group

Credit to Author: Jonny Evans| Date: Thu, 03 Feb 2022 09:08:00 -0800

As if recent revelations about NSO Group weren’t bad enough, yet another Israeli firm — QuaDream — has now been accused of using the same hack to undermine iPhone security.

QuaDream also used the hack, Reuters claims

A Reuters report has the details:

  • QuaDream made use of the same flaw to commit similar attacks against iPhones.
  • The company is smaller than NSO Group, but also sells smartphone hacking tools to governments.
  • Both companies used the same highly sophisticated “zero-click” ForcedEntry attack, which enabled them to remotely break into iPhones without an owner needing to click a malicious link.
  • Once deployed, attackers using the software could access messages, intercept calls, and use the device as a remote listening device. They also gained access to the camera and more.
  • Apple closed this vulnerability in September 2021.
  • It is believed NSO Group software was used to target the family of murdered Saudi journalist Jamal Khashoggi.

The news follows the revelation that the FBI also obtained NSO’s Pegasus spyware, but claims it did not use it. That  also follows another recent claim that NSO Group offered “bags of cash” in exchange for access to US cellular networks via the SS7 network.

To read this article in full, please click here

Read more

Beware bogus OperaGX sponsorship offers

Credit to Author: Christopher Boyd| Date: Thu, 03 Feb 2022 15:36:45 +0000

We look at a scam targeting YouTubers, via an entirely fictitious sponsorship and promotional deal for OperaGX

Categories: Social engineering

Tags:

(Read more…)

The post Beware bogus OperaGX sponsorship offers appeared first on Malwarebytes Labs.

Read more

$320 milllion stolen from Wormhole crypto-trading platform

Credit to Author: Pieter Arntz| Date: Thu, 03 Feb 2022 15:27:55 +0000

Threat actors have stolen an estimated $322 million in cryptocurrencies from the Wormhole trading platform.

Categories: CryptoReports

Tags:

(Read more…)

The post $320 milllion stolen from Wormhole crypto-trading platform appeared first on Malwarebytes Labs.

Read more