Criminals target businesses with malicious extension for Meta’s Ads Manager and accidentally leak stolen accounts

0
[ad_1]

A group of criminals is actively targeting Facebook business users to gain access to their advertising accounts via malicious Chrome extensions. But we spotted that they made a mistake…

Like all social media platforms, Facebook constantly has to deal with fake accounts, scams and malware. We have written about scams targeting consumers that redirect to fake Microsoft alert pages, but there are also threats targeting businesses that use Facebook to promote their products and services.

In the past few weeks, there’s been a resurgence in sponsored posts and accounts that impersonate Meta/Facebook’s own Ads Manager. Crooks are promising better advertising via optimization, and increased performance when you use their (malware-laden) software. Meta has tracked and analyzed several threat actors such as DuckTail that have been active for a number of years with a particular interest for Facebook advertising accounts.

Now, we’ve discovered a new attack that uses malicious Chrome extensions to steal Facebook account credentials and is not related to the DuckTail malware. While tracking this campaign, we noticed the threat actors made a mistake when they packaged one of the malware files with their own stolen data.

We have passed the information about this campaign and the threat actors to Meta and thank it for taking prompt action following our reporting.

Key takeaways

  • Vietnamese threat actors are actively targeting Facebook business accounts
  • Victims are lured via fake Ads Manager software promoted on Facebook
  • Malicious Google Chrome extensions are used to steal and extract login information
  • Over 800 victims worldwide, 310 in the US
  • More than $180K in compromised ad budget

Fake Ads Manager accounts

Ads Manager is the product that enables users to run online ads on Facebook, Instagram and other platforms owned by Meta. An article in TechCrunch from May describes how scammers were buying ads from Meta via verified accounts. They were trying to entice potential victims into downloading software to manage their advertising via a “more professional and secure tool”.

In early June, we identified fraudulent accounts running the same scam using similar lures. It is also worth noting that these accounts often have tens of thousands of followers and any of their posts can quickly become viral. Scammers are primarily targeting business users who may spend ad dollars on the platform.

In order to compromise those accounts, they first need to redirect potential victims onto external websites. We’ve seen several different domains that are essentially phishing pages using the Meta logo and branding. The lure is the Facebook Ads Manager program that is pushed via a download link. We’ve seen various cloud providers abused to host these password-protected RAR archives ranging from Google to Trello, as seen below.

Malicious Chrome extension

Once extracted from the archive, the file is an MSI installer package that installs several components under C:\Program Files (x86)\Ads Manager\Ads Manager. We can see a batch script (perhaps named after Google Bard), and two folders. One of them is for a custom Chrome extension while the System folder contains a standalone WebDriver file.

The batch script is launched after the MSI installer completes and essentially spawns a new browser window launched with the custom extension from that previous installation path, pointing the victim to the Facebook login page.

taskkill /F /IM chrome.exe
taskkill /F /IM chromedriver.exe
timeout /t 1 >nul
start chrome.exe --load-extension="%~dp0/nmmhkkegccagdldgiimedpiccmgmiedagg4" "https://www.facebook.com/business/tools/ads-manager"

That custom extension is cleverly disguised as Google Translate and is considered ‘Unpacked’ because it was loaded from the local computer, rather than the Chrome Web Store. A quick look at its source code reveals immediate hex obfuscation in an attempt to hide what it is actually doing.

After reverse engineering this extension, it became quite clear that it had nothing to do with Google Translate. In fact, the code is entirely focused on Facebook and grabbing important pieces of information that could allow an attacker to log into accounts. We can see that the threat actors are interested in Facebook cookies which they request via the cookies.getAll method.

We also notice an interesting way to exfiltrate that data by using Google Analytics. This technique was previously documented by HUMAN as a way to bypass CSP.

Accidental leak

In total, we identified over 20 different malicious Facebook Ad Manager archives that installed Chrome extensions or instead went with traditional malware executables. While there are variations between samples, the attackers’ main goal appears to be the same, namely to collect Facebook business accounts.

While investigating a new phishing site, we saw an archive for download that looked quite different from the others. Ironically, it seems like the threat actors made a mistake and instead of putting the payload, they leaked their own stolen data, or rather the data they stole from victims.

The site we came across pretends to be Meta Ads Manager and boasts the same claims of increasing ad performance that we’ve seen before. There is a button to download a file called Meta Ads Manager.rar which is hosted on Google Drive.

However, this archive does not contain the expected MSI installer, but instead several text files that were last modified on June 15:

While the file names are self-explanatory, we can see that they contain information about authentication (checkpoint, cookie, token). There is also information about the threat actor who shared this file (file owner) via Google Drive and their Gmail email address (this information has been passed to Meta for further action).

The first row of the file called List_ADS_Tach.txt contains column headers with some names in Vietnamese, confirming the nationality of the individuals behind these attacks. In total, there are 828 rows, which translates into just as many Facebook accounts that were breached.

As expected, the threat actors are particularly interested in their victims’ advertising accounts. We can see different metrics related to ad budget (column titles were translated from Vietnamese and may be slightly inaccurate) as well as currencies:

Prized accounts will be those that have a large remaining balance for ad spend. While we do not know if this threat actor is directly associated with DuckTail, they have the same motives of financial profit from hacked Facebook business accounts.

Finally, by converting the data into a map, we can see that victims are not confined to a particular geolocation, in fact they are distributed worldwide.

The threat actors realized their mistake a few days later and trashed the file from their Google Drive account. They also updated the download link on the phishing site, with a new file hosted via MediaFire (fortunately for users, the file was detected as malware and the download is blocked).

