FreshRSS

πŸ”’
☐ β˜† βœ‡ ZDNet | security RSS

Over 40,000 credentials for government portals found online

December 11th 2018 at 12:46
Malware operators have collected login credentials for government portals in Italy, Saudi Arabia, Portugal, Bulgaria, Romania, more.
☐ β˜† βœ‡ Paul's Security Weekly

Coming Together - Business Security Weekly #110

By paul@securityweekly.com β€” December 11th 2018 at 10:00

This week, Matt and Paul interview Brian Carey, Senior Security Consultant at Rapid7! Brian talks about emerging trends that he is seeing with his clients, and how they impact their clients’ security programs, including maturity, roadmap, and recommendations! In the Leadership Articles, Matt and Paul discuss how to collaborate with people you don’t like, the right way to solve complex business problems, what the habits are of successful people, three things to know before you land a tech job, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/BSWEpisode110

To learn more about Rapid7, go to: www.rapid7.com/securityweekly

Β 

Visit https://www.securityweekly.com/bsw for all the latest episodes!

Visit https://www.activecountermeasures/bsw to sign up for a demo or buy our AI Hunter!

Β 

Visit our website: https://www.securityweekly.com

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

Hackers ramp up attacks on mining rigs before Ethereum price crashes into the gutter

December 10th 2018 at 23:06
Attackers scan for Ethereum wallets and mining rigs that have carelessly exposed port 8545 on the Internet.
☐ β˜† βœ‡ ZDNet | security RSS

Google+ hit by second API bug impacting 52.5 million users

December 10th 2018 at 19:20
Google moves Google+ sunset date forward, from August 2019 to April 2019.
☐ β˜† βœ‡ ZDNet | security RSS

Half of the Tor Project's funding now comes from the private sector

December 10th 2018 at 16:47
Tor Project reports $4.2 million income in 2017, of which only 51 percent came from government funds.
☐ β˜† βœ‡ ZDNet | security RSS

Android adware tricks ad networks into thinking it's an iPhone to make more money

December 10th 2018 at 05:30
New Android adware discovered in 22 apps downloaded over two million times.
☐ β˜† βœ‡ ZDNet | security RSS

Cybercrime and malware, 2019 predictions

December 9th 2018 at 10:39
Experts weigh in on what they believe will happen to the world of cybercrime, malware, and botnets in the coming year.
☐ β˜† βœ‡ ZDNet | security RSS

Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix

December 8th 2018 at 23:44
Bug dealt with in Chrome and Edge, but still a problem for Firefox users.
☐ β˜† βœ‡ Paul's Security Weekly

The Bleeding Edge - Paul's Security Weekly #585

By paul@securityweekly.com β€” December 8th 2018 at 10:00

This week, how Docker containers can be exploited to mine for cryptocurrency, WordPress sites attacking other WordPress sites, why the Marriott breach is a valuable IT lesson, malicious Chrome extensions, why hospitals are the next frontier of cybersecurity, and how someone is claiming to sell a Mass Printer Hijacking service! In our first Technical Segment, we welcome Marcello Salvati, Security Consultant at BHIS, to talk about SILENTTRINITY, a post-exploitation agent powered by Python, IronPython, C#/.NET! In our second Technical Segment, we air a pre-recorded interview of Lenny Zeltser, VP of Products at Minerva! Lenny will be discussing Evasion Tactics in Malware from the Inside Out!

Β 

Full Show Notes: https://wiki.securityweekly.com/Episode585

Visit https://www.securityweekly.com/psw for all the latest episodes!

Β 

To learn more about Minerva Labs, go to: https://l.minerva-labs.com/security-weekly

To learn more about Black Hills Information Security, go to: https://www.blackhillsinfosec.com/PSW

To look more into SILENTTRINITY, go to: https://github.com/byt3bl33d3r/SILENTTRINITY

Β 

Visit https://www.activecountermeasures/psw to sign up for a demo or buy our AI Hunter!

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

Those annoying sextortion scams are redirecting users to ransomware now

December 8th 2018 at 08:30
Sextortion emails take a dark turn and are now trying to infect users with the GandCrab ransomware.
☐ β˜† βœ‡ ZDNet | security RSS

Senator blasts FTC for failing to crack down on Google's ad fraud problems

December 7th 2018 at 22:34
US Senator says Google is profiting off advertising fraud and has no interest in addressing it.
☐ β˜† βœ‡ ZDNet | security RSS

DHS looking into tracking Monero and Zcash transactions

December 7th 2018 at 18:38
DHS has had great success with tracking and analyzing Bitcoin transactions already. They are now looking for similar solutions for tracking "privacy coins."
☐ β˜† βœ‡ ZDNet | security RSS

OpSec mistake brings down network of Dark Web money counterfeiter

December 7th 2018 at 17:04
European law enforcement conducts 300 house searches and makes 235 arrests.
☐ β˜† βœ‡ ZDNet | security RSS

