Menu

Category Archives: Security Advisory

Auto Added by WPeMatico

Most routers full of firmware flaws that leave users at risk

If you own a Wi-Fi router, it may well be riddled with security holes that expose you to a host of threats The post Most routers full of firmware flaws that leave users at risk appeared first on WeLiveSecurity

Virus Bulletin 2018: Supply chain hacking grows up

Striking the balance between supply, demand and safety is a major concern The post Virus Bulletin 2018: Supply chain hacking grows up appeared first on WeLiveSecurity

Make it a cyber-habit: Five simple steps to staying safe online

What are some essential steps you can take to increase your online safety – now and in the long run? The post Make it a cyber-habit: Five simple steps to staying safe online appeared first on WeLiveSecurity

Why ask the public about cybercrime and cybersecurity?

Answers could help raise awareness of situations that people fear The post Why ask the public about cybercrime and cybersecurity? appeared first on WeLiveSecurity

Virus Bulletin 2018: Attack velocity ramps up

Some tips for helping to keep your data more secure from the floor of VB 2018 The post Virus Bulletin 2018: Attack velocity ramps up appeared first on WeLiveSecurity

Facebook: No evidence attackers used stolen access tokens on third-party sites

The social networking behemoth is expected to face a formal investigation by Ireland’s Data Protection Commission in what could be the “acid test” of GDPR since the law became effective in May The post Facebook: No evidence attackers used stolen access tokens on third-party sites appeared first on WeLiveSecurity

IT forensic tools: How to find the right one for each incident

Some online resources that will help you find the most suitable IT forensic tools for each case The post IT forensic tools: How to find the right one for each incident appeared first on WeLiveSecurity

Why keeping your cyber-wits about you matters

WeLiveSecurity is happy to support the European Cyber Security Month (ECSM) with its own “two cents”, split into four articles over the course of October that will be dedicated to promoting the campaign’s goals The post Why keeping your cyber-wits about you matters appeared first on WeLiveSecurity

50 million Facebook users affected in breach

It has yet to be determined whether the accounts were misused or what information was accessed. In the meantime, you can improve your account security with a few easy steps The post 50 million Facebook users affected in breach appeared first on WeLiveSecurity

Top tips for protecting your Smart TV

The final few months of 2018 will likely be a busy time of year for people and cybercriminals will be no different as they continue to look for weak spots in networks The post Top tips for protecting your Smart TV appeared first on WeLiveSecurity

Who’s behind DDoS attacks at UK universities?

The timing of the attacks suggests that many attempts to take the networks offline may not necessarily be perpetrated by organized cybercriminal gangs The post Who’s behind DDoS attacks at UK universities? appeared first on WeLiveSecurity

LoJax: First UEFI rootkit found in the wild, courtesy of the Sednit group

ESET researchers have shown that the Sednit operators used different components of the LoJax malware to target a few government organizations in the Balkans as well as in Central and Eastern Europe The post LoJax: First UEFI rootkit found in the wild, courtesy of the Sednit group appeared first on WeLiveSecurity

Twitter patches bug that may have spilled users’ private messages

The flaw affected one of the platform’s APIs between May 2017 and September 10 of this year, when it was patched “within hours” The post Twitter patches bug that may have spilled users’ private messages appeared first on WeLiveSecurity

Defending your company from cyberattack

ESET CTO Juraj Malcho outlines some of the ways in which organizations can reduce their cybersecurity risk The post Defending your company from cyberattack appeared first on WeLiveSecurity

How to improve hiring practices in cybersecurity

Should schools and businesses do more to combat the shortfall of cybersecurity professionals by changing the hiring process for those interested in having a career in the industry? The post How to improve hiring practices in cybersecurity appeared first on WeLiveSecurity

The Occasional Orator Part 2

Public speaking and presenting at conferences can be daunting for the majority of people but by including some subtle tricks, the speaker can deliver a stronger message The post The Occasional Orator Part 2 appeared first on WeLiveSecurity

Attackers crack Newegg’s defenses, slurp customers’ credit card data

The skimmer, injected into the store’s payment page, harvested credit-card details from the store’s online customers for more than a month The post Attackers crack Newegg’s defenses, slurp customers’ credit card data appeared first on WeLiveSecurity