A low cost, high yield threat

Business users may be tempted to optimize their ad campaigns on Facebook by clicking on certain posts and downloading programs that claim to increase their earnings. This is, however, a very dangerous practice even if (or especially if) the instructions claim that the software is secure and free of malware. Remember that there is no silver bullet and anything that sounds too good to be true may very well be a scam in disguise.

Fraudsters have a lot of time of their hands and spend years studying and understanding how to abuse social media and cloud platforms, where it is a constant arm’s race to keep bad actors out. Based on reports highlighted in TechCrunch’s recent article, the threat actors may also reinvest some of the stolen ad budgets to place out malicious ads to ensnare more victims and perpetuating this cycle.

If you did happen to download one of those malicious Facebook Ad Manager installers, Malwarebytes has your back. We were already picking up several components from these campaigns and have added additional protection for optimal detection coverage. Victims will also want to revoke access to unknown users from their Business Manager account profile that the fraudsters may have added, as well as review their transactions history.

We would like to thank Meta for being receptive to our report and helping to keep users safe.

Indicators of Compromise

Decoy site

fbadmanage[.]info

RAR archives (password 888 or 999)

e73f53ea5dca6d45362fef233c65b99e5b394e97f4f2fe39b374e49c6a273e60
2082e4a8cd0495aabb0f72a41224f134214d0959e208facbfe960c8c74166cda
3638702c83364fc625c0f91388e9b06d94c3486ac0357038f66667d05f9c52e6
547955e97c945ad7283e1637ec0f5e2dbf13c7fb4885a854fb0744542579c6ff
587698e967d05a649428d3a4e45fd64fcea18affd5b021f15d01b8a39a244f8a
6719e6ba89b0a59d325f4531432195afe65154c1d63b9c3bab8ad8925f2f911d
72ba4254e94b7308de92652d1aaf29084fae55d01e0643df1050a638a3bd9dc8
76731d0ed28a552c6f673b6c3e1b08c0499d4b44050df6838439055e01990406
81d9bc3eabe578d606787ab191dd0ff7e8f58a06e35813591e17855daef8505b
8564962190135783b2f21c64cc05fdb226a89a7cbd309ca353fcc31a2a669f0e
8a6a2d439e537b5985b7492f0dded6ae3e1e80133c073d09849712c08927ca55
99057370f8c0312bb5b4a7ed0bd3753b60488e71576af210edd7f813514acb55
a29131934b589eb325a76c7d638ac3a0a55c5f185189c71cdf79d8d662129fb7
b146d19f7ea988f36449463931758935a54b58e1052dd3a5d20060b2e991b1da
c3704b2250e0e8663c86ad5a63e1051004d6967827ef90aab553ddfce682ca5a
c9f0da6aa38d4c3d38dc734d7937cdac47c272cca3e2df030242854a9661d314
d43d288368bad68e600dae08db5e4846adcaeb4a7d1902ab76417fca3f4c0cf7
e94b66b1a3f27dc282a451d3820b3d3d8380be9b9ebab04eedcf4bb0020908e8
f128cbfddf3d5c2f5742d3d5d5dae1a041023eba543ee2ddf4d8afdbd42f29b3
f1b14728d9f42def90e6eec8c32b2ef5eef43e73383eefa70bf70d8be953c3e5
f9ccac29307547adbf779338d6f22bde128feea847012f6392d7ef69cab30878

Analyzed MSI file

fd637520a9ca34f7b4b21164581a4ec498bf106ba168b5cb9fcd54b5c2caafd0

Malwarebytes EDR and MDR remove all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link

7 Best IP Geolocation API For Cybersecurity

0
[ad_1]
Best IP Geolocation API

IP geolocation API services can do far more than serve website visitors in their local language and currency using IP lookup. They can also play a critical role in cybersecurity.

Geolocation data can source the IP address of DDoS (Distributed Denial of Service) attackers in real time.

You can then take that data to the relevant ISP (Internet Service Provider) and ask them to block those IP addresses to stop the attack.

Some cybercriminals will also try to bypass geolocation services to commit fraud. This can be done by using VPNs (Virtual Private Networks) to create a spoof legitimate location.

So, the capability to detect VPNs and other threats can prove critical, especially where customer data and money is involved.

So, here are six of the best IP geolocation APIs for cybersecurity. 

What is IP Geolocation API?

An IP geolocation API is a service that provides geolocation data based on an IP address. It enables you to pinpoint the location of an IP address, which is helpful for many different services and applications.

IP geolocation APIs connect IP addresses to geographic information like country, city, area, latitude and longitude coordinates, time zone, Internet Service Provider (ISP), and other pertinent facts. Analyzing databases, network infrastructure data, and other sources yields this knowledge.

Where are the IP Geolocation APIs Used?

IP geolocation APIs are frequently employed in many different applications, such as:

  • Targeted Advertising: IP geolocation allows advertisers to target consumers in their unique region or nation.
  • Fraud Detection: IP geolocation, the practice of determining a device’s physical location using an IP address, can be used to spot fraudulent or otherwise suspect activity.
  • Security: IP geolocation can aid in the detection and banning of potentially harmful or malicious IP addresses.
  • Compliance with Regulatory Requirements: There are stringent regulatory regulations for some industries that vary by user location, such as online gaming, online pharmacy, and age-restricted content platforms.
  • Content Licensing and Copyright Compliance: Content providers, such as streaming platforms, are subject to copyright laws and license agreements.
  • Network and System Administration: Network administrators can benefit from using IP geolocation APIs to manage and monitor their networks. IP address geolocation, network traffic monitoring, and user behavior analysis are all within their capabilities.

