Menu

Category Archives: Security Advisory

Auto Added by WPeMatico

A recipe for failure: Predictably poor passwords

Security professionals advise to never use ‘beef stew’ as a password. It just isn’t stroganoff. The post A recipe for failure: Predictably poor passwords appeared first on WeLiveSecurity

$5.2 billion worth of Bitcoin transactions possibly tied to ransomware

Threat actors are increasingly using advanced tactics to obfuscate and launder their illicit gains, a report by the US Government finds The post $5.2 billion worth of Bitcoin transactions possibly tied to ransomware appeared first on WeLiveSecurity

Employee offboarding: Why companies must close a crucial gap in their security strategy

There are various ways a departing employee could put your organization at risk of a data breach. How do you offboard employees the right way and ensure your data remains safe? The post Employee offboarding: Why companies must close a crucial gap in their security strategy appeared first on WeLiveSecurity

Don’t get phished! How to be the one that got away

If it looks like a duck, swims like a duck, and quacks like a duck, then it’s probably a duck. Now, how do you apply the duck test to defense against phishing? The post Don’t get phished! How to be the one that got away appeared first on WeLiveSecurity

Microsoft thwarts record‑breaking DDoS attack

The attack, which clocked in at 2.4 Tbps, targeted one of Azure customers based in Europe The post Microsoft thwarts record‑breaking DDoS attack appeared first on WeLiveSecurity

Ransomware cost US companies almost $21 billion in downtime in 2020

The victims lost an average of nine days to downtime and two-and-a-half months to investigations, an analysis of disclosed attacks shows The post Ransomware cost US companies almost $21 billion in downtime in 2020 appeared first on WeLiveSecurity

FontOnLake: Previously unknown malware family targeting Linux

ESET researchers discover a malware family with tools that show signs they’re used in targeted attacks The post FontOnLake: Previously unknown malware family targeting Linux appeared first on WeLiveSecurity

Google to turn on 2FA by default for 150 million users, 2 million YouTubers

Two-factor authentication is a simple way to greatly enhance the security of your account The post Google to turn on 2FA by default for 150 million users, 2 million YouTubers appeared first on WeLiveSecurity

To the moon and hack: Fake SafeMoon app drops malware to spy on you

Cryptocurrencies rise and fall, but one thing stays the same – cybercriminals attempt to cash in on the craze The post To the moon and hack: Fake SafeMoon app drops malware to spy on you appeared first on WeLiveSecurity

UEFI threats moving to the ESP: Introducing ESPecter bootkit

ESET research discovers a previously undocumented UEFI bootkit with roots going back all the way to at least 2012 The post UEFI threats moving to the ESP: Introducing ESPecter bootkit appeared first on WeLiveSecurity

Hackers could force locked iPhones to make contactless payments

Flaws in Apple Pay and Visa could allow criminals to make arbitrary contactless payments – no authentication needed, research finds The post Hackers could force locked iPhones to make contactless payments appeared first on WeLiveSecurity

ESET Threat Report T2 2021

A view of the T2 2021 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report T2 2021 appeared first on WeLiveSecurity

CISA and NSA release guidance for securing VPNs

What your organization should consider when it comes to choosing a VPN solution and hardening it against attacks The post CISA and NSA release guidance for securing VPNs appeared first on WeLiveSecurity

Google releases emergency fix to plug zero‑day hole in Chrome

The emergency release comes a mere three days after Google’s previous update that plugged another 19 security loopholes The post Google releases emergency fix to plug zero‑day hole in Chrome appeared first on WeLiveSecurity

Bug in macOS Finder allows remote code execution

While Apple did issue a patch for the vulnerability, it seems that the fix can be easily circumvented The post Bug in macOS Finder allows remote code execution appeared first on WeLiveSecurity

FamousSparrow: A suspicious hotel guest

Yet another APT group that exploited the ProxyLogon vulnerability in March 2021 The post FamousSparrow: A suspicious hotel guest appeared first on WeLiveSecurity

Plugging the holes: How to prevent corporate data leaks in the cloud

Misconfigurations of cloud resources can lead to various security incidents and ultimately cost your organization dearly. Here’s what you can do to prevent cloud configuration conundrums. The post Plugging the holes: How to prevent corporate data leaks in the cloud appeared first on WeLiveSecurity

