Connect with us

Published

on

Hackers are increasingly using online ads for malicious purposes. Often, it’s happening through routine Google searches.

These schemes are dubbed malvertising, and cyber criminals are striking more often and with increased sophistication. In fall 2023, cybersecurity software firm Malwarebytes tracked a 42% increase month-over-month in malvertising incidents in the U.S. All types of brands are being targeted, whether it’s for phishing purposes or for actual malware, said Jérôme Segura, senior director of research at Malwarebytes. “What I’m seeing is just the tip of the iceberg,” he said.

Many of these rogue ads appear as sponsored content during a search engine query on a desktop or mobile device. But malicious code can also be hidden in ads that appear on mainstream websites consumers routinely visit. Some of these ads will only ensnare consumers who click on them, but in some cases, people can be vulnerable in a more passive way — sometimes just by visiting an infected site, said Erich Kron, security awareness advocate for KnowBe4, a security awareness and training company. 

Corporate employees can also be targets of malvertising, Segura said. He cited a few actual examples that were recently uncovered involving big companies. Lowe’s staff members were targeted via a Google ad for an employee portal claiming to be associated with the retailer. Clicking on the link, “myloveslife.net,” which contains a misspelling of the company’s name, took users to a phishing page with Lowe’s logo. This had the potential to confuse employees since many don’t know offhand the URL for their internal website. “You see the brand, even the official logo of that brand, and for you it’s enough to think it’s real,” Segura said.

Segura also cited an ad meant to impersonate Salesforce-owned communication tool Slack. Initially, by clicking on the ad, he was redirected to a price page on Slack’s official website. But suspecting bad actors were at play, Segura dug deeper and uncovered an impersonation ploy, which involved trying to convince unsuspecting users to download something purporting to be the Slack app.

It’s not Google’s fault, but don’t trust it

Malvertising is not new, but cybercriminals are getting smarter and the ads are often so realistic that it’s easy to be duped. The problem is exacerbated by the fact that so many people use and trust Google as a search engine, where many of the malicious ads can be found. It’s not a problem with Google, per se; malicious ads can also show up in queries using other search engines like Microsoft’s Bing. It’s just that Google is such a widely used search engine and people trust it and let their guard down. “You see something appearing on a Google search, you kind of assume it is something valid,” said Stuart Madnick, professor of information technology at MIT Sloan School of Management. 

Consumers can also fall prey to malicious ads on trusted websites they visit regularly.  Many of these ads are legitimate, but some bad ones can slip through the cracks. “It’s like the post office. Does the mailman check every letter you get to make sure it’s really from Publishers Clearing House?” Madnick said.

Be very careful about where and when you click

Consumers can take steps to protect themselves against malvertising attempts. For instance, they should avoid clicking on sponsored links that come up during an internet search. Often, the first ad below the sponsored one will be the product they are looking for, and since it isn’t sponsored, there’s less chance of being sidelined by malicious code or a phishing attempt.

If you do click on a sponsored link, check the URL at the top of the web page to make sure it’s really where you meant to be before taking any other actions. For example, if you’re trying to visit Gap.com, make sure you’re not really on Gaps.com. Consumers who find themselves on a suspicious site should close the window immediately, said Avinash Collis, assistant professor at Carnegie Mellon University’s Heinz College. In most cases, this will avoid further trouble, he said.

Consumers also need to be careful about clicking ads they see on trusted websites, Kron said. They may, for instance, see ads for products that are much lower in cost than elsewhere. But Kron recommends not clicking and instead visiting the trusted website of the product seller. Most of the time, consumers will be able to search on the provider’s site if a special deal exists, or the deal will be highlighted on the main page of the trusted website, he said.

Also avoid calling a telephone number listed in a sponsored ad because it could be a fake telephone number. If you call it, cyber thieves could gain access to your computer or your personal information, depending on the scheme, said Chris Pierson, CEO of BlackCloak, a cybersecurity and privacy platform that provides digital executive protection for corporate executives.