Best IP Geolocation APIs Features:

Best IP Geolocation APIsFeatures
1. Abstract1. Precise IP geolocation information.
2. Global coverage in its entirety.
3. Updating data in real-time.
4. API integration is simple.
5. Diverse possibilities for use.
2. IP2Location.io1. Precise IP geolocation information.
2. Global coverage in its entirety.
3. Updating data in real time.
4. API integration is simple.
5. Diverse possibilities for use.
3. Ipbase1. Accurate IP geolocation data.
2. Global coverage of IP addresses.
3. Real-time data updates.
4. Developer-friendly API integration.
5. Diverse geolocation applications are supported.
4. ipgeolocation.io1. IP address coverage on a global scale.
2. Updating data in real time.
3. Applications for flexible geolocation are supported.
4. API integration designed for developers.
5. DB-IP1. A wide range of IP addresses are covered.
2. Data updates are provided in real-time.
3. Included are more data points.
4. API integration designed for developers.
6. ipdata1. A wide range of IP addresses are covered.
2. Data updates are provided in real-time.
3. Included are more data points.
4. API integration designed for developers.
7. ipinfo1. Dependable IP geolocation data.
2. IP address coverage on a worldwide basis.
3. Updating data in real-time.
4. Support for API integration.
5. Diverse possibilities for use.

7 Best IP Geolocation APIs in 2023

  • Abstract
  • IP2Location.io
  • Ipbase
  • ipgeolocation.io
  • DB-IP
  • ipdata
  • ipinfo
IP Geolocation APIs
Abstract

Abstract’s powerful IP geolocation service covers over 1.75 million locations across 225,000 cities worldwide, supporting IPv4 and IPv6.

Abstract’s IP geolocation responses also provide information about the timezone, current time, GMT offset, etc.

Furthermore, their IP geolocation responses include country flags in various formats, such as SVG, PNG, emoji, and Unicode, providing visual representation and an enhanced user experience.

Designed to be simple yet powerful, Abstract’s modern REST API strikes the perfect balance between usability and functionality — built to provide a quick time-to-value and an excellent developer experience.

On the other hand, non-programmatic users can use a CSV upload tool that allows bulk queries in easy-to-use formats.

Most importantly, security is a top priority for Abstract, ensuring bank-level protection for all queries.

Any data transmitted to their IP Geolocation API is encrypted using 256-bit SSL encryption (HTTPS), guaranteeing the confidentiality and integrity of the information.

Features:

  • It assists in locating a physical IP address’s location, such as its nation, region, or city.
  • Although it strives for accuracy, there may be restrictions because of many aspects, including how IP addresses are assigned or whether a user utilizes a proxy server.
  • It gives current details about the location connected to an IP address.
  • Developers can include IP geolocation in their programs or websites using specialized tools (APIs).
  • It can let you know whether the IP address belongs to a home user, a company, a mobile device, or a proxy server.

What is best for:

  • Accurate location identification
  • Real-time data updates
  • Versatile usage options.

What could be better:

  • Potential limitations in accuracy
  • Dependence on available data
IP Geolocation APIs
IP2Location.io

IP2Location.io provides a fast and accurate IP Geolocation API tool to determine a user’s geolocation information, such as country, region, city, latitude & longitude, ZIP code, time zone, ASN, ISP, domain, net speed, IDD code, area code, weather station data, MNC, MCC, mobile brand, elevation, usage type, address type, advertisement category, and proxy data.

It supports IPv4 and IPv6 lookup and can be easily integrated into any application. You can get free up to 30,000 IP Geolocation API credits/per month.

In addition, every plan comes with Domain WHOIS API credits – WHOIS API domain lookup that returns comprehensive WHOIS data, such as domain assigned owner contact information, registrar information, registrant information, location, and much more.

The Free package comes with 500 WHOIS API credits/per month.

The ip2location IP geolocation web service uses a granular, pay-as-you-go credit system.

This means it can source simple geographical location information such as city and latitude/longitude and scale up to elevation and weather station.

This API can detect threats, which could support many use cases. However, the full spectrum of threat detection is only available in its sister product, the ip2proxy web service.

Features:

  • IP address accurate geolocation information, including time zone, ZIP/postal code, nation, region, and city.
  • A vast database including IPv4 and IPv6 addresses from throughout the world.
  • Updates in real-time to guarantee the most recent geolocation data.
  • Simple API for smooth integration into systems, websites, or apps.
  • Versatile use for analytics, cybersecurity, ad targeting, content modification, and geotargeting.

Advantages:

  • Accurate geolocation data
  • Comprehensive global coverage
  • Versatile usage options

What could be better:

  • Limited free usage tier
  • Potential dependence on API integration.
Ipbase

ipbase.com provides a powerful IP Geolocation API to gather all necessary information related to location – from country and region details to ZIP codes and time-zone data.

In delivering comprehensive coverage backed up with up-to-the-minute information sets for several applications involving content customization or targeting specific groups with ads. 

ipbase.com provides extensive documentation and integration options, catering to developers from various programming languages.

Its infrastructure is structured to support IPv4 and IPv6 addresses while ensuring solid data security and user privacy.

Moreover, IPbase.com’s reliable performance delivers seamless integration into diverse applications and systems.

Features:

  • IP address geolocation information that is precise.
  • IP address coverage across the globe.
  • Updates in real-time for current information.
  • Data retrieval is made simple through API connectivity.
  • Apps that can be used for analytics, fraud prevention, geotargeting, and content personalization.

What is best for:

  • Global coverage
  • Content customization, and more.
  • Developer-friendly API for easy integration.

What could be better:

  • Potential limitations in accuracy
  • The pricing structure may not be suitable for all users.
  • Only a few extra data points
ipgeolocation.io

This geolocation API can detect a user’s location, sourcing geolocation information including country flag and name, latitude/longitude, currency, and ASN (ISP).

