n How Arid Viper spies on Android users in the Middle East – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 14 Jun 2024 11:58:03 +0000 The spyware, called AridSpy by ESET, is distributed through websites that pose as various messaging apps, a job search app, and a Palestinian Civil Registry app Full Article
n Hacktivism is evolving – and that could be bad news for organizations everywhere By www.welivesecurity.com Published On :: Wed, 19 Jun 2024 09:30:00 +0000 Hacktivism is nothing new, but the increasingly fuzzy lines between traditional hacktivism and state-backed operations make it a more potent threat Full Article
n My health information has been stolen. Now what? By www.welivesecurity.com Published On :: Thu, 20 Jun 2024 09:30:00 +0000 As health data continues to be a prized target for hackers, here's how to minimize the fallout from a breach impacting your own health records Full Article
n Hijacked: How hacked YouTube channels spread scams and malware By www.welivesecurity.com Published On :: Mon, 01 Jul 2024 09:30:00 +0000 Here’s how cybercriminals go after YouTube channels and use them as conduits for fraud – and what you should watch out for when watching videos on the platform Full Article
n Buying a VPN? Here’s what to know and look for By www.welivesecurity.com Published On :: Tue, 25 Jun 2024 09:30:00 +0000 VPNs are not all created equal – make sure to choose the right provider that will help keep your data safe from prying eyes Full Article
n The long-tail costs of a data breach – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 21 Jun 2024 11:54:09 +0000 Understanding and preparing for the potential long-tail costs of data breaches is crucial for businesses that aim to mitigate the impact of security incidents Full Article
n Cyber insurance as part of the cyber threat mitigation strategy By www.welivesecurity.com Published On :: Wed, 26 Jun 2024 11:31:29 +0000 Why organizations of every size and industry should explore their cyber insurance options as a crucial component of their risk mitigation strategies Full Article
n No room for error: Don’t get stung by these common Booking.com scams By www.welivesecurity.com Published On :: Wed, 03 Jul 2024 09:30:00 +0000 From sending phishing emails to posting fake listings, here’s how fraudsters hunt for victims while you’re booking your well-earned vacation Full Article
n AI in the workplace: The good, the bad, and the algorithmic By www.welivesecurity.com Published On :: Tue, 02 Jul 2024 09:30:00 +0000 While AI can liberate us from tedious tasks and even eliminate human error, it's crucial to remember its weaknesses and the unique capabilities that humans bring to the table Full Article
n Key trends shaping the threat landscape in H1 2024 – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 28 Jun 2024 13:13:12 +0000 Learn about the types of threats that 'topped the charts' and the kinds of techniques that bad actors leveraged most commonly in the first half of this year Full Article
n Small but mighty: Top 5 pocket-sized gadgets to boost your ethical hacking skills By www.welivesecurity.com Published On :: Tue, 16 Jul 2024 09:30:00 +0000 These five formidable bits of kit that can assist cyber-defenders in spotting chinks in corporate armors and help hobbyist hackers deepen their understanding of cybersecurity Full Article
n 5 common Ticketmaster scams: How fraudsters steal the show By www.welivesecurity.com Published On :: Tue, 09 Jul 2024 09:30:00 +0000 Scammers gonna scam scam scam, so before hunting for your tickets to a Taylor Swift gig or other in-demand events, learn how to stop fraudsters from leaving a blank space in your bank account Full Article
n Social media and teen mental health – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Thu, 04 Jul 2024 14:31:24 +0000 Social media sites are designed to make their users come back for more. Do laws restricting children's exposure to addictive social media feeds have teeth or are they a political gimmick? Full Article
n HotPage: Story of a signed, vulnerable, ad-injecting driver By www.welivesecurity.com Published On :: Thu, 18 Jul 2024 09:30:00 +0000 A study of a sophisticated Chinese browser injector that leaves more doors open! Full Article
n Understanding IoT security risks and how to mitigate them | Unlocked 403 cybersecurity podcast (ep. 4) By www.welivesecurity.com Published On :: Wed, 10 Jul 2024 09:30:00 +0000 As security challenges loom large on the IoT landscape, how can we effectively counter the risks of integrating our physical and digital worlds? Full Article
n Should ransomware payments be banned? – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 12 Jul 2024 12:30:20 +0000 Blanket bans on ransomware payments are a much-debated topic in cybersecurity and policy circles. What are the implications of outlawing the payments, and would the ban be effective? Full Article
