Security News > 2022 > February

Did we learn nothing from Y2K? Why are some coders still stuck on two digit numbers?
2022-02-25 19:59

If you use Mozilla Firefox or any Chromium-based browser, notably Google Chrome or Microsoft Edge, you'll know that the version numbers of these products are currently at 97 and 98 respectively. If you've ever looked at your browser's User-Agent string, you'll know that these version numbers are, by default, transmitted to every web page you visit, as a kind of handy hint to say, "Look who's coming to dinner."

Microsoft Exchange Bugs Exploited by ‘Cuba’ Ransomware Gang
2022-02-25 19:46

The ransomware gang known as "Cuba" is increasingly shifting to exploiting Microsoft Exchange vulnerabilities - including ProxyShell and ProxyLogon - as initial infection vectors, researchers have found. At the time, the FBI noted that the Cuba ransomware is distributed using a first-stage implant that acts as a loader for follow-on payloads: the Hancitor malware, which has been around for at least five years.

As ecosystems get distributed, cybersecurity leadership will need to transform, Gartner says
2022-02-25 19:12

As ecosystems get distributed, cybersecurity leadership will need to transform, Gartner says. Gartner has released a report of recommendations that are pretty big news for cybersecurity leaders: Their jobs, as they exist now, are becoming obsolete.

Ukraine seeks volunteers to defend networks as Russian troops menace Kyiv
2022-02-25 19:07

As the Russian invasion of Ukraine continues, the latter's government is reportedly seeking cybersecurity volunteers to help defend itself. The Russian National Coordination Center for Computer Incidents has issued an advisory warning of "The threat of an increase in the intensity of computer attacks on Russian information resources."

How Russia’s invasion of Ukraine will affect your cybersecurity
2022-02-25 19:02

What sort of attacks should U.S. businesses expect? Kanry said we don't need to look back very far to see an example of the potential havoc state-sponsored cyberattacks can inflict: The Colonial Pipeline attack.

NHS urges orgs to apply security update for Okta Client RCE bug
2022-02-25 18:58

The UK's NHS Digital agency is warning organizations to apply new security updates for a remote code execution vulnerability in the Windows client for the Okta Advanced Server Access authentication management platform. "NHS Digital is the national digital, data and technology delivery partner for the NHS and social care system," explains the website for NHS Digital.

6 Cyber-Defense Steps to Take Now to Protect Your Company
2022-02-25 18:49

Ransomware is getting worse, but Daniel Spicer, chief security officer at Ivanti, offers a checklist for choosing defense solutions to meet the challenge. Invest in an automated platform that enhances visibility into all connected devices and software and provides context into how those assets are being used, so your IT and security teams can make better decisions.

Top 5 things to know about consent phishing
2022-02-25 18:38

Remember when phishing was a funny new term for tricking people into giving up information? Now there are so many variants, spear phishing, clone phishing, and even whaling! Here are five things to know about Consent Phishing.

Visual Voice Mail on Android may be vulnerable to eavesdropping
2022-02-25 17:49

A security analyst has devised a way to capture Visual Voice Mail credentials on Android devices and then remotely listen to voicemail messages without the victim's knowledge. Visual Voice Mail is a voicemail system used by numerous mobile carriers that allow customers to view, listen to, and manage voicemails in any order.

Jester Stealer malware adds more capabilities to entice hackers
2022-02-25 15:45

An infostealing piece of malware called Jester Stealer has been gaining popularity in the underground cybercrime community for its functionality and affordable prices. According to an analysis from Cyble Research, Jester Stealer is an emerging threat that first appeared on cybercrime forums in July 2021.