A critical security flaw in the WooCommerce plugin Stripe Payment Gateway risked users’ safety. Exploiting the vulnerability could allow an attacker to pilfer the payments directly from the platform and steal other sensitive information. The developers patched the bug and released the security fix with the subsequent plugin version, urging users to update.
Stripe Payment Gateway IDOR Flaw
According to a recent post from Patchstack, a severe security flaw existed in the Stripe Payment Gateway plugin, risking numerous online stores.
Stripe Payment Gateway is a popular WooCommerce plugin empowering online stores to manage payments directly from Stripe API. The plugin currently boasts over 900,000 active installs. That means any vulnerabilities in this plugin if exploited, could directly impact thousands of online stores globally.
Patchstack reported that the plugin API exhibited an Unauthenticated Insecure Direct Object Reference (IDOR) vulnerability. The flaw typically existed due to the lack of proper control access on the javascript_params and payment_fields functions. Exploiting this vulnerability could let an unauthenticated attacker view and access any target users’ names, email addresses, complete addresses, and sensitive financial information.
This vulnerability affected all Stripe Payment Gateway versions before and including 7.4.0. Upon discovering the flaw, Patchstack reported the issue to the plugin developers in April 2023. Then, within a few days, the plugin team released the bug fix with the plugin version 7.4.1 on May 30, 2023.
After waiting for a couple of weeks for the latest plugin release to roll out, Patchstack has now published the details about their findings following the responsible vulnerability disclosure.
Now that the patch has been released, all WordPress admins running Stripe Payment Gateway plugin on their sites must update their stores with the latest plugin release as soon as possible. Such updates are always crucial for online store managers since any security breaches affecting their customers’ data not only impact their customers but also cause a major blow to the store’s credibility and customers’ trust.
Galaxy watch 6 prices have leaked and the cost is about what you would probably expect from Samsung. The Galaxy Watch 6 is the next major smartwatch in the company’s lineup, suspected to be unveiled later this year alongside a new set of phones.
It’s rumored to make a return to the non-classic and classic variations that were available on the Galaxy Watch 4 series. In addition to a rotating bezel. According to the leak via SamMobile, there will be four versions of each of the two models. Giving consumers a wide array of different options to choose from. This will include a 40mm and 44mm version of the Galaxy Watch 6. Both in Bluetooth and LTE variations.
For the Galaxy Watch 6 Classic, the sizes will be 43mm and 47mm. Also with options for Bluetooth or LTE on both sizes.
The Galaxy Watch 6 will likely have a starting cost of €319
This is about what you could expect from Samsung on its upcoming smartwatch. As it’s about on par with the starting prices for the Galaxy Watch 5 series when they launched in 2022. Albeit a little more expensive.
Last year’s Galaxy Watch 5 started at $279. While this year’s seems to be €319 for the 40mm Bluetooth model of the Galaxy Watch 6. If Samsung sets the price to be the same globally, then the starting cost of the Galaxy Watch 6 in the US should be $319.
For the 40mm LTE model the price is rumored to be €369. Meanwhile the prices for the 44mm Bluetooth and LTE models are €349 and €399. The Bluetooth version of the 43mm Galaxy Watch 6 Classic will start a bit higher at €419. Then go up to €449 for the 47mm. As for the LTE models, the 43mm will be €469 and the 47mm will be €499.
In addition to pricing, the leak also mentions colors. The 40mm Galaxy Watch 6 will come in Graphite and Cream options while the 44mm model will come in Graphite and Silver. The Galaxy Watch 6 Classic will come in Black and Silver for all four versions. Worth keeping in mind is that these prices aren’t official. But if they’re correct then there’s not too much of a deviation from pricing on last year’s models.
It’s no secret that Reddit has been in the news lately for all the wrong reasons. However, back in February, Reddit also fell victim to a sophisticated phishing hack, which resulted in the leak of confidential internal documents, codes, contracts, and some personal information belonging to advertisers. Now, in a recent development, the notorious ransomware group, BlackCat, has reportedly claimed responsibility for the attack.
The group is not only demanding a ransom of $4.5 million but also wants Reddit to revert its recently proposed API pricing changes, which had sparked protests from users and moderators.
