• chevron_right

      Deepfake scammer walks off with $25 million in first-of-its-kind AI heist

      news.movim.eu / ArsTechnica · Monday, 5 February - 15:54

    An illustration of six people doing a video teleconference on a laptop computer.

    Enlarge (credit: Getty Images / Benj Edwards )

    On Sunday, a report from the South China Morning Post revealed a significant financial loss suffered by a multinational company's Hong Kong office, amounting to HK$200 million (US$25.6 million), due to a sophisticated scam involving deepfake technology. The scam featured a digitally recreated version of the company's chief financial officer, along with other employees, who appeared in a video conference call instructing an employee to transfer funds.

    Due to an ongoing investigation, Hong Kong police did not release details of which company was scammed.

    Deepfakes utilize AI tools to create highly convincing fake videos or audio recordings , posing significant challenges for individuals and organizations to discern real from fabricated content.

    Read 6 remaining paragraphs | Comments

    • chevron_right

      iPhone : 5 erreurs fréquentes qui exposent vos données aux hackers [Sponso]

      news.movim.eu / Numerama · Monday, 22 January - 06:00

    Cet article a été réalisé en collaboration avec Bitdefender

    Les iPhone sont réputés comme étant les smartphones les plus sûrs du marché, mais qu’en est-il réellement ? Certaines erreurs courantes restent susceptibles de mettre en danger vos données personnelles.

    Cet article a été réalisé en collaboration avec Bitdefender

    Il s’agit d’un contenu créé par des rédacteurs indépendants au sein de l’entité Humanoid xp. L’équipe éditoriale de Numerama n’a pas participé à sa création. Nous nous engageons auprès de nos lecteurs pour que ces contenus soient intéressants, qualitatifs et correspondent à leurs intérêts.

    En savoir plus

    • chevron_right

      Le faux PV de stationnement fait son retour dans les boites mail

      news.movim.eu / Numerama · Tuesday, 2 January - 10:59

    Une campagne de phishing usurpe les finances publiques et prétend par mail qu'une amende de 35 euros est à régler avant le début de l'année 2024.

    • chevron_right

      Arnaques téléphoniques : voici les techniques les plus utilisées et nos conseils pour les déjouer [Sponso]

      news.movim.eu / Numerama · Thursday, 28 December - 06:45

    Cet article a été réalisé en collaboration avec Bitdefender

    Vous avez sécurisé tous vos appareils contre les virus et les malwares, mais que faire pour se prémunir contre les arnaques téléphoniques ? Voici un tour d’horizon des escroqueries les plus répandues, et quelques clés pour les repérer avant que le piège ne se referme sur vous. Et surtout, pour les contrer.

    Cet article a été réalisé en collaboration avec Bitdefender

    Il s’agit d’un contenu créé par des rédacteurs indépendants au sein de l’entité Humanoid xp. L’équipe éditoriale de Numerama n’a pas participé à sa création. Nous nous engageons auprès de nos lecteurs pour que ces contenus soient intéressants, qualitatifs et correspondent à leurs intérêts.

    En savoir plus

    • chevron_right

      Arnaque au CV : c’est quoi cette nouvelle escroquerie qui cible les offres d’emploi ?

      news.movim.eu / JournalDuGeek · Wednesday, 13 December - 08:12

    Entreprise check

    Les cybercriminels ne se contentent plus de viser les particuliers, mais s'attaquent aussi aux professionnels.

    Arnaque au CV : c’est quoi cette nouvelle escroquerie qui cible les offres d’emploi ?

    • chevron_right

      BeStreamWise ‘Piracy=Malware’ Campaign Site Blocked By Security Vendors

      news.movim.eu / TorrentFreak · Tuesday, 12 December - 22:40 · 4 minutes

    malware-s1 The launch of the BeStreamWise online anti-piracy campaign early October was preceded by action in the ‘real’ world.

    After being offered free lifetime subscriptions to a new streaming service from a pop-up stand in London’s Paddington Station, commuters were encouraged to sign up to ‘MalStreams’ using their real personal details.

    Shortly after, a ‘scam’ was revealed; MalStreams didn’t exist but participants had been given a valuable lesson in security. Handing over personal and credit card details to strangers can be more dangerous than people think. Handing over financial details for a lifetime of free service suggests that some people don’t even think at all.

    Run by Sky, Premier League, FACT, ITV, CrimeStoppers, and the UK Intellectual Property Office, among others, the campaign aims to raise awareness of the potential risks of using illegal streaming services.

    Handing over personal and financial information to strangers can have unexpected consequences, as the ‘customers’ of MalStreams quickly discovered. The same applies when people install streaming apps offering premium content for free. Football matches and movies for nothing may sound attractive, the campaign explains, but exposing devices to the risk of malware infection is something few people want.

    Further details on malware risks are available on the BeStreamWise website, at least for those able to access it right now.

    BeStreamWise.com Blocked For Security Reasons

    After being informed that BeStreamWise.com was ‘down’ last evening for no obvious reason, some quick tests revealed a curious situation. The site could be accessed as normal using a VPN but without one it simply wouldn’t load.

    Hoping to find out who, if anyone, was blocking the site, a few network tests revealed that requests were being blocked before even escaping the LAN. The culprit was found in one of the routers where for the first time in over a year, a site had triggered blocking measures on non-VPN outbound traffic.

