Menu

Category Archives: Security Advisory

Auto Added by WPeMatico

Two US cities opt to pay $1m to ransomware operators

A few days apart, two cities in Florida cave in to extortionists’ demands in hopes of restoring access to municipal computer systems The post Two US cities opt to pay $1m to ransomware operators appeared first on WeLiveSecurity

Stopping stalkerware: What needs to change?

What technology makers and others can – and should – do to counter the kind of surveillance that starts at home The post Stopping stalkerware: What needs to change? appeared first on WeLiveSecurity

Hackers breach NASA, steal Mars mission data

The infiltration was only spotted and stopped after the hackers roamed the network undetected for almost a year The post Hackers breach NASA, steal Mars mission data appeared first on WeLiveSecurity

LoudMiner: Cross-platform mining in cracked VST software

The story of a Linux miner bundled with pirated copies of VST (Virtual Studio Technology) software for Windows and macOS The post LoudMiner: Cross-platform mining in cracked VST software appeared first on WeLiveSecurity

You’d better change your birthday – hackers may know your PIN

Are you in the 26% of people who use one of these PIN codes to unlock their phones? The post You’d better change your birthday – hackers may know your PIN appeared first on WeLiveSecurity

Instagram tests new ways to recover hacked accounts

Locked out and out of luck? The photo-sharing platform is trialing new methods to reunite you with your lost account The post Instagram tests new ways to recover hacked accounts appeared first on WeLiveSecurity

Malware sidesteps Google permissions policy with new 2FA bypass technique

ESET analysis uncovers a novel technique bypassing SMS-based two-factor authentication while circumventing Google’s recent SMS permissions restrictions The post Malware sidesteps Google permissions policy with new 2FA bypass technique appeared first on WeLiveSecurity

Spain’s top soccer league fined over its app’s ‘tactics’

La Liga has taken substantial flak for tapping into microphones and geolocation services in fans‘ phones in a bid to root out piracy The post Spain’s top soccer league fined over its app’s ‘tactics’ appeared first on WeLiveSecurity

Why cybercriminals are eyeing smart buildings

A recent talk by ESET’s Global Security Evangelist Tony Anscombe looks at the key security challenges facing intelligent buildings The post Why cybercriminals are eyeing smart buildings appeared first on WeLiveSecurity

Cyberattack exposes travelers’ photos, says US border agency

The images, collected over one and a half months, were taken as the travelers crossed an unspecified border point The post Cyberattack exposes travelers’ photos, says US border agency appeared first on WeLiveSecurity

NSA joins chorus urging Windows users to patch ‘BlueKeep’

The alert comes on the heels of Microsoft’s second advisory calling on people to take action before it’s too late The post NSA joins chorus urging Windows users to patch ‘BlueKeep’ appeared first on WeLiveSecurity

Wajam: From start-up to massively-spread adware

How a Montreal-made “social search engine” application has managed to become a widely-spread adware, while escaping consequences The post Wajam: From start-up to massively-spread adware appeared first on WeLiveSecurity

Hackers steal 19 years’ worth of data from Australia’s top university

It is the second major breach that the Australian National University suffered in 2018 The post Hackers steal 19 years’ worth of data from Australia’s top university appeared first on WeLiveSecurity

2.3 billion files exposed online

Millions of the files that are sitting out in the open across various file storage technologies are actually encrypted by ransomware The post 2.3 billion files exposed online appeared first on WeLiveSecurity

The aftermath of a data breach: A personal story

Criminals used my account to launder credit card transactions into cash, at least where the company transacted with was willing to refund The post The aftermath of a data breach: A personal story appeared first on WeLiveSecurity

A dive into Turla PowerShell usage

ESET researchers analyze new TTPs attributed to the Turla group that leverage PowerShell to run malware in-memory only The post A dive into Turla PowerShell usage appeared first on WeLiveSecurity

