Recently I’ve been seeing lightly-revised versions of a longstanding hoax, says David Harley. Read more on supermarkets and fish perfumes. The post Supermarkets and fishy perfumes appeared first on WeLiveSecurity
For the past two years, I’ve been busy helping Public Key Infrastructure (PKI) customers prepare for and move to SHA-2, the set of cryptographic hash functions that have succeeded SHA-1. Last year, moving to SHA-2 ahead of the global deadline was a nice-to-do preparatory step. This year, now that the migration deadline has passed, it’s required.Many digital-certificate-consuming […]
The latest global cyberattack, detected by ESET as Win32 / Diskcoder.C, considered a variant of Petya, once again highlights the reality outdated systems and insufficient security solutions are still widespread. The post Everything you need to know about the latest variant of Petya appeared first on WeLiveSecurity
This article reveals details about the initial infection vector that was used during the DiskCoder.C outbreak. The post Analysis of TeleBots’ cunning backdoor appeared first on WeLiveSecurity
ESET’s Josep Albors discusses two-factor authentication, which is an underutilized security measure in businesses all over the world. The post Two-factor authentication: An underutilized security measure in businesses appeared first on WeLiveSecurity
This blogpost reveals many details about the Diskcoder.C (aka ExPetr or NotPetya) outbreak and related information about previously unpublished attacks. The post TeleBots are back: Supply-chain attacks against Ukraine appeared first on WeLiveSecurity
Workplace social media security is undoubtedly important for many businesses. In this feature, we answer five key questions relating to it. The post Workplace social media security: 5 questions answered appeared first on WeLiveSecurity
Passwords are often the first line of defense in protecting our personal and financial information, so it pays to have a strong, long and complex password (and easy to remember). Our one minute guide shows you how. The post How to make a strong password appeared first on WeLiveSecurity
Numerous reports are coming out on social media about a new ransomware attack in Ukraine, which could be related to the Petya family. The post New WannaCryptor-like ransomware attack hits Ukraine … may be global in scope appeared first on WeLiveSecurity
As baby boomers retire and the employment gap in cybersecurity is plugged by generation x, we look at how millennials are set to shape the industry. The post Millennials: Meet the next generation of cybersecurity appeared first on WeLiveSecurity
The strange behavior of a simple Windows application caught our attention and sparked the analysis by ESET of a previously undocumented malware. The post Birthday Reminder looks benign but the devil’s in the details: Hooks DNS, serves dodgy ads appeared first on WeLiveSecurity
Experts in the UK and the US have reportedly claimed that the recent global WannaCryptor ransomware attack was initiated by the North Korean Lazarus Group. The post WannaCryptor attack ‘may have come from Lazarus group’ appeared first on WeLiveSecurity
Machine learning (ML) in eight blogposts!? In our last post, let’s take a peek under the hood of ESET’s cybersecurity engine and its ML gears. The post Machine learning by ESET: The road to Augur appeared first on WeLiveSecurity
Senior ESET malware researcher Robert Lipovsky discusses Industroyer, the biggest threat to Industrial Control Systems (ICS) since Stuxnet. The post Industroyer: ICS were developed decades ago with no security in mind appeared first on WeLiveSecurity
ESET researchers have been analyzing samples of dangerous malware – detected by ESET as Win32/Industroyer, and named Industroyer – which is capable of performing an attack on power supply infrastructure. Robert Lipovsky, a researcher at ESET, tells us more. The post Industroyer poses the highest risk for critical infratstructure since Stuxnet appeared first on WeLiveSecurity
Seven years after Stuxnet first came to light, industrial systems security once again in the spotlight, reports ESET’s Robert Lipovsky. The post Seven years after Stuxnet: Industrial systems security once again in the spotlight appeared first on WeLiveSecurity
Smartphone security is, of course, essential these days, but how confident are you in your device’s ability to help keep you safe and secure? The post Would you trust your smartphone with your life? appeared first on WeLiveSecurity
Multimillion dollar movies and TV shows are increasingly being targeted by cybercriminals. ESET’s Stephen Cobb investigates the cyber supply chain risk management problem and explains what to do about it. The post Disney, Depp and the cyber supply chain risk management problem appeared first on WeLiveSecurity
A new survey published by the NSPCC suggests children across the UK are still at risk of accessing inappropriate and potentially harmful content online, despite increased calls for heightened security. The post Children still at risk from inappropriate online content appeared first on WeLiveSecurity
Businesses are confident that they have sufficient cybersecurity systems in place to protect them, but in reality the weak link may be their employees, who lack basic skills and knowledge. The post Employees have “low cyber IQ” despite high corporate confidence appeared first on WeLiveSecurity
ESET has analyzed a sophisticated and extremely dangerous malware, known as Industroyer, which is designed to disrupt critical industrial processes. The post Industroyer: Biggest threat to industrial control systems since Stuxnet appeared first on WeLiveSecurity
It is clear today that our smartphones and tablets have evolved beyond this point, creating new means of technological interaction not previously imagined. The post Trends 2017: Mobile security – the reality of malware … augmented appeared first on WeLiveSecurity
A report from PwC found that many companies across the UK are still unprepared for GDPR measures, despite fines for non-compliance doubling in a year. The post Fines for poor data security double in UK appeared first on WeLiveSecurity
Early in 2017, Kevin Townsend invited David Harley and others to comment on vendor hype. Here he expands on his original commentary. The post Testing, marketing, and rummaging in the FUD banks appeared first on WeLiveSecurity
Regardless of how prominent and effective ransomware appears to be, it is not the most dangerous form of malware. The post Botnets overshadowed by ransomware (in media) appeared first on WeLiveSecurity
Welcome to the Ransomware of Things, where all connected devices are at risk of being compromised, locked and held to ransom by cybercriminals. The post Trends 2017: Ransomware of Things appeared first on WeLiveSecurity
The Turla espionage group is still using watering hole techniques to redirect potentially interesting victims to their C&C infrastructure. The post Turla’s watering hole campaign: An updated Firefox extension abusing Instagram appeared first on WeLiveSecurity
Fewer vulnerabilities are being reported, but are we any safer? In this short video, we take a look at why it’s still a problem. The post Trends 2017: Fewer vulnerabilities are being reported, but are we any safer? appeared first on WeLiveSecurity
The OneLogin breach once again highlights the importance of how companies protect their encrypted data. The post OneLogin data breach may have compromised encrypted information appeared first on WeLiveSecurity
Just weeks after one of the largest global ransomware attacks in history, Infosecurity Europe returns for its 22nd installment. The post Infosecurity Europe: 10 interesting talking points appeared first on WeLiveSecurity
ESET has released a decryptor for AESNI ransomware variants, including XData. Victims who still have encrypted files can now download it from ESET’s utilities page. The post ESET releases decryptor for AESNI ransomware variants, including XData appeared first on WeLiveSecurity
Keen to understand what a virtual private network is? You’ve come to the right place. The post What is VPN and how does it work? appeared first on WeLiveSecurity
When it comes to cybersecurity, what type of employee is most likely to cause a data breach? And how can companies protect themselves? The post 3 types of employees that can cause a data breach appeared first on WeLiveSecurity
The ICO says businesses should stop focussing on the consequences of non-compliance and instead be motivated by the advantages of getting GDPR right. The post ICO urges businesses to focus on becoming GDPR compliant appeared first on WeLiveSecurity
Stephen Cobb, a senior security researcher at ESET, talks about one of the biggest cyberattacks of 2017 – WannaCryptor, aka WannaCry with radio and TV personality Marc Saltzman. The post WannaCryptor, aka WannaCry interview with Stephen Cobb and Marc Saltzman appeared first on WeLiveSecurity
A week after the global outbreak of WannaCryptor, also known as WannaCry, another ransomware, known as XData, has been making rounds. The post XData ransomware making rounds amid global WannaCryptor scare appeared first on WeLiveSecurity
Enforcement of GDPR, the General Data Protection Regulation, begins in May of 2018, imposing data privacy and security requirements on many organizations in the US and other countries. Are you impacted? The post Is the world ready for GDPR? Privacy and cybersecurity impacts are far-reaching appeared first on WeLiveSecurity
Zomato has confirmed that it has been communicating with the hacker responsible for stealing the data of around 17 million of its customers. The post Zomato working with ‘ethical hacker’ to improve security appeared first on WeLiveSecurity
ESET have prepared a new Crysis decrypting tool. Victims who still have their encrypted files can now download the decryptor from its utilities page. The post Keys for Crysis released, as decryption efforts of WannaCryptor files continue appeared first on WeLiveSecurity
Cybersecurity is now a worldwide problem. But far too many citizens, businesses and governments are still making the same old, basic errors. The post Ignoring software updates? You’re making one of five basic security mistakes appeared first on WeLiveSecurity
