Menu

Category Archives: Security Advisory

Auto Added by WPeMatico

Over 100,000 machines remain vulnerable to SMBGhost exploitation

The patch for the critical flaw that allows malware to spread across machines without any user interaction was released months ago The post Over 100,000 machines remain vulnerable to SMBGhost exploitation appeared first on WeLiveSecurity

ESET Threat Report Q3 2020

A view of the Q3 2020 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report Q3 2020 appeared first on WeLiveSecurity

‘Among Us’ players hit by major spam attack

In-game chats were flooded with messages from somebody who tried to coerce players into subscribing to a dubious YouTube channel The post ‘Among Us’ players hit by major spam attack appeared first on WeLiveSecurity

Fraudsters crave loyalty points amid COVID‑19

Scammers even run their own dark-web “travel agencies”, misusing stolen loyalty points and credit card numbers The post Fraudsters crave loyalty points amid COVID‑19 appeared first on WeLiveSecurity

Securing medical devices: Can a hacker break your heart?

Why are connected medical devices vulnerable to attack and how likely are they to get hacked? Here are five digital chinks in the armor. The post Securing medical devices: Can a hacker break your heart? appeared first on WeLiveSecurity

Google patches Chrome zero‑day under attack

In addition to patching the actively exploited bug, the update also brings fixes for another four security loopholes The post Google patches Chrome zero‑day under attack appeared first on WeLiveSecurity

How safe is your USB drive?

What are some of the key security risks to be aware of when using USB flash drives and how can you mitigate the threats? The post How safe is your USB drive? appeared first on WeLiveSecurity

Microsoft issues two emergency Windows patches

The flaws, neither of which is being actively exploited, were fixed merely days after the monthly Patch Tuesday rollout The post Microsoft issues two emergency Windows patches appeared first on WeLiveSecurity

Zoom to begin rolling out end‑to‑end encryption

The videoconferencing platform is making the feature available to users of both free and paid tiers The post Zoom to begin rolling out end‑to‑end encryption appeared first on WeLiveSecurity

50,000 home cameras reportedly hacked, footage posted online

Some footage has already appeared on adult sites, with cybercriminals offering lifetime access to the entire loot for US$150 The post 50,000 home cameras reportedly hacked, footage posted online appeared first on WeLiveSecurity

Attackers chain Windows, VPN flaws to target US government agencies

Bad actors have accessed US elections support systems, although there’s no evidence to suggest that election data has been compromised, say FBI and CISA The post Attackers chain Windows, VPN flaws to target US government agencies appeared first on WeLiveSecurity

ESET takes part in global operation to disrupt Trickbot

Throughout its monitoring, ESET analyzed thousands of malicious samples every month to help this effort The post ESET takes part in global operation to disrupt Trickbot appeared first on WeLiveSecurity

Google adds password breach alerts to Chrome for Android, iOS

The feature is part of the browser’s security improvements that were first built into its desktop version The post Google adds password breach alerts to Chrome for Android, iOS appeared first on WeLiveSecurity

Working from a hotel? Beware the dangers of public Wi‑Fi

As more and more hotels are turning rooms into offices, the FBI is warning remote workers of cyber-threats lurking in the shadows The post Working from a hotel? Beware the dangers of public Wi‑Fi appeared first on WeLiveSecurity

Had your face stolen lately?

It’s easy to reset your password or PIN after a data breach. But reset your face? Not so much. The post Had your face stolen lately? appeared first on WeLiveSecurity

US gov’t warns against paying off ransomware attackers

Companies facilitating ransomware payments run the risk of facing stern penalties for violating US regulations The post US gov’t warns against paying off ransomware attackers appeared first on WeLiveSecurity

5 steps to secure your connected devices

As we steadily adopt smart devices into our lives, we shouldn’t forget about keeping them secured and our data protected The post 5 steps to secure your connected devices appeared first on WeLiveSecurity

Cyber Security Awareness Month is here!

