Layer 7 DDoS Attacks on Microsoft

0
[ad_1]
Microsoft Confirms Hacking

Recently, it’s been confirmed by Microsoft that the current outage problems experienced by the following services of Microsoft were due to intentional Layer 7 DDoS attacks:-

The credit for the attacks goes to a threat actor called Storm-1359 (aka Anonymous Sudan), as per Microsoft’s findings.

Microsoft observed a rise in web traffic targeting specific services starting in early June 2023, resulting in temporary availability issues.

Without any delay, Microsoft instantly started monitoring the ongoing DDoS attacks thoroughly by launching a quick investigation.

Layer 7 DDoS Attacks

Rather than targeting layer 3 or layer 4, the recent DDoS attacks have primarily targeted layer 7.

OSI Layers

To enhance customer protection against similar DDoS attacks, Microsoft strengthened layer 7 defenses by optimizing Azure Web Application Firewall (WAF).

Microsoft discovered that Storm-1359 could use different cloud services and open proxies to launch DDoS attacks using several botnets and tools.

Moreover, here below, we have mentioned the main focuses of Storm-1359:-

  • Causing disruptions
  • Attracting public attention

In a report published recently, Microsoft provided an introductory analysis of the root cause, suggesting DDoS attacks as the potential reason behind the Azure outage, highlighting a noticeable surge in network traffic.

In a Layer 7 DDoS attack, threat actors specifically direct their efforts towards the application level, aiming to overload services by flooding them with excessive requests.

This huge flood of requests overwhelms the services, causing them to become unresponsive since they cannot handle the load.

The threat actors employ multiple DDoS methods to overpower a web service, exhausting its connection pool and causing it to accept new requests.

Types of DDoS Attack Traffic

Here below, we have mentioned all the types of layer 7 DDoS attack traffic:-

  • HTTP(S) flood attack
  • Cache bypass
  • Slowloris

Recommendations

Here below, we have mentioned all the recommendations offered by Microsoft:-

  • To protect web apps, make sure to use layer 7 protection services like Azure Web Application Firewall (WAF).
  • Stay protected against known bad bots by implementing the bot protection managed rule set.
  • Make sure to block the IP addresses and ranges that you identify as malicious.
  • Unknown and suspicious traffic should be blocked.
  • To block and limit the HTTP or HTTPS attacks automatically that have known signatures, create custom WAF rules.

Looking For an All-in-One Multi-OS Patch Management Platform – Try Patch Manager Plus


[ad_2]
Source link

New Malware targets WhatsApp Backups, steals sensitive data

0
[ad_1]

Another day, another malware scare. This time, it’s targeting WhatsApp backups as well as some other sensitive data.

It comes from a hacking group called SpaceCobra, who has developed an instant messaging app, which is able to steal a lot of sensitive information from the target device. And it appears that the threat actor also knows exactly who they want to target. Since researchers have been unable to download the app.

The news comes from ESET, some of their cybersecurity researchers have recently discovered two messaging apps called BingeChat and Chatico, were actually serving GravityRAT, a remote access trojan. The RAT is able to exfiltrate plenty of sensitive information from compromised endpoints. This includes information like call logs, contact list, SMS messages, device location, basic device information and files with specific extensions for pictures, photos and documents.

The apps cannot be found in the Play Store either

This is a pretty sophisticated malware app. Typically, you can find them in the Play Store and download them. But that’s not the case here. The apps cannot be found on the Play Store, nor other app stores. Instead, they can only be downloaded by visiting a special website, and opening an account.

Researchers from ESET could not open up an account on the site, as registrations were showing as “closed” when they visited. This leads the researchers to believe that hackers are being very precise about who to attack. Potentially looking at specific locations or IP addresses.

It appears that the majority of victims seem to be from India. Which sounds about right, since WhatsApp is very popular in that country. The attackers are also from Pakistan. And apparently the campaign has been active since last year.

So how can you protect yourself? Well, since this app needs you to register an account, do not register an account on any fishy looking websites. Especially one that wants your WhatsApp login credentials. That’s just asking for bad news.


[ad_2]
Source link

Googlers try to convince us that Pixel Fold is different from other Foldables

0
[ad_1]

On the eve of Google’s Pixel Fold launching, Engadget got the chance to sit down with a few Google Designers to talk about the new foldable. Which is a first for Google. While Apple is typically late to market with new products and technology, Google is pretty late here too. After all, the first foldables started to land on store shelves back in 2019.

