Menu

Category Archives: Security Advisory

Auto Added by WPeMatico

Programmer’s Day: Resources to audit your code

Taking advantage of the celebration of the Day of the Programmer, we share some audit tools to evaluate the security of your code The post Programmer’s Day: Resources to audit your code appeared first on WeLiveSecurity

Kodi add-ons launch cryptomining campaign

ESET researchers have discovered several third-party add-ons for the popular open-source media player Kodi being used to distribute Linux and Windows cryptocurrency-mining malware The post Kodi add-ons launch cryptomining campaign appeared first on WeLiveSecurity

Patch Tuesday: Microsoft plugs zero-day hole exploited by PowerPool

Microsoft and Adobe have each shipped out their scheduled batches of patches to address security flaws in their respective software The post Patch Tuesday: Microsoft plugs zero-day hole exploited by PowerPool appeared first on WeLiveSecurity

Abandoning a domain name can come back to bite you, research shows

A domain name once left behind can catch up with you – by giving fraudsters access to a treasure trove of sensitive information The post Abandoning a domain name can come back to bite you, research shows appeared first on WeLiveSecurity

Apple yanks top grossing app from Mac App Store for grabbing private user data

The several thousand glowing reviews that Adware Doctor had garnered prior to its removal were “likely fake”, researchers say The post Apple yanks top grossing app from Mac App Store for grabbing private user data appeared first on WeLiveSecurity

100 days of GDPR

What impact has the new data protection directive had on businesses so far? The post 100 days of GDPR appeared first on WeLiveSecurity

Could home appliances knock down power grids?

Far-fetched though it may sound, the answer is yes, according to researchers, who show that electrical grids and smart home appliances could make for a dangerous mix The post Could home appliances knock down power grids? appeared first on WeLiveSecurity

PowerPool malware exploits ALPC LPE zero-day vulnerability

Malware from newly uncovered group PowerPool exploits zero-day vulnerability in the wild, only two days after its disclosure The post PowerPool malware exploits ALPC LPE zero-day vulnerability appeared first on WeLiveSecurity

Of ML and malware: What’s in store?

All things labeled Artificial Intelligence (AI) or Machine Learning (ML) are making waves, but talk of them in cybersecurity contexts often muddies the waters. A new ESET white paper sets out to bring some clarity to a subject where confusion often reigns supreme The post Of ML and malware: What’s in store? appeared first on […]

Majority of the world’s top million websites use HTTPS

The adoption of the protocol’s secure variant has continued its growth spurt in recent months, crossing the 50-percent milestone for the first time ever The post Majority of the world’s top million websites use HTTPS appeared first on WeLiveSecurity

Instagram expands 2FA and account verification

The move is part of a three-pronged plan that is intended to bolster user trust and safety on the photo-sharing platform The post Instagram expands 2FA and account verification appeared first on WeLiveSecurity

Semi-annual balance of mobile security

For Android, malware detections were down 27.48% compared to the first half of 2017; for iOS, they decreased 15% compared to the same period last year The post Semi-annual balance of mobile security appeared first on WeLiveSecurity

PoC targeting critical Apache Struts bug found online

The discovery was made barely two days after the release of a patch that fixes the critical flaw in the web application framework The post PoC targeting critical Apache Struts bug found online appeared first on WeLiveSecurity

Lukáš Štefanko: I hope other app developers don’t follow Epic‘s example

After Epic Games shunned Google Play, debates about threats faced by Android users have taken on a whole new tenor. Joining us to add his voice to the mix is ESET Malware Researcher Lukáš Štefanko The post Lukáš Štefanko: I hope other app developers don’t follow Epic‘s example appeared first on WeLiveSecurity

Why now could be a good time to fortify your Android defenses

Stop us if you’ve heard this before: avoid installing apps from outside Google Play. But what if you’re itching to battle it out in Fortnite? The post Why now could be a good time to fortify your Android defenses appeared first on WeLiveSecurity

Superdrug targeted by miscreants who claim to have stolen customer data

The retailer says that whatever data the crooks have obtained, they weren’t stolen through a breach of its systems The post Superdrug targeted by miscreants who claim to have stolen customer data appeared first on WeLiveSecurity

