Menu

Category Archives: Security Advisory

Auto Added by WPeMatico

Millions of modems at risk of remote hijacking

Multiple cable modem models from various manufacturers found vulnerable to takeover attacks The post Millions of modems at risk of remote hijacking appeared first on WeLiveSecurity

Windows 7 end of life: Time to move on

Today, Microsoft is officially pulling the plug on its support for Windows 7. What’s your plan? The post Windows 7 end of life: Time to move on appeared first on WeLiveSecurity

5 major US wireless carriers vulnerable to SIM swapping attacks

When it comes to protection against this insidious type of scam, the telcos’ authentication procedures leave a lot be desired, a study finds The post 5 major US wireless carriers vulnerable to SIM swapping attacks appeared first on WeLiveSecurity

Mozilla rushes out patch for Firefox zero‑day

The US cybersecurity agency warns that the critical vulnerability could allow attackers to take control of people’s computers The post Mozilla rushes out patch for Firefox zero‑day appeared first on WeLiveSecurity

CES – Taking a smart city for a test drive

No one has a road map for securing a connected city – but there should be a whole atlas of such maps The post CES – Taking a smart city for a test drive appeared first on WeLiveSecurity

Facebook bans deepfakes but not all altered content

Footage defined as parody or satire will be permitted, as the social network isn’t slamming the door on all types of manipulated media The post Facebook bans deepfakes but not all altered content appeared first on WeLiveSecurity

Simple steps to protect yourself against identity theft

As we enter the New Year, be sure to keep up, or adopt, these good data security habits to avoid identity theft The post Simple steps to protect yourself against identity theft appeared first on WeLiveSecurity

20 tips for 2020: Be smarter with your smartphone

In the second blogpost of the two-part series we’ll suggest handy tips to help enhance the security of your mobile devices The post 20 tips for 2020: Be smarter with your smartphone appeared first on WeLiveSecurity

20 tips for 2020: Mistakes to avoid

In this first instalment of the two-article series we will be looking at cybersecurity habits to avoid when using your computing devices The post 20 tips for 2020: Mistakes to avoid appeared first on WeLiveSecurity

Prison surveillance footage posted on YouTube

It’s not a stretch to surmise that the incident was enabled by poor security settings The post Prison surveillance footage posted on YouTube appeared first on WeLiveSecurity

How to get rid of your old devices safely

Disposing of old tech isn’t a one-click solution; there are multiple things you have to consider before moving on to greener pastures The post How to get rid of your old devices safely appeared first on WeLiveSecurity

How to secure your digital Christmas presents

What are some of the key things you should do with your shiny new device as soon as you unbox it? The post How to secure your digital Christmas presents appeared first on WeLiveSecurity

Ambitious scam wants far more than just PayPal logins

An ongoing phishing scam uncovered by ESET researchers seeks to wreak havoc on your money and digital life in one fell swoop The post Ambitious scam wants far more than just PayPal logins appeared first on WeLiveSecurity

38,000 people forced to pick up email passwords in person

Malware and legal requirements force academics and students to join a near-endless line in order to pick up their passwords The post 38,000 people forced to pick up email passwords in person appeared first on WeLiveSecurity

It’s time to disconnect RDP from the internet

Brute-force attacks and BlueKeep exploits usurp convenience of direct RDP connections; ESET releases a tool to test your Windows machines for vulnerable versions The post It’s time to disconnect RDP from the internet appeared first on WeLiveSecurity

The worst passwords of 2019: Did yours make the list?

These passwords may win the popularity contest but lose flat out in security The post The worst passwords of 2019: Did yours make the list? appeared first on WeLiveSecurity

Chrome now warns you if your password has been stolen

The browser’s latest version also aims to up the ante in phishing protection The post Chrome now warns you if your password has been stolen appeared first on WeLiveSecurity

Data leak exposes 750,000 birth certificate applications

A variety of sensitive information has been there for the taking due to an unsecured cloud storage container The post Data leak exposes 750,000 birth certificate applications appeared first on WeLiveSecurity

Cybersecurity Trends 2020: Technology is getting smarter – are we?