How did the Reddit hack occur?
The attackers managed to breach Reddit’s security system by creating a deceptive website that closely resembled the company’s intranet gateway. Therefore, when unsuspecting employees unknowingly disclosed their login details and 2FA codes through carefully crafted prompts on this fake site, the hackers gained access to the system. However, Reddit has assured its users that the hackers did not gain access to any non-public user data.
Demands aligning with Reddit’s API issue
The timing of BlackCat’s revelation is particularly noteworthy, as it aligns with the public outrage caused by Reddit’s recent decision to charge companies for API access. This decision has already led to the shutdown of many popular apps, such as Narwhal and Apollo. And despite the criticism, Reddit CEO Steve Huffman has repeatedly defended the company’s proposed changes, stating that the platform was not originally designed to support third-party apps and that they would not reconsider their position.
“These people who are mad, they’re mad because they used to get something for free, and now it’s going to be not free,” said Reddit CEO Steve Huffman.
But this new demand adds further complexity to the already turbulent situation. This is because, in addition to seeking financial gain, the group is now attempting to influence policies and shape the actions of its target. However, the impact of this new development on API prices remains uncertain, as the company is yet to issue an official statement in response to the demands.
Researchers have found a new malware in the wild actively targeting Windows devices. Identified as “Skuld,” the Go-based malware aims to steal stored data from apps, web browsers, and other stored files from Windows systems.
Skuld Malware Appears As A New Threat For Windows Users
According to a recent report from Trellix, numerous security researchers caught the newly identified “Skuld” malware actively compromising Windows systems.
Written in Golang programming language, Skuld typically functions as a data stealer. Upon reaching a target device, it pilfers stored files from the system and scans web browsers and other installed apps (like Discord) for stored information. Also, some malware samples exhibited crypto-stealing functionalities.
This extensive information-stealing capability owes to the Golang, which empowers the malware creators to design malware executables targeting various operating systems. Also, Go-based malware are relatively difficult to analyze and reverse engineer. Hence, neutralizing Go-malware infections potentially requires more time for the security community.
Before executing its info-stealing functionalities, the malware first checks the system for security measures to escape detection. That includes VM check – to halt execution if caught, and processes scan – to terminate the processes listed in its blocklist.
After that, it exfiltrates data from Discord, web browsers, and system information (including hardware details). It then transmits everything to the attacker via Discord webhook and the Gofile upload service.
Besides data stealing, the malware exhibits clipper functionalities, which assist Skuld in stealing cryptocurrency wallet addresses from the clipboard. Once stolen, the malware facilitates the attacker in stealing money by swapping the wallet address with the attacker’s one.
For now, the exact identity of the threat actor behind Skuld remains unclear. Nonetheless, the researchers have traced the malware to a (presumably) developer with the alias “Deathined,” which keeps appearing briefly on various social media platforms.
Currently, the malware seems under active development, lacking numerous functionalities. But it will likely expand its operations after improvements, possibly emerging as a new for-sale threat on the dark web.
We take a look at a phishing scam that cost 700 DoorDash drivers a combined total of roughly $950k.
A particularly nasty slice of phishing, scamming, and social engineering is responsible for DoorDash drivers losing a group total of around $950k.
DoorDash drivers are contractors who pick up food deliveries from stores and restaurants and deliver the products to the customer. A 21 year old man named David Smith, from Connecticut, allegedly figured out a way to extract large quantities of cash from drivers with a scam stretching back to 2020. Incredibly, this means it all began when he was 18. There’s picking up a new hobby, and then there’s this.
The theft would begin by placing a bogus DoorDash order, receiving the driver details, and then contacting said driver by text and / or phone claiming to be DoorDash support. From here, the driver would be convinced to hand over banking details or log in to a fake portal. The end result would be a loss of funds, and potentially not being able to do their job.
Considering that this took place during the pandemic, targeting drivers may have had a significant impact on vulnerable people whose only way to get food was via services like DoorDash. As with so many scams of this nature, the impact ripples out from the initial victim and never quite stops where you expect it to.
