Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Friday, 16 March 2018

Weekly News Roundup



Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Cybercriminals spotted hiding cryptocurrency mining malware in forked projects on GitHub

Cybercriminals have found another way to spread their malware: uploading cryptocurrency mining code to GitHub, according to security researchers. Developers 'fork' projects on GitHub, which means making a copy of someone else's project in order to build on it. In this case, the cybercriminals fork random projects and then hide malicious executables in the directory structure of these new projects. Read more…

Bitcoin stealing malware distributed on download.com for nearly a year

Bitcoin stealing malware that swaps user accounts with that of the attacker was found to be hosted on Download.com servers for nearly a year. Read more…

Vengeance by DDoS: No one is immune

In what may catch many by surprise, distributed denial of service (DDoS) attacks are being used against companies, organizations, and individuals as an act of vengeance or revenge. No one is immune; documented victims have included non-profit organizations, community colleges, courts and law enforcement entities. Read more…

Victims can sue Yahoo for massive breaches, federal judge says

Plaintiffs suing Yahoo for failing to protect all of the company’s 3 billion users can move forward with the majority of their case, a federal judge in California ruled on Friday. Read more…

Friday, 17 November 2017

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Forever 21 hack reveals payment card data

The clothing retailer says hackers compromised point of sale devices at stores for a good part of the year. Read more…

If you own a Google Home or Amazon Echo, you could be at risk

Remember BlueBorne, the vulnerability that allowed hackers to infiltrate an estimated 5 billion gadgets using only a Bluetooth connection? It’s estimated that 20 million Amazon Echo and Google Home devices were vulnerable to attacks via the BlueBorne exploit. Read more…

Security vulnerability in IoT cameras could allow remote control by hackers

Newly uncovered vulnerabilities in a popular brand of indoor internet-connected cameras could be exploited by attackers in order to gain complete control of the device. Read more…

121 Pieces of Malware Flagged on NSA Employee's Home Computer

Kaspersky Lab's internal investigation found a backdoor Trojan and other malware on the personal computer of the NSA employee who took home agency hacking tools. Read more…

Friday, 10 November 2017

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Fake WhatsApp app downloaded more than one million times

A fake version of the WhatsApp messenger app was downloaded more than a million times from the Google Play Store before it was removed. According to users, the fake contained ads and could download software to users' devices. Read more…

Senators Blast Equifax and Yahoo for Massive Data Breaches

Both Yahoo and Equifax took the stand this week to address the major customer data breaches that happened under their watch and what responsibility their companies had for the historic data breaches that saw billions of Americans' privacy compromised. Read more…

What's going on with Ethereum? $280m in cryptocurrency 'lost' amid security scare

Approximately $280m worth of the cryptocurrency Ethereum has been frozen in time – and potentially lost forever – after an unidentified developer accidentally triggered a critical bug in a shared code library used by digital wallets maintained by Parity Technologies. Read more...

2.7M Verticalscope credentials compromised

The Canadian web forum manager Verticalscope has again been hacked with 2.7 million user accounts being affected this time. The latest incident takes place about one year after the company reported that 45 million user credentials had been compromised. Read more…

Friday, 27 October 2017

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Bad Rabbit: A new Petya-like ransomware that's spreading, but beatable

A new form of ransomware, dubbed Bad Rabbit, is infecting computers via drive-by attacks masquerading as Flash updates. This latest form of rapidly spreading ransomware is believed to be a variant of the Petya family; DLLs associated with it share approximately 67% of their code with known Petya variants. Read more…

WannaCry ransomware: Hospitals were warned to patch system to protect against cyber-attack - but didn't

The National Health Service (NHS) was left vulnerable to the WannaCry ransomware attack because, despite local health trusts being warned to patch their systems, many had failed to do so. A National Audit Office (NAO) investigation found that the impact of WannaCry could have been prevented if basic security best practice had been applied. Read more…

Criminals mimic popular cryptocurrency exchange in Google Play

Cybercriminals took advantage of popular cryptocurrency exchange Poloniex's lack of an official app to dupe unsuspecting users into downloading credential stealing malware. Read more…

Senators try to reform law that allows U.S. agencies to surveil citizens

A bipartisan group of U.S. senators introduced the USA Rights Act to limit surveillance of Americans' communications under Section 702 of the Foreign Intelligence Surveillance Act. Read more…