With 2019 ending, ESET experts offer their insights into how new innovations will impact our privacy, security and lives in the not so distant future The post Cybersecurity Trends 2020: Technology is getting smarter – are we? appeared first on WeLiveSecurity

5 scam prevention tips for seniors

How can people who didn’t grow up with technology protect themselves against some of the most common types of online fraud? The post 5 scam prevention tips for seniors appeared first on WeLiveSecurity

80% of all Android apps encrypt traffic by default

Google keeps pushing in its mission for broader encryption adoption The post 80% of all Android apps encrypt traffic by default appeared first on WeLiveSecurity

Face scanning – privacy concern or identity protection?

What issues would face scanning attached to a mobile device resolve and, if used correctly, would it make the incursion into my privacy acceptable? The post Face scanning – privacy concern or identity protection? appeared first on WeLiveSecurity

Notorious spy tool taken down in global operation

IM-RAT, which could be had for as little as US$25, was bought by nearly 15,000 people The post Notorious spy tool taken down in global operation appeared first on WeLiveSecurity

5 personal (and cheap) data privacy tools that scale for business

Smart selections when starting small can ease the pain as you scale up your company’s privacy infrastructure The post 5 personal (and cheap) data privacy tools that scale for business appeared first on WeLiveSecurity

5 scams to watch out for this shopping season

Black Friday and Cyber Monday are just around the corner and scammers are gearing up to flood you with bogus offers The post 5 scams to watch out for this shopping season appeared first on WeLiveSecurity

Cryptocurrency exchange loses US$50 million in apparent hack

UPbit has announced that, as a precaution, all transactions will remain suspended for at least two weeks The post Cryptocurrency exchange loses US$50 million in apparent hack appeared first on WeLiveSecurity

Stantinko botnet adds cryptomining to its pool of criminal activities

ESET researchers have discovered that the criminals behind the Stantinko botnet are distributing a cryptomining module to the computers they control The post Stantinko botnet adds cryptomining to its pool of criminal activities appeared first on WeLiveSecurity

CyberwarCon – the future of nation‑state nastiness

How the field of play has changed and why endpoint protection still often comes down to doing the basics, even in the face of increasingly complex threats The post CyberwarCon – the future of nation‑state nastiness appeared first on WeLiveSecurity

Registers as “Default Print Monitor”, but is a malicious downloader. Meet DePriMon

ESET researchers have discovered a new downloader with a novel, not previously seen in the wild installation technique The post Registers as “Default Print Monitor”, but is a malicious downloader. Meet DePriMon appeared first on WeLiveSecurity

What does it take to attract top cybersecurity talent?

From professional backgrounds to competitive salaries – a study delves into what it takes to build strong cybersecurity teams The post What does it take to attract top cybersecurity talent? appeared first on WeLiveSecurity

Mispadu: Advertisement for a discounted Unhappy Meal

Another in our occasional series demystifying Latin American banking trojans The post Mispadu: Advertisement for a discounted Unhappy Meal appeared first on WeLiveSecurity

Disney+ accounts hijacked – How to protect yourself

As users are losing access to their accounts by the dozens, we offer a few tips to help keep your streaming subscriptions safe The post Disney+ accounts hijacked – How to protect yourself appeared first on WeLiveSecurity

Microsoft issues patch for Internet Explorer zero‑day

The critical vulnerability could also be exploited via a malicious Microsoft Office document The post Microsoft issues patch for Internet Explorer zero‑day appeared first on WeLiveSecurity

Getting into cybersecurity: Self‑taught vs. university‑educated?

