Menu

Category Archives: Security Advisory

Auto Added by WPeMatico

How do you work out a country’s level of cybersecurity?

The Global Cybersecurity Index (GCI) measures a nation’s commitment to cybersecurity and encourages countries to take the issue more seriously. The post How do you work out a country’s level of cybersecurity? appeared first on WeLiveSecurity.

Flashback Friday: SQL Slammer

Within a few hours of being released in the winter of 2003, SQL Slammer had brought the internet to something of a standstill. We look back at this notable worm. The post Flashback Friday: SQL Slammer appeared first on WeLiveSecurity.

Growth of cybercrime is ‘ruthless’

Cybercrime has established itself as a permanent fixture in 21st century life, with the number of incidents and victims continuing to rise with dogged determination. The post Growth of cybercrime is ‘ruthless’ appeared first on WeLiveSecurity.

Krebs’ website remains online following massive DDoS attack

Brian Krebs’ website appears be to be holding up, following what has been described as “one of the biggest web attacks ever seen”. The post Krebs’ website remains online following massive DDoS attack appeared first on WeLiveSecurity.

A quick fix for stupid password reset questions

It didn’t take 500 million hacked Yahoo accounts to make me hate, hate, hate password reset questions (otherwise known as knowledge-based authentication or KBA). It didn’t help when I heard that password reset questions and answers — which are often identical, required, and reused on other websites — were compromised in that massive hack, too.  […]

What Pippa Middleton can teach us about iCloud security

Pippa Middleton is the latest in a long line of celebrities to have her online accounts broken into by criminals, and private photographs stolen. Have you properly secured your iCloud account? The post What Pippa Middleton can teach us about iCloud security appeared first on WeLiveSecurity.

DDoS robots for the masses: IoT security comes of age

IoT security matters more than ever, explains ESET’s Cameron Camp, as the technology, which offers us so much, is vulnerable to attack from cybercriminals. The post DDoS robots for the masses: IoT security comes of age appeared first on WeLiveSecurity.

USBee: how to spy on an isolated system with a USB

USBee is a form of “air gap attack”. It uses a USB device to transmit the information the attacker wants to steal at frequencies between 240 and 480Mhz. The post USBee: how to spy on an isolated system with a USB appeared first on WeLiveSecurity.

Mr. Robot security recap: 10 lessons learned from season 02

Cybersecurity and hacking play a leading role in the series, so with Mr. Robot season 02 almost over, we want to do a reality check on the scenarios we saw. The post Mr. Robot security recap: 10 lessons learned from season 02 appeared first on WeLiveSecurity.

8 years of Android: malware, malicious apps, and how to stay safe

At eight years old, Android is hugely popular. Both with users and attackers. The post 8 years of Android: malware, malicious apps, and how to stay safe appeared first on WeLiveSecurity.

Half a billion Yahoo users victim to ‘biggest data breach in history’

Yahoo has confirmed that half a billion users may have had their data stolen in what has been described as the ‘biggest data breach in history.’ The post Half a billion Yahoo users victim to ‘biggest data breach in history’ appeared first on WeLiveSecurity.

Book of Eli: African targeted attacks

ESET’s latest research analyzes a piece of malware active since 2012, but which has targeted one specific country – Libya. The post Book of Eli: African targeted attacks appeared first on WeLiveSecurity.

5 simple ways you can protect yourself from phishing attacks

With these top tips, you should have no trouble in keeping yourself protected against all sorts of phishing attacks. The post 5 simple ways you can protect yourself from phishing attacks appeared first on WeLiveSecurity.

Tesla Model S hacked from 12 miles away

A team of researchers was able to hack the controls of a Tesla Model S from a distance of 12 miles – adjusting the mirrors, locks and even slamming on the brakes. The post Tesla Model S hacked from 12 miles away appeared first on WeLiveSecurity.

Seagate NAS hack should scare us all

No fewer than 70 percent of internet-connected Seagate NAS hard drives have been compromised by a single malware program. That’s a pretty startling figure. Security vendor Sophos says the bitcoin-mining malware Miner-C is the culprit.I’m surprised this story hasn’t garnered more attention. Perhaps it’s because we’re talking only 7,000 hard drives possibly in total, or […]

Cybersecurity becoming a key boardroom agenda item

An increase in the number of cyberattacks and growing awareness of the threat has made cybersecurity a key boardroom level consideration. The post Cybersecurity becoming a key boardroom agenda item appeared first on WeLiveSecurity.

Snowden: 4 big security and privacy assumptions he undermined

Oliver Stone’s movie about Edward Snowden, which opens on Friday, September 16th, 2016, has a lot of people looking back at one of the biggest information security breaches in US history, the one we learned about in June, 2013. That’s when the UK-based Guardian newspaper published classified information about the mass electronic surveillance activities of […]

Internet of targets: Webcams and routers in the crosshairs of bad guys

Mass surveillance, stolen data, passwords and misused sensitive information; it seems that there is so much to worry about these days when it comes to your online privacy. All most people want is to browse the web and enjoy its treats instead of bumping into malware or other problems, right? Then you read about things occurring online that […]

WADA cyberattack compromises agency’s database

The World Anti-Doping Agency (WADA) has revealed that it was the victim of a cyberattack, which it has attributed to the Russian cyberespionage group, Tsar Team (APT28). According to the agency, the group, which also goes by the moniker Fancy Bear, was able to gain access to its Anti-Doping Administration and Management System (ADAMS) database. […]

How encryption molded crypto-ransomware

Ransomware is a major threat that keeps growing over time. According to Cisco’s recent midyear report, it dominates the malware market and is the most profitable malware type in history. By now, it seems unlikely any regular reader of our blog does not already know something about ransomware. If you do not—or would like a […]

