Security News > 2021 > May

Pakistan-Linked Hackers Added New Windows Malware to Its Arsenal
2021-05-15 01:13

Cybercriminals with suspected ties to Pakistan continue to rely on social engineering as a crucial component of its operations as part of an evolving espionage campaign against Indian targets, according to new research. The attacks have been linked to a group called Transparent Tribe, also known as Operation C-Major, APT36, and Mythic Leopard, which has created fraudulent domains mimicking legitimate Indian military and defense organizations, and other fake domains posing as file-sharing sites to host malicious artifacts.

Colonial Pipeline Paid Nearly $5 Million in Ransom to Cybercriminals
2021-05-15 01:12

Colonial Pipeline on Thursday restored operations to its entire pipeline system nearly a week following a ransomware infection targeting its IT systems, forcing it to reportedly shell out nearly $5 million to restore control of its computer networks. "Some markets served by Colonial Pipeline may experience, or continue to experience, intermittent service interruptions during this start-up period. Colonial will move as much gasoline, diesel, and jet fuel as is safely possible and will continue to do so until markets return to normal."

RidgeBot 3.4: Allowing users to validate security risks in their internal networks
2021-05-15 01:00

Ridge Security announces new capabilities in RidgeBot 3.4, for post-exploitation validation. Post-exploitation operations are advanced hacking techniques, often utilized by an APT attacks, including the notorious DarkSide hacker group that recently targeted the Colonial Pipeline.

ChaosSearch expands its Data Lake Platform to deliver data insights at scale
2021-05-15 00:30

ChaosSearch has expanded its log analytics Data Lake Platform to deliver multi-model and multi-cloud data lake for cost effective analytics and business intelligence at scale. For business analytics, each new use case requires weeks or even months to set up; data is kept in silos limiting its usefulness to data consumers; data is stored with limited retention; and the need to migrate and manipulate data creates significant cost and compliance risks.

TP-Link introduces four smart home solutions for 24/7 whole-home security and control
2021-05-15 00:00

TP-Link introduced the Kasa Spot, 24/7 Recording and the Kasa Spot Pan Tilt, 24/7 Recording security cameras, offering crystal clear 2K HD video with secure local storage for continuous recording. TP-Link also introduced the Kasa Smart Wi-Fi Mini Plug and Kasa Smart Wi-Fi Outdoor Plug, a pair of refreshed smart plug solutions for whole-home automation with remote and voice control of any appliance.

New Relic promotes Bill Staples to CEO
2021-05-14 22:30

New Relic announced the promotion of Bill Staples to CEO effective July 1, 2021. "When we recruited Bill into the company, we thought that he would be the natural successor to me as CEO at the right time," said Lew Cirne, founder & CEO at New Relic.

Friday Squid Blogging: Far Side Squid Comic
2021-05-14 21:06

"Cellebrite's products are part of the industry of"mobile device forensics" tools. Cellebrite holds itself out as meeting the standards that U.S. courts require for digital forensics.

Ransomware ads now also banned on Exploit cybercrime forum
2021-05-14 20:51

The team behind Exploit, a major cybercrime forum used by ransomware gangs to hire affiliates and advertise their Ransomware-as-a-Service services, has announced that ransomware ads are now banned and will be removed. The move follows the announcement made by the XSS Russian-speaking hacking forum yesterday about ransomware topics being permanently banned.

Apple AirTag hacked again – free internet with no mobile data plan!
2021-05-14 20:08

The owner of the AirTag that called home can decrypt the location in the Find My message, but has no idea which relay device passed the message on. By limiting the length of the hidden message and repeating the same Bluetooth "Public keys" over and over again, Bräunlein's hope was that eventually a complete copy of all the data packets containing the hidden data might make it to Apple.

The Week in Ransomware - May 14th 2021 - One down, many more to go
2021-05-14 18:39

Largest U.S. pipeline shuts down operations after ransomware attack. Colonial Pipeline, the largest fuel pipeline in the United States, has shut down operations after suffering what is reported to be a ransomware attack.