Menu

Category Archives: Security Advisory

Auto Added by WPeMatico

Hundreds of suspected criminals arrested after being tricked into using FBI‑run chat app

Law enforcement around the world used a messaging app called AN0M to monitor the communications of alleged criminals The post Hundreds of suspected criminals arrested after being tricked into using FBI‑run chat app appeared first on WeLiveSecurity

Hacking space: How to pwn a satellite

Hacking an orbiting satellite is not light years away – here’s how things can go wrong in outer space The post Hacking space: How to pwn a satellite appeared first on WeLiveSecurity

Zero‑day in popular WordPress plugin exploited to take over websites

Websites using Fancy Product Designer are susceptible to remote code execution attacks even if the plugin is deactivated The post Zero‑day in popular WordPress plugin exploited to take over websites appeared first on WeLiveSecurity

ESET Threat Report T1 2021

A view of the T1 2021 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report T1 2021 appeared first on WeLiveSecurity

5 common scams targeting teens – and how to stay safe

From knock-off designer products to too-good-to-be-true job offers, here are five common schemes fraudsters use to trick teenagers out of their money and sensitive data The post 5 common scams targeting teens – and how to stay safe appeared first on WeLiveSecurity

Don’t feed the trolls and other tips for avoiding online drama

You may not be able to escape internet trolls, but you have a choice about how you will deal with them – here’s how you can handle trolls without losing your cool The post Don’t feed the trolls and other tips for avoiding online drama appeared first on WeLiveSecurity

I hacked my friend’s website after a SIM swap attack

Here’s how easily your phone number could be stolen, why a successful SIM swap scam is only the beginning of your problems, and how you can avoid becoming a victim of the attack The post I hacked my friend’s website after a SIM swap attack appeared first on WeLiveSecurity

Bluetooth bugs could allow attackers to impersonate devices

Patches to remedy the vulnerabilities should be released over the coming weeks The post Bluetooth bugs could allow attackers to impersonate devices appeared first on WeLiveSecurity

Apple fixes macOS zero‑day bug that let malware take secret screenshots

You would do well to update to macOS Big Sur 11.4 post-haste The post Apple fixes macOS zero‑day bug that let malware take secret screenshots appeared first on WeLiveSecurity

Rom‑con: How romance fraud targets older people and how to avoid it

Online dating scams often follow the same script – here’s what senior citizens should watch out for and how their younger relatives can help them avoid falling victim The post Rom‑con: How romance fraud targets older people and how to avoid it appeared first on WeLiveSecurity

Android 12 will give you more control over how much data you share with apps

An all-new privacy dashboard and better location, microphone and camera controls are all aimed at curbing apps’ data-slurping habits The post Android 12 will give you more control over how much data you share with apps appeared first on WeLiveSecurity

Scams target families of missing persons, FBI warns

Con artists use social media to find and target victims for various nefarious ends, including to extort relatives of missing persons The post Scams target families of missing persons, FBI warns appeared first on WeLiveSecurity

Colonial Pipeline attack: Hacking the physical world

The attack is a reminder of growing cyberthreats to critical infrastructure while also showing why providers of essential services are ripe targets for cybercriminals The post Colonial Pipeline attack: Hacking the physical world appeared first on WeLiveSecurity

Take action now – FluBot malware may be on its way

Why FluBot is a major threat for Android users, how to avoid falling victim, and how to get rid of the malware if your device has already been compromised The post Take action now – FluBot malware may be on its way appeared first on WeLiveSecurity

Android stalkerware threatens victims further and exposes snoopers themselves

ESET research reveals that common Android stalkerware apps are riddled with vulnerabilities that further jeopardize victims and expose the privacy and security of the snoopers themselves The post Android stalkerware threatens victims further and exposes snoopers themselves appeared first on WeLiveSecurity

Verizon’s 2021 DBIR: Phishing and ransomware threats looming ever larger

The report provides unique insights into how the COVID-19 pandemic affected the data breach landscape The post Verizon’s 2021 DBIR: Phishing and ransomware threats looming ever larger appeared first on WeLiveSecurity