Free IP geolocation is available with a plan that supports up to 30,000 API requests per month at up to 1,000 per day. This API is organized into various modules, all available at all tiers.

This includes the security module, which can detect TOR, proxies, and VPNs and use this data to assign a threat score.

Features:

  • IP geolocation data to determine the exact location.
  • IP lookup in bulk for handling several IP addresses.
  • For organizational identification, map IP to the corporation.
  • Identification of time zones for precise time-related data.
  • API is designed for developers to make integration into apps simple.

What is best for:

  • Accurate and reliable IP geolocation data.
  • Additional data points are available, such as organization and time zone.
  • Easy integration API.

What could be better:

  • Pricing plans may not be suitable for all users.
  • Some advanced features may require additional fees.
  • Limitations in accuracy due to various factors.
IP Geolocation APIs
DB-IP

This RESTful API can source country names, languages, currency, and calling codes.

There are three product tiers. Each tier is segmented three times to support more IP Geolocation API requests, and each tier offers free trials.

Only the top tier (Extended) features threat detection, and it can detect proxies and crawlers. It also checks IP addresses against a database of known malicious IP addresses.

Features:

  • Accurate IP geolocation data to determine location.
  • Worldwide coverage and a huge IP address database.
  • Real-time updates for the most recent geolocation data.
  • Versatile use for functions including fraud prevention, content personalization, and geotargeting.
  • API is designed for developers to make integration into systems and applications simple.

What is best for:

  • Precise IP geolocation information.
  • Applications for flexible geolocation are supported.
  • API integration designed for developers.

What could be better:

  • Free use tier with a cap.
  • API integration is required to retrieve geolocation data.
  • Possible privacy issues associated with the gathering of IP addresses.
ipdata

An update can detect a visitor’s location by sourcing data, including ZIP or postal code, flag code, calling code, and time zone.

The free API key is suitable for non-commercial use and is limited to 1,500 daily API requests.

Higher tiers mostly add more IP Geolocation API requests, though the top two also enable SLAs and other enterprise-level options.

Threat detection functionalities can detect TOR, proxies, and BOGON (unallocated IP addresses), and are available at all paid tiers.

Features:

  • Precise IP geolocation information for precise location data.
  • Comprehensive coverage and a sizable IP address database.
  • Updates in real-time to guarantee the most recent geolocation data.
  • ASN, currency, time zone, and other additional data pieces.
  • API is designed for developers to integrate systems and applications easily.

What is best for:

  • Real-time data updates are available.
  • Additional data points are provided.
  • Developer-friendly API integration.

What could be better:

  • Limitations in accuracy due to various factors.
  • API integration is required to retrieve geolocation data.
  • IP address information collecting and processing raises privacy issues.
IP Geolocation APIs
ipinfo

Info can see visitor location data such as latitude/longitude, postal code, time zone, and ASN data, including ISP abuse contact details. There’s a free demo option as well as four paid plans.

Threat detection only becomes available in the top two tiers but includes the capability to detect VPNs, proxy, TOR, hosting, and relay attempts.

While this may satisfy many use cases, a fuller suite of functionality has been split into a separate product.

Features:

  • Accurate IP geolocation information for location information.
  • Comprehensive coverage and a sizable IP address database.
  • Updates in real-time to deliver the most recent geolocation data.
  • Additional information, including the company, time zone, and postal code.
  • API is designed for developers to make integration into systems and applications simple.

What is best for:

  • Comprehensive IP address coverage.
  • Updates in real-time for current information.
  • There are more data points, like organization and timezone.

What could be better:

  • Pricing options are not satisfied.
  • Additional costs for advanced functionality.
  • Several things bring on limitations in accuracy.

Final words

If you have customers, process transactions, or hold customer data, you must treat the potential for cybersecurity threats with the utmost seriousness.

This isn’t just about fraud. It’s also about data protection regulations like the EU’s GDPR (General Data Protection Regulation).

This regulation can acceptable data breaches to 4% of global revenue or €25 million – whichever is higher. There’s also brand damage to consider, as brand value is far easier to lose than gain.

So, it’s essential that you also fully consider the level of cybersecurity functionality that you need from your IP geolocation API.

Remember that while many products have threat detection capabilities, they may not expose them at all product tiers. Also, some products split their best functionality into separate products.

Consider exploring what opportunities there are to test each product so that you can identify whether it’s capable of meeting your business needs.


[ad_2]
Source link

Proposed Massachusetts law to ban sale of your mobile location data

0
[ad_1]

A proposed law would ban brokers from selling mobile location data in Massachusetts.

Cellular location phone data may be banned from sale in the state of Massachusetts, under a proposed law set to ruffle some data broker feathers.

The selling of location data has long been a point of contention for privacy experts. As with so much bulk user data, claims of anonymity from the sellers are never far behind. The reality is often quite different, with individuals or more general patterns routinely revealed in ways nobody thought possible. People were singled out from 500k AOL search records, and interesting findings were made from comparing a Netflix dataset to IMDB ratings back in 2006/07.

With location services, it’s even more important that anonymity is done correctly. Indeed, some would claim that attempts to anonymise data can never be 100% successful. Meanwhile location data can illustrate precise movements, patterns, a daily routine, or information regarding specific activities and pastimes—all of which can be used for nefarious purposes in the wrong hands.

Even when precautions have been taken, user data can still slip through the net in unusual ways. Not so long ago, researchers found it was possible to look at aggregate data from Strava and track the beginning and end positions of user routes via heat maps and social features.

It’s important, then, to try and get it right the first time with mobile data. Sadly, the odds are stacked against this when dedicated firms exist to tie IDs to names and addresses. With brokers selling the data behind the scenes, this proposed law aims to tackle the problem by simply taking the data off the table.

