Security News

Panda Stealer targets cryptocurrency wallets and VPN credentials via malicious XLS attachment
2021-05-11 17:05

Bad actors put a new twist on an existing piece of malware to steal private keys for cryptocurrency accounts and other account credentials, according to analysis from Trend Micro. Panda Stealer uses a fileless approach and looks for private keys and records of previous transactions from cryptocurrency wallets including Dash, Bytecoin, Litecoin and Ethereum, according to Trend Micro.

Kerv acquires cloudThing to further enhance its cloud and digital credentials
2021-05-06 23:30

Whilst continuing its focus on strong and sustainable organic growth, Kerv will also look at acquiring businesses which add new capabilities to further enhance its cloud and digital credentials and/or bring new vertical opportunities. "Explaining the rationale behind the deal, Alastair Mills, executive chairman at Kerv, said:"This acquisition is a significant step for Kerv and a major investment in the rapidly growing digital transformation market.

World Password Day: Computer credentials are just as important as passwords—protect them, too
2021-05-06 21:13

Expert discusses the importance of keeping internal computer credentials as safe as your passwords. TechRepublic's Karen Roby spoke with Robert Haynes of Checkmarx, a software security solution, about World Password Day, May 6, 2021.

HID Global WorkforceID Authentication manages digital and physical identity credentials
2021-04-20 02:00

HID Global announced the general availability WorkforceID Authentication, the latest addition to its cloud platform for creating a seamless, effortless experience for issuing, managing and using identity credentials in physical and digital workplaces. "A person's identity has become the new security perimeter in a hybrid workplace that now extends from home to the office and everywhere in between," said Julian Lovelock, VP Global Business Segment, IAM, with HID Global.

Codecov dev tool warns of stolen credentials from compromised script, undiscovered for two months
2021-04-19 16:03

Codecov, makers of a code coverage tool used by over 29,000 customers, has warned that a compromised script may have stolen credentials over a period of two months, before it was discovered a few weeks ago. Codecov is a cloud-based tool which integrates with GitHub, GitLab, Atlassian Bitbucket, or any Git-based repository.

Popular Codecov code coverage tool hacked to steal dev credentials
2021-04-16 14:44

Codecov online platform for hosted code testing reports and statistics announced on Thursday that a threat actor had modified its Bash Uploader script, exposing sensitive information in customers' continuous integration environment. Codecov provides tools that help developers measure how much of the source code executes during testing, a process known as code coverage, which indicates the potential for undetected bugs being present in the code.

Google Forms and Telegram abused to collect phished credentials
2021-04-07 16:10

Security researchers note an increase in alternative methods to steal data from phishing attacks, as scammers obtain the stolen info through Google Forms or private Telegram bots. Email remains the preferred method to exfiltrate stolen info but these channels foreshadow a new trend in the evolution of phishing kits.

Socure provides identity verification for Microsoft Azure AD verifiable credentials
2021-04-06 23:30

Socure announced the company will provide identity verification services for remote onboarding for individuals accessing decentralized IDs as part of the new Microsoft Azure Active Directory verifiable credentials feature in public preview. Once verified, these credentials can be used to prove an identity across different organizations to accelerate onboarding of users and enable a more trustworthy credential recovery experience.

Onfido’s identity verification to power onboarding for Microsoft’s digital wallet for identity credentials
2021-04-06 23:00

Onfido announced it has been selected by Microsoft to enable fast and secure identity verification and onboarding for its Azure Active Directory verifiable credentials. Once a person's real identity is bound to their digital identity using Onfido's document plus selfie verification, end-users are onboarded to Azure AD and have complete control over their identity from their smartphone, being able to provision its reuse to access additional services.

VMware fixes bug allowing attackers to steal admin credentials
2021-03-30 18:01

VMware has published security updates to address a high severity vulnerability in vRealize Operations that could allow attackers to steal admin credentials after exploiting vulnerable servers. vRealize Operations is an AI-powered and "Self-driving" IT operations management for private, hybrid, and multi-cloud environments, available as an on-premises or SaaS solution.