{"id":27887,"date":"2019-04-12T09:20:21","date_gmt":"2019-04-12T15:20:21","guid":{"rendered":"https://www.webroot.com/blog/?p=27887"},"modified":"2019-04-12T09:20:23","modified_gmt":"2019-04-12T15:20:23","slug":"cyber-news-rundown-tax-extortion-ransomware-scams-corporations","status":"publish","type":"post","link":"https://www.webroot.com/blog/2019\/04\/12\/cyber-news-rundown-tax-extortion-ransomware-scams-corporations\/","title":{"rendered":"Cyber News Rundown: Tax Extortion Ransomware Scams Corporations"},"content":{"rendered":"\n<h2>Tax Extortion Emails Bring Major Threats<\/h2>\n\n\n\n<p>A new <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-extortion-email-threatens-to-install-wannacry-and-ddos-your-network\/\">email\ncampaign<\/a> has been spotted threatening ransomware and DDoS attacks\nover fake tax documents allegedly held by the attackers if a Bitcoin ransom\nisn\u2019t paid. The campaign authors also threaten to send fake tax documents to\nthe IRS through a poorly-worded ransom email that even provides Wikipedia\nexcerpts for each threat put forward. Fortunately, as the campaign seems to be\nfocused on corporations rather than individuals, no payments have been made to\nthe attacker\u2019s crypto coin wallet address. <\/p>\n\n\n\n<h2>Hotel Reservation Data Leaking Through Third-Party Services<\/h2>\n\n\n\n<p>As major <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/two-thirds-of-hotel-sites-leak-guest-booking-info-to-third-parties\/\">data\nbreaches<\/a> continue to flood headlines, a recent study has revealed\nthat nearly two of every three hotels exposes information about its guests to third-parties.\nExcerpts of the data show names, social security numbers, and payment card\ndetails that could give unauthorized users the ability to compromise identities\nor make changes to current reservations. Most of the exposed data involves comping\nthrough third-party services run on hotel websites offering customers\nadditional packages. <\/p>\n\n\n\n<h2>Ransomware Conspirator Jailed in the UK<\/h2>\n\n\n\n<p>Police in the UK have officially charged and jailed a man\nfor his part in the operation of a <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/uk-man-jailed-for-porn-site-1\/\">global\nransomware campaign<\/a> with ties to a Russian criminal organization. Charges\nrange from fraud and blackmail to computer misuse relating to DDoS attacks and\nthe Essex man is set to face at least six years. By masquerading as an\nadvertising agent looking to purchase ad space on high-traffic sites, he was able\nto infect ad links with malware and other exploits to spread his campaign.<\/p>\n\n\n\n<h2>Firefox Begins Blocking Cryptomining Scripts<\/h2>\n\n\n\n<p>Even after the demise of CoinHive, <a href=\"https:\/\/www.zdnet.com\/article\/mozilla-firefox-to-block-cryptomining-scripts-hidden-on-websites-by-default\/\">cryptomining\nscripts<\/a> are still being secretly deployed on thousands of websites\nwithout the knowledge of their owners and visitors. With the release of Firefox\n67 beta, Mozilla is hoping to completely protect their users from malicious\nscripts that download and run cryptominers and other unwanted tracking software\nby using a blacklist created by Disconnect, a VPN developer with a reputation for\nprivacy protection. Additionally, the new Firefox version will block\nfingerprinting scripts commonly used to invade a user\u2019s browsing privacy. <\/p>\n\n\n\n<h2>MyCar App Uses Hardcoded Credentials<\/h2>\n\n\n\n<p>Thousands of cars were left vulnerable after a widely used\nvehicle telematics systems was found to be using <a href=\"https:\/\/www.zdnet.com\/article\/tens-of-thousands-of-cars-left-exposed-to-thieves-due-to-a-hardcoded-password\/\">hardcoded\ncredentials<\/a> in their mobile apps. Used in dozens of different car\nmodels to enable remote control functions, the hardcoded credentials leave these\nvehicles accessible to anyone with the app\u2019s source code and the plaintext\ncredentials within. Fortunately for users, the latest iOS and Android versions of\nthe MyCar app have been updated to resolve this vulnerability. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Tax Extortion Emails Bring Major Threats A new email campaign has been spotted threatening ransomware and DDoS attacks over fake tax documents allegedly held by the attackers if a Bitcoin ransom isn\u2019t paid. The campaign authors also threaten to send fake tax documents to the IRS through a poorly-worded ransom email that even provides Wikipedia [&hellip;]<\/p>\n","protected":false},"author":47,"featured_media":27889,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[21936,21940,21943,21944],"yst_prominent_words":[3565,3881,6665,3769,6091,18123,3493,4849,4261,3937,5953,6531,3529],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/27887"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/47"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=27887"}],"version-history":[{"count":1,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/27887\/revisions"}],"predecessor-version":[{"id":27891,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/27887\/revisions\/27891"}],"wp:featuredmedia":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media\/27889"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=27887"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=27887"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=27887"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=27887"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}