<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security | Matt Crawford</title>
	<atom:link href="https://mattcrawford.me/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>https://mattcrawford.me</link>
	<description>Handyman &#124; Geek &#124; YouTuber</description>
	<lastBuildDate>Wed, 15 Jun 2022 00:16:07 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.3</generator>
<site xmlns="com-wordpress:feed-additions:1">176948450</site>	<item>
		<title>Interesting Phishing Attempt</title>
		<link>https://mattcrawford.me/interesting-phishing-attempt/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=interesting-phishing-attempt</link>
					<comments>https://mattcrawford.me/interesting-phishing-attempt/#comments</comments>
		
		<dc:creator><![CDATA[Matt Crawford]]></dc:creator>
		<pubDate>Wed, 28 Oct 2020 18:00:00 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[e-mail]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[html]]></category>
		<category><![CDATA[lame]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[phishing e-mail]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://mattcrawford.me/?p=5500</guid>

					<description><![CDATA[<p>One of my co-workers received an e-mail with an attachment titled &#8220;INVOICE_26.HTML&#8221; and asked if there was anyway to scan it before clicking on it. Since it&#8217;s an .html file virus scanners would claim it was not infected since the file isn&#8217;t infected with a virus or trojan. This is just a phishing attempt which [&#8230;]</p>
The post <a href="https://mattcrawford.me/interesting-phishing-attempt/">Interesting Phishing Attempt</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">One of my co-workers received an e-mail with an attachment titled &#8220;<strong>INVOICE_26.HTML</strong>&#8221; and asked if there was anyway to scan it before clicking on it.  </p>



<p class="wp-block-paragraph">Since it&#8217;s an .html file virus scanners would claim it was not infected since the file isn&#8217;t infected with a virus or trojan. This is just a phishing attempt which starts when a user opens the fake internet page.</p>



<p class="wp-block-paragraph">So I viewed the source code of the file in notepad ++ and this is what I found.</p>



<pre class="wp-block-code"><code>&lt;!DOCTYPE html>
&lt;html>
&lt;head>
&lt;meta name="viewport" content="width=device-width, initial-scale=1">
&lt;style>
.container {
  position: relative;
  width: 100%;
  max-width: 400px;
}

.container img {
  width: 100%;
  height: auto;
}

.container .btn {
  position: absolute;
  top: 50%;
  left: 50%;
  transform: translate(-50%, -50%);
  -ms-transform: translate(-50%, -50%);
  background-color: #228B22;
  color: white;
  font-size: 16px;
  padding: 12px 24px;
  border: none;
  cursor: pointer;
  border-radius: 5px;
  text-align: center;
}

.container .btn:hover {
  background-color: black;
}
&lt;/style>
&lt;/head>
&lt;body>

&lt;h2>&lt;font face="arial">&lt;u>D&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>ocu&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>ment is sec&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>ured&lt;/u>&lt;/font>&lt;/h2>&lt;br>
&lt;p>&lt;b>&lt;font face="sans serif">Cl&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>ic&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>k be&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>low to v&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>iew com&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>ple&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>te fi&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>le&lt;/font>&lt;/b>&lt;/p>

&lt;div class="container">
  &lt;img src="https://i.ibb.co/qghx6vy/b.jpg" alt="invoice" style="width:100%;height:100%">
  &lt;button class="btn" onclick="window.location.href='https://ingenioxicotencatl.com/adk/wamp.php?warp=020202'" >Vie&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>w Fi&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>le&lt;/button>
&lt;/div>

&lt;/body>
&lt;/html></code></pre>



<p class="wp-block-paragraph">If you actually look through the code you will quickly learn that all that gibberish and random letters will not show up on the page due to it being between the tags shown below.</p>



<pre class="wp-block-code"><code>&lt;span style="font-size: 0px"> &lt;/span></code></pre>



<p class="wp-block-paragraph">Instead anybody viewing the page would simply see the following words.</p>



<pre class="wp-block-preformatted">Document is secured

Click below to view complete file

View File</pre>



<p class="wp-block-paragraph">The words &#8220;View File&#8221; are actually a button which goes to the url shown in the code above. </p>



<p class="wp-block-paragraph">Aka this is just a lame phishing attempt that somebody is trying to confuse the average person with however I&#8217;m no average person and simply do not fall for tricks like this.</p>



<p class="wp-block-paragraph">Check out the links below for more information regarding phishing.</p>



<ul class="wp-block-list"><li><a href="https://ideas.ted.com/why-we-fall-for-phishing-emails-and-how-we-can-protect-ourselves/" target="_blank" rel="noreferrer noopener">Why we fall for phishing e-mails</a> </li><li><a href="https://blog.malwarebytes.com/101/2018/09/6-sure-signs-someone-is-phishing-you-besides-email/" target="_blank" rel="noreferrer noopener">6 sure signs somebody is phishing you</a></li><li><a href="https://www.globallearningsystems.com/what-to-do-after-a-phishing-attack/" target="_blank" rel="noreferrer noopener">What to do after a phishing attack</a>.</li><li><a href="https://www.technologyvisionaries.com/latest-phishing-scams/" target="_blank" rel="noreferrer noopener">What are the latest phishing scams in 2020</a></li></ul>



<p class="wp-block-paragraph">Leave me a comment below if you enjoyed this article!</p>The post <a href="https://mattcrawford.me/interesting-phishing-attempt/">Interesting Phishing Attempt</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></content:encoded>
					
