President and Chairman of Trusted Computing Group (TCG), Dr. Joerg Borchert, shares the news regarding TCG's first ever CodeGen Developer Challenge.
The post Leonardo DRZ wins first ever TCG CodeGen Developer Challenge appeared first on The Security Ledger with Paul F. Roberts.
Related Stories* Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security * Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion * Spotlight: E-Commerce’s Bot and Mouse Game
The security vulnerability could expose passwords and access tokens, along with blueprints for internal infrastructure and finding software vulnerabilities.
You know you want one, because this retro phone is NOT A TOY... except when it comes to cybersecurity.
Attackers use the Telegram handle “Smokes Night” to spread the malicious Echelon infostealer, which steals credentials for cryptocurrency and other user accounts, researchers said.
The origin of the Monero cryptominer file has been traced to a Russian torrent website, researchers report.
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
Researchers found an insecure default behavior in Azure App Service exposing source code of some customer applications deployed using "Local Git."
A new study investigating consumer password use found 25% of online shoppers would abandon their carts of $100 if prompted to reset a password at checkout.
The open-sourced scanner was derived from scanners built by members across the open source community, CISA reports.
Overtaking the Conti ransomware gang, PYSA finds success with government-sector attacks.
A critical privilege-escalation vulnerability could lead to backdoors for admin access nesting in web servers.
Once the dust settles on Log4j, many IT teams will brush aside the need for the fundamental, not-exciting need for better asset and application management.
Don't freak: It's got nothing to do with Log4Shell, except it may be just as far-reaching as Log4j, given HTTPD's tendency to tiptoe into software projects.
The US has returned $154 million in bitcoins stolen by a Sony employee.
However, on December 1, following an investigation in collaboration with Japanese law enforcement authorities, the FBI seized the 3879.16242937 BTC in Ishii’s wallet after obtaining the private key, which made it possible to transfer all the bitcoins to the FBI’s bitcoin wallet.
Zero trust may be one of the hottest trends in cybersecurity, but just eliminating trust from networks isn’t enough to prevent successful organizational data breaches, says Wes Wright, CTO of Imprivata.
The functionality of all-in-one platforms is being deconstructed into a smorgasbord of services that can be used to develop bespoke end-user security procedures for specific work groups, lines of businesses, or customer communities.
Attackers exploiting bugs in the “link preview” feature in Microsoft Teams could abuse the flaws to spoof links, leak an Android user’s IP address and launch a DoS attack.
The UK's NCA and NCCU have shared 225 million stolen emails and passwords with HIBP, which tracks stolen credentials.
The Facebook parent company seeks court's help in identifying the individuals behind some 39,000 websites impersonating its brands to collect login credentials.
Yaron Kassner, CTO and co-founder of Silverfort, discusses why using all-seeing privileged accounts for monitoring is bad practice.
There are 17,000 unpatched Log4j packages in the Maven Central ecosystem, leaving massive supply-chain risk on the table from Log4Shell exploits.
Data from dozens of penetration tests and security assessments suggest nearly every organization can be infiltrated by cyberattackers.
A quarter-billion of those passwords were not seen in previous breaches that have been added to Have I Been Pwned.
If security teams are not logging everything, they are increasing security risk and making it more difficult to investigate and recover from a data breach. Modern log management goes beyond just a SIEM.
Focusing on basic security controls and executing them well is the best way to harden your systems against an attack.
For zero trust to be successful, organizations need to be able to check user identity, device posture, and overall behavior without adding friction to the experience.
Learn more about some tactical measures people are already taking, and some strategic guidance for what to do after the immediate crisis abates.
With recent news of the critical, zero-day vulnerability Apache Log4Shell, we explore how to detect and protect your Apache HTTP servers.
Vladislav Klyushin was allegedly involved in a global operation to trade on nonpublic data stolen from US computer networks.
Meanwhile, Apache Foundation releases third update to logging tool in 10 days to address yet another flaw.
The acquisition of Cedrus Digital, with its consulting-led model and over 150 cloud, data and product engineers, primarily in the United States, will further augment Brillio’s nearshore digital transformation capabilities offered for Fortune 500 clients.
Led by IoT security expert Larry Trowell, the IoT pen-testing services focus on securing ATMs, automotive, medical devices, operational technology, and other embedded systems.
Be happy that your sysadmins are taking one (three, actually!) for the team right now... here's why!
Company partners with Exabeam to launch update to its BlackBerry Guard managed detection and response (MDR) service.
While the shipping industry's cyber posture was better than companies in the Forbes Global 2000, the industry performed lower in key risk group factors.
Challenges were designed to address critical areas of cybersecurity, including reversing, cloud, IoT, open source intelligence, forensics, and machine learning.
Half of security decision makers also say the cyber skills gap will significantly impact their 2022 strategy, according to new research from Neustar.
Citizen Lab published another report on the spyware used against two Egyptian nationals. One was hacked by NSO Group’s Pegasus spyware. The other was hacked both by Pegasus and by the spyware from another cyberweapons arms manufacturer: Cytrox.
We haven’t heard a lot about Cytrox and its Predator spyware. According to Citzen Lab:
We conducted Internet scanning for Predator spyware servers and found likely Predator customers in Armenia, Egypt, Greece, Indonesia, Madagascar, Oman, Saudi Arabia, and Serbia.
Cytrox was reported to be part of Intellexa...
Security experts in Germany discover similar attacks that lock building engineering management firms out of the BASes they built and manage — by turning a security feature against them.
Some think zero trust means you cannot or should not trust employees, an approach that misses the mark and sets up everyone for failure.
And of those redirected to a spoofed web site, almost a quarter will enter their details into a form
Trying to adopt DevSecOps culture? Or already in the thick of it? Trend Research explores the cybersecurity trends for 2022 to enhance your security strategy and get the most out of DevSecOps.
We created a free assessment tool for scanning devices to know whether it is at risk for Log4Shell attacks.
This seems big:
The UK government has officially included decapod crustaceans–including crabs, lobsters, and crayfish–and cephalopod mollusks–including octopuses, squid, and cuttlefish–in its Animal Welfare (Sentience) Bill. This means they are now recognized as “sentient beings” in the UK.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Read my blog posting guidelines here.
Security teams around the world are on high alert dealing with the Log4j vulnerability, but how risky is it, really?
Have you ever seen the message "An error occurred"? Even worse, the message "This error cannot occur"? Facts matter!
The parent company of Facebook and Instagram has warned some 50,000 account holders they are targets of surveillance.
One leader alone can't protect an organization from cyber threats, C-suite leaders agree.
EXPERT INSIGHT: How to assess your exposure to the vulnerability with a combination of asset inventory, testing, solid information sources, and software bills of materials (SBOMs).
The "PseudoManuscrypt" operation infected some 35,000 computers with cyber-espionage malware and targeted computers in both government and private industry.
CISOs are increasingly drawn to the zero trust security model, but implementing a frictionless experience is still a challenge.
