Experts warn of a new Android banking trojan stealing users’ credentials

Experts warn of a new Android banking trojan stealing users’ credentials

Cybersecurity researchers on Monday disclosed a new Android trojan that hijacks users’ credentials and SMS messages to facilitate fraudulent activities against banks in Spain, Germany, Italy, Belgium, and the Netherlands. Called “TeaBot” (or Anatsa), the malware is said to be in its early stages of development, with malicious attacks targeting financial apps commencing in late…

Malspam Campaign Used Hancitor to Download Cuba Ransomware

Malspam Campaign Used Hancitor to Download Cuba Ransomware

Cybercrime , Cybercrime as-a-service , Email Security & Protection Attackers Co-Opted Malware for Data Exfiltration and Ransom, Group-IB Finds Akshaya Asokan (asokan_akshaya) • May 8, 2021     Attackers co-opted the Hancitor malware downloader and recently used it to deliver Cuba ransomware as part of an email spam campaign for data exfiltration and ransom extortion,…

Close to Half of US East Coast Fuel Supply Shutdown Due to Ransomware Cyberattack

Close to Half of US East Coast Fuel Supply Shutdown Due to Ransomware Cyberattack

Colonial system affected by the cyberattack. Colonial is the largest refined products pipeline in the U.S., transporting more than 100 million gallons, or 2.5 million barrels, per day. Its pipeline spans more the 5,500 miles throughout the Southern and Eastern U.S. (Map: Colonial Pipeline) Colonial Pipeline, which accounts for close to half of the United…

City of Tulsa’s online services disrupted in ransomware incident

City of Tulsa’s online services disrupted in ransomware incident

The City of Tulsa, Oklahoma, has suffered a ransomware attack that forced the City to shut down its systems to prevent the further spread of the malware. Tulsa is the second-largest city in Oklahoma, with a population of approximately 400,000 people. Over the weekend, threat actors deployed a ransomware attack on the City of Tulsa’s…

Staff Bonus was “Crass” Phishing Simulation

Staff Bonus was “Crass” Phishing Simulation

A British train company has been criticized for running a cybersecurity test that made employees think they would receive a bonus for working hard during the pandemic. West Midlands Trains sent an email purporting to be from the company’s managing director, Julian Edwards, out to its approximately 2,500 employees. The missive thanked staff for toiling through…

U.S. Declares Emergency in 17 States Over Fuel Pipeline Cyber Attack

U.S. Declares Emergency in 17 States Over Fuel Pipeline Cyber Attack

The ransomware attack against Colonial Pipeline’s networks has prompted the U.S. Federal Motor Carrier Safety Administration (FMCSA) to issue a regional emergency declaration in 17 states and the District of Columbia (D.C.). The declaration provides a temporary exemption to Parts 390 through 399 of the Federal Motor Carrier Safety Regulations (FMCSRs), allowing alternate transportation of…

High Risk Security Vulnerability in Qualcomm mobile processors

High Risk Security Vulnerability in Qualcomm mobile processors

High Risk Security Vulnerability in Qualcomm mobile processors | IT Security News 10. May 2021 A recent study carried out by some cyber security researchers from Checkpoint has discovered a serious vulnerability in nearly 40% of top end mobile phones manufactured by reputed companies such as Google, Samsung, LG, Xiaomi and OnePlus. Experts say that…

CVE-2020-28588

CVE-2020-28588

An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4.66. More specifically, this issue has been introduced in v5.1-rc4 (commit 631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0) and is still present in v5.10-rc4, so it�s likely that all versions in between are affected.