Thu.Oct 13, 2022

article thumbnail

Digital License Plates

Schneier on Security

California just legalized digital license plates, which seems like a solution without a problem. The Rplate can reportedly function in extreme temperatures, has some customization features, and is managed via Bluetooth using a smartphone app. Rplates are also equipped with an LTE antenna, which can be used to push updates, change the plate if the vehicle is reported stolen or lost, and notify vehicle owners if their car may have been stolen.

Risk 57
article thumbnail

New Alchimist attack framework hits Windows, Linux and Mac

Tech Republic Security

The attack framework of probable Chinese origin used by cybercriminals has been discovered. The post New Alchimist attack framework hits Windows, Linux and Mac appeared first on TechRepublic.

Malware 216
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Ongoing exploitation of CVE-2022-41352 (Zimbra 0-day)

SecureList

Overview. On September 10, 2022, a user reported on Zimbra’s official forums that their team detected a security incident originating from a fully patched instance of Zimbra. The details they provided allowed Zimbra to confirm that an unknown vulnerability allowed attackers to upload arbitrary files to up-to-date servers. At the moment, Zimbra has released a patch and shared its installation steps.

article thumbnail

Samsung unveils latest smartphones, smart devices and Galaxy Watch

Tech Republic Security

At the Samsung Developer Conference 2022, the company also discussed its plans for personalized experiences, security and privacy. The post Samsung unveils latest smartphones, smart devices and Galaxy Watch appeared first on TechRepublic.

Internet 167
article thumbnail

How to Avoid Pitfalls In Automation: Keep Humans In the Loop

Speaker: Erroll Amacker

Automation is transforming finance but without strong financial oversight it can introduce more risk than reward. From missed discrepancies to strained vendor relationships, accounts payable automation needs a human touch to deliver lasting value. This session is your playbook to get automation right. We’ll explore how to balance speed with control, boost decision-making through human-machine collaboration, and unlock ROI with fewer errors, stronger fraud prevention, and smoother operations.

article thumbnail

China-linked Budworm APT returns to target a US entity

Security Affairs

The Budworm espionage group resurfaced targeting a U.S.-based organization for the first time, Symantec Threat Hunter team reported. The Budworm cyber espionage group (aka APT27 , Bronze Union , Emissary Panda , Lucky Mouse , TG-3390 , and Red Phoenix) is behind a series attacks conducted over the past six months against a number of high-profile targets, including the government of a Middle Eastern country, a multinational electronics manufacturer, and a U.S. state legislature.

article thumbnail

This top-rated password manager is just $2/month

Tech Republic Security

Take advantage of this limited-time offer on LastPass. A LastPass Premium membership is now available for only $2 per month. The post This top-rated password manager is just $2/month appeared first on TechRepublic.

LifeWorks

More Trending

article thumbnail

How to become a white hat hacker

Tech Republic Security

For just $4 each, The Ultimate White Hat Hacker Certification Bundle offers you 10 cybersecurity courses to teach you how to protect your network. The post How to become a white hat hacker appeared first on TechRepublic.

article thumbnail

Cloudflare blocked a 2.5 Tbps DDoS attack aimed at the Minecraft server

Security Affairs

Cloudflare mitigated a record distributed denial-of-service (DDoS) attack against Wynncraft, one of the largest Minecraft servers. Cloudflare announced it has mitigated a record distributed denial-of-service (DDoS) attack against Wynncraft, one of the largest Minecraft servers. The Cloudflare DDoS threat report 2022 Q3 states that multi-terabit massive DDoS attacks have become increasingly frequent.

DDOS 139
article thumbnail

Feature-Rich 'Alchimist' Cyberattack Framework Targets Windows, Mac, Linux Environments

Dark Reading

The comprehensive, multiplatform framework comes loaded with weapons, and it is likely another effort by a China-based threat group to develop an alternative to Cobalt Strike and Sliver.

128
128
article thumbnail

New Android Banking Malware Deployed Using Vishing

Heimadal Security

New research conducted by a Dutch mobile security company recently discovered a network of phishing websites targeting Italian online-banking users to get a hold of their credentials. Hackers are using a social engineering approach called TOAD, also known as ‘telephone-oriented attack delivery’ that includes calling the victims and using information gathered from malicious websites.

Banking 124
article thumbnail

Why Giant Content Libraries Do Nothing for Your Employees’ Cyber Resilience

Many cybersecurity awareness platforms offer massive content libraries, yet they fail to enhance employees’ cyber resilience. Without structured, engaging, and personalized training, employees struggle to retain and apply key cybersecurity principles. Phished.io explains why organizations should focus on interactive, scenario-based learning rather than overwhelming employees with excessive content.

article thumbnail

Modified WhatsApp App Caught Infecting Android Devices with Malware

The Hacker News

An unofficial version of the popular WhatsApp messaging app called YoWhatsApp has been observed deploying an Android trojan known as Triada. The goal of the malware is to steal the keys that "allow the use of a WhatsApp account without the app," Kaspersky said in a new report. "If the keys are stolen, a user of a malicious WhatsApp mod can lose control over their account.

