Tag: SecurityWeek RSS Feed

UK Printing Company Exposed Military Documents

Cybersecurity researchers say UK-based document printing and binding company Doxzoo exposed hundreds of gigabytes of information, including documents related to the US and British military, by leaving an AWS S3 bucket unprotected. read more   Advertise on IT Security News.…

Android Surveillance Campaign Leverages COVID-19 Crisis

Amid numerous malicious attacks leveraging the current COVID-19 coronavirus crisis, security researchers have discovered an Android surveillance campaign targeting users in Libya. read more   Advertise on IT Security News. Read the complete article: Android Surveillance Campaign Leverages COVID-19 Crisis

Drupal Updates CKEditor to Patch XSS Vulnerabilities

The developers of the Drupal content management system (CMS) announced on Wednesday that updates for versions 8.8.x and 8.7.x address a couple of vulnerabilities affecting the CKEditor library. read more   Advertise on IT Security News. Read the complete article:…

RDP-Capable TrickBot Targets Telecoms Sectors in U.S. and Hong Kong

A recently discovered TrickBot variant targeting telecommunications organizations in the United States and Hong Kong includes a module for remote desktop protocol (RDP) brute-forcing, Bitdefender reports. read more   Advertise on IT Security News. Read the complete article: RDP-Capable TrickBot…

Researchers Hack Windows, Ubuntu, macOS at Pwn2Own 2020

On the first day of the Pwn2Own 2020 hacking competition, participants earned a total of $180,000 for demonstrating exploits targeting Windows 10, Ubuntu Desktop and macOS. read more   Advertise on IT Security News. Read the complete article: Researchers Hack…

Researchers Track Coronavirus-Themed Cyberattacks

Cybercriminals have always used crises and natural disasters to fuel their social engineering activities. The COVID-19 (Coronavirus) pandemic is a massive human crisis, and criminals have been quick to take advantage. People are afraid, and fear is a primary social…

Sixgill Introduces Dark Web Data Feed Product

Threat intelligence provider Sixgill has announced a new product that allows organizations to integrate a real-time, actionable dark web data feed into any security platform. read more   Advertise on IT Security News. Read the complete article: Sixgill Introduces Dark…

Ransomware Is Mostly Deployed After Hours: Report

Most ransomware is deployed after hours, and usually several days after the initial compromise, newly published research from FireEye reveals. read more   Advertise on IT Security News. Read the complete article: Ransomware Is Mostly Deployed After Hours: Report

Tech Companies Partner to Securely Connect IoT to Cloud

Thales, Telstra, Microsoft, and Arduino this week announced a partnership aimed at enabling the secure connection of IoT devices to the cloud. Delivering end-to-end connectivity between devices and cloud platforms, the solution enables “instant and standardized mutual authentication” over cellular…

Two Dozen Arrested for Laundering Funds From BEC, Other Scams

Twenty-four individuals were arrested for laundering funds illegally obtained via business email compromise (BEC), romance, and retirement account scams targeting victims across the United States. The large-scale fraud operation facilitated by the arrested individuals has caused losses of more than…

HHS Says DDoS Attack Failed to Cause Disruption

The U.S. Department of Health and Human Services (HHS) was targeted with a distributed denial-of-service (DDoS) attack on Sunday, but the agency said it did not experience any significant disruption as a result of the incident. read more   Advertise…

There Are Plenty of Phish in the Sea

There Are Plenty of Phish in the Sea for Commercial Phishers and Weekend Scammers Alike The phish market is open. And you don’t have to be an experienced angler to land a catch of the day. read more   Advertise…

Slack Vulnerability Allowed Hackers to Hijack Accounts

A researcher earned $6,500 from Slack last year after finding a critical vulnerability that could have been exploited to hijack Slack accounts. Researcher Evan Custodio discovered in November 2019 that the enterprise collaboration platform’s slackb.com domain was vulnerable to HTTP…

COVID-19 Themed Phishing Campaigns Continue

Another COVID-19 (Coronavirus) phishing campaign has been discovered — this one apparently operated by the Pakistan-based APT36, which is thought to be nation-backed. APT36 has been active since 2016, and possibly earlier, performing cyber espionage activity against Indian defense and…

Many Backdoors Found in Zyxel CloudCNM SecuManager Software

Researchers have discovered 16 types of vulnerabilities, including many backdoors, in Zyxel’s CloudCNM SecuManager network management software. The vendor has confirmed the flaws and says it’s working on patches. read more   Advertise on IT Security News. Read the complete…

How National Security Surveillance Nabs More Than Spies

The case against Nassif Sami Daher and Kamel Mohammad Rammal, two Michigan men accused of food stamp fraud, hardly seemed exceptional. But the tool that agents used to investigate them was extraordinary: a secretive surveillance process intended to identify potential…

European Authorities Dismantle Two SIM Hijacking Gangs

European authorities managed to crack down on two cybercrime gangs responsible for stealing millions by employing SIM hijacking. read more   Advertise on IT Security News. Read the complete article: European Authorities Dismantle Two SIM Hijacking Gangs

US Surveillance Powers Set to Temporarily Expire

Three surveillance powers available to the U.S. government are set to temporarily expire Sunday after a trio of senators opposed a bipartisan House bill that would renew the authorities and impose new restrictions. read more   Advertise on IT Security…

China-linked APT Hackers Launch Coronavirus-Themed Attacks

COVID-19 (Coronavirus) themed malware attacks are now common. The subject matter automatically contains at least two of the primary social engineering triggers, fear and urgency, making it an obvious lure for use by criminals. Even a long-standing China-based APT has…

