Menu

Category Archives: Security Advisory

Auto Added by WPeMatico

Cybersecurity Trends 2021: Staying secure in uncertain times

ESET experts look back at some of the key themes that defined the cybersecurity landscape in the year that’s ending and give their takes on what to expect in 2021 The post Cybersecurity Trends 2021: Staying secure in uncertain times appeared first on WeLiveSecurity

iPhone hack allowed device takeover via Wi‑Fi

Using a zero-click exploit, an attacker could have taken complete control of any iPhone within Wi-Fi range in seconds The post iPhone hack allowed device takeover via Wi‑Fi appeared first on WeLiveSecurity

Turla Crutch: Keeping the “back door” open

ESET researchers discover a new backdoor used by Turla to exfiltrate stolen documents to Dropbox The post Turla Crutch: Keeping the “back door” open appeared first on WeLiveSecurity

Cyberattackers could trick scientists into producing dangerous substances

Without ever setting foot in the lab, a threat actor could dupe DNA researchers into creating pathogens, according to a study describing “an end-to-end cyber-biological attack” The post Cyberattackers could trick scientists into producing dangerous substances appeared first on WeLiveSecurity

Mobile payment apps: How to stay safe when paying with your phone

Are mobile payments and digital wallets safe? Are the apps safer than credit cards? What are the main risks? Here’s what to know. The post Mobile payment apps: How to stay safe when paying with your phone appeared first on WeLiveSecurity

FBI warns of threat actors spoofing Bureau domains, email accounts

The U.S. law enforcement agency shares a sampling of more than 90 spoofed FBI-related domains registered recently The post FBI warns of threat actors spoofing Bureau domains, email accounts appeared first on WeLiveSecurity

SIM swap scam: What it is and how to protect yourself

Here’s what to know about attacks where a fraudster has your number, literally and otherwise The post SIM swap scam: What it is and how to protect yourself appeared first on WeLiveSecurity

Up to 350,000 Spotify accounts hacked in credential stuffing attacks

This won’t be music to your ears – researchers spot an unsecured database replete with records used for an account hijacking spree The post Up to 350,000 Spotify accounts hacked in credential stuffing attacks appeared first on WeLiveSecurity

Security flaws in smart doorbells may open the door to hackers

The peace of mind that comes with connected home security gadgets may be false – your smart doorbell may make an inviting target for unwanted visitors The post Security flaws in smart doorbells may open the door to hackers appeared first on WeLiveSecurity

The worst passwords of 2020: Is it time to change yours?

They’re supremely easy to remember, as well as easy to crack. Here’s how to improve your password security. The post The worst passwords of 2020: Is it time to change yours? appeared first on WeLiveSecurity

Bumble bugs could have exposed personal data of all users

The information at risk of theft due to API flaws included people’s pictures, locations, dating preferences and Facebook data The post Bumble bugs could have exposed personal data of all users appeared first on WeLiveSecurity

Lazarus supply‑chain attack in South Korea

ESET researchers uncover a novel Lazarus supply-chain attack leveraging WIZVERA VeraPort software The post Lazarus supply‑chain attack in South Korea appeared first on WeLiveSecurity

Google patches two new zero‑day flaws in Chrome

The last three weeks have seen a bumper crop of patches for zero-day bugs across software from Google, Apple and Microsoft The post Google patches two new zero‑day flaws in Chrome appeared first on WeLiveSecurity

Hungry for data, ModPipe backdoor hits POS software used in hospitality sector

Backdoor authors show deep knowledge of the targeted POS software, decrypting database passwords from Windows registry values The post Hungry for data, ModPipe backdoor hits POS software used in hospitality sector appeared first on WeLiveSecurity

Microsoft Patch Tuesday fixes 17 critical flaws, Windows zero‑day

The second Tuesday of the month brings another fresh batch of fixes for security vulnerabilities in various Microsoft products The post Microsoft Patch Tuesday fixes 17 critical flaws, Windows zero‑day appeared first on WeLiveSecurity