European police dismantle cybercrime ring with ties to Italian Mafia

The group used phishing, BEC and other types of attacks to swindle victims out of millions The post European police dismantle cybercrime ring with ties to Italian Mafia appeared first on WeLiveSecurity

Microsoft Patch Tuesday fixes actively exploited zero‑day and 85 other flaws

The most recent Patch Tuesday includes a fix for the previously disclosed and actively exploited remote code execution flaw in MSHTML. The post Microsoft Patch Tuesday fixes actively exploited zero‑day and 85 other flaws appeared first on WeLiveSecurity

WhatsApp announces end‑to‑end encrypted backups

The Facebook-owned messaging service plans to roll out the feature to both iOS and Android users in the coming weeks. The post WhatsApp announces end‑to‑end encrypted backups appeared first on WeLiveSecurity

What is a cyberattack surface and how can you reduce it?

Discover the best ways to mitigate your organization’s attack surface, in order to maximize cybersecurity. The post What is a cyberattack surface and how can you reduce it? appeared first on WeLiveSecurity

Beware of these 5 common scams you can encounter on Instagram

From cybercriminal evergreens like phishing to the verification badge scam we look at the most common tactics fraudsters use to trick their victims The post Beware of these 5 common scams you can encounter on Instagram appeared first on WeLiveSecurity

Howard University suffers cyberattack, suspends online classes in aftermath

The university suffered a ransomware attack, however there is no evidence so far of data being accessed or stolen. The post Howard University suffers cyberattack, suspends online classes in aftermath appeared first on WeLiveSecurity

ProtonMail forced to log user’s IP address after an order from Swiss authorities

Following the incident the company has updated its website and privacy policy to clarify its legal obligations to its userbase The post ProtonMail forced to log user’s IP address after an order from Swiss authorities appeared first on WeLiveSecurity

BladeHawk group: Android espionage against Kurdish ethnic group

ESET researchers have investigated a targeted mobile espionage campaign against the Kurdish ethnic group, and that has been active since at least March 2020. The post BladeHawk group: Android espionage against Kurdish ethnic group appeared first on WeLiveSecurity

Twitter introduces new feature to automatically block abusive behavior

Dubbed Safety Mode, the feature will temporarily block authors of offensive tweets from being able to contact or follow users. The post Twitter introduces new feature to automatically block abusive behavior appeared first on WeLiveSecurity

Vaccine passports: Is your personal data in safe hands?

Vaccination passports may facilitate the return to normalcy, but there are also concerns about what kinds of personal data they collect and how well they protect it. Here’s what you should know. The post Vaccine passports: Is your personal data in safe hands? appeared first on WeLiveSecurity

Flaw in the Quebec vaccine passport: analysis

ESET’s cybersecurity expert Marc-Étienne Léveillé analyses in-depth the Quebec’s vaccine proof apps VaxiCode and VaxiCode Verif. The post Flaw in the Quebec vaccine passport: analysis appeared first on WeLiveSecurity

Don’t use single‑factor authentication, warns CISA

The federal agency urges organizations to ditch the bad practice and instead use multi-factor authentication methods The post Don’t use single‑factor authentication, warns CISA appeared first on WeLiveSecurity

Man impersonates Apple support, steals 620,000 photos from iCloud accounts

The man was after sexually explicit photos and videos that he would then share online or store in his own collection The post Man impersonates Apple support, steals 620,000 photos from iCloud accounts appeared first on WeLiveSecurity

Microsoft Power Apps misconfiguration exposes millions of records

The caches of data that were publicly accessible included names, email addresses and social security numbers The post Microsoft Power Apps misconfiguration exposes millions of records appeared first on WeLiveSecurity

The SideWalk may be as dangerous as the CROSSWALK

Meet SparklingGoblin, a member of the Winnti family The post The SideWalk may be as dangerous as the CROSSWALK appeared first on WeLiveSecurity

Are you, the customer, the one paying the ransomware demand?