The Cybersecurity Infrastructure and Security Agency orders federal agencies to take actions to mitigate vulnerabilities to the Apache Log4j flaw and attacks exploiting it.
Kaspersky experts have discovered an attack that used PseudoManuscrypt spyware to hit industrial systems.
If you cannot track, access, or audit data at every stage of the process, then you can't claim your data is secure.
Targets include journalists, dissidents, human rights activists and critics of authoritarian regimes and their families
Researchers observe multiple attempts to deploy a Khonsari ransomware that hits Windows machines by making use of Log4Shell bug
The new API and SDK from Pixalate helps mobile developers avoid getting their apps delisted from app stores by detecting and blocking fraudulent traffic.
In this episode of the podcast (#232), Tomislav Peričin of the firm ReversingLabs joins us to talk about Log4Shell, the vulnerability in the ubiquitous Log4j Apache library. Tomislav tells us why issues related to Log4j won’t be going away anytime soon and how organizations must adapt to deal with the risk it poses.
The post Episode 232: Log4j...
Read the whole entry... »
Click the icon below to listen. Related Stories* Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security * Episode 227: What’s Fueling Cyber Attacks on Agriculture ? * Episode 229: BugCrowd’s Casey Ellis On What’s Hot In Bug Hunting
We analyzed a fileless QAKBOT stager possibly connected to the recently reported Squirrelwaffle campaign.
We review 2020 and 2021 Oracle WebLogic vulnerabilities and how using a unified SaaS platform can help you detect and mitigate these sophisticated risks.
This week, read on Purple Fox’s infection chain observed by Trend Micro’s Managed XDR. Also, learn about the Log4j vulnerability that has the potential to cause ‘incalculable’ damage.
The Log4j flaw exists in a component that is not always easy to detect and is widely used beyond an organization's own networks and systems.
A new variant dubbed "Twizt" has hijacked 969 transactions and stolen the equivalent of nearly $500,000 USD.
Latest episode - listen now! (Yes, there are plenty of critical things to go along with Log4Shell.)
Before the fourth installment of The Matrix premieres, we look at the snags and vulnerabilities in the AI-implemented metaverse.
A look at why this is such a tricky vulnerability and why the industry response has been good, but not great.
A 24-year-old New York man who bragged about helping to steal more than $20 million worth of cryptocurrency from a technology executive has pleaded guilty to conspiracy to commit wire fraud. Nicholas Truglia was part of a group alleged to have stolen more than $100 million from cryptocurrency investors using fraudulent "SIM swaps," scams in which identity thieves hijack a target’s mobile phone number and use that to wrest control over the victim’s online identities.
Graham Cluley Security News is sponsored this week by the folks at Recorded Future. Thanks to the great team there for their support! Ransomware attacks dominate the cybersecurity news headlines, with businesses all over the world wondering if they will be the next victim. It’s a legitimate, and growing fear, as the attackers get more … Continue reading "Free eBook! Ransomware – how to stop it, and how to survive an attack"
Log4j is being exploited by all sorts of attackers, all over the Internet:
At that point it was reported that there were over 100 attempts to exploit the vulnerability every minute. “Since we started to implement our protection we prevented over 1,272,000 attempts to allocate the vulnerability, over 46% of those attempts were made by known malicious groups,” said cybersecurity company Check Point.
And according to Check Point, attackers have now attempted to exploit the flaw on over 40% of global networks.
And a second vulnerability was found, in the patch for the first vulnerability. This is likely not to be the last...
As mandatory reporting bills work their way through the halls of Congress, what should businesses do to prepare for this pending legislation?
The United States Department of Homeland Security (DHS) is inviting security researchers to uncover vulnerabilities and hack into its systems, in an attempt to better protect itself from malicious attacks.
Read more in my article on the Tripwire State of Security blog.
This week on the Kaspersky podcast, Dave and Jeff discuss how a fat-fingered mistake cost an NFT owner a lot of money, Instagram improvements for teens, Log4J, and more.
Noname Security's Series C fundraising tips the startup to over $1 billion in valuation -- a sign that organizations are beginning to look for API security tools and investors are looking for innovation in the space.
After a brief discussion of the Log4Shell vulnerability panic, we chat about how Virgin Media has got itself into hot water, a fat-fingered fumble at the Bored Ape Yacht Club, and how to hack around your sleeping girlfriend's facial recognition.
All this and more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.
Organizations should upgrade ASAP to new version of logging framework released Tuesday by the Apache Foundation, security experts say.
Most companies lack the proper tools to assess their vulnerability to threats facing their AI systems and ML pipelines, prompting Microsoft to release a risk assessment framework.
A new bug bounty program aims to find potential security flaws within certain DHS systems and strengthen the department's security posture.
The early lessons from Log4j indicate that key security principles can help better handle these high-risk software supply chain security incidents if teams have proper support.
Scraping bugs and scraped databases are two new areas of research for the company's bug-bounty and data-bounty programs.
Combined capabilities will help clients address the growing complexity of securing public, private and hybrid cloud, 5G, IoT, and industrial control systems
With access to a user's 3D model and full-body digital tracking, attackers can recreate the perfect replica of a C-level executive to trick employees.
SASE is a promising and burgeoning networking architecture approach, but it's not without some challenges.
The way to improve the security of the modern software development life cycle and reduce the number of application-based breaches is to re-center app security around the needs of developers.
Cloud security is a shared responsibility. which sometimes leads to security gaps and complexity in risk management.
Kryptowire’s end-to-end cybersecurity engine identified vulnerabilities granting system user-level privileges for arbitrary shell script execution.
New flaw is much less severe than the Log4jshell vulnerability, but admins are advised to update Log4j once again
From 2018-2020, users were forced to consent to a new privacy policy to continue using the app - which the Norwegian regulator has ruled as invalid
Four security vendors give their view on staffing issues, zero trust and threat intelligence
Hybrid work is here to stay, and organizations can apply zero trust's three core principles to ensure a secure workforce, Devata says.
Trend Micro's tracking of modern ransomware, as well as of older families, shows which attacks are gaining momentum and which families are particularly dangerous for enterprises and private users.
Automates security policy design to ensure compliance and reduce likelihood of breach announcing significant updates to other marketplace apps.
Google Survey of 1,000 U.S. consumers uncovers data privacy disconnect, a call to action for businesses.
Amid the increase in Log4j attack activity, at least one Iranian state-backed threat group is preparing to target the vulnerability, experts say.
North America-based Superior Plus "temporarily disabled" some of its systems in the wake of the attack.
The attack forced a shutdown of computer systems and websites for Virginia legislative agencies and commissions, reports state.
Microsoft, Adobe, and Google all issued security updates to their products today. The Microsoft patches include six previously disclosed security flaws, and one that that is already being actively exploited. But this month's Patch Tuesday is being overshadowed by the "Log4Shell" 0-day exploit in a popular Java library that web server administrators are now racing to find and patch amid widespread exploitation of the flaw.
