{"id":17955,"date":"2020-03-17T20:37:27","date_gmt":"2020-03-18T04:37:27","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2020\/03\/17\/news-11688\/"},"modified":"2020-03-17T20:37:27","modified_gmt":"2020-03-18T04:37:27","slug":"news-11688","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2020\/03\/17\/news-11688\/","title":{"rendered":"Elite Hackers Are Using Coronavirus Emails to Set Traps"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5e6c33a3c0b1110009a4db31\/master\/pass\/Security_roundup-dv1187002.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lily Hay Newman| Date: Sat, 14 Mar 2020 14:00:00 +0000<\/strong><\/p>\n<p class=\"byline bylines__byline byline--author\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\"><span class=\"byline__name byline--with-bg\"><a class=\"byline__name-link\" href=\"\/contributor\/lily-hay-newman\">Lily Hay Newma<span class=\"link__last-letter-spacing\">n<\/span><\/a><\/span> <\/span><\/p>\n<p>In a week dominated by news of the <a href=\"http:\/\/www.wired.com\/tag\/coronavirus\">global Covid-19 pandemic<\/a>, companies scrambled to find ways of securely supporting employees <a href=\"https:\/\/www.wired.com\/story\/how-to-work-from-home-without-losing-your-mind\/\">working from home<\/a>. But the challenges are extensive, and in sectors like critical infrastructure and government defense, there&#x27;s <a href=\"https:\/\/www.wired.com\/story\/high-stakes-security-set-ups-making-remote-work-impossible\/\">often no safe way<\/a> for workers to be remote.<\/p>\n<p>Meanwhile, President Donald Trump suggested (not for the first time!) on Tuesday that a wall at the southern border with Mexico would help stop the spread of the novel coronavirus into the US. This is <a href=\"https:\/\/www.wired.com\/story\/border-wall-wont-stop-coronavirus\/\">not true for a number of reasons<\/a>. And Washington state made a <a href=\"https:\/\/www.wired.com\/story\/coronavirus-washington-state-primary-2020\/\">good case for vote-by-mail infrastructure<\/a> when its Democratic primary went smoothly on Tuesday in spite of the region&#x27;s major Covid-19 outbreak. The majority of voters send in their ballots rather than appearing at a polling place in person.<\/p>\n<p>In other news, there were some small mercies in the security world this week as the certificate authority Let\u2019s Encrypt <a href=\"https:\/\/www.wired.com\/story\/lets-encrypt-internet-calamity-that-wasnt\/\">engineered a massive course-correction<\/a> after discovering a bug that could have broken millions of websites across the web. And researchers found that a staggering <a href=\"https:\/\/www.wired.com\/story\/most-medical-imaging-devices-run-outdated-operating-systems\/\">83 percent of medical imaging devices<\/a> run on operating systems that are too old to receive security patches from their developers\u2014exposing the machines and healthcare networks more broadly to potential attack.<\/p>\n<p>But wait, there&#x27;s more! Every Saturday we round up the security and privacy stories that we didn\u2019t break or report on in depth but think you should know about. Click on the headlines to read them, and stay safe out there.<\/p>\n<p>Phishing scams have been taking advantage of fears about the spread of novel coronavirus to <a href=\"https:\/\/www.wired.com\/story\/coronavirus-phishing-scams\/\">craft Covid-19-themed emails for weeks<\/a>. Now, more sophisticated state sponsored hackers are getting in on the game. This week, the Chinese firm QiAnXin spotted Russian hackers\u2014possibly affiliated with the groups <a href=\"https:\/\/www.wired.com\/story\/sandworm-kremlin-most-dangerous-hackers\/\">Sandworm<\/a> and <a href=\"https:\/\/www.wired.com\/tag\/fancy-bear\/\">Fancy Bear<\/a>\u2014sending phishing emails laced with malicious document attachments to Ukrainian targets. The emails, which claimed to come from Ukraine&#x27;s Center for Public Health of the Ministry of Health, came amidst a larger disinformation campaign that stoked fear about the spread of Covid-19 in Ukraine and resulted in riots.<\/p>\n<p>Meanwhile, the Vietnamese security firm VinCSS detected a high volume of novel coronavirus-related phishing emails over the last two weeks attributed to government hackers. The emails include a malicious attachment that purports to contain information about Covid-19 from the Vietnamese prime minister. Another campaign attributed to Chinese actors by researchers at Check Point targeted victims in Mongolia. North Korean hackers were also spotted targeting South Korea with phishing attacks at the end of February. The campaigns seemed to target government officials with malware-tainted documents.