Why you should keep your Netflix password to yourself

Sharing is caring – except when it isn’t. Here’s why you shouldn’t share your password for online media services with other people. The post Why you should keep your Netflix password to yourself appeared first on WeLiveSecurity

Data on millions of hotel guests exposed in cloud storage leak

The cache of data sitting wide open on a server included full names, national ID numbers and credit card data The post Data on millions of hotel guests exposed in cloud storage leak appeared first on WeLiveSecurity

Gaming company Capcom hit by cyberattack

The developer of popular video game franchises took swift action to prevent the attack from spreading further across its systems The post Gaming company Capcom hit by cyberattack appeared first on WeLiveSecurity

A career in cybersecurity: Is it for you?

There’s no shortage of opportunities for cybersecurity professionals and people looking to break into this field of endeavor. Could this also be the right career path for you? The post A career in cybersecurity: Is it for you? appeared first on WeLiveSecurity

Google squashes two more Chrome bugs under active attacks

The updates come on the heels of news of attacks exploiting another zero-day in Chrome in tandem with a previously-unknown Windows flaw The post Google squashes two more Chrome bugs under active attacks appeared first on WeLiveSecurity

Google discloses Windows zero‑day bug exploited in the wild

The security hole isn’t expected to be plugged until the forthcoming Patch Tuesday bundle of security fixes The post Google discloses Windows zero‑day bug exploited in the wild appeared first on WeLiveSecurity

IoT security: Are we finally turning the corner?

Better IoT security and data protection are long overdue. Will they go from an afterthought to everyone’s priority any time soon? The post IoT security: Are we finally turning the corner? appeared first on WeLiveSecurity

Over 100,000 machines remain vulnerable to SMBGhost exploitation

The patch for the critical flaw that allows malware to spread across machines without any user interaction was released months ago The post Over 100,000 machines remain vulnerable to SMBGhost exploitation appeared first on WeLiveSecurity

ESET Threat Report Q3 2020

A view of the Q3 2020 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report Q3 2020 appeared first on WeLiveSecurity

‘Among Us’ players hit by major spam attack

In-game chats were flooded with messages from somebody who tried to coerce players into subscribing to a dubious YouTube channel The post ‘Among Us’ players hit by major spam attack appeared first on WeLiveSecurity

Fraudsters crave loyalty points amid COVID‑19

Scammers even run their own dark-web “travel agencies”, misusing stolen loyalty points and credit card numbers The post Fraudsters crave loyalty points amid COVID‑19 appeared first on WeLiveSecurity

Securing medical devices: Can a hacker break your heart?

Why are connected medical devices vulnerable to attack and how likely are they to get hacked? Here are five digital chinks in the armor. The post Securing medical devices: Can a hacker break your heart? appeared first on WeLiveSecurity

Google patches Chrome zero‑day under attack

In addition to patching the actively exploited bug, the update also brings fixes for another four security loopholes The post Google patches Chrome zero‑day under attack appeared first on WeLiveSecurity

How safe is your USB drive?

What are some of the key security risks to be aware of when using USB flash drives and how can you mitigate the threats? The post How safe is your USB drive? appeared first on WeLiveSecurity

Microsoft issues two emergency Windows patches

The flaws, neither of which is being actively exploited, were fixed merely days after the monthly Patch Tuesday rollout The post Microsoft issues two emergency Windows patches appeared first on WeLiveSecurity

Zoom to begin rolling out end‑to‑end encryption

The videoconferencing platform is making the feature available to users of both free and paid tiers The post Zoom to begin rolling out end‑to‑end encryption appeared first on WeLiveSecurity

50,000 home cameras reportedly hacked, footage posted online

Some footage has already appeared on adult sites, with cybercriminals offering lifetime access to the entire loot for US$150 The post 50,000 home cameras reportedly hacked, footage posted online appeared first on WeLiveSecurity

Attackers chain Windows, VPN flaws to target US government agencies

Bad actors have accessed US elections support systems, although there’s no evidence to suggest that election data has been compromised, say FBI and CISA The post Attackers chain Windows, VPN flaws to target US government agencies appeared first on WeLiveSecurity

