Menu

Category Archives: Security Advisory

Auto Added by WPeMatico

Thousands of MongoDB databases ransacked, held for ransom

The cybercriminal behind the ransom raids on almost 23,000 databases threatens to leak the data and alert GDPR regulators The post Thousands of MongoDB databases ransacked, held for ransom appeared first on WeLiveSecurity

Microsoft releases emergency update to fix two serious Windows flaws

The out-of-band update plugs two remote code execution bugs in the Windows Codecs library, including one rated as critical The post Microsoft releases emergency update to fix two serious Windows flaws appeared first on WeLiveSecurity

COVID‑19 contact tracing – technology panacea or privacy nightmare?

Can a technological intervention stem the pandemic while avoiding the privacy pitfalls of location tracking? The post COVID‑19 contact tracing – technology panacea or privacy nightmare? appeared first on WeLiveSecurity

Remote access at risk: Pandemic pulls more cyber‑crooks into the brute‑forcing game

Poorly secured remote access attracts mostly ransomware gangs, but can provide access to coin miners and backdoors too The post Remote access at risk: Pandemic pulls more cyber‑crooks into the brute‑forcing game appeared first on WeLiveSecurity

Facial recognition technology banned in another US city

In a move lauded by privacy advocates, Boston joins the ranks of cities that have voted down the municipal use of the technology The post Facial recognition technology banned in another US city appeared first on WeLiveSecurity

New ransomware posing as COVID‑19 tracing app targets Canada; ESET offers decryptor

ESET researchers dissect an Android app that masquerades as an official COVID-19 contact-tracing app and encrypts files on the victim’s device The post New ransomware posing as COVID‑19 tracing app targets Canada; ESET offers decryptor appeared first on WeLiveSecurity

Majority of new remote employees use their personal laptops for work

And many of them didn’t receive any new security training or tools from their employer to properly secure the devices, a study finds The post Majority of new remote employees use their personal laptops for work appeared first on WeLiveSecurity

Scam uses Elon Musk’s name to trick people out of US$2 million in bitcoin

The giveaway scheme uses the tech titan’s name as part of Bitcoin addresses for extra credibility The post Scam uses Elon Musk’s name to trick people out of US$2 million in bitcoin appeared first on WeLiveSecurity

Digging up InvisiMole’s hidden arsenal

ESET researchers reveal the modus operandi of the elusive InvisiMole group, including newly discovered ties with the Gamaredon group The post Digging up InvisiMole’s hidden arsenal appeared first on WeLiveSecurity

Operation In(ter)ception: Aerospace and military companies in the crosshairs of cyberspies

ESET researchers uncover targeted attacks against high-profile aerospace and military companies The post Operation In(ter)ception: Aerospace and military companies in the crosshairs of cyberspies appeared first on WeLiveSecurity

Ripple20 bugs expose hundreds of millions of devices to attacks

Devices used in the energy, transportation and communications sectors are also affected by the flaws in the TCP/IP software library The post Ripple20 bugs expose hundreds of millions of devices to attacks appeared first on WeLiveSecurity

Survey shows rise in robocalls amid COVID‑19 fears

The unsolicited phone calls tout everything from miracle cures to financial relief – here’s how you can stay safe The post Survey shows rise in robocalls amid COVID‑19 fears appeared first on WeLiveSecurity

Warning issued over hackable security cameras

The owners of the vulnerable indoor cameras are advised to unplug the devices immediately The post Warning issued over hackable security cameras appeared first on WeLiveSecurity

Gamaredon group grows its game

Active APT group adds cunning remote template injectors for Word and Excel documents; unique Outlook mass-mailing macro The post Gamaredon group grows its game appeared first on WeLiveSecurity

Microsoft ships hefty patch load this month

The latest Patch Tuesday knocks out a record-high number of vulnerabilities, including new bugs in the SMB protocol The post Microsoft ships hefty patch load this month appeared first on WeLiveSecurity