<\/p>\n<p>As always, be vigilant for scams in times of stress and uncertainty. Here&#x27;s <a href=\"https:\/\/www.wired.com\/2017\/03\/phishing-scams-fool-even-tech-nerds-heres-avoid\/\">how to spot a phishing attempt<\/a> and keep yourself safe.<\/p>\n<p>The world of digital ads often feels like a lawless free-for-all\u2014and the story of Daniel Yomtobian\u2019s empire of allegedly malicious Chrome extensions isn&#x27;t helping the industry&#x27;s image. Yomtobian is the Los Angeles-based founder and CEO of Advertise.com Inc, an ad network and marketing analytics firm. But an investigation by <em>BuzzFeed News,<\/em> conducted in conjunction with the cybersecurity firm White Ops and traffic analysis group DoubleVerify, charges that Yomtobian is behind a pernicious Chrome extension known as MyPDF, which Google repeatedly removed. In fact, the analysis appears to trace more than 60 malicious extensions back to Yomtobian. &quot;To be clear, I and Advertise.com have never operated an &#x27;ad fraud traffic scheme,&#x27;&quot; he told <em>BuzzFeed News<\/em>. &quot;We have never generated &#x27;fraudulent traffic.&#x27;&quot; The findings, though, paint a picture of the muddled digital ad ecosystem and its problematic incentives.<\/p>\n<p>Comcast customers can pay a few dollars per month extra on their bills to keep their numbers unlisted. Last week, the company accidentally published the personal data of 200,000 customers\u2014all of whom had specifically paid for extra privacy. The mistake exposed names, phone numbers, and addresses. The company has removed the data and is offering an $100 credit to each impacted individual. Comcast also says that customers can change their phone numbers for free, though that is typically no easy feat. Incredibly, this is not the first time Comcast has made this mistake. In 2012, the company did essentially the same thing and ended up paying a $33 million settlement.<\/p>\n<p>The controversial facial recognition service Clearview AI, which aims to identify people using a database of photos taken from social media platforms and other websites, is being sued by Vermont&#x27;s attorney general. <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/ago.vermont.gov\/wp-content\/uploads\/2020\/03\/Complaint-State-v-Clearview.pdf&quot;}\" href=\"https:\/\/ago.vermont.gov\/wp-content\/uploads\/2020\/03\/Complaint-State-v-Clearview.pdf\" rel=\"nofollow noopener\" target=\"_blank\">The suit alleges<\/a> that the company&#x27;s bulk collection of online images for facial recognition is prohibited by the state&#x27;s Consumer Protection Act and its data broker law. Clearview AI already faces numerous lawsuits after expos\u00e9s by <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.nytimes.com\/2020\/01\/18\/technology\/clearview-privacy-facial-recognition.html&quot;}\" href=\"https:\/\/www.nytimes.com\/2020\/01\/18\/technology\/clearview-privacy-facial-recognition.html\" rel=\"nofollow noopener\" target=\"_blank\">the <em>New York Times<\/em><\/a> and <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.buzzfeednews.com\/article\/ryanmac\/clearview-ai-nypd-facial-recognition&quot;}\" href=\"https:\/\/www.buzzfeednews.com\/article\/ryanmac\/clearview-ai-nypd-facial-recognition\" rel=\"nofollow noopener\" target=\"_blank\"><em>Buzzfeed<\/em><\/a>. Tech companies including Google, Microsoft, and Twitter have also sent cease-and-desist letters to the company.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/coronavirus-phishing-ad-fraud-clearview-security-news\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5e6c33a3c0b1110009a4db31\/master\/pass\/Security_roundup-dv1187002.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lily Hay Newman| Date: Sat, 14 Mar 2020 14:00:00 +0000<\/strong><\/p>\n<p>Plus: A Comcast blunder, a Clearview AI lawsuit, and more of the week&#8217;s top security news.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21357],"class_list":["post-17955","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-security-news"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17955","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17955"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17955\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17955"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17955"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17955"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}