Showing posts with label ransomware. Show all posts
Showing posts with label ransomware. Show all posts

Friday, 23 March 2018

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Facebook Controversy: What to Know About Cambridge Analytica and Your Data

This week’s uproar over Facebook Inc. started years ago, with the mishandling of user data. Now that incident, and what followed, is at the center of a debate over how well the world’s largest social network protects its trove of user data. Read more…

Atlanta Ransomware Attack Freezes City Business

Ransomware that struck the city of Atlanta early Thursday morning froze internal and customer-facing applications, but officials say backups are in place and they expect to pay city employees on time next week. Read more…

Cryptocurrency mining malware uses five-year old vulnerability to mine Monero on Linux servers

Hackers are using a five-year-old security vulnerability to infect Linux servers with cryptocurrency-mining malware. The cryptojacking campaign exploits CVE-2013-2618, an old vulnerability in Cacti's Network Weathermap plug-in, an open source tool which is used by network administrators to visualise network activity. Read more…

House passes controversial legislation giving the US more access to overseas data

This week, the House of Representatives passed controversial legislation that would clarify and expand how data held overseas can be obtained by law enforcement in the United States. The change is part of the massive omnibus spending bill, and it incorporates measures first submitted earlier this year as the CLOUD Act. Read more…


Friday, 20 October 2017

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Microsoft never disclosed 2013 hack of secret vulnerability database

Hackers broke into Microsoft's secret, internal bug-tracking database and stole information related to vulnerabilities that were exploited in later attacks. But the software developer never disclosed the breach, Reuters reported, citing former company employees. Read more…

Severe weakness in Wi-Fi security gives hackers wide access to eavesdrop

Nearly everyone using Wi-Fi is being urged to patch their devices as a new widespread vulnerability to virtually all modern protected Wi-Fi networks leaves a huge swath of internet traffic potentially open for eavesdropping. Read more…

Ransomware: Security researchers spot emerging new strain of malware

A new form of ransom is being distributed via the same method as one of the most successful families of file-locking malware, and may represent a new evolution of the menace. Read more…

Phishing campaigns used victim's location to determine whether to deliver Locky or Trickbot

Researchers recently detected two email-based phishing campaigns that infected users with either Locky ransomware or the Trickbot banking trojan based on the victim's geographical location – a technique that the company claims is rather uncommon. Read more…

Friday, 25 August 2017

Weekly NewsRoundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Cryptocurrency cyber crime has skyrocketed alongside the popularity of ICOs

Almost 10% of all the money invested in initial coin offerings (ICOs) this year using cryptocurrency Ethereum has fallen into the hands of thieves. Read more…

Barclays enables voice payments with Siri

Barclays says it’s the first UK high street bank that lets mobile banking customers make a payment by asking Siri. The payment, which relies on TouchID for authentication, can be completed without opening the Barclays mobile banking app. Read more…

Ransomworms on the rise: yet another wake up call for the enterprise

90 percent of enterprises still recording exploits for vulnerabilities that are more than three years old, and 60 percent for vulnerabilities more than ten years old says Fortinet report, with twice as many attacks at weekends. Read more…

Popular Robots are Dangerously Easy to Hack, Cybersecurity Firm Says

Some of the most popular industrial and consumer robots are dangerously easy to hack and could be turned into bugging devices or weapons. Read more…

Friday, 18 August 2017

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Gartner: Cybersecurity Spending Worldwide to Hit $86.4 Billion This Year

The global information security market for 2017 will grow by 7% over last year with spending to reach $86.4 billion, according to a new forecast by Gartner. Read more…

Uber reaches deal with FTC on consumer privacy, agrees to new program

Ridesharing behemoth Uber agreed Tuesday to institute “a culture of privacy” in how it handles personal information from its passengers and drivers, following a Federal Trade Commission investigation that revealed the company misrepresented its internal data access policies and failed to take reasonable security measures to safeguard data in the cloud. Read more…

