Security News > 2023 > November

Security Incident Response Policy
2023-11-05 16:00

The policy's purpose is to define for employees, IT department staff and users the process to be followed when experiencing a suspected IT-security incident. Receiving strange unprompted messages, error windows or pop-up alerts.

Socks5Systemz proxy service infects 10,000 systems worldwide
2023-11-05 15:17

A proxy botnet called 'Socks5Systemz' has been infecting computers worldwide via the 'PrivateLoader' and 'Amadey' malware loaders, currently counting 10,000 infected devices. Socks5Systemz is detailed in a report by BitSight that clarifies that the proxy botnet has been around since at least 2016 but has remained relatively under the radar until recently.

Week in review: Exploited Citrix Bleed vulnerability, Atlassian patches critical Confluence bug
2023-11-05 09:00

From Windows 9x to 11: Tracing Microsoft's security evolutionIn this Help Net Security interview, we feature security researcher Alex Ionescu, the co-author of Windows Internals, one of the founding employees of CrowdStrike, now running his consulting company, Winsider Seminars & Solutions, where he continues to do security research focusing on platform security. How human behavior research informs security strategiesIn this Help Net Security interview, Kai Roer, CEO at Praxis Security Labs, explores the theoretical underpinnings, practical implications, and the crucial role of human behavior in cybersecurity.

Discord will switch to temporary file links to block malware delivery
2023-11-04 15:16

Discord will switch to temporary file links for all users by the end of the year to block attackers from using its CDN for hosting and pushing malware. "Discord is evolving its approach to attachment CDN URLs in order to create a safer and more secure experience for users. In particular, this will help our safety team restrict access to flagged content, and generally reduce the amount of malware distributed using our CDN," Discord told BleepingComputer.

Apple 'Find My' network can be abused to steal keylogged passwords
2023-11-04 14:12

The Find My network and application is designed to help users locate lost or misplaced Apple devices, including iPhones, iPads, Macs, Apple Watches, AirPods, and Apple Tags. The service relies on GPS and Bluetooth data crowd-sourced from millions of Apple devices worldwide to find devices reported as lost or stolen, even if those are offline.

StripedFly Malware Operated Unnoticed for 5 Years, Infecting 1 Million Devices
2023-11-04 09:34

An advanced strain of malware masquerading as a cryptocurrency miner has managed to fly the radar for over five years, infecting no less than one million devices around the world in the process....

'Corrupt' cop jailed for tipping off pal to EncroChat dragnet
2023-11-04 07:37

A British court has sentenced a "Corrupt" cop to almost four years behind bars for tipping off a friend that officers had compromised the EncroChat encrypted messaging app network. Once they'd busted into the network's servers, cops used that access to collect conversations and other data from EncroChat handsets and use this information to make arrests, with the NCA doing the legwork in the UK. To date, British law enforcement has arrested 3,147 suspects and convicted 1,240 of those based on intel harvested from EncroChat, according to the Crown Prosecution Service.

Okta's Recent Customer Support Data Breach Impacted 134 Customers
2023-11-04 06:03

Identity and authentication management provider Okta on Friday disclosed that the recent support case management system breach affected 134 of its 18,400 customers. It further noted that the...

Google Play Store Highlights 'Independent Security Review' Badge for VPN Apps
2023-11-04 05:38

Google is rolling out a new banner to highlight the "Independent security review" badge in the Play Store's Data safety section for Android VPN apps that have undergone a Mobile Application...

The Week in Ransomware - November 3rd 2023 - Hive's Back
2023-11-03 21:08

Over the past couple of months, ransomware attacks have been escalating as new operations launch, old ones return, and existing operations continue to target the enterprise. While these are not confirmed to be ransomware attacks, they share many signs usually associated with such attacks.