Tag Archive for: media

Popular Social Media App Discord Clamps Down To Fight Cyber Attacks – Forbes Advisor


Editorial Note: We earn a commission from partner links on Forbes Advisor. Commissions do not affect our editors’ opinions or evaluations.

Multimedia social platform Discord is cracking down on malicious links, known as malware, by activating stronger security measures. From now on, Discord links that are shared outside the platform will expire after 24 hours. The goal is to lessen users’ exposure to malware, making it harder for identity thieves to steal users’ personal and financial information.

Hackers commonly exploit Discord servers to host malicious files and distribute malware. Malware can include spyware, key-loggers and viruses that infect users’ computers and reveal personal data and access codes, enabling identity theft and other crimes. In the past, familiarity with the Discord brand has often led users to click seemingly safe links that turned out to be malware, bringing on a cyberattack.

The new 24-hour expiration feature will only apply to links shared outside of Discord. Within Discord, shared file links will update automatically, so internal users can access files without the threat of expiration.

“There is no impact for Discord users that share content within the Discord client. Any links within the client will be auto-refreshed,” said Discord communications manager Hannah Stabingas.

Stabingas said the new measures, rolling out in December 2023 and early 2024, will enhance privacy and security for the app’s 150 million-plus active monthly users.

“This will help our safety team restrict access to flagged content and generally reduce the amount of malware distributed using our CDN (content delivery network),” Stabingas said.

Malware has been an ongoing problem for Discord. According to Discord’s latest transparency report, during the third quarter of 2023, 11,885 accounts and 2,389 servers were removed from the platform for deceptive practices. These practices include malware, fraud and scams, according to the report.

Cybersecurity expert Jake Williams, a faculty member at the Institute for Applied Network Security (IANS), says the new changes will likely be…

Source…

Sophisticated KV-botnet linked to Volt Typhoon – SC Media



Sophisticated KV-botnet linked to Volt Typhoon  SC Media

Source…

Data leaks, AI and ransomware topped the headlines in 2023 for SC Media


Ransomware, cloud leaks and AI — oh my! It was a year when both old and new cyber threats shared center stage, while cybersecurity teams also raced to meet creeping compliance deadlines.

Here is a roundup of 10 of SC Media’s most-viewed stories this year, including a mix of news, analysis and opinion, as well as “honorable mentions” that hit on the topics that mattered most to you.

1. 260K dating profiles leaked in publicly accessible ASW S3 storage

Sensitive data doesn’t get much more sensitive than the 340 GB of files leaked by an app called 419 Dating – Chat & Flirt. As we reported in July, a publicly accessible database was discovered in an Amazon Web Services S3 storage bucket by vpnMentor researcher Jeremiah Fowler, who believed the leak was most likely due to a misconfigured firewall. In addition to 260,000 user account email addresses, the database contained explicit photographs and Software Development Kit files for two other dating apps.

Honorable mentions – more on cloud security:

2. NPM software repository flooded with 15K phishing packages

This incident in February highlights dangers lurking in the open-source ecosystem. Thousands of software packages promising game cheats and increased followers on social media platforms like TikTok were uploaded to the NPM repository to lure users to phishing websites. Researchers from Checkmarx said they believed the phishing packages were distributed using an automated process and carried out through multiple user accounts, making it difficult to quickly detect and remove the malicious packages.

Honorable mentions – more on phishing:

3. Google details 0-click bug in Pixel 6 modem

This vulnerability — or rather, a combination of two critical vulnerabilities — could allow an adversary with the right resources to hijack a victim’s Android handset simply by initiating a phone call. Because the exploit relies on the ability to downgrade the Pixel 6’s cellular modem communication to 2G, the Android Red Team members who disclosed the bug at Black Hat in August recommended that all Android users disable 2G communication.

Honorable mentions – more on vulnerability management:

4. Cybercriminals are already using ChatGPT to…

Source…

Synacor Fast Tracks Complex Streaming Integrations With Cloud ID™ Media Connect


Synacor, Inc.

Synacor, Inc.

Consumer identity access management pre-integrations with 500+ networks, services, MVPDs and platforms slashes rollout times for new content deals and launches

Synacor Fast Tracks Complex Streaming Integrations With Cloud ID™ Media Connect

Consumer identity access management pre-integrations with 500+ networks, services, MVPDs and platforms slashes rollout times for new content deals and launchesConsumer identity access management pre-integrations with 500+ networks, services, MVPDs and platforms slashes rollout times for new content deals and launches

Consumer identity access management pre-integrations with 500+ networks, services, MVPDs and platforms slashes rollout times for new content deals and launches

BUFFALO, N.Y., Dec. 20, 2023 (GLOBE NEWSWIRE) — Synacor today announced the Cloud ID™ Media Connect managed consumer identity access management (“CIAM”) service to fast track streaming ecosystem deployments amid a heavily fragmented viewing market. Cloud ID Media Connect can save streaming media companies months or even years of authentication integration work required to connect streaming services to various platforms. The new offering, which is pre-integrated with more than 500 networks, services, MVPDs and platforms, comes as changing business models, more complex deals and a continued wave of new content providers upend streaming market dynamics.

As the streaming market matures, more content is being distributed to more platforms. Deals are often made on the fly with urgent rollout requirements. More content providers are entering the market with no prior experience navigating an increasingly splintered ecosystem. At the same time, security requirements are more pressing than ever, demanding SAML or OAuth integrations that can each take weeks or months to complete and require ongoing support and maintenance. This is further complicated by many providers not offering standard authentication endpoints, requiring custom API integrations. It is not uncommon for content providers to support a dozen or more platform integrations at a time, and some MVPDs or streaming TV providers must accommodate literally thousands of combinations of content provider apps and streaming platforms.

Based on more than a decade of experience managing comprehensive authentication integrations for premium entertainment services, Cloud ID Media Connect delivers a reliable, managed CIAM solution that is now pre-integrated with more than 500 content distributors, platforms and MVPDs, including…

Source…