Tuesday, February 28, 2023

PCMag Security Watch

"LastPass Hacked Again/Meta Tackles Sextortion/Proton VPN wins top Honors."

Views expressed in this cybersecurity, cybercrime update are those of the reporters and correspondents.  Accessed on 28 February 2023, 1944 UTC.  Content provided by email subscription to "PCMag Security Watch."

Source: https://mail.google.com/mail/u/0/#inbox/FMfcgzGrcrmdnVXJWsCccGcZsbHvnJfl ("PCMag Security Watch").

Please click link or scroll down to read your selections.  Thanks for joining us today.

Russ Roberts (https://www.hawaiicybersecurityjournal.net and https://paper.li/RussellRoberts).

Not displaying correctly? View this newsletter online.
PCMAG
TODAY'S FEATURED STORY
Hacker Breached LastPass by Installing Keylogger on Employee's Home Computer

The hacker also exploited a vulnerability in a 'third-party media software package' to help launch malware on the employee's computer.

 
THE LATEST
How to Switch to a New Password Manager

Leaving LastPass? Modern password managers make it very easy to switch between services. Just follow these simple steps.

US Marshals Service Computer System Hit by Ransomware Attack

Hackers also stole data from an IT system in what the US Marshals Service calls 'a major incident.'

What Really Happens In a Data Breach (and What You Can Do About It)

We explain what a data breach means for you—and how to protect yourself against damage to your privacy.

Meta Tackles Revenge Porn, Sextortion With 'Take It Down' Platform

Take It Down uses a hashed coding system to identify explicit images, remove them from the web, and prevent them from being re-posted, Meta says.

Proton VPN Gets a Rare 5-Star Rating

Proton VPN offers an excellent collection of features at a reasonable price and a nearly peerless free subscription option, making it our top choice for VPNs.

Dish Network Hit With Multi-Day Outage, Suspected Ransomware Attack

The satellite-TV provider's websites, apps, and internal systems have been down since Thursday, leaving employees unable to work and customers prevented from paying Dish bills.

 
OTHER TECH NEWS
The FCC Is Going After Scam Texts (Again)
Hacker Circulates Mac Malware Via Pirated Software Torrents
European Commission Bans TikTok From Government-Issued Devices
Signal Boss Says App Will Quit UK if Legislation Weakens Encryption
PCMAG PICKS
These Are the Password Managers We Trust
It's Time to Protect Yourself Againsr Ransomware
Rid Your PC of Malware With These Apps
VPNs Protect Your Privacy
Tech Deals

CSO First Look: Cybersecurity News

"Cybersecurity in Ukraine:  How Ukraine infosec community is coping."

Views expressed in this cybersecurity, cybercrime update are those of the reporters and correspondents.  Accessed on 28 February 2023 1412 UTC. Content provided by "CSO First Look."

Source:  https://mail.google.com/mail/u/0/#inbox/FMfcgzGrcrmdLNzJDXzTDdPvhXbZWWXr (Cybersecurity News from "CSO First Look").

Please click link or scroll down to read your selections.  Thanks for joining us today.

Russ Roberts (https://www.hawaiicybersecurityjournal.net and https://paper.li/RussellRoberts).

CSO

The day's top cybersecurity news and in-depth coverage

CSO FIRST LOOK

28 FEBRUARY, 2023

Cybersecurity in wartime: how Ukraine's infosec community is coping

A year into the war, resilience and adaptation, risk and sacrifice are the hallmarks of being a cybersecurity professional in Ukraine.

Image: Sponsored by Roar B2B Limited: Are you ready to take on these challenges at UK Cyber Week – Expo & Conference 2023

Sponsored by Roar B2B Limited: Are you ready to take on these challenges at UK Cyber Week – Expo & Conference 2023

Whether you're a cyber security or IT expert, or just starting out, we invite you to join us and experience the excitement of Capture the Flag, Battle Bots, Lockpicking Village, Cyber Escape Room, and a lot more, all taking place at UK Cyber Week - Expo & Conference this April! Get your free ticket today!

US warns of cyberattacks by Russia on anniversary of Ukraine war

The US Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory about stepped-up Russian 'disruptive' actions right after Ukraine detected a cyberattack on government websites.

Backdoor deployment overtakes ransomware as top attacker action

Thanks to the availability of malware such as Emotet, deploying backdoors on victims' networks is becoming easier and more lucrative for cybercriminals.

Entitle debuts with automated SaaS permissions-management application

Israel-based cybersecurity startup Entitle's namesake application is designed to automate access requests and grants by delegating approval decisions to business owners instead of IT and devops teams.

What is Traffic Light Protocol? Here's how it supports CISOs in sharing threat data

Traffic Light Protocol (TLP) provides CISOs with best practice guidance on how to share sensitive data within an organization or externally. Here is how to use TLP and more on the latest version, TLP 2.0.

CSO
FacebookTwitterLinkedIn
© 2023 CSO
IDG Communications Ltd.,
101 Euston Road,
London NW1 2RA,
United Kingdom

Monday, February 27, 2023

The Hacker News: Weekly Cybersecurity Newsletter

Here are "the top cybersecurity stories you must read now!"

Apple issues urgent warning.

Are your data safe?

MyloBot Botnet goes global.

Is Twitter leaving you exposed?

-----

Accessed on 27 February 2023, 1418 UTC.  Content provided by email subscription to "The Hacker News."  Source:  https://mail.google.com/mail/u/0/#inbox/FMfcgzGrcjWxRSlHZQRfwScJVQTZbBKn ("The Hacker News:  Weekly Cybersecurity Newsletter").

Please click link or scroll down to read your selections.

Russ Roberts (https://www.cybersecurityjournal.net and https://paper.li/RussellRoberts).

