Security News > 2020 > March

Microsoft to Add Compromised Password Notification to Edge
2020-03-30 18:25

While the affected service may reset passwords to prevent abuse, it's not uncommon for users to set the same password for other websites as well, leaving them exposed to credential stuffing attacks. Microsoft says the Password Monitor feature in Edge will notify users if the password they are entering using autofill has been offered for sale on dark web sites.

Zeus Sphinx Banking Trojan Arises Amid COVID-19
2020-03-30 18:19

The Zeus Sphinx banking trojan is back after being off the scene for nearly three years. First seen in August 2015, Sphinx is a modular malware based on the leaked source code of the infamous Zeus banking trojan, the researchers explained.

Annual Protest to ‘Fight Krebs’ Raises €150K+
2020-03-30 17:42

In protest of that story, forum members donated hundreds of thousands of euros to nonprofits that combat cancer. This week, the forum is celebrating its third annual observance of that protest to "Fight Krebs," albeit with a Coronavirus twist.

How to use an iPhone or Android device as the security key for your Google account
2020-03-30 16:53

How to set up an Android phone as your security key for your Google account. Set up two-step verification for your Google account through your phone or a computer by signing into the webpage for your Google account.

How to protect your organization and remote workers against ransomware
2020-03-30 16:12

Phishing emails and unsecure remote desktop protocol access are two common types of attack methods used to spread ransomware, says cyber breach firm Beazley Breach Response Services.

How to stay on top of coronavirus scams – and all the others too
2020-03-30 15:57

Don't login to company websites via emails or texts. If a company wants or needs you to login to your account, you should already know how to access your account from the company's own site or app.

FBI: Cybercriminals Mailing Malicious USB Devices to Victims
2020-03-30 15:49

The financially-motivated hacking group FIN7 has started mailing malicious USB devices to intended victims in an effort to infect their computers with malware, the FBI warns. Mainly targeting businesses via phishing emails, the cybercrime group appears to have changed tactics recently, and started sending malicious USB devices to victims via the United States Postal Service.

Zettaset Launches Software-Defined Encryption for Kubernetes Environments
2020-03-30 15:41

Kubernetes-specialist Zettaset has introduced software-defined encryption for Kubernetes-managed containers, improving DevSecOps, enhancing data protection, and enabling compliance. The fluid nature of cloud storage requires a software rather than hardware solution - and Zettaset has announced its software-defined XCrypt Kubernetes Encryption offering.

Corporate Workers Warned of 'COVID-19 Payment' Emails Delivering Banking Trojan
2020-03-30 14:59

IBM and FireEye have spotted a campaign that relies on fake "COVID-19 Payment" emails to deliver the Zeus Sphinx banking trojan to people in the United States, Canada and Australia. The emails have the subject line "COVID-19 payment" and they carry malicious documents named "COVID 19 relief."

Remote work and web conferencing: Security and privacy considerations
2020-03-30 13:54

As more and more people remain at home and work from home due to the COVID-19 pandemic, most of them have been forced to use one or many video and audio conferencing applications out of necessity. One particular remote conferencing solution is quickly becoming the solution of choice for many users worldwide: Zoom.