The vulnerabilities caused by weak email security

0
[ad_1]

Why email security

Threats to email security are on the rise. Research conducted for Cyber Security Hub’s Mid-Year Market Report 2022 found that 75 percent of cyber security practitioners think that email-based attacks such as phishing and social engineering are the ‘most dangerous’ cyber security threat to their organizations. Companies must protect this vulnerable asset without compromising its efficiency in communication.

Email security is integral to protecting companies from external threats but also essential to protecting a brand’s customers from outbound threats such as phishing, data breaches and business email compromise (BEC). Without sufficient email security strategies, companies open themselves, their clients, and their customers to the consequences of cyber security incidents.

Threats to email security not only encompass attacks from bad actors but the internal function of the company. Research from Stanford University found that 88 percent of all data breaches are due to an employee mistake, meaning companies must be hypervigilant when training their employees. This training should take place in an easily accessible format so that information is easily retained by employees and future mistakes are avoided.

This threat to the internal workings of a company can also led to further damage to its brand if not dealt with swiftly and effectively. Even long-time customers may lose faith in organizations if they feel they are unable to trust in their cyber security strategy, especially when their personal data is on the line.

In this article, Cyber Security Hub provides guidance on how to implement excellent email security and make sure your employees understand its importance.

Also read: Report on cyber security challenges and spends

The vulnerabilities caused by weak email security

Overlooking email as a security risk is a dangerous oversight for any organization. In 2020, professional services network Deloitte reported that 91 percent of all cyber-attacks began with a phishing email.

There are a number of threats poor email security present, ranging from social engineering attacks, phishing and account compromise to takeover and data theft. Phishing attacks can target users’ passwords and accounts that could contain sensitive and valuable customer information. Credential theft is also a risk as employees may reuse passwords for multiple different platforms across their business and personal life, weakening a business’s security if any of these accounts are compromised or exposed during a data breach.

Djon Ly, digital marketing manager at money service operator Statrys, says that there is no reliable way for businesses to manage passwords or ensure that employees regularly change their passwords. Social engineering and sophisticated hacking techniques can make it difficult for employees to correctly identify fraudulent emails, Ly notes, even if an organization has email protection or holds regular security training.

“Frequently, phishing emails will ask recipients to reset passwords or log in to a fraudulent account website in order to harvest credentials. Even if an organization has email protection and regular security training, it can be very difficult for users to determine whether or not an email is fraudulent,” she explains.

Muhammad Babamia, IT internal audit specialist for cyber security and data and analytics at South African investment holding company Transaction Capital, agrees, stating: “The greatest risk to email security are careless employees.

“People are the weakest link from a cyber security perspective,” he adds. “This is especially true in terms of email security. While email configuration and security layers aid in reducing email-related breaches, they remain in place in some form of reliance on diligence of humans.”

When it comes to email security, while the best software measure may be put in place, true email security also hinges on employees’ abilities to understand why and how the company may be attacked via email, and what to do in the case of a compromise.

“People are the weakest link from a cyber security perspective – this is especially true in terms of email security.”

Muhammad Babamia, IT internal audit specialist at Transaction Capital

The consequences of phishing campaigns can be devastating for businesses. In 2014, Sony Pictures’ employees, including system engineering and network administrators, were targeted with fake emails that looked like legitimate communications from Apple, asking them to verify their Apple ID credentials.

By clicking on the link provided, employees were taken to a legitimate-seeming webpage that required them to input their login details. As these emails were targeted at those who would most likely have access to Sony’s network, these details were then used to hack into its network.

The spear phishing campaign led to multiple gigabytes of data being stolen including business-related content, financial records, customer-facing projects, and digital copies of recently released films. The hack cost Sony an estimated US$15mn.

Kym Welsby, regional director for APAC at Clearswift, a HelpSystems company, notes that one of the main issues with ensuring email security is that email was designed with no security functionality from its outset.

“[Email having no security] was the secret of its success. This was fine when relatively fewer people were using it to contact people they knew only, but with its expansion people no longer know who is contacting them,” Welsby explains.

As employees within a business will be used to people from outside the company contacting them, as well as speaking to people they do not know in a business capacity, this can make them less wary of potentially dangerous or fraudulent emails. There are a number of threats when it comes to email security, from direct attacks on employees through phishing campaigns or social engineering to a lack of security functionality in email.

In the next section of this report, we will explore how to combat these threats.

“[Email having no security] was the secret of its success. This was fine when relatively fewer people were using it to contact people they knew only, but with its expansion people no longer know who is contacting them,”

Kym Welsby, Regional director for APAC at Clearswift, a HelpSystems company

Ensuring email security within your business

Email-based attacks like phishing and social engineering that directly target employees within a business can have devastating consequences for businesses, with three in four cyber security professionals surveyed for Cyber Security Hub’s Mid-Year Market Report 2022 stating these attacks are the ‘most dangerous’ threat to cyber security.

These attacks directly target employees inside a business, placing the responsibility for ensuring the attack does not progress in their hands. Additionally, these attacks often rely on psychologically manipulating employees. They can be very effective in convincing employees to act in ways they would not usually, even if they have had security training.

The effectiveness of phishing attacks may rely on how effectively employees can evaluate whether an email is safe. This can be an issue if employees do not pay attention to cyber security training. Clearswift’s Welsby explains that this complacency in this task may be due to a misconception from those within a business that their antivirus or antimalware software is sufficient to block any and all threats. As antivirus software can only stop and prevent known threats such as malware or ransomware, however, if a breach attempt involves a new, unknown file or URL, it may not be able to block an attack.

