Menu

Category Archives: Security

Articles about security

Pro-Russia group exploits Roundcube zero-day in attacks on European government emails

Our annual analysis of the most notorious malware has arrived. As always, it covers the trends, malware groups, and tips for how to protect yourself and your organization. This post covers highlights of our analysis, including the rise of ransomware as a service (RaaS), the six nastiest malware groups, and the role of artificial intelligence […]

A fortified data vault to give you peace of mind
Hunters International leaks pre-op plastic surgery pics in negotiation no-no
VMware reveals critical vCenter vuln that you may have patched already without knowing it
Hot fuzz: Cascade finds dozens of RISC-V chip bugs using random data storm
Citrix urges ‘immediate; patch for critical NetScaler bug as exploit POC made public
Spanish police make 34 arrests, dismantling cybercriminal gang that stole 4 million people’s data
Ex-NSA techie pleads guilty to selling state secrets to Russia
1Password confirms attacker tried to pull list of admin users after Okta intrusion
Element users are asking for protection against government encryption busting
Irish cops data debacle exposes half a million motorist records
How to have encryption, computation, and compliance all at once
Helping you bridge the cloud security gap
Scammers use India’s real-time payment system to siphon off money, send it to China
Cisco fixes critical IOS XE bug but malware crew way ahead of them
DC elections agency warns entire voting roll may have been stolen
Microsoft opens early access to AI assistant for infosec, Security Copilot
Redefining united data protection

security update

security update

Spearphishing targets in Latin America – Week in security with Tony Anscombe

ESET’s analysis of cybercrime campaigns in Latin America reveals a notable shift from opportunistic crimeware to more complex threats, including those targeting enterprises and governments

Admin behind E-Root stolen creds souk extradited to US
CloudBees readies cloud-native devsecops platform
Strengthening the weakest link: top 3 security awareness topics for your employees

Knowledge is a powerful weapon that can empower your employees to become the first line of defense against threats

Runtime security deep dive: Ask An OpenShift Admin episode 116
Enterprise security challenges for CNI organizations: Technical solutions to address security challenges
Casio keyed up after data loss hits customers in 149 countries
Better safe than sorry: 10 tips to build an effective business backup strategy

How robust backup practices can help drive resilience and improve cyber-hygiene in your company

Europol knocks RagnarLocker offline in second major ransomware bust this year
Millions of new 23andMe genetic data profiles leak on cybercrime forum
Cybercrim claims fresh 23andMe batch takes leaked records to 5 million
Ex-Navy IT manager gets 5 years in slammer for 2018 database heist
Ex-Navy IT manager jailed for selling people’s data on the dark web
October Cybersecurity Awareness Month to target internal security risks
Smashing Security podcast #344: What’s cooking at Booking.com? And a podcast built by AI

security update

Plastic surgeries warned by the FBI that they are being targeted by cybercriminals
D-Link clears up ‘exaggerations’ around data breach
CIA exposed to potential intelligence interception due to X’s URL bug

security update

Israelis told to secure their home security cameras against hackers
US cybercops urge admins to patch amid ongoing Confluence chaos
Vulnerability Exploitability eXchange (VEX) beta files now available
The TLS Extended Master Secret and FIPS in Red Hat Enterprise Linux
British boffins say aircraft could fly on trash, cutting pollution debt by 80%
Will you meet the directive?
Fraudsters target Booking.com customers claiming hotel stay could be cancelled
We’re not in e-Kansas anymore: State courts reel from ‘unauthorized incursion’
BLOODALCHEMY provides backdoor to southeast Asian nations’ secrets
Signal debunks online rumours of zero-day security vulnerability
Regulator, insurers and customers all coming for Progress after MOVEit breach
Staying on top of security updates – Week in security with Tony Anscombe

Why keeping software up to date is a crucial security practice that should be followed by everyone from individual users to SMBs and large enterprises

security update

security update

530K people’s info feared stolen from cloud PC gaming biz Shadow
Bungled ransomware raid targeting WS_FTP servers demanded just 0.018 BTC
Calls for Visual Studio security tweak fall on deaf ears despite one-click RCE exploit
After hackers distribute malware in game updates, Steam adds SMS-based security check for developers
Squid games: 35 security holes still unpatched in proxy after 2 years, now public

security update

security update

Virus Bulletin – building digital armies

Security researchers, global organizations, law enforcement and other government agencies need to have the right conversations and test potential scenarios without the pressure of an actual attack

Virus Bulletin PUA – a love letter

Late nights at VB2023 featured intriguing interactions between security experts and the somewhat enigmatic world of grayware purveyors

6 steps to getting the board on board with your cybersecurity program

How CISOs and their peers can better engage with boards to get long-term buy-in for strategic initiatives

Everest cybercriminals offer corporate insiders cold, hard cash for remote access
Building cyber resilience with data vaults
DISA STIG for Red Hat Enterprise Linux 9 is now available
US construction giant unearths concrete evidence of cyberattack
HM Government has partnered with SANS to train cyber security experts
Smashing Security podcast #343: Four-legged girlfriends, LoveGPT, and a military intelligence failure

security update

security update

security update

US Navy sailor admits selling secret military blueprints to China for $15K
CISOs’ salary growth slows – with pay gap widening
That day you find you’re suddenly in charge of Facebook’s official UK account
From chaos to cadence: Celebrating two decades of Microsoft’s Patch Tuesday
Securing the future of Industry 4.0: WALLIX white paper reveals key strategies – get your copy today!
curl vulnerabilities ironed out with patches after week-long tease
What to expect when the UK-US Data Bridge comes into force this week

security update

It’s 2023 and Microsoft WordPad can be exploited to hijack vulnerable systems
SBF on trial: The Python code that allegedly let Alameda hedge fund spend people’s FTX deposits
HTTP/2 ‘Rapid Reset’ zero-day exploited in biggest DDoS deluge seen yet
Mirai reloads exploit arsenal as botnet embarks on another expansion drive
Researcher bags two-for-one deal on Linux bugs while probing GNOME component
Hacktivists send fake nuclear attack warning via Israeli Red Alert app
Fresh curl tomorrow will patch ‘worst’ security flaw in ages
Ransomware attacks register record speeds thanks to success of infosec industry
Exercise Cyber Star tests Singapore response
DoJ: Ex-soldier tried to pass secrets to China after seeking a ‘subreddit about spy stuff’
Hacktivist attacks erupt in Middle East following Hamas assault on Israel
Datacenter cabling biz Volex confirms digital break-in
Learning from Let’s Encrypt’s 10 years of success
Chinese smart TV boxes infected with malware in PEACHPIT ad fraud campaign

security update

DinodasRAT used against governmental entity in Guayana – Week in security with Tony Anscombe

The backdoor can exfiltrate files, manipulate Windows registry keys, and execute commands that are capable of performing various actions on a victim’s machine

Fake friends and followers on social media – and how to spot them

One of the biggest threats to watch out for on social media is fraud perpetrated by people who aren’t who they claim to be. Here’s how to recognize them.

security update