Malvertising via brand impersonation is back again

0
[ad_1]

Ads containing the official website of an impersonated brand are running again, allowing fraudsters to scam users.

Web search is about to embark on a new journey thanks to artificial intelligence technology that online giants such as Microsoft and Google are experimenting with. Yet, there is a problem when it comes to malicious ads displayed by search engines that AI likely won’t be able to fix.

In recent months, numerous incidents have shown that malvertising is on the rise again and affecting the user experience and trust in their favorite search engine. Indeed, Search Engine Results Pages (SERPs) include paid Google ads that in some cases lead to scams or malware.

One particularly devious kind of malvertising is brand impersonation where criminals are buying ads and going as far as displaying the official brand’s website within the ad snippet. We previously reported several incidents to Google and it appeared that those ads using official URLs were no longer getting through. However, just recently we noticed a surge in new campaigns again.

Brand abuse: Scammers exploit users’ trust

It only takes a few seconds between a search and a click on a result, and most of the time that click happens to be on whatever shows up first. This is why advertisers are buying ads on search engines, not only to drive traffic towards their brands but also to outpace potential competitors. Unfortunately, not all advertisers have good intentions and the worst of them will exploit anything they can to put out ads that are malicious.

For about a week we decided to pull some examples and focused on Amazon-related searches since it is a popular search term (although other popular brands are affected as well). The ads we found were not only claiming to be Amazon’s official website, they also displayed the amazon.com URL in the ad.

Malicious ad for Amazon
Figure 1a: Malicious advert

Network traffic
Figure 1b: Related network traffic

Malicious ad for Amazon
Figure 2a: Malicious advert

Network traffic
Figure 2b: Related network traffic

Malicious ad for Amazon
Figure 3a: Malicious advert

Network traffic
Figure 3b: Related network traffic

Malicious ad for Amazon
Figure 4a: Malicious ad

Network traffic
Figure 4b: Related network traffic

Malicious ad for Amazon
Figure 5a: Malicious ad

Network traffic
Figure 5b: Related network traffic

Below is an animation showing what happens when a victim clicks on one of those ads:

Animation showing a click on an ad leading to a tech support scam pageFigure 6: Malicious advert leads to phishing page

While most of the brand impersonations we have seen recently are pushing tech support scams, this is not the only threat facing consumers. For example, we saw an ad that pretended to be Amazon’s login page but instead redirects users to a phishing site, first stealing their password before collecting their credit card number. 

Malicious ad leading to phishing page
Figure 7: A malicious ad leading to a phishing site

How are these criminals evading detection?

Ad URL

Part of the problem here is that advertisers can be legitimate affiliates and associated with the Amazon brand. Here’s an example of a seller that is advertising on Google and has their own page as an affiliate on Amazon:

Proper way to advertise as Amazon affiliate
Figure 8: An advertiser leveraging the Amazon brand correctly

The problem comes when an advertiser that displays a brand’s official URL within the ad snippet (i.e. https://www.amazon.com) is allowed to submit an ad URL that has nothing to do with that brand. We have seen many examples that include URL shorteners, cloaking services or domains freshly registered for the sole purpose of malicious activity.

Spreadsheet used to report malvertising incidents

Figure 9: Incidents related to Amazon searches tracked in malvertising spreadsheet

The screenshot above is part of a document we have shared with Google where we and other researchers track new malvertising campaigns ranging from scams to malware distribution.

Anti-bot traffic funneling and cloaking

Threat actors often rely on traffic filtering services to push malicious content exclusively to intended victims. Practically all the malicious ads we showed earlier used a kind of traffic distribution and filtering system. This market is a bit of a gray area with some companies advertising as anti-bot or anti-fraud providers while others are shamelessly advertising in places frequented by online criminals.

The goal is to not only game Google’s and other ad networks but also to ensure that only qualified traffic is allowed to come through. With most malvertising from click ads, the practice comes down to something called cloaking.

With cloaking, there are two types of URLs used: the legitimate URL (or decoy) and the money URL (the malicious one). In the picture below we see such parameters as well as the threat actor’s money page which contains folders for Amazon (amz) and YouTube – another keyword abused by malvertisers – (ytb) malvertising campaigns:

Cloaking redirect

Figure 10: Cloaking parameters showing the money page

In this specific case we discovered a number of domains registered by the scammer, serving more or less the same purpose. One important thing to remember is that these domains are not immediately seen by Google. For example, the traffic filtering service will detect if a click is from a real user or a machine. It can then decide to forward the bogus click to Amazon’s website and therefore maintain its cover.