n Hello, is it me you’re looking for? How scammers get your phone number By www.welivesecurity.com Published On :: Mon, 15 Jul 2024 11:45:35 +0000 Your humble phone number is more valuable than you may think. Here’s how it could fall into the wrong hands – and how you can help keep it out of the reach of fraudsters. Full Article
n The tap-estry of threats targeting Hamster Kombat players By www.welivesecurity.com Published On :: Tue, 23 Jul 2024 09:00:00 +0000 ESET researchers have discovered threats abusing the success of the Hamster Kombat clicker game Full Article
n Cursed tapes: Exploiting the EvilVideo vulnerability on Telegram for Android By www.welivesecurity.com Published On :: Mon, 22 Jul 2024 09:00:00 +0000 ESET researchers discovered a zero-day Telegram for Android exploit that allows sending malicious files disguised as videos Full Article
n How a signed driver exposed users to kernel-level threats – Week in Security with Tony Anscombe By www.welivesecurity.com Published On :: Sun, 21 Jul 2024 07:24:11 +0000 A purported ad blocker marketed as a security solution leverages a Microsoft-signed driver that inadvertently exposes victims to dangerous threats Full Article
n Beyond the blue screen of death: Why software updates matter By www.welivesecurity.com Published On :: Fri, 19 Jul 2024 16:20:11 +0000 The widespread IT outages triggered by a faulty CrowdStrike update have put software updates in the spotlight. Here’s why you shouldn’t dread them. Full Article
n Building cyber-resilience: Lessons learned from the CrowdStrike incident By www.welivesecurity.com Published On :: Tue, 23 Jul 2024 12:23:39 +0000 Organizations, including those that weren’t struck by the CrowdStrike incident, should resist the temptation to attribute the IT meltdown to exceptional circumstances Full Article
n Phishing targeting Polish SMBs continues via ModiLoader By www.welivesecurity.com Published On :: Tue, 30 Jul 2024 09:00:00 +0000 ESET researchers detected multiple, widespread phishing campaigns targeting SMBs in Poland during May 2024, distributing various malware families Full Article
n Beware of fake AI tools masking very real malware threats By www.welivesecurity.com Published On :: Mon, 29 Jul 2024 09:00:00 +0000 Ever attuned to the latest trends, cybercriminals distribute malicious tools that pose as ChatGPT, Midjourney and other generative AI assistants Full Article
n Telegram for Android hit by a zero-day exploit – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 26 Jul 2024 11:57:23 +0000 Attackers abusing the EvilVideo vulnerability could share malicious Android payloads via Telegram channels, groups, and chats, all while making them appear as legitimate multimedia files Full Article
n The cyberthreat that drives businesses towards cyber risk insurance By www.welivesecurity.com Published On :: Wed, 31 Jul 2024 09:00:00 +0000 Many smaller organizations are turning to cyber risk insurance, both to protect against the cost of a cyber incident and to use the extensive post-incident services that insurers provide Full Article
n AI and automation reducing breach costs – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 02 Aug 2024 11:30:15 +0000 Organizations that leveraged AI and automation in security prevention cut the cost of a data breach by $2.22 million compared to those that didn't deploy these technologies Full Article
n Why tech-savvy leadership is key to cyber insurance readiness By www.welivesecurity.com Published On :: Wed, 07 Aug 2024 09:00:00 +0000 Having knowledgeable leaders at the helm is crucial for protecting the organization and securing the best possible cyber insurance coverage Full Article
n Top 6 Craigslist scams: Don’t fall for these tricks By www.welivesecurity.com Published On :: Mon, 12 Aug 2024 09:00:00 +0000 Here’s how to spot and dodge scams when searching for stuff on the classified ads website that offers almost everything under the sun Full Article
n Black Hat USA 2024: How cyber insurance is shaping cybersecurity strategies By www.welivesecurity.com Published On :: Thu, 08 Aug 2024 14:40:36 +0000 Cyber insurance is not only a safety net, but it can also be a catalyst for advancing security practices and standards Full Article
n Why scammers want your phone number By www.welivesecurity.com Published On :: Tue, 13 Aug 2024 09:00:00 +0000 Your phone number is more than just a way to contact you – scammers can use it to target you with malicious messages and even exploit it to gain access to your bank account or steal corporate data Full Article
n Black Hat USA 2024: All eyes on election security By www.welivesecurity.com Published On :: Fri, 09 Aug 2024 13:07:56 +0000 In this high-stakes year for democracy, the importance of robust election safeguards and national cybersecurity strategies cannot be understated Full Article
