FreshRSS

🔒
☐ ☆ ✇ WeLiveSecurity

ESET Research Podcast: Finding the mythical BlackLotus bootkit

July 12th 2023 at 11:30
Here's a story of how an analysis of a supposed game cheat turned into the discovery of a powerful UEFI threat
☐ ☆ ✇ WeLiveSecurity

What’s up with Emotet?

July 6th 2023 at 11:30
A brief summary of what happened with Emotet since its comeback in November 2021
☐ ☆ ✇ WeLiveSecurity

The good, the bad and the ugly of AI – Week in security with Tony Anscombe

June 30th 2023 at 15:15
The growing use of synthetic media and the difficulties in distinguishing between real and fake content raise a slew of legal and ethical questions
☐ ☆ ✇ WeLiveSecurity

What to know about the MOVEit hack – Week in security with Tony Anscombe

June 23rd 2023 at 15:30
The US government has now announced a bounty of $10 million for intel linking the Cl0p ransomware gang to a foreign government
☐ ☆ ✇ WeLiveSecurity

Stop Cyberbullying Day: Prevention is everyone's responsibility

June 16th 2023 at 11:30
Strategies for stopping and responding to cyberbullying require a concerted, community-wide effort involving parents, educators and children themselves
☐ ☆ ✇ WeLiveSecurity

Android GravityRAT goes after WhatsApp backups

June 15th 2023 at 11:30
ESET researchers analyzed an updated version of Android GravityRAT spyware that steals WhatsApp backup files and can receive commands to delete files
☐ ☆ ✇ WeLiveSecurity

7 tips for spotting a fake mobile app

June 6th 2023 at 11:30
Plus, 7 ways to tell that you downloaded a sketchy app and 7 tips for staying safe from mobile security threats in the future
☐ ☆ ✇ WeLiveSecurity

Shedding light on AceCryptor and its operation

May 25th 2023 at 11:30
ESET researchers reveal details about a prevalent cryptor, operating as a cryptor-as-a-service used by tens of malware families
☐ ☆ ✇ WeLiveSecurity

Digital security for the self-employed: Staying safe without an IT team to help

May 24th 2023 at 11:30
Nobody wants to spend their time dealing with the fallout of a security incident instead of building up their business
☐ ☆ ✇ WeLiveSecurity

The danger within: 5 steps you can take to combat insider threats

By Márk Szabó — July 13th 2023 at 09:30

Some threats may be closer than you think. Are security risks that originate from your own trusted employees on your radar?

The post The danger within: 5 steps you can take to combat insider threats appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

ESET Research Podcast: Finding the mythical BlackLotus bootkit

By ESET Research — July 12th 2023 at 09:30

A story of how an analysis of a supposed game cheat turned into the discovery of a powerful UEFI threat

The post ESET Research Podcast: Finding the mythical BlackLotus bootkit appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

ESET Threat Report H1 2023

By Roman Kováč — July 11th 2023 at 09:30

A view of the H1 2023 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts

The post ESET Threat Report H1 2023 appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

What’s up with Emotet?

By Jakub Kaloč — July 6th 2023 at 09:30

A brief summary of what happened with Emotet since its comeback in November 2021

The post What’s up with Emotet? appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Verizon 2023 DBIR: What’s new this year and top takeaways for SMBs

By Phil Muncaster — July 3rd 2023 at 09:30

Here are some of the key insights on the evolving data breach landscape as revealed by Verizon’s analysis of more than 16,000 incidents

The post Verizon 2023 DBIR: What’s new this year and top takeaways for SMBs appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Avoid juice jacking and recharge your batteries safely this summer

By Márk Szabó — June 28th 2023 at 09:30

Cybercriminals can use USB charging stations in airports, hotels, malls or other public spaces as conduits for malware

The post Avoid juice jacking and recharge your batteries safely this summer appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Passwords out, passkeys in: are you ready to make the switch?

By Phil Muncaster — June 20th 2023 at 09:30

With passkeys poised for prime time, passwords seem passé. What are the main benefits of ditching one in favor of the other?

The post Passwords out, passkeys in: are you ready to make the switch? appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Android GravityRAT goes after WhatsApp backups

By Lukas Stefanko — June 15th 2023 at 09:30

ESET researchers analyzed an updated version of Android GravityRAT spyware that steals WhatsApp backup files and can receive commands to delete files

The post Android GravityRAT goes after WhatsApp backups appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Cyber insurance: What is it and does my company need it?

