InfoSecHotSpotTwitterFeedRSS: Recent Episodes

Paul F. Roberts

This feed was created by mixing existing feeds from various sources.

View Details

President and Chairman of Trusted Computing Group (TCG), Dr. Joerg Borchert, shares the news regarding TCG's first ever CodeGen Developer Challenge.

The post Leonardo DRZ wins first ever TCG CodeGen Developer Challenge appeared first on The Security Ledger with Paul F. Roberts.

Related Stories* Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security * Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion * Spotlight: E-Commerce’s Bot and Mouse Game

View Details

The security vulnerability could expose passwords and access tokens, along with blueprints for internal infrastructure and finding software vulnerabilities.

View Details

You know you want one, because this retro phone is NOT A TOY... except when it comes to cybersecurity.

View Details

Attackers use the Telegram handle “Smokes Night” to spread the malicious Echelon infostealer, which steals credentials for cryptocurrency and other user accounts, researchers said.

View Details

The origin of the Monero cryptominer file has been traced to a Russian torrent website, researchers report.

View Details

VPNs have become a vulnerability that puts organizations at risk of cyberattacks.

View Details

There was a lot to learn from breaches, vulnerabilities, and attacks this year.

View Details

In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.

View Details

Researchers found an insecure default behavior in Azure App Service exposing source code of some customer applications deployed using "Local Git."

View Details

A new study investigating consumer password use found 25% of online shoppers would abandon their carts of $100 if prompted to reset a password at checkout.

View Details

The open-sourced scanner was derived from scanners built by members across the open source community, CISA reports.

View Details

Phew! An audacious crime... that didn't work out.

View Details

Overtaking the Conti ransomware gang, PYSA finds success with government-sector attacks.

View Details

A critical privilege-escalation vulnerability could lead to backdoors for admin access nesting in web servers.

View Details

Once the dust settles on Log4j, many IT teams will brush aside the need for the fundamental, not-exciting need for better asset and application management.

View Details

Don't freak: It's got nothing to do with Log4Shell, except it may be just as far-reaching as Log4j, given HTTPD's tendency to tiptoe into software projects.

View Details

The US has returned $154 million in bitcoins stolen by a Sony employee.

However, on December 1, following an investigation in collaboration with Japanese law enforcement authorities, the FBI seized the 3879.16242937 BTC in Ishii’s wallet after obtaining the private key, which made it possible to transfer all the bitcoins to the FBI’s bitcoin wallet.

View Details

Zero trust may be one of the hottest trends in cybersecurity, but just eliminating trust from networks isn’t enough to prevent successful organizational data breaches, says Wes Wright, CTO of Imprivata.

View Details

The functionality of all-in-one platforms is being deconstructed into a smorgasbord of services that can be used to develop bespoke end-user security procedures for specific work groups, lines of businesses, or customer communities.

View Details

Attackers exploiting bugs in the “link preview” feature in Microsoft Teams could abuse the flaws to spoof links, leak an Android user’s IP address and launch a DoS attack.

View Details

Here’s how to spot an online scam.

View Details

The UK's NCA and NCCU have shared 225 million stolen emails and passwords with HIBP, which tracks stolen credentials.

View Details

The Facebook parent company seeks court's help in identifying the individuals behind some 39,000 websites impersonating its brands to collect login credentials.

View Details

Yaron Kassner, CTO and co-founder of Silverfort, discusses why using all-seeing privileged accounts for monitoring is bad practice.

View Details

There are 17,000 unpatched Log4j packages in the Maven Central ecosystem, leaving massive supply-chain risk on the table from Log4Shell exploits.

View Details

Data from dozens of penetration tests and security assessments suggest nearly every organization can be infiltrated by cyberattackers.

View Details

A quarter-billion of those passwords were not seen in previous breaches that have been added to Have I Been Pwned.

View Details

The Apache web server just got an update - this one is nothing to do with Log4j!

View Details

If security teams are not logging everything, they are increasing security risk and making it more difficult to investigate and recover from a data breach. Modern log management goes beyond just a SIEM.

View Details

Zero trust is key to not falling victim to the next big vulnerability.

View Details

How Matrix security has changed in the latest installment, The Matrix Resurrections.

View Details

Focusing on basic security controls and executing them well is the best way to harden your systems against an attack.

View Details

Of those, 225 million are new passwords that were not part of the database previously

View Details

For zero trust to be successful, organizations need to be able to check user identity, device posture, and overall behavior without adding friction to the experience.

View Details

Multiple threat groups are currently leveraging Log4j bugs in their operations

View Details

Learn more about some tactical measures people are already taking, and some strategic guidance for what to do after the immediate crisis abates.

View Details

With recent news of the critical, zero-day vulnerability Apache Log4Shell, we explore how to detect and protect your Apache HTTP servers.

View Details

Vladislav Klyushin was allegedly involved in a global operation to trade on nonpublic data stolen from US computer networks.

View Details

Meanwhile, Apache Foundation releases third update to logging tool in 10 days to address yet another flaw.

View Details

The acquisition of Cedrus Digital, with its consulting-led model and over 150 cloud, data and product engineers, primarily in the United States, will further augment Brillio’s nearshore digital transformation capabilities offered for Fortune 500 clients.

View Details

Led by IoT security expert Larry Trowell, the IoT pen-testing services focus on securing ATMs, automotive, medical devices, operational technology, and other embedded systems.

View Details

Be happy that your sysadmins are taking one (three, actually!) for the team right now... here's why!

View Details

Rugged Apps ensures mobile apps are NIAP-compliant.

View Details

Company partners with Exabeam to launch update to its BlackBerry Guard managed detection and response (MDR) service.

View Details

While the shipping industry's cyber posture was better than companies in the Forbes Global 2000, the industry performed lower in key risk group factors.

View Details

Challenges were designed to address critical areas of cybersecurity, including reversing, cloud, IoT, open source intelligence, forensics, and machine learning.

View Details

Ziv Oren previously held the position of chief operations officer at the company.

View Details

Half of security decision makers also say the cyber skills gap will significantly impact their 2022 strategy, according to new research from Neustar.

View Details

Citizen Lab published another report on the spyware used against two Egyptian nationals. One was hacked by NSO Group’s Pegasus spyware. The other was hacked both by Pegasus and by the spyware from another cyberweapons arms manufacturer: Cytrox.

We haven’t heard a lot about Cytrox and its Predator spyware. According to Citzen Lab:

We conducted Internet scanning for Predator spyware servers and found likely Predator customers in Armenia, Egypt, Greece, Indonesia, Madagascar, Oman, Saudi Arabia, and Serbia.

Cytrox was reported to be part of Intellexa...

View Details

Security experts in Germany discover similar attacks that lock building engineering management firms out of the BASes they built and manage — by turning a security feature against them.

View Details

Some think zero trust means you cannot or should not trust employees, an approach that misses the mark and sets up everyone for failure.

View Details

Four ways to find hidden cams in hotel rooms, rented apartments, and elsewhere.

View Details

'High severity' bug fixed is an uncontrolled recursion flaw

View Details

And of those redirected to a spoofed web site, almost a quarter will enter their details into a form

View Details

Trying to adopt DevSecOps culture? Or already in the thick of it? Trend Research explores the cybersecurity trends for 2022 to enhance your security strategy and get the most out of DevSecOps.

View Details

We created a free assessment tool for scanning devices to know whether it is at risk for Log4Shell attacks.

View Details

This seems big:

The UK government has officially included decapod crustaceans–including crabs, lobsters, and crayfish–and cephalopod mollusks–including octopuses, squid, and cuttlefish–in its Animal Welfare (Sentience) Bill. This means they are now recognized as “sentient beings” in the UK.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Read my blog posting guidelines here.