The Hacker News
Weekly Cybersecurity Newsletter

Greetings, fellow defenders of digital security!


It's time to fortify our shields and sharpen our swords because the battle against cyber threats never ceases. Welcome to our weekly cybersecurity newsletter, where we bring you the latest and greatest insights, news, and tips to keep your digital kingdom safe from the relentless attacks of hackers and cybercriminals.


So, join us as we dive into the exciting and ever-evolving world of cybersecurity:


1 — iPhone, iPad, and Mac Devices at Risk: Apple Issues Urgent Warning

Apple recently updated its security advisories to include three new vulnerabilities that affect iOS, iPadOS, and macOS. These vulnerabilities could potentially allow bad actors to read arbitrary files or execute code on affected devices. Overall, this highlights the importance of keeping devices and software up-to-date, as these updates often include important security fixes.


2 — Is Your Data Safe? Even Top-Ranked Android Apps Deceive Users

So, some troubling news has come to light about the safety of Android apps on the Google Play Store. Apparently, an investigation has found some pretty serious issues with the data safety labels that are supposed to tell us whether an app is safe to use or not. These labels can apparently be misleading or even completely false, which is definitely cause for concern. It's important for us to be able to trust the information we're given about the apps we download, so this is definitely something we'll want to keep an eye on.


3 — MyloBot Botnet Goes Global: 50K Devices Infected Daily

A new and dangerous botnet called MyloBot is on the loose and spreading rapidly across the globe. This botnet is infecting over 50,000 devices each day and causing havoc for individuals and businesses alike. The malware uses a multi-stage process to infect devices and can spread through various means, including spam emails, phishing websites, and unpatched software vulnerabilities.


4 — Is Twitter Leaving You Exposed? Only Blue Subscribers Get 2FA via SMS!

Twitter has announced that it will limit SMS-based 2-factor authentication (2FA) to its blue subscribers only. This means that users who rely on SMS-based 2FA to secure their Twitter accounts will need to upgrade to a premium subscription to continue using this feature. Twitter recommends that users switch to app-based 2FA methods, such as Google Authenticator, Authy, or Duo Mobile, which are generally more secure than SMS-based 2FA.


The Hacker News / UPCOMING WEBINARS


We're excited to announce two upcoming webinars that we think you won't want to miss.

1. First up, we have a MythBusting Special that will explore and debunk 9 common myths about file-based threats. In this webinar, we'll dive deep into the misconceptions surrounding file-based attacks and provide you with the knowledge and insights you need to protect your organization against these types of threats.

2. Next, we have a webinar that will tackle the top SaaS security challenges of 2023. As more and more organizations move their operations to the cloud, it's crucial to understand the unique security risks that come with using SaaS applications. In this webinar, our experts will discuss the top challenges facing organizations in 2023 and provide you with practical strategies for overcoming them.

We hope you'll join us for both of these informative and engaging webinars.


5 — Coinbase Security Breached: Employee Fooled by SMS Scam

It has been reported that a Coinbase employee was the victim of an SMS scam as part of a cyber attack. While the attack did result in limited data being exposed, it serves as a stark reminder of the importance of remaining vigilant against sophisticated cyber threats. So, what can we learn from this incident? Education and awareness around cybersecurity threats and best practices are crucial to preventing incidents like this from occurring.


6 — Norway Strikes Back: Millions in Cryptocurrency Seized from Hackers!

The Norwegian police agency Økokrim made a big win against cybercriminals when they announced the seizure of $5.84 million worth of cryptocurrency stolen by the notorious Lazarus Group. This successful operation serves as a reminder of the importance of international cooperation in combating cybercrime.


7 — Havoc Framework: Latest Tool in the Arsenal of Cybercriminals!

It seems that threat actors have found a new tool to use in their illegal activities. The tool in question is called Havoc, and it's an open-source command-and-control (C2) framework that is gaining popularity among cybercriminals as an alternative to other well-known legitimate toolkits like Cobalt Strike, Sliver, and Brute Ratel.


8 — Warning: Your Mac Could Be Secretly Mining Cryptocurrency!

A recent discovery by Jamf Threat Labs has shown that hackers are using Trojanized versions of genuine applications to deploy cryptocurrency mining malware on macOS systems. These sneaky attacks are particularly evasive because they use a familiar and trustworthy application to execute their malicious intent.


As we wrap up this week's cybersecurity newsletter, it's important to remember that cybersecurity is not just a topic for IT professionals and security experts. It affects us all, from the way we shop online to the way we communicate with our friends and family.


As the digital world continues to evolve at a rapid pace, we must remain vigilant and proactive in protecting our personal and sensitive information. From staying up-to-date with the latest security measures to practicing good online habits, there are many steps we can take to stay safe in the digital age.


So, as we head into the new week, let's make a commitment to prioritize our online security and do our part to create a safer, more secure digital world for everyone. Remember, cybersecurity is a team effort, and together we can make a real difference.

Sunday, February 26, 2023

BleepingComputer.com: Cybersecurity News

"PureCryter malware hits govt orgs with ransomware, info-stealers."

Views expressed in this cybersecurity, cybercrime update are those of the reporters and correspondents.  Accessed on 26 February 2023, 1340 UTC.  Content supplied by "BleepingComputer.com."

Source:   https://www.bleepingcomputer.com/

Please click link or scroll down to read your selections.  Thanks for joining us today.

Russ Roberts (https://www.hawaiicybersecurityjournal.net and https://paper.li/RussellRoberts).

VIEW MORE

The Hacker News.

"THN Weekly Recap:  Top cybersecurity threats, tools and tips." Views expressed in this cybersecurity, cyber crime update are thos...