Information Security Buzz
  • HOME
  • Domains
    • Data Breach
    • Malware
    • Application Security
    • IoT
    • Cloud Security
    • Privacy
  • InfoSec Deals
  • Companies
  • Security Experts
  • ISB Conference 2021
  • Register
  • Log In
Top Posts
Qualys Hit With Ransomware And Customer Invoices Leaked
Experts Reaction On PrismHR Hit By Ransomware Attack
Expert Insight On Ryuk’s Revenge: Infamous Ransomware Is...
ObliqueRAT Trojan Lurks On Compromised Websites – Experts...
Microsoft Multiple 0-Day Attack – Tenable Comment
Experts Reaction On Malaysia Airlines 9 Years Old...
IoT Security In The Spotlight, As Research Highlights...
Oxfam Australia Confirms ‘Supporter’ Data Accessed In Cyber...
Expert Reaction On Solarwinds Blames Intern For Weak...
Expert Reaction On Go Is Becoming The Language...
Information Security Buzz
Connecting Security Experts
  • HOME
  • Domains
    • Data Breach
    • Malware
    • Application Security
    • IoT
    • Cloud Security
    • Privacy
  • InfoSec Deals
  • Companies
  • Security Experts
  • ISB Conference 2021
  • Register
  • Log In
Expert(s): November 30, 2020
Tim Helming
Security Advocatefeature_status*/ ?>
DomainTools

Comments Dotted : 5
January 15, 2021

Expert Insight On Classiscam Expands To Europe

It would be best to validate special offers by searching for them manually, rather than trusting a promotion appearing on a website ad.

If it ain’t broke, don’t fix it! There is no incentive for cybercriminals to abandon a technique that still offers them substantial rewards with relatively small effort. The premise of Classiscam is fairly simple, but some groups have gone to the length of appointing fake customer service representatives to add credibility to their operations, which attests to their determination. We can expect that Classicscam cybercrime operations will try to replicate their success in the West,

.....Read More

If it ain’t broke, don’t fix it! There is no incentive for cybercriminals to abandon a technique that still offers them substantial rewards with relatively small effort. The premise of Classiscam is fairly simple, but some groups have gone to the length of appointing fake customer service representatives to add credibility to their operations, which attests to their determination. We can expect that Classicscam cybercrime operations will try to replicate their success in the West, given the consistent monetary returns that they seem to be yielding for the cybercriminals behind them.

 

The best thing users can do to protect themselves from this kind of fraud is to follow the principle that whenever something seems too good to be true, it probably isn’t. It would be best to validate special offers by searching for them manually, rather than trusting a promotion appearing on a website ad – especially if the page it appears on is not particularly secure. Just like phishing scams, these ad-based operations have a strong social engineering component, and the increased recognition of security awareness training as a defense tool is bound to make it a lot harder for attackers to trick users.

 
 
 
  Read Less
Like(2)  (0)

Linkedin Message

@Tim Helming, Security Advocate, provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"It would be best to validate special offers by searching for them manually, rather than trusting a promotion appearing on a website ad...."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/expert-insight-on-classiscam-expands-to-europe

Copy this message and share on your Linkedin profile. Thanks!

Facebook Message

@Tim Helming, Security Advocate, provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"It would be best to validate special offers by searching for them manually, rather than trusting a promotion appearing on a website ad...."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/expert-insight-on-classiscam-expands-to-europe

Copy this message and share on your Facebook profile. Thanks!
    No Comments Yet ....
Please login to comment.
January 04, 2021

Expert Advise On PayPal Smishing Campaign

Cybersecurity awareness training can help prevent these attacks from being successful.

Thanks to advancing knowledge in cybersecurity, most workplaces do a great job of protecting employees from phishing attacks. However, as much as we advance, so do cybercriminals. As we up our game, so do they. And in order to get around our more robust gateways, they build more creative and targeted attacks, such as scam text messages campaigns – smishing.

 

In this case, the exponential increase in online shopping during the lockdown might have made PayPal an even more appealing brand to

.....Read More

Thanks to advancing knowledge in cybersecurity, most workplaces do a great job of protecting employees from phishing attacks. However, as much as we advance, so do cybercriminals. As we up our game, so do they. And in order to get around our more robust gateways, they build more creative and targeted attacks, such as scam text messages campaigns – smishing.

 

In this case, the exponential increase in online shopping during the lockdown might have made PayPal an even more appealing brand to impersonate. A text saying the account has been limited creates an understandable sense of urgency, and while users have learnt to be wary of fraudulent emails, their attention might be lower with text messages, especially given that many brands now communicate with their users via text.

 

When it comes to protecting your organisation and safeguarding against cybercriminals’ tactics, you need to think like them. Cybersecurity awareness training can help prevent these attacks from being successful. To diffuse the risk from this type of campaigns, teach your employees to always visit websites from a browser, rather than by clicking on the link provided in an email… or a text message!

  Read Less
Like(0)  (0)

Linkedin Message

@Tim Helming, Security Advocate, provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"Cybersecurity awareness training can help prevent these attacks from being successful...."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/expert-advise-on-paypal-smishing-campaign

Copy this message and share on your Linkedin profile. Thanks!

