Menu

Blog

Archive for the ‘cybercrime/malcode’ category: Page 40

Sep 4, 2023

Chinese APT Targets Hong Kong in Supply Chain Attack

Posted by in category: cybercrime/malcode

An emerging China-backed advanced persistent threat (APT) group targeted organizations in Hong Kong in a supply chain attack that leveraged a legitimate software to deploy the PlugX/Korplug backdoor, researchers have found.

During the attack, the group leveraged as its PlugX installer malware signed with another legitimate entity, a Microsoft certificate, in an abuse of Microsoft’s Windows Hardware Developer Program, a vulnerability already known to the software vendor.

Sep 4, 2023

North Korean malicious package targets Windows

Posted by in category: cybercrime/malcode

A malicious campaign targeting MacOS, Linux, and Windows systems has been attributed to the North Korean threat group Lazarus. Cybersecurity researchers at ReversingLabs made the disclosure after tracking VMConnect for about a month.

ReversingLabs first spotted the VMConnect campaign in early August. Cybersecurity researcher and blogger Karlo Zanki described it as consisting of two dozen “malicious Python packages” posted on the openly accessible PyPI software repository.

Continue reading “North Korean malicious package targets Windows” »

Sep 4, 2023

Russian State-Backed ‘Infamous Chisel’ Android Malware Targets Ukrainian Military

Posted by in categories: cybercrime/malcode, military, mobile phones

Infamous Chisel is described as a collection of multiple components that’s designed with the intent to enable remote access and exfiltrate information from Android phones.

Besides scanning the devices for information and files matching a predefined set of file extensions, the malware also contains functionality to periodically scan the local network and offer SSH access.

“Infamous Chisel also provides remote access by configuring and executing TOR with a hidden service which forwards to a modified Dropbear binary providing a SSH connection,” the Five Eyes (FVEY) intelligence alliance said.

Sep 4, 2023

Is Bias in AI Algorithms a Threat to Cloud Security?

Posted by in categories: cybercrime/malcode, information science, robotics/AI

Artificial intelligence (AI) has been helping humans in IT security operations since the 2010s, analyzing massive amounts of data quickly to detect the signals of malicious behavior. With enterprise cloud environments producing terabytes of data to be analyzed, threat detection at the cloud scale depends on AI. But can that AI be trusted? Or will hidden bias lead to missed threats and data breaches?

Bias can create risks in AI systems used for cloud security. There are steps humans can take to mitigate this hidden threat, but first, it’s helpful to understand what types of bias exist and where they come from.

Sep 3, 2023

Paramount, Forever 21 Data Breaches Set Stage for Follow-on Attacks

Posted by in category: cybercrime/malcode

A pair of breaches have hit media giant Paramount Global and fashion purveyor Forever 21, exposing personally identifiable information for thousands of people in the latter’s case and setting them up for a raft of follow-on attacks.

In Paramount’s case, the Hollywood bigwig disclosed in a data breach notification letter obtained by media that cyberattackers accessed PII for certain individuals for a month, between May and June of this year. The data included names, birthdates, Social Security numbers, driver’s license numbers, passport numbers, and “information related to [the individual’s] relationship with Paramount.”

It’s unclear if the data pertains to website members, employees, customers, or other profiles — or how many are affected. The data breach notification letter, penned by an operations executive at Nickelodeon Animation Studio, did not elaborate.

Sep 3, 2023

A US Bank Says Sensitive Customer Data Has Been Compromised in Global Cybersecurity Breach

Posted by in category: cybercrime/malcode

A New York-based bank says a global cybersecurity incident has exposed sensitive customer data.

In a letter to customers, M&T Bank says the exploit involves the file transfer tool MOVEit, which is used to securely send and receive confidential information.

According to the bank, the attacker was able to access customer data by targeting one of the lender’s third-party vendors.

Sep 3, 2023

Ethical hacker shows us how easily smart devices can be hacked and give access to your personal info

Posted by in categories: cybercrime/malcode, mobile phones

Smart devices will be hot items this holiday season. They hook up to the internet and can be controlled by your phone. However, we have a demonstration that shows how easy it is to hack your home.

Sep 3, 2023

How cyber-crime has become organised warfare | Four Corners

Posted by in categories: business, cybercrime/malcode, government, military

Every seven minutes a cyber-attack is reported in Australia.

Millions of Australians have had their data stolen in malicious attacks, costing some businesses tens of millions of dollars in ransom. The federal government is warning the country must brace for even more strikes as cyber gangs become more sophisticated and ruthless.

Continue reading “How cyber-crime has become organised warfare | Four Corners” »

Sep 3, 2023

Critical digital infrastructure: Why societies are becoming so vulnerable to cyberattacks |Techtopia

Posted by in categories: biotech/medical, cybercrime/malcode

For weeks, a cyberattack paralyzed the German district of Anhalt-Bitterfeld in 2021, bringing its whole administration to a standstill. It was a stark illustration of how hackers can knock out entire communities in milliseconds — and how digital technology has become vital for running our societies.

Such “critical digital infrastructure” helps boost efficiency. But it also makes communities ever more vulnerable to hacking. And attacks are on the rise. In this episode of Techtopia, DW Chief Technology Correspondent Janosch Delcker investigates how a criminal industry makes billions by taking computers hostage — and how governments can use similar methods as a political weapon.

Continue reading “Critical digital infrastructure: Why societies are becoming so vulnerable to cyberattacks |Techtopia” »

Sep 2, 2023

Watch This Russian Hacker Break Into Our Computer In Minutes | CNBC

Posted by in category: cybercrime/malcode

Mikhail Sosonkin, who works for cybersecurity start-up Synack, showed CNBC firsthand how easy it is to break into a computer.
» Subscribe to CNBC: http://cnb.cx/SubscribeCNBC

About CNBC: From ‘Wall Street’ to ‘Main Street’ to award winning original documentaries and Reality TV series, CNBC has you covered. Experience special sneak peeks of your favorite shows, exclusive video and more.

Continue reading “Watch This Russian Hacker Break Into Our Computer In Minutes | CNBC” »

Page 40 of 220First3738394041424344Last