Tag: Threatpost

Google Chrome To Bar HTTP File Downloads

File downloads like images or executables may not be delivered over HTTPS – even if they are available from an HTTPS website.   Advertise on IT Security News. Read the complete article: Google Chrome To Bar HTTP File Downloads

The RSAC 2020 Trend Report

What’s trending in cybersecurity? This year’s session submissions tell us.   Advertise on IT Security News. Read the complete article: The RSAC 2020 Trend Report

CamuBot Banking Trojan Returns In Targeted Attacks

The malware is back in targeted attacks against Brazilian banking customers, this time using a new technique that involves mobile app authorization.   Advertise on IT Security News. Read the complete article: CamuBot Banking Trojan Returns In Targeted Attacks

Critical Cisco ‘CDPwn’ Protocol Flaws Explained: Podcast

The researcher behind the five critical Cisco flaws, collectively called CDPwn, talks about why Layer 2 protocols are under-researched when it comes to security vulnerabilities.   Advertise on IT Security News. Read the complete article: Critical Cisco ‘CDPwn’ Protocol Flaws…

Ransomware Attack Hinders Toll Group Operations

Customers took to Twitter to air their grievances after some of the transportation giant’s operations were downed.   Advertise on IT Security News. Read the complete article: Ransomware Attack Hinders Toll Group Operations

Two Critical Android Bugs Get Patched in February Update

As part of its February bug fixes, Google is patching a critical severity remote code execution vulnerability and an information disclosure bug.   Advertise on IT Security News. Read the complete article: Two Critical Android Bugs Get Patched in February…

Tesla Autopilot Duped By ‘Phantom’ Images

Researchers were able to fool popular autopilot systems into perceiving projected images as real – causing the cars to brake or veer into oncoming traffic lanes.   Advertise on IT Security News. Read the complete article: Tesla Autopilot Duped By…

Iranian Hackers Target U.S. Gov. Vendor With Malware

APT34 has been spotted in a malware campaign targeting customers and employees of a company that works closely with U.S. federal agencies, and state and local governments.   Advertise on IT Security News. Read the complete article: Iranian Hackers Target…

Bezos, WhatsApp Cyberattacks Show Growing Mobile Sophistication

The recently disclosed Jeff Bezos phone hack and other incidents show that mobile devices are being increasingly targeted by sophisticated nation-state attackers.   Advertise on IT Security News. Read the complete article: Bezos, WhatsApp Cyberattacks Show Growing Mobile Sophistication

New ‘CacheOut’ Attack Targets Intel CPUs

Researchers have release a new proof-of-concept attack targeting a new Intel Speculative-type bug called CacheOut present in most Intel CPUs.   Advertise on IT Security News. Read the complete article: New ‘CacheOut’ Attack Targets Intel CPUs

MTTD and MTTR: Two Metrics to Improve Your Cybersecurity

While there are dozens of metrics available to determine success, there are two key cybersecurity performance indicators every organization should monitor.   Advertise on IT Security News. Read the complete article: MTTD and MTTR: Two Metrics to Improve Your Cybersecurity

Zoom Fixes Flaw Opening Meetings to Hackers

Zoom has patched a flaw that could have allowed attackers to guess a meeting ID and enter a meeting.   Advertise on IT Security News. Read the complete article: Zoom Fixes Flaw Opening Meetings to Hackers

As Necurs Botnet Falls from Grace, Emotet Rises

Researchers wonder if a recent “amateur spam” campaign by the once-prevalant malware distribution botnet is a sign of trojans looking to other infection paths.   Advertise on IT Security News. Read the complete article: As Necurs Botnet Falls from Grace,…

New Bill Proposes NSA Surveillance Reforms

The newly-introduced bill targets the Patriot Act’s Section 215, previously used by the U.S. government to collect telephone data from millions of Americans.   Advertise on IT Security News. Read the complete article: New Bill Proposes NSA Surveillance Reforms

U.S. Gov Agency Targeted With Malware-Laced Emails

The malicious email campaign included a never-before-seen malware downloader called Carrotball, and may be linked to the Konni Group APT.   Advertise on IT Security News. Read the complete article: U.S. Gov Agency Targeted With Malware-Laced Emails

Cisco Warns of Critical Network Security Tool Flaw

The critical flaw exists in Cisco’s administrative management tool, used with network security solutions like firewalls.   Advertise on IT Security News. Read the complete article: Cisco Warns of Critical Network Security Tool Flaw

New Muhstik Botnet Attacks Target Tomato Routers

Palo Alto Networks’ Unit 42 researchers observed a variant of the wormlike botnet that adds scanner technology to brute-force Web authentication.   Advertise on IT Security News. Read the complete article: New Muhstik Botnet Attacks Target Tomato Routers

PoC Exploits Do More Good Than Harm: Threatpost Poll

More than half of security experts think that the good outweighs the bad when it comes to proof-of-concept exploits, according to a recent Threatpost poll.   Advertise on IT Security News. Read the complete article: PoC Exploits Do More Good…

16Shop Phishing Gang Goes After PayPal Users

A sophisticated malware-as-a-service phishing kit includes full customer service and anti-detection technologies.   Advertise on IT Security News. Read the complete article: 16Shop Phishing Gang Goes After PayPal Users

Citrix Accelerates Patch Rollout For Critical RCE Flaw

Citrix has issued the first of several updates fixing a critical vulnerability in various versions of its Citrix Application Delivery Controller (ADC) and Citrix Gateway products.   Advertise on IT Security News. Read the complete article: Citrix Accelerates Patch Rollout…

FTCODE Ransomware Now Steals Chrome, Firefox Credentials

New versions of the ransomware now sniff out saved credentials for Internet Explorer, Mozilla Firefox, Mozilla Thunderbird, Google Chrome and Microsoft Outlook.   Advertise on IT Security News. Read the complete article: FTCODE Ransomware Now Steals Chrome, Firefox Credentials

New JhoneRAT Malware Targets Middle East

Researchers say that JhoneRAT has various anti-detection techniques – including making use of Google Drive, Google Forms and Twitter.   Advertise on IT Security News. Read the complete article: New JhoneRAT Malware Targets Middle East