Mirai’s architects avoid prison thanks to work for FBI

Instead, the three men will cooperate with law enforcement and the broader research community – an area in which, it turns out, they already have quite some experience The post Mirai’s architects avoid prison thanks to work for FBI appeared first on WeLiveSecurity

Fake finance apps on Google Play target users from around the world

Cybercrooks use bogus apps to phish six online banks and cryptocurrency exchange The post Fake finance apps on Google Play target users from around the world appeared first on WeLiveSecurity

The Occasional Orator Part 1

Speaking at conferences can be daunting for presenters but often it is about striking the right balance between content and delivery The post The Occasional Orator Part 1 appeared first on WeLiveSecurity

Bristol airport takes flight screens offline after apparent ransomware attack

The screens in “key locations” are back up and running again, while the airport paid no ransom to return its systems to working order The post Bristol airport takes flight screens offline after apparent ransomware attack appeared first on WeLiveSecurity

One in three UK orgs hit by cryptojacking in previous month, survey finds

Conversely, only a little over one-third of IT executives believe that their systems have never been hijacked to surreptitiously mine digital currencies The post One in three UK orgs hit by cryptojacking in previous month, survey finds appeared first on WeLiveSecurity

Programmer’s Day: Resources to audit your code

Taking advantage of the celebration of the Day of the Programmer, we share some audit tools to evaluate the security of your code The post Programmer’s Day: Resources to audit your code appeared first on WeLiveSecurity

Kodi add-ons launch cryptomining campaign

ESET researchers have discovered several third-party add-ons for the popular open-source media player Kodi being used to distribute Linux and Windows cryptocurrency-mining malware The post Kodi add-ons launch cryptomining campaign appeared first on WeLiveSecurity

Patch Tuesday: Microsoft plugs zero-day hole exploited by PowerPool

Microsoft and Adobe have each shipped out their scheduled batches of patches to address security flaws in their respective software The post Patch Tuesday: Microsoft plugs zero-day hole exploited by PowerPool appeared first on WeLiveSecurity

Abandoning a domain name can come back to bite you, research shows

A domain name once left behind can catch up with you – by giving fraudsters access to a treasure trove of sensitive information The post Abandoning a domain name can come back to bite you, research shows appeared first on WeLiveSecurity

Apple yanks top grossing app from Mac App Store for grabbing private user data

The several thousand glowing reviews that Adware Doctor had garnered prior to its removal were “likely fake”, researchers say The post Apple yanks top grossing app from Mac App Store for grabbing private user data appeared first on WeLiveSecurity

100 days of GDPR

What impact has the new data protection directive had on businesses so far? The post 100 days of GDPR appeared first on WeLiveSecurity

Could home appliances knock down power grids?

Far-fetched though it may sound, the answer is yes, according to researchers, who show that electrical grids and smart home appliances could make for a dangerous mix The post Could home appliances knock down power grids? appeared first on WeLiveSecurity

PowerPool malware exploits ALPC LPE zero-day vulnerability

Malware from newly uncovered group PowerPool exploits zero-day vulnerability in the wild, only two days after its disclosure The post PowerPool malware exploits ALPC LPE zero-day vulnerability appeared first on WeLiveSecurity

Of ML and malware: What’s in store?

All things labeled Artificial Intelligence (AI) or Machine Learning (ML) are making waves, but talk of them in cybersecurity contexts often muddies the waters. A new ESET white paper sets out to bring some clarity to a subject where confusion often reigns supreme The post Of ML and malware: What’s in store? appeared first on […]

Majority of the world’s top million websites use HTTPS

The adoption of the protocol’s secure variant has continued its growth spurt in recent months, crossing the 50-percent milestone for the first time ever The post Majority of the world’s top million websites use HTTPS appeared first on WeLiveSecurity

Instagram expands 2FA and account verification

The move is part of a three-pronged plan that is intended to bolster user trust and safety on the photo-sharing platform The post Instagram expands 2FA and account verification appeared first on WeLiveSecurity

Semi-annual balance of mobile security

For Android, malware detections were down 27.48% compared to the first half of 2017; for iOS, they decreased 15% compared to the same period last year The post Semi-annual balance of mobile security appeared first on WeLiveSecurity

PoC targeting critical Apache Struts bug found online

The discovery was made barely two days after the release of a patch that fixes the critical flaw in the web application framework The post PoC targeting critical Apache Struts bug found online appeared first on WeLiveSecurity

Lukáš Štefanko: I hope other app developers don’t follow Epic‘s example

After Epic Games shunned Google Play, debates about threats faced by Android users have taken on a whole new tenor. Joining us to add his voice to the mix is ESET Malware Researcher Lukáš Štefanko The post Lukáš Štefanko: I hope other app developers don’t follow Epic‘s example appeared first on WeLiveSecurity

Why now could be a good time to fortify your Android defenses

Stop us if you’ve heard this before: avoid installing apps from outside Google Play. But what if you’re itching to battle it out in Fortnite? The post Why now could be a good time to fortify your Android defenses appeared first on WeLiveSecurity

Superdrug targeted by miscreants who claim to have stolen customer data

The retailer says that whatever data the crooks have obtained, they weren’t stolen through a breach of its systems The post Superdrug targeted by miscreants who claim to have stolen customer data appeared first on WeLiveSecurity

Turla: In and out of its unique Outlook backdoor

The latest ESET research offers a rare glimpse into the mechanics of a particularly stealthy and resilient backdoor that the Turla cyberespionage group can fully control via PDF files attached to emails The post Turla: In and out of its unique Outlook backdoor appeared first on WeLiveSecurity

Smart irrigation systems vulnerable to attacks, warn researchers

Internet-connected irrigation systems suffer from security gaps that could be exploited by attackers aiming, for example, to deplete a city’s water reserves, researchers warn The post Smart irrigation systems vulnerable to attacks, warn researchers appeared first on WeLiveSecurity

A heated summer for cybersecurity in Canada

An overview of some of the cyberattacks that Canadian organizations faced in the summer months of 2018 The post A heated summer for cybersecurity in Canada appeared first on WeLiveSecurity

Australian schoolboy hacks into Apple’s network, steals files

His lawyer claims that the teen did the hacking because he admired Apple and dreamed of landing a job in the company The post Australian schoolboy hacks into Apple’s network, steals files appeared first on WeLiveSecurity

Week in security with Tony Anscombe

The first week in security video round-up from WeLiveSecurity The post Week in security with Tony Anscombe appeared first on WeLiveSecurity

Some 2.6 billion data records exposed in first half of 2018

The newly-released report provides an overview of the data breach landscape in the first half of this year The post Some 2.6 billion data records exposed in first half of 2018 appeared first on WeLiveSecurity

Instagram users locked out of accounts en masse

If you’re an Instagrammer, you may want to take some basic precautions, such as picking a strong and unique password and signing up for two-factor authentication sooner rather than later The post Instagram users locked out of accounts en masse appeared first on WeLiveSecurity

Black Hat 2018: AI was supposed to fix security – what happened?

Heralded as the answer to many cybersecurity issues, machine learning hasn’t always delivered The post Black Hat 2018: AI was supposed to fix security – what happened? appeared first on WeLiveSecurity

Can cramming code with bugs make it more secure? Some think so

Unbeknownst to exploit writers, the seemingly mouth-watering bugs would be bogus and non-exploitable The post Can cramming code with bugs make it more secure? Some think so appeared first on WeLiveSecurity

Black Hat: Protecting Industrial Control System

Aiming to protect critical infrastructure against attacks The post Black Hat: Protecting Industrial Control System appeared first on WeLiveSecurity

Attackers grab hold of PGA of America files, demand ransom

The golf association is said to have had little success with restoring access to its files so far The post Attackers grab hold of PGA of America files, demand ransom appeared first on WeLiveSecurity

Interviewing ESET’s experts about the Web’s journey so far – part 3

All good things come to an end, and we’re rounding off our series of interviews to mark the 27th anniversary since computer scientist Tim Berners-Lee publicly announced the World Wide Web project The post Interviewing ESET’s experts about the Web’s journey so far – part 3 appeared first on WeLiveSecurity

