Security News

AI is Security's Best Defense
2021-03-30 19:15

Remote working is here to stay, and with this, security and safety have gained even more relevance. Security analysts are receiving thousands of alerts daily, and now with so many remote workers, these alerts could come from thousands of locations.

How phishing attacks evade traditional security defenses
2021-03-30 18:44

A report issued on Tuesday by email security provider Armorblox looked at the tactics employed by three recent phishing campaigns and suggests ways to avoid these types of scams. In each case, the emails were able to get past security defenses to end up in the inboxes of their targeted victims.

Defense of Convicted Cypriot Hacker in US Not Seeking Appeal
2021-03-22 18:28

A lawyer for a Cypriot hacker who has served almost four years behind bars said he will not appeal against a one-year jail sentence in the US for cyber-crimes he committed as a minor. A Georgia court handed down the jail term on Thursday in the trial of Joshua Pelloso Epifaniou, now 22, who was arrested in Cyprus in May 2017 and last year became the first Cypriot national ever extradited to the United States.

Kasada V2 platform provides defense against advanced bot attacks
2021-03-17 02:30

To address the increasing sophistication of bot attacks, Kasada has upgraded its platform to provide real-time defense against advanced bots that are left undetected by traditional methods. In its V2 release, Kasada has made several improvements that provide customers with an immediate and long-term approach to bot mitigation, without the need for burdensome maintenance.

NanoCore RAT Scurries Past Email Defenses with .ZIPX Tactic
2021-03-11 18:58

That's according to researchers at Trustwave, who found that the campaign is effectively hiding a malicious executable by giving it a.ZIPX file extension, which is used to denote that a.ZIP archive format is compressed using the WinZip archiver. In reality, the appended file is an Icon image file wrapped inside a.RAR package.

Security chaos engineering helps you find holes in your cyber defenses before hackers do
2021-03-08 21:26

This approach is all about data and resilience, not deliberately sabotaging your own network, according to two cybersecurity experts.

Cyber Defense Labs names Marla Beckham as Chief Financial Officer
2021-03-04 23:30

In this role, Ms. Beckham will oversee all financial operations while working closely with our leadership team to support Cyber Defense Labs' business strategy and anticipated growth. Ms. Beckham brings a proven track record of success in leading all aspects of corporate finance with strong expertise in financial management, budgeting and forecasting, risk mitigation, cost controls and strategic planning.

North Korean Hackers Targeting Defense Firms with ThreatNeedle Malware
2021-03-01 01:29

A prolific North Korean state-sponsored hacking group has been tied to a new ongoing espionage campaign aimed at exfiltrating sensitive information from organizations in the defense industry. The next-stage malware functions by embedding its malicious capabilities inside a Windows backdoor that offers features for initial reconnaissance and deploying malware for lateral movement and data exfiltration.

Lazarus Targets Defense Companies with ThreatNeedle Malware
2021-02-26 19:56

The prolific North Korean APT known as Lazarus is behind a spear-phishing campaign aimed at stealing critical data from defense companies by leveraging an advanced malware called ThreatNeedle, new research has revealed. The elaborate and ongoing cyberespionage campaign used emails with COVID-19 themes paired with publicly available personal information of targets to lure them into taking the malware bait, according to Kaspersky, which first observed the activity in mid-2020.

Google looks at bypass in Chromium's ASLR security defense, throws hands up, won't patch garbage issue
2021-02-26 11:58

In early November, a developer contributing to Google's open-source Chromium project reported a problem with Oilpan, the garbage collector for the browser's Blink rendering engine: it can be used to break a memory defense known as address space layout randomization. About two weeks later, Google software security engineer Chris Palmer marked the bug "WontFix" because Google has resigned itself to the fact that ASLR can't be saved - Spectre and Spectre-like processor-level flaws can defeat it anyway, whether or not Oilpan can be exploited.