A month teaching us that when everyone pitches in and does their part, then almost everyone is protected The post Cyber Security Awareness Month is here! appeared first on WeLiveSecurity

LATAM financial cybercrime: Competitors‑in‑crime sharing TTPs

ESET researchers discover surprisingly many indicators of close cooperation among Latin American banking trojans’ authors The post LATAM financial cybercrime: Competitors‑in‑crime sharing TTPs appeared first on WeLiveSecurity

Microsoft 365 services back online after hours‑long outage

Microsoft resolves a service disruption that affected Office 365, Outlook.com, Teams and other cloud-based services The post Microsoft 365 services back online after hours‑long outage appeared first on WeLiveSecurity

APT‑C‑23 group evolves its Android spyware

ESET researchers uncover a new version of Android spyware used by the APT-C-23 threat group against targets in the Middle East The post APT‑C‑23 group evolves its Android spyware appeared first on WeLiveSecurity

FBI, CISA warn of disinformation campaigns about hacked voting systems

Threat actors may spread false claims about compromised voting systems in order to undermine confidence in the electoral process The post FBI, CISA warn of disinformation campaigns about hacked voting systems appeared first on WeLiveSecurity

Ray‑Ban parent company reportedly suffers major ransomware attack

There is no evidence that cybercriminals were also able to steal customer data The post Ray‑Ban parent company reportedly suffers major ransomware attack appeared first on WeLiveSecurity

179 arrested in massive dark web bust

The sting is said to be the US Government’s largest operation targeting crime in the internet’s seedy underbelly The post 179 arrested in massive dark web bust appeared first on WeLiveSecurity

New tool helps companies assess why employees click on phishing emails

NIST’s tool can help organizations improve the testing of their employees’ phish-spotting prowess The post New tool helps companies assess why employees click on phishing emails appeared first on WeLiveSecurity

Mozilla fixes flaw that let attackers hijack Firefox for Android via Wi‑Fi

Attackers could have exploited the flaw to steal victims’ login credentials or install malware on their devices The post Mozilla fixes flaw that let attackers hijack Firefox for Android via Wi‑Fi appeared first on WeLiveSecurity

Plugging in a strange USB drive – What could possibly go wrong?

While wanting to return a found USB flash drive is commendable, you should avoid taking unnecessary risks, lest your device get infested and your data compromised. The post Plugging in a strange USB drive – What could possibly go wrong? appeared first on WeLiveSecurity

Sports data for ransom – it’s not all just fun and games anymore

Sports and training data are more sophisticated and affordable than ever. With the democratization of (sports) performance data, are your personal information safe? The post Sports data for ransom – it’s not all just fun and games anymore appeared first on WeLiveSecurity

Emotet strikes Quebec’s Department of Justice: An ESET Analysis

The cyber attack affects 14 inboxes belonging to the Department of Justice was confirmed by ESET researchers.  The post Emotet strikes Quebec’s Department of Justice: An ESET Analysis appeared first on WeLiveSecurity

Zoom makes 2FA available for all its users

Zoom now supports phone calls, text messages and authentication apps as forms of two-factor authentication   The post Zoom makes 2FA available for all its users appeared first on WeLiveSecurity

Who is calling? CDRThief targets Linux VoIP softswitches

ESET researchers have discovered and analyzed malware that targets Voice over IP (VoIP) softswitches. The post Who is calling? CDRThief targets Linux VoIP softswitches appeared first on WeLiveSecurity

Portland passes the strictest facial recognition technology ban in the US yet 

Oregon’s largest city aims to be a trailblazer when it comes to facial recognition legislation . The post Portland passes the strictest facial recognition technology ban in the US yet  appeared first on WeLiveSecurity

UK University suffers cyberattack, ransomware gang claims responsibility 

The cyber incident has taken most of Newcastle University’s systems offline and officials estimates it will take weeks to recover.  The post UK University suffers cyberattack, ransomware gang claims responsibility  appeared first on WeLiveSecurity

Lead‑offering business booming as usual!

