Category: SecurityWeek RSS Feed

GE Says Some Employees Hit by Data Breach at Canon

General Electric (GE) revealed last week that the personal information of some employees may have been compromised as a result of a data breach suffered by Canon Business Process Services. read more   Advertise on IT Security News. Read the…

Authorities Warn of Escalating COVID-19-Themed Cyberattacks

Authorities in the United States and Europe have issued warnings of increased malicious cyber-activity related to the ongoing COVID-19 (coronavirus) pandemic. In an alert on Friday, the Federal Bureau of Investigation said that scammers are leveraging the current crisis to…

Abuse.ch Launches Free Malware Repository

A newly launched service from abuse.ch aims to make it easy for the community to share known malware samples and access additional intelligence on them.  read more   Advertise on IT Security News. Read the complete article: Abuse.ch Launches Free…

Coronavirus Confinement Challenges Intelligence Services

The home confinement of hundreds of millions of people worldwide to halt coronavirus contagion has presented intelligence services with a challenge: monitoring an explosion in internet traffic, above board and not, even as their own capacity is reduced. read more…

Abuse.ch Launches Free Malware Repository

A newly launched service from abuse.ch aims to make it easy for the community to share known malware samples and access additional intelligence on them.  read more   Advertise on IT Security News. Read the complete article: Abuse.ch Launches Free…

Coronavirus Confinement Challenges Intelligence Services

The home confinement of hundreds of millions of people worldwide to halt coronavirus contagion has presented intelligence services with a challenge: monitoring an explosion in internet traffic, above board and not, even as their own capacity is reduced. read more…

Abuse.ch Launches Free Malware Repository

A newly launched service from abuse.ch aims to make it easy for the community to share known malware samples and access additional intelligence on them.  read more   Advertise on IT Security News. Read the complete article: Abuse.ch Launches Free…

Coronavirus Confinement Challenges Intelligence Services

The home confinement of hundreds of millions of people worldwide to halt coronavirus contagion has presented intelligence services with a challenge: monitoring an explosion in internet traffic, above board and not, even as their own capacity is reduced. read more…

University of Utah Health Discloses Data Breach

University of Utah Health revealed last week that it discovered unauthorized access to some employee email accounts, along with a malware infection on one of its workstations. read more   Advertise on IT Security News. Read the complete article: University…

Flaw in Password Managers Allowed Apps to Steal Credentials

One of the vulnerabilities that researchers from the University of York discovered in widely-used password managers could have resulted in malicious apps stealing users’ credentials. read more   Advertise on IT Security News. Read the complete article: Flaw in Password…

New Mexico Agencies on Edge Amid Rising Ransomware Attacks

New Mexico school districts, universities, and government agencies have collectively spent millions of dollars to regain control of their computer systems after employees unknowingly opened emails containing an encrypted code that effectively shut them out of their systems. read more…

Mozilla to Remove Support for FTP in Firefox

Mozilla is getting ready to remove support for the File Transfer Protocol (FTP) from the Firefox web browser due to security concerns. read more   Advertise on IT Security News. Read the complete article: Mozilla to Remove Support for FTP…

Hackers Target UK Fintech Company Finastra

UK-based financial technology company Finastra is investigating a cybersecurity incident that may involve a piece of ransomware infecting some of its systems. Finastra has over 10,000 employees and it delivers financial software to more than 9,000 customers across 130 countries,…

UK Printing Company Exposed Military Documents

Cybersecurity researchers say UK-based document printing and binding company Doxzoo exposed hundreds of gigabytes of information, including documents related to the US and British military, by leaving an AWS S3 bucket unprotected. read more   Advertise on IT Security News.…

Android Surveillance Campaign Leverages COVID-19 Crisis

Amid numerous malicious attacks leveraging the current COVID-19 coronavirus crisis, security researchers have discovered an Android surveillance campaign targeting users in Libya. read more   Advertise on IT Security News. Read the complete article: Android Surveillance Campaign Leverages COVID-19 Crisis

Drupal Updates CKEditor to Patch XSS Vulnerabilities

The developers of the Drupal content management system (CMS) announced on Wednesday that updates for versions 8.8.x and 8.7.x address a couple of vulnerabilities affecting the CKEditor library. read more   Advertise on IT Security News. Read the complete article:…

RDP-Capable TrickBot Targets Telecoms Sectors in U.S. and Hong Kong

A recently discovered TrickBot variant targeting telecommunications organizations in the United States and Hong Kong includes a module for remote desktop protocol (RDP) brute-forcing, Bitdefender reports. read more   Advertise on IT Security News. Read the complete article: RDP-Capable TrickBot…

Researchers Hack Windows, Ubuntu, macOS at Pwn2Own 2020

On the first day of the Pwn2Own 2020 hacking competition, participants earned a total of $180,000 for demonstrating exploits targeting Windows 10, Ubuntu Desktop and macOS. read more   Advertise on IT Security News. Read the complete article: Researchers Hack…

Researchers Track Coronavirus-Themed Cyberattacks

Cybercriminals have always used crises and natural disasters to fuel their social engineering activities. The COVID-19 (Coronavirus) pandemic is a massive human crisis, and criminals have been quick to take advantage. People are afraid, and fear is a primary social…

