Luxottica confirms 2021 data leak

0
[ad_1]

Italian eyewear brand Luxottica, parent company of Ray-Ban and Oakley, has confirmed that the data of more than 70 million customers was accessed in 2021.

The data was exposed after a third-party data storage provider used by Luxottica suffered a cyber attack. It has not currently been made public how the hackers gained access to its network, or which company the third party was. The data breach and theft was revealed after a malicious actor posted a database of the information for sale on the dark web from April 30 to May 12. 

In a statement to cyber security news site BleepingComputer, Luxottica confirmed the breach, saying it was the result of a cyber attack in 2021 against a third-party contractor that stores its customer data. The eyewear company also shared that the data accessed includes the names, email and home addresses, phone numbers and dates of birth of its customers. The data, however, did not include any payment information or other sensitive or compromising information, like social security numbers or login  credentials.

The company said it discovered the breach through “proactive monitoring procedures” and immediately reported it to the Federal Bureau of Investigation (FBI) and the Italian police once it was revealed. According to Luxottica, the owner of the site that hosted the stolen information has now been arrested, the website shut down and an investigation into the cyber attack launched.

Luxottica has additionally informed the Italian Data Protection Authority (Garante per la protezione dei dati personali) about the breach and will be “considering other notification obligations”. The company says it “remains confident that its systems were not breached and its network remains secure”.

An investigation into how the breach took place remains ongoing.

Top admin of hacking forum arrested

There have been crackdowns against dark web sites in the recent months, with the FBI shutting down notorious dark web hacking site, BreachForums after arresting its top admin in March of this year.

The administrator of the site, who went by ‘Pompompurin’ and was named as Conor Brian Fitzpatrick by the FBI, was allegedly arrested by the Bureau on March 15 on suspicion of hosting and running the forum. 
BreachForums was thought to be the reincarnation of RaidForums, a similar dark web site that was investigated and subsequently shut down by the FBI in April 2022.

It has been used by a number of hackers to break news of data breaches they have committed and as a marketplace for selling the data stolen in these breaches. Large databases of victims’ information have been posted to the site, including those involved in the Medibank data leak, which affected over 9.7 million people. 

On March 21, a new admin for BreachForums, who uses the screen name ‘Baphomet’ made a post via the site’s official Telegram channel. Baphomet said it was the “final update for Breached” and that he would be “taking down the forum”.

“I believe we can assume that nothing is safe anymore. I know that everyone wants the forum up, but there is no value in short term gain for what will likely be a long term loss by propping up Breached as it is,” he added.

The reference to “nothing [being] safe” was likely an allusion to the fact that the FBI has taken control of the forum. When the FBI shut down RaidForums in April 2022, the organization seized all its servers and domains, allowing them access to all posts before it was shut down. 


[ad_2]
Source link

APT Hacker Group Attacking SMBs to Use Their Infrastructure

0
[ad_1]
APT Hacker Group Attacking SMBs

Proofpoint’s security researchers have identified indications of sophisticated threat actors focusing their attention on small and medium-sized enterprises and service providers operating within that particular ecosystem.

The researchers recently issued a cautionary message in their latest report regarding a collection of increasingly severe threats SMBs face. 

Researchers utilized Proofpoint Essentials telemetry, caging a vast range of more than 200,000+ small and medium businesses, to identify distinctive APT trends that present significant risks to SMBs worldwide.

Specifically, they highlight the risk posed by well-funded APT groups, as well as the alarming possibility of supply chain attacks originating from managed service providers that are compromised.

Proofpoint’s advisory carries significant concern, as it sheds light on the vulnerability of SMBs, which frequently operate without dedicated security teams, making them susceptible to malware attacks, similar to defenseless targets.

Persistent Threat Actor Groups

The researchers successfully detected numerous advanced persistent threat (APT) actors, exclusively focusing their attention on small and medium-sized businesses (SMBs), with a notable presence of threat actors affiliated with the national interests of the following countries:-

Organizations prioritize network security by addressing business email compromise (BEC), cybercriminals, ransomware, and common malware found in the daily inflow of emails received globally.

Advanced persistent threat actors conduct targeted phishing campaigns associated with strategic missions, but, still their widespread understanding remains uncommon.

While the specific missions include:-

  • Espionage
  • Intellectual property theft
  • Destructive attacks
  • State-sponsored financial theft
  • Disinformation campaigns

Emerging APT Trends

Proofpoint researchers analyzing one year of APT campaign data have identified Russian, Iranian, and North Korean threat actors conducting phishing campaigns against SMBs, revealing three notable trends in attack types and tactics employed against these businesses.

