Security News

Fruitfly: Unusual Mac backdoor used for tightly targeted attacks? (Help Net Security)
2017-01-18 21:43

Researchers have found and analyzed a Mac backdoor that is unusual in many ways. The malware – detected as OSX.Backdoor.Quimitchin by Malwarebytes but dubbed Fruitfly by Apple – is believed to...

Significant decrease in Locky ransomware attacks (Help Net Security)
2017-01-17 12:45

Locky ransomware attacks have dramatically decreased during December 2016, according to Check Point. Locky, which uses massive spam campaigns as a major distribution vector, only surfaced in 2016...

Friday Squid Blogging: 1874 Giant Squid Attack (Schneier on Security)
2017-01-13 22:52

This article discusses a giant squid attack on a schooner off the coast of Sri Lanka in 1874. As usual, you can also use this squid post to talk about the security stories in the news that I...

Twofish Power Analysis Attack (Schneier on Security)
2017-01-12 12:28

New paper: "A Simple Power Analysis Attack on the Twofish Key Schedule." This shouldn't be a surprise; these attacks are devastating if you don't take steps to mitigate them. The general issue is...

ShadowBrokers Selling Windows Exploits, Attack Tools (Threatpost)
2017-01-11 20:04

The ShadowBrokers are selling a cache of Windows exploits and attack tools for 750 Bitcoin.

Ransom is the main motivation behind cyber attacks (Help Net Security)
2017-01-11 13:00

49% of businesses confirmed being the subject of a ransom campaign in 2016, according to Radware. What’s more, 27% of IT professionals surveyed chose data leakage or loss as a key concern when...

MongoDB Attacks Jump From Hundreds to 28,000 In Just Days (Threatpost)
2017-01-09 22:50

Security researchers report a massive uptick in the number of MongoDB databases hijacked and held for ransom.

Attacks On MongoDB Rise As Hijackings Continue (Threatpost)
2017-01-05 19:53

Open MongoDB databases are being targeted by criminals who are deleting the contents and asking for a ransom.

An SQL Injection Attack Is a Legal Company Name in the UK (Schneier on Security)
2017-01-04 21:17

Someone just registered their company name as ; DROP TABLE "COMPANIES";-- LTD. Reddit thread. Obligatory xkcd comic....

More attacks, new technologies: Cybersecurity predictions for the year ahead (Help Net Security)
2017-01-03 13:00

Every day, the cybersecurity landscape changes. Each new device connected to the network presents a new target for attackers that needs to be secured, and each new social media post creates new...