<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>InfoSecHotSpotTwitterFeedRSS</title>
    <link>http://www.rssmix.com/</link>
    <description>This feed was created by mixing existing feeds from various sources.</description>
    <generator>RSSMix</generator>
    <item>
      <title>Leonardo DRZ wins first ever TCG CodeGen Developer Challenge</title>
      <link>https://feeds.feedblitz.com/~/675928620/_/thesecurityledger~Leonardo-DRZ-wins-first-ever-TCG-CodeGen-Developer-Challenge/</link>
      <feedburner:origLink xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">https://securityledger.com/2021/12/leonardo-drz-wins-first-ever-tcg-codegen-developer-challenge/</feedburner:origLink>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://feeds.feedblitz.com/~/675928620/_/thesecurityledger~Leonardo-DRZ-wins-first-ever-TCG-CodeGen-Developer-Challenge/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <post-id xmlns="com-wordpress:feed-additions:1">476721</post-id>
      <description>&lt;p&gt;President and Chairman of Trusted Computing Group (TCG), Dr. Joerg Borchert, shares the news regarding TCG's first ever CodeGen Developer Challenge.&lt;/p&gt;
&lt;p&gt;The post &lt;a rel="NOFOLLOW" href="https://feeds.feedblitz.com/~/675928620/_/thesecurityledger~Leonardo-DRZ-wins-first-ever-TCG-CodeGen-Developer-Challenge/"&gt;Leonardo DRZ wins first ever TCG CodeGen Developer Challenge&lt;/a&gt; appeared first on &lt;a rel="NOFOLLOW" href="https://securityledger.com"&gt;The Security Ledger with Paul F. Roberts&lt;/a&gt;.&lt;/p&gt;
&lt;!-- --&gt;&lt;/p&gt;&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/12/spotlight-how-secrets-sprawl-undermines-software-supply-chain-security/"&gt;Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/spotlight-automation-beckons-as-devops-iot-drive-pki-explosion/"&gt;Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/09/spotlight-e-commerces-bot-and-mouse-game/"&gt;Spotlight: E-Commerce&amp;#8217;s Bot and Mouse Game&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
      <content:encoded>&lt;p&gt;President and Chairman of Trusted Computing Group (TCG), Dr. Joerg Borchert, shares the news regarding TCG's first ever CodeGen Developer Challenge.&lt;/p&gt;
&lt;p&gt;The post &lt;a rel="nofollow" href="https://feeds.feedblitz.com/~/t/0/_/thesecurityledger/~https://securityledger.com/2021/12/leonardo-drz-wins-first-ever-tcg-codegen-developer-challenge/"&gt;Leonardo DRZ wins first ever TCG CodeGen Developer Challenge&lt;/a&gt; appeared first on &lt;a rel="nofollow" href="https://feeds.feedblitz.com/~/t/0/_/thesecurityledger/~https://securityledger.com"&gt;The Security Ledger with Paul F. Roberts&lt;/a&gt;.&lt;Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.feedblitz.com/~/i/675928620/_/thesecurityledger"&gt;
&lt;/p&gt;&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/12/spotlight-how-secrets-sprawl-undermines-software-supply-chain-security/"&gt;Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/spotlight-automation-beckons-as-devops-iot-drive-pki-explosion/"&gt;Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/09/spotlight-e-commerces-bot-and-mouse-game/"&gt;Spotlight: E-Commerce&amp;#8217;s Bot and Mouse Game&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded>
      <category>application development</category>
      <category>application security</category>
      <category>Security Innovation</category>
      <category>Software</category>
      <category>software development</category>
      <category>storage</category>
      <category>Top Stories</category>
      <category>Trusted Computing Group</category>
      <category>coding</category>
      <category>software</category>
      <pubDate>Thu, 23 Dec 2021 19:19:50 GMT</pubDate>
      <comments>https://feeds.feedblitz.com/~/675928620/_/thesecurityledger~Leonardo-DRZ-wins-first-ever-TCG-CodeGen-Developer-Challenge/#respond</comments>
      <guid isPermaLink="false">https://securityledger.com/?p=476721</guid>
      <dc:creator>Paul Roberts</dc:creator>
      <dc:date>2021-12-23T19:19:50Z</dc:date>
    </item>
    <item>
      <title>4-Year-Old Microsoft Azure Zero-Day Exposes Web App Source Code</title>
      <link>https://threatpost.com/microsoft-azure-zero-day-source-code/177270/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://threatpost.com/microsoft-azure-zero-day-source-code/177270/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/23140337/cloud.jpg" width="800" height="533">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/23140337/cloud.jpg" width="800" height="533">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/23140337/cloud-300x200.jpg" width="300" height="200">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/23140337/cloud-150x150.jpg" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>The security vulnerability could expose passwords and access tokens, along with blueprints for internal infrastructure and finding software vulnerabilities.</description>
      <category>Cloud Security</category>
      <category>Vulnerabilities</category>
      <category>Web Security</category>
      <pubDate>Thu, 23 Dec 2021 19:04:13 GMT</pubDate>
      <comments>https://threatpost.com/microsoft-azure-zero-day-source-code/177270/#respond</comments>
      <guid isPermaLink="false">https://kasperskycontenthub.com/threatpost-global/?p=177270</guid>
      <dc:creator>Tara Seals</dc:creator>
      <dc:date>2021-12-23T19:04:13Z</dc:date>
    </item>
    <item>
      <title>The cool retro phone with a REAL DIAL… plus plenty of IoT problems</title>
      <link>https://nakedsecurity.sophos.com/2021/12/23/the-cool-retro-phone-with-a-real-dial-plus-plenty-of-iot-problems/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://nakedsecurity.sophos.com/2021/12/23/the-cool-retro-phone-with-a-real-dial-plus-plenty-of-iot-problems/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/fpcp-1200.png?w=230&amp;h=130&amp;crop=1" medium="image" />
      <post-id xmlns="com-wordpress:feed-additions:1">647654</post-id>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/fpcp-1200.png" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/fpcp-1200.png?w=170&amp;h=90&amp;crop=1" medium="image" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/oxfbgr-gc.png" medium="image" />
      <description>You know you want one, because  this retro phone is NOT A TOY...  except when it comes to cybersecurity.</description>
      <category>IoT</category>
      <category>Security threats</category>
      <category>bugs</category>
      <category>Buletooth</category>
      <category>Chatter Phone</category>
      <category>data leakage</category>
      <category>iot</category>
      <category>snooping</category>
      <pubDate>Thu, 23 Dec 2021 17:58:34 GMT</pubDate>
      <comments>https://nakedsecurity.sophos.com/2021/12/23/the-cool-retro-phone-with-a-real-dial-plus-plenty-of-iot-problems/#respond</comments>
      <guid isPermaLink="false">https://nakedsecurity.sophos.com/?p=647654</guid>
      <dc:creator>Paul Ducklin</dc:creator>
      <dc:date>2021-12-23T17:58:34Z</dc:date>
    </item>
    <item>
      <title>Telegram Abused to Steal Crypto-Wallet Credentials</title>
      <link>https://threatpost.com/telegram-steal-crypto-wallet-credentials/177266/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://threatpost.com/telegram-steal-crypto-wallet-credentials/177266/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2018/03/20144222/Telegram_Messagees.jpg" width="800" height="573">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2018/03/20144222/Telegram_Messagees.jpg" width="800" height="573">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2018/03/20144222/Telegram_Messagees-300x215.jpg" width="300" height="215">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2018/03/20144222/Telegram_Messagees-150x150.jpg" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>Attackers use the Telegram handle “Smokes Night” to spread the malicious Echelon infostealer, which steals credentials for cryptocurrency and other user accounts, researchers said.</description>
      <category>Cloud Security</category>
      <category>Malware</category>
      <category>Web Security</category>
      <pubDate>Thu, 23 Dec 2021 16:00:22 GMT</pubDate>
      <comments>https://threatpost.com/telegram-steal-crypto-wallet-credentials/177266/#respond</comments>
      <guid isPermaLink="false">https://kasperskycontenthub.com/threatpost-global/?p=177266</guid>
      <dc:creator>Elizabeth Montalbano</dc:creator>
      <dc:date>2021-12-23T16:00:22Z</dc:date>
    </item>
    <item>
      <title>‘Spider-Man: No Way Home’ Download Installs Cryptominer</title>
      <link>https://threatpost.com/spider-man-no-way-home-download-installs-cryptominer/177254/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://threatpost.com/spider-man-no-way-home-download-installs-cryptominer/177254/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22155445/spiderman.jpeg" width="800" height="600">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22155445/spiderman.jpeg" width="800" height="600">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22155445/spiderman-300x225.jpeg" width="300" height="225">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22155445/spiderman-150x150.jpeg" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>The origin of the Monero cryptominer file has been traced to a Russian torrent website, researchers report.</description>
      <category>Malware</category>
      <category>Web Security</category>
      <pubDate>Thu, 23 Dec 2021 15:00:19 GMT</pubDate>
      <comments>https://threatpost.com/spider-man-no-way-home-download-installs-cryptominer/177254/#respond</comments>
      <guid isPermaLink="false">https://kasperskycontenthub.com/threatpost-global/?p=177254</guid>
      <dc:creator>Becky Bracken</dc:creator>
      <dc:date>2021-12-23T15:00:19Z</dc:date>
    </item>
    <item>
      <title>The Future of Work Has Changed, and Your Security Mindset Needs to Follow</title>
      <link>https://www.darkreading.com/attacks-breaches/the-future-of-work-has-changed-and-your-security-mindset-needs-to-follow</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltaea7b1362d54590d/61bcbfe608607828b067c944/RemoteWork_denisismagilov_Adobe.jpeg" type="image/*" />
      <description>VPNs have become a vulnerability that puts organizations at risk of cyberattacks.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt93c26833128fb84f/61bcbd978445252e5ba42236/Mark-Guntrip-1.jpg" type="image/*" />
      <pubDate>Thu, 23 Dec 2021 15:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/attacks-breaches/the-future-of-work-has-changed-and-your-security-mindset-needs-to-follow</guid>
      <dc:creator>Mark Guntrip, Senior Director, Cybersecurity Strategy, Menlo Security</dc:creator>
      <dc:date>2021-12-23T15:00:00Z</dc:date>
    </item>
    <item>
      <title>7 of the Most Impactful Cybersecurity Incidents of 2021</title>
      <link>https://www.darkreading.com/attacks-breaches/6-of-the-most-impactful-cybersecurity-incidents-of-2021</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt4bddad5870a21606/61b1908e49813175aa360f05/cyberattack_Anucha_Cheechang_shutterstock.jpg" type="image/*" />
      <description>There was a lot to learn from breaches, vulnerabilities, and attacks this year.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt02d79fb9a44a4258/60b1e9dd2a25046b35110696/Jai-Vijayan.jpeg" type="image/*" />
      <pubDate>Thu, 23 Dec 2021 14:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/attacks-breaches/6-of-the-most-impactful-cybersecurity-incidents-of-2021</guid>
      <dc:creator>Jai Vijayan, Contributing Writer</dc:creator>
      <dc:date>2021-12-23T14:00:00Z</dc:date>
    </item>
    <item>
      <title>Examining Log4j Vulnerabilities in Connected Cars and Charging Stations</title>
      <link>https://www.trendmicro.com/en_us/research/21/l/examining-log4j-vulnerabilities-in-connected-cars.html</link>
      <description>In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/l/examining-log4j-vulnerabilities-in-connected-cars-and-charging-stations/examining-log4j-vulnerabilities-in-connected-cars.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Exploits &amp; Vulnerabilities</category>
      <category>Trend Micro Research : Research</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <category>Trend Micro Research : Connected Car</category>
      <pubDate>Thu, 23 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:31a6c0dc-6bed-78f9-9d5e-3ad92984ab02</guid>
      <dc:creator>Sébastien Dudek</dc:creator>
      <dc:date>2021-12-23T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Microsoft Customer Source Code Exposed via Azure App Service Bug</title>
      <link>https://www.darkreading.com/threat-intelligence/microsoft-customer-source-code-exposed-via-azure-app-service-bug</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt4673f9433c8a87c7/61c3a0248c873b37a7c6f880/Vulnerabilities_UrbanImages_Alamy.jpg" type="image/*" />
      <description>Researchers found an insecure default behavior in Azure App Service exposing source code of some customer applications deployed using "Local Git."</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt1d62bf1a6a54fdcf/60b1e9ed2d381b69fb11e95e/Sheridan-IWK-125x125.jpg" type="image/*" />
      <pubDate>Wed, 22 Dec 2021 22:05:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/threat-intelligence/microsoft-customer-source-code-exposed-via-azure-app-service-bug</guid>
      <dc:creator>Kelly Sheridan, Senior Editor</dc:creator>
      <dc:date>2021-12-22T22:05:00Z</dc:date>
    </item>
    <item>
      <title>Nearly 50% of People Will Abandon Sites Prohibiting Password Reuse</title>
      <link>https://www.darkreading.com/risk/nearly-50-of-people-will-abandon-sites-prohibiting-password-reuse</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt15ac5bd774737695/61c378ce461bc127f013464d/BeyondIdentitySurveyCharts.jpeg" type="image/*" />
      <description>A new study investigating consumer password use found 25% of online shoppers would abandon their carts of $100 if prompted to reset a password at checkout.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltb160afebfecfaa41/60b1e9ac52bd6156414f3432/SteveZCloseUp.jpeg" type="image/*" />
      <pubDate>Wed, 22 Dec 2021 21:26:44 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/risk/nearly-50-of-people-will-abandon-sites-prohibiting-password-reuse</guid>
      <dc:creator>Steve Zurier, Contributing Writer</dc:creator>
      <dc:date>2021-12-22T21:26:44Z</dc:date>
    </item>
    <item>
      <title>CISA's New Log4j Scanner Aims to Find Vulnerable Apps</title>
      <link>https://www.darkreading.com/vulnerabilities-threats/cisa-s-new-log4j-scanner-aims-to-find-vulnerable-apps</link>
      <description>The open-sourced scanner was derived from scanners built by members across the open source community, CISA reports.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte161b23f0fd3a84b/60b1ea374e7eb868c4c6a293/dr_staff_125x125.jpg" type="image/*" />
      <pubDate>Wed, 22 Dec 2021 20:40:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/vulnerabilities-threats/cisa-s-new-log4j-scanner-aims-to-find-vulnerable-apps</guid>
      <dc:creator>Dark Reading Staff, Dark Reading</dc:creator>
      <dc:date>2021-12-22T20:40:00Z</dc:date>
    </item>
    <item>
      <title>Plundered bitcoins recovered by FBI – all 3,879-and-one-sixth of them!</title>
      <link>https://nakedsecurity.sophos.com/2021/12/22/plundered-bitcoins-recovered-by-fbi-all-3879-and-one-sixth-of-them/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://nakedsecurity.sophos.com/2021/12/22/plundered-bitcoins-recovered-by-fbi-all-3879-and-one-sixth-of-them/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">13</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/doj-1200.jpg?w=230&amp;h=130&amp;crop=1" medium="image" />
      <post-id xmlns="com-wordpress:feed-additions:1">647638</post-id>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/doj-1200.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/doj-1200.jpg?w=170&amp;h=90&amp;crop=1" medium="image" />
      <description>Phew! An audacious crime... that didn't work out.</description>
      <category>Cryptocurrency</category>
      <category>Law &amp; order</category>
      <category>bitcoin</category>
      <category>cyberheist</category>
      <category>doj</category>
      <category>Japan</category>
      <pubDate>Wed, 22 Dec 2021 19:57:02 GMT</pubDate>
      <comments>https://nakedsecurity.sophos.com/2021/12/22/plundered-bitcoins-recovered-by-fbi-all-3879-and-one-sixth-of-them/#comments</comments>
      <guid isPermaLink="false">https://nakedsecurity.sophos.com/?p=647638</guid>
      <dc:creator>Paul Ducklin</dc:creator>
      <dc:date>2021-12-22T19:57:02Z</dc:date>
    </item>
    <item>
      <title>PYSA Emerges as Top Ransomware Actor in November</title>
      <link>https://threatpost.com/pysa-top-ransomware-november/177242/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://threatpost.com/pysa-top-ransomware-november/177242/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22133338/ransomware-victory-e1640198030440.jpg" width="800" height="457">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22133338/ransomware-victory-e1640198030440.jpg" width="800" height="457">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22133338/ransomware-victory-300x171.jpg" width="300" height="171">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22133338/ransomware-victory-150x150.jpg" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>Overtaking the Conti ransomware gang, PYSA finds success with government-sector attacks.</description>
      <category>Malware</category>
      <category>Most Recent ThreatLists</category>
      <pubDate>Wed, 22 Dec 2021 18:39:08 GMT</pubDate>
      <comments>https://threatpost.com/pysa-top-ransomware-november/177242/#respond</comments>
      <guid isPermaLink="false">https://kasperskycontenthub.com/threatpost-global/?p=177242</guid>
      <dc:creator>Becky Bracken</dc:creator>
      <dc:date>2021-12-22T18:39:08Z</dc:date>
    </item>
    <item>
      <title>All in One SEO Plugin Bug Threatens 3M Websites with Takeovers</title>
      <link>https://threatpost.com/all-in-one-seo-plugin-bug-threatens-3m-wordpress-websites-takeovers/177240/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://threatpost.com/all-in-one-seo-plugin-bug-threatens-3m-wordpress-websites-takeovers/177240/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2019/01/28092447/wordpress_plugin_vuln.jpg" width="800" height="471">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2019/01/28092447/wordpress_plugin_vuln.jpg" width="800" height="471">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2019/01/28092447/wordpress_plugin_vuln-300x177.jpg" width="300" height="177">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2019/01/28092447/wordpress_plugin_vuln-150x150.jpg" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>A critical privilege-escalation vulnerability could lead to backdoors for admin access nesting in web servers.</description>
      <category>Vulnerabilities</category>
      <category>Web Security</category>
      <pubDate>Wed, 22 Dec 2021 18:24:07 GMT</pubDate>
      <comments>https://threatpost.com/all-in-one-seo-plugin-bug-threatens-3m-wordpress-websites-takeovers/177240/#respond</comments>
      <guid isPermaLink="false">https://kasperskycontenthub.com/threatpost-global/?p=177240</guid>
      <dc:creator>Tara Seals</dc:creator>
      <dc:date>2021-12-22T18:24:07Z</dc:date>
    </item>
    <item>
      <title>Log4j Reveals Cybersecurity's Dirty Little Secret</title>
      <link>https://www.darkreading.com/vulnerabilities-threats/log4j-reveals-cybersecurity-s-dirty-little-secret</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt2cce6d87973d2432/61bcb3d878250c28786fe177/GenericCyberscurityImage_Sergey_Nivens_Adobe.jpeg" type="image/*" />
      <description>Once the dust settles on Log4j, many IT teams will brush aside the need for the fundamental, not-exciting need for better asset and application management.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltc6eb834f8bc62834/61bca0599cc6202926f29c2a/Mark_Manglicmot_Headshot.png" type="image/*" />
      <pubDate>Wed, 22 Dec 2021 18:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/vulnerabilities-threats/log4j-reveals-cybersecurity-s-dirty-little-secret</guid>
      <dc:creator>Mark Manglicmot, Vice President of Security Services, Arctic Wolf</dc:creator>
      <dc:date>2021-12-22T18:00:00Z</dc:date>
    </item>
    <item>
      <title>Critical Apache HTTPD Server Bugs Could Lead to RCE, DoS</title>
      <link>https://threatpost.com/apache-httpd-server-bugs-rce-dos/177234/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://threatpost.com/apache-httpd-server-bugs-rce-dos/177234/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22123327/cat-hiding.jpeg" width="799" height="533">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22123327/cat-hiding.jpeg" width="799" height="533">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22123327/cat-hiding-300x200.jpeg" width="300" height="200">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22123327/cat-hiding-150x150.jpeg" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>Don't freak: It's got nothing to do with Log4Shell, except it may be just as far-reaching as Log4j, given HTTPD's tendency to tiptoe into software projects.</description>
      <category>Vulnerabilities</category>
      <category>Web Security</category>
      <pubDate>Wed, 22 Dec 2021 17:59:55 GMT</pubDate>
      <comments>https://threatpost.com/apache-httpd-server-bugs-rce-dos/177234/#respond</comments>
      <guid isPermaLink="false">https://kasperskycontenthub.com/threatpost-global/?p=177234</guid>
      <dc:creator>Lisa Vaas</dc:creator>
      <dc:date>2021-12-22T17:59:55Z</dc:date>
    </item>
    <item>
      <title>Stolen Bitcoins Returned</title>
      <link>https://www.schneier.com/blog/archives/2021/12/stolen-bitcoins-returned.html</link>
      <thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">13</thr:total>
      <description>&lt;p&gt;The US has &lt;a href="https://www.bleepingcomputer.com/news/security/us-returns-154-million-in-bitcoins-stolen-by-sony-employee/"&gt;returned&lt;/a&gt; $154 million in bitcoins stolen by a Sony employee.&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;However, on December 1, following an investigation in collaboration with Japanese law enforcement authorities, the FBI seized the 3879.16242937 BTC in Ishii&amp;#8217;s wallet after obtaining the private key, which made it possible to transfer all the bitcoins to the FBI&amp;#8217;s bitcoin wallet.&lt;/p&gt;&lt;/blockquote&gt;</description>
      <content:encoded>&lt;p&gt;The US has &lt;a href="https://www.bleepingcomputer.com/news/security/us-returns-154-million-in-bitcoins-stolen-by-sony-employee/"&gt;returned&lt;/a&gt; $154 million in bitcoins stolen by a Sony employee.&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;However, on December 1, following an investigation in collaboration with Japanese law enforcement authorities, the FBI seized the 3879.16242937 BTC in Ishii&amp;#8217;s wallet after obtaining the private key, which made it possible to transfer all the bitcoins to the FBI&amp;#8217;s bitcoin wallet.&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <category domain="https://www.schneier.com">Uncategorized</category>
      <category domain="https://www.schneier.com">bitcoin</category>
      <category domain="https://www.schneier.com">cryptocurrency</category>
      <category domain="https://www.schneier.com">cybercrime</category>
      <category domain="https://www.schneier.com">FBI</category>
      <category domain="https://www.schneier.com">law enforcement</category>
      <category domain="https://www.schneier.com">theft</category>
      <pubDate>Wed, 22 Dec 2021 16:20:57 GMT</pubDate>
      <guid isPermaLink="false">https://www.schneier.com/?p=64738</guid>
      <dc:creator>Bruce Schneier</dc:creator>
      <dc:date>2021-12-22T16:20:57Z</dc:date>
    </item>
    <item>
      <title>Why We Need to Consolidate Digital Identity Management Before Zero Trust</title>
      <link>https://www.darkreading.com/edge-articles/why-we-need-to-consolidate-digital-identity-management-before-zero-trust</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt8c5aebd08e764751/61c34514a2f30629e20b986e/Panther_Media_GmbH_Alamy_Stock.jpg" type="image/*" />
      <description>Zero trust may be one of the hottest trends in cybersecurity, but just eliminating trust from networks isn’t enough to prevent successful organizational data breaches, says Wes Wright, CTO of Imprivata.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt4b8af951988e387f/61c1c12cfe11ef3693e0ec28/wes-wright-imprivata.jpg" type="image/*" />
      <pubDate>Wed, 22 Dec 2021 15:30:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/edge-articles/why-we-need-to-consolidate-digital-identity-management-before-zero-trust</guid>
      <dc:creator>Wes Wright, CTO, Imprivata</dc:creator>
      <dc:date>2021-12-22T15:30:00Z</dc:date>
    </item>
    <item>
      <title>Future of Identity-Based Security: All-in-One Platforms or Do-It-Yourself Solutions?</title>
      <link>https://www.darkreading.com/operations/future-of-identity-based-security-all-in-one-platforms-or-do-it-yourself-solutions-</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte8e6917b1bae938e/61ba65b7eafdfb39f6373ed5/Thumbprint_Skorzewiak_Alamy.jpg" type="image/*" />
      <description>The functionality of all-in-one platforms is being deconstructed into a smorgasbord of services that can be used to develop bespoke end-user security procedures for specific work groups, lines of businesses, or customer communities.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt7e868a8a2ceed289/61ba4520b04f6f35f2f3959c/Mark_Settle.jpeg" type="image/*" />
      <pubDate>Wed, 22 Dec 2021 15:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/operations/future-of-identity-based-security-all-in-one-platforms-or-do-it-yourself-solutions-</guid>
      <dc:creator>Mark Settle, Seven-Time CIO</dc:creator>
      <dc:date>2021-12-22T15:00:00Z</dc:date>
    </item>
    <item>
      <title>Four Bugs in Microsoft Teams Left Platform Vulnerable Since March</title>
      <link>https://threatpost.com/microsoft-teams-bugs-vulnerable-march/177225/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://threatpost.com/microsoft-teams-bugs-vulnerable-march/177225/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22085506/microsoft-teams-mobile.jpg" width="800" height="533">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22085506/microsoft-teams-mobile.jpg" width="800" height="533">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22085506/microsoft-teams-mobile-300x200.jpg" width="300" height="200">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22085506/microsoft-teams-mobile-150x150.jpg" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>Attackers exploiting bugs in the “link preview” feature in Microsoft Teams could abuse the flaws to spoof links, leak an Android user’s IP address and launch a DoS attack.</description>
      <category>Vulnerabilities</category>
      <pubDate>Wed, 22 Dec 2021 14:03:05 GMT</pubDate>
      <comments>https://threatpost.com/microsoft-teams-bugs-vulnerable-march/177225/#respond</comments>
      <guid isPermaLink="false">https://kasperskycontenthub.com/threatpost-global/?p=177225</guid>
      <dc:creator>Elizabeth Montalbano</dc:creator>
      <dc:date>2021-12-22T14:03:05Z</dc:date>
    </item>
    <item>
      <title>5 online scam red flags | Kaspersky official blog</title>
      <link>https://www.kaspersky.com/blog/online-scam-red-flags/43212/</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/22062636/online-scam-red-flags-featured.jpg" width="1460" height="960">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/22062636/online-scam-red-flags-featured-1024x673.jpg" width="1024" height="673">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/22062636/online-scam-red-flags-featured-300x197.jpg" width="300" height="197">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/22062636/online-scam-red-flags-featured-150x150.jpg" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>Here’s how to spot an online scam.</description>
      <content:encoded>&lt;p&gt;No one — &lt;a href="https://www.kaspersky.com/blog/tales-from-steam/38691/" target="_blank" rel="noopener"&gt;gamer&lt;/a&gt;, &lt;a href="https://www.kaspersky.com/blog/cryptophishing-in-luno/41538/" target="_blank" rel="noopener"&gt;cryptocurrency investor&lt;/a&gt;, or &lt;a href="https://www.kaspersky.com/blog/amazon-related-phishing-scam/37801/" target="_blank" rel="noopener"&gt;online shopper&lt;/a&gt; — is safe from scammers. But no matter who the victim is or how sophisticated the scheme may be, there is always a way to sniff out fraud before it&amp;#8217;s too late. Today we&amp;#8217;re looking at five common signs of online scams to help you avoid danger.&lt;/p&gt;
&lt;h2&gt;1. Stick or carrot&lt;/h2&gt;
&lt;p&gt;Scammers often play on greed or fear. In the first case, they promise a potential victim the moon and the stars — for example, a &lt;a href="https://www.kaspersky.com/blog/data-leak-compensation-scam/32057/" target="_blank" rel="noopener"&gt;large government payout&lt;/a&gt; or &lt;a href="https://www.kaspersky.com/blog/cryptoscam-in-discord/38661/" target="_blank" rel="noopener"&gt;free cryptocurrency&lt;/a&gt;. The second involves intimidation, such as a &lt;a href="https://www.kaspersky.com/blog/extortion-spam/25070/" target="_blank" rel="noopener"&gt;threat to send a video&lt;/a&gt; of the victim watching porn to all of their contacts or to &lt;a href="https://www.kaspersky.com/blog/spam-extortion-reputation/27362/" target="_blank" rel="noopener"&gt;ruin the reputation of their company&amp;#8217;s website&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In both cases, cybercriminals are trying to short-circuit their victim&amp;#8217;s ability to respond rationally. If, after reading such an e-mail, you feel inclined to do exactly what the sender asks (follow a link, send money, call a number, etc.), that&amp;#8217;s actually a warning sign. Take a deep breath and read the message again. Most likely, you&amp;#8217;ll see it for what it is — a trick.&lt;/p&gt;
&lt;h2&gt;2. Ticking clock&lt;/h2&gt;
&lt;p&gt;If emotionally charged situations can cause people to lose the power of critical thinking, then being in a hurry only heightens the problem. Scammers exploit that as well, for example by setting tight deadlines. If a message says you have only a couple of days, hours, or even minutes to &lt;a href="https://www.kaspersky.com/blog/scam-with-playstation-5-giveaway/39089/" target="_blank" rel="noopener"&gt;claim a prize&lt;/a&gt; or buy &lt;a href="https://www.kaspersky.com/blog/cryptoscam-fake-antminer/39398/" target="_blank" rel="noopener"&gt;sought-after equipment&lt;/a&gt; before it sells out, again, it&amp;#8217;s probably a scam.&lt;/p&gt;
&lt;h2&gt;3. Amateurish design&lt;/h2&gt;
&lt;p&gt;Obvious errors in the message are another red flag. Some may be intentional misspellings or substitution of letters with similar-looking numbers or optical counterparts from other alphabets so as to &lt;a href="https://www.kaspersky.com/blog/how-to-protect-yourself-from-phishing/42317/" target="_blank" rel="noopener"&gt;fool spam filters&lt;/a&gt;. In some cases, the sender might simply be illiterate, which is not uncommon among scammers, as opposed to employees of respectable organizations.&lt;/p&gt;
&lt;p&gt;Whatever the reason for the typos, promises of &amp;#8220;0ne мilIion d0llars&amp;#8221; are a sure sign of danger.&lt;/p&gt;
&lt;input type="hidden" class="category_for_banner" value="kis-trial-banking" /&gt;
&lt;h2&gt;4. Searching the database&lt;/h2&gt;
&lt;p&gt;When a potential victim goes to a fraudulent website from an e-mail or chat message, the scammers usually try to draw them in through a series of simple tasks. They might involve taking a short survey or selecting a number of boxes supposedly containing prizes, for example. Quite often, the victim is shown an animation supposedly indicating a database search (for their prizewinning status, for example) or asked to fill out a form. Sometimes they might be invited to read (fake) reviews or comments from &amp;#8220;past winners.&amp;#8221; More recently, we&amp;#8217;ve seen chats with a bot posing as a lawyer, consultant, or support employee.&lt;/p&gt;
&lt;p&gt;Regardless of the details, the overall purpose is simple and clear: Getting the person to invest a bit of time and effort keeps them on the page, and the more invested they feel, the less likely they are to close the page when it asks for payment, which it certainly will. Feel like a website promising a big payday is playing for time? Probably not a good sign.&lt;/p&gt;
&lt;h2&gt;5. Small fee&lt;/h2&gt;
&lt;p&gt;Another favorite trick after hooking a victim is to &lt;a href="https://www.kaspersky.com/blog/delivery-payment-scam/38281/" target="_blank" rel="noopener"&gt;request a small fee&lt;/a&gt;, a transfer for card verification purposes or payment for registration in some database. Without it, the scammers insist, it will not be possible to receive the promised reward.&lt;/p&gt;
&lt;p&gt;The asked-for amount is usually quite small and insignificant against the prospect of untold riches, and may even come with an assurance of payback at a later date. This fee is the first thing that gets stolen, of course. There will be no prize, only the likelihood of losing even more after sharing credit card details with the scammers.&lt;/p&gt;
&lt;h2&gt;To be continued&lt;/h2&gt;
&lt;p&gt;Cybercriminals are constantly inventing new ways to monetize your trust and weaknesses. Simply by looking for these five red flags, you can avoid falling prey to most scams. We will, of course, continue to keep you posted on how to protect yourself, your data, and your money from intruders.&lt;/p&gt;
&lt;input type="hidden" class="category_for_banner" value="kis-trial-banking" /&gt;</content:encoded>
      <category>Threats</category>
      <category>e-mail</category>
      <category>fraud</category>
      <category>phishing</category>
      <category>scam</category>
      <category>spam</category>
      <category>threats</category>
      <pubDate>Wed, 22 Dec 2021 11:33:58 GMT</pubDate>
      <guid isPermaLink="false">https://www.kaspersky.com/blog/?p=43212</guid>
      <dc:creator>Roman Dedenok</dc:creator>
      <dc:date>2021-12-22T11:33:58Z</dc:date>
    </item>
    <item>
      <title>UK Security Agency Shares 225M Passwords With 'Have I Been Pwned'</title>
