Security News

America, when you're done hitting us with the ban hammer, see these on-prem Zoom vulns, says Positive
2021-11-15 20:27

US-sanctioned Positive Technologies has pointed out three vulnerabilities in Zoom that can be exploited to crash or hijack on-prem instances of the videoconferencing system. One of the trio of bugs is an input validation flaw, which can be abused by a malicious Zoom portal administrator to inject and execute arbitrary commands on the machine hosting the software.

US bans China Telecom Americas over national security risks
2021-10-27 15:15

China Telecom Americas is the largest foreign subsidiary of China Telecom Corporation, China's state-owned telecom company. "Indeed, the FCC's own review found that China Telecom Americas poses significant national security concerns due to its control and ownership by the Chinese government, including its susceptibility to complying with communist China's intelligence and cybersecurity laws that are contrary to the interests of the United States."

Bank of America insider charged with money laundering for BEC scams
2021-10-09 16:08

BEC scams use various tactics to compromise or impersonate business email accounts with the end goal of redirecting pending or future payments to bank accounts under a threat actor's control. One of the case examples in the indictment document seen by Bleeping Computer, mentions a single transaction of $356,954, sent by a victim in Boston to what they thought was the bank account of their business partner.

A New Wave of Malware Attack Targeting Organizations in South America
2021-09-20 04:00

A spam campaign delivering spear-phishing emails aimed at South American organizations has retooled its techniques to include a wide range of commodity remote access trojans and geolocation filtering to avoid detection, according to new research. Cybersecurity firm Trend Micro attributed the attacks to an advanced persistent threat tracked as APT-C-36, a suspected South America espionage group that has been active since at least 2018 and previously known for setting its sights on Colombian government institutions and corporations spanning financial, petroleum, and manufacturing sectors.

Paysafe acquires SafetyPay to strengthen its strategic foothold in Latin America
2021-08-16 23:00

SafetyPay is a payments platform that enables eCommerce transactions via an unrivalled choice of open banking and eCash solutions, operating primarily in Latin America. Together the two acquisitions set Paysafe up to be the leading open banking and eCash solutions provider in Latin America, one of the world's fastest-growing online markets.

America enlists Big Tech to help it develop and execute cyber security plans
2021-08-06 03:15

The United States' Cybersecurity and Infrastructure Security Agency has announced the "Standup" of a body called the "Joint Cyber Defense Collaborative" that it hopes will spark ideas for new and improved national responses against electronic threats. The aim of the effort is to get the private sector working alongside government agencies, so they can develop and implement better cyber security plans than are currently in operation.

PwnedPiper critical bug set impacts major hospitals in North America
2021-08-02 10:41

Pneumatic tube system stations used in thousands of hospitals worldwide are vulnerable to a set of nine critical security issues collectively referred to as PwnedPiper. PTS solutions are part of a hospital's critical infrastructure as they are used to quickly deliver items like blood, tissue, lab samples, or medication to where they're needed.

Huawei to America: You're not taking cyber-security seriously until you let China vouch for us
2021-08-02 06:15

Huawei has decided to school America on cyber-security, and its lesson is to co-operate with China so its vendors - including Huawei - can be trusted around the world. Purdy, a former White House adviser on cyber security, makes some decent points - especially when pointing out that the Executive Order is only binding on federal agencies and their private sector suppliers.

Experts Uncover Malware Attacks Targeting Corporate Networks in Latin America
2021-07-08 02:58

Cybersecurity researchers on Thursday took the wraps off a new, ongoing espionage campaign targeting corporate networks in Spanish-speaking countries, specifically Venezuela, to spy on its victims. Dubbed "Bandidos" by ESET owing to the use of an upgraded variant of Bandook malware, the primary targets of the threat actor are corporate networks in the South American country spanning across manufacturing, construction, healthcare, software services, and retail sectors.

America tops ITU's Global Cyber Security Index, UK in tie for second with Saudi Arabia
2021-06-30 06:05

The United Nations International Telecommunication Union published its 2020 Global Cyber Security Index on Tuesday, and listed the US first in overall ranking, followed by a tie for second place tie between the UK and Saudi Arabia. The index ranks nations using 82 questions developed by a panel of experts.