When thinking about security we generally take risk into account. It is well known that risk is a composition of likelihood and potential impact. The post Malware in firmware: how to exploit a false sense of security appeared first on WeLiveSecurity
You always build from the ground up, and every small-medium business (SMB) must build a strong foundation with their management team. The post Canadian SMBs: The importance of a stable foundation appeared first on WeLiveSecurity
In the first part of our series we addressed issues such as the role an everyday internet user has in making the internet a safer place, and ID theft. The second part of the Twitter chat continues with the theme of Simple Steps to Online Safety. The post National Cybersecurity Awareness Month Twitter Chats part […]
Just as there are ways to audit, manage and protect electronic documents, there are ways to manage printed documents, too. The post Securing printed data in the ‘paperless’ office appeared first on WeLiveSecurity
We’ve gathered our own thoughts on the topics chosen each week for this short series of blogs that will be published twice a week. The post National Cybersecurity Awareness Month Twitter Chats appeared first on WeLiveSecurity
The infection mechanism works well – which is crucial for determining how big of a deal a piece of malware is. The post DoubleLocker Android ransomware explained appeared first on WeLiveSecurity
‘KRACK’ or Key Reinstallation AttaCK, as it has been labeled, means third parties could eavesdrop on a network meaning private conversations would no longer be private. The post WPA2 security issues pose serious Wi-Fi safety questions appeared first on WeLiveSecurity
True, most malware isn’t viral any more, but I don’t think that matters in this context. Nor, of course, is the EICAR file a virus, and doesn’t in any respect behave like one. The post Product Testing: Simulation, dissimulation, exasperation appeared first on WeLiveSecurity
DoubleLocker can change the device’s PIN, preventing victims from accessing their devices, and also encrypts the data it finds in them – a combination that has not been seen previously in the Android ecosystem. The post DoubleLocker: Innovative Android Ransomware appeared first on WeLiveSecurity
National Cyber Security Awareness Month and its events have become top of mind for people and businesses in recent years, given the staggering number of recent data breaches and global ransomware attacks. The post Five cool things happening for National Cyber Security Awareness Month appeared first on WeLiveSecurity
Billed as the largest piece of privacy legislation for 20 years, the GDPR isn’t merely a directive, but EU legislation enshrined in law. It has been designed to harmonise different laws to protect individuals’ privacy. The post Is your SME ready for GDPR? appeared first on WeLiveSecurity
A recent Ipsos survey, found that only 26 per cent of Canadian SMBs feel very confident that their business and its information is safe from cyberattacks The post Canadian SMBs: How technology can help you have a better start in business appeared first on WeLiveSecurity
By the 1800s, long before the famous Enigma machine and military computerization to decipher codes, a Victorian woman trapped in a patriarchal world, glimpsed the potential reach of computing and the change it would impose on humanity. The post Ada Lovelace Day: celebrating women in technology appeared first on WeLiveSecurity
As the Asia Pacific region continues to grow, and adoption of digital technologies – by consumers and businesses – continues, the region is starting to appreciate how attractive it has become to cybercriminals. The post Cybersecurity in Asia Pacific appeared first on WeLiveSecurity
Cybersecurity is everyone’s responsibility and organisations need to train staff to ensure they have a more empowered and security savvy workforce. The post It’s time that companies became more cyber-resilient appeared first on WeLiveSecurity
The annual Virus Bulletin International Conference takes place in Madrid, Spain this October and ESET will be well represented across the three-day event. The post ESET at Virus Bulletin 2017 appeared first on WeLiveSecurity
Cloud services are very much what you make of them, and you need to apply at least an equivalent level of rigorousness, in terms of risk assessment, as you would with assets that are hosted on your own network. The post Cloud security policy: The questions you need to ask appeared first on WeLiveSecurity
What’s safer? Using a numeric PIN code to unlock your Android smartphone or relying on a finger squiggle? The answer might surprise you. The post Your Android lock screen pattern isn’t as safe as a PIN code appeared first on WeLiveSecurity
While far behind Bitcoin in market capitalization, Monero has several features that make it a very attractive cryptocurrency to be mined by malware. The post Money-making machine: Monero-mining malware appeared first on WeLiveSecurity
The Android banking trojan that we first informed about in the beginning of this year has found its way to Google Play again and contains new tricks designed to get access to the private banking information of the user. The post Bankbot trojan returns to Google Play with new tricks appeared first on WeLiveSecurity
