Menu

Latest articles

Chinese-linked cyber crims nab $529 million from Indian nationals
Apple patches iPhone and macOS flaws under active attack
Apple patches zero-day holes – even in the brand new iOS 16

security update

Google Cloud closes $5.4b Mandiant acquisition
Security pros get ability to manually add incidents to Microsoft Sentinel
Reducing the risk of ransomware
Boffins build microphone safety kit to detect eavesdroppers
Retbleed fix slugs Linux VM performance by up to 70 percent
Uncle Sam sanctions Iran’s intel agency over Albanian cyberattack
Shape-shifting cryptominer savaging Linux endpoints and IoT
Data tracking poses a ‘national security risk’ FTC told
Feds freeze $30m in cryptocurrency stolen from Axie Infinity
Meta disbands Responsible Innovation team, spreads it out over Facebook and co
How to deal with dates and times without any timezone tantrums…
Toys behaving badly: How parents can protect their family from IoT threats

It pays to do some research before taking a leap into the world of internet-connected toys The post Toys behaving badly: How parents can protect their family from IoT threats appeared first on WeLiveSecurity

Regional restrictions on NFL game broadcasts and rising membership fees on streaming sites like Netflix, Hulu, and Disney Plus are just some reasons why frustrated consumers turn to illegal streaming sites. Marketed as an alternative to legitimate streaming services, illegal streaming sites have become a portal to connect criminals directly to you (their target). Unlike […]

US seeks standards dominance, lets Huawei access previously forbidden crypto tech
Dump these small-biz routers, says Cisco, because we won’t patch their flawed VPN
Mandiant ‘highly confident’ foreign cyberspies will target US midterm elections
Google urges open source community to fuzz test code
RDP on the radar: An up‑close view of evolving remote access threats

Misconfigured remote access services continue to give bad actors an easy access path to company networks – here’s how you can minimize your exposure to attacks misusing Remote Desktop Protocol The post RDP on the radar: An up‑close view of evolving remote access threats appeared first on WeLiveSecurity

Warning issued about Vice Society ransomware gang after attacks on schools
S3 Ep99: TikTok “attack” – was there a data breach, or not? [Audio + Text]
Private equity suits at Thoma Bravo pull out of Darktrace acquisition
Lazarus Group unleashed a MagicRAT to spy on energy providers
Red Hat extends Common Vulnerabilities and Exposure Program expertise as newly-minted Root organization
Essential Guide to Securing Node.JS Applications
What’s the secret behind a secure password?
Halfords slapped on wrist for breaching email marketing laws
DoJ charges pair over China-linked attempt to build semi-autonomous crypto haven on nuked Pacific atoll
Smashing Security podcast #288: Chiquita banana, dumb criminals, and detecting ring binders

security update

security update

security update

Golang adds vulnerability management tooling
Ransomware protection from the top drawer
US school year opens with reading, writing, and ransomware
DEADBOLT ransomware rears its head again, attacks QNAP devices
Worok: The big picture

Focused mostly on Asia, this new cyberespionage group uses undocumented tools, including steganographically extracting PowerShell payloads from PNG files The post Worok: The big picture appeared first on WeLiveSecurity

Massive hotel group IHG struck by cyberattack which disrupts booking systems
Mandiant links APT42 to Iranian ‘terrorist org’
QNAP tells NAS users to “take immediate action” after new wave of DeadBolt ransomware attacks
Cybercriminals target games popular with kids to distribute malware
As Cybersecurity Week begins, Beijing claims US attacked Uni doing military research
Pakistan politicians label government cybersecurity team ‘incompetent’

security update

Go programming language arrives at security warnings that are useful
Cyberattack brings down InterContinental Hotels’ booking systems
Ransomware gang hits second-largest US school district
Newly discovered cyberspy crew targets Asian governments and corporations
Unhappy about excluding nation-state attacks from cyberinsurance? Get ready to pay
Chrome and Edge fix zero-day security hole – update now!
Maximum protection against hostile incursions
NATO investigates after criminals claim to be selling its stolen missile plans
Microsoft mistakenly rated Chromium, Electron, as malware
China orders tech companies to ‘improve traceability’ of users to control ‘rumours and false information’
Peter Eckersley, co-creator of Let’s Encrypt, dies at just 43
Will cyber‑insurance pay out? – Week in security with Tony Anscombe

What if your organization is hit by a cyberattack that is attributed to a nation state? Would your insurance cover the costs of the attack? The post Will cyber‑insurance pay out? – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Google, YouTube ban election trolls ahead of US midterms

security update

Convicted felon busted for 3D printing gun parts
Revealed: US telcos admit to storing, handing over location data
Indian court directs chat app Telegram to disclose details of copyright infringers
3 multicloud lessons for cloud architects
Ex-NSA trio who spied on Americans for UAE now banned from arms exports
How to take control over your digital legacy

Do you have a plan for what will happen to your digital self when you pass away? Here’s how to put your digital affairs in order on Facebook, Google, Twitter and other major online services. The post How to take control over your digital legacy appeared first on WeLiveSecurity

S3 Ep98: The LastPass saga – should we stop using password managers? [Audio + Text]
FBI issues warning after crypto-crooks steal $1.3 billion in just three months
Over 900K Kubernetes clusters are misconfigured! Is your cluster a target?
BlackHat USA 2022: Devils Are in the File Descriptors
Smashing Security podcast #287: Lost in translation, spiders, and slapping tortillas
Here’s how 5 mobile banking apps put 300,000 users’ digital fingerprints at risk
Intro to blockchain consensus mechanisms
Oh no, that James Webb Space Telescope snap might actually contain malware
LabMD gets another shot at defamation claim against ‘extortionate’ infosec biz
FBI: Look out, crooks stole $1.3b in cryptocurrency in just three months this year

security update

URGENT! Apple quietly slips out zero-day update for older iPhones
Student Loan Breach Exposes 2.5M Records
Chrome patches 24 security holes, enables “Sanitizer” safety system
Decisions on health data sharing should not be taken by politicians, citizen juries find
China-linked APT40 gang targets wind farms, Australian government
Find a security hole in Google’s open source and you could bag a $31,337 reward

security update

JavaScript bugs aplenty in Node.js ecosystem – found automatically
Watering Hole Attacks Push ScanBox Keylogger
Boots lets down its customers, by only offering SMS-based 2FA
Blackhat USA 2022: Return to Sender – Detecting Kernel Exploits with eBPF
That ‘clean’ Google Translate app is actually Windows crypto-mining malware
Automation is the ultimate cloud security tip
TikShock: Don’t get caught out by these 5 TikTok scams

Are you aware of the perils of the world’s no. 1 social media? Do you know how to avoid scams and stay safe on TikTok? The post TikShock: Don’t get caught out by these 5 TikTok scams appeared first on WeLiveSecurity

Google Play to ban Android VPN apps from interfering with ads
Critical hole in Atlassian Bitbucket allows any miscreant to hijack servers
LastPass source code breach – do we still recommend password managers?
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms

security update

security update

French hospital crippled by cyberattack – Week in security with Tony Anscombe

As another hospital falls victim to ransomware, Tony weighs in on the much-debated issue of banning ransomware payouts The post French hospital crippled by cyberattack – Week in security with Tony Anscombe appeared first on WeLiveSecurity

77% of security leaders fear we’re in perpetual cyberwar from now on