Experts share their insights on protecting against cyber threats and staying ahead of evolving security risks.
Recently active
Fixing the latest bugs and exploits in Android every month. August 3, 2020 By JOE MARING and JERRY HILDENBRAND Google has detailed the latest Android Security Bulletin and released the fixes for Pixel devices.These are exploits and other security concerns that affect Android as a whole. Issues with the operating system, kernel patches, and driver updates may not affect any particular device, but these need to be fixed in the Android base by the folks maintaining the operating system code. That means Google, and they've detailed the things they have improved for this month.Updated factory images for Pixel devices that are supported are available, and over-the-air updates are rolling out to users. If you don't want to wait, you can download and flash the factory image or OTA update file manually, and here are some handy instructions to get you started. Full Article.
Zero Trust is a security approach that has gained significant attention in the cybersecurity world in recent years. But what is Zero Trust, and how effective is it in protecting against cyber threats? Cybersecurity professionals are rightfully skeptical of phrases that suddenly become buzzwords overnight. However, there are many legitimate technologies and policies that fall under the umbrella term “Zero Trust”. In this post, we will explore the concepts and technologies involved in Zero Trust and attempt to differentiate marketing hype from factual evidence. DefinitionFirst, let’s define zero trust. At its core, Zero Trust is a security model that assumes all users and devices within a network are untrusted and potentially malicious. This means that, rather than relying on the traditional perimeter-based security model which assumes that everything inside the network is trusted, a Zero Trust approach treats all access requests as coming from an untrusted source. There are a few other
The Internet of Things (IoT) has revolutionized how we interact with our surroundings, making life more convenient and efficient. IoT devices connect everyday objects to the internet, allowing us to control our homes, monitor our health, and even track our belongings. However, this interconnectivity comes at a cost: the exponential growth of IoT devices has led to increased cybersecurity risks. In this article, we will discuss trends in IoT and their implications on the cybersecurity landscape, and ponder whether the convenience provided by IoT is worth the security trade-offs. The concept of IoT can be traced back to the 1980s, but it wasn't until the early 2000s that IoT devices began to gain widespread adoption. In the early days of IoT, security was often an afterthought and the focus was on getting a working product out the door. However, as IoT devices have proliferated, the risks associated with their widespread use have become more apparent.I was at a Defcon event about a decad
May 1, 2020 By Tara Seals Two separate attacks have targeted as many as 50,000 different Teams users, with the goal of phishing Office 365 logins. A convincing cyberattack that impersonates notifications from Microsoft Teams in order to steal the Office 365 credentials of employees is making the rounds, according to researchers. Two separate attacks have targeted as many as 50,000 different Teams users, according to findings from Abnormal Security. The news comes as the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) issued a warning about Office 365 remote-work deployments. “CISA continues to see instances where entities are not implementing best security practices in regard to their O365 implementation, resulting in increased vulnerability to adversary attacks,” the agency said. Full Article.
May 3, 2020 By Geoff White The man behind the world's first major computer virus outbreak has admitted his guilt, 20 years after his software infected millions of machines worldwide. Filipino Onel de Guzman, now 44, says he unleashed the Love Bug computer worm to steal passwords so he could access the internet without paying. He claims he never intended it to spread globally. And he says he regrets the damage his code caused. "I didn't expect it would get to the US and Europe. I was surprised," he said in an interview for Crime Dot Com, a forthcoming book on cyber-crime. Full Article.
May 1, 2020 By Tara Seals No longer a simple Android banker, Cerberus is now a full-fledged RAT that can take complete control of devices and automatically spread via mobile device management servers. A newly discovered variant of the Cerberus Android trojan has been spotted, with vastly expanded and more sophisticated info-harvesting capabilities, and the ability to run TeamViewer. It was spotted by researchers being used in a targeted campaign on a multinational conglomerate. Unusually, the sample propagated through the employee pool via the infected company’s mobile device management (MDM) server. Full Article.
May 1, 2020 By Sergiu Gatlan Attackers infected more than 75% of a multinational conglomerate's managed Android devices with the Cerberus banking trojan using the company’s compromised Mobile Device Manager (MDM) server. MDM (also known as Enterprise Mobility Management - EMM) is a mechanism used by companies of all sizes to enroll enterprise-owned devices with the same management server to make it easier to perform tasks such as delivering company-wide device configurations, deploying applications, and more. The Cerberus banking trojan was first spotted in June 2019 and it uses a Malware-as-a-Service (MaaS) business model allowing clients who rent their services to drop their payloads, as well as configure and control devices compromised during their attacks. Full Article.
Dreambot backend servers have gone down and no new samples have been spotted for weeks. May 1, 2020 By Catalin Cimpanu The Dreambot malware botnet appears to have gone silent and possibly shut down, according to a report published today by the CSIS Security Group, a cyber-security firm based in Copenhagen, Denmark. The company is reporting that the Dreambot's backend servers have gone down in March; about the same time when the cybersecurity community also stopped seeing new Dreambot samples distributed in the wild. Full Article.
