Security News

4 Innovative Ways Cyberattackers Hunt for Security Bugs
2021-04-21 20:49

Once they've identified a tempting asset to exploit, attackers employ techniques to find a vulnerability. Some attackers use tried-and-true methods, but the most creative in the group find ways to exploit systems through unexpected vectors.

Cyberattackers Exploiting Critical WordPress Plugin Bug
2021-03-10 20:25

The Plus Addons for Elementor plugin for WordPress has a critical security vulnerability that attackers can exploit to quickly, easily and remotely take over a website. "If you are using The Plus Addons for Elementor plugin, we strongly recommend that you deactivate and remove the plugin completely until this vulnerability is patched," researchers said.

Cyberattackers Target Top Russian Cybercrime Forums
2021-03-04 21:42

Maza, a place online for fraudsters and extorters to connect to pull off their operations, has been breached by an unknown attacker, in just the latest in a series of attacks targeting elite Russian-language cybercrime forums. These forums are where threat actors can go to access ransomware-as-a-service tools, launder stolen money and even get advice on how to improve their crimes, Flashpoint vice president Thomas Hofmann explained to Threatpost.

Cyberattackers Serve Up Custom Backdoor for Oracle Restaurant Software
2020-11-12 22:19

It's notable for its unusual sophistication, according to researchers, evidenced by its multiple modules. The code is specifically taking aim at the Oracle MICROS Restaurant Enterprise Series 3700 POS - a management software suite used by hundreds of thousands of bars, restaurants, hotels and other hospitality establishments worldwide, according to ESET. The attacks have mainly been in the U.S., researchers said - though the initial infection vector is unknown.

Cyberattackers Ramp Up to 1.5M COVID-19 Emails Per Day
2020-04-21 12:51

Cyberattackers have reached a peak of sending 1.5 million malicious emails per day related to the COVID-19 pandemic over the course of the last three months, according to new research. "We saw a rise in unwanted emails containing embedded URLs using the keywords of 'COVID' or 'corona,' from negligible values in January 2020 to over half a million blocked per day the end-of-March onwards," he wrote in the post.

Cyberattackers are delivering malware by using links from whitelisted sites
2020-03-09 14:43

Legitimate-looking links from OneDrive, Google Drive, iCloud, and Dropbox slip by standard security measures. Bad actors have added a new snare to their bag of social engineering tricks- malicious OneDrive, Google Drive, iCloud, and Dropbox links.

Cyberattackers decreased their activity at the end of 2019, but only to change tactics
2020-02-06 05:30

Across the board, malicious cyber-activity was down partly as a result of hectic holiday schedules and vacations with fewer employees around to interact with malicious activity. This decrease in activity also tracks to the heightened malicious activity Nuspire researchers saw at the beginning of 2019.

TP-Link Routers Give Cyberattackers an Open Door to Business Networks
2019-12-18 18:13

Remote attackers can easily compromise the device and pivot to move laterally through the LAN or WAN.

Most concerning security controls for cyberattackers? Deception and IDS
2018-12-14 06:45

Attivo Networks surveyed more than 450 cybersecurity professionals and executives globally to gain insights into detection trends, top threat concerns, attack surface concerns, and what’s on their...

AI-Augmented Security: Can Cyberattackers Counter It?
2018-08-07 14:47

XM Cyber's Adi Ashkenazy on the Latest TrendsAre cyberattackers working on ways to counter artificial intelligence-augmented security? And will the bad guys ever use AI-driven attacks? Adi...