Security professionals advise to never use ‘beef stew’ as a password. It just isn’t stroganoff. The post A recipe for failure: Predictably poor passwords appeared first on WeLiveSecurity
Threat actors are increasingly using advanced tactics to obfuscate and launder their illicit gains, a report by the US Government finds The post $5.2 billion worth of Bitcoin transactions possibly tied to ransomware appeared first on WeLiveSecurity
There are various ways a departing employee could put your organization at risk of a data breach. How do you offboard employees the right way and ensure your data remains safe? The post Employee offboarding: Why companies must close a crucial gap in their security strategy appeared first on WeLiveSecurity
If it looks like a duck, swims like a duck, and quacks like a duck, then it’s probably a duck. Now, how do you apply the duck test to defense against phishing? The post Don’t get phished! How to be the one that got away appeared first on WeLiveSecurity
The attack, which clocked in at 2.4 Tbps, targeted one of Azure customers based in Europe The post Microsoft thwarts record‑breaking DDoS attack appeared first on WeLiveSecurity
The victims lost an average of nine days to downtime and two-and-a-half months to investigations, an analysis of disclosed attacks shows The post Ransomware cost US companies almost $21 billion in downtime in 2020 appeared first on WeLiveSecurity
ESET researchers discover a malware family with tools that show signs they’re used in targeted attacks The post FontOnLake: Previously unknown malware family targeting Linux appeared first on WeLiveSecurity
Two-factor authentication is a simple way to greatly enhance the security of your account The post Google to turn on 2FA by default for 150 million users, 2 million YouTubers appeared first on WeLiveSecurity
Cryptocurrencies rise and fall, but one thing stays the same – cybercriminals attempt to cash in on the craze The post To the moon and hack: Fake SafeMoon app drops malware to spy on you appeared first on WeLiveSecurity
ESET research discovers a previously undocumented UEFI bootkit with roots going back all the way to at least 2012 The post UEFI threats moving to the ESP: Introducing ESPecter bootkit appeared first on WeLiveSecurity
Flaws in Apple Pay and Visa could allow criminals to make arbitrary contactless payments – no authentication needed, research finds The post Hackers could force locked iPhones to make contactless payments appeared first on WeLiveSecurity
A view of the T2 2021 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report T2 2021 appeared first on WeLiveSecurity
What your organization should consider when it comes to choosing a VPN solution and hardening it against attacks The post CISA and NSA release guidance for securing VPNs appeared first on WeLiveSecurity
The emergency release comes a mere three days after Google’s previous update that plugged another 19 security loopholes The post Google releases emergency fix to plug zero‑day hole in Chrome appeared first on WeLiveSecurity
While Apple did issue a patch for the vulnerability, it seems that the fix can be easily circumvented The post Bug in macOS Finder allows remote code execution appeared first on WeLiveSecurity
Yet another APT group that exploited the ProxyLogon vulnerability in March 2021 The post FamousSparrow: A suspicious hotel guest appeared first on WeLiveSecurity
Misconfigurations of cloud resources can lead to various security incidents and ultimately cost your organization dearly. Here’s what you can do to prevent cloud configuration conundrums. The post Plugging the holes: How to prevent corporate data leaks in the cloud appeared first on WeLiveSecurity
The group used phishing, BEC and other types of attacks to swindle victims out of millions The post European police dismantle cybercrime ring with ties to Italian Mafia appeared first on WeLiveSecurity
The most recent Patch Tuesday includes a fix for the previously disclosed and actively exploited remote code execution flaw in MSHTML. The post Microsoft Patch Tuesday fixes actively exploited zero‑day and 85 other flaws appeared first on WeLiveSecurity
The Facebook-owned messaging service plans to roll out the feature to both iOS and Android users in the coming weeks. The post WhatsApp announces end‑to‑end encrypted backups appeared first on WeLiveSecurity
Discover the best ways to mitigate your organization’s attack surface, in order to maximize cybersecurity. The post What is a cyberattack surface and how can you reduce it? appeared first on WeLiveSecurity
