Category: Industry News – HOTforSecurity

Fleeceware – 25 Play Store apps that empty your pockets

Last September, security researchers reported a number of app publishers that practice a shady business model, charging excessive amounts for apps if the user does not cancel the “subscription” before a free trial ends. Although Google Play decommissioned the reported…

iPhones now work as physical security keys for Google services

As multi-factor authentication becomes ubiquitous across all digital services, Google is adding a new safety net for security-conscientious iPhone owners. Apple customers can now use their shiny smartphones as security keys to access Google services securely. The latest update to…

Emotet strikes again, targeting 600 United Nations personnel

The Emotet Trojan, identified by security teams in 2014, started out as banking malware meant to steal sensitive data. Initially focused on the financial sectors, the malware later morphed, adding spamming and malware delivery services. Emotet’s latest phishing campaign targets…

Windows 7 Reaches End of Life

Windows 7, Windows Server 2008, and Windows Server 2008 R2 have reached their end of life, as Microsoft has stopped delivering all updates for the aging operating systems. Microsoft has been warning users about the impending end of life for…

Malicious npm package exfiltrating data from UNIX systems

A malicious JavaScript package was uploaded Dec. 30 2019 on the Node Package Manager (npm), the world’s largest software registry, containing over 800,000 code packages that developers use to write JavaScript applications. The package, identified as 1337qq-js, was spotted stealing sensitive…

Sodinokibi Hackers Now Use Stolen Data for Blackmail

Hackers using the Sodinokibi ransomware published stolen data to further extort their victims, marking a first for operations using this attack vector. Sodinokibi is usually identified in attacks against critical infrastructures, but that’s not a limit of the software. It’s…

Iran-Sponsored Hackers Might Be Probing U.S. Electric Sector

If the latest reports are to be believed, Iran-backed hackers are probing U.S. critical infrastructure by using password-spraying attacks, looking for weakness and human laziness. It’s no surprise that, following the conflict between the United States and Iran so far…

Scammer Easily Defrauds Town of Erie of $1.1 Million

A simple scam was used to rob the town of Erie, Colorado, of more than a million dollars, taking social engineering to another level. An unknown party completed and submitted an electronic form on Erie’s administration website with a simple…

Facebook declares war on ‘deepfakes’

Beleaguered social media platform Facebook is stepping up its game against media manipulation. Recognizing that deepfake content poses a real threat to society, Zuck’s social network swears to ban all such content from its platform, starting now. A blog post…

U.S. Federal Website Defaced with Anti-Trump Message

The little-known website for the Federal Depository Library Program greeted visitors with an unusual image over the weekend, that of a bloody Donald Trump being punched in the face. It was posted by hackers along with a pro-Iran warning message…

Ryuk Ransomware Hits U.S. Coast Guard Facility

Ransomware has struck a facility belonging to the U.S. Coast Guard (USCG), affecting industrial control systems, security cameras, and much more, according to the USCG, which didn’t reveal the name or location of the affected base. The ransomware, identified as…