XSS to TSS: tech support scam campaign abuses cross-site scripting vulnerability

From blog.malwarebytes.com

XSS to TSS: tech support scam campaign abuses cross-site scripting vulnerability

Tech support browser lockers continue to be one of the most common web threats. Not only are they a problem for end users who might end up on the phone with scammers defrauding them of hundreds of dollars, they’ve also caused quite the headache for browser vendors to fix.

Browser lockers are only one element of a bigger plan to redirect traffic from certain sites, typically via malvertising chains from adult portals or sites that offer pirated content.

Read more…

IT Services Giant Sopra Steria Reportedly Hit with Ryuk Ransomware

From hotforsecurity.bitdefender.com

Sopra Steria, one of the world’s biggest IT services companies, has reportedly been hit with the Ryuk ransomware. 

Sopra Steria Group SA is a giant IT firm whose business areas span consulting services, systems integration, enterprise resource planning, implementation of applications, technical support, outsourcing services and professional processes operation.

With around 45,000 employees and offices in 25 countries, the France-based company even lists cybersecurity services among its offerings. But that’s not to say it can’t fall victim to a cyberattack itself. And, according to recent reports, that’s precisely what happened on Tuesday, when ransomware operators reportedly encrypted parts of its network.

Read more…

63 billion credential stuffing attacks hit retail, hospitality, travel industries

From helpnetsecurity.com

attacks industries

Akamai published a report detailing criminal activity targeting the retail, travel, and hospitality industries with attacks of all types and sizes between July 2018 and June 2020. The report also includes numerous examples of criminal ads from the darknet illustrating how they cash in on the results from successful attacks and the corresponding data theft.

Read more…

Android/Trojan.Fadeb.j is the malware that appears on Android phones via pre-installed applications

From 2-spyware.com

Android/Trojan.Fadeb.j

Android/Trojan.Fadeb.j – the threat that gets indicated with this heuristic name by AV detection engines. This is possibly a trojan that can affect the performance significantly. At the same time, it runs in the background and triggers additional processes or disables programs, functions to affect the performance, state of security. This is the threat that possibly is associated with pre-installed apps and cannot be deleted, so you cannot get rid of the threat, in a sense.[1] However, the frustration created with additional pop-ups, unwanted content, and other procedures that trojans cause should be taken care of. 

Read more…

StreamSiteSearch – a potentially unwanted application that delivers sponsored search results

From 2-spyware.com

StreamSiteSearch

StreamSiteSearch is a browser-hijacking app that mainly spreads via software bundle packages, resulting in a stealthy infiltration. Once installed, it sets homepage and new tab address to portal.streamssitesearch.com, applies a customized search engine and begins redirecting all search results to Yahoo. Additionally, the hijacker inserts sponsored links into these results and increases the number of advertisements users see while browsing the web.

Read more…

Discord squashes critical Electron bugs: open source attacks continue to grow

From blog.sonatype.com

My colleague has two kids, ages 9 and 12.  Since the COVID lockdowns they have been playing more online games and each of them use Discord to chat with their friends during gameplay.  Did my colleague or the millions of other Discord users think that vulnerabilities in open source libraries used in the application could result in a takeover of their machines? 

Read more…

XSS to TSS: tech support scam campaign abuses cross-site scripting vulnerability

From malware.news

Tech support browser lockers continue to be one of the most common web threats. Not only are they a problem for end users who might end up on the phone with scammers defrauding them of hundreds of dollars, they’ve also caused quite the headache for browser vendors to fix.

Browser lockers are only one element of a bigger plan to redirect traffic from certain sites, typically via malvertising chains from adult portals or sites that offer pirated content.

Read more…