Security News > 2021 > December

Major trends in online identity verification for 2022
2021-12-03 06:30

Technology is still one step ahead. While some trends may seem bleak, there are straightforward and convenient ways to thwart identity thieves. More companies will adopt stronger identity verification methods to combat continued data leaks.

Tor2Mine cryptominer has evolved: Just patching and cleaning the system won’t help
2021-12-03 06:00

Sophos released new findings on the Tor2Mine cryptominer, that show how the miner evades detection, spreads automatically through a target network and is increasingly harder to remove from an infected system. In the research, Sophos describes new variants of the miner that include a PowerShell script that attempts to disable malware protection, execute the miner payload and steal Windows administrator credentials.

Researchers Detail How Pakistani Hackers Targeting Indian and Afghan Governments
2021-12-03 05:54

A Pakistani threat actor successfully socially engineered a number of ministries in Afghanistan and a shared government computer in India to steal sensitive Google, Twitter, and Facebook credentials from its targets and stealthily obtain access to government portals. Malwarebytes' latest findings go into detail about the new tactics and tools adopted by the APT group known as SideCopy, which is so-called because of its attempts to mimic the infection chains associated with another group tracked as SideWinder and mislead attribution.

CISA Warns of Actively Exploited Critical Zoho ManageEngine ServiceDesk Vulnerability
2021-12-03 05:34

The U.S. Federal Bureau of Investigation and the Cybersecurity and Infrastructure Security Agency are warning of active exploitation of a newly patched flaw in Zoho's ManageEngine ServiceDesk Plus product to deploy web shells and carry out an array of malicious activities.Tracked as CVE-2021-44077, the issue relates to an unauthenticated, remote code execution vulnerability affecting ServiceDesk Plus versions up to, and including, 11305 that if left unfixed "Allows an attacker to upload executable files and place web shells that enable post-exploitation activities, such as compromising administrator credentials, conducting lateral movement, and exfiltrating registry hives and Active Directory files," CISA said.

Phishing kits’ favorite brand? Amazon
2021-12-03 05:30

Research conducted by Egress and Orpheus Cyber has revealed a surge in phishing kits imitating major brands in the lead up to Black Friday, as security experts warn that cybercriminals are stepping up their phishing attacks over the holiday shopping season. Amazon was a popular choice for cybercriminals, with a 334.1% increase in phishing kits impersonating the brand ahead of its anticipated Black Friday promotions.

Top tech trends for 2022
2021-12-03 05:00

Info-Tech Research Group has revealed its annual top tech trends insights for the coming year, based on insights from 475 IT professionals who participated in an industry survey, exploring how ripple effects from the pandemic will impact the evolving digital economy in 2022. Five tech trends identified for 2022 Hybrid collaboration - IT leaders will have an opportunity to lead hybrid work by facilitating collaboration between virtual and onsite employees for a digital employee experience that is flexible, contextual, and free from the friction of current hybrid operating models.

Enterprises are embracing the multicloud, turning to providers for strategy
2021-12-03 04:30

Enterprises in the U.S. are increasingly embracing multicloud operating models and are looking to cloud service providers to help them choose the right clouds for the right workloads, according to a report published by Information Services Group. Today, enterprises are running on multiple clouds that need to be interconnected, integrated and managed, and they are turning to providers for help.

SMS firewall revenue to reach $4.1 billion in 2026
2021-12-03 04:00

Total SMS firewall revenue will increase from $911 million in 2021 to $4.1 billion in 2026; representing an absolute growth of 346%, a Juniper Research study has found. SMS firewalls are third-party solutions that sit within operator networks; enabling the real-time monitoring of network traffic, enhancing operator capabilities to block fraudulent traffic and minimise revenue loss.

CleanMyMac X: Performance and Security Software for Macbook
2021-12-03 01:42

If you are worried about your Macbook's performance and security, including unwanted software, ransomware, or phishing emails, CleanMyMac X software has you covered. CleanMyMac is all-in-all software to optimize your Mac's performance and security.

New Payment Data Stealing Malware Hides in Nginx Process on Linux Servers
2021-12-03 01:34

E-commerce platforms in the U.S., Germany, and France have come under attack from a new form of malware that targets Nginx servers in an attempt to masquerade its presence and slip past detection by security solutions. "This novel code injects itself into a host Nginx application and is nearly invisible," Sansec Threat Research team said in a new report.