Security News > 2024 > February

EU Court of Human Rights Rejects Encryption Backdoors
2024-02-19 16:15

Seemingly most critically, the [Russian] government told the ECHR that any intrusion on private lives resulting from decrypting messages was "Necessary" to combat terrorism in a democratic society. To back up this claim, the government pointed to a 2017 terrorist attack that was "Coordinated from abroad through secret chats via Telegram." The government claimed that a second terrorist attack that year was prevented after the government discovered it was being coordinated through Telegram chats.

ALPHV gang claims it's the attacker that broke into Prudential Financial, LoanDepot
2024-02-19 14:02

ALPHV has now made a number of inflammatory allegations against both victims, which of course should be taken with a substantial grain of salt given that they are indeed criminals. "The claims are categorically false. We continue to have uninterrupted access to their network and are actively exfiltrating information," ALPHV alleged on its site.

Anatsa Android malware downloaded 150,000 times via Google Play
2024-02-19 13:34

The Anatsa banking trojan has been targeting users in Europe by infecting Android devices through malware droppers hosted on Google Play. Last summer, ThreatFabric warned of another Europe-focused Anatsa campaign that also used dropper apps hosted on Google Play, primarily fake PDF viewer apps.

Meta Warns of 8 Spyware Firms Targeting iOS, Android, and Windows Devices
2024-02-19 13:14

Meta Platforms said it took a series of steps to curtail malicious activity from eight different firms based in Italy, Spain, and the United Arab Emirates (U.A.E.) operating in the...

How to Achieve the Best Risk-Based Alerting (Bye-Bye SIEM)
2024-02-19 11:30

Did you know that Network Detection and Response (NDR) has become the most effective technology to detect cyber threats? In contrast to SIEM, NDR offers adaptive cybersecurity with reduced false...

Anatsa Android Trojan Bypasses Google Play Security, Expands Reach to New Countries
2024-02-19 10:29

The Android banking trojan known as Anatsa has expanded its focus to include Slovakia, Slovenia, and Czechia as part of a new campaign observed in November 2023. "Some of the droppers in the...

Safeguarding cyber-physical systems for a smart future
2024-02-19 08:58

Taking these systems offline to upgrade them with better security can be difficult and very expensive, if it can be done at all. "Ideally this process would start with an accurate inventory of the infrastructure and systems you have, which sounds simple enough," adds Grant Bailey, Solutions Engineer with Claroty.

Balancing “super app” ambitions with privacy
2024-02-19 06:30

Boosted data-driven innovation that has added value for users and offers new avenues for business, like AI. The considerations for "Super app" data privacy. While benefits are plenty, one of the key considerations associated with the creation of a "Super app" - with all the potential volumes of data accessible - is what users might lose in terms of privacy.

CVE Prioritizer: Open-source tool to prioritize vulnerability patching
2024-02-19 06:00

CVE Prioritizer is an open-source tool designed to assist in prioritizing the patching of vulnerabilities. The tool leverages the correlation between CVSS and EPSS scores to improve efforts in fixing vulnerabilities.

Inside the strategy of Salesforce’s new Chief Trust Officer
2024-02-19 05:30

At Salesforce, Trust is our #1 value, and we build security into everything we do - across the business and our entire ecosystem - so that our customers and partners can focus on growth. Diving deeper, Salesforce has a world-class security team with security tools and systems to prevent, detect, and respond to any security threat.