					<wfw:commentRss>https://mattcrawford.me/interesting-phishing-attempt/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">5500</post-id>	</item>
		<item>
		<title>Coronavirus and you</title>
		<link>https://mattcrawford.me/coronavirus-and-you/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=coronavirus-and-you</link>
					<comments>https://mattcrawford.me/coronavirus-and-you/#respond</comments>
		
		<dc:creator><![CDATA[Matt Crawford]]></dc:creator>
		<pubDate>Tue, 17 Mar 2020 15:02:53 +0000</pubDate>
				<category><![CDATA[Random]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[china virus]]></category>
		<category><![CDATA[coronavirus]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[health]]></category>
		<category><![CDATA[pandemic]]></category>
		<category><![CDATA[united states]]></category>
		<category><![CDATA[virus]]></category>
		<guid isPermaLink="false">https://t3dus.com/?p=5165</guid>

					<description><![CDATA[<p>By now you likely have seen the news regarding the Coronavirus (COVID-19) and how essentially the world has &#8220;shutdown&#8221; over concerns about spreading the Coronavirus around. If you haven&#8217;t I suggest you check out the CDC website to learn about it. Since Coronavirus has spread most people are hording: Toilet paper Soap Cleaning products Hand [&#8230;]</p>
The post <a href="https://mattcrawford.me/coronavirus-and-you/">Coronavirus and you</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">By now you likely have seen the news regarding the Coronavirus (COVID-19) and how essentially the world has &#8220;shutdown&#8221; over concerns about spreading the Coronavirus around. If you haven&#8217;t I suggest you check out the <a rel="noreferrer noopener" aria-label=" (opens in a new tab)" href="https://www.cdc.gov/coronavirus/2019-ncov/" target="_blank">CDC website to learn about it.</a></p>



<p class="wp-block-paragraph">Since Coronavirus has spread most people are hording:</p>



<ul class="wp-block-list"><li>Toilet paper</li><li>Soap</li><li>Cleaning products</li><li>Hand Sanitizer </li><li>Masks</li><li>Food</li></ul>



<p class="wp-block-paragraph">Since Coronavirus has spread many nations &amp; companies are:</p>



<ul class="wp-block-list"><li>shutting down stores</li><li>closing schools</li><li>closing jobs or pushing working from home</li><li>canceling sporting events</li><li>canceling concerts, festivals, parades, etc</li><li>offering free remote tools to work from home</li></ul>



<p class="wp-block-paragraph">Essentially the entire world is &#8220;shutdown&#8221; until further notice.</p>



<p class="wp-block-paragraph">I urge everybody to take precautions but remain calm during this Coronavirus pandemic since freaking out will only cause added stress and chaos in an already crazy world. </p>



<p class="wp-block-paragraph">Follow the steps at the <a rel="noreferrer noopener" aria-label="CDC Website (opens in a new tab)" href="https://www.cdc.gov/coronavirus/2019-ncov/prepare/prevention.html" target="_blank">CDC Website</a> to take steps to protect yourself.</p>



<p class="wp-block-paragraph">While the Coronavirus pandemic may be a very serious threat to the well being of people, I believe it&#8217;s also a great way for the government to control people in each nation &amp; confine us all to our homes or take away other freedoms. </p>



<h2 class="wp-block-heading">The Earn It Act</h2>



<p class="wp-block-paragraph">For example while the Coronavirus pandemic is going on congress is trying to pass &#8220;The EARN IT Act&#8221; which will do away with encryption and give the government the backdoor they have long wanted into your data. <a rel="noreferrer noopener" aria-label=" (opens in a new tab)" href="https://nakedsecurity.sophos.com/2020/03/13/earn-it-act-threatens-end-to-end-encryption/" target="_blank">Read about it here</a>. </p>



<p class="wp-block-paragraph">If you haven&#8217;t yet please subscribe to my blog to keep on up my posts!</p>The post <a href="https://mattcrawford.me/coronavirus-and-you/">Coronavirus and you</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></content:encoded>
					
					<wfw:commentRss>https://mattcrawford.me/coronavirus-and-you/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">5165</post-id>	</item>
		<item>
		<title>The cyber attack that knocked out Ukraine this morning is now going global</title>
		<link>https://mattcrawford.me/cyber-attack-knocked-ukraine-morning-now-going-global/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cyber-attack-knocked-ukraine-morning-now-going-global</link>
					<comments>https://mattcrawford.me/cyber-attack-knocked-ukraine-morning-now-going-global/#comments</comments>
		
		<dc:creator><![CDATA[Matt Crawford]]></dc:creator>
		<pubDate>Tue, 27 Jun 2017 19:04:01 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[bitcoins]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Petya]]></category>
		<category><![CDATA[ransomware]]></category>
		<guid isPermaLink="false">https://g3k.xyz/?p=2785</guid>

