Tag: cookies

TamperedChef Malware Disguised as Fake PDF Editors Steals Credentials and Cookies
News

TamperedChef Malware Disguised as Fake PDF Editors Steals Credentials and Cookies

In order to distribute a new information stealer known as TamperedChef, cybersecurity experts have uncovered a cybercrime campaign that uses malvertising techniques to send victims to phony websites. In a study released on Wednesday, Truesec researchers Mattias Wåhlén, Nicklas Keijser, and Oscar Lejerbäck Wolf stated that the goal is to trick victims into downloading and installing a trojanized PDF editor that contains an information-stealing Trojan known as TamperedChef. Credentials and site cookies are among the sensitive data that the malware is intended to collect. The campaign's main tactic is the use of multiple fraudulent websites to advertise an installer for AppSuite PDF Editor, a free PDF editor that, when started and installed, prompts the user to accept the terms of serv...
PayPal files patent for new method to detect stolen cookies
News

PayPal files patent for new method to detect stolen cookies

A new technique that PayPal has submitted for patent protection can detect whether a "super-cookie" is being stolen. This could strengthen the cookie-based authentication system and prevent account takeover attempts. PayPal aims to mitigate the possibility of hackers gaining access to victim accounts by means of stolen cookies that carry authentication tokens, so circumventing two-factor authentication (2FA) and avoiding the requirement for legitimate passwords. According to PayPal's patent application, "cookie theft is a sophisticated form of cyberattack, wherein an attacker copies or steals cookies from a victim's computer onto the attacker's web browser." It is further explained that by using a web browser on the attacker's computer read more PayPal files patent for new method...
France Fines Microsoft $64m for Imposing Ad Cookies to its Bing Users
News

France Fines Microsoft $64m for Imposing Ad Cookies to its Bing Users

The Commission nationale de l'informatique et des libertés (CNIL), France's digital privacy watchdog, stated on December 22, 2022 that it had fined US tech giant Microsoft €60 million ($64 million), its largest fine of the year, for using advertising cookies. The CNIL discovered that Bing, a search engine owned by Microsoft, did not have a system in place that would have allowed users to reject cookies as easily as they might have accepted them, as required by the EU's general data protection rule (GDPR). The regulator added that after looking into the matter, it discovered that "cookies were put on users' terminals when they visited [Bing] without their authorization, and these cookies were utilised, among other things, for advertising reasons." Bing stated that users could accept ...