Afraid of online hacks? Worry more about your phone

I talk a lot about the security problems and weaknesses of the internet, as well as the devices connected to it. It’s all true, and we badly need improvements. Yet the irony is that security in our online world is actually better than in our physical world. Think of how many people are scammed by […]

Security takes a backseat for uninterrupted, video game marathons

��}ے�ƒ��(A�”i/}o��%�:#YZ�|�gdmG(���f��8��O�1���32_��YA6�M��t�%�ʪ�����ʪ|t��룷�}�����Ww����z���5�b��4t��q��? ��0��u�

Google to draw attention to insecure HTTP websites

Google is looking to deliver even greater transparency when it comes to online security by identifying publicly – or “marking”, as it puts it – websites that are not as secure as they should be. In a blog, Emily Schechter, a product manager within the tech giant’s Chrome security team, revealed that as of 2017, its browser […]

<div>Grace Hopper: Computer bugs & the language of programming</div>

So, the story goes something like this. In 1947, in Virginia, US, an error was spotted on the Harvard Mark II, one of the first programmable computers in the world. A team went to investigate, discovering that a moth had been caught between a relay in a machine. It was subsequently removed and taped to […]

How to avoid certificate pinning in the latest versions of Android

We previously explained how to construct an analysis environment enabling the certificate pinning process to be bypassed in Android applications, in order to be able to examine network traffic and to easily determine what data is being transmitted over secure communications protocols. In particular, we looked at the steps to take to install Cydia Substrate and Android SSL […]

Business security: Securing your data weak points

��}�r�F���vU�a�g�1�~ˤW��Ļv쳔��},��@@Q���}��������7�’���_�(�v�;{76����t����L?y�����?ޞ���^��~s��(;�1�aG�����쫎� �(��]�6�>T�ν’#nX�{�D�=�Ƞ�*�eb_v�cύ��g3�+��:Jį”F8X�Y��0X�����c3V�[�c�L,�]F��-���T�� �[��b �w�(�0e}9�֍�t����iXcZv��UK�}&j��DkQ/@D^�x�z5����Ϟ=��� CIŖ�6�,0�?l�H%,:�O+������ذ�� �a�f��FV2��qd>U�Q��?��UZ_���h5�{B�^�7D�l�Xx�i}�Ӈ�K��d’*�x��V�Q;L������R���u��� M��x�O�-����#�nc�g�?�l���Y���翋�^Q[���(�/�}o7v�U뽻�ћ��4W���n�/s� :`[9�½/�6�y5ߪ�e��z)�g��/] /����l���+^�HW[�:*� (�ت��N��&������G�� �r�ccÝ~�u!ҏAC�����]��k�Y�a��D�������r��3�}�;3�k��7�ȡ$ E�}���G�9�/�ƩH�m�]r3��1vol�� ��8�Qb�A�)ǚ� q#B#�k���#4��H�1#��Qx bh�n��0N�@_��屗�|�O���^0�x�A�l��ڎ�PQN|h[ ��’�,�V�DM6�St���&r����$��v��zSs �}o�” ����(18���!3�q8͑��I��@!h�;��(�Xq����#e�IPϗ@͹�q�҆�xC�#���y{���.�A]����� �nG���Ca=!��5*�G�1���D������9c��P�n�M,�[�R� e0i`�1�qx��!�I���”n��t�pb ���AS��)~�Z4��CT’N�zs�!�!�L��4A�t+�(4�ۡ�N۱���#;D*�70.ɩ�+��-

The economics of ransomware recovery

Sometimes, the easy way out is the road to ruin. After WeLiveSecurity published the article Ransomware: To pay or not to pay?, SC Computing’s Bradley Barth picked up on a point I made there, where I said that we hear of instances where organizations pay ransomware even though they have backups because it’s cheaper. No […]

OPM criticized for 2015 major data breach shortcomings

The Office of Personnel Management (OPM) has been heavily criticized by the Republican members of the House Oversight and Government Reform Committee for not having in place appropriate cybersecurity measures, which contributed to last year’s major data breach. According to a report from the committee, OPM’s senior leadership were also held culpable for the security incident, […]

Voting machines are still too easy to hack

People have trouble prioritizing risk. For example, you often hear about the threat of voter fraud, when all evidence suggests that the risks of such fraud are inconsequential. In truth, hacked voting machines are much more likely to affect an election’s outcome.  Why would an election fraudster try to herd a flock of criminal participants to […]

Variety confirms CMS hijack by hacking collective OurMine

Variety has confirmed that its content management system (CMS) was hijacked on the weekend by the hacking collective OurMine. Once in, the group was able to send subscribers to the online and print publisher multiple newsletters via email. The subject line stated “Hacked By #OurMine”, while the body text read: “Hello Variety, it’s #OurMine, don’t […]

CEO fraud: How to stay protected against this modern day deception

So, you’re minding your own business working through your day-to-day battle of never-ending emails and sorting through all the stuff you should have finished yesterday. Suddenly, an urgent email drops into your inbox from the boss, asking for an urgent transfer of £8,000 to a designated bank account. It’s not overly unusual: it’s from the […]

18 years of Googling: Malware can still be just one click away

How do you navigate through virtual reality? What is the first webpage you open when you are looking for something online? Where do you go to answer a ‘how to’ question most often? For the majority of users, the answer would be Google. It’s been 18 years since Stanford PhD students Larry Page and Sergey […]

Financial cybersecurity ‘needs to be a key agenda item at G20’

Improving financial cybersecurity at an international level must be a key agenda item at the G20 Summit in China this month (September 4th-5th). This is according to a group of prominent US senators, who have urged president Barack Obama to raise this critical issue at the event. In a letter to the White House, Gary […]

VMworld: Can you trust your API?

The VMware ecosystem has become huge and now encompasses a daunting number of platforms that you don’t even think about, including many in the IoT world. But now, all of these devices have to talk to each other in order to get along, and they do that with Application Program Interfaces (API). Are APIs all […]

Top 5 threats for online gamers and how to avoid them

We all know how much you enjoy playing – socially, professionally or casually – video games, which is why we want to take this opportunity to share more information about safe online gaming. Previously we have discussed how to protect yourself while playing, with professional online gamers offering advice based on their knowledge and experience as […]

VMWorld: Do you know where your data is?

VMWorld this year feels like a confessional – operators coming clean about their lack of data visibility, heads hung in shame. The reasons are many, but foremost is workload – once you provision a data volume you never have time to get back to it and ask why, or update it really to mesh with […]

OSX/Keydnap spreads via signed Transmission application

Last month ESET researchers wrote an article about a new OS X malware called OSX/Keydnap, built to steal the content of OS X’s keychain and maintain a permanent backdoor. At that time of the analysis, it was unclear how victims were exposed to OSX/Keydnap. To quote the original article: “It could be through attachments in […]

<div>Hollywood's 5 biggest hacking myths</div>

If you’ve ever hacked for a living — wearing a white hat, I hope — you probably can’t stand the unrealistic light most shows and movies shine on hacking and hackers. On the big and small screens, supergenius hackers enjoy instantaneous success and always manage to stay one step ahead of the law. Typically they’re […]

21st century cybercriminals: The threat landscape has evolved

��}ے�F���(AsD�”^�n�u��d�n��;+k;�@��`�M�1��/;���_0�OΗlfV@�M�i�ޕf,�@UVV�*++��ᝧoN����3��W/����p�]�ro�ӄ��� 粧��C6����4�a`���Ew5�s��Hp�� ���#���d6�N���p�=�FI�fZ1H���>��B��Q�u�w�޵�����n�~�u�j-7�m��ˡ���;K�!O4�7���P��ݜ%M��v�1

Lax ALM security ‘contributed’ to Ashley Madison data breach

Avid Life Media (ALM), recently rebranded as Ruby Corp, has been heavily criticized for its lax cybersecurity measures, which contributed to the Ashley Madison data breach. According to a joint investigation by the Office of the Privacy Commissioner of Canada and the Office of the Australian Information Commissioner, ALM had “inadequate security safeguards and policies” […]

Do your kids know good password hygiene? Here are some rules

Growing up before the age of the internet and social networks has left many older users unprepared for risks looming in the virtual world. From that perspective, today’s kids are lucky, as the best cybersecurity practices, such as good password hygiene, are at hand. So, if you are not exactly the most security savvy of […]

Paranoia rules! 5 types of imaginary malware

When you’ve been writing about security for as long as I have, you develop a following. I’m grateful to my readers — without them, my editor would need to find another security writer. But I can’t help but notice that among those who consume my content is a small but tenacious group of people who […]

Ransomware: To pay or not to pay?

Towards the end of July 2016, Kevin Townsend brought it to my attention that Europol, the European Union’s law enforcement agency, had announced an initiative to address the ransomware problem. No More Ransom is intended to provide information and help victims recover their data without paying a ransom to the criminals. As well as being […]

Why you should hire good, skilled cybersecurity professionals

��}ے�F���(Q3″i/}�f�Z����QK���ڎ”P$��f�rG�ا�؍8���s��|�ff@�$��� i�Tee孲�����=yy�����޼x~��ݣa4r���A�”��Y����W݊78`�(����Hnx�u� �����w4����%�/��Sύ�io&��0S��V”q��9�A(�n� 3������v�|�=’��Ӯ�”_��#ѭ�b�{A�)=��hصĥm �~4��ڑ�-4�#��2H�8B�Hh�”�� �xn�y��/����`w���E��E�����j��|��پ���0 /�c[�y|��HXL����^�@8�JM�D@Ev3+l$,�w+~`��u��V���>�})BaƁMt�c_SH�P�Dh�w�fPC�� ���w�螦�7C;dH

Nemucod serves nasty package: Ransomware and ad-clickers

Just last week ESET reported on Nemucod shifting away from ransomware and downloading the ad-clicking malware Kovter instead. Now, it seems that the operators of the notorious downloader went a step further and are serving their victims the whole package – ransomware as well as ad-clickers. As before, the targeted user receives an email with […]

Individual arrested in connection with high-profile data at Sage

The City of London Police has confirmed the arrest of a 32-year-old employee in connection with a high-profile data breach at Sage. The woman was apprehended at Heathrow Airport, as part of the force’s “ongoing fraud investigation” into the incident at the accounting and payroll software company. This arrest all but confirms that the unauthorized […]

Nemucod now spreading banking trojans in Brazil

On the morning of Friday August 12th, ESET researchers noticed a huge outbreak of a new Spy.Banker variant, detected as Spy.Banker.ADEA. It happened at around 12pm CET. This new variant is similar to previous ones used by other banking trojans in South America. During execution, the malware checks if the system’s settings are in Portuguese […]

Why security is a transversal issue for video games development

How many times in the field of software development have we heard that safety must be considered from the outset to the release – and subsequent maintenance – of the app or program in question? Hundreds, right? Fortunately, developers have understood this fundamental concept for programming, especially those who write code for operating systems or […]

6 security advances worth celebrating

In the spirit of the Olympics, it’s time to celebrate our hard-won computer security defense advancements. Given the endless stream of news about embarrassing hacks and data breaches, I can see why you might be skeptical. The fact is tens of millions of computers are currently exploited, nearly every company is owned, and those that […]

QuadRooter: Unfortunately, you can’t have it patched for now

Soon after the discovery of the QuadRooter vulnerability, a remedy appeared on the Google Play app store. Unfortunately, neither of the two apps named “Fix Patch QuadRooter” by Kiwiapps Ltd. would patch the Android system. Already pulled from Google Play on ESET’s notice, these apps were malicious, serving their victims with unwanted ads. On top […]

EU-US Privacy Shield launches: Key points to this agreement

There has been a lot riding on this divisive and complicated agreement, which is why it has taken over two and a half years for all the involved parties to iron out all the details. As of July 12th, the new framework was officially adopted and put into effect. The EU-US Privacy Shield, as it […]

QuadRooter vulnerabilities leaves 900 million Android devices at risk of attack

Over 900 million Android smartphones and tablets are vulnerable to cyberattacks, as they contain a set of four vulnerabilities dubbed QuadRooter. These flaws were found in devices that use Qualcomm chipsets, Check Point revealed at this year’s DEF CON 24 Hacking Conference in Las Vegas. It stated that if any of the four vulnerabilities are […]

Old Facebook scam gets ready for new boost

ESET researchers are warning about Facebook hoax scams that spread fake terror news to trick victims into disclosing their Facebook credentials. For example, Facebook users in the Czech Republic were targeted with a fake news report on a “deadly attack in Prague”. Soon after the Facebook scam was publicly disclosed in Czech mainstream media, the […]

Nemucod is back and serving an ad-clicking backdoor instead of ransomware

The trojan downloader Nemucod is back with a new campaign. This time however, it has changed the payload served to its victims – ransomware is not its go-to malware. Currently the “weapon of choice” is a backdoor detected by ESET as Win32/Kovter, in this instance mainly focusing on ad-clicking. As a backdoor, this trojan allows […]

Car hacking: Defcon style

This year at Defcon, the car hacking village is bigger than ever, with more cars, car hacking adapters and giant snarls of tiny exposed wires tied to demo stations with car parts screwed to plywood stands than ever before. It’s car hacking 101 here, and class is in full force. The first thing you notice […]

NIST: It’s time move on from SMS 2FA

SMS-based two-factor authentication (2FA) should be phased out, according to the National Institute of Standards and Technology (NIST) at the US Department of Commerce. In its most recent Digital Authentication Guideline – draft version – the federal technology agency explained that this is because there are risks with this approach. NIST stated that as SMS messages […]

SHA-2 shortcut: Easy certificate management for Linux

I spend a lot of time working on enterprise Public Key Infrastructure (PKI), especially in light of the coming SHA-1 deprecation deadlines. It’s nearly all I do these days. One question my customers ask all the time is how to provision certificates on non-Windows devices and computers. Microsoft does an excellent job of automating the […]

Black Hat 2016: When middleware takes over the world

In years past at Black Hat here in Las Vegas, there was row after row of hardware, then, in later years, row after row of software for your workstation. Now there’s row after row of middleware designed to interpret all that data in real time and try to make sense of it all, to find […]

Afraid someone is misusing your webcam?

Imagine a situation where you are working on your laptop and all of the sudden the green light next to your built-in webcam blinks for a second and immediately goes dark again. Would you just ignore it? Or would you start digging around to find out if it was something more serious? If you want […]

Big spike in card fraud in Europe

There was a notable spike in card fraud in Europe last year, with the UK the worst hit, according to new data from FICO. The tech company revealed that the UK experienced an 18% rise in card fraud over a 12-month period, resulting in losses worth approximately $118 million. The UK is clearly a big […]

Fake Prisma apps found on Google Play

Before the release of the Android version of Prisma, a popular photo transformation app, fake Prisma apps flooded the Google Play Store. ESET researchers discovered fake Prisma apps of different types, including several dangerous trojan downloaders. The Google Play security team removed them from the official Android store at ESET’s notice. Prior to that point, […]

Yahoo looks into major data breach claims

Yahoo is looking into claims that it has become the latest high-profile victim of a major data breach. It is thought up to 200 million accounts are affected. If found to be true, it is thought to be connected to an unknown individual who refers to himself as Peace. He has already claimed responsibility for […]

Car hacking at speed – where vulnerabilities turn from critical to fatal

There’s a fundamental difference between criminal hackers and white hat vulnerability researchers. When a white hat finds a vulnerability they may explore it, and write an interesting presentation about what can be achieved through the flaw, but once they’ve described the security weakness to the appropriate party and the hole is closed – that’s it. […]

2016 Rio Olympic Games: The safe way to obtain tickets online

This year is the year of sporting fans. Over the past few months especially, they have had the opportunity to move from one big sporting event to the next with few gaps in-between. First, just before the summer break, sports fans enjoyed a full month of football with the European Championship in France, followed by […]

Profiles in cryptographic courage

I recently finished reading “Hedy’s Folly” by the scholar Richard Rhodes. In it he discusses the “most beautiful woman in the world,” 1930s and ‘40s superstar Hedy Lamarr. With her composer friend George Antheil, she invented frequency hopping. Frequency hopping (or spread spectrum) is a technology that underlies the communication transport and security of almost […]

Android users to receive notifications when new devices added to account

Android users will receive push notifications on their smartphone, alerting them to a new device being added to their account, Google has announced. It said that this feature is a key component of security, complementing other features like two-step verification and single sign-on. In particular, all of these features ensure that Android users are safe […]

Barclays launches voice recognition technology for telephone banking

When it comes to telephone banking, Barclays is looking to lead the way by enabling voice recognition technology for all of its customers. This means that when it comes to the usual security process for this particular service, instead of typing in a password, customers will instead be verified by their voice. While the bank […]

Get rid of these undesirable ‘friends’ on this popular social network

Whether because they share too much, because they send links and applications that you are not interested in, because you don’t know for real who they are, or because they are too passionate about their opinions, there are some online ‘friends’ that you should keep away from. Tomorrow we will celebrate the International Day of […]

The 10 Security Commandments for every SysAdmin

System administrators are responsible for the reliable operation of corporate IT resources, working around the clock to manage deployments and upgrades, as well as finding the fastest way to solve problems. Celebrating the 17th annual SysAdmin Day, we recognize their dedication and workplace contributions and want to show appreciation for their talent. However, we wondered […]

