Category: SecurityWeek RSS Feed

Microsoft Working on Patches for Wormable SMB Vulnerability

Microsoft is working on patches for a critical remote code execution vulnerability in Server Message Block 3.0 (SMBv3) that exposes systems to “wormable” attacks. read more   Advertise on IT Security News. Read the complete article: Microsoft Working on Patches…

Human Intelligence is Pivotal in a Data-Driven World

It’s Important to Enrich External Threat Intelligence With Context to Understand the Who, What, Where, When, Why and How of an Attack read more   Advertise on IT Security News. Read the complete article: Human Intelligence is Pivotal in a…

European Electrical Energy Organization Discloses Breach

The European Network of Transmission System Operators for Electricity (ENTSO-E) revealed this week that malicious actors breached its corporate network. read more   Advertise on IT Security News. Read the complete article: European Electrical Energy Organization Discloses Breach

Microsoft Patches 115 Vulnerabilities in Windows, Other Products

Microsoft’s Patch Tuesday updates for March 2020 address 115 vulnerabilities, including 26 critical issues affecting Windows, Word, Dynamics Business Central, and the company’s web browsers. read more   Advertise on IT Security News. Read the complete article: Microsoft Patches 115…

Attacks Targeting Recent Microsoft Exchange Flaw Ramping Up

Multiple threat actors are already targeting Microsoft Exchange servers in an attempt to exploit a vulnerability fixed by Microsoft with its February 2020 Patch Tuesday updates. read more   Advertise on IT Security News. Read the complete article: Attacks Targeting…

Hackers Hack Hacking Tools to Hack Hackers

Researchers Uncover Campaign Where Attackers Are Trojanizing Multiple Hacking Tools Used by Other Attackers read more   Advertise on IT Security News. Read the complete article: Hackers Hack Hacking Tools to Hack Hackers

AT&T, Palo Alto Networks and Broadcom Develop Firewall Framework

New Framework Enables Deployment of Firewalls as Software-Based Platforms AT&T, Palo Alto Networks and Broadcom have been developing a framework that enables organizations to deploy firewalls as software-based platforms instead of hardware appliances. read more   Advertise on IT Security…

Google Allows Enrolling Security Keys on More Devices

Google has announced that Android and macOS users can now use more web browsers to initially register security keys to their accounts. read more   Advertise on IT Security News. Read the complete article: Google Allows Enrolling Security Keys on…

Researchers Disclose Two New Attacks Against AMD CPUs

Researchers have identified two new methods for attacking AMD processors, but they are not as dangerous as some of the previously disclosed CPU attacks. read more   Advertise on IT Security News. Read the complete article: Researchers Disclose Two New…

Aussie Watchdog Sues Facebook Over Cambridge Analytica Breach

Australia’s privacy watchdog announced legal action against Facebook Monday for alleged “systematic failures” exposing more than 300,000 Australians to a data breach by Cambridge Analytica. read more   Advertise on IT Security News. Read the complete article: Aussie Watchdog Sues…

Virgin Media Accused of Downplaying Security Incident

Virgin Media has been accused of downplaying the recently disclosed cybersecurity incident that involved the personal information of roughly 900,000 people. read more   Advertise on IT Security News. Read the complete article: Virgin Media Accused of Downplaying Security Incident

US, UK and Estonia Accuse Russia of Cyber Attack on Georgia

UNITED NATIONS (AP) — The United States, United Kingdom and Estonia accused Russia’s military intelligence Thursday of conducting cyber attacks against the Georgian government and media websites in an attempt “to sow discord and disrupt the lives of ordinary Georgians.”…

Facebook Sues Namecheap Over Fraudulent Domains

Facebook announced on Thursday that it has filed a lawsuit against domain registrar Namecheap and its Whoisguard privacy protection service over its refusal to provide information on a series of domains that impersonated the social media company and its services.…

Virgin Media Exposed Personal Information of 900,000 People

UK-based phone, TV and broadband services provider Virgin Media on Thursday admitted that it exposed the personal information of roughly 900,000 people. read more   Advertise on IT Security News. Read the complete article: Virgin Media Exposed Personal Information of…

US Lawmakers Propose Internet Controls to Fight Child Porn

US lawmakers proposed legislation Thursday that could see internet companies held legally responsible for content on their platforms if they don’t do enough to police child pornography. read more   Advertise on IT Security News. Read the complete article: US…

Cruise Operator Carnival Discloses 2019 Data Breach

Leisure travel company Carnival Corporation has started informing customers of a data breach that occurred last year and which resulted in their personal information being accessed by a third-party. read more   Advertise on IT Security News. Read the complete…

