Skip to main content

Posts

Weaponized via Word Documents to Steal Users Credit Card Data , A New Malware Attack Dubbed - RevengeHotels

A new malware campaign dubbed “RevengeHotels” targeting hotels, hostels, hospitality, and tourism companies worldwide aimed to steal credit card data of users and Travelers from hotel management systems. The campaign uses email as the main attack vector to deliver malware via weaponized Word, Excel or PDF documents. In some cases, it exploits patched Remote Code Execution Vulnerability  CVE-2017-0199  in Microsoft Office or WordPad. Researchers from Kaspersky observed tow hacking groups ProCC and RevengeHotels targeting the hospitality sector and they found to be active at least from 2015. Tactics Used – RevengeHotels Threat actors use to register typo-squatting domains impersonating the legitimate company names to trick the user believing the email is from the legitimate source. They use to send emails with details for booking hotels and the spear-phishing email written in the Portuguese language with the malicious file named  Reserva Advogados Associados(...

Wide Range of IoT Devices could get Affected due to a super Critical Flaw in GoAhead Web Server

Cybersecurity researchers today uncovered details of two new vulnerabilities in the GoAhead web server software, a tiny application widely embedded in hundreds of millions of Internet-connected smart devices. One of the two vulnerabilities, assigned as CVE-2019-5096, is a critical code execution flaw that can be exploited by attackers to execute malicious code on vulnerable devices and take control over them. The first vulnerability resides in the way multi-part/form-data requests are processed within the base GoAhead web server application, affecting GoAhead Web Server versions v5.0.1, v.4.1.1, and v3.6.5. According to the researchers at Cisco Talos, while processing a specially crafted HTTP request, an attacker exploiting the vulnerability can cause use-after-free condition on the server and corrupt heap structures, leading to code execution attacks. The second vulnerability, assigned as CVE-2019-5097, also resides in the same component of the GoAhead Web Server and can be exp...

Hackers to Take Full Control of User Accounts Using RCS - A New Android Text Messaging Service

RCS expanded as Rich Communications Services is the next generation SMS protocol aimed to replace the SMS and MMS services. It was taken over by GSM Association in the year February 2008. Starting from April 2018 Google started integrating RCS with its instant messaging mobile app Google Allo. RCS is the IP-based messaging service based on SIP and HTTP to provide various services such as group chats, video calls, file transfers and more. RCS Hacking Attacks According to the Security Research Labs report with some implementations RCS functionality not properly protected and it allows a range of different hacking attacks. The improper implementation of RCS functionality in many networks let hackers gain complete control over the user accounts by stealing RCS configuration files that include SIP and HTTP credentials. The implementation lack in certificate and domain validation which allows an attacker to intercept and manipulate communication in the middle and they also fa...

New Spying on Chrome and Firefox Browser by extension Avast and AVG Browsers

If your Firefox or Chrome browser has any of the below-listed four extensions offered by Avast and its subsidiary AVG installed, you should disable or remove them as soon as possible. Avast Online Security AVG Online Security Avast SafePrice AVG SafePrice Why? Because these four widely installed browser extensions have been caught collecting a lot more data on its millions of users than they are intended to, including your detailed browsing history. Most of you might not even remember downloading and installing these extensions on your web browser, and that's likely because when users install Avast or AVG antivirus on their PCs, the software automatically installs their respective add-ons on the users' browsers. Both online security extensions have been designed to warn users when they visit a malicious or phishing website; whereas, SafePrice extensions help online shoppers learn about best offers, price comparisons, travel deals, and discount coupons from various ...

Europol Shuts Down Over 30,500 Piracy Websites in Global Operation

In a coordinated global law enforcement operation, Europol has taken down more than 30,500 websites for distributing counterfeit and pirated items over the Internet and arrested three suspects. Among other things, the seized domains reportedly offered various counterfeit goods and pirated products and services, including pirated movies, illegal television streaming, music, electronics, cracked software downloads, counterfeit pharmaceuticals, and other illicit products. However, it should be noted that the seized web domains do not include any major pirate websites on the Internet. During the investigation, international law enforcement officials: shut down a total of 30,506 web domains, arrested three suspects, seized 26,000 luxury clothes and perfumes, seized 363 liters of alcoholic beverages, and seized an unspecified number of hardware devices. The officials also identified and froze more than €150,000 from several bank accounts and online payment platforms. The domai...

20Million + Users Stolen Personal Records and been Sold on Dark Web for $4,000 to $ 5000

MixCloud investigating a data breach that impacts more than 20 million registered users for the service. MixCloud is a popular music streaming service. The platform allows the listening and distribution of radio shows, DJ mixes, and podcasts which are uploaded by its users. The company said it has more than 17 million users. MixCloud  was found in the year 2008 and the company located in the United Kingdom and it falls under European data protection rules  GDPR  rules. MixCloud Data Breach A dark web seller knows bt the handle “A_W_S,” listed the data of MixCloud for sale on dark web forums from $4,000, to $5000 or about 0.5 bitcoin. According to Motherboard  analysis  of the data shared by the seller, the data breach found to happen in November and the data found to be authentic. Motherboard verified the data bu using an email sign-up feature, and they found those email addresses are already linked with the account. The following are the data...

Tens of Millions of SMS text Messages & Massive Private Data Leaked Online From Hacked Database

Researchers discovered a massive hacked database online that exposed tens of millions of SMS text messages, and private data belongs to a U.S company TrueDialog. TrueDialog is an American communication company that offering SMS texting solutions to companies such as businesses, universities, and colleges in the USA. Companies claim that they provide Enterprise-grade SMS Texting service, but this massive data leak indicates and leads to huge risks for their customers who have sent and received an SMS for a year of the period. By holding an unsecured database, TrueDialog leaked millions of people’s sensitive data across the USA, and the researchers confirmed that the unprotected database belongs to TrueDialog by finding the evidence of their Host ID “api.truedialog.com”. Discovered database, Also contains millions of account usernames and passwords, PII data of TrueDialog users and their customers, and much more. Since the uncovered database huge volume of data, there is n...