The Tokopedia data has been published on a well-known hacking forum. May 2, 2020 By Catalin Cimpanu A hacker has leaked on Friday the details of 15 million users registered on Tokopedia, Indonesia's largest online store. The hacker claims the data was obtained in an intrusion that took place in March 2020 and is just a small part of the site's entire user database that was obtained in the hack. The leaker said he was sharing the 15 million users sample in the hopes someone could help crack the user passwords, so they could be used to access user accounts. ZDNet has obtained a copy of the leaked file with the help of data breach monitoring service Under the Breach. Full Article.
By Eduard Kovacs on May 01, 2020 Several vulnerabilities, most of which have been described as cross-site scripting (XSS) flaws, have been patched in WordPress this week with the release of version 5.4.1. WordPress 5.4.1, described as a short-cycle security and maintenance release, fixes 17 bugs and 7 vulnerabilities affecting version 5.4 and earlier. WordPress developers pointed out that all versions newer than 3.7 have been updated as well. WordPress security firm Defiant has published a blog post describing each of the patched vulnerabilities and none of them appears too serious or easy to exploit. Full Article.
By Ionut Arghire on May 04, 2020 High-severity vulnerabilities patched in the Ninja Forms and LearnPress WordPress plugins could be exploited to take over vulnerable sites, WordPress security company Defiant reports. The developers of highly popular Ninja Forms last week addressed Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS) vulnerabilities that attackers could chain to trick an admin into importing a contact form containing malicious JavaScript code that would then get executed when certain pages are visited. Full Article.
May 2, 2020 By Mayank Parmar New research claims that China-based Xiaomi is tracking sensitive information and sending it to their servers if you use the Mi browser, which is bundled with all Redmi and Mi phones. In a report by Forbes, security research Gabi Cirlig states that Xiaomi's Mi Browser app sends your internet searches, including incognito mode sessions, to Xiaomi servers in Singapore and Russia. Even more concerning is that Cirlig states that the data being set can easily be associated with a particular user allowing the company to single out users they wish to track. Full Article.
LineageOS source code, OS builds, and signing keys were unaffected, developers said. May 3, 2020 By Catalin Cimpanu Hackers have gained access to the core infrastructure of LineageOS, a mobile operating system based on Android, used for smartphones, tablets, and set-top boxes. The intrusion took place last night, on Saturday, at around 8 pm (US Pacific coast), and was detected before the attackers could do any harm, the LineageOS team said in a statement published less than three hours after the incident. The LineageOS team said the operating system's source code was unaffected, and so were any operating system builds, which had been already paused since April 30, because of an unrelated issue. Full Article.
By Eduard Kovacs on May 01, 2020 Oracle warned customers on Thursday that threat actors have been spotted attempting to exploit multiple recently patched vulnerabilities, including a critical WebLogic Server flaw tracked as CVE-2020-2883. Eric Maurice, director of security assurance at Oracle, said the company had received “reports of attempts to maliciously exploit a number of recently-patched vulnerabilities.” He only mentioned CVE-2020-2883, but advised customers to install the latest patches as soon as possible. Full Article.
May 4, 2020 By Zeljka Zorz Two vulnerabilities in SaltStack Salt, an open-source remote task and configuration management framework, are being actively exploited by attackers, CISA warns. About SaltStack Salt Salt is used for configuring, managing and monitoring servers in datacenters and cloud environments. The Salt installation is the “master” and each server it monitors runs an API agent called a “minion”. The minions send state reports to the master and the master publishes update messages containing instructions/commands to the minions. The communication between the master and its minions is secured (encrypted). Full Article.
May 2, 2020 By Pierluigi Paganini French daily Le Figaro database accidentally exposed online, the archive included roughly 7.4 billion records containing personal information of employees and users. French daily newspaper Le Figaro exposed roughly 7.4 billion records containing personally identifiable information (PII) of employees, reporters, and at least 42,000 users. The database was discovered by the Safety Detectives team of experts lead by the researcher Anurag Sen, it was over 8TB, the archive also included data of accounts registered between February and April 2020, as well as logs of accesses in the same period. Full Article.