…but there are no conferences or exhibitions??? The post Lead‑offering business booming as usual! appeared first on WeLiveSecurity

TikTok Family Pairing: Curate your children’s content and more

With TikTok being all the rage especially with teens, we look at a feature that gives parents greater control over how their children interact with the app The post TikTok Family Pairing: Curate your children’s content and more appeared first on WeLiveSecurity

Microsoft debuts deepfake detection tool

As the US presidential election nears, the company’s new tech should also help assure people that an image or video is authentic The post Microsoft debuts deepfake detection tool appeared first on WeLiveSecurity

Houseparty – should I stay or should I go now?

What’s the benefit of deleting your Houseparty – or any other unused – account, rather than just uninstalling the app? The post Houseparty – should I stay or should I go now? appeared first on WeLiveSecurity

Norway’s parliament struck by hackers

Unknown threat actors were able to exfiltrate information from the email accounts of several parliamentarians The post Norway’s parliament struck by hackers appeared first on WeLiveSecurity

KryptoCibule: The multitasking multicurrency cryptostealer

ESET researchers analyze a previously undocumented trojan that is spread via malicious torrents and uses multiple tricks to squeeze as many cryptocoins as possible from its victims while staying under the radar The post KryptoCibule: The multitasking multicurrency cryptostealer appeared first on WeLiveSecurity

Security flaw allows bypassing PIN verification on Visa contactless payments

The vulnerability could allow criminals to rack up fraudulent charges on the cards without needing to know the PINs The post Security flaw allows bypassing PIN verification on Visa contactless payments appeared first on WeLiveSecurity

DDoS extortion campaign targets financial firms, retailers

The extortionists attempt to scare the targets into paying by claiming to represent some of the world’s most notorious APT groups The post DDoS extortion campaign targets financial firms, retailers appeared first on WeLiveSecurity

New Chrome, Firefox versions fix security bugs, bring productivity features

Chrome gets a new way of managing tabs while Firefox now features a new add-ons blocklist The post New Chrome, Firefox versions fix security bugs, bring productivity features appeared first on WeLiveSecurity

FBI, CISA warn of spike in vishing attacks

Cybercriminals increasingly take aim at teleworkers, setting up malicious duplicates of companies’ internal VPN login pages The post FBI, CISA warn of spike in vishing attacks appeared first on WeLiveSecurity

Cyber attacks: Several Canadian government services disrupted

Several services from the Canadian government, including the national revenue agency, had to be shut down following a series of credential stuffing cyberattacks. The post Cyber attacks: Several Canadian government services disrupted appeared first on WeLiveSecurity

How to secure your TikTok account

From keeping your account safe to curating who can view your liked content, we look at how you can increase your security and privacy on TikTok The post How to secure your TikTok account appeared first on WeLiveSecurity

How to prepare and protect your digital legacy

It’s never too soon to plan for what will happen to your digital presence after you pass away The post How to prepare and protect your digital legacy appeared first on WeLiveSecurity

Ritz London clients scammed after apparent data breach

Armed with personal data stolen from the hotel’s dining reservation system, fraudsters trick guests into handing over their credit card details The post Ritz London clients scammed after apparent data breach appeared first on WeLiveSecurity

Attack of the Instagram clones

Could your social media account be spoofed, why would anybody do it, and what can you do to avoid having a doppelgänger? The post Attack of the Instagram clones appeared first on WeLiveSecurity

Mekotio: These aren’t the security updates you’re looking for…

Another in our occasional series demystifying Latin American banking trojans The post Mekotio: These aren’t the security updates you’re looking for… appeared first on WeLiveSecurity

What is the cost of a data breach?

The price tag is higher if the incident exposed customer data or if it was the result of a malicious attack, an annual IBM study finds The post What is the cost of a data breach? appeared first on WeLiveSecurity

Twitter working to fix issue with 2FA feature

An apparent glitch is preventing a number of users from signing into their accounts The post Twitter working to fix issue with 2FA feature appeared first on WeLiveSecurity

Black Hat 2020: Fixing voting – boiling the ocean?