      <link>https://www.darkreading.com/threat-intelligence/uk-security-agency-shares-225m-passwords-with-have-i-been-pwned-</link>
      <description>The UK's NCA and NCCU have shared 225 million stolen emails and passwords with HIBP, which tracks stolen credentials.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte161b23f0fd3a84b/60b1ea374e7eb868c4c6a293/dr_staff_125x125.jpg" type="image/*" />
      <pubDate>Tue, 21 Dec 2021 22:25:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/threat-intelligence/uk-security-agency-shares-225m-passwords-with-have-i-been-pwned-</guid>
      <dc:creator>Dark Reading Staff, Dark Reading</dc:creator>
      <dc:date>2021-12-21T22:25:00Z</dc:date>
    </item>
    <item>
      <title>Meta Files Federal Lawsuit Against Phishing Operators</title>
      <link>https://www.darkreading.com/attacks-breaches/meta-files-federal-lawsuit-against-phishing-operators</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt0661495b45006d55/61c247cffe11ef3693e0ec94/meta_Rokas_Tenys_shutterstock.jpg" type="image/*" />
      <description>The Facebook parent company seeks court's help in identifying the individuals behind some 39,000 websites impersonating its brands to collect login credentials.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt02d79fb9a44a4258/60b1e9dd2a25046b35110696/Jai-Vijayan.jpeg" type="image/*" />
      <pubDate>Tue, 21 Dec 2021 22:09:03 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/attacks-breaches/meta-files-federal-lawsuit-against-phishing-operators</guid>
      <dc:creator>Jai Vijayan, Contributing Writer</dc:creator>
      <dc:date>2021-12-21T22:09:03Z</dc:date>
    </item>
    <item>
      <title>Time to Ditch Big-Brother Accounts for Network Scanning</title>
      <link>https://threatpost.com/domain-admin-accounts-scan-network/177194/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://threatpost.com/domain-admin-accounts-scan-network/177194/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22135631/big-brother-e1640199459771.jpg" width="800" height="450">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22135631/big-brother-1024x576.jpg" width="1024" height="576">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22135631/big-brother-300x169.jpg" width="300" height="169">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/22135631/big-brother-150x150.jpg" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>Yaron Kassner, CTO and co-founder of Silverfort, discusses why using all-seeing privileged accounts for monitoring is bad practice.</description>
      <category>InfoSec Insider</category>
      <category>Vulnerabilities</category>
      <category>Web Security</category>
      <pubDate>Tue, 21 Dec 2021 22:08:01 GMT</pubDate>
      <comments>https://threatpost.com/domain-admin-accounts-scan-network/177194/#respond</comments>
      <guid isPermaLink="false">https://kasperskycontenthub.com/threatpost-global/?p=177194</guid>
      <dc:creator>Yaron Kassner</dc:creator>
      <dc:date>2021-12-21T22:08:01Z</dc:date>
    </item>
    <item>
      <title>Java Code Repository Riddled with Hidden Log4j Bugs; Here’s Where to Look</title>
      <link>https://threatpost.com/java-supply-chain-log4j-bug/177211/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://threatpost.com/java-supply-chain-log4j-bug/177211/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">2</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/21151757/Logs-e1640117899602.png" width="800" height="533">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/21151757/Logs-1024x682.png" width="1024" height="682">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/21151757/Logs-300x200.png" width="300" height="200">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/12/21151757/Logs-150x150.png" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>There are 17,000 unpatched Log4j packages in the Maven Central ecosystem, leaving massive supply-chain risk on the table from Log4Shell exploits.</description>
      <category>Vulnerabilities</category>
      <category>Web Security</category>
      <pubDate>Tue, 21 Dec 2021 20:46:35 GMT</pubDate>
      <comments>https://threatpost.com/java-supply-chain-log4j-bug/177211/#comments</comments>
      <guid isPermaLink="false">https://kasperskycontenthub.com/threatpost-global/?p=177211</guid>
      <dc:creator>Becky Bracken</dc:creator>
      <dc:date>2021-12-21T20:46:35Z</dc:date>
    </item>
    <item>
      <title>93% of Tested Networks Vulnerable to Breach, Pen Testers Find</title>
      <link>https://www.darkreading.com/attacks-breaches/93-of-tested-networks-vulnerable-to-breach-pentesters-find</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt35bc6abaa6e6b8f7/61c2368b39cc4b37aef7061f/PT-attack-diagram-01.jpg" type="image/*" />
      <description>Data from dozens of penetration tests and security assessments suggest nearly every organization can be infiltrated by cyberattackers.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt58481326324d6911/60b1e9a55d34de550780a990/Robert-Lemos.png" type="image/*" />
      <pubDate>Tue, 21 Dec 2021 20:13:48 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/attacks-breaches/93-of-tested-networks-vulnerable-to-breach-pentesters-find</guid>
      <dc:creator>Robert Lemos, Contributing Writer</dc:creator>
      <dc:date>2021-12-21T20:13:48Z</dc:date>
    </item>
    <item>
      <title>Half-Billion Compromised Credentials Lurking on Open Cloud Server</title>
      <link>https://threatpost.com/half-billion-compromised-credentials-cloud-server/177202/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://threatpost.com/half-billion-compromised-credentials-cloud-server/177202/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/09/30082831/Password-Username.jpg" width="1000" height="667">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/09/30082831/Password-Username.jpg" width="1000" height="667">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/09/30082831/Password-Username-300x200.jpg" width="300" height="200">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.threatpost.com/wp-content/uploads/sites/103/2021/09/30082831/Password-Username-150x150.jpg" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>A quarter-billion of those passwords were not seen in previous breaches that have been added to Have I Been Pwned.</description>
      <category>Breach</category>
      <category>Web Security</category>
      <pubDate>Tue, 21 Dec 2021 20:08:42 GMT</pubDate>
      <comments>https://threatpost.com/half-billion-compromised-credentials-cloud-server/177202/#respond</comments>
      <guid isPermaLink="false">https://kasperskycontenthub.com/threatpost-global/?p=177202</guid>
      <dc:creator>Tara Seals</dc:creator>
      <dc:date>2021-12-21T20:08:42Z</dc:date>
    </item>
    <item>
      <title>Apache’s other product: Critical bugs in ‘httpd’ web server, patch now!</title>
      <link>https://nakedsecurity.sophos.com/2021/12/21/apaches-other-product-critical-bugs-in-httpd-web-server-patch-now/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://nakedsecurity.sophos.com/2021/12/21/apaches-other-product-critical-bugs-in-httpd-web-server-patch-now/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">10</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/ap-1200.jpg?w=230&amp;h=130&amp;crop=1" medium="image" />
      <post-id xmlns="com-wordpress:feed-additions:1">647613</post-id>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/ap-1200.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/ap-1200.jpg?w=170&amp;h=90&amp;crop=1" medium="image" />
      <description>The Apache web server just got an update - this one is nothing to do with Log4j!</description>
      <category>Vulnerability</category>
      <category>Apache</category>
      <category>CVE-2021-44224</category>
      <category>CVE-2021-44790</category>
      <category>httpd</category>
      <category>web server</category>
      <pubDate>Tue, 21 Dec 2021 19:57:39 GMT</pubDate>
      <comments>https://nakedsecurity.sophos.com/2021/12/21/apaches-other-product-critical-bugs-in-httpd-web-server-patch-now/#comments</comments>
      <guid isPermaLink="false">https://nakedsecurity.sophos.com/?p=647613</guid>
      <dc:creator>Paul Ducklin</dc:creator>
      <dc:date>2021-12-21T19:57:39Z</dc:date>
    </item>
    <item>
      <title>How Modern Log Management Strengthens Enterprises’ Security Posture</title>
      <link>https://www.darkreading.com/crowdstrike/how-modern-log-management-strengthens-enterprise-security-posture</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt8a7790bcff9f77cc/61bb798c4b727d376d0c48a2/logs-DmytroOlegovichZakharchuk-Alamy.jpg" type="image/*" />
      <description>If security teams are not logging everything, they are increasing security risk and making it more difficult to investigate and recover from a data breach. Modern log management goes beyond just a SIEM.</description>
      <pubDate>Tue, 21 Dec 2021 19:42:28 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/crowdstrike/how-modern-log-management-strengthens-enterprise-security-posture</guid>
      <dc:creator>Simon Simonsen, Sr. Security Architect, CrowdStrike</dc:creator>
      <dc:date>2021-12-21T19:42:28Z</dc:date>
    </item>
    <item>
      <title>Preemptive Strategies to Stop Log4j and Its Variants</title>
      <link>https://www.darkreading.com/vulnerabilities-threats/preemptive-strategies-to-stop-log4j-and-its-variants</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blta47d93a18ed6e99b/61bbb9a7a2f30629e20b9470/Security_vska_Alamy.jpg" type="image/*" />
      <description>Zero trust is key to not falling victim to the next big vulnerability.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt3b296baaaaccbc2a/61bbb7b4ac124d4b2e71583a/WriterDefault_vladwel_Adobe.jpg" type="image/*" />
      <pubDate>Tue, 21 Dec 2021 18:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/vulnerabilities-threats/preemptive-strategies-to-stop-log4j-and-its-variants</guid>
      <dc:creator>Oded Gonda, VP of Technology &amp; Innovation, Check Point Software Technologies</dc:creator>
      <dc:date>2021-12-21T18:00:00Z</dc:date>
    </item>
    <item>
      <title>What’s new with Matrix security in Resurrections | Kaspersky official blog</title>
      <link>https://www.kaspersky.com/blog/matrix-resurrections-state-of-cybersecurity/43209/</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/21112152/matrix-resurrections-state-of-cybersecurity-featured.jpg" width="1460" height="960">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/21112152/matrix-resurrections-state-of-cybersecurity-featured-1024x673.jpg" width="1024" height="673">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/21112152/matrix-resurrections-state-of-cybersecurity-featured-300x197.jpg" width="300" height="197">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/21112152/matrix-resurrections-state-of-cybersecurity-featured-150x150.jpg" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>How Matrix security has changed in the latest installment, The Matrix Resurrections.</description>
      <content:encoded>&lt;p&gt;In December 2021, the creators of the Matrix rolled out a massive update, &lt;em&gt;The Matrix Resurrections&lt;/em&gt;, perhaps to address &lt;a href="https://www.kaspersky.com/blog/matrix-vulnerabilities/43168/" target="_blank" rel="noopener"&gt;the dire state of security in the system&lt;/a&gt;. As often happens with system bug fixes, the update resolves some but not all issues — and adds some new ones in the process.&lt;/p&gt;
&lt;p&gt;What&amp;#8217;s changed in the Matrix in the 18 years since the last update? Today, we&amp;#8217;re evaluating the latest installment from a cybersecurity perspective. As usual, spoiler alert!&lt;/p&gt;
&lt;h2&gt;Fighting pirate avatars&lt;/h2&gt;
&lt;p&gt;As before, external hackers have infiltrated the Matrix. In the original trilogy, whether the system was serious about fighting the Zion Resistance or just pretending to be was never entirely clear (and the Matrix is hardly the only &lt;a href="https://www.kaspersky.com/blog/dune-information-security/41622/" target="_blank" rel="noopener"&gt;fictional universe that&amp;#8217;s convoluted&lt;/a&gt;). The new movie creates the impression that the Matrix programs genuinely do not want outsiders in their system, that countermeasures are in full force but simply not effective enough.&lt;/p&gt;
&lt;h3&gt;Pirate signal from hacker ships&lt;/h3&gt;
&lt;p&gt;Hacker ships continue to transmit pirate signals to the Matrix, as they did before in &amp;#8220;real reality.&amp;#8221; No firewall was ever implemented at the entrance to the Matrix, though that would have been logical. Using a &lt;a href="https://www.kaspersky.com/blog/zero-trust-security/36423/" target="_blank" rel="noopener"&gt;Zero Trust&lt;/a&gt; approach from the start would have prevented a lot of hassle.&lt;br /&gt;
&lt;strong&gt;Status: &lt;/strong&gt;Unsolved&lt;/p&gt;
&lt;h3&gt;Pirate avatar transfer system&lt;/h3&gt;
&lt;p&gt;Either the Matrix defeated the system that broadcast pirate avatars through simulated telephone landlines and the hackers had to invent something new, or the hackers improved their methods and abandoned wire telephony. Either way, the system is different now: The new breed of rebel uses a complex system of dynamic redirects. In other words, the rebels can now turn doors and mirrors into portals both for quickly transporting pirate avatars from place to place and for logging in to the system. That&amp;#8217;s very similar to the work of the Keymaker in the second movie — perhaps the hackers managed to replicate (or borrow) part of his code.&lt;br /&gt;
&lt;strong&gt;Status: &lt;/strong&gt;Worse than before&lt;/p&gt;
&lt;p&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/p&gt;
&lt;h3&gt;Pirate avatar tracking system&lt;/h3&gt;
&lt;p&gt;The Matrix has become far more responsive to outside avatars&amp;#8217; actions. Countermeasures are now applied (and much more quickly) in almost every case of rebel infiltration — perhaps the creators of the Matrix followed our &lt;a href="https://www.kaspersky.com/blog/matrix-vulnerabilities/43168/" target="_blank" rel="noopener"&gt;recommendations for the original trilogy&lt;/a&gt; and finally implemented &lt;a href="https://www.kaspersky.com/enterprise-security/endpoint-detection-response-edr?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______" target="_blank"&gt;EDR&lt;/a&gt;. Moreover, hackers are now forced to obfuscate their tracks constantly, for example by opening portals in a moving train to keep their activity hidden from the agents for longer.&lt;br /&gt;
&lt;strong&gt;Status:&lt;/strong&gt; Greatly improved&lt;/p&gt;
&lt;h3&gt;Matrix agents&lt;/h3&gt;
&lt;p&gt;The Matrix has abandoned its unique and probably resource-intensive agents. They remain as code, but they exist exclusively within a looped, double-virtual simulation. The Matrix, you see, has learned to switch the avatar of any connected human to bot mode, acting for the system. Visually, the difference is that, whereas an Agent previously replaced a person&amp;#8217;s avatar, now the avatar outwardly remains the same but is taken over by the AI.&lt;/p&gt;
&lt;p&gt;By comparison with agents, bots act more primitively, but they can operate in swarm mode, synchronously and (subjectively) more efficiently. Physical laws still govern the bots&amp;#8217; behavior, however, and the result is essentially the same. Hackers can still get the job done; they just have to work a little harder for it.&lt;br /&gt;
&lt;strong&gt;Status:&lt;/strong&gt; Different, not better&lt;/p&gt;
&lt;h2&gt;Rogue programs&lt;/h2&gt;
&lt;p&gt;The Matrix used to be full of unnecessary programs that had no useful system functions. Along with the update, the AI purged obsolete software throughout the system, destroying the vast majority of rogue programs — not all, of course, but precious few remain. Some have emigrated to the physical world (we won&amp;#8217;t say how; that would be one spoiler too many). In any event, getting rid of outdated software is the right move.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status: &lt;/strong&gt;Greatly improved&lt;/p&gt;
&lt;h2&gt;Network segmentation&lt;/h2&gt;
&lt;p&gt;The Matrix&amp;#8217;s attitude toward isolating subnets remains poor. From the outside, the rebels manage to break in —not only to the Matrix, but also to a simulation of the Matrix, deployed inside on double-virtual servers. In other words, the simulation is on the same thoroughfare, so to speak; once inside the network, an intruder can go anywhere — say, accounts or R&amp;#38;D. In short, the implementation is very sloppy, especially given the absence of an entrance firewall or Zero Trust system.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; About the same&lt;/p&gt;
&lt;h2&gt;Anomaly control system&lt;/h2&gt;
&lt;p&gt;The original trilogy&amp;#8217;s system for controlling anomalies in the code (by means of the One) no longer works. Instead, we have a new system, in which the One and Zion no longer go through cycles of recreation; rather, the Matrix tries to manipulate the reconnected Neo through Trinity and colleagues.&lt;/p&gt;
&lt;p&gt;The result is even more deplorable than before. Instead of one human with some avatar code anomalies, they get two — and that might not be all.&lt;br /&gt;
&lt;strong&gt;Status:&lt;/strong&gt; Much worse&lt;/p&gt;
&lt;h2&gt;The problem of ex-Agent Smith&lt;/h2&gt;
&lt;p&gt;The Matrix did not destroy the code of former Agent Smith, but instead took control of it and tried to implement it in a complex new anomaly control system. The AI is likely interested in that part of the code that retains elements of Neo&amp;#8217;s code.&lt;/p&gt;
&lt;p&gt;The part responsible for uncontrolled replication seems to have been deleted. However, by the end of the movie, Smith frees himself (as usual, thanks to Neo&amp;#8217;s intervention), and he remains in the Matrix. What&amp;#8217;s more, he can now jump from avatar to avatar, an ability the Matrix can&amp;#8217;t control. In other words, if before Smith was a rather stupid virus, it has now morphed into a full-fledged &lt;a href="https://encyclopedia.kaspersky.com/glossary/apt-advanced-persistent-threats/" target="_blank" rel="noopener"&gt;APT&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Much worse&lt;/p&gt;
&lt;h2&gt;New problems&lt;/h2&gt;
&lt;p&gt;The balance of power has changed significantly. First, Zion was not destroyed at the end of the original trilogy, which greatly strengthens humanity. Second, following a split on the machine side, some AI carriers — both intelligent machines and purely software-based personalities — are now on humanity&amp;#8217;s side. The result is several fundamentally new issues.&lt;/p&gt;
&lt;h3&gt;Data leaks&lt;/h3&gt;
&lt;p&gt;The AI carriers absconded with a fair amount of information, some of which is sensitive. The humans now know a lot more about the architecture of the Matrix and various critical systems.&lt;/p&gt;
&lt;h3&gt;Critical infrastructure security&lt;/h3&gt;
&lt;p&gt;The hackers are far more active in the &amp;#8220;real reality&amp;#8221; and now periodically attack critical infrastructure at the physical level. Moreover, the renegade machines actively help humanity hack into other machines at the hardware level, for example, by breaking into the harvester control system and other protected objects. As a result, the Zion rebels can continue stealing the bodies of humans connected to the Matrix.&lt;/p&gt;
&lt;h2&gt;General takeaways&lt;/h2&gt;
&lt;p&gt;To sum up, the Matrix update has worsened the overall security of the machines, not improved it. If the AI had not turned enslaved humans into batteries, perhaps people could have helped out with an &lt;a href="https://www.kaspersky.com/enterprise-security/cybersecurity-services?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______" target="_blank"&gt;independent vulnerability analysis&lt;/a&gt; — well worth the effort before rolling out a massive update.&lt;/p&gt;
&lt;input type="hidden" class="category_for_banner" value="kesb-top3" /&gt;</content:encoded>
      <category>Business</category>
      <category>Enterprise</category>
      <category>movies</category>
      <category>The Matrix</category>
      <category>truth</category>
      <category>vulnerabilities</category>
      <pubDate>Tue, 21 Dec 2021 16:33:41 GMT</pubDate>
      <guid isPermaLink="false">https://www.kaspersky.com/blog/?p=43209</guid>
      <dc:creator>Nikolay Pankov</dc:creator>
      <dc:date>2021-12-21T16:33:41Z</dc:date>
    </item>
    <item>
      <title>The Future of Ransomware</title>
      <link>https://www.darkreading.com/vulnerabilities-threats/the-future-of-ransomware</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt64d1efdd7c06531f/61b8f6924b727d376d0c4740/Ransomware_the_lightwriter_Alamy.jpg" type="image/*" />
      <description>Focusing on basic security controls and executing them well is the best way to harden your systems against an attack.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt90d956b6f7945d16/61b10a75d51ea15f09fcd45f/Dave_Meltzer_Headshot_-_CTO_Tripwire_November_2021.jpg" type="image/*" />
      <pubDate>Tue, 21 Dec 2021 15:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/vulnerabilities-threats/the-future-of-ransomware</guid>
      <dc:creator>Dave Meltzer, Chief Technology Officer, Tripwire</dc:creator>
      <dc:date>2021-12-21T15:00:00Z</dc:date>
    </item>
    <item>
      <title>UK hands over 585 million compromised passwords to 'Have I been pwned' service</title>
      <link>https://www.computing.co.uk/news/4042359/uk-hands-585-million-compromised-passwords-pwned-service</link>
      <description>&lt;img alt="UK hands over 585 million compromised passwords to &amp;#39;Have I been pwned&amp;#39; service" src="https://www.computing.co.uk/api/v1/wps/e45f963/26e6c89d-ad05-49a2-aa74-435a75b470ea/7/password-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Of those, 225 million are new passwords that were not part of the database previously &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 21 Dec 2021 12:41:41 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4042359/uk-hands-585-million-compromised-passwords-pwned-service</guid>
      <dc:date>2021-12-21T12:41:41Z</dc:date>
    </item>
    <item>
      <title>Facebook's internal messages reveal plans to ignore European privacy laws</title>
      <link>https://www.computing.co.uk/news/4042363/facebook-internal-messages-reveal-plans-ignore-european-privacy-laws</link>
      <description>&lt;img alt="Facebook&amp;#39;s internal messages reveal plans to ignore European privacy laws" src="https://www.computing.co.uk/api/v1/wps/05eceab/dbf274d3-832f-4d48-8ffa-7aaa9b094d09/4/smartphone-privacy-iStock-495514569-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt;  &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 21 Dec 2021 12:30:44 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4042363/facebook-internal-messages-reveal-plans-ignore-european-privacy-laws</guid>
      <dc:date>2021-12-21T12:30:44Z</dc:date>
    </item>
    <item>
      <title>How Is Zero Trust Evolving to Be More Continuous in Verifying Trust?</title>
      <link>https://www.darkreading.com/edge-ask-the-experts/how-is-zero-trust-evolving-to-be-more-continuous-in-verifying-trust-</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltf4299ff8d63bb97a/615b47a1bc00fe7cca71887f/ZeroTrust.jpg" type="image/*" />
      <description>For zero trust to be successful, organizations need to be able to check user identity, device posture, and overall behavior without adding friction to the experience.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltf5dd7a87fc3227b1/6177f6289d64530fa03720ba/Ash_Headshot.png" type="image/*" />
      <pubDate>Tue, 21 Dec 2021 11:33:29 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/edge-ask-the-experts/how-is-zero-trust-evolving-to-be-more-continuous-in-verifying-trust-</guid>
      <dc:creator>Ash Devata, General Manager, Cisco Zero Trust and Duo Security</dc:creator>
      <dc:date>2021-12-21T11:33:29Z</dc:date>
    </item>
    <item>
      <title>Belgian defence ministry suffers cyber attack through Log4j exploitation</title>
      <link>https://www.computing.co.uk/news/4042336/belgian-defence-ministry-suffers-cyber-attack-log4j-exploitation</link>
      <description>&lt;img alt="Belgian defence ministry suffers cyber attack through Log4j exploitation" src="https://www.computing.co.uk/api/v1/wps/1629be0/16f2185d-f169-472c-bdac-e6c9e8f29c92/7/defence-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Multiple threat groups are currently leveraging Log4j bugs in their operations &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 21 Dec 2021 08:05:38 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4042336/belgian-defence-ministry-suffers-cyber-attack-log4j-exploitation</guid>
      <dc:date>2021-12-21T08:05:38Z</dc:date>
    </item>
    <item>
      <title>How to detect Apache HTTP Server Exploitation</title>
      <link>https://www.trendmicro.com/en_us/devops/21/l/how-to-detect-apache-http-server-exploitation.html</link>
      <description>With recent news of the critical, zero-day vulnerability Apache Log4Shell, we explore how to detect and protect your Apache HTTP servers.</description>
      <source url="https://www.trendmicro.com/en_us/devops.html">DevOps Resource Center</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/devops/21/l/how-to-detect-apache-http-server-exploitation/log4j-devops.png" type="image/png" />
      <category>Trend Micro DevOps : Workload Security</category>
      <category>Trend Micro DevOps : How To</category>
      <category>Trend Micro DevOps : Network Security</category>
      <category>Trend Micro DevOps : Article</category>
      <category>Trend Micro DevOps : Multi Cloud</category>
      <pubDate>Tue, 21 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:f99e016c-5983-10d9-a7a2-daa951404975</guid>
      <dc:creator>Nitesh Surana</dc:creator>
      <dc:date>2021-12-21T00:00:00Z</dc:date>
    </item>
    <item>
      <title>What to Do About Log4j</title>
      <link>https://www.trendmicro.com/en_us/research/21/l/log4j.html</link>
      <description>Learn more about some tactical measures people are already taking, and some strategic guidance for what to do after the immediate crisis abates.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/l/what-to-do-about-log4j/log4j-rnp.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Cyber Crime</category>
      <category>Trend Micro Research : Expert Perspective</category>
      <category>Trend Micro Research : Exploits &amp; Vulnerabilities</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <category>Trend Micro Research : Cyber Threats</category>
      <pubDate>Tue, 21 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:74a691df-fc0c-8a3d-0af7-8cd058dd2fb1</guid>
      <dc:creator>William Malik</dc:creator>
      <dc:date>2021-12-21T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Russian National Extradited for Illegal Hacking &amp; Trading</title>
      <link>https://www.darkreading.com/threat-intelligence/russian-national-extradited-for-illegal-hacking-trading</link>
      <description>Vladislav Klyushin was allegedly involved in a global operation to trade on nonpublic data stolen from US computer networks.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte161b23f0fd3a84b/60b1ea374e7eb868c4c6a293/dr_staff_125x125.jpg" type="image/*" />
      <pubDate>Mon, 20 Dec 2021 22:55:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/threat-intelligence/russian-national-extradited-for-illegal-hacking-trading</guid>
      <dc:creator>Dark Reading Staff, Dark Reading</dc:creator>
      <dc:date>2021-12-20T22:55:00Z</dc:date>
    </item>
    <item>
      <title>New Log4j Attack Vector Discovered</title>
      <link>https://www.darkreading.com/application-security/researchers-uncover-new-attack-vector-for-log4j-flaw</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt2f6258d8e8d5b4cd/61c106262bcbbe367315eb53/day_10_infographic.png" type="image/*" />
      <description>Meanwhile, Apache Foundation releases third update to logging tool in 10 days to address yet another flaw.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt02d79fb9a44a4258/60b1e9dd2a25046b35110696/Jai-Vijayan.jpeg" type="image/*" />
      <pubDate>Mon, 20 Dec 2021 22:53:50 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/application-security/researchers-uncover-new-attack-vector-for-log4j-flaw</guid>
      <dc:creator>Jai Vijayan, Contributing Writer</dc:creator>
      <dc:date>2021-12-20T22:53:50Z</dc:date>
    </item>
    <item>
      <title>Brillio Acquires Cedrus Digital to Strengthen Their Digital Transformation Service Capabilities</title>
      <link>https://www.darkreading.com/cloud/brillio-acquires-cedrus-digital-to-strengthen-their-digital-transformation-service-capabilities</link>
      <description>The acquisition of Cedrus Digital, with its consulting-led model and over 150 cloud, data and product engineers, primarily in the United States, will further augment Brillio’s nearshore digital transformation capabilities offered for Fortune 500 clients.</description>
      <pubDate>Mon, 20 Dec 2021 20:59:47 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/cloud/brillio-acquires-cedrus-digital-to-strengthen-their-digital-transformation-service-capabilities</guid>
      <dc:date>2021-12-20T20:59:47Z</dc:date>
    </item>
    <item>
      <title>NetSPI Adds IoT Penetration Testing to its Suite of Offensive Security Services</title>
      <link>https://www.darkreading.com/vulnerabilities-threats/netspi-adds-iot-penetration-testing-to-its-suite-of-offensive-security-services</link>
      <description>Led by IoT security expert Larry Trowell, the IoT pen-testing services focus on securing ATMs, automotive, medical devices, operational technology, and other embedded systems.</description>
      <pubDate>Mon, 20 Dec 2021 20:52:42 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/vulnerabilities-threats/netspi-adds-iot-penetration-testing-to-its-suite-of-offensive-security-services</guid>
      <dc:date>2021-12-20T20:52:42Z</dc:date>
    </item>
    <item>
      <title>Log4Shell: The Movie… a short, safe visual tour for work and home</title>
      <link>https://nakedsecurity.sophos.com/2021/12/20/log4shell-the-movie-a-short-safe-visual-tour-for-work-and-home/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://nakedsecurity.sophos.com/2021/12/20/log4shell-the-movie-a-short-safe-visual-tour-for-work-and-home/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">4</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/sysadm.001.png?w=230&amp;h=130&amp;crop=1" medium="image" />
      <post-id xmlns="com-wordpress:feed-additions:1">647586</post-id>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/sysadm.001.png" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/sysadm.001.png?w=170&amp;h=90&amp;crop=1" medium="image" />
      <description>Be happy that your sysadmins are taking one (three, actually!) for the team right now... here's why!</description>
      <category>Video</category>
      <category>CVE-2021-44228</category>
      <category>CVE-2021-45046</category>
      <category>CVE-2021-45105</category>
      <pubDate>Mon, 20 Dec 2021 19:20:19 GMT</pubDate>
      <comments>https://nakedsecurity.sophos.com/2021/12/20/log4shell-the-movie-a-short-safe-visual-tour-for-work-and-home/#comments</comments>
      <guid isPermaLink="false">https://nakedsecurity.sophos.com/?p=647586</guid>
      <dc:creator>Paul Ducklin</dc:creator>
      <dc:date>2021-12-20T19:20:19Z</dc:date>
    </item>
    <item>
      <title>SAIC Launches Rugged Apps to Provide Secure Commercial Apps to Government Users</title>
      <link>https://www.darkreading.com/application-security/saic-launches-rugged-apps-to-provide-secure-commercial-apps-to-government-users</link>
      <description>Rugged Apps ensures mobile apps are NIAP-compliant.</description>
      <pubDate>Mon, 20 Dec 2021 16:40:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/application-security/saic-launches-rugged-apps-to-provide-secure-commercial-apps-to-government-users</guid>
      <dc:date>2021-12-20T16:40:00Z</dc:date>
    </item>
    <item>
      <title>BlackBerry Launches New Managed Extended Detection and Response (XDR) Service</title>
      <link>https://www.darkreading.com/attacks-breaches/blackberry-launches-new-managed-extended-detection-and-response-xdr-service</link>
      <description>Company partners with Exabeam to launch update to its BlackBerry Guard managed detection and response (MDR) service.</description>
      <pubDate>Mon, 20 Dec 2021 16:32:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/attacks-breaches/blackberry-launches-new-managed-extended-detection-and-response-xdr-service</guid>
      <dc:date>2021-12-20T16:32:00Z</dc:date>
    </item>
    <item>
      <title>SecurityScorecard Research Reveals Cyber Vulnerabilities Pose a Threat to U.S. Maritime Security</title>
      <link>https://www.darkreading.com/attacks-breaches/securityscorecard-research-reveals-cyber-vulnerabilities-pose-a-threat-to-u-s-maritime-security</link>
      <description>While the shipping industry's cyber posture was better than companies in the Forbes Global 2000, the industry performed lower in key risk group factors.</description>
      <pubDate>Mon, 20 Dec 2021 16:30:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/attacks-breaches/securityscorecard-research-reveals-cyber-vulnerabilities-pose-a-threat-to-u-s-maritime-security</guid>
      <dc:date>2021-12-20T16:30:00Z</dc:date>
    </item>
    <item>
      <title>Trend Micro Crowns Champions of 2021 Capture the Flag Competition</title>
      <link>https://www.darkreading.com/careers-and-people/trend-micro-crowns-champions-of-2021-capture-the-flag-competition</link>
      <description>Challenges were designed to address critical areas of cybersecurity, including reversing, cloud, IoT, open source intelligence, forensics, and machine learning.</description>
      <pubDate>Mon, 20 Dec 2021 16:28:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/careers-and-people/trend-micro-crowns-champions-of-2021-capture-the-flag-competition</guid>
      <dc:date>2021-12-20T16:28:00Z</dc:date>
    </item>
    <item>
      <title>Reblaze Appoints New CEO</title>
      <link>https://www.darkreading.com/application-security/reblaze-appoints-new-ceo</link>
      <description>Ziv Oren previously held the position of chief operations officer at the company.</description>
      <pubDate>Mon, 20 Dec 2021 16:20:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/application-security/reblaze-appoints-new-ceo</guid>
      <dc:date>2021-12-20T16:20:00Z</dc:date>
    </item>
    <item>
      <title>Four Out of Five Organizations Are Increasing Cybersecurity Budgets for 2022</title>
