Online Security
1 min read
45

WhatsApp Will Disable Your Account If You Don’t Agree Sharing Data With Facebook

January 10, 2021
0

“Respect for your privacy is coded into our DNA,” opens WhatsApp’s privacy policy. “Since we started WhatsApp, we’ve aspired to build our Services with a set of strong privacy principles in mind.” But come February 8, 2021, this opening statement will no longer find a place in the policy. The

Continue Reading
Online Security
2 min read
45

New Attack Could Let Hackers Clone Your Google Titan 2FA Security Keys

January 9, 2021
0

Hardware security keys—such as those from Google and Yubico—are considered the most secure means to protect accounts from phishing and takeover attacks. But a new research published on Thursday demonstrates how an adversary in possession of such a two-factor authentication (2FA) device can clone it by exploiting an electromagnetic side-channel

Continue Reading
Online Security
1 min read
48

North Korean hackers targeting South Korea with RokRat Trojan

January 8, 2021
0

A North Korean hacking group has been found deploying the RokRat Trojan in a new spear-phishing campaign targeting the South Korean government. Attributing the attack to APT37 (aka Starcruft, Ricochet Chollima, or Reaper), Malwarebytes said it identified a malicious document last December that, when opened, executes a macro in memory

Continue Reading
Online Security
1 min read
39

Creating A Strong Password Policy With Specops and NIST Guidelines

January 7, 2021
0

End-user passwords are one of the weakest components of your overall security protocols. Most users tend to reuse passwords across work and personal accounts. They may also choose relatively weak passwords that satisfy company password policies but can be easily guessed or brute-forced. Your users may also inadvertently use breached

Continue Reading
Online Security
1 min read
48

Hackers Using Fake Trump’s Scandal Video to Spread QNode Malware

January 6, 2021
0

Cybesecurity researchers today revealed a new malspam campaign that distributes a remote access Trojan (RAT) by purporting to contain a sex scandal video of U.S. President Donald Trump. The emails, which carry with the subject line “GOOD LOAN OFFER!!,” come attached with a Java archive (JAR) file called “TRUMP_SEX_SCANDAL_VIDEO.jar,” which,

Continue Reading
Online Security
1 min read
45

Healthcare Industry Witnessed 45% Spike in Cyber Attacks Since Nov 20

January 5, 2021
0

Cyberattacks targeting healthcare organizations have spiked by 45% since November 2020 as COVID-19 cases continue to increase globally. According to a new report published by Check Point Research today and shared with The Hacker News, this increase has made the sector the most targeted industry by cybercriminals when compared to

Continue Reading
Online Security
1 min read
42

British Court Rejects U.S. Request to Extradite WikiLeaks’ Julian Assange

January 4, 2021
0

A British court has rejected the U.S. government’s request to extradite Wikileaks founder Julian Assange to the country on charges pertaining to illegally obtaining and sharing classified material related to national security. In a hearing at Westminster Magistrates’ Court today, Judge Vanessa Baraitser denied the extradition on the grounds that

Continue Reading
Online Security
1 min read
46

Ticketmaster To Pay $10 Million Fine For Hacking A Rival Company

January 3, 2021
0

Ticketmaster has agreed to pay a $10 million fine after being charged with illegally accessing computer systems of a competitor repeatedly between 2013 and 2015 in an attempt to “cut [the company] off at the knees.” A subsidiary of Live Nation, the California-based ticket sales and distribution company used the

Continue Reading
Online Security
1 min read
45

Microsoft Says SolarWinds Hackers Accessed Some of Its Source Code

January 2, 2021
0

Microsoft on Thursday revealed that the threat actors behind the SolarWinds supply chain attack were able to gain access to a small number of internal accounts and escalate access inside its internal network. The “very sophisticated nation-state actor” used the unauthorized access to view, but not modify, the source code

Continue Reading
Online Security
1 min read
52

Secret Backdoor Account Found in Several Zyxel Firewall, VPN Products

January 1, 2021
0

Zyxel has released a patch to address a critical vulnerability in its firmware concerning a hardcoded undocumented secret account that could be abused by an attacker to login with administrative privileges and compromise its networking devices. The flaw, tracked as CVE-2020-29583 (CVSS score 7.8), affects version 4.60 present in wide-range

Continue Reading
Online Security
2 min read
44

Attackers Abusing Citrix NetScaler Devices to Launch Amplified DDoS Attacks

December 31, 2020
0

Citrix has issued an emergency advisory warning its customers of a security issue affecting its NetScaler application delivery controller (ADC) devices that attackers are abusing to launch amplified distributed denial-of-service (DDoS) attacks against several targets. “An attacker or bots can overwhelm the Citrix ADC [Datagram Transport Layer Security] network throughput,

Continue Reading
Online Security
1 min read
50

AutoHotkey-Based Password Stealer Targeting US, Canadian Banking Users

December 30, 2020
0

Threat actors have been discovered distributing a new credential stealer written in AutoHotkey (AHK) scripting language as part of an ongoing campaign that started early 2020. Customers of financial institutions in the US and Canada are among the primary targets for credential exfiltration, with a specific focus on banks such

Continue Reading
Online Security
1 min read
36

A Google Docs Bug Could Have Allowed Hackers See Your Private Documents

December 29, 2020
0

Google has patched a bug in its feedback tool incorporated across its services that could be exploited by an attacker to potentially steal screenshots of sensitive Google Docs documents simply by embedding them in a malicious website. The flaw was discovered on July 9 by security researcher Sreeram KL, for

Continue Reading
Online Security
1 min read
46

Law Enforcement Seizes Joker’s Stash — Stolen Credit Card Marketplace

December 28, 2020
0

The US Federal Bureau of Investigation (FBI) and Interpol have allegedly seized proxy servers used in connection with Blockchain-based domains belonging to Joker’s Stash, a notorious fraud bazaar known for selling compromised payment card data in underground forums. The takedown happened last week on December 17. The operators of Joker’s

Continue Reading
Online Security
1 min read
35

A New SolarWinds Flaw Likely Had Let Hackers Install SUPERNOVA Malware

December 27, 2020
0

An authentication bypass vulnerability in the SolarWinds Orion software may have been leveraged by adversaries as zero-day to deploy the SUPERNOVA malware in target environments. According to an advisory published yesterday by the CERT Coordination Center, the SolarWinds Orion API that’s used to interface with all other Orion system monitoring

Continue Reading
Online Security
1 min read
45

Police Arrest 21 WeLeakInfo Customers Who Bought Breached Personal Data

December 26, 2020
0

21 people have been arrested across the UK as part of a nationwide cyber crackdown targeting customers of WeLeakInfo[.]com, a now-defunct online service that had been previously selling access to data hacked from other websites. The suspects used stolen personal credentials to commit further cyber and fraud offences, the NCA

Continue Reading
Online Security
1 min read
40

Microsoft Warns CrowdStrike of Hackers Targeting Azure Cloud Customers

December 25, 2020
0

New evidence amidst the ongoing probe into the espionage campaign targeting SolarWinds has uncovered an unsuccessful attempt to compromise cybersecurity firm Crowdstrike and access the company’s email. The hacking endeavor was reported to the company by Microsoft’s Threat Intelligence Center on December 15, which identified a third-party reseller’s Microsoft Azure

Continue Reading
Tech News
2 min read
57

Huawei 5G passes Testing at DEKRA and OGSMA’s NESAS Evaluation

December 25, 2020
0

Huawei 5G & LTE: The First to Pass 3GPP’s SCAS Testing at DEKRA and Officially Passes the GSMA’s NESAS Evaluation.

Continue Reading