Elizabeth Hernandez
10 Cybersecurity Tips for Small Businesses
Hackers are increasingly targeting small businesses. These 10 cybersecurity tips for small businesses can be implemented to improve security, prevent successful cyberattacks, and avoid costly data breaches. Many small business owners misguidedly think that their company is too small to … Read more
Mongolock Ransomware Deletes Files and Demands Ransom
A new form of MongoLock ransomware is actively being used in a global campaign. A 0.1 BTC ransom is demanded, although file recovery may not be possible. The ransomware immediately deletes files and formats backup drives and a recoverable copy … Read more
Homebuyers and Sellers Targeted ub Solicitor Email Scam
Home purchasers and real estate agents in the United Kingdom and Ireland are being targeted by cybercriminals using a new solicitor email campaign. The scam, which includes mimicking a solicitor, is costing victims thousands. Additionally, there have some cases seen … Read more
Ryuk Ransomware Suspected in Newspaper Cyberattack
The final weekend of 2018 has seen a significant newspaper cyberattack in the United States that has disrupted production of several newspapers published by Tribune Publishing. The attacks were malware-related and impacted the Saturday editions of the Los Angeles Times, … Read more
Guest Wi-Fi Best Practices
Many businesses now offer their customers free access to their Wi-Fi networks, but if guest Wi-Fi best practices are not followed, opening up Wi-Fi networks to guest users is not without risk. You may have provided security awareness training to … Read more
Worst Passwords of 2018 and Password Best Practices Revealed
It’s the time of year when the poor password practices of users are highlighted. This month has seen the list of the worst passwords of 2018 published and a list of 2018’s worst password offenders. The Worst Passwords of 2018 … Read more
Massive Marriott Data Breach Discovered: 500 Million Guests Affected
A massive Marriott data breach has been detected which could affect as many as 500 million individuals who previously made bookings at Starwood Hotels and Resorts. While the data breach is not the largest ever reported – The 2013 Yahoo … Read more
Sophisticated Phishing Scam Spoofed Iceland Police
Police in Iceland have said a highly complex phishing attack is the biggest ever cyberattack the country has ever witnessed. The campaign saw thousands of messages sent that tried to get Icelanders to download a remote access tool that would … Read more
Universities Targeted as Hackers Search for Valuable Research Data
Hackers have been targeted universities extensively in the last year according to figures recently released by Kaspersky Lab. Universities store very valuable information. As research group collate valuable proprietary data. The results of research studies are particularly valuable. It may … Read more
FilesLocker Ransomware: A New RaaS Variant Targeting Chinese and English Speakers
A new ransomware threat has been detected called FilesLocker which is currently being offered as ransomware-as-a-service (RaaS) on a TOR malware forum. FilesLocker ransomware is not a particularly sophisticated ransomware variant, but it still poses a significant threat. FilesLocker ransomware … Read more
Stealthy sLoad Downloader Performs Extensive Reconnaissance Before Delivering Payload
The past few months have seen an increase in new, versatile malware downloaders that gather a significant amount of data about users’ systems before deploying a malicious payload. That payload is determined on the users’ system. Marap malware and Xbash … Read more
XMRig Cryptocurrency Miner Installed Using Fake Adobe Flash Updates
Using fake software updates to spread malware is not a new phenomenon, but a new malware campaign has been discovered that is quite different. Fake Adobe Flash updates are being spread that actually do update the user’s Flash version, albeit … Read more
New Malware Variant CamuBot Trojan Being Used in Targeted Attacks on Companies
Spam or junk email may be the primary method of sharing delivering banking Trojans, however there are many other ways of convincing employees to download and install malware on their computers. The CamuBot Trojan the method used is vishing. Vishing … Read more
CamuBot Trojan Used in Targeted Attacks on Businesses
The CamuBot Trojan is a new malware variant that is being used in vishing campaigns on employees to obtain banking credentials. Cybercriminals Use Vishing to Convince Employees to Install CamuBot Trojan Spam email may be the primary method of delivering … Read more
Versatile New AdvisorsBot Malware Threat Distributed Through Spam Email
Hotels, restaurants, and telecommunications businesses are being focused on in a new spam email campaign that sends a new variety of malware called AdvisorsBot. AdvisorsBot is a malware downloader which, like many malware variants, is being shared vis spam emails … Read more
MagnetoCore Malware Campaign Sees 7,339 Magneto Stores Infected with Payment Card Skimmer
A massive MagnetoCore malware campaign has been uncovered that has seen thousands of Magneto stores compromised and loaded with a payment card scraper. As visitors pay for their purchases on the checkout pages of compromised websites, their payment card information … Read more
New AdvisorsBot Malware Threat Spread Using Spam Email
Hotels, restaurants, and telecommunications companies are being focused on with a new spam email campaign that sends a new form of malware called AdvisorsBot. AdvisorsBot is a malware downloader which, like many strains of malware, is being shared using spam … Read more