European police bust major online investment fraud ring

The operation was carried out against an organized group that used online trading platforms to swindle victims out of US$36 million The post European police bust major online investment fraud ring appeared first on WeLiveSecurity

1 million risky apps rejected or removed from Apple’s App Store in 2020

Apple also claims to have foiled US$1.5 billion worth of potentially fraudulent transactions The post 1 million risky apps rejected or removed from Apple’s App Store in 2020 appeared first on WeLiveSecurity

ESET Research goes to RSA Conference 2021 with two presentations

We will explore two threats – Android stalkerware and XP exploits The post ESET Research goes to RSA Conference 2021 with two presentations appeared first on WeLiveSecurity

ESET Research goes to RSA Conference 2021 with record number of presentations

We will explore Android stalkerware, air-gapped networks and XP exploits The post ESET Research goes to RSA Conference 2021 with record number of presentations appeared first on WeLiveSecurity

WhatsApp will limit features for users who don’t accept new data‑sharing rules

Your account won’t be deleted, but here’s what you may want to be aware of if not even repeated reminders do the trick The post WhatsApp will limit features for users who don’t accept new data‑sharing rules appeared first on WeLiveSecurity

Popular routers found vulnerable to hacker attacks

Millions of Brits could be at risk of cyberattacks due to poor default passwords and a lack of firmware updates The post Popular routers found vulnerable to hacker attacks appeared first on WeLiveSecurity

DDoS attack knocks Belgian government websites offline

The attack overwhelmed the systems of a Belgian ISP, leading to widespread service outages and disruptions The post DDoS attack knocks Belgian government websites offline appeared first on WeLiveSecurity

Fantastic passwords and where your children can find them

How witches, wizards and superheroes can help your kids stay safe from cyber-villains, plus other parenting hacks to encourage your children to use secure passwords The post Fantastic passwords and where your children can find them appeared first on WeLiveSecurity

Microsoft will soon remove Flash Player from Windows 10 devices

The Patch Tuesday security update due in July should hammer the last nail in the coffin of Adobe Flash Player The post Microsoft will soon remove Flash Player from Windows 10 devices appeared first on WeLiveSecurity

Ousaban: Private photo collection hidden in a CABinet

Another in our occasional series demystifying Latin American banking trojans The post Ousaban: Private photo collection hidden in a CABinet appeared first on WeLiveSecurity

INTERPOL aims to deal a blow to digital piracy

The agency’s new initiative will also warn about the high cost of the free lunch – the increased risk of malware exposure The post INTERPOL aims to deal a blow to digital piracy appeared first on WeLiveSecurity

FBI teams up with ‘Have I Been Pwned’ to alert Emotet victims

The data breach notification site now allows you to check if your login credentials may have been compromised by Emotet The post FBI teams up with ‘Have I Been Pwned’ to alert Emotet victims appeared first on WeLiveSecurity

Prime targets: Governments shouldn’t go it alone on cybersecurity

A year into the pandemic, ESET reveals new research into activities of the LuckyMouse APT group and considers how governments can rise to the cybersecurity challenges of the accelerated shift to digital The post Prime targets: Governments shouldn’t go it alone on cybersecurity appeared first on WeLiveSecurity

Apple patches severe macOS security flaw

Mac users are being urged to update to macOS Big Sur 11.3 as at least one threat group is exploiting the zero-day bug to sneak past the operating system’s built-in security mechanisms The post Apple patches severe macOS security flaw appeared first on WeLiveSecurity

4 common ways scammers use celebrity names to lure victims

All that glitters is not gold – look out for fake celebrity endorsements and other con jobs that aren’t going out of fashion any time soon The post 4 common ways scammers use celebrity names to lure victims appeared first on WeLiveSecurity

AirDrop flaws could leak phone numbers, email addresses

You can only stay safe by disabling AirDrop discovery in the system settings of your Apple device, a study says The post AirDrop flaws could leak phone numbers, email addresses appeared first on WeLiveSecurity

Google rushes out fix for zero‑day vulnerability in Chrome

The update patches a total of seven security flaws in the desktop versions of the popular web browser The post Google rushes out fix for zero‑day vulnerability in Chrome appeared first on WeLiveSecurity