ESET takes part in global operation to disrupt Trickbot

Throughout its monitoring, ESET analyzed thousands of malicious samples every month to help this effort The post ESET takes part in global operation to disrupt Trickbot appeared first on WeLiveSecurity

Google adds password breach alerts to Chrome for Android, iOS

The feature is part of the browser’s security improvements that were first built into its desktop version The post Google adds password breach alerts to Chrome for Android, iOS appeared first on WeLiveSecurity

Working from a hotel? Beware the dangers of public Wi‑Fi

As more and more hotels are turning rooms into offices, the FBI is warning remote workers of cyber-threats lurking in the shadows The post Working from a hotel? Beware the dangers of public Wi‑Fi appeared first on WeLiveSecurity

Had your face stolen lately?

It’s easy to reset your password or PIN after a data breach. But reset your face? Not so much. The post Had your face stolen lately? appeared first on WeLiveSecurity

US gov’t warns against paying off ransomware attackers

Companies facilitating ransomware payments run the risk of facing stern penalties for violating US regulations The post US gov’t warns against paying off ransomware attackers appeared first on WeLiveSecurity

5 steps to secure your connected devices

As we steadily adopt smart devices into our lives, we shouldn’t forget about keeping them secured and our data protected The post 5 steps to secure your connected devices appeared first on WeLiveSecurity

Cyber Security Awareness Month is here!

A month teaching us that when everyone pitches in and does their part, then almost everyone is protected The post Cyber Security Awareness Month is here! appeared first on WeLiveSecurity

LATAM financial cybercrime: Competitors‑in‑crime sharing TTPs

ESET researchers discover surprisingly many indicators of close cooperation among Latin American banking trojans’ authors The post LATAM financial cybercrime: Competitors‑in‑crime sharing TTPs appeared first on WeLiveSecurity

Microsoft 365 services back online after hours‑long outage

Microsoft resolves a service disruption that affected Office 365, Outlook.com, Teams and other cloud-based services The post Microsoft 365 services back online after hours‑long outage appeared first on WeLiveSecurity

APT‑C‑23 group evolves its Android spyware

ESET researchers uncover a new version of Android spyware used by the APT-C-23 threat group against targets in the Middle East The post APT‑C‑23 group evolves its Android spyware appeared first on WeLiveSecurity

FBI, CISA warn of disinformation campaigns about hacked voting systems

Threat actors may spread false claims about compromised voting systems in order to undermine confidence in the electoral process The post FBI, CISA warn of disinformation campaigns about hacked voting systems appeared first on WeLiveSecurity

Ray‑Ban parent company reportedly suffers major ransomware attack

There is no evidence that cybercriminals were also able to steal customer data The post Ray‑Ban parent company reportedly suffers major ransomware attack appeared first on WeLiveSecurity

179 arrested in massive dark web bust

The sting is said to be the US Government’s largest operation targeting crime in the internet’s seedy underbelly The post 179 arrested in massive dark web bust appeared first on WeLiveSecurity

New tool helps companies assess why employees click on phishing emails

NIST’s tool can help organizations improve the testing of their employees’ phish-spotting prowess The post New tool helps companies assess why employees click on phishing emails appeared first on WeLiveSecurity

Mozilla fixes flaw that let attackers hijack Firefox for Android via Wi‑Fi

Attackers could have exploited the flaw to steal victims’ login credentials or install malware on their devices The post Mozilla fixes flaw that let attackers hijack Firefox for Android via Wi‑Fi appeared first on WeLiveSecurity

Plugging in a strange USB drive – What could possibly go wrong?

