Tuesday, 3 November 2015

CEO Fraudsters Hit When Using 'Reply-To' Option


Criminals who engage in fraud CEO, also known as business mail compromise, adapt to various new tactics to highlight organizations, such as using the 'reply-to' option. That claims security PhishLabs. CEO fraud is a form of cyber crime involving financial people within an organization to receive an email that appears to come from the director.

In the email is asked to urgently make a large sum of money about. The FBI have criminals in this way for 1.2 billion dollars managed to steal. At the first attack, the criminals were using free email services company or hacked accounts to send fraudulent requests. Now they're using hacked e-mail accounts from Internet company GoDaddy. These accounts are in fact easy to reproduce through phishing attacks, support the use of the 'reply-to' option and the 'identity' feature.

Through this feature simple as the sender can specify any email address. Fraudsters use this feature for composing an e-mail to from a legitimate address of the attacked organization, such as the email address of the director. Then they fill the reply-to address an e-mail address is managed by the criminals. Most e-mail clients only show the name and hide the e-mail address, so employees do not immediately see the reply-to address.

Another change in method is that the first e-mail is concise and contains no payment details. In earlier attacks was financial controller immediately sent to the bank account and amount to. Now the fraudsters exchanged several emails before the account data is transmitted. And also for the bill is the tactic changed. Foreign accounts were first used in China, for example, now the US accounts. PhishLabs advises organizations to create more awareness among the staff and spam filters first so that fraudulent emails are blocked.

Monday, 2 November 2015

Flash Player And Internet Explorer Favorite Cyber Criminal



Internet users who do not update their software run mainly risk of becoming infected with malware if they use Adobe Flash Player and Microsoft Internet Explorer, according to figures from the Russian anti-virus firm Kaspersky Lab. This involves infections via so-called "drive-by downloads."

These cyber criminals use of exploit kits, which automatically infect Internet through unpatched vulnerabilities with malware.Most kits include attacks to exploit vulnerabilities in IE, Flash Player and Silverlight. It is in all of these cases vulnerabilities this year by Adobe and Microsoft were patched. We look at the attacked software, it is mainly Flash Player and Internet Explorer. Attacks on Java even took off. In recent exploit kits there are no exploits for Java included.

Kaspersky Lab also looked at attacks from "web resources" and where those resources are located. 

Forgotten Explorer Vulnerability In Windows 10 Still Patched


Microsoft has previously forgotten vulnerability in Internet Explorer for Windows 10 yet patched. On October 13 released Microsoft Security Bulletin MS15-106 for several critical vulnerabilities in Internet Explorer that could allow an attacker the underlying system could take over completely.

Several of the vulnerabilities were corrected by the Zero Day Initiative (ZDI) of security firm TippingPoint reported to Microsoft. Researchers can at ZDI sell vulnerabilities fee, and TippingPoint notifies the responsible supplier. Next, details of the vulnerability published as the supplier has solved the problem, or has not complied with the deadline of the ZDI.

In this case, made ​​after the publication of the TippingPoint Security Bulletin MS15-106 know that Microsoft is a critical vulnerability in Internet Explorer 11 for Windows 10 had composed, designated as CVE-2015-6045. The vulnerability, however, was not mentioned in the Microsoft Security Bulletin itself, what questions on Twitter made. TippingPoint then pulled the own publication about the vulnerability away.

It now appears that Microsoft had not patched the vulnerability. Thursday appeared namely a new version of the Microsoft Security Bulletin which announces that a new cumulative update was released CVE-2015-6045 in which it is resolved. The update is only for Windows 10, which also need to install the new update. On most systems, however, this happens automatically.

Anti-Virus Neural Network Should Catch More Malware


A small adjustment to malware can cause the virus threat is no longer detected, but an Israeli company claims to have found the solution: artificial neural networks. The neural networks to analyze the properties of millions of malware instances and clean files, and so learned to recognize the characteristics of malware.

The approach should ensure that the virus scanner of the company is better able to detect modified versions of malware that is missed by traditional anti-virus software. Deep learning, such as the approach is called, consists of training of a large network that consists of simulated neurons and synapses to get as complex patterns from the data provided. The intention is that the network can recognize the end of itself completely new ones.

