Security News > 2021

Kansas Man Charged with Tampering with Public Water System
2021-04-01 19:29

The United States Department of Justice this week announced official charges against a Kansas man, for accessing and tampering with a public water system. The man, Wyatt A. Travnichek, 22, of Ellsworth County, Kansas, is accused of accessing the computer system of the Ellsworth County Rural Water District without authorization.

After Hack, Officials Draw Attention to Supply Chain Threats
2021-04-01 18:35

The U.S. government is working to draw attention to supply chain vulnerabilities, an issue that received particular attention late last year after suspected Russian hackers gained access to federal agencies and private corporations by sneaking malicious code into widely used software. The NCSC said it is working with other agencies, including the Cybersecurity and Infrastructure Security Agency, to raise awareness of the supply chain issue.

S3 Ep26: Apple 0-day, crypto vulnerabilities and PHP backdoor [Podcast]
2021-04-01 18:31

Why Apple had to rush out a security update for iDevices. Two cryptographic security holes patched in OpenSSL. How PHP nearly got backdoored by crooks.

US DOJ: Phishing attacks use vaccine surveys to steal personal info
2021-04-01 18:15

The US Department of Justice warns of phishing attacks using fake post-vaccine surveys to steal money from people or tricking them into handing over their personal information. "Consumers receive the surveys via email and text message and are told that, as a gift for filling out the survey, they can choose from various free prizes, such as an iPad Pro," the DOJ said.

Ragnarok Ransomware Hits Boggi Milano Menswear
2021-04-01 18:07

Luxury Italian men's clothing line Boggi Milano has confirmed what Ragnarok was already bragging about on the Dark Web: The brand was hit with a ransomware attack, according to multiple sources. Ragnarok and Boggi Milano representatives who spoke to Bloomberg agree on the facts; the ransomware attack exfiltrated 40 gigabytes of data, including human resources files and salary information.

Molson Coors Cyberattack, Storms Could Cost Company $140 Million
2021-04-01 17:58

Brewing giant Molson Coors said that a disruptive cyberattack, combined with winter storms in Texas, could cost the company upwards of $140 million in short-term EBITDA. The maker of popular beer brands in the U.S., including Coors Light, Miller Lite, Molson Canadian, Blue Moon, Carling, Coors Banquet, and others, revealed on March 11 that a cyberattack severely disrupted several parts of its business, including brewery operations, production, and shipments. "Despite this progress led by the significant efforts of the Molson Coors team, along with the support of leading forensic information technology firms and other advisors, the Company has experienced and continues to experience some delays and disruptions in its business, including brewery operations, production and shipments in the U.K., Canada and the U.S.," a March 26 statement said.

Coinhive domain repurposed to warn visitors of hacked sites, routers
2021-04-01 17:24

After taking over the domains for the notorious Coinhive in-browsing Monero mining service, a researcher is now displaying alerts on hacked websites that are still injecting the mining service's JavaScript. Two years later, CoinHive is still injected on sites.

VMware fixes authentication bypass in data center security software
2021-04-01 16:58

VMware has addressed a critical vulnerability in the VMware Carbon Black Cloud Workload appliance that could allow attackers to bypass authentication after exploiting vulnerable servers. VMware Carbon Black Cloud Workload is a Linux data center security software designed to protect workloads running in virtualized environments.

How financial cybercrime targets shifted in 2020
2021-04-01 16:51

Alongside shifts in what types of financial institutions were being targeted, Kaspersky also noticed regional malware actors going global and advanced persistent threats that aren't normally involved in financial crimes broadening their horizons to include such acts in 2020. In terms of specific numbers, Kaspersky noticed a slight decline in the number of users hit by phishing attacks in 2020, with only 13.21% being targeted, compared to 15.7% in 2019.

Building a Fortress: 3 Key Strategies for Optimized IT Security
2021-04-01 16:22

Knowing just how vulnerable many companies are to organized malicious actors, IT teams are re-evaluating their shortcomings and processes when it comes to building their organizations' security infrastructure. Here are the three strategies that IT teams should prioritize going forward: Zero-trust approaches; patching; and automation.