FreshRSS

🔒
☐ ☆ ✇ The Hacker News

Malvertising Campaign Targets Brazil's PIX Payment System with GoPIX Malware

By Newsroom — October 25th 2023 at 09:13
The popularity of Brazil's PIX instant payment system has made it a lucrative target for threat actors looking to generate illicit profits using a new malware called GoPIX. Kaspersky, which has been tracking the active campaign since December 2022, said the attacks are pulled off using malicious ads that are served when potential victims search for "WhatsApp web" on search engines. "The
☐ ☆ ✇ The Hacker News

1Password Detects Suspicious Activity Following Okta Support Breach

By Newsroom — October 24th 2023 at 04:55
Popular password management solution 1Password said it detected suspicious activity on its Okta instance on September 29 following the support system breach, but reiterated that no user data was accessed. "We immediately terminated the activity, investigated, and found no compromise of user data or other sensitive systems, either employee-facing or user-facing," Pedro Canahuati, 1Password CTO, 
☐ ☆ ✇ WIRED

The Hamas Threat of Hostage Execution Videos Looms Large Over Social Media

By David Gilbert — October 23rd 2023 at 21:02
Hamas has threatened to broadcast videos of hostage executions. With the war between Israel and Hamas poised to enter a new phase, are social platforms ready?
☐ ☆ ✇ WIRED

Who’s Responsible for the Gaza Hospital Explosion? Here’s Why It’s Hard to Know What’s Real

By David Gilbert — October 18th 2023 at 21:27
A flood of false information, partisan narratives, and weaponized “fact-checking" has obscured efforts to find out who’s responsible for an explosion at a hospital in Gaza.
☐ ☆ ✇ WIRED

Elon Musk’s Main Tool for Fighting Disinformation on X Is Making the Problem Worse, Insiders Claim

By Vittoria Elliott, David Gilbert — October 17th 2023 at 22:20
X is promoting Community Notes to solve its disinformation problems, but some former employees and people who currently contribute notes say it’s not fit for that purpose.
☐ ☆ ✇ WIRED

A Graphic Hamas Video Donald Trump Jr. Shared on X Is Actually Real, Research Confirms

By David Gilbert — October 11th 2023 at 19:39
A video posted by Donald Trump Jr. showing Hamas militants attacking Israelis was falsely flagged in a Community Note as being years old, thus making X's disinformation problem worse, not better.
☐ ☆ ✇ WIRED

Elon Musk Is Personally Undermining X’s Efforts to Curb Israel-Hamas War Disinformation

By David Gilbert — October 10th 2023 at 15:19
X’s Trust and Safety team says it’s working to remove false information related to the Israel-Hamas war. Meanwhile, Elon Musk is sharing conspiracies and chatting with QAnon promoters.
☐ ☆ ✇ WIRED

The Israel-Hamas War Is Drowning X in Disinformation

By David Gilbert — October 9th 2023 at 15:53
People who have turned to X for breaking news about the Israel-Hamas conflict are being hit with old videos, fake photos, and video game footage at a level researchers have never seen.
☐ ☆ ✇ The Hacker News

Retool Falls Victim to SMS-Based Phishing Attack Affecting 27 Cloud Clients

By THN — September 18th 2023 at 07:00
Software development company Retool has disclosed that the accounts of 27 of its cloud customers were compromised following a targeted and SMS-based social engineering attack. The San Francisco-based firm blamed a Google Account cloud synchronization feature recently introduced in April 2023 for making the breach worse, calling it a "dark pattern." "The fact that Google Authenticator syncs to
☐ ☆ ✇ The Hacker News

Okta Warns of Social Engineering Attacks Targeting Super Administrator Privileges

By THN — September 2nd 2023 at 04:12
Identity services provider Okta on Friday warned of social engineering attacks orchestrated by threat actors to obtain elevated administrator permissions. “In recent weeks, multiple U.S.-based Okta customers have reported a consistent pattern of social engineering attacks against IT service desk personnel, in which the caller’s strategy was to convince service desk personnel to reset all
☐ ☆ ✇ WIRED

How X Is Suing Its Way Out of Accountability

By Vittoria Elliott — August 15th 2023 at 11:00
The social media giant filed a lawsuit against a nonprofit that researches hate speech online. It’s the latest effort to cut off the data needed to expose online platforms’ failings.
☐ ☆ ✇ The Hacker News

Microsoft Exposes Russian Hackers' Sneaky Phishing Tactics via Microsoft Teams Chats

By THN — August 3rd 2023 at 06:38
Microsoft on Wednesday disclosed that it identified a set of highly targeted social engineering attacks mounted by a Russian nation-state threat actor using credential theft phishing lures sent as Microsoft Teams chats. The tech giant attributed the attacks to a group it tracks as Midnight Blizzard (previously Nobelium). It's also called APT29, BlueBravo, Cozy Bear, Iron Hemlock, and The Dukes.
☐ ☆ ✇ WIRED