These new security measures will undoubtedly not only impact the security of data stored on a phone that has been lost or stolen, but could also complicate the progress of criminal investigations requiring the forensic analysis of a phone. The post Security and privacy on the new iOS 11 appeared first on WeLiveSecurity
Most companies have switched the majority of their services and information over to the cloud. There are many reasons for this, ranging from cost to practicalities. The post Cloud services: What to consider when migrating your infrastructure appeared first on WeLiveSecurity
FinFisher has extensive spying capabilities, such as live surveillance through webcams and microphones, keylogging, and exfiltration of files. What sets FinFisher apart from other surveillance tools, however, are the controversies around its deployments. The post New FinFisher surveillance campaigns: Are internet providers involved? appeared first on WeLiveSecurity
Regardless of how Piriform was breached, for a tool as widely downloaded as CCleaner, with a userbase running into the hundreds of millions, there will be a large impact worldwide, even though only the 32-bit version was affected. The post CConsiderations on the CCleaner incident appeared first on WeLiveSecurity
In the recent Equifax breach you may have noticed that people in the UK and Canada are also affected but there has been little clarification as to how many. The post How many people outside the U.S. are affected by the Equifax breach? appeared first on WeLiveSecurity
Cryptocurrency mining has been used by cybercriminals to make a quick and easy profit while corrupting the victim’s machine in the process. The post Cryptocurrency web mining: In union there is profit appeared first on WeLiveSecurity
Services like Netflix use content delivery networks (CDNs) to maximize bandwidth usage. However, the CDNs might be becoming a new way of spreading malware. The post DownAndExec: Banking malware utilizes CDNs in Brazil appeared first on WeLiveSecurity
Cryptocurrencies work on a decentralized methodology, there is no sever or centralized place that holds account details and transactions. The post State sponsored cryptocurrency: Could it ever be a reality? appeared first on WeLiveSecurity
Indications are that this breach occurred between mid-May and July 2017, and that it was discovered by Equifax on July 29. As this has potentially affected almost half of all adults in the US, you may be wondering how to identify or mitigate problems caused by this breach. The post Equifax breach: 5 defensive steps […]
The credit reporting agency, Equifax, has revealed that they suffered a huge cyberattack that could affect up 143 million Americans. The post Equifax hack could affect half the population of the US appeared first on WeLiveSecurity
The discovered weakness would allow hackers to remotely run code on servers that utilize the REST plugin from Apache Struts, and it is reported that all versions since 2008 are affected. The post Critical security flaw leaves Fortune 100 firms vulnerable appeared first on WeLiveSecurity
China banned the raising of funds using token-based digital currencies and deemed the practice illegal on Monday, in a move seen as an attempt to impose more regulations on the virtual market. The post Chinese cryptocurrency crackdown appeared first on WeLiveSecurity
A hack believed to target only celebrity accounts on Instagram has also accessed millions of users’ private data. The post Six million Instagram accounts hacked appeared first on WeLiveSecurity
WikiLeaks’ whistleblowing website suffered an attack from the group known as OurMine on Thursday The post WikiLeaks suffer defacement at the hands of OurMine group appeared first on WeLiveSecurity
Google has been forced to remove almost 300 apps from its Play Store after learning that apps were being hijacked for DDoS attacks. The post Google removes 300 Android apps following DDoS attack appeared first on WeLiveSecurity
Huge data breach sees more than 700 million email addresses and passwords leaked publicly thanks to a misconfigured spambot, dubbed ‘Onliner’. The post More than 700 million email addresses leaked in huge data breach appeared first on WeLiveSecurity
To some extent, the security software industry relies on the idea that there is always a technological answer to a tech problem but ‘always’ is a big word. The post Security and Education appeared first on WeLiveSecurity
Real Madrid’s official Twitter account was hacked with a post announcing the signing of rival Lionel Messi. The post Spanish giants the latest to fall foul of hackers appeared first on WeLiveSecurity
Malware coded synthetic genomes have caused skepticism within the scientific community, but new research might help to change that perception. The post Malware coded into synthetic genomes appeared first on WeLiveSecurity
Replacement screens for cracked smartphones bought from third party vendors could leave you vulnerable to hackers, a new study has revealed. The post Hackers can control damaged phones using replacement screens appeared first on WeLiveSecurity