Consumers should make sure they are calling a number from official product documentation they have in their possession, Pierson said. Alternatively, consumers could visit the company’s home page for this information. “Doing a [web] search could return results that are not sponsored by the company and telephone numbers that are associated with cybercriminals. All it takes to get an ad out there is money and, of course, cybercriminals that are stealing money, have the ability to pay for that bait,” Pierson said. 

Avoid ‘drive-by-downloads’

Consumers should also make sure the operating system and internet browsers are up-to-date on their computer and mobile phone. 

So-called drive-by-downloads, which can impact people who merely visit a website infected with malicious codes, generally rely on a vulnerability in the user’s browser. This is not as much of a threat for people who keep their browsers and browser extensions up-to-date, Kron said. 

Consumers could also consider installing anti-malware software on their computer and phone. Another option is to avoid ads by installing an ad blocker extension such as uBlock Origin, a free and open-source browser extension for content filtering, including ad blocking. Some consumers may also opt to install a privacy browser such as Aloha, Brave, DuckDuckGo or Ghostery on their personal devices. Many privacy browsers have embedded ad blockers; consumers may still see sponsored ads, but they will see fewer of them, which minimizes the chances of malvertising. 

Consumers who come across suspicious ads should report them to the applicable search engine for investigation and removal if deemed malicious, Collis said. This can help protect other people from being ensnared. 

Proper safety precautions are especially important since there are millions of ads on the internet and cyber thieves are relentless. “You should assume that this could happen to you no matter how careful you are,” Madnick said.

Continue Reading

Technology

Tesla is offering Cybertruck discounts as EV market gets crowded

Published

on

By

Tesla is offering Cybertruck discounts as EV market gets crowded

A soldier walks next to a Tesla Cybertruck, which was donated to the National Guard, after powerful winds fueling devastating wildfires in the Los Angeles area forced people to evacuate, in the Pacific Palisades neighborhood on the west side of Los Angeles, California, U.S. Jan. 13, 2025. 

Daniel Cole | Reuters

Tesla started offering discounts on new Cybertruck vehicles in its inventory this week, according to listings on the company’s website.

Discounts are as high as $1,600 off new Cybertrucks, with the reduced price depending on configuration, and up to around $2,600 for demo versions of the trucks in inventory, the listings show. Production of the angular, unpainted steel pickups has reportedly slowed in recent weeks at Tesla’s factory in Austin, Texas.

Deliveries of the unconventional pickup began reaching customers in 2023. CEO Elon Musk originally unveiled the Cybertruck in 2019 and said it would cost around $40,000, but its base price in the U.S. was closer to $80,000 over the course of 2024.

Wall Street previously viewed the Cybertruck as an important driver of growth for Tesla’s core automotive sales.

While the Cybertruck outsold the Ford Lightning F-150 last year in the U.S. and became the fifth best-selling EV domestically, according to data tracked by Cox Automotive, its high price, repeat recalls and production issues in Austin hampered growth. In November, Tesla initiated its sixth recall in a year  to replace defective drive inverters.

As CNBC previously reported, Tesla’s deliveries declined slightly year-over-year in 2024, even as EV demand worldwide reached a record. A slew of new competitive models from a wide range of automakers eroded Tesla’s market share.

According to Cox data, full-year EV sales reached an estimated 1.3 million in 2024 in the U.S., an increase of 7.3% from the prior year. But Tesla’s sales for the year declined by about 37,000 vehicles.

The Tesla Model Y SUV and Model 3 sedan ranked as the top two best-selling EVs by a wide margin. But both older, more affordable Tesla models saw sales drop from the previous year. Cox estimated Tesla sold around 38,965 Cybertrucks in the U.S. last year.

In recent days, Musk apologized to customers in California for delays in delivering their Cybertrucks. He said the trucks are now being used to bring supplies and wireless internet service to people in Los Angeles impacted by devastating wildfires.

