Microsoft today released updates to fix 113 security vulnerabilities in its various Windows operating systems and related software. Those include at least three flaws that are actively being exploited, as well as two others which were publicly detailed prior to today, potentially giving attackers a head start in figuring out how to exploit the bugs.Continue reading “Microsoft Patch Tuesday, April 2020 Edition”
Category Archives: Cybersecurity
New IRS Site Could Make it Easy for Thieves to Intercept Some Stimulus Payments
The U.S. federal government is now in the process of sending Economic Impact Payments by direct deposit to millions of Americans. Most who are eligible for payments can expect to have funds direct-deposited into the same bank accounts listed on previous years’ tax filings sometime next week. Today, the Internal Revenue Service (IRS) stood upContinue reading “New IRS Site Could Make it Easy for Thieves to Intercept Some Stimulus Payments”
Microsoft Buys Corp.com So Bad Guys Can’t
In February, KrebsOnSecurity told the story of a private citizen auctioning off the dangerous domain corp.com for the starting price of $1.7 million. Domain experts called corp.com dangerous because years of testing showed whoever wields it would have access to an unending stream of passwords, email and other sensitive data from hundreds of thousands ofContinue reading “Microsoft Buys Corp.com So Bad Guys Can’t”
‘War Dialing’ Tool Exposes Zoom’s Password Problems
As the Coronavirus pandemic continues to force people to work from home, countless companies are now holding daily meetings using videoconferencing services from Zoom. But without the protection of a password, there’s a decent chance your next Zoom meeting could be “Zoom bombed” — attended or disrupted by someone who doesn’t belong. And according toContinue reading “‘War Dialing’ Tool Exposes Zoom’s Password Problems”
Phish of GoDaddy Employee Jeopardized Escrow.com, Among Others
A spear-phishing attack this week hooked a customer service employee at GoDaddy.com, the world’s largest domain name registrar, KrebsOnSecurity has learned. The incident gave the phisher the ability to view and modify key customer records, access that was used to change domain settings for a half-dozen GoDaddy customers, including transaction brokering site escrow.com. Escrow.com helps people safelyContinue reading “Phish of GoDaddy Employee Jeopardized Escrow.com, Among Others”
Annual Protest to ‘Fight Krebs’ Raises €150K+
In 2018, KrebsOnSecurity unmasked the creators of Coinhive — a now-defunct cryptocurrency mining service that was being massively abused by cybercriminals — as the administrators of a popular German language image-hosting forum. In protest of that story, forum members donated hundreds of thousands of euros to nonprofits that combat cancer (Krebs means “cancer” in German).Continue reading “Annual Protest to ‘Fight Krebs’ Raises €150K+”
Russians Shut Down Huge Card Fraud Ring
Federal investigators in Russia have charged at least 25 people accused of operating a sprawling international credit card theft ring. Cybersecurity experts say the raid included the charging of a major carding kingpin thought to be tied to dozens of carding shops and to some of the bigger data breaches targeting western retailers over theContinue reading “Russians Shut Down Huge Card Fraud Ring”
US Government Sites Give Bad Security Advice
Many U.S. government Web sites now carry a message prominently at the top of their home pages meant to help visitors better distinguish between official U.S. government properties and phishing pages. Unfortunately, part of that message is misleading and may help perpetuate a popular misunderstanding about Web site security and trust that phishers have beenContinue reading “US Government Sites Give Bad Security Advice”
Who’s Behind the ‘Web Listings’ Mail Scam?
In December 2018, KrebsOnSecurity looked at how dozens of U.S. political campaigns, cities and towns had paid a shady company called Web Listings Inc. after receiving what looked like a bill for search engine optimization (SEO) services rendered on behalf of their domain names. The story concluded that this dubious service had been scamming peopleContinue reading “Who’s Behind the ‘Web Listings’ Mail Scam?”
Security Breach Disrupts Fintech Firm Finastra
Finastra, a company that provides a range of technology solutions to banks worldwide, said it was shutting down key systems in response to a security breach discovered Friday morning. The company’s public statement and notice to customers does not mention the cause of the outage, but their response so far is straight out of theContinue reading “Security Breach Disrupts Fintech Firm Finastra”