WhatsApp Pink: Watch out for this fake update

The malware sends automated replies to messages on WhatsApp and other major chat apps The post WhatsApp Pink: Watch out for this fake update appeared first on WeLiveSecurity

Google’s Project Zero to wait longer before disclosing bug details

The 30-day grace period is designed to speed up the rollout and adoption of patches The post Google’s Project Zero to wait longer before disclosing bug details appeared first on WeLiveSecurity

One in six people use pet’s name as password

Other common and easily hackable password choices include the names of relatives and sports teams, a UK study reveals The post One in six people use pet’s name as password appeared first on WeLiveSecurity

Spring cleaning? Don’t forget about your digital footprint

Here are some quick and easy tips to help you clean up your cyber-clutter and keep your digital footprint tidy The post Spring cleaning? Don’t forget about your digital footprint appeared first on WeLiveSecurity

FBI removes web shells from compromised Exchange servers

Authorities step in to thwart attacks leveraging the recently-disclosed Microsoft Exchange Server vulnerabilities The post FBI removes web shells from compromised Exchange servers appeared first on WeLiveSecurity

WhatsApp flaw lets anyone lock you out of your account

An attacker can lock you out of the app using just your phone number and without requiring any action on your part The post WhatsApp flaw lets anyone lock you out of your account appeared first on WeLiveSecurity

Clubhouse in the spotlight after user records posted online

Reports of another trove of scraped user data add to the recent woes of popular social media platforms The post Clubhouse in the spotlight after user records posted online appeared first on WeLiveSecurity

WhatsApp may soon roll out encrypted chat backups

While chats are end-to-end encrypted, their backups are not – this may change soon The post WhatsApp may soon roll out encrypted chat backups appeared first on WeLiveSecurity

Online health security – when ‘opt out’ isn’t an option

What happens when you try to opt out of e-health to avoid issues in the event of a breach? The post Online health security – when ‘opt out’ isn’t an option appeared first on WeLiveSecurity

Women in cybersecurity: Gender gap narrows but not enough

The number of women joining the ranks of cybersecurity practitioners is steadily increasing, but a lot still needs to be done to close the gap The post Women in cybersecurity: Gender gap narrows but not enough appeared first on WeLiveSecurity

Going dark: Service disruptions at stock exchanges and brokerages

Are you a bull or a bear? If you can’t access your data and money, do your sentiments about the market still matter? The post Going dark: Service disruptions at stock exchanges and brokerages appeared first on WeLiveSecurity

How ESET’s work on SafetyNet® helps protect children online

For over a decade, ESET and the San Diego Police Foundation have been working together to help keep children safe from online threats The post How ESET’s work on SafetyNet® helps protect children online appeared first on WeLiveSecurity

Microsoft rushes out fixes for four zero‑day flaws in Exchange Server

At least one vulnerability is being exploited by multiple cyberespionage groups to attacks targets mainly in the US, per ESET telemetry The post Microsoft rushes out fixes for four zero‑day flaws in Exchange Server appeared first on WeLiveSecurity

Cybersecurity risks and challenges facing the financial industry

A primer on various threats looming over financial companies and the steps that the organizations can take to counter them The post Cybersecurity risks and challenges facing the financial industry appeared first on WeLiveSecurity

Not all cybercriminals are sophisticated

Some perpetrators of online crime and fraud don’t use advanced methods to profit at the expense of unsuspecting victims and to avoid getting caught The post Not all cybercriminals are sophisticated appeared first on WeLiveSecurity

Popular password manager in the spotlight over web trackers

While the trackers in LastPass’ Android app don’t collect any personal data, the news may not sit well with some privacy-minded users The post Popular password manager in the spotlight over web trackers appeared first on WeLiveSecurity

Championing worthy causes: How ESET gives a helping hand

A snapshot of some of the ways ESET makes an impact supporting the well-being of people, communities and the environment The post Championing worthy causes: How ESET gives a helping hand appeared first on WeLiveSecurity