Here below, we have mentioned those three notable trends:-

  • APTs exploit hacked SMB infrastructure for phishing attacks.
  • APTs target SMB financial services with state-aligned, financially motivated attacks.
  • APTs target SMBs for supply chain attacks.

The Exploitation of SMBs’ Infrastructure

In the past year, Proofpoint researchers noted an increase in instances where SMB domains or email addresses were impersonated or compromised, often through successful attacks on web servers or email accounts, either by harvesting credentials or exploiting unpatched vulnerabilities.

Upon achieving a successful compromise, the compromised email address was subsequently employed to transmit malicious emails to subsequent targets.

If a threat actor managed to compromise a web server hosting a domain, they would exploit the legitimacy of said infrastructure, utilizing it to host or distribute malicious malware toward a target unrelated to the initial compromise.

In a notable finding, Proofpoint researchers discovered that the APT actor TA473 (Winter Vivern) exploited compromised SMB infrastructure to conduct phishing campaigns aimed at US and European government entities between November 2022 and February 2023.

Government entities have fallen victim to email account compromises due to exploiting unpatched Zimbra webmail servers.

Not only has TA473 employed compromised small and medium business (SMB) infrastructure to send emails, but they have also utilized compromised SMB domains to distribute malicious malware payloads.

Apart from this, more threat actors groups like TA422 and TA499 actively exploited several SMBs.

By impersonating Ukrainian President Volodymyr Zelensky, TA499 attempted to lure a prominent American celebrity into a video conference call regarding the conflict in Ukraine.

State-aligned threat actors, particularly those associated with North Korea, pose an ongoing threat to the financial services sector by targeting institutions, decentralized finance, and blockchain technology in financially motivated attacks aimed at stealing funds and cryptocurrency, in addition to espionage, intellectual property theft, and destructive attacks.

Proofpoint identified a phishing campaign executed by the North Korea-aligned TA444, targeting a medium-sized digital banking institution in the United States, with the funds obtained likely being utilized to support various aspects of North Korea’s government operations.

Proofpoint’s recent publication highlighted TA444’s deceptive tactics, including impersonating ABF Capital in an email that contained a malicious URL, leading to the distribution of the CageyChameleon malware, showcasing their innovative approach during the latter half of 2022.

TA450’s focus on regional managed service providers (MSPs) in Israel suggests a consistent pattern in their geographic targeting, emphasizing their ongoing interest in exploiting supply chain attacks against vulnerable MSPs to gain access to downstream small and medium-sized business (SMB) users.

APT actors present a real threat to today’s small and medium businesses by compromising their infrastructure, engaging in state-aligned financial theft, and targeting regional MSP supply chains.

APT actors pose a real threat to SMBs today, targeting their infrastructure, conducting financial theft, and attacking MSP supply chains

This research aids business owners and regional MSPs in adopting agile email phishing protection, detecting targeted attacks, prevent spam, and effectively combating cybercrime threats.

Shut Down Phishing Attacks with Device Posture Security – Download Free E-Book


[ad_2]
Source link

YouTube TV Makes NFL Sunday Ticket More Convenient with Unlimited Streams

0
[ad_1]

The NFL Sunday Ticket is coming to YouTube TV this fall, and we’re slowly learning more about the experience fans can expect, later this fall. On Thursday, YouTube TV announced that it is also adding unlimited streams at home for the NFL Sunday Ticket Package.

This comes after feedback from many subscribers about being able to have unlimited concurrent streams. Now this is only going to be in your home. Outside of your home, you’ll be able to use 2 concurrent streams. That is in addition to the unlimited streams at home.

This will be available to those that subscribe via YouTube TV, as well as YouTube Primetime channels.

YouTube TV is also making Multiview available for NFL Sunday Ticket

Among a few other features, YouTube TV is also making Multiview available for NFL Sunday Ticket. Allowing you to watch up to four games at the same time. This is similar to what DIRECTV offered with Sunday Ticket. So it’s not a surprise, but this is new for YouTube TV. In fact, it was testing the feature during March Madness this year.

On top of that, customers will be able to DVR as many games as they want. Since NFL Sunday Ticket does offer every single game – both in-market and out-of-market – to everyone, you can literally record every game. And don’t forget that the Cloud DVR is unlimited. Making this a really sweet option.

