Cybersecurity News
Info of 27.7 million Texas drivers exposed in Vertafore data breach
Vertafore blames incident on human error after user data was stored on an unsecured external storage service. The files were accessed by an external party.13 November 2020
Australian government warns of possible ransomware attacks on health sector
The ACSC says it has seen an uptick in attacks targeting the health sector with SDBBot, a known precursor of the Clop ransomware.12 November 2020
Manufacturing Sees Rising Ransomware Threat
Crypto-ransomware groups are increasingly adopting malware and tools that can probe and attack operational technology, such as industrial control systems, according to an assessment of current threats.12 November 2020
'Pay2Key' Could Become Next Big Ransomware Threat
Researchers from Check Point say an Iranian-based threat actor has successfully attacked multiple Israeli companies could soon go global.12 November 2020
Cyberattackers Serve Up Custom Backdoor for Oracle Restaurant Software
The modular malware is highly sophisticated but may not be able to capture credit-card info.12 November 2020
Credential Stuffing Fills E-commerce Pipeline in 2020
There were 1.3 billion attacks in the third quarter alone, according to new analysis from Arkose Labs.12 November 2020
Animal Jam Hacked, 46M Records Roam the Dark Web
Animal Jam, just the latest in a string of attacks on gaming apps, has adopted a transparent communications strategy after stolen data turned up on a criminal forum.12 November 2020
BlackBerry discovers new hacker-for-hire mercenary group
CostaRicto is the fifth hacker-for-hire mercenary group discovered this year.12 November 2020
New 'CostaRicto' Hack-for-Hire Group Targets Global Businesses
The group of APT mercenaries uses bespoke malware and strong operation security to target a range of organizations, located primarily in Southeast Asia.12 November 2020
DARPA and Academia Jumpstart 5G IoT Security Efforts
With 5G IoT devices projected to hit 49 million units by 2023, researchers launch programs to keep IoT from becoming a blackhole of exfiltration.12 November 2020
Digging into the Dark Web: How Security Researchers Learn to Think Like the Bad Guys
Hacker forums are a rich source of threat intelligence.12 November 2020
Bugs in Critical Infrastructure Gear Allow Sophisticated Cyberattacks
Security problems in Schneider Electric programmable logic controllers allow compromise of the hardware, responsible for physical plant operations.12 November 2020
Google patches two new zero‑day flaws in Chrome
The last three weeks have seen a bumper crop of patches for zero-day bugs across software from Google, Apple and Microsoft
The post Google patches two new zero‑day flaws in Chrome appeared first on WeLiveSecurity
12 November 2020
5 Steps Every Company Should Take to Avoid Data Theft Risk
It's never been easier for employees to download company data and take it with them to their next gig.12 November 2020
2 More Google Chrome Zero-Days Under Active Exploitation
Browser users are once again being asked to patch severe vulnerabilities that can lead to remote code execution.12 November 2020
From Triton to Stuxnet: Preparing for OT Incident Response
Lesley Carhart, with Dragos, gives Threatpost a behind-the-scenes look at how industrial companies are faring during the COVID-19 pandemic - and how they can prepare for future threats.12 November 2020
Comodo open-sources its EDR solution
OpenEDR, announced in September, is available on GitHub starting this week.12 November 2020
Like the Energizer Bunny, Trickbot Goes On and On
Recent efforts to take down the virulent botnet have been largely -- but not entirely -- successful.12 November 2020
KuCoin CEO says 84% of stolen cryptocurrency has been recovered
Estimates suggest millions of dollars in cryptocurrency could still be outstanding.12 November 2020
New ModPipe malware targets hospitality, hotel point of sale systems
The backdoor has been created to target PoS devices actively used by thousands of hotels and restaurants.12 November 2020