Wednesday, February 19, 2020

Google Chrome Play Store Malware, Phishing and now Smishing, IDF Soldiers tricked and more Security News

Google Chrome Extensions.  500 plus extensions spreading dangerous Malware!

I like a lot of users have been using Google's Chrome browser in lieu of other browsers for the past few years.  It was faster and promised to be more secure.  That is not the case any longer.  Hackers have now infiltrated Google's Play Store with more than 116 new malicious apps offered for download.  More than 500 extensions containing malware have been discovered around the world.

Read more and how to check and remove offending extensions at;

https://www.komando.com/security-privacy/chrome-extensions-spread-malware/707273/


Israeli soldiers tricked into installing malware by Hamas agents posing as women

"Members of the Hamas Palestinian militant group have posed as young teenage girls to lure Israeli soldiers into installing malware-infected apps on their phones, a spokesperson for the Israeli Defence Force (IDF) said today."

https://www.zdnet.com/article/israeli-military-tricked-into-installing-malware-by-hamas-agents-posing-as-women/


Microsoft detects and tracks a daily average of around 77,000 active web shells, spread across 46,000 infected servers.

Email users receive numerous emails on a daily basis purporting to be voicemails, faxes or files.  The emails look to be from legit users or maybe from someone they know, either someone the hacker is spoofing or a compromised user.  Often times these emails allude to an invoice or payment, anything to entice the user to open or click on the link or attachment.  Many of these emails are simply tricks to fool the target into giving up their Microsoft Office, Social App or financial credentials.  These are easier to prevent from falling victim to, simply do not give up your credentials without verifying the legitimacy of the email's source.  Of more concern are emails that link to compromised servers hosting websites that are infected with web shells.

Microsoft has released info that it detects and tracks a daily average of 46,000 infected servers.  On these servers, they find 77,000 active web shells.

If you follow a link that lands you on an infected server/website. hackers use web shells to upload other hacking tools on a victim's systems, tools that are later used for reconnaissance operations and lateral movement across a victim's internal network, making simple web server hacks into much bigger security incidents.

If you aren't sure about an email, do not open.

To read more about this serious threat click on the following link;

https://www.zdnet.com/article/microsoft-says-it-detects-77000-active-web-shells-on-a-daily-average/?ftag=TRE49e8aa0&bhid=27630927001468733386426006914379


Phishing scams are costing us more than ever. This trick is most likely to catch you out.
Scammers are still getting big payouts from business email compromise attacks - but almost two-thirds of attacks involve a much simpler scheme.

Businesses are losing over $700m a month to cybercriminals because employees are falling victim to phishing attacks, business email compromise campaigns, and gift card scams – and the amount of money being lost is still on the rise.
Large wire transfers make a significant percentage of the successful attacks

https://www.zdnet.com/article/phishing-scams-are-costing-us-more-than-ever-this-trick-is-most-likely-to-catch-you-out/

This latest phishing scam is spreading fake invoices loaded with malware

Prolific malware turned botnet shows no signs of slowing down as campaigns are launched against financial institutions in the US and UK.

Emotet started life as a banking trojan but has also evolved into a botnet, with its criminal operators leasing out its capabilities to those who want to distribute their own malware to compromise machines.

https://www.zdnet.com/article/this-latest-phishing-scam-is-spreading-fake-invoices-loaded-with-malware/


Scammy, spammy texts have come to your phone. Here's how to avoid getting ripped off by scam artists who've added social engineering to their toolbox.

The computer is not the only device under attack by hackers and con men.  Nowadays, more users are conducting financial transactions using their mobile devices, smartphones.  With the advent of the mobile wallet and financial apps, the bad guys are targeting mobile users with SMS messages or what is called "Smishing" coined from the similar email Phishing term.

For more information and ways to protect yourself, click on the following link;

https://www.howtogeek.com/526115/what-is-smishing-and-how-do-you-protect-yourself/


Mac malware threats are now outpacing attacks on Windows PCs

https://www.zdnet.com/article/mac-malware-is-growing-fast-but-its-still-not-as-dangerous-as-the-attacks-on-windows/

Wednesday, February 12, 2020

Security Updates: Last night was Update Tuesday, Microsoft's February 2020 Patch Tuesday fixes 99 security bugs

Microsoft's February 2020 Patch Tuesday fixes 99 security bugs

The second Tuesday of each month has become known as Patch Tuesday.  Microsoft released yesterday the February 2020 Patch Tuesday security updates. This month's updates include fixes for a whopping 99 vulnerabilities, making this Microsoft's biggest Patch Tuesday known to date.

With the possible combination and variety of installed programs not to mention a myriad of hardware configurations, issues are always a possibility.  Many users postpone updates, however, if possible install updates when available.  The internet is criminal infested and users and their info are under constant assault whether by Google, Alphabet, Facebook, and others gathering information discretely about you or criminals trying to steal your financial information.  There are many legit firms who collect your information and sell it to marketers and then they are hacked and your info is stolen along with millions of others.

On January 17, Microsoft disclosed ongoing attacks where hackers were using this IE zero-day, however, at the time, the OS maker could not provide a patch. This patch is now included with this month's cumulative security updates.

Read about this important update the following link;

https://www.zdnet.com/article/microsofts-february-2020-patch-tuesday-fixes-99-security-bugs/?ftag=TREc64629f&bhid=2219791


Say it's not so! Windows 12 is coming in 2024. Apple iPhone malware/exploits.

Windows 12 is coming soon in 2024 I've read too many emails and articles hinting at a new Windows in the months leading up to 2024 and n...