Ransomware payments may have greater implications than you thought – and not just for the company that gave in to the attackers’ demands The post Are you, the customer, the one paying the ransomware demand? appeared first on WeLiveSecurity

Health authorities in 40 countries targeted by COVID‑19 vaccine scammers

Fraudsters impersonate vaccine manufacturers and authorities overseeing vaccine distribution efforts, INTERPOL warns The post Health authorities in 40 countries targeted by COVID‑19 vaccine scammers appeared first on WeLiveSecurity

Nearly 2 million records from terrorist watchlist exposed online

The secret list was exposed online for three weeks, allowing anyone to access it without any kind of authentication The post Nearly 2 million records from terrorist watchlist exposed online appeared first on WeLiveSecurity

Dumpster diving is a filthy business

One man’s trash is another man’s treasure – here’s why you should think twice about what you toss in the recycling bin The post Dumpster diving is a filthy business appeared first on WeLiveSecurity

Examining threats to device security in the hybrid workplace

As employees split their time between office and off-site work, there’s a greater potential for company devices and data to fall into the wrong hands The post Examining threats to device security in the hybrid workplace appeared first on WeLiveSecurity

IISerpent: Malware‑driven SEO fraud as a service

The last in our series on IIS threats introduces a malicious IIS extension used to manipulate page rankings for third-party websites The post IISerpent: Malware‑driven SEO fraud as a service appeared first on WeLiveSecurity

Ransomware runs rampant, so how can you combat this threat?

A new paper explains how ransomware has become one of the top cyberthreats of the day and how your organization can avoid becoming the next victim The post Ransomware runs rampant, so how can you combat this threat? appeared first on WeLiveSecurity

Deepfakes – the bot made me do it

As fraud involving highly believable synthetic media soars, what can you do to avoid getting scammed? The post Deepfakes – the bot made me do it appeared first on WeLiveSecurity

DEF CON 29: Satellite hacking 101

How peering into the innards of a future satellite can make cybersecurity in space more palatable The post DEF CON 29: Satellite hacking 101 appeared first on WeLiveSecurity

IISpy: A complex server‑side backdoor with anti‑forensic features

The second in our series on IIS threats dissects a malicious IIS extension that employs nifty tricks in an attempt to secure long-term espionage on the compromised servers The post IISpy: A complex server‑side backdoor with anti‑forensic features appeared first on WeLiveSecurity

Is your personal information being abused?

Drowning in spam? A study presented at Black Hat USA 2021 examines if sharing your personal information with major companies contributes to the deluge of nuisance emails, texts and phone calls. The post Is your personal information being abused? appeared first on WeLiveSecurity

Why cloud security is the key to unlocking value from hybrid working

How can companies and employees who start to adapt to hybrid working practices protect themselves against cloud security threats? The post Why cloud security is the key to unlocking value from hybrid working appeared first on WeLiveSecurity

Black Hat 2021 – non‑virtual edition

How is Black Hat USA 2021 different from the past editions of the conference and what kinds of themes may steal the show this year? The post Black Hat 2021 – non‑virtual edition appeared first on WeLiveSecurity

On course for a good hacking

A story of how easily hackers could hit a hole-in-one with the computer network of a premier golf club in the UK. The post On course for a good hacking appeared first on WeLiveSecurity

Tackling the insider threat to the new hybrid workplace

Now that organizations are set to evolve a hybrid blend of home and office-based work for most employees, it is more important then ever to address the risks that insider threat can – willingly or unwitingly – pose. The post Tackling the insider threat to the new hybrid workplace appeared first on WeLiveSecurity

Leading cybersecurity agencies reveal list of most exploited vulnerabilities of the past 2 years

There are 30 vulnerabilities listed in total; organizations would do well to patch their systems if they haven’t done so yet The post Leading cybersecurity agencies reveal list of most exploited vulnerabilities of the past 2 years appeared first on WeLiveSecurity

Booking your next holiday? Watch out for these Airbnb scams

With vacations in full swing, cybercriminals will be looking to scam vacationers looking for that perfect accommodation. The post Booking your next holiday? Watch out for these Airbnb scams appeared first on WeLiveSecurity

Most Twitter users haven’t enabled 2FA yet, report reveals

Twitter’s transparency report revealed that users aren’t quick to adopt 2FA and once they do enable it, they choose the least secure option The post Most Twitter users haven’t enabled 2FA yet, report reveals appeared first on WeLiveSecurity