From cybercriminal evergreens like phishing to the verification badge scam we look at the most common tactics fraudsters use to trick their victims The post Beware of these 5 common scams you can encounter on Instagram appeared first on WeLiveSecurity
The university suffered a ransomware attack, however there is no evidence so far of data being accessed or stolen. The post Howard University suffers cyberattack, suspends online classes in aftermath appeared first on WeLiveSecurity
Following the incident the company has updated its website and privacy policy to clarify its legal obligations to its userbase The post ProtonMail forced to log user’s IP address after an order from Swiss authorities appeared first on WeLiveSecurity
ESET researchers have investigated a targeted mobile espionage campaign against the Kurdish ethnic group, and that has been active since at least March 2020. The post BladeHawk group: Android espionage against Kurdish ethnic group appeared first on WeLiveSecurity
Dubbed Safety Mode, the feature will temporarily block authors of offensive tweets from being able to contact or follow users. The post Twitter introduces new feature to automatically block abusive behavior appeared first on WeLiveSecurity
Vaccination passports may facilitate the return to normalcy, but there are also concerns about what kinds of personal data they collect and how well they protect it. Here’s what you should know. The post Vaccine passports: Is your personal data in safe hands? appeared first on WeLiveSecurity
ESET’s cybersecurity expert Marc-Étienne Léveillé analyses in-depth the Quebec’s vaccine proof apps VaxiCode and VaxiCode Verif. The post Flaw in the Quebec vaccine passport: analysis appeared first on WeLiveSecurity
The federal agency urges organizations to ditch the bad practice and instead use multi-factor authentication methods The post Don’t use single‑factor authentication, warns CISA appeared first on WeLiveSecurity
The man was after sexually explicit photos and videos that he would then share online or store in his own collection The post Man impersonates Apple support, steals 620,000 photos from iCloud accounts appeared first on WeLiveSecurity
The caches of data that were publicly accessible included names, email addresses and social security numbers The post Microsoft Power Apps misconfiguration exposes millions of records appeared first on WeLiveSecurity
Meet SparklingGoblin, a member of the Winnti family The post The SideWalk may be as dangerous as the CROSSWALK appeared first on WeLiveSecurity
Ransomware payments may have greater implications than you thought – and not just for the company that gave in to the attackers’ demands The post Are you, the customer, the one paying the ransomware demand? appeared first on WeLiveSecurity
Fraudsters impersonate vaccine manufacturers and authorities overseeing vaccine distribution efforts, INTERPOL warns The post Health authorities in 40 countries targeted by COVID‑19 vaccine scammers appeared first on WeLiveSecurity
The secret list was exposed online for three weeks, allowing anyone to access it without any kind of authentication The post Nearly 2 million records from terrorist watchlist exposed online appeared first on WeLiveSecurity
One man’s trash is another man’s treasure – here’s why you should think twice about what you toss in the recycling bin The post Dumpster diving is a filthy business appeared first on WeLiveSecurity
As employees split their time between office and off-site work, there’s a greater potential for company devices and data to fall into the wrong hands The post Examining threats to device security in the hybrid workplace appeared first on WeLiveSecurity
The last in our series on IIS threats introduces a malicious IIS extension used to manipulate page rankings for third-party websites The post IISerpent: Malware‑driven SEO fraud as a service appeared first on WeLiveSecurity
A new paper explains how ransomware has become one of the top cyberthreats of the day and how your organization can avoid becoming the next victim The post Ransomware runs rampant, so how can you combat this threat? appeared first on WeLiveSecurity
As fraud involving highly believable synthetic media soars, what can you do to avoid getting scammed? The post Deepfakes – the bot made me do it appeared first on WeLiveSecurity
How peering into the innards of a future satellite can make cybersecurity in space more palatable The post DEF CON 29: Satellite hacking 101 appeared first on WeLiveSecurity
