in HotPage: Story of a signed, vulnerable, ad-injecting driver By www.welivesecurity.com Published On :: Thu, 18 Jul 2024 09:30:00 +0000 A study of a sophisticated Chinese browser injector that leaves more doors open! Full Article
in Understanding IoT security risks and how to mitigate them | Unlocked 403 cybersecurity podcast (ep. 4) By www.welivesecurity.com Published On :: Wed, 10 Jul 2024 09:30:00 +0000 As security challenges loom large on the IoT landscape, how can we effectively counter the risks of integrating our physical and digital worlds? Full Article
in Should ransomware payments be banned? – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 12 Jul 2024 12:30:20 +0000 Blanket bans on ransomware payments are a much-debated topic in cybersecurity and policy circles. What are the implications of outlawing the payments, and would the ban be effective? Full Article
in Hello, is it me you’re looking for? How scammers get your phone number By www.welivesecurity.com Published On :: Mon, 15 Jul 2024 11:45:35 +0000 Your humble phone number is more valuable than you may think. Here’s how it could fall into the wrong hands – and how you can help keep it out of the reach of fraudsters. Full Article
in The tap-estry of threats targeting Hamster Kombat players By www.welivesecurity.com Published On :: Tue, 23 Jul 2024 09:00:00 +0000 ESET researchers have discovered threats abusing the success of the Hamster Kombat clicker game Full Article
in Cursed tapes: Exploiting the EvilVideo vulnerability on Telegram for Android By www.welivesecurity.com Published On :: Mon, 22 Jul 2024 09:00:00 +0000 ESET researchers discovered a zero-day Telegram for Android exploit that allows sending malicious files disguised as videos Full Article
in How a signed driver exposed users to kernel-level threats – Week in Security with Tony Anscombe By www.welivesecurity.com Published On :: Sun, 21 Jul 2024 07:24:11 +0000 A purported ad blocker marketed as a security solution leverages a Microsoft-signed driver that inadvertently exposes victims to dangerous threats Full Article
in Building cyber-resilience: Lessons learned from the CrowdStrike incident By www.welivesecurity.com Published On :: Tue, 23 Jul 2024 12:23:39 +0000 Organizations, including those that weren’t struck by the CrowdStrike incident, should resist the temptation to attribute the IT meltdown to exceptional circumstances Full Article
in Phishing targeting Polish SMBs continues via ModiLoader By www.welivesecurity.com Published On :: Tue, 30 Jul 2024 09:00:00 +0000 ESET researchers detected multiple, widespread phishing campaigns targeting SMBs in Poland during May 2024, distributing various malware families Full Article
in Beware of fake AI tools masking very real malware threats By www.welivesecurity.com Published On :: Mon, 29 Jul 2024 09:00:00 +0000 Ever attuned to the latest trends, cybercriminals distribute malicious tools that pose as ChatGPT, Midjourney and other generative AI assistants Full Article
in Telegram for Android hit by a zero-day exploit – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 26 Jul 2024 11:57:23 +0000 Attackers abusing the EvilVideo vulnerability could share malicious Android payloads via Telegram channels, groups, and chats, all while making them appear as legitimate multimedia files Full Article
in The cyberthreat that drives businesses towards cyber risk insurance By www.welivesecurity.com Published On :: Wed, 31 Jul 2024 09:00:00 +0000 Many smaller organizations are turning to cyber risk insurance, both to protect against the cost of a cyber incident and to use the extensive post-incident services that insurers provide Full Article
in AI and automation reducing breach costs – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 02 Aug 2024 11:30:15 +0000 Organizations that leveraged AI and automation in security prevention cut the cost of a data breach by $2.22 million compared to those that didn't deploy these technologies Full Article
in Why tech-savvy leadership is key to cyber insurance readiness By www.welivesecurity.com Published On :: Wed, 07 Aug 2024 09:00:00 +0000 Having knowledgeable leaders at the helm is crucial for protecting the organization and securing the best possible cyber insurance coverage Full Article
in Black Hat USA 2024: How cyber insurance is shaping cybersecurity strategies By www.welivesecurity.com Published On :: Thu, 08 Aug 2024 14:40:36 +0000 Cyber insurance is not only a safety net, but it can also be a catalyst for advancing security practices and standards Full Article
in Black Hat USA 2024 recap – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 09 Aug 2024 13:53:46 +0000 Unsurprisingly, many discussions revolved around the implications of the CrowdStrike outage, including the lessons it may have offered for bad actors Full Article