Equifax stripped of ‘stable’ outlook over 2017 breach

Add that to the US$1.4 billion that the massive incident has cost the company so far The post Equifax stripped of ‘stable’ outlook over 2017 breach appeared first on WeLiveSecurity

Fake cryptocurrency apps crop up on Google Play as bitcoin price rises

ESET researchers have analyzed fake cryptocurrency wallets emerging on Google Play at the time of bitcoin’s renewed growth The post Fake cryptocurrency apps crop up on Google Play as bitcoin price rises appeared first on WeLiveSecurity

Patch now! Why the BlueKeep vulnerability is a big deal

What you need to know about the critical security hole that could enable the next WannaCryptor The post Patch now! Why the BlueKeep vulnerability is a big deal appeared first on WeLiveSecurity

A journey to Zebrocy land

ESET sheds light on commands used by the favorite backdoor of the Sednit group The post A journey to Zebrocy land appeared first on WeLiveSecurity

What the ban on facial recognition tech will – and will not – do

As San Francisco moves to regulate the use of facial recognition systems, we reflect on some of the many ‘faces’ of the fast-growing technology The post What the ban on facial recognition tech will – and will not – do appeared first on WeLiveSecurity

Cybersecurity training and awareness: helpful resources for educators

Free resources for cybersecurity awareness and training are out there – links to many of them are provided here The post Cybersecurity training and awareness: helpful resources for educators appeared first on WeLiveSecurity

Survey: What should companies do to restore trust post-breach?

The ESET survey among thousands of people in Asia-Pacific (APAC) provides valuable insight into their perceptions of cyber-threats and various common aspects of online security The post Survey: What should companies do to restore trust post-breach? appeared first on WeLiveSecurity

Ice Hockey World Championship: The risks of free live streaming

You think you’re watching the games for free, but are you sure that’s the case? Let’s review some of the risks that may come with free live streaming websites The post Ice Hockey World Championship: The risks of free live streaming appeared first on WeLiveSecurity

Plead malware distributed via MitM attacks at router level, misusing ASUS WebStorage

ESET researchers have discovered that the attackers have been distributing the Plead malware via compromised routers and man-in-the-middle attacks against the legitimate ASUS WebStorage software The post Plead malware distributed via MitM attacks at router level, misusing ASUS WebStorage appeared first on WeLiveSecurity

Verizon’s data breach report: What the numbers say

What are some of the most interesting takeaways from Verizon’s latest annual security report? The post Verizon’s data breach report: What the numbers say appeared first on WeLiveSecurity

Hackers steal US$41 million worth of Bitcoin from cryptocurrency exchange

The thieves bade their time before running off with more than 7,000 Bitcoin ‘in one fell swoop’ The post Hackers steal US$41 million worth of Bitcoin from cryptocurrency exchange appeared first on WeLiveSecurity

Turla LightNeuron: An email too far

ESET research uncovers Microsoft Exchange malware remotely controlled via steganographic PDF and JPG email attachments The post Turla LightNeuron: An email too far appeared first on WeLiveSecurity

World Password Day: A day to review your defenses

So, do you think you’ve been ‘pwned’? That’s the question to ask yourself today The post World Password Day: A day to review your defenses appeared first on WeLiveSecurity

D-Link camera vulnerability allows attackers to tap into the video stream

ESET researchers highlight a series of security holes in a device intended to make homes and offices more secure The post D-Link camera vulnerability allows attackers to tap into the video stream appeared first on WeLiveSecurity

Buhtrap backdoor and ransomware distributed via major advertising platform

Criminal activities against accountants on the rise – Buhtrap and RTM still active The post Buhtrap backdoor and ransomware distributed via major advertising platform appeared first on WeLiveSecurity

BEC fraud losses almost doubled last year

On the good news front, the FBI notes the success of its newly-established team in recovering some of the funds lost in BEC scams The post BEC fraud losses almost doubled last year appeared first on WeLiveSecurity

Over 23 million breached accounts used ‘123456’ as password

The notorious six-digit string continues to ‘reign supreme’ among the most-hacked passwords The post Over 23 million breached accounts used ‘123456’ as password appeared first on WeLiveSecurity

