The Week in Cyber Security and Data Privacy: 11 – 18 December 2023

Welcome to this week’s round-up of the biggest and most interesting news stories. At the end of each month, these incidents – and any others that we find – will be used to inform our monthly analysis of data breaches and cyber attacks. We’re also introducing two new categories this week: ‘AI’ and ‘Key dates’. Publicly disclosed data breaches and cyber attacks: in the spotlight Mr. Cooper reveals 14,690,284 people affected in October breach The largest mortgage provider in the US, Nationstar Mortgage LLC, operating under the name Mr. Cooper, says its investigation into an October cyber attack has uncovered

The post The Week in Cyber Security and Data Privacy: 11 – 18 December 2023 appeared first on IT Governance UK Blog.

December 19, 2023
Read More >>

“Quishing” you a Happy Holiday Season

QR Code phishing scams — What they are and how to avoid them.

Originally invented to keep track of car parts in the early 90s, QR codes have been around for decades. After gaining broader acceptance during the COVID-19 pandemic, they are now—perhaps inevitably—being exploited by cybercriminals. Quishing, or QR Code phishing, exploits smartphone users scanning the 2D barcode, which leads to a phishing site, malicious link, or another cyber attack.

We’ll look at the threat from QR code-based phishing and consider why cybercriminals are adopting this technique. Additionally, we’ll explore opportunities to detect and disrupt these attacks at scale.

QR codes in phishing emails: what’s the threat?

QR codes work precisely as malicious links; a victim who scans the QR code – typically using their smartphone – will be directed towards a malicious site. From here, the deception can continue as with any other phishing campaign.

By now, many know how to spot suspicious-looking links in phishing emails that mimic official communications from established brands or institutions. The opposite is true with QR codes: there is typically no user-accessible way to check the destination before scanning.

From a cybercriminal’s perspective, there are several reasons to use QR codes for phishing, often dubbed quishing, including:

  1. Hiding URLs from users – QR codes provide criminals with a very effective mechanism for hiding suspicious URLs, making this an ideal way to bypass growing user skepticism concerning clicking questionable and shortened URLs.  
  2. Circumventing corporate controls – If users receive a QR-based phishing email on their work computer, they will likely scan the code using their phone. Cybercriminals know personal devices may have less built-in security than a company computer or phone. It’s a subtle way of encouraging victims to use devices not under corporate control and are, therefore, less likely to

December 19, 2023
Read More >>

Netanyahu’s Unsustainable Oslo Ambivalence

“The number of people killed on Oct. 7 and after the Oslo Accords are the same,” Israeli Prime Minister Benjamin Netanyahu reportedly proclaimed in a closed-door meeting of the Knesset’s Foreign Affairs and Defense Committee last week. This tone-deaf s…

December 19, 2023
Read More >>

The New Washington Consensus

On this show, Chris, Melanie, and Zack discuss the so-called “new Washington Consensus” – a reaction to decades of trade liberalization and free market economics that, some warn, has undermined national security and left the United States and others vu…

December 19, 2023
Read More >>