A typical example of how the scam would play out is highlighted in the Stamford Advocate. One driver on her way to a supermarket received a text which advised her not to complete her current order. A call followed, with the individual claiming to be from DoorDash support. He claimed a scam was being perpetuated by drivers, and he needed to make sure that she wasn’t involved.
He sent her a link to verify her identity, and then said she wouldn’t be able to access her earnings / account for roughly four days. Thankfully a reference to a fictitious DoorDash promo tipped her off that something wasn’t right, and she altered her login credentials just in time. Others were not so lucky, with one driver named in the Stamford article losing close to $5,000. A third lost somewhere in the region of $2,000 after being tricked by three scams in a row.
1,750 transactions in total ensured a steady stream of ill-gotten gains for the individual allegedly at the heart of the scheme. Variations on this scam included calls from “DoorDash security” which eventually resulted in banking details being handed over. In some cases, victims may never be identified due to the way some of the reports of theft have been stored in DoorDash’s systems.
It seems the only reason law enforcement has a name for this case at all is by sheer chance, after stumbling upon $700,000+ inside lockboxes while investigating an unrelated incident. At this point in time, it’s not clear that all of the 700 drivers will get their lost funds back.
The Stamford Advocate notes that Smith faces charges of “first-degree larceny, third-degree identity theft, two counts of second-degree forgery, trafficking in personal identifying information and first-degree computer crime”.
The court appearance is scheduled for July 6.
DoorDash mentions that drivers are trained to look out for scams and attacks, but this one managed to sneak in under the radar. While most people wouldn’t dream of targeting gig economy workers during a pandemic, unfortunately some people aren’t most people. All it took here was one individual with a game plan to cheat 700 folks out of close to a million dollars.
How to avoid phishing
Block known bad websites. Malwarebytes DNS filtering blocks malicious websites used for phishing attacks, as well as websites used to spread or control malware.
Don’t take things at face value. Phishing attacks often seem to come from brands you know, and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.
Take action. If you receive a phishing attempt act work, report it to your IT or security team. If you fall for a phish, make your data useless: If you entered a password, change it, if you entered credit card details, change the card.
Use a password manager. Password managers can create, remember, and fill in passwords for you. They protect you against phishing because they won’t enter your credentials into a fake site.
use a FIDO 2FA device. Some forms of two-factor authentication (2FA) can be phished just as easily as a password. 2FA that relies on a FIDO2 device can’t be phished.
Malwarebytes EDR and MDR removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.
The Galaxy S23 Plus is the forgotten-middle child of the Galaxy S23 series, as was the case with the S22 series last year. But it is still a really good option for those that want a larger phone, with better battery life, but don’t necessarily need a S Pen or a larger display like what the Ultra provides. So those that did buy the Galaxy S23 Plus, you’re going to want to check out this buyers guide. This has every accessory that you might want to pick up for your new Galaxy S23 Plus.
Best Samsung Galaxy S23 Plus accessories
In this list, you’ll find things like smartwatches, chargers, cables, and so much more. What you won’t find here are cases. We already have a nice roundup of the very best cases for the Galaxy S23 Plus, which you can check out here.
If you purchased the new Galaxy S23 Plus, then this 45W wall charger is a must-buy. Even though the S23 Plus only supports up to 25W charging, this is going to future-proof you for a bit, as future phones will work with 45W or faster. Allowing you to fully charge it in about 40 minutes. Which is really useful.
The Galaxy Buds 2 Pro are the latest pair of earbuds from Samsung. These were announced last year, and were highly acclaimed. They offer better noise cancellation and better battery life, compared to the previous “Pro” model. Samsung has also included Hi-Fi sound here, so you’re going to get some really good audio quality on these, which is always nice to see.
The PopGrip from PopSockets is a really good accessory for really any phone. And the reason why this is the best PopSocket you can buy right now is because it does allow you to swap out the top. So if you want to change the color, you can do so.
PopGrip is really great because it allows you to hold onto your phone much easier, especially for larger phones, but even works great on smaller ones like the Galaxy S23 Plus. But it also doubles as a sort of kickstand for your smartphone. Allowing you to use it on long flights to watch a movie or two, without having to hold your phone the whole time. It’s a really genius invention, and it’s something that everyone should have.