ISF publishes major update to its information security guide

The Information Security Forum (ISF) has published a major update to its Standard of Good Practice for Information Security  for IT security professionals. The Standard, as it is known, is a comprehensive guide to internet security best practise, providing organizations with a ready-made framework for responding to and managing major incidents. The latest edition shows a […]

Get rid of these undesirable ‘friends’ on major social network

Either because they share too much, because they send links and applications that you are not interested in, because you don’t know for real who they are, or because they are too passionate about their opinions, there are some online ‘friends’ that you should keep away from. Tomorrow we will celebrate the International Day of […]

Security professionals ‘extremely concerned’ by cybercrime threat

Security professionals are more concerned than ever by the threat of cybercrime, according to new poll. The Black Hat Attendee Survey 2016 – the second of its kind – found that 72% of cyber experts anticipate having to deal with a major data breach over the next year. This view is in response to the growing […]

Cyberattacks affect ‘nearly every single company’

��}�r۸���j�a΄�D$�aˎm)7q�����’g�l�uA”$ѦH��=W�w�?���U��or�d��?$˲���JΙ�”�F���h4�;O^��כ�䗷/_��}0��.q�7�i�3�i$��9�i�x�L�8س,�Sfy�] ��:�0j�o���`�bʋ�S��Cߋ�o/������bv[���pBÈŽ$����p����q�O;W��i��c����)�ig�~+�g�Oz6;s���?��ء� ��z�*Hc��̈��g,tF��=��M�����p�&]�e�MYk�*8z>xC�4i���t�>�V�0�Ψ��4ff���=|�����}�����[�g�n���9|v���Q�#`�`��wJB��(�pY4a�%هQ��)��ӂ�������!��f挹���0 ����Sk)+��)�,�ΡY�!��29t�=����� o’ND�x��ؙ:�3�̜xB1�a�o�N���ŀ�4���4″t4bØܻ��

5 highlights from the ‘information security Olympic Games’

There is nothing quite like the Summer Olympic Games. Often described as one of the greatest sports events in the world, the spectacle of this historic sporting extravaganza, in terms of the pomp of the ceremony to the amazing feats achieved by the athletes, makes for captivating viewing. In the spirit of this year’s event, […]

3 ways websites get pwned — and threaten you

Some days when I’m wasting time on the internet, it seems like I can’t visit three websites in a row without hitting a fake “you’re infected” scam or bogus browser extension ad. Most of the time these malicious offerings launch on otherwise legitimate websites — or secretly direct your browser to illegitimate websites. For almost […]

Auto industry publishes first ever cybersecurity best practices

��}ے۸�����gL�-����U�

Researching Mr. Robot, Elliot’s world, and cybersecurity at Comic-Con

(With Comic-Con International 2016 taking place in ESET’s own backyard again this year, we are digging into all-things cybersecurity at the Con. In this article, Guest Writer Anna Keeve enters the world of Mr. Robot). ESET’s support for Comic-Con ranges from tips for staying safe while traveling, and hitting the streets to make sure people […]

Analyzing Mr. Robot: S02E01

��}ے�F���(QsD�”�[߻�:RKkF����h����$� ƥٴ���p�m^�e#6b����OΗlfV���l�c�J3�@�*+++3+3+�����oO�~x�}}�����&��a��5�jߟ֘��}5������w�n���Oy� ֠ν� 7��{�D�MyhPQ��ٗ�ډpC�����5f�_�Zȯ�66xhN?�� G�^������g��ډ�zFh�,��/��|Uט�A���3O�a��̶���◶�5��b�k���h�i8|Э�4b�p-�C�]r��& “���aϸ�/����}�G;���s����7�����M����o.��U����ipi8�e��t3`O^�����n����vv:����W’�v�=��%,��L�v/�ϝA-�&�B��”�56�mj�o��u=��!��f�;�%��v8�M1m�����$�”봻z�MOO”�`��?��W��j�#��Og�������V��74dWS�w���GŸ��-�*�~|��آ2�K�8���� �ӹLJ7>0]jPa!oO��܈B;�r%y�5p(�n��&*”ܸ,��?��5b߻)#�$^�&x���*{Ԛz�����T�%̼J����ta��E��?�%�6L�n��Z��1�)-�Wm�w����w�W�$r#x���0�]�0uR�CGкu���Z0wC�jN9J����v�DT������c;= b~��/��F��{�в���Kh+1B��ۏ-�p��)Z#b�f)���E�V=�z�;^��bQfNN�����t����������v:{�>�v��C(ߦc�6s�Ks��/����wJ>0�{�k�4��O��/f5�-�)�S��”�hSKۧ�` �������,�J%���`+0�PD��İx�o��C�t�6�����tf�|G���”x��)[��C˅�H�Y�PP�~����q��M ���`��� plm�3iiZw���j|d8?�B��䌘��}Z���Fԁ�d�M�/�+{E=‰OQ`�,a��B��’�e�s�€�p�l�|c���!��ۓ�h��R)1�@����a2ԡ����R�@�1� �hyAhK%5�� ����u�J�>5C�Y��}uʸ�^����K8�㥟�#V���Q�����M ��]�`3nN���J`�)���n�m�����M �0�n�V���l����A��1� y����@�WF5U=.�uo��a�t%�k�u@�I������ ��.��^��%����&>/�roE5*K�,Pd�3�2��@�%o?�*]v�a�A��R�X;���E�A?Wi��yN���O �������OJ’oY�)��Q��[1����,�G��~��O��Y�-� ��8��`�e�� ��u�ܡ���nw#]�}���Fk���l)ӡWFȃ�}�cy[�[��JykO��5L8�-{mt�r@o���fF���f�B�wrc�5L�gU}U�Be?�%蛬��K������$j�TPMq� �la�=`�s|*w���l2��?.mn ӿM+��+`�,_x���Y��N*ĴyX�V�Zq���,l�� � /�@U�H} 8?����d�A��G!-�8i’����)�}g���w3’�B�� +6�!��`$Ŋ���߾��E�j�E����b����i���d�X�7�*��b� f�gp�gh���F>���0/�ͮ��P�f{_-s�Q��bVWղ�U s/]�J˜�V�Ug��f��d{m�7�G����彁R�z5����YW_��)1�9m7: ��>��8�E��`�����=���8�D�F�D�9�^�lu��b~K�z�ա��i��9Pd�1�z�@oR�d�pl�=4���L~�|ò���i�ţm(ߣգfY�i�e �֓�;��2�`�N~ti!IWg0.VX�?~�ﰼLӸBF3��`�}M�V⽘6����@.yB=��šIB�7&��] [ph�v��Mj�`_̡����Eǒ�.�~�ygt� ���A1��2x/���;�铱�9Q@)�R�a 6g�*,Iõ��4�W�Gn�f[��t�%M���gՑz)1�V�R��29�>�`�,�cp/V@��=�])}lQX9;n9�’ ��r�sv^��-���c�%uOlTB� 7��v��&o���}*E�Ȁ���k��qՅ��2�oGߺ�On2͖7 ��e���$�Fhw�b��1xt��f���ի��T}���MUW8*���ٌ`� �}a�Di=�zŴ��x��-��§�휏|&YF?nd#YcFVӔF�.Q�#�4:��”�5LF+� ���+��M���tL�?M0i /��*�e#_fb oQuzr�)Ώ�~C��3��e`Tb����~�}##]��7�����ӥ���㧴��w�ɽ��xL�+}Q�����նU/��L�x�T��:s|���;?�����[�?o���5����U������[���5{ �|ޚ�yk�j��fޚ}b}ޚ�yk��ٹ&>o���5������P��7����?�� “6�t(1p�et�rw��Q -�!�ۉ�-�5�D�g�F�ϻID��I=�DӡKr�⁘��_�6f-�J��~F4O�p����B��9�F�H�J�kof�{�!������o��o����U