Scammer domains

Figure 11: Infrastructure used to redirect Google ads to tech support scams

For real traffic, these domains will act as intermediary to the payload pages which tend to be highly disposable and ever changing. There is a simple reason in that these are clearly malicious and will get reported and taken down. However, it is rare for the malvertising infrastructure to actually be disrupted because it is further upstream and rarely documented properly. This allows threat actors to continue with their malicious ad campaigns and simply swap payload pages.

Can Bard fix Google’s malvertising problem?

We asked Google’s AI chatbot Bard if it could fix the malvertising problem that seems to be plaguing its search engine. At first Bard said it was not able to solve this issue:

Asking Bard if it can fix malvertising

Figure 12: Bard answering a query about malvertising

However, on a second attempt Bard claimed it could after all help to fix the malvertising problem:

Asking Bard if it can fix malvertising again

Figure 13: Bard answering the same question in a different way

Regardless, malvertising is a complex issue and given the billions of daily ad impressions, it’s easy for someone nefarious to abuse any given platform. But we don’t need AI to identify certain elements that allow threat actors to impersonate brands. Also, while educating users about malvertising is important, we can’t blame them for clicking on paid ads that are supposedly verified as trusted.

Needless to say that these incidents will encourage users to install ad blockers at the chagrin of publishers whose revenues are heavily dependent on advertising. In the end, it comes down to the user experience and ensuring that it comes first, before anything else.

We then asked for some tips to protect against malvertising. We couldn’t help but notice that Bard suggested using an ad blocker, although a small disclaimer at the bottom clearly states that Bard may display information that does not represent Google’s views. Indeed, the ad industry accounts for almost 80% of Google’s revenues.

Asking Bard for some tips on malvertising

Figure 14: Bard offers some tips on how to protect from malvertising

Malvertising has been a problem for many years and it’s unlikely to change any time soon. It’s important for users to be aware that criminals can buy ads and successfully bypass security mechanisms all the while impersonating well-known brands. If you decide to type the URL in the address bar instead, remember to be careful not to make a typo. This is another area that is highly targeted by typosquatters and can also involve malvertising redirects.

All of the ads mentioned in this blog post have been reported to Google. We would like to thank the people working in the ad unit for their continued support.

Indicators of Compromise

Redirects:

tinyurl[.]com/amzs10
tinyurl[.]com/amz01111

Cloaking domains:

601rajilg[.]xyz
hesit[.]xyz
maydoo[.]xyz
pizz[.]site
ferdo[.]xyz
tableq[.]xyz
veast[.]site
amazonsell[.]pro
amaazoon[.]org
atzipfinder[.]com

Tech support scam domains:

ryderlawns[.]xyz
akochar[.]site
gerots[.]s3.eu-north-1[.]amazonaws[.]com
pay-pal-customer-helpline-app-tt6y3[.]ondigitalocean[.]app
micrwindow-app-38sqh[.]ondigitalocean[.]app
fekon[.]s3.ap-south-1[.]amazonaws[.]com

Malwarebytes Browser Guard provides additional protection to standard ad-blocking features by covering a larger area of the attack chain all the way to domains controlled by attackers. Thanks to its built-in heuristic engine it can also proactively block never-before-seen malicious websites.

We always recommend using a layered approach to security and for malvertising you will need web protection combined with anti-malware protection. Malwarebytes Premium for consumers and Endpoint Protection for businesses provide real-time protection against such threats.

TRY NOW


[ad_2]
Source link

Sony’s INZONE Wireless Gaming Headsets are back on sale

0
[ad_1]

Sony’s popular INZONE wireless (and wired) gaming headsets are back on sale over at Amazon. So now is a good time to pick up a pair.

The Sony INZONE H3 is a wired gaming headset and it is on sale for $58, that’s down from $99. The INZONE H7 gaming headset is also on sale, coming in at $148, that’s down from $229. While the H9 is on sale for $278, and that’s down from $299. So definitely some great prices here.

Both of these headsets are the same, minus one key feature. The INZONE H3 is a wired gaming headset, while the INZONE H7 is a wireless gaming headset. Otherwise they both are over-ear headphones with personalized 360 Spatial Sound included. Which is going to really help you feel really immersed in your game.

These headsets are made specifically for PC and the PlayStation 5. So if you are gaming on either platform, then this is a really good option for you.

On top of that, the INZONE headsets are also very comfortable to wear. Thanks to the shape that is designed to minimize pressure on your ears and offset to the side of your head. There’s also soft nylon earpads, that provide comfort for wearing these all day long.