“Apologies to those expecting Cybertruck deliveries in California over the next few days,” Musk wrote on X. “We need to use those trucks as mobile base stations to provide power to Starlink Internet terminals in areas of LA without connectivity. A new truck will be delivered end of week.”

WATCH: Here’s why Bank of America downgraded Tesla

Tesla: Here's why Bank of America downgraded the stock to neutral

Continue Reading

Technology

Goldman Sachs CEO Solomon says IPO market is ‘going to pick up’ along with dealmaking

Published

on

By

Goldman Sachs CEO Solomon says IPO market is 'going to pick up' along with dealmaking

David Solomon, CEO of Goldman Sachs, speaks during the Reuters NEXT conference, in New York City, U.S., December 10, 2024. 

Mike Segar | Reuters

Goldman Sachs CEO David Solomon says there’s an end in sight to the multi-year IPO drought.

“It’s going to pick up,” Solomon said on Wednesday, in an on-stage interview with Cisco CEO Chuck Robbins at a summit hosted by the computer networking company in Silicon Valley. “It’s been slow, it’s been turned off.”

Solomon, who flew to California for the event just after his Wall Street bank reported fourth-quarter results that blew past analysts’ estimates, said the capital markets broadly are showing signs of life ahead of President-elect Donald Trump’s inauguration next week.

The tech IPO market has largely been dormant since the end of 2021, when tech stocks started falling out of favor due to soaring inflation and rising interest rates. Mergers and acquisitions have been difficult in technology because of hefty regulation that’s restricted the ability for the biggest companies to grow through dealmaking.

Solomon said the mood is changing, and he expects momentum M&A as well as in IPOs.

“We have a more constructive kind of optimism, which always helps,” Solomon said. He later added that, “broadly speaking, I think it’s an improved business environment.”

Earlier in the day, Solomon said on his company’s earnings call that Trump’s election and a swing back to Republican power in Washington is already starting to make an impact in the business world. He noted on the call that “there is a significant backlog from sponsors and an overall increased appetite for dealmaking supported by an improved regulatory backdrop.”

Solomon’s comments on the call and at the Cisco event came on a day when the S&P 500 posted his biggest gain since November, helped by a tame inflation report and Goldman’s results. Goldman’s stock popped 6% on Wednesday.

While the stock market has had a strong two-year run and the S&P 500 and Nasdaq hit fresh records last month, IPOs have yet to see a resurgence. Cloud software vendor ServiceTitan debuted on the Nasdaq in December, marking the first significant venture-backed IPO in the U.S. since Rubrik in April.

“The values came down after 2021, people are growing back into those values,” Solomon said at the Cisco summit.

Some companies have said they’re ready. Chipmaker Cerebras filed to go public in September, but the process was slowed down due to a review by the Treasury Department’s Committee on Foreign Investment in the U.S., or CFIUS. In November, online lender Klarna said it had confidentially filed IPO paperwork with the SEC.

Though he’s bullish about what’s coming, Solomon said that there are structural reasons not to go public. He said 25 years ago there were roughly 13,000 public companies in the U.S., and today that number has come down to 3,800. There are higher standards around disclosure for being public, and there’s now tons of private capital available “at scale.”

“It’s not fun being a public company,” Solomon acknowledged. “Who would want to be a public company?”

WATCH: Goldman Sachs tops estimates

Goldman Sachs tops estimates on strong trading results

Continue Reading

Technology

How VPNs might allow Americans to continue using TikTok

Published

on

By

How VPNs might allow Americans to continue using TikTok

Dado Ruvic | Reuters

If TikTok does indeed go dark on Sunday for Americans, there may be a tool for them to continue accessing the popular social app: VPNs. 

The Chinese-owned app is set to be removed from mobile app stores and the web for U.S. users on Sunday as a result of a law signed by President Joe Biden in April 2024 requiring that the app be sold to a qualified buyer before the deadline. 