Software bugs put nearly 100 million health records at risk of exposure

The slew of vulnerabilities – since patched – were found without the use of automated testing tools The post Software bugs put nearly 100 million health records at risk of exposure appeared first on WeLiveSecurity

Interviewing ESET’s experts about the Web’s journey so far – part 2

Today, we continue with our series of conversations with ESET’s security pros to hear what they have to say about the evolution of the World Wide Web since it was publicly announced 27 years ago The post Interviewing ESET’s experts about the Web’s journey so far – part 2 appeared first on WeLiveSecurity

Apple chip supplier blames WannaCryptor variant for plant shutdowns

The malware outbreak has even prompted concerns of delays in the shipments of the next wave of iPhones The post Apple chip supplier blames WannaCryptor variant for plant shutdowns appeared first on WeLiveSecurity

Interviewing ESET’s experts about the Web’s journey so far – part 1

What has the journey of the World Wide Web been like so far, as seen and experienced by ESET’s security folk? ESET Senior Research Fellow David Harley provides his take in the first installment of our series of interviews marking the Web’s 27th birthday. The post Interviewing ESET’s experts about the Web’s journey so far […]

Reddit reveals breach as attacker circumvents staff’s 2FA

The company has learned the hard way that there are better ways to deliver two-factor authentication than via text messages The post Reddit reveals breach as attacker circumvents staff’s 2FA appeared first on WeLiveSecurity

HP offers rewards for hacking its printers

But don’t get too excited just yet: the first-of-its-kind bug bounty program for printers is invite-only for now The post HP offers rewards for hacking its printers appeared first on WeLiveSecurity

OneDrive app for Android updated with fingerprint authentication

With this update, Microsoft is bringing a feature for Android users that has been available on iOS devices for quite a while now The post OneDrive app for Android updated with fingerprint authentication appeared first on WeLiveSecurity

Inmates hack tablets for free credits prison

The nature of the vulnerability hasn’t been disclosed, but is said to have already been identified and fixed The post Inmates hack tablets for free credits prison appeared first on WeLiveSecurity

Google wants you to beef up your account security with its own hardware token

The company credits hardware-based two-factor authentication with practically eliminating the problem of phishing attacks that have targeted its own employees of late The post Google wants you to beef up your account security with its own hardware token appeared first on WeLiveSecurity

Chrome now flags HTTP sites as “not secure”

This is bad news for many websites that have yet to embrace encrypted connections The post Chrome now flags HTTP sites as “not secure” appeared first on WeLiveSecurity

Fake banking apps on Google Play leak stolen credit card data

Fraudsters are using bogus apps to convince users of three Indian banks to divulge their personal data The post Fake banking apps on Google Play leak stolen credit card data appeared first on WeLiveSecurity

I saw what you did…or did I?

It might seem legit but there are several reasons why you should not always hit the panic button when someone claims to have your email password The post I saw what you did…or did I? appeared first on WeLiveSecurity

Hook, line, and sinker: How to avoid looking ‘phish-y’

Top tips to help you avoid being caught receiving or sending phishing-looking emails The post Hook, line, and sinker: How to avoid looking ‘phish-y’ appeared first on WeLiveSecurity

Bluetooth bug could expose devices to snoopers

Patches have already been released or are expected to see the light of day soon The post Bluetooth bug could expose devices to snoopers appeared first on WeLiveSecurity

Major sites still largely lax on prompting users towards safer password choices, study finds

A study assessed whether or not the most popular English-language websites help users strengthen their security by providing them with guidance on creating safer passwords during account sign-up or password-change processes The post Major sites still largely lax on prompting users towards safer password choices, study finds appeared first on WeLiveSecurity

Canada tackles malicious online advertising

Federal agency issues Notices of Violation to Datablocks and Sunlight Media for allegedly facilitating the installation of malware through online advertising The post Canada tackles malicious online advertising appeared first on WeLiveSecurity

Google slapped with €4.34bn fine by EU over antitrust violations

Tech giant has 90 days to comply with ruling or faces further penalties over ‘anti-competitive’ practices The post Google slapped with €4.34bn fine by EU over antitrust violations appeared first on WeLiveSecurity