You can attach the PopGrip to your case, so that it doesn’t ruin your phone too.
This is the same USB-C cable that Samsung includes in the box of the Galaxy S23 Plus. So there’s nothing special here, it’s just an additional USB-C cable that you can pick up and have in the car, at work, or even elsewhere in your home. It’s always good to have a second USB-C cable somewhere around, for when you need to charge your phone.
The Galaxy Watch 5 is the latest smartwatch from Samsung, and many might say its the best non-Apple smartwatch on the market. It’s definitely a stunning looking watch, and it starts at only $279. It does run on Google’s Wear OS, so you’re getting all of your usual apps that you know and love here. That also includes Google Assistant, Google Wallet and so much more.
The Fitbit Versa 4 is a great fitness tracker to go along with other accessories for your Galaxy S23 Plus. Especially if you’re looking to get in shape this year.
The Versa 4 is the latest in the Versa line for Fitbit. It offers up all of the fitness tracking that you’d expect from Fitbit. Including the ability to track your steps, your workouts, calories burned and much more. It can also deliver some notifications to your wrist.
The Anker PowerPort Atom PD 1 is the perfect USB-C PD charger to use with the Galaxy S23 Plus. While it does still come with one in the box, it never hurts to have a spare somewhere in your home or at work.
This is a 30W charger – and yes, the Galaxy S23 Plus tops out at 25W but this will work on other devices too. It also uses Gallium Nitride or GaN, which makes this charger a lot smaller than you’re probably used too. Which is why we think it is the best option. Since you can easily toss this into your bag when you’re traveling – if we are ever able to do that again.
This is one of the most interesting looking car mounts out there, and it really doesn’t even look like a car mount.
The Spigen Kuel S40 stealth Car Mount is a minimalist car mount for those that don’t want to use magnets. This is a car mount that folds down when it is not in use. Just open it up and stick your phone in the mount, in landscape mode and you are good to go. It’s a good option, because it is fairly small when it is not in use, so that it is not blocking your view of the road all that much.
Spigen offers the Kuel S40 Stealth car mount in only one color. Which is black and blue, so it can blend in with your car a bit more.
This is the new Wireless Charger Duo from Samsung, still capping out at 15W. And that is because Samsung’s phones only do up to 15W. This charger does come in both black and white, so you can choose the one that best fits in your home or office.
With this being a duo charger, you’re able to charge your Galaxy S23 Plus, as well as your smartwatch, or maybe your headphones too. Unfortunately, you can only charge one phone at a time here, as the other, secondary charger is slower. And meant for headphones or a smartwatch.
Apple just joined the long list of companies that banned ChatGPT from being used internally. Prior to this, some other companies also prohibited employees from using ChatGPT over the leak of confidential materials.
As an AI-driven chatbot, ChatGPT uses natural language processing to generate responses to user queries. It was developed by OpenAI and has been widely used by companies for various purposes, including customer service and internal communication.
The chatbot may learn from the data it gets since it employs machine learning algorithms to respond. This might enable the chatbot to gain access to private information about Apple’s trade secrets. The company is known to be highly secretive about its operations. Any data breach could put Apple’s business and reputation at considerable risk.
Apple employees can no longer use ChatGPT internally
According to an internal document that The Wall Street Journal reviewed, the tech giant notified its employees about the ban and asked them not to share confidential data with the ChatGPT. GitHub’s automated coding tool, Copilot, is another tool hit with the Apple ban.
The news comes after Google also warned its employees about using AI chatbots and sharing data with them. Google even asks employees to be cautious when sharing data with the company’s AI chatbot Bard. In another instance, it was reported in early April that ChatGPT had leaked Samsung semiconductor information. All in all, Apple’s concerns seem justified.
The quality of the responses produced by ChatGPT may further justify the ban. The chatbot can produce accurate and pertinent responses, but there is always a chance that it can give inaccurate or misleading information. This could harm Apple’s business operations and confuse employees.
Apple’s plans for AI and chatbots remained vague. The sources constantly say Apple is working on a rival for ChatGPT while the company has not yet shown any clue. With OpenAI’s decision to launch the ChatGPT iOS app, Apple could face a serious setback in the future.