Ensuring good cyber security within businesses requires employees to be engaged with their training so they are better able to retain the information and use it at a later date when they do come across cyber security threats.

How to engage employees with email security

In a discussion between Cyber Security Hub’s Advisory Board, one member suggested that linking email security to a company’s universal goals was very beneficial. This involves conducting multiple phishing tests throughout the year, with the score of said tests affecting a businesses’ bottom line. This is because phishing attacks have an indirect influence on a company’s bottom line. Cyber-attacks cost a lot of money, meaning if a cyber-attack occurs, companies will lose money in operations costs. Additionally, cyber-attacks may lead customers to lose trust in a company and take their business elsewhere, leading to an overall drop in revenue. With bonuses directly linked to profit, financially motivated employees should be more diligent in not clicking on potentially dangerous links, as their good behavior is reinforced and rewarded.

Also read: Strenghthen email security & protection against ransomware attacks

Jorel Van Os, chief information security officer at insurance company Acrisure, suggests companies can better engage their employees by employing the use of short-form video content using real-life case studies as examples.

“[The videos are] a testimonial, with an actor reenacting real case studies,” Van Os remarks. “I think that’s a good, compelling way to [train employees].

“They are one to two minutes each, he explains. “We did a micro-survey on the videos in terms of length of content, effectiveness of content and delivery of content, and we got 4.8 out of five stars out on across hundreds or thousands of people that rated it.”

One such example is a testimonial from an actor posted on LinkedIn entitled ‘My LinkedIn post cost my company a fortune’. In the testimonial, the actor explains that someone posing as a recruiter enticed him into communicating with them first through comments on his LinkedIn posts, then via messages with a lucrative job offer.

The faux recruiter built a relationship with him, and finally sent him a PDF which, supposedly, contained the job offer. Instead, it contained only a cover letter and two blank pages. When the actor reached out to the supposed recruiter, they explained that it was a secure file, and prompted him to download and install a secure PDF reader. When this still did not work, the actor contacted the recruiter again, but the recruiter did not respond to any of his messages. He dismissed this, but weeks later there was a data breach at his company that cost the company millions of dollars. The breach was traced back to him, as the PDF reader had actually contained malware that was used to level an attack against the company.

The actor explains that job scam attacks are becoming more prevalent as people are expected to communicate with strangers, and download the attachments sent to them.

Van Os says that by doing this companies can help employees realize that they are involved with the email security of a business, as well as offering them a framework of what to do during a cyber security incident. It can also provide them with tips of what to look for in potentially malicious communications.

Companies can employ other tactics to keep employees engaged, says Transaction Capital’s Babamia.

“Traditional ‘death by PowerPoint’ presentation styles often lead to bored and inattentive learners,” Babamia remarks. “Organizations need to ensure that participants are engaged through various means of learning such as gamified learning and the use of incentives to promulgate better learning.

“Simulated phishing attacks are a great way to pick out unaware employees. With scare tactics in mind, employees should be more focused to ensure that the consequences of their actions do not lead to a severe breach of the organization’s information security,” he notes.

Ensuring email security beyond employees

In terms of ensuring email security beyond training, Clearswift’s Welsby notes that a layered solution is best, as there will need to be different controls to respond to different threats. He recommends combining content protection like structural sanitization – removal of active content within the email body and attachments and removal or rewriting URLs to go through a different web browser. Identity protection is particularly important, as social engineering and phishing attacks often rely on posing as someone with authority within the business. By looking for the good senders rather than preventing the bad, this allows software to identify and block bad actors post-delivery, preventing the spread.

Kemas Ohale, head of global information security operations at manufacturer of pneumatic control devices SMC Corporation, notes that using an email security solution that combines the power of threat detection artificial intelligence (AI) or machine learning (ML) with the power of the human to form a complete solution can be “highly effective” in keeping organizations safe.

“AI or ML cannot do it alone and neither can humans,” Ohale remarks. “Combining the two into a single solution and reducing the load on our security team through extensive automation is the optimal way to ensure inboxes are as secure as they can be.”

Email security can be ensured by engaging with employees and showing them how cyber security is inherently tied into their job. Beyond this, companies must engage defense strategies including email authentication protocols such as DMARC, structural sanitization and the use of AI or ML to help detect and neutralize threats to protect the email system. In the next section, this report will discuss the importance of email security in protecting your brand.

How email security can protect your brand

Email security is not just important for internal data safety, but for a company’s external brand. Bad email security can affect customers in multiple ways, from exposing their personal information to causing them to see a brand as less secure or trustworthy.

Clearswift’s Welsby notes that while most people think email security is about protecting their organization from threats, companies also need to protect their outbound emails and tell customers and clients to reject messages that are not from the company.

Welsby explains that while using DMARC authentication to detect and prevent email spoofing techniques used in phishing, business email compromise (BEC) and other email-based attacks seems easy in principle, it can be complicated – especially for large organizations.

Also read: 5 steps guide to build email security strategy

“We have had clients use applications to allow others to send emails on their behalf and had one organization that found it was using 200 more email applications than it realized it was using,” says Welsby. “As it was a big retail brand with many custom-built applications and service providers sending emails on its behalf, it took two years to establish the use cases [for email applications to send emails on their behalf].

“Brand protection makes it easier for brands to establish who they are and what services they use,” he adds.

Transaction Capital’s Babamia notes that as largerscale attacks may lead to high-sensitivity email disclosure, should attackers leak highly confidential information to the public, which can affect trust in a company. If this trust is broken, customers may leave the company and use a competitor instead, leading to a potential drop in revenue.