Marriott to reimburse some guests for new passports after massive data breach

December 7th 2018 at 14:53
Hotel chain responds to US senator. Says it will foot the bill for some users' passport replacement costs.
☐ β˜† βœ‡ ZDNet | security RSS

Eastern European banks lose tens of millions of dollars in Hollywood-style hacks

December 7th 2018 at 01:24
Cybercriminals leave laptops, Raspberry Pi boards, and USB thumb drives connected to banks IT networks.
☐ β˜† βœ‡ ZDNet | security RSS

Industrial espionage fears arise over Chrome extension caught stealing browsing history

December 7th 2018 at 00:06
Company test runs own traffic analysis service and finds malicious Chrome extension in its own backyard. Ooops!
☐ β˜† βœ‡ ZDNet | security RSS

ESET discovers 21 new Linux malware families

December 6th 2018 at 15:05
All malware strains are trojanized versions of the OpenSSH server or client apps that include keylogger and backdoor capabilities.
☐ β˜† βœ‡ Paul's Security Weekly

Light Years - Enterprise Security Weekly #118

By paul@securityweekly.com β€” December 6th 2018 at 10:00

This week, Paul and John Strand interview Mike Nichols, the VP of Product for Endgame! Mike joins us to talk about the MITRE evaluation of Endgame, Open-Source Query Language EQL, and more! In the Enterprise Security News, Ixia extends collaboration with ProtectWise, Ping Identity brings in New Customer Identity as a service solution, Fortinet introduces new security automation capabilities on AWS, Yubico announces YubiHSM 2 integration with AWS IoT Greengrass, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/ES_Episode118

Visit https://www.securityweekly.com/esw for all the latest episodes!

Β 

To learn more about Endgame, go to: www.endgame.com

Visit https://www.activecountermeasures/esw to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

Twelve US states join for the first time to file multistate data breach lawsuit

December 6th 2018 at 01:41
Lawsuit details a long list of security fails on MIE's part.
☐ β˜† βœ‡ ZDNet | security RSS

A botnet of over 20,000 WordPress sites is attacking other WordPress sites

December 5th 2018 at 23:44
Botnet is still up and running but law enforcement has been notified.
☐ β˜† βœ‡ ZDNet | security RSS

BeatStars discloses security breach in Twitter live stream

December 5th 2018 at 18:55
BeatStars website mass-defaced after hacker intrusion. Website back up and running again.
☐ β˜† βœ‡ ZDNet | security RSS

Adobe releases out-of-band security update for newly discovered Flash zero-day

December 5th 2018 at 15:26
Zero-day spotted embedded in malicious Office documents uploaded on VirusTotal.
☐ β˜† βœ‡ ZDNet | security RSS

Cyber-espionage group uses Chrome extension to infect victims

December 5th 2018 at 15:00
Suspected North Korean APT uses Google Chrome extension to infect victims in the academic sector.
☐ β˜† βœ‡ Paul's Security Weekly

Stuck In My Teeth - Application Security Weekly #42

By paul@securityweekly.com β€” December 5th 2018 at 10:00

This week, Keith and Paul interview Aleksei Tiurin, Senior Security Researcher at Acunetix! Aleksei joins Keith and Paul this week for a Technical Segment on reverse proxies using WebLogic, Nginx, and Tomcat! In the Application Security News, hackers are opening SMB ports on routers to infect PC’s with NSA malware, bug detectives whip up smarter version of classic AFL fuzzer to hunt code vulnerabilities, malware & rogue users can spy on some apps' HTTPS crypto, exploiting developer infrastructure is insanely easy, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/ASW_Episode42

To learn more about Acunetix, go to: www.acunetix.com/securityweekly

Β 

Visit https://www.securityweekly.com/asw for all the latest episodes!

Visit https://www.activecountermeasures/asw to sign up for a demo or buy our AI Hunter!

Β 

Visit our website: https://www.securityweekly.com

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

The CoAP protocol is the next big thing for DDoS attacks

December 5th 2018 at 04:13
CoAP DDoS attacks have already been detected in the wild, some clocking at 320Gbps.
☐ β˜† βœ‡ ZDNet | security RSS

Google releases Chrome 71 with a focus on security features

December 4th 2018 at 21:35
Google improves Chrome's ability to filter abusive ads and detect shady mobile subscription forms.
☐ β˜† βœ‡ ZDNet | security RSS

Over 100,000 PCs infected with new ransomware strain in China

December 4th 2018 at 15:44
Ransomware authors might have shot themselves in the foot by handling payments via WeChat. Local law enforcement could track ransom payments.
☐ β˜† βœ‡ Paul's Security Weekly

Hack Naked News #199 - December 4, 2018

By paul@securityweekly.com β€” December 4th 2018 at 21:05

This week, hijacking printers to promote a YouTube channel, fake iOS apps that steal money, Google patches 11 critical RCE Android Vulnerabilities, Marriott hack hits 500 million Starwood guests, and getting Pwned through an oscilloscope! Jason Wood from Paladin Security joins us for expert commentary to discuss how the "Iceman" hacker was charged with running a drone-smuggling ring from jail, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/HNNEpisode199

Β 

Visit https://www.securityweekly.com/hnn for all the latest episodes!