Security professionals are burning out from handling too many tools and facing a growing number of threats, and more than 40% see lack of leadership as the main problem.
The December rollout includes 67 security patches and addresses one zero-day and five more publicly known vulnerabilities.
The malicious module our experts are calling OWOWA integrates into IIS Web servers and steals mail credentials.
This is a current list of where and when I am scheduled to speak:
The list is maintained on this page.
Source code is a corporate asset like any other, which makes it an attractive target for hackers.
It’s serious:
The range of impacts is so broad because of the nature of the vulnerability itself. Developers use logging frameworks to keep track of what happens in a given application. To exploit Log4Shell, an attacker only needs to get the system to log a strategically crafted string of code. From there they can load arbitrary code on the targeted server and install malware or launch other attacks. Notably, hackers can introduce the snippet in seemingly benign ways, like by sending the string in an email or setting it as an account username...
One volley of fake news may land, but properly trained AI can shut down similar attempts at their sources.
The accounting firm PricewatersCoopers recently published lessons learned from the disruptive and costly ransomware attack in May 2021 on Ireland's public health system. The unusually candid post-mortem found that nearly two months elapsed between the initial intrusion and the launching of the ransomware. It also found affected hospitals had tens of thousand of outdated Windows 7 systems, and that the health system's IT administrators failed to respond to multiple warning signs that a massive attack was imminent.
The three must-haves in eXtended Detection and Response are: making data accessible, facilitating real-time threat detection, and providing remediation strategies.
Our long-term monitoring of the cyberespionage group Earth Centaur (aka Tropic Trooper) shows that the threat actors are equipped with new tools and techniques. The group seems to be targeting transportation companies and government agencies related to transportation.
Every high-profile breach leaves a trail of bread crumbs, and defenders who monitor access brokers can connect the dots and detect attacks as they unfold.
Everyone is talking about Log4Shell, a zero-day remote code execution exploit in versions of log4j, the popular open source Java logging library.
Government actions help starve attack groups of the resources - money, ability to recruit, and time.
This Tech Tip outlines how enterprises can use Canarytokens to find servers in their organization vulnerable to CVE-2021-44228.
The company confirmed last week that one of its file repositories was accessed by a third party.
Customers advised to adopt alternative internal processes to support the affected human resources services.
The number of bug bounty programs jumped by a third, the median payout for a critical vulnerability report rose to $3,000, but rewards for easier-to-find lower-severity flaws stagnated in 2021.
Find out how to deal with the Log4Shell vulnerability right across your estate. Yes, you need to patch, but that helps everyone else along with you!
Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.
The opening marks the fifth center opened globally, fulfilling a key milestone within the Global Transparency Initiative.
Some tips for effectively combating Web supply chain attacks and customer hijacking via browser extensions.
Left unchecked, these attacks could have devastating effects on government and military secrets and jeopardize the software supply chain and the global economy.
In a matter of days, a large-scale outage of cloud and other online services could cause $15 billion in losses.
Kaspersky opens its fifth Transparency Center. The new facility — our first in North America — is in Fredericton, New Brunswick, Canada.
The incident comes at the time when the government is reportedly working on a Bill to ban 'all private cryptocurrencies' in the country with 'certain exceptions'
NSO Group’s descent into Internet pariah status continues. Its Pegasus spyware was used against nine US State Department employees. We don’t know which NSO Group customer trained the spyware on the US. But the company does:
NSO Group said in a statement on Thursday that it did not have any indication their tools were used but canceled access for the relevant customers and would investigate based on the Reuters inquiry.
“If our investigation shall show these actions indeed happened with NSO’s tools, such customer will be terminated permanently and legal actions will take place,” said an NSO spokesperson, who added that NSO will also “cooperate with any relevant government authority and present the full information we will have.”...
Germany's approach is the opposite to what British government thinks about the use of encryption on digital platforms
Log4Shell., also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched with version 2.15.0 of Log4j on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
Trend Micro's VP of Threat Intelligence, Jon Clay, explores the latest trends in today's threat landscape and why XDR is key to enabling more resilience.
By examining Purple Fox’s routines and activities, both with our initial research and the subject matter we cover in this blog post, we hope to help incident responders, security operation centers (SOCs), and security researchers find and weed out Purple Fox infections in their network.
Researchers found critical vulnerability in Apache Log4j with CVSS 10 designated as CVE-2021-44228 (aka Log4Shell or LogJam). Here’s how to mitigate.
This Tech Tip outlines how enterprise defenders can mitigate the risks of the Log4j vulnerabilities for the short-term while waiting for updates.
The Far Side is always good for a squid reference. Here’s a recent one.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Read my blog posting guidelines here.
A remote code execution vulnerability in Log4j presents a bigger threat to organizations than even the infamous 2017 Apache Struts vulnerability that felled Equifax, they say.
The latest NIST publication outlines how organizations can build systems that can anticipate, withstand, recover from, and adapt to cyberattacks.
Oleg Koshkin was sentenced for running a crypting service used to hide the Kelihos malware from antivirus software.
Rodney Petersen, the director of the National Initiative for Cybersecurity Education (NICE) talks about the massive shortage of information security workers at the United States - estimated at more than 400,000 workers.
The post Episode 231: Solving the US’s Endemic Cybersecurity Worker Shortage appeared first on The Security Ledger with Paul F....
Read the whole entry... »
Click the icon below to listen. Related Stories* Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security * Episode 228: CISA’s Eric Goldstein and the Challenge of Being Everyone’s Friend in Cyber * Episode 227: What’s Fueling Cyber Attacks on Agriculture ?
Just when you thought it was safe to relax for the weekend... a critical bug showed up in Apache's Log4j product
With more staff working remotely, identity, authentication, and access (IAA) has never been more important. Market forecasts, drivers, and trends are explored.
Kaspersky’s security operations center head explains his approach to burnout prevention in SOC teams.
The Dark Reading editorial team, along with contributing writers and editors, share their favorite stories and memories of co-founder and editor-in-chief Tim Wilson, an influential editor and well-respected thought leader in the cybersecurity industry.
Exploring ransomware and other data integrity risks from accelerated digital transformation in the wake of COVID-19.
RLBox can be used to protect web browsers and other software applications from vulnerabilities in subcomponents and libraries.
A January 2021 FBI document outlines what types of data and metadata can be lawfully obtained by the FBI from messaging apps. Rolling Stone broke the story and it’s been written about elsewhere.
I don’t see a lot of surprises in the document. Lots of apps leak all sorts of metadata: iMessage and WhatsApp seem to be the worst. Signal protects the most metadata. End-to-end encrypted message content can be available if the user uploads it to an unencrypted backup server.
EDITED TO ADD (12/13): Here’s a more legible copy of the text.
...
They are exploiting security bugs in four WordPress plugins and 15 Epsilon Framework themes
This week, read about Trend Micro’s predictions for security in the coming year. Also, learn about the Biden administration’s latest initiatives for curtailing attacks on the transport infrastructure.