By Phil Muncaster — June 13th 2023 at 09:30

While not a 'get out of jail free card' for your business, cyber insurance can help insulate it from the financial impact of a cyber-incident

The post Cyber insurance: What is it and does my company need it? appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Asylum Ambuscade: crimeware or cyberespionage?

By Matthieu Faou — June 8th 2023 at 09:30

A curious case of a threat actor at the border between crimeware and cyberespionage

The post Asylum Ambuscade: crimeware or cyberespionage? appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

7 tips for spotting a fake mobile app

By Roman Cuprik — June 6th 2023 at 09:30

Plus, 7 ways to tell that you downloaded a sketchy app and 7 tips for staying safe from mobile security threats in the future

The post 7 tips for spotting a fake mobile app appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

All eyes on APIs: Top 3 API security risks and how to mitigate them

By Phil Muncaster — June 1st 2023 at 09:30

As APIs are a favorite target for threat actors, the challenge of securing the glue that holds various software elements together is taking on increasing urgency

The post All eyes on APIs: Top 3 API security risks and how to mitigate them appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Shedding light on AceCryptor and its operation

By Jakub Kaloč — May 25th 2023 at 09:30

ESET researchers reveal details about a prevalent cryptor, operating as a cryptor-as-a-service used by tens of malware families

The post Shedding light on AceCryptor and its operation appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Digital security for the self‑employed: Staying safe without an IT team to help

By Phil Muncaster — May 24th 2023 at 09:30

Nobody wants to spend their time dealing with the fallout of a security incident instead of building up their business

The post Digital security for the self‑employed: Staying safe without an IT team to help appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Android app breaking bad: From legitimate screen recording to file exfiltration within a year

By Lukas Stefanko — May 23rd 2023 at 09:30

ESET researchers discover AhRat – a new Android RAT based on AhMyth – that exfiltrates files and records audio

The post Android app breaking bad: From legitimate screen recording to file exfiltration within a year appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Top 5 search engines for internet‑connected devices and services

By Camilo Gutiérrez Amaya — May 18th 2023 at 09:30

A roundup of some of the handiest tools that security professionals can use to search for and monitor devices that are accessible from the internet

The post Top 5 search engines for internet‑connected devices and services appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Meet “AI”, your new colleague: could it expose your company’s secrets?

By Roman Cuprik — May 17th 2023 at 09:30

Before rushing to embrace the LLM-powered hire, make sure your organization has safeguards in place to avoid putting its business and customer data at risk

The post Meet “AI”, your new colleague: could it expose your company’s secrets? appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

You may not care where you download software from, but malware does

By Aryeh Goretsky — May 16th 2023 at 09:30

Why do people still download files from sketchy places and get compromised as a result?

The post You may not care where you download software from, but malware does appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

How the war in Ukraine has been a catalyst in private‑public collaborations

By André Lameiras — May 9th 2023 at 08:00

As the war shows no signs of ending and cyber-activity by states and criminal groups remains high, conversations around the cyber-resilience of critical infrastructure have never been more vital

The post How the war in Ukraine has been a catalyst in private‑public collaborations appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Creating strong, yet user‑friendly passwords: Tips for your business password policy

By Roman Cuprik — May 4th 2023 at 09:30

Don’t torture people with exceedingly complex password composition rules but do blacklist commonly used passwords, plus other ways to help people help themselves – and your entire organization

The post Creating strong, yet user‑friendly passwords: Tips for your business password policy appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

APT groups muddying the waters for MSPs

By James Shepperd — May 2nd 2023 at 09:30

A quick dive into the murky world of cyberespionage and other growing threats facing managed service providers – and their customers

The post APT groups muddying the waters for MSPs appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

RSA Conference 2023 – How AI will infiltrate the world

By Cameron Camp — April 26th 2023 at 14:30

As all things (wrongly called) AI take the world’s biggest security event by storm, we round up of some of their most-touted use cases and applications

The post RSA Conference 2023 – How AI will infiltrate the world appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Evasive Panda APT group delivers malware via updates for popular Chinese software

By Facundo Muñoz — April 26th 2023 at 09:30

ESET Research uncovers a campaign by the APT group known as Evasive Panda targeting an international NGO in China with malware delivered through updates of popular Chinese software

The post Evasive Panda APT group delivers malware via updates for popular Chinese software appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Linux malware strengthens links between Lazarus and the 3CX supply‑chain attack