T-Mobile Notifying Customers of Data Breach

Wireless carrier T-Mobile is sending notifications to its customers to inform them of a data breach that resulted in some of their personal information being compromised read more   Advertise on IT Security News. Read the complete article: T-Mobile Notifying…

Over 600 Microsoft Subdomains Can Be Hijacked: Researchers

There are more than 600 legitimate Microsoft subdomains that can be hijacked and abused for phishing, malware delivery and scams, researchers warned this week. read more   Advertise on IT Security News. Read the complete article: Over 600 Microsoft Subdomains…

Cisco Patches Remote Code Execution Flaws in Webex Player

Cisco has released patches to address more than a dozen vulnerabilities across various products, including two code execution bugs in Webex Player that could be exploited remotely.  read more   Advertise on IT Security News. Read the complete article: Cisco…

Hamas-Linked Hackers Add Insurance and Retail to Target List

MoleRATs, a politically-motivated threat actor apparently linked to the Palestinian terrorist organization Hamas, has expanded its target list to include insurance and retail industries, Palo Alto Networks’ security researchers report. read more   Advertise on IT Security News. Read the…

D.C. Council Passes Data Security Legislation

The Council of the District of Columbia on Tuesday unanimously passed a bill whose goal is to expand data breach notification requirements and improve the way organizations protect personal information. read more   Advertise on IT Security News. Read the…

A Zero-Day Homograph Domain Name Attack

What started as almost casual research in November 2019 and disclosed to various vendors as a vulnerability in November and December 2019 and January 2020 was abruptly reclassified and treated as a zero-day vulnerability on February 13, 2020. read more…

Bug Forces Let’s Encrypt to Revoke 3 Million Certificates

Free and open certificate authority (CA) Let’s Encrypt is revoking over 3 million currently-valid certificates after discovering a bug in its Certification Authority Authorization (CAA) code. read more   Advertise on IT Security News. Read the complete article: Bug Forces…

Mobile Payment Fraud on the Rise

Mobile payment fraud is growing, and is growing faster in the mobile ecosystem than anywhere else. While Windows remains the most popular operating system used by fraudsters at 38%, the combined figures for iOS and Android are now 51% of…

Google Patches Critical Remotely Exploitable Android Bug

Google’s March 2020 security updates for Android include fixes for over 70 vulnerabilities, including a critical flaw in media framework.  read more   Advertise on IT Security News. Read the complete article: Google Patches Critical Remotely Exploitable Android Bug

Google Launches Free Fuzzer Benchmarking Service

Google this week announced the launch of FuzzBench, a free and open source service for evaluating fuzzers. The fully automated service was designed to allow for an easy but rigorous evaluation of fuzzing research, in an attempt to boost the…

Legal Services Firm Epiq Hit by Ransomware

Legal services company Epiq has taken its systems offline globally after being hit by a piece of ransomware. Epiq said on Monday that it detected the malware on its systems on February 29. The company said it had found no…

The OT Security Opportunity for CISOs

In my previous column, I talked about the rapidly changing geopolitical landscape and the escalation of cyberattacks on critical infrastructure. Some of you may be wondering: “Why should I care? Russia and other nation-states aren’t focused on me and my…

Super Tuesday Marks First Major Security Test of 2020

Tuesday’s presidential primaries across 14 states mark the first major security test since the 2018 midterm elections, with state and local election officials saying they are prepared to deal with everything from equipment problems to false information about the coronavirus.…

Telecom Sector Increasingly Targeted by Chinese Hackers: CrowdStrike

Threat actors linked to China increasingly targeted the telecommunications sector in 2019, according to endpoint security firm CrowdStrike. CrowdStrike on Tuesday published its 2020 Global Threat Report, which provides data on both state-sponsored and financially-motivated operations observed by the company…

U.S. Government Warns of Continuous Election Meddling Efforts

Foreign actors continue to attempt to interfere with the election process, multiple United States departments and agencies warned in a joint statement released ahead of Tuesday’s presidential primaries. read more   Advertise on IT Security News. Read the complete article:…

Advancing DevSecOps Into the Future

If DevOps represents the union of people, process, and technology to continually provide value to customers, then DevSecOps represents the fusion of value and security provided to those same customers. read more   Advertise on IT Security News. Read the…

Businesses at Risk for Cyberattack But Take Few Precautions

Although businesses are increasingly at risk for cyberattacks on their mobile devices, many aren’t taking steps to protect smartphones and tablets. read more   Advertise on IT Security News. Read the complete article: Businesses at Risk for Cyberattack But Take…

Walgreens Discloses Data Breach Related to Mobile App

Pharmacy store chain Walgreens has started informing some users of its mobile application that their personal and health-related information may have been seen by other customers. read more   Advertise on IT Security News. Read the complete article: Walgreens Discloses…

