Cybersecurity News


The Best Ransomware Response, According to the Data 

The Best Ransomware Response, According to the Data  An analysis of ransomware attack negotiation-data offers best practices.
15 November 2021

High-Severity Intel Processor Bug Exposes Encryption Keys

High-Severity Intel Processor Bug Exposes Encryption Keys CVE-2021-0146, arising from a debugging functionality with excessive privileges, allows attackers to read encrypted files.
15 November 2021

Cybercriminals Target Alibaba Cloud for Cryptomining, Malware

Cybercriminals Target Alibaba Cloud for Cryptomining, Malware Cybercriminals are targeting Alibaba Elastic Computing Service (ECS) instances, disabling certain security features to further their cryptomining goals. Alibaba offers a few unique options that make it a highly attractive target for attackers, researchers noted. According to research from Trend Micro, the Chinese giant’s cloud (also known as Aliyun) has a preinstalled security agent. While […]
15 November 2021

FBI systems compromised to send out fake attack alerts

Hackers break into the Bureau’s email systems to send out at least 100,000 emails warning recipients of imminent cyberattacks

The post FBI systems compromised to send out fake attack alerts appeared first on WeLiveSecurity

15 November 2021

FBI Says Its System Was Exploited to Email Fake Cyberattack Alert

FBI Says Its System Was Exploited to Email Fake Cyberattack Alert The alert was mumbo jumbo, but it was indeed sent from the bureau's email system, from the agency’s own internet address.
15 November 2021

Hoax Email Blast Abused Poor Coding in FBI Website

The Federal Bureau of Investigation (FBI) confirmed today that its fbi.gov domain name and Internet address were used to blast out thousands of fake emails about a cybercrime investigation. According to an interview with the person who claimed responsibility for the hoax, the spam messages were sent by abusing insecure code in an FBI online portal designed to share information with state and local law enforcement authorities.
13 November 2021

Threat from Organized Cybercrime Syndicates Is Rising

Threat from Organized Cybercrime Syndicates Is Rising Europol reports that criminal groups are undermining the EU’s economy and its society, offering everything from murder-for-hire to kidnapping, torture and mutilation.
12 November 2021

Costco Confirms: A Data Skimmer’s Been Ripping Off Customers

Costco Confirms: A Data Skimmer’s Been Ripping Off Customers Big-box behemoth retailer Costco is offering victims 12 months of credit monitoring, a $1 million insurance reimbursement policy and ID theft recovery services.
12 November 2021

Top 10 Cybersecurity Best Practices to Combat Ransomware

Top 10 Cybersecurity Best Practices to Combat Ransomware Immutable storage and more: Sonya Duffin, data protection expert at Veritas Technologies, offers the Top 10 steps for building a multi-layer resilience profile.
12 November 2021

Windows 10 Privilege-Escalation Zero-Day Gets an Unofficial Fix

Windows 10 Privilege-Escalation Zero-Day Gets an Unofficial Fix Researchers warn that CVE-2021-34484 can be exploited with a patch bypass for a bug originally addressed in August by Microsoft.
12 November 2021

Mac Zero Day Targets Apple Devices in Hong Kong

Mac Zero Day Targets Apple Devices in Hong Kong Google researchers have detailed a widespread watering-hole attack that installed a backdoor on Apple devices that visited Hong Kong-based media and pro-democracy sites.
12 November 2021

Week in security with Tony Anscombe

Steps to take right after a data breach – What to consider before going passwordless – 7 million people hit by Robinhood data breach

The post Week in security with Tony Anscombe appeared first on WeLiveSecurity

12 November 2021

Millions of Routers, IoT Devices at Risk from New Open-Source Malware

Millions of Routers, IoT Devices at Risk from New Open-Source Malware BotenaGo, written in Google’s Golang programming language, can exploit more than 30 different vulnerabilities.
12 November 2021

Invest in These 3 Key Security Technologies to Fight Ransomware

Invest in These 3 Key Security Technologies to Fight Ransomware Ransomware volumes are up 1000%. Aamir Lakhani, cybersecurity researcher and practitioner at FortiGuard Labs , discusses secure email, network segmentation and sandboxing for defense.
11 November 2021

Back-to-Back PlayStation 5 Hacks Hit on the Same Day

Back-to-Back PlayStation 5 Hacks Hit on the Same Day Cyberattackers stole PS5 root keys and exploited the kernel, revealing rampant insecurity in gaming devices.
11 November 2021

Cyber-Mercenary Group Void Balaur Attacks High-Profile Targets for Cash

Cyber-Mercenary Group Void Balaur Attacks High-Profile Targets for Cash A Russian-language threat group is available for hire, to steal data on journalists, political leaders, activists and from organizations in every sector.
11 November 2021

No 10 accused of failing to act against states accused of NSO spyware abuses

No 10 accused of failing to act against states accused of NSO spyware abuses

Group of 10 MPs and peers say Boris Johnson’s government has prioritised trade over national security

Boris Johnson’s government has been accused by MPs of prioritising trade agreements over national security in its handling of surveillance abuses on British soil by governments using spyware made by the Israeli company NSO Group.

A letter to the British prime minister signed by 10 MPs and peers has called on the government to end its cybersecurity programmes with countries that are known to have used NSO spyware to target dissidents, journalists and lawyers, among others, and to impose sanctions on NSO, “if they are at all serious about our national security”.

Continue reading...
11 November 2021

Congress Mulls Ban on Big Ransom Payouts

Congress Mulls Ban on Big Ransom Payouts A bill introduced this week would regulate ransomware response by the country's critical financial sector.
11 November 2021

Google debuts ClusterFuzzLite security tool for CI, CD workflows

The fuzzing solution is set to bolster software supply chain security.
11 November 2021

Tiny Font Size Fools Email Filters in BEC Phishing

Tiny Font Size Fools Email Filters in BEC Phishing The One Font BEC campaign targets Microsoft 365 users and uses sophisticated obfuscation tactics to slip past security protections to harvest credentials.
11 November 2021