How Threads' Privacy Policy Compares to Twitter's (and Its Rivals')

By Reece Rogers — July 6th 2023 at 23:46
Want to try out Meta’s new social media app? Here’s more context on what personal data is collected by Threads and similar social media apps.
☐ ☆ ✇ WIRED

Don't Join Threads—Make Instagram's 'Twitter Killer' Join You

By Lily Hay Newman — July 6th 2023 at 18:53
Meta’s Twitter alternative promises that it will work with decentralized platforms, giving you greater control of your data. You can hold the company to that—if you don't sign up.
☐ ☆ ✇ The Hacker News

Cybercrime Group 'Muddled Libra' Targets BPO Sector with Advanced Social Engineering

By Ravie Lakshmanan — June 23rd 2023 at 14:44
A threat actor known as Muddled Libra is targeting the business process outsourcing (BPO) industry with persistent attacks that leverage advanced social engineering ploys to gain initial access. "The attack style defining Muddled Libra appeared on the cybersecurity radar in late 2022 with the release of the 0ktapus phishing kit, which offered a prebuilt hosting framework and bundled templates,"
☐ ☆ ✇ The Hacker News

Kimsuky Targets Think Tanks and News Media with Social Engineering Attacks

By Ravie Lakshmanan — June 8th 2023 at 04:23
The North Korean nation-state threat actor known as Kimsuky has been linked to a social engineering campaign targeting experts in North Korean affairs with the goal of stealing Google credentials and delivering reconnaissance malware. "Further, Kimsuky's objective extends to the theft of subscription credentials from NK News," cybersecurity firm SentinelOne said in a report shared with The
☐ ☆ ✇ WIRED

Inside 4chan’s Top-Secret Moderation Machine

By Justin Ling — June 5th 2023 at 10:00
Internal company documents reveal how the imageboard’s chaotic moderation allowed racism and violence to take over.
☐ ☆ ✇ WeLiveSecurity

5 free OSINT tools for social media

By Martina López — May 31st 2023 at 09:30

A roundup of some of the handiest tools for the collection and analysis of publicly available data from Twitter, Facebook and other social media platforms

The post 5 free OSINT tools for social media appeared first on WeLiveSecurity

☐ ☆ ✇ WIRED

Meta’s $1.3 Billion Fine Is a Strike Against Surveillance Capitalism

By Matt Burgess — May 22nd 2023 at 14:38
The record-breaking GDPR penalty for data transfers to the US could upend Meta's business and spur regulators to finalize a new data-sharing agreement.
☐ ☆ ✇ WIRED

Buffalo Mass Shooting Victims' Families Sue Meta, Reddit, Amazon

By Justin Ling — May 15th 2023 at 20:14
The families of victims of a mass shooting in Buffalo are challenging the platforms they believe led the attacker to carry out a racist massacre.
☐ ☆ ✇ WIRED

Twitter’s Encrypted DMs Are Deeply Inferior to Signal and WhatsApp

By Andy Greenberg — May 11th 2023 at 04:11
The social network’s new privacy feature is technically flawed, opt-in, and limited in its functionality. All this for just $8 a month.
☐ ☆ ✇ WeLiveSecurity

Using Discord? Don’t play down its privacy and security risks

By Márk Szabó — May 3rd 2023 at 09:30

It’s all fun and games until someone gets hacked – here’s what to know about, and how to avoid, threats lurking on the social media juggernaut

The post Using Discord? Don’t play down its privacy and security risks appeared first on WeLiveSecurity

☐ ☆ ✇ WIRED

A US Bill Would Ban Kids Under 13 From Joining Social Media

By Matt Laslo — April 26th 2023 at 19:28
The legislation would insert the government into online platforms’ age-verification efforts—a move that makes some US lawmakers queasy.
☐ ☆ ✇ WIRED

Montana’s Looming TikTok Ban Is a Dangerous Tipping Point

By Lily Hay Newman — April 15th 2023 at 00:28
The state is poised to be the first in the US to block downloads of the popular app, which could ignite a precarious chain reaction for digital rights.
☐ ☆ ✇ WIRED

LinkedIn Verification Now Lets You Verify Your Job and Account

By Lily Hay Newman — April 12th 2023 at 14:23
To beat back fake accounts, the professional social network is rolling out new tools to prove you work where you say you do and are who you say you are.
☐ ☆ ✇ WeLiveSecurity

Cleaning up your social media and passwords: What to trash and what to treasure

By Thomas Uhlemann — April 6th 2023 at 09:30

Give your social media presence a good spring scrubbing, audit your passwords and other easy ways to bring order to your digital chaos