Maersk Previews NotPetya Impact: Up to $300 Million

Danish shipping giant A.P. Møller - Maersk faces a loss of up to $300 million as a result of the NotPetya global malware outbreak. Read more…

Seven Accused in $5M Insider Trading Scheme

The SEC says the scheme revolved around an IT consultant who had access to a computer system that BofA used to track investment banking deals. Read more…


Friday, 7 July 2017

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Breached Bitcoin Bithumb bosses blame bod's BYOD

South Korean cyber-cops are probing a hacking attack on Bithumb, one of the world's biggest Bitcoin exchanges. Miscreants were able to get hold of personal information of roughly 32,000 Bithumb users, or three per cent of the exchange's user base. Read more…


CopyCat Android malware infected 14 million devices, rooted 8 million last year

CopyCat Android mobile malware was able to infect over 14 million devices last year and root eight million of them, researchers have revealed. Read more…


'NotPetya' Hackers Demand $256,000 In Bitcoin To Cure Ransomware Victims

It looks like the hackers responsible for the massive ransomware outbreak that crippled Ukraine last week and infected some of the world's biggest industrial companies, from Maersk to Merck, are posting messages demanding more Bitcoin to unlock victims' files. They're after 100 Bitcoin, currently worth an astonishing $256,000. Read more…

Kaspersky offers to turn over source code to U.S. government

Kaspersky said the U.S. government can audit its source code, a move meant to prove Kaspersky Lab is not in bed with the Russian government. Read more…


Friday, 30 June 2017

Weekly News Roundup



Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Global ransomware attack causes turmoil

Companies across the globe are reporting that they have been struck by a major ransomware cyber-attack. Read more…


Anthem to pay record $115 million to settle U.S. lawsuits over data breach

Anthem Inc., the largest U.S. health insurance company, has agreed to settle litigation over hacking in 2015 that compromised about 79 million people's personal information for $115 million, which lawyers said would be the largest settlement ever for a data breach. Read more…


Kaspersky Lab Faces More U.S. Scrutiny Over Potential Russian Govt. Influence

Moscow-based Kaspersky Lab this week found itself the subject of escalating concerns about the company's possible connections with the Russian government. The immediate worries this time were prompted by news that FBI agents had questioned several of the security vendor's US-based employees. Read more…

8tracks breach yields data on 18M accounts

Hackers accessed 8tracks's user database and pilfered information, including email addresses and encrypted passwords, from at least 18 million accounts signed up for the Internet radio service using email. Read more…


Friday, 23 June 2017

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Honda Shut Down Plant Impacted by WannaCry

Honda, one of the largest automobile manufacturers in the world, announced that it was forced to shut down production at one of its Japanese plants after it was hit by the WannaCry ransomware. Read more…

Skype outage causing connectivity issues, company says it’s a “global incident”

Microsoft’s recently updated communications app Skype has been suffering connectivity issues which began on Monday, June 19th. After hours of downtime on Monday, the company confirmed the issue via a blog post and tweet, which stated that an incident was causing users to either lose connectivity to the application or lose their ability to send and receive messages. Read more…

Data of nearly all registered US voters left unsecured for weeks in RNC trove

Personal data, including names, addresses, voter registration details and social media posts, made vulnerable because of improper security settings. The 198 million individuals captured in the data represent virtually the entire registered voter population. Read more…

New York Supreme Court Justice fell for $1M phishing attack

New York State Supreme Court Justice Lori Sattler was duped out of more than $1 million while trying to sell her Upper East Side apartment and purchase another. Justice Sattler was fooled by a phishing email she thought was from her estate lawyer into wiring nearly $1.1 million to the Commerce Bank of China. Read more…


Tuesday, 20 June 2017

What Can We Learn From WannaCry?


As the dust settles from the initial shock of the WannaCry ransomware and the lasting implications of the attack continue to reveal themselves, it is important to look back and see what we can learn from it. 

BOHH Labs CTO Ken Hawkins reflects below on what can be said about this latest ransomware/malware and the lessons we can learn it.