Turla: In and out of its unique Outlook backdoor

The latest ESET research offers a rare glimpse into the mechanics of a particularly stealthy and resilient backdoor that the Turla cyberespionage group can fully control via PDF files attached to emails The post Turla: In and out of its unique Outlook backdoor appeared first on WeLiveSecurity

Smart irrigation systems vulnerable to attacks, warn researchers

Internet-connected irrigation systems suffer from security gaps that could be exploited by attackers aiming, for example, to deplete a city’s water reserves, researchers warn The post Smart irrigation systems vulnerable to attacks, warn researchers appeared first on WeLiveSecurity

A heated summer for cybersecurity in Canada

An overview of some of the cyberattacks that Canadian organizations faced in the summer months of 2018 The post A heated summer for cybersecurity in Canada appeared first on WeLiveSecurity

Australian schoolboy hacks into Apple’s network, steals files

His lawyer claims that the teen did the hacking because he admired Apple and dreamed of landing a job in the company The post Australian schoolboy hacks into Apple’s network, steals files appeared first on WeLiveSecurity

Week in security with Tony Anscombe

The first week in security video round-up from WeLiveSecurity The post Week in security with Tony Anscombe appeared first on WeLiveSecurity

Some 2.6 billion data records exposed in first half of 2018

The newly-released report provides an overview of the data breach landscape in the first half of this year The post Some 2.6 billion data records exposed in first half of 2018 appeared first on WeLiveSecurity

Instagram users locked out of accounts en masse

If you’re an Instagrammer, you may want to take some basic precautions, such as picking a strong and unique password and signing up for two-factor authentication sooner rather than later The post Instagram users locked out of accounts en masse appeared first on WeLiveSecurity

Black Hat 2018: AI was supposed to fix security – what happened?

Heralded as the answer to many cybersecurity issues, machine learning hasn’t always delivered The post Black Hat 2018: AI was supposed to fix security – what happened? appeared first on WeLiveSecurity

Can cramming code with bugs make it more secure? Some think so

Unbeknownst to exploit writers, the seemingly mouth-watering bugs would be bogus and non-exploitable The post Can cramming code with bugs make it more secure? Some think so appeared first on WeLiveSecurity

Black Hat: Protecting Industrial Control System

Aiming to protect critical infrastructure against attacks The post Black Hat: Protecting Industrial Control System appeared first on WeLiveSecurity

Attackers grab hold of PGA of America files, demand ransom

The golf association is said to have had little success with restoring access to its files so far The post Attackers grab hold of PGA of America files, demand ransom appeared first on WeLiveSecurity

Interviewing ESET’s experts about the Web’s journey so far – part 3

All good things come to an end, and we’re rounding off our series of interviews to mark the 27th anniversary since computer scientist Tim Berners-Lee publicly announced the World Wide Web project The post Interviewing ESET’s experts about the Web’s journey so far – part 3 appeared first on WeLiveSecurity

Software bugs put nearly 100 million health records at risk of exposure

The slew of vulnerabilities – since patched – were found without the use of automated testing tools The post Software bugs put nearly 100 million health records at risk of exposure appeared first on WeLiveSecurity

Interviewing ESET’s experts about the Web’s journey so far – part 2

Today, we continue with our series of conversations with ESET’s security pros to hear what they have to say about the evolution of the World Wide Web since it was publicly announced 27 years ago The post Interviewing ESET’s experts about the Web’s journey so far – part 2 appeared first on WeLiveSecurity

Apple chip supplier blames WannaCryptor variant for plant shutdowns

The malware outbreak has even prompted concerns of delays in the shipments of the next wave of iPhones The post Apple chip supplier blames WannaCryptor variant for plant shutdowns appeared first on WeLiveSecurity

Interviewing ESET’s experts about the Web’s journey so far – part 1

What has the journey of the World Wide Web been like so far, as seen and experienced by ESET’s security folk? ESET Senior Research Fellow David Harley provides his take in the first installment of our series of interviews marking the Web’s 27th birthday. The post Interviewing ESET’s experts about the Web’s journey so far […]