We analyzed new samples of the Yanluowang ransomware. One interesting aspect of these samples is that the files are code-signed. They also terminate various processes which are related to database and backup management.
As the Zero Trust approach gains momentum, more organizations are looking to apply it to their security strategy. Learn how XDR and Zero Trust work together to enhance your security posture.
Volume of traffic associated with the malware is now back at 50% of the volume before law enforcement took the botnet operation down in January 2021, security vendor says.
Penetration audits can be dangerous for people of color. Here is how to keep Black and brown cybersecurity professionals safe during red team engagements.
Outlook features intended to improve collaboration and productivity may make social engineering attacks more effective, researchers find.
A significant percentage of the 2 million consumer and small-business routers produced by a Latvian firm are vulnerable and being used by attackers, a security firm says.
Security experts say the first hours in a phishing page's life are the most dangerous for users.
The latest integration furthers the company’s mission to provide an unmatched security model for businesses, without adding complexity for users.
Google took steps to shut down the Glupteba botnet, at least for now. (The botnet uses the bitcoin blockchain as a backup command-and-control mechanism, making it hard to get rid of it permanently.) So Google is also suing the botnet’s operators.
It’s an interesting strategy. Let’s see if it’s successful.
Investment aims to accelerate growth through continued product innovation and global expansion.
Enterprises will see improved access to data and more relevant insights that will enable them to further strengthen their cybersecurity postures.
Solution secures cloud-to-Internet, cloud-to-cloud, cloud-to-data center, and intra-cloud communications.
"Demonically" possessed devices print out antiwork propaganda, advice on how to secure your store, and is Twitter's new photo privacy policy practical?
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Dinah Davis.
Nations want to collaborate on the creation of next-gen tools that shape new global rules on data use
In our study, we relied on the tactics, techniques, and procedures of MITRE ATT&CK to define the malware capabilities and characteristics of IoT Linux malware. We describe our findings and how IoT malware has been evolving.
Trend Micro Research determined the top 10 Azure services with the highest configuration rates.
A 31-year-old Canadian man has been arrested and charged with fraud in connection with numerous ransomware attacks against businesses, government agencies and private citizens throughout Canada and the United States. Canadian authorities describe him as "the most prolific cybercriminal we've identified in Canada," but so far they've released few other details about the investigation or the defendant. Helpfully, an email address and nickname apparently connected to the accused offer some additional clues.
Cybercriminals are increasingly adopting "living-off-the-land’ techniques, leveraging commonly used tools to fly under the radar of conventional detection tools. But with AI, thousands of organizations have regained the upper hand.
Industrial control systems security firm reaches $635M in funding with this Series E round.
In this Expert Insight, Jack Naglieri, the founder and CEO of Panther Labs, talks about the many challenges of enterprise-scale threat detection and response. Jack provides some steps organizations can take to prepare themselves for the future.
The post How to Overcome Threat Detection and Response Challenges appeared first on The Security Ledger...
Read the whole entry... »
Related Stories* Spotting Hackers at the Pace of XDR – From Alerts to Incidents * Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security * Episode 230: Are Vaccine Passports Cyber Secure?
Once again video has leaked from inside the UK Government that has put it in hot water.
Supermarket chain Spar has had more than 300 of its convenience stores in the UK affected by a ransomware attack, which has forced some to close their doors or only accept cash payments.
Get the lowdown on virtual patching: a simplified, automated solution to shielding vulnerabilities from exploits.
Graham Cluley Security News is sponsored this week by the folks at Recorded Future. Thanks to the great team there for their support! Ransomware attacks dominate the cybersecurity news headlines, with businesses all over the world wondering if they will be the next victim. It’s a legitimate, and growing fear, as the attackers get more … Continue reading "Ransomware – how to stop it, and how to survive an attack. Free eBook by Recorded Future"
The officials targeted were either based in Uganda or worked on matters related to the country
Rarely do cybercriminal gangs that deploy ransomware gain the initial access to the target themselves. More commonly, that access is purchased from a cybercriminal broker who specializes in stealing remote access credentials -- such as usernames and passwords needed to remotely connect to the target's network. In this post we'll look at the clues left behind by "Babam," the handle chosen by a cybercriminal who has sold such access to ransomware groups on many occasions over the past few years.
The UK Government has been fined £500,000 after the addresses of over 1,000 New Years Honours recipients were mistakenly published online, potentially putting some of them at serious risk.
A former employee of Ubiquiti Networks has been arrested and charged in connection with a hack that stole gigabytes of data and attempted to extort US $2 million from the firm.
Read more in my article on the Hot for Security blog.
We looked into exploitation attempts we observed in the wild and the abuse of legitimate platforms Netlify and GitHub as repositories for malware.
This week, learn about how Squirrelwaffle utilized ProxyLogon and ProxyShell to hack email chains. Also, read on a recent data breach of the Los Angeles Planned Parenthood Network.
Finland’s National Cyber Security Centre has issued a warning about malicious SMS messages that have been spammed out to mobile users, directing iPhone owners to phishing sites and Android users to download malware.
Read more in my article on the Tripwire State of Security blog.
Graham Cluley Security News is sponsored this week by the folks at 1Password. Thanks to the great team there for their support! 1Password 8 for Windows is the most modern, productive, and secure version of 1Password yet, helping you manage, access, and protect your sensitive information more easily and securely than ever before. Modern Design … Continue reading "1Password 8 for Windows – improved productivity, and enhanced security & privacy"
In January 2021, technology vendor Ubiquiti Inc. [NYSE:UI] disclosed that a breach at a third party cloud provider had exposed customer account credentials. In March, a Ubiquiti employee warned that the company had drastically understated the scope of the incident, and that the third-party cloud provider claim was a fabrication. On Wednesday, a former Ubiquiti developer was arrested and charged with stealing data and trying to extort his employer while pretending to be a whistleblower.
Cryptocurrency traders suffer a hamster-related loss, beware of charity scammers this holiday season, and do you have the patience to sit through Peter Jackson's eight-hour Beatles documentary?
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.
Mackenzie Jackson, the Developer Advocate at GitGuardian joins Paul to discuss how “secrets sprawl” on sites like GitHub threatens software supply chains.
The post Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Episode 232: Log4j Won’t Go Away (And What To Do About It.) * Episode 227: What’s Fueling Cyber Attacks on Agriculture ? * Spotlight: Your IoT Risk Is Bigger Than You Think. (And What To Do About It.)
Unlike James Bond's Q, the spy agency cannot develop all the technologies it needs in-house
Welcome to your complete guide to AWS re:Invent 2021 Day 3, where you will find tips on how to get the most out of your conference experience both in Las Vegas and virtually.
Following our previous disclosure of compromised Docker hub accounts delivering cryptocurrency miners, we analyze these accounts and discover more malicious actions that you need to be aware of.
Merging the security function into DevOps won't happen overnight, but it's a vital step and the barriers aren't as high as sometimes believed
The ICO has issued a provisional notice to the company to stop further processing of the personal data of people in the UK
Hear leading analyst firm ESG and Chase Renes, system administrator at Vision Bank, discuss the operational, business, and financial value of Trend Micro’s industry-leading XDR solution.