Customers can lose trust in brands when they believe they are not appropriately securing their data, leading to concerned customers to switch to different brands. By ensuring that both employees are fully engaged with and retain information from training, and that there is a robust email security solution in place, companies can put themselves in a better place to identify and mitigate cyber security incidents.

“Brand protection makes it easier for brands to establish who they are and what services they use.”

Muhammad Babamia, IT internal audit specialist at Transaction Capital

Final remarks

There are a number of threats to email security that employees must face. The most dangerous of these are social engineering and phishing attacks, as they directly target employees and can have potentially devastating consequences for their company.

Email security is fundamentally reliant on employees being vigilant against potential inbound attacks. In order to ensure all employees are in the best place to recognize and not engage with malicious emails, companies must take into consideration the way they are educating their employees in regard to cyber security. Using more engaging techniques like shorter videos, relating the content to themselves as employees or using a rewards-based system can help engage employees better, meaning they are in a better position to ensure email security.

Additionally, companies should ensure that they have robust security in place, including the use of structural sensitization and identity protection like DMARC. By using these methods, companies can ensure that phishing attacks are less successful, as URLs can be deemed as safe before they are clicked on, and malicious actors who attempt to pose as higher-ups in the company during social engineering or phishing attacks will be less likely to succeed.

By doing this, companies can protect their employees and the business itself from cyber criminals and in bound threats, while protecting clients and customers from outbound threats. By communicating these efforts with clients and customers, they can build trust in their cyber security, and prevent a loss of trust if a cyber security incident happens as if customers feel their data is not adequately protected, they may leave a business and take their custom elsewhere.

Read a PDF of the Report Here

How do you maintain good email security to strengthen your business model? Please let us know in the comments section below.


[ad_2]
Source link

What is business email compromise?

0
[ad_1]

In this article, Cyber Security Hub explores how cyber attackers use threat vectors like phishing, social engineering and ransomware to enact business email compromise (BEC).

Cybercrime is an ever-growing issue across virtually every industry. Expected to have a global cost as much as US$10trn by 2025, companies must fight to combat malicious actors seeking to gain from cyber attacks against them.

Threat actors increasingly use multiple threat vectors during attacks to overwhelm companies and make it easier for them to gain access to their network. This is makes it more important than ever to safeguard the most common vehicle for an initial breach point – email.  

The majority of hacking groups (65 percent) utilize email-based spear phishing campaigns as their primary attack vector. This cyber attack method targets specific individuals within an organization with the goal of compromising their credentials and using their privileged access to gain further control of a business’ network or steal information that only certain employees have access too.

These campaigns can have a devastating impact, not least from a financial perspective; in May 2022, the US Federal Bureau of Investigation (FBI) reported that BEC had led to a total loss of $43.3bn between June 2016 and December 2021.

In this Cyber Security Hub article will highlight the key vulnerabilities for those without sufficient email security and explain how to block threat actors from carrying out successful attacks while mitigating data loss and fraud.

Read also: Prevent advanced ransomware attacks with good email security

Email security must not be ignored

As the ransomware-as-a-service (RaaS) economy matures, ransomware gangs are demonstrating supreme confidence in their debilitating actions.

In January of this year, the UK’s Royal Mail had to completely halt all dispatch of items overseas after it became the victim of an alleged LockBit ransomware attack. The ransomware caused “severe disruption” to the computerized systems used to send mail abroad and resulted in Royal Mail requesting that customers stop sending mail abroad in the wake of the ransomware attack.

Verizon also noted a 13 percent increase in ransomware breaches in 2022. As ransomware can be spread via BEC, this statistic is especially worrying.

During email-focused cyber attacks, malicious actors may target low-level data within the attack’s early phases. This low-level data can then be used to gain access to and steal more sensitive data. With Microsoft reporting that it takes hackers just 24-48 hours to gain control of a network via a privileged account, even the compromise of low-level accounts can be serious.

For example, a hacker could pose as a job seeker to target those in human resources (HR). Hackers rely on the fact that HR professionals are used to receiving and opening attachments from unknown senders to allow their ransomware to spread across a network. Additionally, if attackers do compromise HR emails, this gives them access to confidential and sensitive company information. 

Read also: The dangerous vulnerabilities caused by weak email security

Best practices for alert organizations

Understanding the human element

Comprehensive email security strategies like the use of strong passwords and email encryption can provide a higher level of protection against BEC. This, however, relies on employees following the rules and with 65 percent of people reusing passwords for multiple or all of their accounts and 73 percent of people using the same passwords for both work and personal accounts, this is easier said than done.

Likewise, research by the Harvard Business Review has found that 67 percent of employees admit that they fail to adhere to cyber security policies, with a failure-to-comply rate at an average of once every 20 tasks. In 85 percent of all cases where employees knowingly broke procedure they cited work-related reasons for doing so, including “to better accomplish tasks for my job”, “to get something I needed” and “to help others get their work done”.

So, companies must recognize that their cyber security policies need to both protect the company while also not preventing their employees from doing their jobs efficiently. Likewise, employees should be made aware of their role as those on the front line against email-based cyber attacks. Not doing so can cause employees to cut corners in the name of efficiency without understanding the ramifications, ultimately endangering the company. 

Read also: Top tips for cyber security training 

Introduce a robust backup strategy 

As cyber attackers may delete or poison uploads as they make their way through a company’s network, it is important that companies have safeguards in place to make sure they are still able to access important documents even in the case that they need to shut down the network. 