The second in our series on IIS threats dissects a malicious IIS extension that employs nifty tricks in an attempt to secure long-term espionage on the compromised servers The post IISpy: A complex server‑side backdoor with anti‑forensic features appeared first on WeLiveSecurity
Drowning in spam? A study presented at Black Hat USA 2021 examines if sharing your personal information with major companies contributes to the deluge of nuisance emails, texts and phone calls. The post Is your personal information being abused? appeared first on WeLiveSecurity
How can companies and employees who start to adapt to hybrid working practices protect themselves against cloud security threats? The post Why cloud security is the key to unlocking value from hybrid working appeared first on WeLiveSecurity
How is Black Hat USA 2021 different from the past editions of the conference and what kinds of themes may steal the show this year? The post Black Hat 2021 – non‑virtual edition appeared first on WeLiveSecurity
A story of how easily hackers could hit a hole-in-one with the computer network of a premier golf club in the UK. The post On course for a good hacking appeared first on WeLiveSecurity
Now that organizations are set to evolve a hybrid blend of home and office-based work for most employees, it is more important then ever to address the risks that insider threat can – willingly or unwitingly – pose. The post Tackling the insider threat to the new hybrid workplace appeared first on WeLiveSecurity
There are 30 vulnerabilities listed in total; organizations would do well to patch their systems if they haven’t done so yet The post Leading cybersecurity agencies reveal list of most exploited vulnerabilities of the past 2 years appeared first on WeLiveSecurity
With vacations in full swing, cybercriminals will be looking to scam vacationers looking for that perfect accommodation. The post Booking your next holiday? Watch out for these Airbnb scams appeared first on WeLiveSecurity
Twitter’s transparency report revealed that users aren’t quick to adopt 2FA and once they do enable it, they choose the least secure option The post Most Twitter users haven’t enabled 2FA yet, report reveals appeared first on WeLiveSecurity
The vulnerability is under active exploitation by unknown attackers and affects a wide range of Apple’s products. The post Apple releases patch for zero‑day flaw in iOS, iPadOS and macOS appeared first on WeLiveSecurity
To mitigate the chances of their Wi-Fi home routers being compromised, users would do well to change the manufacturer’s default access credentials The post Popular Wi‑Fi routers still using default passwords making them susceptible to attacks appeared first on WeLiveSecurity
Cybercriminals may target the popular event with ransomware, phishing, or DDoS attacks in a bid to increase their notoriety or make money The post Cybercriminals may target 2020 Tokyo Olympics, FBI warns appeared first on WeLiveSecurity
On iOS we have seen link shortener services pushing spam calendar files to victims’ devices. The post Some URL shortener services distribute Android malware, including banking or SMS trojans appeared first on WeLiveSecurity
If you’ll be watching Sports Streaming events on your SmartTV, laptop, tablet or cell phone, learn the tips to keep you and your personal data safe. The post Sports events and online streaming: prepare your cybersecurity appeared first on WeLiveSecurity
The latest Patch Tuesday brings a new batch of security updates addressing a total of 117 vulnerabilities The post Microsoft Patch Tuesday fixes 13 critical flaws, including 4 under active attack appeared first on WeLiveSecurity
Lessons to learn from the Kaseya cyberincident to protect your business’ data when doing business with a MSP. The post Choosing your MSP: What the Kaseya incident tells us about third‑party cyber risk appeared first on WeLiveSecurity
How can organizations mitigate the risk of damaging cyberattacks while juggling the constantly changing mix of office and off-site workers? The post The hybrid workplace: What does it mean for cybersecurity? appeared first on WeLiveSecurity
The out-of-band update fixes a remote code execution flaw affecting the Windows Print Spooler service The post Microsoft issues patch to fix PrintNightmare zero‑day bug appeared first on WeLiveSecurity
