BlackBox (Security) Archiv
4.11K subscribers
183 photos
393 videos
167 files
2.67K links
👉🏼 Latest viruses and malware threats
👉🏼 Latest patches, tips and tricks
👉🏼 Threats to security/privacy/democracy on the Internet

👉🏼 Find us on Matrix: https://matrix.to/#/!wNywwUkYshTVAFCAzw:matrix.org
Download Telegram
Man who called Duterte ‘buang’ on Facebook arrested for cyberlibel

MANILA, Philippines — A 41-year-old man was arrested in Agusan del Norte for his Facebook post criticizing President Rodrigo Duterte and Senator Christopher “Bong” Go on Wednesday afternoon.

Caraga police director Brig. Gen. Joselito Esquivel arrested Reynaldo Orcullo, who is a salesman living in Barangay Triangulo, Nasipit town, for alleged libelous statements posted on Facebook, which supposedly called the President “foolish.”

👉🏼 Read more:
https://newsinfo.inquirer.net/1275073/man-from-agusan-del-norte-nabbed-for-controversial-post-vs-bong-go-duterte

#DeleteFacebook #philippines #freespeak #duterte #buang #arrested #cyberlibel
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN
The US Senate just voted to let the FBI access your browser history without a warrant

In a major blow to citizens’ privacy, the US Senate voted today to give law enforcement agencies such as the FBI and CIA the power to look into your browser history without a warrant. Thanks, Mitch McConnell.

Senators Ron Wyden from Oregan and Senator Steve Daines of Montana led the charge to insert privacy protections into the Patriot Act, which gives law enforcement agencies power for surveillance in order to maintain national security. However, the privacy protection amendment fell short by just one vote, as many senators who may have voted in favor of it didn’t show up.

[Read: Using ‘personalized AI’ to end coronavirus lockdown is a stupid, cruel idea]

This vote is a setback to the privacy of citizens at multiple levels. There’s already a growing level of concern among privacy advocates as governments around the world are using the coronavirus pandemic as a shield to insert new surveillance measures without any guardrails.

Evan Greer, the deputy director of Fight For The Future, a non-profit digital advocacy group, told Motherboard that the Patriot Act should be repealed in its entirety:

"The Patriot Act should be repealed in its entirety, set on fire, and buried in the ground. It’s one of the worst laws passed in the last century, and there is zero evidence that the mass surveillance programs it enables have ever saved a single human life."

👉🏼 Read more:
https://thenextweb.com/security/2020/05/14/the-us-senate-just-voted-to-let-the-fbi-access-your-browser-history-without-a-warrant/

#USA #Congress #patriotact #DOJ #phone #metadata #surveillance #privacy #why #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN
👍1
Why You Should Remove DOOM Eternal from your PC Immediately

CLARIFICATION: Denuvo Anti-Tamper is NOT the same as Denuvo Anti-Cheat.

Denuvo Anti-Tamper (henceforth DAT) is software used to obfuscate code during the compiling process. This makes it harder for pirates/crackers to crack the software through reverse engineering. This software has no bearing on the operating system but is built into the executable. It may cause game performance issues at times but that is the extent of it. DAT is what people generally are talking about when they say a game has "Denuvo".

Denuvo Anti-Cheat (henceforth DAC) is the new anti-cheat introduced with update 1. It is an EXTREMELY invasive anti-cheat software that runs at ring-0 (kernel level) of your operating system. Read the thread for more information

Please do not make the error of thinking these two things are the same.

❗️ NOTE:
To make it extra clear. The fact that we were NOT INFORMED that such an intrusive piece of software would be added to the game before purchase is unacceptable. Worse yet, it's required to be running to so much as run the game, multiplayer or not. People are bringing to my attention that some other games use similar anti-cheats. That does not make them any less dangerous and the lack of knowing such software would be employed before purchase makes this doubly unacceptable.

