Security News > 2022 > June

Review: System Mechanic Ultimate Defense
2022-06-16 22:04

For this review, I tried out System Mechanic Ultimate Defense. After installing the product, System Mechanic hits the ground running upon first launch by offering to analyze your system to see what issues it can find and fix.

RSAC branded a 'super spreader event' as attendees share COVID-19 test results
2022-06-16 21:56

Quick show of hands: who came home from this year's RSA Conference without COVID-19? RSA Conference organizers required all attendees to show proof of vaccination or a negative test for their first entry into Moscone Center.

iCloud hacker gets 9 years in prison for stealing nude photos
2022-06-16 21:51

A California man who hacked thousands of Apple iCloud accounts was sentenced to 8 years in prison after pleading guilty to conspiracy and computer fraud in October 2021. Starting from as early as September 2014, 41-year-old Hao Kuo Chi from La Puente, California, started marketing himself as "Icloudripper4you," someone capable of breaching iCloud accounts and stealing anything contained in the linked iCloud storage.

New MaliBot Android banking malware spreads as a crypto miner
2022-06-16 19:43

Cybersecurity researchers have discovered a new Android banking malware named MaliBot, which poses as a cryptocurrency mining app or the Chrome web browser to target users in Italy and Spain. MaliBot focuses on stealing financial information such as e-banking service credentials, crypto wallet passwords, and personal details, while it's also capable of snatching two-factor authentication codes from notifications.

BlackCat Ransomware Gang Targeting Unpatched Microsoft Exchange Servers
2022-06-16 19:32

Microsoft is warning that the BlackCat ransomware crew is leveraging exploits for unpatched Exchange server vulnerabilities to gain access to targeted networks. Upon gaining an entry point, the attackers swiftly moved to gather information about the compromised machines, followed by carrying out credential theft and lateral movement activities, before harvesting intellectual property and dropping the ransomware payload. The entire sequence of events played out over the course of two full weeks, the Microsoft 365 Defender Threat Intelligence Team said in a report published this week.

MaliBot: A New Android Banking Trojan Spotted in the Wild
2022-06-16 19:32

A new strain of Android malware has been spotted in the wild targeting online banking and cryptocurrency wallet customers in Spain and Italy, just weeks after a coordinated law enforcement operation dismantled FluBot. The information stealing trojan, codenamed MaliBot by F5 Labs, is as feature-rich as its counterparts, allowing it to steal credentials and cookies, bypass multi-factor authentication codes, and abuse Android's Accessibility Service to monitor the victim's device screen.

730K WordPress sites force-updated to patch critical plugin bug
2022-06-16 18:58

WordPress sites using Ninja Forms, a forms builder plugin with more than 1 million installations, have been force-updated en masse this week to a new build that addresses a critical security vulnerability likely exploited in the wild. If the plugin hasn't yet been updated automatically to the patched version, you can also manually apply the security update from the dashboard.

Anker Eufy smart home hubs exposed to RCE attacks by critical flaw
2022-06-16 17:38

Anker's central smart home device hub, Eufy Homebase 2, was vulnerable to three vulnerabilities, one of which is a critical remote code execution flaw. Homebase 2 is the video storage and networking gateway for all Anker's Eufy smart home devices, including video doorbells, indoor security cameras, smart locks, alarm systems, and more.

‘Potentially dangerous’ Office 365 flaw discovered
2022-06-16 15:44

Security firm Proofpoint has uncovered what it calls a "Potentially dangerous piece of functionality" in Microsoft Office 365 that allows ransomware to encrypt files stored on SharePoint and OneDrive in a way that renders them unrecoverable without dedicated backups or a decryption key from the attacker. Monetization: Now all original versions of the files are lost, leaving only the encrypted versions of each file in the cloud account.

New cloud-based Microsoft Defender for home now generally available
2022-06-16 15:14

Microsoft has announced today the general availability of Microsoft Defender for Individuals, the company's new security solution for personal phones and computers. This new cross-device security solution is available for all Microsoft 365 customers with Personal or Family subscriptions starting today.