Look-Alike Domains and Visual Confusion

Credit to Author: BrianKrebs| Date: Thu, 08 Mar 2018 16:55:13 +0000

How good are you at telling the difference between domain names you know and trust and imposter or look-alike domains? The answer may depend on how familiar you are with the nuances of internationalized domain names (IDNs), as well as which browser or Web application you’re using. For example, how does your browser interpret the following domain? I’ll give you a hint: Despite appearances, it is most certainly not the actual domain for software firm CA Technologies (formerly Computer Associates Intl Inc.), which owns the original ca.com domain name: https://www.са.com/ Go ahead and click on the link above or cut-and-paste it into a browser address bar. If you’re using Google Chrome, Apple’s Safari, or some recent version of Microsoft’s Internet Explorer or Edge browsers, you should notice that the address converts to “xn--80a7a.com.” This is called “punycode,” and it allows browsers to render domains with non-Latin alphabets like Cyrillic and Ukrainian. Below is what it looks like in Edge on Windows 10; Google Chrome renders it much the same way. Notice what’s in the address bar (ignore the “fake site” and “Welcome to…” text, which was added as a courtesy by the person who registered this domain):

Read more

A massive security flaw discovered in Skype. Fix not coming anytime soon.

Credit to Author: Shriram Munde| Date: Wed, 14 Feb 2018 09:10:30 +0000

Quick Heal Security Labs has recently learned about a serious vulnerability in Skype’s update installer – that’s the bad news. The worse news is, Microsoft is not going to patch the vulnerability anytime soon as this would require the updater to go through a ‘large code revision’. What is this…

Read more

“Who visits your Twitter profile” spam app brings week of chaos

Credit to Author: Christopher Boyd| Date: Tue, 23 Jan 2018 19:17:06 +0000

Last week saw a Twitter spam app claiming to show who “viewed your profile” and spreading throughout the social media platform. See how it spread, and what you can do to avoid being caught by this common scam.

Categories:

Tags:

(Read more…)

The post “Who visits your Twitter profile” spam app brings week of chaos appeared first on Malwarebytes Labs.

Read more

Be wary of Mega Millions winner “giveaway” on social media

Credit to Author: Christopher Boyd| Date: Tue, 16 Jan 2018 18:12:47 +0000

Twitter’s abuzz as a 20-year-old Mega Millions winner claims to be giving away free money for retweets and Amazon purchases. Is this for real?

Categories:

Tags:

(Read more…)

The post Be wary of Mega Millions winner “giveaway” on social media appeared first on Malwarebytes Labs.

Read more

Terdot Trojan likes social media

Credit to Author: Pieter Arntz| Date: Wed, 22 Nov 2017 18:47:17 +0000

The Terdot Trojan is a banker, but it loves to steal your social networks credentials as well.

Categories:

Tags:

(Read more…)

The post Terdot Trojan likes social media appeared first on Malwarebytes Labs.

Read more

How to Opt Out of Equifax Revealing Your Salary History

Credit to Author: BrianKrebs| Date: Mon, 13 Nov 2017 16:55:19 +0000

A KrebsOnSecurity series on how easy big-three credit bureau Equifax makes it to get detailed salary history data on tens of millions of Americans apparently inspired a deeper dive on the subject by Fast Company, which examined how this Equifax division has been one of the company’s best investments. In this post, I’ll show you how to opt out of yet another Equifax service that makes money at the expense of your privacy.

Read more