Facebook Message

@Tim Helming, Security Advocate, provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"Cybersecurity awareness training can help prevent these attacks from being successful...."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/expert-advise-on-paypal-smishing-campaign

Copy this message and share on your Facebook profile. Thanks!
    No Comments Yet ....
Please login to comment.
November 25, 2020

Spoofed FBI Domains Pose Risk Of Cybercrime And Disinformation

The FBI is right to advise the public about the risks posed by spoofed domains.
The FBI is right to advise the public about the risks posed by spoofed domains. Cyber criminals use various methods to get the attention of their intended victims, and the letters F-B-I do get people’s attention. Part of being security-aware, which every individual needs to be, is becoming familiar with common abuse patterns. In this case, many of the illegitimate domains use various other words in conjunction with “fbi,” which is a common practice by malicious actors. But, since.....Read More
The FBI is right to advise the public about the risks posed by spoofed domains. Cyber criminals use various methods to get the attention of their intended victims, and the letters F-B-I do get people’s attention. Part of being security-aware, which every individual needs to be, is becoming familiar with common abuse patterns. In this case, many of the illegitimate domains use various other words in conjunction with “fbi,” which is a common practice by malicious actors. But, since legitimate organizations do own variations on their own domain names, Internet users also need to consider the context of any link they are presented with. For example, if a link referring to the FBI (or other government agency) arrives as an unsolicited text message, there is a high likelihood of fraud. When in doubt, users should type the simplest version of the domain name (such as fbi.gov) into the browser, and navigate around the site to find the content they seek.  Read Less
Like(0)  (0)

Linkedin Message

@Tim Helming, Security Advocate, provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"The FBI is right to advise the public about the risks posed by spoofed domains...."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/spoofed-fbi-domains-pose-risk-of-cybercrime-and-disinformation

Copy this message and share on your Linkedin profile. Thanks!

Facebook Message

@Tim Helming, Security Advocate, provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"The FBI is right to advise the public about the risks posed by spoofed domains...."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/spoofed-fbi-domains-pose-risk-of-cybercrime-and-disinformation

Copy this message and share on your Facebook profile. Thanks!
    No Comments Yet ....
Please login to comment.
November 25, 2020

Experts Warning And Advice On Black Friday Threats

While this does not mean that other shoppers can rest easy, it does indicate that Amazon customers may be the ones most at risk of phishing attacks.
Cybercrime does not exist in a vacuum, and this focus on Amazon from threat actors is reflective of just how dominant the retailer has become. While this does not mean that other shoppers can rest easy, it does indicate that Amazon customers may be the ones most at risk of phishing attacks. For this reason, we would recommend exercising extreme caution in the run-up to Black Friday and Cyber Monday, double-checking the sender’s email address, and the domain names in linked URLs, before.....Read More
Cybercrime does not exist in a vacuum, and this focus on Amazon from threat actors is reflective of just how dominant the retailer has become. While this does not mean that other shoppers can rest easy, it does indicate that Amazon customers may be the ones most at risk of phishing attacks. For this reason, we would recommend exercising extreme caution in the run-up to Black Friday and Cyber Monday, double-checking the sender’s email address, and the domain names in linked URLs, before clicking on any links or attachments, and cross-referencing this with known correspondence from Amazon—or whichever retailer you are shopping with.  Read Less
Like(0)  (0)

Linkedin Message

@Tim Helming, Security Advocate, provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"While this does not mean that other shoppers can rest easy, it does indicate that Amazon customers may be the ones most at risk of phishing attacks. ..."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/experts-warning-and-advice-on-black-friday-threats

Copy this message and share on your Linkedin profile. Thanks!

Facebook Message

@Tim Helming, Security Advocate, provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"While this does not mean that other shoppers can rest easy, it does indicate that Amazon customers may be the ones most at risk of phishing attacks. ..."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/experts-warning-and-advice-on-black-friday-threats

Copy this message and share on your Facebook profile. Thanks!
    No Comments Yet ....
Please login to comment.
October 22, 2020

Montreal’s Société De Transport De Montréal (STM) Public Transport System Hit With A RansomExx Attack

Phishing remains the main vector through which ransomware groups are able to make their way into their targets' systems.
Unfortunately for Montreal's STM public transport system, RansomExx ransomware actors are amongst the threat groups that have upgraded their attacks to both encrypt and steal victims' data. This evolution of ransomware attacks is known as 'double-extortion' because criminals are effectively able to ask for a double payment - one to decrypt the files, and the other to stop the stolen data from being made public. The advice for organisations is to put in place defenses that will allow them to .....Read More
Unfortunately for Montreal's STM public transport system, RansomExx ransomware actors are amongst the threat groups that have upgraded their attacks to both encrypt and steal victims' data. This evolution of ransomware attacks is known as 'double-extortion' because criminals are effectively able to ask for a double payment - one to decrypt the files, and the other to stop the stolen data from being made public. The advice for organisations is to put in place defenses that will allow them to spot the traffic generated by the data being redirected to threat actors' servers - this can be done with DNS firewalling. It is also worth remembering that phishing remains the main vector through which ransomware groups are able to make their way into their targets' systems. For this reason, there is really no excuse not to have an effective email filtering system in place and a cybersecurity awareness program for all employees – up to and including incentives and rewards for successfully identifying a phishing email and flagging it to your security teams. Your staff are often viewed as your biggest risk factor from a security perspective, but sensible policy can turn them into your greatest asset.  Read Less
Like(6)  (0)

Linkedin Message

@Tim Helming, Security Advocate, provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"Phishing remains the main vector through which ransomware groups are able to make their way into their targets\' systems...."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/montreals-societe-de-transport-de-montreal-stm-public-transport-system-hit-with-a-ransomexx-attack

Copy this message and share on your Linkedin profile. Thanks!