👉🏼 Read more:
https://bethesda.net/community/topic/407885/why-you-should-remove-doom-eternal-from-your-pc-immediately

https://www.reddit.com/r/Doom/comments/gjzi01/why_you_should_remove_doom_eternal_denuvo/

#doom #antitamper #dat #denuvo #thinkabout #why
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN
HTTP Status Codes Command This Malware How to Control Hacked Systems

A new version of COMpfun remote access trojan (RAT) has been discovered in the wild that uses HTTP status codes to control compromised systems targeted in a recent campaign against diplomatic entities in Europe.

The cyberespionage malware—traced to Turla APT with "medium-to-low level of confidence" based on the history of compromised victims—spread via an initial dropper that masks itself as a visa application, the Global Research and Analysis Team at Kaspersky discovered.

The Turla APT, a Russian-based threat group, has a long history of carrying out espionage and watering hole attacks spanning various sectors, including governments, embassies, military, education, research, and pharmaceutical companies.

First documented by G-Data in 2014, COMpfun received a significant upgrade last year (called "Reductor") after Kaspersky found that the malware was used to spy on a victim's browser activity by staging man-in-the-middle (MitM) attacks on encrypted web traffic via a tweak in the browser's random numbers generator (PRNG).

👉🏼 Read more:
https://thehackernews.com/2020/05/malware-http-codes.html

https://securelist.com/compfun-http-status-based-trojan/96874/

#cyberespionage #malware #http #hacked
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN
Microsoft warns on COVID-19 cyber-scams

Microsoft is warning about new phishing scams that use COVID-19 as a lure to steal personal information.

The phishing campaigns attempt to deliver malware called Lokibot, “one of the first malware families to use COVID-19 lures,” Microsoft Security Intelligence said in a tweet this week.

Phishing, a widely-used tactic by scammers, uses an email that appears to be from a reputable source and attempts to trick recipients into handing over sensitive personal information like usernames, passwords, and credit card information.

👉🏼 Read more:
https://www.bleepingcomputer.com/news/security/microsoft-warns-of-covid-19-phishing-spreading-info-stealing-malware/

https://www.foxnews.com/tech/microsoft-warns-on-covid-19-cyber-scams

#microsoft #warning #coronavirus #malware #phishing #scammers #lokibot
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN
These are the 37 Senators that voted to let the FBI seize your internet history without a warrant

A key amendment to the USA Freedom Reauthorization Act of 2020 that would have required authorities to obtain a warrant before gaining access to American internet browsing and search history just failed on the Senate floor by a single vote. For those that are unaware, key parts of the Patriot Act – namely the mass surveillance section – is currently unauthorized and needs to be reauthorized by Congress to stay in effect.

The current bill under consideration to do that is called the US FREEDOM Reauthorization Act of 2020 and Senate Majority Leader Mitch McConnell has snuck in an amendment that would allow the Federal Bureau of Investigation (FBI) and Department of Justice (DOJ) to seize internet search and browsing history if they claim it is tied to an active investigation. To try and stop this, Senators Wyden and Daines introduced their own amendment that would stop the FBI from being able to get that information without a warrant – as makes sense. That amendment needed 60 votes to pass, and only received 59 Wednesday afternoon.

37 Senators voted against an amendment that would have stopped the FBI from being able to seize your internet search and browsing history

All in all, 27 Republicans and 10 Democrats voted against the amendment and 4 senators were no-shows. One of the senators that didn’t vote is under self quarantine due to a staff member testing positive for COVID-19. But where were the other 3 senators? Here’s who voted against the Wyden-Daines Amendment to the USA Freedom Reauthorization Act of 2020 that would have blocked McConnell’s plan to let FBI collect web browsing history without a warrant:

👉🏼 Read more:
https://www.privateinternetaccess.com/blog/these-are-the-37-senators-that-voted-to-let-the-fbi-seize-your-internet-history-without-a-warrant/

#USA #Congress #patriotact #DOJ #phone #metadata #surveillance #privacy #why #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN
Linux not Windows: Why Munich is shifting back from Microsoft to open source – again

Munich's flip-flop back to open source is the latest sign of Germany's political sea change over proprietary software.

In a notable U-turn for the city, newly elected politicians in Munich have decided that its administration needs to use open-source software, instead of proprietary products like Microsoft Office.

