Online Security
1 min read
40

Italy CERT Warns of a New Credential Stealing Android Malware

January 28, 2021
0

Researchers have disclosed a new family of Android malware that abuses accessibility services in the device to hijack user credentials and record audio and video. Dubbed “Oscorp” by Italy’s CERT-AGID, the malware “induce(s) the user to install an accessibility service with which [the attackers] can read what is present and

Continue Reading
Online Security
1 min read
50

Warning Issued Over Hackable ADT’s LifeShield Home Security Cameras

January 27, 2021
0

Newly discovered security vulnerabilities in ADT’s Blue (formerly LifeShield) home security cameras could have been exploited to hijack both audio and video streams. The vulnerabilities (tracked as CVE-2020-8101) were identified in the video doorbell camera by Bitdefender researchers in February 2020 before they were eventually addressed on August 17, 2020.

Continue Reading
Online Security
1 min read
40

Targeted Phishing Attacks Strike High-Ranking Company Executives

January 26, 2021
0

An evolving phishing campaign observed at least since May 2020 has been found to target high-ranking company executives across manufacturing, real estate, finance, government, and technological sectors with the goal of obtaining sensitive information. The campaign hinges on a social engineering trick that involves sending emails to potential victims containing

Continue Reading
Online Security
1 min read
53

Enhancing Email Security with MTA-STS and SMTP TLS Reporting

January 25, 2021
0

In 1982, when SMTP was first specified, it did not contain any mechanism for providing security at the transport level to secure communications between mail transfer agents. Later, in 1999, the STARTTLS command was added to SMTP that in turn supported the encryption of emails in between the servers, providing

Continue Reading
Online Security
1 min read
41

Beware! Fully-Functional Exploit Released Online for SAP Solution Manager Flaw

January 24, 2021
0

Cybersecurity researchers have warned of a publicly available fully-functional exploit that could be used to target SAP enterprise software. The exploit leverages a vulnerability, tracked as CVE-2020-6207, that stems from a missing authentication check in SAP Solution Manager (SolMan) version 7.2 SAP SolMan is an application management and administration solution

Continue Reading
Online Security
1 min read
53

SonicWall Hacked Using 0-Day Bugs In Its Own VPN Product

January 23, 2021
0

SonicWall, a popular internet security provider of firewall and VPN products, on late Friday disclosed that it fell victim to a coordinated attack on its internal systems. The San Jose-based company said the attacks leveraged zero-day vulnerabilities in SonicWall secure remote access products such as NetExtender VPN client version 10.x

Continue Reading
Online Security
2 min read
38

Missing Link in a ‘Zero Trust’ Security Model—The Device You’re Connecting With!

January 22, 2021
0

Like it or not, 2020 was the year that proved that teams could work from literally anywhere. While terms like “flex work” and “WFH” were thrown around before COVID-19 came around, thanks to the pandemic, remote working has become the defacto way people work nowadays. Today, digital-based work interactions take

Continue Reading
Online Security
1 min read
43

Here’s How SolarWinds Hackers Stayed Undetected for Long Enough

January 21, 2021
0

Microsoft on Wednesday shared more specifics about the tactics, techniques, and procedures (TTPs) adopted by the attackers behind the SolarWinds hack to stay under the radar and avoid detection, as cybersecurity companies work towards getting a “clearer picture” of one of the most sophisticated attacks in recent history. Calling the

Continue Reading
Online Security
1 min read
46

SolarWinds Hackers Also Breached Malwarebytes Cybersecurity Firm

January 20, 2021
0

Malwarebytes on Tuesday said it was breached by the same group who broke into SolarWinds to access some of its internal emails, making it the fourth major cybersecurity vendor to be targeted after FireEye, Microsoft, and CrowdStrike. The company said its intrusion was not the result of a SolarWinds compromise,

