Cybersecurity News
The Rise of One-Time Password Interception Bots
In February, KrebsOnSecurity wrote about a novel cybercrime service that helped attackers intercept the one-time passwords (OTPs) that many websites require as a second authentication factor in addition to passwords. That service quickly went offline, but new research reveals a number of competitors have since launched bot-based services that make it relatively easy for crooks to phish OTPs from targets.Akamai acquires cybersecurity firm Guardicore for $600 million
Guardicore's zero-trust solutions brought it to the attention of the CDN.Google launches new reward program for Tsunami Security Scanner
The program offers up to $3,133 in financial rewards.Telegram bots are trying to steal your one-time passwords
The tokens can be used to shred second-stage account verification.How to Prevent Account Takeovers in 2021

Gamers Beware: Malware Hunts Steam, Epic and EA Origin Accounts

SAS 2021: FinSpy Surveillance Kit Re-Emerges Stronger Than Ever

Apple Airtag Bug Enables ‘Good Samaritan’ Attack
The new $30 Airtag tracking device from Apple has a feature that allows anyone who finds one of these tiny location beacons to scan it with a mobile phone and discover its owner's phone number if the Airtag has been set to lost mode. But according to new research, this same feature can be abused to redirect the Good Samaritan to an iCloud phishing page -- or to any other malicious website.Paving the Way: Inspiring Women in Payments - A Podcast Featuring Agnes Ng
Sometimes, being a woman brings in a more human touch when navigating through challenging security issues. This sensitivity to customer concerns is exactly what has helped Agnes Ng achieve success as a female entrepreneur in the Singapore payment industry. In this edition of our podcast, Agnes explains that despite a lack of women taking technology courses as part of their education in Singapore, she believes that more doors will be opened to women in technology as part of the government’s initiative to stay ahead as a global city.
FinSpy surveillance malware is now spreading through UEFI bootkits
The spyware had previously been associated with malicious installers and MBR bootkits.Working Exploit Is Out for VMware vCenter CVE-2021-22005 Flaw

SolarWinds Attackers Hit Active Directory Servers with FoggyWeb Backdoor

Credential Spear-Phishing Uses Spoofed Zix Encrypted Email

Scalper bots are now targeting graphics card vendors
Concert tickets are no longer the most coveted items on a reseller's list.5 Steps to Securing Your Network Perimeter

Women, Minorities Are Hacked More Than Others

EU: Russia Behind ‘Ghostwriter’ Campaign Targeting Germany

Google releases emergency fix to plug zero‑day hole in Chrome
The emergency release comes a mere three days after Google’s previous update that plugged another 19 security loopholes
The post Google releases emergency fix to plug zero‑day hole in Chrome appeared first on WeLiveSecurity
3.8 Billion Users’ Combined Clubhouse, Facebook Data Up for Sale

Exchange/Outlook Autodiscover Bug Spills $100K+ Email Passwords