"Where it is technologically and financially possible, the city will put emphasis on open standards and free open-source licensed software," a new coalition agreement negotiated between the recently elected Green party and the Social Democrats says.

The agreement was finalized Sunday and the parties will be in power until 2026. "We will adhere to the principle of 'public money, public code'. That means that as long as there is no confidential or personal data involved, the source code of the city's software will also be made public," the agreement states.

👉🏼 Read more:
https://www.zdnet.com/article/linux-not-windows-why-munich-is-shifting-back-from-microsoft-to-open-source-again/

#OpenSource #linux #munich
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN
Hackers target the air-gapped networks of the Taiwanese and Philippine military

Third state-sponsored malware strain disclosed this week that can jump the air gap and reach isolated networks.

Hackers believed to be operating in the interests of the Chinese government have targeted the air-gapped networks of the Taiwanese and the Philippine military.

Trend Micro says the attacks have been carried out by a group known as Tropic Trooper, also known as KeyBoy.

Attacks involved the use of USBferry, a malware strain that contains a feature allowing it to self-replicate to removable USB devices, such as thumb drives and portable storage systems.

Trend Micro says the point of these attacks was to allow hackers to reach inside air-gapped (isolated, internet-disconnected) networks operated by the Taiwanese and the Philippine militaries, and other targets.

The malware would infect a system with fewer security protections, then wait for a USB device to be connected, infect the device, and wait to be ferried to other parts of a victim's internal network.

On the new device, USBferry would collect sensitive documents inside the USB device's internal storage, and wait until it was ferried back to another internet-connected device, where it would send the data back to Tropic Trooper's command and control servers.

Attacks have been going on for six years
Trend Micro says it's been tracking attacks with the USBferry malware since 2018, but that older incidents have been traced back to 2014 when Tropic Trooper appears to have deployed the malware for the first time.

Historically, the hacker group has been interested in stealing defense and marine-related intelligence from Taiwan and the Philippines.

👉🏼 Read more:
https://www.zdnet.com/article/hackers-target-the-air-gapped-networks-of-the-taiwanese-and-philippine-military/

#china #hackers #hacked #USBferry #taiwanese #philippine #military
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN
Attack against supercomputers

More than 10 high-performance data centers were hacked, including the one in the city of Garching (Germany). They are used for research on Covid-19 therapies, but those affected suspect other motives behind the attacks.

Dieter Kranzlmüller cannot explain what the hacker wanted. "Someone broke in and manipulated the system. But we don't know exactly what he did," says the head of the Leibniz computer centre in Garching near Munich. The high-performance computer SuperMUC-NG is located there. Kranzlmüller's team had to take it off the Internet this week after a hacker had gained access to the system. The Cybercrime Department of the Bavarian State Office of Criminal Investigation is investigating.

The case has shaken the research community, which depends on the expensive machines for its investigations. They are scattered internationally, but can no longer access the computers online. According to Kranzlmüller, in addition to Garching, more than ten high-performance computer centres in different countries are affected, including those in Freiburg, Stuttgart and Jülich. A "serious problem right across the academic community", is what those responsible for the super computer Archer in Edinburgh call it.

Read more 🇩🇪:
https://www.computerbase.de/2020-05/sicherheitsprobleme-europaeische-rechenzentren-supercomputer/

https://www.sueddeutsche.de/digital/supercomputer-hacker-garching-corona-1.4909397

#attack #hacker #hacked #supercumputers #datacenter #research
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN
Hackers who stole files from a law firm to stars like Lady Gaga and Drake doubled their ransom to $42 million and threatened to release 'dirty laundry' on Trump

Grubman, Shire, Meiselas and Sacks was recently the target of a hack by a group called REvil, which is attempting to random the information.

One of the top entertainment law firms in the US — Grubman, Shire, Meiselas and Sacks — was recently the target of a ransomware attack.

REvil, the group behind the attack, on Thursday doubled their ransom to $42 million, Page Six reported.
They also threatened to release "dirty laundry" on President Donald Trump if the amount wasn't paid.
They did not elaborate on what the material might be. Sources told Page Six that Trump had never been a client of the firm.