The Location Shield Act would do the following in Massachusetts:

It shall be unlawful for a covered entity or service provider that lawfully collects and processes location information to:—

(1)collect more precise location information than necessary to carry out the permissible purpose;

(2)retain location information longer than necessary to carry out the permissible purpose;

(3)sell, rent, trade, or lease location information to third parties; or

(4)derive or infer from location information any data that is not necessary to carry out a permissible purpose.

(5)disclose, cause to disclose, or assist with or facilitate the disclosure of an individual’s location information to third parties, unless such disclosure is (i) necessary to carry out the permissible purpose for which the information was collected, or (ii) requested by the individual to whom the location data pertains.

As the American Civil Liberties Union Massachusetts (ACLU) notes, the buying and selling of this data is unregulated and can impact on all manner of privacy and safety issues. Domestic abusers can track ex-partners. Foreign governments can use data for intelligence and tracking purposes. Employers can track and discriminate against employees. A variety of health and abortion access situations could lead to prosecution or harassment.

Owning a mobile device should not lead to this data being potentially made available to anyone with a credit card. There is strong voter support in Massachusetts for a law which would prevent this selling of personal location data, and the bill seems likely to pass.

The big question is whether or not it will inspire other states to follow suit and draft their own versions of a privacy issue sorely in need of rebalancing. 


We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.


[ad_2]
Source link

Update now! Microsoft patches a whopping 130 vulnerabilities

0
[ad_1]

For the July 2023 Patch Tuesday, Microsoft has issued security updates for 130 vulnerabilities, four of which are known to have been actively exploited.

It’s that time of the month again. For the July 2023 Patch Tuesday, Microsoft has issued security updates for 130 vulnerabilities. Nine of the vulnerabilities are rated as critical and four of them are known to be actively exploited.

The Cybersecurity & Infrastructure Security Agency (CISA) has already added these four vulnerabilities to the catalog of known to be exploited vulnerabilities.

The Common Vulnerabilities and Exposures (CVE) database lists publicly disclosed computer security flaws. The actively exploited vulnerabilities are listed as:

CVE-2023-32049 (CVSS score 8.8 out of 10): a Windows SmartScreen Security Feature Bypass vulnerability. The user would have to click on a specially crafted URL to be compromised by the attacker in which case the attacker would be able to bypass the Open File – Security Warning prompt.

CVE-2023-35311 (CVSS score 8.8 out of 10): a Microsoft Outlook Security Feature Bypass vulnerability. The user would have to click on a specially crafted URL to be compromised by the attacker in which case the attacker would be able to bypass the Microsoft Outlook Security Notice prompt. The Preview Pane is an attack vector, but additional user interaction is required.

CVE-2023-32046 (CVSS score 7.8 out of 10): a Windows MSHTML Platform Elevation of Privilege (EoP) vulnerability. Exploitation of the vulnerability requires that a user open a specially crafted file. An attacker would have to convince users to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file in which case the attacker would gain the rights of the user that is running the affected application.

CVE-2023-36874 (CVSS score 7.8.out of 10): a Windows Error Reporting Service Elevation of Privilege vulnerability. An attacker who successfully exploited this vulnerability could gain administrator privileges but the attacker must have local access to the targeted machine and the user must be able to create folders and performance traces on the machine, with restricted privileges that normal users have by default.

The CVE below is under investigation and we will tell you more about it in a separate blogpost.

CVE-2023-36884 (CVSS score 8.3 out of 10): an Office and Windows HTML Remote Code Execution (RCE) vulnerability. An attacker could create a specially crafted Microsoft Office document that enables them to perform remote code execution in the context of the victim. However, an attacker would have to convince the victim to open the malicious file.

Additionally, Microsoft issued an advisory titled Guidance on Microsoft Signed Drivers Being Used Maliciously. The advisory warns about drivers certified by Microsoft’s Windows Hardware Developer Program (MWHDP) which were being used maliciously in post-exploitation activity. In these attacks, the attacker gained administrative privileges on compromised systems before using the drivers. As a result of a Microsoft investigation, the partners’ seller accounts were suspended and detections for all the reported malicious drivers were added. Whether this really solves the problem of digitally signed malicious drivers is doubtful since there are publicly available tools to sign drivers.

Other vendors

Other vendors have synchronized their periodic updates with Microsoft. Here are few major ones that you may find in your environment.

Adobe has released security updates to address vulnerabilities affecting ColdFusion and InDesign

Apple has issued an RSR update for a vulnerability which it says may have been actively exploited.

Cisco has released security updates for several products.

Fortinet has released a security update to address a critical vulnerability (CVE-2023-33308) affecting FortiOS and FortiProxy.

Last week, Google patched three actively exploited Android zero-days.

MOVEit has fixed 3 new vulnerabilities in the Transfer software.

Mozilla has released a security update to address a vulnerability in Firefox and Firefox ESR.

SAP has released its July 2023 Patch Day updates.

VMware released VMware SD-WAN updates to fix a vulnerability.


We don’t just report on vulnerabilities—we identify them, and prioritize action.

Cybersecurity risks should never spread beyond a headline. Keep vulnerabilities in tow by using Malwarebytes Vulnerability and Patch Management.


[ad_2]
Source link

Save 50% on this HP OMEN Gaming Laptop

0
[ad_1]

Today, Best Buy has a great deal on the HP OMEN, which is currently on sale for $799. That’s going to save you roughly 50% off of its regular price. As it is normally priced at $1,579. So definitely a good time to buy one.

HP OMEN – Best Buy

Why you should buy the HP OMEN

The HP OMEN AMD Advantage Edition 16.1″ Gaming Laptop is a powerful and versatile gaming laptop that’s perfect for gamers, creators, and anyone who wants a high-performance laptop. It features an AMD Ryzen 7 6800H processor, 16GB of RAM, and an AMD Radeon RX 6650M GPU, which can handle even the most demanding games and applications.