Facebook ramps up fight against child abuse content

Two new tools will warn users about the risks of searching for and sharing content that exploits children, including the potential legal consequences of doing so The post Facebook ramps up fight against child abuse content appeared first on WeLiveSecurity

Google’s Password Checkup tool rolling out to Android devices

People who use devices running Android 9 or newer will be alerted if their login credentials have been stolen The post Google’s Password Checkup tool rolling out to Android devices appeared first on WeLiveSecurity

Clubhouse chats streamed to third‑party website

The incident raises concerns about the privacy and security of conversations taking place on the platform The post Clubhouse chats streamed to third‑party website appeared first on WeLiveSecurity

Brave browser’s Tor mode exposed users’ dark web activity

A bug in the ad blocking component of Brave’s Tor feature caused the browser to leak users’ DNS queries The post Brave browser’s Tor mode exposed users’ dark web activity appeared first on WeLiveSecurity

Malware authors already taking aim at Apple M1 Macs

The first instance of malicious code native to Apple Silicon M1 Macs emerged a month after the release of devices equipped with the company’s in-house CPUs The post Malware authors already taking aim at Apple M1 Macs appeared first on WeLiveSecurity

Attacks targeting IT firms stir concern, controversy

The Exaramel backdoor, discovered by ESET in 2018, resurfaces in a campaign hitting companies that use an outdated version of a popular IT monitoring tool The post Attacks targeting IT firms stir concern, controversy appeared first on WeLiveSecurity

Romance scams in 2020: Breaking hearts, wallets – and records

As dating apps experience a boom amid COVID-19, losses to romance scams soar too The post Romance scams in 2020: Breaking hearts, wallets – and records appeared first on WeLiveSecurity

Record‑breaking number of vulnerabilities reported in 2020

High-severity and critical bugs disclosed in 2020 outnumber the sum total of vulnerabilities reported 10 years prior The post Record‑breaking number of vulnerabilities reported in 2020 appeared first on WeLiveSecurity

Beware of COVID‑19 vaccine scams and misinformation

The vaccination push provides a vital shot in the arm for the world’s battle against the pandemic, but it’s also a topic ripe for exploitation by fraudsters and purveyors of misinformation The post Beware of COVID‑19 vaccine scams and misinformation appeared first on WeLiveSecurity

Protecting the water supply – hacker edition

What can municipalities do to better protect their water supply systems? The post Protecting the water supply – hacker edition appeared first on WeLiveSecurity

Microsoft patches actively exploited Windows kernel flaw

This month’s relatively humble bundle of security updates fixes 56 vulnerabilities, including a zero-day bug and 11 flaws rated as critical The post Microsoft patches actively exploited Windows kernel flaw appeared first on WeLiveSecurity

Hacker attempts to poison Florida city’s water supply

While the incursion was thwarted in time, cyberattacks targeting critical infrastructure are a major cause for concern The post Hacker attempts to poison Florida city’s water supply appeared first on WeLiveSecurity

ESET Threat Report Q4 2020

A view of the Q4 2020 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report Q4 2020 appeared first on WeLiveSecurity

Facebook etiquette: Behaviors you should avoid

Sharing your thoughts or photos for the world to see is now as easy as pushing a button, but even a seemingly harmless post may come back to haunt you The post Facebook etiquette: Behaviors you should avoid appeared first on WeLiveSecurity

Google: Better patching could have prevented 1 in 4 zero‑days last year

Vendors should fix the root cause of a vulnerability, rather than block just one path to triggering it, says Google The post Google: Better patching could have prevented 1 in 4 zero‑days last year appeared first on WeLiveSecurity

Identity theft spikes amid pandemic

The US Federal Trade Commission received 1.4 million reports of identity theft last year, double the number from 2019 The post Identity theft spikes amid pandemic appeared first on WeLiveSecurity

Kobalos – A complex Linux threat to high performance computing infrastructure

ESET researchers publish a white paper about unique multiplatform malware they’ve named Kobalos The post Kobalos – A complex Linux threat to high performance computing infrastructure appeared first on WeLiveSecurity