NVIDIA Patches DoS Flaws in GPU Driver and vGPU Software

Software security updates NVIDIA released on Friday address multiple denial-of-service (DoS) vulnerabilities in GPU display drivers and Virtual GPU Manager software. read more   Advertise on IT Security News. Read the complete article: NVIDIA Patches DoS Flaws in GPU Driver…

Railroad Construction Firm RailWorks Falls Victim to Ransomware

Rail contractor RailWorks Corporation is notifying employees and third-parties that it recently fell victim to a ransomware attack in which sensitive information might have been compromised. read more   Advertise on IT Security News. Read the complete article: Railroad Construction…

Regulators Move to Fine Telecoms for Selling Location Data

US regulators moved to impose fines Friday against the nation’s four major wireless carriers for selling location data of customers without their consent. The Federal Communications Commission proposed fining T-Mobile more than $91 million; AT&T some $57 million; Verizon $48…

Microsoft Boosts PUA Protections in Edge

Microsoft this week announced new features in its Edge browser to prevent the download of potentially unwanted applications (PUA). read more   Advertise on IT Security News. Read the complete article: Microsoft Boosts PUA Protections in Edge

Assange’s UK Extradition Hearing Paused Until May

A British judge on Thursday paused Julian Assange‘s extradition hearing following four days of intense legal wrangling over Washington’s request for the WikiLeaks founder to stand trial there on espionage charges. read more   Advertise on IT Security News. Read…

Let’s Encrypt Issues Over 1 Billion Certificates

Free and open certificate authority Let’s Encrypt on Thursday issued its billionth certificate, four and a half years after issuing the first certificate. read more   Advertise on IT Security News. Read the complete article: Let’s Encrypt Issues Over 1…

Facebook Sues Analytics Firm for Data Misuse

Facebook on Thursday filed a federal lawsuit against oneAudience data intelligence firm over a tactic it used to gather information about users of social media platforms. read more   Advertise on IT Security News. Read the complete article: Facebook Sues…

Cybercriminals Target Lincoln Health Care Company

A Lincoln health care company has been targeted by cybercriminals, but company officials said there’s no evidence of any patient data being compromised. read more   Advertise on IT Security News. Read the complete article: Cybercriminals Target Lincoln Health Care…

The Urgency for Having a True Security Platform

Ever since the birth of the Next-Generation Firewall, organizations have come to expect security devices that combine a variety of critical features and functions into a single package. To meet that demand, the number of security vendors referring to their…

McAfee Buys Browser Isolation Firm Light Point Security

Santa Clara, Calif-based McAfee has entered into a definitive agreement to acquire Baltimore, MD-based Light Point Security. Financial details have not been disclosed, but on completion of the acquisition, the Light Point staff will join McAfee, while the Light Point…

Google Boosts Detection of Malicious Documents in Gmail

New scanning capabilities that Google rolled out to Gmail have resulted in an increased overall detection rate of malicious documents. read more   Advertise on IT Security News. Read the complete article: Google Boosts Detection of Malicious Documents in Gmail

Iranian Cyberspies Focus on Long-Running Operations

The Iranian cyber-espionage group referred to as MuddyWater continues to focus on long-running operations even after a U.S. airstrike killed General Qassem Soleimani on January 2. read more   Advertise on IT Security News. Read the complete article: Iranian Cyberspies…

Massachusetts Electric Utility Hit by Ransomware

The Reading Municipal Light Department (RMLD), an electric utility in Massachusetts, informed customers on Monday that its systems were targeted last week in a ransomware attack. RMLD says it serves over 68,000 residents in the towns of Reading, North Reading,…

OpenSMTPD Vulnerability Leads to Command Injection

An update released this week for the OpenSMTPD mail server addresses an out-of-bounds read vulnerability that could lead to arbitrary command execution. OpenSMTPD is the open source implementation of the Simple Mail Transfer Protocol (SMTP) in OpenBSD, and its portable…

UK Financial Regulator Admits to Data Breach

Britain’s Financial Conduct Authority on Tuesday admitted to a data breach, in an embarrassing revelation for the regulator and its boss, who shortly takes over at the Bank of England. read more   Advertise on IT Security News. Read the…

Firefox Gets DNS-over-HTTPS as Default in U.S.

Mozilla has started rolling out encrypted DNS-over-HTTPS (DoH) by default for its Firefox users in the United States.  read more   Advertise on IT Security News. Read the complete article: Firefox Gets DNS-over-HTTPS as Default in U.S.

Samsung Says it Leaked Data on Handful of UK Customers

Samsung said Tuesday that a “technical error” caused its website to display other customers’ personal information. The technology company said the error affected only its U.K. website at http://samsung.com/UK and affected fewer than 150 customers. read more   Advertise on…