Battery life on the INZONE H7 is rated at 40 hours, which is actually better than the H9 (which is not on sale today). But that also offers ANC as well as RGB lighting. While neither the H7 nor the H3 have RGB lighting available. But you can still optimize these for better audio in the INZONE Hub, available on both PC and PlayStation 5. The H7 also works on 2.4GHz wireless and Bluetooth. It’s not really needed to use 5GHz, since it needs better coverage over better speeds.

You can pick up the Sony INZONE H3 and INZONE H7 headsets from Amazon by clicking the links below. This sale is likely not going to last very long, so you’re going to want to be quick.

Sony INZONE H3 – Amazon

Sony INZONE H7 – Amazon

Sony INZONE H9 – Amazon


[ad_2]
Source link

Update now! Apple issues patches for three actively used zero-days

0
[ad_1]

Apple issued information about patches against three actively exploited zero-days in WebKit. One vulnerability is new, two were patched earlier this month.

Apple has rolled out security updates for Safari 16.5, watchOS 9.5, tvOS 16.5, iOS 16.5, iPadOS 16.5, iOS 15.7.6, iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Ventura 13.4, and macOS Monterey 12.6.6.

Among the security updates were patches for three actively exploited zero-day vulnerabilities. All these actively exploited vulnerabilities are directly related to the WebKit browser engine.

WebKit is the engine that powers the Safari web browser on Macs as well as all browsers on iOS and iPadOS (all web browsers on iOS and iPadOS are obliged to use it). It is also the web browser engine used by Mail, App Store, and many other apps on macOS, iOS, and Linux.

Devices impacted by the identified exploits include:

  • All iPad Pro models
  • iPad Air (3rd generation and later)
  • iPad (5th generation and later)
  • iPad Mini (5th generation and later)
  • iPhone 6s and later models
  • Mac workstations and laptops running macOS, Big Sur, Monterey, and Ventura
  • Apple Watch (series 4 and later)
  • Apple TV 4K and HD

The updates may already have reached you in your regular update routines, but it doesn’t hurt to check if your device is at the latest update level. If a Safari update is available for your device, you can get it by updating or upgrading macOS, iOS, or iPadOS:

The Common Vulnerabilities and Exposures (CVE) database lists publicly disclosed computer security flaws. The CVE containing the information about the new zero-day is:

  • CVE-2023-32409: An issue where remote attacker may be able to break out of Web Content sandbox was addressed with improved bounds checks.

The notes about the security updates also revealed some information about the Apple’s Rapid Security Response (RSR) update we reported about earlier this month.

RSR is a new type of software patch delivered between Apple’s regular, scheduled software updates. Previously, Apple security fixes came bundled along with features and improvements, but RSRs only carry security fixes. They’re meant to make the deployment of security improvements faster and more frequent.

We now know that the CVEs patched in that RSR update are listed as:

  • CVE-2023-28204: An out-of-bounds read issue in WebKit was addressed with improved input validation. Processing web content may disclose sensitive information.
  • CVE-2023-32373: A use-after-free issue in WebKit which was addressed with improved memory management. Processing maliciously crafted web content may lead to arbitrary code execution.

An out-of-bounds write or read flaw makes it possible to manipulate parts of the memory which are allocated to more critical functions. This could allow an attacker to write code to a part of the memory where it will be executed with permissions that the program and user should not have.

Use after free (UAF) is a vulnerability due to incorrect use of dynamic memory during a program’s operation. If after freeing a memory location a program does not clear the pointer to that memory, an attacker can use the error to manipulate the program.


We don’t just report on vulnerabilities—we identify them, and prioritize action.

Cybersecurity risks should never spread beyond a headline. Keep vulnerabilities in tow by using Malwarebytes Vulnerability and Patch Management.


[ad_2]
Source link

You can use Flipboard to browse Bluesky

0
[ad_1]

Last year, it was Mastodon; this year, it’s Bluesky. This upcoming decentralized social media app is getting a lot of attention as a potential alternative to Twitter. It’s another destination for people to migrate to after leaving the Musk-owned social media platform. Now, according to Engadget, you can use Flipboard to browse your Bluesky feed.

In case you don’t know what Bluesky is, this app is backed by Jack Dorsey, one of the founders of Twitter. This is meant to be a Twitter alternative that will prioritize decentralization. The app has been in development since 2019, and it is still in beta testing. We’re not sure exactly when the app will launch, but it’s going to be pretty soon.