WannaCryptor ‘accidental hero’ pleads guilty to malware charges

Marcus Hutchins, who is best known for his inadvertent role in blunting the WannaCryptor outbreak two years ago, may now face a stretch behind bars The post WannaCryptor ‘accidental hero’ pleads guilty to malware charges appeared first on WeLiveSecurity

Embracing creativity to improve cyber-readiness

How approaching cybersecurity with creativity in mind can lead to better protection from digital threats The post Embracing creativity to improve cyber-readiness appeared first on WeLiveSecurity

Bug in EA’s Origin client left gamers open to attacks

The gaming company has rolled out a fix for the remote code execution vulnerability, so make sure you run the platform’s latest version The post Bug in EA’s Origin client left gamers open to attacks appeared first on WeLiveSecurity

Microsoft reveals breach affecting webmail users

Some users of Microsoft’s web-based email services such as Outlook.com had their account information exposed in an incident that, as it later emerged, also impacted email contents The post Microsoft reveals breach affecting webmail users appeared first on WeLiveSecurity

Your Android phone can now double as a security key

An extra layer of security never hurt anybody, doubly so now that you can turn your phone into a physical security key The post Your Android phone can now double as a security key appeared first on WeLiveSecurity

Hackers crack university defenses in just two hours

More than 50 universities in the United Kingdom had their cyber-defenses tested by ethical hackers, and the ‘grades’ aren’t pretty The post Hackers crack university defenses in just two hours appeared first on WeLiveSecurity

WPA3 flaws may let attackers steal Wi-Fi passwords

The new wireless security protocol contains multiple design flaws that hackers could exploit for attacks on Wi-Fi passwords The post WPA3 flaws may let attackers steal Wi-Fi passwords appeared first on WeLiveSecurity

Credential-stuffing attacks behind 30 billion login attempts in 2018

Streaming media feature among services that take the spotlight in a report on credential-stuffing attacks in 2018 The post Credential-stuffing attacks behind 30 billion login attempts in 2018 appeared first on WeLiveSecurity

OceanLotus: macOS malware update

Latest ESET research describes the inner workings of a recently found addition to OceanLotus’s toolset for targeting Mac users The post OceanLotus: macOS malware update appeared first on WeLiveSecurity

540 million records on Facebook users exposed by third-party apps

The databases, sitting unprotected on cloud servers, contained reams of information amassed by two apps integrated with the social network The post 540 million records on Facebook users exposed by third-party apps appeared first on WeLiveSecurity

NIST cybersecurity resources for smaller businesses

How can smaller businesses address their cybersecurity risks without the resources of large organizations? The post NIST cybersecurity resources for smaller businesses appeared first on WeLiveSecurity

Look who’s stalking

Aren’t we just making it too easy for online followers to become real-life trackers with the amount of open data we are posting online? The post Look who’s stalking appeared first on WeLiveSecurity

Cryptocurrency exchange loses millions in heist

Bithumb believes that, unlike in the past, this theft was the work of rogue insiders The post Cryptocurrency exchange loses millions in heist appeared first on WeLiveSecurity

Global police arrest dozens of people in dark web sting

More trouble in dark markets? A notorious black-market bazaar announces plans to close up shop on the same day as police announce the arrests of 61 people The post Global police arrest dozens of people in dark web sting appeared first on WeLiveSecurity

Two white hats hack a Tesla, get to keep it

The electric automaker is working to release a fix for the underlying vulnerability in a matter of days The post Two white hats hack a Tesla, get to keep it appeared first on WeLiveSecurity

Most second-hand thumb drives contain data from past owners

Our penchant for plugging in random memory sticks isn’t the only trouble with our USB hygiene, a study shows The post Most second-hand thumb drives contain data from past owners appeared first on WeLiveSecurity

I Still Didn’t See What You Did

More advice for detecting and avoiding sextortion scams The post I Still Didn’t See What You Did appeared first on WeLiveSecurity