Using smartphones at a bank might seem like the most routine habit in the world but sometimes these smartphones are being used as way to gain access to the bank’s WiFi and sensitive data. The post What are the risks of allowing people to use their smartphone at the bank? appeared first on WeLiveSecurity
ESET researchers have discovered a new sneaky malware threat named Joao, targeting gamers worldwide. The post Gamescom 2017: It’s all fun and games until black hats step in appeared first on WeLiveSecurity
As a consultant, one the security biggest problems I see is perception: The threats companies think they face are often vastly different than the threats that pose the greatest risk. For example, they hire me to deploy state-of-the-art public key infrastructure (PKI) or an enterprise-wide intrusion detection system when really what they need is better […]
Sony became the latest entertainment company to suffer at the fingertips of hackers after their PlayStation social media channels were temporarily hacked on Sunday evening. The post PlayStation social media accounts briefly hacked appeared first on WeLiveSecurity
Many of the components required to commit cybercrime can be bought and sold online if you know the right part of the internet in which to look. The post Cybercrime update: Big trouble in dark markets? appeared first on WeLiveSecurity
While you might not think tennis and cybersecurity have much in common, both can be unpredictable and therefore require you to keep your eye on the ball. The post Rogers Cup ‘Tech and Tennis Day’ cybersecurity panel appeared first on WeLiveSecurity
General Data Protection Regulation (GDPR) together with the growing number of data breaches are the most pressing reasons why small and medium businesses are implementing data protection technologies – including encryption. The post Buying encryption? Five good questions to ask before you do appeared first on WeLiveSecurity
Google has rewarded a Uruguayan student with $10,000 after he exposed a security flaw that could allow hackers to access sensitive data. The post Google pays $10,000 for student’s bug appeared first on WeLiveSecurity
Ironically named for the criminal hackers that cybersecurity pros spend their days – and not a few nights – defending against, the Black Hat Briefings quickly earned a reputation for excellent technical content. The post Black Hat at 20, DefCon at 25: Not just about breaking things appeared first on WeLiveSecurity
Encryption can be the answer to many data security issues faced by small and medium businesses. Apart from protecting sensitive information from unauthorized use,this technology can also represent another step towards compliance with legislation. The post Avoid getting lost in encryption with these easy steps appeared first on WeLiveSecurity
The Virus Bulletin 2017 Conference has announced some of its Small Talk and reserve papers that will be on the agenda of this year’s event. The post Virus Bulletin 2017: Small Talks announced appeared first on WeLiveSecurity
We all know that there is no such thing as a free lunch, or security product, so what’s the catch? The post What’s the cost of a free lunch? appeared first on WeLiveSecurity
Despite their popularity among users, torrents are a very risky “business”. Apart from the obvious legal trouble you could face for violating the copyright of musicians, filmmakers or software developers, there are security issues as well. The post Why you should view torrents as a threat appeared first on WeLiveSecurity
The number of IoT devices is set to surpass 20 billion by 2020. We take a look at how connected things threaten our security as cybercriminals exploit weaknesses in the smartphones that control them. The post Are smartphones threatening the security of our IoT devices? appeared first on WeLiveSecurity
Trick the firmware and you have access to the whole system. Here at Black Hat, there are a lot of people doing just that. The post Black Hat: Hacking the firmware, the next frontier appeared first on WeLiveSecurity
Anton Cherepanov, a malware researcher at ESET, has picked up a Pwnie Award for Best Backdoor at this year’s ceremony at Black Hat USA 2017 in Las Vegas. The post ESET’s Anton Cherepanov picks up Pwnie for Best Backdoor appeared first on WeLiveSecurity
A homograph attack is what happens when attackers register domains that are similar to the originals, with valid certificates. The post Homograph attacks: Don’t believe everything you see appeared first on WeLiveSecurity
If industry frameworks are to inform and secure the critical infrastructure writ large, here at Black Hat there a lot of people punching holes in them, and in simple ways. The post Black Hat 2017 industrial hacking: The song remains the same appeared first on WeLiveSecurity
This year at Black Hat, tiny automated hacking platforms are everywhere, loaded with tasty purpose-built tools that can be used to break into your systems. The post Black Hat 2017: Non-standard hacking platforms reign supreme appeared first on WeLiveSecurity
A jump box is a secure computer that all admins first connect to before launching any administrative task or use as an origination point to connect to other servers or untrusted environments. Over the last few years, with malicious hackers and malware infesting nearly every enterprise network at will, security admins have been looking for […]
