Home Artists Posts Import Register

Content

We had a bunch of security and privacy news to talk about from the past week!

Hackers found a way to bypass the MasterCard PIN code and make terminals think they're using Visa credit cards instead. Very cool findings! 

https://thehackernews.com/2021/02/new-hack-lets-attackers-bypass.html


According to reports, North Korean attackers may have hacked into Pfizer to find COVID data. 

https://arstechnica.com/gadgets/2021/02/north-korea-may-have-hacked-into-pfizer-servers-looking-for-covid-data/


Speaking of NK, the US DOJ has charged 3 attackers from North Korea for presumably being involved in attacks on Sony, their actions with Wannacry, and for trying to steal 1.3 billion in cash and cryptocurrency.

https://www.cnet.com/news/doj-charges-more-hackers-in-sony-wannacry-attacks/


Let's Encrypt announced they're replacing 200m certificates a day with newly installed infrastructure. Yay!

https://threatpost.com/lets-encrypt-gears-up-to-replace-200m-certificates-a-day/164002/


A new Bluetooth skimmer is being used to steal credit card data off of retail machines!

https://krebsonsecurity.com/2021/02/bluetooth-overlay-skimmer-that-blocks-chip/


An attacker gained access to the water treatment plant in Oldsmar, Florida. Investigators are now suggesting it happened because of weak password use.

https://www.cyberscoop.com/florida-water-facility-hack-password/


Facebook has started blocking content in Australia in response to a new law. 

https://about.fb.com/news/2021/02/changes-to-sharing-and-viewing-news-on-facebook-in-australia/






ACTION ALERTS!

A new phishing email is being used as the first step in this new malware infection! Masslogger targets and steals creds from several different desktop apps including Discord, Firefox, and Chromium based browsers. The emails sent contain a .chm file extension attachment. Be alert and on the lookout for these kind of threats.

https://threatpost.com/masslogger-microsoft-outlook-google-chrome/164011/


Favicons are being exploited (but not in the wild, yet). This research is very cool! You can disable favicons for the time being while we wait for a fix from browser makers.

https://arstechnica.com/information-technology/2021/02/new-browser-tracking-hack-works-even-when-you-flush-caches-or-go-incognito/


QNAP Patched a critical vulnerability. Update now!

https://www.bleepingcomputer.com/news/security/qnap-patches-critical-vulnerability-in-surveillance-station-nas-app/

Comments

No comments found for this post.