This latest attack was put together quickly and seems on the surface to be the work of persons or entities that either are just dabbling in the arena for the first time or it is a brazen attack leaving an easily seen breadcrumb like a trail to the source. Even though it did cause a global issue for a lot of persons, it appears that still today, the oldest tricks are the best in this arena of ransomware.
                
How it generally happens? Target older end of life OS’s with known issues that have not been patched, phish until you find an entry (clicking a link in email, opening an attachment, etc.) onto a single machine, infect (encrypt), demand a ransom from the user and broadcast to the next unsuspecting victim. Of course, it is a little more involved than that from a technology standpoint; however, for the layman in all of us, this is how it happens. In this case, it was primarily spread through Windows XP machines, which support ended for the OS in 2014 after users were notified as far back as 2008. Think about this, Microsoft notified users a full 6 years before it officially ended support for XP and yet still many corporations kept the OS in place. The reasons of course can vary from a smaller company with no budget to fortune 500 or greater companies who have had some machines still in service.

One needs not go into the deep dark corners of hackerdom arenas to know how this spread and works, nor does a person need to buy the latest and greatest operating system and stay in that endless upgrade cycle. Ransomware like this latest gain a foothold and proliferate in the same manner as the Target security breach of 2013 and others. Someone was duped into clicking a link in an email without knowing where it was going or what was going to happen. Once clicked, the end user probably will not know immediately what has happened. Remember this when you click the clink you are unaware of, you cannot react faster than the computer can change its state. Once you click that risky link of the day your entire computer can be locked down or overtaken in a matter of seconds if not milliseconds!

The lesson we should once again learn here is trust. In today’s information / computer age, trust is still the key to a safe journey ended on the Internet. This trust comes from the individual and not a company. There is no better way to protect yourself from infection than knowing where you are going on the Internet. You can draw a similar parallel of following a GPS while driving. Think about how many times the GPS has given you wrong or longer driving routes, and the frustration you might feel knowing in hindsight that there was a better way. If it takes you longer to get somewhere or you must backtrack, that is time lost at best. Not knowing where you are going on the Internet can cost you your identity, compromise your companies’ network and a possible loss data, which can never be retrieved.

You can say metaphorical statements like “If it looks too good to be true don’t believe it” and others but until we stop being complacent in our Internet travels, these kinds of attacks will continue to affect us all to some degree. I say it like this, know your hyperlinks! If the link looks risky, right click on it, copy and paste it somewhere (notepad, etc.) and look at it before you go. Did it originate from the entity it states the email is from? Watch out for a link that points to a different generic top level domain (.com vs .net)? If you’re unsure and want to make sure, call the entity who sent the email. A little bit of vigilance will go a long way to protecting you and your personal details from the more nefarious entities who unfortunately do lurk the Internet.

Friday, 19 May 2017

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

1. India's Zomato says data from 17 million users stolen

Global restaurant guide Zomato revealed this week that hackers have stolen data on about 17 million users. The breach includes personal information, including email addresses and hashed passwords. Read more…

2. 'PATCH Act' Aims to Help Prevent Cyberattacks
New legislation calls for an overhaul of the federal government's software vulnerability disclosure policies following the ransomware outbreak that was fueled by the leak of a stolen National Security Agency cyberweapon. Read more…

3. DocuSign's stolen emails lead to phishing attacks

Threat actors are using stolen DocuSign customer emails in a phishing campaign to spread malicious Word Documents. A third party gained temporary access to communicate service-related announcements to users via email. Read more…


4. Facebook hit with maximum fine for breaking French privacy law

The French data protection watchdog has imposed its harshest penalty on Facebook for six breaches of French privacy law. The breaches include tracking users across websites other than Facebook.com without their knowledge, and compiling a massive database of personal information in order to target advertising. Read more…


Friday, 24 March 2017

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

1. Senate Puts ISP Profits Over Your Privacy
The Senate just voted to roll back your online privacy protections. Many of these rules will roll back the way the FCC can track and profit off of your ever move online. Read more…

