Security News

One key addition to the malware is a small eyeball icon included in the control panel that can be used to recognize whether a user of a device with Anubis installed is looking at the device or not. The threat actors behind Anubis also are developing a way to integrate Yandex maps into the malware to show the location of infected devices, according to the report.

The ai Corporation, an FCA approved expert in payments, fraud and risk management, announced that it has upgraded EazyFuel, its closed loop fuel card platform, to be fully PCI compliant, in anticipation of the expansion of PCI Data Security Standard to cover fuel cards. Ai, whose aiGateway - omni-channel payment gateway - was granted Level 1 Service Provider accreditation recently, has rolled out PCI compliance across its suite of payments, fraud and risk management solutions for the fuel industry, in advance of any change to PCI DSS compliance or regulation.

RepRisk upgrades its ESG Risk Platform allowing users to conduct in-depth risk research on companies
RepRisk, a pioneer and leader in ESG data science announces the launch of its upgraded ESG Risk Platform - the world's largest and most comprehensive due diligence database on ESG and business conduct risks. "RepRisk has been on the cutting edge of ESG data science for over a decade, becoming the first firm to leverage big data techniques to better understand ESG risks in 2006" said Philipp Aeby, CEO of RepRisk.

Apple engineers think they've come up with a simple way to make SMS two-factor authentication one-time codes less susceptible to phishing attacks: agree a common text format so their use can be automated without the need for risky user interaction. The concept proposed by the company's Safari WebKit team is that apps such as mobile browsers will automatically process SMS text codes as they are received, submitting them to the correct website.

Kali Linux 2020.1 released: New tools, Kali NetHunter rootless, and more!Offensive Security have released Kali Linux 2020.1, which is available for immediate download. You can upgrade Windows 7 for free! Why wouldn't you?Windows 7 has been Microsoft's most successful operating system and, it's safe to say, one of the most loved. How industries are evolving their DevOps and security practicesThere's significant variation in DevOps maturation and security integration across the financial services, government, retail, telecom, and technology industries, according to Puppet's report based on nearly 3,000 responses.

Adobe-owned Magento has plugged multiple critical vulnerabilities in its eponymous content management system, the most severe of which could be exploited by attackers to achieve arbitrary code execution. According to the newest Magento-themed security bulletin, three of the six fixed flaws are critical and three are important.

Businesses continuing to run Windows 7 should tread carefully and keep Windows 7 at their peril. Compatibility should not be a big issue as Windows 10 can run on most systems that supported Windows 7.

P&N Bank in Perth, Australia, says a server upgrade gone wrong led to the breach of sensitive personal information in its customer relationship management system. The CRM system contains names, mailing addresses, email addresses, phone numbers, customer numbers, ages, account numbers, account balances and what the bank described as other "Nonsensitive" data related to interactions with customers.

The smartphone will remain the dominant consumer device into the new decade, but the arrival of 5G will not guarantee a surge in device upgrades, according to a GSMA Intelligence research. Only 30-40 per cent of survey respondents in significant markets such as the US, Europe and Australia said the arrival of 5G is likely to result in a smartphone upgrade in the short term.

Malware hunters are sounding the alarm over a new, more effective version of the North Korean "Apple Jeus" macOS software nasty. "To attack macOS users, the Lazarus group has developed homemade macOS malware, and added an authentication mechanism to deliver the next stage payload very carefully, as well as loading the next-stage payload without touching the disk."