CyberSecurity Updates

Incident Of The Week: Checkers Restaurants Details Data Breach

Checkers Drive-In Restaurants Inc. notified its customers that about 15% of its restaurants in 20 states may have had data exposures possibly starting back into 2015, and some lasting until about mid-April this year. The company operates and franchises nearly 900 restaurants. See Related: “Cyber Attack Takes Weather Channel Offline” The data security issue included nine locations in the Tampa area (where the parent company is based) and two in the Orlando area, where payment…

Read More

Iran’s Nuclear Agency Says Email Server Hacked

Iran’s Atomic Energy Organisation said Sunday an email server of its subsidiary was hacked in a “foreign” attack aimed at drawing “attention” amid protests over the death of Mahsa Amini. The Islamic republic has been gripped by weeks-long demonstrations sparked by the death of 22-year-old Amini on September 16 after her arrest for allegedly violating the country’s strict dress code for women. The street violence has led to dozens of deaths, mostly among protesters but…

Read More

Steam account hacked? Here’s how to get it back

What are the warning signs that someone has hijacked your Steam account? Here is what to look for and what you can do to get your account back. The videogaming industry doesn’t stop growing. In fact, it is estimated to reach a market value of $197 billon by the end of 2022 and surpass $250 billon by 2025. This, together with its irresistible allure for ever younger and younger gamers, has contributed to an increase in scams…

Read More

POLONIUM targets Israel with Creepy malware

ESET researchers analyzed previously undocumented custom backdoors and cyberespionage tools deployed in Israel by the POLONIUM APT group ESET researchers reveal their findings about POLONIUM, an advanced persistent threat (APT) group about which little information is publicly available and its initial compromise vector is unknown. POLONIUM is a cyberespionage group first documented by Microsoft Threat Intelligence Center (MSTIC) in June 2022. MSTIC’s assessment is that POLONIUM is an operational group based in Lebanon, coordinating its…

Read More

10 common Zelle scams – and how to avoid them

Fraudsters use various tactics to separate people from their hard-earned cash on Zelle. Here’s how to keep your money safe while using the popular P2P payment service. The consumer payments space has undergone a radical shift in recent years. A new breed of apps, including Venmo, Cash App and Zelle, now offer a fast, effective and free way for users to pay friends, family and selected small businesses. Launched in 2017 by a US banking…

Read More

Patch Tuesday in brief – one 0-day fixed, but no patches for Exchange!

by Paul Ducklin Two weeks ago we reported on two zero-days in Microsoft Exchange that had been reported to Microsoft three weeks before that by a Vietnamese company that claimed to have stumbled across the bugs on an incident response engagement on a customer’s network. (You may need to read that twice.) As you probably recall, the bugs are reminiscent of last year’s ProxyLogin/ProxyShell security problems in Windows, although this time an authenticated connection is…

Read More

S3 Ep104: Should hospital ransomware attackers be locked up for life? [Audio + Text]

by Paul Ducklin THREE DEEP QUESTIONS Should hospital ransomware attackers get life in prison? Who was the Countess of Computer Science, and just how close did we come to digital music in the 19th century? And could a weirdly wacky email brick your iPhone? With Doug Aamoth and Paul Ducklin. Intro and outro music by Edith Mudge. Click-and-drag on the soundwaves below to skip to any point. You can also listen directly on Soundcloud. You…

Read More

Serious Security: Microsoft Office 365 attacked over feeble encryption

by Paul Ducklin We’re not quite sure what to call it right now, so we referred to it in the headline by the hybrid name Microsoft Office 365. (The name “Office” as the collective noun for Microsoft’s word processing, spreadsheet, presentation and collaboration apps is being killed off over the next month or two, to become simply “Microsoft 365”.) We’re sure that people will keep on using the individual app names (Word, Excel, PowerPoint and…

Read More

Incident Of The Week: Malware Infects 25M Android Phones

Cyber security researcher Check Point has warned Android users in a blog on July 10, 2019, that as many as 25 million Android mobile devices have been hit with a malware now being called ‘Agent Smith.’ The malware hides within installed apps like WhatsApp, taking advantage of the vulnerabilities within the Android operating system. See Related: “Securing The Enterprise From Mobile Malware” According to Check Point, this new breed of malware was able to copy…

Read More

Incident Of The Week: Russell Stover's Chocolates Latest To Disclose Retail Poin…

Another week and another data breach from retail point-of-sale (POS) transaction machines. This time, retail store customers of Russell Stover’s Chocolates who used a payment card between February 9 and August 7 of this year could have had their payment card information captured by machines that were infected by malware. The company disclosed the breach this week after notifying authorities and launching its own investigation into the threat. Organization: Russell Stover Chocolates Timeframe of Breach:…

Read More