While wanting to return a found USB flash drive is commendable, you should avoid taking unnecessary risks, lest your device get infested and your data compromised. The post Plugging in a strange USB drive – What could possibly go wrong? appeared first on WeLiveSecurity

Sports data for ransom – it’s not all just fun and games anymore

Sports and training data are more sophisticated and affordable than ever. With the democratization of (sports) performance data, are your personal information safe? The post Sports data for ransom – it’s not all just fun and games anymore appeared first on WeLiveSecurity

Emotet strikes Quebec’s Department of Justice: An ESET Analysis

The cyber attack affects 14 inboxes belonging to the Department of Justice was confirmed by ESET researchers.  The post Emotet strikes Quebec’s Department of Justice: An ESET Analysis appeared first on WeLiveSecurity

Zoom makes 2FA available for all its users

Zoom now supports phone calls, text messages and authentication apps as forms of two-factor authentication   The post Zoom makes 2FA available for all its users appeared first on WeLiveSecurity

Who is calling? CDRThief targets Linux VoIP softswitches

ESET researchers have discovered and analyzed malware that targets Voice over IP (VoIP) softswitches. The post Who is calling? CDRThief targets Linux VoIP softswitches appeared first on WeLiveSecurity

Portland passes the strictest facial recognition technology ban in the US yet 

Oregon’s largest city aims to be a trailblazer when it comes to facial recognition legislation . The post Portland passes the strictest facial recognition technology ban in the US yet  appeared first on WeLiveSecurity

UK University suffers cyberattack, ransomware gang claims responsibility 

The cyber incident has taken most of Newcastle University’s systems offline and officials estimates it will take weeks to recover.  The post UK University suffers cyberattack, ransomware gang claims responsibility  appeared first on WeLiveSecurity

Lead‑offering business booming as usual!

…but there are no conferences or exhibitions??? The post Lead‑offering business booming as usual! appeared first on WeLiveSecurity

TikTok Family Pairing: Curate your children’s content and more

With TikTok being all the rage especially with teens, we look at a feature that gives parents greater control over how their children interact with the app The post TikTok Family Pairing: Curate your children’s content and more appeared first on WeLiveSecurity

Microsoft debuts deepfake detection tool

As the US presidential election nears, the company’s new tech should also help assure people that an image or video is authentic The post Microsoft debuts deepfake detection tool appeared first on WeLiveSecurity

Houseparty – should I stay or should I go now?

What’s the benefit of deleting your Houseparty – or any other unused – account, rather than just uninstalling the app? The post Houseparty – should I stay or should I go now? appeared first on WeLiveSecurity

Norway’s parliament struck by hackers

Unknown threat actors were able to exfiltrate information from the email accounts of several parliamentarians The post Norway’s parliament struck by hackers appeared first on WeLiveSecurity

KryptoCibule: The multitasking multicurrency cryptostealer

ESET researchers analyze a previously undocumented trojan that is spread via malicious torrents and uses multiple tricks to squeeze as many cryptocoins as possible from its victims while staying under the radar The post KryptoCibule: The multitasking multicurrency cryptostealer appeared first on WeLiveSecurity

Security flaw allows bypassing PIN verification on Visa contactless payments

The vulnerability could allow criminals to rack up fraudulent charges on the cards without needing to know the PINs The post Security flaw allows bypassing PIN verification on Visa contactless payments appeared first on WeLiveSecurity

DDoS extortion campaign targets financial firms, retailers

The extortionists attempt to scare the targets into paying by claiming to represent some of the world’s most notorious APT groups The post DDoS extortion campaign targets financial firms, retailers appeared first on WeLiveSecurity

New Chrome, Firefox versions fix security bugs, bring productivity features

Chrome gets a new way of managing tabs while Firefox now features a new add-ons blocklist The post New Chrome, Firefox versions fix security bugs, bring productivity features appeared first on WeLiveSecurity

FBI, CISA warn of spike in vishing attacks

Cybercriminals increasingly take aim at teleworkers, setting up malicious duplicates of companies’ internal VPN login pages The post FBI, CISA warn of spike in vishing attacks appeared first on WeLiveSecurity

Cyber attacks: Several Canadian government services disrupted

Several services from the Canadian government, including the national revenue agency, had to be shut down following a series of credential stuffing cyberattacks. The post Cyber attacks: Several Canadian government services disrupted appeared first on WeLiveSecurity

