Lost24

The security experts from ESET company have discovered a new malware, called Industroyer, that was designed to target equipment installed in power grids.

The experts claim that Industroyer is very dangerous software because it is capable of attacking so-called critical infrastructure, through controlling electricity substation switches and circuit breakers directly. To do so, it uses industrial communication protocols used worldwide in power supply infrastructure, transportation control systems, and other critical infrastructure systems (such as water and gas).

Malicious software has a primary and secondary backdoor feature  a port scanner to search the local network for attached devices, and a data wiper module that deletes the malwa

Lost24

The portal Zaufana Trzecia Strona has recently informed about a leakage of over 50,000 data records from the Independent Public Medical Facility in Koło (town in central Poland).

The stolen data did not concern patients alone, but also included  confidential informations about the hospital staff.

The culprits responsible for the theft have accessed patient healthcare records, containing the most valuable information available, including personal and social security numbers, home addresses and patient health histories.

In the case of hospital staff, the stolen data included series and numbers of the ID cards, mothers' maiden names and bank accounts' numbers.

Surprisingly, to acquire the access to

Lost24

Last month, the police in eastern China's Zhejiang province have arrested 22 people on suspicion of  illegally obtaining and selling iPhone customers data.

It was confirmed that the suspects worked in direct marketing and outsourcing for Apple in China.

The Chinese officials claim that the arrested searched an internal Apple database for sensitive info and then sold it to the black market vendors for between 10 to 180 yuan ($1.50 to $26.50) per piece of information. It is estimated that the suspects may have earned over 50 million yuan, which is the equivalent of approximately $7.4 million.

Apple users are probably wondering what sort of information was stolen/sold?
The data contained customer's names, phon

Lost24

A sophisticated phishing campaign has been directed at the iCloud app users. Recently, a large group of Apple's clients have been receiving false e-mail messages informing the user that their iCloud accounts have been compromised and need to be reset. In order to do so, the users are advised to click on the attached link.
Upon clicking the link the users are redirected to a fake, phishing page designed to look like a official Apple's website. The users are then asked to enter their Apple ID and password to proceed. Once the login process is complete, the victims are advised to confirm their personal information, including their address, phone number, date of birth and credit card information.
This is more than enough information for identity thieves to steal the

Lost24

The security experts from Check Point company have recently discovered a new threat, known as Judy.

What exactly is “Judy”, and why is it considered dangerous?

In short, Judy is a new virus which has successfully bypassed the Google Play Store’s security means, and infected over forty popular game apps. Each app containing Judy's code is capable of silently registering the endangered device to a C&C server, and download additional payload that starts the actual malicious process.

Furthermore, the Judy apps can also display a large number of advertisements. The ads would often dominate the screen almost to the point that the users would need to click on the ads to get rid of them.

According to

Lost24

The security experts from Georgia Institute of Technology (“Georgia Tech”) have discovered a new class of potential attacks affecting Android devices. The exploit, called Cloak and Dagger, affects all versions of Android systems, including the latest 7.1.2.

The way Cloak and Dagger works is pretty straightforward: a malicious app gets downloaded and installed to the Android device, with the necessary permissions being granted without requiring the user’s input.

The exploit takes advantage of two Android permissions – SYSTEM_ALERT_WINDOW (“draw on top”) and BIND_ACCESSIBILITY_SERVICE (“a11y”). The first permission allows apps to overlap on a device’s screen, and the second lets disabled users enter inputs via voice commands.&l

Lost24

We have already written about biometric security systems, commonly implemented, as an additional security measure in debit or credit cards. Similar biometrics-based authentication systems can be found in modern smartphones.
 
One of the most popular models – Samsung Galaxy S8 smartphone – was equipped not with one but three biometric security systems, including face recognition, a fingerprint scanner, and – advertised as “one of the safest ways to keep your phone locked” – an iris scanner. Unfortunately, this claim is now longer true.
 
German hackers from the Chaos Computer Club (CCC) have proven that Samsung’s iris scanner can be fooled by showing it a picture of the owner’s eye. 
However, i

Lost24

It's a possibility because the “world's first operational Robocop” has already reported for duty in Dubai.

The robot, a customized REEM model was designed by the Spanish company PAL Robotics. Here you can see the robot in action. It is less than 170 cm tall, and its armor is made of high-strength plastic.

