Recruiting? Beware malware-infected job applications

Recruiting? Beware malware-infected job applications

Many thanks to our friend Michael Scheidell of Security Privateers for alerting the Tech Hiring community to this danger.

The current shortage of qualified IT security professionals is affecting organizations across the United States, but now it seems that criminals are taking advantage of the booming job market in a new way: Proofpoint reports that cyber criminals have been infecting businesses with malware through fake job applications.

Combining “phishing and social engineering techniques in order to trick users into opening a malicious document”, criminals have been uploading infected files to online job site CareerBuilder.com, which exploit “a memory corruption vulnerability for Word RTF (such as CVE-2014-1761, CVE-2012-0158, and others).”

It may seem a labor-intensive way of attacking organizations, but because of this approach the “probability of the mail being delivered and opened is higher”. As Proofpoint notes, “recipients are likely to read them and open the attachments because not only are they legitimate emails from a reputable service, but these emails are expected and even desired by the recipient. Moreover, because of the way that resumes are circulated within an organization, once the document has been received by the owner of the job listing (often “hr@<company name>”) it will be sent to the hiring manager, interviewers, and other stakeholders, who will open and read it as well. Taking advantage of this dynamic enables the attackers to move laterally through their target organization.”

Having been alerted by Proofpoint, CareerBuilder “took prompt action to address the issue”, but other recruitment sites could still be vulnerable. We recommend you exercise caution when opening attachments from unknown sources – especially if you’re recruiting. Once infected with malware, organizations are at significant risk of data breach, or wider compromise.

by: Neil Ford

Magic Jack Maxwell Appearing Daily @SherlockTalent Booth A16-2

Magic Jack Maxwell Appearing Daily @SherlockTalent Booth A16-2

Visit SherlockTelent @eMerge Americas,  Booth A16-2 and learn some real magic from Magic Jack Maxwell

The 2nd Annual eMerge Americas is off the a flying start with record capacity crowds visiting the Miami Convention Center. It’s really inspirational to me to see so many top companies represented this year.

For SherlockTalent this is really a great opportunity for to meet many of the new faces in the South Florida tech market space and to give them the opportunity to witness our magic first hand.

Top Job Pick – Windows Cloud DevOps Engineer – Ft. Lauderdale

Top Job Pick – Windows Cloud DevOps Engineer – Ft. Lauderdale

Apply to this job.

Our client, a SaaS based management system is in search for a unique hybrid role of a DevOps Engineer position to manage their Windows fleet in the Amazon Cloud.

As a DevOps Engineer you will be a part of their development team and responsible for managing Windows EC2 servers/webservers, Elasticache, RDS, load-balancers, and building automated tools to make your administration easier. You will also participate in day-to-day investigation tasks, and tier-3 support related to our cloud hosting environments.

SherlockTalent loves to share $500 referral bonus!

Visit SherlockTalent @eMerge Booth A16-2 and witness the Magic of our search.

Visit SherlockTalent @eMerge Booth A16-2 and witness the Magic of our search.

eMerge Americas attracts some of the best tech talent in and tech companies in South Florida. During the conference, many local and national companies will be  participating at the hiring fair From college students working towards a computer science degree to seasoned designers and developers, potential hires come with resume in hand searching for jobs and internships alike.

Top 4 things every job-seeker should know:

http://sherlocktalent.com/how-to-secure-talent

http://sherlocktalent.com/building-a-better-resume

http://sherlocktalent.com/changes-in-tech-salaries

http://sherlocktalent.com/phone-interview-tips