Thursday, May 25, 2017

82% of Databases Left Unencrypted in Public Cloud - Anyone surprised?



The team analyzed more than one million cloud resources, processing 12 petabytes of network traffic, and dug for flaws in public cloud infrastructure. They found 4.8 million records, including protected health information (PHI) and personally identifiable information (PII), were exposed because best practices like encryption and access control aren't enforced

More info here:
http://www.darkreading.com/cloud/82--of-databases-left-unencrypted-in-public-cloud/d/d-id/1328966?_mc=sm_dr&hootPostID=af059d8271f774c137025b583778c95d

You have email gateway and you think you are secure - Not if Split tunnel SMTP Tunnel Exploit works

Security vendor Securolytics this week claimed it has devised an exploit that allows an attacker to bypass an organization's email security gateway and directly unload malware on the email server by using the encryption device as a backdoor.




More Info here:

Tuesday, May 23, 2017

If you are a TENCENT customer , you may want to read this



Customers of Tencent, China's biggest technology company, need to be on the lookout for ransomware attackers who would love nothing more than to infect their Android devices.


https://www.grahamcluley.com/tencent-users-beware-theres-a-mobile-ransomware-coming-after-you/

Tuesday, May 16, 2017

The Quote "Lost at Sea" could have a new meaning if this is true



The seaborne cybercrime threat is real: one billionaire had more than £100,000 stolen when criminals hacked his bank account. Others have been blackmailed with compromising photos, and some have already been forced to pay a ransom to unlock their vessel’s navigation systems.


Check Here:
https://www.theguardian.com/world/2017/may/05/cybercrime-billionaires-superyacht-owners-hacking

Friday, May 12, 2017

Have you patched your windows SMB Vulnerabiltiy? - WannaCry Ransomware is actively exploiting it


If you have not done so?
Please do now



Most of the attacks are concentrated in Russia, but machines in 74 countries have been infected


Details below:
https://threatpost.com/leaked-nsa-exploit-spreading-ransomware-worldwide/125654/ 

Whatsapp scam message - Watch out


WhatsApp users are receiving scam messages from trusted sources, offering free Netflix access for a year if they pass on a link to 10 of their contacts.
Of course this shortened link is malicious, and the web page it leads to is actually "stealing information from users' mobile phones for different types of subscriptions, or opening the system's messaging application in order to send an SMS to a premium number with a certain text, or even encouraging users to download applications from unofficial sites,"


For more details:
https://www.scmagazine.com/whatsapp-scam-offers-free-netflix-but-steals-info-and-commits-sms-fraud/article/661195/

Thursday, May 11, 2017

Keylogger - Comes pre-installed?

Talk about being irresponsible

An audio driver that comes installed on some HP-manufactured computers records users’ keystrokes and stores them in a world-readable plaintext file, researchers said Thursday.


For more details:
https://threatpost.com/keylogger-found-in-audio-drivers-on-some-hp-machines/125600/