Security News > 2020 > October

Facebook Announces Bug Bounty Loyalty Program, Streamlined Bug Triage
2020-10-12 18:27

Facebook has announced a series of updates for its bug bounty program, including bonus rewards for engaged researchers, as well as a faster bug triage process. The social media platform announced that it streamlined the triage of security vulnerabilities reported through its bug bounty program, to increase efficiency and lower response timeframe.

Windows Update can be abused to execute malicious programs
2020-10-12 18:02

The Windows Update client has just been added to the list of living-off-the-land binaries attackers can use to execute malicious code on Windows systems. The WSUS / Windows Update client is a utility located at %windir%system32 that provides users partial control over some of the Windows Update Agent's functionality from the command-line.

Windows Update can be abused to execute malicious files
2020-10-12 18:02

The Windows Update client has just been added to the list of living-off-the-land binaries attackers can use to execute malicious code on Windows systems. The WSUS / Windows Update client is a utility located at %windir%system32 that provides users partial control over some of the Windows Update Agent's functionality from the command-line.

Infographic: Ransomware attacks by industry, continent, and more
2020-10-12 18:00

This infographic details ransomware attack trends by industry, continent, and more. Overall, the Lumu flashcard essentially functions as an all-in-one infographic compiling 2020 ransomware trends from an amalgam of sources across the cybersecurity industry.

'You've got the old cheeky Corona': Ireland's pandemic advice SMS service can be spoofed, warns researcher
2020-10-12 16:21

Ireland's efforts to keep residents informed about coronavirus has fallen foul of the same basic SMS vulnerability that one of their British neighbours experienced back in March. Lulzsec-bod-turned-security-consultant Jake Davis reckoned the Irish government is using an SMS sender name that is vulnerable to spoofing - a process that is simple and straightforward, not that we're going to explain how it's done.

QBot uses Windows Defender Antivirus phishing bait to infect PCs
2020-10-12 15:50

The Qbot botnet uses a new template for the distribution of their malware that uses a fake Windows Defender Antivirus theme to trick you into enabling Excel macros. Qbot, otherwise known as QakBot or QuakBot, is Windows malware that steals bank credentials, Windows domain credentials, and provides remote access to threat actors who install ransomware.

QBot uses Windows Defender Antivirus lure to infect computers
2020-10-12 15:50

The Qbot botnet uses a new template for the distribution of their malware that uses a fake Windows Defender Antivirus theme to trick you into enabling Excel macros. Qbot, otherwise known as QakBot or QuakBot, is Windows malware that steals bank credentials, Windows domain credentials, and provides remote access to threat actors who install ransomware.

Cloudflare Launches New Zero Trust Networking, Security Platform
2020-10-12 15:11

Cloudflare on Monday announced the launch of a new zero trust platform that can help organizations address the networing and security challenges associated with an increasingly remote workforce. According to the company, the Cloudflare One platform provides a set of tools that allows users to safely and quickly connect to work applications, it enables remote workers to use the same app without the need to expose it to the public internet, and it makes personal devices more secure for business use.

Hackers Publish Public School District's Stolen Data Online
2020-10-12 14:20

Computer hackers who obtained information about a Virginia public school district's students and employees have posted stolen data online, school officials said Friday in an email to parents and staff. The Fairfax County Public Schools didn't specify the nature or volume of the data that was stolen in the ransomware attack last month.

Tech Companies Take Down TrickBot Botnet Infrastructure
2020-10-12 14:04

Microsoft on Monday revealed that it worked together with industry partners to shut down the infrastructure used by TrickBot operators and block efforts to revive the botnet. The Washington Post reported last week that the U.S. Cyber Command too attempted to hack TrickBot's C&C servers, in an attempt to take the botnet down to prevent attacks seeking to disrupt the U.S. presidential elections.