Attackers exfiltrated a casino’s high-roller list through a connected fish tank Nicole Eagan, the CEO of cybersecurity company Darktrace, revealed that is company investigated that hack of an unnamed casino that was breached via a thermometer in a lobby fish tank. Internet of things devices are enlarging our attack surface, smart devices […]
Mozilla doing Google to block FTP sub resources
Mozilla will do a Goggle Chrome to block the loading of FTP sub-resources in HTTP-HTTPS pages introducing a new flag in Firefox 60 to disable the current FTP support in the browser as scheduled on June 26. But the move, even if executed, never would block direct FTP links on […]
Researchers Create Malware That Steals Data via Power Lines
A team of academics has successfully developed and tested malware that can exfiltrate data from air-gapped computers via power lines. The team —from the Ben-Gurion University of the Negev in Israel— named their data exfiltration technique PowerHammer. PowerHammer works by infecting an air-gapped computer with malware that intentionally alters CPU utilization […]
Compile Error Halts Some GandCrab Ransomware Infections
A script compile error has temporarily stopped the infection chain of a malspam campaign trying to infect users with the GandCrab ransomware. Not all GandCrab versions are affected, but only a GandCrab operation that tries to infect victims via malicious Word files users receive via spam emails. These Word documents contain […]
$3.3 Million stolen from main Coinsecure Bitcoin wallet
Cryptocurrency exchange Coinsecure, India’s second exchange, announced that it has suffered a severe issue, 438 bitcoin, $3,3 million worth of bitcoin Cryptocurrency exchange Coinsecure, India’s second exchange, announced that it has suffered a severe issue, 438 bitcoin, $3,3 million worth of bitcoin, have been transferred from the main wallet to an account that is […]
APT33 devised a code injection technique dubbed Early Bird to evade detection by anti-malware tools
The Iran-linked APT33 group continues to be very active, security researchers at Cyberbit have discovered an Early Bird code injection technique used by the group. The Early Bird method was used to inject the TurnedUp malware into the infected systems evading security solutions. The technique allows injecting a malicious code into a legitimate process, it […]
Malware Distribution Campaign Has Been Raging for More Than Four Months
An organized and highly dynamic malware distribution campaign has been leveraging thousands of hacked websites to redirect users to web pages peddling fake software updates in an attempt to infect them with malware. According to Jerome Segura, the Malwarebytes researcher who analyzed multiple infection chains to piece together the grander […]
Microsoft Removes Antivirus Registry Key Check for All Windows Versions
Microsoft has decided to remove a mandatory « registry key requirement » it introduced in the aftermath of the Meltdown and Spectre vulnerability disclosure. Microsoft used this registry key to prevent Windows updates from being installed on computers running antivirus software incompatible with the Meltdown and Spectre patches. Antivirus vendors were supposed […]
QUANT LOADER TROJAN SPREADS VIA MICROSOFT URL SHORTCUT FILES
Researchers are warning of a new email phishing campaign that downloads and launches the Quant Loader trojan, capable of distributing ransomware and stealing passwords. Barracuda on Tuesday said it has been tracking emails containing zipped Microsoft internet shortcut files with a “.url” file extension sent to millions of inboxes via […]
Phishing par SMS sur WhatsApp : attention aux billets gratuits sur Atlantic Virgin !
Selon un message WhatsApp, Virgin Atlantic offrait deux billets gratuits par famille. Cela semblait trop beau pour être vrai et il est fort probable que cela soit effectivement une arnaque ! Vendredi dernier, nous avons reçu un message WhatsApp qui a piqué notre curiosité : 2 billets gratuits sur Virgin Atlantic ! Billets gratuits […]