Security News

Cybersecurity news aggregator

šŸŽ£
HIGH Attacks Graham Cluley

Smashing Security podcast #478: This job interview could destroy your company

The article describes two distinct threats: a North Korean social engineering campaign using fake cryptocurrency job interviews to steal credentials and funds, and a cryptographic vulnerability in an unspecified aftermarket car alarm system that allows unauthorized unlocking or immobilization of approximately 2.2 million US vehicles via Bluetooth. The car alarm vulnerability has been present since 2017, but the article does not provide specific product names, version ranges, CVSS scores, patches, or workarounds for either issue.
Read Full Article →

You've been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment - with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recruiting you doesn't exist. And North Korean hackers using this trick have already made off with $643 million in crypto this year alone. Meanwhile, researchers at UC San Diego have discovered that 2.2 million cars across the United States can be unlocked or immobilised by anyone with a bit of Bluetooth kit - thanks to one aftermarket car alarm that made a truly spectacular cryptographic blunder. The bug has been sitting there since 2017. Nobody noticed. All this and more in episode 478 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Paul Ducklin.

Share this article