Technology evangelist Marc Saltzman asks: Are you protected against WannaCryptor, aka WannaCry, and other forms of ransomware? The post Are you protected against WannaCryptor and other forms of ransomware? appeared first on WeLiveSecurity
Are governments and financial regulators to blame for WannaCryptor, aka WannaCry, asks Tony Anscombe in this insightful feature. The post WannaCryptor: Are governments and financial regulators to blame? appeared first on WeLiveSecurity
Cybersecurity genius Reuben Paul demonstrates that connected toys can be used for malicious purposes at the World Forum in The Hague. The post Reuben Paul still at it with connected toys hack appeared first on WeLiveSecurity
The massive campaign that spread the WannaCry ransomware wasn’t the only large-scale infection misusing the EternalBlue and DoublePulsar exploits. The post WannaCryptor wasn’t the first to use EternalBlue: Miners misused it days after Shadow Brokers leak appeared first on WeLiveSecurity
Cybercriminals are reportedly demanding a ransom to prevent them from releasing Pirates of the Caribbean: Dead Men Tell No Tales. The post New Pirates of the Caribbean film ‘stolen by cybercriminals’ appeared first on WeLiveSecurity
In this post, ESET’s Cassius Puodzius addresses what we can learn from WannaCryptor ransomware attack, and what we can expect. The post Check-EternalBlue: Is your PC patched against the WannaCryptor worm vulnerability? appeared first on WeLiveSecurity
Without regular security updates, your endpoint will be left standing alone against an entire army of cybercriminals who see you as easy prey. The post Security updates belong in the limelight, not in the dustbin of history appeared first on WeLiveSecurity
At last count, more than 200,000 victims in 150 countries have been hit with the weaponized WannaCry ransomware worm. In the United Kingdom, the National Health Service was hit hard by the worm, potentially threatening patients’ lives.Haven’t we had enough? It’s time to stop pretending that lukewarm, poorly executed security measures are really doing something […]
In recent months, we have started to receive various reports about suspicious and malicious registry keys that had been created on users’ equipment. ESET’s Diego Perez explores. The post Malicious registry keys: Reflective injection appeared first on WeLiveSecurity
Ransomware called WannaCryptor spread rapidly around the world today, encrypting files in as many as 100 countries by using the leaked NSA eternalblue SMB exploit. The post Huge ransomware outbreak disrupts IT systems worldwide, WannaCryptor to blame appeared first on WeLiveSecurity
ESET’s Lucas Paus looks at a new WhatsApp scam that is making the rounds. The fraudsters behind it claim that users can get Netflix free for a year. The post New WhatsApp scam: Netflix free for a year appeared first on WeLiveSecurity
This short feature aims to draw attention to some of the key things you should be doing to bolster your tablet security to keep cybercriminals at bay. The post Tablet security: Is it as good as your smartphone? appeared first on WeLiveSecurity
Law firms, PR agencies, newswires, accountants… all manner of firms need to ensure that they are working hard to secure the information entrusted to them by their corporate clients, and keep it out of unauthorised hands. The post Hackers who stole information from law firms and made millions by insider trading, fined $9 million appeared […]
ESET’s Tony Anscombe takes a closer look at the anti-malware industry. The post Anti-trust, EU complaints and the anti-malware industry appeared first on WeLiveSecurity
The Federal Communications Commission in the US has confirmed that it experienced multiple distributed denial-of-service attacks (DDoS) over the weekend. The post FCC confirms DDoS attacks appeared first on WeLiveSecurity
An increasing number of holidaymakers are finding themselves targeted by online fraudsters, according to a new study. The post Holidaymakers warned against increased threat from online fraudsters appeared first on WeLiveSecurity
A quarter of European companies admit they were not aware of GDPR, with more than half unsure of the impact it will have, according to a new survey. The post IDC: 1 in 4 companies have no clue GDPR is coming their way appeared first on WeLiveSecurity
Sednit is back – this time with two more zero-day exploits embedded in a phishing email titled Trump’s_Attack_on_Syria_English.docx. The post Sednit adds two zero-day exploits using ‘Trump’s attack on Syria’ as a decoy appeared first on WeLiveSecurity
ESET’s Stephen Cobb examines how close we are to the kind of jackware technology shown in the latest Fast and Furious film franchise, Fate of the Furious. The post Jackware hits the big screen in #Fast8: Fate of the Furious appeared first on WeLiveSecurity
Poor business decisions can be very costly, especially in cybersecurity, where so-called false positives can have very damaging consequences. The post False positives can be more costly than a malware infection appeared first on WeLiveSecurity
