US Sanctions Two Members of Russian ‘Cyber Army’ Hacktivist Group

The U.S. sanctioned two members of the Russian hacktivist group Cyber Army of Russia Reborn (CARR) for carrying out cyber operations against critical U.S. infrastructure. CARR has launched low-impact DDoS attacks in Ukraine and its allies since 2022.

Cyware News – Latest Cyber News – ​Read More

Analyzing Container Escape Techniques in Cloud Environments

While containers offer efficiency, they are vulnerable to attacks exploiting misconfigurations. Attackers can execute code or escalate privileges, endangering organizational security.

Cyware News – Latest Cyber News – ​Read More

Attackers Abuse Swap File to Steal Credit Cards

Attackers recently abused the swap file in a Magento e-commerce site to steal credit card information. Despite multiple cleanup attempts, the malware persisted until analysts discovered it.

Cyware News – Latest Cyber News – ​Read More

CrowdStrike Incident Leveraged for Malware Delivery, Phishing, Scams

The major IT outage caused by CrowdStrike is being leveraged by threat actors for phishing, scams, and malware delivery.

The post CrowdStrike Incident Leveraged for Malware Delivery, Phishing, Scams appeared first on SecurityWeek.

SecurityWeek – ​Read More

Scams at the Paris Olympics | Kaspersky official blog

For athletes, the Olympics are the pinnacle of a lifetime’s work. Many train for decades to one day perform under their nation’s flag and sing its anthem far from home. For scammers, it’s much simpler: the Olympics are just another opportunity to cash in on unsuspecting individuals.

Today we tell you how scammers have prepared for the Paris Olympics, how they plan to steal money and personal data from sports fans, and what you need to know to follow your favorite athletes safely.

Olympic-sized data plan

The Paris Olympics kick off on July 26, and French media predict a temporary population explosion with 15.3 million visitors. Naturally, tourists from other countries always want to stay connected, and… who comes to their “aid”? Scammers, of course, armed with a too-good-to-be-true offer — 48GB of supposedly free internet, regardless of your carrier.

48GB of free cheese

Let’s do the math: a standard mobile plan with 40GB of internet and unlimited calls in France costs around €11 (roughly $12USD). Given the number of expected tourists, the cost of providing free internet to all would exceed €168 million (approximately $184 million USD). No telecom company is giving away that much data allowance — after all, many of these visitors will never return to France.

But who’s got the time to think about that when the offer is so tempting, and the Parisian atmosphere is so intoxicating? Alas, after registering and filling out all the forms, the tourist won’t get a single free megabyte, and they may only realize this too late when their phone account runs out of money. At the same time, they’ll have given the scammers their phone number, personal and banking details, and confirmation that they’ll be far from home, watching the Olympics in Paris — and therefore probably won’t be closely monitoring their banking transactions.

Don’t forget your ticket… and scarf!

What are the first things Olympic spectators want? Tickets to the Games, of course. Just in time for the Paris Olympics, scammers have built a network of fake ticket-sales websites. Archery? You bet! Soccer? Naturally. Badminton? Don’t even ask! They’ve got it all covered! To appear legitimate, the scammers have even added pop-ups requesting consent to collect personal data and use web tracking, complete with links to their own “privacy policies” — so the unsuspecting victim also agrees to sharing their data with the scammers!

This fraudulent site “selling” tickets to Olympic events even asks for permission to collect personal data, and has its own privacy policy

The platform offers not only to buy tickets, but also to sell them — just in case you decide to watch rhythmic gymnastics instead of soccer. This way, the scammers can extend their reach to those who’ve bought tickets in advance but changed their plans.

But at least you can safely buy Olympic merch, right? Nope, another trap awaits there too: for fans of cheap merch, scammers have a special gift — phishing websites. Keychains, commemorative coins, magnets, and scarves — scammers offer it all, and at great prices.

Fake store website saying you can return any item you don’t like within 90 days — you just need to receive it first; good luck with that!

Of course, no actual merch — neither official nor even counterfeit — is ever shipped. Buyers are left with nothing but empty wallets and compromised data.

Don’t let scammers win the gold

The best way to protect yourself is a combination: Kaspersky Premium will protect you from phishing links and other online threats, while your own attentiveness, awareness of common scams, and knowledge of how to avoid them will tackle the rest.

Don’t buy tickets from unofficial sources. Stick to the official Olympics website.
Use a virtual card with a spending limit for any online purchases — especially if you’re not 100% sure of the site’s legitimacy.
Turn on two-factor authentication wherever possible. This helps keep your accounts and money safe — particularly if you’re worried you might have entered your details on a phishing site. By the way, you can store 2FA tokens in Kaspersky Password Manager.
Be wary of gifts from strangers. Getting 48GB of free internet sounds great but it really is too good to be true.
Follow our Telegram channel to stay up to date on the latest cybersecurity news.

Kaspersky official blog – ​Read More

SocGholish Malware Exploits BOINC Project for Covert Cyberattacks

The JavaScript downloader malware known as SocGholish (aka FakeUpdates) is being used to deliver a remote access trojan called AsyncRAT as well as a legitimate open-source project called BOINC.
BOINC, short for Berkeley Open Infrastructure Network Computing Client, is an open-source “volunteer computing” platform maintained by the University of California with an aim to carry out “large-scale

The Hacker News – ​Read More

CISA Says Malicious Hackers are ‘Taking Advantage’ of CrowdStrike Outage

The U.S. cybersecurity agency CISA warned against clicking on suspicious links to prevent email compromise. Cybercriminals are already impersonating CrowdStrike in phishing emails, asking for payment to “fix the CrowdStrike apocalypse.”

Cyware News – Latest Cyber News – ​Read More

China Claims Volt Typhoon was a False Flag Inside Job Conspiracy

Beijing has claimed that the Volt Typhoon attack gang, accused by Five Eyes nations of being a Beijing-backed threat to critical infrastructure, was actually fabricated by the US intelligence community.

Cyware News – Latest Cyber News – ​Read More

Fake CrowdStrike Fixes Target Companies With Malware, Data Wipers

Malicious campaigns have emerged, including one targeting BBVA bank customers with a fake CrowdStrike Hotfix that installs remote access tools. Another attack involves a data wiper distributed under the guise of a CrowdStrike update.

Cyware News – Latest Cyber News – ​Read More

Under-Resourced Maintainers Pose Risk to Africa’s Open Source Push

Many nations see open source software as a great equalizer, giving the Global South the tools necessary for sustainable development. But recent supply chain attacks highlight the need for security.

darkreading – ​Read More