View Details

Security teams around the world are on high alert dealing with the Log4j vulnerability, but how risky is it, really?

View Details

Have you ever seen the message "An error occurred"? Even worse, the message "This error cannot occur"? Facts matter!

View Details

The parent company of Facebook and Instagram has warned some 50,000 account holders they are targets of surveillance.

View Details

One leader alone can't protect an organization from cyber threats, C-suite leaders agree.

View Details

EXPERT INSIGHT: How to assess your exposure to the vulnerability with a combination of asset inventory, testing, solid information sources, and software bills of materials (SBOMs).

View Details

The "PseudoManuscrypt" operation infected some 35,000 computers with cyber-espionage malware and targeted computers in both government and private industry.

View Details

CISOs are increasingly drawn to the zero trust security model, but implementing a frictionless experience is still a challenge.

View Details

The Cybersecurity Infrastructure and Security Agency orders federal agencies to take actions to mitigate vulnerabilities to the Apache Log4j flaw and attacks exploiting it.

View Details

Kaspersky experts have discovered an attack that used PseudoManuscrypt spyware to hit industrial systems.

View Details

If you cannot track, access, or audit data at every stage of the process, then you can't claim your data is secure.

View Details

Of cyberattack cases reported to Kroll in 2020, over a third involved ransomware

View Details

Targets include journalists, dissidents, human rights activists and critics of authoritarian regimes and their families

View Details

Researchers observe multiple attempts to deploy a Khonsari ransomware that hits Windows machines by making use of Log4Shell bug

View Details

The new API and SDK from Pixalate helps mobile developers avoid getting their apps delisted from app stores by detecting and blocking fraudulent traffic.

View Details

In this episode of the podcast (#232), Tomislav Peričin of the firm ReversingLabs joins us to talk about Log4Shell, the vulnerability in the ubiquitous Log4j Apache library. Tomislav tells us why issues related to Log4j won’t be going away anytime soon and how organizations must adapt to deal with the risk it poses.

The post Episode 232: Log4j...

Read the whole entry... »

Click the icon below to listen. Related Stories* Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security * Episode 227: What’s Fueling Cyber Attacks on Agriculture ? * Episode 229: BugCrowd’s Casey Ellis On What’s Hot In Bug Hunting

View Details

We analyzed a fileless QAKBOT stager possibly connected to the recently reported Squirrelwaffle campaign.

View Details

We review 2020 and 2021 Oracle WebLogic vulnerabilities and how using a unified SaaS platform can help you detect and mitigate these sophisticated risks.

View Details

This week, read on Purple Fox’s infection chain observed by Trend Micro’s Managed XDR. Also, learn about the Log4j vulnerability that has the potential to cause ‘incalculable’ damage.

View Details

The Log4j flaw exists in a component that is not always easy to detect and is widely used beyond an organization's own networks and systems.

View Details

A new variant dubbed "Twizt" has hijacked 969 transactions and stolen the equivalent of nearly $500,000 USD.

View Details

Latest episode - listen now! (Yes, there are plenty of critical things to go along with Log4Shell.)

View Details

Before the fourth installment of The Matrix premieres, we look at the snags and vulnerabilities in the AI-implemented metaverse.

View Details

A look at why this is such a tricky vulnerability and why the industry response has been good, but not great.

View Details

A 24-year-old New York man who bragged about helping to steal more than $20 million worth of cryptocurrency from a technology executive has pleaded guilty to conspiracy to commit wire fraud. Nicholas Truglia was part of a group alleged to have stolen more than $100 million from cryptocurrency investors using fraudulent "SIM swaps," scams in which identity thieves hijack a target’s mobile phone number and use that to wrest control over the victim’s online identities.

View Details

Graham Cluley Security News is sponsored this week by the folks at Recorded Future. Thanks to the great team there for their support! Ransomware attacks dominate the cybersecurity news headlines, with businesses all over the world wondering if they will be the next victim. It’s a legitimate, and growing fear, as the attackers get more … Continue reading "Free eBook! Ransomware – how to stop it, and how to survive an attack"

View Details

Log4j is being exploited by all sorts of attackers, all over the Internet:

At that point it was reported that there were over 100 attempts to exploit the vulnerability every minute. “Since we started to implement our protection we prevented over 1,272,000 attempts to allocate the vulnerability, over 46% of those attempts were made by known malicious groups,” said cybersecurity company Check Point.

And according to Check Point, attackers have now attempted to exploit the flaw on over 40% of global networks.

And a second vulnerability was found, in the patch for the first vulnerability. This is likely not to be the last...

View Details

As mandatory reporting bills work their way through the halls of Congress, what should businesses do to prepare for this pending legislation?

View Details

The United States Department of Homeland Security (DHS) is inviting security researchers to uncover vulnerabilities and hack into its systems, in an attempt to better protect itself from malicious attacks.

Read more in my article on the Tripwire State of Security blog.

View Details

This week on the Kaspersky podcast, Dave and Jeff discuss how a fat-fingered mistake cost an NFT owner a lot of money, Instagram improvements for teens, Log4J, and more.

View Details

Service has 'a very low level of cybersecurity maturity' finds PwC

View Details

Noname Security's Series C fundraising tips the startup to over $1 billion in valuation -- a sign that organizations are beginning to look for API security tools and investors are looking for innovation in the space.

View Details

After a brief discussion of the Log4Shell vulnerability panic, we chat about how Virgin Media has got itself into hot water, a fat-fingered fumble at the Bored Ape Yacht Club, and how to hack around your sleeping girlfriend's facial recognition.

All this and more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.

View Details

Organizations should upgrade ASAP to new version of logging framework released Tuesday by the Apache Foundation, security experts say.

View Details

Most companies lack the proper tools to assess their vulnerability to threats facing their AI systems and ML pipelines, prompting Microsoft to release a risk assessment framework.

View Details

A new bug bounty program aims to find potential security flaws within certain DHS systems and strengthen the department's security posture.

View Details

The early lessons from Log4j indicate that key security principles can help better handle these high-risk software supply chain security incidents if teams have proper support.

View Details

Scraping bugs and scraped databases are two new areas of research for the company's bug-bounty and data-bounty programs.

View Details

Cloud-native platform automates prevention, detection, and response to cyberattacks.

View Details

Combined capabilities will help clients address the growing complexity of securing public, private and hybrid cloud, 5G, IoT, and industrial control systems

View Details

With access to a user's 3D model and full-body digital tracking, attackers can recreate the perfect replica of a C-level executive to trick employees.

View Details

SASE is a promising and burgeoning networking architecture approach, but it's not without some challenges.

View Details

The way to improve the security of the modern software development life cycle and reduce the number of application-based breaches is to re-center app security around the needs of developers.

View Details

Cloud security is a shared responsibility. which sometimes leads to security gaps and complexity in risk management.

View Details

Kryptowire’s end-to-end cybersecurity engine identified vulnerabilities granting system user-level privileges for arbitrary shell script execution.

View Details

New flaw is much less severe than the Log4jshell vulnerability, but admins are advised to update Log4j once again

View Details

From 2018-2020, users were forced to consent to a new privacy policy to continue using the app - which the Norwegian regulator has ruled as invalid

View Details

Four security vendors give their view on staffing issues, zero trust and threat intelligence

View Details

One zero-day addressed has been observed in active attacks

View Details

Hybrid work is here to stay, and organizations can apply zero trust's three core principles to ensure a secure workforce, Devata says.

View Details

Trend Micro's tracking of modern ransomware, as well as of older families, shows which attacks are gaining momentum and which families are particularly dangerous for enterprises and private users.

View Details

Automates security policy design to ensure compliance and reduce likelihood of breach announcing significant updates to other marketplace apps.