The big difference for YouTube TV having the NFL Sunday Ticket, versus DIRECTV, is that you’ll be able to watch it anywhere, without a satellite dish. Since it’s done over an internet connection.

So how much is NFL Sunday Ticket going to cost? Well, it’ll be $349 for YouTube TV subscribers, and $389 with NFL RedZone. For those that just want Sunday Ticket and not YouTube TV, it’ll be $449 and RedZone is added for $489. Now that price is for the full season. It’s more expensive than any other service, because of the deals the NFL has with FOX and CBS for local games. Unlike MLB.TV, NFL Sunday Ticket does broadcast in-market games.


[ad_2]
Source link

Malicious screen recording app was stealing data for over 9 months

0
[ad_1]

It comes as no surprise that over the past few years, both Google and Apple have been making efforts to prevent malicious apps from entering their respective app stores. However, threat actors always find a way as according to a new report from ESET, a malicious Android app called “iRecorder – Screen Recorder” was secretly recording and transmitting users’ audio every 15 minutes.

Originally launched as a screen recording app back in September 2021, the app reportedly received a malicious update in August 2022, which installed AhMyth, an open-source Remote Access Trojan (RAT), on users’ devices. This allowed the app to record audio, establish a connection to the attacker’s server, and upload recorded audio files and sensitive data. Additionally, with the appropriate permissions, the app was also able to intercept text messages and phone conversations.

Undetected for over nine months

The fact that the app went undetected for over nine months makes this incident even more concerning, as users had no way of realizing that threat actors were recording their voices every 15 minutes. Moreover, researchers also speculate that the app was possibly part of an active espionage campaign, however, this claim remains a hypothesis without additional evidence.

“It is rare for a developer to upload a legitimate app, wait almost a year, and then update it with malicious code,” said ESET security researcher Lukáš Štefanko.

Although Google removed the app from the Play Store after the incident came to light, it is uncertain whether all current users are aware of its malicious behaviour or have taken appropriate action. Therefore, if you still have the app installed, delete it immediately and run a full scan of your device using a trusted antivirus tool. Additionally, users should always exercise caution while downloading an app, even from the Play Store, and pay close attention to the permissions requested by every app on their mobile device. Furthermore, it is important to regularly check if an app is unnecessarily using data in the background.


[ad_2]
Source link

Samsung Bixby update adds new features for US customers

0
[ad_1]

Bixby, Samsung’s virtual assistant, has gone a long way since it was launched five years ago to replace the rather poorly designed S Voice assistant. Thanks to timely and meaningful updates more and more Samsung fans are starting to use Bixby in their everyday lives.

These days Samsung is rolling out another Bixby update specifically designed to improve the user experience for children accounts. When children with Bixby accounts use Samsung’s voice assistant and required additional third-party sharing permissions, they will now be able to request verification of their parental consent.

Currently, this feature is only available in Korea and the United States, but Samsung confirmed that more countries will be added gradually, so anyone with a Samsung phone should get it in the coming weeks.

But this isn’t the only new feature included in the update. According to the changelog spotted by SamMobile, the update introduces the ability to activate voice wake-up when a ringtone, alarm, or Bixby TTS is playing, even without the “Wake up when sound is playing” option.

Users who want voice wake-up to activate when playing music can turn on the “Wake up when media is playing” option in the Bixby settings under Voice wake-up.

Finally, a third new feature added to Bixby in the latest update enables the voice assistant to recommend useful settings related to a wider range of commands. Simply talk to Bixby to start getting these recommendations.

The changelog also mentions that functional improvements and bug fixes have been added too, but no other details are provided. This is a pretty small update that weighs in at around 60MB, at least in Korea and the US where it includes an additional feature.


[ad_2]
Source link

Elon Musk’s SSN allegedly leaked in data breach

0
[ad_1]

Car manufacturer Tesla’s CEO, Elon Musk, may have had his social security number leaked in a data breach that saw 100GB of confidential information accessed.

The Dutch data protection watchdog, Autoriteit Persoonsgegevens (DPA), has said that Tesla may have failed to protect confidential data from employees, customers and business partners.

According to news publication Reuters, Tesla has been accused of failing to protect employee, customer and business partner data after 100GB of confidential information was leaked by an employee. The DPA has said that it is “looking into” the data breach.

According to German newspaper Handelsblatt, the publication which broke the Tesla data leak story, the files leaked include the names of more than 100,000 names of current and former Telsa employees, including the social security number of Tesla CEO Elon Musk.

