- Microsoft says: Lock down your software supply chain before the malware scum get in
May 5, 2017
Microsoft’s security team is urging developers to shore up their software update systems – after catching miscreants hijacking an editing application’s download channels to inject malware into victims’ PCs. In a security advisory, Redmond’s infosec gurus describe Operation WilySupply: their mission to find, isolate and destroy an unusual and highly targeted form of malicious code that ...
- Don’t click that Google Docs link! Gmail hijack mail spreads like wildfire
May 3, 2017
If you get an email today sharing a Google Docs file with you, don’t click it – you may accidentally hand over your Gmail inbox and your contacts to a mystery attacker. The phishing campaign really kicked off in a big way on Wednesday morning, US West Coast time. The malicious email contains what appears to ...
- Anti-Virus Still Has An Important Role to Play In Cybersecurity
April 28, 2017
As Spring approaches, not only do the flowers begin to blossom and the winter clouds disperse, the tech industry begins to understand what the rest of 2017 may bring. In the cybersecurity world, the dangers lurking in the Smart Home because of glaring holes in device security have been widely publicised. The CES show in Vegas showcased ...
- FalseGuide malware victim count jumps to 2 million
April 26, 2017
An estimated 2 million Android users have now fallen victim to malware mistakenly downloaded from Google Play, which was initially reported to have affected approximately 600,000 users. The malware, dubbed FalseGuide, was hidden in more than 40 guide apps for games, the oldest of which was uploaded to Google Play as early as November last year, ...
- Hard Target: Fileless Malware
April 25, 2017
The future of client-side malware attacks is fileless. And it would appear the future has arrived with a growing number of attacks using fileless or in-memory malware to pose a threat to business that’s increasingly difficult to neutralize. “There has been an unequivocal uptick in the use of fileless malware as a threat vector,” said Kevin Epstein, ...
- Fake Delta Airline Receipts Spread Financial Malware
April 24, 2017
Spam emails posing as Delta Air payment confirmation emails are spreading financial and banking malware to computers. According to Heimdal Security firm, a new campaign trying to get access to your financial information was noticed in the wild. Users are receiving spam emails posing as payment confirmations from Delta Air. As the researchers point out, this is ...
- Hajime worm battles Mirai for control of the Internet of Things
April 18, 2017
A battle is raging for control of Internet of Things (IoT) devices. There are many contenders, but two families stand out: the remains of the Mirai botnet, and a new similar family called Hajime. Hajime was first discovered by researchers in October of last year and, just like Mirai (Linux.Gafgyt), it spreads via unsecured devices that ...
- InterContinental Hotel Chain Breach Expands
April 17, 2017
In December 2016, KrebsOnSecurity broke the news that fraud experts at various banks were seeing a pattern suggesting a widespread credit card breach across some 5,000 hotels worldwide owned by InterContinental Hotels Group (IHG). In February, IHG acknowledged a breach but said it appeared to involve only a dozen properties. Now, IHG has released data showing that ...
- Callisto Group hackers targeted Foreign Office data
April 13, 2017
The UK’s Foreign Office was targeted by highly motivated and well-resourced hackers over several months in 2016. The BBC understands the government has investigated the previously unreported attack that began in April last year. The UK’s National Cyber Security Centre would not say whether data was stolen. But a source told the BBC that the most sensitive Foreign ...
- Dridex Campaigns Hitting Millions of Recipients Using Unpatched Microsoft Zero-Day
April 10, 2017
This weekend saw multiple reports of a new zero-day vulnerability that affected all versions of Microsoft Word. Today, Proofpoint researchers observed the document exploit being used in a large email campaign distributing the Dridex banking Trojan. This campaign was sent to millions of recipients across numerous organizations primarily in Australia. This represents a significant level of ...