      <link>https://www.darkreading.com/operations/four-out-of-five-organizations-are-increasing-cybersecurity-budgets-for-2022</link>
      <description>Half of security decision makers also say the cyber skills gap will significantly impact their 2022 strategy, according to new research from Neustar.</description>
      <pubDate>Mon, 20 Dec 2021 16:15:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/operations/four-out-of-five-organizations-are-increasing-cybersecurity-budgets-for-2022</guid>
      <dc:date>2021-12-20T16:15:00Z</dc:date>
    </item>
    <item>
      <title>More on NSO Group and Cytrox: Two Cyberweapons Arms Manufacturers</title>
      <link>https://www.schneier.com/blog/archives/2021/12/more-on-nso-group-and-cytrox-two-cyberweapons-arms-manufacturers.html</link>
      <thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">40</thr:total>
      <description>&lt;p&gt;Citizen Lab published &lt;a href="https://citizenlab.ca/2021/12/pegasus-vs-predator-dissidents-doubly-infected-iphone-reveals-cytrox-mercenary-spyware/"&gt;another report&lt;/a&gt; on the spyware used against two Egyptian nationals. One was hacked by NSO Group&amp;#8217;s Pegasus spyware. The other was hacked both by Pegasus and by the spyware from another cyberweapons arms manufacturer: Cytrox.&lt;/p&gt;
&lt;p&gt;We haven&amp;#8217;t heard a lot about Cytrox and its Predator spyware. According to Citzen Lab:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;We conducted Internet scanning for Predator spyware servers and found likely Predator customers in Armenia, Egypt, Greece, Indonesia, Madagascar, Oman, Saudi Arabia, and Serbia.&lt;/p&gt;
&lt;p&gt;Cytrox was reported to be part of &lt;a href="https://intellexa.com/"&gt;Intellexa...&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;</description>
      <content:encoded>&lt;p&gt;Citizen Lab published &lt;a href="https://citizenlab.ca/2021/12/pegasus-vs-predator-dissidents-doubly-infected-iphone-reveals-cytrox-mercenary-spyware/"&gt;another report&lt;/a&gt; on the spyware used against two Egyptian nationals. One was hacked by NSO Group&amp;#8217;s Pegasus spyware. The other was hacked both by Pegasus and by the spyware from another cyberweapons arms manufacturer: Cytrox.&lt;/p&gt;
&lt;p&gt;We haven&amp;#8217;t heard a lot about Cytrox and its Predator spyware. According to Citzen Lab:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;We conducted Internet scanning for Predator spyware servers and found likely Predator customers in Armenia, Egypt, Greece, Indonesia, Madagascar, Oman, Saudi Arabia, and Serbia.&lt;/p&gt;
&lt;p&gt;Cytrox was reported to be part of &lt;a href="https://intellexa.com/"&gt;Intellexa&lt;/a&gt;, the &lt;a href="https://gizmodo.com/the-lucrative-government-spyware-industry-has-a-new-one-1832568791"&gt;so-called&lt;/a&gt; &amp;#8220;Star Alliance of spyware,&amp;#8221; which was formed to compete with NSO Group, and which describes itself as &amp;#8220;EU-based and regulated, with six sites and R&amp;#038;D labs throughout Europe.&amp;#8221; &lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;In related news, Google&amp;#8217;s Project Zero has &lt;a href="https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html"&gt;published&lt;/a&gt; a detailed analysis of NSO Group&amp;#8217;s zero-click iMessage exploit: FORCED ENTRY.&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;Based on our research and findings, we assess this to be one of the most technically sophisticated exploits we&amp;#8217;ve ever seen, further demonstrating that the capabilities NSO provides rival those previously thought to be accessible to only a handful of nation states. &lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;By the way, this vulnerability was patched on 13 Sep 2021 in iOS 14.8.&lt;/p&gt;</content:encoded>
      <category domain="https://www.schneier.com">Uncategorized</category>
      <category domain="https://www.schneier.com">Citizen Lab</category>
      <category domain="https://www.schneier.com">cyberweapons</category>
      <category domain="https://www.schneier.com">exploits</category>
      <category domain="https://www.schneier.com">spyware</category>
      <pubDate>Mon, 20 Dec 2021 15:17:41 GMT</pubDate>
      <guid isPermaLink="false">https://www.schneier.com/?p=64686</guid>
      <dc:creator>Bruce Schneier</dc:creator>
      <dc:date>2021-12-20T15:17:41Z</dc:date>
    </item>
    <item>
      <title>Zero Trust Shouldn’t Mean Zero Trust in Employees</title>
      <link>https://www.darkreading.com/endpoint/zero-trust-shouldn-t-mean-zero-trust-in-employees</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltf8bbcf769b4c6956/61b7c9e51c97765f0a8d5bcd/Trust_sleepyfellow_Alamy.jpg" type="image/*" />
      <description>Some think zero trust means you cannot or should not trust employees, an approach that misses the mark and sets up everyone for failure.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt71f8513ce6d02222/61b779106cfd9e67c963a4de/Josh-Yavor_CISO_small.png" type="image/*" />
      <pubDate>Mon, 20 Dec 2021 15:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/endpoint/zero-trust-shouldn-t-mean-zero-trust-in-employees</guid>
      <dc:creator>Josh Yavor, CISO, Tessian</dc:creator>
      <dc:date>2021-12-20T15:00:00Z</dc:date>
    </item>
    <item>
      <title>Lights Out: Cyberattacks Shut Down Building Automation Systems</title>
      <link>https://www.darkreading.com/attacks-breaches/lights-out-cyberattacks-shut-down-building-automation-systems</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltfa98b4f9d2303558/61c09a1f7cdfa4273130d633/BAS_FranckBoston_AlamyStockPhoto2.jpeg" type="image/*" />
      <description>Security experts in Germany discover similar attacks that lock building engineering management firms out of the BASes they built and manage — by turning a security feature against them.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltb0e0f8e307c2012b/615dfe95486c9a5b53695aa0/KJH.PNG" type="image/*" />
      <pubDate>Mon, 20 Dec 2021 15:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/attacks-breaches/lights-out-cyberattacks-shut-down-building-automation-systems</guid>
      <dc:creator>Kelly Jackson Higgins, Executive Editor</dc:creator>
      <dc:date>2021-12-20T15:00:00Z</dc:date>
    </item>
    <item>
      <title>How to detect hidden video cameras | Kaspersky official blog</title>
      <link>https://www.kaspersky.com/blog/how-to-find-spy-cameras/43199/</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/20061124/how-to-find-spy-cameras-featured.jpg" width="1460" height="960">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/20061124/how-to-find-spy-cameras-featured-1024x673.jpg" width="1024" height="673">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/20061124/how-to-find-spy-cameras-featured-300x197.jpg" width="300" height="197">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/20061124/how-to-find-spy-cameras-featured-150x150.jpg" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>Four ways to find hidden cams in hotel rooms, rented apartments, and elsewhere.</description>
      <content:encoded>&lt;p&gt;To the average person, directional microphones, hidden cameras, and other surveillance equipment are the stuff of spy movies. Yet such devices can be found everywhere: from small rented apartments to expensive hotel rooms, from the office to the gym, even in your own home. Today, we explore ways to find them.&lt;/p&gt;
&lt;h2&gt;Big Brother&amp;#8217;s little siblings&lt;/h2&gt;
&lt;p&gt;Miniature cameras are inexpensive (at the time of this writing, prices start at about $4), and they connect to regular Wi-Fi to transfer data — say, to the cloud. That means pretty much anyone can play at being a spy in real life. Why would they?&lt;/p&gt;
&lt;p&gt;In some cases, owners of rental apartments install them in case of theft or damage to property. Suspicious spouses and unscrupulous rivals have other reasons. As do pranksters. Then, there are professional extortionists. Simply put, loads of people have loads of excuses.&lt;/p&gt;
&lt;p&gt;How likely are you to encounter surveillance in everyday, private life? A survey of Airbnb users revealed that 11% of respondents had &lt;a href="https://www.pcmag.com/news/most-airbnb-guests-worry-about-hidden-cameras" target="_blank" rel="nofollow noopener"&gt;come across a hidden camera in rented accommodations&lt;/a&gt;. And those are just the ones who found something; not every renter carefully inspects the furnishings. What&amp;#8217;s more, finding such cameras is not always easy. Lenses may be as small as 2 millimeters in diameter, and the box is usually hidden or camouflaged. How are you supposed to know you&amp;#8217;re being spied on?&lt;/p&gt;
&lt;h2&gt;Method 1. Hire an expert&lt;/h2&gt;
&lt;p&gt;The most reliable way to find hidden spy equipment is to entrust the search to a qualified technician with professional equipment. Today, you can find such experts in almost any city; for example, on Craigslist or another website with classified ads.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Pros:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Efficiency&lt;/li&gt;
&lt;li&gt;Reliable results&lt;/li&gt;
&lt;li&gt;Minimal personal effort&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Cons:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Price&lt;/li&gt;
&lt;li&gt;Potential wait time&lt;/li&gt;
&lt;li&gt;Hotel or apartment restrictions&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;If you are worried and plan to stay somewhere for a while, or if you&amp;#8217;re moving in, hiring an expert may be worth the time and money.&lt;/p&gt;
&lt;h2&gt;Method 2. Use dedicated equipment&lt;/h2&gt;
&lt;p&gt;You can buy electromagnetic radiation detectors, optical detectors, and other equipment for detecting hidden cameras and use them to check each room yourself. The cheapest ones, with a detection radius of only a few feet, start at $3; professional and more powerful ones are obviously more expensive.&lt;/p&gt;
&lt;p&gt;Incidentally, the simplest optical detector can be assembled manually; all you need are some red LEDs and a red-light filter. Direct the light at the suspected camera site and look through the filter — any camera lens in view will appear as a bright dot. Bear in mind that the range of such a device will not exceed ten meters (about 30 feet).&lt;/p&gt;
&lt;p&gt;If you decide to check for yourself, pay particular attention to the bathroom and bedroom, where compromising footage might be filmed, as well as smoke detectors and household appliances, common hiding spots. Also check paintings, clocks, flower pots, and even toys.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Pros:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Independence&lt;/li&gt;
&lt;li&gt;Option for regular checks&lt;/li&gt;
&lt;li&gt;DIY potential&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Cons:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Short effective range&lt;/li&gt;
&lt;li&gt;Price&lt;/li&gt;
&lt;li&gt;Time and skill requirements&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;If you&amp;#8217;re the only person you trust — and especially if you aren&amp;#8217;t afraid of soldering some LEDs —this method is for you.&lt;/p&gt;
&lt;h2&gt;Method 3. Use a smartphone&lt;/h2&gt;
&lt;p&gt;Sometimes you can do without special equipment and just use your smartphone camera and a flashlight. Turn off the lights and draw the curtains (the room must be dark), turn on both the flashlight and phone camera, and point them where you think a hidden device might be lurking. If your suspicions are correct, you will see a glare on the smartphone screen. If you can&amp;#8217;t use the phone&amp;#8217;s camera and flashlight simultaneously, use a separate flashlight.&lt;/p&gt;
&lt;p&gt;In some cases, you can even do without a flashlight. Many spy cameras use infrared illumination for filming in the dark. It is invisible to the human eye but not to a smartphone camera. When filming in the dark, the infrared light source will appear on the screen as a pulsing dot. Keep in mind that your smartphone&amp;#8217;s main camera may not do the trick, because it probably has an IR-light filter, so the front camera is a better bet. You can experiment with a TV remote to find out if your smartphone is good for the job.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Pros:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Free&lt;/li&gt;
&lt;li&gt;No special skills required&lt;/li&gt;
&lt;li&gt;No special equipment required&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Cons:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Not all phone models are up to the job&lt;/li&gt;
&lt;li&gt;Time-consuming&lt;/li&gt;
&lt;li&gt;Inefficient — false positives are possible, and cameras without infrared radiation are not visible&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;This method is suitable only for a superficial inspection; it&amp;#8217;s likely to miss something. Still, it&amp;#8217;s better than nothing.&lt;/p&gt;
&lt;h2&gt;Method 4. Trust an app&lt;/h2&gt;
&lt;p&gt;Mobile apps for finding spy cameras and other hidden devices fall into two categories. The first group finds devices by the lens glare, as in the above-described method. Examples include Glint Finder, which detects the glare (or glint) when the light of a flashlight hits a lens. Once that happens, you just have to check the areas for any hidden devices.&lt;/p&gt;
&lt;p&gt;Apps of the second group are designed to search for wireless spy devices. For them to work, you need to connect to the local Wi-Fi. After scanning the router, the app displays a list of connected devices. Check any you&amp;#8217;re not completely sure about, such as your smartphone and laptop. A &lt;a href="https://www.macvendorlookup.com/" target="_blank" rel="nofollow noopener"&gt;dedicated tool&lt;/a&gt; can help you distinguish harmless equipment from tracking devices by the identifier.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Pros:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Reasonably efficient&lt;/li&gt;
&lt;li&gt;Minimal costs&lt;/li&gt;
&lt;li&gt;No equipment required beyond a compatible smartphone&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Cons:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Inferior to specialized devices&lt;/li&gt;
&lt;li&gt;Unsuitable for smart homes with many connected devices&lt;/li&gt;
&lt;li&gt;Unsuitable for hotel Wi-Fi and other public routers with many connected devices&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;br /&gt;
Specialist software occupies the middle ground between professional equipment and improvised means. It&amp;#8217;s probably the best option for cautious travelers, provided they use a trusted app.&lt;/p&gt;
&lt;h2&gt;What to do if you detect a spying device&lt;/h2&gt;
&lt;p&gt;If you find something that looks like a camera or other tracking device, take a photo of it and do an &lt;a href="https://www.google.com/imghp" target="_blank" rel="nofollow noopener"&gt;image search&lt;/a&gt; to find out what it might be. It may be harmless.&lt;/p&gt;
&lt;p&gt;But if your fears are confirmed, you should contact the police, hotel administration, or the booking service you used. For example, AirBnB rules &lt;a href="https://www.airbnb.com/help/article/3061/use-of-cameras-and-recording-devices" target="_blank" rel="nofollow noopener"&gt;explicitly prohibit hidden cameras&lt;/a&gt;, so at least some affected guests have gotten &lt;a href="https://www.washingtonpost.com/technology/2019/01/17/airbnb-refunds-guest-who-found-indoor-cameras-during-his-familys-stay/" target="_blank" rel="nofollow noopener"&gt;refunds&lt;/a&gt; or &lt;a href="https://vancouver.citynews.ca/2018/09/11/tourist-hidden-camera-airbnb/" target="_blank" rel="nofollow noopener"&gt;different accommodations&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Better safe than sorry&lt;/h2&gt;
&lt;p&gt;We&amp;#8217;ve discussed a few ways to make sure that no extortionist, TikTok prankster, or landlord is filming you without permission. But hidden cameras are not the only &lt;a href="https://www.kaspersky.com/blog/travel-security-five-tips/26964/" target="_blank" rel="noopener"&gt;danger when traveling&lt;/a&gt;. Here are some general tips to help you stay safe in unfamiliar surroundings:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Take an external battery to stay connected at all times;&lt;/li&gt;
&lt;li&gt;Download apps to help your trip go more smoothly, such as maps, dictionaries, and translators;&lt;/li&gt;
&lt;li&gt;Don&amp;#8217;t leave valuables &lt;a href="https://encyclopedia.kaspersky.com/glossary/evil-maid/" target="_blank" rel="noopener"&gt;unattended&lt;/a&gt;;&lt;/li&gt;
&lt;li&gt;Never use public computers or terminals for private messaging, logging in to accounts, or online shopping;&lt;/li&gt;
&lt;li&gt;Use a &lt;a href="https://www.kaspersky.com/vpn-secure-connection?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____vpn___" target="_blank"&gt;VPN app&lt;/a&gt; to protect your data from hackers, as well as to have access to content that&amp;#8217;s not available in the country you are visiting.&lt;/li&gt;
&lt;/ul&gt;
&lt;input type="hidden" class="category_for_banner" value="ksec" /&gt;</content:encoded>
      <category>Privacy</category>
      <category>Tips</category>
      <category>hidden cameras</category>
      <category>privacy</category>
      <category>security</category>
      <category>spy cameras</category>
      <category>travel</category>
      <category>video surveillance</category>
      <pubDate>Mon, 20 Dec 2021 14:00:54 GMT</pubDate>
      <guid isPermaLink="false">https://www.kaspersky.com/blog/?p=43199</guid>
      <dc:creator>Leonid Grustniy</dc:creator>
      <dc:date>2021-12-20T14:00:54Z</dc:date>
    </item>
    <item>
      <title>Third Log4j vulnerability uncovered, Apache releases version 2.17.0</title>
      <link>https://www.computing.co.uk/news/4042307/log4j-vulnerability-uncovered-apache-releases-version</link>
      <description>&lt;img alt="Third Log4j vulnerability uncovered, Apache releases version 2.17.0" src="https://www.computing.co.uk/api/v1/wps/fc298a9/da935b99-f9f5-47a2-afa5-249b5fb8caad/9/softwarebug-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; 'High severity' bug fixed is an uncontrolled recursion flaw &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Mon, 20 Dec 2021 12:56:39 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4042307/log4j-vulnerability-uncovered-apache-releases-version</guid>
      <dc:date>2021-12-20T12:56:39Z</dc:date>
    </item>
    <item>
      <title>A fifth of all employees will fall for a phishing message, study finds</title>
      <link>https://www.computing.co.uk/news/4042309/fifth-employees-fall-phishing-message-study</link>
      <description>&lt;img alt="A fifth of all employees will fall for a phishing message, study finds" src="https://www.computing.co.uk/api/v1/wps/bb07181/92b9d29f-f0d1-457b-a0d5-9e1b231ad5f3/1/phishing-185x114.png" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; And of those redirected to a spoofed web site, almost a quarter will enter their details into a form  &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Mon, 20 Dec 2021 12:15:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4042309/fifth-employees-fall-phishing-message-study</guid>
      <dc:date>2021-12-20T12:15:00Z</dc:date>
    </item>
    <item>
      <title>2022 Cybersecurity Trends for DevSecOps</title>
      <link>https://www.trendmicro.com/en_us/devops/21/l/2022-cybersecurity-trends-for-devsecops.html</link>
      <description>Trying to adopt DevSecOps culture? Or already in the thick of it? Trend Research explores the cybersecurity trends for 2022 to enhance your security strategy and get the most out of DevSecOps.</description>
      <source url="https://www.trendmicro.com/en_us/devops.html">DevOps Resource Center</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/devops/21/l/2022-cybersecurity-trends-for-devsecops/2022-cyber-trends.png" type="image/png" />
      <category>Trend Micro DevOps : Cloud Native</category>
      <category>Trend Micro DevOps : Research</category>
      <category>Trend Micro DevOps : Article</category>
      <category>Trend Micro DevOps : Multi Cloud</category>
      <pubDate>Mon, 20 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:d4627efb-e444-b205-edfd-6d45bc336671</guid>
      <dc:date>2021-12-20T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Are Endpoints at Risk for Log4Shell Attacks?</title>
      <link>https://www.trendmicro.com/en_us/research/21/l/are-endpoints-at-risk-for-log4shell-attacks.html</link>
      <description>We created a free assessment tool for scanning devices to know whether it is at risk for Log4Shell attacks.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/l/are-endpoints-at-risk-for-log4shell-attacks/log4shelldesktop-main.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Endpoints</category>
      <category>Trend Micro Research : Exploits &amp; Vulnerabilities</category>
      <category>Trend Micro Research : Research</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <pubDate>Sat, 18 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:187f91a5-bc2a-653e-615e-5041d33ee997</guid>
      <dc:date>2021-12-18T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Friday Squid Blogging: UK Recognizes Squid as Sentient Beings</title>
      <link>https://www.schneier.com/blog/archives/2021/12/friday-squid-blogging-uk-recognizes-squid-as-sentient-beings.html</link>
      <thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">148</thr:total>
      <description>&lt;p&gt;This seems &lt;a href="https://www.iflscience.com/plants-and-animals/octopuses-squid-and-lobsters-recognized-as-sentient-beings-in-uk/"&gt;big&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;The UK government has &lt;a href="https://www.gov.uk/government/news/lobsters-octopus-and-crabs-recognised-as-sentient-beings"&gt;officially&lt;/a&gt; included decapod crustaceans&amp;#8211;including crabs, lobsters, and crayfish&amp;#8211;and cephalopod mollusks&amp;#8211;including octopuses, squid, and cuttlefish&amp;#8211;in its &lt;a href="https://www.iflscience.com/plants-and-animals/animals-now-considered-sentient-beings-in-uk-law-thanks-to-action-for-animals-report/"&gt;Animal Welfare (Sentience) Bill&lt;/a&gt;. This means they are now recognized as &amp;#8220;sentient beings&amp;#8221; in the UK.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.&lt;/p&gt;
&lt;p&gt;Read my blog posting guidelines &lt;a href="https://www.schneier.com/blog/archives/2017/03/commenting_poli.html"&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This seems &lt;a href="https://www.iflscience.com/plants-and-animals/octopuses-squid-and-lobsters-recognized-as-sentient-beings-in-uk/"&gt;big&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;The UK government has &lt;a href="https://www.gov.uk/government/news/lobsters-octopus-and-crabs-recognised-as-sentient-beings"&gt;officially&lt;/a&gt; included decapod crustaceans&amp;#8211;including crabs, lobsters, and crayfish&amp;#8211;and cephalopod mollusks&amp;#8211;including octopuses, squid, and cuttlefish&amp;#8211;in its &lt;a href="https://www.iflscience.com/plants-and-animals/animals-now-considered-sentient-beings-in-uk-law-thanks-to-action-for-animals-report/"&gt;Animal Welfare (Sentience) Bill&lt;/a&gt;. This means they are now recognized as &amp;#8220;sentient beings&amp;#8221; in the UK.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.&lt;/p&gt;
&lt;p&gt;Read my blog posting guidelines &lt;a href="https://www.schneier.com/blog/archives/2017/03/commenting_poli.html"&gt;here&lt;/a&gt;.&lt;/p&gt;</content:encoded>
      <category domain="https://www.schneier.com">Uncategorized</category>
      <category domain="https://www.schneier.com">squid</category>
      <pubDate>Fri, 17 Dec 2021 22:01:29 GMT</pubDate>
      <guid isPermaLink="false">https://www.schneier.com/?p=64665</guid>
      <dc:creator>Bruce Schneier</dc:creator>
      <dc:date>2021-12-17T22:01:29Z</dc:date>
    </item>
    <item>
      <title>How Risky Is the Log4J Vulnerability?</title>
      <link>https://www.darkreading.com/edge-threat-monitor/how-risky-is-the-log4j-vulnerability-</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blta119c0ca4ba5155d/61bd1358f1cd402112e7079b/tm-log4j.jpg" type="image/*" />
      <description>Security teams around the world are on high alert dealing with the Log4j vulnerability, but how risky is it, really?</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltbeb30fde8ec73a32/60d4432c2446e93b5b5a0e0c/Edge-Editors.png" type="image/*" />
      <pubDate>Fri, 17 Dec 2021 20:53:22 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/edge-threat-monitor/how-risky-is-the-log4j-vulnerability-</guid>
      <dc:creator>Edge Editors, Dark Reading</dc:creator>
      <dc:date>2021-12-17T20:53:22Z</dc:date>
    </item>
    <item>
      <title>Serious Security: OpenSSL fixes “error conflation” bugs – how mixing up mistakes can lead to trouble</title>
      <link>https://nakedsecurity.sophos.com/2021/12/17/serious-security-openssl-fixes-error-conflation-bugs-how-mixing-up-mistakes-can-lead-to-trouble/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://nakedsecurity.sophos.com/2021/12/17/serious-security-openssl-fixes-error-conflation-bugs-how-mixing-up-mistakes-can-lead-to-trouble/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">2</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/ossl-darker-1200.png?w=230&amp;h=130&amp;crop=1" medium="image" />
      <post-id xmlns="com-wordpress:feed-additions:1">647553</post-id>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/ossl-darker-1200.png" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/ossl-darker-1200.png?w=170&amp;h=90&amp;crop=1" medium="image" />
      <description>Have you ever seen the message "An error occurred"? Even worse, the message "This error cannot occur"? Facts matter!</description>
      <category>Cryptography</category>
      <category>CVE-2021-4044</category>
      <category>openssl</category>
      <category>Patching</category>
      <category>vulnerability</category>
      <pubDate>Fri, 17 Dec 2021 19:57:52 GMT</pubDate>
      <comments>https://nakedsecurity.sophos.com/2021/12/17/serious-security-openssl-fixes-error-conflation-bugs-how-mixing-up-mistakes-can-lead-to-trouble/#comments</comments>
      <guid isPermaLink="false">https://nakedsecurity.sophos.com/?p=647553</guid>
      <dc:creator>Paul Ducklin</dc:creator>
      <dc:date>2021-12-17T19:57:52Z</dc:date>
    </item>
    <item>
      <title>Meta Acts Against 7 Entities Found Spying on 50,000 Users</title>
      <link>https://www.darkreading.com/threat-intelligence/meta-acts-against-7-entities-found-spying-on-50-000-users</link>
      <description>The parent company of Facebook and Instagram has warned some 50,000 account holders they are targets of surveillance.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte161b23f0fd3a84b/60b1ea374e7eb868c4c6a293/dr_staff_125x125.jpg" type="image/*" />
      <pubDate>Fri, 17 Dec 2021 19:10:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/threat-intelligence/meta-acts-against-7-entities-found-spying-on-50-000-users</guid>
      <dc:creator>Dark Reading Staff, Dark Reading</dc:creator>
      <dc:date>2021-12-17T19:10:00Z</dc:date>
    </item>
    <item>
      <title>Executive Partnerships Are Critical for Cybersecurity Success</title>
      <link>https://www.darkreading.com/edge-articles/executive-partnerships-are-critical-for-cybersecurity-success</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt9fef239f7d09504d/614b53ffd8068d7efec4da7d/boardroom-iStock_000061214250_Medium.jpg" type="image/*" />
      <description>One leader alone can't protect an organization from cyber threats, C-suite leaders agree.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt3b296baaaaccbc2a/61bbb7b4ac124d4b2e71583a/WriterDefault_vladwel_Adobe.jpg" type="image/*" />
      <pubDate>Fri, 17 Dec 2021 18:30:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/edge-articles/executive-partnerships-are-critical-for-cybersecurity-success</guid>
      <dc:creator>Sakshi Udavant, Freelance Writer</dc:creator>
      <dc:date>2021-12-17T18:30:00Z</dc:date>
    </item>
    <item>
      <title>Timely Questions for Log4j Response Now — And for the Future</title>
      <link>https://www.darkreading.com/application-security/timely-questions-for-log4j-response-now---and-for-the-future</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltd1b717f2f5530ac3/61bcdee1e274931fda6845aa/Simon_Lehmann_Alamy_Stock_Photo.jpeg" type="image/*" />
      <description>EXPERT INSIGHT: How to assess your exposure to the vulnerability with a combination of asset inventory, testing, solid information sources, and software bills of materials (SBOMs).</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltfe1742f03c1ccb64/60d43693d9a5243b66924505/KatieMoussouris.jpg" type="image/*" />
      <pubDate>Fri, 17 Dec 2021 17:40:09 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/application-security/timely-questions-for-log4j-response-now---and-for-the-future</guid>
      <dc:creator>Katie Moussouris, Founder &amp; CEO, Luta Security</dc:creator>
      <dc:date>2021-12-17T17:40:09Z</dc:date>
    </item>
    <item>
      <title>PseudoManuscrypt Malware Targeted Government &amp; ICS Systems in 2021</title>
      <link>https://www.darkreading.com/threat-intelligence/pseudomanuscrypt-malware-targeted-government-ics-systems-in-2021</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt2ac68cdf40428caa/61bcd61f7d28862872f7e729/KasperskyChart.png" type="image/*" />
      <description>The "PseudoManuscrypt" operation infected some 35,000 computers with cyber-espionage malware and targeted computers in both government and private industry.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt58481326324d6911/60b1e9a55d34de550780a990/Robert-Lemos.png" type="image/*" />
      <pubDate>Fri, 17 Dec 2021 17:15:58 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/threat-intelligence/pseudomanuscrypt-malware-targeted-government-ics-systems-in-2021</guid>
      <dc:creator>Robert Lemos, Contributing Writer</dc:creator>
      <dc:date>2021-12-17T17:15:58Z</dc:date>
    </item>
    <item>
      <title>Time to Reset the Idea of Zero Trust</title>
      <link>https://www.darkreading.com/crowdstrike/time-to-reset-the-idea-of-zero-trust</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt50ca01acb94fe54c/61bb651c50619737cfdd1059/zerotrust-FitZtudio-Shutterstock.jpg" type="image/*" />
      <description>CISOs are increasingly drawn to the zero trust security model, but implementing a frictionless experience is still a challenge.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt9fbfd6b242a71427/61b83d9962ca795dc781c966/Kapil_Raina_Crowdstrike.jpg" type="image/*" />
      <pubDate>Fri, 17 Dec 2021 17:02:32 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/crowdstrike/time-to-reset-the-idea-of-zero-trust</guid>
      <dc:creator>Kapil Raina, VP Zero Trust &amp; Identity Marketing, CrowdStrike</dc:creator>
      <dc:date>2021-12-17T17:02:32Z</dc:date>
    </item>
    <item>
      <title>CISA Issues Emergency Directive on Log4j</title>
      <link>https://www.darkreading.com/threat-intelligence/cisa-issues-emergency-directive-on-log4j</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt4706b69678a69950/6182f0f18a0585636d714c3b/dhs.jpg" type="image/*" />
      <description>The Cybersecurity Infrastructure and Security Agency orders federal agencies to take actions to mitigate vulnerabilities to the Apache Log4j flaw and attacks exploiting it.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte161b23f0fd3a84b/60b1ea374e7eb868c4c6a293/dr_staff_125x125.jpg" type="image/*" />
      <pubDate>Fri, 17 Dec 2021 16:27:11 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/threat-intelligence/cisa-issues-emergency-directive-on-log4j</guid>
      <dc:creator>Dark Reading Staff, Dark Reading</dc:creator>
      <dc:date>2021-12-17T16:27:11Z</dc:date>
    </item>
    <item>
      <title>Cyberattacks on industrial systems | Kaspersky official blog</title>
      <link>https://www.kaspersky.com/blog/pseudomanuscrypt-industrial-malware/43177/</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/17110547/pseudomanuscrypt-industrial-malware-featured.jpg" width="1460" height="960">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/17110547/pseudomanuscrypt-industrial-malware-featured-1024x673.jpg" width="1024" height="673">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/17110547/pseudomanuscrypt-industrial-malware-featured-300x197.jpg" width="300" height="197">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/17110547/pseudomanuscrypt-industrial-malware-featured-150x150.jpg" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>Kaspersky experts have discovered an attack that used PseudoManuscrypt spyware to hit industrial systems.</description>
      <content:encoded>&lt;p&gt;In June 2021, our specialists discovered new malware called PseudoManuscrypt. PseudoManuscrypt&amp;#8217;s methods are fairly standard for spyware. It functions as a keylogger, gathers information about established VPN connections and saved passwords, steals clipboard contents, records sound using the built-in microphone (if the computer has one), and captures images. One variant can also steal the credentials of QQ and WeChat messengers, capture screen video and has a function that attempts disabling security solutions. Then it sends the data to the attackers&amp;#8217; server. &lt;/p&gt;
&lt;p&gt;For the technical details of the attack and indicators of compromise, see &lt;a href="https://ics-cert.kaspersky.com/reports/2021/12/16/pseudomanuscrypt-a-mass-scale-spyware-attack-campaign/" target="_blank" rel="noopener"&gt;our ICS CERT report&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Origin of the name&lt;/h2&gt;
&lt;p&gt;Our experts found some similarities between the new attack and the already known &lt;a href="https://ics-cert.kaspersky.com/reports/2021/02/25/lazarus-targets-defense-industry-with-threatneedle/" target="_blank" rel="nofollow noopener"&gt;Manuscrypt&lt;/a&gt; campaign, but analysis revealed that a completely different actor, the APT41 group, had previously used part of the malware code in its attacks. We have yet to establish responsibility for the new attack, and for now we&amp;#8217;re calling it PseudoManuscrypt.&lt;/p&gt;
&lt;h2&gt;How PseudoManuscrypt infects a system&lt;/h2&gt;
&lt;p&gt;Successful infection rests on a rather complex chain of events. The attack on a computer usually begins when the user downloads and executes a malware that imitates pirated install package for popular software.&lt;/p&gt;
