ESET researchers uncover the toolset used by the FamousSparrow APT group, including two undocumented versions of the group’s signature backdoor, SparrowDoor
ESET researchers detail a global espionage operation by FishMonger, the APT group run by I‑SOON
The group’s Operation AkaiRyū begins with targeted spearphishing emails that use the upcoming World Expo 2025 in Osaka, Japan, as a lure
Here’s what’s been hot on the AI scene over the past 12 months, how it’s changing the face of warfare, and how you can fight AI-powered scams
ESET researchers discover new ties between affiliates of RansomHub and of rival gangs Medusa, BianLian, and Play
While relatively rare, real-world incidents impacting operational technology highlight that organizations in critical infrastructure can’t afford to dismiss the OT threat
Listen up, this is sure to be music to your ears – a few minutes spent securing your account today can save you a ton of trouble tomorrow
Malicious use of AI is reshaping the fraud landscape, creating major new risks for businesses
ESET researchers uncovered MirrorFace activity that expanded beyond its usual focus on Japan and targeted a Central European diplomatic institute with the ANEL backdoor
By taking time to understand and communicate the impact of undesirable online behavior, you can teach your kids an invaluable set of life lessons for a new digital age
Big shifts in the infostealer scene, novel attack vector against iOS and Android, and a massive surge in investment scams on social media
Take a moment to think beyond our current capabilities and consider what might come next in the grand story of evolution
With AI’s pattern recognition capabilities well-established, Mr. Schölkopf’s talk shifts the focus to a pressing question: what will be the next great leap for AI?
Ransomware payments trending down, the cyber-resilience gap facing SMBs, and APT groups embracing generative AI – it’s a wrap on another month filled with impactful security news
Here’s how to avoid being hit by fraudulent websites that scammers can catapult directly to the top of your search results
The Sednit espionage group, also known as the Sofacy group, APT28 or “Fancy Bear”, has been targeting various institutions for many years. We recently discovered a component the group employed to reach physically isolated computer networks — “air-gapped” networks — and exfiltrate sensitive files from them through removable drives.
After taking a look at recent Korplug (PlugX) detections, we identified two larger scale campaigns employing this well-known Remote Access Trojan. This blog gives an overview of the first one
Microsoft’s .NET framework, which is used to build millions of websites and online applications, is taking further steps to go completely open-source, Microsoft has announced at the Connect() virtual development event. The company also stated its commitment to eventually ensure the free code runs on Mac OS and Linux too, Wired reports.
ESET study reveals many IT professionals are guilty of storing indecent material on their mobile phones, which would leave them embarrassed if lost.
APT actors trying to use big events as a lure to compromise their targets is nothing new. Tibetan NGOs being targeted by APT actors is also nothing new. Thus, surrounding the upcoming G20 2014 summit that is held in Brisbane, Australia, we were expecting to see G20 themed threats targeted at Tibetan NGOs. A Win32/Farfli […]
For ordinary laptop and smartphone users, Wi-Fi is not ideal – but it’s sometimes near-inescapable.
Mobile payments look set to be one of the defining technologies of 2015, as the launch of Apple Pay catalyses a boom in cardless payments – both from Apple’s own system, and rivals playing catch-up.
Microsoft released a patch last week for a critical vulnerability allowing remote code execution in Internet Explorer. This vulnerability is significant because it exploits an old bug present in Internet Explorer versions 3 through 11.
It’s easy to imagine that ALL connected devices – from fridges to CCTV cameras – are a security nightmare, but there are simple, sensible steps you can take to lock these risks down.
Self-driving cars are just around the corner, with the UK government putting up £10 million (around $15.6 million) for cities to pilot trials as soon as next year, but the country’s Institute of Engineering and Technology (IET) today issued stern warnings about the security of the technology.
Privacy and security online are hot button topics in America today, as a new survey by the Pew Research Center confirms, mirroring similar results from two different privacy and security surveys conducted by ESET.
Since the discovery of Stuxnet several years ago, there has been a parade of targeted malware that may have been created or sponsored by nation states. Does an average person or business really need to worry about these things?
Technology might evolve, but cyber gangs rely on tried-and-tested tactics. With a bit of care and attention, it’s easy to sort the genuine bargains from the too-good-to-be-true fakes.
The long-term health effects of electronic cigarettes – or E-cigarettes – are still open for discussion – but the devices could harm your computer, at least if one report is to be believed.
Firefox 34, the latest version of the Mozilla’s popular web browser has disabled support for SSL 3.0 in reaction to the POODLE exploit, reported by We Live Security back in October.
Three UK firms have been fined over $500,000 for a scam that involved Android apps signing up to a subscription service, and suppressing notifications informing the victim they were being charged, according to The Guardian.
Private data such as addresses and social security numbers can be just as valuable to cybercriminals as valid credit card details can be to thieves – if not more so. Lock yours down with our tips.
