GTA 6 Leaks, The Odyssey Malware, and Water Grid Attacks: This Week in Cybersecurity | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Maybe you’ve heard about this little video game coming out soon called Grand Theft Auto VI. Well, while most people are waiting to get their hands on it, one enterprising group, CyberLeek, claims to have a copy and has been posting images and videos from it, prompting Rockstar Games to file copyright takedowns to stem the flow. The group is also asking folks to buy their memecoin, supposedly to fight anti-consumerism in games, while critics note they probably hacked a dev build and just want a payout. Depending on how this plays out, we might be watching the birth of another hacking group. 

Speaking of hacks, the FBI is warning infrastructure companies that hackers targeting water systems across the United States are likely using AI to streamline their operations. So if you’ve been wondering when AI is going to make security nightmares in the real world worse, guess what: It’s already happening.

In other news, we covered a report from researchers at Incogni that examines the privacy policies and data retention practices of 13 major AI companies and the chatbots they offer. From names like ChatGPT and Gemini to Meta AI, Perplexity, and even Grok, the report identifies which chatbots are the most privacy-friendly and transparent in their practices and which are the worst offenders. We also checked out a privacy-focused AI tool that reveals where popular chatbots get your data in the first place. It’s worth trying out yourself.

Finally, if you’ve ever wondered what retailers, both online and brick-and-mortar, do with your personal data once you give it to them to make a purchase, we looked into it. You have to hand over some information to make a purchase, of course, but to some of those companies, the data they get from you is way more valuable than the cost of the goods or services you purchase. We also have tips to protect your privacy while you shop.

Now, let’s see what else is going on in the infosec world this week.


Pirating The Odyssey? You Might Get Hit With Malware

Anytime a piece of media explodes in popularity, piracy follows quickly. No judgment there, but it’s important to remember that whenever something on the internet becomes popular, it’s also a target for scammers and hackers looking for a quick payday off of other people. Over at the Bitdefender blog, we have yet another example of this, with a new malware campaign targeting people looking to download copies of The Odyssey from pirate websites or forums. Essentially, hackers disguise malware as ripped Blu-ray releases or other legitimate video versions of the movie, and once downloaded, users get infected. 

In this case, the malware in question is called Lumma and is designed to steal browser sessions for popular websites, passwords, authentication cookies, browser autofill information, saved payment data, and crypto wallets. This playbook isn’t new by any means: We’ve seen similar campaigns for other box office blockbusters, and the malware isn’t particularly complicated. Usually, the attacker’s goal is to prioritize breadth over depth, collecting whatever information they can from unsuspecting users and avoiding persistence or backdoors that might lead investigators to them. Researchers at Bitdefender note they’ve already seen the malware on popular torrent trackers, so be careful if that’s a place you’re known to hang out.


How Hackers Use AI to Boost Malware Campaigns

This one’s a little bit in the weeds, so stay with me here. Researchers at Gambit, a threat intelligence and security firm, studied three completely unrelated threat actors conducting hacking or malware campaigns online to see how they operate, specifically how they’re using AI to bolster their campaigns. What they found shouldn’t be a surprise if you’ve been following our coverage, but it is certainly concerning. In short, attackers have turned to AI to do what AI products themselves promise: Increase the productivity of their malware campaigns. 

Some highlights of the report include the attackers using AI to write one-off scripts tailored specifically to their targets’ systems and computing environments, building new exploitation tools, handling the day-to-day tasks of debugging and perfecting their tools, and, in some cases, even focusing their efforts on higher-value targets, like company executives, leaders, or specifically interesting targets. In at least one of the cases, the researchers note that the AI-assisted intrusion caused significant disruption to the organization that was targeted, and in another, they noted that the intrusion got very close to the organization’s recovery layer, threatening backups and other systems that victims would turn to in order to get critical systems back online. Overall, it’s scary, especially if you work in an IT department.


ShinyHunters Dumps 1.6M RingCentral Accounts After Voice-Phish Scam

ShinyHunters is at it again, this time dumping data of 1.6 million unique email addresses, alongside names, physical addresses, and phone numbers tied to RingCentral accounts. RingCentral is a company that provides communication and collaboration tools to businesses. According to The Register, the company confirmed the breach at the end of July and, in a statement, claimed that the attack was a “sophisticated social engineering campaign” that impacted a “limited portion of RingCentral customers.” 

The company has been quiet about the issue aside from that statement (which isn’t uncommon, especially given the legal risks) and didn’t specifically name who ran the campaign. However, on its own website, the ShinyHunters group claimed that it had breached the company, made off with over 623GB of data, and had told RingCentral it had until the end of July to pay or it would dump the data on the open web. RingCentral, apparently, didn’t pay the demand, and ShinyHunters did what it threatened. The group told The Register that all it had to do was voice-phish an employee, tricking them into handing over their password. 

In short, it’s another reminder that humans are the weakest link when it comes to security, as well as a reminder that companies need to take that seriously, especially considering AI-powered voice deepfakes and other freely available tools make phishing attacks easier (and easier to fall for) than they’ve ever been.


Ask Our Expert: Are Those Email Blackmail Demands Actually Real?

Do you have a question about online privacy or security? I’m here to help! You can submit your question here, and I may answer it in an upcoming SecurityWatch column and newsletter. If you’re not subscribed to the newsletter, head here to sign up, and check back each week for the latest updates from PCMag’s security team. Now, on to this week’s question!

Recommended by Our Editors

Loren S asks: “Are those hackers who email you, saying, ‘Pay now, or we will ruin your life,’ real? Can they actually access info, pics, etc. on your phone, or is it a trap?”

Thanks for your question, Loren! So the short answer is no, they’re not real. This is a classic phishing attack. If you see one of those emails claiming the hacker has pictures or video of you doing unspeakable things, and that they’ll release them if you don’t pay, odds are very high that it’s a scam designed to prey on your fear and uncertainty.

The scammers responsible for messages like that usually send them out in bulk to batches of email addresses they’ve obtained around the web, and if they get even a handful of fearful responses or payments out of the tens of thousands of automated emails they send, it’s still a solid payout. Simply mark them as spam, ignore them, delete them, and call it a day.

The slightly longer answer, though, is that while the types of emails I mentioned above are almost certainly scams, if you find that someone is specifically targeting you, you may need to pay a little more attention. Recently, the FBI warned that hackers are coming for your nudes, but in that case, they’re not trying to get you to pay them; they just want the goods so they can post, share, or sell them online. Also, in that case, the hackers try to get into your online accounts, social media, or devices to obtain the material they want, so there’s usually no email or demand to pay.

So while I can’t say that every email like that is an obvious fake designed to scare you, the vast majority of them are. And unless you’ve recently been hacked, you don’t have much to worry about.

About Our Expert



——————————————————-


Click Here For The Original Source.