&lt;p&gt;You can find PseudoManuscrypt bait by searching the Internet for a pirated software. Websites that distribute malicious code matching popular queries rank high in search engine results, a metric attackers seem to monitor. &lt;/p&gt;
&lt;p&gt;Here you can clearly see why there have been so many attempts to infect industrial systems. In addition to providing malware posing as popular software (such as office suites, security solutions, navigation systems, and 3D first-person shooters), the attackers also offer fake install packages for professional software, including certain utilities for interacting with programmable logic controllers (PLC) using the ModBus. The result: an abnormally high number of infected industrial control system (ICS) computers (7.2% of the total).&lt;/p&gt;
&lt;div id="attachment_43178" style="width: 1167px" class="wp-caption aligncenter"&gt;&lt;a href="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/17105945/pseudomanuscrypt-industrial-malware-search-results.png"&gt;&lt;img aria-describedby="caption-attachment-43178" src="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/17105945/pseudomanuscrypt-industrial-malware-search-results.png" alt="Search results for pirated software. PseudoManuscrypt can be found at the very first link." width="1157" height="947" class="size-full wp-image-43178" /&gt;&lt;/a&gt;&lt;p id="caption-attachment-43178" class="wp-caption-text"&gt;Search results for pirated software. PseudoManuscrypt can be found at the very first link. &lt;a href="https://ics-cert.kaspersky.ru/reports/2021/12/16/pseudomanuscrypt-a-mass-scale-spyware-attack-campaign/" target="_blank" rel="noopener"&gt;Sourse&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;The example in the screenshot above features software for system administrators and network engineers. Theoretically such an attack vector could provide attackers with full access to the company&amp;#8217;s infrastructure.&lt;/p&gt;
&lt;p&gt;The attackers also use a Malware-as-a-Service (MaaS) delivery mechanism, paying other cybercriminals to distribute PseudoManuscrypt. That practice gave rise to an interesting feature our experts found when analyzing the MaaS platform: Sometimes PseudoManuscrypt was bundled with other malware that the victim installed as a single package. The purpose of PseudoManuscrypt is to spy, but other malicious programs seek other objectives, such as data encryption for money extortion. &lt;/p&gt;
&lt;h2&gt;Who is PseudoManuscrypt targeting?&lt;/h2&gt;
&lt;p&gt;The largest number of PseudoManuscrypt detections have occurred in Russia, India, Brazil, Vietnam, and Indonesia. Of the huge number of attempts to run malicious code, users at industrial organizations account for a significant share. Victims in this sector include managers of building automation systems, energy companies, manufacturers, construction companies, and even service providers for water treatment plants. In addition, an unusually large number of affected computers were involved in engineering processes, and in the production of new products in industrial companies.&lt;/p&gt;
&lt;h2&gt;Methods for defending against PseudoManuscrypt&lt;/h2&gt;
&lt;p&gt;For protection against PseudoManuscrypt you must have reliable and regularly updated protective solutions, and they must be installed on 100% of a company&amp;#8217;s systems. In addition, we recommend instituting policies that make disabling protection difficult. &lt;/p&gt;
&lt;p&gt;For IT systems in industry, we also offer a specialized solution, &lt;a href="https://www.kaspersky.com/enterprise-security/industrial?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder____" target="_blank"&gt;Kaspersky Industrial CyberSecurity&lt;/a&gt;, which both protects computers (including specialized ones) and monitors data transfers that use specific protocols.&lt;/p&gt;
&lt;p&gt;Also keep in mind the importance of raising personnel awareness of cybersecurity risks. You can&amp;#8217;t totally rule out the possibility of clever phishing attacks, but you can help staff stay alert, and also educate them about the danger of installing unauthorized (and especially pirated) software on computers with access to industrial systems.&lt;/p&gt;</content:encoded>
      <category>Business</category>
      <category>Enterprise</category>
      <category>Industrial Cybersecurity</category>
      <category>Industrial systems</category>
      <category>spyware</category>
      <pubDate>Fri, 17 Dec 2021 16:14:38 GMT</pubDate>
      <guid isPermaLink="false">https://www.kaspersky.com/blog/?p=43177</guid>
      <dc:creator>Enoch Root</dc:creator>
      <dc:date>2021-12-17T16:14:38Z</dc:date>
    </item>
    <item>
      <title>Is Data Security Worthless if the Data Life Cycle Lacks Clarity?</title>
      <link>https://www.darkreading.com/risk/is-data-security-worthless-if-the-data-lifecycle-lacks-clarity-</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltfba0791e04cf6e00/61ae7346d96937695e762ba5/LocksOnDigitalBackground_Aleksey_Funtap_Alamy.jpg" type="image/*" />
      <description>If you cannot track, access, or audit data at every stage of the process, then you can't claim your data is secure.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltfd3956c21b8c5513/60d4352890ef0d39a2f3fb8d/SM_FrancoisAmigorena.jpg" type="image/*" />
      <pubDate>Fri, 17 Dec 2021 15:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/risk/is-data-security-worthless-if-the-data-lifecycle-lacks-clarity-</guid>
      <dc:creator>François Amigorena, Founder &amp; CEO, IS Decisions</dc:creator>
      <dc:date>2021-12-17T15:00:00Z</dc:date>
    </item>
    <item>
      <title>How to respond if your firm is victim to a ransomware attack</title>
      <link>https://www.computing.co.uk/opinion/4042253/respond-firm-victim-ransomware-attack</link>
      <description>&lt;img alt="How to respond if your firm is victim to a ransomware attack" src="https://www.computing.co.uk/api/v1/wps/e5ffbd1/303703e4-0a2c-450b-b7c0-1ad78710cedb/5/petya-ransomware-message-185x114.jpeg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Of cyberattack cases reported to Kroll in 2020, over a third involved ransomware &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Fri, 17 Dec 2021 13:30:06 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/opinion/4042253/respond-firm-victim-ransomware-attack</guid>
      <dc:date>2021-12-17T13:30:06Z</dc:date>
    </item>
    <item>
      <title>Meta bans seven private surveillance groups for using Facebook to spy on people worldwide</title>
      <link>https://www.computing.co.uk/news/4042244/meta-bans-seven-private-surveillance-facebook-spy-people-worldwide</link>
      <description>&lt;img alt="Meta bans seven private surveillance groups for using Facebook to spy on people worldwide" src="https://www.computing.co.uk/api/v1/wps/89cef8f/1105bc0d-36f4-4dab-a37d-d148e9ca572a/10/facebook-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Targets include journalists, dissidents, human rights activists and critics of authoritarian regimes and their families &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Fri, 17 Dec 2021 11:41:46 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4042244/meta-bans-seven-private-surveillance-facebook-spy-people-worldwide</guid>
      <dc:date>2021-12-17T11:41:46Z</dc:date>
    </item>
    <item>
      <title>Khonsari ransomware exploiting Log4j bug to target Minecraft servers, Microsoft confirms</title>
      <link>https://www.computing.co.uk/news/4042224/khonsari-ransomware-exploiting-log4j-bug-target-minecraft-servers-microsoft-confirms</link>
      <description>&lt;img alt="Khonsari ransomware exploiting Log4j bug to target Minecraft servers, Microsoft confirms" src="https://www.computing.co.uk/api/v1/wps/bdb5916/5bb4098a-38ba-4e69-8249-b0b9d3530396/9/log4shell-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Researchers observe multiple attempts  to deploy a Khonsari ransomware that hits Windows machines by making use of Log4Shell bug &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Fri, 17 Dec 2021 08:26:37 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4042224/khonsari-ransomware-exploiting-log4j-bug-target-minecraft-servers-microsoft-confirms</guid>
      <dc:date>2021-12-17T08:26:37Z</dc:date>
    </item>
    <item>
      <title>Mobile App Developers Keep Fraudulent Traffic at Bay with Anti-Fraud API</title>
      <link>https://www.darkreading.com/dr-tech/mobile-app-developers-keep-fraudulent-traffic-at-bay-with-anti-fraud-api</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt120bfa1494016f81/614b409f79be080fa4994705/bot-Zapp2Photoshutterstock_524844376.jpg" type="image/*" />
      <description>The new API and SDK from Pixalate helps mobile developers avoid getting their apps delisted from app stores by detecting and blocking fraudulent traffic.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt93784ffee79538e7/60d4371522d24e38a3806ecf/fahmida.png" type="image/*" />
      <pubDate>Fri, 17 Dec 2021 00:32:02 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/dr-tech/mobile-app-developers-keep-fraudulent-traffic-at-bay-with-anti-fraud-api</guid>
      <dc:creator>Fahmida Y. Rashid, Features Editor, Dark Reading</dc:creator>
      <dc:date>2021-12-17T00:32:02Z</dc:date>
    </item>
    <item>
      <title>Episode 232: Log4j Won’t Go Away (And What To Do About It.)</title>
      <link>https://feeds.feedblitz.com/~/675372840/_/thesecurityledger~Episode-Logj-Won%e2%80%99t-Go-Away-And-What-To-Do-About-It/</link>
      <feedburner:origLink xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">https://securityledger.com/2021/12/episode-232-log4j-wont-go-away-and-what-to-do-about-it/</feedburner:origLink>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://feeds.feedblitz.com/~/675372840/_/thesecurityledger~Episode-Logj-Won%e2%80%99t-Go-Away-And-What-To-Do-About-It/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <itunes:subtitle xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">In this episode of the podcast (#232), Tomislav Peričin of the firm ReversingLabs joins us to talk about Log4Shell, the vulnerability in the ubiquitous Log4j Apache library. Tomislav tells us why issues related to Log4j won’t be going away anytime soon...</itunes:subtitle>
      <itunes:summary xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><![CDATA[<br />
In this episode of the podcast (#232), <a rel="NOFOLLOW" rel="noreferrer noopener" href="https://www.reversinglabs.com/company/leadership/management-team/tomislav-pericin" target="_blank">Tomislav Peričin</a> of the firm ReversingLabs joins us to talk about Log4Shell, the vulnerability in the ubiquitous Log4j Apache library. Tomislav tells us why issues related to Log4j won’t be going away anytime soon and how organizations must adapt to deal with the risk it poses. <br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
If you’ve been paying attention to your infosec news feed this week, you’ve been inundated with stories and <a rel="NOFOLLOW" href="https://www.google.com/search?q=Log4j+OR+Log4Shell&#38;sxsrf=AOaemvIDdQxcrlUfyjxGtSEYbtOjpxX2Jw:1639748487865&#38;source=lnms&#38;tbm=nws&#38;sa=X&#38;ved=2ahUKEwjjgI-R--r0AhUvjokEHYR2DbsQ_AUoAXoECAEQAw&#38;biw=1255&#38;bih=610&#38;dpr=2" target="_blank" rel="noreferrer noopener">headlines about something called “log4j, </a>a (previously) obscure library that is a common component of a number of Apache software frameworks. This quiet little soldier of the open source software world,&#160; we now know, has a glaring security hole in it that allows remote code execution on affected systems.&#160;<br />
<br />
<br />
<br />
<a rel="NOFOLLOW" href="https://securityledger.com/2021/06/episode-218-denial-of-sustenance-attacks-the-cyber-risk-to-agriculture/" target="_blank" rel="noreferrer noopener">Episode 218: Denial of Sustenance Attacks -The Cyber Risk To Agriculture</a><br />
<br />
<br />
<br />
<a rel="NOFOLLOW" href="https://www.reversinglabs.com/company/leadership/management-team/tomislav-pericin" target="_blank" rel="noreferrer noopener">Tomislav Peričin</a> is the co-founder and Chief Software Architect at ReversingLabs. <br />
<br />
<br />
<br />
Log4j: A Very Popular Library<br />
<br />
<br />
<br />
And that’s a big problem. Why? Well, it turns out that Log4j is a very, very, very popular software library. The firm Sonatype notes that in November, log4j-core, the vulnerable version of the module, was the 252nd most popular component by download volume in Sonatype’s Maven Central code repository. That’s out of a total population of 7.1 million artifacts &#8211; that’s the top 0.003% percentile in popularity by downloads. To date, <a rel="NOFOLLOW" href="https://github.com/NCSC-NL/log4shell/blob/main/software/README.md" target="_blank" rel="noreferrer noopener">more than 2000 software packages</a>&#160;<a rel="NOFOLLOW" href="https://github.com/NCSC-NL/log4shell/blob/main/software/README.md">have been identified</a>&#160;that are potentially vulnerable to attacks targeting log4j. Those include both the popular Minecraft massively multiplayer online game as well as&#160;<a rel="NOFOLLOW" href="https://techcrunch.com/2021/12/10/apple-icloud-twitter-and-minecraft-vulnerable-to-ubiquitous-zero-day-exploit/">Apple’s iCloud and Twitter</a>. SAP announced on Wednesday that it, alone, patched 20 applications that used Log4j. In the meantime, threat actors are scanning the Internet to identify servers vulnerable to exploitation.<br />
<br />
<br />
<br />
<a rel="NOFOLLOW" href="https://securityledger.com/2021/03/episode-208-getting-serious-about-hardware-supply-chains-with-goldman-sachs-michael-mattioli/" target="_blank" rel="noreferrer noopener">Episode 208: Getting Serious about Hardware Supply Chains with Goldman Sachs’ Michael Mattioli</a><br />
<br />
<br />
<br />
Supply Chain Risks: The New Normal<br />
<br />
<br />
<br />
What does this mean for your organization? And what does the Log4j vulnerability tell us about the shape of cyber risks and threats to come? We invited <a rel="NOFOLLOW" rel="noreferrer noopener" href="https://www.reversinglabs.com/company/leadership/management-team/tomislav-pericin" target="_blank">Tomislav Peričin</a> in to the Security Ledger studios to talk. Tomislav is the Chief Software Architect at the firm <a rel="NOFOLLOW" rel="noreferrer noopener" href="https://www.reversinglabs.com" target="_blank">ReversingLabs</a> and he’s an expert in software analysis and supply chain risks.]]></itunes:summary>
      <itunes:author xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">Paul F. Roberts</itunes:author>
      <itunes:duration xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">26:04</itunes:duration>
      <rawvoice:embed xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/">&lt;iframe src="https://player.blubrry.com/?media_url=https%3A%2F%2Fmedia.blubrry.com%2Fthe_security_ledger_podcasts%2Fcontent.blubrry.com%2Fthe_security_ledger_podcasts%2FEpisode_232_Log4J_with_Tomislav_Pericin.mp3&amp;amp;podcast_link=https%3A%2F%2Fsecurityledger.com%2F2021%2F12%2Fepisode-232-log4j-wont-go-away-and-what-to-do-about-it%2F#darkOrLight-light&amp;shownotes-ffffff&amp;shownotesBackground-444444&amp;download-ffffff&amp;downloadBackground-003366&amp;subscribe-ffffff&amp;subscribeBackground-fb8c00&amp;share-ffffff&amp;shareBackground-1976d2" scrolling="no" width="100%" height="138px" frameborder="0" id="blubrryplayer-1" class="blubrryplayer" title="Blubrry Podcast Player"&gt;&lt;/iframe&gt;</rawvoice:embed>
      <post-id xmlns="com-wordpress:feed-additions:1">476715</post-id>
      <feedburner:origEnclosureLink xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">https://media.blubrry.com/the_security_ledger_podcasts/content.blubrry.com/the_security_ledger_podcasts/Episode_232_Log4J_with_Tomislav_Pericin.mp3</feedburner:origEnclosureLink>
      <description>&lt;p&gt;In this episode of the podcast (#232), Tomislav Peričin of the firm ReversingLabs joins us to talk about Log4Shell, the vulnerability in the ubiquitous Log4j Apache library. Tomislav tells us why issues related to Log4j won’t be going away anytime soon and how organizations must adapt to deal with the risk it poses. &lt;/p&gt;
&lt;p&gt;The post &lt;a rel="NOFOLLOW" href="https://feeds.feedblitz.com/~/675372840/_/thesecurityledger~Episode-Logj-Won%e2%80%99t-Go-Away-And-What-To-Do-About-It/"&gt;Episode 232: Log4j...&lt;/a&gt;&lt;/p&gt;&lt;p style="clear:left"&gt;&lt;span class="fbz_teasertext"&gt;&lt;a href="https://feeds.feedblitz.com/~/675372840/_/thesecurityledger"&gt;&lt;b&gt;Read the whole entry...&lt;/b&gt;&lt;/a&gt;&amp;#160;&lt;!-- _!fbztxtlnk!_ https://feeds.feedblitz.com/~/675372840/_/thesecurityledger --&gt;&lt;b&gt;&amp;#187;&lt;/b&gt;&lt;/p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="fbz_enclosure" style="clear:left"&gt;&lt;audio controls="controls" style="display:block;padding:0.5em 0;max-width:100%;"&gt;&lt;source src="https://feeds.feedblitz.com/-/675372838/_/thesecurityledger.mp3"&gt;Click the icon below to listen.&lt;/audio&gt;&lt;a href="https://feeds.feedblitz.com/-/675372838/_/thesecurityledger.mp3" title="Play audio"&gt;&lt;img border="0" width="40" height="40" src="https://assets.feedblitz.com/i/podplay.png"/&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/12/spotlight-how-secrets-sprawl-undermines-software-supply-chain-security/"&gt;Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/episode-227-whats-fueling-cyber-attacks-on-agriculture/"&gt;Episode 227: What&amp;#x2019;s Fueling Cyber Attacks on Agriculture ?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/11/episode-229-bugcrowds-casey-ellis-on-whats-hot-in-bug-hunting/"&gt;Episode 229: BugCrowd&amp;#x2019;s Casey Ellis On What&amp;#x2019;s Hot In Bug Hunting&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
      <content:encoded>&lt;p&gt;In this episode of the podcast (#232), Tomislav Peričin of the firm ReversingLabs joins us to talk about Log4Shell, the vulnerability in the ubiquitous Log4j Apache library. Tomislav tells us why issues related to Log4j won’t be going away anytime soon and how organizations must adapt to deal with the risk it poses. &lt;/p&gt;
&lt;p&gt;The post &lt;a rel="nofollow" href="https://feeds.feedblitz.com/~/t/0/_/thesecurityledger/~https://securityledger.com/2021/12/episode-232-log4j-wont-go-away-and-what-to-do-about-it/"&gt;Episode 232: Log4j...&lt;/a&gt;&lt;/p&gt;&lt;p style="clear:left"&gt;&lt;span class="fbz_teasertext"&gt;&lt;a href="https://feeds.feedblitz.com/~/675372840/_/thesecurityledger"&gt;&lt;b&gt;Read the whole entry...&lt;/b&gt;&lt;/a&gt;&amp;#160;&lt;!-- _!fbztxtlnk!_ https://feeds.feedblitz.com/~/675372840/_/thesecurityledger --&gt;&lt;b&gt;&amp;#187;&lt;/b&gt;&lt;/p&gt;&lt;/span&gt;&lt;Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.feedblitz.com/~/i/675372840/_/thesecurityledger"&gt;
&lt;/p&gt;&lt;div class="fbz_enclosure" style="clear:left"&gt;&lt;audio controls="controls" style="display:block;padding:0.5em 0;max-width:100%;"&gt;&lt;source src="https://feeds.feedblitz.com/-/675372838/_/thesecurityledger.mp3"&gt;Click the icon below to listen.&lt;/audio&gt;&lt;a href="https://feeds.feedblitz.com/-/675372838/_/thesecurityledger.mp3" title="Play audio"&gt;&lt;img border="0" width="40" height="40" src="https://assets.feedblitz.com/i/podplay.png"/&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/12/spotlight-how-secrets-sprawl-undermines-software-supply-chain-security/"&gt;Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/episode-227-whats-fueling-cyber-attacks-on-agriculture/"&gt;Episode 227: What&amp;#x2019;s Fueling Cyber Attacks on Agriculture ?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/11/episode-229-bugcrowds-casey-ellis-on-whats-hot-in-bug-hunting/"&gt;Episode 229: BugCrowd&amp;#x2019;s Casey Ellis On What&amp;#x2019;s Hot In Bug Hunting&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded>
      <enclosure url="https://feeds.feedblitz.com/-/675372838/_/thesecurityledger.mp3" length="37544121" type="audio/mpeg" />
      <category>Apache Foundation</category>
      <category>Apache Struts</category>
      <category>Business</category>
      <category>Companies</category>
      <category>Log4J</category>
      <category>Log4Shell</category>
      <category>Podcasts</category>
      <category>Reversing Labs</category>
      <category>SBOM (software bill of materials)</category>
      <category>Software</category>
      <category>Spotlight</category>
      <category>supply chain</category>
      <category>podcast</category>
      <category>reports</category>
      <category>ReversingLabs</category>
      <category>SBOM</category>
      <category>software bill of materials</category>
      <category>software supply chain</category>
      <category>vulnerabilities</category>
      <pubDate>Fri, 17 Dec 2021 00:02:00 GMT</pubDate>
      <comments>https://feeds.feedblitz.com/~/675372840/_/thesecurityledger~Episode-Logj-Won%e2%80%99t-Go-Away-And-What-To-Do-About-It/#respond</comments>
      <guid isPermaLink="false">https://securityledger.com/?p=476715</guid>
      <dc:creator>Paul Roberts</dc:creator>
      <dc:date>2021-12-17T00:02:00Z</dc:date>
    </item>
    <item>
      <title>Staging a Quack: Reverse Analyzing a Fileless QAKBOT Stager</title>
      <link>https://www.trendmicro.com/en_us/research/21/l/staging-a-quack-reverse-analyzing-fileless-qakbot-stager.html</link>
      <description>We analyzed a fileless QAKBOT stager possibly connected to the recently reported Squirrelwaffle campaign.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/l/staging-a-quack-reverse-analyzing-a-fileless-qakbot-stager/cover-staging-a-quack-reverse-analyzing-a-fileless-qakbot-stager.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Malware</category>
      <category>Trend Micro Research : Cyber Crime</category>
      <category>Trend Micro Research : Cyber Threats</category>
      <category>Trend Micro Research : Endpoints</category>
      <category>Trend Micro Research : Ransomware</category>
      <category>Trend Micro Research : Spam</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <pubDate>Fri, 17 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:66c7b269-e304-c428-0811-4e4158ba6a0c</guid>
      <dc:creator>Abraham Camba</dc:creator>
      <dc:date>2021-12-17T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Oracle WebLogic Detection and Mitigation</title>
      <link>https://www.trendmicro.com/en_us/devops/21/l/oracle-weblogic-detection-and-mitigation.html</link>
      <description>We review 2020 and 2021 Oracle WebLogic vulnerabilities and how using a unified SaaS platform can help you detect and mitigate these sophisticated risks.</description>
      <source url="https://www.trendmicro.com/en_us/devops.html">DevOps Resource Center</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/devops/21/l/oracle-weblogic-detection-and-mitigation/devops-oracle.jpg" type="image/jpeg" />
      <category>Trend Micro DevOps : Workload Security</category>
      <category>Trend Micro DevOps : How To</category>
      <category>Trend Micro DevOps : Network Security</category>
      <category>Trend Micro DevOps : Article</category>
      <category>Trend Micro DevOps : Multi Cloud</category>
      <pubDate>Fri, 17 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:b9796eec-688c-251a-3f73-de0360b30f44</guid>
      <dc:creator>Jiri Sykora</dc:creator>
      <dc:date>2021-12-17T00:00:00Z</dc:date>
    </item>
    <item>
      <title>This Week in Security News - December 17, 2021</title>
      <link>https://www.trendmicro.com/en_us/research/21/l/this-week-in-security-news-dec-17-2021.html</link>
      <description>This week, read on Purple Fox’s infection chain observed by Trend Micro’s Managed XDR. Also, learn about the Log4j vulnerability that has the potential to cause ‘incalculable’ damage.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/week-in-security-news.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Cloud</category>
      <category>Trend Micro Research : Exploits &amp; Vulnerabilities</category>
      <category>Trend Micro Research : Expert Perspective</category>
      <category>Trend Micro Research : Cyber Threats</category>
      <category>Trend Micro Research : Endpoints</category>
      <category>Trend Micro Research : IoT</category>
      <category>Trend Micro Research : Ransomware</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <pubDate>Fri, 17 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:590bd4e5-bd58-081d-030d-114b0ed4199f</guid>
      <dc:creator>Jon Clay</dc:creator>
      <dc:date>2021-12-17T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Why Log4j Mitigation Is Fraught With Challenges</title>
      <link>https://www.darkreading.com/application-security/why-log4j-mitigation-is-fraught-with-challenges</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt5772763d9c6d816c/61bbbd9d625ce7366d165486/Armis_-_Log4j_Attacked_Devices_at_IT_Environments.png" type="image/*" />
      <description>The Log4j flaw exists in a component that is not always easy to detect and is widely used beyond an organization's own networks and systems.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt02d79fb9a44a4258/60b1e9dd2a25046b35110696/Jai-Vijayan.jpeg" type="image/*" />
      <pubDate>Thu, 16 Dec 2021 23:15:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/application-security/why-log4j-mitigation-is-fraught-with-challenges</guid>
      <dc:creator>Jai Vijayan, Contributing Writer</dc:creator>
      <dc:date>2021-12-16T23:15:00Z</dc:date>
    </item>
    <item>
      <title>Phorpiex Botnet Variant Spread Across 96 Countries</title>
      <link>https://www.darkreading.com/attacks-breaches/phorpiex-botnet-variant-spread-across-96-countries</link>
      <description>A new variant dubbed "Twizt" has hijacked 969 transactions and stolen the equivalent of nearly $500,000 USD.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte161b23f0fd3a84b/60b1ea374e7eb868c4c6a293/dr_staff_125x125.jpg" type="image/*" />
      <pubDate>Thu, 16 Dec 2021 21:15:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/attacks-breaches/phorpiex-botnet-variant-spread-across-96-countries</guid>
      <dc:creator>Dark Reading Staff, Dark Reading</dc:creator>
      <dc:date>2021-12-16T21:15:00Z</dc:date>
    </item>
    <item>
      <title>S3 Ep63: Log4Shell (what else?) and Apple kernel bugs [Podcast+Transcript]</title>
      <link>https://nakedsecurity.sophos.com/2021/12/16/s3-ep63-log4shell-what-else-and-apple-kernel-bugs-podcasttranscript/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://nakedsecurity.sophos.com/2021/12/16/s3-ep63-log4shell-what-else-and-apple-kernel-bugs-podcasttranscript/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/09/ns-1200-logo-podcast-with-mic.png?w=230&amp;h=130&amp;crop=1" medium="image" />
      <post-id xmlns="com-wordpress:feed-additions:1">647542</post-id>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/09/ns-1200-logo-podcast-with-mic.png" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/09/ns-1200-logo-podcast-with-mic.png?w=170&amp;h=90&amp;crop=1" medium="image" />
      <description>Latest episode - listen now! (Yes, there are plenty of critical things to go along with Log4Shell.)</description>
      <category>Apple</category>
      <category>Podcast</category>
      <category>CVE-2021-44228</category>
      <category>Exploit</category>
      <category>iPhone</category>
      <category>jailbreak</category>
      <category>Log4Shell</category>
      <category>macOS</category>
      <category>Naked Security Podcast</category>
      <pubDate>Thu, 16 Dec 2021 19:41:40 GMT</pubDate>
      <comments>https://nakedsecurity.sophos.com/2021/12/16/s3-ep63-log4shell-what-else-and-apple-kernel-bugs-podcasttranscript/#respond</comments>
      <guid isPermaLink="false">https://nakedsecurity.sophos.com/?p=647542</guid>
      <dc:creator>Paul Ducklin</dc:creator>
      <dc:date>2021-12-16T19:41:40Z</dc:date>
    </item>
    <item>
      <title>The flawed cybersecurity of The Matrix | Kaspersky official blog</title>
      <link>https://www.kaspersky.com/blog/matrix-vulnerabilities/43168/</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/16131036/matrix-vulnerabilities-featured.jpg" width="1460" height="960">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/16131036/matrix-vulnerabilities-featured-1024x673.jpg" width="1024" height="673">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/16131036/matrix-vulnerabilities-featured-300x197.jpg" width="300" height="197">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/16131036/matrix-vulnerabilities-featured-150x150.jpg" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>Before the fourth installment of The Matrix premieres, we look at the snags and vulnerabilities in the AI-implemented metaverse.</description>
      <content:encoded>&lt;p&gt;The Matrix trilogy (The Matrix, The Matrix Reloaded, The Matrix Revolutions) told of the successful implementation of the metaverse before the idea went mainstream. The creator of this virtual world (or, rather, neural-interactive simulation), we learn, was an artificial intelligence that once defeated and enslaved humanity. The process was not without bugs, which brings us to today&amp;#8217;s topic.&lt;/p&gt;
&lt;p&gt;For starters, between the limited data human characters have and the constant misinformation from the AI, viewers never know precisely what&amp;#8217;s true, or how realistic their view of the world is at any given moment.&lt;/p&gt;
&lt;p&gt;But we are not interested in philosophical subtext here; our focus is on information security, so we will rely on what are considered the established facts at the end of the third movie. Spoiler alert for anyone who hasn&amp;#8217;t watched the whole trilogy but intends to.&lt;/p&gt;
&lt;h2&gt;Fighting the Zion Resistance&lt;/h2&gt;
&lt;p&gt;At the trilogy&amp;#8217;s finale, it becomes clear that the struggle with rebels infiltrating the Matrix is all staged. For the latest cycle of rebellion to succeed, the Matrix needs a certain number of external enemies, so we don&amp;#8217;t know for sure whether the agents are really trying to catch Morpheus and his team, or if they&amp;#8217;re just simulating a frenzy of activity. From a cybersecurity perspective, it&amp;#8217;s not clear whether we&amp;#8217;re seeing bugs or features — a design flaw or something deliberately introduced into the Matrix (perhaps as a sort of &lt;a href="https://encyclopedia.kaspersky.com/glossary/honeypot-glossary/" target="_blank" rel="noopener"&gt;honeypot&lt;/a&gt;).&lt;/p&gt;
&lt;h3&gt;Pirate signal from Resistance ships&lt;/h3&gt;
&lt;p&gt;The Matrix&amp;#8217;s population consists of avatars of enslaved humans who are wired to the system, and of programs that originally existed in the form of code. Why remote broadcasting of signals from outside the system was initially implemented, allowing third-party avatars to be uploaded, remains unclear.&lt;/p&gt;
&lt;p&gt;Such anomalies are usually a result of some sort of debug access that someone forgot to close, but in this case the developers were not human, so that explanation doesn&amp;#8217;t fit. Anyway, even if they implemented remote connection on purpose — if it was a feature, not a bug — why didn&amp;#8217;t the auto-programmers implement a firewall to block any pirate signals?&lt;/p&gt;
&lt;h3&gt;Uncontrolled avatar transmission system&lt;/h3&gt;
&lt;p&gt;Inside the Matrix, pirate avatars can appear and disappear only through phone cables (although how mobile and landline phones differ inside a virtual reality framework is not explained). Moreover, Matrix agents are, in principle, able to deactivate the line — at least, they cut it when Morpheus was captured. But if it is so critical for Matrix infiltration and exfiltration, why don&amp;#8217;t the agents ban it, or at least disable it throughout the operation zone?&lt;/p&gt;
&lt;h3&gt;Incomplete addressing system&lt;/h3&gt;
&lt;p&gt;Despite the objective need for such information, the Matrix lacks precise location data for each specific object inside virtual reality. We can assume that pirate avatars are able to hide their location in virtual space, but to stay on the tail of the still-connected Neo in the system, agents needed an additional tracking device. There&amp;#8217;s obviously a fault in the addressing system.&lt;/p&gt;
&lt;p&gt;That raises questions about Morpheus&amp;#8217; notorious red pill. In his words, it is a tracking program &amp;#8220;designed to disrupt your input/output carrier signals, so we can pinpoint your location.&amp;#8221; Why isn&amp;#8217;t the Matrix monitoring for such anomalies? Being able to intercept the &amp;#8220;rescue team&amp;#8221; seems pretty important.&lt;/p&gt;
&lt;h3&gt;Artificial constraints on Matrix Agents&lt;/h3&gt;
&lt;p&gt;Matrix agents are AIs that can temporarily replace the avatar of any human connected to the system. They can violate the conventional laws of physics, but only up to a point. The twins from the second part of the trilogy are far less impeded by physics, so why can&amp;#8217;t such conditional constraints be lifted, at least temporarily, during the operation to capture perpetrators?&lt;br /&gt;
Adding to the mounting errors in their code, for some reason agents have the ability to disconnect from the Matrix information system simply by removing their earpieces, a clear vulnerability if ever there was one.&lt;/p&gt;
&lt;h3&gt;Zion mainframe codes&lt;/h3&gt;
&lt;p&gt;The whole point of the machines&amp;#8217; hunt for Morpheus in the first movie was to gain the access codes to the Zion mainframe, which every captain knows. That raises a host of questions about why the person with the access codes to the rebels&amp;#8217; critical infrastructure would also be the one who goes into the Matrix.&lt;/p&gt;
&lt;p&gt;That point is especially strange if one recalls that there are people on board without any interface for connecting to the Matrix. Entrusting valuable information to them would obviously be far safer. It&amp;#8217;s a misstep by the liberated humans, plain and simple: equivalent in today&amp;#8217;s real world to attaching a sticky note with passwords to your monitor and then giving a TV interview with it in the background.&lt;/p&gt;
&lt;h2&gt;Rogue software&lt;/h2&gt;
&lt;p&gt;For some reason, the Matrix is unable to effectively get rid of programs that are no longer required. Lurking deep inside are various smart apps from old versions of the Matrix: information smugglers, semiphysical militants, a program called Seraph that defines its function as &amp;#8220;I protect that which matters most&amp;#8221; (a predictable slogan for any information security company).&lt;/p&gt;
