News
-
Science of Security and Privacy 2021 Annual ReportThe Science of Security and Privacy 2021 Annual Report is now available. Science of Security and Privacy 2021 Annual Report highlights the progress and accomplishments of this initiative.
-
"Critical Zoom Vulnerability Triggers Remote Code Execution Without User Input"Pwn2OW is a contest that allows white-hat cybersecurity professionals and teams to compete in the discovery of bugs in popular software and services. This year the winning team was Computest, and they discovered a vulnerability in Zoom. The…
-
"Microsoft Uses Machine Learning to Predict Attackers' Next Steps"Researchers at Microsoft have built a model that uses Machine Learning (ML) to attribute cyberattacks to specific groups based on Tactics, Techniques, and Procedures (TTPs) and to predict their next steps. The Microsoft researchers are discovering…
-
"Over 90% of Organizations Hit by a Mobile Malware Attack in 2020"Researchers from Checkpoint conducted a new study where they polled 1800 customers of its Harmony Mobile device threat protection product. The researchers discovered that every global organization suffered at least one mobile malware attack in 2020…
-
"Researchers Develop Method for Enhancing Resilience against Replay Attacks In Computer Systems"Complex, multi-tier systems' reliance on layered communications in the performance of tasks increases vulnerability as every point of contact could be a target for replay attacks. In replay attacks, the malicious actor uses information already in the…
-
"National Supply Chain Integrity Month: Campaign to Raise Awareness of Supply Chain Threats and Mitigation"April is National Supply Chain Integrity Month. The National Counterintelligence and Security Center (NCSC) is partnering with government and industry partners throughout April for the 4th annual National Supply Chain Integrity Month to encourage…
-
"UK Firms Suffer Record Number of Cyber-Attacks in Q1"Researchers at Beaming discovered that there was no let up for UK businesses in the first three months of 2021, with commercial organizations suffering an 11% year-on-year increase in cyber-attacks during the period. The researchers found that UK…
-
"Data from 500M LinkedIn Users Posted for Sale Online"In yet another incident of threat actors scraping data from public profiles and slinging it online for potential cybercriminal misuse, researchers have found that personal data from more than 500 million LinkedIn users have been posted for sale online.…
-
"Cybercrime Group Lazarus Upgrades its Arsenal with Vyveva Malware"ESET researchers found a new backdoor that is being used by the Lazarus hacking group in attacks against freight and logistic organizations in South Africa. The malware dubbed Vyveva performs backdoor activities such as exfiltrating files, collecting…
-
"Fraudsters Use HTML Lego to Evade Detection in Phishing Attack"Researchers with Trustwave SpiderLabs have released a detailed analysis of a new phishing campaign aimed at Microsoft 365 users. The fraudsters behind the campaign employ "HTML Lego" to deliver a fake Microsoft login page. According to Trustwave, the…
-
"Scientists Harness Chaos to Protect Devices From Hackers"Researchers at Ohio State University have discovered how to use chaos to help create fingerprints for electronic devices that might be unique enough to thwart the most sophisticated hackers. The researchers believe these fingerprints are unique enough to…
-
"SAP Issues Advisory On the Exploit of Old Vulnerabilities to Target Enterprise Applications"SAP and Onapsis recently released a joint threat intelligence report to help SAP customers protect themselves against active cyber threats aimed at compromising organizations running unsecured SAP applications. The report highlights activities in which…