When it comes to protecting corporate information, some doubt whether or not the cloud is the best option. We look at all the security services available. The post Is it safe to store corporate information on Google Drive (or similar services)? appeared first on WeLiveSecurity
Cameron Camp, in attendance at this year’s Black Hat in Las Vegas, takes a closer look at attacks against physical infrastructure. The post Black Hat 2017: Hacking the physical world appeared first on WeLiveSecurity
Social engineering may play a vital part in persuading a victim to open a malicious executable or website, says ESET’s David Harley on social engineering and ransomware. The post Social engineering and ransomware appeared first on WeLiveSecurity
ESET researchers have discovered an Android app store distributing malware on a mass scale. The post Malware found lurking behind every app at alternative Android store appeared first on WeLiveSecurity
A new £20 million cybersecurity programme to train teenagers will be launched in the UK this autumn, as part of the government’s plans to address the skills gap. The post £20 million cybersecurity programme to train teenagers set to launch in UK appeared first on WeLiveSecurity
Thales Group has announced the results of its 2017 data threat report, showing that the number of global data breaches has increased from 2016. The post 88% feel vulnerable to data threats appeared first on WeLiveSecurity
This year at Black Hat, it will be incumbent upon newer vendors to make sensational claims to gain market share from established vendor, says Cameron Camp. The post Going to Black Hat? Bring your (marketing) wallet appeared first on WeLiveSecurity
ESET are giving away a total of $30,000 in prize money to nonprofits to celebrate 30 years of continuous technological innovation in IT security. The post ESET celebrates 30 years of innovation in IT security by giving away $30,000 to nonprofits appeared first on WeLiveSecurity
Since the beginning of 2017, ESET has been conducting an investigation into a complex threat mainly targeting Russia and Ukraine. Stantinko has stood out. The post Stantinko: A massive adware campaign operating covertly since 2012 appeared first on WeLiveSecurity
A Russian man has been sentenced to five years in prison for helping develop the Citadel malware, which was used to steal personal financial information. It cost more than $5 million in losses. The post Citadel “mechanic” receives five year prison sentence appeared first on WeLiveSecurity
We are halfway through the year and it is a good opportunity to analyze the extent to which the ideas we gathered in the Trends 2017: Security Held Ransom report have come true. The post Mid-year review: Have our security trends for 2017 become reality? appeared first on WeLiveSecurity
Businesses leave themselves open to potential data breaches through their ex-employees, according to a new study by OneLogin. The post OneLogin: Businesses vulnerable to data breaches by ex-employees appeared first on WeLiveSecurity
Lloyd’s of London have reported that a serious cyberattack could cost the global economy as much as a devastating natural disaster. The post A major cyberattack could cost the global economy $53 billion appeared first on WeLiveSecurity
You ultimately decide what links you click on, and whether you hand over your passwords and payment card details. Always think twice, because the wrong decision could prove costly. The post Beware bogus ‘WhatsApp subscription ending’ emails and texts appeared first on WeLiveSecurity
How do patches work? Could the Microsoft patch have stopped WannaCryptor? All your questions answered. The post Patching: Your questions answered appeared first on WeLiveSecurity
Recent research from the SANS Institute confirms that security of industrial control systems is increasingly seen and understood to be a serious issue. The post Industrial control security practitioners worry about threats … for a reason appeared first on WeLiveSecurity
Critical security holes keep being found in Adobe Flash Player. Have you updated yours yet? The post Adobe Flash Player users should update their software NOW appeared first on WeLiveSecurity
The Information Commissioner’s Office (ICO) has launched an International Strategy, which provides guidance on key issues such as GDPR and changing technologies. The post UK’s ICO launches first ever International Strategy appeared first on WeLiveSecurity
Recently I’ve been seeing lightly-revised versions of a longstanding hoax, says David Harley. Read more on supermarkets and fish perfumes. The post Supermarkets and fishy perfumes appeared first on WeLiveSecurity
For the past two years, I’ve been busy helping Public Key Infrastructure (PKI) customers prepare for and move to SHA-2, the set of cryptographic hash functions that have succeeded SHA-1. Last year, moving to SHA-2 ahead of the global deadline was a nice-to-do preparatory step. This year, now that the migration deadline has passed, it’s required.Many digital-certificate-consuming […]
