Security News

5 tips for businesses on Safer Internet Day
2020-02-11 14:12

Note that it's more than just One Safe Internet Day, where you spend 24 hours taking security seriously, only to fall back on bad habits the day after. As the old saying goes, "Cybersecurity is a journey, not a destination," and that's why we have SAFER internet day - it's all about getting BETTER at cybersecurity, no matter how safe you think you are already.

Was Internet in Iran Hit by DDoS Attack?
2020-02-10 20:03

Over the weekend, an extensive disruption to Iran's telecommunication networks knocked out about 25 percent of the country's internet service for several hours, according to NetBlocks, a nonprofit organization that tracks internet freedom across the globe. The disruption, which took place at about 11:45 a.m. local time Saturday, caused an initial outage of cellular and fixed-line services in Iran for nearly an hour, with the country only able to partially recover its full internet service several hours after the incident, NetBlocks says.

Iran Says Foils Cyberattack Targeting Internet Providers
2020-02-10 05:05

Iran repelled a cyberattack on Saturday that disrupted the country's internet services for an hour, a telecommunications ministry official said. "At 11:44 a distributed denial-of-service attack disrupted the internet services of some mobile and fixed operators for an hour," tweeted Sajad Bonabi.

Russian super-crook behind $20m internet fraud den Cardplanet and malware-exchange forum pleads guilty
2020-01-24 04:40

A 29-year-old Russian scumbag has admitted masterminding the Cardplanet underworld marketplace as well as a second forum for elite fraudsters. Aleksei Burkov appeared in a US federal district court in Virginia this week to plead guilty [PDF] to access device fraud, and conspiracy to commit computer intrusion, identity theft, wire and access device fraud, and money laundering.

WindiLeaks: 250 million Microsoft customer support records dating back to 2005 exposed to open internet
2020-01-22 14:00

Five identical Elasticsearch databases containing 250 million records of Microsoft customer support incidents were exposed on the internet for all to see for at least two days right at the end of 2019. What data was published? These are logs of customer service and support interactions between 2005 and now.

Unofficial Patch Released for Recently Disclosed Internet Explorer Zero-Day
2020-01-22 12:20

ACROS Security's 0patch service on Tuesday released an unofficial fix for CVE-2020-0674, a recently disclosed vulnerability in Internet Explorer that has been exploited in targeted attacks. Microsoft informed customers last Friday that Internet Explorer is affected by a zero-day vulnerability.

Microsoft Warns of Zero-Day Internet Explorer Exploits
2020-01-20 12:33

Microsoft says it's prepping a patch to fix a memory corruption flaw in multiple versions of Internet Explorer that is being exploited by in-the-wild attackers. The flaw, which exists in a scripting engine built into Internet Explorer, could be exploited by attackers to remotely execute code of their choosing, Microsoft says.

Microsoft to Patch Internet Explorer Vulnerability Exploited in Targeted Attacks
2020-01-20 05:12

Microsoft announced on Friday that it's in the process of developing a patch for a zero-day vulnerability in Internet Explorer that has been exploited in targeted attacks, reportedly by a threat group tracked as DarkHotel. According to Microsoft, the vulnerability can be exploited for remote code execution in the context of the targeted user.

It's Friday, the weekend has landed... and Microsoft warns of an Internet Explorer zero day exploited in the wild
2020-01-18 01:17

Microsoft let slip on Friday an advisory detailing an under-attack zero-day vulnerability for Internet Explorer. In brief... A poorly configured Elasticsearch database left an app's baby photos and videos accessible from the public internet.

What do Brit biz consultants and X-rated cam stars have in common? Wide open... AWS S3 buckets on public internet
2020-01-15 23:54

A pair of misconfigured cloud-hosted file silos have left thousands of peoples' sensitive info sitting on the open internet. The latest demonstration of this comes from eggheads at VPNmentor, who this week said they found two open AWS S3 buckets, one belonging to a UK consulting firm and another run by an adult webcam host.