PrivacyDigest · @PrivacyDigest
310 followers · 1291 posts · Server mas.to

Moves to Counter New and Repeat Account Takeovers

The company is adding new tools as bad actors use ChatGPT-themed lures and mask their infrastructure in an attempt to trick victims and elude defenders.

wired.com/story/meta-attacker-

#chatgpt #accounttakeover #malware #meta

Last updated 2 years ago

Stephen Lawton · @StephenLawton
18 followers · 10 posts · Server federated.press

Bank customers have expectations that money in their checking accounts are safe from . Sometimes their FDIC-insured funds aren't so safe. Here's a cautionary tale in @DarkReading: When Banking Laws Don't Protect Consumers From

darkreading.com/edge-articles/

#cyberattacks #cybertheft #accounttakeover

Last updated 2 years ago

· @Capros
14 followers · 27 posts · Server sfba.social

Bank customers have expectations that money in their checking accounts are safe from . Sometimes their FDIC-insured funds aren't so safe. Here's a cautionary tale in @DarkReading: When Banking Laws Don't Protect Consumers From

darkreading.com/edge-articles/

#cyberattacks #cybertheft #accounttakeover

Last updated 2 years ago

DHd2023 · @DHdKonferenz
248 followers · 51 posts · Server fedihum.org

📢 durch die Stipendiat:innen der
Wir sind gespannt und freuen uns!

#accounttakeover #DHd2023

Last updated 2 years ago

Tech news from Canada · @TechNews
284 followers · 7290 posts · Server mastodon.roitsystems.ca
IT News · @itnewsbot
2914 followers · 250407 posts · Server schleuss.online

How to Protect Yourself from Twitter’s 2FA Crackdown - Twitter is disabling SMS-based two-factor authentication. Switch to these alternatives to... - wired.com/story/twitter-2fa-sm /securityadvice /securitynews /privacy

#accounttakeover #security

Last updated 2 years ago

TribalCyberSecurity · @tribalcyber
27 followers · 11 posts · Server infosec.exchange
nieldk :verified: 💻 · @nieldk
186 followers · 274 posts · Server infosec.exchange

This is still going on. Just helped s friend recover from this attack. USE MFA! Everywhere! And DO NOT, ever, send ANY codes to ANYONE!

#scam #accounttakeover

Last updated 2 years ago

Zate 🦘🇦🇺 · @zate
486 followers · 968 posts · Server infosec.exchange

It looks like we have another round of the running in circles arm waving, so I will add here what I just replied to one of the threads.

So, generally, many, many websites use your email address to log you in. some use a username, but it's more the norm to use your email.

The same email that has been in countless leaks for years and years is on countless "consolidated" lists etc., and is likely run against all manner of websites as part of the standard billions-long email stuffing lists.

Given that so many websites have email enumeration issues because it is sort of hard to both allow a user to lookup if their email exists or not when registering and make it not able to tell the same thing to a massively distributed, slow attack coming from residential IP's .. then they are going to know quickly if you are on a site.

They likely don't care. The list of URLs your email is associated with is unlikely to give any of these extensive operations any advantage. They already factor in that knowledge.

So then, I assume you're going to jump ship to some other password provider, of which there are many. Of which, just about all are, or will be, under attack at some point. If you think you are going to jump to a provider who can protect your stuff 100%, then that's funny.

I know, I know, we can/should all host our passwords on our self-hosted service or only locally in our systems, and sure, that likely does provide a certain measure of security, I guess? But I already do that. It's an encrypted block here locally that I ask LastPass to store and backup.

For this kind of thing, you must factor in Shannon's maxim / Kerckhoffs's principle in that the enemy knows the system. Assume they can get to the encrypted blob, and assume they can know your username on a site. The controls still hold secure in this case.

#lastpass #infosec #cybersecurity #accounttakeover #passwords

Last updated 2 years ago

Mufasa · @ne1for23
349 followers · 3432 posts · Server mastodon.sdf.org

Meta reportedly disciplined or fired more than two dozen workers for taking over Facebook user accounts

Meta Platforms fired or disciplined dozens of employees and contractors over the course of the last year for compromising Facebook user accounts, according to reporting by The Wall Street Journal.

In some cases, the Journal wrote, the contractors, working for Allied Universal, accepted bribes to take control of user accounts.


cnbc.com/2022/11/17/meta-disci

#meta #facebook #accounttakeover #bribes

Last updated 2 years ago

Ken · @Khansen
8 followers · 6 posts · Server mastodon.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

Popular TP-Link Family of Kasa Security Cams Vulnerable to Attack - Researcher warns the highly-rated Kasa family of security cameras have bugs that gives hackers acc... more: threatpost.com/popular-tp-link -linkpatch -link

#ato #kasa #kc200 #hacks #securitycam #tp #kasacamkc120 #consumercamera #accounttakeover #vulnerabilities #kasasmartkc300s2system

Last updated 5 years ago