Malware 123
article thumbnail

Life in pursuit of answers: In the words of Ada Yonath

We Live Security

From a little girl financially helping her family in Jerusalem to a Nobel Prize laureate. That is the exceptional life of Ada Yonath in a nutshell. The post Life in pursuit of answers: In the words of Ada Yonath appeared first on WeLiveSecurity.

122
122
article thumbnail

YoWhatsApp, unofficial WhatsApp Android app spreads the Triada Trojan

Security Affairs

Kaspersky researchers warn of a recently discovered malicious version of a popular WhatsApp messenger mod dubbed YoWhatsApp. Kaspersky researchers discovered an unofficial WhatsApp Android application named ‘YoWhatsApp’ that steals access keys for users’ accounts. Mod apps are advertised as unofficial versions of legitimate apps that have features that the official one does not supports.

Mobile 120
article thumbnail

WhatsApp Clone Caught Stealing Users’ Accounts

Heimadal Security

A WhatsApp clone app called “YoWhatsApp” has been found stealing access keys for users’ accounts. The app uses the same permission as the standard WhatsApp app, but it includes additional features such as the ability to customize the interface or block access to chats. The latest version of the app has been discovered to send […]. The post WhatsApp Clone Caught Stealing Users’ Accounts appeared first on Heimdal Security Blog.

article thumbnail

Zero Trust Mandate: The Realities, Requirements and Roadmap

The DHS compliance audit clock is ticking on Zero Trust. Government agencies can no longer ignore or delay their Zero Trust initiatives. During this virtual panel discussion—featuring Kelly Fuller Gordon, Founder and CEO of RisX, Chris Wild, Zero Trust subject matter expert at Zermount, Inc., and Principal of Cybersecurity Practice at Eliassen Group, Trey Gannon—you’ll gain a detailed understanding of the Federal Zero Trust mandate, its requirements, milestones, and deadlines.

article thumbnail

WhatsApp Mods are caught distributing malware

CyberSecurity Insiders

Modified versions of WhatsApp are illegal and those still using them should quickly make a note of the following alert. Researchers from Kaspersky have discovered that those using YoWhatsApp are being targeted with trojan malware named Triada having capabilities of stealing data from mobile phone and indulging in espionage. So, customers using modified versions of any social media app are being urged to stop using such mobile software’s as it can trigger unnecessary privacy concerns and can sign

Malware 115
article thumbnail

Cyberattackers Spoof Google Translate in Unique Phishing Tactic

Dark Reading

The campaign uses a combination of tactics and a common JavaScript obfuscation technique to fool both end users and email security scanners to steal credentials.

Phishing 110
article thumbnail

News about NHS and CommonSpirit Health Ransomware attacks

CyberSecurity Insiders

Advanced, the IT services provider of NHS has confirmed that a ransomware attack on its servers that took place in August this year led to data breach. However, the firm isn’t prepared yet to confirm the leak of patient data in the attack. A news resource that only covers details related to the healthcare sector has confirmed that data related to 16 of StaffPlan and Caresys customers were accessed and stolen by hackers.

article thumbnail

Researchers Uncover Custom Backdoors and Spying Tools Used by Polonium Hackers

The Hacker News

A threat actor tracked as Polonium has been linked to over a dozen highly targeted attacks aimed at Israelian entities with seven different custom backdoors since at least September 2021.

Insurance 109
article thumbnail

Next-Level Fraud Prevention: Strategies for Today’s Threat Landscape

Speaker: Sierre Lindgren

Fraud is a battle that every organization must face – it’s no longer a question of “if” but “when.” Every organization is a potential target for fraud, and the finance department is often the bullseye. From cleverly disguised emails to fraudulent payment requests, the tactics of cybercriminals are advancing rapidly. Drawing insights from real-world cases and industry expertise, we’ll explore the vulnerabilities in your processes and how to fortify them effectively.

article thumbnail

What You Need for a Strong Security Posture

Dark Reading

From the basics to advanced techniques, here's what you should know.

108
108
article thumbnail

How Brand Protection Can Address the Risk of GAN Deepfakes

Security Boulevard

Deepfakes are a concept that has taken root in popular culture. Most deepfakes are benign; the good ones go viral and can often make us laugh. But in the very near future, deepfake attacks waged against businesses will be unlikely to put a smile on anyone’s face. I’ll describe the technology behind deepfakes, known as. The post How Brand Protection Can Address the Risk of GAN Deepfakes appeared first on Security Boulevard.