The Israeli Deep Instinct says to train their own neural network with a large number of files and settings. A time- and computing-intensive process, which runs on a cluster of GPUs. According to founder and CTO Eli David can own the solution 20% more malware detection than existing solutions. So it can tell whether a file appears sufficient to existing malware makes it suspicious, says MIT Technology Review.

A small adjustment or particular string in the code is therefore no longer enough to deceive the virus. According to Professor George Cybenko the British Dartmouth College is the idea of ​​neural networks to find malware is not new, but gives the appearance of deep learning possible for renewed interest. He argues that the promised results must first be tested. In addition, malware authors are very persistent. "If there is a breakthrough, they will do research and come with a new approach," he warns.

British Vodafone Customers Hacked Via Reused Password


More than 1800 British Vodafone customers have been hacked by them the password to their Vodafone account also used for other websites, as has informed the telecom provider know. The provider allows attackers this week have attempted to access the account details of customers.

This made the attackers use email addresses and passwords from an unknown outside source. According to Vodafone's own systems are not hacked. Through the data, the attackers were able to log on to the accounts of customers in 1827. In addition, the attackers may access names, phone numbers, bank identification codes and the last four digits of the bank account given.

In a "handful" affected customers attempting to use this data for fraudulent purposes on their Vodafone account. According to Vodafone, criminals can commit fraud with the stolen data and customers run the risk of being targeted by phishing attacks.The provider of these customers blocked the account and they then informed and helped to change the account information.Also, the British police have opened an investigation.

Sunday, 1 November 2015

Third Suspect Arrested For Assault On TalkTalk


The British police for the third time this week arrested a suspect for the attack on the British ISP TalkTalk, with data from less than 1.2 million customers were stolen. That the Metropolitan Police today announced.

The third suspect was arrested yesterday afternoon. It is a 20-year-old man. Earlier this week, two boys were 15 and 16 arrested. The provider has since announced that there is indeed in the attack data is captured, but less than was initially assumed. It is less than 1.2 million e-mail addresses, names and phone numbers of customers. In addition, tens of thousands of birth dates, account numbers and partly made ​​unrecognizable credit and debit card data captured. How the attackers managed to pull the trigger is still unknown.

Pentagon Wants More Cyber Discipline At Workplace


The Pentagon wants employees to have more knowledge of Internet threats and has developed a plan for cyber discipline "in the workplace should provide. Terry Halvorsen announced that the Chief Information Officer (CIO) of the US Department of Defense.

Follow Halvorsen is important that as people go online, they do so with the appropriate rules and knowledge. To achieve this knowledge the Pentagon has developed a plan. "First we look at the basics, such as higher levels of education and more tools for common attacks such as spear phishing, setting up fake sites, things like that." The second step is mainly looked at it the more advanced threats and how they can be prevented. "It is the same combination of training, education and tools, but they are more advanced and you need more education and training." Also according to Halvorsen comes to teaching managers and ensure they know what their responsibilities are and what they need to know.

To bring the desired cyber discipline in card will the Pentagon to work with a scorecard, which measures how leaders, units and commanders do it. "Everyone is judged," said Halvorsen. The new policy has implications not only for the military, but also for suppliers, reports Federal News Radio. In addition, managers will also be held accountable for IT security problems.This relates to measures that both users and their commander accountable if there are violated basic rules for "cyber hygiene". How it will actually look Halvorsen did not know, but according to the CIO know people in the army of the consequences if they do not comply with the basic rules for cyber hygiene.

Lost Smartphones Often Cleared Through Factory Reset



Lost smartphones are often deleted from the factory reset and not be returned to the rightful owner, according to research by anti-virus company Avast. Five months ago the virus fighter intentionally 20 Android smartphones behind in New York City and San Francisco.

The aircraft were the Avast Anti-theft app, Lookout and Clean Master installed. Also, each smartphone contact information was provided. Four phones were returned, but 15 phones were deleted from the factory reset. 11 of the phones were more than 24 hours online after they were "lost" and seven of the phones did Avast follow some months. At the moment that Avast the data published, there were 4 out of lost phones, and in-line use. The virus fighter could monitor usage because the own app survived the factory reset.

Researcher Demonstrates Cheap Disposable Laptop


According to researcher Georg Wicherski has physical access to laptops and other devices at the border or in hotel rooms always been a way for intelligence services to gather information. With the introduction of full disk encryption, it was necessary for the service to apply firmware and hardware implants and to gain access.