Vast hack‑for‑hire scheme targeted thousands of people, organizations

An obscure Indian company operated a scheme targeting banks, non-profits, politicians and journalists all over the world, a report says The post Vast hack‑for‑hire scheme targeted thousands of people, organizations appeared first on WeLiveSecurity

Alarm sounded over security risks in online voting system

Bad actors could tamper with ballots cast via OmniBallot without being detected by voters, election officials or the tool’s developer, a study finds The post Alarm sounded over security risks in online voting system appeared first on WeLiveSecurity

Apple hopes to bolster password security with open source project

The tech giant wants developers of password managers to collaborate for better user experience and security The post Apple hopes to bolster password security with open source project appeared first on WeLiveSecurity

Mozilla fixes high‑risk Firefox flaws, bug in DoH feature

The browser maker rolls out updates on back-to-back days, including a patch to avoid unintentionally overloading DNS providers The post Mozilla fixes high‑risk Firefox flaws, bug in DoH feature appeared first on WeLiveSecurity

Facebook now lets you delete old posts in bulk

Dealing with skeletons lurking in your Facebook closet has never been easier The post Facebook now lets you delete old posts in bulk appeared first on WeLiveSecurity

Google adds Nest devices to Advanced Protection Program

You can now shore up your smart home security by leveraging Google’s top security offering The post Google adds Nest devices to Advanced Protection Program appeared first on WeLiveSecurity

Bug in ‘Sign in with Apple’ could have allowed account hijacking

The tech giant rewards the bug bounty hunter who found the severe flaw in its login mechanism with US$100,000 The post Bug in ‘Sign in with Apple’ could have allowed account hijacking appeared first on WeLiveSecurity

3 things to discuss with your kids before they join social media

What are some of the key things your children should know about before they make their first foray into social media? The post 3 things to discuss with your kids before they join social media appeared first on WeLiveSecurity

People know reusing passwords is risky – then do it anyway

And most people don’t change their password even after hearing about a breach, a survey finds The post People know reusing passwords is risky – then do it anyway appeared first on WeLiveSecurity

Critical Android flaw lets attackers hijack almost any app, steal data

Left unpatched, the vulnerability could expose almost all Android users to the risk of having their personal data intercepted by attackers The post Critical Android flaw lets attackers hijack almost any app, steal data appeared first on WeLiveSecurity

From Agent.BTZ to ComRAT v4: A ten‑year journey

Turla has updated its ComRAT backdoor and now uses the Gmail web interface for Command and Control The post From Agent.BTZ to ComRAT v4: A ten‑year journey appeared first on WeLiveSecurity

Crooks threaten to leak customer data stolen from e‑commerce sites

A hack-and-extort campaign takes aim at poorly secured databases replete with customer information that can be exploited for further attacks The post Crooks threaten to leak customer data stolen from e‑commerce sites appeared first on WeLiveSecurity

Two years later, has GDPR fulfilled its promise?

Has the landmark law helped build a culture of privacy in organizations and have consumers become more wary of sharing their personal data? The post Two years later, has GDPR fulfilled its promise? appeared first on WeLiveSecurity

Chrome 83 arrives with enhanced security and privacy controls

New features include DNS over HTTPS, a Safety Check section and simpler cookie management The post Chrome 83 arrives with enhanced security and privacy controls appeared first on WeLiveSecurity

No “Game over” for the Winnti Group

The notorious APT group continues to play the video game industry with yet another backdoor The post No “Game over” for the Winnti Group appeared first on WeLiveSecurity

These things may be cool, but are they safe?

