Security news that informs and inspires

All Articles

2327 articles:

The Art of Extortion: Cybercriminals Build Up Blackmail Tactics

When it comes to cyber extortion, attackers are constantly on the hunt for new ways to put pressure on victims to pay up.

Ransomware, Data Breaches, Extortion

Attackers Tied to Iran Targeting Office 365 in Password Spraying Campaign

A new group with ties to the Iranian government is conducting a password-spraying campaign against Office 365 accounts.

Microsoft, Iran

FIN12 Ransomware Attackers Target Medical Facilities

The FIN12 group is targeting healthcare providers in the U.S. with aggressive cyberattacks that deploy the Ryuk ransomware.

Healthcare Security, Cybercrime, Ransomware

Scanning Activity for Apache Flaw Began Before Public Disclosure

Attackers were scanning for CVE-2021-41773 in the Apache web server several days before the flaw was disclosed publicly.

Apache

BlackTech Espionage Gang Adds to Malware Toolset

Researchers at VB2021 localhost gave an inside look into new malware families that the BlackTech espionage group is now using.

Malware, APT, Net Exploitation

Behind the Rising Tide of Cybersecurity Legislation

At the 2021 Aspen Cyber Summit this week, lawmakers discussed why cybersecurity legislation is picking up - and challenges in the legislative process.

Government, Cybersecurity, Legislation

Espionage Attacks Against Telecom, Aerospace Firms Reveal Stealthy RAT

A RAT that has stayed under the radar for at least three years was recently uncovered in highly targeted espionage attacks against companies in the telecommunications and aerospace industries.

Malware, Cyber Crime, Dropbox, Remote Access Trojan

U.S. Forms Cryptocurrency Enforcement Team to Disrupt Ransomware Payments

The Department of Justice has formed a new National Cryptocurrency Enforcement Team to help disrupt ransomware payments to cybercriminals.

Ransomware, Governance

Apache Fixes Web Server Path Traversal Flaw Under Active Attack

Apache has released a fix for a path traversal flaw (CVE-2021-41773) that has been exploited in the wild.

Apache

New ESPecter UEFI Bootkit Discovered

Researchers have discovered a new UEFI bootkit called ESPecter that can modify the Windows Boot Manager.

Malware, UEFI

Fear of Pegasus Spyware Used to Spread Sarwent RAT

The fear surrounding the Pegasus spyware tool is being used to lure victims to a fake Amnesty International site that installs the Sarwent RAT.

Malware

Device Security is ‘The Big Hairy Monster Under the Bed’

The security of IoT and non-general purpose computing devices represents a systemic risk to corporate and national security, experts say.

Government, Iot Security

Nobelium Deploying FoggyWeb Backdoor in Targeted Attacks

The Nobelium attackers, who are responsible for the SolarWinds intrusion, have been deploying a new backdoor called FoggyWeb in targeted attacks.

Microsoft, Solarwinds

Attackers Target Critical VMware Bug

There is active exploitation of the vCenter Server bug disclosed last week, along with mass scanning activity looking for vulnerable servers.

Vmware

FISMA Update Could Boost CISA’s Authority

Potential new legislation to update FISMA could codify CISA's role and grant it additional authority.

Government, Ransomware