&lt;p&gt;According to the Oracle, they should all have been removed, but instead they chose to disconnect from the system and live autonomously inside the virtual reality. The existence of uncontrolled obsolete software is a clear vulnerability, just as it is in real life. They &lt;em&gt;literally&lt;/em&gt; help hackers attack the Matrix!&lt;/p&gt;
&lt;h3&gt;Software smuggling&lt;/h3&gt;
&lt;p&gt;Some programs exist exclusively in the &amp;#8220;world of machines&amp;#8221; yet can be smuggled in to the virtual world of the Matrix, which human avatars can inhabit. The ability to bring in such programs highlights some serious system segmentation issues. In particular, a direct communication channel should not exist between two segments designed to be isolated.&lt;/p&gt;
&lt;h2&gt;Backdoor corridor&lt;/h2&gt;
&lt;p&gt;Among the exiles is the Keymaker program, which creates keys for backdoors. We don&amp;#8217;t know to what extent the Keymaker actually is an exile — perhaps he, like the Oracle, is part of the system to control the rebels through the Chosen One. Not only does the Keymaker cut access keys using a file and a lathe, but it also informs hackers of the existence of a whole corridor of backdoors granting access to different parts of the Matrix, from the Core Network to the Source, the heart of the system. Both the Keymaker and the corridor pose a fundamental security threat to the entire system, especially considering how it&amp;#8217;s protected against outsiders.&lt;/p&gt;
&lt;p&gt;The main problem with the corridor&amp;#8217;s security is that for some reason it exists according to the notional laws of the virtual world, depending on emulated power plants (that do not actually produce power) and computers at these virtual stations. And these laws in the Matrix, as we know, are notoriously easy to break. Even putting an agent in the corridor would be more effective — so why didn&amp;#8217;t they? No money to pay its salary?&lt;/p&gt;
&lt;h2&gt;Clones of Agent Smith&lt;/h2&gt;
&lt;p&gt;Matrix agents originally had a feature that let them replace the avatar code of any hardwired human. However, agents have always existed as individual copies. At the end of the first movie, Neo, having acquired anomalous abilities, infiltrates Agent Smith and tries to destroy him from the inside, with some part of the code of Neo&amp;#8217;s avatar being transferred into the agent&amp;#8217;s code. After that, Smith goes haywire and gains the ability to bypass artificial constraints, both the laws of the physical world and the ban on existing in one copy. In other words, he becomes a full-fledged virus.&lt;/p&gt;
&lt;p&gt;By all appearances, Smith is the first virus in the Matrix; otherwise, there is no explanation for why the system has no antivirus solution for tracking software anomalies, isolating and removing dangerous applications that threaten the security of the system. Considering that most of the people freed from the Matrix are hackers, we find that very odd. &lt;/p&gt;
&lt;p&gt;Be that as it may, the existence of Smith, now able to copy his code into any avatar or program, serves as an argument in Neo&amp;#8217;s negotiations with the AI. In the end, Neo physically connects to the Matrix, allows Smith to &amp;#8220;infect&amp;#8221; his avatar, connects to the Smith-net, and destroys all of the Smiths.&lt;/p&gt;
&lt;p&gt;As a result, the machines agree to a truce, to stop exterminating humans, and even to release those who don&amp;#8217;t want to live in the Matrix. But they could have just built a &lt;a href="https://os.kaspersky.com/?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder____&amp;utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=gl_wpplaceholder_nv0092&amp;utm_content=link&amp;utm_term=gl_kdaily_organic_e5924wkogrsrnx0" target="_blank"&gt;secure operating system&lt;/a&gt; from the start, or at least used a &lt;a href="https://www.kaspersky.com/small-to-medium-business-security?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______" target="_blank"&gt;reliable security solution&lt;/a&gt; in combination with an &lt;a href="https://www.kaspersky.com/enterprise-security/endpoint-detection-response-edr?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______" target="_blank"&gt;EDR system&lt;/a&gt; capable of tracking network anomalies!&lt;/p&gt;
&lt;input type="hidden" class="category_for_banner" value="kesb-top3" /&gt;</content:encoded>
      <category>Business</category>
      <category>Enterprise</category>
      <category>movies</category>
      <category>The Matrix</category>
      <category>truth</category>
      <category>vulnerabilities</category>
      <pubDate>Thu, 16 Dec 2021 18:12:38 GMT</pubDate>
      <guid isPermaLink="false">https://www.kaspersky.com/blog/?p=43168</guid>
      <dc:creator>Nikolay Pankov</dc:creator>
      <dc:date>2021-12-16T18:12:38Z</dc:date>
    </item>
    <item>
      <title>Log4Shell: The Big Picture</title>
      <link>https://www.darkreading.com/vulnerabilities-threats/log4shell-the-big-picture</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte0f9169d7cc2f4fa/61ba23f74b727d376d0c480a/Alert_Skorzewiak_Alamy.jpg" type="image/*" />
      <description>A look at why this is such a tricky vulnerability and why the industry response has been good, but not great.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte7ddea7da43c74dd/61b8fc610c86f53774da5c83/richard-ford-headshot.png" type="image/*" />
      <pubDate>Thu, 16 Dec 2021 18:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/vulnerabilities-threats/log4shell-the-big-picture</guid>
      <dc:creator>Richard Ford, Chief Technology Officer, Praetorian</dc:creator>
      <dc:date>2021-12-16T18:00:00Z</dc:date>
    </item>
    <item>
      <title>NY Man Pleads Guilty in $20 Million SIM Swap Theft</title>
      <link>https://krebsonsecurity.com/2021/12/ny-man-pleads-guilty-in-20-million-sim-swap-theft/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://krebsonsecurity.com/2021/12/ny-man-pleads-guilty-in-20-million-sim-swap-theft/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">29</slash:comments>
      <description>A 24-year-old New York man who bragged about helping to steal more than $20 million worth of cryptocurrency from a technology executive has pleaded guilty to conspiracy to commit wire fraud. Nicholas Truglia was part of a group alleged to have stolen more than $100 million from cryptocurrency investors using fraudulent "SIM swaps," scams in which identity thieves hijack a target’s mobile phone number and use that to wrest control over the victim’s online identities.</description>
      <content:encoded>&lt;p&gt;A 24-year-old New York man who bragged about helping to steal more than $20 million worth of cryptocurrency from a technology executive has pleaded guilty to conspiracy to commit wire fraud. &lt;strong&gt;Nicholas Truglia&lt;/strong&gt; was part of a group alleged to have stolen more than $100 million from cryptocurrency investors using fraudulent &amp;#8220;SIM swaps,&amp;#8221; scams in which identity thieves hijack a target’s mobile phone number and use that to wrest control over the victim’s online identities.&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" class="aligncenter wp-image-40415" src="https://krebsonsecurity.com/wp-content/uploads/2017/08/phonefraudsmaller.png" alt="" width="759" height="383" srcset="https://krebsonsecurity.com/wp-content/uploads/2017/08/phonefraudsmaller.png 609w, https://krebsonsecurity.com/wp-content/uploads/2017/08/phonefraudsmaller-580x292.png 580w" sizes="(max-width: 759px) 100vw, 759px" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Truglia&lt;/strong&gt; &lt;a href="https://krebsonsecurity.com/wp-content/uploads/2021/12/trugliaadmission.png" target="_blank" rel="noopener"&gt;admitted&lt;/a&gt; to a New York federal court that he let a friend use his account at crypto-trading platform &lt;strong&gt;Binance&lt;/strong&gt; in 2018 to launder more than $20 million worth of virtual currency stolen from &lt;strong&gt;Michael Terpin&lt;/strong&gt;, a cryptocurrency investor who co-founded the first angel investor group for bitcoin enthusiasts.&lt;/p&gt;
&lt;p&gt;Following the theft, Terpin filed a civil lawsuit against Truglia with the Los Angeles Superior court. In May 2019, the jury awarded Terpin a $75.8 million judgment against Truglia. In January 2020, a New York grand jury &lt;a href="https://krebsonsecurity.com/wp-content/uploads/2021/12/trugliaIndictment.pdf" target="_blank" rel="noopener"&gt;criminally indicted Truglia&lt;/a&gt; (PDF) for his part in the crypto theft from Terpin.&lt;/p&gt;
&lt;p&gt;A SIM card is the tiny, removable chip in a mobile device that allows it to connect to the provider’s network. Customers can legitimately request a SIM swap when their mobile device has been damaged or lost, or when they are switching to a different phone that requires a SIM card of another size.&lt;/p&gt;
&lt;div id="attachment_57927" style="width: 308px" class="wp-caption alignright"&gt;&lt;img aria-describedby="caption-attachment-57927" loading="lazy" class=" wp-image-57927" src="https://krebsonsecurity.com/wp-content/uploads/2021/12/truglia.png" alt="" width="298" height="249" /&gt;&lt;p id="caption-attachment-57927" class="wp-caption-text"&gt;Nicholas Truglia, holding bottle. Image: twitter.com/erupts&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;But fraudulent SIM swaps are frequently abused by scam artists who trick mobile providers into tying a target’s service to a new SIM card and mobile phone controlled by the scammers. Unauthorized SIM swaps often are perpetrated by fraudsters who have already stolen or phished a target’s password, as many financial institutions and online services rely on text messages to send users a one-time code for multi-factor authentication.&lt;/p&gt;
&lt;p&gt;Compounding the threat, many websites let customers reset their passwords merely by clicking a link sent via SMS to the mobile phone number tied to the account, meaning anyone who controls that phone number can reset the passwords for those accounts.&lt;/p&gt;
&lt;p&gt;Reached for comment, Terpin said his assailant got off easy.&lt;/p&gt;
&lt;p&gt;&amp;#8220;I am outraged that after nearly four years and hundreds of pages of evidence that the best the prosecutors could recommend was a plea bargain for a single, relatively minor count of the unauthorized use of a Binance exchange account, when all the evidence points toward Truglia being one of two masterminds of a wide-ranging criminal conspiracy to steal crypto from me and others,&amp;#8221; Terpin told KrebsOnSecurity.&lt;/p&gt;
&lt;p&gt;Terpin said public court records already show Truglia bragging about stealing his funds and using it to finance a lavish lifestyle.&lt;/p&gt;
&lt;p&gt;&amp;#8220;He at the very least withdrew 100 bitcoin (worth $1.6 million at the time and nearly $5 million today) from my theft into his wallet at a separate, US-based exchange, and then moved or spent it,&amp;#8221; Terpin said. &amp;#8220;The fact is that the intentional theft of $24 million, whether taken at the point of a gun in a bank or through a SIM card swap, is a major felony. Truglia should be prosecuted to the fullest extent of the law.&amp;#8221;&lt;/p&gt;
&lt;div id="attachment_57938" style="width: 755px" class="wp-caption aligncenter"&gt;&lt;img aria-describedby="caption-attachment-57938" loading="lazy" class=" wp-image-57938" src="https://krebsonsecurity.com/wp-content/uploads/2021/12/trugliaplane.png" alt="" width="745" height="686" /&gt;&lt;p id="caption-attachment-57938" class="wp-caption-text"&gt;Nicholas Truglia, showing off a diamond-studded Piaget watch while aboard a private jet. Image: twitter.com/erupts.&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;&lt;span id="more-57917"&gt;&lt;/span&gt;Terpin also is waging an ongoing civil lawsuit against 18-year-old &lt;strong&gt;Ellis Pinsky&lt;/strong&gt;, who&amp;#8217;s accused of working with Truglia as part of a SIM swapping crew that has stolen more than $100 million in cryptocurrency. According to Terpin, Pinsky was 15 when he took part in the $24 million 2018 SIM swap, but he returned $2 million worth of cryptocurrency after being confronted by Terpin&amp;#8217;s investigators.&lt;/p&gt;
&lt;p&gt;&amp;#8220;On the surface, Pinsky is an &amp;#8216;All American Boy,'&amp;#8221; Terpin&amp;#8217;s civil suit charges. &amp;#8220;The son of privilege, he is active in extracurricular activities and lives a suburban life with a doting mother who is a prominent doctor.&amp;#8221;&lt;/p&gt;
&lt;p&gt;&amp;#8220;Despite their wholesome appearances, Pinsky and his other cohorts are in fact evil computer geniuses with sociopathic traits who heartlessly ruin their innocent victims’ lives and gleefully boast of their multi-million-dollar heists,&amp;#8221; the lawsuit continues. &amp;#8220;Pinsky is reputed to have used his ill-gotten gains to purchase multi-million-dollar watches and is known to go on nightclub sprees at high end clubs in New York City, and Truglia rented private jets and played the part of a dashing playboy with young women pampering him.&amp;#8221;&lt;/p&gt;
&lt;p&gt;Pinksy could not be immediately reached for comment. But a review of the latest filings in the lawsuit show that Pinsky&amp;#8217;s attorneys stopped representing him because he no longer had the funds to pay for their services. The most recent entry in the New York Southern District&amp;#8217;s docket asks the court to give Pinsky additional time to seek counsel, and hints that barring that he may end up representing himself.&lt;/p&gt;
&lt;div id="attachment_57929" style="width: 756px" class="wp-caption aligncenter"&gt;&lt;img aria-describedby="caption-attachment-57929" loading="lazy" class=" wp-image-57929" src="https://krebsonsecurity.com/wp-content/uploads/2021/12/pinsky.png" alt="" width="746" height="448" /&gt;&lt;p id="caption-attachment-57929" class="wp-caption-text"&gt;Ellis Pinsky, in a photo uploaded to his social media profile.&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;Truglia is still being criminally prosecuted in Santa Clara, Calif., the home of the &lt;a href="https://krebsonsecurity.com/2018/11/busting-sim-swappers-and-sim-swap-myths/" target="_blank" rel="noopener"&gt;REACT task force&lt;/a&gt;, which pursues SIM-swapping cases nationwide. In November 2018, REACT investigators and New York authorities &lt;a href="https://nypost.com/2018/11/20/man-hacked-into-silicon-valley-execs-phones-to-steal-cryptocurrency-cops/" target="_blank" rel="noopener"&gt;arrested Truglia&lt;/a&gt; on suspicion of using SIM swaps to steal approximately $1 million worth of cryptocurrencies from &lt;strong&gt;Robert Ross&lt;/strong&gt;, a San Francisco father of two who later went on to found the victim advocacy website &lt;a href="https://www.stopsimcrime.org" target="_blank" rel="noopener"&gt;stopsimcrime.org&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;According to &lt;a href="https://nypost.com/2018/11/20/man-hacked-into-silicon-valley-execs-phones-to-steal-cryptocurrency-cops/" target="_blank" rel="noopener"&gt;published reports&lt;/a&gt;, Truglia and his accomplices also perpetrated SIM swaps against the CEO of the blockchain storage service 0Chain; hedge-funder Myles Danielson, vice president of Hall Capital Partners; and Gabrielle Katsnelson, the co-founder of the startup SMBX.&lt;/p&gt;
&lt;p&gt;Truglia is currently slated to be sentenced in April 2022 for his guilty plea in New York. He faces a maximum sentence of up to 20 years in prison.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Erin West&lt;/strong&gt;, deputy district attorney for Santa Clara County, told KrebsOnSecurity that SIM swapping remains a major problem. But she said many of the victims they&amp;#8217;re now assisting are relatively new cryptocurrency investors for whom a SIM swapping attack can be financially devastating.&lt;/p&gt;
&lt;p&gt;&amp;#8220;Originally, the SIM swap targets were the early adopters of crypto,&amp;#8221; West said. &amp;#8220;Now we&amp;#8217;re seeing a lot more of what I would call normal people trying their hand at crypto, and that makes a lot more people a target. It makes people who are unfamiliar with their personal security online vulnerable to hackers whose entire job is to figure out how to part people from their money.&amp;#8221;&lt;/p&gt;
&lt;p&gt;West said REACT continues to train state and local law enforcement officials across the country on how to successfully investigate and prosecute SIM swapping cases.&lt;/p&gt;
&lt;p&gt;&amp;#8220;The good news is our partners across the nation are learning how to conduct these cases,&amp;#8221; she said. &amp;#8220;Where this was a relatively new phenomenon three years ago, other smaller jurisdictions around the country are now learning how to prosecute this crime.&amp;#8221;&lt;/p&gt;
&lt;p&gt;All of the major wireless carriers let customers add security against SIM swaps and related schemes by setting a PIN that needs to be provided over the phone or in person at a store before account changes should be made. But these security features can be bypassed by incompetent or &lt;a href="https://krebsonsecurity.com/2018/05/t-mobile-employee-made-unauthorized-sim-swap-to-steal-instagram-account/" target="_blank" rel="noopener"&gt;corrupt&lt;/a&gt; &lt;a href="https://krebsonsecurity.com/2018/08/florida-man-arrested-in-sim-swap-conspiracy/" target="_blank" rel="noopener"&gt;mobile store employees&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;For some tips on how to minimize your chances of becoming the next SIM swapping victim, check out the “What Can You Do?” section at &lt;a href="https://krebsonsecurity.com/2018/08/hanging-up-on-mobile-in-the-name-of-security/" target="_blank" rel="noopener"&gt;the conclusion of this story&lt;/a&gt;.&lt;/p&gt;</content:encoded>
      <category>Ne'er-Do-Well News</category>
      <category>SIM Swapping</category>
      <category>Ellis Pinsky</category>
      <category>Erin West</category>
      <category>Michael Terpin</category>
      <category>Nicholas Truglia</category>
      <category>REACT Task Force</category>
      <category>Robert Ross</category>
      <category>SIM swapping</category>
      <category>stopsimcrime.com</category>
      <pubDate>Thu, 16 Dec 2021 17:52:03 GMT</pubDate>
      <comments>https://krebsonsecurity.com/2021/12/ny-man-pleads-guilty-in-20-million-sim-swap-theft/#comments</comments>
      <guid isPermaLink="false">https://krebsonsecurity.com/?p=57917</guid>
      <dc:creator>BrianKrebs</dc:creator>
      <dc:date>2021-12-16T17:52:03Z</dc:date>
    </item>
    <item>
      <title>Free eBook! Ransomware – how to stop it, and how to survive an attack</title>
      <link>https://grahamcluley.com/feed-sponsor-recorded-future-30/</link>
      <description>Graham Cluley Security News is sponsored this week by the folks at Recorded Future. Thanks to the great team there for their support! Ransomware attacks dominate the cybersecurity news headlines, with businesses all over the world wondering if they will be the next victim. It’s a legitimate, and growing fear, as the attackers get more &amp;#8230; &lt;a href="https://grahamcluley.com/feed-sponsor-recorded-future-30/" class="more-link"&gt;Continue reading&lt;span class="screen-reader-text"&gt; "Free eBook! Ransomware &amp;#8211; how to stop it, and how to survive an attack"&lt;/span&gt;&lt;/a&gt;</description>
      <category>Feed only</category>
      <pubDate>Thu, 16 Dec 2021 16:10:07 GMT</pubDate>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333606</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-12-16T16:10:07Z</dc:date>
    </item>
    <item>
      <title>More Log4j News</title>
      <link>https://www.schneier.com/blog/archives/2021/12/more-log4j-news.html</link>
      <thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">25</thr:total>
      <description>&lt;p&gt;Log4j is &lt;a href="https://www.zdnet.com/article/log4j-flaw-nearly-half-of-corporate-networks-have-been-targeted-by-attackers-trying-to-use-this-vulnerability/"&gt;being exploited&lt;/a&gt; by all sorts of attackers, all over the Internet:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;At that point it was reported that there were over 100 attempts to exploit the vulnerability every minute. &amp;#8220;Since we started to implement our protection we prevented over 1,272,000 attempts to allocate the vulnerability, over 46% of those attempts were made by known malicious groups,&amp;#8221; said cybersecurity company Check Point.&lt;/p&gt;
&lt;p&gt;And according to Check Point, attackers have now attempted to exploit the flaw on over 40% of global networks.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;And a &lt;a href="https://www.zdnet.com/article/second-log4j-vulnerability-found-apache-log4j-2-16-0-released/"&gt;second&lt;/a&gt; &lt;a href="https://arstechnica.com/information-technology/2021/12/patch-fixing-critical-log4j-0-day-has-its-own-vulnerability-thats-under-exploit/"&gt;vulnerability&lt;/a&gt; was found, in the patch for the first vulnerability. This is likely not to be the last...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Log4j is &lt;a href="https://www.zdnet.com/article/log4j-flaw-nearly-half-of-corporate-networks-have-been-targeted-by-attackers-trying-to-use-this-vulnerability/"&gt;being exploited&lt;/a&gt; by all sorts of attackers, all over the Internet:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;At that point it was reported that there were over 100 attempts to exploit the vulnerability every minute. &amp;#8220;Since we started to implement our protection we prevented over 1,272,000 attempts to allocate the vulnerability, over 46% of those attempts were made by known malicious groups,&amp;#8221; said cybersecurity company Check Point.&lt;/p&gt;
&lt;p&gt;And according to Check Point, attackers have now attempted to exploit the flaw on over 40% of global networks.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;And a &lt;a href="https://www.zdnet.com/article/second-log4j-vulnerability-found-apache-log4j-2-16-0-released/"&gt;second&lt;/a&gt; &lt;a href="https://arstechnica.com/information-technology/2021/12/patch-fixing-critical-log4j-0-day-has-its-own-vulnerability-thats-under-exploit/"&gt;vulnerability&lt;/a&gt; was found, in the patch for the first vulnerability. This is likely not to be the last.&lt;/p&gt;</content:encoded>
      <category domain="https://www.schneier.com">Uncategorized</category>
      <category domain="https://www.schneier.com">data protection</category>
      <category domain="https://www.schneier.com">patching</category>
      <category domain="https://www.schneier.com">vulnerabilities</category>
      <category domain="https://www.schneier.com">zero-day</category>
      <pubDate>Thu, 16 Dec 2021 15:50:29 GMT</pubDate>
      <guid isPermaLink="false">https://www.schneier.com/?p=64660</guid>
      <dc:creator>Bruce Schneier</dc:creator>
      <dc:date>2021-12-16T15:50:29Z</dc:date>
    </item>
    <item>
      <title>Dear Congress: It's Complicated. Please Consider This When Crafting New Cybersecurity Legislation</title>
      <link>https://www.darkreading.com/risk/dear-congress-it-s-complicated-please-consider-this-when-crafting-new-cybersecurity-legislation</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt3c183202d854aed2/61b3acd2165ecc7460180133/Capitol_efaah0_Alamy.jpg" type="image/*" />
      <description>As mandatory reporting bills work their way through the halls of Congress, what should businesses do to prepare for this pending legislation?</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte6d96f8d9b97dae7/61b3822e165ecc7460180123/Lyndon_Headshot.png" type="image/*" />
      <pubDate>Thu, 16 Dec 2021 15:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/risk/dear-congress-it-s-complicated-please-consider-this-when-crafting-new-cybersecurity-legislation</guid>
      <dc:creator>Lyndon Brown, Chief Strategy Officer, Pondurance</dc:creator>
      <dc:date>2021-12-16T15:00:00Z</dc:date>
    </item>
    <item>
      <title>The DHS is inviting hackers to break into its systems, but there are rules of engagement</title>
      <link>https://www.tripwire.com/state-of-security/government/the-dhs-is-inviting-hackers-to-break-into-its-systems-but-there-are-rules-of-engagement/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://www.tripwire.com/state-of-security/government/the-dhs-is-inviting-hackers-to-break-into-its-systems-but-there-are-rules-of-engagement/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <description>The United States Department of Homeland Security (DHS) is inviting security researchers to uncover vulnerabilities and hack into its systems, in an attempt to better protect itself from malicious attacks.

Read more in my article on the Tripwire State of Security blog.</description>
      <category>Guest blog</category>
      <category>Vulnerability</category>
      <category>bug bounty</category>
      <category>Department of Homeland Security</category>
      <category>vulnerability</category>
      <pubDate>Thu, 16 Dec 2021 14:45:51 GMT</pubDate>
      <comments>https://www.tripwire.com/state-of-security/government/the-dhs-is-inviting-hackers-to-break-into-its-systems-but-there-are-rules-of-engagement/#respond</comments>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333602</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-12-16T14:45:51Z</dc:date>
    </item>
    <item>
      <title>Fat finger sells NFT for fraction of price | Kaspersky official blog</title>
      <link>https://www.kaspersky.com/blog/transatlantic-cable-podcast-232/43161/</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/16065428/transatlantic-cable-podcast-232-featured.jpg" width="1460" height="960">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/16065428/transatlantic-cable-podcast-232-featured-1024x673.jpg" width="1024" height="673">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/16065428/transatlantic-cable-podcast-232-featured-300x197.jpg" width="300" height="197">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/16065428/transatlantic-cable-podcast-232-featured-150x150.jpg" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>This week on the Kaspersky podcast, Dave and Jeff discuss how a fat-fingered mistake cost an NFT owner a lot of money, Instagram improvements for teens, Log4J, and more.</description>
      <content:encoded>&lt;p&gt;This week on the &lt;a href="https://www.kaspersky.com/blog/?s=podcast" target="_blank" rel="noopener"&gt;Kaspersky &lt;em&gt;Transatlantic Cable&lt;/em&gt; podcast&lt;/a&gt;, our good friend Ahmed is a bit under the weather, so we return temporarily to our original podcast lineup.&lt;/p&gt;
&lt;p&gt;We jump right in with the story everyone&amp;#8217;s been talking about: Log4J. We start out with an overview of what is going on there and then hop into a second story about botnets leveraging the vulnerability. After that, we discuss a case of fat fingers causing an NFT to be sold for $3,000 — sounds like no big deal, but it was valued at $300,000. Once that cheap sales went through, the item was flipped for a whole lot more money. Talk about an oopsie.&lt;/p&gt;
&lt;blockquote class="twitter-tweet" data-width="500" data-dnt="true"&gt;
&lt;p lang="en" dir="ltr"&gt;This log4j (CVE-2021-44228) vulnerability is extremely bad. Millions of applications use Log4j for logging, and all the attacker needs to do is get the app to log a special string. So far iCloud, Steam, and Minecraft have all been confirmed vulnerable.&lt;/p&gt;
&lt;p&gt;&amp;#8212; Marcus Hutchins (@MalwareTechBlog) &lt;a href="https://twitter.com/MalwareTechBlog/status/1469289471463944198?ref_src=twsrc%5Etfw"&gt;December 10, 2021&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;&lt;script async src="https://platform.twitter.com/widgets.js" charset="utf-8"&gt;&lt;/script&gt;&lt;/p&gt;
&lt;p&gt;From there, our discussion shifts to Instagram. Prior to its grilling by the US Congress, the social network announced some changes to the platform. The changes aim to improve users&amp;#8217; experiences and avoid some of the associated harms such as bullying, damage to self-image, and more. Dave and I debate a bit whether it&amp;#8217;s just a PR stunt or something that will really benefit society.&lt;/p&gt;
&lt;p&gt;Our fourth story has us diving into a lawsuit Google filed against some hackers. The problem is that it appears largely symbolic.&lt;/p&gt;
&lt;p&gt;For our final story, we head to China, where a man stole more than $20,000 from an ex-girlfriend by unlocking her phone and bank account while she was sleeping — creepy! And to close out the podcast for the year, we offer some tips for anyone who gets new electronics over the holidays.&lt;/p&gt;
&lt;p&gt;If you liked what you heard, please consider subscribing and sharing with your friends. For more information on the stories we covered, see the links below:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.zdnet.com/article/log4j-rce-activity-began-on-december-1-as-botnets-start-using-vulnerability/" target="_blank" rel="noopener"&gt;Log4j RCE activity began on December 1 as botnets start using vulnerability&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://threatpost.com/log4shell-attacks-origin-botnet/176977/" target="_blank" rel="noopener"&gt;Where the latest Log4Shell attacks are coming from&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.bbc.com/news/technology-59638565" target="_blank" rel="noopener"&gt;Bored Ape NFT accidentally sells for $3,000 instead of $300,000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.bbc.com/news/technology-59565631" target="_blank" rel="noopener"&gt;Instagram announces changes ahead of political grilling&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.bbc.com/news/world-us-canada-59571417" target="_blank" rel="noopener"&gt;Google sues alleged Russian cyber criminals&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nypost.com/2021/12/13/man-steals-23k-using-exs-phone-through-facial-recognition-report/" target="_blank" rel="noopener"&gt;Man stole $23K using ex&amp;#8217;s phone through facial recognition while she slept: report&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;#160;&lt;br /&gt;
&lt;iframe src="//html5-player.libsyn.com/embed/episode/id/21504437/height/90/theme/custom/thumbnail/yes/direction/backward/render-playlist/no/custom-color/00a88e/" frameborder="0" scrolling="no" marginwidth="0" marginheight="0"  width="100%" height="90px"&gt;&lt;/iframe&gt;&lt;/p&gt;
&lt;div class="podcast-subscribe"&gt;&lt;a data-omniture-download-button-type="TrialBuilds" data-omniture-product-name="podcast-itunes" class="itunes" href="https://itunes.apple.com/us/podcast/talk-security/id909407206" target="_blank"&gt;&lt;img src="https://www.kaspersky.com/blog/wp-content/plugins/kaspersky-embeds/img/button-subscribe-apple.png" /&gt;&lt;/a&gt;&lt;a data-omniture-download-button-type="TrialBuilds" data-omniture-product-name="podcast-spotify" class="spotify" href="https://open.spotify.com/show/1VGCKlOoQ9C24dJiCHGTK5" target="_blank"&gt;&lt;img src="https://www.kaspersky.com/blog/wp-content/plugins/kaspersky-embeds/img/button-subscribe-spotify.png" /&gt;&lt;/a&gt;&lt;a data-omniture-download-button-type="TrialBuilds" data-omniture-product-name="podcast-googleplay" class="google" href="https://play.google.com/music/m/Iyc2gocjmpw44j4aafwzvd4uwee?t=Transatlantic_Cable_Podcast" target="_blank"&gt;&lt;img src="https://www.kaspersky.com/blog/wp-content/plugins/kaspersky-embeds/img/button-subscribe-google.png" /&gt;&lt;/a&gt;&lt;a data-omniture-download-button-type="TrialBuilds" data-omniture-product-name="podcast-rss" class="rss" href="http://talksecurity.kaspersky-podcasts.libsynpro.com/rss" target="_blank"&gt;&lt;img src="https://www.kaspersky.com/blog/wp-content/plugins/kaspersky-embeds/img/button-subscribe-rss.png" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;p&gt;&amp;#160;&lt;br /&gt;
&lt;input type="hidden" class="category_for_banner" value="ksc-trial-generic" /&gt;&lt;/p&gt;</content:encoded>
      <category>News</category>
      <category>podcast</category>
      <pubDate>Thu, 16 Dec 2021 11:55:41 GMT</pubDate>
      <guid isPermaLink="false">https://www.kaspersky.com/blog/?p=43161</guid>
      <dc:creator>Jeffrey Esposito</dc:creator>
      <dc:date>2021-12-16T11:55:41Z</dc:date>
    </item>
    <item>
      <title>Irish health service missed several chances to stop devastating ransomware attack</title>
      <link>https://www.computing.co.uk/news/4042136/irish-health-service-missed-chances-stop-devastating-ransomware-attack</link>
      <description>&lt;img alt="Irish health service missed several chances to stop devastating ransomware attack" src="https://www.computing.co.uk/api/v1/wps/36e2efc/02e2bb72-6c8f-44be-a73e-4e1014ffdf86/7/hse-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Service has 'a very low level of cybersecurity maturity' finds PwC &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Thu, 16 Dec 2021 09:30:48 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4042136/irish-health-service-missed-chances-stop-devastating-ransomware-attack</guid>
      <dc:date>2021-12-16T09:30:48Z</dc:date>
    </item>
    <item>
      <title>Rise in API-Based Attacks Underscore Investments in New Tools</title>
      <link>https://www.darkreading.com/emerging-tech/rise-in-api-based-attacks-underscore-investments-in-new-tools</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltac279a328e97c1d4/614b45ddef0b985fd46f1826/Slide4_Mobile-App_alexsl_iStock_000073915835_Medium.png" type="image/*" />
      <description>Noname Security's Series C fundraising tips the startup to over $1 billion in valuation -- a sign that organizations are beginning to look for API security tools and investors are looking for innovation in the space.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt93784ffee79538e7/60d4371522d24e38a3806ecf/fahmida.png" type="image/*" />
      <pubDate>Thu, 16 Dec 2021 01:30:32 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/emerging-tech/rise-in-api-based-attacks-underscore-investments-in-new-tools</guid>
      <dc:creator>Fahmida Y. Rashid, Features Editor, Dark Reading</dc:creator>
      <dc:date>2021-12-16T01:30:32Z</dc:date>
    </item>
    <item>
      <title>Smashing Security podcast #256: Virgin Media just won’t take no for an answer, NFT apes, and bad optics</title>
      <link>https://grahamcluley.com/smashing-security-podcast-256/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://grahamcluley.com/smashing-security-podcast-256/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <description>After a brief discussion of the Log4Shell vulnerability panic, we chat about how Virgin Media has got itself into hot water, a fat-fingered fumble at the Bored Ape Yacht Club, and how to hack around your sleeping girlfriend's facial recognition.

