Forwarded from Cyber Security News
Apple and Google Join Forces to Stop Unauthorized Tracking Alert System
The goal is to standardize the alerting mechanisms and minimize opportunities for misuse across Bluetooth location-tracking devices from different vendors. To that end, Samsung, Tile, Chipolo, eufy Security, and Pebblebee have all come on board.
A crucial aspect of the proposed specification is the use of a pairing registry, which contains verifiable (but obfuscated) identity information of the owner of an accessory (e.g., phone number or email address) along with the serial number of the accessory.
📸 Photo: Apple com
@Cyber_Security_Channel
The goal is to standardize the alerting mechanisms and minimize opportunities for misuse across Bluetooth location-tracking devices from different vendors. To that end, Samsung, Tile, Chipolo, eufy Security, and Pebblebee have all come on board.
A crucial aspect of the proposed specification is the use of a pairing registry, which contains verifiable (but obfuscated) identity information of the owner of an accessory (e.g., phone number or email address) along with the serial number of the accessory.
📸 Photo: Apple com
@Cyber_Security_Channel
👍1
دفعت إدارة عمدة مقاطعة سان برناردينو 1.1 مليون دولار فدية
على الرغم من أن مكتب التحقيقات الفيدرالي وهيئات إنفاذ القانون يوصون دائمًا بعدم دفع فدية في هذه الهجمات ، في هذه الحالة ، اختارت الإدارة الدفع على الأرجح لأنه لم يكن لديهم طريقة أخرى لاستعادة الأنظمة المشفرة أو لتجنب الكشف عن البيانات الحساسة.
قال كليفورد نيومان ، مدير مركز USC لأمن أنظمة الكمبيوتر ، لصحيفة Los Angeles Times: "إذا كنت تدفع من خلال عملة مشفرة ، فأنت لا تعرف لمن تدفعها". "يمكن أن يكون كيانًا خاضعًا للعقوبات ، سواء كانت إيران ، أو كوريا الشمالية ، أو منظمة إرهابية".
San Bernardino County Sheriff’s Department Paid a $1.1M Ransom
Despite the FBI and law enforcement bodies always recommend not paying ransom in these attacks, in this case, the department opted to pay likely because they had no other way to recover the encrypted systems or to avoid the disclosure of sensitive data.
“If you’re paying through cryptocurrency, you don’t know who you’re paying it to,” Clifford Neuman, the director of USC’s Center for Computer Systems Security, told the Los Angeles Times. “It could be a sanctioned entity, whether it’s Iran, whether it’s North Korea, whether it’s a terrorist organization”.
@OgluF
على الرغم من أن مكتب التحقيقات الفيدرالي وهيئات إنفاذ القانون يوصون دائمًا بعدم دفع فدية في هذه الهجمات ، في هذه الحالة ، اختارت الإدارة الدفع على الأرجح لأنه لم يكن لديهم طريقة أخرى لاستعادة الأنظمة المشفرة أو لتجنب الكشف عن البيانات الحساسة.
قال كليفورد نيومان ، مدير مركز USC لأمن أنظمة الكمبيوتر ، لصحيفة Los Angeles Times: "إذا كنت تدفع من خلال عملة مشفرة ، فأنت لا تعرف لمن تدفعها". "يمكن أن يكون كيانًا خاضعًا للعقوبات ، سواء كانت إيران ، أو كوريا الشمالية ، أو منظمة إرهابية".
San Bernardino County Sheriff’s Department Paid a $1.1M Ransom
Despite the FBI and law enforcement bodies always recommend not paying ransom in these attacks, in this case, the department opted to pay likely because they had no other way to recover the encrypted systems or to avoid the disclosure of sensitive data.
“If you’re paying through cryptocurrency, you don’t know who you’re paying it to,” Clifford Neuman, the director of USC’s Center for Computer Systems Security, told the Los Angeles Times. “It could be a sanctioned entity, whether it’s Iran, whether it’s North Korea, whether it’s a terrorist organization”.
@OgluF
Security Affairs
San Bernardino County Sheriff’s Department paid a $1.1M ransom
The San Bernardino County Sheriff’s Department confirmed that it has paid a $1.1-million ransom after the April ransomware attack.
خبر مهم لمستخدمي #WordPress
يعرض البرنامج المساعد WordPress Advanced Custom Fields XSS + 2M موقع للهجمات
وأشار الباحثون إلى أن المشكلة قابلة للاستغلال بغض النظر عما إذا كانت منافذ إدارة cPanel (2080 ، 2082 ، 2083 ، 2086) معرضة خارجيًا أم لا. أفاد الباحثون أن المشكلة قابلة للاستغلال أيضًا لاستهداف مواقع الويب على المنفذين 80 و 443 إذا كانت تدار بواسطة cPanel.
يمكن للمهاجم استغلال المشكلة لاختطاف جلسة cPanel لمستخدم شرعي وتنفيذ أنشطة ضارة ، بما في ذلك تحميل قذيفة ويب والحصول على تنفيذ الأوامر.
WordPress Advanced Custom Fields plugin XSS exposes +2M Sites to Attacks
The researchers pointed out that the issue is exploitable regardless of whether or not the cPanel management ports (2080, 2082, 2083, 2086) are exposed externally. The researchers reported that the issue is also exploitable to target websites on ports 80 and 443 if they are being managed by cPanel.