Security Awareness Training Best Practices
Security awareness training best practices to help your organization tackle the weakest link in the security chain: Your employees. The Importance of Security Awareness Training It doesn’t matter how comprehensive your security defenses are and how much you invested on … Read more
New AdvisorsBot Malware Threat Distributed Through Spam Email
Hotels, restaurants, and telecommunications businesses are the focus of a new spam email campaign that broadcasts a new form of malware titled AdvisorsBot. AdvisorsBot is a malware downloader which, like many malware variants, is being sent using spam emails containing … Read more
Fake WannaCry Ransomware Campaign Uncovered
In May 2017, WannaCry ransomware attacks brought many businesses to a stop, with the UK’s National Health Service (NHS) a notable target. Now, a little more than 12 months later, a new WannaCry ransomware campaign is being operated, or so … Read more
UnityPoint Health Phishing Attack Impacts 1.4 Million
Many large healthcare data breaches recently have been reported that have seen hackers obtain access to employees’ email accounts and sensitive data, although the recently shared UnityPoint Health phishing attack stands out due to the massive number of individuals that … Read more
Adidas Phishing Scam Discovered
A new Adidas phishing scam has been discovered that involves offering free shoes and money. The messages claim that Adidas is celebrating its 69th anniversary and sending 2,500 lucky customers a free pair of Adidas sneakers along with a free … Read more
Cybercriminal Net €2 million Using Lazio Phishing Scam
The Lazio phishing scam looks to have lead to a €2 million loss for the Italian Serie A football team, which made the final installment of a transfer of a football player to the bank account of a cybercriminal. The … Read more
Rapid Spread of Cryptocurrency Mining PowerGhost Malware
A huge cryptocurrency mining campaign has been discovered by security experts at Kaspersky Lab – a campaign that has lead to the creation of a vast network of devices infected with PowerGhost malware. PowerGhost malware is being downloaded to all … Read more
2017: Ransomware Attacks Estimated to Reach $5bn
The cost of ransomware attacks cannot be estimated by the amounts illegally earned by hackers due to ransom payments. In fact, the ransom payments are just a small part of the costs experienced by companies that have been attacked with … Read more
Your Router May Have Been Compromised: Urgent Action Required
A hacking group has succeeded in infecting hundreds of thousands of routers with VPNFilter malware. The scale of the malware campaign is astonishing. So far more than half a million routers are believed to have been infected with the malware, … Read more
Tech Support Scams Grow by 24% During 2017
Microsoft has published new figures that show there has been a sizeable upwards surge in tech support scams over the past 12 months. The amount of victims that have reported these scams to Microsoft increased by 24% in 2017. The … Read more
Syrian Refugee Phishing and Active Shooter Campaigns
Two new phishing campaigns have been uncovered recently that have seen phishers sink to new depths. An active shooter phishing campaign has been discovered that uses fear and urgency to steal details, while a Syrian refugee phishing campaign focuses on … Read more
Phishing News: Active Shooter and Syrian Refugee Campaigns
Two new phishing campaigns have been discovered in the last three weeks that have seen phishers sink to new depths. An active shooter phishing campaign has been discovered that uses fear and urgency to steal credentials, while a Syrian refugee … Read more
2018 Largest Data Breach Involved Exposing of 340 Million-Records
A database of U.S. consumer information has been left unprotected online by the marketing company Exactis. With 340 million records, this is the largest data breach of 2018. While you may not be familiar with the Florida-based data broker Exactis, … Read more
Worst Data Breaches of 2017
2017 has been a particularly bad year for data violations, but what were the worst data breaches of 2017? We have put together a list of the largest and most serious cyber attacks that came to light in 2017. Equifax … Read more
Rockingham School District Loses $314,000 to Emotet Malware Infection
The Rockingham school district in North Carolina identified that Emotet malware had been downloaded to its network in late November. The cost of tackling the infection was a massive $314,000. The malware was sent using spam emails, which arrived in … Read more
Emotet Malware Infection Cost Rockingham School District $314,000 to Resolve
The Rockingham school district in North Carolina discovered Emotet malware had been installed on its network in late November. The cost of resolving the infection was an astonishing $314,000. The malware was delivered via spam emails, which arrived in multiple … Read more
Wi-Fi Alliance Enhances WPA2 and Announces WPA3 Protocol Coming Later this Year
15 years after the launch of the wireless security protocol WPA2, the Wi-Fi Alliance has announced this year will see the release of the WPA3 protocol. The transition period from the WPA2 to WPA3 protocol is expected to take several … Read more
Malware Attack at Forever 21 POS Continued for 7 Months
A recently identified Forever 21 POS malware attack has resulted in customers’ credit card data being accessed. While malware attacks on retail POS systems are now a regular occurance, in the case of the Forever 21 POS malware attack, the … Read more
Are Password Managers Safe?