Cyber security researcher Alex Vakulov explains that having a ‘3-2-1′ backup strategy can help ensure the safety of critical data: “[Using the 3-2-1 method] two copies are stored locally on the same site but on different media. The third copy is separated from the previous two, for example it is kept in the cloud. Accordingly, if something happens to the first storage, then the data still remains in another storage in the [on premises] data center. If access to the entire data center is lost, a backup copy remains in the cloud.” 

By using multiple backups, companies can mitigate the risk and impact of business email compromise, allowing them to continue to function while also being able to shut down the network to stop malicious actors from gaining further access to it and/or poisoning or stealing data. 

Increase endpoint security 

In today’s digital climate, the number of devices in use across an organization has risen exponentially, as most employees need access to multiple devices in order to do their jobs. When paired with the emergence of hybrid or completely remote working and the move away from a secured on-premises network, this means that businesses must be constantly vigilant about endpoint security. 

This need is already being recognized in the cyber security space, with Cyber Security Hub’s own research finding that 44 percent of cyber security professionals say their company is currently investing in endpoint security

As well as protecting the devices on its network, companies need to protect the network itself. To do this, companies should increase their detection and response capabilities. This need has similarly been recognized by businesses, with the same research finding more than two fifths (42 percent) of companies are investing in threat detection and response.  

Conclusion: combine a human-centric approach with key software investments 

An employee-centric approach to ransomware and BEC threat prevention allows all employees to understand the risk of these threats. By shifting a security strategy approach to understanding the human element of these attacks, companies can help prevent these attacks by stopping them before they infiltrate the network.  

Additionally, companies should identify the areas in which they can invest to better strengthen their ability to protect against and respond to cyber attacks, including endpoint security, cloud storage and backup facilities, and detection and response software. 

This means companies have a double-layered threat prevention approach and are not solely reliant on endpoints and other technology to stop ransomware after it is activated. 


[ad_2]
Source link

What is business email compromise?

0
[ad_1]

In this article, Cyber Security Hub explores how cyber attackers use threat vectors like phishing, social engineering and ransomware to enact business email compromise (BEC).

Cybercrime is an ever-growing issue across virtually every industry. Expected to have a global cost as much as US$10trn by 2025, companies must fight to combat malicious actors seeking to gain from cyber attacks against them.

Threat actors increasingly use multiple threat vectors during attacks to overwhelm companies and make it easier for them to gain access to their network. This is makes it more important than ever to safeguard the most common vehicle for an initial breach point – email.  

The majority of hacking groups (65 percent) utilize email-based spear phishing campaigns as their primary attack vector. This cyber attack method targets specific individuals within an organization with the goal of compromising their credentials and using their privileged access to gain further control of a business’ network or steal information that only certain employees have access too.

These campaigns can have a devastating impact, not least from a financial perspective; in May 2022, the US Federal Bureau of Investigation (FBI) reported that BEC had led to a total loss of $43.3bn between June 2016 and December 2021.

In this Cyber Security Hub article will highlight the key vulnerabilities for those without sufficient email security and explain how to block threat actors from carrying out successful attacks while mitigating data loss and fraud.

Read also: Prevent advanced ransomware attacks with good email security

Email security must not be ignored

As the ransomware-as-a-service (RaaS) economy matures, ransomware gangs are demonstrating supreme confidence in their debilitating actions.

In January of this year, the UK’s Royal Mail had to completely halt all dispatch of items overseas after it became the victim of an alleged LockBit ransomware attack. The ransomware caused “severe disruption” to the computerized systems used to send mail abroad and resulted in Royal Mail requesting that customers stop sending mail abroad in the wake of the ransomware attack.

Verizon also noted a 13 percent increase in ransomware breaches in 2022. As ransomware can be spread via BEC, this statistic is especially worrying.

During email-focused cyber attacks, malicious actors may target low-level data within the attack’s early phases. This low-level data can then be used to gain access to and steal more sensitive data. With Microsoft reporting that it takes hackers just 24-48 hours to gain control of a network via a privileged account, even the compromise of low-level accounts can be serious.

For example, a hacker could pose as a job seeker to target those in human resources (HR). Hackers rely on the fact that HR professionals are used to receiving and opening attachments from unknown senders to allow their ransomware to spread across a network. Additionally, if attackers do compromise HR emails, this gives them access to confidential and sensitive company information. 

Read also: The dangerous vulnerabilities caused by weak email security

Best practices for alert organizations

Understanding the human element

Comprehensive email security strategies like the use of strong passwords and email encryption can provide a higher level of protection against BEC. This, however, relies on employees following the rules and with 65 percent of people reusing passwords for multiple or all of their accounts and 73 percent of people using the same passwords for both work and personal accounts, this is easier said than done.

Likewise, research by the Harvard Business Review has found that 67 percent of employees admit that they fail to adhere to cyber security policies, with a failure-to-comply rate at an average of once every 20 tasks. In 85 percent of all cases where employees knowingly broke procedure they cited work-related reasons for doing so, including “to better accomplish tasks for my job”, “to get something I needed” and “to help others get their work done”.

So, companies must recognize that their cyber security policies need to both protect the company while also not preventing their employees from doing their jobs efficiently. Likewise, employees should be made aware of their role as those on the front line against email-based cyber attacks. Not doing so can cause employees to cut corners in the name of efficiency without understanding the ramifications, ultimately endangering the company. 