A pair of malicious apps were discovered in the Google Play Store recently by cybersecurity firm Cyfirma. The latter said that the apps were used by state-sponsored threat actors to collect location data and contact lists from targeted devices. Cyfirma, with medium confidence, says that the attack comes from a hacking group in India called “DoNot.” The attacks have been spotted in Pakistan.
The two apps in the Play Store are nSure Chat and iKHfaa VPN. The latter copied code from a legitimate app called Liberty VPN (virtual private network used by those browsing the internet to avoid being tracked) and added additional code to access and collect the contacts list and discover the location of the target. The app also continued tracking the location of the target in real-time.
Those installing the iKHfaa VPN app are asked to enable location service
While most VPNs do not ask for permission to use location and contacts, iKHfaa VPN does. This made Cyfirma suspicious enough to dig deeper to find that “DoNot” was the attacker behind the malware. When installing the VPN app, it would also show a pop-up asking users to “turn on device location, which uses Google’s location service. If the GPS on the targeted person’s phone is on and active, the malicious app will be able to figure out the current location of the target. If not, the previous location will appear.
The first two apps listed by the developer in the Play Store are malicious
The two aforementioned apps, and a third one from the same developer (which does not appear to be malicious), remain in the Google Play Store. If you have either one installed on your phone no matter where you live, make sure to uninstall them as soon as possible. The name of the developer is SecurITY Industry and the number of downloads for the malicious apps is low which means that they are aimed at specific targets even though they appear in Google’s app storefront.
If this app is available from the Google Play Store in your region, do not install it on your phone
Remember, one of the best ways to prevent yourself from installing a malicious app on your phone to read the comments section. Look for red flags such as complaints from those who installed the app about their phones running too hot, running too slow, and suffering from rapid battery depletion. These are some of the signs that should make you run away from an app instead of installing it.
Heads up, Android users! The latest GravityRAT malware variant now targets Android devices and steals WhatsApp chat backups. The malware reaches the devices by posing as a chat app. Again, this highlights the essentiality of downloading only known apps from trusted sources.
According to a recent report from ESET, a new GravityRAT malware variant has been actively targeting Android devices.
GravityRAT is a spyware known since 2015 as a potent remote access trojan targeting Windows, macOS, and Android systems. It has run numerous malicious campaigns with different iterations, each bearing more advanced malicious capabilities.
The recent GravityRAT variant targets Android devices and steals various files, including WhatsApp backups. To achieve this goal, the threat actors rolled out “BingeChat,” – a supposed chat app. The app offers numerous attractive features, including end-to-end encryption, voice chats, file sharing, an easy user interface, and free availability to lure users.
To further instigate curiosity and add a sense of legitimacy to the app, the threat actors have restricted the app download to an “invite-only” mode with registration requirements. This seemingly prevents the app analysis from potential researchers and ensures a targeted victim base.
Apparently, the app functions usually because the threat actors have developed it on the open-source Android messenger OMEMO IM. That’s how it avoids alarming users about the embedded GravityRAT malware in this trojanized app.
After being downloaded and installed, the app requests risky permissions, which any legit messaging app would request. These include access to SMS messages, contact lists, call logs, location, and device details. Once obtained, the app transmits all this information to the attackers’ C&C.
Alongside these capabilities, the new GravityRAT malware hidden inside the BingeChat app also receives commands regarding file deletion, call log deletion, and contact list deletion. Moreover, it steals files with various extensions, including crypt14, crypt12, crypt13, and crypt18 extensions that often represent WhatsApp chat encrypted backups.
SpaceCobra Identified As Possible Attacker
The researchers have shared a detailed technical analysis of this malware and the BingeChat campaign in their report.
For now, the exact identity of the threat actors behind this malware remains unknown. But ESET names the “SpaceCobra” group as the one behind GravityRAT.
While the recent campaign seemingly continues, it remains unclear how the attackers manage to reach their potential target users. That’s because the app doesn’t exist on the Google Play Store, which suggests that the attackers may be approaching their potential victims through other means, luring them into downloading the app from their domain.
Yet, the one thing that always saves users from such threats is to avoid downloading apps and clicking on links from unknown and untrusted sources.