24. July 2021

XKCD ‘Immune Factory’

BSides Vancouver 2021 – Marek Mikita’s ‘Sysmon Monitoring Different Way’

macOS Malware Added New Weapons to Its Arsenal To Attack Google Chrome & Telegram

Japanese computers hit by a wiper malware ahead of 2021 Tokyo Olympics

CISSPs from Around The Globe: An Interview with Theresa Grafenstine

BSides Vancouver 2021 – Rossilyne Tan’s & Danielle Cheng’s ‘Get Smart On Smart Tech!’

Active Directory Certificate Services (ADCS – PKI) domain admin vulnerability, (Sat, Jul 24th)

Wi-Fi Routers with Default Passwords are Vulnerable to Attacks

Porn Showed Up on Legit News Sites Thanks to Internet Rot

Porn Showed Upon on Legit News Sites Thanks to Internet Rot

Fastest VPN deal: Get lifetime protection for 10 devices for only $25

Top Stories: Hands-On With MagSafe Battery Pack, iPhone 13 Always-On Display?

Why some investors are banking on a bitcoin IRA instead of Social Security

Google Cloud, Partnered With Palo Alto Networks, Receives US Government Success Memo

USD 50 Million Ransom Demanded from Saudi Aramco Over Leaked Data

Hacker Employ Milanote App for Spreading Phishing Email

Researchers Embedded Malware into an AI’s ‘Neurons’ and it Worked Scarily Well

‘Build’ or ‘Buy’ your own antivirus product

Agent.Tesla Dropped via a .daa Image and Talking to Telegram, (Sat, Jul 24th)

Weekly Update 253

Bouncy Castle and the Impact of Cryptographic Vulnerabilities

The work of the Runet was tested in the exercise of disconnection from the global network

Developer-Led Code Security: Why False Positives Are Worse than False Negatives

Girl Scouts Safeguards Data with BlackFog

Obtaining password hashes of Windows systems with PetitPotam attack

Security Information and Event Management (SIEM) – A Detailed Explanation

Trustwave Government Solutions Joins the Cybersecurity and Infrastructure Security Agency (CISA) Cyber Information Sharing and Collaboration Program (CISCP)

Be The Strongest Link In Your Organization’s Supply Chain

Eclypsium Detects Severe Vulns in Accellion FTA Devices

Protecting the hybrid workplace through Zero Trust security

Week in security with Tony Anscombe

10 consejos esenciales de ciberseguridad para principiantes

Entrust adds automated key lifecycle management for AWS customers

Fraud Follows A Surge in Mobile Adoption

Mind the Backdoor

Nodle partners with ESTV to expand its reach into gaming and esports

Inseego Wavemaker PRO 2000e delivers throughput and reliability for industrial IoT and enterprise networks

Sophos acquires Braintrace to provide better security outcomes to their MDR customers

Flashpoint collaborates with Cybermerc to enhance its threat intelligence solution

AvosLocker enters the ransomware scene, asks for partners

Appgate participates in the implementation of a Zero Trust Architecture Project with NCCoE

Immuta expands its leadership team with two key hires

Discord CDN and API Abuses Drive Wave of Malware Detections

LastPass: Password Manager Review for 2021

Redundancy for resilience: The importance of layered protection in the cloud

EFF, ACLU Urge Appeals Court to Revive Challenge to Los Angeles’ Collection of Scooter Location Data

IT Security News Daily Summary 2021-07-23

Phishing attacks get smarter as targets struggle to keep up

Everything New in the iOS 15 Maps App: Updated Details, AR Walking Directions, Globe View and More

Warnings That Work: Combating Misinformation Without Deplatforming

DOD rolls out AR/VR technology at 5G testbed

Best practices to conduct a user access review

What Will Cybersecurity Look Like Over the Next Five Years?

The workforce and mission arguments for modernizing human capital management systems

Detecting, blocking grid cyberattacks

Open-source model finds best places for EV charging stations

Army tests HPC climate model in Azure cloud

DoD to employ 5G testbeds and AR/VR technology to inform training operations

Even after Emotet takedown, Office docs deliver 43% of all malware downloads now

Biden Administration Responds to Geopolitical Cyber Threats

Combating Shadow IT: A Customer Uses DTEX for Cybersecurity & More

Why Do Ransomware Attacks Keep Happening

Data Brokers are the Problem

A 16-year-old bug (CVE-2021-3438) in printer driver affects millions of printers worldwide

XLoader, a $49 spyware that could target both Windows and macOS devices

Boosting Morale During Tough Times Will Also Boost Your Security Resilience

Senate NDAA pushes for more domestic production, increased cyber authorities

Home and Office Routers are Targeted by Chinese State Hackers

APT Gang Distributed Android Trojan via Syrian e-Government Platform

DDoS Attacks Are Back, More Aggressive Than Ever

Password-Stealing Windows Malware has been Discovered

Review: Hyper’s $40 Magnetic Wireless Battery Pack Is a Worthy Competitor to Apple’s MagSafe Battery Pack

Apple Explains How the Photos People Recognition Feature Has Improved in iOS 15

5 Steps to Improving Ransomware Resiliency

BSides Vancouver 2021 – Vivek Ponnada’s ‘Is The Power Grid A Huge Cybersecurity Risk?’

Estonian hacker Pavel Tsurkan pleads guilty for operating a proxy botnet.

Deals: Apple Pencil 2 Drops to $103.99 on Verizon ($25 Off)

Celebrating Duo’s 2021 Community Impact Award Winners

Six Terms to Up Your IoT Vocabulary

MacRumors Giveaway: Win Custom MacRumors-Themed AirPods From Electronic Finishing Solutions

Busted! Fraud-as-a-Service gang that sold 2FA-proof phishing arrested

CNA legal filings lift the curtain on a Phoenix CryptoLocker ransomware attack

How DuckDuckGo makes money selling search, not privacy

Exploiting Wi-Fi Stack on Tesla Model S

Tencent Keen Security Lab joins GENIVI Alliance

Tencent Keen Security Lab: Experimental Security Assessment on Lexus Cars

Tencent Security Keen Lab: Experimental Security Assessment of Mercedes-Benz Cars

Holes in Linux Kernel Could Pose Problems for Red Hat, Ubuntu, Other Distros

Free Active Directory – 10 Users Free with JumpCloud

People of JumpCloud | Abbie Rastatter

The 25 most dangerous software vulnerabilities to watch out for

US court gets UK Twitter hack suspect arrested in Spain

Global Outage Disrupts the Services of Major Websites

Apple Working on External Display With Built-In A13 Chip

Actor Adrian Grenier explains why bitcoin is central to his plan to build a communal farm in Texas

Implementing Controls Without Breaking Everything (Including the Bank)

Windows Defender update caught removing zip, exe, source code files

How AI Will Transform Data Security

FIN7’s Liquor Lure Compromises Law Firm with Backdoor

Threat Actors Target Kubernetes Clusters via Argo Workflows

BSides Vancouver 2021 – Ruchi Gautam’s ‘Privacy Concerns In The Connected Car Ecosystem’

Sigstore: An open answer to software supply chain trust and security

Departing employees pose significant cloud security risks, report finds

European Commission proposes changes to EU law to increase cryptocurrency transaction transparency

CASE STUDY: Archroma: designing security into company processes with Edgescan

Tokyo Olympics 2021 on Russian Cyber Attack Radar

Microsoft Security Under Scrutiny After Recent Incidents

App Store Classic ‘Jetpack Joyride’ Launches on Apple Arcade

Gartner MQ for PAM regards One Identity as a Leader in 2021

Now Available: Microsoft 365 Application for Duo Single Sign-On

Cybersecurity: These are the most dangerous and most common software vulnerabilities to watch out for

House Passes Several Critical Infrastructure Cybersecurity Bills

Why implementing Zero Trust is more important than ever before

Sharing Knowledge to Overcome Possible Future Enemies

Q2 Ransom Payment Amounts Decline as Ransomware becomes a National Security Priority

