Security News

Microsoft warns of surge in HTML smuggling phishing attacks
2021-11-12 15:27

Microsoft has seen a surge in malware campaigns using HTML smuggling to distribute banking malware and remote access trojans. While HTML smuggling is not a new technique, Microsoft is seeing it increasingly used by threat actors to evade detection, including the Nobelium hacking group behind the SolarWinds attacks.

Windows 10 App Installer abused in BazarLoader malware attacks
2021-11-11 21:34

The TrickBot gang operators are now abusing the Windows 10 App Installer to deploy their BazarLoader malware on the systems of targets who fall victim to a highly targeted spam campaign. When clicking the button, the browser will first show a warning asking the victim if they want to allow the site to open App Installer.

Cyber-Mercenary Group Void Balaur Attacks High-Profile Targets for Cash
2021-11-11 18:48

Russian-language group Void Balaur, also tracked under the name Rockethack, has been identified as a prolific cyber-merecenary group, available for hire to break into the email and social-media accounts of high-profile, high-stakes targets around the world. After monitoring Void Balaur for more than a year, Trend Micro has released a report that identified more than 3,500 of the group's targets.

Magniber ransomware gang now exploits Internet Explorer flaws in attacks
2021-11-11 16:04

The Magniber ransomware gang is now using two Internet Explorer vulnerabilities and malicious advertisements to infect users and encrypt their devices. The Magniber gang is known for its use of vulnerabilities to breach systems and deploy their ransomware.

How cybercriminals use bait attacks to gather info about their intended victims
2021-11-11 14:12

With a bait attack, criminals try to obtain the necessary details to plan future attacks against their targets, says Barracuda. Cybercriminals often will research potential victims to help strategize exactly how and where to attack them.

New bill sets ransomware attack response rules for US financial orgs
2021-11-11 13:54

New legislation introduced this week by US lawmakers aims to set ransomware attack response "Rules of road" for US financial institutions. If signed into law, the new bill will require US financial institutions impacted by a ransomware attack to notify the Director of the Treasury Department's Financial Crimes Enforcement Network with details on the attack and any associated ransom demands.

Gmail accounts are used in 91% of all baiting email attacks
2021-11-11 08:32

Bait attacks are on the rise, and it appears that actors who distribute this special kind of phishing emails prefer to use Gmail accounts to conduct their attacks. According to a report by Barracuda, who surveyed 10,500 organizations, 35% of them received at least one bait attack email in September 2021 alone.

Humanizing hackers: Entering the minds of those behind the attacks
2021-11-11 05:30

Ethical hackers are helping build our defenses against data breaches and cybercrime, protect privacy, and restore trust about the digital landscape. Hackers operate across all geographies, but our systems at BOS Framework see most hacker attacks from China, Russia, Pakistan, and North Korea.

DDoS attacks were a more serious threat in Q3 2021 than ever before
2021-11-11 05:15

Link11 has released new data from its network on the development of the DDoS threat: The number of attacks remains at a very high level in Q3 2021. While single attack methods are declining, multi-vector attacks are becoming the norm in the DDoS threat landscape.

Phishing attacks grow 31.5% over 2020, social media attacks continue to climb
2021-11-11 04:45

Phishing remains the dominant attack vector for bad actors, growing 31.5 percent over 2020, according to a PhishLabs report. Notably, attacks in September 2021 were more than twice as high as the previous year.