Security News

Which users are at higher risk of email-based phishing and malware?
2021-02-11 12:05

Australian users are, for example, at a higher risk of being targeted that U.S.-based users, and older people are more likely to be targeted than youngsters. The researchers have analyzed over 1.2 billion email-based phishing and malware attacks against Gmail users and have singled out some interesting findings.

No phish for the likes of you, thank you very much! Google finds email villains are picky about demographics, country
2021-02-10 09:30

Kind old Google has published data on targeted email attacks and dispensed advice to help users separate friend from foe. The pandemic has presented malware-laden email flingers with a world of opportunity and a whole new set of attack vectors.

How to easily check if an email is legit or a scam, and protect yourself and your company
2021-02-08 21:41

Because my email address is public, most of these messages are unsolicited; a few might even be dangerous. Scam emails often look real; they're personalized and can be quite convincing.

Countless emails wrongly blocked as spam after Cisco's SpamCop failed to renew domain name at the weekend
2021-02-01 07:04

Cisco's anti-spam service SpamCop failed to renew spamcop.net over weekend, causing it to lapse, which resulted in countless messages being falsely labeled and rejected as spam around the world. When the domain name expired, *.spamcop.net resolved to a domain parking service's IP address.

Business executives targeted with Office 365-themed phishing emails
2021-01-26 13:43

An ongoing campaign powered by a phishing kit sold on underground forums is explicitly targeting high-ranking executives in a variety of sectors and countries with fake Office 365 password expiration notifications, Trend Micro researchers warn. The compromised accounts can be used to send out even more convincing phishing emails, perpetrate BEC scams, or collect sensitive information.

Enhancing Email Security with MTA-STS and SMTP TLS Reporting
2021-01-25 23:44

Mail Transfer Agent-Strict Transport Security is a relatively new standard that enables mail service providers the ability to enforce Transport Layer Security to secure SMTP connections and to specify whether the sending SMTP servers should refuse to deliver emails to MX hosts that that does not offer TLS with a reliable server certificate. SMTP TLS Reporting is a standard that enables reporting issues in TLS connectivity experienced by applications that send emails and detect misconfigurations.

SCM market to reach $2.2B in total web and email security revenues by 2024
2021-01-25 04:00

The Secure Content Management market is expected to achieve an 11.4% compound annual growth rate to reach $2.2 billion in total web and email security revenues by 2024, according to Frost & Sullivan. Threats include more advanced and sophisticated targeted phishing emails, business email compromises, and malicious content.

Amazon Kindle RCE Attack Starts with an Email
2021-01-22 21:55

Three vulnerabilities in the Amazon Kindle e-reader would have allowed a remote attacker to execute code and run it as root - paving the way for siphoning money from unsuspecting users. Yogev Bar-On, researcher at Realmode Labs, found that it was possible to email malicious e-books to the devices via the "Send to Kindle" feature to start a chain of attack - a discovery that earned him $18,000 from the Amazon bug-bounty program.

Malwarebytes says SolarWinds hackers accessed its internal emails
2021-01-19 15:03

Cybersecurity firm Malwarebytes today confirmed that the threat actor behind the SolarWinds supply-chain attack were able to gain access to some company emails. "While Malwarebytes does not use SolarWinds, we, like many other companies were recently targeted by the same threat actor," Malwarebytes CEO and co-founder Marcin Kleczynski said.

AnyVan confirms digital break-in, says customer names, emails and hashed passwords exposed
2021-01-19 08:45

Anyvan, the European online marketplace that lets users buy delivery, transport or removal services from a network of providers, has confirmed it was the victim of a digital burglary that involved the theft of customers' personal data. The company wrote to customers mid-last week to inform them of a "Breach of security resulting in the unauthorised access to data from our user database," according to the email seen by The Register.