Human trafficking in cybercrime, social media identity theft and more

The Jerich Show Podcast
The Jerich Show Podcast
Human trafficking in cybercrime, social media identity theft and more
Loading
/

In this episode, Erich and Javvad talking about human trafficking related to cybercrime operations, social media account takeovers and more!

 

Stories from the show:

Guilty verdict in the Uber breach case makes personal liability real for CISOs
https://www.csoonline.com/article/3676148/guilty-verdict-in-the-uber-breach-case-makes-personal-liability-real-for-cisos.html

Jury Finds Former Uber CSO Joe Sullivan Guilty of Cover-Up
https://www.govinfosecurity.com/jury-finds-former-uber-cso-joe-sullivan-guilty-cover-up-a-20187 

Twitter post by Whitney Merrill – @wbm312
https://twitter.com/wbm312/status/1577827226196013056 

SUPERSEDING INDICTMENT
https://dd80b675424c132b90b3-e48385e382d2e5d17821a5e1d8e4c86b.ssl.cf1.rackcdn.com/external/sullivansupersedingindictment-dec222021.pdf

Twitter whistleblower tells Senate of ‘egregious’ security failings by company
https://www.theguardian.com/technology/2022/sep/13/twitter-whistleblower-testimony-congress-peiter-zatko 

Hundreds of Indians Reportedly Trafficked to Myanmar by Cybercrime Operations
https://www.irrawaddy.com/news/burma/hundreds-of-indians-reportedly-trafficked-to-myanmar-by-cybercrime-operations.html/amp

Police arrest teen for using leaked Optus data to extort victims
https://www.bleepingcomputer.com/news/security/police-arrest-teen-for-using-leaked-optus-data-to-extort-victims/

An identity scam that has grown in the past 12 months by more than 1,000% – social media account takeover
https://www.idtheftcenter.org/wp-content/uploads/2022/09/2022-Consumer-Impact-Report_V3.4_Final_Linked.pdf

Categories
General Ramblings

Live Hurricane Ian Video and Weather

Here are some links to live hurricane Ian videos and weather info from a weather station in Trinity, Florida (north of Tampa). It should remain pretty calm, but I wanted it here for people that are curious what it’s like this far away.

Video 1 from Trinity:

Video 2 from Trinity:

Weather data in Trinity (note: wind speeds will not be accurate):

https://www.wunderground.com/dashboard/pws/KFLTRINI16?cm_ven=localwx_pwsdash

Video of the Skyway bridge in Tampa:

Categories
Cybersecurity Tech Talk

What is credential stuffing, and why do I care?

Credential stuffing is when known passwords and usernames are used to try to take over online accounts. Recently an organization had almost 200,000 customer accounts compromised like this.

Learn more about it and what to do to protect yourself.

Categories
Cybersecurity Tech Talk

Amazon Scam Text Message – What Actually Happens When You Click?

Have you ever wondered what happens when you click on a link from one of thos Amazon text messages that say your account is suspended? Here I run through one of those so you understand what they are doing.

TLDR; They capture anything you put in the form, login info, social security number, credit card, whatever.

Do not try this at home – This was done from a secure computer that is resistant to viruses. Some of these links CAN try to infect your computer or phone.

An Uber incident, WeTransfer used to spread malware and much more!

The Jerich Show Podcast
The Jerich Show Podcast
An Uber incident, WeTransfer used to spread malware and much more!



Loading





/

In this episode, Erich and Javvad speak about the Uber breach, using WeTransfer to spread malware, UK folks fear that their kids will turn to cybercrime due to the rising cost-of-living, and more.