With the big voting day rapidly approaching, can the security of the election still be shored up? If so, how? The post Black Hat 2020: Fixing voting – boiling the ocean? appeared first on WeLiveSecurity

Blackbaud data breach: What you should know

Here’s what to be aware of if your personal data was compromised in the breach at the cloud software provider The post Blackbaud data breach: What you should know appeared first on WeLiveSecurity

Beyond KrØØk: Even more Wi‑Fi chips vulnerable to eavesdropping

At Black Hat USA 2020, ESET researchers delved into details about the KrØØk vulnerability in Wi-Fi chips and revealed that similar bugs affect more chip brands than previously thought The post Beyond KrØØk: Even more Wi‑Fi chips vulnerable to eavesdropping appeared first on WeLiveSecurity

NSA shares advice on how to limit location tracking

The intelligence agency warns of location tracking risks and offers tips for how to reduce the amount of data shared The post NSA shares advice on how to limit location tracking appeared first on WeLiveSecurity

FBI warns of surge in online shopping scams

In one scheme, shoppers ordering gadgets or gym equipment are in for a rude surprise – they receive disposable face masks instead The post FBI warns of surge in online shopping scams appeared first on WeLiveSecurity

How much is your personal data worth on the dark web?

The going prices are lower than you probably think – your credit card details, for example, can sell for a few bucks The post How much is your personal data worth on the dark web? appeared first on WeLiveSecurity

ESET Threat Report Q2 2020

A view of the Q2 2020 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report Q2 2020 appeared first on WeLiveSecurity

FBI warns of disruptive DDoS amplification attacks

The Bureau expects cybercriminals to increasingly abuse new threat vectors for large-scale DDoS attacks The post FBI warns of disruptive DDoS amplification attacks appeared first on WeLiveSecurity

Almost 4,000 databases now wiped in ‘Meow’ attacks

The attackers and their motivations remain unknown; however, the incidents yet again highlight the risks of careless data security The post Almost 4,000 databases now wiped in ‘Meow’ attacks appeared first on WeLiveSecurity

Google adds security enhancements to Gmail, Meet and Chat

The tech giant introduces its own version of verified accounts in Gmail, rolls out increased moderation controls in Meet, and enhances phishing protection in Chat The post Google adds security enhancements to Gmail, Meet and Chat appeared first on WeLiveSecurity

Privacy watchdogs urge videoconferencing services to boost privacy protections

The open letter highlights five security and privacy principles that require heightened attention from videoconferencing services The post Privacy watchdogs urge videoconferencing services to boost privacy protections appeared first on WeLiveSecurity

Argentine telecom company hit by major ransomware attack

Telecom Argentina says it has contained the attack and regained access to its systems without paying up The post Argentine telecom company hit by major ransomware attack appeared first on WeLiveSecurity

7 VPN services leaked data of over 20 million users, says report

A report calls into question the providers’ security practices and dismisses their claims of being no-log VPN services The post 7 VPN services leaked data of over 20 million users, says report appeared first on WeLiveSecurity

Data breach reports down by one‑third in first half of 2020

The Identity Theft Resource Center doesn’t expect the trend to last, however The post Data breach reports down by one‑third in first half of 2020 appeared first on WeLiveSecurity

High‑profile Twitter accounts hacked to promote Bitcoin scam

Tech titans and prominent politicians among victims of a sprawling hack that Twitter says leveraged its internal tools The post High‑profile Twitter accounts hacked to promote Bitcoin scam appeared first on WeLiveSecurity

Mac cryptocurrency trading application rebranded, bundled with malware

ESET researchers lure GMERA malware operators to remotely control their Mac honeypots The post Mac cryptocurrency trading application rebranded, bundled with malware appeared first on WeLiveSecurity

Microsoft patches critical, wormable flaw in Windows DNS Server

The company urges organizations to waste no time in installing updates to fix the vulnerability that rates a ‘perfect’ 10 on the severity scale The post Microsoft patches critical, wormable flaw in Windows DNS Server appeared first on WeLiveSecurity

