Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
New Phishing Attack Targets 550M Email Users Worldwide
Newest First  |  Oldest First  |  Threaded View
ThomasMaloney
50%
50%
ThomasMaloney,
User Rank: Apprentice
12/21/2018 | 2:23:32 AM
Recognize and avoid
This really is no surprise to me. There are billions of people around the world. Why should a mere 550 million be a surprise? At the end of the day, there are so many of these hacks and scams and fake emails going around that if you sneeze, you'll probably receive 3 while you were at it. We just need to stay vigilant and informed so that we're able to recognize them when they hit us!
CameronRobertson
50%
50%
CameronRobertson,
User Rank: Moderator
12/13/2018 | 10:28:20 PM
Too easy
Sadly, I have to admit that I have personally taken online quizzes too just for fun. Some of them even offered rewards which are not that great but hey, who wouldn't want a free gift just for taking an easy 5-minute quiz? However, we need to be on our toes at all times especially for quizzes that ask for our credit card details. If we are not expected to pay for anything, why would they want our credit card details then? Look out for such factors to safeguard ourselves.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/30/2018 | 9:24:09 PM
Re: online quiz or contest
True enough, but I have been known to search for a coupon code or two.... Anything that actively searches for you can turn into trouble.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/29/2018 | 6:00:11 PM
Re: Coupon lure is emblematic of broader concern
As data is shared, sold, stolen, inherited and otherwise obtained from a variety of sources and over time It becomes more valuable. Now it is noy only the raw data but also the relation, that is invaluable.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/29/2018 | 5:57:59 PM
Re: Coupon lure is emblematic of broader concern
The real threat from casually proffered data I woudl agree, that is the one actionable and most impactful.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/29/2018 | 5:55:57 PM
Re: Coupon lure is emblematic of broader concern
enterprise might invest large sums to attain data of a similar nature shouldn't surprise us. When facebook says we do not sell user data, they play with the wording, of course they sell data, that is what ads are about, they would not get any ads if they did not have the data
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/29/2018 | 5:53:06 PM
Re: Coupon lure is emblematic of broader concern
others value data which we don't That is true, we give ot away for free to facebook , google and otehrs without any concern what so ever.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/29/2018 | 5:51:38 PM
online quiz or contest
online quiz or contest are good way of gettign people engage and trapped. My rule is: I do not need any coupon or discount on anyting from the Internet.
BrianN060
50%
50%
BrianN060,
User Rank: Ninja
4/26/2018 | 1:19:38 PM
Coupon lure is emblematic of broader concern
For decades, retailers have used "with your card" coupons to generate data about their customers (who doesn't have a wallet, keychain or smartphone full of "membership cards"?).  The key takeaways with these incentives are: that others value data which we don't, and that we have come to accept these forms of coercion to participate.  That a criminal enterprise might invest large sums to attain data of a similar nature shouldn't surprise us. 

Also, the enticements to participate in social media services, such as Facebook, are of a similar nature, and serve the same purpose: to leave us little choice but to take the bait.  After all, how many can afford to pay a third more at the grocery store, or not to participate in a "Facebook only" web event? 

The data gathered, even if we are aware of the extent, never seems to be anything we should worry about - and taken as individual packets, utilized by the original entity, perhaps it isn't.  The real threat from casually proffered data is when it is processed in combination with data from a number of sources and instances.  As data is shared, sold, stolen, inherited and otherwise obtained from a variety of sources and over time, the value of this "information ore" to someone we never met far exceeds the cost of collection. 

At the end of the day, does it really matter if the organization or website used to obtain this "trivial" data is legitimate or not?  Data has no loyalty

 


Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11107
PUBLISHED: 2020-04-02
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution.
CVE-2020-11444
PUBLISHED: 2020-04-02
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
CVE-2020-7617
PUBLISHED: 2020-04-02
ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.
CVE-2020-8835
PUBLISHED: 2020-04-02
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the intr...
CVE-2020-8423
PUBLISHED: 2020-04-02
A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the configuration of the Wi-Fi network.