Security News > 2021

General Says Attacks by Foreign Hackers Are 'Clarion Call'
2021-03-26 10:59

The U.S. Cyber Command conducted more than two dozen operations aimed at thwarting interference in last November's presidential election, the general who leads the Pentagon's cyber force said Thursday. Nakasone's appearance before the committee came as the U.S. deals with major cyber intrusions, including a breach by elite Russian hackers that exploited supply chain vulnerabilities to break into the networks of federal government agencies and private companies.

Critical Flaw in Jabber for Windows Could Lead to Code Execution
2021-03-26 09:05

Cisco this week announced the release of software updates that address several vulnerabilities in Jabber for desktop and mobile platforms, the most severe of which could be abused to execute arbitrary code with elevated privileges. The bugs impact Cisco Jabber for Windows, macOS, and mobile platforms, and are not dependable to one another.

OpenSSL Releases Patches for 2 High-Severity Security Vulnerabilities
2021-03-26 07:56

The maintainers of OpenSSL have released a fix for two high-severity security flaws in its software that could be exploited to carry out denial-of-service attacks and bypass certificate verification. While CVE-2021-3449 affects all OpenSSL 1.1.1 versions, CVE-2021-3450 impacts OpenSSL versions 1.1.1h and newer.

FBI exposes weakness in Mamba ransomware, DiskCryptor
2021-03-26 07:30

The FBI warns that Mamba ransomware attacks have been directed at entities in the public and private sector, including local governments, transportation agencies, legal services, technology services, industrial, commercial, manufacturing, and construction businesses. Mamba ransomware relies on an open-source software solution named DiskCryptor to encrypt victim computers in the background with a key defined by the attacker.

New infosec products of the week: March 26, 2021
2021-03-26 06:30

Magic WAN with Magic Firewall gives customers of all sizes a one-stop-shop to connect and secure data, devices, offices, cloud networks, and more without relying on hardware boxes. Magic WAN is a SaaS solution that connects any traffic source to Cloudflare's global network for secure, fast connectivity, and Magic Firewall integrates with it to enforce security rules across all traffic.

70% of organizations recognize the importance of secure coding practices
2021-03-26 06:00

A research from Secure Code Warrior has revealed an attitudinal shift in the software development industry, with organizations bucking traditional practices for DevOps and Secure DevOps. The global survey of professional developers and their managers found 70% of organizations recognize the importance of secure coding practices, with results indicating an industry-wide shift from reaction to prevention is underway.

The war against the virus also fueling a war against digital fraud
2021-03-26 05:30

TransUnion's latest analysis of global online fraud trends found that since the COVID-19 pandemic began, fraudsters are increasing their rate of digital schemes against businesses. A recent study found that more than one in three global consumers have recently been targeted by digital fraud related to COVID-19.

Attack volume surged by 48% during the first year of the pandemic
2021-03-26 05:00

A Mimecast report details how threat actors targeted remote workers during the first year of the pandemic, March 2020 - February 2021. The report describes how attack volume surged by 48% during the first year of the pandemic, with sudden increases in volume corresponding to spikes in COVID-19 infection rates in April and October 2020.

Financial services and insurance faring better than most in the pandemic year
2021-03-26 04:30

While 2020 was one of the most challenging years for every business, those in financial services and insurance have fared better than most. While 74% of organizations across all sectors have now introduced DevOps, for example, this rises to 81% in financial services and 84% in insurance.

With more than 400,000 crypto scams created in 2020, increase of 75% predicted for 2021
2021-03-26 04:00

The findings of a Bolster report, along with real life examples, clearly correlate the rise in crypto scams to the value and popularity of cryptocurrencies as well as the increase in individuals seeking financial assistance during the COVID-19 pandemic. With more than 400,000 crypto scams created in 2020, there was a 40 percent increase compared to 2019.