Posts

Showing posts with the label USB Drives

The Biggest Takeaways from Recent Malware Attacks

Image
Among the never-ending list of malicious software that threat actors use in cyber attacks are viruses, worms, trojans, ransomware, spyware, and adware. Today's malware is not just about causing immediate damage; some programs get embedded within systems to siphon off data over time, disrupt operations strategically, or lay the groundwork for massive, coordinated attacks.  A prime example is a recently found malicious backdoor in a popular compression tool, known as xz Utils. Thankfully the malicious code was identified early “due to bad actor sloppiness”, but the consequences could’ve been massive. Read on to get the lowdown on recent high-profile malware attacks along with strategies to help limit malware risks at your organization.  Recent High-Profile Malware Attacks Here's a detailed overview of recent malware attacks, highlighting key incidents and offering valuable insights and lessons learned from each event. StripedFly A prolific and advanced cross-platform malware fra...

Thwarting attacks from the charging socket: Team explores protecting mobile device touchscreens from 'ghost touch'

By Silke Paradowski,  TechXplore Touch screens on mobile devices can be attacked and manipulated via charging cables and power supply units. This is what researchers at the System Security Lab at TU Darmstadt have discovered together with a Chinese research team. Several smartphones and standalone touchscreen panels could be compromised in practical tests by simulated touches, the "ghost touches." The results were presented at this year's IEEE Symposium on Security and Privacy. The researchers from TU Darmstadt and Zhejiang University in Hangzhou carried out attacks on capacitive touchscreens via charging cables and power adapters, revealing a new way to attack mobile devices. Similar to their previous research project, "GhostTouch," the researchers were able to create false touches, called "Ghost Touches," on multiple touchscreens and manipulate the device via them. The international research team had to overcome two main challenges. The first was to ...

City contractor goes out for drinks after work, loses memory stick containing personal data on nearly half a million residents

By CBS A Japanese city has been left with more than a headache after admitting a contractor lost a USB containing personal data on all 460,000 residents during a night out. The western city of Amagasaki said Thursday that a private contractor, whose name has not been disclosed, was carrying the memory stick when he went to have drinks after work. But the individual, who was working on a municipal pandemic relief program, lost the bag containing the USB on Tuesday evening.  "We deeply regret that we have profoundly harmed the public's trust in the administration of the city," an Amagasaki official told a press conference. The information was copied onto the USB to facilitate its transfer to a call center in nearby Osaka. It included the names, genders, addresses, birthdays and other personal information of all the city's residents, as well as tax data and bank account information on some locals, the city said. But there may be a silver lining, as the city says the data...

When Your Smart ID Card Reader Comes With Malware

Image
By  Krebs On Security Millions of U.S. government employees and contractors have been issued a secure smart ID card that enables physical access to buildings and controlled spaces, and provides access to government computer networks and systems at the cardholder’s appropriate security level. But many government employees aren’t issued an approved card reader device that lets them use these cards at home or remotely, and so turn to low-cost readers they find online. What could go wrong? Here’s one example. KrebsOnSecurity recently heard from a reader — we’ll call him “Mark” because he wasn’t authorized to speak to the press — who works in IT for a major government defense contractor and was issued a Personal Identity Verification (PIV) government smart card designed for civilian employees. Not having a smart card reader at home and lacking any obvious guidance from his co-workers on how to get one, Mark opted to purchase a $15 reader from Amazon that said it was made to handle U.S. ...

Stealthy Raspberry Robin Worm Is Spreading Malware Via USB Drives

Image
by Zak Killian, Hot Hardware When you are investigating a crime, one of the most important things to establish is "motive." If you know a crime has been committed, having an understanding of why it happened is a critical step to figuring out who did it. In the strictest sense, installing software on someone else's computer isn't a crime. It's not until it becomes malicious software—"malware"—that it's a problem, and it doesn't become malware until it does something troublesome, like encrypting user files, opening security backdoors, or crashing the system altogether. Threat intelligence group Red Canary is tracking a worm that it calls Raspberry Robin, and it's definitely malware, but the question of "why" is still, in fact, a big question. Red Canary has found the worm in multiple of its customers' environments starting back in September 2021, though it says most of the activity from the threat has occurred since January of thi...