The final version of the 2017 OWASP Top 10 has been released on Monday and some kinds of vulnerabilities that are not serious have been substituted with vulnerabilities that are more expected to pose a significant threat. Many years ago, injection remained the top web application security vulnerability, but there […]
Not again: Hackers steal $31 million worth of crypto
Crypto hackers are at it again. According to Tether, a company that’s behind the cryptocurrency of the same name (known by the symbol USDT), someone recently stole nearly $31 million from its digital vault. The announcement, together with Tether’s website, is currently offline, but an archived version says that « $30,950,010 […]
Biggest Cybersecurity Threats for 2018
IBM recently announced the shocking average cost of data breach. While down around 10 percent, the global average for a data breach is $3.62 million. For many companies, the cost of suffering a cyberattack is enough to take the business down entirely, so it has never been more vital for […]
US CERT issues warning on ASLR vulnerability in Windows
US CERT has issued a warning on a vulnerability in Windows’ Address Space Layout Randomization (ASLR) that affects Windows 8, Windows 8.1, and Windows 10 which could an attacker to take control of an affected system. CERT’s Will Dormann wrote in Vulnerability Note #817544 that both the Enhanced Mitigation Experience […]
‘Advanced’ Cyber Attack Targets Saudi Arabia
The government’s National Cyber Security Centre said the attack involved the use of « Powershell » malware, but it did not comment on the source of the attack or which government bodies were targeted. RIYADH, SAUDI ARABIA: Saudi authorities said Monday they had detected an « advanced » cyber attack targeting the kingdom, in […]
According to a report recently published by the security firm Corero the number of DDoS Attacks doubled in the First Half of 2017 due to unsecured IoT.
Denial of Service (DoS) attacks have been around as long as computers have been networked. But if your business relies on the Internet to sell products or collaborate, a DoS attack is more than a nuisance, it can be critical. Over the past few years, the number of DoS attacks […]
Google Collects Android Location Data Even When Location Service Is Disabled
Do you own an Android smartphone? If yes, then you are one of those billions of users whose smartphone is secretly gathering location data and sending it back to Google. Google has been caught collecting location data on every Android device owner since the beginning of this year (that’s for […]
Critical Flaws in Intel Processors Leave Millions of PCs Vulnerable
In past few months, several research groups have uncovered vulnerabilities in the Intel remote administration feature known as the Management Engine (ME) which could allow remote attackers to gain full control of a targeted computer. Now, Intel has admitted that these security vulnerabilities could « potentially place impacted platforms at risk. » […]
Android Malware Appears Linked to Lazarus Cybercrime Group
The McAfee Mobile Research team recently examined a new threat, Android malware that contains a backdoor file in the executable and linkable format (ELF). The ELF file is similar to several executables that have been reported to belong to the Lazarus cybercrime group. (For more on Lazarus, read this post […]
BankBot Returns On Play Store – A Never Ending Android Malware Story
Even after so many efforts by Google for making its Play Store away from malware, shady apps somehow managed to fool its anti-malware protections and infect people with malicious software. A team of researchers from several security firms has uncovered two new malware campaigns targeting Google Play Store users, of […]