Friday, 20 October 2017

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Microsoft never disclosed 2013 hack of secret vulnerability database

Hackers broke into Microsoft's secret, internal bug-tracking database and stole information related to vulnerabilities that were exploited in later attacks. But the software developer never disclosed the breach, Reuters reported, citing former company employees. Read more…

Severe weakness in Wi-Fi security gives hackers wide access to eavesdrop

Nearly everyone using Wi-Fi is being urged to patch their devices as a new widespread vulnerability to virtually all modern protected Wi-Fi networks leaves a huge swath of internet traffic potentially open for eavesdropping. Read more…

Ransomware: Security researchers spot emerging new strain of malware

A new form of ransom is being distributed via the same method as one of the most successful families of file-locking malware, and may represent a new evolution of the menace. Read more…

Phishing campaigns used victim's location to determine whether to deliver Locky or Trickbot

Researchers recently detected two email-based phishing campaigns that infected users with either Locky ransomware or the Trickbot banking trojan based on the victim's geographical location – a technique that the company claims is rather uncommon. Read more…

Tuesday, 20 June 2017

What Can We Learn From WannaCry?


As the dust settles from the initial shock of the WannaCry ransomware and the lasting implications of the attack continue to reveal themselves, it is important to look back and see what we can learn from it. 

BOHH Labs CTO Ken Hawkins reflects below on what can be said about this latest ransomware/malware and the lessons we can learn it.

This latest attack was put together quickly and seems on the surface to be the work of persons or entities that either are just dabbling in the arena for the first time or it is a brazen attack leaving an easily seen breadcrumb like a trail to the source. Even though it did cause a global issue for a lot of persons, it appears that still today, the oldest tricks are the best in this arena of ransomware.
                
How it generally happens? Target older end of life OS’s with known issues that have not been patched, phish until you find an entry (clicking a link in email, opening an attachment, etc.) onto a single machine, infect (encrypt), demand a ransom from the user and broadcast to the next unsuspecting victim. Of course, it is a little more involved than that from a technology standpoint; however, for the layman in all of us, this is how it happens. In this case, it was primarily spread through Windows XP machines, which support ended for the OS in 2014 after users were notified as far back as 2008. Think about this, Microsoft notified users a full 6 years before it officially ended support for XP and yet still many corporations kept the OS in place. The reasons of course can vary from a smaller company with no budget to fortune 500 or greater companies who have had some machines still in service.

One needs not go into the deep dark corners of hackerdom arenas to know how this spread and works, nor does a person need to buy the latest and greatest operating system and stay in that endless upgrade cycle. Ransomware like this latest gain a foothold and proliferate in the same manner as the Target security breach of 2013 and others. Someone was duped into clicking a link in an email without knowing where it was going or what was going to happen. Once clicked, the end user probably will not know immediately what has happened. Remember this when you click the clink you are unaware of, you cannot react faster than the computer can change its state. Once you click that risky link of the day your entire computer can be locked down or overtaken in a matter of seconds if not milliseconds!

The lesson we should once again learn here is trust. In today’s information / computer age, trust is still the key to a safe journey ended on the Internet. This trust comes from the individual and not a company. There is no better way to protect yourself from infection than knowing where you are going on the Internet. You can draw a similar parallel of following a GPS while driving. Think about how many times the GPS has given you wrong or longer driving routes, and the frustration you might feel knowing in hindsight that there was a better way. If it takes you longer to get somewhere or you must backtrack, that is time lost at best. Not knowing where you are going on the Internet can cost you your identity, compromise your companies’ network and a possible loss data, which can never be retrieved.

You can say metaphorical statements like “If it looks too good to be true don’t believe it” and others but until we stop being complacent in our Internet travels, these kinds of attacks will continue to affect us all to some degree. I say it like this, know your hyperlinks! If the link looks risky, right click on it, copy and paste it somewhere (notepad, etc.) and look at it before you go. Did it originate from the entity it states the email is from? Watch out for a link that points to a different generic top level domain (.com vs .net)? If you’re unsure and want to make sure, call the entity who sent the email. A little bit of vigilance will go a long way to protecting you and your personal details from the more nefarious entities who unfortunately do lurk the Internet.