Reddit reveals breach as attacker circumvents staff’s 2FA

The company has learned the hard way that there are better ways to deliver two-factor authentication than via text messages The post Reddit reveals breach as attacker circumvents staff’s 2FA appeared first on WeLiveSecurity

HP offers rewards for hacking its printers

But don’t get too excited just yet: the first-of-its-kind bug bounty program for printers is invite-only for now The post HP offers rewards for hacking its printers appeared first on WeLiveSecurity

OneDrive app for Android updated with fingerprint authentication

With this update, Microsoft is bringing a feature for Android users that has been available on iOS devices for quite a while now The post OneDrive app for Android updated with fingerprint authentication appeared first on WeLiveSecurity

Inmates hack tablets for free credits prison

The nature of the vulnerability hasn’t been disclosed, but is said to have already been identified and fixed The post Inmates hack tablets for free credits prison appeared first on WeLiveSecurity

Google wants you to beef up your account security with its own hardware token

The company credits hardware-based two-factor authentication with practically eliminating the problem of phishing attacks that have targeted its own employees of late The post Google wants you to beef up your account security with its own hardware token appeared first on WeLiveSecurity

Chrome now flags HTTP sites as “not secure”

This is bad news for many websites that have yet to embrace encrypted connections The post Chrome now flags HTTP sites as “not secure” appeared first on WeLiveSecurity

Fake banking apps on Google Play leak stolen credit card data

Fraudsters are using bogus apps to convince users of three Indian banks to divulge their personal data The post Fake banking apps on Google Play leak stolen credit card data appeared first on WeLiveSecurity

I saw what you did…or did I?

It might seem legit but there are several reasons why you should not always hit the panic button when someone claims to have your email password The post I saw what you did…or did I? appeared first on WeLiveSecurity

Hook, line, and sinker: How to avoid looking ‘phish-y’

Top tips to help you avoid being caught receiving or sending phishing-looking emails The post Hook, line, and sinker: How to avoid looking ‘phish-y’ appeared first on WeLiveSecurity

Bluetooth bug could expose devices to snoopers

Patches have already been released or are expected to see the light of day soon The post Bluetooth bug could expose devices to snoopers appeared first on WeLiveSecurity

Major sites still largely lax on prompting users towards safer password choices, study finds

A study assessed whether or not the most popular English-language websites help users strengthen their security by providing them with guidance on creating safer passwords during account sign-up or password-change processes The post Major sites still largely lax on prompting users towards safer password choices, study finds appeared first on WeLiveSecurity

Canada tackles malicious online advertising

Federal agency issues Notices of Violation to Datablocks and Sunlight Media for allegedly facilitating the installation of malware through online advertising The post Canada tackles malicious online advertising appeared first on WeLiveSecurity

Google slapped with €4.34bn fine by EU over antitrust violations

Tech giant has 90 days to comply with ruling or faces further penalties over ‘anti-competitive’ practices The post Google slapped with €4.34bn fine by EU over antitrust violations appeared first on WeLiveSecurity

British Airways cancelled flights at Heathrow after ‘IT system issue’

Thousands of British Airways passengers left stranded at Heathrow airport following incident The post British Airways cancelled flights at Heathrow after ‘IT system issue’ appeared first on WeLiveSecurity

A deep dive down the Vermin RAThole

ESET researchers have analyzed remote access tools cybercriminals have been using in an ongoing espionage campaign to systematically spy on Ukrainian government institutions and exfiltrate data from their systems The post A deep dive down the Vermin RAThole appeared first on WeLiveSecurity

Irishman extradited to the US to face charges relating to Silk Road

Gary Davis accused of working as an administrator for the notorious dark web marketplace appears in a federal court in New York The post Irishman extradited to the US to face charges relating to Silk Road appeared first on WeLiveSecurity

Facebook fined over data privacy scandal

Social media giant fined in the UK for failing to protect users’ personal information and for a lack of transparency The post Facebook fined over data privacy scandal appeared first on WeLiveSecurity

Trends 2018: Doing time for cybercrime

Law enforcement and malware research join forces to take down cybercriminals The post Trends 2018: Doing time for cybercrime appeared first on WeLiveSecurity