2. Hackers holding 300 million iCloud account details to ransom raise their price to $700,000, despite assurances from Apple
Hackers behind a criminal attack planned against iCloud and iPhone users say they are still preparing to breach the accounts of up to 750 million users. Read more…

3. C.I.A. Developed Tools to Spy on Mac Computers, WikiLeaks Disclosure Shows
This week it came out from WikiLeaks’ most recent dump of classified government documents that the C.I.A. developed tools to spy on Mac computers by injecting software into the chips that control the computers’ fundamental operations. Read more…

4. Banks and Tech Firms Battle Over Something Akin to Gold: Your Data
Technology startups and big banks are at opposing ends on how to protect customer data, yet neither is talking about the increasingly standard protection method of encryption, as they engage in a tug-of-war over the data because of its value. Read more…


Friday, 24 February 2017

Weekly News Roundup



Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

1. Everything You Need to Know About Cloudbleed, the Latest Internet Security Disaster
Another major data leak – this time hitting some major brands. A Cloudflare bug has led to a lot of data being leaked including passwords, personal information, cookies and more. Read more…

2. Hackers behind bank attack campaign use Russian as decoy
A new twist has come out in the recent hacking attacks on financial institutions around the globe. New analysis on the malware samples show that Russian words and commands were inserted into the malware to throw investigators off. Read more…

3. Google Chrome users targeted with ‘missing font’ malware scam
A security researcher is warning Google Chrome users about a scam to install a fake “missing font” as a way to infect them with malware. Read more…

4. New macOS ransomware spotted in the wild
A new file-encrypting ransomware program for macOS is being distributed through BitTorrent websites, and users who fall victim to it won’t be able to recover their files, even if they pay. Read more…

Thursday, 23 February 2017

Cybersecurity Trends to Watch for in 2017






Everyone made their top predictions for what’s to come in 2017 in the security industry, and only a couple of months in, it has already been an eventful year.

With cybersecurity protection becoming a top line item for enterprises, it is critical to stay on top of the biggest trends emerging. Below are several trends that have been hot topics so far in the beginning of 2017 and deserve a close eye of attention as we navigate throughout the rest of the year.
  1. Ransomware: Already early in the year, we have heard numerous stories of companies in all sectors being hit with ransomware attacks. This trend is expected to continue rising. Market estimates that the ransomware protection market is expected to grow from USD 8.16 Billion in 2016 to USD 17.36 Billion by 2021. Ransomware has gained popularity among many cybercriminals since they know most organizations would rather pay the ransom fee to get their data back rather than admit there had been a breach or stop operations while they are being exploited.

  2. Mobile security: Despite the popularity and norm of mobile devices and BYOD strategies accepted as standard in today’s enterprise model, there is still huge concern around security. A Ponemon Institute study found that 84% of respondents are very concerned about malware threats to their mobile applications. In fact, 60%, or six out of 10 of the respondents, say their organization had been breached as the result of an insecure mobile application over the past 12 months. Hackers are taking advantage of the way users rely on 24x7 access to their personal information via their mobile devices, such as accessing their bank accounts and credit cards, and using malware to that steal information and redirect users to malicious sites.
  3. Security of Internet of Things devices: There is constant talk about the impact the Internet of Things and how the connected world can improve both our personal and professional lives, but these devices also bring a host of security issues, as these devices serve as an easy entry point for cybercriminals to enter our networks. Gartner predicts that by 2020, addressing compromises in IoT security will have increased security costs to 20% of annual security budgets, from less than 1% in 2015. We have already seen the major impact attacks can have on IoT devices with the Dyn attack. This trend will continue as the number of connected devices we are using increases.

  4. Challenges in the cybersecurity workforce: Just a few months in to 2017, and there are many conversations swirling around the trend of a global shortage of cybersecurity professionals. According to a report from ISACA, 55% of organizations reported that it takes at least three months to fill open cybersecurity positions, while 32% said they take six months or more. There seems to be a disconnect between what employers are looking for and what skills candidates are bringing in terms of in terms of cybersecurity skills. With new technologies impacting the way we approach security, this will be an interesting trend we continue to monitor.