Operation NightScout: Supply‑chain attack targets online gaming in Asia

ESET researchers uncover a supply-chain attack used in a cyberespionage operation targeting online‑gaming communities in Asia The post Operation NightScout: Supply‑chain attack targets online gaming in Asia appeared first on WeLiveSecurity

Emotet botnet disrupted in global operation

The law enforcement action is one of the most significant operations against cybercriminal enterprises ever The post Emotet botnet disrupted in global operation appeared first on WeLiveSecurity

Data Privacy Day: Top tips for safe remote learning

As schools and students continue to contend with the very real cyber-risks of virtual classrooms, we share some advice for protecting children’s data and privacy The post Data Privacy Day: Top tips for safe remote learning appeared first on WeLiveSecurity

Apple patches three iOS zero‑days under attack

The company emits emergency updates to fix bugs affecting devices ranging from iPhones to Apple Watches The post Apple patches three iOS zero‑days under attack appeared first on WeLiveSecurity

Wormable Android malware spreads via WhatsApp messages

“Download This application and Win Mobile Phone”, reads the message attempting to trick users into downloading a fake Huawei app The post Wormable Android malware spreads via WhatsApp messages appeared first on WeLiveSecurity

Vadokrist: A wolf in sheep’s clothing

Another in our occasional series demystifying Latin American banking trojans The post Vadokrist: A wolf in sheep’s clothing appeared first on WeLiveSecurity

DNSpooq bugs expose millions of devices to DNS cache poisoning

Security flaws in a widely used DNS software package could allow attackers to send users to malicious websites or to remotely hijack their devices The post DNSpooq bugs expose millions of devices to DNS cache poisoning appeared first on WeLiveSecurity

FBI warns of voice phishing attacks stealing corporate credentials

Criminals coax employees into handing over their access credentials and use the login data to burrow deep into corporate networks The post FBI warns of voice phishing attacks stealing corporate credentials appeared first on WeLiveSecurity

WhatsApp delays privacy policy update after confusion, backlash

Millions of people flock to Signal and Telegram as WhatsApp scrambles to assuage users’ concerns The post WhatsApp delays privacy policy update after confusion, backlash appeared first on WeLiveSecurity

CES 2021: Car spying – your insurance company is watching you

Your ‘networked computer on wheels’ has a privacy problem – and you may not be in the driver’s seat when it comes to your data The post CES 2021: Car spying – your insurance company is watching you appeared first on WeLiveSecurity

CES 2021: Router swarms invade your home (and know where you are)

New mesh Wi-Fi routers may be the answer to your wireless signal woes, but how about your privacy and security? The post CES 2021: Router swarms invade your home (and know where you are) appeared first on WeLiveSecurity

Hackers leak stolen COVID‑19 vaccine documents

The documents related to COVID-19 vaccine and medications were stolen from the EU’s medicines agency last month The post Hackers leak stolen COVID‑19 vaccine documents appeared first on WeLiveSecurity

Operation Spalax: Targeted malware attacks in Colombia

ESET researchers uncover attacks targeting Colombian government institutions and private companies, especially from the energy and metallurgical industries The post Operation Spalax: Targeted malware attacks in Colombia appeared first on WeLiveSecurity

5 common scams and how to avoid them

Fraudsters are quick to exploit current events for their own gain, but many schemes do the rounds regardless of what’s making the news. Here are 5 common scams you should look out for. The post 5 common scams and how to avoid them appeared first on WeLiveSecurity

WhatsApp updates privacy policy to enable sharing more data with Facebook

Many users have until February 8 to accept the new rules – or else lose access to the app The post WhatsApp updates privacy policy to enable sharing more data with Facebook appeared first on WeLiveSecurity

Stolen employee credentials put leading gaming firms at risk

It’s hardly fun and games for top gaming companies and their customers as half a million employee credentials turn up for sale on the dark web The post Stolen employee credentials put leading gaming firms at risk appeared first on WeLiveSecurity

PayPal users targeted in new SMS phishing campaign

The scam starts with a text warning victims of suspicious activity on their accounts The post PayPal users targeted in new SMS phishing campaign appeared first on WeLiveSecurity

Would you take the bait? Take our phishing quiz to find out!