In the rush to embrace IoT devices, we shouldn’t trade in our privacy and security for the added convenience The post These things may be cool, but are they safe? appeared first on WeLiveSecurity

Bluetooth flaw exposes countless devices to BIAS attacks

As many as 30 smartphones, laptops and other devices were tested – and all were found to be vulnerable The post Bluetooth flaw exposes countless devices to BIAS attacks appeared first on WeLiveSecurity

European supercomputers hacked to mine cryptocurrency

Several high-performance computers working on COVID-19 research have been forced offline following a string of attacks The post European supercomputers hacked to mine cryptocurrency appeared first on WeLiveSecurity

Mikroceen: Spying backdoor leveraged in high‑profile networks in Central Asia

ESET researchers dissect a backdoor deployed in attacks against multiple government agencies and major organizations operating in two critical infrastructure sectors in Asia The post Mikroceen: Spying backdoor leveraged in high‑profile networks in Central Asia appeared first on WeLiveSecurity

Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks

ESET researchers uncover several instances of malware that uses various attack vectors to target systems isolated by an air gap The post Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks appeared first on WeLiveSecurity

WannaCryptor remains a global threat three years on

WannaCryptor is still alive and kicking, so much so that it sits atop the list of the most commonly detected ransomware families The post WannaCryptor remains a global threat three years on appeared first on WeLiveSecurity

Lukas Stefanko: How we fought off a DDoS attack from a mobile botnet

Hot on the heels of his research into an attack that attempted to take down ESET’s website, Lukas Stefanko sheds more light on threats posed by mobile botnets The post Lukas Stefanko: How we fought off a DDoS attack from a mobile botnet appeared first on WeLiveSecurity

Thunderbolt flaws open millions of PCs to physical hacking

A new attack method enables bad actors to access data on a locked computer via an evil maid attack within 5 minutes The post Thunderbolt flaws open millions of PCs to physical hacking appeared first on WeLiveSecurity

Over 160 million user records put up for sale on the dark web

Eleven companies, ranging from online marketplaces to news websites, have had their user databases poached The post Over 160 million user records put up for sale on the dark web appeared first on WeLiveSecurity

Breaking news? App promises news feeds, brings DDoS attacks instead

After being targeted by an Android DDoS app, ESET seized the opportunity to analyze the attack and to help put an end to it The post Breaking news? App promises news feeds, brings DDoS attacks instead appeared first on WeLiveSecurity

Digital transformation could be accelerated by COVID‑19

The pandemic has highlighted the need for businesses to act with alacrity and prepare for the long haul – and to do so with cybersecurity in mind The post Digital transformation could be accelerated by COVID‑19 appeared first on WeLiveSecurity

5 common password mistakes you should avoid

Password recycling or using easy-to-guess passwords are just two common mistakes you may be making when protecting your digital accounts The post 5 common password mistakes you should avoid appeared first on WeLiveSecurity

Almost a million WordPress websites targeted in massive campaign

An unknown threat actor is exploiting vulnerabilities in plugins for which patches have been available for months, or even years The post Almost a million WordPress websites targeted in massive campaign appeared first on WeLiveSecurity

Professional data leakage: How did that security vendor get my personal data?

…and why are they selling it to other security vendors and product testers? The post Professional data leakage: How did that security vendor get my personal data? appeared first on WeLiveSecurity

Ghost blogging platform servers hacked to mine cryptocurrency

Ghost wasn’t the only victim of break-ins over the weekend that exploited critical holes in infrastructure automation software for which patches were available The post Ghost blogging platform servers hacked to mine cryptocurrency appeared first on WeLiveSecurity

Sextortion scammers still shilling with stolen passwords

The email includes the potential victim’s password as evidence of a hack, but there is more than meets the eye The post Sextortion scammers still shilling with stolen passwords appeared first on WeLiveSecurity

ESET Threat Report

A view of the Q1 2020 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report appeared first on WeLiveSecurity

Grandoreiro: How engorged can an EXE get?