Continue Reading
Online Security
1 min read
46

A Set of Severe Flaws Affect Popular DNSMasq DNS Forwarder

January 19, 2021
0

Cybersecurity researchers have uncovered multiple vulnerabilities in Dnsmasq, a popular open-source software used for caching Domain Name System (DNS) responses, thereby potentially allowing an adversary to mount DNS cache poisoning attacks and remotely execute malicious code. The seven flaws, collectively called “DNSpooq” by Israeli research firm JSOF, echoes previously disclosed

Continue Reading
Online Security
1 min read
48

Apple Removes macOS Feature That Allowed Apps to Bypass Firewall Security

January 18, 2021
0

Apple has removed a controversial feature from its macOS operating system that allowed the company’s own first-party apps to bypass content filters, VPNs, and third-party firewalls. Called “ContentFilterExclusionList,” it included a list of as many as 50 Apple apps like iCloud, Maps, Music, FaceTime, HomeKit, the App Store, and its

Continue Reading
Online Security
1 min read
46

NSA Suggests Enterprises Use ‘Designated’ DNS-over-HTTPS’ Resolvers

January 17, 2021
0

The U.S. National Security Agency (NSA) on Friday said DNS over HTTPS (DoH) — if configured appropriately in enterprise environments — can help prevent “numerous” initial access, command-and-control, and exfiltration techniques used by threat actors. “DNS over Hypertext Transfer Protocol over Transport Layer Security (HTTPS), often referred to as DNS

Continue Reading
Online Security
2 min read
42

WhatsApp Delays Controversial ‘Data-Sharing’ Privacy Policy Update By 3 Months

January 16, 2021
0

WhatsApp said on Friday that it wouldn’t enforce its recently announced controversial data sharing policy update until May 15. Originally set to go into effect next month on February 8, the three-month delay comes following “a lot of misinformation” about a revision to its privacy policy that allows WhatsApp to

Continue Reading
Online Security
1 min read
31

Researchers Disclose Undocumented Chinese Malware Used in Recent Attacks

January 15, 2021
0

Cybersecurity researchers have disclosed a series of attacks by a threat actor of Chinese origin that has targeted organizations in Russia and Hong Kong with malware — including a previously undocumented backdoor. Attributing the campaign to Winnti (or APT41), Positive Technologies dated the first attack to May 12, 2020, when

Continue Reading
Online Security
1 min read
41

Experts Uncover Malware Attacks Against Colombian Government and Companies

January 14, 2021
0

Cybersecurity researchers took the wraps off an ongoing surveillance campaign directed against Colombian government institutions and private companies in the energy and metallurgical industries. In a report published by ESET on Tuesday, the Slovak internet security company said the attacks — dubbed “Operation Spalax” — began in 2020, with the

Continue Reading
Online Security
1 min read
44

Intel Adds Hardware-Enabled Ransomware Detection to 11th Gen vPro Chips

January 13, 2021
0

Intel and Cybereason have partnered to build anti-ransomware defenses into the chipmaker’s newly announced 11th generation Core vPro business-class processors. The hardware-based security enhancements are baked into Intel’s vPro platform via its Hardware Shield and Threat Detection Technology (TDT), enabling profiling and detection of ransomware and other threats that have

Continue Reading
Online Security
1 min read
52

Warning — 5 New Trojanized Android Apps Spying On Users In Pakistan

January 12, 2021
0

Cybersecurity researchers took the wraps off a new spyware operation targeting users in Pakistan that leverages trojanized versions of legitimate Android apps to carry out covert surveillance and espionage. Designed to masquerade apps such as the Pakistan Citizen Portal, a Muslim prayer-clock app called Pakistan Salat Time, Mobile Packages Pakistan,

Continue Reading
Online Security
1 min read
52

Researchers Find Links Between Sunburst and Russian Kazuar Malware

January 11, 2021
0

Cybersecurity researchers, for the first time, may have found a potential connection between the backdoor used in the SolarWinds hack to a previously known malware strain. In new research published by Kaspersky researchers today, the cybersecurity firm said it discovered several features that overlap with another backdoor known as Kazuar,

Continue Reading