As for Flipboard, this app has been around for a while. It will aggregate articles from different sites and publications and display them on a feed. You will scroll through your feed to access all of the latest articles. If you want to stay up to date with all of your favorite news, then you should give it a try.

You can use Flipboard to navigate your Bluesky feed

This move is part of Bluesky’s plan to take on Twitter. Also, this is a part of Flipboard’s plan. The newsfeed platform has integrated with another decentralized social media platform, Mastodon. With this integration, Flipboard is now a much more desirable news aggregation platform.

Using Flipboard, you’ll be able to flip through your Bluesky feed. This is extremely useful if you happen to use both apps. Instead of hopping from app to app, you can see your news articles and your social media feed all in one place. This is a very interesting integration, as Bluesky is not even out of beta testing Yet.

As Twitter continues to fumble, other platforms seem to be conspiring to steal as many people from it as they can. A lot of people have been claimed by Mastodon, and even Hive Social is getting a bit of a following. Bluesky is the latest, and we’ll just have to see how it fares.


[ad_2]
Source link

Google to pay $40m for “deceptive and unfair” location tracking practices

0
[ad_1]

We take a look at a case where Google is agreeing to pay $40m as a result of disclosure related to location tracking issues.

Google is going to pay $39.9 million to Washington State to put to rest a lawsuit about its location tracking practices which has been in play since last year. Google was accused of “misleading consumers” by State Attorney General Bob Ferguson. From the AG press release:

Attorney General Bob Ferguson today announced Google will pay $39.9 million to Washington state as a result of his office’s lawsuit over misleading location tracking practices. Google will also implement a slate of court-ordered reforms to increase transparency about its location tracking settings.

Ferguson’s lawsuit against Google asserted that the tech giant deceptively led consumers to believe that they have control over how Google collects and uses their location data. In reality, consumers could not effectively prevent Google from collecting, storing and profiting from their location data.

The lawsuit itself, announced back in January 2022, claimed Google used a “number of deceptive and unfair practices” to obtain user content for tracking. Practices highlighted included “hard to find” location settings, misleading descriptions of location settings, and “repeated nudging” to enable location settings alongside incomplete disclosures of Google’s location data collection.

These practices were set alongside the large amount of profit Google generated from using consumer data to sell advertising. Google made close to $150 billion from advertising in 2020, and the case pointed out that location data is a key component of said advertising. As per the Attorney General:

(Google) has a financial incentive to dissuade users from withholding access to that data.

The location based argument is focused on the discrepancy between claims related to what data Google stores in theory with location data turned off, and what it obtains in practice:

When users enable a setting called “Location History,” Google saves data on users’ location to, as it says in its account settings, “give you personalised maps, recommendations based on places you’ve visited, and more.”

Google told users that when Location History was disabled, the company did not continue to store the user’s location. For years, Google’s help page stated, “With Location History off, the places you go are no longer stored.” That statement was false. For example, the company collects location data under a separate setting — “Web & App Activity” — that is defaulted “on” for all Google Accounts.

The consent decree filed on Wednesday means Google will need to be more transparent with regard to tracking. The search engine giant will also need to provide more detailed information in cases where location technologies are involved.

AG Ferguson had this to say:

Google denied Washington consumers the ability to choose whether the company could track their sensitive location data, deceived them about their privacy options and profited from that conduct. Today’s resolution holds one of the most powerful corporations accountable for its unethical and unlawful tactics.

Google has been on the receiving end of legal action led by Ferguson for some time now. Just last month, he partnered with the US Department of Justice and a bipartisan group of attorneys general for an antitrust lawsuit aiming to break up Google’s monopolisation of display advertising. There have also been other antitrust lawsuits in this space, and in 2021 Google paid $423,659.76 in relation to violating the state’s campaign finance disclosure law.

We still don’t know how these proposed changes will take shape in terms of what consumers will see. “…with no federal law governing online privacy in the United States, state regulators are forced to make do with what they have” according to Android Central. With Ferguson showing no signs of letting up, Washington State is taking that philosophy to the max.


Malwarebytes EDR and MDR removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link

Top 10 Best BMX Android Games

0
[ad_1]

The wind through your hair, the rumble of the bike on the dirt path, the feeling of the soft living room couch under your bottom. There are a ton of great BMX games on the Google Play Store that you can download and play from the comfort of your couch. Here are some of the best BMX games that you can download now.

These games either involve doing sick tricks to rack up points, racing opponents, or navigating through obstacles. So, get your helmet on, and don’t forget your shoulder pads!

