handmade.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
handmade.social is for all handmade artisans to create accounts for their Etsy and other handmade business shops.

Server stats:

36
active users

#malware

4 posts3 participants0 posts today

Malicious actors have taken notice of news about the US Social Security System. We've seen multiple spam campaigns that attempt to phish users or lure them to download malware.

Emails with subjects like "Social Security Administrator.", "Social Security Statement", and "ensure the accuracy of your earnings record" contain malicious links and attachments.

One example contained a disguised URL that redirected to user2ilogon[.]es in order to download the trojan file named SsaViewer1.7.exe.

Actors using social security lures are connected to malicious campaigns targeting major brands through their DNS records.

Block these:

user2ilogon[.]es
viewer-ssa-gov[.]es
wellsffrago[.]com
nf-prime[.]com
deilvery-us[.]com
wllesfrarqo-home[.]com
nahud[.]com.

#dns #lookalikes #lookalikeDomain #threatintel #cybercrime #threatintelligence #cybersecurity #infoblox #infobloxthreatintel #infosec #pdns #malware #scam #ssa

#TroyHunt fell for a #phishing attack on his mailinglist members: troyhunt.com/a-sneaky-phish-ju

Some of the ingredients: #Outlook and its habit of hiding important information from the user and missing #2FA which is phishing-resistant.

Use #FIDO2 with hardware tokens if possible (#Passkeys without FIDO2 HW tokens are NOT phishing-resistant due to the possibility of being able to trick users with credential transfers: arxiv.org/abs/2501.07380) and avoid Outlook (or #Microsoft) whenever possible.

Further learning: it could happen to the best of us! Don't be ashamed, try to minimize risks and be open about your mistakes.

Note: any 2FA is better than no 2FA at all.

Troy Hunt · A Sneaky Phish Just Grabbed my Mailchimp Mailing ListYou know when you're really jet lagged and really tired and the cogs in your head are just moving that little bit too slow? That's me right now, and the penny has just dropped that a Mailchimp phish has grabbed my credentials, logged into my account and exported the mailing

slrpnk.net/post/19958860

How to install #Windows11 with better #privacy and user control.

There are extremely many people still using Windows 10 or even older, which will become a real security issue soon.

This guide is for people that need to keep using Windows. I used it to upgrade an unsupported Laptop to Windows 11, which is worlds better than Windows 10, after you clean it up. It makes Windows ***almost*** a nice OS ;)

slrpnk.netMaking sure you're not a bot!

ClickFix and malware seem to prefer PowerShell aliases: iwr iex for obfuscation, so I thought why not simply disable and turn them into canaries.

Of course impact is highly org and user dependent, but since it's deployed per user+host profile, we can easily apply it to the primary, non-privileged or service identity.

And yes, still disable Win+R, Win+X, log and get control on EPs. If you're already hunting iwr, you hopefully know where they run as current user.

Another Monday. Another edition of the Privacy Roundup featuring news items curated with end user #privacy and #security in mind.

This edition features:

- #Android Apps using #Bluetooth and Wi-Fi connection data to estimate and collect user location data
- #Apple Passwords app used insecure HTTP
- Video gamers beware: another game pulled from Steam for being #malware in disguise
- Free online converters adding malware to converted files
- Threat actors using #Reddit posts to push information stealing malware, primarily targeting #cryptocurrency traders/enthusiasts
- Data breaches at the largest US sperm bank and a large teacher union

… and more.

#privacymatters #databreach #cybersecurity #cybersecurity #infosec #gaming

avoidthehack.com/privacy-week1

Avoid the Hack (avoidthehack!)Privacy Roundup: Week 12 of Year 2025Week 12 of the Privacy Roundup includes news items covering Android apps using bluetooth and Wi-Fi to track user location, Apple Passwords using insecure HTTP, sensitive information compromised in hacks of a large teacher union and a sperm bank, threat actors using Reddit posts to push information stealing malware, and more!

@psuPete Recommends Weekly highlights on cyber security issues, 3/22/25 - Five highlights from this week: Memo details #Trump plan to sabotage the #SocialSecurity Administration; Everything You Say To Your Fire TV & #Echo Will Be Sent to #Amazon Soon; The DNA of organised #crime is changing – and so is the threat to #Europe; Judge Rips #DOGE Dig Into Social Security Records; and Big AI platforms can generate #Chrome #malware with this technique. llrx.com/2025/03/pete-recommen #AI privacy #cybercrime

1/ the fact that #Tether never took any action before today to block the world's foremost russian #ransomware laundering crypto exchange (#Garantex) from using their #USDT token tells you everything you need to know about Tether (and therefore about Trump's Commerce Secretary #HowardLutnick, who manages Tether's money).

IMHO the fact that this is happening now suggests that the Trump administration has already made some kind of deal with #Putin.

protos.com/garantex-says-usdt-

Protos · Garantex says 'USDT in Russian wallets under threat' as Tether freezes $27MGarantex was sanctioned by the EU in February as it stepped up its efforts to bring an end to “Russia’s war of aggression against Ukraine.”

I just got a phone call purportedly from Bluehost, referring to my URL specifically, saying it looks like there is a malware attack on my site. I have had a couple of unknown site views today. But there is no clear problem with my site, and I am aware that SiteLock and others are shady as hell.

Is this a scam? Is this a good reason to just shut down my old site and find a new host? Is this the kick in the butt I've been waiting for?

Valve removes Steam game that contained malware

techcrunch.com/2025/02/13/valv

The game was called PirateFi, and billed itself as “a thrilling survival game set in a vibrant, low-poly world where you can choose to play solo or with others in multiplayer mode.” It’s not known exactly how many people downloaded the game, but its store rating had a 9/10 score out of 51 reviews, according to an archived version of its Steam page seen by TechCrunch.

TechCrunch · Valve removes Steam game that contained malware | TechCrunchThe gaming giant told affected users: "Consider fully reformatting your operating system"

#iPhone apps found on App Store with #malware that reads your screenshots for key data

"SparkCat"

Malware found on the App Store (and the #Google Play Store) used OCR to read screenshots. It scanned a user's photo library to search for recovery phrases for crypto wallets.

Some affected apps were listed by threat actors, circumventing Apple's guardrails for listing on the App Store. Other apps appeared to be compromised without the developer's knowledge.

Remember, no app store is 100% safe.

Also, avoid storing sensitive information in your photo library.

#apple #cybersecurity #security

9to5mac.com/2025/02/05/iphone-

9to5Mac · iPhone apps found on App Store with malware that reads your screenshots for key dataA new case of iPhone malware has been discovered in apps downloaded from the App Store. It reads your screenshots looking for key info.