The main advantage of the robot is its ability to communicate in several languages, which is a big plus for providing information to foreign visitors. The machine is equipped with a touch screen that can be used to pay fines for traffic violations, or to report offenses and crimes directly to the local police station. It is also fitte

Lost24

Internet Protocol (IP) webcams can be infected with a new Internet of Things (IoT) botnet called Persirai.

It has been estimated that almost 2000 IP cameras' models of various brands are vulnerable to the Persirai's attacks, due to several flaws found in there firmware (software built into the device that provides basic operating procedures). The vulnerabilities can be easily exploited by cybercriminals in variety of ways, for example by commandeering the vulnerable devices as minions in Distributed-Denial-of-Service (DDoS) attacks.

Fortunately, so far no main DDoS assaults utilizing Persirai have been detected, however this might be the preliminary staging for an additional main assault.

The security experts from Trend Micro claim t

Lost24

Do not be fooled by the tempting messages send via WhatsApp, offering one year of free membership access to Netflix.

WhatsApp users have been receiving scam messages from friendly sources, linking to a Netflix-like page. The person who clicks on the link will be redirected to the page that promises free access to Netflix on one condition – sending the link to 10 more people using the WhatsApp messenger.

If the condition is met, the victim is redirected to an external domain, unrelated to Netflix, that uses a trusted certificate to feign legitimacy. This page has the ability to automatically detect a device’s language and display its contents accordingly. It also allows the cybercriminals to mine the mobile devices for data, send SMS messag

Lost24

The security experts from Google Project Zero have revealed a vulnerability associated with Wi-fi chipsets developed by Broadcom, currently being used in the Android, iPhone, Samsung, Acer, Motorola, LG, Sony Ericson and Asus devices.

The flaw can be exploited by hackers to gain control over the device. In order to do so the attackers need to be within the Wi-fi range of the affected device to silently take it over. The vulnerability allows to send Wi-fi frames, crafted with abnormal values, to the Wi-Fi controller in order to overflow the firmware’s stack.

High-skilled hackers can also deploy malicious code to take full control over the victim's device and install malicious apps, like banking Trojans and ransomware, without the victim's kno

Lost24

Cybercriminals have attacked PKO BP bank clients. Fraudsters have been sending false e-mail messages entitled "Payment confirmation".

The messages do not contain any text, but only attached PDF file named "pko-trans-details-170507-121204.pdf".

As reported by the Niebezpiecznik portal, when the file is being opened, it tries to establish a connection with the cybercriminals' server. If a user opens a file using Adobe Acrobat Reader in Windows, the connection to the server is blocked.

However, should the user open the file with another program, he or she may download the malicious file which will infect the computer.

PKO BP bank assures that they analyze every signal and information recei

Lost24

Once again Android OS uses were attacked by the unknown group of cybercriminals. The hackers have created a new banking malware, masquerading as a Flashlight LET Widget app. Dissimilar to other banking trojans with a static arrangement of targeted banking apps, this malware can progressively change its functionality.

The malicious app, detected by the security experts from ESET company, was defined as Trojan.Android/Charger.B.

Once the app is installed and launched, it requests device administrator rights. With the rights and permissions granted, the app hides and is available only as a Widget.

The malware registers the infected device to the hackers’ server. Based on commands from the server, the trojan can steal victims

Lost24

Microsoft is enabling a new Microsoft Account sign-in option as a handy addition to the company’s iOS and Android Microsoft Authenticator phone app. Instead of using Microsoft Authenticator for two-step authentication, the app user can sign into the account without a password.

The new feature is available for website sign-ins that require Microsoft Account, such as Outlook.com, Skype.com, and OneDrive.com.

How dose it work?
To enable the feature, the user must first install the Microsoft Authenticator app, then select his or her account from the dropdown button and lastly choose enable phone sign-in. From now one, during logging into a Microsoft Account, a new option “Use the Microsoft Authenticator app instead” will appear at t

Lost24

On April 24, 2017, the Polish Ministry of Digital Affairs has activated a new e-service entitled "Check your penalty points", which allows every driver to verify their actual sum of penalty points earned for traffic offenses.
What is important, the new on-line service is available for FREE on the government portal https://obywatel.gov.pl.
Aside from the amount of the penalty points, each driver can also verify additional informations, such as the date/place of the traffic offense, and the type, brand and the registration number of vehicle involved.

In order to use the service safely, the drivers ought to set up a trusted eGO profile by filling up the on-line registration form, available at the https://pz.gov.pl

Read more

0 - Comment