Security News > 2020 > April

We've seen a recent surge of concern about sextortion emails over the last few days. A sextortion or porn scam email is where cybercriminals email you out of the blue to claim that they've implanted malware on your computer, and have therefore been able to keep tabs on your online activity.

People drawing Social Security payments from the government will receive stimulus payments the same way. A review of the Web site set up to accept bank account information for the stimulus payments reveals few other mandatory identity checks to complete the filing process.

Sucuri researcher Ben Martin recently investigated a skimmer attack lodged against a WooCommerce site and found that it differs from prior payment-card campaigns that have targeted WordPress-based e-commerce destinations - in that the malware doesn't just intercept payment information entered into the fields on a check-out page. Forwarding payments to the attacker's PayPal email instead of the legitimate website owner. Seeing a dedicated credit card swiping malware within WordPress is something fairly new."

The squid drawings of Yuuki Tokuda are simply incredible. I tried to figure out how to buy one of them, but everything is in Japanese.

Or, you could make use of a feature, introduced in Android 9, called SMS Verification Code Autofill. To enable SMS Verification Code Autofill, you must first enable Autofill.

Starting with Android 9, you can make two-factor authentication even easier.

Join Today Policies make it easy to set a training plan for end users and improve risk management strategies. Whether your existing policy needs an update, or you need to start from scratch, this collection of policies from TechRepublic Premium will make it easy to get started on a security improvement process.

A critical information-disclosure bug in VMware's Directory Service could lay bare the contents of entire corporate virtual infrastructures, if exploited by cyberattackers. The vmdir in turn is a central component to the vCenter SSO. Also, vmdir is used for certificate management for the workloads governed by vCenter, according to VMware.

Cato Networks, a firm poised to take advantage of the sudden acceleration of business transformation and working from home caused by the COVID-19 pandemic, has raised $77 million in a Series D funding round. "While many companies struggle to enable work-from-home remote access to all employees, Cato customers only had to flip-a-switch. That's the power of one converged global network and security platform enabling enterprises to be ready for whatever's next."

12% of users have reportedly stopped using Zoom altogether, the social platform Blind found. Zoom has been slammed for a wide array of security issues over the past couple of weeks, including Zoom bombings, personal data leaks, absence of end-to-end encryption, and more.