View Details

Google Survey of 1,000 U.S. consumers uncovers data privacy disconnect, a call to action for businesses.

View Details

Amid the increase in Log4j attack activity, at least one Iranian state-backed threat group is preparing to target the vulnerability, experts say.

View Details

North America-based Superior Plus "temporarily disabled" some of its systems in the wake of the attack.

View Details

The attack forced a shutdown of computer systems and websites for Virginia legislative agencies and commissions, reports state.

View Details

Microsoft, Adobe, and Google all issued security updates to their products today. The Microsoft patches include six previously disclosed security flaws, and one that that is already being actively exploited. But this month's Patch Tuesday is being overshadowed by the "Log4Shell" 0-day exploit in a popular Java library that web server administrators are now racing to find and patch amid widespread exploitation of the flaw.

View Details

Security professionals are burning out from handling too many tools and facing a growing number of threats, and more than 40% see lack of leadership as the main problem.

View Details

The December rollout includes 67 security patches and addresses one zero-day and five more publicly known vulnerabilities.

View Details

Get 'em while they're hot!

View Details

The malicious module our experts are calling OWOWA integrates into IIS Web servers and steals mail credentials.

View Details

This is a current list of where and when I am scheduled to speak:

  • I’m speaking at the RSA Conference 2022 in San Francisco on February 8, 2022.
  • I’m speaking at IT-S Now 2022 in Vienna on June 2, 2022.
  • I’m speaking at the 14th International Conference on Cyber Conflict, CyCon 2022, in Tallinn, Estonia on June 3, 2022.

The list is maintained on this page.

View Details

Source code is a corporate asset like any other, which makes it an attractive target for hackers.

View Details

It’s serious:

The range of impacts is so broad because of the nature of the vulnerability itself. Developers use logging frameworks to keep track of what happens in a given application. To exploit Log4Shell, an attacker only needs to get the system to log a strategically crafted string of code. From there they can load arbitrary code on the targeted server and install malware or launch other attacks. Notably, hackers can introduce the snippet in seemingly benign ways, like by sending the string in an email or setting it as an account username...

View Details

One volley of fake news may land, but properly trained AI can shut down similar attempts at their sources.

View Details

The current guidance is to use 'alternative business continuity protocols'

View Details

The accounting firm PricewatersCoopers recently published lessons learned from the disruptive and costly ransomware attack in May 2021 on Ireland's public health system. The unusually candid post-mortem found that nearly two months elapsed between the initial intrusion and the launching of the ransomware. It also found affected hospitals had tens of thousand of outdated Windows 7 systems, and that the health system's IT administrators failed to respond to multiple warning signs that a massive attack was imminent.

View Details

The three must-haves in eXtended Detection and Response are: making data accessible, facilitating real-time threat detection, and providing remediation strategies.

View Details

Our long-term monitoring of the cyberespionage group Earth Centaur (aka Tropic Trooper) shows that the threat actors are equipped with new tools and techniques. The group seems to be targeting transportation companies and government agencies related to transportation.

View Details

Every high-profile breach leaves a trail of bread crumbs, and defenders who monitor access brokers can connect the dots and detect attacks as they unfold.

View Details

Everyone is talking about Log4Shell, a zero-day remote code execution exploit in versions of log4j, the popular open source Java logging library.

View Details

Government actions help starve attack groups of the resources - money, ability to recruit, and time.

View Details

This Tech Tip outlines how enterprises can use Canarytokens to find servers in their organization vulnerable to CVE-2021-44228.

View Details

The company confirmed last week that one of its file repositories was accessed by a third party.

View Details

Customers advised to adopt alternative internal processes to support the affected human resources services.

View Details

More than 60 variants of the original exploit were introduced over the last day alone.

View Details

The number of bug bounty programs jumped by a third, the median payout for a critical vulnerability report rose to $3,000, but rewards for easier-to-find lower-severity flaws stagnated in 2021.

View Details

Find out how to deal with the Log4Shell vulnerability right across your estate. Yes, you need to patch, but that helps everyone else along with you!

View Details

Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.

View Details

Most targeted industry shifts from the financial and insurance sector in 2020.

View Details

The opening marks the fifth center opened globally, fulfilling a key milestone within the Global Transparency Initiative.

View Details

Some tips for effectively combating Web supply chain attacks and customer hijacking via browser extensions.

View Details

Left unchecked, these attacks could have devastating effects on government and military secrets and jeopardize the software supply chain and the global economy.

View Details

In a matter of days, a large-scale outage of cloud and other online services could cause $15 billion in losses.

View Details

Kaspersky opens its fifth Transparency Center. The new facility — our first in North America — is in Fredericton, New Brunswick, Canada.

View Details

The incident comes at the time when the government is reportedly working on a Bill to ban 'all private cryptocurrencies' in the country with 'certain exceptions'

View Details

NSO Group’s descent into Internet pariah status continues. Its Pegasus spyware was used against nine US State Department employees. We don’t know which NSO Group customer trained the spyware on the US. But the company does:

NSO Group said in a statement on Thursday that it did not have any indication their tools were used but canceled access for the relevant customers and would investigate based on the Reuters inquiry.

“If our investigation shall show these actions indeed happened with NSO’s tools, such customer will be terminated permanently and legal actions will take place,” said an NSO spokesperson, who added that NSO will also “cooperate with any relevant government authority and present the full information we will have.”...

View Details

Germany's approach is the opposite to what British government thinks about the use of encryption on digital platforms

View Details

Log4Shell., also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched with version 2.15.0 of Log4j on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.

View Details

Trend Micro's VP of Threat Intelligence, Jon Clay, explores the latest trends in today's threat landscape and why XDR is key to enabling more resilience.

View Details

By examining Purple Fox’s routines and activities, both with our initial research and the subject matter we cover in this blog post, we hope to help incident responders, security operation centers (SOCs), and security researchers find and weed out Purple Fox infections in their network.

View Details

Researchers found critical vulnerability in Apache Log4j with CVSS 10 designated as CVE-2021-44228 (aka Log4Shell or LogJam). Here’s how to mitigate.

View Details

This Tech Tip outlines how enterprise defenders can mitigate the risks of the Log4j vulnerabilities for the short-term while waiting for updates.

View Details

The Far Side is always good for a squid reference. Here’s a recent one.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Read my blog posting guidelines here.

View Details

A remote code execution vulnerability in Log4j presents a bigger threat to organizations than even the infamous 2017 Apache Struts vulnerability that felled Equifax, they say.

View Details

The latest NIST publication outlines how organizations can build systems that can anticipate, withstand, recover from, and adapt to cyberattacks.

View Details

Oleg Koshkin was sentenced for running a crypting service used to hide the Kelihos malware from antivirus software.

View Details

Rodney Petersen, the director of the National Initiative for Cybersecurity Education (NICE) talks about the massive shortage of information security workers at the United States - estimated at more than 400,000 workers.

The post Episode 231: Solving the US’s Endemic Cybersecurity Worker Shortage appeared first on The Security Ledger with Paul F....

Read the whole entry... »

Click the icon below to listen. Related Stories* Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security * Episode 228: CISA’s Eric Goldstein and the Challenge of Being Everyone’s Friend in Cyber * Episode 227: What’s Fueling Cyber Attacks on Agriculture ?

View Details

Just when you thought it was safe to relax for the weekend... a critical bug showed up in Apache's Log4j product

View Details

With more staff working remotely, identity, authentication, and access (IAA) has never been more important. Market forecasts, drivers, and trends are explored.

View Details

Kaspersky’s security operations center head explains his approach to burnout prevention in SOC teams.

View Details

The Dark Reading editorial team, along with contributing writers and editors, share their favorite stories and memories of co-founder and editor-in-chief Tim Wilson, an influential editor and well-respected thought leader in the cybersecurity industry.

