Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
New Phishing Attack Targets 550M Email Users Worldwide
Newest First  |  Oldest First  |  Threaded View
ThomasMaloney
ThomasMaloney,
User Rank: Apprentice
12/21/2018 | 2:23:32 AM
Recognize and avoid
This really is no surprise to me. There are billions of people around the world. Why should a mere 550 million be a surprise? At the end of the day, there are so many of these hacks and scams and fake emails going around that if you sneeze, you'll probably receive 3 while you were at it. We just need to stay vigilant and informed so that we're able to recognize them when they hit us!
CameronRobertson
CameronRobertson,
User Rank: Moderator
12/13/2018 | 10:28:20 PM
Too easy
Sadly, I have to admit that I have personally taken online quizzes too just for fun. Some of them even offered rewards which are not that great but hey, who wouldn't want a free gift just for taking an easy 5-minute quiz? However, we need to be on our toes at all times especially for quizzes that ask for our credit card details. If we are not expected to pay for anything, why would they want our credit card details then? Look out for such factors to safeguard ourselves.
RyanSepe
RyanSepe,
User Rank: Ninja
4/30/2018 | 9:24:09 PM
Re: online quiz or contest
True enough, but I have been known to search for a coupon code or two.... Anything that actively searches for you can turn into trouble.
Dr.T
Dr.T,
User Rank: Ninja
4/29/2018 | 6:00:11 PM
Re: Coupon lure is emblematic of broader concern
As data is shared, sold, stolen, inherited and otherwise obtained from a variety of sources and over time It becomes more valuable. Now it is noy only the raw data but also the relation, that is invaluable.
Dr.T
Dr.T,
User Rank: Ninja
4/29/2018 | 5:57:59 PM
Re: Coupon lure is emblematic of broader concern
The real threat from casually proffered data I woudl agree, that is the one actionable and most impactful.
Dr.T
Dr.T,
User Rank: Ninja
4/29/2018 | 5:55:57 PM
Re: Coupon lure is emblematic of broader concern
enterprise might invest large sums to attain data of a similar nature shouldn't surprise us. When facebook says we do not sell user data, they play with the wording, of course they sell data, that is what ads are about, they would not get any ads if they did not have the data
Dr.T
Dr.T,
User Rank: Ninja
4/29/2018 | 5:53:06 PM
Re: Coupon lure is emblematic of broader concern
others value data which we don't That is true, we give ot away for free to facebook , google and otehrs without any concern what so ever.
Dr.T
Dr.T,
User Rank: Ninja
4/29/2018 | 5:51:38 PM
online quiz or contest
online quiz or contest are good way of gettign people engage and trapped. My rule is: I do not need any coupon or discount on anyting from the Internet.
BrianN060
BrianN060,
User Rank: Ninja
4/26/2018 | 1:19:38 PM
Coupon lure is emblematic of broader concern
For decades, retailers have used "with your card" coupons to generate data about their customers (who doesn't have a wallet, keychain or smartphone full of "membership cards"?).  The key takeaways with these incentives are: that others value data which we don't, and that we have come to accept these forms of coercion to participate.  That a criminal enterprise might invest large sums to attain data of a similar nature shouldn't surprise us. 

Also, the enticements to participate in social media services, such as Facebook, are of a similar nature, and serve the same purpose: to leave us little choice but to take the bait.  After all, how many can afford to pay a third more at the grocery store, or not to participate in a "Facebook only" web event? 

The data gathered, even if we are aware of the extent, never seems to be anything we should worry about - and taken as individual packets, utilized by the original entity, perhaps it isn't.  The real threat from casually proffered data is when it is processed in combination with data from a number of sources and instances.  As data is shared, sold, stolen, inherited and otherwise obtained from a variety of sources and over time, the value of this "information ore" to someone we never met far exceeds the cost of collection. 

At the end of the day, does it really matter if the organization or website used to obtain this "trivial" data is legitimate or not?  Data has no loyalty

 


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Incorporating a Prevention Mindset into Threat Detection and Response
Threat detection and response systems, by definition, are reactive because they have to wait for damage to be done before finding the attack. With a prevention-mindset, security teams can proactively anticipate the attacker's next move, rather than reacting to specific threats or trying to detect the latest techniques in real-time. The report covers areas enterprises should focus on: What positive response looks like. Improving security hygiene. Combining preventive actions with red team efforts.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-31650
PUBLISHED: 2022-05-25
In SoX 14.4.2, there is a floating-point exception in lsx_aiffstartwrite in aiff.c in libsox.a.
CVE-2022-31651
PUBLISHED: 2022-05-25
In SoX 14.4.2, there is an assertion failure in rate_init in rate.c in libsox.a.
CVE-2022-29256
PUBLISHED: 2022-05-25
sharp is an application for Node.js image processing. Prior to version 0.30.5, there is a possible vulnerability in logic that is run only at `npm install` time when installing versions of `sharp` prior to the latest v0.30.5. If an attacker has the ability to set the value of the `PKG_CONFIG_PATH` e...
CVE-2022-26067
PUBLISHED: 2022-05-25
An information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to arbitrary file read. An attacker can send a sequence of requests to trigger this vulnera...
CVE-2022-26077
PUBLISHED: 2022-05-25
A cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications functionality of Open Automation Software OAS Platform V16.00.0112. A targeted network sniffing attack can lead to a disclosure of sensitive information. An attacker can sniff networ...