					<description><![CDATA[<p>A sweeping set of cyber attacks hit critical services in Ukraine this morning, and have so far shown no signs of slowing down. The attacks appear to be related to a new strain of the ransomware known as Petya, which Costin Raiu, director of global research and analysis at Kaspersky Lab, says is already spreading [&#8230;]</p>
The post <a href="https://mattcrawford.me/cyber-attack-knocked-ukraine-morning-now-going-global/">The cyber attack that knocked out Ukraine this morning is now going global</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></description>
										<content:encoded><![CDATA[<p>A sweeping set of cyber attacks hit critical services in Ukraine this morning, and have so far shown no signs of slowing down. The attacks appear to be related to a new strain of the ransomware known as Petya, which Costin Raiu, director of global research and analysis at Kaspersky Lab, says is already spreading worldwide.</p>
<p>In the space of hours, Ukraine’s government, top energy companies, private and state banks, main airport, and Kyiv’s metro system all reported hits on their systems. The attacker was not immediately clear—Wired, in a recent story, <a href="https://www.wired.com/story/russian-hackers-attack-ukraine/">described Russia</a> as using its neighbor as a “test lab for cyber war,” but Moscow denies any part in past attacks. Its own state oil giant Rosneft <a href="https://twitter.com/jc_stubbs/status/879679832241696769">also reported</a> being hit by a cyberattack today; Rosneft’s website was unresponsive at time of writing. It’s unclear if the attacks are linked. Another Russian oil firm, Bashneft, <a href="https://twitter.com/Reevellp/status/879712232740966400">has been hit too</a>.</p>
<p>More at <a href="https://qz.com/1015755/ukraine-cyber-attack-the-petyapetrwrap-ransomware-with-similarities-to-wannacry-is-now-going-global/">QZ.com</a></p>
<p>&nbsp;</p>The post <a href="https://mattcrawford.me/cyber-attack-knocked-ukraine-morning-now-going-global/">The cyber attack that knocked out Ukraine this morning is now going global</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></content:encoded>
					
					<wfw:commentRss>https://mattcrawford.me/cyber-attack-knocked-ukraine-morning-now-going-global/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2785</post-id>	</item>
		<item>
		<title>Vault 7 : CIA Hacking Tools Revealed!</title>
		<link>https://mattcrawford.me/vault-7-cia-hacking-tools-revealed/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=vault-7-cia-hacking-tools-revealed</link>
					<comments>https://mattcrawford.me/vault-7-cia-hacking-tools-revealed/#respond</comments>
		
		<dc:creator><![CDATA[Matt Crawford]]></dc:creator>
		<pubDate>Fri, 10 Mar 2017 16:02:29 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cia]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[nsa]]></category>
		<category><![CDATA[spying]]></category>
		<category><![CDATA[united states]]></category>
		<category><![CDATA[usa]]></category>
		<category><![CDATA[vault7]]></category>
		<category><![CDATA[wikileaks]]></category>
		<guid isPermaLink="false">https://g3k.xyz/?p=2670</guid>

					<description><![CDATA[<p>Wiki leaks released details about CIA hacking tools and how extensive their spying really is and the news is absolutely terrifying! If you weren&#8217;t worried about privacy before then you should be now! &#160; Read the full details here at WikiLeaks</p>
The post <a href="https://mattcrawford.me/vault-7-cia-hacking-tools-revealed/">Vault 7 : CIA Hacking Tools Revealed!</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></description>
										<content:encoded><![CDATA[<p>Wiki leaks released details about CIA hacking tools and how extensive their spying really is and the news is absolutely terrifying!</p>
<p>If you weren&#8217;t worried about privacy before then you should be now!</p>
<p>&nbsp;</p>
<p>Read the full details here at <a href="https://wikileaks.org/ciav7p1/">WikiLeaks</a></p>The post <a href="https://mattcrawford.me/vault-7-cia-hacking-tools-revealed/">Vault 7 : CIA Hacking Tools Revealed!</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></content:encoded>
					
					<wfw:commentRss>https://mattcrawford.me/vault-7-cia-hacking-tools-revealed/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2670</post-id>	</item>
		<item>
		<title>E-mail Scams &#038; Phishing</title>
		<link>https://mattcrawford.me/e-mail-scams-phishing/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=e-mail-scams-phishing</link>
					<comments>https://mattcrawford.me/e-mail-scams-phishing/#respond</comments>
		
		<dc:creator><![CDATA[Matt Crawford]]></dc:creator>
		<pubDate>Thu, 09 Feb 2017 21:13:46 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[e-mail phishing]]></category>
		<category><![CDATA[e-mails]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[office 365]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scams]]></category>
		<guid isPermaLink="false">https://g3k.xyz/?p=2621</guid>