Facebook Message

@Tim Helming, Security Advocate, provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"Phishing remains the main vector through which ransomware groups are able to make their way into their targets\' systems...."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/montreals-societe-de-transport-de-montreal-stm-public-transport-system-hit-with-a-ransomexx-attack

Copy this message and share on your Facebook profile. Thanks!
    No Comments Yet ....
Please login to comment.

SECURELY DOTTED BY

Jake Moore, Cybersecurity Specialist, ESET

"In general, malicious actors now use full-blown extortion tactics to make sure they get what they came for in attacks like this. "

Qualys Hit With Ransomware And Customer Invoices Leaked

Ilia Kolochenko, CEO, ImmuniWeb

"Qualys’s response to the incident is a laudable example of transparent and professional handling of a security incident. "

Qualys Hit With Ransomware And Customer Invoices Leaked

Natalie Page, Cyber Threat Intelligence Analyst, Sy4 Security

"Due to the nature of this organisation, PrismHR makes for an extremely valuable target to an adversary looking to extract sensitive information. "

Experts Reaction On PrismHR Hit By Ransomware Attack

Lewis Jones, Threat Intelligence Analyst, Talion

"Ransomware renders any files it touches unreadable unless, and until, a victim pays for a digital key needed to unlock the encryption on them. "

Experts Reaction On PrismHR Hit By Ransomware Attack

Stephen Kapp, CTO and Founder, Cortex Insight

"An attack like this will not only impact PrismHR but also its customers who will need access to systems in order to pay employees. "

Experts Reaction On PrismHR Hit By Ransomware Attack

Richard Walters, CTO , Censornet

"“Careless clicks sink ships.” "

Expert Insight On Ryuk’s Revenge: Infamous Ransomware Is Back And Stronger Than Ever

Saryu Nayyar, CEO, Gurucul

"The evolution of the ObliqueRAT trojan is a good example of how malicious actors are constantly updating their tools and techniques. "

ObliqueRAT Trojan Lurks On Compromised Websites – Experts Comments

James McQuiggan, Security Awareness Advocate, KnowBe4

"It is essential to conduct red team or pen testing exercises. "

Experts Reaction On Malaysia Airlines 9 Years Old Data Breach

Nikos Mantas, Incident Response Expert, Obrela Security Industries

"Data security should be a priority for all organisations today. "

Experts Reaction On Malaysia Airlines 9 Years Old Data Breach

David Sygula, Senior Cybersecurity Analyst , CybelAngel

"Organisations must constantly scan for leaked documents outside the enterprise perimeter. "

Experts Reaction On Malaysia Airlines 9 Years Old Data Breach

Satnam Narang, Senior Research Engineer, Tenable

"We expect other threat actors to begin leveraging these vulnerabilities in the coming days and weeks. "

Microsoft Multiple 0-Day Attack – Tenable Comment

Sam Curry, Chief Security Officer, Cybereason

"Total transparency is needed and they need to hone in on more specific details and be completely transparent with Enrich members. "

Experts Reaction On Malaysia Airlines 9 Years Old Data Breach

Florian Thurmann, Technical Director, EMEA , Synopsys Software Integrity Group

"Your organisation won’t be able to determine which of their employees has made a given change in the system. "

Experts Reaction On Malaysia Airlines 9 Years Old Data Breach

Alan Grau, VP of IoT , Sectigo

"Best-practices for IoT device security include strong authentication and secure software updates. "

IoT Security In The Spotlight, As Research Highlights Alexa Security Flaws

Jake Moore, Cybersecurity Specialist, ESET

"Sensitive data such as this leaked into dark web forums can have damaging consequences. "

Oxfam Australia Confirms ‘Supporter’ Data Accessed In Cyber Attack

WORKING WITH US

About Us

Advertise With Us

Information Security Companies

Contact Us

ISB CONFERENCE

ISB Conference 2021

THE PAGES

Privacy Policy

Terms & Conditions

RSS Feeds

INFORMATION SECURITY EXPERTS

Information Security Experts: Comments Dotted

Register and Comments

Categories

  • Facebook
  • Twitter

Copyright © 2020 ISBuzz Pty Ltd is a company registered in Australia with company number 605 203 772 whose registered office is 14 Alanvale Street, Harrison, ACT 2914.


Back To Top
Information Security Buzz
  • Home
  • Experts Comments on News
  • Security Articles
  • Vendor News
  • Study & Research
  • ISBuzz Expert Panel