View Details

Patch Log4j urgently admins urged, as memories of 2017 Equifax hack loom large

View Details

Exploring ransomware and other data integrity risks from accelerated digital transformation in the wake of COVID-19.

View Details

RLBox can be used to protect web browsers and other software applications from vulnerabilities in subcomponents and libraries.

View Details

A January 2021 FBI document outlines what types of data and metadata can be lawfully obtained by the FBI from messaging apps. Rolling Stone broke the story and it’s been written about elsewhere.

I don’t see a lot of surprises in the document. Lots of apps leak all sorts of metadata: iMessage and WhatsApp seem to be the worst. Signal protects the most metadata. End-to-end encrypted message content can be available if the user uploads it to an unencrypted backup server.

EDITED TO ADD (12/13): Here’s a more legible copy of the text.

...

View Details

They are exploiting security bugs in four WordPress plugins and 15 Epsilon Framework themes

View Details

This week, read about Trend Micro’s predictions for security in the coming year. Also, learn about the Biden administration’s latest initiatives for curtailing attacks on the transport infrastructure.

View Details

We analyzed new samples of the Yanluowang ransomware. One interesting aspect of these samples is that the files are code-signed. They also terminate various processes which are related to database and backup management.

View Details

As the Zero Trust approach gains momentum, more organizations are looking to apply it to their security strategy. Learn how XDR and Zero Trust work together to enhance your security posture.

View Details

The authorization is effective until December 31, 2022.

View Details

Volume of traffic associated with the malware is now back at 50% of the volume before law enforcement took the botnet operation down in January 2021, security vendor says.

View Details

Penetration audits can be dangerous for people of color. Here is how to keep Black and brown cybersecurity professionals safe during red team engagements.

View Details

Outlook features intended to improve collaboration and productivity may make social engineering attacks more effective, researchers find.

View Details

A significant percentage of the 2 million consumer and small-business routers produced by a Latvian firm are vulnerable and being used by attackers, a security firm says.

View Details

Listen now or read as an article! (Full transcript inside.)

View Details

Security experts say the first hours in a phishing page's life are the most dangerous for users.

View Details

The latest integration furthers the company’s mission to provide an unmatched security model for businesses, without adding complexity for users.

View Details

Google took steps to shut down the Glupteba botnet, at least for now. (The botnet uses the bitcoin blockchain as a backup command-and-control mechanism, making it hard to get rid of it permanently.) So Google is also suing the botnet’s operators.

It’s an interesting strategy. Let’s see if it’s successful.

View Details

Fraud awareness training is just the beginning.

View Details

Scholarship's goal is to advance women in cybersecurity, risk, and privacy.

View Details

Investment aims to accelerate growth through continued product innovation and global expansion.

View Details

Enterprises will see improved access to data and more relevant insights that will enable them to further strengthen their cybersecurity postures.

View Details

Scholarships are part of an effort to bridge the cybersecurity workforce gap.

View Details

Solution secures cloud-to-Internet, cloud-to-cloud, cloud-to-data center, and intra-cloud communications.

View Details

"Demonically" possessed devices print out antiwork propaganda, advice on how to secure your store, and is Twitter's new photo privacy policy practical?

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Dinah Davis.

View Details

Nations want to collaborate on the creation of next-gen tools that shape new global rules on data use

View Details

Cybercriminals now try to use MSPs' own internal tools against them

View Details

The company is now directing Nickel's traffic to its own servers

View Details

In our study, we relied on the tactics, techniques, and procedures of MITRE ATT&CK to define the malware capabilities and characteristics of IoT Linux malware. We describe our findings and how IoT malware has been evolving.

View Details

Trend Micro Research determined the top 10 Azure services with the highest configuration rates.

View Details

A 31-year-old Canadian man has been arrested and charged with fraud in connection with numerous ransomware attacks against businesses, government agencies and private citizens throughout Canada and the United States. Canadian authorities describe him as "the most prolific cybercriminal we've identified in Canada," but so far they've released few other details about the investigation or the defendant. Helpfully, an email address and nickname apparently connected to the accused offer some additional clues.

View Details

Cybercriminals are increasingly adopting "living-off-the-land’ techniques, leveraging commonly used tools to fly under the radar of conventional detection tools. But with AI, thousands of organizations have regained the upper hand.

View Details

Industrial control systems security firm reaches $635M in funding with this Series E round.

View Details

In this Expert Insight, Jack Naglieri, the founder and CEO of Panther Labs, talks about the many challenges of enterprise-scale threat detection and response. Jack provides some steps organizations can take to prepare themselves for the future.

The post How to Overcome Threat Detection and Response Challenges appeared first on The Security Ledger...

Read the whole entry... »

Related Stories* Spotting Hackers at the Pace of XDR – From Alerts to Incidents * Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security * Episode 230: Are Vaccine Passports Cyber Secure?

View Details

Once again video has leaked from inside the UK Government that has put it in hot water.

View Details

Supermarket chain Spar has had more than 300 of its convenience stores in the UK affected by a ransomware attack, which has forced some to close their doors or only accept cash payments.

View Details

More than 300 branches have been affected as a result of the attack

View Details

Never been done before, the company says

View Details

Get the lowdown on virtual patching: a simplified, automated solution to shielding vulnerabilities from exploits.

View Details

Graham Cluley Security News is sponsored this week by the folks at Recorded Future. Thanks to the great team there for their support! Ransomware attacks dominate the cybersecurity news headlines, with businesses all over the world wondering if they will be the next victim. It’s a legitimate, and growing fear, as the attackers get more … Continue reading "Ransomware – how to stop it, and how to survive an attack. Free eBook by Recorded Future"

View Details

The officials targeted were either based in Uganda or worked on matters related to the country

View Details

It follows Twitter's recent removal of checkmarks from many verified accounts

View Details

Rarely do cybercriminal gangs that deploy ransomware gain the initial access to the target themselves. More commonly, that access is purchased from a cybercriminal broker who specializes in stealing remote access credentials -- such as usernames and passwords needed to remotely connect to the target's network. In this post we'll look at the clues left behind by "Babam," the handle chosen by a cybercriminal who has sold such access to ransomware groups on many occasions over the past few years.

View Details

The UK Government has been fined £500,000 after the addresses of over 1,000 New Years Honours recipients were mistakenly published online, potentially putting some of them at serious risk.

View Details

A former employee of Ubiquiti Networks has been arrested and charged in connection with a hack that stole gigabytes of data and attempted to extort US $2 million from the firm.

Read more in my article on the Hot for Security blog.

View Details

Sir Elton John and cricketer Ben Stokes are among individuals affected by the breach

View Details

We looked into exploitation attempts we observed in the wild and the abuse of legitimate platforms Netlify and GitHub as repositories for malware.

View Details

This week, learn about how Squirrelwaffle utilized ProxyLogon and ProxyShell to hack email chains. Also, read on a recent data breach of the Los Angeles Planned Parenthood Network.

View Details

Finland’s National Cyber Security Centre has issued a warning about malicious SMS messages that have been spammed out to mobile users, directing iPhone owners to phishing sites and Android users to download malware.

Read more in my article on the Tripwire State of Security blog.

View Details

Graham Cluley Security News is sponsored this week by the folks at 1Password. Thanks to the great team there for their support! 1Password 8 for Windows is the most modern, productive, and secure version of 1Password yet, helping you manage, access, and protect your sensitive information more easily and securely than ever before. Modern Design … Continue reading "1Password 8 for Windows – improved productivity, and enhanced security & privacy"

View Details

In January 2021, technology vendor Ubiquiti Inc. [NYSE:UI] disclosed that a breach at a third party cloud provider had exposed customer account credentials. In March, a Ubiquiti employee warned that the company had drastically understated the scope of the incident, and that the third-party cloud provider claim was a fabrication. On Wednesday, a former Ubiquiti developer was arrested and charged with stealing data and trying to extort his employer while pretending to be a whistleblower.

