May 21, 2020 Massive Phishing Campaign Distributing Legitimate Remote Admin Tool as RAT A phishing campaign has been detected that exploits the COVID-19 pandemic to spread a legitimate remote administration tool which is being used as a remote ... Read more
May 19, 2020 Another Malware Variant Identified that Targets Air-Gapped Networks In the past week, three cybersecurity firms have announced they have found malware variants that are being used to target air-gapped networks. First came the ... Read more
May 15, 2020 Ramsay Malware Designed to Steal Data from Air-Gapped Networks A new malware toolkit has been discovered that appears to have been developed to steal sensitive data from air-gapped networks. Researchers at ESET have named ... Read more
May 14, 2020 Prioritize Patching and Fix These Commonly Exploited Vulnerabilities A joint alert has been issued by the U.S. Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation ... Read more
May 1, 2020 Easily Exploitable RCE Salt Vulnerabilities Discovered that Require Urgent Attention Researchers at F-Secure have identified two high severity vulnerabilities in the SaltStack Python-based open source Salt project, which can allow remote code execution as root ... Read more
April 27, 2020 Sophos Discovers and Patches Actively Exploited Flaw in its XG Firewall Sophos has released a patch for a zero-day vulnerability in its XG Firewall which has been exploited in attacks to deliver malware. The flaw was ... Read more
April 23, 2020 Actively Exploited Zero-Day Flaws Identified in iOS Mail Application Two critical zero-day vulnerabilities have been identified in the iOS Mail application that have been exploited by threat actors in attacks on high profile targets ... Read more
April 21, 2020 Phishing Campaign Claims Tens of Millions of Euros of Government COVID-19 Payouts A phishing campaign has resulted in losses of tens of millions of Euros for the German North-Rhine-Westphalia (NRW) government. The NRW government’s Ministry of Economic ... Read more
April 15, 2020 Three Actively Exploited Flaws Patched by Microsoft On April 2020 Patch Tuesday, Microsoft made available updates to fix 113 flaws in its operating systems and software solutions, 19 of which have been ... Read more
April 14, 2020 FTC: Coronavirus and COVID-19 Scams Result in Losses of $12.78 Million in 2020 Figures released by the U.S. Federal Trade Commission (FTC) have revealed the extent of losses to coronavirus and COVID-19 scams in 2020. The FTC received ... Read more
April 8, 2020 Zoom Installers are Being Bundled with Malware The sheer number of people now working from home to maintain social distancing during the coronavirus lockdown has resulted in huge interest in teleconferencing platforms ... Read more
April 6, 2020 Lokibot Information Stealer Distributed in Spear Phishing ampaign Impersonating WHO Researchers at Fortinet’s FortiGuard Labs have identified a new spear phishing campaign that impersonates the World Health Organization (WHO) to distribute the LokiBot information stealer. ... Read more
April 3, 2020 Beware of New Coronavirus Wiper Malware A new wiper malware has been detected that uses a similar method to the 2017 NotPetya wiper malware to trash computers by overwriting the Master ... Read more
April 2, 2020 Phishing Campaigns Using Offer of Coronavirus Financial Relief as Lure Governments around the world are developing financial relief packages to help citizens that have been unable to work due to the coronavirus and are facing ... Read more
March 31, 2020 Micropatch Released for Actively Exploited Windows Font Processing Vulnerabilities Library were being actively exploited in the wild. The flaws concern how type 1 PostScript fonts are handled. The flaws can be exploited if a ... Read more
March 30, 2020 Cybercriminals are Changing DNS Settings on Routers to Deliver Malware Through Fake Coronavirus Apps A malware distribution campaign has been detected that uses malicious coronavirus apps to deliver the Oski information stealing Trojan. The campaign was detected by Bitdefender ... Read more
March 23, 2020 All Supported Windows Versions Affected by Two Actively Exploited Zero-Day RCE Flaws Microsoft has issued a security advisory about two actively exploited zero-day flaws in Windows Adobe Type Manager Library. The critical remote code execution vulnerabilities affect ... Read more
March 20, 2020 WHO Director-General Impersonated in Spam Campaign Delivering HawkEye Keylogger and Malware Downloader Another coronavirus-themed phishing campaign has been detected impersonating the World Health Organization (WHO), or more specifically, the Director-General of WHO, Dr. Tedros Adhanom Ghebreyesus. The ... Read more
March 19, 2020 Coronavirus Pandemic Guidance on Telehealth & HIPAA Released by OCR After the announcement made by the HHS’ Office for Civil Rights that enforcement of HIPAA compliance linked to the good faith provision of telehealth services ... Read more
March 11, 2020 Microsoft Announces Takedown of Necurs Botnet Microsoft has announced it has seized the U.S. command and control infrastructure of the Necurs botnet and has taken steps to prevent the infrastructure from ... Read more
March 10, 2020 Microsoft Exchange RCE Vulnerability Being Actively Exploited in the Wild A post-auth remote code execution vulnerability affecting all supported versions of Microsoft Exchange Server is now being exploited in the wild by multiple advanced persistent ... Read more
March 6, 2020 Vulnerability in Walgreens Mobile App Secure Messaging Feature Made PHI Accessible Walgreens has started contacting customers to make them aware that a portion of their protected health information may have been accessed by unauthorized individual due ... Read more
March 6, 2020 TrickBot Trojan Gets Trickier with ActiveX Control to Automatically Run Malicious Macros The TrickBot Trojan is now even trickier now that a Windows 10 ActiveX control has been incorporated to automatically run malicious macros in email Office ... Read more
March 4, 2020 More Than 1 Billion Devices Affected by Kr00k Wi-Fi Encryption Vulnerability A vulnerability has been identified in Wi-Fi chips manufactured by Broadcom and Cypress which are used in more than a billion devices, according to a ... Read more
February 27, 2020 74% of Phishing Sites Now Use HTTPS The latest phishing activity trends report from the Anti-Phishing Working Group (APWG) shows a decline in the number of detected phishing sites after the 3-year ... Read more
February 26, 2020 Phishers’ Favorite Report Reveals Massive Increase in WhatsApp Phishing URLs The Q4, 2019 Phishers’ Favorite report from email security firm Vade Secure shows PayPal is the most impersonated brand in phishing attacks, making it two ... Read more
February 20, 2020 Q4 2019 Threat Report Reveals Emotet Dominates Threat Landscape The Q4, 2019 Threat Report from cybersecurity firm Proofpoint has confirmed Emotet was the biggest malware threat in 2019, accounting for 37% of all malicious ... Read more
February 18, 2020 Fresh Warnings Issued About Coronavirus Phishing Scams Fresh warnings have been issued about coronavirus phishing scams that are being conducted to steal sensitive data and spread malware. Multiple threat actors are taking ... Read more
February 11, 2020 Threat from Phishing Highlighted on Safer Internet Day Today is Safer Internet Day, a global event aimed at promoting safer use of online technology and the creation of a safe and stimulating online ... Read more
February 7, 2020 Malware Campaign Delivers Package of Seven Malware Variants via BitBucket Cybereason’s Nocturnus research team has identified a malware distribution campaign that aims to deliver multiple malware variants via the cloud storage platform BitBucket. The researchers ... Read more