Menu

Category Archives: Security

Articles about security

SolarWinds: SEC ‘lacks the competence’ to regulate cybersecurity
MOVEit cybercriminals unearth fresh zero-day to exploit on-prem SysAid hosts
Russia’s Sandworm – not just missile strikes – to blame for Ukrainian power blackouts
What to do with a cloud intrusion toolkit in 2023? Slap a chat assistant on it, duh
Smashing Security podcast #347: Trolls, military data, and the hitman and her

security update

Women sue plastic surgery after hack saw their naked photos posted online
Microsoft, Meta detail plans to fight election disinformation in 2024
Microsoft .NET 8 enhances ID management
Atlassian cranks up the threat meter to max for Confluence authorization flaw
Monero Project admits thieves stole 6-figure sum from a wallet in mystery breach
Making iPhones and iPads crash with a Flipper Zero
Cancer treatments cancelled after Canadian hospitals hit by ransomware attack
Preventing data theft with ADX technology
Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
Microsoft likens MFA to 1960s seatbelts, buckles admins in yet keeps eject button
UK may demand tech world tell it about upcoming security features
Fresh find shines new light on North Korea’s latest macOS malware
Google hopes to better fight malicious apps with real-time scanning on Android devices
Woman jailed after Rentahitman.com assassin turned out to be – surprise – FBI
ICE faces heat after agents install thousands of personal apps, VPNs on official phones

security update

security update

US slaps sanctions on accused fave go-to money launderer of Russia’s rich
Okta breach affected 134 orgs, ‘or less than 1%’ of customers, company admits
Securing frontline Operational Technology environments
Is ChatGPT writing your code? Watch out for malware
KubeCon points to the future of enterprise IT

security update

The mysterious demise of the Mozi botnet – Week in security with Tony Anscombe

Various questions linger following the botnet’s sudden and deliberate demise, including: who actually initiated it?

Who killed Mozi? Finally putting the IoT zombie botnet in its grave

How ESET Research found a kill switch that had been used to take down one of the most prolific botnets out there

‘Corrupt’ cop jailed for tipping off pal to EncroChat dragnet

security update

security update

81K people’s sensitive info feared stolen from Hilb after email inboxes ransacked
Ex-GCHQ software dev jailed for stabbing NSA staffer
Microsoft pins hopes on AI once again – this time to patch up Swiss cheese security
UK data watchdog fines three text spammers for flouting electronic marketing rules
FTX crypto-villain Sam Bankman-Fried convicted on all charges
Feds collar suspected sanctions-busting Russian smugglers of US tech
Infosec pros can secure IT, but have harder time securing job satisfaction
Critical Apache ActiveMQ flaw under attack by ‘clumsy’ ransomware crims
Okta tells 5,000 of its own staff that their data was accessed in third-party breach
The state of API security in 2023
Boeing acknowledges cyberattack on parts and distribution biz
FBI boss: Taking away our Section 702 spying powers could be ‘devastating’
Smashing Security podcast #346: How hackers are breaching Booking.com, and the untrustworthy reviews
Ransomware crooks SIM swap medical research biz exec, threaten to leak stolen data

security update

security update

Mozi botnet murder mystery: China or criminal operators behind the kill switch?
Splunk cuts 7% of workforce ahead of Cisco acquisition
Critical vulnerability in F5 BIG-IP under active exploitation
Cybercrooks amp up attacks via macro-enabled XLL files
Get your very own ransomware empire on the cheap, while stocks last
Meeting the challenge of OT security
Indian politicians say Apple warned them of state-sponsored attacks
US officials close to persuading allies to not pay off ransomware crooks
‘Mass exploitation’ of Citrix Bleed underway as ransomware crews pile in

security update

security update

security update

security update

Now Russians accused of pwning JFK taxi system to sell top spots to cabbies
India’s biggest data breach? Hacking gang claims to have stolen 815 million people’s personal information
Ace holed: Hardware store empire felled by cyberattack
Finance orgs have 30 days to confess cyber sins under incoming FTC rules
Cybersecurity snafu sends British Library back to the Dark Ages
UK policing minister urges doubling down on face-scanning tech
Meta’s ad-free scheme dares you to buy your privacy back, one euro at a time
3 things for your 2024 cloud to-do list
Stop what you’re doing and patch this critical Confluence flaw, warns Atlassian
Florida man jailed after draining $1M from victims in crypto SIM swap attacks
Unpatched NGINX ingress controller bugs can be abused to steal Kubernetes cluster secrets
Cryptojackers steal AWS credentials from GitHub in 5 minutes
Stanford schooled in cybersecurity after Akira claims ransomware attack
LockBit alleges it boarded Boeing, stole ‘sensitive data’

security update

Roundcube Webmail servers under attack – Week in security with Tony Anscombe

The zero-day exploit deployed by the Winter Vivern APT group only requires that the target views a specially crafted message in a web browser

security update

security update

Protecting your intellectual property and AI models using Confidential Containers
Ask An OpenShift Admin episode 117: Security considerations while designing a CI/CD Pipeline
Apple Private Wi-Fi hasn’t worked for the past three years
F5 hurriedly squashes BIG-IP remote code execution bug
ESET APT Activity Report Q2–Q3 2023

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q2 and Q3 2023

Microsoft unveils shady shenanigans of Octo Tempest and their cyber-trickery toolkit
Have you accidentally hired a North Korean IT worker who’s spying on your company?
King Charles III signs off on UK Online Safety Act, with unenforceable spying clause
Apple drops urgent patch against obtuse TriangleDB iPhone malware

security update

security update

Forget the outside hacker, the bigger threat is inside by the coffee machine
Phony Corsair job vacancy targets LinkedIn users with DarkGate malware
Side channel attacks take bite out of Apple silicon with iLeakage exploit
Winter Vivern exploits zero-day vulnerability in Roundcube Webmail servers

ESET Research recommends updating Roundcube Webmail to the latest available version as soon as possible

ServiceNow quietly addresses unauthenticated data exposure flaw from 2015

security update

security update

Canada goosed as attackers shutter hospitals and China deepfakes its politicians