Archive for December 8, 2022

Elon Musk Picks A Fight With Apple Again As He Hikes Twitter Blue Pricing to $11 For iPhone Users

Posted in Commentary with tags , on December 8, 2022 by itnerd

After visiting Apple HQ to make peace with Apple after taking shots at them over them allegedly pulling advertising, Elon Musk is stirring things up again according to Reuters as he’s wanting to charge $11 for Twitter Blue if you pay via his iPhone App. But if you pay directly on Twitter.com, it’s $7.99.

This is clearly about making sure that Apple’s 30% cut of anything bought in app in the Apple ecosystem stays in Elon’s pocket. The real question is, will Apple retaliate? That’s going to be tricky because if Apple does nothing, other app developers will try the same thing. But if they go to war with Elon, it might be playing into his hands as he wants to pick a fight with Apple. It will be interesting to see which option Apple chooses.

Get your popcorn ready. This will be fun.

New Research: Fake Invoice Attack with Malware Bypasses Office 365, Targeting 100,000 Mailboxes 

Posted in Commentary on December 8, 2022 by itnerd

Armorblox has a deep dive into their latest analysis on an attack targeting end users across a large, national institution within the Education Industry with an email almost identical to an invoice reminder notification from a trusted vendor. 

Upon opening the attachment, unsuspecting victims were met with a message that seemed to be from Microsoft informing the recipient that he or she was being taken to the organization’s sign-in page. No matter if the end user immediately closed the attachment or waited to be navigated through, just opening the attachment initiated the installation of malware onto the user’s machine. 

Further details of this attack can be found in the blog, including:

  • What techniques were used to get past traditional email security filters and pass the eye tests of unsuspecting users?
  • How this attack  bypassed Microsoft Office 365 email security, potentially compromising more than 100,000 mailboxes.
  • Guidance and recommendations that can be used to prevent similar attacks.

You can read the deep dive here.

Security Researcher Demonstrates Attackers Communicate via DNS to Attack Air-Gapped Networks

Posted in Commentary on December 8, 2022 by itnerd

Pentera has releaseda new research report on how Uriel Gabay, Security Researcher at Pentera was able to bypass an air-gapped network to execute an attack. In order to protect an organization’s critical assets from Internet access, IT teams often create isolated or ‘air-gapped’ networks. 

These networks are largely considered inherently untouchable, but Pentera Labs Research was able to bridge the air-gap and access them with only a few lines of code. Air-gapped networks may not have direct access to the Internet, but they still often require DNS services in order to resolve a company’s internal DNS records. 

Uriel was able to exploit this reality to execute an attack over the DNS and showcase how hackers could relatively easily access offline information that organizations assumed was safe.

You can read the research here.

2022 Uber Eats Cravings Report reveals fun and unusual Canadian delivery trends

Posted in Commentary with tags on December 8, 2022 by itnerd

This week, Uber Eats is launching its fourth annual Cravings Report revealing all the ways Canadians enjoyed getting their favorite sips and eats exactly how they wanted them. 

From Canada’s most polite and pickiest cities to the largest Uber Eats restaurant orders, this year’s report offers a snapshot of the most popular, most unique—and in some cases—most unusual delivery requests received over the last year. 

Here are some of the year’s juiciest delivery trends: