Cyber Security Today, Feb. 1, 2023 – Microsoft tracks 100 gangs using ransomware, Google Fi customer data is copied and more

Share post:

Microsoft tracks 100 gangs using ransomware, Google Fi customer data is copied and more.

Welcome to Cyber Security Today. It’s Wednesday, February 1st, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsDay.com in the U.S.

Cyb er Security Today on Amazon Alexa Cyber Security Today on Google Podcasts Subscribe to Cyber Security Today on Apple Podcasts

There are more than 100 threat actors deploying over 50 families of ransomware, according to Microsoft. In a series of tweets this week it said attackers continue to use phishing and unpatched applications for initial access. However, the use of malvertising as well as fake application and browser updates for initial compromise is increasing.

Google Fi, which is Google’s cellular network provider, has confirmed it has suffered a data breach. According to TechCrunch, Google said the unnamed primary network provider for the service acknowledged customer data — including phone numbers and SIM card serial numbers — were copied. No payment card data or passwords were taken. However, the news story said at least one Google Fi customer claimed in a Reddit post that their phone number was hijacked for two hours. That was enough time for the attacker to use the phone to send and receive text messages.

Cyber crooks continue trying to leverage the document-signing service called DocuSign to steal employees’ login credentials. According to researchers at Armorblox, one of the latest phishing campaigns has a subject line saying, “Please DocuSign: Approve document 2023-01-11.” One tip this is a scam: While the message appears to come from DocuSign, the full email address of the sender shows it didn’t. It’s another example of why IT has to show employees how to turn on the ability to display the full sender’s email address for all messages. The targets of this particular campaign are companies that use the Proofpoint email protection service. Victims who click on the attached document are asked to sign in using their Proofpoint credentials to read the supposed document. Organizations that use Proofpoint have to warn employees to beware of this scam.

YouTube content creators need to toughen their security to avoid their sites being taken over by cryptocurrency scammers. That’s the word from researchers at Guardio Labs. Hacking YouTube channels in what’s called StreamJacking isn’t new. What’s going on now is that it’s being used to spread cryptocurrency scams once the YouTube channel is taken over. Often these messages pretend to be from entrepreneur Elon Musk offering giveaways: Victims are promised a two-for-one swap of any cryptocurrency they send in. What really happens is the crook just takes the digital coins. Meanwhile, the owner of the hijacked YouTube channel can’t get control back. This happens because the owner is tricked into giving away their login credentials, often by falling for email messages promising hacked software or modifications to video games. If you fall for an offer to cheat, don’t complain when you get hacked.

Maintainers of open-source repositories like PyPI, GitHub and others are reminded that some threat actors are determined to drop poisoned packages of code on their platforms. Researchers at Checkmarx this week detailed how one group used several tactics over four months to deposit code that steals credentials, bitcoin wallets and more from victims. These are developers who downloaded the packages and put them in their applications. Open code repositories have to beef up their security, while developers need to be more cautious in downloading packages.

There’s no shortage of reports about hospitals being hit with cyber attacks. Here’s more evidence: Kroll, a cyber risk evaluation provider, says that of its customers healthcare firms were the most breached sector last year. They overtook financial institutions as the most hacked industry. Also during 2022, breaches at industrial services doubled.

Finally, with Super Bowl Sunday less than two weeks away a reminder that crooks will push email and text scams. Officials at BullWall remind sports teams and companies to use email authentication procedures to make sure their brand and domains aren’t spoofed. Fans should be careful with pitches for tickets, T-shirts and other trinkets that appear too good to be true.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Feb. 1, 2023 – Microsoft tracks 100 gangs using ransomware, Google Fi customer data is copied and more first appeared on IT World Canada.

Howard Solomon
Howard Solomonhttps://www.itworldcanada.com
Currently a freelance writer, I'm the former editor of ITWorldCanada.com and Computing Canada. An IT journalist since 1997, I've written for several of ITWC's sister publications including ITBusiness.ca and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Meta’s new release sparks debate about open versus closed source AI: Hashtag Trending for Friday, April 19, 2024

Just how real is quantum computing? We have an amazing guest on our Weekend Edition who will talk about how she is helping people prepare for IT careers using quantum computing. Meta’s new AI release sparks a debate about open versus closed source AI, major legislation expanding US government surveillance capabilities goes largely unnoticed, big

IT World Canada 2024-04-17 21:18:05

More Windows PCs previously blocked are now able to upgrade to Windows 11. Apple has fallen to number two in terms of iPhone market share. Salesforce makes news with a possible acquisition of Informatica. And a new AI wearable device gets savage reviews. All this and more on the “winners and losers” edition of Hashtag

Cisco Duo’s Multifactor Authentication service compromised by social engineering attack

Cisco Duo, a prominent provider of multifactor authentication (MFA) services, has fallen victim to a cyberattack targeting one...

Cyber Security Today, April 17, 2024 – More suspicious attempts to take over open source projects, a data theft at a Cisco Duo partner,...

This episode reports on security updates from Delinea and PuTTY, and reports on bad bots and threat actors going after Zoo

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways