Security News > 2022 > January

‘Elephant Beetle’ spends months in victim networks to divert transactions
2022-01-05 13:00

The actors inject fraudulent transactions into the network and steal small amounts over long periods, leading to an overall theft of millions of dollars. The actors need to conduct long-term surveillance and research, so the next primary goal is to remain undetected for several months.

More Russian Cyber Operations against Ukraine
2022-01-05 12:12

Both Russia and Ukraine are preparing for military operations in cyberspace.

Windows giant seeks Pluton-ic relationship with chipmaker: AMD first out of the gates with Microsoft's security processor
2022-01-05 12:11

The RPG Greetings, traveller, and welcome back to The Register Plays Games, our monthly gaming column. In terms of quality at the point of release, Halo Infinite has stepped out as the clear winner.

Microsoft code-sign check bypassed to drop Zloader malware
2022-01-05 11:00

A new Zloader campaign exploits Microsoft's digital signature verification to deploy malware payloads and steal user credentials from thousands of victims from 111 countries. Zloader is a banking malware first spotted back in 2015 that can steal account credentials and various types of sensitive private information from infiltrated systems.

How can SMBs extend their SecOps capabilities without adding headcount?
2022-01-05 09:01

There is an alternative way for procuring security expertise: by retaining the services of managed security service providers and managed detection and response providers. MSSPs usually assist organizations' IT departments in managing the IT infrastructure and keeping it secure by managing security equipment/systems, monitoring security logs, supervising patch management, and similar preventative security measures.

How ransomware gangs went pro
2022-01-05 08:30

Cybercriminal groups started deploying post-intrusion ransomware in 2015, which involved human attackers gaining initial access to the system and moving laterally through the organization until it found the appropriate target. Attack groups have repeatedly upped the ante, evolving with JavaScript-based ransomware and fileless attacks.

SMBs should consider new approaches for increasing their cybersecurity posture
2022-01-05 06:30

SMBs can obtain advice about cybersecurity quite easily from a plethora of resources. Extreme risks shouldn't be left unaddressed, because cyberattacks against SMBs are too common and attackers still successfully exploit human weaknesses, primarily via email.

API security: Understanding the next top attack vector
2022-01-05 06:00

While traditional application security controls remain necessary, they are not quite up to the API security challenge. There are certain basic API security practices organizations can implement to create a more resilient API security posture.

How companies manage data and AI initiatives
2022-01-05 04:30

In the Foreword to this year's survey, NewVantage Partners CEO Randy Bean, and Thomas H. Davenport, a Fellow with the firm, write "The ten years of the survey provide a useful measure of progress-or the lack thereof in some respects-in how companies are managing these important initiatives. From 2012 to 2022 the survey has assessed the initiatives that large companies are focused on, where they are investing and the returns they are getting, the roles assigned to manage data, and the issues that cause significant challenges." The state of data and AI initiatives Investment in data and AI initiatives continues to grow as efforts deliver measurable results.

#AI
Embedded hypervisor software market to reach $1.16 billion by 2026
2022-01-05 04:00

36% of the growth will originate from APAC for the embedded hypervisor software market. China and Japan are the key markets for embedded hypervisor software in APAC. Market growth in APAC will be faster than the growth of the market in other regions.