The post Cleaning up your social media and passwords: What to trash and what to treasure appeared first on WeLiveSecurity

☐ ☆ ✇ WIRED

How Good Smile, a Major Toy Company, Kept 4chan Online

By Justin Ling — March 29th 2023 at 14:26
Documents obtained by WIRED confirm that Good Smile, which licenses toy production for Disney, was an investor in the controversial image board.
☐ ☆ ✇ WeLiveSecurity

Staying safe on OnlyFans: The naked truth

By Jake Moore — March 28th 2023 at 09:30

How content creators and subscribers can embrace the social media platform without (overly) exposing themselves to the potentially toxic brew of NSFW content and privacy threats

The post Staying safe on OnlyFans: The naked truth appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

What TikTok knows about you – and what you should know about TikTok

By Roman Cuprik — March 24th 2023 at 10:30

As TikTok CEO attempts to placate U.S. lawmakers, it’s time for us all to think about the wealth of personal information that TikTok and other social media giants collect about us

The post What TikTok knows about you – and what you should know about TikTok appeared first on WeLiveSecurity

☐ ☆ ✇ WIRED

The TikTok Hearing Revealed That Congress Is the Problem

By Dell Cameron — March 24th 2023 at 00:42
The interrogation of CEO Shou Zi Chew highlighted US lawmakers’ own failure to pass privacy legislation.
☐ ☆ ✇ WIRED

TikTok Paid for Influencers to Attend the Pro-TikTok Rally in DC

By Matt Laslo — March 23rd 2023 at 21:50
The embattled social media company brought out the checkbook to ensure at least 30 of its biggest assets—creators—were in DC to help fend off critics.
☐ ☆ ✇ WIRED

The TikTok CEO’s Face-Off With Congress Is Doomed

By Matt Laslo — March 22nd 2023 at 11:00
On Thursday, Shou Zi Chew will meet a rare united front in the US Congress against the Chinese-owned social media app that has lawmakers in a tizzy.
☐ ☆ ✇ WeLiveSecurity

Twitter ends free SMS 2FA: Here’s how you can protect your account now

By Roman Cuprik — March 20th 2023 at 16:30

Twitter’s ditching of free text-message authentication doesn’t mean that you should forgo using 2FA. Instead, switch to another – and, indeed, better – 2FA option.

The post Twitter ends free SMS 2FA: Here’s how you can protect your account now appeared first on WeLiveSecurity

☐ ☆ ✇ WIRED

Senator Warner on the Restrict Act and a US TikTok Ban

By Dell Cameron — March 16th 2023 at 16:59
WIRED spoke with the coauthor of the Restrict Act, a bipartisan bill to crack down on tech from six “hostile” countries.
☐ ☆ ✇ WIRED

The Push to Ban TikTok in the US Isn’t About Privacy

By Matt Laslo — February 23rd 2023 at 12:00
Lawmakers are increasingly hellbent on punishing the popular social network while efforts to pass a broader privacy law have dwindled.
☐ ☆ ✇ The Hacker News

New S1deload Malware Hijacking Users' Social Media Accounts and Mining Cryptocurrency

By Ravie Lakshmanan — February 23rd 2023 at 10:45
An active malware campaign has set its sights on Facebook and YouTube users by leveraging a new information stealer to hijack the accounts and abuse the systems' resources to mine cryptocurrency. Bitdefender is calling the malware S1deload Stealer for its use of DLL side-loading techniques to get past security defenses and execute its malicious components. "Once infected, S1deload Stealer steals
☐ ☆ ✇ Naked Security

Coinbase breached by social engineers, employee data stolen

By Paul Ducklin — February 21st 2023 at 17:58
Another day, another "sophisticated" attack. This time, the company has handily included some useful advice along with its mea culpa...

☐ ☆ ✇ The Hacker News

Coinbase Employee Falls for SMS Scam in Cyber Attack, Limited Data Exposed

By Ravie Lakshmanan — February 21st 2023 at 10:13
Popular cryptocurrency exchange platform Coinbase disclosed that it experienced a cybersecurity attack that targeted its employees. The company said its "cyber controls prevented the attacker from gaining direct system access and prevented any loss of funds or compromise of customer information." The incident, which took place on February 5, 2023, resulted in the exposure of a "limited amount of
☐ ☆ ✇ The Hacker News

Hackers Abused Microsoft's "Verified Publisher" OAuth Apps to Breach Corporate Email Accounts

By Ravie Lakshmanan — February 1st 2023 at 05:30
Microsoft on Tuesday said it took steps to disable fake Microsoft Partner Network (MPN) accounts that were used for creating malicious OAuth applications as part of a phishing campaign designed to breach organizations' cloud environments and steal email. "The applications created by these fraudulent actors were then used in a consent phishing campaign, which tricked users into granting
❌