The laptop also has a 16.1-inch Full HD IPS display with a 144Hz refresh rate, which provides smooth and responsive gameplay. It also has a backlit keyboard, a fingerprint reader, and a long-lasting battery that can keep you gaming all day long.

Here are some additional reasons why you should buy the HP OMEN AMD Advantage Edition 16.1″ Gaming Laptop:

  • It’s powered by an AMD Ryzen 7 6800H processor, which is one of the most powerful mobile processors available.
  • It has an AMD Radeon RX 6650M GPU, which can handle even the most demanding games and applications.
  • It has a 16.1-inch Full HD IPS display with a 144Hz refresh rate, which provides smooth and responsive gameplay.
  • It has a backlit keyboard, a fingerprint reader, and a long-lasting battery that can keep you gaming all day long.
  • It comes with a free one-year subscription to Xbox Game Pass Ultimate, which gives you access to over 100 games on PC and Xbox.

If you’re looking for a powerful and versatile gaming laptop that can handle anything you throw at it, the HP OMEN AMD Advantage Edition 16.1″ Gaming Laptop is the perfect choice for you. Order yours today and start enjoying all the benefits of this amazing laptop.

HP OMEN – Best Buy


[ad_2]
Source link

How to secure your business before going on vacation

0
[ad_1]

Are you a critical security expert for your organization? Are you also going on vacation? Here’s how to ensure your time away from the office doesn’t get interrupted with a security incident.

For many, the summer months should be a time of peace: Maybe taking some vacation, maybe strolling across warm, soft sands as sapphire waves lap up against your feet, maybe even spending time with family (that you like).

But for determined cybercriminals, these periods of near-universal rest and relaxation are actually moments of attack.

In particular, ransomware gangs have shown a nasty habit of starting their attacks at the least convenient times: When computers are idle, when employees who might notice a problem are out of the office, and when the IT or security staff who might deal with it are shorthanded. 

Cybercriminals like to attack at night and at weekends, and they love holidays and special events. On the July 4 weekend in 2021, the REvil ransomware gang was likely hosting its own celebrations after pulling off an enormous supply-chain attack on Kaseya, one of the biggest IT solutions providers in the US for managed service providers (MSPs). Threat actors used a Kaseya VSA auto-update to push ransomware into more than 1,000 businesses.

But it isn’t just holiday weekends that cybercriminals leverage for attacks. They can also likely predict when IT professionals go on vacation—the summer.  

Why out-of-office attacks work

Ransomware works by encrypting huge numbers of files on as many of an organization’s computers as possible. Performing this kind of strong encryption is resource intensive and can take a long time, so even if an organization doesn’t spot the malware used in an attack, its tools might notice that something is amiss. 

“You never think you’re gonna be hit by ransomware,” said Ski Kacoroski, a system administrator with the Northshore School District in Washington state, speaking on Malwarebytes’ Lock & Code podcast. On the podcast, Kacoroski spoke about Northshore’s nighttime attack: 

“It was an early Saturday morning. I got a text from my manager saying ‘something is up’…after a short while I realized that [a] server had been hit by ransomware. It took us several more hours before we realized exactly how much had been hit.”

Kacaroski added “We had some high CPU utilizations alert the night before when they started their attack, but most of us were already asleep by midnight.”

Be prepared 

When REvil first attacked Kaseya in 2021, Malwarebytes Labs relied on the expertise of Adam Kujawa, a cybersecurity evangelist, to understand what steps organizations should take to minimize the chance that a holiday weekend could be ruined by a cyberattack. That advice is still good today—including for any IT or security employee going on vacation—so we’re offering it again for readers. 

Do these before leaving for vacation 

  • Run a deep scan on all endpoints, servers, and interconnected systems to ensure there are no threats lurking on those systems, waiting to attack! 
  • Once you know those systems are clean, force a password change a week or two out from the holiday or vacation time so any guessed or stolen credentials are rendered useless. 
  • Employ stricter access requirements for sensitive data, such as multi-factor authentication (MFA), Manager Authorization, and requiring a local network connection. Although this will make it a more difficult for employees (for a short amount of time), this will also make it significantly more difficult for attackers to traverse networks and gain access to unauthorized data. Once the holiday or vacation time ends, you can revert these policies since you’ll have more eyes to watch out for threats. 
  • Provide guidance to employees on not posting about vacations and/or holiday plans on social media. 
  • Provide free—or free for a limited time—security software to employees to use on personal systems 
  • Ensure all remotely accessible connections (e.g., VPNs, RDP connections) are secured with MFA. 

Schedule these during vacation 

  • Ensure all non-essential systems and endpoints are shut down at the end of the day. 
  • Reduce risk by disabling or shutting down systems and/or processes which might be exploitable, if they aren’t needed. 
  • Ensure there is always someone watching the network during the holiday or planned vacation, and make sure they are equipped to handle a sudden attack situation. We suggest creating a cyberattack reaction and recovery plan that includes call sheets, procedures on communicating with law enforcement and collecting evidence, and what systems can be isolated or shut down without seriously affecting the operations of the organization.

“The only mistake in life is a lesson not learned”

When we asked Kacaroski why he came forward to tell his ransomware story when many others are reluctant to, he told us: “The only mistake in life is a lesson not learned.”

A lesson we can all learn here is that cybercriminals are not reluctant to ruin somebody’s vacation plans. So don’t wait for an attack to happen to your organization before you decide you need to be ready. Prepare now, and enjoy uninterrupted peace of mind during your vacation.