    According to the AI protection service supplied by Trend Micro, the domain had been blocked for phishing. A subsequent test on the Trend Micro global portal returned the same result, with the following detail: Fraudulent sites that mimic legitimate sites to gather sensitive information, such as user names and passwords.

    Since so-called ‘false positives’ are not unusual, checking with other security vendors can help to shine a light on situations like these. Unfortunately, that failed to clear things up as expected, at least not initially.

    Multiple Security Vendors Report Malicious Behavior

    Subsequent tests revealed that Avira had also flagged BeStreamWise.com for phishing, CDRF and CyRadar had settled on malicious, while AlphaMountain simply reported suspicious activity.

    Thanks to its bold layout, however, URLScan.io quickly provided information that may explain why BeStreamWise was flagged for suspected phishing, which entity it was believed to be masquerading as, and who vendors may have been trying to protect.

    Whatever the specific reasons behind the alerts, the above indicates that the BeStreamWise domain faces allegations of impersonating Sky. The broadcaster actually runs the campaign site on its own infrastructure, making foul play unlikely, but whether this largely unadvertised direct connection played a part in these alerts is unknown.

    For its part, the BeStreamWise campaign believes there’s little to be concerned about.

    “BeStreamWise.com raises awareness of the risks involved in illegal streaming. Given the nature of the topic, we are extremely vigilant over the security of the site. It is functioning normally and we have not detected any issues, but we will continue to investigate,” a spokesperson informs TorrentFreak.

    While the campaign doesn’t believe there’s much to worry about, these warnings aren’t new and may even precede the campaign’s official launch.

    Domain Flagged Since Before Official Launch

    The results of at least five full scans are available on URLScan and potentially more if any scans were designated as private. The oldest scan was carried out on September 28 , followed by others on October 7 , October 17 , and October 19 .

    All of these scans signaled ‘malicious behavior’ which raises the question of how many people tried to visit BeStreamWise over the past couple of months to learn about malware, only to be blocked from accessing it due to a possible risk of malware.

    Bad Labeling, Bad Outcomes

    Another potential issue lies with Comodo’s Xcitium Verdict Cloud , which has categorized BeStreamWise.com as a ‘media sharing’ site. This type of mislabeling can have serious knock-on effects, as we’re only too aware.

    TorrentFreak has been wrongfully categorized as a media-sharing platform on more than one occasion, which led to readers being prevented from accessing the site via public WiFi services on more than one occasion .

    In 2018, Comcast erroneously blocked TorrentFreak for being ‘suspicious’ and in 2013, customers of Sky were unable to access the site after an exploit placed us on the UK’s pirate site blocking list.

    So to summarize, watch out for malware but remember that not all reports of malware are accurate. Also be aware that when pirate apps receive a clean bill of health following a malware scan, in a worrying number of more recent cases that can mean absolutely nothing. Not exactly a comfort, but reality nonetheless.

    From: TF , for the latest news on copyright battles, piracy and more.

    • chevron_right

      The growing abuse of QR codes in malware and payment scams prompts FTC warning

      news.movim.eu / ArsTechnica · Tuesday, 12 December - 01:48 · 1 minute

    A woman scans a QR code in a café to see the menu online.

    Enlarge / A woman scans a QR code in a café to see the menu online.

    The US Federal Trade Commission has become the latest organization to warn against the growing use of QR codes in scams that attempt to take control of smartphones, make fraudulent charges, or obtain personal information.

    Short for quick response codes, QR codes are two-dimensional bar codes that automatically open a Web browser or app when they’re scanned using a phone camera. Restaurants, parking garages, merchants, and charities display them to make it easy for people to open online menus or to make online payments. QR codes are also used in security-sensitive contexts. YouTube, Apple TV, and dozens of other TV apps, for instance, allow someone to sign into their account by scanning a QR code displayed on the screen. The code opens a page on a browser or app of the phone, where the account password is already stored. Once open, the page authenticates the same account to be opened on the TV app. Two-factor authentication apps provide a similar flow using QR codes when enrolling a new account.

    The ubiquity of QR codes and the trust placed in them hasn’t been lost on scammers, however. For more than two years now, parking lot kiosks that allow people to make payments through their phones have been a favorite target . Scammers paste QR codes over the legitimate ones. The scam QR codes lead to look-alike sites that funnel funds to fraudulent accounts rather than the ones controlled by the parking garage.

    Read 5 remaining paragraphs | Comments

    • chevron_right

      Ameli retrouve l’accès à FranceConnect après des problèmes de phishing

      news.movim.eu / Numerama · Thursday, 7 December - 14:29

    Ameli a réactivé l'accès à FranceConnect un an après l'avoir suspendu. Des incidents de sécurité avaient conduit le service public à couper la liaison au portail.

    • chevron_right

      Le Covid revient, et avec lui les arnaques à l’assurance maladie

      news.movim.eu / Numerama · Saturday, 2 December - 18:58

    Une campagne de phishing prétend qu'il faut renouveler sa carte Vitale et ajoute un message de prévention sur l'épidémie de Covid pour donner plus de poids à l'escroquerie. [Lire la suite]

    Abonnez-vous aux newsletters Numerama pour recevoir l’essentiel de l’actualité https://www.numerama.com/newsletter/