View Details

Lack of resources is a massive blocker, so you'll need to prioritise

View Details

The cash comes from ransomware payouts to mitigate REvil attacks

View Details

Cryptocurrency traders suffer a hamster-related loss, beware of charity scammers this holiday season, and do you have the patience to sit through Peter Jackson's eight-hour Beatles documentary?

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.

View Details

Mackenzie Jackson, the Developer Advocate at GitGuardian joins Paul to discuss how “secrets sprawl” on sites like GitHub threatens software supply chains.

The post Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security appeared first on The Security Ledger with Paul F. Roberts.

Click the icon below to listen. Related Stories* Episode 232: Log4j Won’t Go Away (And What To Do About It.) * Episode 227: What’s Fueling Cyber Attacks on Agriculture ? * Spotlight: Your IoT Risk Is Bigger Than You Think. (And What To Do About It.)

View Details

Unlike James Bond's Q, the spy agency cannot develop all the technologies it needs in-house

View Details

Welcome to your complete guide to AWS re:Invent 2021 Day 3, where you will find tips on how to get the most out of your conference experience both in Las Vegas and virtually.

View Details

Following our previous disclosure of compromised Docker hub accounts delivering cryptocurrency miners, we analyze these accounts and discover more malicious actions that you need to be aware of.

View Details

The breach reportedly started on 22 June and ended on 3 November

View Details

Merging the security function into DevOps won't happen overnight, but it's a vital step and the barriers aren't as high as sometimes believed

View Details

The ICO has issued a provisional notice to the company to stop further processing of the personal data of people in the UK

View Details

Hear leading analyst firm ESG and Chase Renes, system administrator at Vision Bank, discuss the operational, business, and financial value of Trend Micro’s industry-leading XDR solution.

View Details

Misconfigurations pose the biggest threat to cloud security. We compiled the top 10 AWS services with the highest misconfiguration rates.

View Details

Cloud misconfigurations can become opportunities for cyberattacks or lead to data breaches. Organizations must mitigate them before incurring significant and costly consequences.

View Details

The Prime Minister of Australia has said his government will introduce legislation which will compel social media companies to "unmask anonymous online trolls," and allow victims to launch defamation proceedings.

Read more in my article on the Hot for Security blog.

View Details

Reply-chain attacks allow hackers to send malicious emails from genuine accounts

View Details

Welcome to your complete guide to AWS re:Invent 2021, where you will find tips on how to get the most out of your conference experience both in Las Vegas and virtually.

View Details

Trend Micro, alongside Amazon Web Services, provides the latest in cloud-native deployment options. We have simplified network security, protecting customers across Virtual Private Clouds (VPCs) without needing agents to be installed on instances.

View Details

We have been tracking a campaign involving the SpyAgent malware that abuses well-known remote access tools (RATs) for some time now. While previous versions of the malware have been covered by other researchers, our blog entry focuses on the malicious actor’s latest attacks.

View Details

Police in Tarragona, Spain, have arrested a man and a woman after they allegedly infected computers at high-street stores with malware with the intention of mining cryptocurrency on them.

Read more in my article on the Hot for Security blog.

View Details

Imagine being able to disconnect or redirect Internet traffic destined for some of the world's largest companies -- just by spoofing an email. This is the nature of a threat vector recently removed by a Fortune 500 firm that operates one of the world's largest Internet backbones.

View Details

As we creep toward a post-pandemic world, organizations need to plan accordingly. Explore Trend Micro’s latest cyber risk research to enable your business to maximize its growth and potential.

View Details

Graham Cluley Security News is sponsored this week by the folks at 1Password. Thanks to the great team there for their support! 1Password 8 for Windows has been reimagined with productivity improvements, enhanced security and privacy features, and a new, modern design. 1Password 8 helps you manage, access, and protect your sensitive information more easily … Continue reading "Try out 1Password 8 for Windows, where security meets productivity"

View Details

Security researchers are warning biomanufacturing facilities around the world that they are being targeted by a sophisticated new strain of malware, known as Tardigrade.

Read more in my article on the Tripwire State of Security blog.

View Details

Heating systems are left vulnerable to attack in the high courts, cybercrime unicorns have become a reality (but what are they?), over 15 Terabytes of NFTs are made available for anyone to download ... and Carole reveals her Pick of the Year.

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mikko Hyppönen.

View Details

The United Kingdom government has introduced new legislation designed to improve the security of "smart" internet-connected devices used in people's homes.

Read more in my article on the Hot for Security blog.

View Details

Microsoft has described the flaw as having a high impact on data integrity, confidentiality and availability

View Details

Seeks to bar the Israeli firm from using its products

View Details

Hackers will attempt to target online shoppers on Black Friday and Cyber Monday, it warns

View Details

The attacker used a compromised password to access the company's provisioning system for Managed WordPress

View Details

Web-hosting firm and domain registrar GoDaddy has revealed that it has suffered cyber attack which saw a hacker gain access to details of over one million customers.

Read more in my article on the Hot for Security blog.

View Details

Explore this comprehensive guide to application security, which provides an overview of the importance of embedding runtime application security controls in the application build workflow to protect cloud-native web applications and APIs.

View Details

We observed BazarLoader adding two new arrival mechanisms to their current roster of malware delivery techniques.

View Details

Explore Trend Micro’s latest research into Void Balaur, a prolific cybermercenary group, to learn how to defend against attacks launched by this growing group of threat actors.

View Details

The 26 United Nations Climate Change Conference pushes for countries of parties to adopt more widespread EV use in order to reduce the looming threats of climate change.

View Details

In August, KrebsOnSecurity warned that scammers were contacting people and asking them to unleash ransomware inside their employer's network, in exchange for a percentage of any ransom amount paid by the victim company. This week, authorities in Nigeria arrested a suspect in connection with the scheme -- a young man who said he was trying to save up money to help fund a new social network.

View Details

Meanwhile WhatsApp has published a new privacy policy for users in Ireland and across Europe

View Details

One of the more common ways cybercriminals cash out access to bank accounts involves draining the victim's funds via Zelle, a "peer-to-peer" (P2P) payment service used by many financial institutions that allows customers to quickly send cash to friends and family. Naturally, a great deal of phishing schemes that precede these bank account takeovers begin with a spoofed text message from the target's bank warning about a suspicious Zelle transfer. What follows is a deep dive into how this increasingly clever Zelle fraud scam typically works, and what victims can do about it.

View Details

To help you enhance your defense against ransomware, Trend Micro Research shares key insights on how ransomware as a service (RaaS) operators work.

View Details

This week, learn about how the QAKBOT Loader malware has evolved its techniques and strategies over time. Also, read about the most recent initiative by the legislation to further cybersecurity protection.

View Details

Squirrelwaffle is known for using the tactic of sending malicious spam as replies to existing email chains. We look into how by investigating its exploit of Microsoft Exchange Server vulnerabilities, ProxyLogon and ProxyShell.

View Details

Over two years, Trend Micro Research scoured the underground forums for insight into the N-day exploit market. Discover their findings and how you can secure your organization against exploits.

View Details

Ransomware gangs have amassed big fortunes to compete with traditional buyers of zero-days, researchers find

View Details

This article will provide guidelines aimed at helping readers understand how to detect and prevent ransomware and limit its effect.

View Details

The CEO of a South Carolina technology firm has pleaded guilty to 20 counts of wire fraud in connection with an elaborate network of phony companies set up to obtain more than 735,000 Internet Protocol (IP) addresses from the nonprofit organization that leases the digital real estate to entities in North America.

