A week in security (April 02 – April 08)

A week in security (December 17 – 23)

Last week on Labs we looked at Fuchsia OS as a possible alternative for Android, explained all the reasons why cybercriminals want to hack your phone, discussed a flaw in Twitter form that may have been abused by nation states, gave you a Christmas tech scams roundup, revealed why many online quizzes qualify as phishing scams, gave some tips about safely using those smart speakers you got for Christmas, pointed out that the Underminer exploit kit improved its latest iteration, and reminded everyone that Chromebooks can and do get infected.

Other cybersecurity news

  • PewDiePie hackers strike again: hackers claimed that they launched yet another attack tricking hundreds of thousands of printers globally to print pamphlets promoting YouTube celebrity “PewDiePie.” (Source: ThreatPost)
  • Equifax breach was entirely preventable: the Republican majority staff of the U.S. House of Representatives Committee on Oversight and Government Reform says the hack attack and subsequent data breach suffered by credit reporting agency Equifax in 2017 “was entirely preventable.” (Source: BankInfoSecurity)
  • Top 100 worst passwords of 2018: after evaluating more than 5 million passwords leaked on the Internet, SplashData found that computer users continue using the same predictable, easily guessable passwords. (Source: TeamsID)
  • Twitter memes to deliver malware commands: attackers developed a way to use memes posted to Twitter to control RAT-infected computers. The operators use steganography to hide the instructions in images, which the malware then parses and executes. (Source: TechSpot)
  • Cloudflare providing DDoS protection for terrorist websites: Cloudflare is facing accusations that it’s providing cybersecurity protection for at least seven terrorist organizations—a situation that some legal experts say could put it in legal jeopardy. (Source: Gizmodo)
  • Government user credentials found on Dark Web: researchers from Group-IB have discovered more than 40,000 user accounts on the Dark Web that appear to be compromised credentials for online government websites in 30 countries. (Source: SecurityWeek)
  • Remote firmware attack renders servers unbootable: security researchers have found a way to corrupt the firmware of a critical component usually found in servers to turn the systems into an unbootable hardware assembly. (Source: BleepingComputer)
  • How hackers bypass Gmail 2FA: a new Amnesty International report goes into some of the technical details around how hackers can automatically phish two-factor authentication tokens sent to phones. (Source: Motherboard)
  • Pile of EU diplomatic cables nicked: the New York Times has published what it says are excerpts from hacked EU diplomatic cables obtained after discovering passwords that let them into a low-level EU database of diplomatic messages and cables. (Source: The Register)

Stay safe, everyone!