Security

Microsoft accounts targeted by EvilProxy phishing kits

Multifactor authentication (MFA) defenses are being bypassed by a ready-made phishing tool that has targeted thousands of victims, says Proofpoint cybersecurity firm.
Read more about Microsoft accounts targeted by EvilProxy phishing kits

Balada Injector still at large – new domains discovered

During a routine web monitoring operation, we discovered an address that led us down a rabbit hole of WordPress-orientated “hack waves” caused by the Balada Injector malware. This evidence suggests that the malware is still at large and still evading security software by utilizing new domain names and slight changes between the waves of obfuscated attacks.
Read more about Balada Injector still at large – new domains discovered

GDPR compliance is not cybersecurity, says analyst

Compliance on paper does not add up to better protection in real life and this is costing businesses more in the long run, claims Imperva
Read more about GDPR compliance is not cybersecurity, says analyst

Points.com glitch left millions of records exposed

A major back-end provider for free flights, hotel bookings, and other points-based rewards had multiple security flaws that potentially put millions of customers’ personal data in jeopardy.
Read more about Points.com glitch left millions of records exposed

Satellites easier to hack than a Windows device

Satellites are full of exploitable vulnerabilities. Attackers could use these flaws to launch themselves into orbit, closer to more valuable targets, a satellite security researcher believes.
Read more about Satellites easier to hack than a Windows device

Ransom gangs have cost manufacturers $46B

Downtime caused by ransomware attacks on the manufacturing industry have cost it $46 billion over the past five years, a cybercrime round-up can reveal.
Read more about Ransom gangs have cost manufacturers $46B

Zero-day bug exploiting Meta hits Salesforce

Cloud-based software company Salesforce was left wide open to a cyberattack exploiting the reputation of tech giant Meta thanks to a previously undetected bug.
Read more about Zero-day bug exploiting Meta hits Salesforce

Burger King forgets to put a password on their systems, again

The fast food giant put their systems and data at risk by exposing sensitive credentials to the public for a second time.
Read more about Burger King forgets to put a password on their systems, again

Chrome extensions: they see everything

1
Your handy adblocker, price tracker, or spell checker extension might be significantly risking your online safety. Oren Koren, Co-Founder of the cybersecurity firm Veriti, advised me to delete all Chrome extensions, and he’s not the only one. Four more cybersecurity researchers have similar opinions.
Read more about Chrome extensions: they see everything

Everlast hacked, customer credit cards compromised

Everlast, the well-known American boxing equipment brand, recently had its online shop hacked by a cybergang linked to the world’s biggest online bank heist. Customer credit card data has been silently skimmed for at least three weeks, the Cybernews research team found.
Read more about Everlast hacked, customer credit cards compromised

Italy targeted by new malware strain

A threat group known for going after targets in Europe and Asia has been deploying a new form of malware against Italian organizations, cybersecurity company Proofpoint says.
Read more about Italy targeted by new malware strain

US Senator demands feds investigate Microsoft over China email and SolarWinds hack

1
Oregon Senator Ron Wyden is pushing three federal agencies to hold Microsoft accountable for security failures that led to two major hacking campaigns impacting multiple government offices – a recently discovered Chinese-led cyberespionage campaign and the infamous 2020 SolarWinds hack.
Read more about US Senator demands feds investigate Microsoft over China email and SolarWinds hack

Deloitte joins fellow Big Four MOVEit victims PWC, EY

Big Four financial services firm Deloitte confirms to Cybernews that it's part of the latest round of victims claimed in the MOVEit attacks.
Read more about Deloitte joins fellow Big Four MOVEit victims PWC, EY

DepositFiles exposed config file, jeopardizing user security

1
DepositFiles, a popular web hosting service, left its environment configuration file accessible, revealing a trove of highly sensitive credentials.
Read more about DepositFiles exposed config file, jeopardizing user security

macOS RedLine Stealer malware found on fake blockchain games

macOS is being abused to create malicious software embedded in bogus games, a malware hunter has disclosed.
Read more about macOS RedLine Stealer malware found on fake blockchain games

Apple extends spyware patch to all devices

Apple has now extended an emergency patch notice, which was recently issued for newer devices, to its entire array of platforms, Sophos cybersecurity firm reports.
Read more about Apple extends spyware patch to all devices

Imagine360 data breach: medical information, Social Security numbers compromised

Imagine360, a health plan solution company based in Pennsylvania, has disclosed a data breach affecting over 130,000 people.
Read more about Imagine360 data breach: medical information, Social Security numbers compromised

Average cost of data breach reaches $4.5M – you’re the one who pays

The frequency and cost of data breaches are increasing. However, companies are reluctant to invest in safeguarding their systems. What’s more, many organizations transfer the cost of the breach to consumers.
Read more about Average cost of data breach reaches $4.5M – you’re the one who pays

Tampa hospital hit hard in cyberattack

Tampa General Hospital (TGH) confirms patient data was compromised during a more than two-week-long cyberattack. Now, multiple ransomware gangs are claiming to possess the stolen data.
Read more about Tampa hospital hit hard in cyberattack

First search result leads to malware: crooks now paying for ads

Cybercriminals are finding new ways to poison search results. They’re filling Google with paid ads using so-called ‘malvertising’ campaigns, which lead unaware users to malicious sites that exploit their data and trust.
Read more about First search result leads to malware: crooks now paying for ads