Cybersecurity News
Rickroll Grad Prank Exposes Exterity IPTV Bug

Verizon’s Visible Wireless Carrier Confirms Credential-Stuffing Attack

Missouri Governor Vows to Prosecute St. Louis Post-Dispatch for Reporting Security Vulnerability
On Wednesday, the St. Louis Post-Dispatch ran a story about how its staff discovered and reported a security vulnerability in a Missouri state education website that exposed the Social Security numbers of 100,000 elementary and secondary teachers. In a press conference this morning, Missouri Gov. Mike Parson (R) said fixing the flaw could cost the state $50 million, and vowed his administration would seek to prosecute and investigate the "hackers" and anyone who aided the publication in its "attempt to embarrass the state and sell headlines for their news outlet."CryptoRom Scam Rakes in $1.4M by Exploiting Apple Enterprise Features

Podcast: 67% of Orgs Have Been Hit by Ransomware at Least Once

Employee offboarding: Why companies must close a crucial gap in their security strategy
There are various ways a departing employee could put your organization at risk of a data breach. How do you offboard employees the right way and ensure your data remains safe?
The post Employee offboarding: Why companies must close a crucial gap in their security strategy appeared first on WeLiveSecurity
FreakOut Botnet Turns DVRs Into Monero Cryptominers

Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers

Cybersecurity Month: Defense Against Phishing Attacks
As an Official Champion of National Cyber Security Awareness Month (NCSAM), the Council will be sharing educational resources on payment security best practices on the PCI Perspectives blog, and through our Twitter (@PCISSC) and LinkedIn pages. The Council will align these resources with the four weekly themes outlined by the National Cyber Security Alliance:
How Coinbase Phishers Steal One-Time Passwords
A recent phishing campaign targeting Coinbase users shows thieves are getting cleverer about phishing one-time passwords (OTPs) needed to complete the login process. It also shows that phishers are attempting to sign up for new Coinbase accounts by the millions as part of an effort to identify email addresses that are already associated with active accounts.Mandating a Zero-Trust Approach for Software Supply Chains

OpenSea ‘Free Gift’ NFTs Drain Cryptowallet Balances

International cryptocurrency scam ring targets European dating app users
You might lose your money as well as your heart.Apple: Forcing app sideloading would turn iPhones into virus-prone 'pocket PCs'
Apple says that sideloading would undermine the "privacy and security protections" of iPhones.30 Mins or Less: Rapid Attacks Extort Orgs Without Ransomware

Bugs allowing malicious NFT uploads uncovered in OpenSea marketplace
Malicious NFTs could have become an attack vector for hackers trying to steal digital wallet funds.Don’t get phished! How to be the one that got away
If it looks like a duck, swims like a duck, and quacks like a duck, then it's probably a duck. Now, how do you apply the duck test to defense against phishing?
The post Don’t get phished! How to be the one that got away appeared first on WeLiveSecurity
Microsoft Kills Bug Being Exploited in MysterySnail Espionage Campaign

Patch Tuesday, October 2021 Edition
Microsoft today issued updates to plug more than 70 security holes in its Windows operating systems and other software, including one vulnerability that is already being exploited in active attacks. This month's Patch Tuesday also includes security fixes for the newly released Windows 11 operating system.Windows Zero-Day Actively Exploited in Widespread Espionage Campaign