Stories from the show:

Uber investigating ‘cybersecurity incident’ after report of breach
https://www.reuters.com/business/autos-transportation/uber-investigating-computer-network-breach-nyt-2022-09-16/

Cybercrime Fears for Children as Cost-of-Living Bites
https://www.infosecurity-magazine.com/news/cybercrime-fears-children/

Hackers are using WeTransfer links to spread malware
https://www.msn.com/en-us/news/technology/hackers-are-using-wetransfer-links-to-spread-malware/ar-AA11MEiM

Hackers now use ‘sock puppets’ for more realistic phishing attacks
https://www.bleepingcomputer.com/news/security/hackers-now-use-sock-puppets-for-more-realistic-phishing-attacks/

Hong Kong consumers want right to choose when firms use AI
https://www.zdnet.com/article/hong-kong-consumers-want-right-to-choose-when-firms-use-ai/

Log4j Still a Problem, Credential Stuffing Yeilds 200k Accounts and more!

The Jerich Show Podcast
The Jerich Show Podcast
Log4j Still a Problem, Credential Stuffing Yeilds 200k Accounts and more!



Loading





/

This week, Javvad and Erich discuss the campaign the Lazarus group is using against US energy companies, surveillance camera access for sale, and how credential stuffing compromised almost 200k accounts at North Face. All this and more!

 

Stories from the show:

Cybercriminals Are Selling Access to Chinese Surveillance Cameras
https://threatpost.com/cybercriminals-are-selling-access-to-chinese-surveillance-cameras/180478/

 

200,000 North Face accounts hacked in credential stuffing attack
https://www.bleepingcomputer.com/news/security/200-000-north-face-accounts-hacked-in-credential-stuffing-attack/

 

North Korea’s Lazarus hackers are exploiting Log4j flaw to hack US energy companies
https://techcrunch.com/2022/09/08/north-korea-lazarus-united-states-energy/

 

How the ‘man in black’ was exposed by the Russian women he terrorised

https://www.bbc.com/news/world-europe-62799246

 

Stealthy Coinminers, Ransomware Victims List Over Doubles and More!

The Jerich Show Podcast
The Jerich Show Podcast
Stealthy Coinminers, Ransomware Victims List Over Doubles and More!



Loading





/

In this episode, Javvad and Erich discussa crafty coinminer malware that lays dormant for a while, Okta credential thefts, a huge increase in potential victims of a ransomware attack, and a possible device that allows bad actors to simulate swipes and taps on phones from under a table. 

All this and more!

Accepted the Risk Video:
https://www.youtube.com/watch?v=9IG3zqvUqJY

Stories from the show:

Twilio Hackers Scarf 10K Okta Credentials in Sprawling Supply-Chain Attack
https://www.darkreading.com/remote-workforce/twilio-hackers-okta-credentials-sprawling-supply-chain-attack

Windows malware delays coinminer install by a month to evade detection
https://www.bleepingcomputer.com/news/security/windows-malware-delays-coinminer-install-by-a-month-to-evade-detection/

Individuals affected by vendor ransomware attack reaches 2.7M
https://www.beckershospitalreview.com/cybersecurity/vendor-ransomware-attack-affects-2-7m-healthcare-organizations.html

Hacking device can secretly swipe and tap your smartphone screen
https://www.newscientist.com/article/2335970-hacking-device-can-secretly-swipe-and-tap-your-smartphone-screen/

Categories
Cybersecurity Quotes

Phishing-as-a-service platform ‘Robin Banks’ targets financial firms

I was fortunate to to be quoted in this article about the Phishing as a Service group ‘Robin Banks’. Check it out

https://www.scmagazine.com/analysis/email-security/phishing-as-a-service-platform-robin-banks-targets-financial-firms

Categories
Cybersecurity

Paralyzed By Paranoia

I work in the interesting field of cybersecurity and have for quite some time. Throughout the years, I have found myself increasingly skeptical about people and organizations. It could just be my old age, after all my goal in retirement is to spend my days sitting on my front porch telling kids to get off my lawn, but it could be something else. In this line of work, I hear about scams and see the ugly side of the digital world quite often, and I think it has impacted me.

