Cybersecurity News
Researchers Foil Phishing Attempt on Netflix Customers
Hackers use two stolen domains to steal credentials from Netflix users and then send them to the real Netflix site.7.5M Banking Customers Affected in Dave Security Breach
The financial services app confirms user data was compromised in a data breach at its former third-party provider, WayDev.Autonomous IT: Less Reacting, More Securing
Keeping data secure requires a range of skills and perfect execution. AI makes that possible.FBI warns of disruptive DDoS amplification attacks
The Bureau expects cybercriminals to increasingly abuse new threat vectors for large-scale DDoS attacks
The post FBI warns of disruptive DDoS amplification attacks appeared first on WeLiveSecurity
As Businesses Move to the Cloud, Cybercriminals Follow Close Behind
In the wake of COVID-19, data theft is by far the top tactic, followed by cryptomining and ransomware.Kaspersky: North Korean hackers are behind the VHD ransomware
North Korean hackers return to actively deploying ransomware after the huge WannaCry debacle.Podcast: Security Lessons Learned In Times of Uncertainty

Researchers Warn of High-Severity Dell PowerEdge Server Flaw

New Linux malware uses Dogecoin API to find C&C server addresses
Security researchers discover Doki, a new backdoor malware strain targeting Docker instances.Business ID Theft Soars Amid COVID Closures
Identity thieves who specialize in running up unauthorized lines of credit in the names of small businesses are having a field day with all of the closures and economic uncertainty wrought by the COVID-19 pandemic, KrebsOnSecurity has learned. This story is about the victims of a particularly aggressive business ID theft ring that's spent years targeting small businesses across the country and is now pivoting toward using that access for pandemic assistance loans and unemployment benefits.ShinyHunters Offers Stolen Data on Dark Web
The threat actor offers more than 26 million records from a series of data breaches.Ratings for Open Source Projects Aim to Make Software More Secure
Two companies have teamed up to rate open source projects, but can adopting repository ratings help developers make better decisions regarding open source?Microsoft Revamps Windows Insider Preview Bug Bounty Program

Ransomware attack on Garmin thought to be the work of 'Evil Corp'

Russian cybercrime gang is believed to be responsible for taking Garmin services offline
A ransomware attack that took the GPS and smartwatch business Garmin entirely offline for more than three days is believed to have been carried out by a Russian cybercriminal gang which calls itself “Evil Corp”.
Garmin began to restore services to customers on Monday morning, after being held hostage for a reported ransom of $10m, although some services were still operating with limited functionality.
Ransomware is the most common form of criminal malware currently in use. Targets are commonly infected through malicious emails, which may trick them into downloading and running the software, or through exploiting vulnerabilities in other software such as Adobe Flash. When the ransomware program is activated, it encrypts the user’s hard drive with a single use encryption key, before flashing up a message asking for ransom, typically in the form of a payment in the cryptocurrency Bitcoin.
Related: Garmin down: how to still get your activities on to Strava
Continue reading...Attackers Exploiting High-Severity Network Security Flaw, Cisco Warns

CISA says 62,000 QNAP NAS devices have been infected with the QSnatch malware
QSnatch malware, first spotted in late 2019, has grown from 7,000 bots to more than 62,000, according to a join US CISA and UK NCSC security alert.Almost 4,000 databases now wiped in ‘Meow’ attacks
The attackers and their motivations remain unknown; however, the incidents yet again highlight the risks of careless data security
The post Almost 4,000 databases now wiped in ‘Meow’ attacks appeared first on WeLiveSecurity
Encryption Under ‘Full-Frontal Nuclear Assault’ By U.S. Bills