in Be careful what you pwish for – Phishing in PWA applications By www.welivesecurity.com Published On :: Tue, 20 Aug 2024 09:00:00 +0000 ESET analysts dissect a novel phishing method tailored to Android and iOS users Full Article
in The great location leak: Privacy risks in dating apps By www.welivesecurity.com Published On :: Mon, 12 Aug 2024 14:51:08 +0000 What if your favorite dating, social media or gaming app revealed your exact coordinates to someone you’d rather keep at a distance? Full Article
in How a BEC scam cost a company $60 million – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 16 Aug 2024 11:01:54 +0000 Business email compromise (BEC) has once again proven to be a costly issue, with a company losing $60 million in a wire transfer fraud scheme Full Article
in How regulatory standards and cyber insurance inform each other By www.welivesecurity.com Published On :: Wed, 21 Aug 2024 09:00:00 +0000 Should the payment of a ransomware demand be illegal? Should it be regulated in some way? These questions are some examples of the legal minefield that cybersecurity teams must deal with Full Article
in Exploring Android threats and ways to mitigate them | Unlocked 403 cybersecurity podcast (ep. 5) By www.welivesecurity.com Published On :: Mon, 26 Aug 2024 09:00:00 +0000 The world of Android threats is quite vast and intriguing. In this episode, Becks and Lukáš demonstrate how easy it is to take over your phone, with some added tips on how to stay secure Full Article
in PWA phishing on Android and iOS – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 23 Aug 2024 09:00:00 +0000 Phishing using PWAs? ESET Research's latest discovery might just ruin some users' assumptions about their preferred platform's security Full Article
in Analysis of two arbitrary code execution vulnerabilities affecting WPS Office By www.welivesecurity.com Published On :: Wed, 28 Aug 2024 09:00:00 +0000 Demystifying CVE-2024-7262 and CVE-2024-7263 Full Article
in The key considerations for cyber insurance: A pragmatic approach By www.welivesecurity.com Published On :: Wed, 04 Sep 2024 09:00:00 +0000 Would a more robust cybersecurity posture impact premium costs? Does the policy offer legal cover? These are some of the questions organizations should consider when reviewing their cyber insurance options Full Article
in In plain sight: Malicious ads hiding in search results By www.welivesecurity.com Published On :: Tue, 03 Sep 2024 09:00:00 +0000 Sometimes there’s more than just an enticing product offer hiding behind an ad Full Article
in Stealing cash using NFC relay – Week in Security with Tony Anscombe By www.welivesecurity.com Published On :: Wed, 28 Aug 2024 14:01:52 +0000 The discovery of the NGate malware by ESET Research is another example of how sophisticated Android threats have become Full Article
in Bitcoin ATM scams skyrocket – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 06 Sep 2024 10:25:42 +0000 The schemes disproportionately victimize senior citizens, as those aged 60 or over were more than three times as likely as younger adults to fall prey to the scams Full Article
in 6 common Geek Squad scams and how to defend against them By www.welivesecurity.com Published On :: Wed, 11 Sep 2024 09:00:00 +0000 Learn about the main tactics used by scammers impersonating Best Buy’s tech support arm and how to avoid falling for their tricks Full Article
in AI security bubble already springing leaks By www.welivesecurity.com Published On :: Mon, 16 Sep 2024 09:00:00 +0000 Artificial intelligence is just a spoke in the wheel of security – an important spoke but, alas, only one Full Article
in Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023 By www.welivesecurity.com Published On :: Thu, 26 Sep 2024 09:00:00 +0000 ESET Research has conducted a comprehensive technical analysis of Gamaredon’s toolset used to conduct its cyberespionage activities focused in Ukraine Full Article
in CosmicBeetle joins the ranks of RansomHub affiliates – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 13 Sep 2024 10:21:33 +0000 ESET researchers also find that CosmicBeetle attempts to exploit the notoriety of the LockBit ransomware gang to advance its own ends Full Article
in Understanding cyber-incident disclosure By www.welivesecurity.com Published On :: Wed, 18 Sep 2024 09:02:40 +0000 Proper disclosure of a cyber-incident can help shield your business from further financial and reputational damage, and cyber-insurers can step in to help Full Article
in Influencing the influencers | Unlocked 403 cybersecurity podcast (ep. 6) By www.welivesecurity.com Published On :: Thu, 19 Sep 2024 09:00:00 +0000 How do analyst relations professionals sort through the noise to help deliver the not-so-secret sauce for a company's success? We spoke with ESET's expert to find out. Full Article
in FBI, CISA warning over false claims of hacked voter data – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 20 Sep 2024 11:03:10 +0000 With just weeks to go before the US presidential election, the FBI and the CISA are warning about attempts to sow distrust in the electoral process Full Article