View Details

Everything DevOps teams need to know about web application security risks and best practices.

View Details

In this blog entry, we will take a look at the ProxyShell vulnerabilities that were being exploited in these events, and dive deeper into the notable post-exploitation routines that were used in four separate incidents involving these web shell attacks.

View Details

The digital transformations that accompanied the pandemic are here to stay. To succeed in the post-pandemic era, organizations must come to a shared understanding about cybersecurity as a critical element of business risk.

View Details

A total of 13 suspects believed to be members of two prolific cybercrime rings were arrested as a global coalition across five continents involving law enforcement and private partners, including Trend Micro, sought to crack down on big ransomware operators.

View Details

We looked at how some malicious groups disable features in Alibaba Cloud ECS instances for illicit mining of Monero.

View Details

QAKBOT operators resumed email spam operations towards the end of September after an almost three-month hiatus. QAKBOT detection has become a precursor to many critical and widespread ransomware attacks. Our report shares some insight into the new techniques and tools this threat is using.

View Details

This week, learn about the prolific cybermercenaries, Void Balaur, and their recent attacks. Also, read on the 80-country agreement to mobilize safeguards against cyberattacks.

View Details

We can see signs of increased activity in areas of business that use 5G around the world. 5G technology will usher in new personal services through smartphones, and it will also play a large part in industry.

View Details

In this episode of the podcast (#230) Siddarth Adukia, a regional Director at NCC Group, joins host Paul Roberts to talk about the (cyber) risks and (public health) rewards of vaccine passport systems: how they work, how they can be compromised and what to do about it.

The post Episode 230: Are Vaccine Passports Cyber Secure? appeared first on ...

Read the whole entry... »

Click the icon below to listen. Related Stories* Spotlight: COVID Broke Security. Can We Fix It In 2022? * Spotlight: Operationalizing MDR with Pondurance CISO Dustin Hutchison * Spotlight: Your IoT Risk Is Bigger Than You Think. (And What To Do About It.)

View Details

Using a new batch of campaign samples, we take a look at its more recent cybercrime contributions and compare them with its previous deployments to demonstrate the group’s use of upgraded tools and payloads.

View Details

November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November.

View Details

One of the most prolific cybermercenaries is Void Balaur, a Russian-speaking threat actor group that has launched attacks against different sectors and industries all over the world.

View Details

We talk with Casey Ellis, founder and CTO of BugCrowd about how the market for software bugs has changed since the first bug bounty programs emerged nearly 20 years ago, and what’s hot in bug hunting in 2021.

The post Episode 229: BugCrowd’s Casey Ellis On What’s Hot In Bug Hunting appeared first on The Security Ledger with Paul F. Roberts.

Click the icon below to listen. Related Stories* Spotlight: When Ransomware Comes Calling * Episode 232: Log4j Won’t Go Away (And What To Do About It.) * Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion

View Details

In this Spotlight edition of the podcast, we’re joined by Curtis Simpson, the Chief Information Security Officer at Armis. Curtis and I discuss the growing cyber risks posed by Internet of Things devices within enterprise networks. IoT and OT (operation technology) deployments are growing and pose challenges to organizations that are still...

Read the whole entry... »

Click the icon below to listen. Related Stories* Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion * Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security * Episode 230: Are Vaccine Passports Cyber Secure?

View Details

Brian Trzupek of DigiCert joins Paul to talk about the findings of a recent State of PKI Automation survey and the challenges of managing fast-growing population of tens of thousands of PKI certificates.

The post Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion appeared first on The Security Ledger with Paul F. Roberts.

Click the icon below to listen. Related Stories* Episode 216: Signed, Sealed and Delivered: The Future of Supply Chain Security * Spotlight: COVID Broke Security. Can We Fix It In 2022? * Episode 229: BugCrowd’s Casey Ellis On What’s Hot In Bug Hunting

View Details

Eric Goldstein, Executive Assistant Director for Cybersecurity for the Cybersecurity and Infrastructure Security Agency (CISA), says the agency is all about helping companies and local government to keep hackers at bay. But are organizations ready to ask for help?

The post Episode 228: CISA’s Eric Goldstein on being Everyone’s Friend in Cyber...

Read the whole entry... »

Click the icon below to listen. Related Stories* Episode 229: BugCrowd’s Casey Ellis On What’s Hot In Bug Hunting * Episode 227: What’s Fueling Cyber Attacks on Agriculture ? * Spotlight: Operationalizing MDR with Pondurance CISO Dustin Hutchison

View Details

Contacless Mastercard and Maestro PINs can be bypasses due to a new vulnerability discovered by Swiss College of Engineering in Zurich, according to Cybersecurity News. 

The key aspect of the flaw is that it allows thieves to use a hacked Mastercard or Maestro card to make contactless payments without having to input the PIN to complete the transaction, if properly exploited.

Properly in this case entails first installing dedicated software on two Android smartphones. One device is used to simulate a point of sale terminal being installed, while the other acts as a card emulator that allows the modified transaction information to be transmitted to a real point-of-sale device. Once the card initiates a transaction, it reveals all related information.

To avert further attacks, security experts will not reveal the app in question 

Experts from ETH Zu...

View Details

Following sophisticated cyberattacks that targeted critical infrastructure, organizations and governments around the world, Microsoft, Amazon, Apple, IBM and Google pledged to invest a total of $30 billion in cybersecurity advances over the next 5 years, according to The Hacker News. 

US plans to develop a framework to improve the supply chain technologies and broaden CISA's role in safeguarding natural gas pipelines. A meeting was held in this sense at the While House that included top representatives from various US companies who agreed to help improve cybersecurity.

The pledges come following repeated high-profile cyberattacks on SolarWinds, Microsoft, Colonial Pipeline,

View Details

Microsoft issued a warning about a huge phishing campaign that uses open email links to steal credentials, according to The Hacker News.

An old idiom advises us to work smart, not hard and nobody applies it better than modern hackers. Using something as common as URLs, threat actors manage to trick numerous users into introducing sensitive information that could grant access to an organization's network, steal credit card information or personal data that can be used for blackmailing. Nowadays, some manage to perfect their campaigns to the point where they are not even detected by advanced and up-to-date anti-malware solutions.

Microsoft 365 Defender Threat Intelligence Team explained in a report "Attackers co...

View Details

With an average cost of a data breach reaching an all-time high of $4.24 million, still some companies fail to see the full picture and don't meet modern cybersecurity standards, according to Tripwire.  

Despite the fact that online threats are increasing on a daily basis, numerous firms fail to recognize the importance of proper cybersecurity. Interestingly enough, many companies are not aware that they are bound by state, industry, and international laws. Although there is no uniform national or global cybersecurity law in place, companies that fail to meet certain legislation can face legal consequences.

As cybersecurity becomes more of a serious concern, the need for online defense is starting to worry more governments around the world. Aside from the potential data loss, companies that...

View Details

Microsoft sent out a warning to thousands of cloud computing customers regarding threat actors that can view, modify, or even delete master databases if they gain access to their systems, according to Reuters.

Wiz announced that Microsoft Azure's flagship Cosmos database contain a vulnerability that allows access to keys that control access to the databases of hundreds of companies. Unable to update those keys itself, Microsoft sent an email to its customers Thursday asking them to create new keys. The software giant compensated Wiz with $40,000 in cash for discovering and reporting the security flaw.

Microsoft said, "Microsoft recently became aware of a vulnerability in Azure Cosmos DB that could potentially allow a user to gain access to another customer's resources by using the account's primary read-w...