Read also: Top tips for cyber security training 

Introduce a robust backup strategy 

As cyber attackers may delete or poison uploads as they make their way through a company’s network, it is important that companies have safeguards in place to make sure they are still able to access important documents even in the case that they need to shut down the network. 

Cyber security researcher Alex Vakulov explains that having a ‘3-2-1′ backup strategy can help ensure the safety of critical data: “[Using the 3-2-1 method] two copies are stored locally on the same site but on different media. The third copy is separated from the previous two, for example it is kept in the cloud. Accordingly, if something happens to the first storage, then the data still remains in another storage in the [on premises] data center. If access to the entire data center is lost, a backup copy remains in the cloud.” 

By using multiple backups, companies can mitigate the risk and impact of business email compromise, allowing them to continue to function while also being able to shut down the network to stop malicious actors from gaining further access to it and/or poisoning or stealing data. 

Increase endpoint security 

In today’s digital climate, the number of devices in use across an organization has risen exponentially, as most employees need access to multiple devices in order to do their jobs. When paired with the emergence of hybrid or completely remote working and the move away from a secured on-premises network, this means that businesses must be constantly vigilant about endpoint security. 

This need is already being recognized in the cyber security space, with Cyber Security Hub’s own research finding that 44 percent of cyber security professionals say their company is currently investing in endpoint security

As well as protecting the devices on its network, companies need to protect the network itself. To do this, companies should increase their detection and response capabilities. This need has similarly been recognized by businesses, with the same research finding more than two fifths (42 percent) of companies are investing in threat detection and response.  

Conclusion: combine a human-centric approach with key software investments 

An employee-centric approach to ransomware and BEC threat prevention allows all employees to understand the risk of these threats. By shifting a security strategy approach to understanding the human element of these attacks, companies can help prevent these attacks by stopping them before they infiltrate the network.  

Additionally, companies should identify the areas in which they can invest to better strengthen their ability to protect against and respond to cyber attacks, including endpoint security, cloud storage and backup facilities, and detection and response software. 

This means companies have a double-layered threat prevention approach and are not solely reliant on endpoints and other technology to stop ransomware after it is activated. 


[ad_2]
Source link

Major Cybercrime Crackdown: Encrypted Messenger Exclu Seized

0
[ad_1]

So far, authorities have arrested 48 people in connection with Exclu, discovered two drug labs and a cocaine-processing facility, and confiscated $4.3 million, several kilograms of drugs, and luxury items.

European law-enforcement authorities have seized Exclu, an encrypted communication service that cybercriminals used as their primary channel to carry out organized crime, mainly trading drugs.

According to authorities, 48 people have been arrested so far in connection with the service and seizure of guns, drugs, and millions in cash. Reportedly, police raided 79 locations in the Netherlands, Germany, and Belgium on Friday. The arrested individuals were operators, administrators, and users of Exclu.

The investigation into the encrypted communication service, identified as Exclu Messenger Service, was started in September 2020. Their probe revealed that Exclu was offered as a smartphone app and came with a 6-month license, costing around 800 euros or $860. The service had 3,000 users, of which around 750 were based in the Netherlands.

“Exclu made it possible to exchange messages, photos, notes, voice memos, chat conversations, and videos with other users,” Dutch police revealed. The service was popular among criminals for its high level of security.

After starting their investigation into the Exclu secret communication service, authorities hacked the platform and accessed the messages passed between criminal gangs for five months before carrying out the raids.

Dutch, French, Italian, and Swedish police participated in this investigation, which was supervised by Eurojust and Europol. At least two drug labs, a cocaine-processing facility, four million euros (or $4.3 million), several kilograms of drugs, and luxury goods were confiscated from the suspects.

Exclu isn’t the only encrypted online chat platform shut down by law enforcement. Back in June 2020, encrypted communication provider EncroChat was forced to cease operations after suffering a malware attack.

In July 2020, however, authorities dismantled the entire infrastructure of EncroChat and arrested over 800 individuals, including some prominent crime figures, by using information acquired through EncroChat.

  1. Europol Busts Crypto Fraud Call Centers
  2. DoubleVPN’s servers used by ransomware seized
  3. 48 DDoS-hiring Sites Busted by FBI in Major Sweep
  4. iSpoof seized; UK’s largest bank call scam disrupted
  5. Online piracy hacker network Sparks Group dismantled

[ad_2]
Source link

Reddit Hacked After Employee Bites on Phishing Scam

0
[ad_1]

Reddit has become a victim of yet another data breach, in which threat actors have accessed the company’s internal documents, dashboards, business systems, and more.

On Thursday, Reddit confirmed that the platform had become a target of a sophisticated phishing attack on February 5th, 2023. The company revealed that the attackers targeted its employees by sending out plausible-sounding prompts via a website that looked exactly like Reddit’s intranet gateway. The objective of this attack was to steal credentials and second-factor tokens.

The incident should not come as a surprise, as companies such as Cisco, Twilio, GoDaddy, and others have suffered security breaches due to employees lacking cybersecurity knowledge.

According to Reddit, Several employees received malicious emails sent via a fake website. One of the employees entered their credentials into this cloned website, which allowed the attacker(s) to hack into Reddit. Reddit asserts that its primary production system wasn’t breached, where Reddit stores most of its data.

After the affected employee informed the Security team, the team learned about the attack, and Reddit then launched an investigation into the incident. The company responded to the incident by removing the invader’s access to its system.

“We’re continuing to closely investigate and monitor the situation and working with our employees to fortify our security skills. As we all know, the human is often the weakest part of the security chain.”

