Security News

Telnyx is the latest VoIP provider hit with DDoS attacks
2021-11-10 21:18

Telnyx is the latest VoIP telephony provider targeted with distributed denial-of-service attacks, causing worldwide outages since yesterday. Starting November 9th at approximately 11 PM EST, Telnyx was targeted with a DDoS attack causing all telephony services to fail or be delayed.

These industries were the most affected by the past year of ransomware attacks
2021-11-10 17:48

After what has been a year of averaging more than a thousand ransomware attacks per day, NordLocker said that data released by hackers shows an unexpected industry at the top. Cloud security provider NordLocker has released a report of the 35 industries most hit by ransomware over the past year, and in what may be a surprise to some, the construction industry appears to have been the hardest hit.

TrickBot teams up with Shatak phishers for Conti ransomware attacks
2021-11-10 15:52

A threat actor tracked as Shatak recently partnered with the ITG23 gang to deploy Conti ransomware on targeted systems. The Shatak operation partners with other malware developers to create phishing campaigns that download and infect victims with malware.

Microsoft patches Excel zero-day used in attacks, asks Mac users to wait
2021-11-10 15:36

During this month's Patch Tuesday, Microsoft has patched an Excel zero-day vulnerability exploited in the wild by threat actors. Microsoft also patched a second Excel security flaw used during the Tianfu Cup hacking contest last month, a remote code execution bug tracked as CVE-2021-40442 and exploitable by unauthenticated attackers.

Organizations believe they are ready for ransomware attacks
2021-11-10 06:00

Over the past year there has been a dramatic rise in ransomware attacks, and while all organizations are a target, large enterprises are bearing the brunt - experiencing an average of 10,000 attacks over the past two years. Respondents cited phishing emails with ransomware attachments, web security, and phishing emails leading to a drive-by download as primary sources of ransomware attacks.

Dependency Combobulator: Open source toolkit to combat dependency confusion attacks
2021-11-10 05:45

Apiiro released Dependency Combobulator, a modular and extensible open source toolkit to detect and prevent dependency confusion attacks. Dependency confusion compromises the open source software ecosystem by tricking end-users, developers and automation-systems into installing a malicious dependency instead of the correct one they intended to install, resulting in the compromise of their software.

Shotgun targeting of malware attacks will be the defining infosec theme of 2022, reckons Sophos
2021-11-09 19:30

Future malware and ransomware infections will consist of "Shotgun attacks with pinpoint targeting", according to Sophos' 2022 threat report. As if that wasn't enough, the British infosec biz reckons established commodity malware attacks will end up delivering ever more ransomware, while extortion tactics used by ransomware gangs will become more diverse and intense - with the aim of browbeating victims into handing over cash.

Kaspersky finds 31% increase in "smart" DDoS attacks
2021-11-09 18:10

Q3 beat every record in terms of daily number of DDoS attacks, according to a new report from Kaspersky. The total number of DDoS attacks was up 24% compared to Q3 2020 while the number of advanced, "Smart" attacks was up 31% over the same time period.

12 New Flaws Used in Ransomware Attacks in Q3
2021-11-09 18:06

A dozen new vulnerabilities were used in ransomware attacks this quarter, bringing the total number of vulnerabilities associated with ransomware to 278: a 4.5 percent increase over Q2, according to a new report. The news about the new vulnerabilities that have been pounced on by ransomware operators comes from Ivanti's Q3 2021 ransomware index spotlight report, published on Tuesday and conducted with Cyber Security Works and Cyware.

Ransomware attacks are increasingly exploiting security vulnerabilities
2021-11-09 17:57

The number of security flaws associated with ransomware rose from 266 to 278 last quarter, according to security firm Ivanti. A report released Tuesday by security firm Ivanti looks at the rise in vulnerabilities exploited by ransomware attacks.