Security Leftovers

-
Yet another Windows ransomware strain appears on the scene [iophk: Windows TCO]
The global security firm Sophos said in a blog post that it had begun noticing the new Windows ransomware on 18 March as it took aim at Exchange boxes that still had not been patched to fix the ProxyLogon vulnerabilities disclosed by Microsoft on 3 March.
Mark Loman, a director of Engineering for Next-Gen Technologies at Sophos, said the new ransomware did not have the most sophisticated of payloads.
-
Oil and gas company Shell suffers Accellion-related data breach
Multinational oil and gas company Royal Dutch Shell plc is the latest victim of a data breach related to a vulnerability in software from Accellion Inc.
In a statement last week, Shell said that the data security incident involved Accellion’s File Transfer Appliance that it uses to transfer large data files securely. The data accessed, during a “limited window of time” according to Shell, included some personal data along with data from Shell companies and some of their stakeholders. Shell noted that there is no evidence of any impact on their core information technology systems, since the fire transfer service is isolated from the rest of the company’s infrastructure.
-
Mimecast confirms [attackers] behind SolarWinds supply chain attack accessed limited amount of customer information
-
Continued Worsening of Ransomware [iophk: Windows TCO]
Is there no solution? A means of detecting the patterns left by this kind of malware?
-
The Worsening State of Ransomware [iophk: Windows TCO]
The problem is growing worse, despite the development of new and more advanced ways to battle it, including the use of behavioral analytics and artificial intelligence (AI). "Cybergangs use different cryptographic algorithms and they distribute software that is remarkably sophisticated and difficult to detect," Hinkley says. "Today, there is almost no barrier to entry and the damage that's inflicted is enormous."
-
Phish Leads to Breach at Calif. State Controller
A phishing attack last week gave attackers access to email and files at the California State Controller’s Office (SCO), an agency responsible for handling more than $100 billion in public funds each year. The phishers had access for more than 24 hours, and sources tell KrebsOnSecurity the intruders used that time to steal Social Security numbers and sensitive files on thousands of state workers, and to send targeted phishing messages to at least 9,000 other workers and their contacts.
-
Spectre attacks against websites still a serious threat, Google warns
Three years after the infamous Spectre vulnerability was discovered, [attackers] can still exploit the security flaw in order to force web browsers to leak information, Google’s security team warns.
The problem has arisen despite extensive efforts by browser developers to harden their software against Spectre-style attacks.
The results of the research was published on the Google Security Blog on Friday (March 12) and include a proof-of-concept exploit written in JavaScript that still works against several browsers, operating systems, and processors.
The key lesson from the research is that Spectre still haunts the industry – so developers need to deploy application-level mitigation measures in order to guard against potential attacks.
-

- Login or register to post comments
Printer-friendly version- 2392 reads
PDF version
More in Tux Machines
- Highlights
- Front Page
- Latest Headlines
- Archive
- Recent comments
- All-Time Popular Stories
- Hot Topics
- New Members
digiKam 7.7.0 is released
After three months of active maintenance and another bug triage, the digiKam team is proud to present version 7.7.0 of its open source digital photo manager. See below the list of most important features coming with this release.
|
Dilution and Misuse of the "Linux" Brand
|
Samsung, Red Hat to Work on Linux Drivers for Future Tech
The metaverse is expected to uproot system design as we know it, and Samsung is one of many hardware vendors re-imagining data center infrastructure in preparation for a parallel 3D world.
Samsung is working on new memory technologies that provide faster bandwidth inside hardware for data to travel between CPUs, storage and other computing resources. The company also announced it was partnering with Red Hat to ensure these technologies have Linux compatibility.
|
today's howtos
|








.svg_.png)
Content (where original) is available under CC-BY-SA, copyrighted by original author/s.

Recent comments
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago