Security News > 2020

How to enable 2FA on a per-user basis in Nextcloud
2020-03-16 16:50

If you want to enable two-factor authentication for Nextcloud on a per-user basis, it's just a simple app installation away.

How to enable 2FA on a per-user basis in Nextcloud
2020-03-16 16:47

If you want to enable two-factor authentication for Nextcloud on a per-user basis, it's just a simple app installation away. The first thing you must do is enable two-factor authentication for your Nextcloud server.

There Are Plenty of Phish in the Sea
2020-03-16 16:23

Today, for modest amounts of money, would-be scammers can buy high-quality phishing tools online, through the Dark Web, enabling them to skip all the fuss and bother of actually learning how to code or do graphics or any of the other steps required to successfully scam someone. There the price of a phishing page averaged $338. Phishing - essentially stealing sensitive information like passwords, credentials, reset notifications and other forms of access through trickery - is the single most common form of online attack.

Organizations Slow to Patch Targeted Microsoft Exchange Vulnerability
2020-03-16 16:19

Organizations have fallen behind with the patching of a Microsoft Exchange Server vulnerability addressed with Microsoft's February 2020 Patch Day updates and already targeted in attacks. The issue, which exists because keys created at installation are not unique, is tracked as CVE-2020-0688 and impacts Microsoft Exchange 2010, 2013, 2016, and 2019.

Report: US Health and Human Services department hit by cyberattack amidst coronavirus fears
2020-03-16 16:03

The U.S Department of Health and Human Services was the victim of a cyberattack on Sunday as the federal government attempts to deal with the coronavirus crisis, according to a report from Bloomberg. "The U.S. Health & Human Services fell victim to a Distributed Denial of Service attack yesterday when several endpoints controlled by a nation-state attacked their networks," Stephen Boyce, principal consultant at risk management and digital forensics firm Crypsis Group, said.

Health workers are top of phishers' target lists thanks to data value
2020-03-16 15:30

Nurses are among the groups most heavily targeted by email scammers because of the value of the data they can access, according to email security biz Proofpoint's Adenike Cosgrove. Cosgrove, an infosec strategist for Proofpoint, told The Register that not only are nurses and other frontline healthcare professionals at the top of phishing target lists, but that a healthcare worker asked her for advice on security best practice - rather than her own organisation's security team.

COVID-19 Themed Phishing Campaigns Continue
2020-03-16 15:22

The first report on the new campaign came in a RedDrip Team tweet on March 12, 2020: "Malicious document, pretending to be from the Government of #India with health advisory of Coronavirus, seems delivered by #Transparent Tribe. Victims are lured to enable macro to execute #Crimson #RAT payload.". There have been numerous media reports about the Chinese nation-state APT Vicious Panda.

Slack Vulnerability Allowed Hackers to Hijack Accounts
2020-03-16 15:14

A researcher earned $6,500 from Slack last year after finding a critical vulnerability that could have been exploited to hijack Slack accounts. The vulnerability was reported to Slack in mid-November via the company's bug bounty program on HackerOne and it was patched within 24 hours, which is not uncommon for Slack when it comes to account hijacking issues.

TSA Admits Liquid Ban Is Security Theater
2020-03-16 14:31

Passengers will now be allowed to travel with containers of liquid hand sanitizer up to 12 ounces. The agency cautioned that the shift could mean slightly longer waits at checkpoint because the containers may have to be screened separately when going through security.

ProtonMail, ProtonVPN Will Use Alternative Routing to Bypass Censorship
2020-03-16 12:57

Over the coming weeks, a new alternative routing feature will become available across all of the ProtonMail and ProtonVPN mobile and desktop applications, the company says. "While we have largely been able to overcome censorship and attacks, it's imperative that we remain one step ahead of those who would seek to spy on people and restrict the freedom of information. Alternative routing is an additional capability which helps us ensure users can access our services," Proton says.