Visit https://www.activecountermeasures/hnn to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ Paul's Security Weekly

That's Success - Business Security Weekly #109

By paul@securityweekly.com β€” December 4th 2018 at 10:00

This week, Matt Alderman interviews Jay Prassl, CEO of Automox in a Pre-Recorded interview! Jay explains what Automox does, how Automox bridges the gap between ITOps and SecOps use case, and how Automox defines the way to patch systems in the MacOS, Linux, Windows, and MSP! In the Leadership Articles, Paul is joined by Jason Alburquerque to discuss the new math of leadership, how pragmatic leaders can transform stuck organizations, why building a work community is critical, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/BSWEpisode109

Β 

To learn more about Automox, go to: www.automox.com

Visit https://www.securityweekly.com/bsw for all the latest episodes!

Visit https://www.activecountermeasures/bsw to sign up for a demo or buy our AI Hunter!

Β 

Visit our website: https://www.securityweekly.com

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

Quora discloses mega breach impacting 100 million users

December 4th 2018 at 02:17
Account info, passwords, emails, private messages, and user votes were exposed.
☐ β˜† βœ‡ ZDNet | security RSS

Researchers discover SplitSpectre, a new Spectre-like CPU attack

December 4th 2018 at 01:36
Spectre-like variations continue to be discovered, just as academics predicted at the start of 2018.
☐ β˜† βœ‡ ZDNet | security RSS

Two iOS fitness apps tricked users into making TouchID payments

December 3rd 2018 at 20:19
Both apps β€”"Fitness Balance app" and "Calories Tracker app"β€” removed from the Apple App Store.
☐ β˜† βœ‡ ZDNet | security RSS

New online service will hack printers to spew out spam

December 3rd 2018 at 17:30
PewDiePie hack has spawned a new web service over the weekend: Printer-Spam-as-a-Service.
☐ β˜† βœ‡ ZDNet | security RSS

Czech Republic blames Russia for multiple government network hacks

December 3rd 2018 at 15:23
Czech intelligence service says two Russian cyber-espionage groups hacked Ministry of Foreign Affairs, Ministry of Defense, and members of the Czech Army.
☐ β˜† βœ‡ ZDNet | security RSS

Marriott sued hours after announcing data breach

December 3rd 2018 at 00:52
One class-action lawsuit is seeking $12.5 billion in damages.
☐ β˜† βœ‡ ZDNet | security RSS

ACLU wants court to release documents on the US' attempt at backdooring Facebook Messenger

December 1st 2018 at 20:05
While the FBI-vs-Apple battle played out in the public, the FBI-vs-Facebook encryption backdoor war remained a secret for months.
☐ β˜† βœ‡ Paul's Security Weekly

Donut Jokes - Paul's Security Weekly #584

By paul@securityweekly.com β€” December 1st 2018 at 10:00

This week, Wietse Venema and Dan Farmer, the Developers of Security Administrator Tool for Analyzing Networks (SATAN) Sven Morgenroth of Netsparker will talk about PHP Object injection vulnerabilities and explain the dangers of PHP's unserialize function, and the crew will wrap the show with the Security News!

Full Show Notes: https://wiki.securityweekly.com/Episode584

To learn more about Netsparker, go to: https://www.netsparker.com/securityweekly

Follow us on Twitter: https://www.twitter.com/securityweekly

☐ β˜† βœ‡ ZDNet | security RSS

Twitter user hacks 50,000 printers to tell people to subscribe to PewDiePie

December 1st 2018 at 01:09
Hacker lends a helping hand to YouTube star losing his crown.
☐ β˜† βœ‡ ZDNet | security RSS

Moscow's new cable car system infected with ransomware two days after launch

November 30th 2018 at 15:45
Cable car system is now back up and running after a two-day downtime.
☐ β˜† βœ‡ ZDNet | security RSS

Marriott reveals data breach affecting 500 million hotel guests

November 30th 2018 at 14:26
Hackers have had access to the Starwood guest reservation database since 2014.
☐ β˜† βœ‡ ZDNet | security RSS

These are the worst hacks, cyberattacks, and data breaches of 2018

November 30th 2018 at 14:19
Millions of records were lost, services were disrupted, and credit card data was stolen as hackers ran amok over the year.
☐ β˜† βœ‡ ZDNet | security RSS