Google is aiming to help and explain why their foldable isn’t just another foldable. Starting off with the shape of the Pixel Fold. It’s one of the wider foldables on the market. Compared to the Galaxy Z Fold 4 which has a very skinny front display, Google’s is actually more of a regular phone size. And George Hwang, one of Google’s product managers on the Pixel Fold, said that this design choice was on purpose, and wanted it to be shaped more like a passport. Hwang said that when they “talk about the Pixel Fold, we often talk about the outer display first.”

Hwang continued on by saying that their “focus on form factor was critical and quite intentional to make sure that we offered a usable exterior display, such that you could use the phone like you want to.” That might sound kind of odd, but with other foldables, that outer display is tall and skinny. Making it tough to use for every app. But this outer display is a 17.4:9 aspect ratio, making it even wider than most smartphones these days. Many are 21:9 or 20:9 in 2023.

Google explains how software can be tricky on a foldable

As you might expect, software can be tricky on a foldable. Particularly a book-style foldable like the Pixel Fold. Because, not only does Google need to build in phone and tablet software to take advantage of the cover display and the main display, but also how the main display is opened. If it’s opened completely flat, or at an angle.

Google’s other product manager that Engadget talked to, Andrea Zvinakis, stated that they “wanted there to be a user benefit to unfolding the device rather than just seeing an expanded phone layout. That’s why we created things like dual shade for notifications that leverage both sides of the display.”

Of course, this new style can also unlock other potentials, like the dual-screen interpreter mode that Google showed off at I/O last month. Allowing two people to see what’s being said, in different languages. Making this really useful for traveling to foreign countries where your language might not be the main language spoken.

Sadly, Google wasn’t able to offer a lower price for the Pixel Fold. It still starts at $1,799, the same price as Samsung’s competitor. But that should change in the coming years as foldables become more mainstream and the components get cheaper.


[ad_2]
Source link

GravityRAT Spyware WhatsApp

0
[ad_1]

Since August 2022, a recently discovered Android virus named “GravityRAT” has rapidly circulated through a new Android malware campaign. 

It gains access to phones by disguising itself as a fraudulent chat app called ‘BingeChat‘ in order to steal users’ sensitive data.

BingeChat

ESET researcher Lukas Stefanko discovered that the latest version of GravityRAT now steals WhatsApp backup files.

The creation of WhatsApp backups is intended to facilitate the migration of users’ message history, media files, and data to different or new devices.

While it’s crucial to be aware that these backups may include unencrypted sensitive data like:-

Technical analysis

Since 2015, GravityRAT has been active and in operation, but it shifted its focus to Android devices in 2020 for the very first time.

The spyware is exclusively utilized by ‘SpaceCobra,’ its operators, for selected operations with specific targets.

The spyware disguises itself as a chat application called ‘BingeChat,’ which claims to offer:-

  • End-to-end encryption
  • A user-friendly interface
  • Advanced functionalities
powerful features

The delivery of the app occurs through the website “bingechat[.]net” or other available platforms.

However, downloading it requires an invitation, prompting visitors to register a new account or provide sensitive data like credentials.

download

Presently, registrations are closed, and this method is employed solely for the purpose of targeting specific people with the distribution of malicious apps.

In 2021, the operators of GravityRAT once again employed the tactic of promoting malicious Android APKs to their targets.

This time, they utilized a chat app called ‘SoSafe,’ while a previous app named ‘Travel Mate Pro‘ was used before that.

Stefanko discovered that the app is a modified version of OMEMO IM, which is an authentic open-source instant messaging application for Android but is now infused with a trojan.

It was revealed by an ESET analyst that SpaceCobra employed a fraudulent app called “Chatico.”

This app was distributed to targeted individuals through the website “chatico.co[.]uk” during the summer of 2022.

Permissions asked

Upon installation on the target’s device, BingeChat requests permissions that pose potential risks. The permissions include access to the following:-

  • Contacts
  • Location
  • Phone
  • SMS
  • Storage
  • Call logs
  • Camera
  • Microphone

As instant messaging apps commonly require these permissions, they are unlikely to trigger suspicion or seem strange to the targeted individual.