					<description><![CDATA[<p>We have been getting a ton of E-mail Scams and Phishing e-mails at work lately (mostly due to Office 365 and their poor spam filtering) and I wanted to take a few minutes to share some of them and point out how you can easily detect that they are not Genuine e-mails. Please leave us [&#8230;]</p>
The post <a href="https://mattcrawford.me/e-mail-scams-phishing/">E-mail Scams & Phishing</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></description>
										<content:encoded><![CDATA[<p>We have been getting a ton of E-mail Scams and Phishing e-mails at work lately (mostly due to Office 365 and their poor spam filtering) and I wanted to take a few minutes to share some of them and point out how you can easily detect that they are not Genuine e-mails.</p>
<p>Please leave us a comment at the bottom if you might of fallen for one of these phishing e-mails!</p>
<h3>Colorful&nbsp;Language!</h3>
<p style="padding-left: 30px;">This first one is from somebody claiming to be &#8220;Cadwalader, Wickersham and Taft LLP&#8221;&nbsp;using colorful language and trying to trick you into clicking on a fake link to what is likely a phishing website or virus/malware.</p>
<p style="padding-left: 30px;"><a href="https://mattcrawford.me/wp-content/uploads/2017/02/cadwalader_b.png"><img fetchpriority="high" decoding="async" class="alignnone size-full wp-image-2629" src="https://mattcrawford.me/wp-content/uploads/2017/02/cadwalader_b.png" alt="" width="560" height="241" srcset="https://mattcrawford.me/wp-content/uploads/2017/02/cadwalader_b.png 560w, https://mattcrawford.me/wp-content/uploads/2017/02/cadwalader_b-300x129.png 300w" sizes="(max-width: 560px) 100vw, 560px" /></a></p>
<h3>Apple Phishing</h3>
<p style="padding-left: 30px;">This 2nd one is claiming to be from Apple &amp; is trying to trick you to click a link and login to your apple account.</p>
<p style="padding-left: 30px;">Were you to actually click the link and login to your apple account they likely would capture your real apple password through the fake website!</p>
<p style="padding-left: 30px;"><a href="https://mattcrawford.me/wp-content/uploads/2017/02/Apple.png"><img decoding="async" class="alignnone size-full wp-image-2627" src="https://mattcrawford.me/wp-content/uploads/2017/02/Apple.png" alt="" width="480" height="720" srcset="https://mattcrawford.me/wp-content/uploads/2017/02/Apple.png 480w, https://mattcrawford.me/wp-content/uploads/2017/02/Apple-200x300.png 200w" sizes="(max-width: 480px) 100vw, 480px" /></a></p>
<h3>Upgrade your Account!</h3>
<p style="padding-left: 30px;">This is a phishing e-mail trying to trick you into clicking on a link to &#8220;Upgrade&#8221; your account to see your &#8220;missing e-mails&#8221;</p>
<p style="padding-left: 30px;"><a href="https://mattcrawford.me/wp-content/uploads/2017/02/Phishing-upgradeacct.png"><img decoding="async" class="alignnone size-full wp-image-2630" src="https://mattcrawford.me/wp-content/uploads/2017/02/Phishing-upgradeacct.png" alt="" width="352" height="282" srcset="https://mattcrawford.me/wp-content/uploads/2017/02/Phishing-upgradeacct.png 352w, https://mattcrawford.me/wp-content/uploads/2017/02/Phishing-upgradeacct-300x240.png 300w" sizes="(max-width: 352px) 100vw, 352px" /></a></p>
<p style="padding-left: 30px;">Here&#8217;s another one trying to trick you into clicking a link to upgrade your account.</p>
<p style="padding-left: 30px;"><a href="https://mattcrawford.me/wp-content/uploads/2017/02/Phishing-upgradeacct2.png"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-2632" src="https://mattcrawford.me/wp-content/uploads/2017/02/Phishing-upgradeacct2.png" alt="" width="685" height="205" srcset="https://mattcrawford.me/wp-content/uploads/2017/02/Phishing-upgradeacct2.png 685w, https://mattcrawford.me/wp-content/uploads/2017/02/Phishing-upgradeacct2-300x90.png 300w" sizes="(max-width: 685px) 100vw, 685px" /></a></p>
<h3>Print This</h3>
<p style="padding-left: 30px;">This one is trying to trick the user into clicking a link so they can help somebody out by &#8220;printing&#8221; a document for them.&nbsp;Quite a weird phishing e-mail if u ask me!</p>
<p style="padding-left: 30px;"><a href="https://mattcrawford.me/wp-content/uploads/2017/02/phishing-printthis.jpg"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-2633" src="https://mattcrawford.me/wp-content/uploads/2017/02/phishing-printthis.jpg" alt="" width="490" height="222" srcset="https://mattcrawford.me/wp-content/uploads/2017/02/phishing-printthis.jpg 490w, https://mattcrawford.me/wp-content/uploads/2017/02/phishing-printthis-300x136.jpg 300w" sizes="(max-width: 490px) 100vw, 490px" /></a></p>
<h3>You&#8217;ve been selected!</h3>
<p style="padding-left: 30px;">Phishing scam from &#8220;Amazon&#8221; trying to get you to complete some survey. It&#8217;s not really from amazon and u won&#8217;t actually get anything but maybe some malware or a virus if you do anything this says!</p>
<p style="padding-left: 30px;"><a href="https://mattcrawford.me/wp-content/uploads/2017/02/phishing-youbeenselected.png"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-2634" src="https://mattcrawford.me/wp-content/uploads/2017/02/phishing-youbeenselected.png" alt="" width="844" height="715" srcset="https://mattcrawford.me/wp-content/uploads/2017/02/phishing-youbeenselected.png 844w, https://mattcrawford.me/wp-content/uploads/2017/02/phishing-youbeenselected-300x254.png 300w, https://mattcrawford.me/wp-content/uploads/2017/02/phishing-youbeenselected-768x651.png 768w" sizes="(max-width: 844px) 100vw, 844px" /></a></p>
<p>Would you of fallen for any of these phishing e-mails?! Leave us a comment below!</p>The post <a href="https://mattcrawford.me/e-mail-scams-phishing/">E-mail Scams & Phishing</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></content:encoded>
					
					<wfw:commentRss>https://mattcrawford.me/e-mail-scams-phishing/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2621</post-id>	</item>
		<item>
		<title>Over 67,000 Websites Defaced via Recently Patched WordPress Bug</title>
		<link>https://mattcrawford.me/over-67000-websites-defaced-via-recently-patched-wordpress-bug/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=over-67000-websites-defaced-via-recently-patched-wordpress-bug</link>
					<comments>https://mattcrawford.me/over-67000-websites-defaced-via-recently-patched-wordpress-bug/#respond</comments>
		