Webroot and BrightCloud product and services are unaffected by the Log4j vulnerability. For more information on all OpenText products, please see this advisoryhttps://www.opentext.com/support/log4j-remote-code-execution-advisoryCompanies released lists of products affected by a newly discovered vulnerability found in the Apache Log4j library that’s already identified on billions of systems around the globe. In other cyber security news, Volvo suffered a security incident affecting their computer systems that may have also caused a breach of sensitive company information.Hundreds of financial institutions hit by Anubis malwareThe Anubis Android malware that has plagued the Google Play store for several years has resurfaced to again target financial apps for their login credentials. While it is still unclear which group is operating this recent Anubis campaign, many different groups have used it in the past. It is believed that this latest campaign is still in its early stages and is bei
Artificial intelligence (AI) and machine learning (ML) are going to revolutionize the field of cybersecurity. These technologies can be used to improve the detection and prevention of cyber threats, making it easier for organizations to protect their networks and data. However, as with any new technology, there are also potential risks and challenges that must be considered.One of the biggest benefits of AI and ML in cybersecurity is their ability to automatically detect and respond to cyber threats. These technologies can be used to analyze large amounts of data, such as network traffic logs and characteristics of files to identify patterns and anomalies that may indicate a cyber attack or malicious nature. They can also be used to automatically respond to threats, such as by shutting down a compromised system or blocking a malicious IP address. Additionally, the benefits of AI and ML in cybersecurity is their ability to improve the efficiency and effectiveness of incident response. T
Following @'s recent remark in the thread AVG changes privacy policy to harvest users' personal data and sell it to advertisers on Webroot's recent change of privacy policy as follows: In some cases, we may choose to share your personal information with third parties who have not explicitly agreed to provide the same level of protection to your information as we do. What's that all about?!? And what's this all about: We may also share your personal information with ... selected ... advertisers, marketers, and advertising and marketing networks that use the information to select and serve relevant ads to you and others on our site, on other sites, and in apps, as permitted under applicable law and in accordance with your communication preferences (existing Webroot privacy policy also cited by@curlyq in the above-mentioned thread)? I would have posted these queries to that thread, but posting has apparently been disabled in that thread (??). Thus the need to create a new th
2023 was the LARGEST Black Hat yet! The crowds were very large at every keynote and in the expo hall. Compared to last year - we are definitely back and beating pre-Covid numbers. I’m just going to say that Artificial Intelligence was the buzzword of the conference and you couldn’t attend a single briefing or visit a booth without hearing it. It’s definitely not going anywhere 🤖 Another long post coming so get that scroll wheel ready 🤠 Weather was typical Vegas HOT at the Mandalay Bay (102f), but not as hot as it had been the week before we all arrived - which was a scorching 113f🔥 Thankfully there was no flash flooding like last year. REGISTRATION I’m happy to report that Black Hat finally have registration down and can handle the massive amount of crowds. Even if you don’t have the handy QR code, you can still get a speedy process with just your email. This is a welcome change from previous years and I no longer dread registration - THANK YOU! This looks almost identical to las
We’re back in almost full force at BlackHat 2022! The crowds were definitely back compared to last year and while not quite what they used to be pre-Covid, it definitely feels like we’re closer to getting back to normal 😎. This post is going to be a long one, so get that scrolling finger ready. The calm before the storm ⛈🌧Weather at the Mandalay Bay was usual Vegas hot, but as I’m sure many if you saw it took a turn for the worse with flash floods towards the end of the conference heading into DEFCON (heaviest rainfall in 10 years!) USA TODAYREGISTRATION Registration was much more organized that previous years and it was as simple as scanning a QR code and then going to a station to collect your backpack. It was definitely busy with lines the day of the opening keynote, but the day before wasn’t bad at all. They really upped their game from last year when they had technical difficulties and the lines wrapped around the pillars, so Kudos to Mandalay Bay + BlackHat. Backpacks are
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-20131 Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data VulnerabilityThis type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges
1st June 2017 By Dell Cameron Although storing passwords in plaintext anywhere online is fundamentally the opposite of security, routine data breaches at some of the world’s biggest companies haven’t dissuaded some users from engaging in this obviously terrible practice. Case in point: As Vocativ reported on Thursday, the company behind Trello, the popular workplace app, was forced to implement privacy protections on some users’ behalf due to their own total lack of regard for basic security controls. First, Trello is a handy web-based app best described as a tool for organization and collaboration. It’s a convenient way to manage big projects by creating lists, sharing documents and assigning tasks. A newsroom, for example, might use a
The RSA Conference 2023 has come and gone, but the excitement it brought to our community is still very much alive! As one of the most anticipated events in the cybersecurity world, this year's conference did not disappoint. With a plethora of insightful presentations, captivating booth displays, and cutting-edge cybersecurity solutions showcased, RSA 2023 was a memorable experience for everyone involved. In this post, we'll take you on a visual journey through some of the highlights, featuring snapshots from innovative booths, introductions to our expert presenters, and a not-so brief synopsis of the thought-provoking briefings that I had the privilege of attending. Get ready to dive into the world of cybersecurity and relive the energy that permeated RSA Conference 2023! EXPO HALL The Expo hall at RSA Conference 2023 was a true embodiment of excitement and innovation, buzzing with energy as industry professionals and cybersecurity enthusiasts alike gathered to explore the latest br
See Also - Exploits Swirling for Major Security Defect in Apache Log4j This Tech Tip outlines how enterprise defenders can mitigate the risks of the Log4j vulnerabilities for the short-term while waiting for updates. December 11, 2021 By Fahmida Y. Rashid Researchers are warning that attackers are actively exploiting the newly publicized unauthenticated remote code execution vulnerability in Log4j, the Java-based logging tool from Apache. While the bulk of the work to mitigate CVE-2021-44228 falls on application owners and software developers, enterprise security teams also have to do their part to keep their organizations secure.This Tech Tip provides short-term mitigations for affected enterprise security teams who don’t yet have updates available, can’t install the updates right away for whatever reason, or won’t be receiving updates at all.Consider the following scenario: a vendor has a financial application that uses Java and the vulnerable version of Log4j. Any organization tha
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.