Cyber Security News


  • Germany stands down cyber boss over Russian ties

    October 19, 2022

    Germany’s government has stood down the president of its Federal Office for Information Security, Arne Schönbohm, over his links to Russia. Schönbohm’s woes erupted last week when late-night chat show ZDF Magazine Royale branded him a “Cyberclown” in a Twitter thread that detailed some of the wurst moments of his career: Among the matters raised in the ...

  • ‘Fully undetectable’ Windows backdoor gets detected

    October 18, 2022

    SafeBreach Labs says it has detected a novel fully undetectable (FUD) PowerShell backdoor, which calls into question the accuracy of threat naming. More significantly, the malware may backdoor your Windows system by masquerading as part of the update process. Tomer Bar, director of security research at SafeBreach, explains in an advisory that the software nasty and associated ...

  • Spyder Loader: Malware Seen in Recent Campaign Targeting Organizations in Hong Kong

    October 18, 2022

    Symantec has observed a likely continuation of the Operation CuckooBees activity, this time targeting organizations in Hong Kong. Operation CuckooBees was first documented in May 2022 by researchers at Cybereason, who said the intelligence-gathering campaign had been operating under the radar since at least 2019, stealing intellectual property and other sensitive data from victims. The victims observed ...

  • CISA Releases Two Industrial Control Systems Advisories

    October 18, 2022

    CISA released two Industrial Control Systems (ICS) advisories on October 18, 2022. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations: ICSA-22-291-01 Advantech R-SeeNet ICSA-21-336-06 Hitachi Energy APM Edge (Update A) Read more… Source: U.S. Cybersecurity and Infrastructure ...

  • Verizon notifies prepaid customers their accounts were breached

    October 18, 2022

    Verizon warned an undisclosed number of prepaid customers that attackers gained access to Verizon accounts and used exposed credit card info in SIM swapping attacks. “We determined that between October 6 and October 10, 2022, a third party actor accessed the last four digits of the credit card used to make automatic payments on your account,” ...

  • Japanese giants to offer security-as-a-service for connected cars

    October 18, 2022

    Japanese industrial giants NTT Communications Corporation and Denso Corporation have decided to start a business “to respond to the threat of increasingly sophisticated cyber-attacks against vehicles.” NTT Communications is a global IT services company that is a member of the NTT Group (which confusingly also operates NTT Data, another global IT services company). Denso is an ...

  • Defenders beware: A case for post-ransomware investigations

    October 18, 2022

    Ransomware is one of the most pervasive threats that Microsoft Detection and Response Team (DART) responds to today. The groups behind these attacks continue to add sophistication to their tactics, techniques, and procedures (TTPs) as most network security postures increase. In this blog, DART researchers detail a recent ransomware incident in which the attacker used a ...

  • The benefits of taking an intent-based approach to detecting Business Email Compromise 

    October 18, 2022

    Business email compromise (BEC) is one of the most financially damaging online crimes. As per the internet crime 221 report, the total loss in 2021 due to BEC is around 2.4 billion dollars. Since 2013, BEC has resulted in a 43 billion dollars loss. The report defines BEC as a scam targeting businesses (not individuals) ...

  • Europol: 31 arrested for stealing cars by hacking keyless tech

    October 18, 2022

    With the support of Europol and Eurojust, the French authorities in cooperation with their Spanish and Latvian counterparts have dismantled a car theft ring which used a fraudulent software to steal vehicles without using the physical key fob. The criminals targeted vehicles with keyless entry and start systems, exploiting the technology to get into the car ...

  • Linux dodges serious Wi-Fi security exploits

    October 17, 2022

    You may recall that Linus Torvalds recently added support for Rust in the Linux kernel. One of the big reasons for adding Rust was to put an end to Linux code memory problems. It can’t come soon enough. Recently, five serious Linux Wi-Fi security holes were uncovered. What did they all have in common? Go ahead, guess? ...

  • Malware dev claims to sell new BlackLotus Windows UEFI bootkit

    October 17, 2022

    A threat actor is selling on hacking forums what they claim to be a new UEFI bootkit named BlackLotus, a malicious tool with capabilities usually linked to state-backed threat groups. UEFI bootkits are planted in the system firmware and are invisible to security software running within the operating system because the malware loads in the initial ...