The attacker can exploit the issue to hijack a legitimate user’s cPanel session and carry out malicious activities, including uploading a web shell and gaining command execution.
@OgluF
يعرض البرنامج المساعد WordPress Advanced Custom Fields XSS + 2M موقع للهجمات
وأشار الباحثون إلى أن المشكلة قابلة للاستغلال بغض النظر عما إذا كانت منافذ إدارة cPanel (2080 ، 2082 ، 2083 ، 2086) معرضة خارجيًا أم لا. أفاد الباحثون أن المشكلة قابلة للاستغلال أيضًا لاستهداف مواقع الويب على المنفذين 80 و 443 إذا كانت تدار بواسطة cPanel.
يمكن للمهاجم استغلال المشكلة لاختطاف جلسة cPanel لمستخدم شرعي وتنفيذ أنشطة ضارة ، بما في ذلك تحميل قذيفة ويب والحصول على تنفيذ الأوامر.
WordPress Advanced Custom Fields plugin XSS exposes +2M Sites to Attacks
The researchers pointed out that the issue is exploitable regardless of whether or not the cPanel management ports (2080, 2082, 2083, 2086) are exposed externally. The researchers reported that the issue is also exploitable to target websites on ports 80 and 443 if they are being managed by cPanel.
The attacker can exploit the issue to hijack a legitimate user’s cPanel session and carry out malicious activities, including uploading a web shell and gaining command execution.
@OgluF
Security Affairs
WordPress Advanced Custom Fields plugin XSS exposes +2M sites to attacks
A reflected cross-site scripting vulnerability is the Advanced Custom Fields plugin for WordPress exposed over 2 million sites to hacking.
مصادر فيها مجموعة من usernames, passwords:
1️⃣ https://github.com/danielmiessler/SecLists
2️⃣ https://www.openwall.com/wordlists/
@OgluF
1️⃣ https://github.com/danielmiessler/SecLists
2️⃣ https://www.openwall.com/wordlists/
@OgluF
إن هاتفك الشخصي هو حافظ اسرارك لما يحتويه من معلومات شخصية وكلمات مرور وصور وغيرها .. وعند تعرضه للاختراق يعرض خصوصيتك للخطر حيث لا يتوقف المحتالون عن تطوير أساليبهم في الاختراق وقد لا يعلم المستخدم العادي الكثير عن الهجمات الإلكترونية لذلك سنستعرض بعض العلامات التي قد تدل على اختراق الهواتف الذكية:
• انخفاض حاد في شحن البطارية نتيجة زيادة معدل الاستهلاك.
• برامج تم تنزيلها على الهاتف دون سابق معرفة.
• ظهور إعلانات منبثقة دون معرفة سبب ظهورها.
• انغلاق الهاتف وإعادة تشغيله من تلقاء نفسه.
• تكرر حدوث عطل مفاجئ في هاتفك.
• عند سماع ضوضاء أثناء إجراء المكالمات.
ولتجنب حدوث عمليات الاختراق او التجسس على هاتفك يجب مراعاة ما يلي :
• تحديث النظام والتطبيقات دورياً لأن الشركات لا تقوم فقط بإضافة ميزات جديدة لأنظمة التشغيل بل تقوم بسد الثغرات الأمنية وإصلاح الأخطاء في النظام فإذا اكتشف أحد المخترقين هذه الثغرات ولم تقم بتحديث نظامك فإن هاتفك في خطر.
• تجنب استخدام الواي فاي العام وفي الشوارع لاحتمالية اختراقه من قبل الكثيرين.
• الحذر من أي رابط لا تعرف مصدره ، إذ تعد هذه الطريقة أسهل وأخطر طرق الاختراق.
• تجنب تنزيل تطبيقات على الهاتف إلا من مصادر معلومة وموثوق بها وقراءة أذونات التطبيقات قبل تحميلها وعدم الضغط على موافق قبل التحقق منها.
• انخفاض حاد في شحن البطارية نتيجة زيادة معدل الاستهلاك.
• برامج تم تنزيلها على الهاتف دون سابق معرفة.
• ظهور إعلانات منبثقة دون معرفة سبب ظهورها.
• انغلاق الهاتف وإعادة تشغيله من تلقاء نفسه.
• تكرر حدوث عطل مفاجئ في هاتفك.
• عند سماع ضوضاء أثناء إجراء المكالمات.
ولتجنب حدوث عمليات الاختراق او التجسس على هاتفك يجب مراعاة ما يلي :
• تحديث النظام والتطبيقات دورياً لأن الشركات لا تقوم فقط بإضافة ميزات جديدة لأنظمة التشغيل بل تقوم بسد الثغرات الأمنية وإصلاح الأخطاء في النظام فإذا اكتشف أحد المخترقين هذه الثغرات ولم تقم بتحديث نظامك فإن هاتفك في خطر.
• تجنب استخدام الواي فاي العام وفي الشوارع لاحتمالية اختراقه من قبل الكثيرين.
• الحذر من أي رابط لا تعرف مصدره ، إذ تعد هذه الطريقة أسهل وأخطر طرق الاختراق.
• تجنب تنزيل تطبيقات على الهاتف إلا من مصادر معلومة وموثوق بها وقراءة أذونات التطبيقات قبل تحميلها وعدم الضغط على موافق قبل التحقق منها.
❤1