Google hit with €1.49 billion antitrust fine by EU

The third penalty that Europe has levied on the tech giant in less than two years brings the total to €8.25 billion The post Google hit with €1.49 billion antitrust fine by EU appeared first on WeLiveSecurity

Fake or Fake: Keeping up with OceanLotus decoys

ESET researchers detail the latest tricks and techniques OceanLotus uses to deliver its backdoor while staying under the radar The post Fake or Fake: Keeping up with OceanLotus decoys appeared first on WeLiveSecurity

You should pick your Android security app wisely, test shows

It’s prudent to get a security solution for your device, but a test by AV-Comparatives shows why you need to choose judiciously The post You should pick your Android security app wisely, test shows appeared first on WeLiveSecurity

I didn’t see what you did, redux

Cyberblackmail/sextortion again raises its not-so-pretty little head The post I didn’t see what you did, redux appeared first on WeLiveSecurity

Facebook suffer most severe outage ever

Facebook owned Instagram and WhatsApp also affected by unexplained interruption The post Facebook suffer most severe outage ever appeared first on WeLiveSecurity

Over 2 billion records exposed by email marketing firm

The repository of email addresses and other records would offer a gold mine of data for scammers The post Over 2 billion records exposed by email marketing firm appeared first on WeLiveSecurity

Gaming industry still in the scope of attackers in Asia

Asian game developers again targeted in supply-chain attacks distributing malware in legitimately signed software The post Gaming industry still in the scope of attackers in Asia appeared first on WeLiveSecurity

Flaws in smart car alarms exposed 3 million cars to hijack

The vulnerabilities, which resided in associated smartphone apps, were both easy to find and easy to fix The post Flaws in smart car alarms exposed 3 million cars to hijack appeared first on WeLiveSecurity

RSA conference, USA 2019: Keynotes and key words

A bright tomorrow of technical delight, or a dismal future of digital dysfunction? The post RSA conference, USA 2019: Keynotes and key words appeared first on WeLiveSecurity

RSA 2019: Protecting your privacy in a NIST and GDPR world

Protecting your privacy is no longer just an option but a legal requirement in many parts of the world The post RSA 2019: Protecting your privacy in a NIST and GDPR world appeared first on WeLiveSecurity

Latest Chrome update plugs a zero-day hole

Users should waste no time in updating to the browser’s latest version The post Latest Chrome update plugs a zero-day hole appeared first on WeLiveSecurity

RSA – IoT security meets SMB

Some tips that businesses can do to get better at it without breaking the bank The post RSA – IoT security meets SMB appeared first on WeLiveSecurity

Payment processors remain phishers’ favorites

The latest report from the Anti-Phishing Working Group offers a mixed bag of findings about the phishing landscape in 2018 The post Payment processors remain phishers’ favorites appeared first on WeLiveSecurity

Teen earns US$1 million in bug bounties

A ‘white hat’ from Argentina has come a long way since winning his first reward of US$50 in 2016 The post Teen earns US$1 million in bug bounties appeared first on WeLiveSecurity

Coinhive cryptocurrency miner to call it a day next week

The service became notorious for its use by ne’er-do-wells looking to make a quick buck by hijacking the processing power of victim machines to generate virtual money The post Coinhive cryptocurrency miner to call it a day next week appeared first on WeLiveSecurity

‘Highly critical’ bug exposes unpatched Drupal sites to attacks

Worse, attackers have already been spotted targeting the flaw to deliver cryptocurrency miners and other payloads The post ‘Highly critical’ bug exposes unpatched Drupal sites to attacks appeared first on WeLiveSecurity

How to spot if your password was stolen in a security breach

Following the revelation that a list containing millions of stolen usernames and passwords had appeared online, we tell you a few different ways to find out if your credentials were stolen in that—or any other—security breach The post How to spot if your password was stolen in a security breach appeared first on WeLiveSecurity

