Posts

KnowBe4 - Gone Phishing: Employer Faces Liability for Mistakenly Disclosing W-2 Forms to Scammer

Image
Attorneys Zuckerman Spaeder noted on JDSUPRA: "When employers are caught off guard, they can face not only the loss of their own assets, but also liability to their employees . For example, in a recent case,  Curry v. Schletter Inc. , No. 1:17-cv-0001-MR-DLH (W.D.N.C. Mar. 26, 2018), a federal district court permitted employees to proceed with their claims that their employer violated various duties when it was victimized by a phishing scam. In Curry, the employer mistakenly sent the employees’ W-2 forms to an unauthorized third party who pretended to be an executive at the company. The employer told its employees what had happened, and offered identity theft protection and credit monitoring in an effort to regain employee trust. But a number of the employees weren’t satisfied and sued the company . from KnowBe4 Security Awareness Training Blog https://blog.knowbe4.com/gone-phishing-employer-faces-liability-for-mistakenly-disclosing-w-2-forms-to-scammer

Schneier - Security Vulnerabilities in VingCard Electronic Locks

Researchers have disclosed a massive vulnerability in the VingCard eletronic lock system, used in hotel rooms around the world: With a $300 Proxmark RFID card reading and writing tool, any expired keycard pulled from the trash of a target hotel, and a set of cryptographic tricks developed over close to 15 years of on-and-off analysis of the codes Vingcard electronically writes to its keycards, they found a method to vastly narrow down a hotel's possible master key code. They can use that handheld Proxmark device to cycle through all the remaining possible codes on any lock at the hotel, identify the correct one in about 20 tries, and then write that master code to a card that gives the hacker free reign to roam any room in the building. The whole process takes about a minute. [...] The two researchers say that their attack works only on Vingcard's previous-generation Vision locks, not the company's newer Visionline product. But they estimate that it nonetheless affect...

KnowBe4 - Scam Of The Week: World's Largest Phishing Botnet Grows Evasive

Image
The notorious Necurs botnet is one of the oldest and largest spam and phishing delivery systems in existence. It controls millions of machines that the criminal botmasters use to send malicious payloads. Necurs has now adopted a retro trick to make itself more evasive and less likely to have its phishing intercepted by your filters. from KnowBe4 Security Awareness Training Blog https://blog.knowbe4.com/scam-of-the-week-worlds-largest-phishing-botnet-grows-evasive

SANS - Issue #33 - Volume XX - SANS Newsbites - April 27th, 2018

from SANS Institute | Newsletters - Newsbites - RSS https://www.sans.org/newsletters/newsbites/xx/33

KnowBe4 - PDF Files Can Be Abused to Steal Windows Credentials

Image
PDF files can be weaponized by malicious  actors to steal Windows credentials (NTLM hashes) without any user interaction, and only by opening a file, according to Assaf Baharav , a security researcher with cyber-security Check Point. from KnowBe4 Security Awareness Training Blog https://blog.knowbe4.com/pdf-files-can-be-abused-to-steal-windows-credentials

Schneier - Friday Squid Blogging: Bizarre Contorted Squid

This bizarre contorted squid might be a new species, or a previously known species exhibiting a new behavior. No one knows. As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered. Read my blog posting guidelines here . from Schneier on Security https://www.schneier.com/blog/archives/2018/04/friday_squid_bl_622.html

KnowBe4 - Ransomware up 350% says 2018 Global Threat Intelligence Report

Image
NTT Security 2018 Global Threat Intelligence Report (GTIR): Ransomware up 350% and spyware ranks first in volume of malware at 26% reflecting attackers' desire for long-term presence for information. Summary of key global findings: 77% of ransomware was detected in four industry sectors 73% of malware attacks started with phishing emails 53% of worldwide phishing attacks originated from EMEA 33% of all attempted login attacks used the same 25 passwords 3 most attacked industries now include Finance and Manufacturing from KnowBe4 Security Awareness Training Blog https://blog.knowbe4.com/ransomware-up-350-says-2018-global-threat-intelligence-report