Sixgill Introduces Dark Web Data Feed Product

Threat intelligence provider Sixgill has announced a new product that allows organizations to integrate a real-time, actionable dark web data feed into any security platform. read more   Advertise on IT Security News. Read the complete article: Sixgill Introduces Dark…

Ransomware Is Mostly Deployed After Hours: Report

Most ransomware is deployed after hours, and usually several days after the initial compromise, newly published research from FireEye reveals. read more   Advertise on IT Security News. Read the complete article: Ransomware Is Mostly Deployed After Hours: Report

Tech Companies Partner to Securely Connect IoT to Cloud

Thales, Telstra, Microsoft, and Arduino this week announced a partnership aimed at enabling the secure connection of IoT devices to the cloud. Delivering end-to-end connectivity between devices and cloud platforms, the solution enables “instant and standardized mutual authentication” over cellular…

Two Dozen Arrested for Laundering Funds From BEC, Other Scams

Twenty-four individuals were arrested for laundering funds illegally obtained via business email compromise (BEC), romance, and retirement account scams targeting victims across the United States. The large-scale fraud operation facilitated by the arrested individuals has caused losses of more than…

HHS Says DDoS Attack Failed to Cause Disruption

The U.S. Department of Health and Human Services (HHS) was targeted with a distributed denial-of-service (DDoS) attack on Sunday, but the agency said it did not experience any significant disruption as a result of the incident. read more   Advertise…

There Are Plenty of Phish in the Sea

There Are Plenty of Phish in the Sea for Commercial Phishers and Weekend Scammers Alike The phish market is open. And you don’t have to be an experienced angler to land a catch of the day. read more   Advertise…

Slack Vulnerability Allowed Hackers to Hijack Accounts

A researcher earned $6,500 from Slack last year after finding a critical vulnerability that could have been exploited to hijack Slack accounts. Researcher Evan Custodio discovered in November 2019 that the enterprise collaboration platform’s slackb.com domain was vulnerable to HTTP…

COVID-19 Themed Phishing Campaigns Continue

Another COVID-19 (Coronavirus) phishing campaign has been discovered — this one apparently operated by the Pakistan-based APT36, which is thought to be nation-backed. APT36 has been active since 2016, and possibly earlier, performing cyber espionage activity against Indian defense and…

Many Backdoors Found in Zyxel CloudCNM SecuManager Software

Researchers have discovered 16 types of vulnerabilities, including many backdoors, in Zyxel’s CloudCNM SecuManager network management software. The vendor has confirmed the flaws and says it’s working on patches. read more   Advertise on IT Security News. Read the complete…

How National Security Surveillance Nabs More Than Spies

The case against Nassif Sami Daher and Kamel Mohammad Rammal, two Michigan men accused of food stamp fraud, hardly seemed exceptional. But the tool that agents used to investigate them was extraordinary: a secretive surveillance process intended to identify potential…

European Authorities Dismantle Two SIM Hijacking Gangs

European authorities managed to crack down on two cybercrime gangs responsible for stealing millions by employing SIM hijacking. read more   Advertise on IT Security News. Read the complete article: European Authorities Dismantle Two SIM Hijacking Gangs

US Surveillance Powers Set to Temporarily Expire

Three surveillance powers available to the U.S. government are set to temporarily expire Sunday after a trio of senators opposed a bipartisan House bill that would renew the authorities and impose new restrictions. read more   Advertise on IT Security…

China-linked APT Hackers Launch Coronavirus-Themed Attacks

COVID-19 (Coronavirus) themed malware attacks are now common. The subject matter automatically contains at least two of the primary social engineering triggers, fear and urgency, making it an obvious lure for use by criminals. Even a long-standing China-based APT has…

House Strikes Deal to Extend Surveillance Powers

House lawmakers prepared to extend surveillance authorities that expire this month, releasing legislation that represents a rare bipartisan agreement after members of both parties said they wanted to ensure the tools preserved civil liberties. read more   Advertise on IT…

Facebook Takedowns Reveal Sophistication of Russian Trolls

Facebook and Twitter revealed evidence Thursday suggesting that Russian efforts to interfere in the U.S. presidential election are getting more sophisticated and harder to detect. The companies said they have removed dozens of fake accounts and pages from their services.…

Out-of-Band Windows Updates Patch Wormable SMB Vulnerability

Microsoft has released out-of-band updates for Windows to patch a critical remote code execution vulnerability in Server Message Block 3.0 (SMBv3) that has been described as “wormable.” read more   Advertise on IT Security News. Read the complete article: Out-of-Band…

Intel Patches 27 Vulnerabilities Across Product Portfolio

Intel this week released patches for more than two dozen vulnerabilities impacting graphics drivers, FPGA, processors NUC, BlueZ, and other products.  read more   Advertise on IT Security News. Read the complete article: Intel Patches 27 Vulnerabilities Across Product Portfolio

Avast AntiTrack Flaw Allows MitM Attacks on HTTPS Traffic

A vulnerability in Avast’s anti-tracking solution could allow malicious actors to perform man-in-the-middle (MitM) attacks on HTTPS traffic, a security researcher has discovered. The security flaw, which impacts both Avast and AVG AntiTrack, as they share underlying code, resides in…