Distributed via spam emails pretending to be complaints from an Internet Service Provider (ISP), a newly observed Locky ransomware variant appends the .AESIR extension to the encrypted files, security researchers reveal.
read more
Europe Cracks Down on Money Mules: 178 Arrested in Global Operation
178 individuals have been arrested across Europe for money laundering activities. More specifically, the individuals were acting as money mules helping criminals move stolen money out of the country of theft to criminal bank accounts abroad. The action was coordinated by Europol and Eurojust with assistance from law enforcement agencies in 16 European countries, together with the FBI and the U.S. Secret Services.
read more
Researchers Detect 57 Million Scans for Netis Router Backdoor
News of a backdoor in routers produced by China-based networking solutions provider Netis Systems might be of the past, but the vulnerability is part of the present: tens of millions of attempts to scan for the backdoor have been registered since August, Trend Micro researchers warn.
read more
Siemens Releases Firmware Updates to Patch SIMATIC Flaws
Siemens has released firmware updates for some of its SIMATIC communications processors and controllers to address several medium-severity vulnerabilities discovered by researchers from various organizations.
read more
Proactive Security – Does It Exist?
For years, security experts have been struggling to create proactive security products and proactive cyber defense strategies. If we had them, would we have been better prepared for all the major attack campaigns the industry has experienced of late – from the Target breach in 2013 to the Sony hack in 2014 to the recent IoT DDoS hacks and the DNC-related attacks?
read more
Android Trojan Prevents Security Apps From Launching
A newly discovered Android banking Trojan has been designed not only to be resilient to anti-malware applications, but also to counter them by preventing them from launching, Fortinet security researchers warn.
read more
Microsoft Plans Valentine’s Breakup With SHA-1
Starting on February 14, 2017, Microsoft’s Edge and Internet Explorer 11 web browsers will no longer load sites protected with a SHA-1 certificate, but will instead display an invalid certificate warning.
read more
Several DoS Vulnerabilities Patched in NTP
The CERT Coordination Center and the Network Time Foundation announced on Monday the availability of NTP 4.2.8p9, which includes nearly 40 security patches, bug fixes and improvements.
read more
Office 365 Flaw Made Fake Microsoft Emails Look Legitimate
A flaw in Office 365 could have been exploited by attackers to send out malicious emails and make them look as if they were coming from a legitimate microsoft.com address.
read more
Pentagon Announces Vulnerability Disclosure Policy
The U.S. Department of Defense (DoD) announced on Monday that it has created a vulnerability disclosure policy that aims to provide guidance to researchers on how to disclose security holes found in the organization’s public-facing websites.
read more

