Monday, 27 May 2019

Hackers reportedly used a tool developed by the NSA to attack Baltimore’s computer systems

Since May 7th, the Baltimore’s city government has been dealing with a ransomware attack that has shut down everything from its email to the systems that allow residents to pay water bills, purchase homes, and other services. According to a report in The New York Times, the tool that has crippled the city is a National Security Agency creation called EternalBlue, which has been used in other high-profile cyberattacks.

According to security experts, hackers used EternalBlue, which exploits a vulnerability in certain versions of Microsoft’s Windows XP and Vista systems, allowing an external party to execute remote commands on their target. The tool was leaked by hacking group The ShadowBrokers in April 2017, and within a day, Microsoft had released a patch to fix the exploit. But patching a system doesn’t mean that those vulnerabilities are entirely closed: users must first apply the patch. Hackers using EternalBlue have since been responsible for several major cyberattacks, including Wannacry in May 2017, and the NotPetya attacks against Ukranian banks and infrastructure in June 2017.

Sunday, 19 May 2019

Global co-operation on cyber security is long overdue

Security researchers recently revealed that a previously unknown hacker group carried out a series of attacks on government agencies in 13 countries by redirecting agency computers to hacker-controlled servers. This happened through the manipulation of domain name system (DNS) infrastructure. And it followed a US Department of Homeland Security alert disclosing a global campaign, subsequently linked to Iran, to redirect internet traffic and steal sensitive information also by compromising DNS infrastructure.

The DNS is an attractive target because it serves as a global address book, translating internet names we know into IP addresses that computers can recognise. The infrastructure supporting DNS is maintained by a number of core companies that administer internet domains, register new domain names, and host DNS “lookup” services which convert those domain names into IP addresses.

Sunday, 12 May 2019

‘Unhackable’ Biometric USB Offers Up Passwords in Plain Text

A simple Wireshark analysis was enough to subvert the gadget, which uses iris identification to protect the drive.

A USB stick dubbed eyeDisk that uses iris recognition to unlock the drive claims to be “unhackable” – only, it isn’t. In fact, a simple Wireshark analysis revealed the device’s password – in plain text.

Friday, 19 April 2019

Beware these 5 dangerous WhatsApp scams

WhatsApp has become the most prominent messaging platform across many parts of the world, offering a range of features which enable faster and more convenient communication.

The application also boasts impressive security, with end-to-end encryption delivering secure communication.

Due to its high rate of adoption however, it has also become a targeted platform for scammers and attacks which aim to either compromise the user’s details or infect their device with malware.

Beware these 5 dangerous WhatsApp scams

Friday, 12 April 2019

OceanLotus group adds updated macOS malware to its arsenal

A new version of the macOS malware used by OceanLotus group has been identified by researchers from ESET. Security researcher Romain Dumont from ESET detailed their observations in a blog on Tuesday.

The latest version of the macOS malware was found sporting more features than its earlier versions. In fact, this version underwent a structural change and was harder to detect in infected systems.

apple,computer,air,macbook,brand,business,communication,design,designer,editorial,environment,girl,illustrative,internet,ipad,iphone,laptop,lifestyle,mac,mobile,modern,office,online,people,person,smartphone,technology,text,things,typing,using,woman,work

Tuesday, 9 April 2019

Microsoft Releases April 2019 Security Updates — Two Flaws Under Active Attack

Microsoft today released its April 2019 software updates to address a total of 74 CVE-listed vulnerabilities in its Windows operating systems and other products, 13 of which are rated critical and rest are rated Important in severity.

April 2019 security updates address flaws in Windows OS, Internet Explorer, Edge, MS Office, and MS Office Services and Web Apps, ChakraCore, Exchange Server, .NET Framework and ASP.NET, Skype for Business, Azure DevOps Server, Open Enclave SDK, Team Foundation Server, and Visual Studio.

None of the vulnerabilities addressed this month by the tech giant were disclosed publicly at the time of release, leaving the two recently disclosed zero-day flaws in Internet Explorer and Edge browsers still open for hackers.

https://thehackernews.com/2019/04/microsoft-patch-updates.html

Saturday, 30 March 2019

Understanding a cybercrook’s thinking to make people your first defence against phishing

Ransomware attacks worldwide rose by 350 per cent from 2016 to 2017 says a recent special report by SC Magazine sponsored by Cofense, a provider of intelligent phishing defence solutions.

“Security pros constantly invent better mousetraps, but the mice never stop evolving,” is Josh Bartolomie’s first statement in the report. The Director of Research at Cofense goes on to ask: if the ‘mice’ keep evolving, how exactly can organisations stop attacks?

Anton Jacobsz, CEO at Networks Unlimited Africa, a distribution partner with Cofense in sub-Saharan Africa, says phishing attacks rely on a single moment of inattention or ignorance.

Cyber Security in the Context of International Security

 Cyber security is everyone’s responsibility. What are the current trends in threats, risks, and vulnerabilities? How do threat actors explo...