Security News > 2022 > December

What Developers Need to Fight the Battle Against Common Vulnerabilities
2022-12-01 11:13

It's becoming apparent that while cybersecurity platforms and defenses are critical components in defense against modern attacks, what is truly needed is secure code that can be deployed free from vulnerabilities. Many developers say they are willing to champion security and commit to higher standards of code quality and secure output, but they can't do it alone.

Twenty years on, command-line virus scanner ClamAV puts out version 1
2022-12-01 10:51

The ClamAV command-line virus scanner used on many Linux boxes has attained an important-looking milestone release: version 1.0.0. It's not really the first finished version, of course.

Schoolyard Bully Trojan Apps Stole Facebook Credentials from Over 300,000 Android Users
2022-12-01 10:07

More than 300,000 users across 71 countries have been victimized by a new Android threat campaign called the Schoolyard Bully Trojan. Mainly designed to steal Facebook credentials, the malware is camouflaged as legitimate education-themed applications to lure unsuspecting users into downloading them.

Schoolyard Bully Trojan Apps Stole Facebook Credentials from Over 300,000 Android Users
2022-12-01 10:07

More than 300,000 users across 71 countries have been victimized by a new Android threat campaign called the Schoolyard Bully Trojan. Mainly designed to steal Facebook credentials, the malware is camouflaged as legitimate education-themed applications to lure unsuspecting users into downloading them.

Researchers 'Accidentally’ Crash KmsdBot Cryptocurrency Mining Botnet Network
2022-12-01 09:48

An ongoing analysis into an up-and-coming cryptocurrency mining botnet known as KmsdBot has led to it being accidentally taken down. The botnet strikes both Windows and Linux devices spanning a wide range of microarchitectures with the primary goal of deploying mining software and corralling the compromised hosts into a DDoS bot.

Malware Authors 'Accidentally' Crash KmsdBot Cryptocurrency Mining Botnet
2022-12-01 09:48

An ongoing analysis into an up-and-coming cryptocurrency mining botnet known as KmsdBot has led to it being accidentally taken down. The botnet strikes both Windows and Linux devices spanning a wide range of microarchitectures with the primary goal of deploying mining software and corralling the compromised hosts into a DDoS bot.

LastPass, GoTo announce security incident
2022-12-01 09:35

LastPass and its affiliate GoTo have announced that they suffered a security incident and, in LastPass' case, a possible data breach. "Based on the investigation to date, we have detected unusual activity within our development environment and third-party cloud storage service," GoTo CEO Paddy Srinivasan noted, and explained that the third-party cloud storage service in question is shared by GoTo, a cloud-baser SaaS provider of remote work collaboration and IT management tools, and LastPass, the company behind the popular password manager of the same name.

LastPass Suffers Another Security Breach; Exposed Some Customers Information
2022-12-01 09:35

Popular password management service LastPass said it's investigating a second security incident that involved attackers accessing some of its customer information. "We recently detected unusual activity within a third-party cloud storage service, which is currently shared by both LastPass and its affiliate, GoTo," LastPass CEO Karim Toubba said.

LastPass Suffers Another Security Breach; Exposed Some Customers Information
2022-12-01 09:35

Popular password management service LastPass said it's investigating a second security incident that involved attackers accessing some of its customer information. "We recently detected unusual activity within a third-party cloud storage service, which is currently shared by both LastPass and its affiliate, GoTo," LastPass CEO Karim Toubba said.

Meet the most comprehensive portable cybersecurity device
2022-12-01 09:09

A little investment can go a long way, especially while the Deeper Connect Pico Decentralized VPN and Cybersecurity Hardware is available on sale with free shipping until December 8. Deeper Connect Pico is one of the most unique cybersecurity hardware devices you'll see.