Security News > 2021

SpamCop anti-spam service suffers an outage after its domain expired
2021-01-31 23:29

Cisco's SpamCop anti-spam service suffered an outage Sunday after its domain was mistakenly allowed to expire. SpamCop provides a Real-time Blackhole List that mail servers can use to determine if incoming mail should be considered spam.

European Authorities Disrupt Emotet — World's Most Dangerous Malware
2021-01-31 21:16

Law enforcement agencies from as many as eight countries dismantled the infrastructure of Emotet, a notorious email-based Windows malware behind several botnet-driven spam campaigns and ransomware attacks over the past decade. "What made Emotet so dangerous is that the malware was offered for hire to other cybercriminals to install other types of malware, such as banking Trojans or ransomware, onto a victim's computer."

Experts Detail A Recent Remotely Exploitable Windows Vulnerability
2021-01-31 21:10

"This vulnerability allows an attacker to relay NTLM authentication sessions to an attacked machine, and use a printer spooler MSRPC interface to remotely execute code on the attacked machine," the researchers said in a Friday advisory. NTLM relay attacks are a kind of man-in-the-middle attacks that typically permit attackers with access to a network to intercept legitimate authentication traffic between a client and a server and relay these validated authentication requests in order to access network services.

Google uncovers new iOS security feature Apple quietly added after zero-day attacks
2021-01-31 21:06

Google Project Zero on Thursday disclosed details of a new security mechanism that Apple quietly added to iOS 14 as a countermeasure to prevent attacks that were recently found to leverage zero-days in its messaging app. Dubbed "BlastDoor," the improved sandbox system for iMessage data was disclosed by Samuel Groß, a Google Project Zero researcher tasked with studying zero-day vulnerabilities in hardware and software systems.

Windows 10 features that boost your PC's security and privacy
2021-01-31 18:15

Like almost all operating systems, Windows 10 is vulnerable to security and privacy issues, and researchers have proved that Microsoft can track a lot of your activities to improve their products and enable personalized ads and promotions. Thankfully, Windows 10 allows us to improve the operating system's security and privacy using the built-in settings app.

OT Cybersecurity Firm Mission Secure Raises $5.6 Million in Series B Funding
2021-01-31 11:57

Mission Secure, a provider of visibility and cybersecurity solutions for industrial environments, announced this week that it has closed a Series B financing round in the amount of $5.6 million. The company raised its first outside funding through a seed round in late 2014, and has consistently added funding over the years, with the total amount raised by the company now at $22.5 million.

Week in review: Sudo vulnerability, Emotet takedown, execs targeted with Office 365 phishing
2021-01-31 08:55

"Serious" vulnerability found in Libgcrypt, GnuPG's cryptographic libraryLibgcrypt 1.9.0, the newest version of a cryptographic library integrated in the GNU Privacy Guard free encryption software, has a "Severe" security vulnerability and should not be used, warned Werner Koch. Sudo vulnerability allows attackers to gain root privileges on Linux systemsA vulnerability in sudo, a powerful and near-ubiquitous open-source utility used on major Linux and Unix-like operating systems, could allow any unprivileged local user to gain root privileges on a vulnerable host.

GnuPG crypto library can be pwned during decryption – patch now!
2021-01-31 02:12

Bug hunter Tavis Ormandy of Google's Project Zero just discovered a dangerous bug in the GNU Privacy Guard team's libgcrypt encryption software. The libgcrypt library is an open-source toolkit that anyone can use, but it's probably best known as the encryption library used by the GNU Privacy Guard team's own widely deployed GnuPG software.

Beware: Malicious Home Depot ad gets top spot in Google Search
2021-01-30 17:49

A malicious Home Depot advertising campaign is redirect Google search visitors to tech support scams. Malicious Google search ads are nothing new, with campaigns for Amazon Prime, PayPal, and eBay seen in the past.

UK Research and Innovation (UKRI) suffers ransomware attack
2021-01-30 15:12

The UK Research and Innovation is dealing with a ransomware incident that encrypted data and impacted two of its services, one offering information to subscribers and the platform for peer review of various parts of the agency. UKRI is a public body of the Government of the United Kingdom, tasked with investing in science and research.