When a user attempts to register on BingeChat, the app transfers the following details automatically to a C2 server operated by the threat actor:-

  • Call logs
  • Contact lists
  • SMS messages
  • Device location
  • Basic device information

As a safety measure, it is advised that users must avoid downloading any APKs from other unknown or unreliable sources.

Additionally, it is important to exercise caution and be vigilant regarding app permissions during installation.

Looking For an All-in-One Multi-OS Patch Management Platform – Try Patch Manager Plus


[ad_2]
Source link

BlackCat threatens to leak 80GB of Reddit data

0
[ad_1]

Ransomware gang ALPHV, most commonly known as BlackCat, is allegedly responsible for the theft of 80GB of data from social media site Reddit. 

The allegation comes directly from the ransomware gang, who have claimed responsibility for a data breach that happened in February of this year. In a post on the gang’s data leaks site, BlackCat claimed to have stolen 80GB of compressed data during the attack and are planning on selling it. 

The malicious actors claimed to have contacted Reddit on both April 13 and June 16, demanding the site pay them US$4.5 million to delete the data, but received no response. BlackCat said that as they are “very confident that Reddit will not pay any money for their data”, they will be selling it.

The threat actors said that they are “very happy to know that the public will be able to read about all the statistics they track about their users and all the interesting confidential data [they] took”. The gang also claimed that Reddit “silently censor” users. 

Source: BleepingComputer

Cyber security news site, BleepingComputer, said that it was able to confirm that the attack referenced by BlackHat was the phishing attack against Reddit in February of this year.

The February phishing attack against Reddit

The breach occurred on February 5, after a phishing attack was launched at Reddit employees. The site said the attack contained “plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens”. 

After obtaining an employee’s credentials, the malicious actors were then able to gain access to Reddit’s internal systems. This meant that the hackers accessed Reddit’s internal business systems, dashboard, documents and source code.  

After being alerted to the phishing attack by the employee whose account was accessed, Reddit said it “removed the infiltrator’s access” and launched an investigation into the breach. The site noted that “similar phishing attacks” had been reported recently

The data accessed in the breach included “limited contact information for (currently hundreds of) company contacts and employees (current and former), as well as limited advertiser information”, but Reddit confirmed that “user passwords and accounts are safe”.

The site also reported that there was “no evidence” any of its primary production systems being accessed, or that any of its users’ “non-public data” had been accessed or posted online.

Reddit launched an internal investigation into the breach, as well as enhancing its security systems. Additionally, it urged users to enable multi-factor authentication and use a password manager both to set up complex passwords and to prevent themselves from being phished. 


[ad_2]
Source link

Galaxy Z Fold 5 & Flip 5 pricing info may surprise you

0
[ad_1]

The Samsung Galaxy Z Fold 5 and Flip 5 are coming next month, and some pricing information just surfaced. This info comes from Revegnus, a tipster, but the exact price tags are not revealed here.

The Galaxy Z Fold 5 & Flip 5 pricing info just surfaced

Still, the tipster did share some useful info. He said that the Galaxy Z Flip 5’s price tag will be on the same level as it was for last year’s model. In other words, you can expect a similar price tag as for the Flip 4.

For those of you out of the loop, the Galaxy Z Flip 4 launched with a $999 price tag. So, the Galaxy Z Flip 5 will either cost exactly $999, or its price tag will be really close to that.

What about the Galaxy Z Fold 5? That handset will be even more affordable than the Galaxy Z Fold 4, it seems. The tipster claims that the device will see a “slight reduction in price compared to its predecessor”.

The Galaxy Z Fold 4 launched with a price tag of $1,799. That was for the 256GB storage model of the device. The 512GB and 1TB iterations were more expensive of course.

The Galaxy Z Fold 5 will be a bit more affordable than the Fold 4

The Galaxy Z Fold 5 will cost less than $1,799, it seems. Will we get a $1,699 price tag, or will Samsung be able to pull off something even more affordable than that? Well, it remains to be seen.

Truth be said, this is not all that surprising. The Galaxy Z Fold 5 will look very similar to its predecessor. It will have the same form factor, pretty much. It will, however, include a different hinge, and fold flat as a result.