Misconfigurations pose the biggest threat to cloud security. We compiled the top 10 AWS services with the highest misconfiguration rates.
Cloud misconfigurations can become opportunities for cyberattacks or lead to data breaches. Organizations must mitigate them before incurring significant and costly consequences.
The Prime Minister of Australia has said his government will introduce legislation which will compel social media companies to "unmask anonymous online trolls," and allow victims to launch defamation proceedings.
Read more in my article on the Hot for Security blog.
Welcome to your complete guide to AWS re:Invent 2021, where you will find tips on how to get the most out of your conference experience both in Las Vegas and virtually.
Trend Micro, alongside Amazon Web Services, provides the latest in cloud-native deployment options. We have simplified network security, protecting customers across Virtual Private Clouds (VPCs) without needing agents to be installed on instances.
We have been tracking a campaign involving the SpyAgent malware that abuses well-known remote access tools (RATs) for some time now. While previous versions of the malware have been covered by other researchers, our blog entry focuses on the malicious actor’s latest attacks.
Police in Tarragona, Spain, have arrested a man and a woman after they allegedly infected computers at high-street stores with malware with the intention of mining cryptocurrency on them.
Read more in my article on the Hot for Security blog.
Imagine being able to disconnect or redirect Internet traffic destined for some of the world's largest companies -- just by spoofing an email. This is the nature of a threat vector recently removed by a Fortune 500 firm that operates one of the world's largest Internet backbones.
As we creep toward a post-pandemic world, organizations need to plan accordingly. Explore Trend Micro’s latest cyber risk research to enable your business to maximize its growth and potential.
Graham Cluley Security News is sponsored this week by the folks at 1Password. Thanks to the great team there for their support! 1Password 8 for Windows has been reimagined with productivity improvements, enhanced security and privacy features, and a new, modern design. 1Password 8 helps you manage, access, and protect your sensitive information more easily … Continue reading "Try out 1Password 8 for Windows, where security meets productivity"
Security researchers are warning biomanufacturing facilities around the world that they are being targeted by a sophisticated new strain of malware, known as Tardigrade.
Read more in my article on the Tripwire State of Security blog.
Heating systems are left vulnerable to attack in the high courts, cybercrime unicorns have become a reality (but what are they?), over 15 Terabytes of NFTs are made available for anyone to download ... and Carole reveals her Pick of the Year.
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mikko Hyppönen.
The United Kingdom government has introduced new legislation designed to improve the security of "smart" internet-connected devices used in people's homes.
Read more in my article on the Hot for Security blog.
Microsoft has described the flaw as having a high impact on data integrity, confidentiality and availability
Hackers will attempt to target online shoppers on Black Friday and Cyber Monday, it warns
The attacker used a compromised password to access the company's provisioning system for Managed WordPress
Web-hosting firm and domain registrar GoDaddy has revealed that it has suffered cyber attack which saw a hacker gain access to details of over one million customers.
Read more in my article on the Hot for Security blog.
Explore this comprehensive guide to application security, which provides an overview of the importance of embedding runtime application security controls in the application build workflow to protect cloud-native web applications and APIs.
We observed BazarLoader adding two new arrival mechanisms to their current roster of malware delivery techniques.
Explore Trend Micro’s latest research into Void Balaur, a prolific cybermercenary group, to learn how to defend against attacks launched by this growing group of threat actors.
The 26 United Nations Climate Change Conference pushes for countries of parties to adopt more widespread EV use in order to reduce the looming threats of climate change.
In August, KrebsOnSecurity warned that scammers were contacting people and asking them to unleash ransomware inside their employer's network, in exchange for a percentage of any ransom amount paid by the victim company. This week, authorities in Nigeria arrested a suspect in connection with the scheme -- a young man who said he was trying to save up money to help fund a new social network.
Meanwhile WhatsApp has published a new privacy policy for users in Ireland and across Europe
One of the more common ways cybercriminals cash out access to bank accounts involves draining the victim's funds via Zelle, a "peer-to-peer" (P2P) payment service used by many financial institutions that allows customers to quickly send cash to friends and family. Naturally, a great deal of phishing schemes that precede these bank account takeovers begin with a spoofed text message from the target's bank warning about a suspicious Zelle transfer. What follows is a deep dive into how this increasingly clever Zelle fraud scam typically works, and what victims can do about it.
To help you enhance your defense against ransomware, Trend Micro Research shares key insights on how ransomware as a service (RaaS) operators work.
This week, learn about how the QAKBOT Loader malware has evolved its techniques and strategies over time. Also, read about the most recent initiative by the legislation to further cybersecurity protection.
Squirrelwaffle is known for using the tactic of sending malicious spam as replies to existing email chains. We look into how by investigating its exploit of Microsoft Exchange Server vulnerabilities, ProxyLogon and ProxyShell.
Over two years, Trend Micro Research scoured the underground forums for insight into the N-day exploit market. Discover their findings and how you can secure your organization against exploits.
Ransomware gangs have amassed big fortunes to compete with traditional buyers of zero-days, researchers find
This article will provide guidelines aimed at helping readers understand how to detect and prevent ransomware and limit its effect.
The CEO of a South Carolina technology firm has pleaded guilty to 20 counts of wire fraud in connection with an elaborate network of phony companies set up to obtain more than 735,000 Internet Protocol (IP) addresses from the nonprofit organization that leases the digital real estate to entities in North America.
Everything DevOps teams need to know about web application security risks and best practices.
In this blog entry, we will take a look at the ProxyShell vulnerabilities that were being exploited in these events, and dive deeper into the notable post-exploitation routines that were used in four separate incidents involving these web shell attacks.
The digital transformations that accompanied the pandemic are here to stay. To succeed in the post-pandemic era, organizations must come to a shared understanding about cybersecurity as a critical element of business risk.
A total of 13 suspects believed to be members of two prolific cybercrime rings were arrested as a global coalition across five continents involving law enforcement and private partners, including Trend Micro, sought to crack down on big ransomware operators.
We looked at how some malicious groups disable features in Alibaba Cloud ECS instances for illicit mining of Monero.
QAKBOT operators resumed email spam operations towards the end of September after an almost three-month hiatus. QAKBOT detection has become a precursor to many critical and widespread ransomware attacks. Our report shares some insight into the new techniques and tools this threat is using.
This week, learn about the prolific cybermercenaries, Void Balaur, and their recent attacks. Also, read on the 80-country agreement to mobilize safeguards against cyberattacks.
We can see signs of increased activity in areas of business that use 5G around the world. 5G technology will usher in new personal services through smartphones, and it will also play a large part in industry.
In this episode of the podcast (#230) Siddarth Adukia, a regional Director at NCC Group, joins host Paul Roberts to talk about the (cyber) risks and (public health) rewards of vaccine passport systems: how they work, how they can be compromised and what to do about it.