Reddit

Reddit CTO Christopher Slowe wrote that the attacker could access internal documents, dashboards, and business systems. Exposed data includes limited contact information of company contacts, which are currently in the hundreds, and current/former employees’ data. Reddit noted that limited advertiser info was also exposed.

The company, however, has assured Redditors that their data is secure and was not affected in this incident. “Based on our investigation so far, Reddit user passwords and accounts are safe,” the company’s spokesperson stated.

They further noted that after several days-long investigations by security, engineering, and data science (and friends), the company didn’t find any evidence that its customers’ non-public data was accessed or Reddit’s data was published/distributed online.

In a comment to Hackread.com, Sam Humphries, Head of Security Strategy, EMEA, Exabeam said that “This latest incident is yet another reminder that all it takes is one employee’s credentials to be stolen to open the door to an organisation’s internal systems.”

“Fortunately, in the case of Reddit, the targeted employee self-reported the incident to their security team, allowing for prompt investigation and response,” Sam added.

He further advised that “Organisations need to place as much (if not more) emphasis on detection as prevention. This will allow them to more efficiently and effectively identify malicious behaviour indicative of a compromised employee account and minimise data theft.”

Matt Aldridge, Principal Solutions Consultant at OpenText Cybersecurity, pointed out a crucial weakness: employees with no education on cybersecurity. “It’s also crucial to ensure staff are properly trained to identify threats,” Matt emphasised.

“There’s no use investing in sophisticated cybersecurity software and services if employees continue to click on dangerous phishing links that slip through the net, in turn granting cybercriminals access to the business network – It’s like turning on a fancy home security alarm, but leaving a window open – you’ll be left playing catch-up after the bad guys get in,” Matt added.

Nevertheless, Reddit recommends that users switch to two-factor authentication. Slowe also hosted an AMA to answer queries related to the incident and confirmed that the employee who had self-reported the incident wasn’t fired but had been shifted to stocks as a punishment.

  1. Hackers hit Reddit; deface 70+ Subreddits
  2. Game of Thrones Season 8 script pages leaked on Reddit
  3. Reddit hacked: Hackers steal copy of old database backup

[ad_2]
Source link

Geo Targetly URL Shortener Abused in Phishing Scam

0
[ad_1]

Geo Targetly is a legitimate online service that offers its own URL shortening service, similar to Bitly, called Geo Link.

Researchers at Check Point Software Company’s security firm, Avanan, have discovered a new wave of phishing attacks in which actors use the Geo Targetly product, Geo Link, to redirect users to malicious links.

What’s worse, following this modus operandi, scammers can launch targeted attacks according to the victim’s region and language through this service.

The latest Reddit hack teaches us one major lesson: Do not underestimate phishing attacks.

Hackread.com

For your information, Geo Targetly is a legitimate website that lets businesses and advertisers redirect users to ads or pages in their local markets. Its Geo Link service is essentially a URL shortener, according to the company, just like Bitly.

Threat actors use Geo Targeting to target potential victims at specific locations through phishing emails. This could be a massive blow to the cybersecurity fraternity, as exploitation of get targeting may be the ultimate game-changer for cybercriminals.

“In this attack, hackers redirect users via Geo Targetly … and provide them with customized, localized phishing pages,” Avanan researchers stated.

The said tool is used to display ads based on the user’s location. So, the ads viewed by someone in France would be different than those shown to someone in the US. Now, hackers can launch geo-specific phishing content and send malicious emails customized by region and language to their targets.

Email Content

One of the emails Avanan researchers analyzed was in Spanish and was sent to users in Colombia. It appears to be about a speeding subpoena. The email’s subject line translation is as follows:

“Subject: Notification of subpoena for excess of maximum speed allowed on urban roads of 60 km/h.”

The email contains a link. When the recipient clicks on “See Compared,” they are redirected to the Geo Targetly page. Since the user is in Colombia, the email will redirect them to a Colombian page.

Phishing email screenshot provided by Avanan

But that’s not the exciting part. The customization that hackers perform to attack their targets according to their location is the exciting part. With this trick, they can target multiple users in different parts of the world simultaneously.

By exploiting Geo Targetly, attackers can create phishing URLs that redirect users in certain regions to inauthentic login pages that appear legitimate. Due to this personalization, victims will be trapped and click on the link. This technique is based on the “spray-and-pray” method, in which thousands of phishing emails are sent at once.

How to Stay Protected?

Researchers recommend users check the URLs included in their emails and browsers before clicking on them. Avanan’s cybersecurity researcher Jeremy Fuchs stated that this is a widespread attack campaign.

Since there is no security flaw in Geo Targetly that threat actors have exploited, the only line of defence is staying vigilant. Geo Targetly has confirmed that hackers used its service to target users.

The company removed Geo Link from its free trial, considerably reducing its exploitation in phishing campaigns. Geo Targetly has also limited the creation of new accounts unless the user shares their legitimate company email account and domain.

  1. SMS Phishing scam Dupes Zendesk Staff
  2. Phishing Attacks Using Unicode Characters
  3. Zoom Phishing Scam Steals MS Exchange Data
  4. Gmail Phishing Scam Stole Data Using Attachment
  5. Phishing: Microsoft & PayPal, most targeted brands

[ad_2]
Source link

ChatGPT may lead to lower wages: economist famously predicted

0
[ad_1]

In 2013, Oxford University economists Carl Benedikt Frey and Michael Osborne predicted that nearly half of all jobs in the US (47%) were under threat from computerization or automation in a decade or two. In other words, they suggested that AI (artificial intelligence) would reduce manpower in many industries.