How to secure your TikTok account

From keeping your account safe to curating who can view your liked content, we look at how you can increase your security and privacy on TikTok The post How to secure your TikTok account appeared first on WeLiveSecurity

How to prepare and protect your digital legacy

It’s never too soon to plan for what will happen to your digital presence after you pass away The post How to prepare and protect your digital legacy appeared first on WeLiveSecurity

Ritz London clients scammed after apparent data breach

Armed with personal data stolen from the hotel’s dining reservation system, fraudsters trick guests into handing over their credit card details The post Ritz London clients scammed after apparent data breach appeared first on WeLiveSecurity

Attack of the Instagram clones

Could your social media account be spoofed, why would anybody do it, and what can you do to avoid having a doppelgänger? The post Attack of the Instagram clones appeared first on WeLiveSecurity

Mekotio: These aren’t the security updates you’re looking for…

Another in our occasional series demystifying Latin American banking trojans The post Mekotio: These aren’t the security updates you’re looking for… appeared first on WeLiveSecurity

What is the cost of a data breach?

The price tag is higher if the incident exposed customer data or if it was the result of a malicious attack, an annual IBM study finds The post What is the cost of a data breach? appeared first on WeLiveSecurity

Twitter working to fix issue with 2FA feature

An apparent glitch is preventing a number of users from signing into their accounts The post Twitter working to fix issue with 2FA feature appeared first on WeLiveSecurity

Black Hat 2020: Fixing voting – boiling the ocean?

With the big voting day rapidly approaching, can the security of the election still be shored up? If so, how? The post Black Hat 2020: Fixing voting – boiling the ocean? appeared first on WeLiveSecurity

Blackbaud data breach: What you should know

Here’s what to be aware of if your personal data was compromised in the breach at the cloud software provider The post Blackbaud data breach: What you should know appeared first on WeLiveSecurity

Beyond KrØØk: Even more Wi‑Fi chips vulnerable to eavesdropping

At Black Hat USA 2020, ESET researchers delved into details about the KrØØk vulnerability in Wi-Fi chips and revealed that similar bugs affect more chip brands than previously thought The post Beyond KrØØk: Even more Wi‑Fi chips vulnerable to eavesdropping appeared first on WeLiveSecurity

NSA shares advice on how to limit location tracking

The intelligence agency warns of location tracking risks and offers tips for how to reduce the amount of data shared The post NSA shares advice on how to limit location tracking appeared first on WeLiveSecurity

FBI warns of surge in online shopping scams

In one scheme, shoppers ordering gadgets or gym equipment are in for a rude surprise – they receive disposable face masks instead The post FBI warns of surge in online shopping scams appeared first on WeLiveSecurity

How much is your personal data worth on the dark web?

The going prices are lower than you probably think – your credit card details, for example, can sell for a few bucks The post How much is your personal data worth on the dark web? appeared first on WeLiveSecurity

ESET Threat Report Q2 2020

A view of the Q2 2020 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report Q2 2020 appeared first on WeLiveSecurity

FBI warns of disruptive DDoS amplification attacks

The Bureau expects cybercriminals to increasingly abuse new threat vectors for large-scale DDoS attacks The post FBI warns of disruptive DDoS amplification attacks appeared first on WeLiveSecurity

Almost 4,000 databases now wiped in ‘Meow’ attacks

The attackers and their motivations remain unknown; however, the incidents yet again highlight the risks of careless data security The post Almost 4,000 databases now wiped in ‘Meow’ attacks appeared first on WeLiveSecurity

Google adds security enhancements to Gmail, Meet and Chat

The tech giant introduces its own version of verified accounts in Gmail, rolls out increased moderation controls in Meet, and enhances phishing protection in Chat The post Google adds security enhancements to Gmail, Meet and Chat appeared first on WeLiveSecurity

Privacy watchdogs urge videoconferencing services to boost privacy protections

The open letter highlights five security and privacy principles that require heightened attention from videoconferencing services The post Privacy watchdogs urge videoconferencing services to boost privacy protections appeared first on WeLiveSecurity

