Security News > 2021

S3 Ep14: Money scams, HTTPS by default, and hardcoded passwords [Podcast]
2021-01-07 19:26

We advise you how to react when a friend suddenly asks for money, explain why Chromium is finally aiming for HTTPS by default, and warn you why you should never, ever hardcode passwords into your software. WHERE TO FIND THE PODCAST ONLINE. You can listen to us on Soundcloud, Apple Podcasts, Google Podcasts, Spotify, Stitcher, Overcast and anywhere that good podcasts are found.

Ryuk ransomware Bitcoin wallets point to $150 million operation
2021-01-07 19:17

Security researchers following the money circuit from Ryuk ransomware victims into the threat actor's pockets estimate that the criminal organization made at least $150 million. Threat intelligence companies Advanced Intelligence and HYAS tracked 61 Bitcoin wallets attributed to the Ryuk malware enterprise and discovered that the cryptocurrency moves from an intermediary to Huobi and Binance exchanges.

How to quickly check to see if your Linux server is under a DoS attack from a single IP address
2021-01-07 19:03

Jack Wallen shows you an easy way to determine if your Linux server is under a DDoS attack and how to quickly stop it. How? In this piece I'm going to show you a few commands that can help you discern if your server is being hit by a denial of service attack, which comes from a single IP address and attempts to cripple a website to render its server inaccessible.

Ezuri Memory Loader Abused in Linux Attacks
2021-01-07 19:01

Security researchers at AT&T's Alien Labs have identified multiple malware attacks leveraging the Ezuri memory loader to execute payloads without writing them to disk. Executed directly in memory, without leaving traces on disk, fileless malware is commonly used in attacks targeting Windows systems, but isn't often seen in malware attacks targeting Linux.

Managed Intelligence Firm Nisos Raises $6 Million
2021-01-07 18:43

Virginia-based managed intelligence company Nisos announced this week that it raised $6 million in a new funding round. Nisos previously raised $6.1 million from Columbia Capital, a funding round that was announced in early 2019.

Threatpost Poll: Weigh in on Ransomware Security
2021-01-07 18:34

It's no secret that ransomware attacks continue to rise - with the number of attacks jumping by 350 percent since 2018. Healthcare systems have been hit particularly hard over the past year by ransomware actors, with a recent report saying that healthcare organizations have seen a 45 percent increase in cyberattacks since November.

New Year, New Ransomware: Babuk Locker Targets Large Corporations
2021-01-07 18:08

Only a few days into the new year, one of the first new ransomware strains of 2021 has been discovered. Dubbed Babuk Locker, the ransomware appears to have successfully compromised five companies thus far, according to new research.

Hacker sells Aurora Cannabis files stolen in Christmas cyberattack
2021-01-07 17:29

A hacker is selling the data stolen from cannabis giant Aurora Cannabis after breaching their systems on Christmas day. Aurora Cannabis is a Canadian cannabis producer listed on both the Toronto Stock Exchange and the New York Stock Exchange.

Perseverance. Pushing Security Operations Forward in 2021
2021-01-07 15:55

How we have persevered has evolved through the years, and now we have the capacity to reach new levels of security operations maturity. Over the past few years, we've seen a movement towards the construct of a single security architecture to accelerate detection and response.

Lacework Banks $525 Million as Cloud Security Market Heats Up
2021-01-07 15:52

Lacework, a five-year-old cybersecurity company that automates security across enterprise cloud deployments, has reached unicorn status with the closing of a $525 million round of Series D financing. The Silicon Valley company, which automates security across public and private cloud deployments, is now valued north of $1 billion.