New Malware Hidden in Apple IDE Targets macOS …

New Malware Hidden in Apple IDE Targets macOS …

XcodeSpy is latest example of growing attacks on software supply chain. Researchers from SentinelOne have discovered new malware targeting developers of macOS apps in the latest sign of growing attacker interest in the software supply chain. The malware, XcodeSpy, is disguised as a legitimate Xcode open source project called TabBarInteraction that provides macOS developers with…

Microsoft Defender Antivirus Now Automatically Mitigates Exchange Server Vulnerabilities

Microsoft Defender Antivirus Now Automatically Mitigates Exchange Server Vulnerabilities

“Microsoft has implemented an automatic mitigation tool within Defender Antivirus to tackle critical vulnerabilities in Exchange Server,” reports ZDNet: On March 18, the Redmond giant said the software will automatically mitigate CVE-2021-26855, a severe vulnerability that is being actively exploited in the wild. This vulnerability is one of four that can be used in a…

Microsoft Defender Antivirus Now Protects Users Against Ongoing Exchange Attacks

Microsoft Defender Antivirus Now Protects Users Against Ongoing Exchange Attacks

Microsoft Defender Antivirus Now Protects Users Against Ongoing Exchange Attacks | IT Security News 19. March 2021 Microsoft informed customers on Thursday that Defender Antivirus and System Center Endpoint Protection now provide automatic protection against attacks exploiting the recently disclosed Exchange Server vulnerabilities. read more Like this: Like Loading… Related Tags: SecurityWeek RSS Feed Sponsors…

‘Is this the way you hope to hold this dialogue’: US-China high-level talks in Alaska descend into bickering, United States News & Top Stories

‘Is this the way you hope to hold this dialogue’: US-China high-level talks in Alaska descend into bickering, United States News & Top Stories

ANCHORAGE (BLOOMBERG) – The first high-level talks between the United States and China since President Joe Biden took office descended immediately into bickering and recriminations, with each side sharply criticising the other over human rights, trade and international alliances. US Secretary of State Antony Blinken began his remarks at the meeting in Anchorage, Alaska, by…

US Charges Swiss ‘Hacktivist’ for Data Theft and Leaks

US Charges Swiss ‘Hacktivist’ for Data Theft and Leaks

The Justice Department has charged a Swiss hacker with computer intrusion and identity theft, just over a week after the hacker took credit for helping to break into the online systems of a U.S. security-camera startup. An indictment against 21-year-old Till Kottmann was brought Thursday by a grand jury in the Seattle-based Western District of…

Chinese nation state hackers linked to Finnish Parliament hack

Chinese nation state hackers linked to Finnish Parliament hack

Chinese nation-state hackers have been linked to an attack on the Parliament of Finland that took place last year and led to the compromise of some parliament email accounts. “Some parliament e-mail accounts may have been compromised as a result of the attack, among them e-mail accounts that belong to MPs,” Parliament officials said at…

Hackers Used Trojanized Xcode to Target macOS Developers

Hackers Used Trojanized Xcode to Target macOS Developers

Cybercrime , Endpoint Security , Fraud Management & Cybercrime Supply Chain Attack Hits Development Environment Akshaya Asokan (asokan_akshaya) • March 19, 2021     Hackers used Trojanized Xcode projects to install backdoors on developers’ devices as part of a supply chain attack, security firm Sentinel Labs reports. Xcode is Apple’s integrated development environment for macOS….

Electrical Grid’s Distribution Systems More Vulnerable

Electrical Grid’s Distribution Systems More Vulnerable

Business Continuity Management / Disaster Recovery , Endpoint Security , Governance & Risk Management Audit Recommends Energy Department Implement Better Protections Scott Ferguson (Ferguson_Writes) • March 19, 2021     The U.S. electrical grid’s distribution systems that deliver electricity directly to customers are increasingly vulnerable to cyberthreats, and the Department of Energy needs to do…