Jackware: When connected cars meet ransomware

2016 is already being dubbed “The Year of Ransomware” and ransomware features prominently in my upcoming “Mid-Year Threat Review” webinar. In that webinar I will also be talking about the IoT (Internet of Things) and more specifically the IoIT (the Internet of Insecure Things); mainly because risks arising from the latter are on the rise. […]

Malicious scripts gaining prevalence in Brazil

Had we looked at a map of malware detections in Brazil a year ago, we would have seen that the two main computer threats were the downloaders that installed banking trojans, and the banking trojans themselves. Today the situation remains the same, but with an extra special ingredient – while threats used to be Windows .exe […]

Passwords not compromised by Ubuntu Forums data breach

A major data breach on the Ubuntu Forums has not compromised the passwords of its affected users. In an update to its announcement that an incident had taken place, its developer Canonical Ltd was keen to highlight that this information was not accessed. However, as Jane Silber, CEO of Canonical Ltd, revealed, usernames, emails addresses […]

4 basic security facts everyone should know

Today, almost all hacking is done by professional criminals. In many countries, illegal hacking accounts for more crime, dollar-wise, than noncomputer crime. The United Kingdom recently joined that club. Why is this important? First, if you find malware on your system, there’s a good chance it’s trying to steal your money. Second, no one is […]

A smarter approach to password security ‘needed’

��}�r�Ʋ�o�*�0��5Ș�K&}d�>�9�㍜�͵��!0$!��Q��������j�j��ϭ�’��M�$�=3�E��h�ٲ�H$0��������3��Γ�����)�����on?�DS�8���j?�(��Ⱦ�)��L��?0o��Sf��]��z8a��߂O���SQ^Tcb�{n��H{3�BL�D�”2��CsB��E�8i� 1��p����v�M}�C’�����,_եS�S�m6� ʔ��V4�Y��6�ƿ4��ڑM-4��z�*Hc�;L�i�,�G� �xn�`ئ��:�%�{����Ģ�5z���q�^��o��1��©�y����۷,;�:?��rF��@�����k�ͅN(�U�v���$: -6Ϳ�ޙ��`�)r@�Do�_�E�n��C!�����0?�*||�%�?����C��Ȯ�Յ�E%��S=�v�S�}�Ln �J�*^]ۮ�Vh����)�s�Pε,|#�����-LU���*�>*�J��{���������̠90��y1���z��h�)i�o{�>�4�%i�h�*���pۘK/��F4v������|`E���7D}��BLQm�{͛`���L@�]f{d4���n���Eu��,�>�J_���Q@��`�n�$_�n �u�9H��=��5�’�� 5-}���fg�p;� v�����[2���= �Ƃ��iځ ���n�Y4�=�#:t��jRQo����j帷s5�YוZX��W�W���ӄ;&�.���j���0�?m����y�q[����: ULt���c�;�z�|6`y�Y���aP��?C]�#NC� l�P’b�K�y+V6���Wk`���a��’oE�1Zz��Ł�ê��9��3�W

Firefighting, security and compliance

��}�v9��}N�L�d����fɔǖ�.��%W��:`&H��Ld�E˥s�q�w_v��u��?�/و��$E�tu�Ue���@D “�y����_�>c߾{����’��e.�ƃ���Ok��ȹ���M��?l���7���wkP��É���-�D�NEĩ�!~���A�Dz��”���5f�o�Z$.�66xdMx�hG#�����p����c�DN}9C7�ų��ǢX��S1�]8b�� ʕ�9v4��±�A_Z����Z��n���cW� �B�ȱ�� � {��g��d﹯zOm.������[���m����V�^��4��c�H��n�ɳ����㝽���n��|o����O”��X�� T���=K ��{Q� ㈅�6u”�/�� fK�D���Zp�����y����t�ڝ�v�G�H �m$�&�H_ќDו��9�����tTTD�劥�qr���e�~�÷�8ps8~�AD�9C.ϵ�`/�-�P����CG�p5�#n�����S~������Ǫr�2tcɐ����C��d��:�w�et�����a�s�ݹ��v:+�M� Z�Zh��^o4Y����q�|,�摜v�}Wr;L�f2���͏�8ז�x��H��ȵ��)�%������4�`(E9X�X���S�x�oI�/��8 ���֎�ĭ���rf��|1��S�H�l�>Ն