Passwords should be complex and difficult to guess, but that makes them difficult to remember, so what about using password managers to get around that problem? Are password managers safe and secure? Are they better than attempting to remember passwords … Read more
Mobile Accounts Drained of Money by Xafecopy Malware
Xafecopy malware is a new Trojan that is being leveraged to take money from victims using their smartphone devices. The malware looks like a useful apps that function exactly as expected, although along with the useful functions, the apps have … Read more
Social Media Accounts Being Hack to Allow Terdot Trojan Steal Banking Details
The Terdot Trojan is a new strain of Zeus, a highly effective banking Trojan that was first spotted in 2009. While Zeus has been discontinued, its source code has been accessible since 2011, allowing hackers to create a range of … Read more
Social Media Accounts Hijacks by Banking Terdot Trojan
The Terdot Trojan is a form of Zeus, a highly successful banking Trojan that first was seen in 2009. While Zeus is no longer doing the rounds, its source code has been available since 2011, allowing cyber criminals to produce … Read more
Terdot Trojan Steals Banking Credentials and Hijacks Social Media Accounts
The Terdot Trojan is a new incarnation of Zeus, a highly successful banking Trojan that first appeared in 2009. While Zeus has been retired, its source code has been available since 2011, allowing hackers to develop a swathe of new … Read more
Combosquatting: Study Reveals Extent of Use of Trademarks in Web Attacks
Combosquatting is a popular technique used by hackers, spammers, and scammers to fool users into downloading malware or revealing their credentials. Combosquatting should not be confused with typosquatting. The latter involves the purchasing of domains with transposed letters or common … Read more
Microsoft Office Attacks Without Macros
Microsoft Office documents that include malicious macros are commonly used to distribute malware and ransomware. However, security experts have now identified Microsoft Office attacks without macros, and the technique is more difficult to block. While you can turn off macros … Read more
Phishing Website Key to Equifax Breach Success
The cyberattack on Equifax impacted around 50% of the population of the United States. 143 million U.S. consumers may have had their sensitive data illegally obtained by hackers, as did around 400,000 individuals in the United Kingdom and 100,000 consumers … Read more
IoT Reaper Botnet Growing at Alarming Rate
Last year, the Mirai botnet was used in massive DDoS attacks; however, the IoT Reaper botnet could redefine massive. The Mirai botnet, which mostly consisted of IoT devices, was capable of delivering DDoS attacks in excess of 1 terabit per … Read more
Self-Replicating Worm Module Incorporated in Trickbot Malware
Trickbot malware is a banking Trojan that has been around for some time, although its developers have recently created a WannaCry ransomware-style worm module that allows it to spread much more swiftly. The latest NotPetya attacks also included a similar … Read more
Windows 10 Attacked by Bashware
A new attack method – termed Bashware – could permit hackers to download malware to Windows 10 computing devices without being discovered by security software, according to research published by Check Point. The Windows Subsystem for Linux (WSL) was brought … Read more
HIPAA Compliance and Phishing: Email Attacks Can Result in HIPAA Penalties
A phishing attack on a HIPAA-covered entity has lead to in a $400,000 HIPAA breach fine for non-compliance. This is not the first time a phishing attack has resulted in a penalty from OCR for non-compliance. The failure to stop … Read more
Beware of Equifax Phishing Scams – Cybercriminals Are Typosquatting to Catch the Unwary
Consumers should be wary of Equifax phishing attacks following massive data breach revealed earlier this month. The 143 million records possibly stolen in the breach will be monetized, which means many will likely be sold to hackers. Trend Micro has … Read more
Lack of Two-Factor Authentication Linked to Deloitte Data Breach
This week, news has emerged about a serious Deloitte data breach that allegedly resulted in ‘several gigabytes’ of sensitive emails sent to and from the accountancy firm’s clients being obtained by hackers. Deloitte is one of the big four accountancy … Read more
NHS Computers Taken Offline After Barts Health Malware Attack:
A Barts Health malware attack resulted in the shutdown of hospital IT systems on Friday last week as the UK NHS Trust attempted to address the damage caused and limit the infection. Barts Health is the biggest NHS Trust in … Read more