Another in our occasional series demystifying Latin American banking trojans The post Grandoreiro: How engorged can an EXE get? appeared first on WeLiveSecurity

Microsoft Teams flaw could let attackers hijack accounts

Microsoft plugs a security hole that could have enabled attackers to weaponize a GIF in order to hijack Teams accounts and steal data The post Microsoft Teams flaw could let attackers hijack accounts appeared first on WeLiveSecurity

Following ESET’s discovery, a Monero mining botnet is disrupted

ESET researchers discover, and play a key role in the disruption of, a 35,000-strong botnet spreading in Latin America via infected USB drives The post Following ESET’s discovery, a Monero mining botnet is disrupted appeared first on WeLiveSecurity

iOS Mail app flaws may have left iPhone users vulnerable for years

A pair of vulnerabilities in the default email app on iOS devices is believed to have been exploited against high-profile targets The post iOS Mail app flaws may have left iPhone users vulnerable for years appeared first on WeLiveSecurity

Buying a secondhand device? Here’s what to keep in mind

If you’re trying to be responsible towards the planet, also be responsible to yourself and take these steps so that the device doesn’t end up costing you more than you’ve saved The post Buying a secondhand device? Here’s what to keep in mind appeared first on WeLiveSecurity

Serious flaws found in multiple smart home hubs: Is your device among them?

In worst-case scenarios, some vulnerabilities could even allow attackers to take control over the central units and all peripheral devices connected to them The post Serious flaws found in multiple smart home hubs: Is your device among them? appeared first on WeLiveSecurity

How gamification can boost your cybersecurity training

Security is not a game, but learning about it could be – here’s why adding the fun factor can help employees become more cyber-aware The post How gamification can boost your cybersecurity training appeared first on WeLiveSecurity

Work from home: Should your digital assistant be on or off?

Being at your beck and call is central to the “personality” of your digital friend, but there are situations when the device could use some time off The post Work from home: Should your digital assistant be on or off? appeared first on WeLiveSecurity

Hey there! Are you using WhatsApp? Your account may be hackable

Can someone take control of your WhatsApp account by just knowing your phone number? We ran a small test to find out. The post Hey there! Are you using WhatsApp? Your account may be hackable appeared first on WeLiveSecurity

Americans report US$13 million in losses from coronavirus scams

The median loss to fraudulent schemes that exploit the global health crisis is almost US$600 The post Americans report US$13 million in losses from coronavirus scams appeared first on WeLiveSecurity

Is “global privacy” an oxymoron?

While in France, a citizen of Brazil who resides in California books a bungee jump in New Zealand. Is it a leap of faith into the unknown, for both the operator and the thrill-seeker? The post Is “global privacy” an oxymoron? appeared first on WeLiveSecurity

Top tips for videoconferencing security

ESET Chief Security Evangelist Tony Anscombe shares advice on how to keep your virtual meet-ups private and safe while you’re holed up at home during the pandemic The post Top tips for videoconferencing security appeared first on WeLiveSecurity

600,000 people affected in email provider breach

The users’ personal data are now up for grabs on the dark web for anywhere between US$3,500 and US$22,000 worth of Bitcoin The post 600,000 people affected in email provider breach appeared first on WeLiveSecurity

What to do you if your phone is lost or stolen

Losing your smartphone can be expensive, but the cost of the device may not be the final price you’ll be paying The post What to do you if your phone is lost or stolen appeared first on WeLiveSecurity

Work from home: Securing RDP and remote access

As work from home is the new norm in the coronavirus era, you’re probably thinking of enabling remote desktop connections for your off-site staff. Here’s how to do it securely. The post Work from home: Securing RDP and remote access appeared first on WeLiveSecurity

Marriott hacked again, 5.2 million guests affected

Bad actors accessed a range of personally identifiable information, including names, dates of birth and a lot more The post Marriott hacked again, 5.2 million guests affected appeared first on WeLiveSecurity

Coronavirus con artists continue to spread infections of their own

The scam machine shows no signs of slowing down, as fraudsters dispense bogus health advice, peddle fake testing kits and issue malware-laced purchase orders The post Coronavirus con artists continue to spread infections of their own appeared first on WeLiveSecurity

Have you backed up your smartphone lately?

