New Threat Detected on Binance's Smart Chain!

Gone Phishing Banner

Welcome to Gone Phishing, your daily cybersecurity newsletter that take no cyber-prisoners ๐Ÿ’€

Todayโ€™s hottest cybersecurity news stories:

  • ๐Ÿ’ฒ Binanceโ€™s not so smartchain gets exploited by โ€˜EtherHidingโ€™ ๐Ÿ‘€

  • ๐Ÿšฆ Signal debunks reports of zero-day vuln, finds no evidence ๐Ÿคฒ

  • ๐Ÿ“ฑ Steam adds SMS security check for devs to combat malware ๐Ÿ‘พ

Lost in the Ether โœจ

๐Ÿ” Cybersecurity Alert! New Threat Detected on Binance's Smart Chain!

๐ŸŒ Threat actors have taken their game to the "next level" by using Binance's Smart Chain (BSC) contracts, and it's time to stay informed! This campaign, known as EtherHiding, was discovered by Guardio Labs two months ago.

๐Ÿ‘พ This sneaky malware campaign started by compromising WordPress sites, tricking visitors into updating their browsers, and then unleashing information-stealing malware like Amadey, Lumma, or RedLine.

๐Ÿ’ฅ But now, they've adapted! These cybercriminals are using blockchain, making it decentralised, anonymous, and nearly unstoppable. ๐Ÿ˜ฑ

๐Ÿ•ต๏ธโ€โ™€๏ธ Security experts Nati Tal and Oleg Zaytsev warn that "this campaign is up and harder than ever to detect and take down." ๐Ÿ˜จ

๐Ÿ”— In the latest attacks, malicious code is injected into websites to create a smart contract on the BNB Smart Chain, fetching even more dangerous payloads from a command-and-control (C2) server. Victims are duped into downloading malicious files.

๐Ÿšซ And here's the catch: These criminals are using decentralised services, making it challenging to stop them. ๐Ÿ˜ก

๐Ÿ‘ฎ So, what can you do to stay safe? Keep your WordPress site secure! Update your plugins, remove unnecessary admin users, and use strong passwords. ๐Ÿ’ช

๐Ÿฆ  Stay informed, stay safe, and protect your online world! ๐ŸŒ๐Ÿ›ก๏ธ๐Ÿ”’

Cybersecurity is more important than ever, and your Mac or PC are no exception. Over time, your Mac or PC can accumulate junk files, malware, and other threats that can slow it down and make it vulnerable to attack.

That's where MacPaw comes in. MacPaw offers a suite of easy-to-use apps that can help you clean, optimize, and secure your Mac. With MacPaw, you can:

  • Remove junk files and malware to free up space and improve performance

  • Protect your privacy by erasing sensitive data

  • Optimize your startup settings to speed up boot times

  • Manage your extensions and apps to keep your Mac or PC running smoothly

Since 2008 MacPaw is trusted by over 30 million users worldwide, and it's the perfect solution for keeping your Mac or PC safe and secure.

Hackers: Woah, your sending out mixed Signals ๐Ÿ˜ต

๐Ÿ”’ Signal Denies Zero-Day Vulnerability Reports! ๐Ÿ“ฑ

๐Ÿšซ Signal, the popular encrypted messaging app, has responded to rumours of a zero-day vulnerability, calling them unfounded.

The company conducted a thorough investigation and found no evidence to support the claim. They also reached out to the U.S. government, which could not validate the alleged flaw.

๐Ÿ” Signal is urging anyone with valid information to report it to security@signal[.]org, emphasising the importance of responsible disclosure.

๐Ÿง This comes after reports surfaced over the weekend suggesting a zero-day vulnerability in Signal could potentially grant complete access to a targeted mobile device. As a precaution, users are advised to disable link previews within the app by going to Signal Settings > Chats > Generate link previews.

๐Ÿ’ฐ Meanwhile, the market for zero-day exploits in messaging apps is booming, with prices ranging from $1.7 million to $8 million. These vulnerabilities are highly sought after by nation-state threat actors for remote code execution and surveillance.

๐ŸŒ Amnesty International reports spyware attacks against journalists, politicians, and academics in various regions, aiming to deploy the Predator spyware developed by the Intellexa alliance.