Other sensitive data included in the leak includes the phone numbers, private email addresses and salaries of employees, bank details of customers and confidential details from Tesla production. This would mean the breach would violate European Union General Data Protection Regulation (EU GDPR) laws.

According to Handelsblatt, a Tesla lawyer said a “disgruntled former employee” had abused their position as a service technician to gain access to the data and legal action would be taken against said individual. 


[ad_2]
Source link

iRecorder Android App Targeted Its Users With AhRAT Malware

0
[ad_1]

Heads up, Android users! If you ever installed the iRecorder app on your phone, it’s time to uninstall it now, as it might be spying on your device. Researchers found the iRecorder app suddenly turned malicious as it infected the target Android devices with AhRAT malware.

iRecorder App Sneakily Barraged Android Users With AhRAT Malware

According to a recent report from ESET, their researchers found malicious activities associated with the iRecorder app on Play Store. Specifically, they observed iRecorder deploying AhRAT spying malware on the respective Android devices.

What’s peculiar in this recent malicious campaign is that the threat actors seemingly waited for quite some time before preying on the users. As observed, the iRecorder app first appeared on the Google Play Store in September 2021. At that time, the app had no malicious codes. And it remained harmless, functioning as a mere screen recording app until August 2022, after which it suddenly started deploying malware.

With version 1.3.8, iRecorder began deploying AhRAT RAT on the devices to monitor users’ activities. Briefly, AhRAT, as the researchers analyzed, is a new remote access trojan based on the open-source AhMyth Android RAT.

After becoming trojanized, the app started functioning maliciously, performing many sneaky activities in the background. While it continued to serve as a screen recorder, it also began extracting users’ surroundings’ sounds via the device’s microphone and stealing stored documents (files with specific extensions) from the device. It would then transmit all the exfiltrated data to its C&C.

Google Removed iRecorder From The Play Store

Following the researchers’ report, Google removed the malicious app from the Play Store. However, until then, the app already garnered over 50,000 downloads, indicating the extent of AhRAT’s infection.

However, the iRecorder app seemed to be a single instance deploying the AhRAT malware. The researchers could observe no other app associated with this campaign. Also, they could not link the activity to any specific threat actor group. However, according to ESET, the specificity of the app’s maliciousness hints at some cyber espionage.

For now, users still running the iRecorder app on their devices must remove it immediately to stop the malware activity. Also, users must always download apps from known developers to avoid falling prey to such scams.

Let us know your thoughts in the comments.


[ad_2]
Source link

YouTube Stories are shutting down next month

0
[ad_1]

YouTube Stories will soon be a thing of the past. The feature is going away in a month. The company has announced that you will no longer be able to post Stories starting on June 26th. Stories shared before that will expire seven days after they were originally posted. The Google-owned video site encourages creators to use Community posts to share quick updates with their viewers.

You might be already familiar with the Stories feature on social media apps. Snapchat introduced this content format where anything you share automatically disappears after a fixed time, which is usually 24 hours. Facebook, Instagram, Skype, LinkedIn, Twitter, YouTube, and many other platforms copied this format from Snapchat, some giving it a unique name of their own (Twitter called it Fleets).

However, not all of them had as much success with Stories as Snapchat or Facebook. Twitter discontinued Fleets less than a year after launch, while LinkedIn waved goodbye to its version of the feature after a year too. Turns out this format isn’t popular on YouTube either. “Amongst creators who use both posts and Stories, posts on average drive many times more comments and likes compared to Stories,” the company said in its announcement.

YouTube added that Community posts are now available to millions of creators. The company has brought some popular aspects of Stories to Community posts to make the feature more appealing. You now get rich editing tools and the ability to make posts expire automatically after 24 hours. Creators can also use new engagement features such as polls and quizzes to strengthen connections or start conversations with their audiences.

YouTube gave Stories its own spin but that didn’t work

YouTube launched Stories in late 2017. The feature was initially called Reels but the company later renamed it to Stories. Following a limited availability for about a year, Stories were expanded to all creators with 10,000 subscribers in late 2018. YouTube gave the feature a unique spin to make it look different. Most notably, those temporary posts live on for a whole week before disappearing, which is a lot longer than the 24-hour time limit on other platforms.

But as YouTube added more ways for creators to engage with their audiences apart from long-form videos, Stories started to take the back seat. The arrival of Shorts, a TikTok-style feed of short videos, in 2020 (out of beta in 2021) may have particularly spelled its demise. The feature lived on for two more years but never caught on with creators. And as of June 26, 2023, YouTube Stories will be a thing of the past.


