News
-
"New Windows Trojan Steals Browser Credentials, Outlook Files"Researchers with Palo Alto's Unit 42 research team have discovered a new information-stealing trojan, which targets Microsoft Windows systems with an onslaught of data-exfiltration capabilities. The trojan is called PyMicropsia (due to it being built…
-
"Phishing Campaign Uses Outlook Migration Message"Researchers at Abnormal Security have released details about an ongoing phishing campaign aimed at harvesting users' Office 365 credentials. The phishing emails in the campaign are designed to appear as if they were sent from the IT department…
-
"Contact-Tracing Apps Still Expose Users to Security, Privacy Issues"An analysis of 95 COVID-19 contact-tracing apps conducted by the mobile security firm Guardsquare revealed that 40% did not use the official API of the Exposure Notifications protocol created by Apple and Google to protect user privacy and security. The…
-
"Ad-Injecting Malware Hijacks Chrome, Edge, Firefox"The Microsoft 365 Defender Research Team has issued a warning about ad-injecting malware called Adrozek. According to Microsoft, cybercriminals have been distributing Adrozek malware since May 2020, with its peak occurring in August when more than 30,000…
-
"Researchers Warn of Security Vulnerabilities in These Widely Used Point-of-Sale Terminals"Security vulnerabilities have been discovered in two widely used Point-of-Sale (PoS) terminals that could allow cybercriminals to conduct a number of malicious activities such as stealing credit card details, cloning terminals, and more. The…
-
"PLEASE_READ_ME Ransomware Attacks 85K MySQL Servers"Researchers are warning of an active ransomware campaign that is targeting MySQL database servers. MySQL is an open-source relational database management system. The ransomware is called PLEASE_READ_ME, and has so far breached at least 85,000…
-
"Critical Steam Flaws Could Let Gamers Crash Opponents’ Computers"Valve fixed critical bugs (CVE-2020-6016, CVE-2020-6017, CVE-2020-6018, and CVE-2020-6019) in its Steam gaming client, a popular platform for video games like Counter Strike: Global Offensive, Dota2, and Half Life. The first three CVEs score 9.8…
-
"Security by Design"Nadya Bliss, the executive director of Arizona State University's Global Security Initiative, and her colleagues from the University of Maryland, Lehigh University, Cornell University, and the University of Utah are calling on technologists to prioritize…
-
"Palo Alto Creates Visualization Tool to Guide Response to Egregor Ransomware Attacks"Palo Alto's Unit 42 developed a tool to help security teams visualize the techniques used by the attack group behind the Egregor ransomware attacks and to improve responses to these attacks. The Unit 42 ATOM Viewer allows security professionals to view…
-
"Vulnerabilities Found in Multiple GE Imaging Systems"A team of researchers at CyberMDX discovered flaws in more than one hundred different GE Healthcare imaging and ultrasound products widely used in US hospitals. The exploitation of these vulnerabilities could allow attackers to gain access to Protected…
-
"Google Open-Sources Atheris, a Tool for Finding Security Bugs in Python Code"Google has open-sourced its Python fuzzing utility called Atheris. Fuzzing refers to the process of feeding a software application with invalid or random data until it reveals a flaw. The goal of fuzzing is to find and fix vulnerabilities in software…