Critical Jira Flaw In Atlassian Could Lead To RCE

Israel To Examine Whether Spyware Export Rules Should Be Tightened

Kaseya Has Acquired The REvil Ransomware Decryption Key

Researchers Find New Attack Vector Against Kubernetes Clusters

Next iPad Mini Won’t Feature Mini-LED Display, Claims Display Analyst

Deals: Shop Record Low Prices Across Apple’s Full MacBook Pro and MacBook Air Lineup (Up to $499 Off)

Facebook Gaming Now Available to iOS Users Through Web App Due to App Store Policy

Law Firm Campbell Disclosed Data Breach Following Ransomware Attack

Systemd Vulnerability Could Risk Denial-of-Service Across Major Linux Systems

Latest big data developments in the realm of data lakehouse

Risk & Repeat: Vulnerability patching still falling short

Deals: Get Apple’s MagSafe Charger for $29.99 on Woot ($9 Off)

States weigh bans on ransomware payoffs

Researchers find new attack vector against Kubernetes clusters via misconfigured Argo Workflows instances

Dutch Police Arrest Alleged Member of ‘Fraud Family’ Cybercrime Gang

TikTok fined €750,000 for Violating Children’s Privacy

Nations come together to condemn China: APT31 and APT40

Levashov Walks. Russian Spam King gets slap on the wrist

EU takes aim at ransomware with plans to make Bitcoin traceable, prohibit anonymity

GitHub boosts supply chain security for Go modules

Microsoft warns over this unusual malware that targets Windows and Linux

Over 80 US Municipalities’ Sensitive Information, Including Resident’s Personal Data, Left Vulnerable in Massive Data Breach

Nasty Windows Printer Driver Vulnerability

Commercial Location Data Used to Out Priest

Apple Not Trying Hard Enough to Protect Users Against Surveillance, Researchers Say

Five steps to password policy compliance

Important News Websites Host Hardcore Porn After Vidme Domain Purchase

Kaseya Managed to Obtain the Universal Decryptor After the REvil Ransomware Attack

DNS Global Outage Affected Websites and Online Services

Cyber Risk Management Firm Safe Security Raises $33 Million

Hackers Exploit the COVID-19 Pandemic for Cyber Scams

Managed Detection and Response in Q4 2020

Uncovering Shenanigans in an IP Address Block via Hurricane Electric’s BGP Toolkit (II), (Fri, Jul 23rd)

The Free Security Tools & Software You Can Use for Your Online Protection

CNA’s Network Was Breached Via Fake Browser Update

France’s Macron Changes Phone, After NSO Pegasus Report

Netskope report finds cloud-delivered malware increased 68% in Q2

Updated Kaseya ransomware attack FAQ: What we know now

Manufactured Whistleblowing: Data Leaks as Subversion

Ransomware: Kaseya says it has now got the REvil decryption key – and it works

Kaseya Obtains Universal Decryptor for REvil Ransomware

Nasty macOS Malware XCSSET Now Targets Google Chrome, Telegram Software

Simplify VPN with Cisco Secure Managed Remote Access

What Is An Identity and Access Management So-lution and How Can Businesses Benefit From It?

New Windows Print Spooler Zero-Day Bug Triggers Remote Attacks

Oil Firm Saudi Aramco Suffered Data Breach – Data Put For Sale On Dark Web

MosaicLoader Malware Targets Users Looking For Pirated Software

Saudi Aramco Confirms Data Breach After $50m Ransom Demand

Estonian Botnet Operator Pleads Guilty in U.S. Court

Industrial Cybersecurity Firm SynSaber Launches With $2.5M in Seed Funding

Pulse Security Devices Identified with Malware: Alerts CISA

New Windows and Linux Flaws: Provide Attackers Highest System Privileges

Dutch Police Arrest Two Hackers Tied to “Fraud Family” Cybercrime Ring

Wake up! Identify API Vulnerabilities Proactively, From Code Back to Production

Hole blasted in Guntrader: UK firearms sales website’s CRM database breached, 111,000 users’ info spilled online

Government To Compensate Victims Of Post Office Horizon Fiasco

Kaseya says it has now got the REvil ransomware decryption key – and it works

Are advertising unique IDs anonymous?