Ready to learn more about staying safe before heading out on vacation? Read more at our “Stay on Vacation” hub:

Stay on vacation


[ad_2]
Source link

Another leak hints at a substantial price hike for Galaxy Tab S9

0
[ad_1]

With Samsung‘s Galaxy Unpacked event drawing close, more information about the upcoming Galaxy products is hitting the internet. Recent leaks have suggested that the new foldables and tablets will cost higher than their respective predecessors. Another source has hinted at a price hike for the Galaxy Tab S9 series.

According to noted tipster SnoopyTech, Samsung will price the base Galaxy Tab S9, which comes with 8GB of RAM and 128GB of storage, at CAD 1,099 (roughly $835) in Canada. The Galaxy Tab S9+, with 12GB of RAM and 256GB of storage, will come with a price tag of CAD 1,349 (roughly $1,025). Finally, the 12GB+256GB Galaxy Tab S9 Ultra will cost CAD 1,599 (roughly $1,215) in the country.

If this information is correct, Samsung is increasing the prices of its flagship tablets by as much as CAD 200 in Canada. The base Galaxy Tab S8, Galaxy Tab S8+, and Galaxy Tab S8 Ultra debuted in the country with price tags of CAD 899, CAD 1,149, and CAD 1,399, respectively (via). A previous leak suggested a similar price hike in Europe. The new tablets are said to cost upwards of €930 in the region, notably more than the starting price of €750 for the Galaxy Tab S8 series.

That said, we can’t confirm the authenticity of these alleged Galaxy Tab S9 prices. The same goes for the alleged European prices of the Galaxy Z Fold 5 and Galaxy Z Flip 5 as well. The figures probably leaked through third-party retailers, which often list unreleased devices with higher price tags. They adjust the prices once the products are on sale. We will let you know when we have more information.

You can already reserve the new Samsung foldables and tablets

Samsung will officially unveil its next-gen foldables and flagship tablets on July 26. The company will host a big launch party, aka the Galaxy Unpacked event, in Seoul, South Korea, for the Galaxy Z Fold 5, Galaxy Z Flip 5, and Galaxy Tab S9 series. The Galaxy Watch 6 series smartwatches will also debut on the same day.

While the official launch is still a couple of weeks away, you can already reserve them. Samsung is allowing its fans to pre-reserve the new foldables, tablets, and smartwatches through its website. You don’t need to pay a penny, but the company will give you a $50 Samsung Credit if you go on to pre-order the devices once they are here. Stay tuned and we will keep you posted with all the latest leaks and rumors about the new Samsung products.


[ad_2]
Source link

New Apple case patent could revolutionize iPad designs

0
[ad_1]

Ever since their inception, phone cases have largely served just one purpose, i.e. to protect the device from fall damage by using materials such as plastic and carbon fibre. However, it looks like Apple might be looking to change this notion, as the US Patent and Trademark Office has recently awarded the company with a new patent which would allow them to develop an iPad case with an outer ring that not only safeguards the mobile device but also incorporates additional components and serves as a multifunctional kickstand.

The “Peripheral Housing for a Computing Device” patent, credited to six inventors, including renowned individuals such as Paul X. Wang and Keith J. Hendren, has the potential to revolutionize iPads by allowing users to prop them up on a table at adjustable angles, providing an improved viewing angle for watching videos. Additionally, the case itself will incorporate a substantial loop bumper that encircles all edges of the main unit, thus further protecting the device from fall damage.

In addition to the ergonomic benefits, the patent also notes that due to the recent advancements in component miniaturization, such as processors, batteries, memory, and integrated circuits, the bumper could also accommodate extra features such as batteries, cameras, and various accessories. This integration would enable Apple to make its devices even thinner potentially, thus further enhancing the user experience.

Still a patent

Although this new patent suggests that Apple has considered incorporating this design in a future model, it is also important to note that the patent does not guarantee the immediate implementation of the proposed technology in Apple’s devices. This is because the company files for numerous patents each year, and given that this patent would require the company to make significant redesigns for the iPad, it’s even more unlikely that such a device will ever see the light of day.


[ad_2]
Source link

Everything you need to know

0
[ad_1]

It’s now 2023, which means that Android 14 is just around the corner. It’s hard to believe that we are already preparing to get Android 14 from Google, for the Pixel and other Android smartphones. In this article, we’re going to round up everything you need to know about Android 14. Like when it’ll be released, what it’ll be called, what features might be included and more.

Google began the road to Android 14 on February 8, 2023 with the release of the first developer preview.

What will Android 14 be called?

This year, Android 14 will officially be called simply, Android 14. However, Google does still stick with its dessert names internally. Even thought they ditched that starting with Android 10 back in 2019. This year, Google is onto the letter U for dessert names.

  • Android 10 – Quince Tart
  • Android 11 – Red Velvet Cake
  • Android 12 – Snow Cone
  • Android 13 – Tiramisu

So what’s the dessert name for U? Well, according to 9to5Google, it has been reported that Google is calling it Upside Down Cake. But you’ll likely never hear that name from Google.

When will Android 14 be released?

Google has mostly stuck with a similar schedule every year, since releasing the new version of Android independent of new Pixels or Nexus devices. Here’s how the schedule has gone recently:

  • Android 13 – August 2022
  • Android 12 – October 2021
  • Android 11 – September 2020
  • Android 10 – September 2019

When Google releases the first developer preview, they always say that the stable version will be launching in Q3. That is technically, July 1 to September 30. Though we typically see it the day after Labor Day. In 2021, things were delayed a bit, so it came out closer to the Pixel launch. And in 2022, it came out a week before Labor Day. So the Labor Day holiday is a good time to start thinking about this new version of Android launching.

What’s the developer preview schedule?