I’m no world-class hacker/penetration tester, but I’ve been able to break into any organization I’ve been (legally) hired to do so in an hour or less, except for one place that took me three hours. That was on my second engagement with the customer after it had implemented many of the protections I had recommended […]
There are big changes happening to the infosec landscape:, says ESET’s Michael Aguilar. It’s therefore time to take note and take action. The post Big changes in the infosec landscape: Time to take note and take action appeared first on WeLiveSecurity
Criminal hackers have struck again and stolen the personal data of 26,000 Debenhams Flowers customers. Here’s what you need to know and do. The post Cybercriminals are saying it with flowers from Debenhams appeared first on WeLiveSecurity
If surveillance, cybersecurity, and privacy are things you think about a lot, you should find The Circle interesting viewing. The post Surveillance, cybersecurity, and the future of privacy in The Circle appeared first on WeLiveSecurity
Gannett Co, which owns a host of media titles across the US, has reportedly suffered a data breach following a phishing attack. The post Gannett Co data breach: 18,000 employees reportedly affected appeared first on WeLiveSecurity
We look at key trends for 2017 within this sector, from password security to the need for security education at all institutions: schools, businesses, governments. The post Security education and social responsibility appeared first on WeLiveSecurity
The modern computer password was introduced to computer science and the wider world in 1960 by Fernando Corbató. We look at its history and impact. The post A short history of the computer password appeared first on WeLiveSecurity
Fingerprint security is growing in prominence, but is the technology behind it really as secure as we think it is? In this feature, we tackle three myths. The post Fingerprint security: Three myths busted appeared first on WeLiveSecurity
Recently, many people received a phishing email from a mailinator.com address that was attached to a malicious Google doc. Beware. The post Beware Google Docs phishing attack appeared first on WeLiveSecurity
Businesses that fall victim to a DDoS attack could lose, on average, as much as $2.5 million in revenue, new research has suggested. The post A DDoS attack could cost businesses as much as $2.5 million appeared first on WeLiveSecurity
Peter Stancik discusses the new Digital Identity Guidelines drafted by NIST, which offers an update on password security. The post No more pointless password requirements appeared first on WeLiveSecurity
Sabrina Pagnotta takes a closer look at what motivates some young people to become cybercriminals. You may be surprised to find out some of the reasons. The post What motivates some young people to become cybercriminals? appeared first on WeLiveSecurity
Cybersecurity should be a priority for educational institutions, says ESET’s Lysa Myers. It’s important to protect students and staff from cybercriminals. The post School’s almost out … Don’t let cybercriminals in appeared first on WeLiveSecurity
A single protective technology means a single point of failure. A company aiming to build reliable and strong cybersecurity defenses should opt for a solution offering multiple complementary technologies. The post A single protective technology means a single point of failure appeared first on WeLiveSecurity
As a traveling consultant, I visit lots of businesses during the year and examine their security plans. For decades, I’ve secretly scoffed at what they’ve tried to do because it was often too little, too late—and misdirected.But these days, I run into more and more companies that get it right rather than wrong, with ideas […]
Recently, here at our research lab, we have seen an increase in the number of JS/Chromex.Submelius threats detected, says Camilo Gutiérrez Amaya. The post Fake Chrome extensions inject code into web pages appeared first on WeLiveSecurity
World Day for Safety and Health at Work takes place on April 28th 2017. You should use this as an opportunity to improve your cybersecurity posture. The post Is cybersecurity now as important as health and safety? appeared first on WeLiveSecurity
Two men are facing a prison sentence after admitting their part in the recent TalkTalk data breach. The post Young duo sentenced over role in TalkTalk data breach appeared first on WeLiveSecurity
Consumers have placed a high level of trust in healthcare organizations to keep their data safe, but companies cannot afford to take this for granted. The post Healthcare providers ‘cannot be complacent over data security’ appeared first on WeLiveSecurity
David Harley discusses a scam that has been making the rounds where, it’s reported, cold-calling scammers ask the victim ‘Can you hear me?’. The post Scam calls: Can you hear me, mother? appeared first on WeLiveSecurity
ESET’s Stephen Cobb looks at whether or not cybercrime and other cybersecurity issues will undermine the digital economy. The post Will cybercrime and other cybersecurity issues undermine the digital economy? appeared first on WeLiveSecurity