Security experts at ESET have released their latest research into the notorious TorrentLocker malware, which has infected thousands of computer systems around the world, taking data hostage and demanding a ransom be paid to ensure its safe return.
As regular readers will know, every year we publish our predictions on cybercrime attacks for the year ahead. Well, our South American research team has spent the last few weeks putting together our predictions for 2015.
Today, we are publishing research on ransomware that emerged in 2014. We have posted blog articles about this threat before, to raise awareness when we realized the criminals were targeting the United Kingdom and Spain.
The nonprofit organization that looks after name and internet domains has been hit by a spear phishing hack that has compromised company data, reports The Register.
Hackers can eavesdrop on your phone calls and text messages even with cell networks using “the most advanced encryption available” according to The Washington Post.
Win32/VirLock is ransomware that locks victims’ screens but also acts as parasitic virus, infecting existing files on their computers. The virus is also polymorphic, which makes it an interesting piece of malware to analyze. This is the first time such combination of malware features has been observed.
Turns out that the Material Girl has had her material stolen, and she’s blaming hackers!
Barack Obama promises that the United States will respond to the Sony hack, and North Korea drops off the internet. Is there a connection?
Fingerprint biometrics are entering the mainstream as a security measure, with both Apple and Samsung relying on readers to secure their flagship phones – but biometrics may not be as secure as many believe.
Like many others, I was enchanted by The Hobbit (and later Lord of the Rings) at a young age – long before Peter Jackson turned J R R Tolkien’s middle-earth fantasy books into a series of blockbuster movies.
Moonpig, the online personalised card company, has been accused of a shockingly sloppy attitude to security, after apparently leaving a serious hole in its security unpatched.
19,000 Bitcoin – valued at around $275 each, so $5 million together – have been stolen from a majour European Bitcoin exchange, reports RT.
With nearly 160,000 lust-ridden techies, corporate denizens and a few of us security types descending on a slightly crisp wintery Las Vegas to see what all the fuss is about at CES 2015, here are a few things to keep an eye out for this year at the show.
Today, we published our research about Windows exploitation in 2014. This report contains interesting information about vulnerabilities in Microsoft Windows and Office patched over the course of the year, drive-by download attacks and mitigation techniques.
Microsoft has warned of a new variant of a banking malware that appears to be targeting German speakers, according to PC World.
AOL has taken steps to stop a set of malicious advertisements being served through their sites, including The Huffington Post, Computer Business Review reports.
Ever lost a kid somewhere? Not anymore if the gadget vendors have anything to say about it. Now you can digitally strap your kid to your tablet and keep track of them. Kids not running enough to stay trim? There’s an app for that that works the same way. Got high blood sugar? You can […]
Facebook users around the world have reported the return of the network’s longer-lasting hoaxes – a legal disclaimer which allows users to regain copyright over their images and other content. Here’s why it doesn’t work.
Google has revealed that Android smartphones and tablets running versions of the software released before 4.3 (Jellybean) will no longer be given official updates to an important part of the software
Are hacking victims “hacking back”? That question was recently posed in headlines like this one from Bloomberg: FBI Investigating Whether Companies Are Engaged in Revenge Hacking. The Marketplace reporter, Ben Johnson, speculated that 2015 might be the year of “hacking back” when he asked me about revenge hacking.
The rent-a-DDoS service that knocked out Xbox Live and Playstation Network is powered by thousands of hacked residential internet routers.
British Prime Minister David Cameron has stated his belief that encrypted messaging services must have backdoor access to government agencies
President Barack Obama is planning to push legislation which would protect companies from lawsuits for sharing cyberthreat data with the government, reports the Washington Post.
The Swiss state owned Banque Cantonale de Geneve has confirmed that hackers have released confidential customer correspondences after the bank refused to pay the ransom demanded by the attackers
While phishing-related malware is still mostly Windows targeting, attacks that rely purely on social engineering and fake web sites might be delivered by any platform, including smartphones and tablets. The more cautious you are, the better informed you are, and the more you think before you click, the more chance you have of leaving phishing […]
It started, innocently enough, as a question asked in the ESET Security Forum titled “Eset – Do I Really Need Antivirus On My Linux Distros?” However, the answer to that seemingly simple question on Linux antivirus is more complex than a simple yes-or-no response.
Lizard Squad failed to encrypt its database of LizardStresser’s registered users – storing details of their usernames and passwords in plaintext. A schoolboy error if ever I heard one.
Cybercrime: there’s too much of it, and we need to do more to deter it. With the President of the United States now making frequent references to “doing more about cybercrime” now is a good time to look at what steps must be taken.
More than 1,800 Minecraft login details have been leaked online, German news site Heise.de has revealed.
Facebook has announced plans to crack down on spam and hoaxes in the newsfeed, with a note highlighting ‘false information’ when enough people flag the link as a hoax.
