Online Security
2 min read
35

Trend Micro blocks over 232 million attacks in Malaysia during 1H21

October 8, 2021
0

Trend Micro blocked 40.9 billion email threats, malicious files, and malicious URLs for customers in the first half of 2021.

Continue Reading
Online Security
1 min read
34

Ransomware Group FIN12 Aggressively Going After Healthcare Targets

October 8, 2021
0

An “aggressive” financially motivated threat actor has been identified as linked to a string of RYUK ransomware attacks since October 2018, while maintaining close partnerships with TrickBot-affiliated threat actors and using a publicly available arsenal of tools such as Cobalt Strike Beacon payloads to interact with victim networks. Cybersecurity firm

Continue Reading
Online Security
1 min read
31

Code Execution Bug Affects Yamale Python Package — Used by Over 200 Projects

October 7, 2021
0

A high-severity code injection vulnerability has been disclosed in 23andMe’s Yamale, a schema and validator for YAML, that could be trivially exploited by adversaries to execute arbitrary Python code. The flaw, tracked as CVE-2021-38305 (CVSS score: 7.8), involves manipulating the schema file provided as input to the tool to circumvent

Continue Reading
Online Security
1 min read
35

Iranian Hackers Abuse Dropbox in Cyberattacks Against Aerospace and Telecom Firms

October 6, 2021
0

Details have emerged about a new cyber espionage campaign directed against the aerospace and telecommunications industries, primarily in the Middle East, with the goal of stealing sensitive information about critical assets, organizations’ infrastructure, and technology while remaining in the dark and successfully evading security solutions. Boston-based cybersecurity company Cybereason dubbed

Continue Reading
Online Security
1 min read
33

New Study Links Seemingly Disparate Malware Attacks to Chinese Hackers

October 5, 2021
0

Chinese cyber espionage group APT41 has been linked to seemingly disparate malware campaigns, according to fresh research that has mapped together additional parts of the group’s network infrastructure to hit upon a state-sponsored campaign that takes advantage of COVID-themed phishing lures to target victims in India. “The image we uncovered

Continue Reading
Online Security
1 min read
38

Poorly Configured Apache Airflow Instances Leak Credentials for Popular Services

October 4, 2021
0

Cybersecurity researchers on Monday discovered misconfigurations across older versions of Apache Airflow instances belonging to a number of high-profile companies across various sectors, resulting in the exposure of sensitive credentials for popular platforms and services such as Amazon Web Services (AWS), Binance, Google Cloud Platform (GCP), PayPal, Slack, and Stripe.

Continue Reading
Online Security
1 min read
41

Here’s a New Free Tool to Discover Unprotected Cloud Storage Instances

October 3, 2021
0

The IDC cloud security survey 2021 states that as many as 98% of companies were victims of a cloud data breach within the past 18 months. Fostered by the pandemic, small and large organizations from all over the world are migrating their data and infrastructure into a public cloud, while

Continue Reading
Online Security
2 min read
39

Apple Pay Can be Abused to Make Contactless Payments From Locked iPhones

October 2, 2021
0

Cybersecurity researchers have disclosed an unpatched flaw in Apple Pay that attackers could abuse to make an unauthorized Visa payment with a locked iPhone by taking advantage of the Express Travel mode set up in the device’s wallet. “An attacker only needs a stolen, powered on iPhone. The transactions could

Continue Reading
Online Security
1 min read
34

Chinese Hackers Used a New Rootkit to Spy on Targeted Windows 10 Users

October 1, 2021
0

A formerly unknown Chinese-speaking threat actor has been linked to a long-standing evasive operation aimed at South East Asian targets as far back as July 2020 to deploy a kernel-mode rootkit on compromised Windows systems. Attacks mounted by the hacking group, dubbed GhostEmperor by Kaspersky, are also said to have

