Security News

Microsoft offers defense against 'ice phishing' crypto scammers
2022-02-18 11:17

Microsoft has some advice on how to defend against "Ice phishing" and other novel attacks that aim to empty cryptocurrency wallets, for those not already abstaining. Ice phishing, as Microsoft describes it, is a clickjacking, or a user interface redress attack, that "[tricks] a user into signing a transaction that delegates approval of the user's tokens to the attacker.

Romance scammer who targeted 670 women gets 28 months in jail
2022-01-17 19:13

A UK-based scammer who preyed on nearly 700 women and conned nine of them out of £20,000, has been sent to prison. Romance scammers, just like fraudsters who talk you into investing in bogus cryptocurrency schemes, trick their victims person-to-person by building up a facade based on trust, behind which the criminals persuade their victims to send money of their own accord.

When Scammers Get Scammed, They Take It to Cybercrime Court
2021-12-07 20:01

Blocked from legitimate courts, cybercriminals have set up their own system for settling disputes, handing over ultimate decision-making to senior underground forum administrators who have awarded claims totaling as much as $20 million. A new report from Analyst1 details activities inside these underground systems and found more than 600 requests for mediation on just one Russian-language forum alone, tackling disputes ranging from missing affiliate payments to contract violations.

S3 Ep61: Call scammers, cloud insecurity, and facial recognition creepiness [Podcast+Transcript]
2021-12-02 20:50

Oh! No! The wannabe wizard that went to school with a trainee Sith. LISTEN NOW. Click-and-drag on the soundwaves below to skip to any point in the podcast.

US government securities watchdog spoofed by investment scammers – don’t fall for it!
2021-11-24 19:57

The US Securities and Exchange Commission has issued numerous warnings over the years about fraudsters attempting to adopt the identity of SEC officials, including by phone call spoofing. Call spoofing is where a scammer calls you up on your landline or mobile phone, claims to be from organisation X, and then reassures you by saying, "If you don't believe me, check the number I'm calling from."

Smishing kicks into high gear as scammers use package delivery texts as clickbait
2021-11-23 10:00

'Tis the season for scammers to use SMS messages to deliver malicious links straight to your phone. Jacinta Tobin explained the spike in malicious text messages in a blog post on Proofpoint's site.

Most SS7 exploit service providers on dark web are scammers
2021-11-17 19:34

Are these hacking services as abundant as rumored, or is the dark web full of scammers that are merely waiting to snatch the money of aspiring spies? Analysts at SOS Intelligence have searched the dark web for providers of SS7 exploitation services and found 84 unique onion domains claiming to offer them.

Google Ads for Faux Cryptowallets Net Scammers At Least $500K
2021-11-05 15:51

Crypto-thieves are buying Google Ads to target victims with fake wallets, which steal credentials and drain balances. Clicking on the malicious Google Ad takes the user to a malicious site doctored to look like the Phantom wallet site, Check Point noted.

Squid Game Crypto Scammers Rip Off Investors for Millions
2021-11-02 20:55

Players in the Squid Game cryptocurrency market have been eliminated - at least their investment has - by what cryptocurrency watchers have called a classic "Rug-pull" scam. When SQUID tokens were first released last week, they were valued at a paltry $0.01 but promised entry into a game with the same premise as the Squid Game series from Netflix - players in desperate financial straits compete in a ruthless, deadly series of games for a shot at winning millions.

Week in review: MITRE ATT&CK v10 released, BEC scammers’ latest tricks, WFH security tactics
2021-10-24 08:00

Remote access security strategy under scrutiny as hybrid/remote working persistsA report by Menlo Security highlights growing concerns about securing users as the trend for hybrid and remote working is set to remain. In a recent report, Allianz Global Corporate & Specialty analyzes the latest risk developments around ransomware and outlines how companies can strengthen their defenses with good cyber hygiene and IT security practices.