Fast forward to today, i. e. a decade later, automation is part of almost every industry, while AI-powered services like ChatGPT are threatening to eat up many jobs. Frey has now opined that ChatGPT and the like could lead to lower wages even if workers manage to cling to their jobs.

ChatGPT could create more competition, leading to lower wages

According to Frey, computers still haven’t replaced half of the manpower in the US. However, the trend is there. And, the arrival of ChatGPT may have just fueled it. He said automation will create more competition in various industries, driving wages down. Frey pointed to the steadily falling income of prime-age men to explain how AI is affecting employment. “I think there’s a risk that ChatGPT makes us a lot more productive in easy-to-do stuff, but the hard part to figure out is how we can use AI to create innovation that then creates new occupations and new industries,” he told Fortune.

In a separate interview with Business Insider, Frey likened ChatGPT ‘s AI revolution to Uber disrupting the taxi market. He said the arrival of Uber and the like resulted in more taxis on the streets. But it also led to more competition, thus effecting a wage cut of around ten percent for drivers.

“Uber didn’t reduce the demand for taxi drivers,” Frey said. “It, if anything, increased the number of people driving cars for a living, but it reduced the amount the earnings capacity of incumbent drivers”. He suggests ChatGPT will similarly impact creative industries like writing, music, art, graphic design, and even computer programming.

AI could help improve employment in many areas

While AI may replace some jobs, it could also help improve employment in some areas. Perhaps emerging technologies will transform many jobs rather than outright replace those. Some roles will evolve and require a new set of knowledge and skill.

As such, people who lack the required skills for this transformation might end up losing their jobs, but they will be replaced by another human. “I think there’s this somewhat misguided distinction between replacement and jobs being changed and transformed by technology,” Frey said.

He added that technological advancements, such as ChatGPT, are good for society. “It’s the reason that we’re a lot more prosperous today than a couple of hundred years ago,” the economist said.

The conversational AI chatbot created by Microsoft-backed OpenAI has raked in over 100 million users in just two months. Many tech biggies are rushing to introduce their own ChatGPT alternatives, including Google which recently launched Bard. It remains to be seen how these services impact employment in the coming years.


[ad_2]
Source link

Everything you need to know

0
[ad_1]

The term “broke the internet” is tossed around a lot, but there are few things that actually break the internet. One of these things is ChatGPT. This is an extremely powerful AI (Artificial Intelligence) chatbot that put a lot of big companies at attention. So, what is this technology and what does it mean for the future of AI? Here’s everything you need to know about ChatGPT.

What is ChatGPT?

The concept of ChatGPT isn’t new. It’s a chatbot- a piece of software that simulates a human conversation. You’re able to send messages to it and get responses as though you’re talking to a human being. There’s a certain humanization factor to it that we’re seeing with voice assistants such as Amazon Alexa and Google Assistant.

ChatGPT is much the same thing, and it’s been making waves since November 2022. It has a simple interface with a text field on the bottom. You’re able to type in whatever query you want and get a prompt response.

What can you do with ChatGPT?

That is the million-dollar question because it’s what this chatbot can do that is making companies like Google quake in their boots. Some say that ChatGPT does a lot, and others will argue that it does too much. The responses that ChatGPT delivers range from conversational to informative.

Basic knowledge

This is, perhaps, the biggest threat to Google. We’re all used to turning to Google to find results for just about anything. Baby care tips, local restaurants, information on quantum mechanics, etc. Well, ChatGPT does the same thing, but it cuts out the middleman. If you search for the best way to swaddle a baby on Google, you’ll get about 31,400,000 results. Those results will involve ads, contradictory results, and downright wrong information.

However, if you ask ChatGPT, it will just tell you how to- plain and simple. You won’t have to wade through an endless pool of results. If you type in “How to swaddle a baby” in ChatGPT right now, you’ll get a clear and concise list of five steps.

You’ll also be able to ask it factual questions. You can ask questions like “When was Jupiter discovered?”, “Who was Muzio Clementi?”, or “How much energy does it take for an electron to jump from the lowest energy level in a carbon atom?”. ChatGPT will give you a clear to-the-point answer with additional context.

Advice

This is an area where ChatCPT stands out. As stated before, you’re getting a direct response, not a wall of search results. This means that getting advice is a lot easier. Typing in something like “I need advice on what to teach my kid”. Again, you’ll get a direct list of items to keep in mind. If you type this in Google, you’ll see a highlight from an article along with other search results.

What might make ChatGPT’s implementation more tempting is the mentality about it. If you want advice on parenting, who would you rather ask, your mother/father or a group of 50 parents who are likely to have contradicting advice? Getting one answer from one source will likely make people feel more confident about the results rather than a slew of results that won’t agree with one another.

What also makes ChatGPT tempting is the conversational aspect. If you don’t like the results, you can say (type) so, and the chatbot will alter its results based on that. You can’t really do that with Google.

For example, “I want advice on buying a new pet” was entered, and we got this result:

ChatGPT Pet 1

This result gives you a list of things you should consider when buying a pet, but if you have an additional question, then you can inquire further. Below is the rest of the conversation.

So, you can see how you’re able to have a conversation with the bot to get further information.

Conversation/support

This might be one of the oddest aspects of this chatbot, but you can have idle chit-chat with it. You can start a conversation about pretty much anything.

We were able to hold a conversation about going out with a friend and wanting to pay her back for treating us to lunch. ChatGPT remained consistent and even offered advice on the way. There was another extended conversation centering around the loss of a pet. It offered condolences and gave advice on coping. If you’re in need of conversation, ChatGPT could actually hold a conversation.

