Security News

How open source security flaws pose a threat to organizations
2021-04-13 16:09

How do such products fare on security? Though the community-based approach toward open source means that security flaws should be identified quickly, patching those flaws and applying the patches is another matter. In a report released Tuesday, design automation company Synopsys looked at commercial applications that use open source code to see how they dealt with security flaws.

The benefits of cyber threat intelligence
2021-04-12 04:30

In this Help Net Security podcast, Maurits Lucas, Director of Intelligence Solutions at Intel 471, discusses the benefits of cyber threat intelligence. You need to plan and invest both time and resources well ahead of time to make sure you're at the right position at the right time to collect intelligence.

Attackers deliver legal threats, IcedID malware via contact forms
2021-04-09 17:55

Threat actors are using legitimate corporate contact forms to send phishing emails that threaten enterprise targets with lawsuits and attempt to infect them with the IcedID info-stealing malware. IcedID is a modular banking trojan first spotted in 2017 and updated to also deploy second-stage malware payloads, including Trickbot, Qakbot, and Ryuk ransomware.

Cybersecurity threats and cybercrime trends of 2020
2021-04-09 04:30

Bitdefender released a report revealing top cybersecurity threats, frequency of threats and cybercrime trends of 2020. "Our 2020 findings depict consumers under constant assault from cybercriminals looking to capitalize on fear and societal uncertainty accompanying the global pandemic," said Bogdan Botezatu, director of threat research and reporting at Bitdefender.

Threat Stack partners with Liquid Web to extend the Threat Stack Oversight IDS to customers
2021-04-07 23:30

As part of this partnership, Liquid Web customers can employ the Threat Stack Oversight Intrusion Detection System as an additional layer of security to Liquid Web servers with an advanced Intrusion Detection System. Together, Threat Stack Oversight and Liquid Web will provide customers with real-time monitoring for user, process, network, and file behaviors in critical systems across Linux and Windows servers.

SAP partners with Onapsis to mitigate active threats against unprotected SAP applications
2021-04-07 23:15

SAP and Onapsis jointly released a cyber threat intelligence report providing actionable information on how malicious threat actors are targeting and potentially exploiting unprotected mission-critical SAP applications. Both companies note that many organizations still have not applied relevant mitigations that have long been provided by SAP. Customers who fail to apply these protective measures and allow unprotected SAP applications to continue to operate put themselves and their business at risk.

Cyble raises $4M to provide early warning intelligence on cyber threats
2021-04-06 22:30

The funding comes as Cyble graduates from Y Combinator, which accepted Cyble into its Winter 2021 cohort and provided pre-seed funding in January of this year. "As we continue to deliver what modern organizations need, the seed funding reaffirms our strategy and vision. It will enable Cyble to onboard resources and scale our SaaS platform, Cyble Vision, in lock step with our rapidly growing client base," says Manish Chachada, COO and Co-founder of Cyble.

Threat Actors Quick to Target (Patched) SAP Vulnerabilities
2021-04-06 20:14

Threat actors are constantly targeting new vulnerabilities in SAP applications within days after the availability of security patches, according to a joint report issued by SAP and Onapsis. Used within more than 400,000 organizations for resource planning, management of product lifecycle, human capital, and supply chain, and for various other purposes, SAP's applications represent an attractive target for adversaries.

Review: Group-IB Threat Hunting Framework
2021-04-06 05:00

Perform advanced threat hunting using logs from THF Huntpoint, email channel, traffic and behavior markers of each analyzed file from any source. THF Huntbox enables incident management, correlation of events and collaboration between analysts during threat hunting and IR activities.

Financial Sector Remains Most Targeted by Threat Actors: IBM
2021-04-02 12:42

Organizations in the financial and insurance sectors were the most targeted by threat actors in 2020, continuing a trend that was first observed roughly five years ago, IBM Security reports. Retail and professional services rounded up the top five most targeted sectors, IBM says.