Security News > 2023 > February

Digital forensics and incident response: The most common DFIR incidents
2023-02-24 23:57

Digital forensics is growing while being more tied with incident response, according to the latest State of Enterprise Digital Forensics and Incident Response survey from Magnet Forensics. Digital forensics increasingly involved with incident response.

Bitcoin mining rig found stashed in school crawlspace
2023-02-24 23:30

Pics A Massachusetts man accused of using his job as a city's assistant facilities director to hide a cryptocurrency mining operation in the crawlspace of a school has surrendered himself to authorities on Friday morning after skipping his Thursday arraignment. A judge issued a default warrant for Nadeam Nahas' arrest yesterday on charges of fraudulent use of electricity and vandalizing a school, in relation with the cryptomining operation discovered under Cohasset Middle/High School in December, 2021.

Google destroyed evidence for antitrust battle, Feds complain
2023-02-24 22:30

The US Department of Justice asked the judge hearing its antitrust case against Google to sanction the search advertising giant for destruction of evidence. The case has since progressed into the discovery phase and now the DoJ contends that Google has ignored its responsibility to preserve evidence relevant to the case.

Friday Squid Blogging: Squid Processing Facility
2023-02-24 22:02

This video of a modern large squid processing ship is a bit gory, but also interesting. As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered.

News Corp says state hackers were on its network for two years
2023-02-24 18:44

Mass media and publishing giant News Corporation says that attackers behind a breach disclosed in 2022 first gained access to its systems two years before, in February 2020. This was revealed in data breach notification letters sent to employees affected by the data breach, who had some of their personal and health information accessed, while the threat actors had access to an email and document storage system used by several News Corp businesses.

News Corp says state hackers breached its systems 3 years ago
2023-02-24 18:44

Mass media and publishing giant News Corporation says that attackers behind a breach disclosed in 2022 first gained access to its systems two years before, in February 2020. This was revealed in data breach notification letters sent to employees affected by the data breach, who had some of their personal and health information accessed, while the threat actors had access to an email and document storage system used by several News Corp businesses.

Stanford University discloses data breach affecting PhD applicants
2023-02-24 16:27

Stanford University disclosed a data breach after files containing Economics Ph.D. program admission information were downloaded from its website between December 2022 and January 2023. Last week, the university sent data breach notification letters to those who submitted personal and health information as part of the graduate application to its Department of Economics, informing them that their info was accessed without authorization.

DLL sideloading and CVE attacks show diversity of threat landscape
2023-02-24 15:59

Threat watchers have spotted new cybersecurity exploits illustrating the protean nature of hacks as malware groups adapt and find new opportunities in dynamic link libraries and common vulnerabilities and exposures. Figure A. Zugec said Bitdefender has seen a large spike in the use of this tactic "Due to the fact that DLL sideloading allows the threat actors to stay hidden. Many endpoint security solutions are going to see that the DLL files are executable, signed, for example, by Microsoft or by any big name company known to be trusted. But, this trusted library is going to load malicious code."

Google Teams Up with Ecosystem Partners to Enhance Security of SoC Processors
2023-02-24 15:38

Google said it's working with ecosystem partners to harden the security of firmware that interacts with Android. While the Android operating system runs on what's called the application processor, it's just one of the many processors of a system-on-chip that cater to various tasks like cellular communications and multimedia processing.

How to Tackle the Top SaaS Challenges of 2023
2023-02-24 14:01

Are you prepared to tackle the top SaaS challenges of 2023? With high-profile data breaches affecting major companies like Nissan and Slack, it's clear that SaaS apps are a prime target for cyberattacks. Join us for an upcoming webinar that will equip you with the insights you need to overcome the top SaaS challenges of 2023.