Cybersecurity News
Facebook Bans Spy-for-Hire Firms for Targeting 50K People
Meta, Facebook’s parent company, said that the seven banned actors run fake accounts on its platforms to deceive users and plant malware on targets’ phones.17 December 2021
Spider-Man Movie Release Frenzy Bites Fans with Credit-Card Harvesting
Attackers are using the excitement over the new Spider-Man movie to steal bank information and spread malware.17 December 2021
Malicious Joker App Scores Half-Million Downloads on Google Play
Joker malware was found lurking in the Color Message app, ready to fleece unsuspecting users with premium SMS charges.17 December 2021
Week in security with Tony Anscombe
Why the vulnerability in Log4j poses a grave threat – What businesses should know about Log4Shell – ESET wraps up a series of deep-dives into Latin American banking trojans
The post Week in security with Tony Anscombe appeared first on WeLiveSecurity
17 December 2021
Brand-New Log4Shell Attack Vector Threatens Local Hosts
The discovery, which affects services running as localhost that aren't exposed to any network or the internet, vastly widens the scope of attack possibilities.17 December 2021
Security firm Blumira discovers major new Log4j attack vector
A basic Javascript WebSocket connection can trigger a local Log4j remote code attack via a drive-by compromise. Wonderful. Truly wonderful.17 December 2021
Convergence Ahoy: Get Ready for Cloud-Based Ransomware
Oliver Tavakoli, CTO at Vectra AI, takes us inside the coming nexus of ransomware, supply-chain attacks and cloud deployments.17 December 2021
Conti Gang Suspected of Ransomware Attack on McMenamins
The incident occurred last weekend at the popular chain of restaurants, hotels and breweries, which is still facing disruptions.17 December 2021
‘Tropic Trooper’ Reemerges to Target Transportation Outfits
Analysts warn that the attack group, now known as 'Earth Centaur,' is honing its attacks to go after transportation and government agencies.16 December 2021
‘PseudoManuscrypt’ Mass Spyware Campaign Targets 35K Systems
It’s similar to Lazarus’s Manuscrypt malware, but the new spyware is splattering itself onto government organizations and ICS in a non-Lazarus-like, untargeted wave of attacks.16 December 2021
NY Man Pleads Guilty in $20 Million SIM Swap Theft
A 24-year-old New York man who bragged about helping to steal more than $20 million worth of cryptocurrency from a technology executive has pleaded guilty to conspiracy to commit wire fraud. Nicholas Truglia was part of a group alleged to have stolen more than $100 million from cryptocurrency investors using fraudulent "SIM swaps," scams in which identity thieves hijack a target’s mobile phone number and use that to wrest control over the victim’s online identities.16 December 2021
‘DarkWatchman’ RAT Shows Evolution in Fileless Malware
The new tool manipulates Windows Registry in unique ways to evade security detections and is likely being used by ransomware groups for initial network access.16 December 2021
Suspected Iranian hackers target airline with new backdoor
The attack was performed by abusing the Slack workspace application.16 December 2021
Victims awarded $18 million in GirlsDoPorn online video case, boss on the run
The sex trafficking case impacts hundreds of victims, including young women seeking modeling work.16 December 2021
Relentless Log4j Attacks Include State Actors, Possible Worm
More than 1.8 million attacks, against half of all corporate networks, have already launched to exploit Log4Shell.15 December 2021
Malicious Exchange Server Module Hoovers Up Outlook Credentials
"Owowa" stealthily lurks on IIS servers, waiting to harvest successful logins when an Outlook Web Access (OWA) authentication request is made.15 December 2021
SAP Kicks Log4Shell Vulnerability Out of 20 Apps
SAP’s still feverishly working to patch another 12 apps vulnerable to the Log4Shell flaw, while its Patch Tuesday release includes 21 other fixes, some rated at 9.9 criticality.15 December 2021
What every business leader needs to know about Log4Shell
Hundreds of thousands of attempts to exploit the vulnerability are under way
The post What every business leader needs to know about Log4Shell appeared first on WeLiveSecurity
15 December 2021
Meta targets user information, database scraping in bug bounty expansion
Meta's Facebook came under fire for a scraping incident earlier this year.15 December 2021
Ransomware in 2022: We're all screwed
Security experts tell us what to expect in the cybercriminal landscape as we head into the new year. It's not good.15 December 2021