Recently, my wife and I decided to buy some land. We have been looking for years, but had quit looking due to prices. Then, this opportunity just showed up out of nowhere (well on Facebook Marketplace), and next thing I know, we are making an offer. The people we bought the property from will still be our neighbors and he is a retired real estate pro, so the decision to do the sale without realtors on both sides made sense financially, however I was still nervous about it. His daughter, a current realtor, was kind enough to write up contracts and point us at a good title company, so it wasn’t like we were totally blind here. Over the course of a couple of weeks while we worked through some financial stuff, we spent some weekends doing some clean up at the property with the sellers permission and we got to know each other pretty well. In the back of my mind, I still had this gut-wrenching fear that things would go wrong.

When it was time to close, we met up with the title folk and signed the papers, then we had to transfer funds. Now this was a cash deal, so it was a matter of wiring money from our bank accounts to the title company, however I have heard so many stories about wire transfer fraud, that I was nearly sick with nerves when it came time to do the transfers.

I have no reason not to trust the seller. I looked up his name on the next-door property and the one we were buying, and they were the same (another scam is selling property you don’t own). I’ve seen his ID and I know that he lives in that house, yet I am still nervous almost to the point of paralysis while we wait for the property deed to be recorded and show up officially online (this can take several weeks right now).

So, what is the point of this story? Well, it’s this, it is not bad to be cautious these days as scams are everywhere. There are many that originate on social media and it is important to apply reason when looking at things, however it is important not to let paranoia steal the joy from what should be a happy event. Do your due diligence and remember that deals that seem too good to be true, are.

2 tips for Facebook Marketplace:

  • Ads that include an alternate email address to contact, often saying something like ‘This is my parents, which I listed for them’ followed by that other email address, is usually fake. They are simply getting you to communicate off Facebook. Ads that have unrealistic prices, are fake. They want to open a conversation with you and will often attempt to get you to leave a deposit, or will tell you they are sending a code from Google Voice to prove you are ‘not a scammer’. The code is actually from Google Voice, but is being used so they can associate a Google Voice phone number with your cell phone, and use it for scams.
Extreme low price, vacation mode and an alternative email address. This one has it all
They have clearly taken over this account and are spamming all across the country as quickly as possible. Facebook can track when you glanced at an advertisement and feed you ads for years, but can’t seem to figure this trick out
  • Ads that have unrealistic prices, are fake. They want to open a conversation with you and will often attempt to get you to leave a deposit, or will tell you they are sending a code from Google Voice to prove you are ‘not a scammer’. The code is actually from Google Voice, but is being used so they can associate a Google Voice phone number with your cell phone, and use it for scams. These also seem to favor lines such as  ‘just serviced 3 days ago’ and ‘no rust, no dents, original paint, no accidents and clean title’, almost verbatim across ads
This is only about $10k under blue book, and has nothing at all wrong with it, it was just serviced after all. Totally not legit.
Same pattern on spamming across the country from a taken over legitimate account.

On the Road, Twitter is a Mess, French Hospital Down, and More

The Jerich Show Podcast
The Jerich Show Podcast
On the Road, Twitter is a Mess, French Hospital Down, and More



Loading





/

In this episode, Erich is on the road in Dallas for the Podcast Movement conference, but him and Javvad still take the time out to discuss some major stories on cybersecurity this week. 

Stories from the show:

LastPass developer systems hacked to steal source code
https://www.bleepingcomputer.com/news/security/lastpass-developer-systems-hacked-to-steal-source-code/

Twitter whistleblower alleges ‘egregious deficiencies’ in security measures
https://www.theguardian.com/technology/2022/aug/23/twitter-whistleblower-peiter-zatko-mudge-security

Cyber attackers disrupt services at French hospital, demand $10 million ransom
https://www.france24.com/en/europe/20220823-cyber-attackers-disrupt-services-at-french-hospital-demand-10-million-ransom

Researchers Find Counterfeit Phones with Backdoor to Hack WhatsApp Accounts
https://thehackernews.com/2022/08/researchers-find-counterfeit-phones.html