Are you considering a career in cybersecurity? What learning path(s) should you take? Does formal education matter? ESET experts share their insights. The post Getting into cybersecurity: Self‑taught vs. university‑educated? appeared first on WeLiveSecurity

Facebook bug turns on iPhone camera in the background

A recent update to the Facebook’s iOS app introduced a bug that had some users worried The post Facebook bug turns on iPhone camera in the background appeared first on WeLiveSecurity

Can regulations improve cybersecurity? In APAC, opinions vary

An ESET-commissioned survey among enterprises also shows that while respondents in most countries agree on the need to bolster cyber-defenses, some are reluctant to adopt cybersecurity solutions The post Can regulations improve cybersecurity? In APAC, opinions vary appeared first on WeLiveSecurity

First BlueKeep attacks prompt fresh warnings

The infamous vulnerability has been exploited for a cryptocurrency mining campaign, but more damaging attacks may still be in store The post First BlueKeep attacks prompt fresh warnings appeared first on WeLiveSecurity

Android keyboard app caught red‑handed trying to make sneaky purchases

The virtual keyboard app ai.type, which has racked up 40 million downloads, has been found to sign up users to premium services without their consent The post Android keyboard app caught red‑handed trying to make sneaky purchases appeared first on WeLiveSecurity

Five ways to strengthen employee cybersecurity awareness

How can organizations foster a workplace environment that enables employees to acquire the skills needed to keep cyber-threats at bay? The post Five ways to strengthen employee cybersecurity awareness appeared first on WeLiveSecurity

Antimalware Day 2019: Building a culture of cybersecurity awareness

The introduction to a series of articles marking this year’s Antimalware Day and highlighting the importance of cyber-readiness The post Antimalware Day 2019: Building a culture of cybersecurity awareness appeared first on WeLiveSecurity

Deepfakes: When seeing isn’t believing

Is the world as we know it ready for the real impact of deepfakes? The post Deepfakes: When seeing isn’t believing appeared first on WeLiveSecurity

Facebook builds tool to confound facial recognition

However, the social network harbors no plans to deploy the technology in any of its services any time soon The post Facebook builds tool to confound facial recognition appeared first on WeLiveSecurity

What you may be getting wrong about cybersecurity

Attention-grabbing cyberattacks that use fiendish exploits are probably not the kind of threat that should be your main concern – here’s what your organization should focus on instead The post What you may be getting wrong about cybersecurity appeared first on WeLiveSecurity

Facebook lays out plan to protect elections

How is the social network preparing to curtail the spread of misinformation as the election season heats up? The post Facebook lays out plan to protect elections appeared first on WeLiveSecurity

Tracking down the developer of Android adware affecting millions of users

ESET researchers discovered a year-long adware campaign on Google Play and tracked down its operator. The apps involved, installed eight million times, use several tricks for stealth and persistence. The post Tracking down the developer of Android adware affecting millions of users appeared first on WeLiveSecurity

Smart cities must be cyber‑smart cities

As cities turn to IoT to address long-standing urban problems, what are the risks of leaving cybersecurity behind at the planning phase? The post Smart cities must be cyber‑smart cities appeared first on WeLiveSecurity

NordVPN reveals breach at datacenter provider

The company says that the incident, going back to March 2018, affected only 1 out of its 3,000 servers The post NordVPN reveals breach at datacenter provider appeared first on WeLiveSecurity

Winnti Group’s skip‑2.0: A Microsoft SQL Server backdoor

Notorious cyberespionage group debases MSSQL The post Winnti Group’s skip‑2.0: A Microsoft SQL Server backdoor appeared first on WeLiveSecurity

What was wrong with Alexa? How Amazon Echo and Kindle got KRACKed

ESET Smart Home Research Team uncovers Echo, Kindle versions vulnerable to 2017 Wi-Fi vulnerabilities The post What was wrong with Alexa? How Amazon Echo and Kindle got KRACKed appeared first on WeLiveSecurity

Operation Ghost: The Dukes aren’t back – they never left

ESET researchers describe recent activity of the infamous espionage group, the Dukes, including three new malware families The post Operation Ghost: The Dukes aren’t back – they never left appeared first on WeLiveSecurity

Streaming devices track viewing habits, study finds

Do you know what kind of data your streaming device may be collecting while you binge watch? The post Streaming devices track viewing habits, study finds appeared first on WeLiveSecurity

