Telegram (AI) YouTube Facebook X
Ру
Phishers target cryptocurrencies, Taiwan turns to IPFS, and other cybersecurity developments

Phishers target cryptocurrencies, Taiwan turns to IPFS, and other cybersecurity developments

We’ve gathered the week’s most important cybersecurity news.

  • The deBridge protocol team reported an attempted cyberattack.
  • Media described how Russia gained control over the internet in the occupied city of Kherson.
  • Taiwan began using IPFS to protect against cyberattacks.

WhatsApp announces new privacy features

Meta chief executive Mark Zuckerberg announced the rollout of new features in WhatsApp aimed at enhancing privacy.

Among them are the ability to adjust who can see your online status, leave groups without notifying all members, and restrict screenshots of messages.

Media revealed how Russia established internet control in the occupied Kherson

Weeks after Russia occupied Ukrainian Kherson, Russian troops visited local internet providers’ offices and demanded to relinquish control of their networks. The New York Times reports.

After that, Kherson mobile and internet traffic were redirected through Russian networks. Later, access to Facebook, Instagram and Twitter was blocked, and Ukrainian mobile networks were shut down, forcing residents to use Russian mobile operators.

The outlet noted that a similar situation has been observed in other cities occupied by Russian forces.

The authors noted that restricting internet access “is part of Russia’s strategy”:

“[It] has made these Ukrainian regions vulnerable to an extensive system of digital censorship and surveillance. Russia can monitor web traffic and digital communications, spread propaganda and control the news.”

Hackers attempted to attack the deBridge protocol

The cross-chain interaction and liquidity transfer protocol deBridge came under cyberattack. The Lazarus group is reportedly behind it, according to cofounder Alex Smirnov.

The attackers, posing as him, sent a letter to deBridge staff titled “New Salary Adjustments.” Most team members immediately flagged the suspicious email, but one downloaded and opened the file. The attack was not successful, but helped deBridge study its characteristics.

“The attack vector is as follows: the user clicks a link in the email, downloads and opens an archive, tries to open a PDF, but the PDF asks for a password. The user opens password.txt.lnk and compromises the entire system,” explained Smirnov.

The attack does not affect macOS users, but Windows-based systems remain at risk, he added.

Experts discuss a phishing campaign targeting Coinbase, MetaMask, Kraken and Gemini users

In 2022, attackers created phishing pages via Google Sites and Microsoft Azure to steal cryptocurrency wallets and accounts for Coinbase, MetaMask, Kraken and Gemini, Netskope Threat Labs reports.

The phishing pages are promoted in comments on other sites, mainly blogs. The sites imitate various cryptocurrency platforms.

Subsequently, attackers gain access to victims’ seed phrases, logins and passwords that victims enter on fake pages.

“Netskope strongly recommends that users never enter credentials after following a link. Instead, always go directly to the site,” the specialists noted.

Taiwan begins using Ethereum-based IPFS technology to protect against cyberattacks

The Ministry of Digital Affairs in Taiwan has deployed the IPFS technology to safeguard its infrastructure, Decrypt reports.

The ministry noted that it launched the initiative on the same day China began military exercises near Taiwan following a visit by U.S. House Speaker Nancy Pelosi.

Hackers attacked Twilio and Cloudflare via phishing SMS

Twilio, the cloud software provider, reported a phishing attack against its staff. Subsequently, the attackers gained access to internal systems and data of Twilio’s clients.

The SMS messages purportedly came from the company’s IT department, inviting staff to log into the system via a link to update their password.

Upon detection, Twilio’s security team revoked access to the compromised accounts. Nevertheless, the attackers obtained data from about 125 of the firm’s clients.

Hackers used similar methods to target Cloudflare employees, but the attackers did not succeed in breaching Cloudflare’s systems.

Also on ForkLog:

What to read this weekend?

Why Telegram is not the best solution for protecting privacy, as explained in our exclusive:

Read ForkLog’s bitcoin news in our Telegram — crypto news, prices and analysis.

Подписывайтесь на ForkLog в социальных сетях

Telegram (основной канал) Facebook X
Нашли ошибку в тексте? Выделите ее и нажмите CTRL+ENTER

Рассылки ForkLog: держите руку на пульсе биткоин-индустрии!

We use cookies to improve the quality of our service.

By using this website, you agree to the Privacy policy.

OK