Security researchers at Trustwave spotted a new malicious campaign that uses a multi-stage attack to deploy a password stealer. Researchers at Trustwave have spotted a new malware-based campaign that uses a multi-stage infection to deploy a password stealer malware. Hackers leverage the infamous Necurs botnet to distribute spam emails delivering Microsoft Office documents […]
Année : 2018
Phishing: L’arnaque passe aussi par la carte SIM !
Plusieurs consommateurs ont alerté l’UFC-Que Choisir d’une arnaque dont ils ont récemment été victimes, baptisée « arnaque à la carte SIM ». Basée sur la technique du phishing, qui consiste à récolter des renseignements personnels (coordonnées bancaires, identifiants, etc.) en usurpant l’identité d’un fournisseur ou d’une administration, elle permet aux escrocs de […]
Une vicieuse attaque de phishing usurpe Air France
Une campagne de phishing particulièrement évoluée, promettant des billets de vol gratuits, sévit depuis la fin de semaine dernière. L’URL utilisée renvoyant sur un site malveillant utilise un caractère issu de l’alphabet phonétique rendant l’escroquerie presque indécelable. L’URL utilisée par les pirates de l’attaque par phishing ciblant Air France renvoie […]
Un Ransomware Dash d’origine russe infecte des fichiers PDF
Il y a un nouveau ransomware, qui cible les ordinateurs des victimes au moyen de fichiers PDF téléchargeables. Il faut faire preuve de la plus grande précaution lors du téléchargement de fichiers PDF provenant d’expéditeurs inconnus. Qu’est-ce que GandCrab ? La menace imminente est apparue après que LMNTRIX, une société […]
Flight Sim Game Maker Embeds Password-Stealing Malware in Game Mod
Gamers are accusing a company that makes mods for Microsoft’s Flight Simulator X game of putting a password stealer inside one of its add-ons. The company defended its decision by saying the malware works part of a Digital Rights Management (DRM) platform and only activates when users are using a […]
Nearly 8,000 Security Flaws Did Not Receive a CVE ID in 2018
A record-breaking number of 20,832 vulnerabilities have been discovered in 2017 but only 12,932 of these received an official CVE identifier last year, a Risk Based Security (RBS) report reveals. This means that 7,900 security bugs remained without a CVE-2017-XXXXX number, and were left off the databases of many security […]
White House: Cyberattacks Cost US Economy Between $57B and $109B in 2016
Citing a report from the Council of Economic Advisers (CEA), the White House said on Friday that cyberattacks cost the US economy somewhere between $57 billion to $109 billion in 2016. The estimate includes losses from a wide variety of activities, such as DDoS attacks, data breaches, ransom demands, downed infrastructure, lost […]
Null Character Bug Lets Malware Bypass Windows 10 Anti-Malware Scan Interface
Malware that embeds a null character in its code can bypass security scans performed by the Anti-Malware Scan Interface (AMSI) on Windows 10 boxes. Microsoft fixed this vulnerability last week when it released the February 2018 Patch Tuesday security updates. Flaw affects AMSI Windows 10 security feature The vulnerability resides […]
Free Ransomware Available on Dark Web
The McAfee Advanced Threat Research team recently analyzed a ransomware-as-a-service threat that is available for free and without registration. This malware was first seen in July 2017 with the extension .shifr. It has now appeared in recent detections with the extension .cypher. Ransomware-as-a-Service Ransomware-as-a-service is a cybercrime economic model that allows […]
Inside the Capabilities and Detection of UDPoS Malware
Imagine a job that changes every day of your life, where you get to do something new each week – that’s what it’s like working in the cybersecurity industry. For me, this is ideal—smarter adversaries, new challenges, and the constant struggle to predict and prepare for the future of security in […]