Ammyy Admin compromised with malware again; World Cup used as cover

Website altered to serve a malware-tainted version of otherwise legitimate software with the global event in Russia acting as a smokescreen The post Ammyy Admin compromised with malware again; World Cup used as cover appeared first on WeLiveSecurity

Certificates stolen from Taiwanese tech-companies misused in Plead malware campaign

D-Link and Changing Information Technologies code-signing certificates stolen and abused by highly skilled cyberespionage group focused on East Asia, particularly Taiwan The post Certificates stolen from Taiwanese tech-companies misused in Plead malware campaign appeared first on WeLiveSecurity

Attackers could use heat traces left on keyboard to steal passwords

The attack, called “Thermanator”, could use your body heat against you in order to steal your credentials or any other short string of text that you have typed on a computer keyboard The post Attackers could use heat traces left on keyboard to steal passwords appeared first on WeLiveSecurity

Five tips for pentesters in iOS

Recommendations for pentesters looking for security flaws in iOS applications made by developers The post Five tips for pentesters in iOS appeared first on WeLiveSecurity

Going on vacation? Five things to do before you leave

You’ve set up an out-of-office auto-responder and packed your stuff, but have you done all of your “homework” before you rush out the front door for that well-deserved time off? The post Going on vacation? Five things to do before you leave appeared first on WeLiveSecurity

Britain’s tax authority reports takedown of record 20,000 fake sites

Her Majesty’s Revenue & Customs (HMRC) is “consistently the most abused government brand”, according to the National Cyber Security Centre (NCSC) The post Britain’s tax authority reports takedown of record 20,000 fake sites appeared first on WeLiveSecurity

The principle of least privilege: A strategy of limiting access to what is essential

The principle of least privilege is a security strategy applicable to different areas, which is based on the idea of only granting those permissions that are necessary for the performance of a certain activity The post The principle of least privilege: A strategy of limiting access to what is essential appeared first on WeLiveSecurity

How (over)sharing on social media can trip you up

Profuse recounting of details from your life via social media may come at a price The post How (over)sharing on social media can trip you up appeared first on WeLiveSecurity

Twitter bots, disassemble

Social media giants announce new measures to tackle bots and abusers The post Twitter bots, disassemble appeared first on WeLiveSecurity

World Cup squads briefed on cybersecurity best practices

The football associations of countries competing at Russia 2018 are taking no chances when it comes to cyber-related issues The post World Cup squads briefed on cybersecurity best practices appeared first on WeLiveSecurity

Wi-Fi security gets a boost as WPA3 standard is launched

The new wireless security protocol is poised to make hacking Wi-Fi connections a whole lot harder The post Wi-Fi security gets a boost as WPA3 standard is launched appeared first on WeLiveSecurity

Microsoft Edge bug could be exploited to spill your emails to malicious sites

Since a patch for the flaw has already been released, users are well advised to make sure that they’re running the browser’s most recent version The post Microsoft Edge bug could be exploited to spill your emails to malicious sites appeared first on WeLiveSecurity

Ham-fisted hacker gets jail time for serial DDoS attacks

The tale of “Bitcoin Baron” reveals a worrying picture and illustrates how easy it has become to wreak havoc on the internet The post Ham-fisted hacker gets jail time for serial DDoS attacks appeared first on WeLiveSecurity

South Korea’s largest cryptocurrency exchange hacked

Bithumb has claimed that $31.5 million worth of virtual coins were stolen by hackers The post South Korea’s largest cryptocurrency exchange hacked appeared first on WeLiveSecurity

11 ‘teammates’ to help you win your own cybersecurity game

Our lineup may seem heavy on the defensive side, but such is the nature of game plans for warding off a range of threats lurking in cyberspace The post 11 ‘teammates’ to help you win your own cybersecurity game appeared first on WeLiveSecurity

Europol and partners dismantle prolific cyber-extortion gang

The arrest of a 25-year-old French man in Thailand apparently seals the fate of Rex Mundi, a hack-and-extort collective that operated since at least 2012 The post Europol and partners dismantle prolific cyber-extortion gang appeared first on WeLiveSecurity

New Telegram-abusing Android RAT discovered in the wild

Entirely new malware family discovered by ESET researchers The post New Telegram-abusing Android RAT discovered in the wild appeared first on WeLiveSecurity