Google aims for password-free app and site logins on Android

With FIDO2 certification for Android, Google is setting the stage for password-less app and website sign-ins on a billion devices The post Google aims for password-free app and site logins on Android appeared first on WeLiveSecurity

Escalating DNS attacks have domain name steward worried

The keeper of the internet’s ‘phone book’ is urging a speedy adoption of security-enhancing DNS specifications The post Escalating DNS attacks have domain name steward worried appeared first on WeLiveSecurity

Cyber-extortionists take aim at lucrative targets

A new report shines some light on multiple aspects of the growing threat of cyber-extortion The post Cyber-extortionists take aim at lucrative targets appeared first on WeLiveSecurity

How costly are sweetheart swindles?

And that’s on top of the heartache experienced by the tens of thousands of people who fall for romance scams each year The post How costly are sweetheart swindles? appeared first on WeLiveSecurity

Siegeware: When criminals take over your smart building

Siegeware is what you get when cybercriminals mix the concept of ransomware with building automation systems: abuse of equipment control software to threaten access to physical facilities The post Siegeware: When criminals take over your smart building appeared first on WeLiveSecurity

Switzerland offers cash for finding security holes in its e-voting system

Anybody with hacking prowess can take a crack at reading votes or even rigging the vote count itself The post Switzerland offers cash for finding security holes in its e-voting system appeared first on WeLiveSecurity

Criminal hacking hits Managed Service Providers: Reasons and responses

Recent news articles show that MSPs are now being targeted by criminals, and for a variety of nefarious reasons. Why is this happening, and what should MSPs do about it? The post Criminal hacking hits Managed Service Providers: Reasons and responses appeared first on WeLiveSecurity

Google: Here’s how we cracked down on bad apps last year

Apps downloaded from Google Play were eight times less likely to compromise a device than apps from other sources The post Google: Here’s how we cracked down on bad apps last year appeared first on WeLiveSecurity

Smoke damage and hard drives

A closer look at the damage caused by smoke particles and some steps you can take to aid recovery The post Smoke damage and hard drives appeared first on WeLiveSecurity

Malta’s leading bank resumes operations after cyberheist-induced shutdown

Bank of Valetta, which went dark for a day after the fraudulent transfers of €13 million, is now looking to get the money back The post Malta’s leading bank resumes operations after cyberheist-induced shutdown appeared first on WeLiveSecurity

Attack at email provider wipes out almost two decades’ worth of data

Instead of seeking financial gain or other goals, the attacker leaves ‘scorched digital earth’ behind The post Attack at email provider wipes out almost two decades’ worth of data appeared first on WeLiveSecurity

When love becomes a nightmare: Online dating scams

Roses are red, violets are blue, watch out for these scams or it may happen to you The post When love becomes a nightmare: Online dating scams appeared first on WeLiveSecurity

Why you should choose a pseudonym at Starbucks

Innocently providing your name at your local coffee shop is just an example of how easy it can be for miscreants to cut through the ‘privacy’ of social media accounts The post Why you should choose a pseudonym at Starbucks appeared first on WeLiveSecurity

Apple to pay teenager who uncovered FaceTime bug

The decision to award the bug has been welcomed but one security researcher has said that they need to do more to compensate those who find bugs The post Apple to pay teenager who uncovered FaceTime bug appeared first on WeLiveSecurity

DanaBot updated with new C&C communication

ESET researchers have discovered new versions of the DanaBot Trojan, updated with a more complicated protocol for C&C communication and slight modifications to architecture and campaign IDs The post DanaBot updated with new C&C communication appeared first on WeLiveSecurity

Google rolls out Chrome extension to warn you about compromised logins

The new tool aims to help in an age when billions of login credentials are floating around the internet The post Google rolls out Chrome extension to warn you about compromised logins appeared first on WeLiveSecurity

European Commission orders recall of children’s smartwatch over privacy concerns

The watch has been found to expose its wearers to a high level of risk of being contacted and monitored by attackers The post European Commission orders recall of children’s smartwatch over privacy concerns appeared first on WeLiveSecurity

