Security News > 2022

Behind the scenes: A day in the life of a cybersecurity curriculum director
2022-01-05 16:39

The Kennedy Space Center kick-started Andee Harston's career in cybersecurity. Here's how she worked her way up to overseeing the cybersecurity curriculum for Infosec.

Remember Norton 360's bundled cryptominer? Irritated folk realise Ethereum crafter is tricky to delete
2022-01-05 15:56

Norton antivirus's inbuilt cryptominer has re-entered the public consciousness after a random Twitter bod expressed annoyance at how difficult it is to uninstall. Exe, Norton 360's signed cryptocurrency-mining binary, to installations of Norton antivirus isn't new - but it seems to have taken the non-techie world a few months to realise what's going on.

iOS malware can fake iPhone shut downs to snoop on camera, microphone
2022-01-05 14:54

Historically, when malware infects an iOS device, it can be removed simply by restarting the device, which clears the malware from memory. When an iPhone is shut off, its screen naturally goes dark, the camera is turned off, 3D touch feedback does not respond to long presses, sounds from calls and notifications are muted, and all vibrations are absent.

‘Malsmoke’ Exploits Microsoft’s E-Signature Verification
2022-01-05 13:00

Threat actors are exploiting Microsoft's digital signature verification to steal user credentials and other sensitive information by delivering the ZLoader malware, which previously has been used to distribute Ryuk and Conti ransomware, researchers have found. Researchers at Check Point Research discovered the cybercriminal group Malsmoke delivering the campaign, which they traced back to November 2021, according to a report posted online Wednesday.

‘Elephant Beetle’ spends months in victim networks to divert transactions
2022-01-05 13:00

The actors inject fraudulent transactions into the network and steal small amounts over long periods, leading to an overall theft of millions of dollars. The actors need to conduct long-term surveillance and research, so the next primary goal is to remain undetected for several months.

More Russian Cyber Operations against Ukraine
2022-01-05 12:12

Both Russia and Ukraine are preparing for military operations in cyberspace.

Windows giant seeks Pluton-ic relationship with chipmaker: AMD first out of the gates with Microsoft's security processor
2022-01-05 12:11

The RPG Greetings, traveller, and welcome back to The Register Plays Games, our monthly gaming column. In terms of quality at the point of release, Halo Infinite has stepped out as the clear winner.

Microsoft code-sign check bypassed to drop Zloader malware
2022-01-05 11:00

A new Zloader campaign exploits Microsoft's digital signature verification to deploy malware payloads and steal user credentials from thousands of victims from 111 countries. Zloader is a banking malware first spotted back in 2015 that can steal account credentials and various types of sensitive private information from infiltrated systems.

How can SMBs extend their SecOps capabilities without adding headcount?
2022-01-05 09:01

There is an alternative way for procuring security expertise: by retaining the services of managed security service providers and managed detection and response providers. MSSPs usually assist organizations' IT departments in managing the IT infrastructure and keeping it secure by managing security equipment/systems, monitoring security logs, supervising patch management, and similar preventative security measures.

How ransomware gangs went pro
2022-01-05 08:30

Cybercriminal groups started deploying post-intrusion ransomware in 2015, which involved human attackers gaining initial access to the system and moving laterally through the organization until it found the appropriate target. Attack groups have repeatedly upped the ante, evolving with JavaScript-based ransomware and fileless attacks.