Google released the first developer preview on February 8, 2023. There will be a second beta, likely released on the second Wednesday of March, before moving onto the betas in April. Google typically releases the previews and betas on the second Wednesday of each month. This comes after releasing the security update on the first Monday of the month.

What’s the beta schedule for Android 14?

Google has released the schedule for the betas and the previews for Android 14. It mostly matches up with previous launches. Where we will get two developer previews. Followed by the first beta in April.

  • Developer Preview 1 – Released February 8, 2023
  • Developer Preview 2 – Released March 8, 2023
  • Beta 1 – Released on April 12, 2023
  • Beta 2 – Released on May 10, 2023
  • Beta 3 – Released on June 7, 2023
  • Beta 4 – Released on July 11, 2023
  • Stable release – August/September 2023

Screenshot 2023 01 05 at 8 43 20 AM

What features are we going to see in Android 14?

It’s still pretty early, and while we really don’t know what features we could see in Android 14, since Google hasn’t yet launched the preview, we do have a pretty good idea. Thanks to some digging around in the source code, seeing some commits and a few other ways. So here’s what we’re expecting to see in Android 14.

Satellite Calls

After Apple launched Satellite capabilities on the iPhone 14 last year, it was pretty much a no-brainer that Google would do the same fro Apple. Though, Google’s Hiroshi Lockheimer confirmed that they are working on Satellite connectivity, even before the iPhone 14 was announced.

While Lockheimer’s tweet doesn’t necessarily spell out Satellite Calling, we do have some more evidence. This time from Qualcomm. It is launching Snapdragon Satellite, which will be part of the Snapdragon 8 Gen 2 processor. Though it won’t be on every phone with the Snapdragon 8 Gen 2. So it’s definitely likely that Google will add support in Android 14.

Predictive back navigation

This feature has actually long been talked about on various versions of Android over the past few years. But it looks like it could actually be available in Android 14. Basically, the way that back button works currently is, you might be going back or you might be quitting the app. The predictive back navigation aims to fix that. What will happen is that you’ll get a sneak peak of the home screen before you finish your command. This will show you if you are about to quit the app or not.

While this sounds a bit complicated, in practice it shouldn’t be. As mentioned, this was originally built for Android 13, but then got pushed back for Android 14.

Health Connect

We’re hearing that Health Connect could actually be built into Android 14. Health Connect is basically a syncing app that Google built, which can sync different health apps with each other. So you can connect MyFitnessPal, Samsung Health and Fitbit all to Health Connect and have them share data with each other. It’s also very helpful if you switched watches. Say you’ve been using a Galaxy Watch for a few years and switch over to a Pixel Watch, now you can bring your data from Samsung over to Fitbit easily.

Now, with Android 14, it’s likely going to be pre-installed on your phone. It’s already available in the Play Store, but not many people know about it. This would make it easier for people to know it exists, and actually use it.

Android Beam is finally dying

Do you remember Android Beam? That kind of cool feature where you could share pictures and files with someone else via NFC by tapping your phones against each other? Yeah, Google actually deprecated it in Android 10, back in 2019. But now, it is officially finally gone from AOSP.

So what’s the big deal with that? Well, Google does have Nearby Share, which does work a lot better. However, it does rely on Google Mobile Services (GMS). So not all phones can use it. For instance, Huawei’s phones are unable to use it, since they can’t work with Google. So this is effectively stripping out a feature from non-GMS enabled devices.

Will my phone get Android 14?

Will your phone get Android 14? That’s going to depend on two things: the manufacturer of your phone, and how old it is. Most manufacturers are now promising two or more years of Android updates. So anything released in 2021 or later should get updated. Some, like Samsung and Google promise three years, so anything released in 2020 or later will get updated.

Now the other question is when? Well, for Google, we know Pixels will get updated right away. Likely within a couple of days of Google releasing Android 14 to AOSP. Samsung and OnePlus have been pretty quick with releasing updates for new versions of Android recently, so they will likely be about one to two months behind the final release. As for the others? Who knows at this point. We still don’t even have a preview yet, let alone know when Google will release Android 14.


[ad_2]
Source link

watchOS 10 Public Beta now available too

0
[ad_1]

In addition to iOS 17 Public Beta being released today, Apple also released watchOS 10 Public Beta today. So now you can sign up and run the public beta on your Apple Watch. The website is still not live for signing up, but that should change in the coming minutes.

watchOS 10 is a pretty significant upgrade for the Apple Watch this year, and it has actually been running pretty smoothly throughout the first three developer betas. So there’s that.

When you are able to sign up for the Public Beta, the update is going to come in at a pretty hefty size. It should be around a gigabyte in size, and you will need to have your watch on the charger and above 50% charge. Since this is a big update, you really don’t want your watch to lose battery and die in the middle of the update.

What’s new in watchOS 10?

With watchOS 10, Apple actually debuted a pretty big redesign here. And it also changed the way some things work. So you’ll need to rework your muscle memory. For instance, a swipe up from the bottom now opens a list of widgets, instead of Quick Settings. A tap of the side button now opens the Quick Settings. Among a few other changes.

The widgets in watchOS 10 are actually really good. However, they are mostly limited to first-party widgets right now. So you have Activity, Clock, Heart Rate, Weather, and others from Apple. There’s no third-party apps with widgets just yet. That should change as we get closer to the launch in September.

Apple also introduced two new watch faces here in watchOS 10, that includes Palette and Snoopy. The Snoopy watchface has characters from the Peanuts cartoon and the they change with animations throughout the day. It’s a pretty cool looking watchface, to say the least.

But that’s watchOS 10, and now it’s available in Public Beta, which means we are getting closer to a stable release.


[ad_2]
Source link