Banking Applications - Google/Apple - Twitter APi's - Questions 4 #Bouzy

1 year ago
112

Everything in this video is in the public domain, I will be showing articles & Relevant information.

Covid fraud losses could top £4.9bn after swindlers given ‘open goal’, MPs warn
https://www.independent.co.uk/news/uk/politics/covid-loans-fraud-government-losses-b2080888.html

Software developer banned for abusing £850,000 of investments
https://www.gov.uk/government/news/software-developer-banned-for-abusing-850000-of-investments

APP fraud is a growing problem for banks
30 March 2022
https://www.finextra.com/blogposting/22075/app-fraud-is-a-growing-problem-for-banks

Warning Issued Against Malicious Apps Having Millions Of Downloads On Google Play And The App Store
https://www.digitalinformationworld.com/2022/09/warning-issued-against-malicious-apps.html

Apple warns of flaw that lets hackers seize control of iPhones, iMacs
https://english.alarabiya.net/business/technology/2022/08/19/Apple-warns-of-flaw-that-lets-hackers-seize-control-of-iPhones-iMacs-

"Xenomorph is a trojan
Xenomorph is a trojan that steals credentials from banking applications on users' devices. It is also capable of intercepting users' SMS messages and notifications, enabling it to steal one-time passwords and multifactor authentication requests.

Security Researchers Discover 10 App Store Apps Engaging in Ad Fraud
https://www.macrumors.com/2022/09/26/ios-app-store-ad-fraud/

Mitigating malware and ransomware attacks
How to defend organisations against malware or ransomware attacks
https://www.ncsc.gov.uk/guidance/mitigating-malware-and-ransomware-attacks

Malicious Google Play Store App Spotted Distributing Xenomorph Banking Trojan
November 11, 2022
https://thehackernews.com/2022/11/these-two-google-play-store-apps.html

App Store stopped nearly $1.5 billion in fraudulent transactions in 2021
Prevented over 1.6 million risky and untrustworthy apps and app updates from defrauding users throughout the year
https://www.apple.com/newsroom/2022/06/app-store-stopped-nearly-one-point-five-billion-in-fraudulent-transactions-in-2021/

https://www.mirror.co.uk/money/fraud-victims-robbed-28000-per-26417102Fraud victims robbed of £28,000 per hour in UK bank transfer scams
According to a study carried out by Which?, customers have been left to shoulder losses of £4.7 million a week or £28,203 a hour -
that’s more than the equivalent of the average UK wage of £25,971.

Big banks in the UK want Big Tech to chip in on fraud repayment
Article by Jenna McNamee | Jul 26, 2022
https://www.insiderintelligence.com/content/big-banks-big-tech-fraud-repayment

Banks warn of fraud ‘epidemic’ as losses soar from authorised push payment scams
Fake investments and fraudsters impersonating the police cost victims the most, says UK Finance
https://www.ft.com/content/df5c61b1-3430-45c3-976a-3af8789a2dae

Two new malicious dropper apps distributed via #Google Play Store have been caught infecting users' #Android devices with Xenomorph banking #malware.
https://twitter.com/TheHackersNews/status/1591158067554500609

Third-party risk is any risk brought on to an organization by external parties in its ecosystem or supply chain. Such parties may include vendors, suppliers, partners, contractors, or service providers,
who have access to internal company or customer data, systems, processes, or other privileged information.2 Sept 2022

Explaining Digital Third Parties

In the software supply chain, third parties are easy to understand.
Software vendors (like SolarWinds) provide a product (Orion) for their customers. Malicious actors can then compromise those customers by compromising the vendor in various ways—in the case of SolarWinds, by injecting malicious code into a legitimate patch or update.
https://www.forbes.com/sites/forbestechcouncil/2022/04/19/five-reasons-why-content-from-third-parties-is-more-dangerous-than-you-think/?sh=595edb102e90

Abuse of Twitter app (and the blocking endpoint) Twitter Developers
https://twittercommunity.com/t/abuse-of-twitter-app-and-the-blocking-endpoint/148699

Twitter API keys found leaked in over 3,200 apps, raising concerns for linked accounts
Business and verified Twitter accounts linked to affected apps are at risk of takeover, use in malicious campaigns
https://www.itpro.co.uk/security/368704/twitter-api-leaks-found-in-over-3200-apps-prompt-security-concerns

Twitter Warns API Flaw Abuse May Have Unmasked Users
'State-Sponsored Actors' Might Be Behind Move to Map Phone Numbers to Accounts
Jeremy Kirk (jeremy_kirk) • February 4, 2020
https://www.bankinfosecurity.com/twitter-api-could-be-used-to-map-phone-numbers-to-accounts-a-13680

Hackers abused Twitter API to match usernames to phone numbers
February 4, 2020 By Pierluigi Paganini
https://securityaffairs.co/wordpress/97286/hacking/hackers-abused-twitter-api.html

Loading comments...