Showing posts with label cybercrime. Show all posts
Showing posts with label cybercrime. Show all posts

Tuesday, October 29, 2013

Buffer App strengthens security becuase of spam.


buffer-hacked
http://www.hyphenet.com/blog/buffer-app-strengthens-security-becuase-spam./

bufferapp.com, a social sharing website that allows you to schedule posts on Facebook, Twitter and Google+, was attacked with spam on Saturday.  The attack was first noticed when a blast of spammy weight-loss links were added to users Facebook and Twitter pages.

If you opened up the links to the weight-loss sites, it is possible you may have opened your system to a bit a spam yourself.

It looks like Buffer blasted Facebook only with the weight-loss spam and nothing else, but sources are still indefinite.

Buffer has fixed the problem and upgraded their security to prevent the spam from happening again.

“We greatly apologize for this big mess we’ve created. Buffer has been hacked,” co-founder Leo Widrich said in a Facebook post on Saturday morning.

The Buffer App, said on Sunday it is encrypting OAuth access tokens.  This allows users to access other applications and will do so without revealing passwords.  Buffer also created a new security parameter to the API (applications programming interface) calls, making it nearly bullet-proof.

Buffer’s founder Joel Gascoigne wrote, “We have greatly increased security of how we are posting to Twitter and Facebook and have confidence to cover the security holes the hackers have used to break into our system.”

Facebook said 30,000 Buffer users were affected with the spam issues.  This is around 6.3 percent of the 476,343 Facebook accounts connected to Buffer.


When Buffer users go back to their accounts, they will need to reconnect to their Twitter accounts but not their Facebook ones.

The company continues to work on examining exactly what happened, including how the hackers managed to break into Buffer and just what, exactly, are the consequences from the spam.

Have you seen a trend in weight-loss sites in your Facebook?  Let us know your experience below!

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+.

References:
Buffer encrypts access tokens after spammer hack – CSO
http://www.cso.com.au/article/530175/buffer_encrypts_access_tokens_after_spammer_hack/
October 28, 2013
Schedule-Posting App Buffer Survives Spam Attack, Back Online – PC Magazine
http://www.pcmag.com/article2/0,2817,2426403,00.asp
October 27, 2013
Social Sharing App Buffer Hacked, Temporarily Halts Service – All Things D
http://allthingsd.com/20131026/social-sharing-app-buffer-hacked-temporarily-halts-service/

Monday, October 7, 2013

How to Spot Banking Cyber-Criminals in the Act

Banks are trustworthy financial institutions that we don’t think twice about handing our money over to.   This is why we have to be aware of the banking thieves waiting for us to give up our personal information, because many of these attacks seem very convincing.

Cybercriminals are good at swindling you into thinking they are trustworthy companies just trying to help you out.  Don’t be fooled, there are ways to tell weather or not the emails and phone calls are fake.

Hesperbot a new Trojan that has been detected by ESET, uses high-tech mechanisms to bypass the banking security systems.  This is canny social engineering trick for victims to fall for the scam.

Here are some tips to use when distinguishing between the behavior of a banking thief and the real institution:

number-one
http://www.hyphenet.com/blog/spot-banking-cyber-criminals/
Never confirm anything through a text message
Banks will send you a text, informing you that your account has changed.  Do not believe this!  Banks will not ask you to confirm anything through a text message.  Do not ever click on links or put in passwords from a text message you may receive from a bank.



number-two
http://www.hyphenet.com/blog/spot-banking-cyber-criminals/
Don’t believe any deadline threats
Banks will let you know if something is “urgent” with suspicion of fraud pertaining to matters regarding your funds.  Banks will not ever send you a message threatening a deadline about your account shutting down. Cybercriminals are always in a rush to get you to fall for their scam.  Their websites are often flagged or blocked pretty quickly so the faster you respond to their “urgent” message, the better for them.



number-three
http://www.hyphenet.com/blog/spot-banking-cyber-criminals/
Don’t trust links about a “new version” of your banking app
There are noted attempts of fraudulent instillation on your phone with a new app for your banking system.  The malicious apps are trying to bypass security systems to get into your bank accounts.  You can call your bank to double check on the upgrade, or go to their website.  These apps are now being analyzed.



number-four
http://www.hyphenet.com/blog/spot-banking-cyber-criminals/ 
Watch out for shortened URLs in an email
Cybercriminals can use shortened URLs to trick people into clicking onto a fraudulent website.  URL-shortening deceives users into clicking a link without ever knowing where it will take you.  You may have seen shortened URLs from twitter and YouTube, but your bank will not use them.