Connecting the dots: Exposing the arsenal and methods of the Winnti Group

New ESET white paper released describing updates to the malware arsenal and campaigns of this group known for its supply-chain attacks The post Connecting the dots: Exposing the arsenal and methods of the Winnti Group appeared first on WeLiveSecurity

ESET discovers Attor, a spy platform with curious GSM fingerprinting

ESET researchers discover a previously unreported cyberespionage platform used in targeted attacks against diplomatic missions and governmental institutions, and privacy-concerned users The post ESET discovers Attor, a spy platform with curious GSM fingerprinting appeared first on WeLiveSecurity

How concerned are you about the privacy challenges of your IoT devices?

An ESET survey of thousands of people in North America provides a peek into how they perceive the privacy and security of their smart home connected devices The post How concerned are you about the privacy challenges of your IoT devices? appeared first on WeLiveSecurity

Internet pioneer Dr. Paul Vixie on global internet security

We sat down with internet pioneer and Farsight Security CEO Dr. Paul Vixie, who co-invented some of the services that are central to the ‘Net’s fabric, to discuss a range of issues affecting security and privacy The post Internet pioneer Dr. Paul Vixie on global internet security appeared first on WeLiveSecurity

Inside consumer perceptions of security and privacy in the connected home

The ESET survey polled 4,000 people to get a sense of their attitudes towards the privacy and security implications of smart home technology The post Inside consumer perceptions of security and privacy in the connected home appeared first on WeLiveSecurity

Needles in a haystack: Picking unwanted UEFI components out of millions of samples

ESET experts describe how they trained a machine-learning model to recognize a handful of unwanted UEFI components within a flood of millions of harmless samples The post Needles in a haystack: Picking unwanted UEFI components out of millions of samples appeared first on WeLiveSecurity

Hospitals in US, Australia hobbled by ransomware

The incidents send medical staff back to the days of pen and paper The post Hospitals in US, Australia hobbled by ransomware appeared first on WeLiveSecurity

Casbaneiro: Dangerous cooking with a secret ingredient

Número dois in our series demystifying Latin American banking trojans The post Casbaneiro: Dangerous cooking with a secret ingredient appeared first on WeLiveSecurity

Do apps need all the permissions?

Why you should ensure that all those apps on your smartphone only run with the permissions they reasonably need to do their job The post Do apps need all the permissions? appeared first on WeLiveSecurity

Cyber Security Awareness Month starts today!

October is upon us, reminding us to make choices every day that will scare cybersecurity threats away The post Cyber Security Awareness Month starts today! appeared first on WeLiveSecurity

Microsoft rushes out patch for Internet Explorer zero‑day

There is no word on which threat actor is abusing the severe vulnerability for attacks The post Microsoft rushes out patch for Internet Explorer zero‑day appeared first on WeLiveSecurity

Do companies take cybersecurity seriously enough?

Many companies are ranking cybersecurity as a top 5 priority but their actions do not measure up to the claim, a survey finds The post Do companies take cybersecurity seriously enough? appeared first on WeLiveSecurity

No summer vacations for Zebrocy

ESET researchers describe the latest components used in a recent Sednit campaign The post No summer vacations for Zebrocy appeared first on WeLiveSecurity

Universities warned to brace for cyberattacks

The UK’s cybersecurity agency also outlines precautions that academia should take to mitigate risks The post Universities warned to brace for cyberattacks appeared first on WeLiveSecurity

Remote access flaws found in popular routers, NAS devices

In almost all tested units, the researchers achieved their goal of obtaining remote root-level access The post Remote access flaws found in popular routers, NAS devices appeared first on WeLiveSecurity

Nearly all of Ecuador’s citizens caught up in data leak

The humongous collection of extensive personal details about millions of people could be a gold mine for scam artists The post Nearly all of Ecuador’s citizens caught up in data leak appeared first on WeLiveSecurity