A hacker group that stole 756 gigabytes of data from one of top US entertainment law firms has doubled their ransom to $42 million, and threatened to release "dirty laundry" on President Donald Trump if the money is not paid.

👉🏼 Weiter auf:
https://www.businessinsider.fr/us/revil-hackers-threaten-trump-dirty-laundry-taken-from-law-firm-2020-5

#hacker #hacked #ransom #LadyGaga #drake #trump
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN
Forwarded from We Are Change
🚨🚨The US Government is Seizing Massive New Surveillance Powers

We tried to warn you. The Patriot Act will soon be much stronger and more invasive.

https://news4achange.com/the-us-government-is-seizing-massive-new-surveillance-powers/
Huge, mysterious list appears online of where people met, personal information and more of tens of millions

'There's nothing you nor I can do about it,' notes security expert

A huge data dump includes the personal information of tens of millions of people and where they have met – and its origin is a mystery.

The breach includes almost 90GB of people's personal data, including details of where they have been and met people.

But there is no clue where the information has actually come from in the first place.

Though the information has been hosted publicly, and available to anyone, there is no hint about where it was first collected from.

The dump includes listings of individual people, including information on their social media sites, phone numbers and addresses. Unusually, however, it also includes details about where people have met, and information about where the people listed within the dump may know each other from.

As such, it appears that the data was probably collected from CRM, or customer relationship management, software. Users presumably took down a contact's personal information as well as a note about where they had met them to remember in future, and recorded it in a piece of software, which has since been breached.

But Troy Hunt, who tracks such data breaches and runs the website HaveIBeenPwned.com to allow users to check if they have been caught up in them, said that he had been unable to find any clue about what that software might be or how it had become public.

"Nowhere – absolutely nowhere – was there any indication of where the data had originated from," he wrote in a blog post announcing the find.

👉🏼 Read more:
https://www.independent.co.uk/life-style/gadgets-and-tech/news/data-dump-personal-information-breach-crm-a9515931.html

https://www.troyhunt.com/the-unattributable-db8151dd-data-breach/

#leak #breach #CRM
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN
Facebook Welcomes GIPHY as Part of Instagram Team

GIPHY, a leader in visual expression and creation, is joining the Facebook company today as part of the Instagram team. GIPHY makes everyday conversations more entertaining, and so we plan to further integrate their GIF library into Instagram and our other apps so that people can find just the right way to express themselves.

A lot of people in our community already know and love GIPHY. In fact, 50% of GIPHY’s traffic comes from the Facebook family of apps, half of that from Instagram alone. By bringing Instagram and GIPHY together, we can make it easier for people to find the perfect GIFs and stickers in Stories and Direct. Both our services are big supporters of the creator and artist community, and that will continue. Together, we can make it easier for anyone to create and share their work with the world.

👉🏼 Read more:
https://about.fb.com/news/2020/05/welcome-giphy/

#DeleteFacebook #fb #giphy #instagram
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN
2Africa: a transformative subsea cable for future internet connectivity in Africa announced by global and African partners

2Africa is one of the largest subsea projects in the world, connecting 23 countries in Africa, the Middle East and Europe

#China #Mobile #International, #Facebook, #MTN #GlobalConnect, #Orange, #stc, #Telecom #Egypt, #Vodafone and #WIOCC announced today that they will partner to build #2Africa, which will be the most comprehensive #subsea #cable to serve the African continent and Middle East region. The parties have appointed #Alcatel Submarine Networks (“#ASN”) to build the cable in a fully funded project which will greatly enhance connectivity across Africa and the Middle East.

At 37,000km long, 2Africa will be one of the world’s largest subsea cable projects and will interconnect Europe (eastward via Egypt), the Middle East (via Saudi Arabia), and 21 landings in 16 countries in Africa. The system is expected to go live in 2023/4, delivering more than the total combined capacity of all subsea cables serving Africa today, with a design capacity of up to 180Tbps on key parts of the system. 2Africa will deliver much needed internet capacity and reliability across large parts of Africa, supplement the fast-growing capacity demand in the Middle East and underpin the further growth of 4G, 5G and fixed broadband access for hundreds of millions of people.