View Details

A vpnMentor investigation found that a 134 GB server owned by EskyFun is exposed and user data was leaked for game titles such as Metamorph M, The Three Kingdoms Legend, Adventure Story, Rainbow Story, and Fantasy MMORPG.

The aforementioned games were downloaded 1.6 million times, whereas the leaked information had more than 365 million records. An intriguing aspect is that developers increased the amount of analytics, monitoring and authorization options available for the games, some needing more permissions even before they were installed.

Data disclosed includes IP and IMEI numbers, mobile device event logs, device information, phone numbers, EskyFun network passwords, current operating system, rooted or otherwise rooted phones, player acquisition and transaction reports, mailing, and support requests. Various data points were also used to identify profile individuals as well as tw...

View Details

Cybercriminals are launching a new scam to take advantage of the release of Kanye West's Donda album by distributing malicious fake downloads on the Internet, according to Tech Republic.

Cybersecurity firm Kaspersky proactively studied the event to see if threat actors were spreading any malware across the Internet. They emphasized that one of the scams is to target the release of highly anticipated media (movies, music), as they can place the malicious code in fake files that can be easily downloaded.

This particular scam attempt involves the uploading of fake malicious files to the Internet that are similar to those that were identified prior to the introduction of Black Widow. Kanye's fans are given a link to download the album and then asked to participate in a survey to confirm they are not robots. Afterwards, customers are redirected to a...

View Details

Over the course of September 2019 to April 2021, Palo Alto Network's Unit 42 monitored firewall traffic and phishing sites detected by URL filters. The number of new phishing pages per week increased significantly when individuals began working from home. 

Threat actors improved and intensified their phishing attacks by exploiting remote work environments where employees were not protected by corporate firewalls. Cybersecurity experts noticed a sudden and significant drop in traffic between March and April 2020, when COVID began spreading across the United States, forcing companies to switch to remote work. 

Education and high-tech industries saw significant declines in traffic during this period, with the latter having the steepest drop: education (a 46% drop), most likely due to school closures, and high-tech (a 35% drop), probably because more employees starting working from home...

View Details

Two zero-day vulnerabilities affecting Unitrends backup and continuity service have been patches by Kaseya recently, according to The Hacker News. 

Dutch Institute for Vulnerability Disclosure (DIVD) informed that the provider of IT infrastructure management solutions has solved server software bugs 10.5.5-2 reported on August 12. Both vulnerabilities are part of a trio of flaws discovered and reported on July 3, 2021. The issues encompass both an authenticated vulnerability to remote code execution and a privilege escalation fault on Unitrends servers from the read-only user to the administrator.

Users of unpatched software should avoid connecting the affected servers to the Internet 

A previously unknown client vulnerability in Kaseya Unitrends has not yet been patched. Then again, the company issues some firewall rules recommendations to...

View Details

A new report titled SANS 2021 OT/ICS Cybersecurity Report contains alarming information gathered from 480 individuals in various industries. Organizations that use operational technology (OT) and industrial control systems (ICS) are very concerned about cyber attacks. 

The findings highlight the need for businesses to improve the ability to anticipate and respond to emerging threats and opportunities. While many are taking precautions to reduce risks, they are unaware if the breaches already occurred within their organization. To summarize the findings: Approximately 70% of respondents indicated that the risk to their operational technology environment was high or severe. With many companies concerned about cyber risk in their operating environment, 48% of respondents did not know whether they had encountered a breach of o...

View Details

Linux-based machines that are directly connected to the Internet can be targets for attackers who can quickly push potentially dangerous web-based shells, ransomware, Trojans, and other malicious software, according to The Hacker News. 

Trend Micro produced a comprehensive analysis of the Linux threat landscape, highlighting the barriers and vulnerabilities that have plagued the operating system in the first half of the year. The information was gathered using honeypots, sensors and anonymous telemetry.

According to the company, which has detected about 15 million malware attacks targeting Linux-based cloud environments, ransomware and coin miners account for 54% of all malware, while web shells represent 29% of all recorded events. 

Researchers evaluated over 50 million events from 100,000 unique Linux servers and identified 15 separate vulnerabilities used in th...

View Details

Following reports of personal data leaked online from the entire population, a small Swiss town revealed that it had misjudged the seriousness of the cyber attack late in the day before, according to Security Week. 

Rolle, a small, lovely town on the beaches of Lake Geneva, acknowledged that it had been targeted by a ransomware attack and that sensitive information on some administrative systems had been compromised. The attack took place on May 30 and the city government said that only modest amounts of data were compromised at the time. Moreover, all information was restored from backup copies of the original files. However, according to an investigation published Wednesday by the French daily Le Temps, the attack was considerably larger.

Cybercriminals stole names, residences, and social security numbers

Le Temps cites an unidentified ...

View Details

On Wednesday, President Joe Biden will meet with top executives from some of the country's largest technology and financial companies, as the White House seeks private sector backing for a unified cyber defense against emerging threats, according to MCU Times. 

The gathering comes amid an increase in ransomware attacks on critical infrastructure, extorting multi-million dollar payments from large corporations, and other illicit cyber operations linked to foreign hackers by US authorities. According to a senior government official, the purpose of the conversation is to identify the root causes of hostile cyber activity as well as ways in which the private sector may contribute to enhancing cybersecurity.

The President Biden proposed an infrastructure bill would provide about $1 trillion in cybersecurity subsidies to state, local and tribal governmen...

View Details

Chinese advanced persistent threat (APT) gangs have resumed their hacking activities, with one of the attacks targeting an American computer retailer using an unknown backdoor referred to as Sidewalk, according to The Hacker News.

In a report, ESET Cybersecurity Researchers Mathieu Tartare and Thibaut Passilly describe the fresh backdoor as modular, allowing the dynamic loading of additional modules from specific control and command servers. The malware is also designed to target Cloudflare workers as C&C servers and Google Docs as dead drop resolvers. 

Security researchers describe SideWalk as "responsible for reading the encrypted shellcode from disk, decrypting it and injecting it into a legitimate process using the process hollowing techniqu...

View Details

FluBot Android malware is back and already launched several attacks outside the regular geographical region of impact, according to Cyware. 

Recently conducted research into the FluBot banking malware has revealed an upsurge in the number of dangerous distribution pages in a variety of Australian, Polish, and German financial institutions.  

Numerous intriguing elements were incorporated by the threat actors in the new operations that now collected user credentials by overlaying several popular banking applications. The design of the malicious web pages is devised to disseminate text messages that appear to be voicemail notifications or shipment tracking information, but are actually scams. 

It is worth noting that the cybercriminals were able to accomplish all of this while remaining undetected during the infection process thanks to a Domain Generation Algorithm (D...

View Details

A mistake by a health care worker resulted in the leaking of medical information of about 12,000 patients. The phishing attack took place on June 21 and lasted only 45 minutes, according to The Spectrum. 

While he breach exposed medical record numbers, birth dates, procedures, and insurance provider names, provider names, the two-month investigation determined that the breach posed a negligible risk to the patients affected. Moreover, Revere Health believes that the hacker is not attempting to publish the patient medical information, but rather is using the incident as a platform to conduct more sophisticated phishing email attacks against other employees. 

Bob Freeze, the director of marketing and communications, stated that the stolen data affected patients of the Heart of Dixie Cardiology Department in St. Georg...

View Details

In an unexpected data leak, more than 38 million records from 47 organizations using Microsoft's gateway platform Power Apps were accidentally published online, according to The Hacker News. 

The unfortunate incident resulted in the leakage of sensitive information on servers of corporations such as Microsoft, J.B. Hunt, and American Airlines along with government agencies from Indiana, Maryland, and New York City.

Power Apps are mostly used for developing custom low-code applications for mobile devices as well as websites. The programs created by Microoft have a number of advantages, such as APIs that allow other applications to access data, templates as well as managing and collecting information and storage.