Top 10 Best BMX Android Games Summary

Before we get going, here’s a quick overview of the apps including the prices and in-app purchases associated with them.

Game Download Cost In-app cost (per item)
Touchgrind BMX 2 Free $0.99 – $24.99
Trail Boss BMX $3.99 None
Max Air BMX Free $1.99 – $14.99
Xtreme BMX Offroad Cycle Game Free $2.99 – $36.99
BMX Cycle Race: Cycle Stunts Free $0.99 – $11.99
Flip Rider – BMX Tricks Free $1.99 – $14.99
Trial Xtreme 4 Bike Racing Free $0.10 – $199.99
BMX FE3D 2 Free $1.49 – $9.99
BMX Boy Free None
BMX Space Free $0.99 – $19.99

Top 10 Best BMX Android Games

Below, we have a more in-depth explanation of all of the games on this list.

Touchgrind BMX 2

  • Download Cost: Free
  • In-App Cost: $0.99 – $24.99
  • Size: 815MB
  • Google Play Rating: 4.4  stars out of 5

This game doesn’t really bother with adding human characters. Instead, it focuses on the only part that matters, the bike. In this game, you’ll pilot an unmanned bike and perform all sorts of stunts to earn points.

This game definitely stands out from the other games for only having you control a bike. However, as you play, you’ll be able to unlock different bike designs as you play, and they’re all pretty nice to look at. You can also customize your bikes.

As for the gameplay, you’ll hold two fingers on your phone and move them accordingly to do different tricks when you gain some air. There are a ton of tricks that you can do, so most of the fun will just be in learning the tricks.

Download Touchgrind BMX 2

Trail Boss BMX

  • Download Cost: $3.99
  • In-App Cost: None
  • Size: 369MB
  • Google Play Rating: 4.6  stars out of 5

This is one of the more robust games on this list. Trail Boss has five different difficulty levels that offer a range of challenge. The point of this game is to ride along different trails and make your way to the end of them. While you’re riding, you’ll be able to perform tricks when you gain air.

There are a bunch of customization options that you can use to personalize your bike. You can customize the color of the frame, fork, handlebars, grips, stems, tires, tire walls, rims, chain, cranks, hubs, spokes, pedals, seat post, seat, hardware, and chainring.

There are no in-app purchases in this game. You just pay the $3.99 to get it and that’s it. If you have Google Play Pass, then you can get it for free.

Download Trail Boss BMX

Max Air BMX

  • Download Cost: Free
  • In-App Cost: $1.99 – $14.99
  • Size: 107MB
  • Google Play Rating: 4.5  stars out of 5

MAx Air BMX is a pretty simple BMX game that has you performing tricks in a 2.5D environment. The stages are ramps that you go back and forth on while performing tricks. As you perform tricks, you’ll earn coins that you can use to unlock more characters.

You’ll go down the ramp and hold your finger down once you get air. The longer you hold your finger down, the more points you’ll gather. However, you’ll need to be careful not to have your finger down when your character lands. If that happens, then your character will fall.

The longer you go without falling, the faster your character will ride. This means that you’ll gain more air and earn more points.

Download Max Air BMX

Xtreme BMX Offroad Cycle Game

  • Download Cost: Free
  • In-App Cost: $2.99 – $36.99
  • Size: 57MB
  • Google Play Rating: 4.8  stars out of 5

This is a BMX racing game that has you racing in different locations and types of environments. It strives for authenticity, so it’s a bit more realistic than other games.

When you start, you can choose between a male and a female racer. When you choose, you’ll be thrown right into the action.  The game is a bit slower-paced than some of the other games on this list, but it makes for a more realistic experience. You’ll need to control your speed to navigate the changing terrain and avoid obstacles.

The gameplay is pretty simple with the steering control on the left of the screen and the acceleration and brake on the right of the screen. It’s a fun and simple game to play.

Download Xtreme BMX Offroad Cycle Game

BMX Cycle Race: Cycle Stunts

BMX Cycle Race

  • Download Cost: Free
  • In-App Cost: $0.99 – $11.99
  • Size: 50MB
  • Google Play Rating: 4.4  stars out of 5

If you’re looking for a more robust BMX game, then you’ll want to try this one. In this game, you’ll be racing other riders in different locations for the gold. You’ll be racing through race tracks, but you’ll also race on roads where you’ll need to avoid traffic and other hazards.

Along the way, you’ll be performing stunts, and this adds some neat variety to the game. It’s a pretty high-octane experience that will keep you coming back for more. The conrol scheme is similar to other games like it. The steering controls are on the left of the screen and the acceleration and brakes are on the right.

