Items tagged with security
by
Tim Sweezy - Mon, Feb 27, 2023
The Mozilla Foundation has released a study into Google Play Store's Data Safety labels that found nearly 80 percent of the apps reviewed were false or misleading. Apps such as TikTok, Twitter, and Facebook are listed among those that are...
Read more...
by
Ryan Whitwam - Fri, Feb 17, 2023
Samsung unveiled its latest Galaxy smartphones earlier this month, and they're officially on sale today. They've got a plethora of new goodies, like a 200MP camera and an overclocked Snapdragon chip. Samsung has revealed yet another...
Read more...
by
Nathan Wasson - Tue, Feb 14, 2023
Mortal Kombat has a reputation for being brutal, but rather than exacting excessive violence on video game characters, unknown threat actors are brazenly brutalizing their victims’ finances in a Mortal Kombat-themed ransomware campaign...
Read more...
by
Paul Lilly - Tue, Feb 14, 2023
Scammers are real pieces of...work (substitute any word you like) as they rarely display any scruples—they prey on the elderly, think nothing of wiping out someone's hard-earned life savings, and are opportunistic predators. That latter...
Read more...
by
Nathan Wasson - Mon, Feb 13, 2023
Pepsi Bottling Ventures (PBV) has suffered a major data breach, with hackers making off with a trove of sensitive information. The company has begun notifying affected individuals of this incident, but the details remain sparse. According...
Read more...
by
Paul Lilly - Fri, Feb 10, 2023
Hackers recently managed to infiltrate Reddit and gain access to internal documents, source code, and internal business systems, an admin for the site disclosed. According to Reddit, the cyberattack was the result of a "sophisticated...
Read more...
by
Paul Lilly - Thu, Feb 09, 2023
In a perfect world, online stores would treat your personal data with the most stringent security policies, taking extra precautions to make sure your details don't end up for sale on the dark web. And to be fair, some do (or at least come...
Read more...
by
Nathan Wasson - Fri, Feb 03, 2023
Last year saw a rise in threat actors abusing Microsoft Office macros to infect their victims’ systems with malware, prompting Microsoft to block macros embedded in documents downloaded from the internet. In response, threat actors have...
Read more...
by
Nathan Wasson - Thu, Feb 02, 2023
We often report on phishing campaigns involving fraudulent customer support agents who trick victims into giving up sensitive information or installing malware on their systems. However, sometimes threat actors flip this script, instead...
Read more...
by
Paul Lilly - Wed, Feb 01, 2023
Scams in some form or another have been around for ages, and certainly through the majority of the computer era. They employ different rouses and have different goals, but one thing that binds many of them is they rely on victims letting...
Read more...
by
Nathan Wasson - Wed, Feb 01, 2023
The password manager KeePass is currently the subject of a debate concerning whether or not a particular design decision should be considered a security vulnerability. At the center of this debate is KeePass’ support of triggers, one of...
Read more...
by
Nathan Wasson - Mon, Jan 30, 2023
Earlier this month, a Swiss hacker who goes by the name maia arson crimew exfiltrated a copy the US government’s No Fly List from an insecure server. This list, which names individuals who are forbidden from flying anywhere within US...
Read more...
by
Paul Lilly - Mon, Jan 30, 2023
One of the best ways to avoid mucking up your mobile device with malware is to only download and install software from official app stores. However, you still should never let your guard down, even when avoiding the side-loading scene...
Read more...
by
Nathan Ord - Sat, Jan 28, 2023
In 2022, the National Security Agency, in conjunction with the U.K’s National Cyber Security Centre, reported a critical vulnerability in the Windows CryptoAPI to Microsoft. While this was patched in August of 2022 and published in October...
Read more...
by
Nathan Wasson - Fri, Jan 27, 2023
Last November, two weeks after the Biden administration held the second International Counter Ransomware Summit, the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of...
Read more...
by
Nathan Wasson - Thu, Jan 26, 2023
Yesterday, the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) published a joint cybersecurity advisory warning network...
Read more...
by
Nathan Wasson - Wed, Jan 25, 2023
TA444 is an advanced persistent threat (APT) group believed to be associated with the North Korean government. However, rather than receiving financial backing from its government, the group seems to bring in revenue for the government...
Read more...
by
Nathan Wasson - Tue, Jan 24, 2023
Over the past week, Gmail users have been reporting abuse of the Google Ads platform. However, rather than conducting ad fraud or placing ads that distribute malware, the actors behind this recent activity are leveraging the Google Ads...
Read more...
by
Nathan Wasson - Tue, Jan 24, 2023
A massive ad fraud campaign has shut down after undergoing mitigation efforts organized by HUMAN, cybersecurity firm that works to distinguish human beings from bots for the purpose of disrupting cybercrime. The ad fraud campaign, dubbed...
Read more...
by
Ryan Whitwam - Mon, Jan 23, 2023
The key to any malware campaign is getting malicious code onto a target device, and often, attackers will use a legitimate app store as a vector. Samsung's Android smartphones ship with the Google Play Store, which has hosted its fair...
Read more...
by
Paul Lilly - Mon, Jan 23, 2023
FanDuel is sending out emails to customers letting them know of a security incident that compromised certain private details. According to the email, which we received first-hand, the security breach occurred at a third-party vendor that...
Read more...
by
Nathan Wasson - Fri, Jan 20, 2023
Yesterday, T-Mobile, one of the big three mobile internet service providers in the US, announced that it recently fell victim to a data breach. The company disclosed this information in both a news release and a filing with the Securities...
Read more...