Selfies for kids – A guide for parents

Are you – and especially your children – aware of the risks that may come with sharing selfies? The post Selfies for kids – A guide for parents appeared first on WeLiveSecurity

ESET discovered an undocumented backdoor used by the infamous Stealth Falcon group

ESET researchers discovered a backdoor linked to malware used by the Stealth Falcon group, an operator of targeted spyware attacks against journalists, activists and dissidents in the Middle East The post ESET discovered an undocumented backdoor used by the infamous Stealth Falcon group appeared first on WeLiveSecurity

Week in security

This week, we present an introduction to the MITRE ATT&CK framework, the review of the mobile threats and vulnerabilities detected for mobile during the first half of 2019, and Firefox 69 new features. The post Week in security appeared first on WeLiveSecurity

Semi‑annual balance of mobile security 2019

Malware detections for iOS increased, as did the number of vulnerabilities detected in this operating system, while in the case of Android, the number of reported vulnerabilities decreased, although the number of highly critical bugs reported increased. The post Semi‑annual balance of mobile security 2019 appeared first on WeLiveSecurity

Firefox 69: Third‑Party Tracking Cookies and Cryptomining Now Blocked by Default

Firefox new Enhanced Tracking Protection (ETP) feature launched to all users of the browser to offer better privacy and protection from cryptojacjing. The post Firefox 69: Third‑Party Tracking Cookies and Cryptomining Now Blocked by Default appeared first on WeLiveSecurity

What is MITRE ATT&CK and how is it useful?

An introduction to the MITRE ATT&CK framework and how it can help organize and classify various types of threats and adversarial behaviors. The post What is MITRE ATT&CK and how is it useful? appeared first on WeLiveSecurity

First‑of‑its‑kind spyware sneaks into Google Play

ESET analysis breaks down the first known spyware that is built on the AhMyth open-source espionage tool and has appeared on Google Play – twice The post First‑of‑its‑kind spyware sneaks into Google Play appeared first on WeLiveSecurity

Education and privacy legislation at ChannelCon

As education is becoming an increasingly vital tool in companies’ security toolboxes, the question arises: How can they effectively implement security awareness training? The post Education and privacy legislation at ChannelCon appeared first on WeLiveSecurity

Ransomware wave hits 23 towns in Texas

The attack, which has victimized mostly smaller local governments, is thought to have been unleashed by a single threat actor The post Ransomware wave hits 23 towns in Texas appeared first on WeLiveSecurity

Microsoft warns of new BlueKeep‑like flaws

Unlike BlueKeep, however, these vulnerabilities affect more recent Windows versions, including Windows 10 The post Microsoft warns of new BlueKeep‑like flaws appeared first on WeLiveSecurity

In the Balkans, businesses are under fire from a double‑barreled weapon

ESET researchers discovered a campaign that uses two malicious tools with similar capabilities to ensure both resilience and broader potential for the attackers The post In the Balkans, businesses are under fire from a double‑barreled weapon appeared first on WeLiveSecurity

Hacking my airplane – BlackHat edition

After welcoming hacking research, automobile technology started to get better at defending against hacks. So why has the airline industry not been as welcoming? The post Hacking my airplane – BlackHat edition appeared first on WeLiveSecurity

Facebook hits two app developers with lawsuit

The legal action, brought over alleged click injection fraud, is said to be among the first of its kind The post Facebook hits two app developers with lawsuit appeared first on WeLiveSecurity

Varenyky: Spambot à la Française

ESET researchers document malware-distributing spam campaigns targeting people in France The post Varenyky: Spambot à la Française appeared first on WeLiveSecurity

FBI warns of romance scams using online daters as money mules

Up to 30 percent of romance fraud victims in 2018 are estimated to have been used as money mules The post FBI warns of romance scams using online daters as money mules appeared first on WeLiveSecurity

Sharpening the Machete

ESET research uncovers a cyberespionage operation targeting the Venezuelan military The post Sharpening the Machete appeared first on WeLiveSecurity