Stop Cyberbullying Day: Advice for victims and witnesses

A comprehensive list of some of the online resources available to victims, their families and friends The post Stop Cyberbullying Day: Advice for victims and witnesses appeared first on WeLiveSecurity

Phishing anniversary: Here’s a free $50/month subscription

Adidas “prize” used as bait in attempt to lure people into biting The post Phishing anniversary: Here’s a free $50/month subscription appeared first on WeLiveSecurity

World Cup dream team: ESET vs. Malware

An all-star line-up to go head-to-head with malware The post World Cup dream team: ESET vs. Malware appeared first on WeLiveSecurity

Major breach at British retailer Dixons Carphone affects nearly six million bank cards

Intruders also accessed 1.2 million personal data records, such as names, addresses or email addresses, in what is shaping up to be one of Britain’s biggest data breaches involving a single company The post Major breach at British retailer Dixons Carphone affects nearly six million bank cards appeared first on WeLiveSecurity

Chile to revolutionize cybersecurity after the recent cyberattack

The country’s financial authorities met to establish a new cybersecurity plan following attack on the Bank of Chile The post Chile to revolutionize cybersecurity after the recent cyberattack appeared first on WeLiveSecurity

World Cup watching: The common threats found when using streaming sites

On the eve of the 2018 FIFA World Cup in Russia, we take a closer look at the possible cybersecurity risks that exist on sports streaming websites The post World Cup watching: The common threats found when using streaming sites appeared first on WeLiveSecurity

US government report highlights gaps in battle against botnets

The report also identifies goals that are intended to help mitigate risks associated with botnets and to increase the resilience of the internet ecosystem The post US government report highlights gaps in battle against botnets appeared first on WeLiveSecurity

Spain’s La Liga app uses fans’ phones to detect illegal soccer broadcasts

La Liga says that the functionality requires the user’s express consent and that it is only intended to detect unauthorized broadcasts of soccer games. The post Spain’s La Liga app uses fans’ phones to detect illegal soccer broadcasts appeared first on WeLiveSecurity

74 people arrested in US-led crackdown on email scams

The international effort to disrupt Business Email Compromise (BEC) schemes also resulted in the seizure of nearly $2.4 million and the recovery of around $14 million in fraudulent wire transfers. The post 74 people arrested in US-led crackdown on email scams appeared first on WeLiveSecurity

Android users: Beware these popularity-faking tricks on Google Play

Tricksters have been misleading users about the functionality of apps by displaying bogus download numbers The post Android users: Beware these popularity-faking tricks on Google Play appeared first on WeLiveSecurity

Interred in the Internet of Everything

The security implications of devices connecting and sharing data The post Interred in the Internet of Everything appeared first on WeLiveSecurity

Atlanta’s ransomware attack: Police dashcam video archives lost forever

The city has spent $5 million to restore files, rebuild impacted systems, and harden its cyber-defenses The post Atlanta’s ransomware attack: Police dashcam video archives lost forever appeared first on WeLiveSecurity

InvisiMole: surprisingly equipped spyware, undercover since 2013

Hunting for secrets from high-profile targets while staying in the shadows The post InvisiMole: surprisingly equipped spyware, undercover since 2013 appeared first on WeLiveSecurity

VPNFilter update: More bad news for routers

New research into VPNFilter finds more devices hit by malware that’s nastier than first thought, making rebooting and remediating of routers more urgent. The post VPNFilter update: More bad news for routers appeared first on WeLiveSecurity

You have NOT won! A look at fake FIFA World Cup-themed lotteries and giveaways

With the 2018 FIFA World Cup in Russia just days away, fraudsters are increasingly using all things soccer as bait to reel in unsuspecting fans so that they get more than they bargained for The post You have NOT won! A look at fake FIFA World Cup-themed lotteries and giveaways appeared first on WeLiveSecurity

WeLiveSecurity named Best Corporate Security Blog!

