Security News > 2022 > January

FluBot malware now targets Europe posing as Flash Player app
2022-01-07 17:37

The widely distributed FluBot malware continues to evolve, with new campaigns distributing the malware as Flash Player and the developers adding new features. Once in the device, FluBot can steal online banking credentials, send or intercept SMS messages, and capture screenshots.

Norton 360 wants to pay you a pittance to mine Ethereum cryptocurrency
2022-01-07 17:05

Cybersecurity software company NortonLifeLock is coming under fire for its decision late last year to begin installing Ethereum mining software on its Norton 360 customers' PCs without their permission or knowledge. Norton Crypto, the new Norton 360 mining component, isn't enabled without the user opting in, but that hasn't stopped users from taking to Norton's Crypto forum to register their discontent, and they aren't all upset about the sneaky installation.

Diversity job board Canvas.com ordered to stop using domain name
2022-01-07 16:52

Learning management platform Instructure claims the domain name Canvas.com and its logo contain elements that conflict with Instructure's Canvas product and line of business. Court documents seen by Domain Name Wire reveal, over subsequent years, Instructure's product capabilities expanded to allow users to showcase their resumes, professional references, and keep tabs on companies as well as new job openings.

US counterintelligence shares tips to block spyware attacks
2022-01-07 16:22

The US National Counterintelligence and Security Center and the Department of State have jointly published guidance on defending against attacks using commercial surveillance tools. Tips shared in the joint advisory are designed to help people at risk of being targeted by surveillance campaigns block attempts to track their location, record their conversations, and harvest their personal information and online activity using mercenary spyware deployed on their mobile devices.

QNAP: Get NAS Devices Off the Internet Now
2022-01-07 16:14

Get your internet-exposed, network-attached storage devices off the internet now, Taiwanese manufacturer QNAP warns: Ransomware and brute-force attacks are widely targeting all network devices. "The most vulnerable victims will be those devices exposed to the Internet without any protection," QNAP said on Friday, urging all QNAP NAS users to follow security-setting instructions that the Taiwanese NAS maker included in its alert.

Log4J-Related RCE Flaw in H2 Database Earns Critical Rating
2022-01-07 15:12

Researchers discovered a bug related to the Log4J logging library vulnerability, which in this case opens the door for an adversary to execute remote code on vulnerable systems. JFrog security discovered the flaw and rated critical in the context of the H2 Java database console, a popular open-source database, according to a Thursday blog post by researchers.

NHS warns of hackers exploiting Log4Shell in VMware Horizon
2022-01-07 14:29

UK's National Health Service has published a cyber alert warning of an unknown threat group targeting VMware Horizon deployments with Log4Shell exploits. According to the NHS notice, the actor is leveraging the exploit to achieve remote code execution on vulnerable VMware Horizon deployments on public infrastructure.

QNAP warns of ransomware targeting Internet-exposed NAS devices
2022-01-07 13:20

QNAP has warned customers today to secure Internet-exposed network-attached storage devices immediately from ongoing ransomware and brute-force attacks. "QNAP urges all QNAP NAS users to follow the security setting instructions below to ensure the security of QNAP networking devices," the Taiwanese NAS maker said in a press release issued today.

Norton’s Antivirus Product Now Includes an Ethereum Miner
2022-01-07 12:13

Norton 360 can now mine Ethereum. It’s opt-in, and the company keeps 15%. It’s hard to uninstall this option.

Salesforce mandates MFA by default
2022-01-07 07:30

This change has profound implications: customers unable to implement MFA across their access by the set date can continue to use Salesforce without MFA at their own risk. Thales statistics suggest that 90 per cent of cyberattacks utilise compromised credentials in some way, which if correct implies that failing to implement MFA on Salesforce is potentially shifting responsibility for almost all cyberattacks involving the service.