Houzz discloses data breach, asks some users to reset passwords

Citing an ongoing investigation, the company wouldn’t say how or when the incident occurred The post Houzz discloses data breach, asks some users to reset passwords appeared first on WeLiveSecurity

Four new caches of stolen logins put Collection #1 in the shade

The recently discovered tranches of stolen login credentials freely floating around the internet total 2.2 billion records The post Four new caches of stolen logins put Collection #1 in the shade appeared first on WeLiveSecurity

Japan to probe citizens’ IoT devices in the name of security

Smart devices were targeted by more than one-half of cyberattacks detected in the country in 2017 The post Japan to probe citizens’ IoT devices in the name of security appeared first on WeLiveSecurity

Cybercrime black markets: Dark web services and their prices

A closer look at cybercrime as a service on the dark web The post Cybercrime black markets: Dark web services and their prices appeared first on WeLiveSecurity

‘We’re coming for you’, global police tell DDoS attack buyers

First closing in on operators, now on users, as the hunt continues and law enforcement in many countries is about to swoop on people who bought DDoS attacks on WebStresser The post ‘We’re coming for you’, global police tell DDoS attack buyers appeared first on WeLiveSecurity

“Love you” malspam gets a makeover for massive Japan-targeted campaign

ESET researchers have detected a substantial new wave of the “Love you” malspam campaign, updated to target Japan and spread GandCrab 5.1 The post “Love you” malspam gets a makeover for massive Japan-targeted campaign appeared first on WeLiveSecurity

Apple takes Group FaceTime offline after discovery of spying bug

The company is rushing to fix a glitch that may let other iPhone users hear and see you – before you answer the call The post Apple takes Group FaceTime offline after discovery of spying bug appeared first on WeLiveSecurity

Hear me out! Thousands tell UK taxman to wipe their voice IDs

Even so, the database has grown to seven million voiceprints amid a controversy that puts the spotlight on the privacy implications of the collection of biometric information The post Hear me out! Thousands tell UK taxman to wipe their voice IDs appeared first on WeLiveSecurity

Russia hit by new wave of ransomware spam

Among the increased number of malicious JavaScript email attachments observed in January 2019, ESET researchers have spotted a large wave of ransomware-spreading spam targeting Russian users The post Russia hit by new wave of ransomware spam appeared first on WeLiveSecurity

Suspected GDPR violations prompt over 95,000 complaints

Eight months after the landmark rules came into effect, data released by the European Commission provides a glimpse into the law’s application The post Suspected GDPR violations prompt over 95,000 complaints appeared first on WeLiveSecurity

Can you spot the phish? Take Google’s test

Everybody loves quizzes. So why not take this one and hone your phish-spotting prowess? The post Can you spot the phish? Take Google’s test appeared first on WeLiveSecurity

Former employee blamed for hack of WordPress plugin maker

The plugin’s users are recommended to change their passwords on WPML’s website following havoc reportedly wrought by a disgruntled ex-employee The post Former employee blamed for hack of WordPress plugin maker appeared first on WeLiveSecurity

Google fined €50 million for violating EU data privacy rules

France’s data protection watchdog issues the first major penalty under the EU’s new privacy regime The post Google fined €50 million for violating EU data privacy rules appeared first on WeLiveSecurity

Email security does not end with your password

A strong password is a great start, but there are more ways to make sure that your email is as secure as possible The post Email security does not end with your password appeared first on WeLiveSecurity

Twitter bug may have exposed private tweets of Android users for years

If you use Twitter for Android and want your tweets to be private, you may want to play safe and review your settings The post Twitter bug may have exposed private tweets of Android users for years appeared first on WeLiveSecurity

Two men charged with hacking into SEC in stock-trading scheme

The hacking duo is believed to have exploited a software flaw and compromised several SEC workstations with malware in order to take early peeks at financial disclosures The post Two men charged with hacking into SEC in stock-trading scheme appeared first on WeLiveSecurity