Top 5 Best Dark Web Browser for Anonymous Web Browsing With Ultimate Privacy – 2021

Kaseya obtained a universal decryptor for REvil ransomware attack

iPhone 13 May Support 25W Fast Charge Power Adapter

Kaseya obtains universal REvil decryptor

Security and privacy laws, regulations, and compliance: The complete guide

Top cybersecurity M&A deals for 2021

Kaseya Obtains Universal Decryptor for Ransomware Attack Victims

Meross Launches Modular Smart LED Floor Lamp With HomeKit Support

Nomad Opens Pre-Orders for $35 Leather Cover for Apple’s MagSafe Battery Pack

Instagram Introduces Sensitive Content Control | Avast

Air Force taps Google Cloud for aircraft maintenance system

Ransomware Payouts in Review. Highest Payments, Trends & Stats

Red light for migrant smugglers speeding at up to 250 km/h

Directives Issued After US Pipeline Ransomware Attack

AirPods 3 Rumored to Launch Alongside iPhone 13 at Expected September Event

Tech support scams subside somewhat, but Millennials and Gen Z think they’re bulletproof and suffer

Want your endpoint security product in the ‘Microsoft Consumer Antivirus Providers for Windows’ ?

Olympic Ticket Data Leaked, Says Japanese Government

Understanding Certificate Policies and Practice Statements

Threat Report Portugal: Q2 2021

First Episode of ‘Ted Lasso’ Season 2 Debuts on Apple TV+

Audi – 2,743,539 breached accounts

Kaseya Ransomware Attack Update

Cyber Attack on Transnet South Africa Shipping

This Week in Security News – July 23, 2021

More than half of all Aussies continue to encounter forms of cyber scams in 2021

COVIDSafe feedback process changes as app moves into business as usual mode

US Offers Bounty for Tips on State-Sponsored Cybercrime

Akamai software update triggered a bug that took offline major sites

New infosec products of the week: July 23, 2021

Cloud WAF Helps To Stop Breaches Before they Happen

40% fell victim to a phishing attack in the past month

BT tries to crack cyber crime, grabs stake in Safe Security

Uber found to have interfered with privacy of over 1 million Australians

User data privacy decisions can be easily manipulated

Kaseya Gets Universal Decryptor to Help REvil Ransomware Victims

Logging: A Deep Dive

Government IT decision makers worried about security risks related to cloud migration

Trending: 4,500+ Cyber Pros Enroll in Free (ISC)2 Ransomware Course in Less Than a Month in Order to Fortify Their Preparedness and Response Skills

MWC Barcelona 2021 – Highlights from the biggest mobile trade show

Manufacturers turning to zero trust to better secure their networks

How prepared are organizations for the challenges of the changing SAP landscape

Cloud WAF Helps that to Stop Breaches Before they Happen

IoT ML and AI services to reach $3.6 billion in 2026

Kuo: Mini-LED MacBook Air Coming in Mid-2022

AnyVision OnPatrol: A tactical surveillance mobile app for law enforcement and military personnel

ISC Stormcast For Friday, July 23rd, 2021 https://isc.sans.edu/podcastdetail.html?id=7598, (Fri, Jul 23rd)

Sisense Extense Framework provides users access to actionable intelligence inside applications

Dremio Cloud empowers self-service and interactive analytics on the data lake

Straive Data Platform derives actionable insights out of unstructured datasets

Cognito Flow offers online verification requirements for global business customers

Council of Europe’s Actions Belie its Pledges to Involve Civil Society in Development of Cross Border Police Powers Treaty

Kaseya obtains REvil decryptor, starts sharing it with afflicted customers

Popular Wi‑Fi routers still using default passwords making them susceptible to attacks

Ermetic’s governance capabilities allow organizations to enforce their own security standards

GTT’s portal feature provides expanded visibility into network security and performance

Ridge Security enhances web application testing in RidgeBot 3.5

Never mind the trolls, Discord hosts ‘significant volumes of malware’ in its CDN

API Abuse Is a Data Security Issue Here to Stay

Most Falsehoods “Tend to Promote Conservative Positions”

Innodisk launches 112-Layer 3D TLC SSDs with increased capacity

Spectra Logic partners with StorMagic to deliver active archive repository for video surveillance

Generated on 2021-07-24 23:55:28.156949