Thanks to everyone who reads us and voted for us! The post WeLiveSecurity named Best Corporate Security Blog! appeared first on WeLiveSecurity

The cyberattack on banks in Mexico: The challenges posed to cybersecurity

Following the massive cyberattack on banks in Mexico, we consider what can cybersecurity can do to help the industry The post The cyberattack on banks in Mexico: The challenges posed to cybersecurity appeared first on WeLiveSecurity

Router reboot: How to, why to, and what not to do

The FBI say yes but should you follow this advice? And if you do follow it, do you know how to do so safely? The post Router reboot: How to, why to, and what not to do appeared first on WeLiveSecurity

False contest to win jersey of the Brazilian team found on WhatsApp

The scam circulated through WhatsApp aimed at users in Brazil claiming that Nike will give away the jersey that the team will wear at Russia 2018. The post False contest to win jersey of the Brazilian team found on WhatsApp appeared first on WeLiveSecurity

An acoustic attack can bluescreen your Windows computer

Security researchers have demonstrated how attackers could cause physical damage to hard drives, and cause PCs to crash, just by playing sounds through a computer’s speaker. The post An acoustic attack can bluescreen your Windows computer appeared first on WeLiveSecurity

Trends 2018: Critical infrastructure attacks on the rise

Healthcare sectors, critical manufacturing, food production and transportation also said to be targets for cybercriminals The post Trends 2018: Critical infrastructure attacks on the rise appeared first on WeLiveSecurity

World Cup scams: how to avoid an own goal

Whether travelling to enjoy the matches in person, or watching from home, fans should be on the lookout for foul play The post World Cup scams: how to avoid an own goal appeared first on WeLiveSecurity

Europol sets up EU-wide team to fight dark web crime

Embedded within the agency’s European Cybercrime Centre (EC3), the new team will also work together with law enforcement globally in an effort to reduce the size of the underground illegal economy The post Europol sets up EU-wide team to fight dark web crime appeared first on WeLiveSecurity

More curious, less cautious: Protecting kids online

How we can help protect a generation for which digital is the way of the world? The post More curious, less cautious: Protecting kids online appeared first on WeLiveSecurity

UNICEF now using cryptocurrency mining for fundraising

So far in 2018, the NGO has launched two charity campaigns with the aim of raising funds through cryptocurrency mining. The post UNICEF now using cryptocurrency mining for fundraising appeared first on WeLiveSecurity

Two Canadian banks warn attackers may have stolen customer data

Simplii Financial and Bank of Montreal are believed to have suffered a twin attack that was soon followed by blackmail threats The post Two Canadian banks warn attackers may have stolen customer data appeared first on WeLiveSecurity

Scammers raid man’s bank account while he waits on hold to fraud hotline

Criminals have set their sights on customers of a bank that has been struggling with a switchover to a new computer platform The post Scammers raid man’s bank account while he waits on hold to fraud hotline appeared first on WeLiveSecurity

Hacker jailed for selling personal data on dark web

Grant West used popular food app Just Eat to gain access to thousands of emails and passwords The post Hacker jailed for selling personal data on dark web appeared first on WeLiveSecurity

Why GDPR affects companies around the world (video)

Learn what businesses need to be mindful of with the new legislation The post Why GDPR affects companies around the world (video) appeared first on WeLiveSecurity

Woman says Alexa recorded and shared the private conversation she was having with her husband

It’s every Amazon Alexa owner’s worst nightmare – your private conversations not just being listened to, but shared with random contacts without your knowledge. The post Woman says Alexa recorded and shared the private conversation she was having with her husband appeared first on WeLiveSecurity

Facebook refines 2FA setup, adds authenticator app support

Do try this at home! If you haven’t taken advantage of the extra protection that two-factor authentication offers, now is a great time to do so. And you don’t even need to hand over your phone number. The post Facebook refines 2FA setup, adds authenticator app support appeared first on WeLiveSecurity

BackSwap malware finds innovative ways to empty bank accounts

ESET researchers have discovered a piece of banking malware that employs a new technique to bypass dedicated browser protection measures The post BackSwap malware finds innovative ways to empty bank accounts appeared first on WeLiveSecurity

GDPR: One rule to rule them all – legally

It’s almost here but what are the legal ramifications of the incoming legislation for businesses The post GDPR: One rule to rule them all – legally appeared first on WeLiveSecurity