All this and more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.</description>
      <enclosure url="https://aphid.fireside.fm/d/1437767933/dd3252a8-95c3-41f8-a8a0-9d5d2f9e0bc6/cc38c94b-b498-4fc6-920e-f4fb08ac7e0a.mp3" type="audio/mpeg" />
      <category>Law &amp; order</category>
      <category>Mobile</category>
      <category>Podcast</category>
      <category>Spam</category>
      <category>Vulnerability</category>
      <category>facial recognition</category>
      <category>log4j</category>
      <category>log4shell</category>
      <category>NFT</category>
      <category>Smashing Security</category>
      <category>Virgin Media</category>
      <category>vulnerability</category>
      <pubDate>Thu, 16 Dec 2021 00:08:09 GMT</pubDate>
      <comments>https://grahamcluley.com/smashing-security-podcast-256/#respond</comments>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333588</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-12-16T00:08:09Z</dc:date>
    </item>
    <item>
      <title>Original Fix for Log4j Flaw Fails to Fully Protect Against DoS Attacks, Data Theft</title>
      <link>https://www.darkreading.com/application-security/original-fix-for-log4j-flaw-fails-to-fully-protect-against-dos-attacks-data-theft</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte15683317a3a8309/61ba6f25670bc637d59bb512/log4j_Mashka_shutterstock.jpg" type="image/*" />
      <description>Organizations should upgrade ASAP to new version of logging framework released Tuesday by the Apache Foundation, security experts say.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt02d79fb9a44a4258/60b1e9dd2a25046b35110696/Jai-Vijayan.jpeg" type="image/*" />
      <pubDate>Wed, 15 Dec 2021 23:11:32 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/application-security/original-fix-for-log4j-flaw-fails-to-fully-protect-against-dos-attacks-data-theft</guid>
      <dc:creator>Jai Vijayan, Contributing Writer</dc:creator>
      <dc:date>2021-12-15T23:11:32Z</dc:date>
    </item>
    <item>
      <title>Companies Must Assess Threats to AI &amp; ML Systems in 2022: Microsoft</title>
      <link>https://www.darkreading.com/risk/companies-must-assess-threats-to-ai-ml-systems-in-2022-microsoft</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte4689bb9d4891a78/61ba7e150c86f53774da5d45/MachineLearning_AlexeyKotelnikov_Alamy.jpg" type="image/*" />
      <description>Most companies lack the proper tools to assess their vulnerability to threats facing their AI systems and ML pipelines, prompting Microsoft to release a risk assessment framework.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt58481326324d6911/60b1e9a55d34de550780a990/Robert-Lemos.png" type="image/*" />
      <pubDate>Wed, 15 Dec 2021 23:09:30 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/risk/companies-must-assess-threats-to-ai-ml-systems-in-2022-microsoft</guid>
      <dc:creator>Robert Lemos, Contributing Writer</dc:creator>
      <dc:date>2021-12-15T23:09:30Z</dc:date>
    </item>
    <item>
      <title>Dept. of Homeland Security Launches 'Hack DHS' Program</title>
      <link>https://www.darkreading.com/endpoint/dept-of-homeland-security-launches-hack-dhs-program</link>
      <description>A new bug bounty program aims to find potential security flaws within certain DHS systems and strengthen the department's security posture.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte161b23f0fd3a84b/60b1ea374e7eb868c4c6a293/dr_staff_125x125.jpg" type="image/*" />
      <pubDate>Wed, 15 Dec 2021 21:30:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/endpoint/dept-of-homeland-security-launches-hack-dhs-program</guid>
      <dc:creator>Dark Reading Staff, Dark Reading</dc:creator>
      <dc:date>2021-12-15T21:30:00Z</dc:date>
    </item>
    <item>
      <title>Analysis: Log4j Vulnerability Highlights the Value of Defense-in-Depth, Accurate Inventory</title>
      <link>https://www.darkreading.com/omdia/analysis-log4j-vulnerability-highlights-the-value-of-defense-in-depth-accurate-inventory</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt7058891718c0fdf7/61aa7d61c6fba4679d2a9c3b/LocksOnAGrid_Aleksey_Funtap_Alamy.jpg" type="image/*" />
      <description>The early lessons from Log4j indicate that key security principles can help better handle these high-risk software supply chain security incidents if teams have proper support.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltef94f9b74bb63c60/61bb7263b04f6f35f2f39630/F.Montenegro-Print_300.jpg" type="image/*" />
      <pubDate>Wed, 15 Dec 2021 20:13:59 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/omdia/analysis-log4j-vulnerability-highlights-the-value-of-defense-in-depth-accurate-inventory</guid>
      <dc:creator>Fernando Montenegro, Senior Principal Analyst, Omdia</dc:creator>
      <dc:date>2021-12-15T20:13:59Z</dc:date>
    </item>
    <item>
      <title>Meta Expands Bug-Bounty Program to Include Data Scraping</title>
      <link>https://www.darkreading.com/vulnerabilities-threats/meta-expands-bug-bounty-program-to-include-data-scraping</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt272e4521ab1e80b8/61ba47114b727d376d0c4810/FBMeta_GKImages_Alamy.jpg" type="image/*" />
      <description>Scraping bugs and scraped databases are two new areas of research for the company's bug-bounty and data-bounty programs.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt1d62bf1a6a54fdcf/60b1e9ed2d381b69fb11e95e/Sheridan-IWK-125x125.jpg" type="image/*" />
      <pubDate>Wed, 15 Dec 2021 19:50:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/vulnerabilities-threats/meta-expands-bug-bounty-program-to-include-data-scraping</guid>
      <dc:creator>Kelly Sheridan, Senior Editor</dc:creator>
      <dc:date>2021-12-15T19:50:00Z</dc:date>
    </item>
    <item>
      <title>Cybereason Announces Availability of AI-Driven Cybereason XDR and EDR on Google Cloud Marketplace</title>
      <link>https://www.darkreading.com/cloud/cybereason-announces-availability-of-ai-driven-cybereason-xdr-and-edr-on-google-cloud-marketplace</link>
      <description>Cloud-native  platform automates prevention, detection, and response to cyberattacks.</description>
      <pubDate>Wed, 15 Dec 2021 19:35:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/cloud/cybereason-announces-availability-of-ai-driven-cybereason-xdr-and-edr-on-google-cloud-marketplace</guid>
      <dc:date>2021-12-15T19:35:00Z</dc:date>
    </item>
    <item>
      <title>Kroll Acquires Security Compass Advisory</title>
      <link>https://www.darkreading.com/cloud/kroll-acquires-security-compass-advisory</link>
      <description>Combined capabilities will help clients address the growing complexity of securing public, private and hybrid cloud, 5G, IoT, and industrial control systems</description>
      <pubDate>Wed, 15 Dec 2021 19:30:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/cloud/kroll-acquires-security-compass-advisory</guid>
      <dc:date>2021-12-15T19:30:00Z</dc:date>
    </item>
    <item>
      <title>Privacy and Safety Issues With Facebook's New 'Metaventure'</title>
      <link>https://www.darkreading.com/vulnerabilities-threats/privacy-and-safety-issues-with-facebook-s-new-metaventure-</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltaad0a05ce4c3245f/61b3789d1949776906099b56/Metaverse_mustafa_kaya_Alamy.jpg" type="image/*" />
      <description>With access to a user's 3D model and full-body digital tracking, attackers can recreate the perfect replica of a C-level executive to trick employees.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt9f1744b2a326acff/61b373adcfa0b975943c42ca/Zahid_Anwar.JPG" type="image/*" />
      <pubDate>Wed, 15 Dec 2021 18:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/vulnerabilities-threats/privacy-and-safety-issues-with-facebook-s-new-metaventure-</guid>
      <dc:creator>Zahid Anwar, Associate Professor of Cybersecurity in the NDSU Department of Computer Science</dc:creator>
      <dc:date>2021-12-15T18:00:00Z</dc:date>
    </item>
    <item>
      <title>What Are the Pros and Cons of a SASE Architecture?</title>
      <link>https://www.darkreading.com/edge-ask-the-experts/what-are-the-pros-and-cons-of-a-sase-architecture-</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt7cf8e850f6292c8e/612d20f5b34eb77fa576d50f/DesktopAsAService-AndSus-adobe-cp.jpg" type="image/*" />
      <description>SASE is a promising and burgeoning networking architecture approach, but it's not without some challenges.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltf049f5509a99409c/617c03ff7ce9a21030aa4643/shaila-shankar-cisco.jpg" type="image/*" />
      <pubDate>Wed, 15 Dec 2021 17:35:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/edge-ask-the-experts/what-are-the-pros-and-cons-of-a-sase-architecture-</guid>
      <dc:creator>Shaila Shankar, SVP and General Manager, Cisco Cloud Network and Security</dc:creator>
      <dc:date>2021-12-15T17:35:00Z</dc:date>
    </item>
    <item>
      <title>Why We Need "Developer-First" Application Security</title>
      <link>https://www.darkreading.com/application-security/why-we-need-developer-first-application-security</link>
      <description>The way to improve the security of the modern software development life cycle and reduce the number of application-based breaches is to re-center app security around the needs of developers.</description>
      <pubDate>Wed, 15 Dec 2021 15:36:12 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/application-security/why-we-need-developer-first-application-security</guid>
      <dc:date>2021-12-15T15:36:12Z</dc:date>
    </item>
    <item>
      <title>Why Cloud Storage Isn't Immune to Ransomware</title>
      <link>https://www.darkreading.com/attacks-breaches/why-cloud-storage-isn-t-immune-to-ransomware</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blta5143ce90b48b225/61b28ca3b2a9e8758ed9cfa0/DigitalChain_Panther_Media_GmbH_Alamy.jpg" type="image/*" />
      <description>Cloud security is a shared responsibility. which sometimes leads to security gaps and complexity in risk management.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltab7cf58a01d229bf/60d4458ce1461d39eb817930/Shai-Morag.png" type="image/*" />
      <pubDate>Wed, 15 Dec 2021 15:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/attacks-breaches/why-cloud-storage-isn-t-immune-to-ransomware</guid>
      <dc:creator>Shai Morag, CEO, Ermetic</dc:creator>
      <dc:date>2021-12-15T15:00:00Z</dc:date>
    </item>
    <item>
      <title>Kryptowire Collaborates With Orange and Finds Vulnerabilities in Mobile Devices</title>
      <link>https://www.darkreading.com/vulnerabilities-threats/kryptowire-collaborates-with-orange-and-finds-vulnerabilities-in-mobile-devices</link>
      <description>Kryptowire’s end-to-end cybersecurity engine identified vulnerabilities granting system user-level privileges for arbitrary shell script execution.</description>
      <pubDate>Wed, 15 Dec 2021 14:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/vulnerabilities-threats/kryptowire-collaborates-with-orange-and-finds-vulnerabilities-in-mobile-devices</guid>
      <dc:date>2021-12-15T14:00:00Z</dc:date>
    </item>
    <item>
      <title>Another Java Log4j vulnerability discovered</title>
      <link>https://www.computing.co.uk/news/4042104/java-log4j-vulnerability-discovered</link>
      <description>&lt;img alt="Another Java Log4j vulnerability discovered" src="https://www.computing.co.uk/api/v1/wps/bacd778/93d266ae-1eda-4178-8f6f-7477d5fee880/4/software-bug-iStock-804501162-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; New flaw is much less severe than the Log4jshell vulnerability, but admins are advised to update Log4j once again  &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 15 Dec 2021 12:25:33 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4042104/java-log4j-vulnerability-discovered</guid>
      <dc:date>2021-12-15T12:25:33Z</dc:date>
    </item>
    <item>
      <title>Norway fines Grindr £5.5 million for personal data sharing</title>
      <link>https://www.computing.co.uk/news/4042089/norway-fines-grindr-gbp-million-personal-sharing</link>
      <description>&lt;img alt="Norway fines Grindr £5.5 million for personal data sharing" src="https://www.computing.co.uk/api/v1/wps/47594a0/2d30b29c-15cd-40e4-ae26-f229264bd70e/3/iStock-Gay-couple-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; From 2018-2020, users were forced to consent to a new privacy policy to continue using the app - which the Norwegian regulator has ruled as invalid &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 15 Dec 2021 11:31:02 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4042089/norway-fines-grindr-gbp-million-personal-sharing</guid>
      <dc:date>2021-12-15T11:31:02Z</dc:date>
    </item>
    <item>
      <title>Securing NHS Trusts: what cyber solutions should be prioritised?</title>
      <link>https://www.computing.co.uk/analysis/4042082/securing-nhs-trusts-cyber-solutions-prioritised</link>
      <description>&lt;img alt="Securing NHS Trusts: what cyber solutions should be prioritised? " src="https://www.computing.co.uk/api/v1/wps/067aa36/f6dfd20a-9d3f-4ed5-b84f-458e89f748b3/2/cyber-security-health-iStock-884932176-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Four security vendors give their view on staffing issues, zero trust and threat intelligence &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 15 Dec 2021 11:01:46 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/analysis/4042082/securing-nhs-trusts-cyber-solutions-prioritised</guid>
      <dc:date>2021-12-15T11:01:46Z</dc:date>
    </item>
    <item>
      <title>Microsoft fixes six zero-days in December Patch Tuesday update</title>
      <link>https://www.computing.co.uk/news/4042070/microsoft-fixes-zero-days-december-patch-tuesday-update</link>
      <description>&lt;img alt="Microsoft fixes six zero-days in December Patch Tuesday update" src="https://www.computing.co.uk/api/v1/wps/c88e024/7d2e1b87-764a-4dc4-a766-2217c6332636/6/Microsoft-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; One zero-day addressed has been observed in active attacks &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 15 Dec 2021 08:11:06 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4042070/microsoft-fixes-zero-days-december-patch-tuesday-update</guid>
      <dc:date>2021-12-15T08:11:06Z</dc:date>
    </item>
    <item>
      <title>Cisco's Ash Devata on Securing the Hybrid Workforce With Zero Trust</title>
      <link>https://www.darkreading.com/edge/cisco-ash-devata-on-hybrid-workforce-and-zero-trust</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt8fe9d10e0d899447/60e3bcac21d15821fe843966/voice-wave_000025124526_Small.jpg" type="image/*" />
      <description>Hybrid work is here to stay, and organizations can apply zero trust's three core principles to ensure a secure workforce, Devata says.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltbeb30fde8ec73a32/60d4432c2446e93b5b5a0e0c/Edge-Editors.png" type="image/*" />
      <pubDate>Wed, 15 Dec 2021 02:19:25 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/edge/cisco-ash-devata-on-hybrid-workforce-and-zero-trust</guid>
      <dc:creator>Edge Editors, Dark Reading</dc:creator>
      <dc:date>2021-12-15T02:19:25Z</dc:date>
    </item>
    <item>
      <title>Volatile and Adaptable: Tracking the Movements of Modern Ransomware</title>
      <link>https://www.trendmicro.com/en_us/research/21/l/volatile-and-adaptable-tracking-the-movements-of-modern-ransomware.html</link>
      <description>Trend Micro's tracking of  modern ransomware, as well as of older families, shows which attacks are gaining momentum and which families are particularly dangerous for enterprises and private users.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/l/volatile-and-adaptable-tracking-the-movements-of-modern-ransomware/banner%20volatile%20ransomware.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Endpoints</category>
      <category>Trend Micro Research : Ransomware</category>
      <category>Trend Micro Research : Research</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <pubDate>Wed, 15 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:b828238b-3597-6826-7c56-694d816018c3</guid>
      <dc:creator>Trend Micro Research</dc:creator>
      <dc:date>2021-12-15T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Tufin Introduces Security Policy Builder (SPB) App to Marketplace</title>
      <link>https://www.darkreading.com/operations/tufin-introduces-security-policy-builder-spb-app-to-marketplace</link>
      <description>Automates security policy design to ensure compliance and reduce likelihood of breach announcing significant updates to other marketplace apps.</description>
      <pubDate>Tue, 14 Dec 2021 23:54:22 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/operations/tufin-introduces-security-policy-builder-spb-app-to-marketplace</guid>
      <dc:date>2021-12-14T23:54:22Z</dc:date>
    </item>
    <item>
      <title>Ground Labs Research Reveals 71% of American Consumers are Unaware of Data Protection Laws</title>
      <link>https://www.darkreading.com/risk/ground-labs-research-reveals-71-of-american-consumers-are-unaware-of-data-protection-laws</link>
      <description>Google Survey of 1,000 U.S. consumers uncovers data privacy disconnect, a call to action for businesses.</description>
      <pubDate>Tue, 14 Dec 2021 23:52:11 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/risk/ground-labs-research-reveals-71-of-american-consumers-are-unaware-of-data-protection-laws</guid>
      <dc:date>2021-12-14T23:52:11Z</dc:date>
    </item>
    <item>
      <title>Attackers Target Log4j to Drop Ransomware, Web Shells, Backdoors</title>
      <link>https://www.darkreading.com/attacks-breaches/attackers-target-log4j-to-drop-ransomware-web-shells-backdoors</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt77ab6561f1e72234/61b913f4f1cd402112e70573/image002_(1).png" type="image/*" />
      <description>Amid the increase in Log4j attack activity, at least one Iranian state-backed threat group is preparing to target the vulnerability, experts say.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt02d79fb9a44a4258/60b1e9dd2a25046b35110696/Jai-Vijayan.jpeg" type="image/*" />
      <pubDate>Tue, 14 Dec 2021 23:18:58 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/attacks-breaches/attackers-target-log4j-to-drop-ransomware-web-shells-backdoors</guid>
      <dc:creator>Jai Vijayan, Contributing Writer</dc:creator>
      <dc:date>2021-12-14T23:18:58Z</dc:date>
    </item>
    <item>
      <title>Propane Gas Distributor Hit With Ransomware</title>
      <link>https://www.darkreading.com/attacks-breaches/propane-distributor-hit-with-ransomware</link>
      <description>North America-based Superior Plus "temporarily disabled" some of its systems in the wake of the attack.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte161b23f0fd3a84b/60b1ea374e7eb868c4c6a293/dr_staff_125x125.jpg" type="image/*" />
      <pubDate>Tue, 14 Dec 2021 22:48:48 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/attacks-breaches/propane-distributor-hit-with-ransomware</guid>
      <dc:creator>Dark Reading Staff, Dark Reading</dc:creator>
      <dc:date>2021-12-14T22:48:48Z</dc:date>
    </item>
    <item>
      <title>Ransomware Hits Virginia Legislative Agencies</title>
      <link>https://www.darkreading.com/attacks-breaches/ransomware-hits-virginia-legislative-agencies</link>
      <description>The attack forced a shutdown of computer systems and websites for Virginia legislative agencies and commissions, reports state.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte161b23f0fd3a84b/60b1ea374e7eb868c4c6a293/dr_staff_125x125.jpg" type="image/*" />
      <pubDate>Tue, 14 Dec 2021 22:40:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/attacks-breaches/ransomware-hits-virginia-legislative-agencies</guid>
      <dc:creator>Dark Reading Staff, Dark Reading</dc:creator>
      <dc:date>2021-12-14T22:40:00Z</dc:date>
    </item>
    <item>
      <title>Microsoft Patch Tuesday, December 2021 Edition</title>
      <link>https://krebsonsecurity.com/2021/12/microsoft-patch-tuesday-december-2021-edition/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://krebsonsecurity.com/2021/12/microsoft-patch-tuesday-december-2021-edition/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">24</slash:comments>
      <description>Microsoft, Adobe, and Google all issued security updates to their products today. The Microsoft patches include six previously disclosed security flaws, and one that that is already being actively exploited. But this month's Patch Tuesday is being overshadowed by the "Log4Shell" 0-day exploit in a popular Java library that web server administrators are now racing to find and patch amid widespread exploitation of the flaw.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Microsoft&lt;/strong&gt;, &lt;strong&gt;Adobe&lt;/strong&gt;, and &lt;strong&gt;Google&lt;/strong&gt; all issued security updates to their products today. The Microsoft patches include six previously disclosed security flaws, and one that is already being actively exploited. But this month&amp;#8217;s Patch Tuesday is overshadowed by the &amp;#8220;&lt;strong&gt;Log4Shell&lt;/strong&gt;&amp;#8221; 0-day exploit in a popular &lt;strong&gt;Java&lt;/strong&gt; library that web server administrators are now racing to find and patch amid widespread exploitation of the flaw.&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" class="aligncenter wp-image-56287" src="https://krebsonsecurity.com/wp-content/uploads/2021/07/windupate.png" alt="" width="764" height="538" srcset="https://krebsonsecurity.com/wp-content/uploads/2021/07/windupate.png 841w, https://krebsonsecurity.com/wp-content/uploads/2021/07/windupate-768x541.png 768w, https://krebsonsecurity.com/wp-content/uploads/2021/07/windupate-782x550.png 782w, https://krebsonsecurity.com/wp-content/uploads/2021/07/windupate-100x70.png 100w" sizes="(max-width: 764px) 100vw, 764px" /&gt;&lt;/p&gt;
&lt;p&gt;Log4Shell is the name picked for a critical flaw disclosed Dec. 9 in the popular logging library for Java called &amp;#8220;&lt;strong&gt;log4j&lt;/strong&gt;,&amp;#8221; which is included in a huge number of Java applications. Publicly released exploit code allows an attacker to force a server running a vulnerable log4j library to execute commands, such as downloading malicious software or opening a backdoor connection to the server.&lt;/p&gt;
&lt;p&gt;According to researchers at &lt;strong&gt;Lunasec&lt;/strong&gt;, many, many services are vulnerable to this exploit.&lt;/p&gt;
&lt;p&gt;&amp;#8220;Cloud services like Steam, Apple iCloud, and apps like Minecraft have already been found to be vulnerable,&amp;#8221; Lunasec &lt;a href="https://www.lunasec.io/docs/blog/log4j-zero-day/" target="_blank" rel="noopener"&gt;wrote&lt;/a&gt;. &amp;#8220;Anybody using Apache Struts is likely vulnerable. We&amp;#8217;ve seen similar vulnerabilities exploited before in breaches like the 2017 Equifax data breach. An extensive list of responses from impacted organizations has been compiled &lt;a href="https://gist.github.com/SwitHak/b66db3a06c2955a9cb71a8718970c592" target="_blank" rel="noopener"&gt;here&lt;/a&gt;.&amp;#8221;&lt;/p&gt;
&lt;p&gt;&amp;#8220;If you run a server built on open-source software, there’s a good chance you are impacted by this vulnerability,&amp;#8221; said &lt;strong&gt;Dustin Childs&lt;/strong&gt; of Trend Micro&amp;#8217;s Zero Day Initiative. &amp;#8220;Check with all the vendors in your enterprise to see if they are impacted and what patches are available.&amp;#8221;&lt;/p&gt;
&lt;p&gt;Part of the difficulty in patching against the Log4Shell attack is identifying all of the vulnerable web applications, said &lt;strong&gt;Johannes Ullrich&lt;/strong&gt;, an incident handler and blogger for the &lt;strong&gt;SANS Internet Storm Center&lt;/strong&gt;. &amp;#8220;Log4Shell will continue to haunt us for years to come. Dealing with log4shell will be a marathon,&amp;#8221; Ullrich said. &amp;#8220;Treat it as such.&amp;#8221; SANS has &lt;a href="https://isc.sans.edu/forums/diary/RCE+in+log4j+Log4Shell+or+how+things+can+get+bad+quickly/28120/" target="_blank" rel="noopener"&gt;a good walk-through&lt;/a&gt; of how simple yet powerful the exploit can be.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;John Hultquist&lt;/strong&gt;, vice president of intelligence analysis at &lt;strong&gt;Mandiant&lt;/strong&gt;, said the company has seen Chinese and Iranian state actors leveraging the log4j vulnerability, and that the Iranian actors are particularly aggressive, having taken part in ransomware operations that may be primarily carried out for disruptive purposes rather than financial gain.&lt;/p&gt;
&lt;p&gt;&amp;#8220;We anticipate other state actors are doing so as well, or preparing to,&amp;#8221; Hultquist said. &amp;#8220;We believe these actors will work quickly to create footholds in desirable networks for follow-on activity, which may last for some time. In some cases, they will work from a wish list of targets that existed long before this vulnerability was public knowledge. In other cases, desirable targets may be selected after broad targeting.&amp;#8221;&lt;/p&gt;
&lt;p&gt;Researcher &lt;strong&gt;Kevin Beaumont&lt;/strong&gt; had a more lighthearted take on Log4Shell &lt;a href="https://twitter.com/GossiTheDog/status/1470787395805192199" target="_blank" rel="noopener"&gt;via Twitter&lt;/a&gt;:&lt;/p&gt;
&lt;p&gt;&amp;#8220;Basically the perfect ending to cybersecurity in 2021 is a 90s style Java vulnerability in an open source module, written by two volunteers with no funding, used by large cybersecurity vendors, undetected until Minecraft chat got pwned, where nobody knows how to respond properly.&amp;#8221;&lt;/p&gt;
&lt;p&gt;The&lt;strong&gt; Cybersecurity and Infrastructure Security Agency&lt;/strong&gt; (CISA) has joined with the &lt;strong&gt;FBI&lt;/strong&gt;, &lt;strong&gt;National Security Agency&lt;/strong&gt; (NSA) and partners abroad in publishing &lt;a href="https://www.cisa.gov/uscert/ncas/alerts/aa21-356a" target="_blank" rel="noopener"&gt;an advisory&lt;/a&gt; to help organizations mitigate Log4Shell and other Log4j-related vulnerabilities.&lt;/p&gt;
&lt;p&gt;&lt;span id="more-57908"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;A half-dozen of the vulnerabilities addressed by Microsoft today earned its most dire &amp;#8220;critical&amp;#8221; rating, meaning malware or miscreants could exploit the flaws to gain complete, remote control over a vulnerable Windows system with little or no help from users.&lt;/p&gt;
&lt;p&gt;The Windows flaw already seeing active exploitation is &lt;a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43890" target="_blank" rel="noopener"&gt;CVE-2021-43890&lt;/a&gt;, which is a &amp;#8220;spoofing&amp;#8221; bug in the &lt;strong&gt;Windows AppX installer&lt;/strong&gt; on &lt;strong&gt;Windows 10.&lt;/strong&gt; Microsoft says it is aware of attempts to exploit this flaw using specially crafted packages to implant malware families like &lt;a href="https://krebsonsecurity.com/?s=Emotet" target="_blank" rel="noopener"&gt;Emotet&lt;/a&gt;, &lt;a href="https://krebsonsecurity.com/?s=trickbot" target="_blank" rel="noopener"&gt;Trickbot&lt;/a&gt;, and &lt;a href="https://www.proofpoint.com/us/blog/threat-insight/bazaflix-bazaloader-fakes-movie-streaming-service" target="_blank" rel="noopener"&gt;BazaLoader&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Kevin Breen&lt;/strong&gt;, director of threat research for Immersive Labs, said &lt;a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43905" target="_blank" rel="noopener"&gt;CVE-2021-43905&lt;/a&gt; stands out of this month&amp;#8217;s patch batch.&lt;/p&gt;
&lt;p&gt;&amp;#8220;Not only for its high &lt;a href="https://www.techtarget.com/searchsecurity/definition/CVSS-Common-Vulnerability-Scoring-System" target="_blank" rel="noopener"&gt;CVSS score&lt;/a&gt; of 9.6, but also because it’s noted as &amp;#8216;exploitation more likely&amp;#8217;,&amp;#8221; Breen observed.&lt;/p&gt;
&lt;p&gt;Microsoft also patched &lt;a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43883" target="_blank" rel="noopener"&gt;CVE-2021-43883&lt;/a&gt;, an elevation of privilege vulnerability in Windows Installer.&lt;/p&gt;
&lt;p&gt;&amp;#8220;This appears to be a fix for a patch bypass of &lt;a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41379" target="_blank" rel="noopener"&gt;CVE-2021-41379&lt;/a&gt;, another elevation of privilege vulnerability in Windows Installer that was reportedly fixed in November,&amp;#8221; &lt;strong&gt;Satnam Narang&lt;/strong&gt; of Tenable points out. &amp;#8220;However, researchers discovered that fix was incomplete, and a proof-of-concept was made public late last month.&amp;#8221;&lt;/p&gt;
&lt;p&gt;Google issued five security fixes for &lt;strong&gt;Chrome&lt;/strong&gt;, including one rated critical and three others with high severity. If you’re browsing with Chrome, keep a lookout for when you see an “Update” tab appear to the right of the address bar. If it’s been a while since you closed the browser, you might see the Update button turn from green to orange and then red. Green means an update has been available for two days; orange means four days have elapsed, and red means your browser is a week or more behind on important updates. Completely close and restart the browser to install any pending updates.&lt;/p&gt;
&lt;p&gt;Also, Adobe issued patches to correct more than 60 security flaws in &lt;a href="https://helpx.adobe.com/security.html" target="_blank" rel="noopener"&gt;a slew of products,&lt;/a&gt; including Adobe Audition, Lightroom, Media Encoder, Premiere Pro, Prelude, Dimension, After Effects, Photoshop, Connect, Experience Manager and Premiere Rush.&lt;/p&gt;
&lt;p&gt;Standard disclaimer: Before you update Windows, &lt;em&gt;please&lt;/em&gt; make sure you have backed up your system and/or important files. It’s not uncommon for a Windows update package to hose one’s system or prevent it from booting properly, and some updates have been known to erase or corrupt files.&lt;/p&gt;
&lt;p&gt;So do yourself a favor and backup before installing any patches. Windows 10 even has some &lt;a href="https://lifehacker.com/how-to-back-up-your-computer-automatically-with-windows-1762867473" target="_blank" rel="noopener noreferrer"&gt;built-in tools&lt;/a&gt; to help you do that, either on a per-file/folder basis or by making a complete and bootable copy of your hard drive all at once.&lt;/p&gt;
&lt;p&gt;And if you wish to ensure Windows has been set to pause updating so you can back up your files and/or system before the operating system decides to reboot and install patches on its own schedule, &lt;a href="https://www.computerworld.com/article/3543189/check-to-make-sure-you-have-windows-updates-paused.html" target="_blank" rel="noopener noreferrer"&gt;see this guide&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you experience glitches or problems installing any of these patches this month, please consider leaving a comment about it below; there’s a decent chance other readers have experienced the same and may chime in here with useful tips.&lt;/p&gt;
&lt;p&gt;Additional reading:&lt;/p&gt;
&lt;p&gt;&lt;a href="https://isc.sans.edu/forums/diary/Microsoft+December+2021+Patch+Tuesday/28132/" target="_blank" rel="noopener"&gt;SANS ISC listing&lt;/a&gt; of each Microsoft vulnerability patched today, indexed by severity and affected component.&lt;/p&gt;</content:encoded>
      <category>Time to Patch</category>
      <category>adobe</category>
      <category>chrome</category>
      <category>CVE-2021-41379</category>
      <category>CVE-2021-43883</category>
      <category>CVE-2021-43890</category>
      <category>CVE-2021-43905</category>
      <category>Dustin Childs</category>
      <category>google</category>
      <category>Immersive Labs</category>
      <category>Johannes Ullrich</category>
      <category>Kevin Beaumont</category>
      <category>Kevin Breen</category>
      <category>microsoft</category>
      <category>Microsoft Patch Tuesday December 2021</category>
      <category>sans internet storm center</category>
      <category>Satnam Narang</category>
      <category>Tenable</category>
      <category>trend micro</category>
      <pubDate>Tue, 14 Dec 2021 22:23:44 GMT</pubDate>
      <comments>https://krebsonsecurity.com/2021/12/microsoft-patch-tuesday-december-2021-edition/#comments</comments>
      <guid isPermaLink="false">https://krebsonsecurity.com/?p=57908</guid>
      <dc:creator>BrianKrebs</dc:creator>
      <dc:date>2021-12-14T22:23:44Z</dc:date>
    </item>
    <item>
      <title>Tool Overload &amp; Attack Surface Expansion Plague SOCs</title>
      <link>https://www.darkreading.com/operations/tool-overload-attack-surface-expansion-plague-socs</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt7e22aa76d3e8b275/61b91188b751b33b766c65b9/communication-gap-devo.jpg" type="image/*" />
      <description>Security professionals are burning out from handling too many tools and facing a growing number of threats, and more than 40% see lack of leadership as the main problem.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt58481326324d6911/60b1e9a55d34de550780a990/Robert-Lemos.png" type="image/*" />
      <pubDate>Tue, 14 Dec 2021 22:15:43 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/operations/tool-overload-attack-surface-expansion-plague-socs</guid>
      <dc:creator>Robert Lemos, Contributing Writer</dc:creator>
      <dc:date>2021-12-14T22:15:43Z</dc:date>
    </item>
    <item>
      <title>Microsoft Patches Zero-Day Spreading Emotet Malware</title>
      <link>https://www.darkreading.com/vulnerabilities-threats/microsoft-patches-zero-day-spreading-emotet-malware</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt89b5817585cda670/61b90d0fbcdb952119ebc455/Patching_MR_AdobeStock.jpg" type="image/*" />
      <description>The December rollout includes 67 security patches and addresses one zero-day and five more publicly known vulnerabilities.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt1d62bf1a6a54fdcf/60b1e9ed2d381b69fb11e95e/Sheridan-IWK-125x125.jpg" type="image/*" />
      <pubDate>Tue, 14 Dec 2021 21:30:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/vulnerabilities-threats/microsoft-patches-zero-day-spreading-emotet-malware</guid>
      <dc:creator>Kelly Sheridan, Senior Editor</dc:creator>
      <dc:date>2021-12-14T21:30:00Z</dc:date>
    </item>
    <item>
      <title>Apple security updates are out – and not a Log4Shell mention in sight</title>
      <link>https://nakedsecurity.sophos.com/2021/12/14/apple-security-updates-are-out-and-not-a-log4shell-mention-in-sight/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://nakedsecurity.sophos.com/2021/12/14/apple-security-updates-are-out-and-not-a-log4shell-mention-in-sight/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">4</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/01/appleupd-1200.png?w=230&amp;h=130&amp;crop=1" medium="image" />
      <post-id xmlns="com-wordpress:feed-additions:1">647519</post-id>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/01/appleupd-1200.png" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/01/appleupd-1200.png?w=170&amp;h=90&amp;crop=1" medium="image" />
      <description>Get 'em while they're hot!</description>
      <category>Apple</category>
      <category>iPad</category>
      <category>iPhone</category>
      <category>macOS</category>
      <category>Patch</category>
      <category>vulnerability</category>
      <pubDate>Tue, 14 Dec 2021 19:55:30 GMT</pubDate>
      <comments>https://nakedsecurity.sophos.com/2021/12/14/apple-security-updates-are-out-and-not-a-log4shell-mention-in-sight/#comments</comments>
      <guid isPermaLink="false">https://nakedsecurity.sophos.com/?p=647519</guid>
      <dc:creator>Paul Ducklin</dc:creator>
      <dc:date>2021-12-14T19:55:30Z</dc:date>
    </item>
    <item>
      <title>Malicious module in IIS Web server | Kaspersky official blog</title>
      <link>https://www.kaspersky.com/blog/owowa-weaponizing-web-mail-outlook/43145/</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/14140634/owowa-weaponizing-web-mail-outlook-featured.jpg" width="1460" height="960">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/14140634/owowa-weaponizing-web-mail-outlook-featured-1024x673.jpg" width="1024" height="673">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/14140634/owowa-weaponizing-web-mail-outlook-featured-300x197.jpg" width="300" height="197">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/14140634/owowa-weaponizing-web-mail-outlook-featured-150x150.jpg" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>The malicious module our experts are calling OWOWA integrates into IIS Web servers and steals mail credentials.</description>
      <content:encoded>&lt;p&gt;A malicious Internet Information Services (IIS) module is turning Outlook on the web into a tool for stealing credentials and a remote access panel. Unknown actors have used the module, which our researchers call OWOWA, in targeted attacks.&lt;/p&gt;
&lt;h2&gt;Why Outlook on the web attracts attackers&lt;/h2&gt;
&lt;p&gt;Outlook on the web (previously known as Exchange Web Connect, Outlook Web Access, and Outlook Web App, or simply OWA) is a Web-based interface for accessing Microsoft&amp;#8217;s Personal Information Manager service. The app is deployed on Web servers running IIS.&lt;/p&gt;
&lt;p&gt;Many companies use it to provide employees with remote access to corporate mailboxes and calendars without having to install a dedicated client. There are several methods of implementing Outlook on the web, one of which involves using Exchange Server on site, which is what cybercriminals are drawn to. In theory, gaining control of this app gives them access to all corporate correspondence, along with endless opportunities to expand their attack on the infrastructure and launch additional BEC campaigns.&lt;/p&gt;
&lt;h2&gt;How OWOWA works&lt;/h2&gt;
&lt;p&gt;OWOWA loads on compromised IIS Web servers as a module for all compatible apps, but its purpose is to intercept credentials entered into OWA. The malware checks requests and responses on Outlook on the Web login page, and if it sees a user has entered credentials and received an authentication token in response, it writes the username and password to a file (in encrypted form).&lt;/p&gt;
&lt;p&gt;In addition, OWOWA allows attackers to control its functionality directly through the same authentication form. By entering certain commands into the username and password fields, an attacker can retrieve the harvested information, delete the log file, or execute arbitrary commands on the compromised server through PowerShell.&lt;/p&gt;