Download BMX Cycle Race: Cycle Stunts

Flip Rider – BMX Tricks

  • Download Cost:
  • In-App Cost: $1.99 – $14.99
  • Size: 111MB
  • Google Play Rating: 4.5  stars out of 5

Flip Rider is a fun and simple BMX game that has you flipping on a ramp to earn you points. In this game, you’ll be on a bike ramp, and when you gain air, you’ll need to do flips. The point of the game is to see how many flips you can do before you land.

If you keep landing your tricks through the round, you’ll start to see a trail develop behind you, and your speed will increase. This means that you’ll be able to catch more air to perform tricks.

As you play the game, you’ll unlock more stages and environments. This adds some nice variety to the game and gives you an incentive to land more tricks.

Download Flip Rider – BMX Tricks

Trial Xtreme 4 Bike Racing

  • Download Cost: Free
  • In-App Cost: $0.10 – $199.99
  • Size: 362MB
  • Google Play Rating: 4 stars out of 5

In this game, you’re racing other players on impossible BMX tracks. They defy the laws of physics, and that makes it that much more fun. This is a 2.5D game, so you’ll be moving along one plane while racing the opponent.

As you race, you’ll need to be sure to keep your bike steady in the air when you make jumps. You’ll tap either one of the buttons on the left side of the screen to control your bike. It’s important to land your jumps properly because that affects your speed.

What’s neat about this game is the selection of customizations you have for your bike. You can change the look of your bike with tons of different add-ons. You can do this along with upgrading your bike’s performance.

Download Trial Xtreme 4 Bike Racing

BMX FE3D 2

  • Download Cost: Free
  • In-App Cost: $1.49 – $9.99
  • Size: 92MB
  • Google Play Rating: 4.3  stars out of 5

This game takes an approach similar to the Tony Hawk Pro Skater games from back in the day. When you start off, you’ll customize your character with some basic customizations and get going.

When you start, you’ll be placed in one of several different parks. Your job is to reawaken the 90s kid in you and perform trick after trick. Just like the old Pro Skater games, you’ll hop on the ramps, half-pikes, and other structures to perform a myriad of different insane stunts.

As you play, you’ll be able to upgrade your character’s stats. This way, you’ll be able to perform the stunts more easily as time goes on. It’s a great game to play if you’re looking for a nostalgic experience.

Download BMX FE3D 2

BMX Boy

  • Download Cost: Free
  • In-App Cost: None
  • Size: 22MB
  • Google Play Rating: 4.3  stars out of 5

BMX Boy is reminiscent of those simple biker games that you’d play on your internet browser. It’s very straightforward, and it has a certain charm to it. When you start, you’ll tap the screen to hop over the obstacles in your way. Along the way, you’ll gather these blue stars. As you collect them, you’ll gain XP points to level up.

You’ll use the acceleration button on the left of the screen to control your speed, and you’ll tap on the right side to tilt the titular BMX Boy forward. It’ll be a balancing act of tilting your character forward just enough to land your jumps. It’s a fun and simple time waster.

Download BMX Boy

BMX Space

 

  • Download Cost: Free
  • In-App Cost: $0.99 – $19.99
  • Size: 87MB
  • Google Play Rating: 4.3 stars out of 5

BMX Space is a fun and straightforward game to pass the time. When you start, you’ll be able to customize your character and the bike. This game is a level-based game where you have to perform different tricks before the time runs out. There are a bunch of levels that you’ll need to go through.

You’ll use the joystick on the left of the screen to move and the one on the right to control your character in the air. Using the combination, you’ll be able to perform a myriad of different stunts.

Download BMX Space


[ad_2]
Source link

Hackers Use Weaponized DOCX File to Deploy Stealthy Malware

0
[ad_1]
Weaponized DOCX File

CERT-UA has identified and addressed a cyber attack on the government information systems of Ukrainian governmental state bodies.

Through investigation, it was discovered that the department’s email address received communications on April 18, 2023, and April 20, 2023, appearing to originate from the authentic email account of the Embassy from Tajikistan (In Ukraine).

Weaponized DOCX File

Suspected to be a result of the compromised state of the embassy, these emails comprised an attachment in the form of a document that contained a macro in the initial case while referring to the same document in the later incident.

When the document is downloaded, and its macro is activated, it creates and opens a DOCX file called “SvcRestartTaskLogon” with a macro that generates another file with the “WsSwapAssessmentTask” macro. 

