G-Spam
By Kevin Whelan Posted June 14, 2019 In ITC's Threat of the Week

G-Spam

This week, the brilliant/devious (delete as applicable) folks at Kaspersky called out the mighty Google for allowing its own applications to be facilitators of spam, often containing malicious payloads – drive-by malicious sites and other nasty malware vectors.

The story is that content generated and shared by one G-App (Calendar etc.) is treated much more leniently than content from the outside world as it passes through the mighty G-Wall and therefore is much more likely to reach the G-Spot (don’t say you didn’t see that coming) with its sneaky little payloads intact.

This is very difficult to protect against, so look forward to a flurry of meetings with Dr Double-Cheap Viagra turning up in your Google Calendar in the coming months.

It would probably be best to advise your users and family (especially the old and young) to do the following:

  • Do not open messages from unknown senders.
  • Never accept invitations from people you don’t know.
  • Do not tap or click links in messages you weren’t expecting.
  • And install a reliable security solution with an antispam module to filter out at least some of the spam that wriggles through Google’s filter.

Of course this may seem like bleeding obvious advice to you cyber security professionals but it isn’t to many and the word is worth spreading.

Regular victims, sorry darling readers of this blog, might remember us talking about the definitely messed up mystery hacker SandboxEscaper who clearly has a vendetta against Microsoft (almost certainly not alone, have you seen what they are trying to do to CERN?).

Well of course last Tuesday was patch Tuesday and all of the usual suspects belted out multiple patches. Many of Microsoft’s were patches not just against the work of SbE but also to patch previous patches and in some cases patches for patches of patches. A recursion loop is imminent, patch your shizzle before it eats the world.

A day like Patch Tuesday can often be dismissed as ‘just a day’, interesting then that many works of fiction take place in just a day. James Joyce’s Ulysses for instance runs to 730 pages or so and all the action (if you could call it that as you fall into a coma) takes place on one day, the 16th of June 1904 (Father’s day this Sunday, please let us not receive a copy of the mighty tome as punishment for being bad Dads). You probably don’t want to be writing a 730 page report on why your entire organisation was taken down because you didn’t patch, even if it might be more entertaining reading than the work of Joyce.

Prioritising patching (that cannot be automated) is essential and we believe impossible without a vulnerability management platform, something which we are pretty skilled at and would love to help you with. As usual contact us at: [email protected] or call 020 7517 3900 if you would like any advice or just a chat about what Troy Hunt is really like.

It looks like Assange is going to America where no doubt he will receive a very fair trial, after his claims to be a journalist are dismissed. The mood of law enforcers around the world is focussing on punishing hackers and the like as the four year imprisonment of the Welsh hacker Daniel Kelley proves. We can’t see it going well for Mr Assange, can you?

Have a great weekend and Happy Father’s day to Dads good and bad.

要查看或添加评论,请登录

Tom Millar的更多文章

  • Sonic Boom

    Sonic Boom

    It has been an un-seasonably frenetic week in the Cyber Security coal mines this week, so much so that this week’s rant…

    2 条评论
  • Barr Humbug

    Barr Humbug

    Unfortunately we will not be talking about the legendary A.G.

    3 条评论
  • Mug Shot

    Mug Shot

    Unless you have been participating in one of those tiresome live ‘off the grid’ challenges, and we mean a proper one…

  • To Fine, To Serve

    To Fine, To Serve

    Unless you have been stricken with memory loss, brainwashed by positive corporate messaging, or otherwise impaired, you…

  • Silence is Golden

    Silence is Golden

    Do you remember reports about a Russian cybergang called Silence? They launched successful attacks against a number of…

  • Hip Hop

    Hip Hop

    Regular readers of these ramblings will remember that we first reported about the nefarious activities of the Chinese…

  • Delphic Oracle

    Delphic Oracle

    For some time, we have heard rumours circulating in some of the darker parts of the web about issues with Oracle’s…

  • HackFest

    HackFest

    This week has seen a large number of hacking announcements; it is going to be tricky to squeeze even the interesting…

  • Mine Host

    Mine Host

    A couple of weeks ago we talked about a serious vulnerability (wormable, apparently) now called BlueKeep in the…

  • Patient Zero

    Patient Zero

    Have you heard of the mystery hacker SandboxEscaper? To refresh your memories, SandboxEscaper is an avid Windows…

社区洞察

其他会员也浏览了