By Peter Kálnai — April 20th 2023 at 09:30

Similarities with newly discovered Linux malware used in Operation DreamJob corroborate the theory that the infamous North Korea-aligned group is behind the 3CX supply-chain attack

The post Linux malware strengthens links between Lazarus and the 3CX supply‑chain attack appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Discarded, not destroyed: Old routers reveal corporate secrets

By Cameron Camp — April 18th 2023 at 13:00

When decommissioning their old hardware, many companies 'throw the baby out with the bathwater'

The post Discarded, not destroyed: Old routers reveal corporate secrets appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Safety first: 5 cybersecurity tips for freelance bloggers

By Márk Szabó — April 14th 2023 at 09:30

The much-dreaded writer’s block isn’t the only threat that may derail your progress. Are you doing enough to keep your blog (and your livelihood) safe from online dangers?

The post Safety first: 5 cybersecurity tips for freelance bloggers appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

What are the cybersecurity concerns of SMBs by sector?

By Editor — April 12th 2023 at 09:30

Some sectors have high confidence in their in-house cybersecurity expertise, while others prefer to enlist the support of an external provider to keep their systems and data secured

The post What are the cybersecurity concerns of SMBs by sector? appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Why you should spring clean your home network and audit your backups

By Thomas Uhlemann — April 5th 2023 at 09:30

Do you know how many devices are connected to your home network? You don’t? This is precisely why it’s time for a network audit.

The post Why you should spring clean your home network and audit your backups appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Spring into action and tidy up your digital life like a pro

By Thomas Uhlemann — April 4th 2023 at 09:30

Spring is in the air and as the leaves start growing again, why not breathe some new life into the devices you depend on so badly?

The post Spring into action and tidy up your digital life like a pro appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

World Backup Day: Avoiding a data disaster is a forever topic 

By Márk Szabó — March 31st 2023 at 09:30

By failing to prepare you are preparing to fail. Make sure you're able to bounce back if, or when, a data disaster strikes.

The post World Backup Day: Avoiding a data disaster is a forever topic  appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

ESET Research Podcast: A year of fighting rockets, soldiers, and wipers in Ukraine

By ESET Research — March 30th 2023 at 09:30

ESET experts share their insights on the cyber-elements of the first year of the war in Ukraine and how a growing number of destructive malware variants tried to rip through critical Ukrainian systems

The post ESET Research Podcast: A year of fighting rockets, soldiers, and wipers in Ukraine appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Understanding Managed Detection and Response – and what to look for in an MDR solution

By Phil Muncaster — March 23rd 2023 at 10:30

Why your organization should consider an MDR solution and five key things to look for in a service offering

The post Understanding Managed Detection and Response – and what to look for in an MDR solution appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Not‑so‑private messaging: Trojanized WhatsApp and Telegram apps go after cryptocurrency wallets

By Lukas Stefanko — March 16th 2023 at 10:30

ESET researchers analyzed Android and Windows clippers that can tamper with instant messages and use OCR to steal cryptocurrency funds

The post Not‑so‑private messaging: Trojanized WhatsApp and Telegram apps go after cryptocurrency wallets appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

The slow Tick‑ing time bomb: Tick APT group compromise of a DLP software developer in East Asia

By Facundo Muñoz — March 14th 2023 at 10:30

ESET Research uncovered a campaign by APT group Tick against a data-loss prevention company in East Asia and found a previously unreported tool used by the group

The post The slow Tick‑ing time bomb: Tick APT group compromise of a DLP software developer in East Asia appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Love scam or espionage? Transparent Tribe lures Indian and Pakistani officials

By Lukas Stefanko — March 7th 2023 at 10:30

ESET researchers analyze a cyberespionage campaign that distributes CapraRAT backdoors through trojanized and supposedly secure Android messaging apps – but also exfiltrates sensitive information

The post Love scam or espionage? Transparent Tribe lures Indian and Pakistani officials appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

MQsTTang: Mustang Panda’s latest backdoor treads new ground with Qt and MQTT

By Alexandre Côté Cyr — March 2nd 2023 at 10:30

ESET researchers tease apart MQsTTang, a new backdoor used by Mustang Panda, which communicates via the MQTT protocol

The post MQsTTang: Mustang Panda’s latest backdoor treads new ground with Qt and MQTT appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

BlackLotus UEFI bootkit: Myth confirmed

By Martin Smolár — March 1st 2023 at 10:30

The first in-the-wild UEFI bootkit bypassing UEFI Secure Boot on fully updated UEFI systems is now a reality

The post BlackLotus UEFI bootkit: Myth confirmed appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

ESET Research Podcast: Ransomware trashed data, Android threats soared in T3 2022

By ESET Research — February 28th 2023 at 10:30

And that’s just the tip of the iceberg when it comes to the trends that defined the cyberthreat landscape in the final four months of 2022.