Details of 142 million MGM hotel guests selling for US$2,900

It appears that the July 2019 breach at MGM Resorts affected far more people than initially thought The post Details of 142 million MGM hotel guests selling for US$2,900 appeared first on WeLiveSecurity

Mobile security threats amid COVID‑19 and beyond: A Q&A with Lukas Stefanko

ESET malware researcher Lukas Stefanko gives us a peek behind the scenes of his analysis of CryCryptor ransomware and puts the threat into a broader context The post Mobile security threats amid COVID‑19 and beyond: A Q&A with Lukas Stefanko appeared first on WeLiveSecurity

Welcome Chat as a secure messaging app? Nothing could be further from the truth

ESET research uncovers a malicious operation that both spies on victims and leaks their data The post Welcome Chat as a secure messaging app? Nothing could be further from the truth appeared first on WeLiveSecurity

Zoom patches zero‑day flaw in Windows client

The vulnerability exposed Zoom users running Windows 7 or earlier OS versions to remote attacks The post Zoom patches zero‑day flaw in Windows client appeared first on WeLiveSecurity

Billions of stolen passwords for sale on the dark web

While logins to music and video streaming services sell for less than ten dollars each, domain admin access is being offered for US$120,000 The post Billions of stolen passwords for sale on the dark web appeared first on WeLiveSecurity

More evil: A deep look at Evilnum and its toolset

ESET research gives a detailed picture of the operations of the Evilnum group and its toolkit deployed in attacks against carefully chosen targets in the fintech sector The post More evil: A deep look at Evilnum and its toolset appeared first on WeLiveSecurity

Popular home routers plagued by critical security flaws

A study paints a dim picture of router security, as none of the 127 devices tested was free of severe vulnerabilities The post Popular home routers plagued by critical security flaws appeared first on WeLiveSecurity

Attackers target critical flaw in popular networking gear

The vulnerability, which received the highest possible severity score, leaves thousands of devices at risk of being taken over by remote attackers. A patch is available. The post Attackers target critical flaw in popular networking gear appeared first on WeLiveSecurity

Raising children in the social media limelight? Pause before you post

How (over)sharing your children’s triumphs and antics with the world may impact their immediate and distant future – and how to reduce the risks of ‘sharenting’ The post Raising children in the social media limelight? Pause before you post appeared first on WeLiveSecurity

The Fed shares insight on how to combat synthetic identity fraud

The Federal Reserve looks at ways to counter what is thought to be the fastest-growing type of financial crime in the country The post The Fed shares insight on how to combat synthetic identity fraud appeared first on WeLiveSecurity

Thousands of MongoDB databases ransacked, held for ransom

The cybercriminal behind the ransom raids on almost 23,000 databases threatens to leak the data and alert GDPR regulators The post Thousands of MongoDB databases ransacked, held for ransom appeared first on WeLiveSecurity

Microsoft releases emergency update to fix two serious Windows flaws

The out-of-band update plugs two remote code execution bugs in the Windows Codecs library, including one rated as critical The post Microsoft releases emergency update to fix two serious Windows flaws appeared first on WeLiveSecurity

COVID‑19 contact tracing – technology panacea or privacy nightmare?

Can a technological intervention stem the pandemic while avoiding the privacy pitfalls of location tracking? The post COVID‑19 contact tracing – technology panacea or privacy nightmare? appeared first on WeLiveSecurity

Remote access at risk: Pandemic pulls more cyber‑crooks into the brute‑forcing game

Poorly secured remote access attracts mostly ransomware gangs, but can provide access to coin miners and backdoors too The post Remote access at risk: Pandemic pulls more cyber‑crooks into the brute‑forcing game appeared first on WeLiveSecurity

Facial recognition technology banned in another US city

In a move lauded by privacy advocates, Boston joins the ranks of cities that have voted down the municipal use of the technology The post Facial recognition technology banned in another US city appeared first on WeLiveSecurity

New ransomware posing as COVID‑19 tracing app targets Canada; ESET offers decryptor