In countries where the 2Africa cable will land, service providers will obtain capacity in carrier-neutral data centres or open-access cable landing stations on a fair and equitable basis. This will support healthy internet ecosystem development by facilitating greatly improved accessibility for businesses and consumers alike.

The 2Africa cable has been designed to improve resilience and maximise performance, including the option of a seamless optical crossing between East Africa and Europe. The 2Africa parties and Airtel have signed an agreement with Telecom Egypt to provide a completely new crossing linking the Red Sea and the Mediterranean, the first in over a decade. This includes new cable landing stations and deployment of next-generation fibre on two new, diverse terrestrial routes parallel to the Suez Canal from Ras Ghareb to Port Said, and a new subsea link that will provide a third path between Ras Ghareb and Suez.

Read more:
https://www.orange.com/en/Press-Room/press-releases/press-releases-2020/2Africa-a-transformative-subsea-cable-for-future-internet-connectivity-in-Africa-announced-by-global-and-African-partners

📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN
Average American had personal data stolen at least 4 times last year, report says

Over the past decade or so you’ve probably noticed the increasing frequency of major data breaches around the world. There have been at least 200 documented data breaches since 2005, and the number of records exposed is only on the rise as more folks move their lives online. With more people transitioning facets of their lives online in the context of the “stay home” orders of the 2020 pandemic, these numbers of are sure to climb even higher in years to come.

It’s impossible to know the impact and extent to which data breaches are occurring as many almost certainly go unreported. Here are some of the data breaches we analyzed in our research:

👉🏼 Read more:
https://www.interest.com/personal-finance/the-average-american-had-personal-information-stolen-at-least-4-times-in-2019/

https://en.wikipedia.org/wiki/List_of_data_breaches

https://www.statista.com/statistics/273550/data-breaches-recorded-in-the-united-states-by-number-of-breaches-and-records-exposed/

https://theweek.com/articles/730439/have-almost-certainly-been-hacked

#USA #hacked #breach #leak
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN
Noyb files complaint against Google under GDPR, saying Android Advertising ID can be tracked

Every phone has an Android Advertising ID and it can be used to track your phone’s actions – and tied back to your identity. A privacy advocacy group called Noyb – European Center for Digital Rights has filed a legal complaint with the Austrian Data Protection Agency against Google under Europe’s GDPR law. Noyb stands for None of Your Business – and that’s exactly how activists feel about the use of the Android Advertising ID to track Android users. Noyb was started by Austrian privacy activist Max Schrems who has filed privacy cases against Google and Facebook in the past and is deservedly highly celebrated in the privacy community.

‼️ Noyb’s privacy lawyer, Stefano Rossetti succinctly summed up the problem:

In essence, you buy a new Android phone, but by adding a tracking ID they ship you a tracking device.

How the Android Advertising ID violates the GDPR
This Android Advertising ID is on by default and does not allow users to opt-out. If you choose not to be targeted by “interest-based ads” that still doesn’t get rid of the Android Advertising ID. Even if it did, that still wouldn’t be a GDPR compliant for Google to go about this. To be compliant under the GDPR, Google is supposed to get opt-in user consent before setting up any sort of tracking ID. Right now, all users can do is have Google change their advertising ID – which may hinder the ability of third party apps to track your Android device, but doesn’t do anything to stop Google from tracking you with the Android Advertising ID.

👉🏼 Read more:
https://www.privateinternetaccess.com/blog/noyb-files-complaint-against-google-under-gdpr-saying-android-advertising-id-can-be-tracked/

#android #google #DeleteGoogle #GDPR #advertising #id #tracking #privacy
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN
Media is too big
VIEW IN TELEGRAM
Dark Winter, Restaurant Snitches, Black Mirror – New World Next Week

This week on the New World Next Week: Plandemic planners threaten a dark winter for America; the reopening comes with strings attached; and reality has officially overtaken science fiction.

https://www.corbettreport.com/dark-winter-restaurant-snitches-black-mirror-new-world-next-week/

MP3:
http://www.corbettreport.com/mp3/2020-05-14_James_Evan_Pilato.mp3

#corbettreport #video #podcast
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN
U.S. Secret Service: “Massive Fraud” Against State Unemployment Insurance Programs

A well-organized Nigerian crime ring is exploiting the COVID-19 crisis by committing large-scale fraud against multiple state unemployment insurance programs, with potential losses in the hundreds of millions of dollars, according to a new alert issued by the U.S. Secret Service.