The usage of the BitTorrent protocol and Lua modules separates Linux/Shishiga from other types of malware, according to analysis by ESET. The post Linux Shishiga malware using LUA scripts appeared first on WeLiveSecurity
Machine learning alone is not enough to protect endpoints and predicting an attacker’s next moves. Other security solutions and human input are needed. The post Machine learning and math can’t trump smart attackers appeared first on WeLiveSecurity
Today’s increasingly miniaturized world is giving rise to all sorts of hardware devices that can hack almost any computer, device, or network. Plug in an item the size of a USB stick and all your hard-won protections could be defeated. If you haven’t been paying attention to this field of attack, what you learn might […]
Russian hacker receives the longest sentence ever handed down for hacking-related charges in the United States. The post US court hits Russian PoS hacker with record 27 year jail sentence appeared first on WeLiveSecurity
A new report suggests young cybercriminals are often motivated by the possibility of notoriety, rather than financial gain. The post Young cybercriminals ‘more motivated by peer respect than financial gain’ appeared first on WeLiveSecurity
Nearly half of all UK businesses have experienced a cybersecurity incident over the last 12 months, according to a new government paper. The post Nearly half of UK businesses experienced a cybersecurity incident in the last 12 months appeared first on WeLiveSecurity
The InterContinental Hotels Group says the implementation of its SPS system helped to minimize the damage caused by a recent data breach. The post InterContinental Hotels Group reveals ‘how it minimized recent malware attack’ appeared first on WeLiveSecurity
ESET researchers have discovered another banking trojan on Google Play targeting Android users – this time disguised as a Flashlight widget. The post Turn the light on and give me your passwords! appeared first on WeLiveSecurity
Machine learning (ML) is routinely cited by post-truth vendors as their biggest selling point, their main advantage. But ML – if it’s done properly – comes with problems and limitations. The post When PR and reality collide: The truth about machine learning in cybersecurity appeared first on WeLiveSecurity
As a traveling enterprise security consultant, I get to see security teams at their best and their worst. Under stress, some teams work like a well-oiled machines, while others devolve into inefficient, finger-pointing bureaucracies.Every great computer security team has a synergistic collection of skilled professionals who work well together to meet common goals. The team […]
Only 11% of positions in the global cybersecurity workforce are occupied by women. We take a look at why and what is being done to change this. The post Women in cybersecurity: Slowly but surely, change is coming appeared first on WeLiveSecurity
GDPR is coming into play in May 2018, but a lot of companies remain unprepared, which could have implications on how they process data. The post 10 ways to prepare your organization for GDPR appeared first on WeLiveSecurity
ESET researchers have discovered and reported scammers stealing PayPal and Paxful credentials disguised as a tool for YouTube monetization, and a bitcoin trading marketplace. The post Real or virtual currency? Scammers accept both appeared first on WeLiveSecurity
The Internet Society says that current perceptions of data encryption are misguided and need to change for the sake of the digital economy. The post Internet Society: Encryption is key to growing world economy appeared first on WeLiveSecurity
There is no magic in machine learning. It’s a field of computer science that gives computers the ability to find patterns in huge amounts of data. The post Don’t buy the elixir of youth: Machine learning is not magic appeared first on WeLiveSecurity
Welcome to the beginning of a new series of short articles focused on the currents state of AI, all the ins and outs of machine learning, and how it affects cybersecurity. The post Fighting post-truth with reality in cybersecurity appeared first on WeLiveSecurity
A smartphone’s internal sensors may provide cybercriminals with enough information to be able to guess a user PINs and passwords, according to new research by Newcastle University in the UK. The post Smartphone sensors ‘can reveal PINs and passwords’ appeared first on WeLiveSecurity
If you’ve been paying attention lately, you’ve likely noticed that more of your everyday websites are going HTTPS by default: Twitter, Facebook, LinkedIn, and even your favorite search engine.This is a good development. For years, critics have derided default, widespread HTTPS encryption and authentication as unnecessary and performance-wasting. But now that we’ve seen most of […]
David Harley and Josep Albors on the evolution of tech support scams and why the current high incidence of reports in Spain are significant. The post Spanish Harmada: More on tech support scams appeared first on WeLiveSecurity