&lt;p&gt;For a more detailed technical description of the module with indicators of compromise, see &lt;a href="https://securelist.com/owowa-credential-stealer-and-remote-access/105219/" target="_blank" rel="noopener"&gt;Securelist&amp;#8217;s post&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Who are the victims of OWOWA attacks?&lt;/h2&gt;
&lt;p&gt;Our experts detected OWOWA-based attacks on servers in several Asian countries: Malaysia, Mongolia, Indonesia, and the Philippines. However, our experts have reason to believe the cybercriminals are also interested in organizations in Europe.&lt;/p&gt;
&lt;p&gt;The majority of targets were government agencies, with at least one being a transport company (also state-owned).&lt;/p&gt;
&lt;h2&gt;How to guard against OWOWA&lt;/h2&gt;
&lt;p&gt;You can use the appcmd.exe command — or the regular IIS configuration tool — to detect the malicious OWOWA module (or any other third-party IIS module) on the IIS Web server. Keep in mind, however, that any Internet-facing server, like any computer, needs &lt;a href="https://www.kaspersky.com/small-to-medium-business-security?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______" target="_blank"&gt;protection&lt;/a&gt;.&lt;/p&gt;
&lt;input type="hidden" class="category_for_banner" value="kesb-trial" /&gt;</content:encoded>
      <category>Business</category>
      <category>Enterprise</category>
      <category>SMB</category>
      <category>e-mail</category>
      <category>Exchange</category>
      <category>Outlook</category>
      <category>web applications</category>
      <category>web threats</category>
      <pubDate>Tue, 14 Dec 2021 19:08:46 GMT</pubDate>
      <guid isPermaLink="false">https://www.kaspersky.com/blog/?p=43145</guid>
      <dc:creator>Kaspersky Team</dc:creator>
      <dc:date>2021-12-14T19:08:46Z</dc:date>
    </item>
    <item>
      <title>Upcoming Speaking Engagements</title>
      <link>https://www.schneier.com/blog/archives/2021/12/upcoming-speaking-engagements-15.html</link>
      <thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total>
      <description>&lt;p&gt;This is a current list of where and when I am scheduled to speak:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;I’m speaking at the &lt;a href="https://www.rsaconference.com/"&gt;RSA Conference 2022&lt;/a&gt; in San Francisco on February 8, 2022.&lt;/li&gt;
&lt;li&gt;I’m speaking at &lt;a href="https://its-now.science/"&gt;IT-S Now 2022&lt;/a&gt; in Vienna on June 2, 2022.&lt;/li&gt;
&lt;li&gt;I’m speaking at the 14th International Conference on Cyber Conflict, &lt;a href="https://www.cycon.org/"&gt;CyCon 2022,&lt;/a&gt; in &lt;span class="hero-header__banner-meta"&gt;Tallinn, Estonia&lt;/span&gt; on June 3, 2022.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The list is maintained on &lt;a href="https://www.schneier.com/events/"&gt;this page&lt;/a&gt;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This is a current list of where and when I am scheduled to speak:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;I’m speaking at the &lt;a href="https://www.rsaconference.com/"&gt;RSA Conference 2022&lt;/a&gt; in San Francisco on February 8, 2022.&lt;/li&gt;
&lt;li&gt;I’m speaking at &lt;a href="https://its-now.science/"&gt;IT-S Now 2022&lt;/a&gt; in Vienna on June 2, 2022.&lt;/li&gt;
&lt;li&gt;I’m speaking at the 14th International Conference on Cyber Conflict, &lt;a href="https://www.cycon.org/"&gt;CyCon 2022,&lt;/a&gt; in &lt;span class="hero-header__banner-meta"&gt;Tallinn, Estonia&lt;/span&gt; on June 3, 2022.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The list is maintained on &lt;a href="https://www.schneier.com/events/"&gt;this page&lt;/a&gt;.&lt;/p&gt;</content:encoded>
      <category domain="https://www.schneier.com">Uncategorized</category>
      <category domain="https://www.schneier.com">Schneier news</category>
      <pubDate>Tue, 14 Dec 2021 18:05:47 GMT</pubDate>
      <guid isPermaLink="false">https://www.schneier.com/?p=64638</guid>
      <dc:creator>Schneier.com Webmaster</dc:creator>
      <dc:date>2021-12-14T18:05:47Z</dc:date>
    </item>
    <item>
      <title>Source Code Leaks: The Real Problem Nobody Is Paying Attention To</title>
      <link>https://www.darkreading.com/vulnerabilities-threats/source-code-leaks-the-real-problem-nobody-is-paying-attention-to</link>
      <description>Source code is a corporate asset like any other, which makes it an attractive target for hackers.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt858b70e4f9f0f234/61b11485a9dcae750b76e9bd/Mackenzie_Jackson.JPG" type="image/*" />
      <pubDate>Tue, 14 Dec 2021 18:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/vulnerabilities-threats/source-code-leaks-the-real-problem-nobody-is-paying-attention-to</guid>
      <dc:creator>Mackenzie Jackson, Developer Advocate, GitGuardian</dc:creator>
      <dc:date>2021-12-14T18:00:00Z</dc:date>
    </item>
    <item>
      <title>On the Log4j Vulnerability</title>
      <link>https://www.schneier.com/blog/archives/2021/12/on-the-log4j-vulnerability.html</link>
      <thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">56</thr:total>
      <description>&lt;p&gt;It&amp;#8217;s &lt;a href="https://www.wired.com/story/log4j-log4shell/"&gt;serious&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;The range of impacts is so broad because of the nature of the vulnerability itself. Developers use logging frameworks to keep track of what happens in a given application. To exploit Log4Shell, an attacker only needs to get the system to log a strategically crafted string of code. From there they can load arbitrary code on the targeted server and install malware or launch other attacks. Notably, hackers can introduce the snippet in seemingly benign ways, like by sending the string in an email or setting it as an account username...&lt;/p&gt;&lt;/blockquote&gt;</description>
      <content:encoded>&lt;p&gt;It&amp;#8217;s &lt;a href="https://www.wired.com/story/log4j-log4shell/"&gt;serious&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;The range of impacts is so broad because of the nature of the vulnerability itself. Developers use logging frameworks to keep track of what happens in a given application. To exploit Log4Shell, an attacker only needs to get the system to log a strategically crafted string of code. From there they can load arbitrary code on the targeted server and install malware or launch other attacks. Notably, hackers can introduce the snippet in seemingly benign ways, like by sending the string in an email or setting it as an account username.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="https://blog.talosintelligence.com/2021/12/apache-log4j-rce-vulnerability.html"&gt;Threat advisory&lt;/a&gt; from Cisco. Cloudflare &lt;a href="https://twitter.com/eastdakota/status/1469800951351427073"&gt;found it&lt;/a&gt; in the wild before it was disclosed. CISA is &lt;a href="https://www.cyberscoop.com/log4j-cisa-easterly-most-serious/"&gt;very&lt;/a&gt; &lt;a href="https://www.cisa.gov/news/2021/12/11/statement-cisa-director-easterly-log4j-vulnerability"&gt;concerned&lt;/a&gt;, saying that hundreds of millions of devices are likely affected.&lt;/p&gt;</content:encoded>
      <category domain="https://www.schneier.com">Uncategorized</category>
      <category domain="https://www.schneier.com">Apache</category>
      <category domain="https://www.schneier.com">vulnerabilities</category>
      <category domain="https://www.schneier.com">zero-day</category>
      <pubDate>Tue, 14 Dec 2021 15:55:34 GMT</pubDate>
      <guid isPermaLink="false">https://www.schneier.com/?p=64644</guid>
      <dc:creator>Bruce Schneier</dc:creator>
      <dc:date>2021-12-14T15:55:34Z</dc:date>
    </item>
    <item>
      <title>Combat Misinformation by Getting Back to Security Basics</title>
      <link>https://www.darkreading.com/attacks-breaches/combat-misinformation-by-getting-back-to-security-basics</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt8358398370b2df8d/61b104da1949776906099a32/Misinformation_GoodIdeas_Alamy.jpg" type="image/*" />
      <description>One volley of fake news may land, but properly trained AI can shut down similar attempts at their sources.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltde679c37c866283c/61b0f117506c9a6c8921e4db/D_Spurling.png" type="image/*" />
      <pubDate>Tue, 14 Dec 2021 15:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/attacks-breaches/combat-misinformation-by-getting-back-to-security-basics</guid>
      <dc:creator>Dan Spurling, Senior Vice President, Product Engineering, Teradata</dc:creator>
      <dc:date>2021-12-14T15:00:00Z</dc:date>
    </item>
    <item>
      <title>Kronos ransomware restoration may take 'weeks'</title>
      <link>https://www.computing.co.uk/news/4041989/kronos-ransomware-restoration-weeks</link>
      <description>&lt;img alt="Kronos ransomware restoration may take &amp;#39;weeks&amp;#39;" src="https://www.computing.co.uk/api/v1/wps/18c67aa/a1249f68-4539-44b0-81ec-80be552a8bfc/4/060420-tesla-3-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; The current guidance is to use 'alternative business continuity protocols' &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 14 Dec 2021 07:29:36 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4041989/kronos-ransomware-restoration-weeks</guid>
      <dc:date>2021-12-14T07:29:36Z</dc:date>
    </item>
    <item>
      <title>Inside Ireland’s Public Healthcare Ransomware Scare</title>
      <link>https://krebsonsecurity.com/2021/12/inside-irelands-public-healthcare-ransomware-scare/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://krebsonsecurity.com/2021/12/inside-irelands-public-healthcare-ransomware-scare/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">25</slash:comments>
      <description>The accounting firm PricewatersCoopers recently published lessons learned from the disruptive and costly ransomware attack in May 2021 on Ireland's public health system. The unusually candid post-mortem found that nearly two months elapsed between the initial intrusion and the launching of the ransomware. It also found affected hospitals had tens of thousand of outdated Windows 7 systems, and that the health system's IT administrators failed to respond to multiple warning signs that a massive attack was imminent.</description>
      <content:encoded>&lt;p&gt;The consulting firm &lt;strong&gt;PricewaterhouseCoopers&lt;/strong&gt; recently published lessons learned from the disruptive and costly ransomware attack in May 2021 on Ireland&amp;#8217;s public health system. The unusually candid post-mortem found that nearly two months elapsed between the initial intrusion and the launching of the ransomware. It also found affected hospitals had tens of thousands of outdated &lt;strong&gt;Windows 7&lt;/strong&gt; systems, and that the health system&amp;#8217;s IT administrators failed to respond to multiple warning signs that a massive attack was imminent.&lt;/p&gt;
&lt;div id="attachment_57865" style="width: 767px" class="wp-caption aligncenter"&gt;&lt;img aria-describedby="caption-attachment-57865" loading="lazy" class=" wp-image-57865" src="https://krebsonsecurity.com/wp-content/uploads/2021/12/hsetimeline.png" alt="" width="757" height="518" /&gt;&lt;p id="caption-attachment-57865" class="wp-caption-text"&gt;PWC&amp;#8217;s timeline of the days leading up to the deployment of Conti ransomware on May 14.&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;Ireland&amp;#8217;s &lt;strong&gt;Health Service Executive&lt;/strong&gt; (HSE), which operates the country&amp;#8217;s public health system, got hit with &lt;a href="https://www.cisa.gov/uscert/ncas/alerts/aa21-265a" target="_blank" rel="noopener"&gt;Conti ransomware&lt;/a&gt; on May 14, 2021. A timeline in the report (above) says the initial infection of the &amp;#8220;patient zero&amp;#8221; workstation happened on Mar. 18, 2021, when an employee on a Windows computer opened a booby-trapped Microsoft Excel document in a phishing email that had been sent two days earlier.&lt;/p&gt;
&lt;p&gt;Less than a week later, the attacker had established a reliable backdoor connection to the employee&amp;#8217;s infected workstation. After infecting the system, &amp;#8220;the attacker continued to operate in the environment over an eight week period until the detonation of the Conti ransomware on May 14, 2021,&amp;#8221; the report states.&lt;/p&gt;
&lt;p&gt;According to &lt;a href="https://www.hse.ie/eng/services/publications/conti-cyber-attack-on-the-hse-full-report.pdf" target="_blank" rel="noopener"&gt;PWC&amp;#8217;s report&lt;/a&gt; (PDF), there were multiple warnings about a serious network intrusion, but those red flags were either misidentified or not acted on quickly enough:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On Mar. 31, 2021, the HSE&amp;#8217;s antivirus software detected the execution of two software tools commonly used by ransomware groups &amp;#8212; &lt;a href="https://www.secureworks.com/blog/detecting-cobalt-strike-cybercrime-attacks" target="_blank" rel="noopener"&gt;Cobalt Strike&lt;/a&gt; and &lt;a href="https://www.secureworks.com/blog/detecting-cobalt-strike-cybercrime-attacks" target="_blank" rel="noopener"&gt;Mimikatz&lt;/a&gt; &amp;#8212; on the Patient Zero Workstation. But the antivirus software was set to monitor mode, so it did not block the malicious commands.&amp;#8221;&lt;/li&gt;
&lt;li&gt;On May 7, the attacker compromised the HSE&amp;#8217;s servers for the first time, and over the next five days the intruder would compromise six HSE hospitals. On May 10, one of the hospitals detected malicious activity on its Microsoft Windows Domain Controller, a critical &amp;#8220;keys to the kingdom&amp;#8221; component of any Windows enterprise network that manages user authentication and network access.&lt;/li&gt;
&lt;li&gt;On 10 May 2021, security auditors first identified evidence of the attacker compromising systems within Hospital C and Hospital L. Hospital C’s antivirus software detected Cobalt Strike on two systems but failed to quarantine the malicious files.&lt;/li&gt;
&lt;li&gt;On May 13, the HSE&amp;#8217;s antivirus security provider emailed the HSE&amp;#8217;s security operations team, highlighting unhandled threat events dating back to May 7 on at least 16 systems. The HSE Security Operations team requested that the Server team restart servers.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;By then it was too late. At just after midnight Ireland time on May 14, the attacker executed the Conti ransomware within the HSE. The attack &lt;a href="https://cyberlaw.ccdcoe.org/wiki/Health_Service_Executive_ransomware_attack_(2021)" target="_blank" rel="noopener"&gt;disrupted services at several Irish hospitals&lt;/a&gt; and resulted in the near complete shutdown of the HSE&amp;#8217;s national and local networks, forcing the cancellation of many outpatient clinics and healthcare services. The number of appointments in some areas dropped by up to 80 percent.&amp;#8221;&lt;/p&gt;
&lt;p&gt;Conti initially demanded USD $20 million worth of virtual currency in exchange for a digital key to unlock HSE servers compromised by the group. But perhaps in response to the public outcry over the HSE disruption, Conti reversed course and gave the HSE the decryption keys without requiring payment.&lt;/p&gt;
&lt;p&gt;Still, the work to restore infected systems would take months. The HSE ultimately enlisted members of the Irish military to bring in laptops and PCs to help restore computer systems by hand. It wasn&amp;#8217;t until September 21, 2021 that the HSE declared 100 percent of its servers were decrypted.&lt;/p&gt;
&lt;p&gt;As bad as the HSE ransomware attack was, the PWC report emphasizes that it could have been far worse. For example, it is unclear how much data would have been unrecoverable if a decryption key had not become available as the HSE’s backup infrastructure was only periodically backed up to offline tape.&lt;/p&gt;
&lt;p&gt;The attack also could have been worse, the report found:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;if there had been intent by the Attacker to target specific devices within the HSE environment (e.g. medical devices);&lt;/li&gt;
&lt;li&gt;if the ransomware took actions to destroy data at scale;&lt;/li&gt;
&lt;li&gt;if the ransomware had auto-propagation and persistence capabilities, for example by using an exploit to propagate across domains and trust-boundaries to medical devices (e.g. the EternalBlue exploit used by the WannaCry and NotPetya15 attacks);&lt;/li&gt;
&lt;li&gt;if cloud systems had also been encrypted such as the COVID-19 vaccination system&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The PWC report contains numerous recommendations, most of which center around hiring new personnel to lead the organization&amp;#8217;s redoubled security efforts. But it is clear that the HSE has an enormous amount of work ahead &lt;a href="https://krebsonsecurity.com/2015/04/whats-your-security-maturity-level/" target="_blank" rel="noopener"&gt;to grow in security maturity&lt;/a&gt;. For example, the report notes the HSE&amp;#8217;s hospital network had over 30,000 Windows 7 workstations that were deemed end of life by the vendor.&lt;/p&gt;
&lt;p&gt;&amp;#8220;The HSE assessed its cybersecurity maturity rating as low,&amp;#8221; PWC wrote. &amp;#8220;For example, they do not have a CISO or a Security Operations Center established.&amp;#8221;&lt;span id="more-57854"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;PWC also estimates that efforts to build up the HSE&amp;#8217;s cybersecurity program to the point where it can rapidly detect and respond to intrusions are likely to cost &amp;#8220;a multiple of the HSE&amp;#8217;s current capital and operation expenditure in these areas over several years.&amp;#8221;&lt;/p&gt;
&lt;div id="attachment_29580" style="width: 1081px" class="wp-caption aligncenter"&gt;&lt;img aria-describedby="caption-attachment-29580" loading="lazy" class="size-full wp-image-29580" src="https://krebsonsecurity.com/wp-content/uploads/2014/11/SecurityMaturity.png" alt="" width="1071" height="743" srcset="https://krebsonsecurity.com/wp-content/uploads/2014/11/SecurityMaturity.png 1071w, https://krebsonsecurity.com/wp-content/uploads/2014/11/SecurityMaturity-285x198.png 285w, https://krebsonsecurity.com/wp-content/uploads/2014/11/SecurityMaturity-600x416.png 600w" sizes="(max-width: 1071px) 100vw, 1071px" /&gt;&lt;p id="caption-attachment-29580" class="wp-caption-text"&gt;One idea of a &amp;#8220;security maturity&amp;#8221; model.&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;In June 2021, the HSE&amp;#8217;s director general said the recovery costs for the May ransomware attack &lt;a href="https://www.bankinfosecurity.com/irish-ransomware-attack-recovery-cost-estimate-600-million-a-16931" target="_blank" rel="noopener"&gt;were likely to exceed USD $600 million&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;What&amp;#8217;s remarkable about this incident is that the HSE is publicly funded by the Irish government, and so in theory it has the money to spend (or raise) to pay for all these ambitious recommendations for increasing their security maturity.&lt;/p&gt;
&lt;p&gt;That stands in stark contrast to the healthcare system here in the United States, where the single biggest impediment to doing security well continues to be lack of making it a real budget priority. Also, most healthcare organizations in the United States are private companies that operate on razor-thin profit margins.&lt;/p&gt;
&lt;p&gt;I know this because in 2018 I was asked to give the keynote at an annual gathering of the &lt;strong&gt;Healthcare Information Sharing and Analysis Group&lt;/strong&gt; (H-ISAC), an industry group centered on sharing information about cybersecurity threats. I almost didn&amp;#8217;t accept the invitation: I&amp;#8217;d written very little about healthcare security, which seemed to be dominated by coverage of whether healthcare organizations complied with the letter of the law in the United States. That compliance centered on the &lt;a href="https://www.cdc.gov/phlp/publications/topic/hipaa.html#:~:text=The%20Health%20Insurance%20Portability%20and,the%20patient's%20consent%20or%20knowledge." target="_blank" rel="noopener"&gt;Health Insurance Portability and Accountability Act&lt;/a&gt; (HIPAA), which prioritizes protecting the integrity and privacy of patient data.&lt;/p&gt;
&lt;p&gt;To get up to speed, I interviewed over a dozen of the healthcare security industry&amp;#8217;s best and brightest minds. A common refrain I heard from those interviewed was that if it was security-related but didn&amp;#8217;t have to do with compliance, there probably wasn&amp;#8217;t much chance it would get any budget.&lt;/p&gt;
&lt;p&gt;Those sources unanimously said that however well-intentioned, it&amp;#8217;s not clear that the &amp;#8220;protect the data&amp;#8221; regulatory approach of HIPPA was working from an overall threat perspective. According to &lt;a href="https://www.healthcareitnews.com/news/biggest-healthcare-data-breaches-2021" target="_blank" rel="noopener"&gt;HealthcareIT News&lt;/a&gt;, more than 40 million patient records have been compromised in incidents reported to the federal government in 2021 so far alone.&lt;/p&gt;
&lt;p&gt;During my 2018 talk, I tried to emphasize the primary importance of being able to respond quickly to intrusions. Here&amp;#8217;s a snippet of what I told that H-ISAC audience:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&amp;#8220;The term &amp;#8216;Security Maturity&amp;#8217; refers to the street smarts of an individual or organization, and this maturity generally comes from making plenty of mistakes, getting hacked a lot, and hopefully learning from each incident, measuring response times, and improving.&lt;/p&gt;
&lt;p&gt;Let me say up front that all organizations get hacked. Even ones that are doing everything right from a security perspective get hacked probably every day if they’re big enough. By hacked I mean someone within the organization falls for a phishing scam, or clicks a malicious link and downloads malware. Because let’s face it, it only takes one screw up for the hackers to get a foothold in the network.&lt;/p&gt;
&lt;p&gt;Now this is in itself isn’t bad. Unless you don&amp;#8217;t have the capability to detect it and respond quickly. And if you can&amp;#8217;t do that, you run the serious risk of having a small incident metastasize into a much larger problem.&lt;/p&gt;
&lt;p&gt;Think of it like the medical concept of the &amp;#8216;Golden Hour:&amp;#8217; That short window of time directly following a traumatic injury like a stroke or heart attack in which life-saving medicine and attention is likely to be most effective. The same concept holds true in cybersecurity, and it&amp;#8217;s exactly why so many organizations these days are placing more of their resources into incident response, instead of just prevention.&amp;#8221;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;The United States&amp;#8217; somewhat decentralized healthcare system means that many ransomware outbreaks tend to be limited to regional or local healthcare facilities. But a well-placed ransomware attack or series of attacks could inflict serious damage on the sector: A &lt;a href="https://www2.deloitte.com/us/en/insights/industry/health-care/hospital-mergers-acquisition-trends.html" target="_blank" rel="noopener"&gt;December 2020 report from Deloitte&lt;/a&gt; says the top 10 health systems now control a 24 percent market share and their revenue grew at twice the rate of the rest of the market.&lt;/p&gt;
&lt;p&gt;In October 2020, KrebsOnSecurity &lt;a href="https://krebsonsecurity.com/2020/10/fbi-dhs-hhs-warn-of-imminent-credible-ransomware-threat-against-u-s-hospitals/" target="_blank" rel="noopener"&gt;broke the story&lt;/a&gt; that the &lt;strong&gt;FBI&lt;/strong&gt; and &lt;strong&gt;U.S. Department of Homeland Security&lt;/strong&gt; had obtained chatter from a top ransomware group which warned of an &amp;#8220;imminent cybercrime threat to U.S. hospitals and healthcare providers.&amp;#8221; Members associated with the Russian-speaking ransomware group known as Ryuk had discussed plans to deploy ransomware at more than 400 healthcare facilities in the United States.&lt;/p&gt;
&lt;p&gt;Hours after that piece ran, I heard from a respected H-ISAC security professional who questioned whether it was worth getting the public so riled up. The story had been updated multiple times throughout the day, and there were at least five healthcare organizations hit with ransomware within the span of 24 hours.&lt;/p&gt;
&lt;p&gt;&amp;#8220;I guess it would help if I understood what the baseline is, like how many healthcare organizations get hit with ransomware on average in one week?&amp;#8221; I asked the source.&lt;/p&gt;
&lt;p&gt;&amp;#8220;It&amp;#8217;s more like one a day,&amp;#8221; the source confided.&lt;/p&gt;
&lt;p&gt;In all likelihood, the HSE will get the money it needs to implement the programs recommended by PWC, however long that takes. I wonder how many U.S.-based healthcare organizations could say the same.&lt;/p&gt;</content:encoded>
      <category>A Little Sunshine</category>
      <category>Data Breaches</category>
      <category>Ransomware</category>
      <category>Conti ransomware</category>
      <category>H-ISAC</category>
      <category>Health Service Executive</category>
      <category>HSE</category>
      <category>Ireland</category>
      <category>PriceWaterhouseCoopers</category>
      <category>ransomware</category>
      <category>Ryuk</category>
      <pubDate>Tue, 14 Dec 2021 02:13:34 GMT</pubDate>
      <comments>https://krebsonsecurity.com/2021/12/inside-irelands-public-healthcare-ransomware-scare/#comments</comments>
      <guid isPermaLink="false">https://krebsonsecurity.com/?p=57854</guid>
      <dc:creator>BrianKrebs</dc:creator>
      <dc:date>2021-12-14T02:13:34Z</dc:date>
    </item>
    <item>
      <title>XDR: What It Is, What It Isn't</title>
      <link>https://www.darkreading.com/crowdstrike/xdr-what-it-is-what-it-isn-t</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt9b7e32584d879045/61b83a84165ecc74601801f9/network-screen-_WavebreakmediaLtd-alamy-2g6x52n.jpg" type="image/*" />
      <description>The three must-haves in eXtended Detection and Response are: making data accessible, facilitating real-time threat detection, and providing remediation strategies.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt9c36357b6a758691/61b83b516936db746d6d6cb5/ZekiTuredi_crowdstrike.jpg" type="image/*" />
      <pubDate>Tue, 14 Dec 2021 01:26:57 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/crowdstrike/xdr-what-it-is-what-it-isn-t</guid>
      <dc:creator>Zeki Turedi, CTO for EMEA, CrowdStrike</dc:creator>
      <dc:date>2021-12-14T01:26:57Z</dc:date>
    </item>
    <item>
      <title>Collecting In the Dark: Tropic Trooper Targets Transportation and Government</title>
      <link>https://www.trendmicro.com/en_us/research/21/l/collecting-in-the-dark-tropic-trooper-targets-transportation-and-government-organizations.html</link>
      <description>Our long-term monitoring of the cyberespionage group Earth Centaur (aka Tropic Trooper) shows that the threat actors are equipped with new tools and techniques. The group seems to be targeting transportation companies and government agencies related to transportation.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/l/collecting-in-the-dark-tropic-trooper-targets-transportation-and-government-organizations/earth%20trooper%20banner.jpg" type="image/jpeg" />
      <category>Trend Micro Research : APT &amp; Targeted Attacks</category>
      <category>Trend Micro Research : Endpoints</category>
      <category>Trend Micro Research : Research</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <pubDate>Tue, 14 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:6db8d481-4337-d9dc-2f93-57cac506afa5</guid>
      <dc:creator>Nick Dai</dc:creator>
      <dc:date>2021-12-14T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Tales from the Dark Web: Fingerprinting Access Brokers on Criminal Forums</title>
      <link>https://www.darkreading.com/crowdstrike/tales-from-the-dark-web-fingerprinting-access-brokers-on-criminal-forums</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt79ed729ae9a850f8/61b8331849813175aa3610d2/investigating-federico-caputo-Alamy-JBTGH3.jpg" type="image/*" />
      <description>Every high-profile breach leaves a trail of bread crumbs, and defenders who monitor access brokers can connect the dots and detect attacks as they unfold.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt84fa8c65a0bfb064/61b83c7189fca95dc5b460ba/Bart_LenaertsBergmans_crowdstrike.jpg" type="image/*" />
      <pubDate>Mon, 13 Dec 2021 23:52:24 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/crowdstrike/tales-from-the-dark-web-fingerprinting-access-brokers-on-criminal-forums</guid>
      <dc:creator>Bart Lenaerts-Bergmans, Senior Product Marketing Manager, Threat Intelligence,CrowdStrike</dc:creator>
      <dc:date>2021-12-13T23:52:24Z</dc:date>
    </item>
    <item>
      <title>Log4Shell: The race is on to fix millions of systems and internet-connected devices</title>
      <link>https://grahamcluley.com/log4shell/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://grahamcluley.com/log4shell/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <description>Everyone is talking about Log4Shell, a zero-day remote code execution exploit in versions of log4j, the popular open source Java logging library.</description>
      <category>Malware</category>
      <category>Vulnerability</category>
      <category>Apache</category>
      <category>log4j</category>
      <category>log4shell</category>
      <category>Minecraft</category>
      <category>open source</category>
      <category>vulnerability</category>
      <pubDate>Mon, 13 Dec 2021 23:37:43 GMT</pubDate>
      <comments>https://grahamcluley.com/log4shell/#respond</comments>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333579</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-12-13T23:37:43Z</dc:date>
    </item>
    <item>
      <title>Why Classifying Ransomware as a National Security Threat Matters</title>
      <link>https://www.darkreading.com/dr-tech/why-classifying-ransomware-as-a-national-security-threat-matters</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt6bed4e17c1211755/60e2f85bcc810807a334810c/government_shutterstock_771481801_489by2xx.png" type="image/*" />
      <description>Government actions help starve attack groups of the resources - money, ability to recruit, and time.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt93784ffee79538e7/60d4371522d24e38a3806ecf/fahmida.png" type="image/*" />
      <pubDate>Mon, 13 Dec 2021 23:10:59 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/dr-tech/why-classifying-ransomware-as-a-national-security-threat-matters</guid>
      <dc:creator>Fahmida Y. Rashid, Features Editor, Dark Reading</dc:creator>
      <dc:date>2021-12-13T23:10:59Z</dc:date>
    </item>
    <item>
      <title>How Do I Find My Servers With the Log4j Vulnerability?</title>
      <link>https://www.darkreading.com/dr-tech/how-do-i-find-which-servers-have-the-log4j-vulnerability-</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt9bc060177ed71e3c/615bd0bb72f27552bdb80e33/computer_smartphone_iStock_75724573.jpg" type="image/*" />
      <description>This Tech Tip outlines how enterprises can use Canarytokens to find servers in their organization vulnerable to CVE-2021-44228.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt93784ffee79538e7/60d4371522d24e38a3806ecf/fahmida.png" type="image/*" />
      <pubDate>Mon, 13 Dec 2021 22:41:20 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/dr-tech/how-do-i-find-which-servers-have-the-log4j-vulnerability-</guid>
      <dc:creator>Fahmida Y. Rashid, Features Editor, Dark Reading</dc:creator>
      <dc:date>2021-12-13T22:41:20Z</dc:date>
    </item>
    <item>
      <title>Volvo Confirms R&amp;D Data Stolen in Breach</title>
      <link>https://www.darkreading.com/threat-intelligence/volvo-confirms-r-d-data-stolen-in-breach</link>
      <description>The company confirmed last week that one of its file repositories was accessed by a third party.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte161b23f0fd3a84b/60b1ea374e7eb868c4c6a293/dr_staff_125x125.jpg" type="image/*" />
      <pubDate>Mon, 13 Dec 2021 22:15:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/threat-intelligence/volvo-confirms-r-d-data-stolen-in-breach</guid>
      <dc:creator>Dark Reading Staff, Dark Reading</dc:creator>
      <dc:date>2021-12-13T22:15:00Z</dc:date>
    </item>
    <item>
      <title>Kronos Suffers Ransomware Attack, Expects Full Restoration to Take 'Weeks'</title>
      <link>https://www.darkreading.com/attacks-breaches/kronos-suffers-ransomware-attack-expects-full-restoration-to-take-weeks-</link>
      <description>Customers advised to adopt alternative internal processes to support the affected human resources services.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte161b23f0fd3a84b/60b1ea374e7eb868c4c6a293/dr_staff_125x125.jpg" type="image/*" />
      <pubDate>Mon, 13 Dec 2021 21:45:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/attacks-breaches/kronos-suffers-ransomware-attack-expects-full-restoration-to-take-weeks-</guid>
      <dc:creator>Dark Reading Staff, Dark Reading</dc:creator>
      <dc:date>2021-12-13T21:45:00Z</dc:date>
    </item>
    <item>
      <title>40% of Corporate Networks Targeted by Attackers Seeking to Exploit Log4j</title>
      <link>https://www.darkreading.com/application-security/40-of-corporate-networks-targeted-by-attackers-seeking-to-exploit-log4j</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt070056254b66a67b/61b7ae986cfd9e67c963a4e4/image002.png" type="image/*" />
      <description>More than 60 variants of the original exploit were introduced over the last day alone.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt02d79fb9a44a4258/60b1e9dd2a25046b35110696/Jai-Vijayan.jpeg" type="image/*" />
      <pubDate>Mon, 13 Dec 2021 21:25:41 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/application-security/40-of-corporate-networks-targeted-by-attackers-seeking-to-exploit-log4j</guid>
      <dc:creator>Jai Vijayan, Contributing Writer</dc:creator>
      <dc:date>2021-12-13T21:25:41Z</dc:date>
    </item>
    <item>
      <title>Bug-Bounty Programs Shift Focus to Most Critical Flaws</title>
      <link>https://www.darkreading.com/application-security/bug-bounty-programs-shift-focus-to-most-critical-flaws</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt3cb53565705bac65/61b3c2df1c97765f0a8d5b0f/bounties-hackerone.jpg" type="image/*" />
      <description>The number of bug bounty programs jumped by a third, the median payout for a critical vulnerability report rose to $3,000, but rewards for easier-to-find lower-severity flaws stagnated in 2021.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt58481326324d6911/60b1e9a55d34de550780a990/Robert-Lemos.png" type="image/*" />
      <pubDate>Mon, 13 Dec 2021 21:10:58 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/application-security/bug-bounty-programs-shift-focus-to-most-critical-flaws</guid>
      <dc:creator>Robert Lemos, Contributing Writer</dc:creator>
      <dc:date>2021-12-13T21:10:58Z</dc:date>
    </item>
    <item>
      <title>Log4Shell explained – how it works, why you need to know, and how to fix it</title>
      <link>https://nakedsecurity.sophos.com/2021/12/13/log4shell-explained-how-it-works-why-you-need-to-know-and-how-to-fix-it/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://nakedsecurity.sophos.com/2021/12/13/log4shell-explained-how-it-works-why-you-need-to-know-and-how-to-fix-it/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">60</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/shell-1220.jpg?w=230&amp;h=130&amp;crop=1" medium="image" />
      <post-id xmlns="com-wordpress:feed-additions:1">647469</post-id>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/shell-1220.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/shell-1220.jpg?w=170&amp;h=90&amp;crop=1" medium="image" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/7z-file-692.png" medium="image" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/7z-remv-692.png" medium="image" />
      <description>Find out how to deal with the Log4Shell vulnerability right across your estate. Yes, you need to patch, but that helps everyone else along with you!</description>
      <category>Vulnerability</category>
      <category>CVE-2021-44228</category>
      <category>Log4j</category>
      <category>Log4Shell</category>
      <pubDate>Mon, 13 Dec 2021 19:41:01 GMT</pubDate>
      <comments>https://nakedsecurity.sophos.com/2021/12/13/log4shell-explained-how-it-works-why-you-need-to-know-and-how-to-fix-it/#comments</comments>
      <guid isPermaLink="false">https://nakedsecurity.sophos.com/?p=647469</guid>
      <dc:creator>Paul Ducklin</dc:creator>
      <dc:date>2021-12-13T19:41:01Z</dc:date>
    </item>
    <item>
      <title>Name That Toon: Modern-Day Frosty</title>
      <link>https://www.darkreading.com/threat-intelligence/name-that-toon-modern-day-frosty</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt68f9c01919d6cd43/61b79cfd1afa056e4cf22a65/DR_Dec2021Toon.jpg" type="image/*" />
      <description>Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltf97d71984b60d7ed/60b1e88b5d34de550780a96e/Klossner_iwk_photo.gif" type="image/*" />
      <pubDate>Mon, 13 Dec 2021 19:05:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/threat-intelligence/name-that-toon-modern-day-frosty</guid>
      <dc:creator>John Klossner, Cartoonist</dc:creator>
      <dc:date>2021-12-13T19:05:00Z</dc:date>
    </item>
    <item>
      <title>Darktrace Reports Information Technology and Communications Sector Most Targeted by Cyberattackers in 2021</title>
      <link>https://www.darkreading.com/attacks-breaches/darktrace-reports-information-technology-and-communications-sector-most-targeted-by-cyberattackers-in-2021</link>
      <description>Most targeted industry shifts from the financial and insurance sector in 2020.</description>
      <pubDate>Mon, 13 Dec 2021 17:38:34 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/attacks-breaches/darktrace-reports-information-technology-and-communications-sector-most-targeted-by-cyberattackers-in-2021</guid>
      <dc:date>2021-12-13T17:38:34Z</dc:date>
    </item>
    <item>
      <title>Kaspersky Opens Doors to New Transparency Center in North America</title>
      <link>https://www.darkreading.com/vulnerabilities-threats/kaspersky-opens-doors-to-new-transparency-center-in-north-america</link>
      <description>The opening marks the fifth center opened globally, fulfilling a key milestone within the Global Transparency Initiative.</description>
