Technology

US Sanctions Pegasus-maker NSO Group and 3 Others For Selling Spyware

The U.S. Commerce Department on Wednesday added four companies, including Israel-based spyware companies NSO Group and Candiru, to a list of entities engaging in “malicious cyber activities.” The agency said the two companies were added to the list based on evidence that “these entities developed and supplied spyware to foreign governments that used these tools […]

US Sanctions Pegasus-maker NSO Group and 3 Others For Selling Spyware Read More »

Our journey to API security at Raiffeisen Bank International

This article was written by Peter Gerdenitsch, Group CISO at Raiffeisen Bank International, and is based on a presentation given during Imvision’s Executive Education Program, a series of events focused on how enterprises are taking charge of the API security lifecycle. Launching the “Security in Agile” program Headquartered in Vienna, Raiffeisen Bank International (RBI) operates

Our journey to API security at Raiffeisen Bank International Read More »

Facebook to Shut Down Facial Recognition System and Delete Billions of Records

Facebook’s newly-rebranded parent company Meta on Tuesday announced plans to discontinue its decade-old “Face Recognition” system and delete a massive trove of more than a billion users’ facial recognition templates as part of a wider initiative to limit the use of the technology across its products. The Menlo Park tech giant described the about-face as “one of the largest

Facebook to Shut Down Facial Recognition System and Delete Billions of Records Read More »

Mekotio Banking Trojan Resurfaces with New Attacking and Stealth Techniques

The operators behind the Mekotio banking trojan have resurfaced with a shift in its infection flow so as to stay under the radar and evade security software, while staging nearly 100 attacks over the last three months. “One of the main characteristics […] is the modular attack which gives the attackers the ability to change

Mekotio Banking Trojan Resurfaces with New Attacking and Stealth Techniques Read More »

BlackMatter Ransomware Reportedly Shutting Down; Latest Analysis Released

An analysis of new samples of BlackMatter ransomware for Windows and Linux has revealed the extent to which the operators have continually added new features and encryption capabilities in successive iterations over a three-month period. No fewer than 10 Windows and two Linux versions of the ransomware have been observed in the wild to date,

BlackMatter Ransomware Reportedly Shutting Down; Latest Analysis Released Read More »

Google Warns of New Android 0-Day Vulnerability Under Active Targeted Attacks

Google has rolled out its monthly security patches for Android with fixes for 39 flaws, including a zero-day vulnerability that it said is being actively exploited in the wild in limited, targeted attacks. Tracked as CVE-2021-1048, the zero-day bug is described as a use-after-free vulnerability in the kernel that can be exploited for local privilege escalation. Use-after-free

Google Warns of New Android 0-Day Vulnerability Under Active Targeted Attacks Read More »

Alert! Hackers Exploiting GitLab Unauthenticated RCE Flaw in the Wild

A now-patched critical remote code execution (RCE) vulnerability in GitLab’s web interface has been detected as actively exploited in the wild, cybersecurity researchers warn, rendering a large number of internet-facing GitLab instances susceptible to attacks. Tracked as CVE-2021-22205, the issue relates to an improper validation of user-provided images that results in arbitrary code execution.

Alert! Hackers Exploiting GitLab Unauthenticated RCE Flaw in the Wild Read More »

Google to Pay Hackers $31,337 for Exploiting Patched Linux Kernel Flaws

Google on Monday announced that it will pay security researchers to find exploits using vulnerabilities, previously remediated or otherwise, over the next three months as part of a new bug bounty program to improve the security of the Linux kernel. To that end, the company is expected to issue rewards worth $31,337 for exploiting privilege

Google to Pay Hackers $31,337 for Exploiting Patched Linux Kernel Flaws Read More »

Researchers Uncover ‘Pink’ Botnet Malware That Infected Over 1.6 Million Devices

Cybersecurity researchers disclosed details of what they say is the “largest botnet” observed in the wild in the last six years, infecting over 1.6 million devices primarily located in China, with the goal of launching distributed denial-of-service (DDoS) attacks and inserting advertisements into HTTP websites visited by unsuspecting users. Qihoo 360’s Netlab security team dubbed

Researchers Uncover ‘Pink’ Botnet Malware That Infected Over 1.6 Million Devices Read More »