Skip to main content

Posts

The Vulnerabilities of the Past Are the Vulnerabilities of the Future

  Major software vulnerabilities are a fact of life, as illustrated by the fact that Microsoft has patched between 55 and 110 vulnerabilities each month this year – with 7% to 17% of those vulnerabilities being critical. May had the fewest vulnerabilities, with a total of 55 and only four considered critical. The problem is that the critical vulnerabilities are things we have seen for many years, like remote code execution and privilege escalation. Microsoft isn't the only big name regularly patching major vulnerabilities: We see monthly security updates coming from Apple, Adobe, Google, Cisco, and others. Everything old is new again With major vulnerabilities in so many applications, is there any hope for a secure future? The answer is, of course, yes, but that does not mean there won't be challenges getting there. The vulnerabilities being seen may not be new to those of us who have been  defending against attackers  for years or even decades, but the adversaries contin...

This phishing campaign delivers fake ransomware

  EXECUTIVE SUMMARY: Feint and punch? This ransomware fake-out might mean that your team will have to put up a good fight in order to avoid a flash knockdown… Microsoft reports an active phishing campaign in which threat actors distribute a computer infection that spreads “fake ransomware”. The ransomware look-a-like involved is in fact trojan malware that can result in a full computer takeover. In Windows systems, this malware offers hackers an easy backdoor entry point. Once in the system, passwords and other  credentials can be harvested  from both email clients and web browsers. The roster of user platforms at risk of compromise include Outlook, Internet Explorer, Firefox and Chrome. The email campaign First, emails purporting to contain payment-related information arrive in users’ inboxes. Then, users who open the emails and click on the attachment are immediately connected to a malicious domain. Ultimately, this leads to the download of the Java-based STRRAT malware...

DarkSide Ransomware Gang Extorted $90 Million from Several Victims in 9 Months

  DarkSide, the hacker group behind the  Colonial Pipeline ransomware attack  earlier this month, received $90 million in bitcoin payments following a nine-month ransomware spree, making it one of the most profitable cybercrime groups. "In total, just over $90 million in bitcoin ransom payments were made to DarkSide, originating from 47 distinct wallets," blockchain analytics firm Elliptic  said . "According to  DarkTracer , 99 organisations have been infected with the DarkSide malware - suggesting that approximately 47% of victims paid a ransom, and that the average payment was $1.9 million." Of the total $90 million haul, the DarkSide's developer is said to have received $15.5 million in bitcoins, while the remaining $74.7 million was split among its various affiliates. FireEye's research into DarkSide's affiliate program had  previously revealed  that its creators take a 25% cut for payments under $500,000 and 10% for ransoms above $5 million, with ...

How cloud technologies drive innovation and digital transformation

  At the industry-leading global cyber event, CPX 360 2021, thousands of guests watched the presentations delivered by some of the best cloud security experts of our era. Understanding cloud complexity and design is key in leading a successful 21 st   century enterprise. Cloud security expert and Check Point Technical Marketing Engineer Maya Levine offered insights into how cloud technologies drive innovation and transformation. Maya Levine is a regular speaker at technology conferences and conducts media interviews with news channels. Her must-have insights can also be found here. As Levine describes it, attackers are taking advantage of the changes cloud environments have prompted. They’re eager to exploit security gaps. Nonetheless, it is possible to mitigate cloud-based risks. So, what is it about cloud applications that is different from on-premise? You’re only paying for what you’re using.  This is a big draw from a user or operations perspective. You don’t have to ...

Applications and Threats Content Release Notes

  Threat Intelligence Report Top Attacks and Breaches The biochemical systems at an Oxford university research lab currently studying the Covid-19 pandemic has been  breached . Clinical research was not affected by the incident. Breached systems include machines used to prepare biochemical samples, and hackers are currently attempting to  sell  their access to those machines. Twitter has permanently  suspended  multiple accounts found to be part of four disinformation campaign networks, most likely operated by state-sponsored actors associated with Iran, Russia and Armenia. The Iranian infrastructure was previously used to disrupt the 2020 US presidential campaign discourse. Gmail accounts of global pro-Tibet organizations have been  targeted  by the Chinese APT TA413, an espionage group known for its operations against civil dissidents. The campaign leverages a customized malicious Mozilla Firefox browser extension to gain control over the victim...