The post ESET Research Podcast: Ransomware trashed data, Android threats soared in T3 2022 appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

A year of wiper attacks in Ukraine

By ESET Research — February 24th 2023 at 10:30

ESET Research has compiled a timeline of cyberattacks that used wiper malware and have occurred since Russia’s invasion of Ukraine in 2022

The post A year of wiper attacks in Ukraine appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

WinorDLL64: A backdoor from the vast Lazarus arsenal?

By Vladislav Hrčka — February 23rd 2023 at 10:30

The targeted region, and overlap in behavior and code, suggest the tool is used by the infamous North Korea-aligned APT group

The post WinorDLL64: A backdoor from the vast Lazarus arsenal? appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

ESET SMB Digital Security Sentiment Report: The damaging effects of a breach

By Editor — February 21st 2023 at 10:30

SMBs need to not only reduce their odds of being hit by an attack, but also implement processes that they can follow if their defenses are breached

The post ESET SMB Digital Security Sentiment Report: The damaging effects of a breach appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Security amidst a global frost

By Cameron Camp — February 16th 2023 at 16:15

No longer relegated to a side-show, tech is embedded into virtually every new piece of gear entering the battlefield

The post Security amidst a global frost appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

These aren’t the apps you’re looking for: fake installers targeting Southeast and East Asia

By Matías Porolli — February 16th 2023 at 10:30

ESET researchers have identified a campaign using trojanized installers to deliver the FatalRAT malware, distributed via malicious websites linked in ads that appear in Google search results

The post These aren’t the apps you’re looking for: fake installers targeting Southeast and East Asia appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Confident cybersecurity means fewer headaches for SMBs

By Editor — February 13th 2023 at 10:30

Small and medium-sized businesses have good reason to be concerned about the loss of data and financial impacts

The post Confident cybersecurity means fewer headaches for SMBs appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Into the void: Your tech and security in digital darkness

By Aryeh Goretsky — February 7th 2023 at 10:30

No internet, perfect security? Two ESET researchers perform a thought experiment where they consider the implications of being plunged into digital darkness.

The post Into the void: Your tech and security in digital darkness appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

SwiftSlicer: New destructive wiper malware strikes Ukraine

By Editor — January 27th 2023 at 17:45

Sandworm continues to conduct attacks against carefully chosen targets in the war-torn country

The post SwiftSlicer: New destructive wiper malware strikes Ukraine appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Introducing IPyIDA: A Python plugin for your reverse‑engineering toolkit

By Rene Holt — January 12th 2023 at 10:30

ESET Research announces IPyIDA 2.0, a Python plugin integrating IPython and Jupyter Notebook into IDA

The post Introducing IPyIDA: A Python plugin for your reverse‑engineering toolkit appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Now you can legally repair your tech – sort of

By Cameron Camp — January 11th 2023 at 10:30

A new law portends a future where (we hope) it will be easier for us all to repair, fix, upgrade, and just tinker with things we already own

The post Now you can legally repair your tech – sort of appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

StrongPity espionage campaign targeting Android users

By Lukas Stefanko — January 10th 2023 at 10:30

ESET researchers identified an active StrongPity campaign distributing a trojanized version of the Android Telegram app, presented as the Shagle app – a video-chat service that has no app version

The post StrongPity espionage campaign targeting Android users appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

Cracked it! Highlights from KringleCon 5: Golden Rings

By Rene Holt — January 9th 2023 at 14:00

Learning meets fun at the 2022 SANS Holiday Hack Challenge – strap yourself in for a crackerjack ride at the North Pole as I foil Grinchum's foul plan and recover the five golden rings

The post Cracked it! Highlights from KringleCon 5: Golden Rings appeared first on WeLiveSecurity

☐ ☆ ✇ WeLiveSecurity

2022 in review: 10 of the year’s biggest cyberattacks

By Phil Muncaster — December 27th 2022 at 10:30

The past year has seen no shortage of disruptive cyberattacks – here’s a round-up of some of the worst hacks and breaches that have impacted a variety of targets around the world in 2022

The post 2022 in review: 10 of the year’s biggest cyberattacks appeared first on WeLiveSecurity

❌