This is how Docker containers can be exploited to mine for cryptocurrency

November 30th 2018 at 12:37
Containers are becoming a target for cryptojacking in rising numbers.
☐ β˜† βœ‡ ZDNet | security RSS

Samba Trojan becomes the bread and butter of fresh attack campaign

November 30th 2018 at 10:46
The malware's veteran operators go low and slow to compromise Linux machines without detection.
☐ β˜† βœ‡ ZDNet | security RSS

Floyd Mayweather, DJ Khaled settle SEC charges over illegal endorsement of cryptocurrency ICOs

November 30th 2018 at 09:26
"You can call me Floyd Crypto Mayweather from now on."
☐ β˜† βœ‡ ZDNet | security RSS

US Senate computers will use disk encryption

November 30th 2018 at 00:48
New security measure is meant to protect sensitive Senate data on stolen Senate laptops and computers.
☐ β˜† βœ‡ ZDNet | security RSS

After Microsoft complaints, Indian police arrest tech support scammers at 26 call centers

November 29th 2018 at 20:04
Indian police raid 26 call centers, make 63 arrests.
☐ β˜† βœ‡ ZDNet | security RSS

Sky Brasil exposes data of 32 million subscribers

November 29th 2018 at 18:06
The cause of the data leak was an Internet-accessible ElasticSearch server that was left without a password.
☐ β˜† βœ‡ ZDNet | security RSS

Hackers can exploit this bug in surveillance cameras to tamper with footage

November 29th 2018 at 15:00
Researchers have uncovered a vulnerability which can be used to completely compromise surveillance cameras and feeds.
☐ β˜† βœ‡ ZDNet | security RSS

AriseBank CEO faces 120 years behind bars over alleged cryptocurrency scam

November 29th 2018 at 13:00
Millions of dollars in investor funds were allegedly spent by the suspect on a luxury lifestyle.
☐ β˜† βœ‡ ZDNet | security RSS

KingMiner malware hijacks the full power of Windows Server CPUs

November 29th 2018 at 11:54
Attack rates are rising and detection rates are falling.
☐ β˜† βœ‡ Paul's Security Weekly

Back on the Saddle - Enterprise Security Weekly #117

By paul@securityweekly.com β€” November 29th 2018 at 10:00

This week, Paul and John Strand to interview Jeremy Winter, Director of Azure Management at Microsoft, to talk about Microsoft's Azure program, what they have built, and how it helps further the evolving roles of Cloud Ops and Cloud Security! In the Enterprise News this week, StackPath launches EdgeEngine Serverless Computing, Alcide advances Cloud-Native security firewall platform, Orkus launches Access Governance platform for Cloud Security, Tufin announces a new Cloud Security solution, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/ES_Episode117

Visit https://www.securityweekly.com/esw for all the latest episodes!

Visit https://www.activecountermeasures/esw to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

Dunkin' Donuts accounts may have been hacked in credential stuffing attack

November 29th 2018 at 01:19
Hackers were after user accounts in the company's rewards points program.
☐ β˜† βœ‡ ZDNet | security RSS

Dell announces security breach

November 28th 2018 at 22:14
Company says it detected an intrusion at the start of the month, but financial data was not exposed.
☐ β˜† βœ‡ ZDNet | security RSS

Hackers are opening SMB ports on routers so they can infect PCs with NSA malware

November 28th 2018 at 20:04
Akamai says that over 45,000 routers have been compromised already.
☐ β˜† βœ‡ ZDNet | security RSS

New industrial espionage campaign leverages AutoCAD-based malware

November 28th 2018 at 15:57
Researchers warn about industrial espionage group targeting companies in the energy sector with AutoCAD-based malware.
☐ β˜† βœ‡ ZDNet | security RSS

ElasticSearch server exposed the personal data of over 57 million US citizens

November 28th 2018 at 15:00
Leaky database taken offline, but not after leaking user details for nearly two weeks.
☐ β˜† βœ‡ ZDNet | security RSS

Atrium Health data breach exposed 2.65 million patient records

November 28th 2018 at 12:19
The security incident also exposed an estimated 700,000 Social Security numbers.
☐ β˜† βœ‡ ZDNet | security RSS

Second time lucky: Cisco pushes fix for failed Webex vulnerability patch

November 28th 2018 at 11:30
New attack techniques have rendered the original patch useless.
☐ β˜† βœ‡ ZDNet | security RSS

IBM QRadar Advisor with Watson boosted with MITRE framework

November 28th 2018 at 11:00
The machine learning system is being given a crash course in cybercriminal techniques.
☐ β˜† βœ‡ ZDNet | security RSS

Pegasus gov't spyware used to target colleague of slain drug cartel journalist

November 28th 2018 at 10:23
Just days after the death of a reporter investigating drug cartels, the spyware appeared on the radar.
❌