The post Episode 230: Are Vaccine Passports Cyber Secure? appeared first on ...
Read the whole entry... »
Click the icon below to listen. Related Stories* Spotlight: COVID Broke Security. Can We Fix It In 2022? * Spotlight: Operationalizing MDR with Pondurance CISO Dustin Hutchison * Spotlight: Your IoT Risk Is Bigger Than You Think. (And What To Do About It.)
Using a new batch of campaign samples, we take a look at its more recent cybercrime contributions and compare them with its previous deployments to demonstrate the group’s use of upgraded tools and payloads.
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November.
One of the most prolific cybermercenaries is Void Balaur, a Russian-speaking threat actor group that has launched attacks against different sectors and industries all over the world.
We talk with Casey Ellis, founder and CTO of BugCrowd about how the market for software bugs has changed since the first bug bounty programs emerged nearly 20 years ago, and what’s hot in bug hunting in 2021.
The post Episode 229: BugCrowd’s Casey Ellis On What’s Hot In Bug Hunting appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Spotlight: When Ransomware Comes Calling * Episode 232: Log4j Won’t Go Away (And What To Do About It.) * Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion
In this Spotlight edition of the podcast, we’re joined by Curtis Simpson, the Chief Information Security Officer at Armis. Curtis and I discuss the growing cyber risks posed by Internet of Things devices within enterprise networks. IoT and OT (operation technology) deployments are growing and pose challenges to organizations that are still...
Read the whole entry... »
Click the icon below to listen. Related Stories* Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion * Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security * Episode 230: Are Vaccine Passports Cyber Secure?
Brian Trzupek of DigiCert joins Paul to talk about the findings of a recent State of PKI Automation survey and the challenges of managing fast-growing population of tens of thousands of PKI certificates.
The post Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Episode 216: Signed, Sealed and Delivered: The Future of Supply Chain Security * Spotlight: COVID Broke Security. Can We Fix It In 2022? * Episode 229: BugCrowd’s Casey Ellis On What’s Hot In Bug Hunting
Eric Goldstein, Executive Assistant Director for Cybersecurity for the Cybersecurity and Infrastructure Security Agency (CISA), says the agency is all about helping companies and local government to keep hackers at bay. But are organizations ready to ask for help?
The post Episode 228: CISA’s Eric Goldstein on being Everyone’s Friend in Cyber...
Read the whole entry... »
Click the icon below to listen. Related Stories* Episode 229: BugCrowd’s Casey Ellis On What’s Hot In Bug Hunting * Episode 227: What’s Fueling Cyber Attacks on Agriculture ? * Spotlight: Operationalizing MDR with Pondurance CISO Dustin Hutchison
Contacless Mastercard and Maestro PINs can be bypasses due to a new vulnerability discovered by Swiss College of Engineering in Zurich, according to Cybersecurity News.
The key aspect of the flaw is that it allows thieves to use a hacked Mastercard or Maestro card to make contactless payments without having to input the PIN to complete the transaction, if properly exploited.
Properly in this case entails first installing dedicated software on two Android smartphones. One device is used to simulate a point of sale terminal being installed, while the other acts as a card emulator that allows the modified transaction information to be transmitted to a real point-of-sale device. Once the card initiates a transaction, it reveals all related information.
To avert further attacks, security experts will not reveal the app in question
Experts from ETH Zu...
Following sophisticated cyberattacks that targeted critical infrastructure, organizations and governments around the world, Microsoft, Amazon, Apple, IBM and Google pledged to invest a total of $30 billion in cybersecurity advances over the next 5 years, according to The Hacker News.
US plans to develop a framework to improve the supply chain technologies and broaden CISA's role in safeguarding natural gas pipelines. A meeting was held in this sense at the While House that included top representatives from various US companies who agreed to help improve cybersecurity.
The pledges come following repeated high-profile cyberattacks on SolarWinds, Microsoft, Colonial Pipeline,
Microsoft issued a warning about a huge phishing campaign that uses open email links to steal credentials, according to The Hacker News.
An old idiom advises us to work smart, not hard and nobody applies it better than modern hackers. Using something as common as URLs, threat actors manage to trick numerous users into introducing sensitive information that could grant access to an organization's network, steal credit card information or personal data that can be used for blackmailing. Nowadays, some manage to perfect their campaigns to the point where they are not even detected by advanced and up-to-date anti-malware solutions.
Microsoft 365 Defender Threat Intelligence Team explained in a report "Attackers co...
With an average cost of a data breach reaching an all-time high of $4.24 million, still some companies fail to see the full picture and don't meet modern cybersecurity standards, according to Tripwire.
Despite the fact that online threats are increasing on a daily basis, numerous firms fail to recognize the importance of proper cybersecurity. Interestingly enough, many companies are not aware that they are bound by state, industry, and international laws. Although there is no uniform national or global cybersecurity law in place, companies that fail to meet certain legislation can face legal consequences.
As cybersecurity becomes more of a serious concern, the need for online defense is starting to worry more governments around the world. Aside from the potential data loss, companies that...
Microsoft sent out a warning to thousands of cloud computing customers regarding threat actors that can view, modify, or even delete master databases if they gain access to their systems, according to Reuters.
Wiz announced that Microsoft Azure's flagship Cosmos database contain a vulnerability that allows access to keys that control access to the databases of hundreds of companies. Unable to update those keys itself, Microsoft sent an email to its customers Thursday asking them to create new keys. The software giant compensated Wiz with $40,000 in cash for discovering and reporting the security flaw.
Microsoft said, "Microsoft recently became aware of a vulnerability in Azure Cosmos DB that could potentially allow a user to gain access to another customer's resources by using the account's primary read-w...
A vpnMentor investigation found that a 134 GB server owned by EskyFun is exposed and user data was leaked for game titles such as Metamorph M, The Three Kingdoms Legend, Adventure Story, Rainbow Story, and Fantasy MMORPG.
The aforementioned games were downloaded 1.6 million times, whereas the leaked information had more than 365 million records. An intriguing aspect is that developers increased the amount of analytics, monitoring and authorization options available for the games, some needing more permissions even before they were installed.
Data disclosed includes IP and IMEI numbers, mobile device event logs, device information, phone numbers, EskyFun network passwords, current operating system, rooted or otherwise rooted phones, player acquisition and transaction reports, mailing, and support requests. Various data points were also used to identify profile individuals as well as tw...
Cybercriminals are launching a new scam to take advantage of the release of Kanye West's Donda album by distributing malicious fake downloads on the Internet, according to Tech Republic.
Cybersecurity firm Kaspersky proactively studied the event to see if threat actors were spreading any malware across the Internet. They emphasized that one of the scams is to target the release of highly anticipated media (movies, music), as they can place the malicious code in fake files that can be easily downloaded.
This particular scam attempt involves the uploading of fake malicious files to the Internet that are similar to those that were identified prior to the introduction of Black Widow. Kanye's fans are given a link to download the album and then asked to participate in a survey to confirm they are not robots. Afterwards, customers are redirected to a...