The crease control won’t be much better than it was on the Galaxy Z Fold 4, though, based on rumors. Samsung is taking a similar path with the Fold 4, so it’s not surprising it managed to lower its price a bit.


[ad_2]
Source link

Zoom calls are coming to Sony Bravia TVs soon

0
[ad_1]

It’s no secret that over the past few years, working from home has become a popular alternative for employees as it not only gives them more time with their family members but also helps the company save operational costs. Now, in an effort to make the virtual meeting experience more immersive, Sony has announced that its Bravia TVs will be the first to support Google’s new Zoom for TV app, offering a seamless and convenient way to participate in virtual meetings from the comfort of your living room couch.

This move by Sony follows Apple’s integration of FaceTime into Apple TV, and although it is a significant development, Bravia TVs do not come with built-in webcams. Therefore, users will need to purchase a $200 accessory called Bravia Cam to complete the setup. However, it is important to note that the Bravia Cam not only facilitates Zoom calls but also adjusts sound and picture settings based on the user’s position and distance from the TV.

Additionally, the accessory features a proximity alert system that detects when children are sitting too close to the TV and ensures that kids maintain a safe viewing distance. Moreover, the cam also includes a power-saving mode that automatically dims the TV when no one is watching, saving energy and prolonging the TV’s life.

Not available yet

While Sony has announced the new features and the Bravia cam accessory, the Zoom for TV app will be available for Bravia TVs “by early summer.” Shusuke Tomonaga, the head of Bravia product design at Sony, expressed enthusiasm about the partnership, stating, “This partnership will allow our customers to enjoy more realistic video communication on a big screen in the living room, enabling them to be more connected to the people they care about, whether they are working from home, studying remotely, or simply catching up with friends and family.”


[ad_2]
Source link

A total of 8 Samsung devices just surfaced in promo images

0
[ad_1]

Samsung’s entire Unpacked 2023 lineup just surfaced. The Samsung Galaxy Z Fold 5, Galaxy Z Flip 5, Galaxy Tab S9 series, Galaxy Watch 6, and the Galaxy Buds 3 all surfaced in promo images.

The Galaxy Z Fold 5, Flip 5, Watch 6 & devices surfaced

All of these devices will launch in Seoul next month, and they have just been shared by Evan Blass, a well-known tipster. These seem to be Samsung’s official promo images that obviously slipped from the company’s grasp.

If you check out the gallery below the article, you’ll see all the images that appeared, all six of them. In addition to that, SnoopyTech, another tipster, added an image that shows the entire Galaxy Tab S9 series. That image is also included below.

You can see both the Galaxy Watch 6 and Galaxy Watch 6 Classic in these images, along with the entire Galaxy Tab S9 series, including the Galaxy Tab S9, Tab S9+, and the Tab S9 Ultra.

A total of 8 Samsung products leaked in promo images

Needless to say, Samsung will have its hands full next month. We’re looking at 8 products in total here. We’ve counted every single member of the Tab S9 series, and Watch 6 series separately, of course.

Thanks to these images, we can also see some colors that these devices will be available. For example, the Galaxy Buds 3 are shown in a white color, while the Galaxy Z Flip 5 surfaced in both a green and silver color.

The Galaxy Watch 6 and Galaxy Watch 6 Classic are shown in a number of different colors. Well, their bands are different in terms of color, the frame of the watch will likely come in silver and black colors only, that goes for both models.

We still don’t know the exact launch date of all these products, but we do know they’re coming next month. Samsung also confirmed that a global press event will be hosted in Seoul, Korea, its homeland. The exact date will likely be confirmed in the near future.


[ad_2]
Source link

Elevate your visual storytelling with the Apexel 60X telephoto lens

0
[ad_1]

In today’s digital age, visual storytelling plays a crucial role in capturing and sharing our experiences. With the advancement of smartphone photography, individuals have gained unprecedented access to powerful tools for expressing their narratives. Among these tools, the Apexel 60X Telephoto Lens has emerged as a game-changer, offering impressive zoom capabilities and enhancing the storytelling potential of smartphone photography.

Understanding the Apexel 60X Telephoto Lens

The Apexel 60X Telephoto Lens is designed to revolutionize the way we perceive long-range smartphone photography. With its impressive 60X magnification, you can capture distant subjects with astounding detail and precision. This lens boasts a range of features and specifications that set it apart from its competitors in the market. By embracing the benefits of a zoom lens for mobile photography, users can unlock new creative possibilities and elevate their visual storytelling endeavors.

