Security News

US govt sites showing porn, viagra ads share a common software vendor
2021-09-17 10:11

A security researcher noticed all of these sites share a common software vendor. Mil domains using a common software product provided by Laserfiche, a government contractor.

#US
This is AUKUS for China – US, UK, Australia reveal defence tech-sharing pact
2021-09-16 03:27

Australia, the United States of America, and the United Kingdom have signed a new defence and technology-sharing pact. Dubbed AUKUS, the headline item of the pact is assistance from the UK and US to help Australia build nuclear-powered submarines that are interoperable with their own fleets.

Ex-US intel, military trio were cyber-mercenaries for UAE, say prosecutors
2021-09-15 06:45

Three former US intelligence and military operatives broke America's weapons export and computer security laws by, among other things, helping the United Arab Emirates hijack and siphon data from people's iPhones, it emerged on Tuesday. US citizens Marc Baier, 49, and Ryan Adams, 34, and ex-citizen Daniel Gericke, 40, were charged [PDF] with using "Illicit, fraudulent, and criminal means, including the use of advanced covert hacking systems that utilized computer exploits obtained from the United States and elsewhere, to gain unauthorized access to protected computers in the United States and elsewhere and to illicitly obtain information ... from victims from around the world."

Why you should avoid those fun social media "tell us about yourself" questions
2021-09-14 16:19

The questions have gotten more sophisticated and less suspicious. I've noticed a significant uptick in Facebook questions that ask users to answer seemingly innocent questions one wouldn't think could put anyone in danger.

Jenkins struck by 'Confluenza' as US Cyber Command warns Atlassian flaw 'cannot wait'
2021-09-06 13:51

The Jenkins team issued a reminder over the weekend that one should keep one's systems patched as it found itself with a compromised Confluence service. Although the affected instance of Confluence integrated with the company's identity system, the group said: "At this time we have no reason to believe that any Jenkins releases, plugins, or source code have been affected."

US SEC: Watch out for Hurricane Ida-related investment scams
2021-09-04 15:12

The US Securities and Exchange Commission has warned investors to be "Extremely wary" of potential investment scams related to Hurricane Ida's aftermath. This alert comes from SEC's Office of Investor Education and Advocacy, which regularly issues investor alerts to warn investors about the latest investment frauds and scams.

US officials, experts fear China ransacked Exchange servers for data to train AI systems
2021-08-31 19:23

The massive attack on Microsoft Exchange servers in March may have been China harvesting information to train AI systems, according to US government officials and computer-security experts who talked to NPR. The plundering of these Exchange systems was attributed to Chinese government cyber-spies known as Hafnium; Beijing denied any involvement. It's said the crew exploited four zero-days in Redmond's mail software in a chain to hijack the servers and siphon off data.

FIN8 Targets US Bank With New ‘Sardonic’ Backdoor
2021-08-27 17:32

The financially motivated FIN8 cybergang used a brand-new backdoor - dubbed Sardonic by the Bitdender researchers who first spotted it - in attempted breaches of networks belonging to two unidentified U.S. financial organizations. It's a nimble newcomer, researchers wrote: "The Sardonic backdoor is extremely potent and has a wide range of capabilities that help the threat actor leverage new malware on the fly without updating components," according to Bitdefender's report.

Microsoft and Google to invest billions to bolster US cybersecurity
2021-08-26 15:27

Executives and leaders from big tech, education, the finance sector, and infrastructure have committed to bolstering US interests' security during yesterday's White House cybersecurity summit. The Biden administration has added natural gas pipelines to the Industrial Control Systems Cybersecurity Initiative, aiming to strengthen critical infrastructure cybersecurity.

Tech companies pledge to help toughen US cybersecurity in White House meeting
2021-08-26 13:55

In a meeting with President Biden at the White House on Wednesday, Apple, Google, Microsoft and other companies announced their intentions to devote money and training toward strengthening U.S. cybersecurity. As one step, the White House said that the National Institute of Standards and Technology will work with businesses to improve the security of the technology supply chain.