Online Security
1 min read
53

Google Discloses Poorly-Patched, Now Unpatched, Windows 0-Day Bug

December 24, 2020
0

Google’s Project Zero team has made public details of an improperly patched zero-day security vulnerability in Windows print spooler API that could be leveraged by a bad actor to execute arbitrary code. Details of the unpatched flaw were revealed publicly after Microsoft failed to patch it within 90 days of

Continue Reading
Online Security
1 min read
47

How to Defend Against Malware, Phishing, and Scams During COVID-19 Crisis

December 23, 2020
0

As if the exponential rise in phishing scams and malware attacks in the last five years wasn’t enough, the COVID-19 crisis has worsened it further. The current scenario has given a viable opportunity to cybercriminals to find a way to target individuals, small and large enterprises, government corporations. According to

Continue Reading
Online Security
1 min read
37

A Second Hacker Group May Have Also Breached SolarWinds, Microsoft Says

December 22, 2020
0

As the probe into the SolarWinds supply chain attack continues, new digital forensic evidence has brought to light that a separate threat actor may have been abusing the IT infrastructure provider’s Orion software to drop a similar persistent backdoor on target systems. “The investigation of the whole SolarWinds compromise led

Continue Reading
Online Security
2 min read
45

Common Security Misconfigurations and Their Consequences

December 21, 2020
0

Everyone makes mistakes. That one sentence was drummed into me in my very first job in tech, and it has held true since then. In the cybersecurity world, misconfigurations can create exploitable issues that can haunt us later – so let’s look at a few common security misconfigurations. The first

Continue Reading
Online Security
1 min read
40

New Evidence Suggests SolarWinds’ Codebase Was Hacked to Inject Backdoor

December 20, 2020
0

The investigation into how the attackers managed to compromise SolarWinds’ internal network and poison the company’s software updates is still underway, but we may be one step closer to understanding what appears to be a very meticulously planned and highly-sophisticated supply chain attack. A new report published by ReversingLabs today

Continue Reading
Online Security
1 min read
41

Software Supply-Chain Attack Hits Vietnam Government Certification Authority

December 19, 2020
0

Cybersecurity researchers today disclosed a new supply-chain attack targeting the Vietnam Government Certification Authority (VGCA) that compromised the agency’s digital signature toolkit to install a backdoor on victim systems. Uncovered by Slovak internet security company ESET early this month, the “SignSight” attack involved modifying software installers hosted on the CA’s

Continue Reading
Online Security
1 min read
37

Microsoft Says Its Systems Were Also Breached in Massive SolarWinds Hack

December 18, 2020
0

The massive state-sponsored espionage campaign that compromised software maker SolarWinds also targeted Microsoft, as the unfolding investigation into the hacking spree reveals the incident may have been far more wider in scope, sophistication, and impact than previously thought. News of Microsoft’s compromise was first reported by Reuters, which also said

Continue Reading
Online Security
1 min read
46

How to Use Password Length to Set Best Password Expiration Policy

December 17, 2020
0

One of the many features of an Active Directory Password Policy is the maximum password age. Traditional Active Directory environments have long using password aging as a means to bolster password security. Native password aging in the default Active Directory Password Policy is relatively limited in configuration settings. Let’s take

Continue Reading
Online Security
1 min read
42

SolarWinds Issues Second Hotfix for Orion Platform Supply Chain Attack

December 16, 2020
0

Network monitoring services provider SolarWinds officially released a second hotfix to address a critical vulnerability in its Orion platform that was exploited to insert malware and breach public and private entities in a wide-ranging espionage campaign. In a new update posted to its advisory page, the company urged its customers

Continue Reading
Online Security
1 min read
48

Wormable Gitpaste-12 Botnet Returns to Target Linux Servers, IoT Devices

December 15, 2020
0

A new wormable botnet that spreads via GitHub and Pastebin to install cryptocurrency miners and backdoors on target systems has returned with expanded capabilities to compromise web applications, IP cameras, and routers. Early last month, researchers from Juniper Threat Labs documented a crypto-mining campaign called “Gitpaste-12,” which used GitHub to

Continue Reading
Online Security
1 min read
35

A Huge Dataset of 20 Million Malware Samples Released Online

December 14, 2020
0

Cybersecurity firms Sophos and ReversingLabs on Monday jointly released the first-ever production-scale malware research dataset to be made available to the general public that aims to build effective defenses and drive industry-wide improvements in security detection and response. “SoReL-20M” (short for Sophos-ReversingLabs – 20 Million), as it’s called, is a

Continue Reading
Online Security
1 min read
46

Mount Locker Ransomware Offering Double Extortion Scheme to Other Hackers

December 13, 2020
0

A relatively new ransomware strain behind a series of breaches on corporate networks has developed new capabilities that allow it to broaden the scope of its targeting and evade security software—as well as with ability for its affiliates to launch double extortion attacks. The MountLocker ransomware, which only began making

Continue Reading
Online Security
1 min read
45

Facebook Tracks APT32 OceanLotus Hackers to IT Company in Vietnam

December 12, 2020
0

Cybersecurity researchers from Facebook today formally linked the activities of a Vietnamese threat actor to an IT company in the country after the group was caught abusing its platform to hack into people’s accounts and distribute malware. Tracked as APT32 (or Bismuth, OceanLotus, and Cobalt Kitty), the state-aligned operatives affiliated

Continue Reading
Online Security
1 min read
47

Watch Out! Adrozek Malware Hijacking Chrome, Firefox, Edge, Yandex Browsers

December 11, 2020
0

Microsoft on Thursday took the wraps off an ongoing campaign impacting popular web browsers that stealthily injects malware-infested ads into search results to earn money via affiliate advertising. “Adrozek,” as it’s called by the Microsoft 365 Defender Research Team, employs an “expansive, dynamic attacker infrastructure” consisting of 159 unique domains,

Continue Reading
Online Security
1 min read
45

Valve’s Steam Server Bugs Could’ve Let Hackers Hijack Online Games

December 10, 2020
0

Critical flaws in a core networking library powering Valve’s online gaming functionality could have allowed malicious actors to remotely crash games and even take control over affected 3rd-party game servers. “An attacker could remotely crash an opponent’s game client to force a win or even perform a ‘nuclear rage quit’

Continue Reading
Online Security
1 min read
39

Amnesia:33 — Critical TCP/IP Flaws Affect Millions of IoT Devices

December 9, 2020
0

Cybersecurity researchers disclosed a dozen new flaws in multiple widely-used embedded TCP/IP stacks impacting millions of devices ranging from networking equipment and medical devices to industrial control systems that could be exploited by an attacker to take control of a vulnerable system. Collectively called “AMNESIA:33” by Forescout researchers, it is

Continue Reading
Online Security
1 min read
47

Zero-Click Wormable RCE Vulnerability Reported in Microsoft Teams

December 8, 2020
0

A zero-click remote code execution (RCE) bug in Microsoft Teams desktop apps could have allowed an adversary to execute arbitrary code by merely sending a specially-crafted chat message and compromise a target’s system. The issues were reported to the Windows maker by Oskars Vegeris, a security engineer from Evolution Gaming,

Continue Reading
Online Security
1 min read
35

Payment Card Skimmer Group Using Raccoon Info-Stealer to Siphon Off Data

December 7, 2020
0

A cybercrime group known for targeting e-commerce websites unleashed a “multi-stage malicious campaign” earlier this year designed with an intent to distribute information stealers and JavaScript-based payment skimmers. In a new report published today and shared with The Hacker News, Singapore-based cybersecurity firm Group-IB attributed the operation to the same

Continue Reading