{"id":26471,"date":"2018-12-21T06:00:11","date_gmt":"2018-12-21T13:00:11","guid":{"rendered":"https://www.webroot.com/blog/?p=26471"},"modified":"2019-03-20T17:28:37","modified_gmt":"2019-03-20T23:28:37","slug":"cyber-news-rundown-facebook-bug-exposes-photos","status":"publish","type":"post","link":"https://www.webroot.com/blog/2018\/12\/21\/cyber-news-rundown-facebook-bug-exposes-photos\/","title":{"rendered":"Cyber News Rundown: Facebook Bug Exposes User Photos"},"content":{"rendered":"\n<h2>Facebook API Bug Reveals Photos from 6.8 Million Users<\/h2>\n\n\n\n<p>Facebook announced this week that an <a href=\"https:\/\/www.securityweek.com\/photos-68-million-facebook-users-exposed-api-bug\">API\nbug<\/a> had been found that allowed third-party apps to access all user\nphotos, rather than only those posted to their timeline. The vulnerability was\nonly available for 12 days in mid-September, but could still impact up to 6.8\nmillion users who had granted apps access to their photos in that time. <\/p>\n\n\n\n<h2>Children\u2019s Charity Falls Victim to Email Scam<\/h2>\n\n\n\n<p>Over $1 million was recently diverted from a <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/save-the-children-hit-by-1m-bec\/\">children\u2019s\ncharity organization<\/a> after hackers were able to gain access to an\ninternal email account and begin creating false documents and invoices. Due to\na lack of additional authentication measures, the funds were promptly\ntransferred to a Japanese bank account, though insurance was able to compensate\nfor most of the loss after the scam was finally discovered. <\/p>\n\n\n\n<h2>Email Extortion Scams Now Include Hitmen<\/h2>\n\n\n\n<p>The latest in a series of <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-extortion-email-threatens-to-send-a-hitman-unless-you-pay-4k\/?fbclid=IwAR0KCMqD1OsQjtzwsImde8iUP-vK14SQhD2YG4voS8jC4e63Bao_TM0ZSII\">email\nextortion campaigns<\/a> promises its victims will be executed by a\nhitman if a Bitcoin ransom of $4,000 isn\u2019t paid within 38 hours. Given such\npoorly executed scare tactics, it comes as no surprise that the payment account\nhas still not received any funds after several days. Hopefully, as the threats\nof violence leads to victims contacting law enforcement rather than paying the\nscammers, these types of scams will become more rare. <\/p>\n\n\n\n<h2>Hackers Force Printers to Spam PewDiePie Message<\/h2>\n\n\n\n<p>Nearly <a href=\"https:\/\/www.bbc.com\/news\/technology-46552339\">50,000 printers<\/a>\naround the world have been spamming out a message suggesting subscribing to\nPewDiePie on YouTube and recommending the recipient improve their printer\nsecurity. The group behind the spam has stated they want to raise awareness of the\nreal threat of unsecured devices connected to the internet and how they can be\nused maliciously. In addition to sending print-outs, attackers could also steal\ndata being printed or modify documents while they are being printed. <\/p>\n\n\n\n<h2>Cybersecurity Audit Shows Major Vulnerabilities in U.S. Missile Systems<\/h2>\n\n\n\n<p> A recent report showed that U.S. ballistic missile defense systems have consistently <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/us-ballistic-missile-defense-systems-fail-cybersecurity-audit\/\">failed security audits<\/a> for the past five years. Some of the major flaws included a lack of encryption for data stored on removable devices, patches reported in previous years that remained untouched, and the regular use of single-factor authentication for entire facilities. Physical security issues that could leave highly-sensitive data exposed to anyone willing to simply try to access it were also detailed in the report.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Facebook API Bug Reveals Photos from 6.8 Million Users Facebook announced this week that an API bug had been found that allowed third-party apps to access all user photos, rather than only those posted to their timeline. The vulnerability was only available for 12 days in mid-September, but could still impact up to 6.8 million [&hellip;]<\/p>\n","protected":false},"author":47,"featured_media":27323,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[],"yst_prominent_words":[23739,3959,3673,22197,5109,5337,23737,4947,23591,23741,3769,20445,3493,4497,4463,23743,17893,5573,3479,3529],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/26471"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/47"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=26471"}],"version-history":[{"count":3,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/26471\/revisions"}],"predecessor-version":[{"id":26479,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/26471\/revisions\/26479"}],"wp:featuredmedia":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media\/27323"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=26471"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=26471"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=26471"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=26471"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}