Skip to main content

Posts

MOVEit and 3 VPN hacked!

  MOVEit At the end of May 2023,  MOVEit , a data transfer program, fell victim to a Ransomware attack  ONE DAY  after vulnerability in the program was made public. Reuters announced the attack on 1 June 2023, and on 7 June the hackers made their terms known. The personal data of a large number of users, including over 100,000 employees of British Airways and BOOTS, to name but these two companies, could have been compromised. VPN - A database containing more than 360 million  SuperVPN  user records has been found publicly accessible on the web. Confidential information such as e-mail addresses and geolocation data are thus made public. -  GeckoVPN  and  ChatVPN : 21 million users' details, including payment details, circulate on dark web forums. These incidents should draw our attention both to the security of the file transfer systems on the market and to the dangers of vulnerabilities being disclosed. When you use the services of a third p...

Operation Triangulation: Kaspersky launches a malware detection tool June 2023 by Kaspersky

Following the report published on the Operation Triangulation attack campaign targeting iOS devices, Kaspersky researchers have released a special "triangle_check" utility that automatically scans for malware infection. The tool is publicly shared on GitHub and available for macOS, Windows and Linux. On 1 June, Kaspersky researchers reported a new mobile APT targeting iOS devices. The campaign uses zero-click exploits transmitted via iMessage to install malware and take full control of the device and user data, with the ultimate aim of spying on users discreetly. The victims included Kaspersky employees, but the company's researchers believe that the scope of the attack goes far beyond the organisation. By continuing their investigation, Kaspersky researchers intend to provide greater clarity and detail on the global proliferation of this spyware. The initial report already included a detailed description of the mechanisms for self-checking traces of compromise using the ...

CHATGPT HAS A VIVID IMAGINATION!

This is what has just happened in the United States, before P. Kevin Castel, Judge of the District Court, S.D. New York in the case of Mata v. Avianca, Inc (1:22-cv-01461). The plaintiff is represented by Steven A. Schwartz, an attorney with 30 years of experience who used the artificial intelligence program ChatGPT to conduct his legal research, the results of which he included in his affidavit. In the documents that he filled in support of his affidavit, he cites eight court decisions that he believes are relevant to his case: #1 Exhibit Varghese v. China Southern Airlines, #2 Shaboon v. Egypt Air, #3 Peterson v. Iran Air, #4 Martinez v. Delta Airlines, #5 Estate of Durden v. KLM Royal Dutch Airlines, #6 Ehrlich v. American Airlines, #7 Miller v. United Airlines, Inc, #8 Ttivelloni-Lorenzi v. Pan American World Airways, Inc (LoDuca, Peter) (Entered: 04/25/2023). However, neither opposing counsel nor the judge himself were able to locate the decisions and citations cited and summarize...

BOT attacks: a growing threat on the Internet

Bot attacks , the malicious and damaging use of automated computer programs known as bots (or BOTS), have become a growing concern and a pervasive reality in the modern digital landscape. BOTS, or software robots, are automated programs originally designed to perform tasks on the Internet without human intervention. Unfortunately, hackers have also managed to turn them into a hacking technique, created with malicious intent, to manipulate, defraud or disrupt a site, application, API or users, potentially causing enormous damage to businesses and users, compromising the security of systems and data. To carry out their BOTS attacks, the majority of hackers use software called botkits, which are freely available online and sold on the Dark Web. Vendors of this type of software also offer paid services to carry out BOT attacks, including software to power DDoS attacks. BOT attacks include, but are not limited to,  Email Spam , which is used to send spam emails containing malicious soft...

SECURITY OF DIGITAL PAYMENTS

LexisNexis Risk Solutions has just published its study on cybercrime in the year 2022 pointing to a 20% annual increase in the rate of digital attacks worldwide with significant peaks in Asia-Pacific, Latin America and North America at the end of the year. The study, which is based on the analysis of 79.8 billion transactions, highlights that alternative payment methods, such as digital wallets, QR code payments and person-to-person transfers, continue to grow in popularity, particularly in the  Asia-Pacific  region with a  50%  year-on-year increase in the region's payment attack rate. The implication, according to Stephen Topliss, Vice President of Fraud and Identity Strategy, is that "multi-factor authentication alone as a defence is inadequate in today's digital world. Organisations, industries and countries need to collaborate and identify the interconnected signals of complex fraud attacks, as criminal networks working in a structured manner are here to stay. T...