Incidents

Your Google account just got more interesting

Google have announced a new version of their Desktop Search program.
One of the new features is called “Search Across Computers”. You can read about it on the Google site.

“Search Across Computers enables you to search your documents and viewed web pages across all your computers.

Search Across Computers makes the following files searchable from your other computers:

* Web history (from Internet Explorer, Firefox, Netscape, and Mozilla)
* Microsoft Word documents
* Microsoft Excel spreadsheets
* Microsoft PowerPoint presentations
* PDF files and Text files in My Documents”

To make this function work the searchable files get uploaded to Google’s servers.

For this feature to operate you need to use your Google account, the same one that you use for Gmail, Orkut and the other Google services.

This means that if an attacker can obtain your Google login details, he will be able to access your confidential files.

The good side is that this feature is an option and is not turned on by default.

We advise you to keep it that way.

Your Google account just got more interesting

Your email address will not be published. Required fields are marked *

 

Reports

Focus on DroxiDat/SystemBC

An unknown actor targeted an electric utility in southern Africa with Cobalt Strike beacons and DroxiDat, a new variant of the SystemBC payload. We speculate that this incident was in the initial stages of a ransomware attack.

APT trends report Q2 2023

This is our latest summary of the significant events and findings, focusing on activities that we observed during Q2 2023.

Meet the GoldenJackal APT group. Don’t expect any howls

GoldenJackal is an APT group, active since 2019, that usually targets government and diplomatic entities in the Middle East and South Asia. The main feature of this group is a specific toolset of .NET malware, JackalControl, JackalWorm, JackalSteal, JackalPerInfo and JackalScreenWatcher.

Subscribe to our weekly e-mails

The hottest research right in your inbox