Security News > 2021

Semperis appoints Guido Grillenmeier as chief technologist
2021-02-11 23:30

Semperis announced the appointment of Guido Grillenmeier as chief technologist. "Guido brings unmatched domain expertise to his role at Semperis. Our global network of customers, partners, and technology alliances will benefit greatly from his appointment to the Semperis leadership team," said Mickey Bresman, CEO of Semperis.

Working at a safe distance, safely: Remote work at industrial sites brings extra cyber risk
2021-02-11 22:46

Giving remote access directly to the engineering workstation for the control system increases cybersecurity risk for an industrial company. There will still be cases where you may want to grant remote access to an engineer to deal with an emergency situation and then revoke the access once the work is done, but if you can limit this access and enable staff to complete their routine work while reducing direct access to the control system, you can minimize the risk of cybersecurity events that could cause safety and environmental incidents.

Iranian Hackers Utilize ScreenConnect to Spy On UAE, Kuwait Government Agencies
2021-02-11 21:33

UAE and Kuwait government agencies are targets of a new cyberespionage campaign potentially carried out by Iranian threat actors, according to new research. Attributing the operation to be the work of Static Kitten, Anomali said the "Objective of this activity is to install a remote management tool called ScreenConnect with unique launch parameters that have custom properties," with malware samples and URLs masquerading as the Ministry of Foreign Affairs of Kuwait and the UAE National Council.

Pre-Valentine’s Day Malware Attack Mimics Flower, Lingerie Stores
2021-02-11 21:32

With Valentine's Day approaching this weekend, several people have received "Recent order" email confirmations for flowers or lingerie. These emails are actually part of a spear-phishing attack, which ultimately leads recipients to a malicious document that executes the BazaLoader malware.

Poor Password Security Led to Recent Water Treatment Facility Hack
2021-02-11 21:32

New details have emerged about the remote computer intrusion at a Florida water treatment facility last Friday, highlighting a lack of adequate security measures needed to bulletproof critical infrastructure environments. The breach involved an unsuccessful attempt on the part of an adversary to increase sodium hydroxide dosage in the water supply to dangerous levels by remotely accessing the SCADA system at the water treatment plant.

Phishing awareness gone wrong: Facebook tries to seize websites set up for staff security training
2021-02-11 20:42

Security biz Proofpoint and its subsidiary Wombat Security Technologies have sued Facebook and its Instagram subsidiary to prevent the seizure of internet domain names used for security testing. It sets up domain names that incorporate trademarked terms, like Facebook and Instagram, or fragments of those terms that have similar looking domain names.

Internet Explorer 11 zero-day vulnerability gets unofficial micropatch
2021-02-11 19:34

An Internet Explorer 11 zero-day vulnerability used against security researchers, not yet fixed by Microsoft, today received a micropatch that prevents exploitation. An MHT file, or MIME HTML, is a special file format used by Internet Explorer to store a web page and its resources in a single archive file.

Internet Explorer 11 zero-day vulnerability gets a free micropatch
2021-02-11 19:34

An Internet Explorer 11 zero-day vulnerability used against security researchers, not yet fixed by Microsoft, today received a micropatch that prevents exploitation. An MHT file, or MIME HTML, is a special file format used by Internet Explorer to store a web page and its resources in a single archive file.

Data Privacy Management Firm WireWheel Raises $20 Million
2021-02-11 19:32

Arlington, Va.-based data privacy management company WireWheel on Wednesday announced that it raised $20 million in a Series B funding round. WireWheel has developed a SaaS privacy platform that can be used by organizations of all sizes.

The Intelligent Edge: An Increasing Target for Bad Actors
2021-02-11 19:24

Each edge environment comes with its own set of unique risks and vulnerabilities, which is why they have become a prime target for cybercriminals, who are shifting significant resources to strategically target and exploit emerging network edge environments. The intelligent edge is widely defined as the combination of advanced wireless connectivity, compact processing power, and AI to analyze and aggregate data in a location as close as possible to where it is captured in a network.