Cyber Security Today, August 29, 2022 – Door Dash hacked, Facebook ready to face the music and Sephora agrees to pay a $1.2 million penalty

Spread the love

Door Dash hacked, Facebook ready to face the music and Sephora agrees to pay a $1.2 million penalty.

Welcome to Cyber Security Today. It’s Monday August 29th, 2022. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com.

 

The text-based phishing campaign against Twilio and CrowdStrike users I told you about last week continues to have a wider impact. Food delivery service Door Dash has acknowledged personal information of what it says is a small number of its users was recently stolen. How did it happen? According to the TechCrunch news site, the hackers got into Door Dash’s IT system after stealing the usernames and passwords of Twilio employees. Those credentials were then used to access some of Door Dash’s internal tools. Twilio and CrowdStrike staff are getting text messages with links to phony websites that mimic their companies’ login authentication pages. If they click on the links and log in the hackers get their usernames and passwords. The names, email addresses, delivery addresses and phone numbers of some Door Dash users were stolen. In addition, the hackers got the last four digits of payment cards of an unnamed number of people,

The last chapter of the Facebook-Cambridge Analytica scandal may be coming to an end. According to the Associated Press news agency, Facebook’s parent company, Meta Platforms, has reached a tentative settlement in a class action privacy lawsuit launched by American and British Facebook users. Terms of the settlement haven’t been disclosed in court documents. However, a San Francisco court has been asked to allow a 60-stay of proceedings in the suit while lawyers finalize the deal.

See also  The Atlanta Reign is getting slammed on social media after signing controversial streamer

The four-year-old lawsuit alleges that the personal information of Facebook users was released to third parties, including Cambridge Analytica, without their consent. That now-defunct consulting company had data on 87 million Facebook users, collected when some 300,000 users responded to questions about their digital life in an app. Unknown to that group of people, the app also collected data on their Facebook friends. The data was used in a number of political campaigns in the U.S. and the United Kingdom spawning an uproar in those countries and in Canada. In 2019 Facebook agreed to pay US$100 million to settle allegations by the U.S. Securities and Exchange Commission that it knew for two years Facebook data had been misued by Cambridge Analytica and didn’t tell users or the public.

Meanwhile, California says cosmetics retailer Sephora has agreed to pay US$1.2 million to settle allegations the company violated its tough Consumer Privacy Act by not telling consumers it was selling their personal information to third parties. Sephora allowed third parties like marketing firms to install cookies on their website and in their app to track customers’ actions. According to NBC News, Sephora says this isn’t an objectionable “sale” of data. It’s common to allow the installation of cookies to provide consumers more personalized shopping and ads, the company said.

See also  Twitter Updates Violent Speech Policy to Add More Elements

One of the most common commercial tools used by threat actors is called Cobalt Strike. Actual or illegally copied versions of the tool are used by threat actors for maintaining access to their command and control servers. But IT defensive systems are increasingly looking for signs of unwanted Cobalt Strike Beacons on their networks. So threat actors are turning to a new tool called Sliver. In a column last week Microsoft pointed out that Sliver is either being used as a replacement for or in conjunction with Cobalt Strike. Cybersecurity teams should be scanning their networks for signs of Sliver including unique HTTP headers, JARM hashes and evidence of process injection. They should also turn on Windows’ network protection, filter email to block messages with malware that can lead to downloading of Sliver and CrowdStrike, and make sure employees use multifactor authentication to protect against stolen credentials

There’s a link to the detailed Microsoft report here.

Atlassian has found a critical vulnerability in the on-premise versions of its Bitbucket Server and Data Center. This is a Git-based code hosting and collaboration tool used by developers using Atlassian’s Jira and Trello applications. All on-premise instances running any versions between 7 and 8.3.0 inclusive must be patched.

See also  Lightning Network Whitepaper Publication Date Explained

Finally, experienced privacy-minded individuals worried about email trackers hidden in links and images in email they get, or who want to hide their email address, can consider a service from those behind the DuckDuckGo browser. The organization has been testing an Email Protection service for some time. It’s a free email forwarding service that removes some hidden email trackers. Now that beta test is being opened to everyone. You can use Email Protection with your current email provider. The service also allows users to create a private Duck Address when you enter an email address in a form for signing up to newsletters and such. Remember, it’s still a beta service.

That’s it for now Remember links to details about podcast stories are in the text version at ITWorldCanada.com.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

!function(f,b,e,v,n,t,s)
{if(f.fbq)return;n=f.fbq=function(){n.callMethod?
n.callMethod.apply(n,arguments):n.queue.push(arguments)};
if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version=’2.0′;
n.queue=[];t=b.createElement(e);t.async=!0;
t.src=v;s=b.getElementsByTagName(e)[0];
s.parentNode.insertBefore(t,s)}(window,document,’script’,
‘https://connect.facebook.net/en_US/fbevents.js’);
fbq(‘init’, ‘1348048558951275’);
fbq(‘track’, ‘PageView’);

Source link

Neon-lit text graphic reading "social schmuck" with a retro style.
Website | + posts
  • Related Posts

    Java Burn Review – Drink coffee and lose weight

    Spread the love

    Spread the loveJava Burn Review This revolutionary dietary supplement, designed to turbocharge your coffee routine, sets a new weight loss and fat-burning standard. With a carefully selected blend of all-natural…

    Read more

    Pocket Battle Gift Codes: Exclusive List of Rewards

    Spread the love

    Spread the love Pocket Battle offers an immersive gaming experience as a captivating Pokemon parody game, showcasing a diverse collection of creatures from all generations, including the elusive legendary Pokemon.…

    Read more

    You Missed

    Java Burn Review – Drink coffee and lose weight

    Java Burn Review – Drink coffee and lose weight

    Pocket Battle Gift Codes: Exclusive List of Rewards

    Pocket Battle Gift Codes: Exclusive List of Rewards

    Debbie Nelson, Eminem’s Mother, Dies at 69

    Debbie Nelson, Eminem’s Mother, Dies at 69

    Cyber Monday Deals on Headphones and TVs Still Available

    Cyber Monday Deals on Headphones and TVs Still Available

    Election Integrity Efforts: Meta Aims to Smooth Tensions with Trump

    Election Integrity Efforts: Meta Aims to Smooth Tensions with Trump

    Pete Hegseth Married? Discover His Current and Ex-Wives

    Pete Hegseth Married? Discover His Current and Ex-Wives

    Amazon Music Launches Its Own Spotify Wrapped Feature

    Amazon Music Launches Its Own Spotify Wrapped Feature

    Rihanna Fans Call Her Out for Cookie Monster Lookalike Style

    Rihanna Fans Call Her Out for Cookie Monster Lookalike Style

    Enron’s Potential Comeback as a Crypto Company

    December 3, 2024: Tomarket Daily Combo Highlights

    December 3, 2024: Tomarket Daily Combo Highlights

    java burn weight loss with coffee

    This will close in 0 seconds