		<dc:creator><![CDATA[Matt Crawford]]></dc:creator>
		<pubDate>Tue, 07 Feb 2017 18:39:15 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[defacement]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress update]]></category>
		<guid isPermaLink="false">https://g3k.xyz/?p=2613</guid>

					<description><![CDATA[<p>WordPress sites that haven&#8217;t been updated to the most recent version, v4.7.2, released last week, are under attack as four hacking groups are conducting mass defacement campaigns. According to web security firm Sucuri, who detected the attacks after details of the vulnerability became public last Monday, the attacks have been slowly growing, reaching almost 3,000 [&#8230;]</p>
The post <a href="https://mattcrawford.me/over-67000-websites-defaced-via-recently-patched-wordpress-bug/">Over 67,000 Websites Defaced via Recently Patched WordPress Bug</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></description>
										<content:encoded><![CDATA[<p>WordPress sites that haven&#8217;t been updated to the most recent version, v4.7.2, released last week, are under attack as four hacking groups are conducting mass defacement campaigns.</p>
<p>According to web security firm Sucuri, who detected the attacks after details of the vulnerability became public last Monday, the attacks have been slowly growing, reaching almost 3,000 defacements per day.</p>
<p>Attackers are exploiting a vulnerability in the WordPress REST API, which the WordPress team fixed almost two weeks ago, but for which they <a href="https://www.bleepingcomputer.com/news/security/wordpress-team-fixed-a-zero-day-behind-everyones-back-and-told-no-one/" target="_blank" rel="noopener noreferrer">published public details last Monday</a>.</p>
<p><figure id="attachment_2614" aria-describedby="caption-attachment-2614" style="width: 800px" class="wp-caption alignnone"><a href="https://t3dus.com/wp-content/uploads/2017/02/Chart-exploit-attempts.png"><img loading="lazy" decoding="async" class="wp-image-2614 size-full" src="https://t3dus.com/wp-content/uploads/2017/02/Chart-exploit-attempts.png" width="800" height="526" srcset="https://mattcrawford.me/wp-content/uploads/2017/02/Chart-exploit-attempts.png 800w, https://mattcrawford.me/wp-content/uploads/2017/02/Chart-exploit-attempts-300x197.png 300w, https://mattcrawford.me/wp-content/uploads/2017/02/Chart-exploit-attempts-768x505.png 768w" sizes="(max-width: 800px) 100vw, 800px" /></a><figcaption id="caption-attachment-2614" class="wp-caption-text">Defacement attempts via REST API flaw over time (via Sucuri)</figcaption></figure></p>
<p>The vulnerability allows a remote attacker to craft an HTTP request that pings a REST API endpoint and alters titles and content on the user&#8217;s website.</p>
<p>Exploiting the flaw is trivial, and according to Sucuri, a few public exploits have been published online since last week.</p>
<h2>Over 67,000 websites defaced already</h2>
<p>Even if the vulnerability affects only WordPress 4.7.0 and 4.7.1 and the CMS has a built-in auto-update feature for security issues, many websites haven&#8217;t been updated.</p>
<p>Based on data collected from Sucuri&#8217;s honeypot test servers, four attackers have been busy in the past week trying to exploit the flaw.</p>
<table border="0" cellspacing="1" cellpadding="1">
<tbody>
<tr>
<td>Group name</td>
<td>IP</td>
<td>Estimated victims</td>
</tr>
<tr>
<td>w4l3XzY3</td>
<td>176.9.36.102<br />
185.116.213.71<br />
134.213.54.163<br />
2a00:1a48:7808:104:9b57:dda6:eb3c:61e1 (IPv6 address)</td>
<td>66,000</td>
</tr>
<tr>
<td>Cyb3r-Shia</td>
<td>37.237.192.22</td>
<td>500</td>
</tr>
<tr>
<td>By+NeT.Defacer</td>
<td>144.217.81.160</td>
<td>500</td>
</tr>
<tr>
<td>By+Hawleri_hacker</td>
<td>144.217.81.160</td>
<td>500</td>
</tr>
</tbody>
</table>
<p>Since the attacks have been going on for some days, Google has already started to index some of these defacements.</p>
<p><figure id="attachment_2615" aria-describedby="caption-attachment-2615" style="width: 967px" class="wp-caption alignnone"><a href="https://t3dus.com/wp-content/uploads/2017/02/Google-Results.png"><img loading="lazy" decoding="async" class="wp-image-2615 size-full" src="https://t3dus.com/wp-content/uploads/2017/02/Google-Results.png" width="967" height="560" srcset="https://mattcrawford.me/wp-content/uploads/2017/02/Google-Results.png 967w, https://mattcrawford.me/wp-content/uploads/2017/02/Google-Results-300x174.png 300w, https://mattcrawford.me/wp-content/uploads/2017/02/Google-Results-768x445.png 768w" sizes="(max-width: 967px) 100vw, 967px" /></a><figcaption id="caption-attachment-2615" class="wp-caption-text">Defaced websites indexed by Google</figcaption></figure></p>
<p>Currently, the groups using the REST API flaw to deface websites are only doing it for public brand exposure, only altering page titles and their content by adding their own name.<br />
<a href="https://t3dus.com/wp-content/uploads/2017/02/Defaced-Site.png"><img loading="lazy" decoding="async" class="size-full wp-image-2616" src="https://t3dus.com/wp-content/uploads/2017/02/Defaced-Site.png" alt="" width="967" height="537" srcset="https://mattcrawford.me/wp-content/uploads/2017/02/Defaced-Site.png 967w, https://mattcrawford.me/wp-content/uploads/2017/02/Defaced-Site-300x167.png 300w, https://mattcrawford.me/wp-content/uploads/2017/02/Defaced-Site-768x426.png 768w" sizes="(max-width: 967px) 100vw, 967px" /></a> One of the defaced sites</p>
<p>Sucuri&#8217;s CTO, Daniel Cid, <a href="https://blog.sucuri.net/2017/02/wordpress-rest-api-vulnerability-abused-in-defacement-campaigns.html" target="_blank" rel="nofollow noopener noreferrer">expects to see</a> professional defacers enter the fold, such as SEO spam groups that will utilize the vulnerability to post more complex content, such as links and images.</p>
<p>This types of defacements are used to boost the SEO ranking of other sites or promote shady products. Websites that suffer from SEO-targeted defacements also have their SERP (Search Engine Result Page) indicator affected and risk losing their reputation on search engines, which in turns drives down traffic to their site.</p>
<p>Website owners are advised to update to WordPress 4.7.2. as soon as possible in order to avoid losing visibility on Google due to this REST API security issue.</p>
<p>Source: <a href="https://www.bleepingcomputer.com/news/security/over-67-000-websites-defaced-via-recently-patched-wordpress-bug/">Bleeping Computer</a></p>The post <a href="https://mattcrawford.me/over-67000-websites-defaced-via-recently-patched-wordpress-bug/">Over 67,000 Websites Defaced via Recently Patched WordPress Bug</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></content:encoded>
					