British Airways cancelled flights at Heathrow after ‘IT system issue’

Thousands of British Airways passengers left stranded at Heathrow airport following incident The post British Airways cancelled flights at Heathrow after ‘IT system issue’ appeared first on WeLiveSecurity

A deep dive down the Vermin RAThole

ESET researchers have analyzed remote access tools cybercriminals have been using in an ongoing espionage campaign to systematically spy on Ukrainian government institutions and exfiltrate data from their systems The post A deep dive down the Vermin RAThole appeared first on WeLiveSecurity

Irishman extradited to the US to face charges relating to Silk Road

Gary Davis accused of working as an administrator for the notorious dark web marketplace appears in a federal court in New York The post Irishman extradited to the US to face charges relating to Silk Road appeared first on WeLiveSecurity

Facebook fined over data privacy scandal

Social media giant fined in the UK for failing to protect users’ personal information and for a lack of transparency The post Facebook fined over data privacy scandal appeared first on WeLiveSecurity

Trends 2018: Doing time for cybercrime

Law enforcement and malware research join forces to take down cybercriminals The post Trends 2018: Doing time for cybercrime appeared first on WeLiveSecurity

Ammyy Admin compromised with malware again; World Cup used as cover

Website altered to serve a malware-tainted version of otherwise legitimate software with the global event in Russia acting as a smokescreen The post Ammyy Admin compromised with malware again; World Cup used as cover appeared first on WeLiveSecurity

Certificates stolen from Taiwanese tech-companies misused in Plead malware campaign

D-Link and Changing Information Technologies code-signing certificates stolen and abused by highly skilled cyberespionage group focused on East Asia, particularly Taiwan The post Certificates stolen from Taiwanese tech-companies misused in Plead malware campaign appeared first on WeLiveSecurity

Attackers could use heat traces left on keyboard to steal passwords

The attack, called “Thermanator”, could use your body heat against you in order to steal your credentials or any other short string of text that you have typed on a computer keyboard The post Attackers could use heat traces left on keyboard to steal passwords appeared first on WeLiveSecurity

Five tips for pentesters in iOS

Recommendations for pentesters looking for security flaws in iOS applications made by developers The post Five tips for pentesters in iOS appeared first on WeLiveSecurity

Going on vacation? Five things to do before you leave

You’ve set up an out-of-office auto-responder and packed your stuff, but have you done all of your “homework” before you rush out the front door for that well-deserved time off? The post Going on vacation? Five things to do before you leave appeared first on WeLiveSecurity

Britain’s tax authority reports takedown of record 20,000 fake sites

Her Majesty’s Revenue & Customs (HMRC) is “consistently the most abused government brand”, according to the National Cyber Security Centre (NCSC) The post Britain’s tax authority reports takedown of record 20,000 fake sites appeared first on WeLiveSecurity

The principle of least privilege: A strategy of limiting access to what is essential

The principle of least privilege is a security strategy applicable to different areas, which is based on the idea of only granting those permissions that are necessary for the performance of a certain activity The post The principle of least privilege: A strategy of limiting access to what is essential appeared first on WeLiveSecurity

How (over)sharing on social media can trip you up

Profuse recounting of details from your life via social media may come at a price The post How (over)sharing on social media can trip you up appeared first on WeLiveSecurity

Twitter bots, disassemble

Social media giants announce new measures to tackle bots and abusers The post Twitter bots, disassemble appeared first on WeLiveSecurity

World Cup squads briefed on cybersecurity best practices

The football associations of countries competing at Russia 2018 are taking no chances when it comes to cyber-related issues The post World Cup squads briefed on cybersecurity best practices appeared first on WeLiveSecurity

Wi-Fi security gets a boost as WPA3 standard is launched

The new wireless security protocol is poised to make hacking Wi-Fi connections a whole lot harder The post Wi-Fi security gets a boost as WPA3 standard is launched appeared first on WeLiveSecurity

Microsoft Edge bug could be exploited to spill your emails to malicious sites

Since a patch for the flaw has already been released, users are well advised to make sure that they’re running the browser’s most recent version The post Microsoft Edge bug could be exploited to spill your emails to malicious sites appeared first on WeLiveSecurity