Over the course of September 2019 to April 2021, Palo Alto Network's Unit 42 monitored firewall traffic and phishing sites detected by URL filters. The number of new phishing pages per week increased significantly when individuals began working from home.
Threat actors improved and intensified their phishing attacks by exploiting remote work environments where employees were not protected by corporate firewalls. Cybersecurity experts noticed a sudden and significant drop in traffic between March and April 2020, when COVID began spreading across the United States, forcing companies to switch to remote work.
Education and high-tech industries saw significant declines in traffic during this period, with the latter having the steepest drop: education (a 46% drop), most likely due to school closures, and high-tech (a 35% drop), probably because more employees starting working from home...
Two zero-day vulnerabilities affecting Unitrends backup and continuity service have been patches by Kaseya recently, according to The Hacker News.
Dutch Institute for Vulnerability Disclosure (DIVD) informed that the provider of IT infrastructure management solutions has solved server software bugs 10.5.5-2 reported on August 12. Both vulnerabilities are part of a trio of flaws discovered and reported on July 3, 2021. The issues encompass both an authenticated vulnerability to remote code execution and a privilege escalation fault on Unitrends servers from the read-only user to the administrator.
Users of unpatched software should avoid connecting the affected servers to the Internet
A previously unknown client vulnerability in Kaseya Unitrends has not yet been patched. Then again, the company issues some firewall rules recommendations to...
A new report titled SANS 2021 OT/ICS Cybersecurity Report contains alarming information gathered from 480 individuals in various industries. Organizations that use operational technology (OT) and industrial control systems (ICS) are very concerned about cyber attacks.
The findings highlight the need for businesses to improve the ability to anticipate and respond to emerging threats and opportunities. While many are taking precautions to reduce risks, they are unaware if the breaches already occurred within their organization. To summarize the findings: Approximately 70% of respondents indicated that the risk to their operational technology environment was high or severe. With many companies concerned about cyber risk in their operating environment, 48% of respondents did not know whether they had encountered a breach of o...
Linux-based machines that are directly connected to the Internet can be targets for attackers who can quickly push potentially dangerous web-based shells, ransomware, Trojans, and other malicious software, according to The Hacker News.
Trend Micro produced a comprehensive analysis of the Linux threat landscape, highlighting the barriers and vulnerabilities that have plagued the operating system in the first half of the year. The information was gathered using honeypots, sensors and anonymous telemetry.
According to the company, which has detected about 15 million malware attacks targeting Linux-based cloud environments, ransomware and coin miners account for 54% of all malware, while web shells represent 29% of all recorded events.
Researchers evaluated over 50 million events from 100,000 unique Linux servers and identified 15 separate vulnerabilities used in th...
Following reports of personal data leaked online from the entire population, a small Swiss town revealed that it had misjudged the seriousness of the cyber attack late in the day before, according to Security Week.
Rolle, a small, lovely town on the beaches of Lake Geneva, acknowledged that it had been targeted by a ransomware attack and that sensitive information on some administrative systems had been compromised. The attack took place on May 30 and the city government said that only modest amounts of data were compromised at the time. Moreover, all information was restored from backup copies of the original files. However, according to an investigation published Wednesday by the French daily Le Temps, the attack was considerably larger.
Cybercriminals stole names, residences, and social security numbers
Le Temps cites an unidentified ...
On Wednesday, President Joe Biden will meet with top executives from some of the country's largest technology and financial companies, as the White House seeks private sector backing for a unified cyber defense against emerging threats, according to MCU Times.
The gathering comes amid an increase in ransomware attacks on critical infrastructure, extorting multi-million dollar payments from large corporations, and other illicit cyber operations linked to foreign hackers by US authorities. According to a senior government official, the purpose of the conversation is to identify the root causes of hostile cyber activity as well as ways in which the private sector may contribute to enhancing cybersecurity.
The President Biden proposed an infrastructure bill would provide about $1 trillion in cybersecurity subsidies to state, local and tribal governmen...
Chinese advanced persistent threat (APT) gangs have resumed their hacking activities, with one of the attacks targeting an American computer retailer using an unknown backdoor referred to as Sidewalk, according to The Hacker News.
In a report, ESET Cybersecurity Researchers Mathieu Tartare and Thibaut Passilly describe the fresh backdoor as modular, allowing the dynamic loading of additional modules from specific control and command servers. The malware is also designed to target Cloudflare workers as C&C servers and Google Docs as dead drop resolvers.
Security researchers describe SideWalk as "responsible for reading the encrypted shellcode from disk, decrypting it and injecting it into a legitimate process using the process hollowing techniqu...
FluBot Android malware is back and already launched several attacks outside the regular geographical region of impact, according to Cyware.
Recently conducted research into the FluBot banking malware has revealed an upsurge in the number of dangerous distribution pages in a variety of Australian, Polish, and German financial institutions.
Numerous intriguing elements were incorporated by the threat actors in the new operations that now collected user credentials by overlaying several popular banking applications. The design of the malicious web pages is devised to disseminate text messages that appear to be voicemail notifications or shipment tracking information, but are actually scams.
It is worth noting that the cybercriminals were able to accomplish all of this while remaining undetected during the infection process thanks to a Domain Generation Algorithm (D...
A mistake by a health care worker resulted in the leaking of medical information of about 12,000 patients. The phishing attack took place on June 21 and lasted only 45 minutes, according to The Spectrum.
While he breach exposed medical record numbers, birth dates, procedures, and insurance provider names, provider names, the two-month investigation determined that the breach posed a negligible risk to the patients affected. Moreover, Revere Health believes that the hacker is not attempting to publish the patient medical information, but rather is using the incident as a platform to conduct more sophisticated phishing email attacks against other employees.
Bob Freeze, the director of marketing and communications, stated that the stolen data affected patients of the Heart of Dixie Cardiology Department in St. Georg...
In an unexpected data leak, more than 38 million records from 47 organizations using Microsoft's gateway platform Power Apps were accidentally published online, according to The Hacker News.
The unfortunate incident resulted in the leakage of sensitive information on servers of corporations such as Microsoft, J.B. Hunt, and American Airlines along with government agencies from Indiana, Maryland, and New York City.
Power Apps are mostly used for developing custom low-code applications for mobile devices as well as websites. The programs created by Microoft have a number of advantages, such as APIs that allow other applications to access data, templates as well as managing and collecting information and storage.
Key information that went missing:
The misconfiguration of a port could lead to making the stored data public and this is what happened h...
The hacker known as Mr. White found a way to resolve one of the biggest cryptocurrency thefts of all time, according to CNBC.
Earlier this week, Poly Network, a decentralized financial network, announced that about $600 million in bitcoin had been stolen from its vaults due to a coding error. The sum was changed immediately to other cryptocurrencies, namely a total of $273 million in Ethereum tokens, $253 million in Binance Smart Chain tokens, and $85 million in USDC.