Risk 105
article thumbnail

Siemens SIMATIC Flaw Allows Theft of Cryptographic Keys

Heimadal Security

Recent discoveries identified a vulnerability in Siemens SIMATIC programmable logic controller (PLC), which can be exploited to retrieve the hardcoded, global private cryptographic keys and seize control of the devices. Identified as CVE-2022-38465 and rated 9.3 on the CVSS scoring scale, the vulnerability has been addressed by the German industrial manufacturing company, as part of security updates issued […].

article thumbnail

POLONIUM APT targets Israel with a new custom backdoor dubbed PapaCreep

Security Affairs

An APT group tracked as Polonium employed custom backdoors in attacks aimed at Israelian entities since at least September 2021. POLONIUM APT focused only on Israeli targets, it launched attacks against more than a dozen organizations in various industries, including engineering, information technology, law, communications, branding and marketing, media, insurance, and social services.

Malware 103
article thumbnail

Prevent Data Breaches With Zero-Trust Enterprise Password Management

Keeper Security is transforming cybersecurity for people and organizations around the world. Keeper’s affordable and easy-to-use solutions are built on a foundation of zero-trust and zero-knowledge security to protect every user on every device. Our next-generation privileged access management solution deploys in minutes and seamlessly integrates with any tech stack to prevent breaches, reduce help desk costs and ensure compliance.

article thumbnail

Google Brings Passkeys to Android & Chrome

Heimadal Security

Google announced on October 12, 2022, his support for Passkeys on Android and Chrome. This is the next-generation login standard and aims to create a safer cyber environment by replacing traditional passwords with unique digital keys that are saved on your device. Passkeys were created by FIDO Alliance and supported also by Apple and Microsoft […].

Passwords 104
article thumbnail

Microsoft is rebranding 'Office' to Microsoft 365

Bleeping Computer

After 32 years, Microsoft has begun to kill off the Microsoft Office brand, with plans to rebrand its Office.com and Office cloud-based apps to Microsoft 365 in the near future. [.].

99
article thumbnail

PoC Exploit Released for Critical Fortinet Auth Bypass Bug Under Active Attacks

The Hacker News

A proof-of-concept (PoC) exploit code has been made available for the recently disclosed critical security flaw affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager, making it imperative that users move quickly to apply the patches. "FortiOS exposes a management web portal that allows a user to configure the system," Horizon3.ai researcher James Horseman said.

98
article thumbnail

The $1 Billion Alex Jones Effect

WIRED Threat Level

The Infowars host now knows the cost of “free speech”—but does the landmark judgment signal a crackdown on disinformation?

Media 98
article thumbnail

Optimizing The Modern Developer Experience with Coder

Many software teams have migrated their testing and production workloads to the cloud, yet development environments often remain tied to outdated local setups, limiting efficiency and growth. This is where Coder comes in. In our 101 Coder webinar, you’ll explore how cloud-based development environments can unlock new levels of productivity. Discover how to transition from local setups to a secure, cloud-powered ecosystem with ease.

article thumbnail

Android and Chrome start showing passwords the door

Malwarebytes

Google has announced that it's bringing passkey support to both Android and Chrome. On May 5, 2022, it said it would implement passwordless support in Android and Chrome and the latest annoncement about passkeys is an important step in that journey. Passkeys. Passkeys are a replacement for passwords. They are faster to sign in with, easier to use, and much more secure.

article thumbnail

New COVID-19 Phishing Campaign Uses Google Forms

Heimadal Security

Recent attacks use phishing emails to impersonate the U.S. Small Business Administration (SBA) and rely on Google Forms to host phishing pages that steal the personal details of business owners. COVID-19-themed phishing campaigns are not unheard of in the U.S., but this time the attack is actually based on a legitimate financial recovery program the SBA ran […].

article thumbnail

Only half of teens agree they "feel supported online" by parents

Malwarebytes

Not enough children and teenagers trust their parents to support them online, and not enough parents know exactly how to give the support their children need. Those are some of the latest findings from joint research conducted this summer by Malwarebytes and 1Password, which we have published today in the report “ Forever connected: the realities of parenting and growing up online.” The data from our two, parallel surveys—one for Generation Z respondents aged 13 to 25 and one f

article thumbnail

The discovery of Alchimist C2 tool, revealed a new attack framework to target Windows, macOS, and Linux systems

Security Affairs

Experts discovered a new attack framework, including a C2 tool dubbed Alchimist, used in attacks against Windows, macOS, and Linux systems. Researchers from Cisco Talos discovered a new, previously undocumented attack framework that included a C2 dubbed Alchimist. The framework is likely being used in attacks aimed at Windows, macOS, and Linux systems.

Malware 98
article thumbnail

The Tumultuous IT Landscape Is Making Hiring More Difficult

After a year of sporadic hiring and uncertain investment areas, tech leaders are scrambling to figure out what’s next. This whitepaper reveals how tech leaders are hiring and investing for the future. Download today to learn more!