Security News > 2021 > January

Friday Squid Blogging: Searching for Giant Squid by Collecting Environmental DNA
2021-01-08 22:02

The idea is to collect and analyze random DNA floating around the ocean, and using that to figure out where the giant squid are. As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered.

Malicious Software Infrastructure Easier to Get and Deploy Than Ever
2021-01-08 21:31

Simple to use and deploy offensive security tools, making it easier than ever for criminals with little technical know-how to get in on cybercrime are seeing a significant rise, researchers say. Recorded Future's 2020 Adversary Infrastructure Report explained that researchers anticipate increased adoption of open-source tools because they're easy to use and accessible to criminals without deep technical expertise.

A Look Ahead at 2021: SolarWinds Fallout and Shifting CISO Budgets
2021-01-08 20:44

With the budgeting cycles,starting back up again, I think that we're gonna see a lot of investment in cloud security and endpoint security for employee off-site devices and things like that. I'm really curious what the implication there might be for security, because I think that there's going to be a lot of other unprecedented security challenges or issues, as employees go back to work - whether it's companies starting to think about using exposure notification or contact-tracing apps within the workplace - or companies struggling with a hybrid remote/employees working in the office model think.

Ryuk Rakes in $150M in Ransom Payments
2021-01-08 20:19

Joint research released this week from Brian Carter, principal researcher at HYAS, and Vitali Kremez, CEO at Advanced Intelligence, took a the look under the Ryuk hood concerning the business operations of the group. The two were able to trace payments involving 61 Bitcoin deposit addresses attributed to the Ryuk ransomware.

APT Horoscope
2021-01-08 20:19

This delightful essay matches APT hacker groups up with astrological signs. This is me: Capricorn is renowned for its discipline, skilled navigation, and steadfastness. Just like Capricorn, Helix...

NVIDIA Ships Patches for High-Severity Security Flaws
2021-01-08 20:09

A total of six security flaws were patched in the NVIDIA GPU display driver, all of them affecting the kernel mode layer. Also leading to denial of service are the next two flaws addressed with this set of patches, namely CVE‑2021‑1053 and CVE‑2021‑1054, NVIDIA explains in an advisory.

US courts system fears SolarWinds snafu could have let state hackers poke about in sealed case documents
2021-01-08 19:30

The SolarWinds hack exposed sealed US court documents - which could have a serious effect on Western sanctions against state-backed hackers. Infosec journalist Brian Krebs reported a US Courts Administrative Office statement about the impact of the Russian-backed SolarWinds hack, quoting an anonymous source as saying that the agency was "Hit hard".

Twitter permanently suspends Trump's account for fear of violence
2021-01-08 19:12

Twitter has permanently suspended President Trump's account for concerns that Trump's tweets may cause further violence in the United States. After the violent protests of January 6th, 2020, Twitter banned Trump's account for 12 hours to prevent it from being used to incite violence, such as what occurred in the US Capitol building.

Equifax Buys Fraud Prevention Firm Kount in $640 Million Deal
2021-01-08 19:00

Equifax on Friday announced plans to shell out $640 million to acquire Kount, a company that sells e-commerce retail fraud protection. The Atlanta, Ga.-based Equifax said the deal would expand its worldwide footprint in digital identity and fraud prevention solutions.

How to use Dropbox Vault to secure sensitive files
2021-01-08 18:50

You can protect your online files by placing them in a virtual vault secured by a PIN. Those of you who use Dropbox to store files online may be concerned about the security of your cloud-based content. For sensitive files that need an extra layer of protection, Dropbox now offers a vault.