While it also includes a “SoftwareProtectionPlatform” file categorized as HATVIBE, which can load and execute additional files.

During the course of technical investigation, it was documented that on April 25, 2023, supplementary programs were generated on the computer, possibly facilitated by HATVIBE, under uncertain circumstances.

Here below, we have mentioned those additional generated apps:-

  • LOGPIE keylogger
  • CHERRYSPY backdoor

The files are created with Python and secured with PyArmor, while the “pytransform” module, providing encryption and code obfuscation, is further safeguarded with Themida.

The STILLARCH malware is employed for searching and exfiltrating files, including data from the LOGPIE keylogger, with file extensions such as:-

Further analysis of infrastructure and associated data determined that the group’s targets include organizations from various countries engaging in espionage activities under the code name UAC-0063, which have been monitored since 2021.

To minimize the vulnerability scope, it is advisable to limit user accounts from executing “mshta.exe,” Windows Script Host (“wscript.exe,” “cscript.exe”), and the Python interpreter, thereby reducing the potential attack surface.

Shut Down Phishing Attacks with Device Posture Security – Download Free E-Book


[ad_2]
Source link

Employee guilty of joining ransomware attack on his own company

0
[ad_1]

An employee that tried to take advantage of a ransomware attack on his own company has pleaded guilty after 5 years of denying he had anything to do with it.

A 28-year old IT Security Analyst pleaded guilty and will consequently be convicted of blackmail and unauthorized access to a computer with intent to commit other offences.

It all started when the UK gene and cell therapy company Oxford BioMedica fell victim to a cybersecurity incident which involved unauthorized access to part of the company’s computer systems on 27 February, 2018. The intruder notified senior staff members at the company and demanded a ransom. As an IT Security Analyst at the company, Ashley Liles was tasked with investigating the incident.

He worked alongside colleagues and the police in an attempt to mitigate the incident. But at some point he must have decided to use the circumstances to enrich himself. According to the South East Regional Organised Crime Unit (SEROCU), Liles commenced a separate and secondary attack against the company.

As part of his plan he changed the Bitcoin payment address of the attacker to his own in emails to the board members. And he set up an email address very similar to that of the attacker. From that email address he began emailing his employer to pressurize the company to pay the ransom.

Unfortunately for Liles, a payment was never made and the unauthorized access to the private emails was noticed during the investigation. Due to some poor choices when it came to his own security, the police arrested Liles and searched his home.

The unauthorized access to the emails could be traced back to his home address, which gave the police sufficient grounds to seize a computer, laptop, phone, and a USB stick. Despite his attempts to wipe the data from his devices, the police was able to recover enough data to act as evidence to prove his crimes and establish his direct involvement.

Liles denied any involvement for five years. But on May 17, 2023 during a hearing at Reading Crown Court, he changed his plea to guilty. The case has now been adjourned for sentencing at the same court on July 11, 2023.

While this definitely qualifies as an insider threat, this one seems to have been opportunistic rather than premeditated. The term is often associated with disgruntled employees, but they can also be coerced, or jump on an opportunity that presents itself, as Liles did. The case emphasizes the need for effective access control policies, even when an emergency presents itself. You do not want to make the scope of the incident worse by giving up your access policies in light of an investigation.

Access to resources should always be limited to what is needed to get the job done. And incidental access should be revoked when the need is no longer there. We’re not saying that every employee should be treated as a suspect or potential insider threat. That will result in an unworkable situation. But you should have measures in place to limit the damage and find any culprit.

How to avoid ransomware

  • Block common forms of entry. Create a plan for patching vulnerabilities in internet-facing systems quickly; and disable or harden remote access like RDP and VPNs.
  • Prevent intrusions. Stop threats early before they can even infiltrate or infect your endpoints. Use endpoint security software that can prevent exploits and malware used to deliver ransomware.
  • Detect intrusions. Make it harder for intruders to operate inside your organization by segmenting networks and assigning access rights prudently. Use EDR or MDR to detect unusual activity before an attack occurs.
  • Stop malicious encryption. Deploy Endpoint Detection and Response software like Malwarebytes EDR that uses multiple different detection techniques to identify ransomware, and ransomware rollback to restore damaged system files.
  • Create offsite, offline backups. Keep backups offsite and offline, beyond the reach of attackers. Test them regularly to make sure you can restore essential business functions swiftly.
  • Don’t get attacked twice. Once you’ve isolated the outbreak and stopped the first attack, you must remove every trace of the attackers, their malware, their tools, and their methods of entry, to avoid being attacked again.

