30 Jul

Phishing targeting Polish SMBs continues via ModiLoader

ESET Research ESET researchers detected multiple, widespread phishing campaigns targeting SMBs in Poland during May 2024, distributing various malware families Jakub Kaloč 30 Jul 2024

Author rabih
30 Jul

Proofpoint phishing palaver plagues millions with ‘perfectly spoofed’ emails from IBM, Nike, Disney, others

A huge phishing campaign exploited a security blind-spot in Proofpoint’s email filtering systems to send an average of three million “perfectly spoofed” messages a day

Author rabih
30 Jul

Malaysia is working on an internet ‘kill switch’, says minister

Legislation for an internet “kill switch” will reach Malaysia’s Parliament in October, according to the country’s minister for Law and Institutional Reform. Minister Azalina Othman

Author rabih
29 Jul

Meta’s AI safety system defeated by the space bar

Meta’s machine-learning model for detecting prompt injection attacks – special prompts to make neural networks behave inappropriately – is itself vulnerable to, you guessed it,

Author rabih
29 Jul

Post-CrowdStrike, Microsoft to discourage use of kernel drivers by security tools

Updated Microsoft has vowed to reduce cybersecurity vendors’ reliance on kernel-mode code, which was at the heart of the CrowdStrike super-snafu this month. Redmond shared

Author rabih
29 Jul

US border cops really must get a warrant in NY before searching your phones, devices

US border agents must obtain a warrant, in New York at least, to search anyone’s phone and other electronic device when traveling in or out

Author rabih
29 Jul

Post-CrowdStrike, Microsoft to discourage use of kernel drivers by security software

Microsoft has admitted that its estimate of 8.5 million machines crashed by CrowdStrike’s faulty software update was based on incomplete data and vowed to reduce

Author rabih
29 Jul

Microsoft admits 8.5M CrowdStruck machines estimate was lowballed

Microsoft has admitted that its estimate of 8.5 million machines crashed by CrowdStrike’s faulty software update was almost certainly too low, and vowed to reduce

Author rabih
29 Jul

Intruders at HealthEquity rifled through storage, stole 4.3M people’s data

HealthEquity, a US fintech firm for the healthcare sector, admits that a “data security event” it discovered at the end of June hit the data

Author rabih
29 Jul

Google apologizes for breaking password manager for millions of Windows users with iffy Chrome update

Google celebrated Sysadmin Day last week by apologizing for breaking its password manager for millions of Windows users – just as many Windows admins were

Author rabih
29 Jul

Beware of fake AI tools masking very real malware threats

Generative AI (GenAI) is making waves across the world. Its popularity and widespread use has also attracted the attention of cybercriminals, leading to various cyberthreats.

Author rabih
29 Jul

Microsoft admits 8.5 million CrowdStruck machines estimate was lowballed

Microsoft has admitted that its estimate of 8.5 million machines crashed by CrowdStrike’s faulty software update was almost certainly too low, and vowed to reduce

Author rabih
29 Jul

China ponders creating a national ‘cyberspace ID’

Beijing may soon issue “cyberspace IDs” to its citizens, after floating a proposal for the scheme last Friday. Although the policy is only open for

Author rabih
29 Jul

Secure Boot useless on hundreds of PCs from major vendors after key leak

Infosec in brief Protecting computers’ BIOS and the boot process is essential for modern security – but knowing it’s important isn’t the same as actually

Author rabih
26 Jul

CrowdStrike meets Murphy’s Law: Anything that can go wrong will

Opinion CrowdStrike’s recent Windows debacle will surely earn a prominent place in the annals of epic tech failures. On July 19, the cybersecurity giant accomplished

Author rabih
26 Jul

Progress discloses second critical flaw in Telerik Report Server in as many months

Progress Software’s latest security advisory warns customers about the second critical vulnerability targeting its Telerik Report Server in as many months. CVE-2024-6327 is an insecure

Author rabih
26 Jul

Telegram for Android hit by a zero-day exploit – Week in security with Tony Anscombe

Video Attackers abusing the “EvilVideo” vulnerability could share malicious Android payloads via Telegram channels, groups, and chats, all while making them appear as legitimate multimedia

Author rabih
26 Jul

North Korean chap charged for attacks on US hospitals, military, NASA – and even China

The US Department of Justice on Thursday charged a North Korean national over a series of ransomware attacks on stateside hospitals and healthcare providers, US

Author rabih
Load moreLoadingAll items loaded