					<wfw:commentRss>https://mattcrawford.me/over-67000-websites-defaced-via-recently-patched-wordpress-bug/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2613</post-id>	</item>
		<item>
		<title>Ransomware Spreads Via Fake &#8216;Chrome Font Pack&#8217;</title>
		<link>https://mattcrawford.me/ransomware-spreads-via-fake-chrome-font-pack/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ransomware-spreads-via-fake-chrome-font-pack</link>
					<comments>https://mattcrawford.me/ransomware-spreads-via-fake-chrome-font-pack/#respond</comments>
		
		<dc:creator><![CDATA[Matt Crawford]]></dc:creator>
		<pubDate>Tue, 07 Feb 2017 18:24:09 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[randomware]]></category>
		<category><![CDATA[security risk]]></category>
		<category><![CDATA[virus]]></category>
		<guid isPermaLink="false">https://g3k.xyz/?p=2609</guid>

					<description><![CDATA[<p>There is a new malware on the loose, masquerading as an update for Chrome.  If you see a popup or other notice that tells you that you need a font update for Chrome, please ignore it and let us know immediately. Palo Alto Networks threat intelligence analyst Brad Duncan reported that “Spora”, a powerful new [&#8230;]</p>
The post <a href="https://mattcrawford.me/ransomware-spreads-via-fake-chrome-font-pack/">Ransomware Spreads Via Fake ‘Chrome Font Pack’</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></description>
										<content:encoded><![CDATA[<p><a href="https://t3dus.com/wp-content/uploads/2017/02/chromefontpack.jpg"><img loading="lazy" decoding="async" class="alignleft size-medium wp-image-2611" src="https://t3dus.com/wp-content/uploads/2017/02/chromefontpack-300x182.jpg" alt="" width="300" height="182" srcset="https://mattcrawford.me/wp-content/uploads/2017/02/chromefontpack-300x182.jpg 300w, https://mattcrawford.me/wp-content/uploads/2017/02/chromefontpack-768x467.jpg 768w, https://mattcrawford.me/wp-content/uploads/2017/02/chromefontpack-1024x623.jpg 1024w, https://mattcrawford.me/wp-content/uploads/2017/02/chromefontpack.jpg 1069w" sizes="(max-width: 300px) 100vw, 300px" /></a>There is a new malware on the loose, masquerading as an update for Chrome.  If you see a popup or other notice that tells you that you need a font update for Chrome, please ignore it and let us know immediately.</p>
<p>Palo Alto Networks threat intelligence analyst Brad Duncan reported that “Spora”, a powerful new ransomware strain that is able to encrypt files without communicating to a command-and-control server, is using a social engineering attack vector using fake “Chrome Font Pack” pop-ups.</p>
<p>Most ransomware spreads either through spam and email attachments or “malvertising”—fake ads that contain malware or malware links. Spora exploits unpatched vulnerabilities in both browsers and operating systems.</p>
<p>Spora&#8217;s evil geniuses have compromised multiple websites and turned the website pages into an unreadable font.  They tell visitors that the “HoeflerText” font is missing from the user’s browser and that they can fix this by downloading the &#8220;Chrome Font Pack.&#8221;</p>
<p>People then download and install the malicious code by double-clicking the &#8220;update.exe&#8221; file which kicks off the malicious code. The bad guys even provide help by showing where the victims can find the install file.</p>
<p>The moral of the story is this:  Be vigilant, be aware, and be prepared.   Keep your computer’s browsers updated to the latest versions, and make sure your operating systems are updated with the latest security patches.</p>
<p>And as always, “Think Before You Click”!</p>The post <a href="https://mattcrawford.me/ransomware-spreads-via-fake-chrome-font-pack/">Ransomware Spreads Via Fake ‘Chrome Font Pack’</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></content:encoded>
					