in Don’t panic and other tips for staying safe from scareware By www.welivesecurity.com Published On :: Wed, 25 Sep 2024 09:00:00 +0000 Keep your cool, arm yourself with the right knowledge, and other tips for staying unshaken by fraudsters’ scare tactics Full Article
in Gamaredon's operations under the microscope – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 27 Sep 2024 13:26:04 +0000 ESET research examines the group's malicious wares as used to spy on targets in Ukraine in the past two years Full Article
in Separating the bee from the panda: CeranaKeeper making a beeline for Thailand By www.welivesecurity.com Published On :: Wed, 02 Oct 2024 13:00:00 +0000 ESET Research details the tools and activities of a new China-aligned threat actor, CeranaKeeper, focusing on massive data exfiltration in Southeast Asia Full Article
in Why system resilience should mainly be the job of the OS, not just third-party applications By www.welivesecurity.com Published On :: Tue, 01 Oct 2024 13:00:00 +0000 Building efficient recovery options will drive ecosystem resilience Full Article
in Mind the (air) gap: GoldenJackal gooses government guardrails By www.welivesecurity.com Published On :: Mon, 07 Oct 2024 09:00:00 +0000 ESET Research analyzed two separate toolsets for breaching air-gapped systems, used by a cyberespionage threat actor known as GoldenJackal Full Article
in Telekopye transitions to targeting tourists via hotel booking scam By www.welivesecurity.com Published On :: Thu, 10 Oct 2024 08:55:00 +0000 ESET Research shares new findings about Telekopye, a scam toolkit used to defraud people on online marketplaces, and newly on accommodation booking platforms Full Article
in The complexities of attack attribution – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 04 Oct 2024 11:55:10 +0000 Attributing a cyberattack to a specific threat actor is a complex affair, as evidenced by new ESET research published this week Full Article
in Cyber insurance, human risk, and the potential for cyber-ratings By www.welivesecurity.com Published On :: Tue, 08 Oct 2024 09:00:00 +0000 Could human risk in cybersecurity be managed with a cyber-rating, much like credit scores help assess people’s financial responsibility? Full Article
in Aspiring digital defender? Explore cybersecurity internships, scholarships and apprenticeships By www.welivesecurity.com Published On :: Mon, 14 Oct 2024 09:00:00 +0000 The world needs more cybersecurity professionals – here are three great ways to give you an ‘in’ to the ever-growing and rewarding security industry Full Article
in Quishing attacks are targeting electric car owners: Here’s how to slam on the brakes By www.welivesecurity.com Published On :: Tue, 15 Oct 2024 09:00:00 +0000 Ever alert to fresh money-making opportunities, fraudsters are blending physical and digital threats to steal drivers’ payment details Full Article
in GoldenJackal jumps the air gap … twice – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 11 Oct 2024 13:28:05 +0000 ESET research dives deep into a series of attacks that leveraged bespoke toolsets to compromise air-gapped systems belonging to governmental and diplomatic entities Full Article
in Protecting children from grooming | Unlocked 403 cybersecurity podcast (ep. 7) By www.welivesecurity.com Published On :: Wed, 16 Oct 2024 09:00:00 +0000 “Hey, wanna chat?” This innocent phrase can take on a sinister meaning when it comes from an adult to a child online – and even be the start of a predatory relationship Full Article
in CloudScout: Evasive Panda scouting cloud services By www.welivesecurity.com Published On :: Mon, 28 Oct 2024 10:00:00 +0000 ESET researchers discovered a previously undocumented toolset used by Evasive Panda to access and retrieve data from cloud services Full Article
in Threat actors exploiting zero-days faster than ever – Week in security with Tony Anscombe By www.welivesecurity.com Published On :: Fri, 18 Oct 2024 12:10:04 +0000 The average time it takes attackers to weaponize a vulnerability, either before or after a patch is released, shrank from 63 days in 2018-2019 to just five days last year Full Article
in Tony Fadell: Innovating to save our planet | Starmus highlights By www.welivesecurity.com Published On :: Mon, 28 Oct 2024 10:30:00 +0000 As methane emissions come under heightened global scrutiny, learn how a state-of-the-art satellite can pinpoint their sources and deliver the insights needed for targeted mitigation efforts Full Article
in How to remove your personal information from Google Search results By www.welivesecurity.com Published On :: Wed, 30 Oct 2024 10:00:00 +0000 Have you ever googled yourself? Were you happy with what came up? If not, consider requesting the removal of your personal information from search results. Full Article