n Black Hat USA 2024 recap – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 09 Aug 2024 13:53:46 +0000 Unsurprisingly, many discussions revolved around the implications of the CrowdStrike outage, including the lessons it may have offered for bad actors Full Article
n Be careful what you pwish for – Phishing in PWA applications By www.welivesecurity.com Published On :: Tue, 20 Aug 2024 09:00:00 +0000 ESET analysts dissect a novel phishing method tailored to Android and iOS users Full Article
n The great location leak: Privacy risks in dating apps By www.welivesecurity.com Published On :: Mon, 12 Aug 2024 14:51:08 +0000 What if your favorite dating, social media or gaming app revealed your exact coordinates to someone you’d rather keep at a distance? Full Article
n NGate Android malware relays NFC traffic to steal cash By www.welivesecurity.com Published On :: Thu, 22 Aug 2024 09:00:00 +0000 Android malware discovered by ESET Research relays NFC data from victims’ payment cards, via victims’ mobile phones, to the device of a perpetrator waiting at an ATM Full Article
n How a BEC scam cost a company $60 million – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 16 Aug 2024 11:01:54 +0000 Business email compromise (BEC) has once again proven to be a costly issue, with a company losing $60 million in a wire transfer fraud scheme Full Article
n How regulatory standards and cyber insurance inform each other By www.welivesecurity.com Published On :: Wed, 21 Aug 2024 09:00:00 +0000 Should the payment of a ransomware demand be illegal? Should it be regulated in some way? These questions are some examples of the legal minefield that cybersecurity teams must deal with Full Article
n Exploring Android threats and ways to mitigate them | Unlocked 403 cybersecurity podcast (ep. 5) By www.welivesecurity.com Published On :: Mon, 26 Aug 2024 09:00:00 +0000 The world of Android threats is quite vast and intriguing. In this episode, Becks and Lukáš demonstrate how easy it is to take over your phone, with some added tips on how to stay secure Full Article
n Old devices, new dangers: The risks of unsupported IoT tech By www.welivesecurity.com Published On :: Tue, 27 Aug 2024 09:00:00 +0000 In the digital graveyard, a new threat stirs: Out-of-support devices becoming thralls of malicious actors Full Article
n PWA phishing on Android and iOS – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 23 Aug 2024 09:00:00 +0000 Phishing using PWAs? ESET Research's latest discovery might just ruin some users' assumptions about their preferred platform's security Full Article
n Analysis of two arbitrary code execution vulnerabilities affecting WPS Office By www.welivesecurity.com Published On :: Wed, 28 Aug 2024 09:00:00 +0000 Demystifying CVE-2024-7262 and CVE-2024-7263 Full Article
n The key considerations for cyber insurance: A pragmatic approach By www.welivesecurity.com Published On :: Wed, 04 Sep 2024 09:00:00 +0000 Would a more robust cybersecurity posture impact premium costs? Does the policy offer legal cover? These are some of the questions organizations should consider when reviewing their cyber insurance options Full Article
n In plain sight: Malicious ads hiding in search results By www.welivesecurity.com Published On :: Tue, 03 Sep 2024 09:00:00 +0000 Sometimes there’s more than just an enticing product offer hiding behind an ad Full Article
n Stealing cash using NFC relay – Week in Security with Tony Anscombe By www.welivesecurity.com Published On :: Wed, 28 Aug 2024 14:01:52 +0000 The discovery of the NGate malware by ESET Research is another example of how sophisticated Android threats have become Full Article
n CosmicBeetle steps up: Probation period at RansomHub By www.welivesecurity.com Published On :: Tue, 10 Sep 2024 09:00:00 +0000 CosmicBeetle, after improving its own ransomware, tries its luck as a RansomHub affiliate Full Article
n Bitcoin ATM scams skyrocket – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 06 Sep 2024 10:25:42 +0000 The schemes disproportionately victimize senior citizens, as those aged 60 or over were more than three times as likely as younger adults to fall prey to the scams Full Article
n 6 common Geek Squad scams and how to defend against them By www.welivesecurity.com Published On :: Wed, 11 Sep 2024 09:00:00 +0000 Learn about the main tactics used by scammers impersonating Best Buy’s tech support arm and how to avoid falling for their tricks Full Article
n AI security bubble already springing leaks By www.welivesecurity.com Published On :: Mon, 16 Sep 2024 09:00:00 +0000 Artificial intelligence is just a spoke in the wheel of security – an important spoke but, alas, only one Full Article
n Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023 By www.welivesecurity.com Published On :: Thu, 26 Sep 2024 09:00:00 +0000 ESET Research has conducted a comprehensive technical analysis of Gamaredon’s toolset used to conduct its cyberespionage activities focused in Ukraine Full Article