Security News

Lazarus APT Spinoff Linked to Banking Hacks (Threatpost)
2017-04-03 20:38

The Lazarus Group has splintered off a group whose mission is to attack banks and steal money in order to fund its operations.

Fileless Banking Malware Attackers Break In, Cash Out, Disappear (Threatpost)
2017-04-03 19:57

Attackers behind February's fileless malware attacks dropped malware on some bank ATMs that gave them the ability to dispense money, "at any time, at the touch of a button."

Lines Around Cyber Threat Intelligence Sharing Blurring (Threatpost)
2017-04-03 17:02

The lines between between information shared between intelligence services, companies, and the government are getting increasingly blurry, a Georgetown professor warned.

Memory Corruption Mitigations Doing Their Job (Threatpost)
2017-04-03 17:00

At the Security Analyst Summit, Mark Dowd described how memory corruption mitigations are successfully driving up exploit development costs.

Fake SEO Plugin Used In WordPress Malware Attacks (Threatpost)
2017-04-03 16:29

Malware that passes itself off as a WordPress SEO plugin has been infecting sites and opening a backdoor for hackers on thousands of sites.

Russian-Speaking Turla Joins APT Elite (Threatpost)
2017-04-03 16:09

Researchers may have found a link between Moonlight Maze of the late ’90s and the Turla APT, which would elevate Turla to the ranks of the Equation Group as an elite nation-state attacker.

Verizon Rebuts Critics of Data-Collecting App (Threatpost)
2017-03-31 20:33

The Electronic Frontier Foundation retracted a blog post today highly critical of Verizon and the upcoming rollout of an app called AppFlash made by Evie Labs.

Threatpost News Wrap, March 31, 2017 (Threatpost)
2017-03-31 15:55

This year's Security Analyst Summit is previewed and the news of the week is discussed, including a Microsoft IIS zero day, a new Mirai variant, and the broadband privacy ruling.

Aviation-Related Phishing Campaigns Seeking Credentials (Threatpost)
2017-03-31 11:00

Researchers warn of a wave in aviation-themed phishing attacks that aim to steal credentials and install malware.

New Mirai Variant Carries Out 54-Hour DDoS Attacks (Threatpost)
2017-03-30 18:50

Researchers are tracking a new variant of the Mirai malware after it launched a 54-hour long DDoS attack against a U.S. college.