A recent report from Piper Jaffray found that 75% of companies expected to increase their IT security spending in 2015, following a year of high-profile hacks and data breaches in 2014.
NSA whistleblower Edward Snowden has claimed he doesn’t use an iPhone for fear of surveillance technology in the smartphone, reports The Independent.
Google’s Project Zero has released information on three as yet unpatched vulnerabilities in Apple’s OS X operating system, reports Ars Technica.
A vulnerability in Android’s Wi-Fi Direct functionality has been uncovered by security researchers.
ESET’s researchers recently encountered a piece of malware targeting the filling of the forms belonging to the Consulate of Poland. To understand why it is first necessary to have a brief look at the application process for visas.
Singer Taylor Swift has had her Twitter and Instagram accounts hacked, but laughed off claims that the hackers will release nude photographs of her.
Blackhat, the hacker movie directed by Michael Mann and starring Chris Hemsworth, could spread awareness of digital threats. If it is a learning opportunity, what are the lessons?
Even though WhatsApp now encrypts all of its messages and data, it pays to be secure with your chats. Here are our top WhatsApp security tips.
The recent opening of the Hacker List portal brings to mind the age-old question: Would you hire a hacker?
A new porn scam is spreading startlingly quickly through Facebook – one that has managed to spread malware to over 110,000 users in 48 hours, reports The Guardian.
President Obama’s budget proposal for the 2016 fiscal year includes a projected 10 percent increase in cybersecurity spend, reports Reuters.
A vulnerability in the latest patched version of Microsoft Internet Explorer that could allow hackers to launch “highly credible phishing attacks” has been uncovered, according to PC World.
Facebook updated its privacy settings at the end of January. As Facebook turns 11 today, here’s what you need to know about the new settings and how they could affect you.
A cat leads to a notorious death threat hacker finally being caught and jailed in Japan.
Is it time for big companies – at the very least – to abandon weak password security? If so, what password alternatives are there?
Buying and selling on eBay can be great, but it can also be fraught with risk. Here are some of the most common eBay scams and how they can be avoided.
It’s Safer Internet Day. But millions of devices which have not been designed with security in mind are connecting to the internet. Shouldn’t we be able to tell the manufacturers that enough is enough?
WhatsApp’s privacy settings are “broken” and can be bypassed by downloading a simple bit of software, claims the Dutch developer behind proof-of-concept tool WhatsSpy Public.
Facebook has officially launched ThreatExchange – a collaborative social network where companies can share information on cybersecurity threats, in an effort to neuter potential damage.
A Facebook hack that allowed attackers to remotely delete any photo they wanted to from the social network has been patched by the company.
With Valentine’s Day nearly upon us, millions will be looking for love online. Here’s six online dating scams to look out for.
Jamie Oliver’s website was affected by a malware issue, a spokesperson for the British celebrity chef has told the BBC.
Lenovo’s installation of a security-breaking app called Superfish on some computers has customers justifiably angry, but some folks are now unnecessarily confused by false positive detection.
A report by HP has found that 44 percent of all of the breaches in 2014 were caused by known vulnerabilities, between two and four years old.
One of the terms I’m most often asked to explain is what a “zero day” vulnerability or exploit is; let’s look at what that phrase entails.
The Ramnit botnet that is said to have affected 3.2 million computers has been shut down by European police.
After the Anthem mega-breach, questions abound about possible abuses of medical data. Here is a breakdown that offers some context.
A pair of possible exploits in hardware and software used for playing Blu-ray discs have come to light, reports PC World.
A widespread, long-standing security flaw that allows attackers to decrypt HTTPS-protected traffic between certain device and potentially millions of websites has been uncovered by security researchers, reports Ars Technica.
In this post, we lift the veil on Casper – another piece of software that we believe to have been created by the same organization that is behind Babar and Bunny.
There are many female researchers and computer experts who contribute to the field, helping everyone enjoy safer technology. We spoke to one of the most prominent: Lysa Myers, a member of our research team in the US.
An attempt to silence feminism blog Femsplain backfires on DDoS attackers, as they only help to raise its profile.
A number of seemingly unconnected Western websites were hacked over the weekend, with messages claiming Islamic State as the perpetrator.
iOS and OS X the most vulnerable operating systems? Don’t confuse vulnerabilities with exploits, or patch frequency with insecurity.
ESET assess the differences between CryptoFortress and TorrentLocker: two very different strains of ransomware.
One thing Microsoft has been very public about is Windows 10’s new strategy of releasing patches to update the operating system at different times for consumer and enterprise versions.
Apple fans keen to get their hands on the Apple Watch are advised to think before they click, after hackers exploited a wave of enthusiasm around the launch with a phishing scam linked to a fake giveaway.
IT teams’ time is always limited, and it doesn’t help when other things get in the way. Here’s seven things that waste your IT team’s time.
