Security News > 2021 > June

Microsoft Signs Malware That Spreads Through Gaming
2021-06-28 16:36

Microsoft signed a driver being distributed within gaming environments that turned out to be a malicious network filter rootkit. G DATA malware analyst Karsten Hahn first noticed the rootkit, publicly posting the find on June 17 and simultaneously reaching out to Microsoft.

Like Their Adversaries, Threat Hunters Need Anonymity
2021-06-28 16:16

How can we be sure that threat hunters stay safe, and don't themselves become a threat to the systems they protect? Conducting threat intelligence and incident response from unsecure locations can expose threat hunters to discovery by the very hackers they are chasing and opens up technical, legal and governance challenges.

Critical CISO Initiatives for the Second Half of 2021
2021-06-28 16:00

How are you dynamically provisioning access for temporary workers? How are you managing privileged access? The challenges in terms of risky account discovery and clean-up, risk-based access certifications, as well as risk-based authentication has become a critical area for our customers. The next critical customer goal is around detecting and preventing insider threats.

Leaked Windows 11 screenshots show new File Explorer, Settings app
2021-06-28 14:28

Leaked screenshots of an internal Microsoft build of Windows 11 have given us a glimpse of the upcoming changes coming to File Explorer and the Settings app. The screenshots of the new features were leaked this morning on Twitter, allowing us to see some of the latest Windows 11 features not present in the early preview build leaked earlier this month.

Mercedes-Benz USA Says Vendor Exposed Customer Information
2021-06-28 14:02

Mercedes-Benz USA said last week that sensitive personal information pertaining to its customers was inadvertently exposed by a vendor. This information includes self-reported credit scores, along with a small number of credit card details, dates of birth, driver license numbers, and social security numbers.

Android: How to enable the Password Checkup feature
2021-06-28 14:00

Google has released a new password checker for Android. Find out how to enable and use this security feature on your Android device.

GitHub Paid Out Over $1.5 Million via Bug Bounty Program Since 2016
2021-06-28 12:42

Microsoft-owned software development solutions provider GitHub announced on Friday that it has paid out more than $1.5 million through its bug bounty program since 2016, when it started using the HackerOne bug bounty platform. According to the company, in 2020, it paid out over half a million dollars for more than 200 vulnerabilities affecting its products and services.

Cybersecurity study: SolarWinds attack cost affected US companies an average of $12 million
2021-06-28 12:00

New survey finds that the attack also motivated more information sharing within the industry and improved supply chain security. The good news is that security teams are beefing up network defenses, but the bad news is that most companies have recently suffered a cybersecurity incident that required a board meeting.

NFC Flaws in POS Devices and ATMs
2021-06-28 11:53

Josep Rodriguez, a researcher and consultant at security firm IOActive, has spent the last year digging up and reporting vulnerabilities in the so-called near-field communications reader chips used in millions of ATMs and point-of-sale systems worldwide. NFC systems are what let you wave a credit card over a reader - rather than swipe or insert it - to make a payment or extract money from a cash machine.

Microsoft: SolarWinds Hackers Continue to Target IT Companies
2021-06-28 11:50

Microsoft says it has observed new activity associated with Nobelium, the Russia-linked threat actor that compromised IT management and monitoring solutions provider SolarWinds. The SolarWinds attack was brought to light in early December 2020 and it involved compromising SolarWinds' Orion monitoring product to deliver trojanized updates to the company's customers worldwide, in an effort to breach their networks.