Google Search

Showing posts with label Notice. Show all posts
Showing posts with label Notice. Show all posts

Monday, June 3, 2013

Fake Zendesk security notice spammed out, directs traffic to Canadian drug websites

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

I'm always on the lookout for breaking news about companies who might have had their systems hacked, so when I received the following email earlier today my interest was piqued.

Its subject line was "An important notice about security".

Fake security notice, pretending to be related to Zendesk breach

We recently learned that the vendor we use to answer support requests and other emails (Zendesk) experienced a security breach.

We're sending you this email because we received or answered a message from you using Zendesk. Unfortunately your name, email address and subject line of your message were improperly accessed during their security breach. To help keep your account secure, please:

* Don't share your password. We will never send you an email asking for your password. If you get an email like this, please let us know right away.

* Beware of suspicious emails. If you get any emails that look like they're from our Support Team but don't feel right, please let us know - especially if they include details about your support request.

* Use a strong password. If your password is weak, you can create a new one [LINK]

We're really sorry this happened, and we'll keep working with law enforcement and our vendors to ensure your information is protected.

Support Team

In a nutshell, the email claims to be from an online company which is using the Zendesk customer service portal to help it answer queries from customers.

ZendeskYou may even remember that Zendesk was hacked in February, and companies such as Tumblr, Twitter and Pinterest contacted some of their users to warn them that email addresses were possibly exposed.

What's different this time is that the body of the email doesn't really make clear *what* company is contacting me. Which seems strange.

Yes, the email mentions Zendesk - but just *who* is the company that was using Zendesk and has suffered as a result of the breach at Zendesk?

With no clear details in the email, the only way to find out is to click on the links... right?

Well, if you do that, you'll find your browser taken on a journey which ultimately (via some temporary redirects) leads you to a Canadian pharmacy website, trying to sell you Viagra and Cialis:

Canadian Pharmacy website

In short, the whole email is a campaign - using the disguise of an important security notice (complete with sensible advice to use strong passwords, and be wary of unsolicited emails!) to trick you into clicking on the link.

These cybercriminals certainly have some gall.

Of course, whoever is behind this campaign could easily change the redirects to point to a more malicious webpage, or a phishing site if they wished. Which would make it even worse.

Interestingly, this isn't the only way in which the spammers have been promoting this particular online drugs store.

Paul Baccas in SophosLabs uncovered for me that in the last 24 hours we have also had reports from customers who have received bogus Facebook notifications pointing to the same site.

Facebook-related spam message

We all probably know someone who is so addicted to Facebook, and stalking their friends' online activity, that they wouldn't hesitate from clicking on a link which they believed had come from the social network.

Remember to always practice safe computing online, including the rule about always being suspicious of unsolicited emails.

If you're not careful, you might not only be visiting spammers' websites - you could also potentially be putting your computer and its sensitive data in danger.

Follow @gcluley

View the original article here

Monday, June 18, 2012

Facebook privacy notice chain letter is a hoax

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Facebook logoSorry folks, but posting a supposed legal disclaimer to your Facebook profile does not alter the Terms of Service (ToS) or privacy policies governing how your content is viewed on Facebook.

Many (dozens!) of Facebook users have submitted tips to Naked Security over the last week alerting us to a new chain letter/hoax circulating among well-meaning Facebook users.

The message reads as follows:

"Facebook is now a publicly traded entity. Unless you state otherwise, anyone can infringe on your right to privacy once you post to this site. It is recommended that you and other members post a similar notice as this, or you may copy and paste this version. If you do not post such a statement once, then you are indirectly a......llowing public use of items such as your photos and the information contained in your status updates.

PRIVACY NOTICE: Warning - any person and/or institution and/or Agent and/or Agency of any governmental structure including but not limited to the United States Federal Government also using or monitoring/using this website or any of its associated websites, you do NOT have my permission to utilize any of my profile information nor any of the content contained herein including, but not limited to my photos, and/or the comments made about my photos or any other "picture" art posted on my profile.

You are hereby notified that you are strictly prohibited from disclosing, copying, distributing, disseminating, or taking any other action against me with regard to this profile and the contents herein. The foregoing prohibitions also apply to your employee , agent , student or any personnel under your direction or control.

The contents of this profile are private and legally privileged and confidential information, and the violation of my personal privacy is punishable by law. UCC 1-103 1-308 ALL RIGHTS RESERVED WITHOUT PREJUDICE. (M)"

Terms and Conditions image courtesy of ShutterstockUnfortunately taking control of your online identity is not as simple as making a declaration on your Facebook wall. Using any website to store content or personal details requires compliance with the site's Terms of Service.

These messages are simply another chain letter type hoax pinned upon wishful thinking.

If you are uncomfortable with Facebook monetizing your content or making your content available to the US government you either need to avoid posting the content to Facebook, or more carefully control your privacy settings and hope the authorities don't seek a court order for your information.

If you receive one of these messages from a friend, kindly notify them that it is not legally valid. You might also suggest they check with Snopes or the Naked Security Facebook page before propagating myths.

Follow @chetwisniewski

Terms and Conditions image courtesy of Shutterstock.


View the original article here

Monday, March 5, 2012

Google Offers $1M to Hackers, Goldman Gets Wells Notice: Hot Trends

NEW YORK (TheStreet) -- Popular searches on the Internet Wednesday include Google(GOOG) as the company announces it will offer $1 million in rewards to hackers who can infiltrate Chrome.

Google said it will pay hackers who are participating in the Pwnium hacking contest not only for infiltrating Chrome but for other targets as well. Google said it will pay $20,000 to any contestant who can hack Windows, Flash or a device driver, which would be problems users of all browsers could face. Google will up the ante for those who can hack Chrome, offering $40,000 each to those who can hack flaws specific to Chrome and $60,000 to those who can exploit only bugs in Chrome. The only other requirement is that those who exploit any flaws must submit the details to Google's security team.

Google said it's willing to pay such high figures in order to test Chrome against some of the world's most innovative hackers in a safer setting where not only will flaws be identified, but fixed.

Goldman Sachs(GS) and Wells Fargo(WFC) are hot topics as both banks revealed they have received "Wells notices" from the Securities and Exchange Commission, which indicates the SEC plans to recommend legal action against the banks and gives the banks time to prepare.

The legal action pertains to the banks' actions involving mortgage-backed securities deals at the time the financial crisis was beginning. Goldman's Wells notice pertains to a $1.3 billion subprime mortgage-backed securities deal the bank underwrote in late 2006. Wells Fargo said its Wells notice related to the bank's disclosures involving mortgage-backed securities.

These Wells notices are the latest in a string of investigations and action the U.S. government is taking to hold banks accountable for their contribution to the subprime housing crisis.

Costco(COST) is another popular search as the company reported better-than-expected fiscal second-quarter earnings and revenue.

Costco's performance beat expectations as profit rose 13%. The wholesale club operator reported net income of $394 million, or 90 cents per share, up from $348 million, or 79 cents, a year ago. Revenue from membership fees also rose to $459 million from $426 million.


View the original article here