Barring a last-minute sale or reprieve from the Supreme Court, the app will almost certainly vanish from the app stores for iPhones and Android phones. It won’t be removed from people’s phones, but the app could stop working. 

TikTok plans to shut its service for Americans on Sunday, meaning that even those who already have the app downloaded won’t be able to continue using it, according to reports this week from Reuters and The Information. Apple and Google didn’t comment on their plans for taking down the apps from their app stores on Sunday.

“Basically, an app or a website can check where users came from,” said Justas Palekas, a head of product at IProyal.com, a proxy service. “Based on that, then they can impose restrictions based on their location.”

Masking your physical internet access point

That may stop most users, but for the particularly driven Americans, using VPNs might allow them to continue using the app. 

VPNs and a related business-to-business technology called proxies work by tunneling a user’s internet traffic through a server in another country, making it look like they are accessing the internet from a location different than the one they are physically in. 

This works because every time a computer connects to the internet, it is identified through an IP number, which is a 12-digit number that is different for every single computer. The first six digits of the number identifies the network, which also includes information about the physical region the request came from.

In China, people have used VPNs for years to get around the country’s firewall, which blocks U.S. websites such as Google and Facebook. VPNs saw big spikes in traffic when India banned TikTok in 2020, and people often use VPNs to watch sporting events from countries where official broadcasts aren’t available. 

As of 2022, the VPN market was worth nearly $38 billion, according to the VPN Trust Initiative, a lobbying group.

“We consistently see significant spikes in VPN demand when access to online platforms is restricted, and this situation is no different,” said Lauren Hendry Parsons, privacy advocate at ExpressVPN, a VPN provider that costs $5 per month to use.

“We’re not here to endorse TikTok, but the looming U.S. ban highlights why VPNs matter— millions rely on them for secure, private, and unrestricted access to the internet,” ProtonVPN posted on social media earlier this week. ProtonVPN offers its service for $10 a month. 

The price of VPNs

Both ExpressVPN and ProtonVPN allow users to set their internet-access location. 

Most VPN services charge a monthly fee to pay for their servers and traffic, but some use a business model where they collect user data or traffic trends, such as when Meta offered a free VPN so it could keep an eye on which competitors’ apps were growing quickly.

A key tradeoff for those who use VPN is speed due to requests having to flow through a middleman computer to mask a users’ physical location. 

And although VPNs have worked in the past when governments have banned apps, that doesn’t ensure that VPNs will work if TikTok goes dark. It won’t be clear if ExpressVPN would be able to access TikTok until after the ban takes place, Parsons told CNBC in an email. It’s also possible that TikTok may be able to determine Americans who try to use VPNs to access the app.  

(L-R) Sarah Baus of Charleston, S.C., holds a sign that reads “Keep TikTok” as she and other content creators Sallye Miley of Jackson, Mississippi, and Callie Goodwin of Columbia, S.C., stand outside the U.S. Supreme Court Building as the court hears oral arguments on whether to overturn or delay a law that could lead to a ban of TikTok in the U.S., on January 10, 2025 in Washington, DC. 

Andrew Harnik | Getty Images

VPNs and proxies to evade regional restrictions have been part of the internet’s landscape for decades, but their use is increasing as governments seek to ban certain services or apps.

Apps are removed by government request all the time. Nearly 1500 apps were removed in regions due to government takedown demands in 2023, according to Apple, with over 1,000 of them in China. Most of them are fringe apps that break laws such as those against gambling, or Chinese video game rules, but increasingly, countries are banning apps for national security or economic development reasons.

Now, the U.S. is poised to ban one of the most popular apps in the country — with 115 million users, it was the second most downloaded app of 2024 across both iOS and Android, according to an estimate provided to CNBC from Sensor Tower, a market intelligence firm.

“As we witness increasing attempts to fragment and censor the internet, the role of VPNs in upholding internet freedom is becoming increasingly critical,” Parsons said.

WATCH: Chinese TikTok alternative surges

Chinese TikTok alternative surges

Continue Reading

Trending