With World Backup Day upon us, we walk you through the ways to back up your iPhone or Android phone so that your personal information remains safe The post Have you backed up your smartphone lately? appeared first on WeLiveSecurity

Work from home: Videoconferencing with security in mind

With COVID-19 concerns canceling face-to-face meetings, be aware of the security risks of videoconferencing and how to easily overcome them The post Work from home: Videoconferencing with security in mind appeared first on WeLiveSecurity

HPE issues fix to stop some SSDs from self‑destructing

If left unpatched, a firmware flaw in some enterprise-class solid-state drives could make data on them unrecoverable as early as this fall The post HPE issues fix to stop some SSDs from self‑destructing appeared first on WeLiveSecurity

Public health vs. personal privacy: Choose only one?

As the world turns to technology to track and contain the COVID-19 pandemic, could this spell the end of digital privacy rights? The post Public health vs. personal privacy: Choose only one? appeared first on WeLiveSecurity

Microsoft warns of two Windows zero‑day flaws

Updates for the critical-rated vulnerabilities, which are being actively exploited in the wild, are still weeks away The post Microsoft warns of two Windows zero‑day flaws appeared first on WeLiveSecurity

The good, the bad and the plain ugly

A prolific ransomware gang vows to dial back its campaigns and spare healthcare organizations altogether during the COVID-19 crisis. It’s no cause for celebration. The post The good, the bad and the plain ugly appeared first on WeLiveSecurity

Keep calm and carry on working (remotely)

How can employees stay motivated and productive while teleworking during the COVID-19 crisis? The post Keep calm and carry on working (remotely) appeared first on WeLiveSecurity

What to do if your Twitter account has been hacked

Losing access to your account can be stressful, but there are steps you can take to get it back – and to avoid getting hacked again The post What to do if your Twitter account has been hacked appeared first on WeLiveSecurity

Security flaws found in popular password managers

Not all they’re cracked up to be? Several password vaults contain vulnerabilities, both new and previously disclosed but never patched, a study says The post Security flaws found in popular password managers appeared first on WeLiveSecurity

Work from home: Improve your security with MFA

Remote work can be much safer with the right cyber‑hygiene practices in place – multi‑factor authentication is one of them The post Work from home: Improve your security with MFA appeared first on WeLiveSecurity

Stantinko’s new cryptominer features unique obfuscation techniques

ESET researchers bring to light unique obfuscation techniques discovered in the course of analyzing a new cryptomining module distributed by the Stantinko group’s botnet The post Stantinko’s new cryptominer features unique obfuscation techniques appeared first on WeLiveSecurity

Work from home: How to set up a VPN

As the COVID-19 pandemic has many organizations switching employees to remote work, a virtual private network is essential for countering the increased security risks The post Work from home: How to set up a VPN appeared first on WeLiveSecurity

FBI warns of human traffickers luring victims on dating apps

The warning highlights one of the potential risks associated with revealing too much private information online The post FBI warns of human traffickers luring victims on dating apps appeared first on WeLiveSecurity

COVID‑19 and the forced workplace exodus

As the pandemic forces many employees to work from home, can your organization stay productive – and safe? The post COVID‑19 and the forced workplace exodus appeared first on WeLiveSecurity

Beware scams exploiting coronavirus fears

From malware-laden emails to fake donations, these are some of the most common cons you should watch out for amid the public health crisis The post Beware scams exploiting coronavirus fears appeared first on WeLiveSecurity

European power grid organization hit by cyberattack

The incident affected our office network, says ENTSO-E, as it implements measures to avoid future cyber-incursions The post European power grid organization hit by cyberattack appeared first on WeLiveSecurity

Tracking Turla: New backdoor delivered via Armenian watering holes

Can an old APT learn new tricks? Turla’s TTPs are largely unchanged, but the group recently added a Python backdoor. The post Tracking Turla: New backdoor delivered via Armenian watering holes appeared first on WeLiveSecurity

Flaw in popular VPN service may have exposed customer data

NordVPN praised its bug bounty program and said that a fix had been shipped within two days The post Flaw in popular VPN service may have exposed customer data appeared first on WeLiveSecurity

Microsoft: 99.9 percent of hacked accounts didn’t use MFA

Only 11 percent of all enterprise accounts have multi-factor authentication enabled The post Microsoft: 99.9 percent of hacked accounts didn’t use MFA appeared first on WeLiveSecurity

