Menu

Latest articles

Private equity suits at Thoma Bravo pull out of Darktrace acquisition
Lazarus Group unleashed a MagicRAT to spy on energy providers
Red Hat extends Common Vulnerabilities and Exposure Program expertise as newly-minted Root organization
Essential Guide to Securing Node.JS Applications
What’s the secret behind a secure password?
Halfords slapped on wrist for breaching email marketing laws
DoJ charges pair over China-linked attempt to build semi-autonomous crypto haven on nuked Pacific atoll
Smashing Security podcast #288: Chiquita banana, dumb criminals, and detecting ring binders

security update

security update

security update

Golang adds vulnerability management tooling
Ransomware protection from the top drawer
US school year opens with reading, writing, and ransomware
DEADBOLT ransomware rears its head again, attacks QNAP devices
Worok: The big picture

Focused mostly on Asia, this new cyberespionage group uses undocumented tools, including steganographically extracting PowerShell payloads from PNG files The post Worok: The big picture appeared first on WeLiveSecurity

Massive hotel group IHG struck by cyberattack which disrupts booking systems
Mandiant links APT42 to Iranian ‘terrorist org’
QNAP tells NAS users to “take immediate action” after new wave of DeadBolt ransomware attacks
Cybercriminals target games popular with kids to distribute malware
As Cybersecurity Week begins, Beijing claims US attacked Uni doing military research
Pakistan politicians label government cybersecurity team ‘incompetent’

security update

Go programming language arrives at security warnings that are useful
Cyberattack brings down InterContinental Hotels’ booking systems
Ransomware gang hits second-largest US school district
Newly discovered cyberspy crew targets Asian governments and corporations
Unhappy about excluding nation-state attacks from cyberinsurance? Get ready to pay
Chrome and Edge fix zero-day security hole – update now!
Maximum protection against hostile incursions
NATO investigates after criminals claim to be selling its stolen missile plans
Microsoft mistakenly rated Chromium, Electron, as malware
China orders tech companies to ‘improve traceability’ of users to control ‘rumours and false information’
Peter Eckersley, co-creator of Let’s Encrypt, dies at just 43
Will cyber‑insurance pay out? – Week in security with Tony Anscombe

What if your organization is hit by a cyberattack that is attributed to a nation state? Would your insurance cover the costs of the attack? The post Will cyber‑insurance pay out? – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Google, YouTube ban election trolls ahead of US midterms

security update

Convicted felon busted for 3D printing gun parts
Revealed: US telcos admit to storing, handing over location data
Indian court directs chat app Telegram to disclose details of copyright infringers
3 multicloud lessons for cloud architects
Ex-NSA trio who spied on Americans for UAE now banned from arms exports
How to take control over your digital legacy

Do you have a plan for what will happen to your digital self when you pass away? Here’s how to put your digital affairs in order on Facebook, Google, Twitter and other major online services. The post How to take control over your digital legacy appeared first on WeLiveSecurity

S3 Ep98: The LastPass saga – should we stop using password managers? [Audio + Text]
FBI issues warning after crypto-crooks steal $1.3 billion in just three months
Over 900K Kubernetes clusters are misconfigured! Is your cluster a target?
BlackHat USA 2022: Devils Are in the File Descriptors
Smashing Security podcast #287: Lost in translation, spiders, and slapping tortillas
Here’s how 5 mobile banking apps put 300,000 users’ digital fingerprints at risk
Intro to blockchain consensus mechanisms
Oh no, that James Webb Space Telescope snap might actually contain malware
LabMD gets another shot at defamation claim against ‘extortionate’ infosec biz
FBI: Look out, crooks stole $1.3b in cryptocurrency in just three months this year

security update

URGENT! Apple quietly slips out zero-day update for older iPhones
Student Loan Breach Exposes 2.5M Records
Chrome patches 24 security holes, enables “Sanitizer” safety system
Decisions on health data sharing should not be taken by politicians, citizen juries find
China-linked APT40 gang targets wind farms, Australian government
Find a security hole in Google’s open source and you could bag a $31,337 reward

security update

JavaScript bugs aplenty in Node.js ecosystem – found automatically
Watering Hole Attacks Push ScanBox Keylogger
Boots lets down its customers, by only offering SMS-based 2FA
Blackhat USA 2022: Return to Sender – Detecting Kernel Exploits with eBPF
That ‘clean’ Google Translate app is actually Windows crypto-mining malware
Automation is the ultimate cloud security tip
TikShock: Don’t get caught out by these 5 TikTok scams

Are you aware of the perils of the world’s no. 1 social media? Do you know how to avoid scams and stay safe on TikTok? The post TikShock: Don’t get caught out by these 5 TikTok scams appeared first on WeLiveSecurity

Google Play to ban Android VPN apps from interfering with ads
Critical hole in Atlassian Bitbucket allows any miscreant to hijack servers
LastPass source code breach – do we still recommend password managers?
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms

security update

security update

French hospital crippled by cyberattack – Week in security with Tony Anscombe

As another hospital falls victim to ransomware, Tony weighs in on the much-debated issue of banning ransomware payouts The post French hospital crippled by cyberattack – Week in security with Tony Anscombe appeared first on WeLiveSecurity

77% of security leaders fear we’re in perpetual cyberwar from now on

security update

PyPI warns of first-ever phishing campaign against its users
What is doxing and how to protect yourself

Doxing can happen to anyone – here’s how you can reduce the odds that your personal information will be weaponized against you The post What is doxing and how to protect yourself appeared first on WeLiveSecurity

Ransomware Attacks are on the Rise
Now Oktapus gets access to some DoorDash customer info via phishing attack
Firefox 104 is out – no critical bugs, but update anyway
LastPass hackers steal source code, no evidence of users’ passwords compromised
Twilio, Cloudflare just two of 135 orgs targeted by Oktapus phishing campaign
LastPass source code, blueprints stolen by intruder

security update

security update

Cybercriminals Are Selling Access to Chinese Surveillance Cameras

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or spoofing.

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

Updated images that include numerous enhancements, security, and bug fixes are now available for Red Hat OpenShift Data Foundation 4.11.0 on Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact

An update for systemd is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for curl is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Crooks target top execs on Office 365 with MFA-bypass scheme
S3 Ep97: Did your iPhone get pwned? How would you know? [Audio + Text]
Twitter, Meta kill hundreds of pro-Western troll accounts
Ever present danger
How RavenDB Has Earned the Trust of Hundreds of Companies
Shout-out to whoever went to Black Hat and had North Korean malware on their PC