Cybersecurity News
iPhones vulnerable to hacking tool for months, researchers say

Analysis: NSO Group’s Pegasus spyware could allegedly track locations and access passwords
For almost a year, spyware sold by Israel’s NSO Group was allegedly armed with a computer security super-weapon: a zero-footprint, zero-click, zero-day exploit that used a vulnerability in iMessage to seize control of an iPhone at the push of a button.
That means it would have left no visible trace of being placed on target’s phones, could be installed by simply sending a message that the victim didn’t even need to click on, and worked even on phones that were running the then-latest version of iOS, the operating system for iPhones.
Continue reading...Firefox to ship 'network partitioning' as a new anti-tracking defense
Firefox's "network partitioning" feature to ship in v85, scheduled for January 2021.Cloud is King: 9 Software Security Trends to Watch in 2021

Apple, Google, Microsoft, and Mozilla ban Kazakhstan's MitM HTTPS certificate
This marks the second time browsers makers had to intervene and block a certificate used by the Kazakhstan government to spy on its citizens.Microsoft Confirms Its Network Was Breached With Tainted SolarWinds Updates

FBI Warns of DoppelPaymer Attacks on Critical Infrastructure
The operators behind DoppelPaymer have begun calling victims to pressure them into paying ransom, officials say.Sunburst’s C2 Secrets Reveal Second-Stage SolarWinds Victims

VMware Flaw a Vector in SolarWinds Breach?
U.S. government cybersecurity agencies warned this week that the attackers behind the widespread hacking spree stemming from the compromise at network software firm SolarWinds used weaknesses in other, non-SolarWinds products to attack high-value targets. According to sources, among those was a flaw in software virtualization platform VMware, which the U.S. National Security Agency (NSA) warned on Dec. 7 was being used by Russian hackers to impersonate authorized users on victim networks.FBI & Interpol disrupt Joker's Stash, the internet's largest carding marketplace
Four threat intel firms, Digital Shadows, Intel 471, Gemini Advisory, and Kela, said the disruption was temporary.Week in security with Tony Anscombe
Supply‑chain attack against a certification authority in Southeast Asia. Holiday online… Safely! Scammers targeting PayPal users. Week in security with Tony Anscombe
The post Week in security with Tony Anscombe appeared first on WeLiveSecurity
Microsoft Caught Up in SolarWinds Spy Effort, Joining Federal Agencies

Cyberpunk 2077 Headaches Grow: New Spyware Found in Fake Android Download

Insider Threats: What Are They, Really?

5 Key Takeaways from the SolarWinds Breach

2021 Cybersecurity Predictions: The Intergalactic Battle Begins
There's much in store for the future of cybersecurity, and the most interesting things aren't happening on Earth.NSA warns of federated login abuse for local-to-cloud attacks
The US National Security Agency describes two techniques abused in recent attacks for escalating attacks from local networks to cloud infrastructure.Microsoft says it identified 40+ victims of the SolarWinds hack
Microsoft says 80% of the victims it identified were located in the United States.Microsoft was also breached in recent SolarWinds supply chain hack, report
Report claims that after hackers breached Microsoft, they used Microsoft's own products to attack other companies.Malicious Browser Extensions for Social Media Infect Millions of Systems
At least 28 third-party add-ons for top social media sites, including Facebook and Vimeo, redirect users to phishing sites and steal data.How to Increase Your Security Posture with Fewer Resources