From Carnaval to Cinco de Mayo – The journey of Amavaldo

The first in an occasional series demystifying Latin American banking trojans The post From Carnaval to Cinco de Mayo – The journey of Amavaldo appeared first on WeLiveSecurity

Android ransomware is back

ESET researchers discover a new Android ransomware family that attempts to spread to victims’ contacts and deploys some unusual tricks The post Android ransomware is back appeared first on WeLiveSecurity

Scam impersonates WhatsApp, offers ‘free internet’

The fraudulent campaign is hosted by a domain that is home to yet more bogus offers pretending to come from other well-known brands The post Scam impersonates WhatsApp, offers ‘free internet’ appeared first on WeLiveSecurity

Streaming service endures 13‑day DDoS raid

The attack, unleashed by a 400,000-strong Mirai-style botnet, may be the largest of its kind on record The post Streaming service endures 13‑day DDoS raid appeared first on WeLiveSecurity

Data breaches can haunt firms for years

The compromised company may bear the financial brunt of the breach within the first year after the incident occurs, but the price tag is still far from final The post Data breaches can haunt firms for years appeared first on WeLiveSecurity

VLC player has a critical flaw – and there’s no patch yet

On the flip side, there are currently no known cases of the vulnerability being exploited in the wild The post VLC player has a critical flaw – and there’s no patch yet appeared first on WeLiveSecurity

Okrum: Ke3chang group targets diplomatic missions

Tracking the malicious activities of the elusive Ke3chang APT group, ESET researchers have discovered new versions of malware families linked to the group, and a previously unreported backdoor The post Okrum: Ke3chang group targets diplomatic missions appeared first on WeLiveSecurity

BlueKeep patching isn’t progressing fast enough

Keeping up with BlueKeep; or how many internet-facing systems, and in which countries and industries, remain ripe for exploitation? The post BlueKeep patching isn’t progressing fast enough appeared first on WeLiveSecurity

How your Instagram account could have been hijacked

A researcher found that it was possible to subvert the platform’s password recovery mechanism and take control of user accounts The post How your Instagram account could have been hijacked appeared first on WeLiveSecurity

Buhtrap group uses zero‑day in latest espionage campaigns

ESET research reveals notorious crime group also conducting espionage campaigns for the past five years The post Buhtrap group uses zero‑day in latest espionage campaigns appeared first on WeLiveSecurity

Windows zero‑day CVE‑2019‑1132 exploited in targeted attacks

ESET research discovers a zero-day exploit that takes advantage of a local privilege escalation vulnerability in Windows The post Windows zero‑day CVE‑2019‑1132 exploited in targeted attacks appeared first on WeLiveSecurity

UK’s data watchdog hands out two mega‑fines for breaches

The times they have a-changed since the ICO could only slap fines worth a fraction of the current amounts The post UK’s data watchdog hands out two mega‑fines for breaches appeared first on WeLiveSecurity

Malicious campaign targets South Korean users with backdoor-laced torrents

ESET researchers have discovered a malicious campaign distributing a backdoor via torrents, with Korean TV content used as a lure The post Malicious campaign targets South Korean users with backdoor-laced torrents appeared first on WeLiveSecurity

NHS warned to act now to keep hackers at bay

A trifecta of issues impact the organization’s cyber-resilience and conspire to put it in the firing line of cyberattacks The post NHS warned to act now to keep hackers at bay appeared first on WeLiveSecurity

Two billion user logs leaked by smart home vendor

The leak, which apparently has yet to be plugged, exposes a range of very specific data about users The post Two billion user logs leaked by smart home vendor appeared first on WeLiveSecurity

Ex-Equifax executive sent to jail for insider trading after breach

“Sounds bad”, the former Equifax CIO wrote in a text after learning of the breach that ended up affecting almost half the US population The post Ex-Equifax executive sent to jail for insider trading after breach appeared first on WeLiveSecurity

Microsoft enhances OneDrive to secure your critical files

The new feature is intended to protect the kind of data that you hold particularly dear The post Microsoft enhances OneDrive to secure your critical files appeared first on WeLiveSecurity