CVE-2021-35392
CVE-2021-35392
Google recently removed nine malicious apps from the Play Store after they were found stealing Facebook users’ logins and passwords. Discovered by security researchers at Dr. Web, these stealer trojans were found using a special mechanism to trick users into disclosing their Facebook login details by offering them photo editing and app lock features as well…
Adversaries are deploying DearCry ransomware on victim systems after hacking into on-premise Microsoft Exchange servers that remain unpatched, Microsoft acknowledged late Thursday. “Microsoft observed a new family of human operated ransomware attack customers,” Microsoft Security Program Manager Phillip Misner tweeted at 9:19 p.m. ET Thursday. “Human operated ransomware attacks are utilizing the Microsoft Exchange vulnerabilities…
Enterprise cloud security firm Qualys has become the latest victim to join a long list of entities to have suffered a data breach after zero-day vulnerabilities in its Accellion File Transfer Appliance (FTA) server were exploited to steal sensitive business documents. As proof of access to the data, the cybercriminals behind the recent hacks targeting…
3rd Party Risk Management , Governance & Risk Management , IT Risk Management NIST, CISA Highlight Key Steps to Take Akshaya Asokan (asokan_akshaya) • April 28, 2021 The U.S. Cybersecurity and Infrastructure Security Agency and the National Institute of Standards and Technology have released a report providing insights on how to enhance supply…
Fraud Management & Cybercrime , Fraud Risk Management , ID Fraud Insurers Have a Great Opportunity to Become Guardians of Customer Data Robert Harris • August 24, 2021 The rapid rise of digitalization and new data-gathering technologies has encouraged a lot of well-meaning advice about how insurers can use data more effectively to…
A senior official at the United States Department of Justice (DOJ) has said that ransomware attacks in America are to be investigated with a similar urgency as incidences of terrorism. The official told news agency Reuters that cyber-assaults using this particular type of malware are to be prioritized more highly now following a passel of ransomware attacks against entities…