Webroot Weekly Highlights - 9/21/2018

  • 21 September 2018
  • 1 reply
  • 483 views

Userlevel 7
Badge +48
This is a weekly highlight of the best articles and news going on in the Community.
 
See any stories that catch your interest? What would you like to see in the future? Let us know in the comments below!
 
 

 
 
 
 
Local Denver woman's Instagram account hacked and held for ransom
 
Cassie Gallegos Moore, a Denver based travel blogger has recently seen her Instagram account hacked and held for ransom. 
 
Talking with Denver's FOX31, Nick Emanuel (or @ as you all know him here on the Webroot Community) explains: 
 
"It's almost like magic tricks. They want you to believe in that email," Emanuel said. "If bad guys can make money, they're going to continue to do this, and unfortunately there isn't an end to it." 
 
See the full article here
_____________________________________________________
 
6 sure signs someone is phishing you—besides email
 
There are several common and, unfortunately, frequently successful avenues of attack that cybercriminals can use to part you from your personal contact and financial information. These phishing attack methods include email, phone calls, corrupted software or apps, social media, advertisements, and even direct SMS (text) messages.
 
See the full article here.
____________________________________________________
 
Ask a Security Expert: 'When End-User Security Awareness Fails, What’s Next?
 
According to Gareth Brown, director of business IT security and support firm Sytec, this is one of the most common questions he receives from clients. Unfortunately, he has a good point. Employees are going to click on things they shouldn’t — despite what businesses do to prevent it.
 
See the full article here.
_____________________________________________________
 
NewEgg cracked in breach, hosted card-stealing code within its own checkout
 
 
Details of the breach were reported by the security research firms RiskIQ (which exposed the code behind the British Airways attack) and Volexity Threat Research today. The attack was shut down by NewEgg on September 18, but it appears to have been actively siphoning off payment data since August 16, according to reports from the security researchers.   
See the full article here.
_____________________________________________________
 
 

1 reply

Userlevel 4
I too see this several times a day. Its scary to think that a lot of time and hard work can be gone in an instant in this digital age.
I think you guys are trying to implement this already with your Script Shield Beta but the link hijacks that are happening with scareware/social hacks/browser lockers telling people "Your computer is infected and if you don't call this fake number all your stuff will be gone" should be addressed.
I would also like a lot of the adware/fake driver programs and other potentially unwanted programs/applications to be addressed. I was told before that its hard to decide if these can/should be blocked due to multiple things like legal reasons but they use a lot of third party drivers including network drivers that can be backdoored or easily manipulated with program integration techniques.

Reply