Tuesday, January 29, 2019

If your phone starts listening BEFORE you answer, will that be considered a BUG or Feature (AI may be). Apparently, FaceTime has this problem and Apple is scrambling to fix this embarrassingly dangerous “snooping” bug in FaceTime app.



The bug goes like this:


  1. Call someone from your contacts using FaceTime.
  2. Their phone will ring.
  3. Use the “Add Person” option to include a new participant in the chat, namely yourself. 


…and you can immediately hear the audio feed from the person who hasn’t answered the call yet.

https://nakedsecurity.sophos.com/2019/01/29/apple-facetime-eavesdropping-bug/

Need a reason to move to Firefox 65? - New Content Blocking controls!!



  1. Users can block known trackers in Private Browsing Mode. In the future, this setting will also block third-party tracking cookies
  2. Users can also pick from a “strict” setting that blocks all known trackers by Firefox in all windows;  or a “custom” setting that enables users to pick and choose which trackers and cookies they would like to block.
  3. A new “Security/ Anti-Tracking policy


https://threatpost.com/mozilla-firefox-65-anti-tracking/141281/

Thursday, January 24, 2019

Beware of "WhatsApp Gold" scam - this hoax involves sending WhatsApp messages to users regarding downloading an update for WhatsApp. However, in reality, it isn’t an update but malware.

WhatsApp has confirmed that it is a new hoax that’s being spread by scammers to trap users by convincing them that by clicking on the link they will be able to receive an updated version of the messaging app.

Preview of the Scam Message Below:




https://www.hackread.com/whatsapp-gold-scam-with-malware-payload

Wednesday, January 23, 2019

AI in cybersecurity - The term has quickly evolved in the industry from FUD factor to buzzword. Believing AI is the silver bullet that can address all cybersecurity challenges is as dangerous.AI still needs humans to provide reliable data.

 A lack of quality data leads to poor results. Even with quality data, trained AI tends to produce false positives and is not very good at explaining how it arrived at a certain conclusion, as it lacks the ability to understand context.

For this reason, humans remain a critical part of the equation. They are still needed to fine-tune AI systems and to investigate the alerts, validate and stratify the severity of threats, and determine the best way to remediate an attack.


https://www.scmagazine.com/home/opinion/balancing-ai-with-human-intelligence-in-cybersecurity/

Attention, PHP users - It appears that anyone downloading and installing an updated edition from PEAR (PHP Extension and Application Repository, a framework and distribution system for reusable PHP component) in the last half-year could have been compromised.



The administrators of the PEAR package manager website have taken the site offline, having discovered that hackers breached the site, and apparently planted malicious code into the software.

https://www.grahamcluley.com/poisoned-pear-php-extension-repository-download-infected-for-up-to-six-months/

Monday, January 21, 2019

OWASP IoT TOP 10 (2018)


Why is it that bad guy seem to be more innovative in the Security Space - New technique to detect Sandbox

 malicious Android apps in the official Google Play Store are using the motion-sensors of infected devices. If the apps fail to detect any movement (which is - of course - unlikely in a sandbox environment in a research lab!), they refuse to activate their malicious payload.
If, however, there has been movement, the apps display a fake system update dialog which attempts to trick the poor user into installing a piece of banking malware called Anubis

https://www.grahamcluley.com/android-malware-motion-sensor/