Security News

Egregor ransomware criminals allegedly busted in Ukraine
2021-02-15 18:40

According to a report from radio station France Inter, numerous cybercriminals connected to the Egregor ransomware gang have recently been arrested. Since Tuesday [last week], police in the two countries have been working together in an effort to dismantle a cybercrime group suspected of initiating hundreds of ransomware attacks dating back to September 2020.[] Police arrested a number of hackers suspected of working with the Egregor cybercrime gang, providing hacking, logistical, and financial support.

Emotet Takedown Disrupts Vast Criminal Infrastructure; NetWalker Site Offline
2021-01-27 18:04

UPDATE. The virulent malware known as Emotet - one of the most prolific malware strains globally - has been dealt a blow thanks to a takedown by an international law-enforcement consortium. "One of the things that makes Emotet so dangerous is that Emotet opens the door to other types of malware, as it were. Large criminal groups were given access to some of those systems for payment to install their own malware. Concrete examples of this are the financial malware Trickbot and the ransomware Ryuk.".

Ghost hack – criminals use deceased employee’s account to wreak havoc
2021-01-26 20:37

The Sophos Rapid Response team has just written up a recent case study of a network attack that involved the account of a sysadmin who had died three months before. The account of the late employee wasn't shut down because various internal services had been configured to use it, presumably because the deceased had been involved in setting up those services in the first place.

Criminal, Domestic Violence Case Info Exposed in Cook County Leak
2021-01-26 17:24

UPDATE. A non-password protected database exposed 323,000 court records for at least four months, according to researchers. The database exposed the names of various people involved in sensitive criminal, domestic-abuse or child-custody court cases, related to a county in Illinois.

Singapore changes the rules and will now use COVID-19 contact-tracing app data in criminal cases
2021-01-05 03:58

The Singapore government has decided to use data gathered by its TraceTogether COVID-19-coronavirus contact-tracing app in criminal investigations. Minister of State for Home Affairs Desmond Tan replied by saying that Singapore's Criminal Procedure Code means its Police can obtain any data for criminal investigations, including data gathered by TraceTogether.

Vishing criminals let rip with two scams at once
2020-12-08 14:35

Phone scams, where a person or a computer calls you up and tries to trick you into saying, buying or doing something you later regret, are still a prevalent sort of cybercrime. What we have noticed is that most of the scam calls we're getting these days are automated, and that the calls themselves - just like phishing emails that are trying to cajole you into taking the next step by yourself - are merely calls-to-action, not full-on sales pitches in their own right.

How DMARC Can Stop Criminals Sending Fake Emails on Behalf of Your Domain
2020-12-07 02:47

DMARC enforces the use of a combination ofSPF andDKIM email authentication technologies to ensure only real emails are delivered to the end receivers. Without DMARC, all emails sent from the email domain of your business reaches the receiver's inbox without any security check or validation.

Sales of CEO email accounts may give cyber criminals access to the "crown jewels" of a company
2020-12-02 16:32

A hacker began selling access to hundreds of stolen executive email accounts last Friday, ZDNet reported. Javvad Malik, security awareness advocate at cybersecurity company KnowBe4, called email account access the "Crown jewels" for anyone looking to damage an organization, and the accounts of C-level executives were even more integral to an enterprise.

2020's biggest innovators? Hackers and cyber-criminals, again, says Darktrace
2020-11-13 07:00

That group is the hacker and cyber attacker fraternity, which has spotted that the sudden switch to remote working arrangements has delivered them a much wider attack surface to target, while security pros are stretched thinner than ever. By thinking like them before you start to fight back, which is what we'll be showing you how to do in our webcast How I'd Attack You, on November 18 at 0900 PT. The Register's own one-man attack surface Tim Phillips will be joined by Dan Fein and Mariana Pereira of cyber defence specialists Darktrace.

Week in review: Criminals leveraging Office 365, endpoint attack anatomy, medical devices cybersec
2020-10-18 08:12

The anatomy of an endpoint attackA lot has changed across the cybersecurity threat landscape in the last decade, but one thing has remained the same: the endpoint is under siege. Cybercriminals are using legitimate Office 365 services to launch attacksVectra released its report on Microsoft Office 365, which highlights the use of Office 365 in enterprise cyberattacks.