Apexel 60X Telephoto Lens Review

When considering the Apexel 60X Telephoto Lens, it’s essential to evaluate its build quality and design considerations. This lens is crafted with premium materials, ensuring durability and stability during use. Additionally, its ergonomic design provides a comfortable and intuitive experience, allowing photographers to capture their stories with ease.

Image quality and zoom performance are critical aspects to consider when assessing any telephoto lens. The Apexel 60X mobile lens excels in these areas, delivering exceptional sharpness and clarity at various zoom levels. Whether you’re capturing stunning landscapes or documenting wildlife, this lens unlocks your creative potential and allows you to take your photography to the next level.

Furthermore, the lens’s low-light performance and image stabilization capabilities contribute to consistently high-quality output. To truly understand its capabilities, it’s important to examine sample images that showcase the lens’s ability to capture incredible detail even from a long range.

Eagle image (Apexel)

Smartphone Photography Accessories

The Apexel 60X Telephoto Lens Kits comes equipped with a comprehensive set of accessories that elevate your photography experience. The extendable and stable tripod provides a solid foundation for capturing steady shots in any situation. Its foldable legs make it convenient for travel and outdoor photography.The metal clamp mount ensures secure attachment to your smartphone, while the rubber lens hood protects the lens from glare and unwanted reflections, ensuring optimal image quality.Remote shutter releases provide greater control over your shots, enabling you to capture precise moments effortlessly.

Universal Compatibility for Mobile Phones and Ease of Use

Apexel understands the importance of compatibility in the ever-evolving smartphone market. The 60X Telephoto Lens Kits is designed to be universally compatible with the latest smartphone models across different brands.

For example, the latest Samsung Galaxy S23 Ultra, 8, S9, S10, S22, Note 8, Note 9, and Note 10 etc. and iPhone 13/14 series,the Google Pixel series, One Plus 6, 6T, and 7 Pro etc.

Whether you own an Android or iOS device, this lens seamlessly integrates with your smartphone, unleashing its full potential and transforming it into a powerful camera that rivals dedicated photography equipment.

Installing and setting up the lens is a straightforward process, and a step-by-step guide is provided to ensure a hassle-free experience. Adjusting settings according to your preferences will further optimize the lens’s performance.

Enhancing Your Visual Storytelling

Long-range smartphone photography, made possible by the Apexel 60X Telephoto Lens Kits, opens up new creative avenues for visual storytelling. The ability to capture distant subjects with precision and detail adds a whole new dimension to your narratives. By leveraging this lens, you can experiment with unique perspectives and compositions, offering your audience a fresh and captivating visual experience.

Conclusion

The Apexel 60X Telephoto Lens presents a remarkable opportunity to elevate your visual storytelling through smartphone photography. Its exceptional zoom capabilities and compatibility with various devices make it a valuable accessory for any storyteller. By exploring the potential of long-range smartphone photography and leveraging the lens’s zoom capabilities, you can create compelling narratives that resonate with your audience. As mobile photography continues to evolve, it’s clear that the Apexel 60X lens is at the forefront, empowering users to tell stories in new and exciting ways. Embrace this powerful tool, and embark on a journey of visual storytelling that captivates and inspires.


[ad_2]
Source link

The brandjacking threat: How companies can avoid losing brand equity – GBHackers – Latest Cyber Security News

0
[ad_1]

Cybersecurity is a constant concern for modern companies. While enterprises can use several world-class tools to protect their internal networks, they can rarely monitor what goes on outside them. Brandjacking, an increasingly prolific threat, is testing most companies’ security postures. Unfortunately, companies are discovering they cannot account for such attacks.

The US Federal Trade Commission (FTC) considers it a big enough threat to propose new laws to prosecute such instances. So what is brandjacking and what should you know about it?

What is brandjacking?

Brandjacking refers to a malicious actor’s attempt at impersonating a legitimate company to defraud consumers. The malicious actor leverages the trusted company’s brand equity to trick consumers into divulging sensitive information.