Caught between a rock and a hard place, many ransomware victims cave in to extortion demands. Here’s what might change the calculus. The post Ransomware: To pay or not to pay? Legal or illegal? These are the questions … appeared first on WeLiveSecurity
ESET Research uncovers an active malicious campaign that uses new versions of old malware, Bandook, to spy on its victims The post Bandidos at large: A spying campaign in Latin America appeared first on WeLiveSecurity
As news breaks about the supply-chain ransomware attack against Kaseya’s IT management software, here’s what we know so far The post Kaseya supply‑chain attack: What we know so far appeared first on WeLiveSecurity
A global operation takes down the infrastructure of DoubleVPN and seizes data about its customers The post Global police shut down VPN service favored by cybercriminals appeared first on WeLiveSecurity
Information scraped from LinkedIn user profiles includes full names, gender, email addresses and phone numbers The post Data for 700 million LinkedIn users up for grabs on hacker forum appeared first on WeLiveSecurity
Are you on Facebook? So are scammers. Here are some of the most common con jobs on Facebook you should watch out for and how you can tell if you’re being scammed. The post Common Facebook scams and how to avoid them appeared first on WeLiveSecurity
What was it like to work for, and be friends with, the larger-than-life technology entrepreneur back when he helped shape the computer security industry? The post In Memoriam: John McAfee appeared first on WeLiveSecurity
Cyberattacks targeting the gaming industry skyrocket, with web attacks more than tripling year-on-year in 2020 The post Gaming industry under siege from cyberattacks during pandemic appeared first on WeLiveSecurity
The Brave Search engine takes on Google, promising to let users surf the web without leaving a trace The post Brave launches its own, privacy‑focused search engine appeared first on WeLiveSecurity
It can be difficult to tell a legitimate website apart from an unsafe one – follow these steps to identify and protect yourself from bad websites The post How to tell if a website is safe appeared first on WeLiveSecurity
What does the increasingly fuzzy line between traditional cybercrime and attacks attributed to state-backed groups mean for the future of the threat landscape? The post State‑sponsored or financially motivated: Is there any difference anymore? appeared first on WeLiveSecurity
Most medical and fitness apps in Google Play have tracking capabilities enabled and their data collection practices aren’t transparent The post Most health apps engage in unhealthy data‑harvesting habits appeared first on WeLiveSecurity
By failing to prepare you are preparing to fail – here’s what you can do today to minimize the impact of a potential ransomware attack in the future The post 5 essential things to do before ransomware strikes appeared first on WeLiveSecurity
OSINT can be used by anyone, both for good and bad ends – here’s how defenders can use it to keep ahead of attackers The post OSINT 101: What is open source intelligence and how is it used? appeared first on WeLiveSecurity
The fraudsters ran their campaigns from the cloud and used phishing and email forwarding rules to steal their targets’ financial information. The post Microsoft takes down large‑scale BEC operation appeared first on WeLiveSecurity
How do vishing scams work, how do they impact businesses and individuals, and how can you protect yourself, your family and your business? The post Vishing: What is it and how do I avoid getting scammed? appeared first on WeLiveSecurity
The latest Chrome update patches a bumper crop of security flaws across the browser’s desktop versions The post Google fixes actively exploited Chrome zero‑day appeared first on WeLiveSecurity
ESET researchers discover a new campaign that evolved from the Quarian backdoor The post BackdoorDiplomacy: Upgrading from Quarian to Turian appeared first on WeLiveSecurity
ESET researchers shed light on new campaigns from the quiet Gelsemium group The post Gelsemium: When threat actors go gardening appeared first on WeLiveSecurity
Law enforcement around the world used a messaging app called AN0M to monitor the communications of alleged criminals The post Hundreds of suspected criminals arrested after being tricked into using FBI‑run chat app appeared first on WeLiveSecurity
Hacking an orbiting satellite is not light years away – here’s how things can go wrong in outer space The post Hacking space: How to pwn a satellite appeared first on WeLiveSecurity