Malwarebytes EDR and MDR removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link

Samsung details Knox Matrix as the security platform turns 10

0
[ad_1]

Samsung‘s award-winning mobile security platform Knox is ten years old! The company introduced Knox at Mobile World Congress in February 2013. Over the past decade, it has evolved into one of the most trusted security platforms for mobile devices, safeguarding billions of consumers and businesses on the way. In a recent Newsroom post celebrating the 10th anniversary of Knox, Samsung talked about its vision for the platform in the years ahead, including Knox Matrix.

Samsung Knox Matrix is the future of mobile security

At SDC 2022 in October, Samsung announced Knox Matrix as the security platform of the future. It is a private blockchain-based platform that builds on its existing solution. But instead of safeguarding a single device, it offers the same level of protection to all connected devices in an ecosystem.

According to Samsung, there are already more than 14 billion connected devices on the market. From smartphones, tablets, and TVs to refrigerators, washing machines, and robot vacuum cleaners, people use an array of connected devices in their households. This ecosystem will keep growing, and this poses a massive security risk. Existing security platforms can only protect a single device. If one of the devices in an ecosystem has weaker security, it may allow threat actors to compromise the security of other devices as well.

This is where Samsung’s Knox Matrix comes into play. It enables all devices in the ecosystem to protect one another, ensuring strong security for all. The bigger your device ecosystem is, the stronger its overall security. Moreover, should the security of one of them be compromised, the platform will automatically isolate it from the rest of the ecosystem. This allows you to use your connected devices in the same manner as before while also safeguarding them from potential exploitations.

Samsung says the whole platform relies on three critical technologies. Firstly, Trust Chain enables devices in an ecosystem to monitor each other for threats. Credential Sync secures user information as you move data between devices. Finally, Cross Platform SDK enables consistent Knox Matrix security standards for devices on various operating systems and platforms, including Android, Tizen, Windows, and others. The security platform manages all of this within a private blockchain.

Samsung’s next-gen security platform will arrive in 2024

Samsung originally planned to debut Knox Matrix this year. But the company has now delayed its launch to 2024. It is needing more time to ensure that the platform is interoperable across every device type and security system. “Knox Matrix’s development is going strong, but there are challenges on the way to the next frontier. These include reconciling the many different types of products, with varying operating systems and security standards, into a frictionless system able to work as one,” it said in the Newsroom post.

Samsung now plans to launch the first Knox Matrix-compatible models in 2024. It will start with mobile Galaxy products, such as smartphones and tablets. The Galaxy S24 series could be the first to get the new security system. If not, we might be looking at the 2024 foldables. The company will gradually add more device categories such as home appliance devices within the next two to three years. Partner devices will follow next, though the development for partner device compatibility is already underway.


[ad_2]
Source link

Bill Gates talks about the future of AI and its impact on Big Tech

0
[ad_1]

Microsoft co-founder and one of the wealthiest men on the planet Bill Gates has talked about AI and how it can reshape customer behavior. Speaking at the Goldman Sachs and SV Angel event, Gates alluded to the capability of AI to challenge Big Tech companies like Google and Amazon.

Gates predicted that the top AI company in the future would be a company that could build a personal agent to perform tasks for people. He added that AI could “radically” change user behaviors. For example, users don’t need to visit a website or shop in an online store anymore.

“Whoever wins the personal agent, that’s the big thing because you will never go to a search site again, you will never go to a productivity site, you’ll never go to Amazon again,” Gates said.

Bill Gates says a personal digital agent could abolish Google and Amazon

Microsoft co-founder added that the future AI winner could be either a startup or a tech giant, and there is a 50-50 percent chance for it. He controlled the AI-driven personal agent and would be able to understand users’ needs and read them the stuff they normally don’t have time to read.

Bill Gates also said he was impressed by some AI startups like Inflection, which was co-founded by a former DeepMind executive Mustafa Suleyman. Gates added he’d be “disappointed if Microsoft didn’t come in there.”

According to Gates, the AI digital agent still needs a few years to be ready for mainstream use. But the companies will continue to integrate chatbots like ChatGPT into their products. Gates noted that AI could help develop more advanced drugs to cure diseases like Alzheimer’s.

Finally, Bill Gates said generative AI technologies that can produce texts would affect white-collar workers. Additionally, humanoid robots that are cheaper than actual human workers will greatly impact blue-collar workers.

“As we invent these robots, we just need to make sure they don’t get Alzheimer’s,” Gates said.


[ad_2]
Source link