|
Several companies from the automotive industry were targeted by BitPaymer ransomware operators during August, in attacks that used an Apple zero-day vulnerability impacting the Apple Software Update service bundled with iTunes and iCloud for Windows. Apple Software Update is an updater service that gets automatically installed computers when users install iTunes or iCloud for Windows or when using Boot Camp Assistant to install Windows on a Mac. This service is designed to keep all Apple apps up to date on a Windows device, as well as to deliver software and security updates to Windows installations running on Macs computers. BitPaymer's operators found an unquoted path vulnerability within Apple Software Update for Windows which allowed them to launch their ransomware payload on the devices of any target that used iTunes or iCloud, as well as on those where they were previously uninstalled since the updater service is not also removed automatically. As part of their attacks, the BitPaymer operators executed a previously dropped ransomware payload instead of the Apple Software Update binary by abusing the zero-day. They did this by taking advantage of the fact that Apple's developers did not surround the service binary's execution path with quotes. This made it possible for them to launch the BitPaymer ransomware dropped in the form of a binary named 'Program' without an extension. Given that the Apple Software Update binary is signed by Apple, using it to launch the ransomware payload also enabled them to evade detection, fooling the behavioral engine of anti-malware solutions present on the compromised systems. Learn more by visiting OUR FORUM. Using a credential stuffing attack, an unauthorized person was able to gain access to a TransUnion Canada web portal and use it to pull consumer credit files. BleepingComputer has learned that starting last week TransUnion Canada began sending out data security incident notifications via postal mail to consumers whose information was exposed in a credential stuffing attack. These notifications state that an unauthorized user utilized a TransUnion business portal to perform credit file lookups between June 28th and July 11th, 2019. The attacker was able to gain access to the portal using a TransUnion customer's account that was stolen in a credential stuffing attack. Once the unauthorized user gained access to the TransUnion portal, they could perform credit searches using a consumer's name, address, DOB, or Social Insurance Number ("SIN). If the correct information was entered, a credit file would be shown that contains the consumer's name, date of birth, current and past addresses, and information related to the credit, such as loan obligations, amounts owed, and payment history. Actual account numbers, though, would not be included in the report. While this is not a data breach in the sense that the hacker was able to gain access to the TransUnion's full database, it is still concerning as they would have been able to query for a consumer's credit file. As the information exposed in this security incident could easily be used by the attacker for identity theft, it is strongly recommended that all affected users monitor their credit history for fraudulent activity or new unauthorized lines of credit. Learn more by visiting OUR FORUM. The beauty of announcing a device that won't launch for a year is that you don't have to toss out the specs list or inner workings for the wolves to tear apart. You can build excitement first. This is what Microsoft did last week with the Surface Duo, a dual-screen device that also happens to be the company's first phone in years -- even though Microsoft says the Duo isn't actually a phone. We know the gist of the product -- an Android phone (which Microsoft denies is actually a phone) that essentially doubles your screen space to take on foldable phone design. Although we have to wait until "holiday 2020" to meet the Duo, Microsoft has certainly created a sense of hype by leaping back into the game at a time when phones that double the available screen space are seen as the next big thing in phone design. A quick flash of the Surface Duo taken from an executive's pocket, a 2-minute video and a few minutes with a non-functioning prototype were our only glimpses at the device. Microsoft's well-orchestrated teaser gives us only fragments of detail, leaving us to wonder if the Duo will come together as a device that could truly take on foldable phones like the Galaxy Fold and upcoming foldable Motorola Razr. Foldable phones aren't expected to be cheap. Samsung sells its Galaxy Fold for $1,980, and the (delayed) Huawei Mate X will go for the equivalent of $2,600. While the Surface Duo won't be a foldable phone, it achieves about the same goal by doubling up on the given screen space you have to work with for watching videos, reading, typing, and playing games. This extra screen space is the real benefit, and the Galaxy Fold proves what a convenience it is. It's a convenience you're also expected to pay for. Follow this and lots more on OUR FORUM. |
Latest Articles
|