Websites using Fancy Product Designer are susceptible to remote code execution attacks even if the plugin is deactivated The post Zero‑day in popular WordPress plugin exploited to take over websites appeared first on WeLiveSecurity
A view of the T1 2021 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report T1 2021 appeared first on WeLiveSecurity
From knock-off designer products to too-good-to-be-true job offers, here are five common schemes fraudsters use to trick teenagers out of their money and sensitive data The post 5 common scams targeting teens – and how to stay safe appeared first on WeLiveSecurity
You may not be able to escape internet trolls, but you have a choice about how you will deal with them – here’s how you can handle trolls without losing your cool The post Don’t feed the trolls and other tips for avoiding online drama appeared first on WeLiveSecurity
Here’s how easily your phone number could be stolen, why a successful SIM swap scam is only the beginning of your problems, and how you can avoid becoming a victim of the attack The post I hacked my friend’s website after a SIM swap attack appeared first on WeLiveSecurity
Patches to remedy the vulnerabilities should be released over the coming weeks The post Bluetooth bugs could allow attackers to impersonate devices appeared first on WeLiveSecurity
You would do well to update to macOS Big Sur 11.4 post-haste The post Apple fixes macOS zero‑day bug that let malware take secret screenshots appeared first on WeLiveSecurity
Online dating scams often follow the same script – here’s what senior citizens should watch out for and how their younger relatives can help them avoid falling victim The post Rom‑con: How romance fraud targets older people and how to avoid it appeared first on WeLiveSecurity
An all-new privacy dashboard and better location, microphone and camera controls are all aimed at curbing apps’ data-slurping habits The post Android 12 will give you more control over how much data you share with apps appeared first on WeLiveSecurity
Con artists use social media to find and target victims for various nefarious ends, including to extort relatives of missing persons The post Scams target families of missing persons, FBI warns appeared first on WeLiveSecurity
The attack is a reminder of growing cyberthreats to critical infrastructure while also showing why providers of essential services are ripe targets for cybercriminals The post Colonial Pipeline attack: Hacking the physical world appeared first on WeLiveSecurity
Why FluBot is a major threat for Android users, how to avoid falling victim, and how to get rid of the malware if your device has already been compromised The post Take action now – FluBot malware may be on its way appeared first on WeLiveSecurity
ESET research reveals that common Android stalkerware apps are riddled with vulnerabilities that further jeopardize victims and expose the privacy and security of the snoopers themselves The post Android stalkerware threatens victims further and exposes snoopers themselves appeared first on WeLiveSecurity
The report provides unique insights into how the COVID-19 pandemic affected the data breach landscape The post Verizon’s 2021 DBIR: Phishing and ransomware threats looming ever larger appeared first on WeLiveSecurity
The operation was carried out against an organized group that used online trading platforms to swindle victims out of US$36 million The post European police bust major online investment fraud ring appeared first on WeLiveSecurity
Apple also claims to have foiled US$1.5 billion worth of potentially fraudulent transactions The post 1 million risky apps rejected or removed from Apple’s App Store in 2020 appeared first on WeLiveSecurity
We will explore two threats – Android stalkerware and XP exploits The post ESET Research goes to RSA Conference 2021 with two presentations appeared first on WeLiveSecurity
We will explore Android stalkerware, air-gapped networks and XP exploits The post ESET Research goes to RSA Conference 2021 with record number of presentations appeared first on WeLiveSecurity
Your account won’t be deleted, but here’s what you may want to be aware of if not even repeated reminders do the trick The post WhatsApp will limit features for users who don’t accept new data‑sharing rules appeared first on WeLiveSecurity
Millions of Brits could be at risk of cyberattacks due to poor default passwords and a lack of firmware updates The post Popular routers found vulnerable to hacker attacks appeared first on WeLiveSecurity