The latest global cyberattack, detected by ESET as Win32 / Diskcoder.C, considered a variant of Petya, once again highlights the reality outdated systems and insufficient security solutions are still widespread. The post Everything you need to know about the latest variant of Petya appeared first on WeLiveSecurity
This article reveals details about the initial infection vector that was used during the DiskCoder.C outbreak. The post Analysis of TeleBots’ cunning backdoor appeared first on WeLiveSecurity
ESET’s Josep Albors discusses two-factor authentication, which is an underutilized security measure in businesses all over the world. The post Two-factor authentication: An underutilized security measure in businesses appeared first on WeLiveSecurity
This blogpost reveals many details about the Diskcoder.C (aka ExPetr or NotPetya) outbreak and related information about previously unpublished attacks. The post TeleBots are back: Supply-chain attacks against Ukraine appeared first on WeLiveSecurity
Workplace social media security is undoubtedly important for many businesses. In this feature, we answer five key questions relating to it. The post Workplace social media security: 5 questions answered appeared first on WeLiveSecurity
Passwords are often the first line of defense in protecting our personal and financial information, so it pays to have a strong, long and complex password (and easy to remember). Our one minute guide shows you how. The post How to make a strong password appeared first on WeLiveSecurity
Numerous reports are coming out on social media about a new ransomware attack in Ukraine, which could be related to the Petya family. The post New WannaCryptor-like ransomware attack hits Ukraine … may be global in scope appeared first on WeLiveSecurity
As baby boomers retire and the employment gap in cybersecurity is plugged by generation x, we look at how millennials are set to shape the industry. The post Millennials: Meet the next generation of cybersecurity appeared first on WeLiveSecurity
The strange behavior of a simple Windows application caught our attention and sparked the analysis by ESET of a previously undocumented malware. The post Birthday Reminder looks benign but the devil’s in the details: Hooks DNS, serves dodgy ads appeared first on WeLiveSecurity
Experts in the UK and the US have reportedly claimed that the recent global WannaCryptor ransomware attack was initiated by the North Korean Lazarus Group. The post WannaCryptor attack ‘may have come from Lazarus group’ appeared first on WeLiveSecurity
Machine learning (ML) in eight blogposts!? In our last post, let’s take a peek under the hood of ESET’s cybersecurity engine and its ML gears. The post Machine learning by ESET: The road to Augur appeared first on WeLiveSecurity
Senior ESET malware researcher Robert Lipovsky discusses Industroyer, the biggest threat to Industrial Control Systems (ICS) since Stuxnet. The post Industroyer: ICS were developed decades ago with no security in mind appeared first on WeLiveSecurity
ESET researchers have been analyzing samples of dangerous malware – detected by ESET as Win32/Industroyer, and named Industroyer – which is capable of performing an attack on power supply infrastructure. Robert Lipovsky, a researcher at ESET, tells us more. The post Industroyer poses the highest risk for critical infratstructure since Stuxnet appeared first on WeLiveSecurity
Seven years after Stuxnet first came to light, industrial systems security once again in the spotlight, reports ESET’s Robert Lipovsky. The post Seven years after Stuxnet: Industrial systems security once again in the spotlight appeared first on WeLiveSecurity
Smartphone security is, of course, essential these days, but how confident are you in your device’s ability to help keep you safe and secure? The post Would you trust your smartphone with your life? appeared first on WeLiveSecurity
Multimillion dollar movies and TV shows are increasingly being targeted by cybercriminals. ESET’s Stephen Cobb investigates the cyber supply chain risk management problem and explains what to do about it. The post Disney, Depp and the cyber supply chain risk management problem appeared first on WeLiveSecurity
A new survey published by the NSPCC suggests children across the UK are still at risk of accessing inappropriate and potentially harmful content online, despite increased calls for heightened security. The post Children still at risk from inappropriate online content appeared first on WeLiveSecurity
Businesses are confident that they have sufficient cybersecurity systems in place to protect them, but in reality the weak link may be their employees, who lack basic skills and knowledge. The post Employees have “low cyber IQ” despite high corporate confidence appeared first on WeLiveSecurity
ESET has analyzed a sophisticated and extremely dangerous malware, known as Industroyer, which is designed to disrupt critical industrial processes. The post Industroyer: Biggest threat to industrial control systems since Stuxnet appeared first on WeLiveSecurity
It is clear today that our smartphones and tablets have evolved beyond this point, creating new means of technological interaction not previously imagined. The post Trends 2017: Mobile security – the reality of malware … augmented appeared first on WeLiveSecurity