					<wfw:commentRss>https://mattcrawford.me/ransomware-spreads-via-fake-chrome-font-pack/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2609</post-id>	</item>
		<item>
		<title>Adobe Acrobat auto-installed a vulnerable Chrome extension on Windows PCs</title>
		<link>https://mattcrawford.me/adobe-acrobat-auto-installed-a-vulnerable-chrome-extension-on-windows-pcs/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=adobe-acrobat-auto-installed-a-vulnerable-chrome-extension-on-windows-pcs</link>
					<comments>https://mattcrawford.me/adobe-acrobat-auto-installed-a-vulnerable-chrome-extension-on-windows-pcs/#respond</comments>
		
		<dc:creator><![CDATA[Matt Crawford]]></dc:creator>
		<pubDate>Thu, 19 Jan 2017 15:49:34 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[flaw]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://g3k.xyz/?p=2585</guid>

					<description><![CDATA[<p>Adobe is no stranger to finding itself in the security headlines for all the wrong reasons, and it seems that things may not be changing as we enter 2017. There was controversy earlier this month when news broke about how Adobe took the opportunity on Patch Tuesday of using its regular security updates to force [&#8230;]</p>
The post <a href="https://mattcrawford.me/adobe-acrobat-auto-installed-a-vulnerable-chrome-extension-on-windows-pcs/">Adobe Acrobat auto-installed a vulnerable Chrome extension on Windows PCs</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></description>
										<content:encoded><![CDATA[<p>Adobe is no stranger to <a href="https://www.tripwire.com/state-of-security/latest-security-news/mozilla-blocks-all-versions-of-adobe-flash-until-publicly-known-security-vulnerabilities-are-fixed/" target="_blank" rel="noopener noreferrer">finding itself in the security headlines for all the wrong reasons</a>, and it seems that things may not be changing as we enter 2017.</p>
<p>There was controversy earlier this month when news broke about how <a href="https://www.tripwire.com/state-of-security/latest-security-news/adobe-ordered-pay-1-million-2013-mega-breach/" target="_blank" rel="noopener noreferrer">Adobe</a> took the opportunity on Patch Tuesday of using its regular security updates to force Adobe Acrobat DC users into silently installing a Google Chrome extension.</p>
<p>As <em>Bleeping Computer</em> <a title="Link to Bleeping Computer" href="https://www.bleepingcomputer.com/news/software/adobe-acrobat-reader-dc-update-installs-chrome-browser-extension/" target="_blank" rel="nofollow noopener noreferrer">reports</a>, most people first found out about the extension, which offers the ability to easily convert webpages into PDF files, when they saw a prompt asking them to approve the following permissions:</p>
<ul>
<li>Read and change all your data on the websites you visit</li>
<li>Manage your downloads</li>
<li>Communicate with cooperating native applications</li>
</ul>
<p>Read more on: <a href="https://www.tripwire.com/state-of-security/featured/adobe-acrobat-chrome-extension/">TripWire</a></p>The post <a href="https://mattcrawford.me/adobe-acrobat-auto-installed-a-vulnerable-chrome-extension-on-windows-pcs/">Adobe Acrobat auto-installed a vulnerable Chrome extension on Windows PCs</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></content:encoded>
					
					<wfw:commentRss>https://mattcrawford.me/adobe-acrobat-auto-installed-a-vulnerable-chrome-extension-on-windows-pcs/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2585</post-id>	</item>
		<item>
		<title>New SnapChat Privacy Issue</title>
		<link>https://mattcrawford.me/new-snapchat-privacy-issue/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=new-snapchat-privacy-issue</link>
					<comments>https://mattcrawford.me/new-snapchat-privacy-issue/#respond</comments>
		
		<dc:creator><![CDATA[Matt Crawford]]></dc:creator>
		<pubDate>Fri, 11 Nov 2016 15:11:04 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[snapchat]]></category>
		<category><![CDATA[snapchat privacy]]></category>
		<guid isPermaLink="false">https://g3k.xyz/?p=2491</guid>

					<description><![CDATA[<p>It has dawned on me that with SnapChat&#8217;s latest release there is a new SnapChat privacy issue that I have stumbled upon. In the latest release of SnapChat they now allow people to &#8220;Press and hold on a snap to send it to a friend&#8221; which basically means. IF your SnapChat privacy is set to [&#8230;]</p>
The post <a href="https://mattcrawford.me/new-snapchat-privacy-issue/">New SnapChat Privacy Issue</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></description>
										<content:encoded><![CDATA[<p>It has dawned on me that with SnapChat&#8217;s latest release there is a new SnapChat privacy issue that I have stumbled upon.</p>
<p>In the latest release of SnapChat they now allow people to &#8220;Press and hold on a snap to send it to a friend&#8221; which basically means.</p>
<ul>
<li>IF your SnapChat privacy is set to <em>Public</em> then anybody can now send your stories to anybody &amp; they can see it.</li>
<li>If your SnapChat privacy is set to <em>Friends</em> then anybody can send your stories to anybody but only your friends can see it.</li>
</ul>
<p><a href="https://t3dus.com/wp-content/uploads/2016/11/SC.png"><img loading="lazy" decoding="async" class="wp-image-2492 size-full" src="https://t3dus.com/wp-content/uploads/2016/11/SC.png" alt="sc" width="406" height="190" srcset="https://mattcrawford.me/wp-content/uploads/2016/11/SC.png 406w, https://mattcrawford.me/wp-content/uploads/2016/11/SC-300x140.png 300w" sizes="(max-width: 406px) 100vw, 406px" /></a></p>
<p>I have tested this many different ways and it&#8217;s a pretty scary thought that this is possible. Worse yet, the person who&#8217;s snap you share IS NOT NOTIFIED that you shared it with whomever..</p>
<p>SnapChat really should of thought better about this before implementing this feature.</p>The post <a href="https://mattcrawford.me/new-snapchat-privacy-issue/">New SnapChat Privacy Issue</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></content:encoded>
					