Key information that went missing: 

The misconfiguration of a port could lead to making the stored data public and this is what happened h...

View Details

The hacker known as Mr. White found a way to resolve one of the biggest cryptocurrency thefts of all time, according to CNBC.

Earlier this week, Poly Network, a decentralized financial network, announced that about $600 million in bitcoin had been stolen from its vaults due to a coding error. The sum was changed immediately to other cryptocurrencies, namely a total of $273 million in Ethereum tokens, $253 million in Binance Smart Chain tokens, and $85 million in USDC.

Surprisingly, the thief known as Mr. White Hat, began recovering assets almost shortly after the discovery and distributed t...

View Details

A customized version of the WhatsApp Messaging App for Android has been found to display full-screen advertising, register device users for unwanted premium subscriptions without their agreement and deliver dangerous payloads, says The Hacker News. 

Generally speaking, modifications of legitimate Android apps are launched to perform functions that were not originally intended. For instance, you can customize icons, disable video calls, add themes or hide features like Recently Seen with FMWhatsApp. Then again, not all mods are launched with good intentions and this is another case of why you should be wary of too-good-to-be-true free services.

The FMWhatsApp version discovered by

View Details

Researchers identified 4 new ransomware gangs that are targeting businesses and key infrastructure, according to The Hacker News. 

Ransomware attacks nowadays did not only increase in frequency and intensity, but went beyond financial gain, posing a threat to the national security of firms, hospitals, schools, and governments worldwide. Palo Alto Networks' Unit 42 threat intelligence team notes "While the ransomware crisis appears poised to get worse before it gets better, the cast of cybercrime groups that cause the most damage is constantly changing".

While we did not hear too much of them lately compared to previous years, Unit 42 says this is just the calm before the storm. Let's explore the latest ransomware kits on the market and the groups behind them.

AvosLocker

AvosLocker is a late-June ransomware company that exploits press announce...

View Details

Singapore and the U.S. signed several Memorandums of Understanding (MOUs) to expand their cybersecurity cooperation in areas such as defense, banking, and research and development, according to ZDNet. These activities include increased information sharing, team building, training and skills development. 

Three MOUs were signed on Monday during the US' three-day visit to Asia Vice President Kamala Harris. One was an agreement between Singapore and the U.S. Cyber Security and Infrastructure Security Agency (CISA) aimed at expanding the cybersecurity partnership beyond data sharing and exchange. Both government agencies will explore new areas of cooperation, such as important technological research and development.  The first MOU will allow both partners to strengthen existing partnerships between the countries so that they are able to work clo...

View Details

The Department of Defense's Cyber Command issued warnings about a possibly significant cyberattack against the United States Department of State that may have occurred in recent weeks.  

According to yesterday's report from Fox News, it is still unclear how much damage has been done following the security incident, who the perpetrator was and whether the operations of the institutions have been affected. Given the nature of the Department, the information cannot be divulged, making things more complicated.

A department spokesperson told Fox News, "The Department takes seriously its responsibility to safeguard its information and continuously takes steps to ensure information is protected" [...] "For security reasons, we are not in a position to discuss the nature or scope of any alleged cybersecurity incidents at this time".

T...

View Details

With each passing day, the fallout from T-Mobile's recent data breach grows more serious. An update released Friday suggests hacking firms unlawfully obtained the personal information of another 5.3 million postpaid customers, including names, addresses, birthdates, IMSIs, IMEIs, and phone numbers, according to Fox Business. 

The firm recently declared it discovered an additional 667,000 accessible user accounts that included addresses, phone numbers, customer names, and dates of birth. The latest figures put the total number of people affected by the security breach at more than 50 million, an increase from...

View Details

Cybersecurity firm Check Point discovered disturbing statistics concerning the significant growth in the weekly number of cyber attacks directed against firms and organizations in the world of education, according to Times of Israel. 

Schools, colleges, and research institutions are among the organizations that have been targeted. In July 2021, there was an average of 1,739 attacks per organization per week, a 29% increase from the same month last year. The top 3 countries affected by the issue include: India - average of 5,196 assaults and 29% increase from 2020 Italy - average of 5,016 assaults and 70% increase from 2020 Israel - average o...

View Details

The cyberattack that crippled Iranian trains last month was recently attributed to the cybercriminal group Indra. The group is known for a series of attacks on several Syrian organizations using a wiper on the hacked networks, according to Cyware. 

As expected, Indra denies any involvement in the latest attack on Iran. Then again, a large body of evidence suggests that the attackers were aware and had prior knowledge of the targeted networks. The attackers have distributed three different versions of Comet, Stardust, and Meteor wipers across victims' social media networks in the past couple of years.

According to CheckPoint

View Details

IBM X-Force published the specifics of an early variant of an emerging ransomware strain dubbed Diavol, according to Security Intelligence.

Several months ago, Fortinet discovered an unsuccessful ransomware attempt employing the Diavol payload that was targeting a client of the firm. When the experts from the security business investigated the incident, they discovered a ransomware strain that was capable of launching successful attacks. However, IBM's security specialists disagree, stating that the malware is still in the early stages of development and that it was built solely for the purpose of research and development.

The Diavol ransomware sample uses RSA encryption, an algorithm that can prioritize the file types ...

View Details

In the first six months of this year, 600 vulnerabilities were discovered in ICS products (Industrial Control Systems), impacting 76 vendors. The number of vulnerabilities increased by 41% in the same period, according to Claroty's ICS Risk & Vulnerability Report: H1 2021. 

As the need to connect devices to the internet increases, so does the risk of being attacked by cybercriminals. Companies need to drive their business and invest in Operational Technology (OT) devices, and threat actors are using this growth to their advantage, seeking to launch hacking campaigns by taking advantage of companies that have vulnerable IT systems. 

Advantech (22), WAGO (23), Rockwell Automation (35), Schneider Electric (65) and Siemens (146 vulnerabilities) are the most affected manufacturers. An important aspect is that the list of affected manufacturers also includes 20 companies whose product...

View Details

In recent months, more crypto exchange platforms have been targeted by hackers. The most recent attack resulted in the theft of $97 million worth of digital assets from the Japanese cryptocurrency exchange Liquid, according to ZDNet. 

Liquid did not provide an estimate of damages because it is subject to analyses of the Financial Services Agency from Japan. Nevertheless, the attack affected many users, as Liquid is among the top 20 crypto exchanges in the world in terms of daily trading volume, sums estimated at more than $133 million per day on CoinMarketCap.

On the other hand. blockchain analytics firm Elliptic, claimed hackers obtained more than $97 million in cryptoc...

View Details

Trend Micro spotted recent malicious activity conducted by cybercriminal group Confucius. The hackers launched a spear-phishing campaign using Pegasus lures to trick users into clicking on a malicious document that downloads a data theft code.  

The attack begins with a clean email that contains a text copied from a legitimate Pakistani newspaper article.Two days later, the victim receives a new email with a warning from a Pakistani military official about the Pegasus spyware that includes a cutt.ly link to encrypted Word document and a decryption password.

Regardless of the action taken by the victim, clicking on either of the links leads to downloading the Word document. If the target makes the mistake of entering...

View Details

Following a series of disruptive and headline-grabbing ransomware attacks on corporations in the United States over the past several months, the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA) has released a list of suggestions to prevent and respond to these sorts of attacks. 

The information sheet called Protecting Sensitive and Personal Information from Ransomware-Caused Data Breaches contains numerous recommendations. In addition, the paper advises companies not to pay a ransom if they are the target of a ransomware attack. 

The fact sheet reads “Ransomware is a serious and increasing threat to all government and private sector organizations, including critical infrastructure organizations. In response, the U.S. government launched...