Continue Reading
Online Security
1 min read
42

New Azure AD Bug Lets Hackers Brute-Force Passwords Without Getting Caught

September 30, 2021
0

Cybersecurity researchers have disclosed an unpatched security vulnerability in the protocol used by Microsoft Azure Active Directory that potential adversaries could abuse to stage undetected brute-force attacks. “This flaw allows threat actors to perform single-factor brute-force attacks against Azure Active Directory (Azure AD) without generating sign-in events in the targeted

Continue Reading
Online Security
1 min read
31

Beware! This Android Trojan Stole Millions of Dollars from Over 10 Million Users

September 29, 2021
0

A newly discovered “aggressive” mobile campaign has infected north of 10 million users from over 70 countries via seemingly innocuous Android apps that subscribe the individuals to premium services costing €36 (~$42) per month without their knowledge. Zimperium zLabs dubbed the malicious trojan “GriftHorse.” The money-making scheme is believed to

Continue Reading
Online Security
1 min read
34

New BloodyStealer Trojan Steals Gamers’ Epic Games and Steam Accounts

September 28, 2021
0

A new advanced trojan sold on Russian-speaking underground forums comes with capabilities to steal users’ accounts on popular online video game distribution services, including Steam, Epic Games Store, and EA Origin, underscoring a growing threat to the lucrative gaming market. Cybersecurity firm Kaspersky, which coined the malware “BloodyStealer,” said it

Continue Reading
Online Security
1 min read
51

Russian Turla APT Group Deploying New Backdoor on Targeted Systems

September 27, 2021
0

State-sponsored hackers affiliated with Russia are behind a new series of intrusions using a previously undocumented implant to compromise systems in the U.S., Germany, and Afghanistan. Cisco Talos attributed the attacks to the Turla advanced persistent threat (APT) group, coining the malware “TinyTurla” for its limited functionality and efficient coding

Continue Reading
Online Security
1 min read
43

SonicWall Issues Patches for a New Critical Flaw in SMA 100 Series Devices

September 26, 2021
0

Network security company SonicWall has addressed a critical security vulnerability affecting its Secure Mobile Access (SMA) 100 series appliances that can permit remote, unauthenticated attackers to gain administrator access on targeted devices remotely. Tracked as CVE-2021-20034, the arbitrary file deletion flaw is rated 9.1 out of a maximum of 10

Continue Reading
Online Security
2 min read
37

Urgent Chrome Update Released to Patch Actively Exploited Zero-Day Vulnerability

September 25, 2021
0

Google on Friday rolled out an emergency security patch to its Chrome web browser to address a security flaw that’s known to have an exploit in the wild. Tracked as CVE-2021-37973, the vulnerability has been described as use after free in Portals API, a web page navigation system that enables

Continue Reading
Online Security
1 min read
46

Apple’s New iCloud Private Relay Service Leaks Users’ Real IP Addresses

September 24, 2021
0

A new as-yet unpatched weakness in Apple’s iCloud Private Relay feature could be circumvented to leak users’ true IP addresses from iOS devices running the latest version of the operating system. Introduced with iOS 15, which was officially released this week, iCloud Private Relay aims to improve anonymity on the

Continue Reading
Online Security
1 min read
39

A New Bug in Microsoft Windows Could Let Hackers Easily Install a Rootkit

September 23, 2021
0

Security researchers have disclosed an unpatched weakness in Microsoft Windows Platform Binary Table (WPBT) affecting all Windows-based devices since Windows 8 that could be potentially exploited to install a rootkit and compromise the integrity of devices. “These flaws make every Windows system vulnerable to easily-crafted attacks that install fraudulent vendor-specific

Continue Reading
Online Security
1 min read
40

Microsoft Warns of a Wide-Scale Phishing-as-a-Service Operation

September 22, 2021
0

Microsoft has opened the lid on a large-scale phishing-as-a-service (PHaaS) operation that’s involved in selling phishing kits and email templates as well as providing hosting and automated services at a low cost, thus enabling cyber actors to purchase phishing campaigns and deploy them with minimal efforts. “With over 100 available

Continue Reading