House Strikes Deal to Extend Surveillance Powers

House lawmakers prepared to extend surveillance authorities that expire this month, releasing legislation that represents a rare bipartisan agreement after members of both parties said they wanted to ensure the tools preserved civil liberties. read more   Advertise on IT…

Facebook Takedowns Reveal Sophistication of Russian Trolls

Facebook and Twitter revealed evidence Thursday suggesting that Russian efforts to interfere in the U.S. presidential election are getting more sophisticated and harder to detect. The companies said they have removed dozens of fake accounts and pages from their services.…

Out-of-Band Windows Updates Patch Wormable SMB Vulnerability

Microsoft has released out-of-band updates for Windows to patch a critical remote code execution vulnerability in Server Message Block 3.0 (SMBv3) that has been described as “wormable.” read more   Advertise on IT Security News. Read the complete article: Out-of-Band…

Intel Patches 27 Vulnerabilities Across Product Portfolio

Intel this week released patches for more than two dozen vulnerabilities impacting graphics drivers, FPGA, processors NUC, BlueZ, and other products.  read more   Advertise on IT Security News. Read the complete article: Intel Patches 27 Vulnerabilities Across Product Portfolio

Avast AntiTrack Flaw Allows MitM Attacks on HTTPS Traffic

A vulnerability in Avast’s anti-tracking solution could allow malicious actors to perform man-in-the-middle (MitM) attacks on HTTPS traffic, a security researcher has discovered. The security flaw, which impacts both Avast and AVG AntiTrack, as they share underlying code, resides in…

Microsoft Working on Patches for Wormable SMB Vulnerability

Microsoft is working on patches for a critical remote code execution vulnerability in Server Message Block 3.0 (SMBv3) that exposes systems to “wormable” attacks. read more   Advertise on IT Security News. Read the complete article: Microsoft Working on Patches…

Human Intelligence is Pivotal in a Data-Driven World

It’s Important to Enrich External Threat Intelligence With Context to Understand the Who, What, Where, When, Why and How of an Attack read more   Advertise on IT Security News. Read the complete article: Human Intelligence is Pivotal in a…

European Electrical Energy Organization Discloses Breach

The European Network of Transmission System Operators for Electricity (ENTSO-E) revealed this week that malicious actors breached its corporate network. read more   Advertise on IT Security News. Read the complete article: European Electrical Energy Organization Discloses Breach

Microsoft Patches 115 Vulnerabilities in Windows, Other Products

Microsoft’s Patch Tuesday updates for March 2020 address 115 vulnerabilities, including 26 critical issues affecting Windows, Word, Dynamics Business Central, and the company’s web browsers. read more   Advertise on IT Security News. Read the complete article: Microsoft Patches 115…

Attacks Targeting Recent Microsoft Exchange Flaw Ramping Up

Multiple threat actors are already targeting Microsoft Exchange servers in an attempt to exploit a vulnerability fixed by Microsoft with its February 2020 Patch Tuesday updates. read more   Advertise on IT Security News. Read the complete article: Attacks Targeting…

Hackers Hack Hacking Tools to Hack Hackers

Researchers Uncover Campaign Where Attackers Are Trojanizing Multiple Hacking Tools Used by Other Attackers read more   Advertise on IT Security News. Read the complete article: Hackers Hack Hacking Tools to Hack Hackers

AT&T, Palo Alto Networks and Broadcom Develop Firewall Framework

New Framework Enables Deployment of Firewalls as Software-Based Platforms AT&T, Palo Alto Networks and Broadcom have been developing a framework that enables organizations to deploy firewalls as software-based platforms instead of hardware appliances. read more   Advertise on IT Security…

Google Allows Enrolling Security Keys on More Devices

Google has announced that Android and macOS users can now use more web browsers to initially register security keys to their accounts. read more   Advertise on IT Security News. Read the complete article: Google Allows Enrolling Security Keys on…

Researchers Disclose Two New Attacks Against AMD CPUs

Researchers have identified two new methods for attacking AMD processors, but they are not as dangerous as some of the previously disclosed CPU attacks. read more   Advertise on IT Security News. Read the complete article: Researchers Disclose Two New…

Aussie Watchdog Sues Facebook Over Cambridge Analytica Breach

Australia’s privacy watchdog announced legal action against Facebook Monday for alleged “systematic failures” exposing more than 300,000 Australians to a data breach by Cambridge Analytica. read more   Advertise on IT Security News. Read the complete article: Aussie Watchdog Sues…

Virgin Media Accused of Downplaying Security Incident

Virgin Media has been accused of downplaying the recently disclosed cybersecurity incident that involved the personal information of roughly 900,000 people. read more   Advertise on IT Security News. Read the complete article: Virgin Media Accused of Downplaying Security Incident

US, UK and Estonia Accuse Russia of Cyber Attack on Georgia

UNITED NATIONS (AP) — The United States, United Kingdom and Estonia accused Russia’s military intelligence Thursday of conducting cyber attacks against the Georgian government and media websites in an attempt “to sow discord and disrupt the lives of ordinary Georgians.”…

Facebook Sues Namecheap Over Fraudulent Domains

Facebook announced on Thursday that it has filed a lawsuit against domain registrar Namecheap and its Whoisguard privacy protection service over its refusal to provide information on a series of domains that impersonated the social media company and its services.…

Virgin Media Exposed Personal Information of 900,000 People

UK-based phone, TV and broadband services provider Virgin Media on Thursday admitted that it exposed the personal information of roughly 900,000 people. read more   Advertise on IT Security News. Read the complete article: Virgin Media Exposed Personal Information of…

US Lawmakers Propose Internet Controls to Fight Child Porn

US lawmakers proposed legislation Thursday that could see internet companies held legally responsible for content on their platforms if they don’t do enough to police child pornography. read more   Advertise on IT Security News. Read the complete article: US…