					<wfw:commentRss>https://mattcrawford.me/new-snapchat-privacy-issue/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2491</post-id>	</item>
		<item>
		<title>Yahoo Security Breach</title>
		<link>https://mattcrawford.me/yahoo-security-breach/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=yahoo-security-breach</link>
					<comments>https://mattcrawford.me/yahoo-security-breach/#respond</comments>
		
		<dc:creator><![CDATA[Matt Crawford]]></dc:creator>
		<pubDate>Fri, 23 Sep 2016 14:48:55 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[fuck yahoo]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[yahoo]]></category>
		<category><![CDATA[yahoo sucks]]></category>
		<category><![CDATA[yahoo.com]]></category>
		<guid isPermaLink="false">https://g3k.xyz/?p=2461</guid>

					<description><![CDATA[<p>Yahoo finally comes clean about a security breach that happened over 2 years ago. I got this e-mail today which is a bit late in my opinion Yahoo. Glad I don&#8217;t rely on their services for anything important because they clearly don&#8217;t have security in mind. See their e-mail below. NOTICE OF DATA BREACH Dear [&#8230;]</p>
The post <a href="https://mattcrawford.me/yahoo-security-breach/">Yahoo Security Breach</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></description>
										<content:encoded><![CDATA[<p>Yahoo finally comes clean about a security breach that happened over 2 years ago. I got this e-mail today which is a bit late in my opinion Yahoo.</p>
<p>Glad I don&#8217;t rely on their services for anything important because they clearly don&#8217;t have security in mind. See their e-mail below.</p>
<p style="padding-left: 30px;"><img loading="lazy" decoding="async" class="wp-image-2462 size-full alignnone" src="https://t3dus.com/wp-content/uploads/2016/09/yahoologo.jpg" alt="yahoologo" width="500" height="78" srcset="https://mattcrawford.me/wp-content/uploads/2016/09/yahoologo.jpg 500w, https://mattcrawford.me/wp-content/uploads/2016/09/yahoologo-300x47.jpg 300w" sizes="(max-width: 500px) 100vw, 500px" /></p>
<p style="padding-left: 30px;"><span style="text-decoration: underline;"><strong>NOTICE OF DATA BREACH</strong></span></p>
<p>Dear Matt,</p>
<p style="padding-left: 30px;">We are writing to inform you about a data security issue that may involve your Yahoo account information.</p>
<p style="padding-left: 30px;"><strong>What Happened?</strong><br />
A copy of certain user account information was stolen from our systems in late 2014 by what we believe is a state-sponsored actor. We are closely coordinating with law enforcement on this matter and working diligently to protect you.</p>
<p style="padding-left: 30px;"><strong>What Information Was Involved?</strong><br />
The stolen user account information may have included names, email addresses, telephone numbers, dates of birth, hashed passwords (the vast majority with bcrypt) and, in some cases, encrypted or unencrypted security questions and answers. Not all of these data elements may have been present for your account. The ongoing investigation suggests that stolen information did not include unprotected passwords, payment card data, or bank account information; payment card data and bank account information are not stored in the system that the investigation found to be affected.</p>
<p style="padding-left: 30px;"><strong>What We Are Doing</strong><br />
We are taking action to protect our users:<br />
We are asking potentially affected users to promptly change their passwords and adopt alternate means of account verification.<br />
We invalidated unencrypted security questions and answers so they cannot be used to access an account.<br />
We are recommending that all users who haven&#8217;t changed their passwords since 2014 do so.<br />
We continue to enhance our systems that detect and prevent unauthorized access to user accounts.<br />
We are working closely with law enforcement on this matter.</p>
<p style="padding-left: 30px;">Our investigation into this matter continues.</p>
<p style="padding-left: 30px;"><strong>What You Can Do</strong><br />
We encourage you to follow these security recommendations:<br />
Change your password and security questions for any other accounts on which you used the same or similar information used for your Yahoo account.<br />
Review your accounts for suspicious activity.<br />
Be cautious of any unsolicited communications that ask for your personal information or refer you to a web page asking for personal information.<br />
Avoid clicking on links or downloading attachments from suspicious emails.</p>
<p style="padding-left: 30px;">Additionally, please consider using Yahoo Account Key, a simple authentication tool that eliminates the need to use a password altogether.</p>
<p style="padding-left: 30px;"><strong>For More Information</strong><br />
For more information about this issue and our security resources, please visit the Yahoo Security Issue FAQs page available at https://yahoo.com/security-update.</p>
<p style="padding-left: 30px;">Protecting your information is important to us and we work continuously to strengthen our defenses against the threats targeting our industry.</p>
<p style="padding-left: 30px;">Sincerely,<br />
Bob Lord<br />
Chief Information Security Officer<br />
Yahoo</p>The post <a href="https://mattcrawford.me/yahoo-security-breach/">Yahoo Security Breach</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></content:encoded>
					
					<wfw:commentRss>https://mattcrawford.me/yahoo-security-breach/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2461</post-id>	</item>
	</channel>
</rss>