Guildma: The Devil drives electric

The fourth installment of our occasional series demystifying Latin American banking trojans The post Guildma: The Devil drives electric appeared first on WeLiveSecurity

Fraud Prevention Month: How to protect yourself from scams

ESET Chief Security Evangelist Tony Anscombe sat down with us to share his insights on how to avoid falling prey to online fraud The post Fraud Prevention Month: How to protect yourself from scams appeared first on WeLiveSecurity

Voice assistants can be hacked with ultrasonic waves

With access to text messages and the ability to make fraudulent phone calls, attackers could wreak more damage than you’d think The post Voice assistants can be hacked with ultrasonic waves appeared first on WeLiveSecurity

Brave comes out on top in browser privacy study

By contrast, two web browsers share identifiers that are tied to the device hardware and so persist even across fresh installs The post Brave comes out on top in browser privacy study appeared first on WeLiveSecurity

5 reasons to consider a career in cybersecurity

From competitive salaries to ever-evolving job descriptions, there are myriad reasons why a cybersecurity career could be right for you The post 5 reasons to consider a career in cybersecurity appeared first on WeLiveSecurity

RSA 2020 – Is your machine learning/quantum computer lying to you?

And how would you know if the algorithm was tampered with? The post RSA 2020 – Is your machine learning/quantum computer lying to you? appeared first on WeLiveSecurity

Facial recognition company Clearview AI hit by data theft

The startup came under scrutiny after it emerged that it had amassed 3 billion photos from social media for facial recognition software The post Facial recognition company Clearview AI hit by data theft appeared first on WeLiveSecurity

RSA 2020 – Hacking humans

What the human battle against biological viruses can teach us about fighting computer infections – and vice versa The post RSA 2020 – Hacking humans appeared first on WeLiveSecurity

Did someone file your taxes before you?

With tax season – and tax scams – in full swing, here’s how fraudsters can steal your tax refund, and how you can avoid becoming a victim The post Did someone file your taxes before you? appeared first on WeLiveSecurity

Is bug hunting a viable career choice?

With earnings of top ethical hackers surpassing hundreds of thousands of dollars, some would say yes The post Is bug hunting a viable career choice? appeared first on WeLiveSecurity

KrØØk: Serious vulnerability affected encryption of billion+ Wi‑Fi devices

ESET researchers uncover a previously unknown security flaw allowing an adversary to decrypt some wireless network packets transmitted by vulnerable devices The post KrØØk: Serious vulnerability affected encryption of billion+ Wi‑Fi devices appeared first on WeLiveSecurity

Is your phone listening to you?

Do social media listen in on our conversations in order to target us with ads? Or are we just a bit paranoid? A little test might speak a thousand words. The post Is your phone listening to you? appeared first on WeLiveSecurity

MGM Resorts data breach exposes details of 10.6 million guests

A number of celebrities, government officials and tech CEOs were also caught up in the incident The post MGM Resorts data breach exposes details of 10.6 million guests appeared first on WeLiveSecurity

Linux and malware: Should you worry?

Malicious code is nothing to worry about on Linux, right? Hold your penguins. How Linux malware has gone from the sidelines to the headlines. The post Linux and malware: Should you worry? appeared first on WeLiveSecurity

What DNS encryption means for enterprise threat hunters

The dawn of the DNS over HTTPS era is putting business security and SOC teams to the challenge The post What DNS encryption means for enterprise threat hunters appeared first on WeLiveSecurity

Sensitive plastic surgery photos exposed online

Other leaked records include videos, facial and body scans, as well as a range of patients’ personal data The post Sensitive plastic surgery photos exposed online appeared first on WeLiveSecurity

Plugin flaw leaves up to 200,000 WordPress sites at risk of attack

A fix is available, so you may want to make sure that you run the plugin’s latest version The post Plugin flaw leaves up to 200,000 WordPress sites at risk of attack appeared first on WeLiveSecurity