[ad_2]
Source link

Snapdragon 8+ Gen 2 won’t be much different than Snapdragon 8 Gen 2

0
[ad_1]

The upcoming Snapdragon 8+ Gen 2 won’t be much different than the Snapdragon 8 Gen 2, it seems. A well-known tipster has offered more insight into Qualcomm’s upcoming flagship-grade processor.

The Snapdragon 8+ Gen 2 won’t be much different than its predecessor

This information comes from Digital Chat Station, as he shared the info via Weibo. He says that the Snapdragon 8+ Gen 2 will basically just be an overclocked version of the Snapdragon 8 Gen 2.

He also notes that the chip will be considerably more expensive, though. That could result in price increases for the phones that will utilize it. The chip is already being tested by a number of Chinese smartphone OEMs, including Xiaomi, OPPO, Meizu, and iQOO.

The iQOO 11s could be the first phone to feature the Snapdragon 8+ Gen 2. That smartphone is expected to arrive in the third quarter of this year. The Redmi K60 Ultra is also rumored to include the chip.

It will just be an overclocked version of the Snapdragon 8 Gen 2

Considering that the tipster says this will just be an overclocked version of the Snapdragon 8 Gen 2, we presume that nothing else will be changed. If that’s the case, it may not be worth getting for many OEMs, considering the price.

The Snapdragon 8 Gen 2 is an outstanding SoC, with great power consumption, and it also doesn’t heat all that much compared to the Snapdragon 8 Gen 1. A higher clock speed is probably not enough to justify a major price increase.

We’ll, of course, have to wait for the chip to actually launch in order to be sure. It does seem to be on the way, though, despite the fact rumors claimed otherwise until recently. Qualcomm wants to continue its tradition of releasing two flagship-grade processors every year.

The Snapdragon 8+ Gen 2 is expected to arrive in the near future, as the Snapdragon 8 Gen 3 is expected to launch towards the end of the year.


[ad_2]
Source link

You can buy the Motorola Edge (2022) for only $349

0
[ad_1]

Amazon has a great sale going on right now for the Motorola Edge (2022). It’s currently priced at $349, which is going to save you $250 off of the regular price. That does bring it down to its all-time lowest price.

Motorola Edge (2022) – Amazon

Why you should buy the Motorola Edge (2022)

The Motorola Edge (2022) is a great smartphone for anyone looking for a powerful and affordable device. It has a sleek design, a powerful processor, and a long-lasting battery. It also has a great camera system that can take stunning photos and videos.

Here are some of the reasons why you should buy the Motorola Edge (2022):

  • Powerful processor: The Motorola Edge (2022) is powered by the Qualcomm Snapdragon 778G processor, which is one of the most powerful processors on the market. This processor can handle even the most demanding tasks, such as gaming and video editing.
  • Long-lasting battery: The Motorola Edge (2022) has a large 5000mAh battery that can easily last for a full day on a single charge. This means you can use your phone all day without having to worry about running out of power.
  • Great camera system: The Motorola Edge (2022) has a triple-lens rear camera system that can take stunning photos and videos. The main camera has a 50MP sensor, and the other two cameras have 13MP and 2MP sensors. The front-facing camera has a 32MP sensor for taking selfies.
  • Sleek design: The Motorola Edge (2022) has a sleek and stylish design that will turn heads. It is made of durable materials and has a water-resistant design.
  • Affordable price: The Motorola Edge (2022) is very affordable, especially considering all the features it offers. You can get it for just $349.

If you are looking for a powerful and affordable smartphone, the Motorola Edge (2022) is a great option. It has a sleek design, a powerful processor, a long-lasting battery, a great camera system, and an affordable price.

Here are some additional features of the Motorola Edge (2022):

  • 144Hz refresh rate: The Motorola Edge (2022) has a 144Hz refresh rate, which means that the screen updates 144 times per second. This makes for a smoother and more responsive experience when gaming or scrolling through social media.
  • 6.6-inch OLED display: The Motorola Edge (2022) has a 6.6-inch OLED display with a resolution of 2400 x 1080 pixels. The OLED display provides deep blacks and vibrant colors.
  • Android 12: The Motorola Edge (2022) comes with Android 12, and has since been upgraded to Android 13.

Overall, the Motorola Edge (2022) is a great smartphone for anyone looking for a powerful and affordable device. It has a sleek design, a powerful processor, a long-lasting battery, a great camera system, and an affordable price.

Motorola Edge (2022) – Amazon


[ad_2]
Source link