Is the message real or fake? Take our Phishing Derby quiz to find out how much you know about phishing. The post Would you take the bait? Take our phishing quiz to find out! appeared first on WeLiveSecurity

New warning issued over COVID‑19 vaccine fraud, cyberattacks

Cybercriminals look to cash in on the vaccine rollout, including by falsely offering to help people jump the line The post New warning issued over COVID‑19 vaccine fraud, cyberattacks appeared first on WeLiveSecurity

21 arrested after allegedly using stolen logins to commit fraud

UK police also give some food for thought to those on the verge of breaking the law The post 21 arrested after allegedly using stolen logins to commit fraud appeared first on WeLiveSecurity

Smart tech gifts: How to keep your kids and family safe

Cyberthreats can take the fun out of connected gadgets – here’s how to make sure your children enjoy the tech without putting themselves or their family at risk The post Smart tech gifts: How to keep your kids and family safe appeared first on WeLiveSecurity

7 ways malware can get into your device

You know that malware is bad, but are you also aware of the various common ways in which it can infiltrate your devices? The post 7 ways malware can get into your device appeared first on WeLiveSecurity

Cybersecurity Advent calendar: Stay aware, stay safe!

When it comes to holiday gifts, surprise and wonder are always welcome. When it comes to protecting your security, however, you don’t want to leave anything to chance. The post Cybersecurity Advent calendar: Stay aware, stay safe! appeared first on WeLiveSecurity

Operation SignSight: Supply‑chain attack against a certification authority in Southeast Asia

ESET researchers have uncovered a supply-chain attack on the website of a government in Southeast Asia. The post Operation SignSight: Supply‑chain attack against a certification authority in Southeast Asia appeared first on WeLiveSecurity

Cybersecurity Advent calendar: Stay close to one another… Safely!

This year, many of us will be celebrating Christmas with our loved ones virtually, however we shouldn’t underestimate the value of securing our online communication. The post Cybersecurity Advent calendar: Stay close to one another… Safely! appeared first on WeLiveSecurity

Medical scans of millions of patients exposed online

Other leaked data included a range of personal information such as names, addresses and personal healthcare information. The post Medical scans of millions of patients exposed online appeared first on WeLiveSecurity

How scammers target PayPal users and how you can stay safe

What are some common ploys targeting PayPal users? Here’s what you should watch out for when using the popular payment service. The post How scammers target PayPal users and how you can stay safe appeared first on WeLiveSecurity

Cybersecurity Advent calendar: Tips for buying gifts and not receiving coal

While shopping for the perfect presents, be on the lookout for naughty cybercriminals trying to ruin your Christmas cheer by tricking you out of both gifts and money The post Cybersecurity Advent calendar: Tips for buying gifts and not receiving coal appeared first on WeLiveSecurity

Operation StealthyTrident: corporate software under attack

LuckyMouse, TA428, HyperBro, Tmanger and ShadowPad linked in Mongolian supply-chain attack The post Operation StealthyTrident: corporate software under attack appeared first on WeLiveSecurity

Microsoft Patch Tuesday fixes 58 flaws

The last Patch Tuesday of the year brings another fresh batch of fixes for Microsoft products and while the number may be lower the patches are no less important. The post Microsoft Patch Tuesday fixes 58 flaws appeared first on WeLiveSecurity

The Internal Revenue Service expands identity protection to all tax‑payers

U.S. tax-payers will be able to enroll in the Identity Protection PIN program that was previously available only to certain users starting mid-January. The post The Internal Revenue Service expands identity protection to all tax‑payers appeared first on WeLiveSecurity

Google patches four high‑severity flaws in Chrome

The new release patches a total of eight vulnerabilities affecting the desktop versions of the popular browser. The post Google patches four high‑severity flaws in Chrome appeared first on WeLiveSecurity

Cybersecurity Advent Calendar: Let Santa in, keep hackers out!

Santa will soon come down the chimney, but there are potential entry points into your home and digital life that you should never leave open The post Cybersecurity Advent Calendar: Let Santa in, keep hackers out! appeared first on WeLiveSecurity