Apple releases patch for zero‑day flaw in iOS, iPadOS and macOS

The vulnerability is under active exploitation by unknown attackers and affects a wide range of Apple’s products. The post Apple releases patch for zero‑day flaw in iOS, iPadOS and macOS appeared first on WeLiveSecurity

Popular Wi‑Fi routers still using default passwords making them susceptible to attacks

To mitigate the chances of their Wi-Fi home routers being compromised, users would do well to change the manufacturer’s default access credentials The post Popular Wi‑Fi routers still using default passwords making them susceptible to attacks appeared first on WeLiveSecurity

Cybercriminals may target 2020 Tokyo Olympics, FBI warns

Cybercriminals may target the popular event with ransomware, phishing, or DDoS attacks in a bid to increase their notoriety or make money The post Cybercriminals may target 2020 Tokyo Olympics, FBI warns appeared first on WeLiveSecurity

Some URL shortener services distribute Android malware, including banking or SMS trojans

On iOS we have seen link shortener services pushing spam calendar files to victims’ devices. The post Some URL shortener services distribute Android malware, including banking or SMS trojans appeared first on WeLiveSecurity

Sports events and online streaming: prepare your cybersecurity

If you’ll be watching Sports Streaming events on your SmartTV, laptop, tablet or cell phone, learn the tips to keep you and your personal data safe. The post Sports events and online streaming: prepare your cybersecurity appeared first on WeLiveSecurity

Microsoft Patch Tuesday fixes 13 critical flaws, including 4 under active attack

The latest Patch Tuesday brings a new batch of security updates addressing a total of 117 vulnerabilities The post Microsoft Patch Tuesday fixes 13 critical flaws, including 4 under active attack appeared first on WeLiveSecurity

Choosing your MSP: What the Kaseya incident tells us about third‑party cyber risk

Lessons to learn from the Kaseya cyberincident to protect your business’ data when doing business with a MSP. The post Choosing your MSP: What the Kaseya incident tells us about third‑party cyber risk appeared first on WeLiveSecurity

The hybrid workplace: What does it mean for cybersecurity?

How can organizations mitigate the risk of damaging cyberattacks while juggling the constantly changing mix of office and off-site workers? The post The hybrid workplace: What does it mean for cybersecurity? appeared first on WeLiveSecurity

Microsoft issues patch to fix PrintNightmare zero‑day bug

The out-of-band update fixes a remote code execution flaw affecting the Windows Print Spooler service The post Microsoft issues patch to fix PrintNightmare zero‑day bug appeared first on WeLiveSecurity

Ransomware: To pay or not to pay? Legal or illegal? These are the questions …

Caught between a rock and a hard place, many ransomware victims cave in to extortion demands. Here’s what might change the calculus. The post Ransomware: To pay or not to pay? Legal or illegal? These are the questions … appeared first on WeLiveSecurity

Bandidos at large: A spying campaign in Latin America

ESET Research uncovers an active malicious campaign that uses new versions of old malware, Bandook, to spy on its victims The post Bandidos at large: A spying campaign in Latin America appeared first on WeLiveSecurity

Kaseya supply‑chain attack: What we know so far

As news breaks about the supply-chain ransomware attack against Kaseya’s IT management software, here’s what we know so far The post Kaseya supply‑chain attack: What we know so far appeared first on WeLiveSecurity

Global police shut down VPN service favored by cybercriminals

A global operation takes down the infrastructure of DoubleVPN and seizes data about its customers The post Global police shut down VPN service favored by cybercriminals appeared first on WeLiveSecurity

Data for 700 million LinkedIn users up for grabs on hacker forum

Information scraped from LinkedIn user profiles includes full names, gender, email addresses and phone numbers The post Data for 700 million LinkedIn users up for grabs on hacker forum appeared first on WeLiveSecurity

Common Facebook scams and how to avoid them

Are you on Facebook? So are scammers. Here are some of the most common con jobs on Facebook you should watch out for and how you can tell if you’re being scammed. The post Common Facebook scams and how to avoid them appeared first on WeLiveSecurity

