Cyber Security Today, May 19, 2023 – Beware of .zip websites, Dropbox is abused by crooks, infected Android phones and more

Beware of .zip websites, Dropbox is abused by crooks, infected Android phones and more.

Welcome to Cyber Security Today. It’s Friday, May 19th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.

Cyb er Security Today on Amazon Alexa Cyber Security Today on Google Podcasts Subscribe to Cyber Security Today on Apple Podcasts

 

IT security leaders should regularly warn employees about the risks of downloading unapproved .zip files. Now they have to be warned about going to websites whose addresses end in .zip. Earlier this month Google approved the use of a number of new top-level domains, including one that ends in .zip. So I could get a domain like “www.howard[.]zip”. However, threat actors are already creating malicious websites ending in .zip to take advantage of unsuspecting victims. Researchers at Netcraft say they’ve already found bad websites using this trick, including one named ‘microsoft-office[.]zip’ that goes to a fake Microsoft login page. Make sure your staff knows to stay away from such pages.

Hackers are using free Dropbox accounts to spread malware. Researchers at Avanan detailed how one scheme works: After creating a free Dropbox account the attacker sends a resume as a PDF to a victim. When they click on the PDF they go to Dropbox, which looks legitimate. To view the PDF, the victim has to sign in with their email account credentials. That sends them to a malicious website that looks like Microsoft OneDrive. However, it downloads malware. In addition, the attacker gets the victim’s email login credentials. This scam may fool some IT defence systems that accept DropBox as a non-threatening website. Employees should be warned to be suspicious of resumes they have to log into to view.

Perhaps millions of Android phones sold around the world have been infected during the manufacturing process with malware. That’s according to researchers at Trend Micro. It calls the gang behind this operation Lemon Group, and says over 50 brands of mobile devices have been infected. One is a copy of a premier line of devices from an unnamed major manufacturer. The malware allows the gang to install different plugins, including ones that intercept SMS text messages, steal Facebook and WhatsApp data and push unwanted ads to smartphones. Make sure when you buy an Android phone it comes from a legitimate and trustworthy company or cellphone provider.

Spring is here. And with it people are thinking of summer vacations. McAfee issued a reminder that there are a lot of online travel-related scams. So make sure the hotel, motel or apartment reservation service you use is legitimate. And when you’re on vacation stay away from Wi-Fi networks in airports, restaurants and accommodations. Avoid free USB charging ports at airports and malls as well. One hint: Travel deals that are too good to be true probably are fake.

Finally, Google has issued a patch for its Chrome browser. It closes 12 vulnerabilities. The up-to-date version start in 113 and end in .94.

That’s it for this show. However, later today the Week in Review edition will be out. Guest David Shipley of Beauceron Security and I will discuss recent news including the testimony before a U.S. Senate committee on regulating artificial intelligence, the latest use of facial recognition software and more.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, May 19, 2023 – Beware of .zip websites, Dropbox is abused by crooks, infected Android phones and more first appeared on IT World Canada.

Top Stories

Related Articles

May 31, 2025 A coordinated supply chain attack has compromised between 500 and 1,000 e-commerce websites by exploiting vulnerabilities in 21 more...

May 31, 2025 A widely used open-source Go library, easyjson, used in healthcare, finance and even defence has come under scrutiny more...

May 31, 2025 (EDITORIAL) A messaging tool used by Trump administration officials to archive encrypted Signal messages has been hacked — more...

April 22, 2025 Anthropic, a leading artificial intelligence company, anticipates that AI-powered virtual employees could begin operating within corporate networks as more...

Jim Love

Jim Is and author and pud cast host with over 40 years in technology.