๐Ÿ‘€ Stay vigilant in the world of cybersecurity; threats are evolving fast! ๐ŸŒ๐Ÿ›ก๏ธ

๐ŸŽฃ Catch of the Day!! ๐ŸŒŠ๐ŸŸ๐Ÿฆž

๐Ÿƒ The Motley Fool: โ€œFool me once, shame on โ€” shame on you. Fool me โ€” you can't get fooled again.โ€ Good olโ€™ George Dubya ๐Ÿ˜‚ Let us tell whoโ€™s not fooling around though; thatโ€™s the Crรผe ๐Ÿ‘€ at Motley Fool. Youโ€™d be a fool (alright, enough already! ๐Ÿ™ˆ) not to check out their Share Tips from time to time so your savings can one day emerge from their cocoon as a beautiful butterfly! ๐Ÿ› Kidding aside, if you check out their website theyโ€™ve actually got a ton of great content with a wide variety of different investment ideas to suit most budgets ๐Ÿค‘ (LINK)

๐Ÿšต Wander: Find your happy place. Cue Happy Gilmore flashback ๐ŸŒ๏ธโ›ณ๐ŸŒˆ๐Ÿ•Š๏ธ Mmmm Happy Placeโ€ฆ ๐Ÿ˜‡ So, weโ€™ve noticed a lot of you guys are interested in travel. As are we! We stumbled upon this cool company that offers a range of breath-taking spots around the United States and, honestly, the website alone is worth a gander. When all you see about the Land of the free and the home of the brave is news of rioting, looting and school shootings, itโ€™s easy to forget how beautiful some parts of it are. The awe-inspiring locations along with the innovative architecture of the hotels sets Wander apart from your run of the mill American getaway ๐Ÿž๏ธ๐Ÿ˜ (LINK)

๐ŸŒŠ Digital Ocean: If you build it they will come. Nope, weโ€™re not talking about a baseball field for ghosts โšพ๐Ÿ‘ป๐Ÿฟ (Great movie, to be fair ๐Ÿ™ˆ). This is the Digital Ocean whoโ€™ve got a really cool platform for building and hosting pretty much anything you can think of. If you check out their website youโ€™ll find yourself catching the buzz even if you canโ€™t code (guilty ๐Ÿ˜‘). But if you can and youโ€™re looking for somewhere to test things out or launch something new or simply enhance what youโ€™ve got, weโ€™d recommend checking out their services foโ€™ sho ๐Ÿ˜‰ And how can you not love their slogan: Dream it. Build it. Grow it. Right on, brother! ๐ŸŒฟ (LINK)

SMS Our Souls ๐Ÿ™

๐ŸŽฎ Valve Introduces SMS-Based Security for Steam Developers ๐Ÿ“ฑ

Valve, the force behind the Steam gaming platform, is upping its security game in response to reports of malware-infected game updates.

Last month, some gamers received alarming messages from Steam support, revealing that certain game updates contained malware. Valve claims fewer than 100 people downloaded these infected games.

๐Ÿ•ต๏ธโ€โ™‚๏ธ One affected game, "NanoWar: Cells VS Virus," developer Benoit Fresion, reported a compromise of his Steam developer account due to stolen session cookies from his browser.

๐Ÿ“ฒ Valve's new security measure is SMS-based, providing game developers with a confirmation code via text message during login attempts to update their apps. This adds an extra layer of verification beyond a username and password.

โš ๏ธ However, experts warn that SMS-based two-factor authentication can be vulnerable to SIM swap attacks. Hackers can trick mobile carriers into switching a phone number to a different SIM card and gain access to verification codes sent via SMS.

๐Ÿ’ช While this step is an improvement, stronger security options like app-based TOTP authenticators or hardware keys could offer better protection.

๐Ÿ” Steam developers are advised to link their phone numbers to their accounts by October 24, 2023, to enhance security.

๐Ÿ–ฅ๏ธ In addition, safeguard your devices and computers to protect your game development work from malicious threats.

๐ŸŽฎ Stay safe in the gaming world! ๐Ÿ›ก๏ธ

๐Ÿ—ž๏ธ Extra, Extra! Read all about it!

Every few weeks, we carefully select three hot newsletters to show you. Reputation is everything, so any links we share come from personal recommendation or carefully researched businesses at the time of posting. Enjoy!

  • ๐Ÿ’Š HealthHack: Tech is making it easier than ever to reach your fitness goals, from wearable devices to nutrition apps, this newsletter does the research for you, get all the latest health tech gadgets delivered to your inbox. 

  • โ‚ฟ Crypto Nutshell: A well written and beautifully designed newsletter giving you the lowdown on crypto and web3, highly recommend if interested to get up to date info on the crypto/web3 market.

  • ๐Ÿง  Big Brain: Trending AI news, jobs and tools delivered in 3 minutes per day.

Let us know what you think!

So long and thanks for reading all the phish!

Give us a rating?

Login or Subscribe to participate in polls.