Security News

Proxmox Mail Gateway 6.4: Protects orgs from spam, viruses, Trojans, and phishing emails
2021-03-31 01:15

Enterprise software developer Proxmox Server Solutions GmbH has released Proxmox Mail Gateway 6.4, the latest version of its open-source email security solution. Proxmox Mail Gateway is a complete operating system based on Debian Buster 10.9, but using Linux kernel 5.4.106, which is under long term support status.

SolarWinds Attackers Accessed DHS Emails, Report
2021-03-30 16:54

The SolarWinds cyberattackers compromised the head of the Department of Homeland Security under former president Trump and other top-ranking members of the department's cybersecurity staff, according to a report. With Sunburst embedded, the attackers were then able to pick and choose which organizations to further penetrate, in a massive cyberespionage campaign that has hit nine U.S. government agencies, tech companies like Microsoft and 100 others hard.

And that's yet another UK education body under attack from ransomware: Servers, email, phones yanked offline
2021-03-30 12:12

The Harris Federation, a not-for-profit charity responsible for running 50 primary and secondary academies in London and Essex, has become the latest UK education body to fall victim to ransomware. In a message to pupils and parents, the group, which is led and run by teachers, admitted that criminals had meddled with its servers.

AP Sources: SolarWinds Hack Got Emails of Top DHS Officials
2021-03-29 12:41

"The SolarWinds hack was a victory for our foreign adversaries, and a failure for DHS," said Sen. Rob Portman of Ohio, top Republican on the Senate's Homeland Security and Governmental Affairs Committee. An inquiry by the AP found new details about the breach at DHS and other agencies, including the Energy Department, where hackers accessed top officials' private schedules.

How to Effectively Prevent Email Spoofing Attacks in 2021?
2021-03-29 04:45

Email spoofing is used in phishing attacks to trick users into believing the message is from a person or entity they either know or can trust. Email spoofing is possible because the email system used to represent email addresses provides no way for outbound servers to verify the legitimacy of the sender's address.

FatFace sends controversial data breach email after ransomware attack
2021-03-27 13:41

British clothing brand FatFace has sent a controversial 'confidential' data breach notification to customers after suffering a ransomware attack earlier this year. This week, customers began receiving data breach notifications revealing that the popular lifestyle clothing brand, FatFace, had suffered a data breach after a cyberattack on January 17th, 2021.

Microsoft warns of phishing attacks bypassing email gateways
2021-03-23 17:40

An ongoing phishing operation that stole an estimated 400,000 OWA and Office 365 credentials since December has now expanded to abuse new legitimate services to bypass secure email gateways. The attacks are part of multiple phishing campaigns collectively dubbed the "Compact" Campaign, active since early 2020 first detected by the WMC Global Threat Intelligence Team.

Egress Analytics provides full visibility of email security risk
2021-03-23 03:00

Egress has announced enhancements to its reporting functionality, equipping customers with full visibility of their email security risk. Egress Analytics is available as part of Egress Prevent, Egress' flagship solution which utilizes contextual machine learning to mitigate the risk of human-activated email data breaches.

Business email compromise scams proved costly to victims in 2020
2021-03-19 14:38

The FBI received more than 19,000 complaints of business email compromises last year, costing victims around $1.8 billion. Among the many types of cyber crimes affecting organizations and individuals last year, business email compromises and email account compromises proved especially costly.

NanoCore RAT Scurries Past Email Defenses with .ZIPX Tactic
2021-03-11 18:58

That's according to researchers at Trustwave, who found that the campaign is effectively hiding a malicious executable by giving it a.ZIPX file extension, which is used to denote that a.ZIP archive format is compressed using the WinZip archiver. In reality, the appended file is an Icon image file wrapped inside a.RAR package.