Surprisingly, the thief known as Mr. White Hat, began recovering assets almost shortly after the discovery and distributed t...
A customized version of the WhatsApp Messaging App for Android has been found to display full-screen advertising, register device users for unwanted premium subscriptions without their agreement and deliver dangerous payloads, says The Hacker News.
Generally speaking, modifications of legitimate Android apps are launched to perform functions that were not originally intended. For instance, you can customize icons, disable video calls, add themes or hide features like Recently Seen with FMWhatsApp. Then again, not all mods are launched with good intentions and this is another case of why you should be wary of too-good-to-be-true free services.
The FMWhatsApp version discovered by
Researchers identified 4 new ransomware gangs that are targeting businesses and key infrastructure, according to The Hacker News.
Ransomware attacks nowadays did not only increase in frequency and intensity, but went beyond financial gain, posing a threat to the national security of firms, hospitals, schools, and governments worldwide. Palo Alto Networks' Unit 42 threat intelligence team notes "While the ransomware crisis appears poised to get worse before it gets better, the cast of cybercrime groups that cause the most damage is constantly changing".
While we did not hear too much of them lately compared to previous years, Unit 42 says this is just the calm before the storm. Let's explore the latest ransomware kits on the market and the groups behind them.
AvosLocker
AvosLocker is a late-June ransomware company that exploits press announce...
Singapore and the U.S. signed several Memorandums of Understanding (MOUs) to expand their cybersecurity cooperation in areas such as defense, banking, and research and development, according to ZDNet. These activities include increased information sharing, team building, training and skills development.
Three MOUs were signed on Monday during the US' three-day visit to Asia Vice President Kamala Harris. One was an agreement between Singapore and the U.S. Cyber Security and Infrastructure Security Agency (CISA) aimed at expanding the cybersecurity partnership beyond data sharing and exchange. Both government agencies will explore new areas of cooperation, such as important technological research and development. The first MOU will allow both partners to strengthen existing partnerships between the countries so that they are able to work clo...
The Department of Defense's Cyber Command issued warnings about a possibly significant cyberattack against the United States Department of State that may have occurred in recent weeks.
According to yesterday's report from Fox News, it is still unclear how much damage has been done following the security incident, who the perpetrator was and whether the operations of the institutions have been affected. Given the nature of the Department, the information cannot be divulged, making things more complicated.
A department spokesperson told Fox News, "The Department takes seriously its responsibility to safeguard its information and continuously takes steps to ensure information is protected" [...] "For security reasons, we are not in a position to discuss the nature or scope of any alleged cybersecurity incidents at this time".
T...
With each passing day, the fallout from T-Mobile's recent data breach grows more serious. An update released Friday suggests hacking firms unlawfully obtained the personal information of another 5.3 million postpaid customers, including names, addresses, birthdates, IMSIs, IMEIs, and phone numbers, according to Fox Business.
The firm recently declared it discovered an additional 667,000 accessible user accounts that included addresses, phone numbers, customer names, and dates of birth. The latest figures put the total number of people affected by the security breach at more than 50 million, an increase from...
Cybersecurity firm Check Point discovered disturbing statistics concerning the significant growth in the weekly number of cyber attacks directed against firms and organizations in the world of education, according to Times of Israel.
Schools, colleges, and research institutions are among the organizations that have been targeted. In July 2021, there was an average of 1,739 attacks per organization per week, a 29% increase from the same month last year. The top 3 countries affected by the issue include: India - average of 5,196 assaults and 29% increase from 2020 Italy - average of 5,016 assaults and 70% increase from 2020 Israel - average o...
The cyberattack that crippled Iranian trains last month was recently attributed to the cybercriminal group Indra. The group is known for a series of attacks on several Syrian organizations using a wiper on the hacked networks, according to Cyware.
As expected, Indra denies any involvement in the latest attack on Iran. Then again, a large body of evidence suggests that the attackers were aware and had prior knowledge of the targeted networks. The attackers have distributed three different versions of Comet, Stardust, and Meteor wipers across victims' social media networks in the past couple of years.
According to CheckPoint
IBM X-Force published the specifics of an early variant of an emerging ransomware strain dubbed Diavol, according to Security Intelligence.
Several months ago, Fortinet discovered an unsuccessful ransomware attempt employing the Diavol payload that was targeting a client of the firm. When the experts from the security business investigated the incident, they discovered a ransomware strain that was capable of launching successful attacks. However, IBM's security specialists disagree, stating that the malware is still in the early stages of development and that it was built solely for the purpose of research and development.
The Diavol ransomware sample uses RSA encryption, an algorithm that can prioritize the file types ...
In the first six months of this year, 600 vulnerabilities were discovered in ICS products (Industrial Control Systems), impacting 76 vendors. The number of vulnerabilities increased by 41% in the same period, according to Claroty's ICS Risk & Vulnerability Report: H1 2021.
As the need to connect devices to the internet increases, so does the risk of being attacked by cybercriminals. Companies need to drive their business and invest in Operational Technology (OT) devices, and threat actors are using this growth to their advantage, seeking to launch hacking campaigns by taking advantage of companies that have vulnerable IT systems.
Advantech (22), WAGO (23), Rockwell Automation (35), Schneider Electric (65) and Siemens (146 vulnerabilities) are the most affected manufacturers. An important aspect is that the list of affected manufacturers also includes 20 companies whose product...
In recent months, more crypto exchange platforms have been targeted by hackers. The most recent attack resulted in the theft of $97 million worth of digital assets from the Japanese cryptocurrency exchange Liquid, according to ZDNet.
Liquid did not provide an estimate of damages because it is subject to analyses of the Financial Services Agency from Japan. Nevertheless, the attack affected many users, as Liquid is among the top 20 crypto exchanges in the world in terms of daily trading volume, sums estimated at more than $133 million per day on CoinMarketCap.
On the other hand. blockchain analytics firm Elliptic, claimed hackers obtained more than $97 million in cryptoc...
Trend Micro spotted recent malicious activity conducted by cybercriminal group Confucius. The hackers launched a spear-phishing campaign using Pegasus lures to trick users into clicking on a malicious document that downloads a data theft code.
The attack begins with a clean email that contains a text copied from a legitimate Pakistani newspaper article.Two days later, the victim receives a new email with a warning from a Pakistani military official about the Pegasus spyware that includes a cutt.ly link to encrypted Word document and a decryption password.
Regardless of the action taken by the victim, clicking on either of the links leads to downloading the Word document. If the target makes the mistake of entering...
Following a series of disruptive and headline-grabbing ransomware attacks on corporations in the United States over the past several months, the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA) has released a list of suggestions to prevent and respond to these sorts of attacks.
The information sheet called Protecting Sensitive and Personal Information from Ransomware-Caused Data Breaches contains numerous recommendations. In addition, the paper advises companies not to pay a ransom if they are the target of a ransomware attack.
The fact sheet reads “Ransomware is a serious and increasing threat to all government and private sector organizations, including critical infrastructure organizations. In response, the U.S. government launched...