ESET researchers dissect an Android app that masquerades as an official COVID-19 contact-tracing app and encrypts files on the victim’s device The post New ransomware posing as COVID‑19 tracing app targets Canada; ESET offers decryptor appeared first on WeLiveSecurity

Majority of new remote employees use their personal laptops for work

And many of them didn’t receive any new security training or tools from their employer to properly secure the devices, a study finds The post Majority of new remote employees use their personal laptops for work appeared first on WeLiveSecurity

Scam uses Elon Musk’s name to trick people out of US$2 million in bitcoin

The giveaway scheme uses the tech titan’s name as part of Bitcoin addresses for extra credibility The post Scam uses Elon Musk’s name to trick people out of US$2 million in bitcoin appeared first on WeLiveSecurity

Digging up InvisiMole’s hidden arsenal

ESET researchers reveal the modus operandi of the elusive InvisiMole group, including newly discovered ties with the Gamaredon group The post Digging up InvisiMole’s hidden arsenal appeared first on WeLiveSecurity

Operation In(ter)ception: Aerospace and military companies in the crosshairs of cyberspies

ESET researchers uncover targeted attacks against high-profile aerospace and military companies The post Operation In(ter)ception: Aerospace and military companies in the crosshairs of cyberspies appeared first on WeLiveSecurity

Ripple20 bugs expose hundreds of millions of devices to attacks

Devices used in the energy, transportation and communications sectors are also affected by the flaws in the TCP/IP software library The post Ripple20 bugs expose hundreds of millions of devices to attacks appeared first on WeLiveSecurity

Survey shows rise in robocalls amid COVID‑19 fears

The unsolicited phone calls tout everything from miracle cures to financial relief – here’s how you can stay safe The post Survey shows rise in robocalls amid COVID‑19 fears appeared first on WeLiveSecurity

Warning issued over hackable security cameras

The owners of the vulnerable indoor cameras are advised to unplug the devices immediately The post Warning issued over hackable security cameras appeared first on WeLiveSecurity

Gamaredon group grows its game

Active APT group adds cunning remote template injectors for Word and Excel documents; unique Outlook mass-mailing macro The post Gamaredon group grows its game appeared first on WeLiveSecurity

Microsoft ships hefty patch load this month

The latest Patch Tuesday knocks out a record-high number of vulnerabilities, including new bugs in the SMB protocol The post Microsoft ships hefty patch load this month appeared first on WeLiveSecurity

Vast hack‑for‑hire scheme targeted thousands of people, organizations

An obscure Indian company operated a scheme targeting banks, non-profits, politicians and journalists all over the world, a report says The post Vast hack‑for‑hire scheme targeted thousands of people, organizations appeared first on WeLiveSecurity

Alarm sounded over security risks in online voting system

Bad actors could tamper with ballots cast via OmniBallot without being detected by voters, election officials or the tool’s developer, a study finds The post Alarm sounded over security risks in online voting system appeared first on WeLiveSecurity

Apple hopes to bolster password security with open source project

The tech giant wants developers of password managers to collaborate for better user experience and security The post Apple hopes to bolster password security with open source project appeared first on WeLiveSecurity

Mozilla fixes high‑risk Firefox flaws, bug in DoH feature

The browser maker rolls out updates on back-to-back days, including a patch to avoid unintentionally overloading DNS providers The post Mozilla fixes high‑risk Firefox flaws, bug in DoH feature appeared first on WeLiveSecurity

Facebook now lets you delete old posts in bulk

Dealing with skeletons lurking in your Facebook closet has never been easier The post Facebook now lets you delete old posts in bulk appeared first on WeLiveSecurity

Google adds Nest devices to Advanced Protection Program

You can now shore up your smart home security by leveraging Google’s top security offering The post Google adds Nest devices to Advanced Protection Program appeared first on WeLiveSecurity

Bug in ‘Sign in with Apple’ could have allowed account hijacking

The tech giant rewards the bug bounty hunter who found the severe flaw in its login mechanism with US$100,000 The post Bug in ‘Sign in with Apple’ could have allowed account hijacking appeared first on WeLiveSecurity