number-five
http://www.hyphenet.com/blog/spot-banking-cyber-criminals/
Don’t trust couriers to pick up your “faulty” bank card
Courier scams are starting to become a problem with bank fraud.  The “bank” will call you telling you a courier will arrive to collect a faulty bank card.  A courier then arrives at your home asking for your bank card because it is “faulty” then proceed to give you a new bank card that is safe to use.  Do not fall for this.  And don’t let them in your house.  If your card is indeed faulty, the bank will instruct you to destroy it.  Never hand your bank card over to anyone.



number-six
http://www.hyphenet.com/blog/spot-banking-cyber-criminals/ 
Watch out for phone calls for you to “prove” your identity
A new scam is a phone call from either “the police” or “your bank”, telling you they have found fraudulent transactions on your card.  The criminals will ask you to prove your identity by calling a real bank number.  The trick is, when you hang up the criminals are still on the phone with a fake dial tone, then they ask you to enter your passwords and you just gave your account into away.



number-seven
http://www.hyphenet.com/blog/spot-banking-cyber-criminals/ 
Don’t believe new email addresses
Be wise to receiving an email to your work email or any other address letting you know they are contacting you this way because it is a work day and they are more likely to get a hold of you.  Banks will not add another email address on their own.  The email address you give them should be the only one in their system.



number-eight
http://www.hyphenet.com/blog/spot-banking-cyber-criminals/
Check to make sure the web page is secure
If you are on a real banking website, there should be a symbol in your browser’s address bar.  This shows you it is secure with a lock padlock or unbroken key symbol.  If there is no symbol in the browser, be wary, the page may not be real.



number-nine
http://www.hyphenet.com/blog/spot-banking-cyber-criminals/ 
Banks should always use your name
If you receive an email addressing you as “Dear Customer” or “youremail@yahoo.com”, go no further.  Banks will always use your name and even include the last four of your social or account number.  Any emails addressed to anything friendly sounding but your name is often spam.



number-ten
http://www.hyphenet.com/blog/spot-banking-cyber-criminals/
Don’t give up your personal information
When a bank gets a hold of you in suspicion of fraud, they will ask you to verify personal information.  Usually your phone pin number is asked for you to use, not your debit card pin.  Never give up any personal information like your mother’s maiden name or the name of your first pet.  Scammers use this to hack into other accounts of yours.


You can find a list of detailed phishing scams from ESET here.
Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+
References:
A scam-spotters guide: Ten things your bank will NEVER do – but cybercriminals will – We Live Security
http://www.welivesecurity.com/2013/09/12/a-scam-spotters-guide-ten-things-your-bank-will-never-do-but-cybercriminals-will/

Monday, September 24, 2012

Researchers Discover E-Store Selling Stolen Credit Card Information

What do cybercriminals do with stolen credit card data?

While the obvious answer may be “use it to purchase whatever they want,” we are forgetting another route cyber-thieves can take: selling that stolen data to others.

Researchers over at Webroot have stumbled upon an online store that appears to be focused solely on selling stolen credit card information to anyone that’s willing to take the risk.

According to Webroot’s Dancho Danchev, the site appears to be well put together for the most part, complete with a “well-developed” search engine that helps fraudsters find exactly what they’re looking for.

“The service is currently offering 9,132 stolen credit cards for sale, and has already managed to sell 3292 credit cards to prospective cybercriminals.” Danchev revealed in a blog post on Monday.

Professional Looking eStore Offers Stolen Credit Card DataScreenshot Credit: Webroot


Fees for card information vary depending on the card type: Debit cards go for just $16 while credit cards fetch $30 or more. Discounts are promised to those that purchase the data in bulk.

Fraudsters appear to be satisfied with the sales price and have already snatched up the information for 3,292 cards.

As to why the e-store owner opted to sell the stolen data opposed to use it, Danchev says that answer is surprisingly simple. “The practice is called “risk forwarding” which intersects with the e-shop owner’s desire to achieve instant financial liquidity of his assets, “ Danchev explained. “Instead of manually verifying the balance of the cards, he’s focused on bulk orders and forwarding the risk of getting caught to the prospective customers of his services.”

Photo Credit: 401(k)2012

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet“Like” us on Facebook or add us to your circle on Google+.