Argentine telecom company hit by major ransomware attack

Telecom Argentina says it has contained the attack and regained access to its systems without paying up The post Argentine telecom company hit by major ransomware attack appeared first on WeLiveSecurity

7 VPN services leaked data of over 20 million users, says report

A report calls into question the providers’ security practices and dismisses their claims of being no-log VPN services The post 7 VPN services leaked data of over 20 million users, says report appeared first on WeLiveSecurity

Data breach reports down by one‑third in first half of 2020

The Identity Theft Resource Center doesn’t expect the trend to last, however The post Data breach reports down by one‑third in first half of 2020 appeared first on WeLiveSecurity

High‑profile Twitter accounts hacked to promote Bitcoin scam

Tech titans and prominent politicians among victims of a sprawling hack that Twitter says leveraged its internal tools The post High‑profile Twitter accounts hacked to promote Bitcoin scam appeared first on WeLiveSecurity

Mac cryptocurrency trading application rebranded, bundled with malware

ESET researchers lure GMERA malware operators to remotely control their Mac honeypots The post Mac cryptocurrency trading application rebranded, bundled with malware appeared first on WeLiveSecurity

Microsoft patches critical, wormable flaw in Windows DNS Server

The company urges organizations to waste no time in installing updates to fix the vulnerability that rates a ‘perfect’ 10 on the severity scale The post Microsoft patches critical, wormable flaw in Windows DNS Server appeared first on WeLiveSecurity

Details of 142 million MGM hotel guests selling for US$2,900

It appears that the July 2019 breach at MGM Resorts affected far more people than initially thought The post Details of 142 million MGM hotel guests selling for US$2,900 appeared first on WeLiveSecurity

Mobile security threats amid COVID‑19 and beyond: A Q&A with Lukas Stefanko

ESET malware researcher Lukas Stefanko gives us a peek behind the scenes of his analysis of CryCryptor ransomware and puts the threat into a broader context The post Mobile security threats amid COVID‑19 and beyond: A Q&A with Lukas Stefanko appeared first on WeLiveSecurity

Welcome Chat as a secure messaging app? Nothing could be further from the truth

ESET research uncovers a malicious operation that both spies on victims and leaks their data The post Welcome Chat as a secure messaging app? Nothing could be further from the truth appeared first on WeLiveSecurity

Zoom patches zero‑day flaw in Windows client

The vulnerability exposed Zoom users running Windows 7 or earlier OS versions to remote attacks The post Zoom patches zero‑day flaw in Windows client appeared first on WeLiveSecurity

Billions of stolen passwords for sale on the dark web

While logins to music and video streaming services sell for less than ten dollars each, domain admin access is being offered for US$120,000 The post Billions of stolen passwords for sale on the dark web appeared first on WeLiveSecurity

More evil: A deep look at Evilnum and its toolset

ESET research gives a detailed picture of the operations of the Evilnum group and its toolkit deployed in attacks against carefully chosen targets in the fintech sector The post More evil: A deep look at Evilnum and its toolset appeared first on WeLiveSecurity

Popular home routers plagued by critical security flaws

A study paints a dim picture of router security, as none of the 127 devices tested was free of severe vulnerabilities The post Popular home routers plagued by critical security flaws appeared first on WeLiveSecurity

Attackers target critical flaw in popular networking gear

The vulnerability, which received the highest possible severity score, leaves thousands of devices at risk of being taken over by remote attackers. A patch is available. The post Attackers target critical flaw in popular networking gear appeared first on WeLiveSecurity

Raising children in the social media limelight? Pause before you post

How (over)sharing your children’s triumphs and antics with the world may impact their immediate and distant future – and how to reduce the risks of ‘sharenting’ The post Raising children in the social media limelight? Pause before you post appeared first on WeLiveSecurity

The Fed shares insight on how to combat synthetic identity fraud

The Federal Reserve looks at ways to counter what is thought to be the fastest-growing type of financial crime in the country The post The Fed shares insight on how to combat synthetic identity fraud appeared first on WeLiveSecurity