These attacks happen outside a company’s network. For instance, a hacker might set up a lookalike website and steal credit card information. A legitimate company has no way of controlling these incidents but suffers from the blowback. Consumers might believe the company has swindled them and create a negative brand perception.

Here are the different kinds of brandjacking attacks:

  1. Cybersquatting – A hacker impersonates a trusted web domain.
  2. Subdomain jacking – Hackers can leverage unused subdomains and redirect traffic to a malicious website.
  3. Clickjacking – A malicious actor causes a pop-up to appear on a legitimate website, redirect traffic, and perpetrate fraud.
  4. Malvertisements – A hacker runs ads using a trusted brand’s name and redirects traffic to a lookalike website.

Damages associated with brandjacking

Brandjacking occurs outside a company’s network and at first glance, blaming the company for such attacks seems unfair. This is true. However, companies must proactively protect their brands since competitors might leverage these incidents to steal a march ahead.

Here are other reasons why a company must protect against brandjacking.

Negative reputation

Any data breach or security incident causes brand embarrassment. Brandjacking, ironically, happens only to companies that have worked hard to establish themselves as leaders in their sectors. After all, if no one has heard of or trusts a company, a malicious actor has little incentive to brandjack it.

Given the effort companies pour into building a brand, protecting it at all costs is logical. Even if the loss of reputation following a brandjacking attempt is unfair, a company suffers a loss of trust with its audience. If the company fails to take any action against the perpetrators or sweeps the problem under the carpet, consumers are more likely to associate that brand with fraud

Financial loss

Some brandjacking attempts can lead to lawsuits that create financial losses. For instance, a malicious actor who leverages an unused subdomain or an unused employee credential to redirect traffic from the company’s website is exposing its security flaws.

In such cases, regulators are unlikely to look the other way and will likely impose hefty fines. Given the existence of stringent data privacy laws like GDPR, companies cannot afford to ignore any attempts at compromising user safety online. The fines that accompany such violations are enough to cripple profits. The fallout from negative publicity following such rulings will further reduce a company’s ability to raise prices and compete.

Diminishing customer trust

The combined effect of the loss of brand trust and potential litigation leaves a company on shaky ground for the future. User trust is critical in supporting a business during challenging times. Repeated brandjacking attacks give the impression that a company is unable to combat malicious actors, reducing user trust.

In turn, these events dim a company’s prospects and leave it in an uncertain position. Consumer trust is a valuable asset when a company experiences challenging economic conditions. During these moments, being able to draw from a stable user base puts a company in an ideal position to increase market share while its competition flounders.

3 ways to prevent brandjacking

Here’s how companies can proactively prevent brandjacking.

As with the rest of cybersecurity, tool usage goes a long way toward monitoring and preventing brandjacking attempts. For instance, Adultblock by Network Solutions blocks a malicious actor from registering a company’s name to an adult domain. Other tools like Red Points monitors the web for impersonation attempts and notifies companies after the fact.

Memcyco, a real-time website impersonation protection tool, enables companies to immediately alert their users when they enter a spoofed brand website and provides the company with full details of the attack, allowing security teams to respond immediately to prevent further damage. Memcyco’s Proof of Source Authenticity solution (PoSA™) also provides an unforgeable digital watermark displayed on brand websites to prove site authenticity to their users.

The right protection and prevention tools can help companies open communication channels with their users and help them build brand trust.

Monitor different attack vectors

An attack vector is the path a malicious actor takes when infiltrating a system or carrying out an attack. In the case of brandjacking, phishing and social engineering are common attack vectors. Attackers send malware-loaded emails or impersonate trusted employees to get people to divulge sensitive information.

Companies must monitor these different vectors always and educate their employees about what to watch out for. Education is critical here. Security awareness training must go beyond mere awareness and change behavior

Continuously validate security approach

Security threats change regularly and continuously validating a security approach is the best way to ensure a company is always protected. Continuous monitoring tools and processes test and mimic a malicious attack, locate holes in a security setup, and work to plug them automatically.

Common attack vectors like misconfiguration errors or DDoS attacks tend to be nullified by continuous security monitoring.

Novel approaches to combat new threats

Brandjacking isn’t a new threat. However, the way attackers are executing it is novel and creates a serious problem for companies. Given the effort and resources companies pour into brand creation, protecting it is the obvious choice. 


[ad_2]
Source link