The answer to this was the use of disposable data without hardware. Eg laptops that could be thrown away after the trip."Unfortunately, not everyone is a target which is a director and the budget for each trip to buy a new laptop," said Wicherski.The researcher works for security firm Crowd Strike and is co-author of the Android Hacker's Handbook.

Chromebook

This week demonstrated it at a conference in Finland solution, namely an inexpensive disposable laptop based on a Chromebook. Across Vice Magazine Wicherski says that he deliberately chose a Chromebook because they are relatively inexpensive. They are also compatible with Core Boot, opensource firmware. This gives the user more control over the booting process of the laptop, and can thus check that during charging no malware is active.

Every Chromebook itself better protect against attacks can be a pin of the SPI flash memory is removed, the chip containing the BIOS. By removing the pin, the chip 'read-only' and put an attacker can not easily make adjustments. "By using Core Boot, that really the first that runs on your processor, and then as slowly as possible to take control, then for every subsequent step to use cryptographic signatures, it becomes much harder for an implant develop."

Regarding ChromeOS that by default on the Chromebook runs chooses Wicherski sure to replace it by Arch Linux. Due to the tinkering and the required knowledge of the boot process to be disposable laptop is not suitable for everyone, give the researcher. It is also not a panacea. "It only protects against software and firmware implants that are added to the border, and it prevents some hardware implants." Yet users still need to encrypt their communications, otherwise they are vulnerable to software attacks, Wicherski decision.

IBM: Businesses Need Flash Apps Replaced By HTML5


Companies that offer Flash applications are wise to that HTML5 to convert, since the call for an internet browser without plug-ins is getting stronger, says David Strom IBM. Strom pointing to newer versions of Chrome and Firefox that no longer support the old NPAPI plug-sustaining nature. The main reasons for this are security and performance issues.

Recently, Mozilla announced that it is supporting the Java browser plug-in will cease altogether. However, there is a plug-in that is still supported, and that's Adobe Flash Player. Increasingly parties, however, are calling for an alternative, so that Internet users do not need more plug-ins to view online content or use. So pleaded Facebook CSO Alex Stamos before the end of the Flash technology.

According to Strom, this is not a new trend, since the appearance of the first Apple iPad without Flash support organizations have attempted to create websites with HTML5, the intended successor of Flash. This year, however, HTML5 can make its breakthrough, according to security evangelist at IBM. He argues that the time has come for organizations and companies for their Flash based apps to HTML5 to convert.

Less Than 1.2 Million Customer Data Stolen By Talk Talk


When the attack on the British provider TalkTalk took place last week and which two teenagers were arrested, less than 1.2 million customer data stolen, so the affected company has announced. At first it was unclear whether the attackers had managed to access data.

That is still the case, according to a statement from the provider's own website. The specific number of affected customers is not given, except that it is "less" than 1.2 million e-mail addresses, names and phone numbers. Less than 28,000 credit and debit card data of which the middle six figures were removed. Less than 21,000 unique bank accounts and codes, and fewer than 15,000 birth dates. TalkTalk will now inform all affected customers.

The stolen credit and debit card details can not be used for financial transactions, according to the provider. However, as a precaution decided to share bank data of the subscribers affected by the major UK banks to allow them to take extra measures. Subscribers are also advised to get a year's free to leave monitor their credit. In addition TalkTalk advises subscribers to be alert. "Although the scale of the attack is much smaller than initially believed, we advise you to be alert and to take all precautions to protect yourself from fraudulent calls and e-mails."

Fraudulent Android App Appears As A Word Document


Researchers regularly rogue Android apps by posing as porn app or Flash Player, but now there's also discovered a malicious app that will let the user into believing that it is a Microsoft Word document. For example, the icon of the app resembles that of Word.

The file allows users think that matters 'data'. If the file is opened, the app asks for administrator privileges. After installation, the malware seeks to SMS messages and other information like IMEI number, SIM card number, device ID, contact information and other matters and sends it to the attacker. The malware can also send text messages and dial phone numbers specified by the attacker. The app is aimed at Chinese users and is distributed outside of Google Play.

According to security firm Zscaler, discovered that the app is not surprising that PC-based malware techniques appear in the mobile domain, since mobile devices are now ubiquitous. For Windows, there is still active malware via common icons and file names occurs as a document and try to entice users to open.