Researchers at SecureWorks have uncovered a new type of phishing attack that tries to trick victims into forwarding their telephone calls to the attacker to thwart attempts by a bank to detect fraud. The attack, found by the Atlanta-based security vendor this week, begins with an e-mail sent from the phisher telling the potential victim their bank needs to verify their phone number immediately, and their account will be suspended if they do not confirm the number. The victim is told to confirm their number by dialing *72 and then another number, effectively forwarding their calls to the phisher's telephone. . After going through this process, the victim is asked in the e-mail to update their personal information, such as bank account and Social Security numbers. If the victim's bank calls to question an unusual transaction while the calls are being forwarded, the phisher need only confirm the illegal transaction is legitimate, SecureWorks researcher Don Jackson wrote on the company's Web site. The link for this article located at eWeek is no longer available. . After going through this process, the victim is asked in the e-mail to update their personal informa. researchers, secureworks, uncovered, phishing, attack, tries, trick, victims. . LinuxSecurity.com Team
The carwhisperer project intends to sensibilise manufacturers of carkits and other Bluetooth appliances without display and keyboard for the possible security threat evolving from the use of standard passkeys. A Bluetooth passkey is used within the pairing process that takes place, when two Bluetooth enabled devices connect for the first time. Besides other public data, the passkey is a secret parameter used in the process that generates and exchanges the so-called link key. In Bluetooth communication scenarios the link key is used for authentication and encryption of the information that is exchanged between the counterparts of the communication. . The cw_scanner script is repeatedly performing a device inquiry for visible Bluetooth devices of which the class matches the one of Bluetooth Headsets and Hands-Free Units. Once a visible Bluetooth device with the appropriate device class is found, the cw_scanner script executes the carwhisperer binary that connects to the found device (on RFCOMM channel 1) and opens a control connection and connects the SCO links. The link for this article located at Trifinite.org is no longer available. . The CarWhisperer initiative improves Bluetooth security in automotive audio systems, tackling vulnerabilities and ensuring user privacy for a safer driving experience. Bluetooth Security,Carkit Security,Communication Threats,Device Inquiry. . LinuxSecurity.com Team
Britain's Civil Aviation Authority has issued a safety alert about a new threat to air passengers: hackers taking over air traffic control transmissions and giving pilots bogus orders. The number of incidents in which radio hackers have broken into frequencies used . . . . Britain's Civil Aviation Authority has issued a safety alert about a new threat to air passengers: hackers taking over air traffic control transmissions and giving pilots bogus orders. The number of incidents in which radio hackers have broken into frequencies used by British air traffic controllers and given false instructions to pilots, or broadcasted fake distress calls, are on an alarming rise. There were three such incidents there in 1998, 18 last year, and now, so far this year, 20. The link for this article located at abcnews.com is no longer available. . An advisory issued by the UK's Civil Aviation Authority highlights increasing risks of radio interference affecting air traffic management systems.. Air Traffic Control, Radio Hacking, Communication Threats, Civil Aviation Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.