Researchers at Abnormal Security have uncovered attempts to steal Office 365 user credentials on the pretext of conducting surveys among employees. In the campaign, the victim receives an email from a genuine SurveyMonkey site, but the message contains a hidden link, which upon clicking, redirects the victim to a Microsoft form submission page. The user has to submit their Office 365 email and password to proceed. This way, the malicious actors steal the unsuspecting user’s Microsoft account security credentials. The email is sent from a real SurveyMonkey domain (surveymonkeyuser.com), but with a different reply-to domain. That reply-to domain was registered only 1 month ago. The…
ISBuzz Team
Researchers at vpnMentor discovered the unsecured database hosted on AWS as part of a broader web mapping project and quickly traced it back to casino app Clubillion in March. The online database, which was finally secured on April 5, was updated with huge amounts of users’ personal information every single day: in the region of 200 million new records, and included personally identifiable information (PII) including emails, private messages, winnings and IP addresses.
The Maharashtra Cyber Police warned citizens not to click on Tiktok links as they may contain malware aimed at capturing user data. An official told PTI that the department had found that fraudsters were creating fake Tiktok Pro links to snare people who want to download the video-sharing device that is now banned in the country along with several other Chinese apps. He said online fraudsters were sending links through WhatsApp and text messages to trap gullible netizens.
Microsoft warns that with the shift to remote working, customers are exposed to additional security threats such as consent phishing, besides conventional credential theft and email phishing attacks. Consent phishing is a variant of application-based attack where the targets are tricked into providing malicious Office 365 OAuth applications (web apps registered by the attackers with an OAuth 2.0 provider) access to their Office 365 accounts. Once the victims grant the malicious apps permissions to their account data, the threat actors get their hands on access and refresh tokens that allow them to take control of the targets’ Microsoft accounts and…
Tech news site Motherboard obtained webinar slides by a company called SpyCloud presented to prospective customers. In that webinar, the company claimed to “empower investigators from law enforcement agencies and enterprises around the world to more quickly and efficiently bring malicious actors to justice.” The slides were shared by a source who was concerned about law enforcement agencies buying access to hacked data. SpyCloud confirmed the slides were authentic to Motherboard.
A new report has revealed the true extent of stolen account logins to be found circulating on the dark web amongst cybercriminals. The Digital Shadows Photon Research team has spent 18 months auditing criminal forums and marketplaces across the dark web and found that the number of stolen usernames and passwords in circulation has increased by 300% since 2018. There are now more than 15 billion of these stolen credentials, from 100,000 data breaches, available to cybercrime actors. Of this number, some 5 billion are said to be unique, with no repeated credential pairs. The “From Exposure to Takeover” report warns that there’s…
Researchers at Agari say that Cosmic Lynx, a new group believed to be from the Russian cybercriminal space, is responsible for more than 200 BEC attacks since July 2019 and shows operational complexity not seen before with other BEC actors. Cosmic Lynx focuses on multinational corporations and tries to score big, asking for large sums (hundreds of thousands or even millions of USD) to be transferred to mule accounts in Hong Kong.
As reported by ZDNet, Mozilla has temporarily suspended the Firefox Send file-sharing service as the organization investigates reports of abuse from malware operators and while it adds a “Report abuse” button. The browser maker took down the service today after ZDNet reached out to inquire about Firefox Send’s increasing prevalence in current malware operations. Mozilla launched Firefox Send in March 2019. The service provides secure and private file-hosting and file-sharing capabilities for Firefox users. Despite its name, the service is in reality accessible for anyone accessing the send.firefox.com web portal.
It has been reported the US Secret Service sent out a security alert last month to the US private sector and government organisations warning about an increase in hacks of managed service providers (MSPs). In a security alert sent out on June 12, Secret Service officials said their investigations team (GIOC — Global Investigations Operations Center) has been seeing an increase in incidents where hackers breach MSP solutions and use them as a springboard into the internal networks of the MSP’s customers.
It has been reported that almost 15 percent of the Android users who were targeted with mobile adware or malware last year were left with undeletable files. It was discovered that several preinstalled adware on Android devices carrying Trojans, loaders, and other malware on top of their “legitimate” payload. Adware is a type of malware that hides itself on a device in a bid to serve undesired adverts, including scam ads, to users. Apps containing adware are usually a big nuisance for users as they can drain battery resources, steal personal details of users, and also increase network traffic.