Fake apps on Google Play tricked users into paying instead of delivering promised followers

��}��F��o)��P�fE�”~5�Kl�Ԓl�J��-�땵E�HB 0>�͑;b��~]�]Ľ�E������=�EµwT� ���uhY�����[M���@_&ls��H�w�s�d�Fz�>0�e��ǖU������S�pE�ՠe��p���X�A�[�G�q�>zA��= >�&�K���P�0���>.g��’�g����^�>���b ���� [���#[��������{���Ç�U���9�^���P�0 ���ji�9v�p��[���{��.t��w������5�W����q�|p�K���LA kiK��V����Uk��2ܲ��ü�a�vE��Ac�o� &>a�Z����K��Ԩ���P”��`L�����5l;���#`���03�3��4�< �A�BBeO�,L�_5P�H}��~���%h��4�XTs�kCCM�8!DS�X�r�W��?T�Z�vY��l��1J}ɴ[ù�)��fptN�Gw�������Y�~ ����q�sN-�(�6w#������/z8�V��1��)&��*y�.�"���n�#�]���;� � c�(�b�*��^B���/�>�����2w%U�m�*�o��)�>#�K���¤g���i’ͭДֳ����o��E7��d���$�[Q� �h����m���lq{��Bs`��+�b ���$�S�,���}��J JҖ���-��1�m̕��C;Q�����}`E���7D}��BLQm���`���L@��k�=2���n���Eu��,�>�J82�=/ ������’R�����C�f ��C��1X�FX� R�4v�o���è`���`�=��+�ۣ0a”��;��g��

Were you planning on downloading the Pokémon GO APK? Beware fake versions!

Since 2015, thousands of aspiring Pokémon trainers have been waiting for the release of Pokémon GO, the augmented reality game that will allow players to catch hidden Pokémon’s in the real world and conquer “gyms” through the internet, traveling both physically as well as within the app itself. For the first time, we will be […]

Spotted! 9 signs of a malicious download

Most people’s computers get exploited in only a handful of ways. Among the most popular methods is tricking people into downloading and running Trojans. Often, unsuspecting users get socially engineered into running a malicious file or app by following a link in email or visiting a website. It can be tough to spot the fake […]

Ransomware: First files … now complete devices

A major threats to computer security is malicious code. In fact, over the years, it has become one of the main causes of security incidents, from the first viruses in 1986 to the most sophisticated malware of today. And this particular type of malware, although it is not new, has become increasingly troublesome for both businesses […]

Chicago man pleads guilty in celebrity iCloud data breach

��}�r۸���j�a� ��H��_�#�:Nr&g�gf�&YDBm���ò&���g�j���V��}��$� ��$˲���MΙ�”�F���h4�Gw��9>���3��髗�����Cꎺ s�O�lh_vot@�Q��7�� 3��u�

Data leak dangers: Know your weak spots

From customer credit card details that ease the flow at online checkouts to employee records that are vital to HR departments, today’s businesses are built on sensitive data. In many ways, it’s the lifeblood that makes the modern company tick. If experience is anything to go by, though, it can also feel like the next […]

The security review: How secure are our cash machines?

Welcome to this week’s security review, including a closer look at cash machine security on the 49-year anniversary of the ATM. Also this week, we looked at how to stay safe from malicious scripts and how to avoid data leaks by plugging the holes in your organization’s defenses. ATMs turn 49: How secure are our cash machines? […]

How to secure your social media accounts

Courtesy of Facebook, Twitter, Instagram and Snapchat – to name but a few – we are increasingly living digital lives, where we interact and engage with our friends and family online. Social media has, without a shadow of a doubt, become central to our way of life. And yet, while millions use these platforms on a […]

<div>Hard Rock Hotel & Casino Las Vegas experiences data breach</div>

��}�r۸���j�a� ��H��_�#�$Nr&��kǞ���d] It(��˞���kl��Cl�>���’�n��ɲ�d2w�s&�H��ht7�F�ᝧo�}��p�����’��#��}���OG #6r��Z0�’�$ �-+��Y~|W�:�Nu����p�ʋ��=�k���0?1�/B�[��k ;O,l���(fI?MFƞF�A=��j���8�!Mܡ��z�Ϝ1+V���3��� J��3�I&}���63�q}7q�g�6�X�Sic���0�E�ȵ��W �����f�G��(��^u�:�uF�ã÷�m��/�?����Ǻ����&�lw���vw�{��vv�۝��v��{����Γǝ��E����G1���Ʌ�� c@��/�nDZF��qi_#ׇ��&�x6��3�g,fv�ɅiSk)+��)�-�ΡY�!��29t�=����;�A�’nL�x� �ĝ��3���dB1�an?L��c�h��#�!H�G��ix@i��yIc�3���M�I��RP�I���b X`��>�05p��M��n�V�n��c�w���1″�a�3z��!��p�$��(�2��x/@qP���T �|�(qm�-,�C��ِ/j�/5��F���{���_y -�#�dm]9��W���,^Z%L����9�6��2�;F��qgk��~�w���o����h�E�v�v��lm�w�A�Q)��;�c��X*�6 ��:q>�I$���p��%]*5a�>��V�N�4����K ʂ>lX�,hCi��ő[H�`J]�,-��Yxf�@Ǔ ��w8�[�׀� 9z�^:v}���h�FR͍SzF�[m%n�� f��,d���=bI�����’mHc�h�}��x���ފ͙D��’F�޲����x���n�|����Z����Ï8H#�i�4� �j��ˡ֓�=���m/u��Ә�� ���gN����#��[���./�_wF�ϕ^���-��)�M�m~:��[N��F�ɉ͞yy����}�]'{�f��E-d���z��Ʈl͹��3��؝����t �ۖm����֡e8��~o9;�}���eο,��*�J�n�f�}ڲ�z�o �eY/~rqLǯA�44AjMh٤a�|�p�zN�n^b��ָ5i�� j���QD/A[�9[s:�ƂQ4�4��_�����E2�ٿ�n�=;�Y�

11 essential data security tips for travelers

I travel all over the world for my job, and for my hobbies. Although there are still plenty of places I haven’t been, I’ve visited enough foreign countries that I don’t deny it when someone calls me a world traveler. Over the years, I’ve experienced my fair share of foreign spying. I know what it’s […]

Hard Rock Cafe experiences data breach

The Hard Rock Cafe and Casino Las Vegas has released a statement alerting customers that their data may have been compromised if they visited the resort between October 27th, 2015 and March 21st, 2016. After receiving several reports of unauthorized activity associated with payment cards, the resort started an investigation into their card payment methods. […]

Stay cyber safe on the road: 10 tips for this summer season

��}�۶��o�*���R,��/�X��Ήϵco�I6��NQ$$q�”~�Fq������[�O��Or�d��?��hd’ٲωM�@��_h4��{��������ׯ_�}��`��h`�p��0�#ﲯ��!�$IxhYl�Sj�} ��y

Digital patch kit: How to protect yourself from data leaks

��}�۶��o�*���ZR,��/�X��N�s�؛qN��;E��DE0�Yq����٭ڭ�Wت}��or�d� ER�F��N�e��”�F��_h4��w��:}�����wo^��u��8�x̳�QO���Ƃ��=M���8��c���pӏ�jP���1���-x��NxlQQ�����=�T�1�c��,��寞��� ��c+�x�K�~�1�_ �?�?>�O�$�bw��A=��Έ��ք�K�Oƹ�S׉�=�_�6��G������G���^� �H����ȍ�~�Cw�ڀ��s����ߧ���D�x/;O����g���׭�Z?}aw>t/�Z�D���:V̍V;�����Q������ig������j�~s�����vW�b��������iQL�?K����pb�=����*���B��K0o

<div>Not so fast: Some security defaults shouldn't change</div>

There’s an old security mantra that says “always change the defaults!” Although this seems like a good general rule, in fact it’s true only for certain kinds of settings. Changing the defaults in other cases will just end up biting you in the end with little increased security to show for it. A few months […]

Cyberattacks should be included in international humanitarian law

��}�۶��o�*��gM)I]��K�챓�|�mfr��l�DBg(��e4g��c�V�>�V���y��@ �H���N�e��”�F���h4���=�$S�x��5�?i$��Ƚ�k�x�L�$ܷ�`�Sf��} ��ysƬXէS���]6�(QJ�’��v����?Z���ĥ���c�N�q�=f�nŒs�#�D_�|2�������> �t�{�}�P�� �^��w��?�9�������9��&�lw��/vw�{O�vv�۝�w;;�vg���g;Ϟvz����g$b^_��K��ƀ �_�ݎc�L��ҾF�_’0�}M�l63g�s�Y��4r�K���,4$RV2aS[�C�xC�er�{������Oܘ ����;uc��Ʉ0b��}������C�$��T���!��m/u������|�G&���ȥ>0��%�U��؎ܰ4h��x����b�mDl�yD;�I�7Y���y�L(�L`�S���x��|`,o��;;V{��nY*�F��Q@�P�2-�I�(���E�%u/@9P�����`�(qm�-,��r�m�zQC��^�ky �̠�p���(����+h�Ij���,K�~�f��*a:��O� (�a���1�[ǝ���^�a���n/7 ���A�n�ou�@��Q ��;�c���*�5 ��:q>د�Y�N��Cz��i8V��-] �o��Q����F�ڂ�J)Y���Uǂ�P�v��8VIL��/��?’�,b���$���$N��%�qB�^�%���]��S5/�uT�┞S�V@�;3�w��y2�48u�X���8&}�IҘ��o�w8��`}�bsf���i�� b,^�۽��~���mA=3���#��f��’ zV/-�r����-����l�l�=s �=������2�ͮvuu��7J}���5l��O�o�4h��9���rZ�5�MNl����O8���fk��c�p�”y�@��к��0���( ��`(;pG�{����]�;��͈%i����0��16�3�X8:A���|�c �#�u��$��Z�� %��G�ھE�����vo{����׆����N��n������iB��U�iz�’�A��8T���S�@�v� �/�l������:M�2m9}�}��C���N���z[�ZȐ��m�Vm�]ۚs��g�� !(��=�E��e�m���uhYN�.���[N���@_els��/��ʹR���Gv��l�^�[ClY֋�]���? �ZZ6i2�9���Ӱ�W��5nMZ��(�n�i��FFЖ`�֜-��`�8 q”����L& 6��ڭ�6�����jL��_&6�P޻�’?����7���o��~���hKe�z�����)’K���|l`9����T�ټj�i��v��Z0�6q�zl !���e���;|#���l��t��ơG/��©���Ѧ~ЇA�yA`[�ra� h�}�0w�uծϽ,:q������3f��Yu”�����0�b+ltN�������P�[���4��37Yt1�z6������:�V� �_�;���:3����T�ňE��I���U��9�}�

Acer experiences major data breach

Acer has experienced a major data breach, with up to 34,500 of its customers thought to be affected. It has already submitted a “breach notification sample” to the Office of the Attorney General in California, which states that one of its ecommerce sites was compromised. Worryingly, the electronics corporation has admitted that the data breach […]