A memo seen by KrebsOnSecurity that the Secret Service circulated to field offices around the United States on Thursday says the ring has been filing unemployment claims in different states using Social Security numbers and other personally identifiable information (PII) belonging to identity theft victims, and that “a substantial amount of the fraudulent benefits submitted have used PII from first responders, government personnel and school employees.”

“It is assumed the fraud ring behind this possesses a substantial PII database to submit the volume of applications observed thus far,” the Secret Service warned. “The primary state targeted so far is Washington, although there is also evidence of attacks in North Carolina, Massachusetts, Rhode Island, Oklahoma, Wyoming and Florida.”

The Secret Service said the fraud network is believed to consist of hundred of “mules,” a term used to describe willing or unwitting individuals who are recruited to help launder the proceeds of fraudulent financial transactions.

“In the state of Washington, individuals residing out-of-state are receiving multiple ACH deposits from the State of Washington Unemployment Benefits Program, all in different individuals’ names with no connection to the account holder,” the notice continues.

👉🏼 Read more:
https://krebsonsecurity.com/2020/05/u-s-secret-service-massive-fraud-against-state-unemployment-insurance-programs/

#USA #SecretService #alert #nigerian #fraud #coronavirus
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN
RATicate Group Hits Industrial Firms With Revolving Payloads

A new threat group uses NSIS as an installer to target industrial companies with revolving payloads, including LokiBot, FormBook, BetaBot, Agent Tesla and Netwire.

Researchers have unearthed a new cybercrime group, RATicate, which is behind several waves of malspam attacks targeting industrial companies with various information-stealing payloads – from LokiBot to Agent Tesla.

At least six separate campaigns have been tied to RATicate, with the first wave starting November and the most recent spotted in March. All campaigns leveraged Nullsoft Scriptable Install System (NSIS), a legitimate, open-source tool used to create Windows installers, to ultimately drop various remote access trojans (RATs) on victims’ systems.

More recently, “a new campaign we believe connected to the same actors leverages concern about the global COVID-19 pandemic to convince victims to open the payloads,” said Markel Picado, threat researcher with SophosLabs, in a Thursday analysis. “This is a shift in tactics, but we suspect that this group constantly changes the way they deploy malware — and that the group has conducted campaigns prior to this past November.”

👉🏼 Read more:
https://threatpost.com/raticate-group-industrial-firms-revolving-payloads/155775/

#RATicate #payloads #LokiBot #NSIS #RATs #malspam
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN
NOT DELIVERING Amazon ending ‘hero pay’ in Canada slashing hourly wages and cutting double overtime pay despite coronavirus outbreaks

AMAZON is cancelling "hero pay" for its Canadian workforce, despite rising infections in its warehouses - and as CEO Jeff Bezos prepares to become the world's first trillionaire.

The pay was granted in recognition of working in hazardous conditions during the pandemic, and equated to a $2 wage increase and double overtime pay.

The announcement was made in an internal company memo, obtained by PressProgress, and came as a number of workers tested positive in warehouses across the country.

“We are providing a final extension of the temporary $2/hour pay increase and double overtime pay through May 30.”

After that, the memo continues: “we will return to our regular pay and overtime structure.”

On May 1, an outbreak at an Alberta warehouse was declared, after five people tested positive.

👉🏼 Read more:
https://pressprogress.ca/amazon-tells-canadian-warehouse-workers-theyre-getting-a-pay-cut/

#DeleteAmazon #bezos #thinkabout #why
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN
News Wrap May 15
News Wrap: Ransomware Extortion Tactics, Contact-Tracing App Security Worries

Threatpost editors discuss the top news stories of the week ended May 15

https://threatpost.com/news-wrap-ransomware-extortion-tactics-contact-tracing-app-security/155796/

#NewsWrap #podcast
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
📡@FLOSSb0xIN