Producing written content

Now, let’s get down to the juicy stuff. You can ask ChatGPT to write you several forms of written content. This includes full news articles, product reviews, poems, stories, scripts, and much MUCH more.

For example, we asked it to write a 2000-word review of the HTC 10, and it delivered- albeit extremely dryly. We also had it write a story about a mean boy who gets hit just deserts.

Other examples include a poem about the night, a plot synopsis of Toy Story, a script about a couple just getting home from the store, and more. Each time, we were able to offer changes, and ChatGPT made them.

Writing code

One of the smash-hit features of this chatbot is the ability for it to write actual code. You just need to ask it to write code for the action you want the program to perform. We asked for code for an app that can tell time, and it gave us some python examples to add to the app.

ChatGPT code

What can’t ChatGPT do?

While ChatGPT can write code, it can not write an entire program. Also, it can’t give you advice on certain sensitive subjects. These could involve subjects like sex, pregnancy, murder, violence, etc.

Obviously, while this chatbot can produce original content, just know that it will be rather clinical. Sure, that’s great for looking up advice, encyclopedia knowledge, recipes, etc., but anything like articles or reviews won’t show any personality. The HTC review read like a press release with even LESS personality.

How much does ChatGPT cost?

There are two ways to use ChatGPT. You can use the core functionality for free. This means that you can ask it questions until your heart’s content. The company doesn’t put a limit on how many inquiries you can put in.

In fact, OpenAI thrives off of this input. However, there are a few limitations. At times in the day when a ton of people are using it, you won’t have access to the service. You’ll need to wait until traffic goes down.

However, there is a paid tier that costs $20/month. With this, you’ll have access to it regardless of the traffic. Also, it will process your results more quickly. Last but not least, you’ll have early access to new features with the paid tier.

Do I need an account to use it?

Yes. In order to use the service, you’ll need to sign in. You can either set up an OpenAI account or sign in with either your Google or Microsoft account.

Is using ChatGPT content illegal?

At this point (early 2023) there are no laws or regulations stating that you’re not allowed to use the AI-generated content that ChatGPT makes. While there are obvious moral roadblocks, you can use your generated articles or stories and publish them.

You’ll just need to take into account the rules and regulations of the specific publication companies that you’re submitting to. They have the final word.

What should I be worried about with ChatGPT?

As of the writing of this, ChatGPT’s knowledge stops at 2021. So, there’s a lot of information that it doesn’t know from modern events. This means that you run the risk of getting out-of-date or inaccurate information.

Also, despite how advanced ChatGPT is, it’s still not human. This means that it could accidentally give results that are heavily offensive. They could, unintentionally, be biased or hurtful. This technology is still being developed, so you’ll want to keep that in mind.

Try out ChatGPT


[ad_2]
Source link

Apple Q1 2023 Results: $30.0B Profit, But Still a Miss

0
[ad_1]
Apple has announced its financial results for Q1 2023 (Q4 2022 calendar quarter). The Cupertino giant generated $117.2 billion in revenue and a net quarterly profit of $30.0 billion. This is a slight decrease compared to the same quarter of last year, where they posted revenue of $123.9 billion and a net quarterly profit of […]
[ad_2]
Source link

Samsung updates Galaxy S10 Lite to February security patch

0
[ad_1]

Samsung has begun rolling out the February 2023 Android security patch to the Galaxy S10 Lite. The device is currently picking up the latest security update in Europe. A wider rollout should follow in the coming days. The handset received the January SMR (Security Maintenance Release) in the US just a few days back. So users stateside may have to wait a few weeks to get the new security release.

The February SMR for the Galaxy S10 Lite comes with the firmware build number G770FXXS6HWB1 in Europe. As of this writing, the update is only available to users in Spain. But it should just be a matter of time before it reaches other European countries. Samsung should also expand the rollout to more regions over the next few days. We will let you know when it arrives in the US.

In the meantime, you can go to the Software update menu in Settings and tap on Download and install to check for updates manually. If an update is available, you will be prompted to download it. If you don’t see any pending updates, wait a few days and check again. You may also get a notification when the OTA (over the air) release becomes available for your Galaxy S10 Lite unit.

This update doesn’t bring anything notable. There aren’t any new features or improvements here. Samsung is only pushing the latest vulnerability fixes to the Galaxy S10 Lite. There are plenty of those, though. The February SMR patches more than 50 vulnerabilities, including seven Galaxy-specific ones. The Korean firm patched issues with Secure Folder, Contacts, Phone, Fingerprint TA, and more system apps.

The remaining vulnerability patches found in the February SMR are part of Google’s latest ASB (Android Security Bulletin). These are issues found in Android OS and other partner components. The Android maker labeled five patches as “critical” this month. Some of those could lead to remote code execution. The remaining patches were all labeled “high-severity” by Google.

Galaxy S10 Lite may not get Samsung’s One UI 5.1 update

Samsung launched the Galaxy S10 Lite in early 2020, just a month before the Galaxy S20 series. Both devices arrived with Android 10 out of the box and received updates to Android 11, Android 12, and Android 13. While neither is eligible for Android 14, the Korean firm has confirmed that the latter will get One UI 5.1, which debuted with the Galaxy S23 series last week. The Galaxy S10 Lite appears to be missing out on it. We will let you know when Samsung starts rolling out the One UI 5.1 update to older Galaxy devices.


[ad_2]
Source link