Security
Unraveling EternalBlue: inside the WannaCry’s enabler
WannaCry and NotPetya, probably two most damaging cyberattacks in recent history, were both only made possible because of EternalBlue. Here is how the NSA-developed cyber monster works, and how you should defend against it.
Read more about Unraveling EternalBlue: inside the WannaCry’s enabler
Topgolf Callaway Brands hacked, over a million golfers exposed
Over a million customers of Topgolf Callaway Brands, an American sports equipment manufacturing company that operates a chain of golf centers, have had their personal information leaked and will be asked to change passwords.
Read more about Topgolf Callaway Brands hacked, over a million golfers exposed
North Korean malicious package targets Windows
A malicious campaign targeting MacOS, Linux, and Windows systems has been attributed to the North Korean threat group Lazarus.
Read more about North Korean malicious package targets Windows
Russia’s spies using new crude malware to target Android devices in Ukraine
The Russian military intelligence service GRU can access compromised Android devices with a new malware dubbed Infamous Chisel. Spotted and described by Ukraine’s security agency, the technical details of the malicious campaign were published by the National Cyber Security Centre (NCSC) in the UK and international partners.
Read more about Russia’s spies using new crude malware to target Android devices in Ukraine
Chinese spies target Android users with fake Signal, Telegram apps
Two separate Chinese spy campaigns involving fake Signal and Telegram messaging apps targeting US and European Android users were discovered by ESET security researchers.
Read more about Chinese spies target Android users with fake Signal, Telegram apps
Credentials of NASA, Tesla, DoJ, Verizon, and 2K others leaked by workplace safety organization
The National Safety Council has leaked nearly 10,000 emails and passwords of their members, exposing 2000 companies, including governmental organizations and big corporations.
Read more about Credentials of NASA, Tesla, DoJ, Verizon, and 2K others leaked by workplace safety organization
GDPR used by new ransom gang to extort victims
The EU’s General Data Protection Regulation (GDPR) is being leveraged by a new ransomware group to pressure victims into paying up.
Read more about GDPR used by new ransom gang to extort victims
QakBot malware platform taken down by FBI
The US Department of Justice (DoJ) says QakBot, a decades-old malware platform with ties to Russia, has been dismantled by the FBI with the help of international law enforcement.
Read more about QakBot malware platform taken down by FBI
Just three malware loaders used in 80% of attacks
Three malware loaders, QakBot, SocGholish, and Raspberry Robin, wreak havoc in 80% of incidents, according to the threat researchers of IT security firm ReliaQuest.
Read more about Just three malware loaders used in 80% of attacks
Dangerous new Telegram bot automates scamming with no skill required
Hordes of wannabe scammers without any IT knowledge now have a new tool at their disposal. Attackers, referring to their victims as “mammoths,” were themselves labeled as “Neanderthals” by ESET researchers for the level of skills required to use the new Telegram bot.
Read more about Dangerous new Telegram bot automates scamming with no skill required
Multi-hospital ransom attack in US claimed by Rhysida gang
The early August ransomware attack on California-based Prospect Medical Holdings (PMH) – a multi-state conglomerate of over a dozen major hospitals and more than 150 outpatient facilities – has been claimed by the Rhysida ransom group.
Read more about Multi-hospital ransom attack in US claimed by Rhysida gang
Ransomware encryption devastates CloudNordic, customer data lost
Danish cloud provider CloudNordic has suffered a devastating ransomware attack that left most customer data irretrievable. Its systems have been shut down and the company is facing bankruptcy.
Read more about Ransomware encryption devastates CloudNordic, customer data lost
Hackers exposed 2.6 million Duolingo users, more available for scraping
Duolingo, the popular language learning app, has had some of its users exposed online. The scraped data of 2.6 million people, which was on sale in January, is now available on the cybercrime marketplace BreachForums. Open API allows the scraping of more data.
Read more about Hackers exposed 2.6 million Duolingo users, more available for scraping
Defense contractor Belcan leaks admin password with a list of flaws
US Government and defense contractor Belcan left its super admin credentials open to the public. A lapse that could have resulted in a serious supply chain attack, the Cybernews research team reveals.
Read more about Defense contractor Belcan leaks admin password with a list of flaws
FBI: Space industry espionage is latest cyber threat
The FBI and other counterintelligence agencies are warning that nation-state-sponsored cyber spies are actively trying to steal research and trade secrets from companies involved with the US space industry.
Read more about FBI: Space industry espionage is latest cyber threat
Alarming lack of cybersecurity practices on world's most popular websites
The world’s most popular websites lack basic cybersecurity hygiene, an investigation by Cybernews shows.
Read more about Alarming lack of cybersecurity practices on world's most popular websites
Cl0p dumps all MOVEit victim data on clearnet, threat insiders talk ransom strategy
In what could be seen as a bold move or a sign of desperation, the Cl0p ransomware group has made good on its August 15th promise to publish the files of all its victims if contact was not made by the latest deadline. Does this mean the MOVEit fiasco is finally winding down? Cybernews gets the 411 on Cl0p strategy from two threat intel leaders during Black Hat.
Read more about Cl0p dumps all MOVEit victim data on clearnet, threat insiders talk ransom strategy
Think twice before accepting notifications on Chrome: threats on the rise
Clicking the “Allow” button online is asking for trouble. Dubious websites exploit push notification functionality to serve ads, malware, or phish users' credentials. And the trend shows that these attacks are on the rise.
Read more about Think twice before accepting notifications on Chrome: threats on the rise
UK govt contractor leaks employee passport data
MPD FM, a facility management and security company providing services to various UK government departments, left an open instance that exposed employee passports, visas, and other sensitive data.
Read more about UK govt contractor leaks employee passport data
Beware of thermal attacks, security experts warn
Thermal attacks can crack users’ passwords in mere seconds by analyzing the traces of heat their fingertips leave on keyboards and screens.
Read more about Beware of thermal attacks, security experts warn