Ham-fisted hacker gets jail time for serial DDoS attacks

The tale of “Bitcoin Baron” reveals a worrying picture and illustrates how easy it has become to wreak havoc on the internet The post Ham-fisted hacker gets jail time for serial DDoS attacks appeared first on WeLiveSecurity

South Korea’s largest cryptocurrency exchange hacked

Bithumb has claimed that $31.5 million worth of virtual coins were stolen by hackers The post South Korea’s largest cryptocurrency exchange hacked appeared first on WeLiveSecurity

11 ‘teammates’ to help you win your own cybersecurity game

Our lineup may seem heavy on the defensive side, but such is the nature of game plans for warding off a range of threats lurking in cyberspace The post 11 ‘teammates’ to help you win your own cybersecurity game appeared first on WeLiveSecurity

Europol and partners dismantle prolific cyber-extortion gang

The arrest of a 25-year-old French man in Thailand apparently seals the fate of Rex Mundi, a hack-and-extort collective that operated since at least 2012 The post Europol and partners dismantle prolific cyber-extortion gang appeared first on WeLiveSecurity

New Telegram-abusing Android RAT discovered in the wild

Entirely new malware family discovered by ESET researchers The post New Telegram-abusing Android RAT discovered in the wild appeared first on WeLiveSecurity

Stop Cyberbullying Day: Advice for victims and witnesses

A comprehensive list of some of the online resources available to victims, their families and friends The post Stop Cyberbullying Day: Advice for victims and witnesses appeared first on WeLiveSecurity

Phishing anniversary: Here’s a free $50/month subscription

Adidas “prize” used as bait in attempt to lure people into biting The post Phishing anniversary: Here’s a free $50/month subscription appeared first on WeLiveSecurity

World Cup dream team: ESET vs. Malware

An all-star line-up to go head-to-head with malware The post World Cup dream team: ESET vs. Malware appeared first on WeLiveSecurity

Major breach at British retailer Dixons Carphone affects nearly six million bank cards

Intruders also accessed 1.2 million personal data records, such as names, addresses or email addresses, in what is shaping up to be one of Britain’s biggest data breaches involving a single company The post Major breach at British retailer Dixons Carphone affects nearly six million bank cards appeared first on WeLiveSecurity

Chile to revolutionize cybersecurity after the recent cyberattack

The country’s financial authorities met to establish a new cybersecurity plan following attack on the Bank of Chile The post Chile to revolutionize cybersecurity after the recent cyberattack appeared first on WeLiveSecurity

World Cup watching: The common threats found when using streaming sites

On the eve of the 2018 FIFA World Cup in Russia, we take a closer look at the possible cybersecurity risks that exist on sports streaming websites The post World Cup watching: The common threats found when using streaming sites appeared first on WeLiveSecurity

US government report highlights gaps in battle against botnets

The report also identifies goals that are intended to help mitigate risks associated with botnets and to increase the resilience of the internet ecosystem The post US government report highlights gaps in battle against botnets appeared first on WeLiveSecurity

Spain’s La Liga app uses fans’ phones to detect illegal soccer broadcasts

La Liga says that the functionality requires the user’s express consent and that it is only intended to detect unauthorized broadcasts of soccer games. The post Spain’s La Liga app uses fans’ phones to detect illegal soccer broadcasts appeared first on WeLiveSecurity

74 people arrested in US-led crackdown on email scams

The international effort to disrupt Business Email Compromise (BEC) schemes also resulted in the seizure of nearly $2.4 million and the recovery of around $14 million in fraudulent wire transfers. The post 74 people arrested in US-led crackdown on email scams appeared first on WeLiveSecurity

Android users: Beware these popularity-faking tricks on Google Play

Tricksters have been misleading users about the functionality of apps by displaying bogus download numbers The post Android users: Beware these popularity-faking tricks on Google Play appeared first on WeLiveSecurity

Interred in the Internet of Everything

The security implications of devices connecting and sharing data The post Interred in the Internet of Everything appeared first on WeLiveSecurity