In Memoriam: John McAfee

What was it like to work for, and be friends with, the larger-than-life technology entrepreneur back when he helped shape the computer security industry? The post In Memoriam: John McAfee appeared first on WeLiveSecurity

Gaming industry under siege from cyberattacks during pandemic

Cyberattacks targeting the gaming industry skyrocket, with web attacks more than tripling year-on-year in 2020 The post Gaming industry under siege from cyberattacks during pandemic appeared first on WeLiveSecurity

Brave launches its own, privacy‑focused search engine

The Brave Search engine takes on Google, promising to let users surf the web without leaving a trace The post Brave launches its own, privacy‑focused search engine appeared first on WeLiveSecurity

How to tell if a website is safe

It can be difficult to tell a legitimate website apart from an unsafe one – follow these steps to identify and protect yourself from bad websites The post How to tell if a website is safe appeared first on WeLiveSecurity

State‑sponsored or financially motivated: Is there any difference anymore?

What does the increasingly fuzzy line between traditional cybercrime and attacks attributed to state-backed groups mean for the future of the threat landscape? The post State‑sponsored or financially motivated: Is there any difference anymore? appeared first on WeLiveSecurity

Most health apps engage in unhealthy data‑harvesting habits

Most medical and fitness apps in Google Play have tracking capabilities enabled and their data collection practices aren’t transparent The post Most health apps engage in unhealthy data‑harvesting habits appeared first on WeLiveSecurity

5 essential things to do before ransomware strikes

By failing to prepare you are preparing to fail – here’s what you can do today to minimize the impact of a potential ransomware attack in the future The post 5 essential things to do before ransomware strikes appeared first on WeLiveSecurity

OSINT 101: What is open source intelligence and how is it used?

OSINT can be used by anyone, both for good and bad ends – here’s how defenders can use it to keep ahead of attackers The post OSINT 101: What is open source intelligence and how is it used? appeared first on WeLiveSecurity

Microsoft takes down large‑scale BEC operation

The fraudsters ran their campaigns from the cloud and used phishing and email forwarding rules to steal their targets’ financial information. The post Microsoft takes down large‑scale BEC operation appeared first on WeLiveSecurity

Vishing: What is it and how do I avoid getting scammed?

How do vishing scams work, how do they impact businesses and individuals, and how can you protect yourself, your family and your business? The post Vishing: What is it and how do I avoid getting scammed? appeared first on WeLiveSecurity

Google fixes actively exploited Chrome zero‑day

The latest Chrome update patches a bumper crop of security flaws across the browser’s desktop versions The post Google fixes actively exploited Chrome zero‑day appeared first on WeLiveSecurity

BackdoorDiplomacy: Upgrading from Quarian to Turian

ESET researchers discover a new campaign that evolved from the Quarian backdoor The post BackdoorDiplomacy: Upgrading from Quarian to Turian appeared first on WeLiveSecurity

Gelsemium: When threat actors go gardening

ESET researchers shed light on new campaigns from the quiet Gelsemium group The post Gelsemium: When threat actors go gardening appeared first on WeLiveSecurity

Hundreds of suspected criminals arrested after being tricked into using FBI‑run chat app

Law enforcement around the world used a messaging app called AN0M to monitor the communications of alleged criminals The post Hundreds of suspected criminals arrested after being tricked into using FBI‑run chat app appeared first on WeLiveSecurity

Hacking space: How to pwn a satellite

Hacking an orbiting satellite is not light years away – here’s how things can go wrong in outer space The post Hacking space: How to pwn a satellite appeared first on WeLiveSecurity

Zero‑day in popular WordPress plugin exploited to take over websites

Websites using Fancy Product Designer are susceptible to remote code execution attacks even if the plugin is deactivated The post Zero‑day in popular WordPress plugin exploited to take over websites appeared first on WeLiveSecurity

ESET Threat Report T1 2021

A view of the T1 2021 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report T1 2021 appeared first on WeLiveSecurity

5 common scams targeting teens – and how to stay safe

From knock-off designer products to too-good-to-be-true job offers, here are five common schemes fraudsters use to trick teenagers out of their money and sensitive data The post 5 common scams targeting teens – and how to stay safe appeared first on WeLiveSecurity

