Sun.Oct 18, 2020

article thumbnail

FIN11 gang started deploying ransomware to monetize its operations

Security Affairs

The financially-motivated hacker group FIN11 has started spreading ransomware to monetize its cyber criminal activities. The financially-motivated hacker group FIN11 has switched tactics starting using ransomware as the main monetization method. The group carried out multiple high-volume operations targeting companies across the world, most of them in North America and Europe.

article thumbnail

Future Imperfect

Trend Micro

All the way back in 2012, Trend Micro was lucky enough to be asked to participate in a very exciting research project initiated under the auspices of the International Cyber Security Protection Alliance (ICSPA) on which I worked alongside experts from Europol’s European Cyber Crime Centre (EC3) led by Dr. Victoria Baines.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Microsoft released out-of-band Windows fixes for 2 RCE issues

Security Affairs

Microsoft released two out-of-band security updates to address remote code execution (RCE) bugs in the Microsoft Windows Codecs Library and Visual Studio Code. Microsoft has released two out-of-band security updates to address two remote code execution (RCE) vulnerabilities that affect the Microsoft Windows Codecs Library and Visual Studio Code. The two vulnerabilities, tracked as CVE-2020-17022 and CVE-2020-17023 , have been rated as important severity.

article thumbnail

Just leave that Docker API on the front porch, no one will steal it

Trend Micro

The global rush to move resources and infrastructure to the cloud as a result of Covid-19 has moved the attack surface from on-premise environments to the cloud.

Malware 52
article thumbnail

The Importance of User Roles and Permissions in Cybersecurity Software

How many people would you trust with your house keys? Chances are, you have a handful of trusted friends and family members who have an emergency copy, but you definitely wouldn’t hand those out too freely. You have stuff that’s worth protecting—and the more people that have access to your belongings, the higher the odds that something will go missing.

article thumbnail

QQAAZZ crime gang charged for laundering money stolen by malware gangs

Security Affairs

Multiple members of QQAAZZ multinational cybercriminal gang were charged for providing money-laundering services to high-profile malware operations. 20 members of the multinational cybercriminal group QQAAZZ were charged this week in the US, Portugal, Spain, and the UK for providing money-laundering services. The arrests are the result of an unprecedented international law enforcement operation, coordinated by the Europol and dubbed Operation 2BaGoldMule, involving agencies from 16 countries.

Malware 110
article thumbnail

Not All Telework Solutions are Created Equal

Approachable Cyber Threats

Category Awareness, Vulnerabilities. Risk Level. It may seem like forever ago when that email arrived: all personnel will begin working from home effective Monday. As the COVID-19 pandemic overtook the world, many organizations knew they needed to work remotely, but many struggled to figure out how to activate their business continuity plans. Unfortunately, many organization’s didn’t plan out their IT scenarios, and quickly turned to work-from-home technology options that worked, instead of work

More Trending

article thumbnail

QAnon/8Chan Sites Briefly Knocked Offline

Krebs on Security

A phone call to an Internet provider in Oregon on Sunday evening was all it took to briefly sideline multiple websites related to 8chan/8kun — a controversial online image board linked to several mass shootings — and QAnon , the far-right conspiracy theory which holds that a cabal of Satanic pedophiles is running a global child sex-trafficking ring and plotting against President Donald Trump.

DDOS 360
article thumbnail

Iran-linked Silent Librarian APT targets universities again

Security Affairs

Iran-linked cyberespionage group Silent Librarian has launched a new phishing campaign aimed at universities around the world. Iran-linked APT group Silent Librarian has launched another phishing campaign targeting universities around the world. The Silent Librarian, also tracked as Cobalt Dickens and TA407, targeted tens of universities in four continents in the last couple of years.

Phishing 127