Security News

If your hair isn't already gray, 2022's security threats will get it there, warn infosec duo
2021-10-28 07:25

FireEye and McAfee, whose business models center around charging enterprises money to protect their networks from cyber-threats, issued a joint report this week predicting next year you'll see an increase in cyber-threats, particularly those against enterprise networks and the staff who run them. Nation states will "Increase their offensive operations by leveraging cybercriminals." as senior principal McAfee engineer Christiaan Beek theorized, citing the example of US indictments against four Chinese nationals who were allegedly running front companies on behalf of Beijing.

Top cybersecurity threats enterprises will face in 2022
2021-10-28 03:30

McAfee and FireEye released its 2022 Threat Predictions, examining the top cybersecurity threats they predict enterprises will face in 2022. Skilled engineers and security architects from the recently combined entity offer a preview of how the threat landscape might look in 2022 and how these new or evolving threats could potentially impact enterprises, countries, and civilians.

Despite increased cyber threats, many organizations have no defense plans in place
2021-10-28 03:00

98% of U.S. executives report that their organizations experienced at least one cyber event in the past year, compared to a slightly lower rate of 84% in non-U.S. executives, according to a Deloitte survey. Further, COVID-19 pandemic disruption led to increased cyber threats to U.S. executives' organizations at a considerably higher rate than non-U.S. executives experienced.

9 key security threats that organizations will face in 2022
2021-10-26 15:32

Supply chain attacks, misinformation campaigns, mobile malware and larger scale data breaches are just some of the threats to watch for next year, Check Point Software says. Following reports of stolen crypto wallets triggered by free airdropped NFTs, Check Point discovered that attackers could steal such wallets by exploiting security flaws.

Threat Actors Abuse Discord to Push Malware
2021-10-22 11:44

Threat actors are abusing the core features of the popular Discord digital communication platform to persistently deliver various types of malware-in particular remote access trojans that can take over systems-putting its 150 million users at risk, researchers have found. Researchers warn, "Many files sent across the Discord platform are malicious, pointing to a significant amount of abuse of its self-hosted CDN by actors by creating channels with the sole purpose of delivering these malicious files," according to a report published Thursday by Team RiskIQ. Initially Discord attracted gamers, but the platform is now being used by organizations for workplace communication.

Tech support scams becoming the top phishing threat to consumers
2021-10-22 03:30

The latest findings show tech support scams, which often arrive as a pop-up alert convincingly disguised using the names and branding of major tech companies, have become the top phishing threat to consumers. Tech support scams are expected to proliferate in the upcoming holiday season, as well as shopping and charity-related phishing attacks.

Acer hacked twice in a week by the same threat actor
2021-10-19 16:40

Acer has suffered a second cyberattack in just a week by the same hacking group that says other regions are vulnerable. Last week, threat actors known as 'Desorden' emailed journalists to say they hacked Acer India's servers and stole data, including customer information.

About 26% of all malicious JavaScript threats are obfuscated
2021-10-19 16:03

Obfuscation is when easy-to-understand source code is converted into a hard to understand and confusing code that still operates as intended. Obfuscation can be achieved through various means like the injection of unused code into a script, the splitting and concatenating of the code, or the use of hexadecimal patterns and tricky overlaps with function and variable naming.

Tech support scams top list of latest phishing threats
2021-10-19 15:30

Tech support scams work because they try to trick people into believing there's a serious security crisis with their computers, says Norton Labs. The tech support ruse was the number one scam described by Norton Labs in its new October Consumer Cyber Safety Pulse Report.

CISA Issues Warning On Cyber Threats Targeting Water and Wastewater Systems
2021-10-15 07:10

The U.S. Cybersecurity Infrastructure and Security Agency on Thursday warned of continued ransomware attacks aimed at disrupting water and wastewater facilities, highlighting five incidents that occurred between March 2019 and August 2021. "This activity-which includes attempts to compromise system integrity via unauthorized access-threatens the ability of WWS facilities to provide clean, potable water to, and effectively manage the wastewater of, their communities," CISA, along with the Federal Bureau of Investigation, the Environmental Protection Agency, and the National Security Agency, said in a joint bulletin.