Don’t feed the trolls and other tips for avoiding online drama

You may not be able to escape internet trolls, but you have a choice about how you will deal with them – here’s how you can handle trolls without losing your cool The post Don’t feed the trolls and other tips for avoiding online drama appeared first on WeLiveSecurity

I hacked my friend’s website after a SIM swap attack

Here’s how easily your phone number could be stolen, why a successful SIM swap scam is only the beginning of your problems, and how you can avoid becoming a victim of the attack The post I hacked my friend’s website after a SIM swap attack appeared first on WeLiveSecurity

Bluetooth bugs could allow attackers to impersonate devices

Patches to remedy the vulnerabilities should be released over the coming weeks The post Bluetooth bugs could allow attackers to impersonate devices appeared first on WeLiveSecurity

Apple fixes macOS zero‑day bug that let malware take secret screenshots

You would do well to update to macOS Big Sur 11.4 post-haste The post Apple fixes macOS zero‑day bug that let malware take secret screenshots appeared first on WeLiveSecurity

Rom‑con: How romance fraud targets older people and how to avoid it

Online dating scams often follow the same script – here’s what senior citizens should watch out for and how their younger relatives can help them avoid falling victim The post Rom‑con: How romance fraud targets older people and how to avoid it appeared first on WeLiveSecurity

Android 12 will give you more control over how much data you share with apps

An all-new privacy dashboard and better location, microphone and camera controls are all aimed at curbing apps’ data-slurping habits The post Android 12 will give you more control over how much data you share with apps appeared first on WeLiveSecurity

Scams target families of missing persons, FBI warns

Con artists use social media to find and target victims for various nefarious ends, including to extort relatives of missing persons The post Scams target families of missing persons, FBI warns appeared first on WeLiveSecurity

Colonial Pipeline attack: Hacking the physical world

The attack is a reminder of growing cyberthreats to critical infrastructure while also showing why providers of essential services are ripe targets for cybercriminals The post Colonial Pipeline attack: Hacking the physical world appeared first on WeLiveSecurity

Take action now – FluBot malware may be on its way

Why FluBot is a major threat for Android users, how to avoid falling victim, and how to get rid of the malware if your device has already been compromised The post Take action now – FluBot malware may be on its way appeared first on WeLiveSecurity

Android stalkerware threatens victims further and exposes snoopers themselves

ESET research reveals that common Android stalkerware apps are riddled with vulnerabilities that further jeopardize victims and expose the privacy and security of the snoopers themselves The post Android stalkerware threatens victims further and exposes snoopers themselves appeared first on WeLiveSecurity

Verizon’s 2021 DBIR: Phishing and ransomware threats looming ever larger

The report provides unique insights into how the COVID-19 pandemic affected the data breach landscape The post Verizon’s 2021 DBIR: Phishing and ransomware threats looming ever larger appeared first on WeLiveSecurity

European police bust major online investment fraud ring

The operation was carried out against an organized group that used online trading platforms to swindle victims out of US$36 million The post European police bust major online investment fraud ring appeared first on WeLiveSecurity

1 million risky apps rejected or removed from Apple’s App Store in 2020

Apple also claims to have foiled US$1.5 billion worth of potentially fraudulent transactions The post 1 million risky apps rejected or removed from Apple’s App Store in 2020 appeared first on WeLiveSecurity

ESET Research goes to RSA Conference 2021 with two presentations

We will explore two threats – Android stalkerware and XP exploits The post ESET Research goes to RSA Conference 2021 with two presentations appeared first on WeLiveSecurity

ESET Research goes to RSA Conference 2021 with record number of presentations

We will explore Android stalkerware, air-gapped networks and XP exploits The post ESET Research goes to RSA Conference 2021 with record number of presentations appeared first on WeLiveSecurity

WhatsApp will limit features for users who don’t accept new data‑sharing rules

Your account won’t be deleted, but here’s what you may want to be aware of if not even repeated reminders do the trick The post WhatsApp will limit features for users who don’t accept new data‑sharing rules appeared first on WeLiveSecurity

Popular routers found vulnerable to hacker attacks

Millions of Brits could be at risk of cyberattacks due to poor default passwords and a lack of firmware updates The post Popular routers found vulnerable to hacker attacks appeared first on WeLiveSecurity