      <pubDate>Mon, 13 Dec 2021 17:35:59 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/vulnerabilities-threats/kaspersky-opens-doors-to-new-transparency-center-in-north-america</guid>
      <dc:date>2021-12-13T17:35:59Z</dc:date>
    </item>
    <item>
      <title>2 Website Threats to Address for the Holiday Shopping Rush</title>
      <link>https://www.darkreading.com/vulnerabilities-threats/2-website-threats-to-address-ahead-of-the-holiday-shopping-rush</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt142361c6d7acfb5a/61b27601f763d07473959424/ChristmasPresents_Piotr_Kaźmierski_Alamy.jpg" type="image/*" />
      <description>Some tips for effectively combating Web supply chain attacks and customer hijacking via browser extensions.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte37cdd331d538154/60b1e7b42a25046b3511064a/PedroFortuna.png" type="image/*" />
      <pubDate>Mon, 13 Dec 2021 15:15:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/vulnerabilities-threats/2-website-threats-to-address-ahead-of-the-holiday-shopping-rush</guid>
      <dc:creator>Pedro Fortuna, CTO and Co-Founder, Jscrambler</dc:creator>
      <dc:date>2021-12-13T15:15:00Z</dc:date>
    </item>
    <item>
      <title>Why the Private Sector Is Key to Stopping Russian Hacking Group APT29</title>
      <link>https://www.darkreading.com/attacks-breaches/why-the-private-sector-is-key-to-stopping-russian-hacking-group-apt29</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt2d65e38bbb926ed0/61b0c34a08871175a48ce402/HackerWithMap_NicoElNino_Alamy.jpg" type="image/*" />
      <description>Left unchecked, these attacks could have devastating effects on government and military secrets and jeopardize the software supply chain and the global economy.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltba222522d4817446/61acd44667f7b65c33606e91/Shmulik_Yehezkel.png" type="image/*" />
      <pubDate>Mon, 13 Dec 2021 15:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/attacks-breaches/why-the-private-sector-is-key-to-stopping-russian-hacking-group-apt29</guid>
      <dc:creator>Shmulik Yehezkel, Chief Critical Cyber Operations Officer &amp; CISO, CYE</dc:creator>
      <dc:date>2021-12-13T15:00:00Z</dc:date>
    </item>
    <item>
      <title>Why Cloud Service Providers Are a Single Point of Failure</title>
      <link>https://www.darkreading.com/cloud/why-cloud-service-providers-are-a-single-point-of-failure</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt8016638b347030de/61ae92673a693068e136bb46/CloudComputing_AkuZone_Alamy.jpg" type="image/*" />
      <description>In a matter of days, a large-scale outage of cloud and other online services could cause $15 billion in losses.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt47e357f8e2247e4c/60b1e7472d381b69fb11e912/MarkWilczek.png" type="image/*" />
      <pubDate>Mon, 13 Dec 2021 15:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/cloud/why-cloud-service-providers-are-a-single-point-of-failure</guid>
      <dc:creator>Marc Wilczek, Digital Strategist &amp; COO, Link11</dc:creator>
      <dc:date>2021-12-13T15:00:00Z</dc:date>
    </item>
    <item>
      <title>Kaspersky opens Transparency Center in North America | Kaspersky official blog</title>
      <link>https://www.kaspersky.com/blog/kaspersky-transparency-center-north-america/43133/</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/13080807/kaspersky-transparency-center-north-america-featured.jpg" width="1460" height="960">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/13080807/kaspersky-transparency-center-north-america-featured-1024x673.jpg" width="1024" height="673">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/13080807/kaspersky-transparency-center-north-america-featured-300x197.jpg" width="300" height="197">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/13080807/kaspersky-transparency-center-north-america-featured-150x150.jpg" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>Kaspersky opens its fifth Transparency Center. The new facility — our first in North America — is in Fredericton, New Brunswick, Canada.</description>
      <content:encoded>&lt;p&gt;At the tail end of 2017, Eugene Kaspersky made a bold announcement: that we would be launching our &lt;a href="https://www.kaspersky.com/blog/even-more-transparency/19943/" target="_blank" rel="noopener"&gt;Global Transparency Initiative&lt;/a&gt;. The program has since given our prospective customers, governments, and partners the unprecedented ability to inspect our source code.&lt;/p&gt;
&lt;p&gt;Trust in cybersecurity being vital, the company knew transparency needed to be more than just words — and that revealing our source code in any way meant we needed extra levels of security. To address the first part, we decided to open up Transparency Centers around the world where the folks listed above could inspect our code in a safe and secure location. In addition to satisfying any concerns they had, they could also help further &lt;a href="https://www.kaspersky.com/blog/kaspersky-lab-mythbusters/23138/" target="_blank" rel="noopener"&gt;debunk media myths&lt;/a&gt; about backdoors or other nonsense. The first of the centers was in Zurich, Switzerland; &lt;a href="https://www.kaspersky.com/blog/transparency-status-updates/23637/" target="_blank" rel="noopener"&gt;others opened elsewhere in Europe as well as Latin America and Asia&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The latest is in Fredericton, New Brunswick, Canada. As a US citizen, I&amp;#8217;m excited about this opening it&amp;#8217;s just a short flight and drive away. To get a good look at any other centers would involve flying across the Atlantic! Aside from my general interest in checking out the center, I was pleased to sit down recently with Robert Cataldo, Kaspersky North America&amp;#8217;s managing director, to discuss why our newest center is so important to the company&amp;#8217;s business.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Jeff Esposito:&lt;/strong&gt; &lt;em&gt;Rob, can you tell us a bit about why transparency is important to Kaspersky?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Robert Cataldo:&lt;/strong&gt; Transparency should be an important principle for every organization, but especially for those in cybersecurity. Industry, academia, government, and consumers trust us to protect their most precious and confidential information. To maintain and build this trust, we consider it essential to clearly communicate the transparency measures we&amp;#8217;re taking and to allow interested stakeholders the opportunity to evaluate all aspects of our business practices and development procedures.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;JE:&lt;/strong&gt; &lt;em&gt;This is the first Transparency Center on this side of the Atlantic; why is it important for the business — and why Canada?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;RC:&lt;/strong&gt; Our global vision for the formal transparency initiative established about four years ago included a physical transparency center in North America where interested parties could come and conduct code reviews or even be trained on what to look for during such reviews. We felt it important to deliver on this vision to ensure that we have accessible transparency centers for all the major regions around the world where we operate. We considered many factors when choosing the location for North America, but a big driver for being in New Brunswick became the partnership we could enter into with &lt;a href="https://cybernb.ca/" target="_blank" rel="nofollow noopener"&gt;CyberNB&lt;/a&gt;, which now hosts our facility in its brand new Cyber Centre.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;JE:&lt;/strong&gt; &lt;em&gt;What does this center mean for the business in the Americas?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;RC:&lt;/strong&gt; The center is a big step toward setting the right example in North America and creating a high standard of openness in our industry.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;JE:&lt;/strong&gt; &lt;em&gt;What will a verified customer or partner get to experience in the Transparency Center?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;RC:&lt;/strong&gt; In addition to conducting a full review of our source code, rules, and code base updates, customers and partners can also be trained on the important elements to look for as part of our Cyber Capacity Building Program. Moreover, while there, we can also arrange for product briefings and/or demonstrations for anyone interested.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;JE:&lt;/strong&gt; &lt;em&gt;What can we expect from our partnership with CyberNB? How does it help further the message of the GTI?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;RC:&lt;/strong&gt; CyberNB fosters collaboration, sharing, and improved cybermeasures among critical infrastructure, industry, academia, and government and holds a common vision with Kaspersky concerning the importance of transparency in our industry. They have their own transparency center in the Cyber Centre, which creates an opportunity for us to compare notes and help each other improve. CyberNB has also created a member program referred to as CIPNet, short for Critical Infrastructure Protection Network. Kaspersky is a proud member of CIPNet and we&amp;#8217;ve already begun exploring synergies with other members to proliferate our transparency principles and further our mission of building a safer world for our partners and customers.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/13081241/kaspersky-transparency-center-north-america-cybernb.jpg"&gt;&lt;img src="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/13081241/kaspersky-transparency-center-north-america-cybernb.jpg" alt="Cyber Center in Fredericton, New Brunswick" width="1340" height="890" class="aligncenter size-full wp-image-43138" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;JE:&lt;/strong&gt; &lt;em&gt;Talk a bit about the Cyber Centre, the building that our Transparency Center is housed in. I heard you were able to visit and tour the facility. Is that correct?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;RC:&lt;/strong&gt; The Cyber Centre in Fredericton, New Brunswick is brand-new, and I was fortunate enough to be invited to tour the facility in early December. The center is a modern, world-class building with a well-planned layout for large briefings, small business collaborations, transparency reviews, product certifications, trainings, and all kinds of business events. The center also houses CyberNB&amp;#8217;s critical infrastructure SOC, which features large displays of the various forms of threat intelligence — including Kaspersky&amp;#8217;s own threat data feeds — and security tools CIPNet members can take advantage of.&lt;/p&gt;
&lt;p&gt;Access to the Transparency Center is available on request. To learn more about Kaspersky&amp;#8217;s Global Transparency Initiative, please visit its &lt;a href="https://www.kaspersky.com/transparency-center" target="_blank" rel="noopener"&gt;website&lt;/a&gt;.&lt;/p&gt;
&lt;input type="hidden" class="category_for_banner" value="kesb-top3" /&gt;</content:encoded>
      <category>Business</category>
      <category>Enterprise</category>
      <category>News</category>
      <category>Global Transparency Initiative</category>
      <category>GTI</category>
      <category>kaspersky</category>
      <category>transparency</category>
      <pubDate>Mon, 13 Dec 2021 14:00:59 GMT</pubDate>
      <guid isPermaLink="false">https://www.kaspersky.com/blog/?p=43133</guid>
      <dc:creator>Jeffrey Esposito</dc:creator>
      <dc:date>2021-12-13T14:00:59Z</dc:date>
    </item>
    <item>
      <title>Indian PM Narendra Modi's Twitter account hacked to declare bitcoin legal tender</title>
      <link>https://www.computing.co.uk/news/4041956/indian-pm-narendra-modi-twitter-account-hacked-declare-bitcoin-legal-tender</link>
      <description>&lt;img alt="Indian PM Narendra Modi&amp;#39;s Twitter account hacked to declare bitcoin legal tender" src="https://www.computing.co.uk/api/v1/wps/2924abd/2b202181-1fe3-48b7-87e7-367ab00c0dec/8/Modi-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; The incident comes at the time when the government is reportedly working on a Bill to ban 'all private cryptocurrencies' in the country with 'certain exceptions' &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Mon, 13 Dec 2021 12:25:03 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4041956/indian-pm-narendra-modi-twitter-account-hacked-declare-bitcoin-legal-tender</guid>
      <dc:date>2021-12-13T12:25:03Z</dc:date>
    </item>
    <item>
      <title>NSO Group’s Pegasus Spyware Used Against US State Department Officials</title>
      <link>https://www.schneier.com/blog/archives/2021/12/nso-groups-pegasus-spyware-used-against-us-state-department-officials.html</link>
      <thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">65</thr:total>
      <description>&lt;p&gt;NSO Group&amp;#8217;s descent into Internet pariah status continues. Its Pegasus spyware &lt;a href="https://www.reuters.com/technology/exclusive-us-state-department-phones-hacked-with-israeli-company-spyware-sources-2021-12-03/"&gt;was used&lt;/a&gt; against nine US State Department employees. We don&amp;#8217;t know which NSO Group customer trained the spyware on the US. But the company does:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;NSO Group said in a statement on Thursday that it did not have any indication their tools were used but canceled access for the relevant customers and would investigate based on the Reuters inquiry.&lt;/p&gt;
&lt;p&gt;&amp;#8220;If our investigation shall show these actions indeed happened with NSO&amp;#8217;s tools, such customer will be terminated permanently and legal actions will take place,&amp;#8221; said an NSO spokesperson, who added that NSO will also &amp;#8220;cooperate with any relevant government authority and present the full information we will have.&amp;#8221;...&lt;/p&gt;&lt;/blockquote&gt;</description>
      <content:encoded>&lt;p&gt;NSO Group&amp;#8217;s descent into Internet pariah status continues. Its Pegasus spyware &lt;a href="https://www.reuters.com/technology/exclusive-us-state-department-phones-hacked-with-israeli-company-spyware-sources-2021-12-03/"&gt;was used&lt;/a&gt; against nine US State Department employees. We don&amp;#8217;t know which NSO Group customer trained the spyware on the US. But the company does:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;NSO Group said in a statement on Thursday that it did not have any indication their tools were used but canceled access for the relevant customers and would investigate based on the Reuters inquiry.&lt;/p&gt;
&lt;p&gt;&amp;#8220;If our investigation shall show these actions indeed happened with NSO&amp;#8217;s tools, such customer will be terminated permanently and legal actions will take place,&amp;#8221; said an NSO spokesperson, who added that NSO will also &amp;#8220;cooperate with any relevant government authority and present the full information we will have.&amp;#8221;&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <category domain="https://www.schneier.com">Uncategorized</category>
      <category domain="https://www.schneier.com">cyberespionage</category>
      <category domain="https://www.schneier.com">hacking</category>
      <category domain="https://www.schneier.com">Israel</category>
      <category domain="https://www.schneier.com">spyware</category>
      <pubDate>Mon, 13 Dec 2021 12:16:44 GMT</pubDate>
      <guid isPermaLink="false">https://www.schneier.com/?p=64630</guid>
      <dc:creator>Bruce Schneier</dc:creator>
      <dc:date>2021-12-13T12:16:44Z</dc:date>
    </item>
    <item>
      <title>Germany's new government vows to support end-to-end encryption while UK looks to undermine it</title>
      <link>https://www.computing.co.uk/news/4041944/germany-government-vows-support-end-end-encryption-uk-looks-undermine</link>
      <description>&lt;img alt="Germany&amp;#39;s new government vows to support end-to-end encryption while UK looks to undermine it" src="https://www.computing.co.uk/api/v1/wps/d1185bb/5d500958-eeae-4009-a3c9-43202828cbe7/13/encryption-02-185x114.jpeg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Germany's approach is the opposite to what British government thinks about the use of encryption on digital platforms &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Mon, 13 Dec 2021 10:18:24 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4041944/germany-government-vows-support-end-end-encryption-uk-looks-undermine</guid>
      <dc:date>2021-12-13T10:18:24Z</dc:date>
    </item>
    <item>
      <title>Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited</title>
      <link>https://www.trendmicro.com/en_us/research/21/l/patch-now-apache-log4j-vulnerability-called-log4shell-being-acti.html</link>
      <description>Log4Shell., also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched with version 2.15.0 of Log4j on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/l/patch-now-apache-log4j-vulnerability-called-log4shell-being-actively-exploited/log4shell-main.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Articles, News, Reports</category>
      <category>Trend Micro Research : Exploits &amp; Vulnerabilities</category>
      <category>Trend Micro Research : Research</category>
      <pubDate>Mon, 13 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:94309dd2-e41b-6521-e266-7367f7231bc4</guid>
      <dc:creator>Ranga Duraisamy</dc:creator>
      <dc:date>2021-12-13T00:00:00Z</dc:date>
    </item>
    <item>
      <title>A Look Into Purple Fox’s Server Infrastructure</title>
      <link>https://www.trendmicro.com/en_us/research/21/l/a-look-into-purple-fox-server-infrastructure.html</link>
      <description>By examining Purple Fox’s routines and activities, both with our initial research and the subject matter we cover in this blog post, we hope to help incident responders, security operation centers (SOCs), and security researchers find and weed out Purple Fox infections in their network.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/l/a-look-into-purple-fox-infrastructure/purplefox-641.png" type="image/png" />
      <category>Trend Micro Research : Malware</category>
      <category>Trend Micro Research : Endpoints</category>
      <category>Trend Micro Research : Research</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <pubDate>Mon, 13 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:35c300eb-d0f2-d12c-047e-393f174113f2</guid>
      <dc:creator>Jay Yaneza</dc:creator>
      <dc:date>2021-12-13T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Why You Need XDR in Today's Threat Landscape</title>
      <link>https://www.trendmicro.com/en_us/ciso/21/l/why-xdr-is-necessary-in-todays-attack-landscape.html</link>
      <description>Trend Micro's VP of Threat Intelligence, Jon Clay, explores the latest trends in today's threat landscape and why XDR is key to enabling more resilience.</description>
      <source url="https://www.trendmicro.com/en_us/ciso.html">CISO Resource Center</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/ciso/21/l/why-xdr-is-necessary-in-todays-attack-landscape/why-xdr-necessary.jpg" type="image/jpeg" />
      <category>Trend Micro CISO : Article</category>
      <category>Trend Micro CISO : Digital Transformation</category>
      <category>Trend Micro CISO : Cloud</category>
      <category>Trend Micro CISO : Expert Perspective</category>
      <category>Trend Micro CISO : Risk Management</category>
      <category>Trend Micro CISO : Detection and Response</category>
      <pubDate>Mon, 13 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:a1e268a7-b713-8caa-37f0-1c302366a7d2</guid>
      <dc:creator>Jon Clay</dc:creator>
      <dc:date>2021-12-13T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Log4Shell: critical vulnerability in Apache Log4j | Kaspersky official blog</title>
      <link>https://www.kaspersky.com/blog/log4shell-critical-vulnerability-in-apache-log4j/43124/</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/11094615/log4shell-critical-vulnerability-in-apache-log4j-featured.jpg" width="1460" height="960">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/11094615/log4shell-critical-vulnerability-in-apache-log4j-featured-1024x673.jpg" width="1024" height="673">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/11094615/log4shell-critical-vulnerability-in-apache-log4j-featured-300x197.jpg" width="300" height="197">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/11094615/log4shell-critical-vulnerability-in-apache-log4j-featured-150x150.jpg" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>Researchers found critical vulnerability in Apache Log4j with CVSS 10 designated as CVE-2021-44228 (aka Log4Shell or LogJam). Here’s how to mitigate.</description>
      <content:encoded>&lt;p&gt;Various information security news outlets reported on the discovery of critical vulnerability &lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228" target="_blank" rel="nofollow noopener"&gt;CVE-2021-44228&lt;/a&gt; in the Apache Log4j library (CVSS severity level 10 out of 10). Millions of Java applications use this library to log error messages. To make matters worse, attackers are already actively exploiting this vulnerability. For this reason, the Apache Foundation recommends all developers to update the library to version 2.15.0, and if this is not possible, use one of the methods described on the &lt;a href="https://logging.apache.org/log4j/2.x/security.html" target="_blank" rel="nofollow noopener"&gt;Apache Log4j Security Vulnerabilities page&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Why CVE-2021-44228 is so dangerous&lt;/h2&gt;
&lt;p&gt;CVE-2021-44228, also named Log4Shell or LogJam, is a &lt;a href="https://encyclopedia.kaspersky.com/glossary/remote-code-execution-rce/" target="_blank" rel="noopener"&gt;Remote Code Execution (RCE)&lt;/a&gt; class vulnerability. If attackers manage to exploit it on one of the servers, they gain the ability to execute arbitrary code and potentially take full control of the system.&lt;/p&gt;
&lt;p&gt;What makes CVE-2021-44228 especially dangerous is the ease of exploitation: even an inexperienced hacker can successfully execute an attack using this vulnerability. According to the researchers, attackers only need to force the application to write just one string to the log, and after that they are able to upload their own code into the application due to the &lt;em&gt;message lookup substitution&lt;/em&gt; function.&lt;/p&gt;
&lt;p&gt;Working &lt;a href="https://encyclopedia.kaspersky.com/glossary/poc-proof-of-concept/" target="_blank" rel="noopener"&gt;Proofs of Concept (PoC)&lt;/a&gt; for the attacks via CVE-2021-44228 are already available on the Internet. Therefore, it&amp;#8217;s not surprising that cybersecurity companies are already registering massive network scans for vulnerable applications as well as attacks on honeypots.&lt;/p&gt;
&lt;p&gt;This vulnerability was discovered by Chen Zhaojun of Alibaba Cloud Security Team.&lt;/p&gt;
&lt;h2&gt;What is Apache Log4J and why is this library is so popular?&lt;/h2&gt;
&lt;p&gt;Apache Log4j is part of the Apache Logging Project. By and large, usage of this library is one of the easiest ways to log errors, and that is why most Java developers use it.&lt;/p&gt;
&lt;p&gt;Many large software companies and online services use the Log4j library, including Amazon, Apple iCloud, Cisco, Cloudflare, ElasticSearch, Red Hat, Steam, Tesla, Twitter, and many more. Because of the library being so popular, some information security researchers expect a significant increase in the attacks on vulnerable servers over the coming days.&lt;/p&gt;
&lt;blockquote class="twitter-tweet" data-width="500" data-dnt="true"&gt;
&lt;p lang="und" dir="ltr"&gt;&lt;a href="https://twitter.com/hashtag/Log4Shell?src=hash&amp;#38;ref_src=twsrc%5Etfw"&gt;#Log4Shell&lt;/a&gt; &lt;a href="https://t.co/1bKDwRQBqt"&gt;pic.twitter.com/1bKDwRQBqt&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;#8212; Florian Roth ⚡️ (@cyb3rops) &lt;a href="https://twitter.com/cyb3rops/status/1469326219174891520?ref_src=twsrc%5Etfw"&gt;December 10, 2021&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;&lt;script async src="https://platform.twitter.com/widgets.js" charset="utf-8"&gt;&lt;/script&gt;&lt;/p&gt;
&lt;h2&gt;Which versions of the Log4j library is vulnerable and how can you protect your servers from attack?&lt;/h2&gt;
&lt;p&gt;Almost all versions of Log4j are vulnerable, starting from 2.0-beta9 to 2.14.1. &lt;strong&gt; The simplest and most effective protection method is to install the most recent version of the library, 2.15.0&lt;/strong&gt;. You can download it on the &lt;a href="https://logging.apache.org/log4j/2.x/download.html" target="_blank" rel="nofollow noopener"&gt;project page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If for some reason updating the library is not possible, Apache Foundation recommends using one of the mitigation methods. In case of Log4J versions from 2.10 to 2.14.1, they advise setting the &lt;strong&gt;log4j2.formatMsgNoLookups&lt;/strong&gt; system property, or setting the &lt;strong&gt;LOG4J_FORMAT_MSG_NO_LOOKUPS&lt;/strong&gt; environment variable to &lt;strong&gt;true&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;To protect earlier releases of Log4j (from 2.0-beta9 to 2.10.0), the library developers recommend removing the &lt;strong&gt;JndiLookup&lt;/strong&gt; class from the classpath: &lt;strong&gt;zip -q -d log4j-core &amp;#8211; *. Jar org / apache / logging / log4j / core / lookup / JndiLookup .class&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;In addition, we recommend to install &lt;a href="https://www.kaspersky.com/small-to-medium-business-security?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______" target="_blank"&gt;security solutions&lt;/a&gt; on your servers — in many cases this will allow you to detect the launch of malicious code and stop the attack&amp;#8217;s development.&lt;/p&gt;
&lt;p&gt;You can find more information about Log2shell vulnerabilities here:&lt;br /&gt;
&lt;iframe title="The Log4Shell Vulnerability – explained: how to stay secure" src="https://www.slideshare.net/slideshow/embed_code/key/q7Jk6GuP1owRUb" width="427" height="356" frameborder="0" marginwidth="0" marginheight="0" scrolling="no" style="border:1px solid #CCC; border-width:1px; margin-bottom:5px; max-width: 100%;" allowfullscreen&gt; &lt;/iframe&gt; &lt;/p&gt;
&lt;div style="margin-bottom:5px"&gt; &lt;strong&gt; &lt;a href="https://www.slideshare.net/KasperskyLabGlobal/the-log4shell-vulnerability-explained-how-to-stay-secure-250878098" title="The Log4Shell Vulnerability – explained: how to stay secure" target="_blank"&gt;The Log4Shell Vulnerability – explained: how to stay secure&lt;/a&gt; &lt;/strong&gt; from &lt;strong&gt;&lt;a href="https://www.slideshare.net/KasperskyLabGlobal" target="_blank"&gt;Kaspersky&lt;/a&gt;&lt;/strong&gt; &lt;/div&gt;
&lt;input type="hidden" class="category_for_banner" value="kesb-trial" /&gt;</content:encoded>
      <category>Business</category>
      <category>Enterprise</category>
      <category>SMB</category>
      <category>Threats</category>
      <category>0days</category>
      <category>Apache</category>
      <category>CVE-2021-44228</category>
      <category>Log4j</category>
      <category>vulnerabilities</category>
      <pubDate>Sat, 11 Dec 2021 14:47:22 GMT</pubDate>
      <guid isPermaLink="false">https://www.kaspersky.com/blog/?p=43124</guid>
      <dc:creator>Nikolay Pankov</dc:creator>
      <dc:date>2021-12-11T14:47:22Z</dc:date>
    </item>
    <item>
      <title>What to Do While Waiting for the Log4j Updates</title>
      <link>https://www.darkreading.com/dr-tech/what-to-do-while-waiting-for-the-log4ju-updates</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt3fee3feceeb7f8d5/61b192f649813175aa360f0f/printer_Rawpixel_shutterstock.jpg" type="image/*" />
      <description>This Tech Tip outlines how enterprise defenders can mitigate the risks of the Log4j vulnerabilities for the short-term while waiting for updates.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt93784ffee79538e7/60d4371522d24e38a3806ecf/fahmida.png" type="image/*" />
      <pubDate>Sat, 11 Dec 2021 04:06:54 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/dr-tech/what-to-do-while-waiting-for-the-log4ju-updates</guid>
      <dc:creator>Fahmida Y. Rashid, Features Editor, Dark Reading</dc:creator>
      <dc:date>2021-12-11T04:06:54Z</dc:date>
    </item>
    <item>
      <title>Friday Squid Blogging: The Far Side Squid Comic</title>
      <link>https://www.schneier.com/blog/archives/2021/12/friday-squid-blogging-the-far-side-squid-comic.html</link>
      <thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">164</thr:total>
      <description>&lt;p&gt;&lt;i&gt;The Far Side&lt;/i&gt; is always good for a squid reference. &lt;a href="https://www.thefarside.com/2021/11/26/0"&gt;Here&amp;#8217;s a recent one&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.&lt;/p&gt;
&lt;p&gt;Read my blog posting guidelines &lt;a href="https://www.schneier.com/blog/archives/2017/03/commenting_poli.html"&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;i&gt;The Far Side&lt;/i&gt; is always good for a squid reference. &lt;a href="https://www.thefarside.com/2021/11/26/0"&gt;Here&amp;#8217;s a recent one&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.&lt;/p&gt;
&lt;p&gt;Read my blog posting guidelines &lt;a href="https://www.schneier.com/blog/archives/2017/03/commenting_poli.html"&gt;here&lt;/a&gt;.&lt;/p&gt;</content:encoded>
      <category domain="https://www.schneier.com">Uncategorized</category>
      <category domain="https://www.schneier.com">squid</category>
      <pubDate>Fri, 10 Dec 2021 22:05:35 GMT</pubDate>
      <guid isPermaLink="false">https://www.schneier.com/?p=64632</guid>
      <dc:creator>Bruce Schneier</dc:creator>
      <dc:date>2021-12-10T22:05:35Z</dc:date>
    </item>
    <item>
      <title>Security Experts Sound Alarm on Zero-Day in Widely Used Log4j Tool</title>
      <link>https://www.darkreading.com/vulnerabilities-threats/security-experts-sound-alarm-on-zero-day-in-widely-used-log4j-tool</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt1c821960984aee07/61b3c3ef6cfd9e67c963a450/exploit_LeoWolfert_shutterstock.jpg" type="image/*" />
      <description>A remote code execution vulnerability in Log4j presents a bigger threat to organizations than even the infamous 2017 Apache Struts vulnerability that felled Equifax, they say.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt02d79fb9a44a4258/60b1e9dd2a25046b35110696/Jai-Vijayan.jpeg" type="image/*" />
      <pubDate>Fri, 10 Dec 2021 22:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/vulnerabilities-threats/security-experts-sound-alarm-on-zero-day-in-widely-used-log4j-tool</guid>
      <dc:creator>Jai Vijayan, Contributing Writer</dc:creator>
      <dc:date>2021-12-10T22:00:00Z</dc:date>
    </item>
    <item>
      <title>NIST Cyber-Resiliency Framework Extended to Include Critical Infrastructure Controls</title>
      <link>https://www.darkreading.com/edge-articles/nist-cyber-resiliency-framework-extended-to-include-critical-infrastructure-controls</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt1de8532c065d89c6/614b43e17b9106022d73f78d/network-security-engineer-Moon-Light-PhotoStudio--shutterstock_252937375.jpg" type="image/*" />
      <description>The latest NIST publication outlines how organizations can build systems that can anticipate, withstand, recover from, and adapt to cyberattacks.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltbeb30fde8ec73a32/60d4432c2446e93b5b5a0e0c/Edge-Editors.png" type="image/*" />
      <pubDate>Fri, 10 Dec 2021 21:47:43 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/edge-articles/nist-cyber-resiliency-framework-extended-to-include-critical-infrastructure-controls</guid>
      <dc:creator>Edge Editors, Dark Reading</dc:creator>
      <dc:date>2021-12-10T21:47:43Z</dc:date>
    </item>
    <item>
      <title>Russian National Sentenced for Role in Kelihos Botnet</title>
      <link>https://www.darkreading.com/threat-intelligence/russian-national-sentenced-for-role-in-kelihos-botnet</link>
      <description>Oleg Koshkin was sentenced for running a crypting service used to hide the Kelihos malware from antivirus software.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte161b23f0fd3a84b/60b1ea374e7eb868c4c6a293/dr_staff_125x125.jpg" type="image/*" />
      <pubDate>Fri, 10 Dec 2021 20:50:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/threat-intelligence/russian-national-sentenced-for-role-in-kelihos-botnet</guid>
      <dc:creator>Dark Reading Staff, Dark Reading</dc:creator>
      <dc:date>2021-12-10T20:50:00Z</dc:date>
    </item>
    <item>
      <title>Episode 231: Solving the US’s Endemic Cybersecurity Worker Shortage</title>
      <link>https://feeds.feedblitz.com/~/674843258/_/thesecurityledger~Episode-Solving-the-US%e2%80%99s-Endemic-Cybersecurity-Worker-Shortage/</link>
      <feedburner:origLink xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">https://securityledger.com/2021/12/episode-231-solving-the-us-endemic-cybersecurity/</feedburner:origLink>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://feeds.feedblitz.com/~/674843258/_/thesecurityledger~Episode-Solving-the-US%e2%80%99s-Endemic-Cybersecurity-Worker-Shortage/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <itunes:subtitle xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">Rodney Petersen, the director of the National Initiative for Cybersecurity Education (NICE) talks about the massive shortage of information security workers at the United States - estimated at more than 400,000 workers.</itunes:subtitle>
      <itunes:summary xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><![CDATA[<br />
In this episode of the podcast (#231) <a rel="NOFOLLOW" rel="noreferrer noopener" href="https://www.nist.gov/people/rodney-petersen" target="_blank">Rodney Petersen</a>, the director of the National Initiative for Cybersecurity Education (NICE) at the National Institute of Standards and Technology (NIST) joins host Paul Roberts to talk about the massive shortage of information security workers at the United States &#8211; estimated at more than 400,000 workers. Rodney talks about how NICE is working to promote information security skills and development.<br />
<br />
<br />
<br />
As always, &#160;you can check our full conversation in&#160;<a rel="NOFOLLOW" href="https://www.blubrry.com/the_security_ledger_podcasts/">our latest Security Ledger podcast at Blubrry</a>. You&#160;<a rel="NOFOLLOW" rel="noreferrer noopener" href="https://itunes.apple.com/us/podcast/the-security-ledger-podcast/id680045866?mt=2" target="_blank">can also listen to it on iTunes</a>&#160;and&#160;<a rel="NOFOLLOW" rel="noreferrer noopener" href="https://open.spotify.com/show/5YZ0iBx5uwjbqRWeR7bHcQ?si=41x7hihbSAuQ21YbII-CDQ&#38;dl_branch=1" target="_blank">Spotify</a>. Or, check us out on&#160;<a rel="NOFOLLOW" rel="noreferrer noopener" href="https://podcasts.google.com/feed/aHR0cHM6Ly9mZWVkcy5mZWVkYmxpdHouY29tL3RoZXNlY3VyaXR5bGVkZ2Vy" target="_blank">Google Podcasts</a>,&#160;<a rel="NOFOLLOW" href="https://www.stitcher.com/podcast/the-security-ledger-4/the-security-ledger-podcast">Stitcher</a>,&#160;<a rel="NOFOLLOW" href="https://radiopublic.com/the-security-ledger-WDR2Z9">Radio Public</a>&#160;and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to&#160;<a rel="NOFOLLOW" href="http://securityledger.com/subscribe">securityledger.com/subscribe</a>&#160;to get notified whenever a new podcast is posted.&#160;<br />
<br />
<br />
<br />
[<a rel="NOFOLLOW" href="https://content.blubrry.com/the_security_ledger_podcasts/Episode_231_Rodney_Petersen_of_NIST.mp3" target="_blank" rel="noreferrer noopener">MP3</a>]<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
Rodney is the&#160;director of&#160;the National Initiative for Cybersecurity Education (NICE)<br />
<br />
<br />
<br />
The U.S. is struggling with a multitude of economic challenges these days. On top of a pandemic, which is crippling sectors like retail, entertainment and restaurants, companies are struggling with what’s been termed the “Great Resignation” &#8211; a nation-wide wave of quitting by workers worried about risks to their health or just fed up with substandard salaries, working conditions or both.&#160;<br />
<br />
<br />
<br />
<a rel="NOFOLLOW" href="https://securityledger.com/2021/03/episode-207-sara-tatsis-of-blackberry-on-finding-and-keeping-women-in-cyber/" target="_blank" rel="noreferrer noopener">Episode 207: Sarah Tatsis of BlackBerry on finding and Keeping Women in Cyber</a><br />
<br />
<br />
<br />
But in the information security field, a “Great Resignation” would be considered a good problem to have. After all, in order to have workers resign, you first have to find and hire them, and that’s been a nearly constant challenge for organizations in need of information security talent in a country that has an <a rel="NOFOLLOW" href="https://www.washingtonpost.com/politics/2021/08/02/cybersecurity-202-governments-facing-severe-shortage-cyber-workers-when-it-needs-them-most/" target="_blank" rel="noreferrer noopener">estimated 465,000 unfilled cybersecurity jobs.</a>&#160;<br />
<br />
<br />
<br />
What is the source of the U.S.’s chronic information security worker shortage and what can be done about it? To answer those questions, we invited Rodney Petersen into the studios to talk. Rodney is the&#160;director of&#160;the National Initiative for Cybersecurity Education (NICE) at the<a rel="NOFOLLOW" href="https://www.nist.gov/" target="_blank" rel="noreferrer noopener"> National Institute of Standards and Technology (NIST)</a> in the U.S. Department of Commerce.&#160;In this conversation, we talk about the challenges of developing the cybersecurity workforce and why “teach...]]></itunes:summary>
      <itunes:author xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">Paul F. Roberts</itunes:author>
      <itunes:duration xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">26:18</itunes:duration>
      <rawvoice:embed xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/">&lt;iframe src="https://player.blubrry.com/?media_url=https%3A%2F%2Fmedia.blubrry.com%2Fthe_security_ledger_podcasts%2Fcontent.blubrry.com%2Fthe_security_ledger_podcasts%2FEpisode_231_Rodney_Petersen_of_NIST.mp3&amp;amp;podcast_link=https%3A%2F%2Fsecurityledger.com%2F2021%2F12%2Fepisode-231-solving-the-us-endemic-cybersecurity%2F#darkOrLight-light&amp;shownotes-ffffff&amp;shownotesBackground-444444&amp;download-ffffff&amp;downloadBackground-003366&amp;subscribe-ffffff&amp;subscribeBackground-fb8c00&amp;share-ffffff&amp;shareBackground-1976d2" scrolling="no" width="100%" height="138px" frameborder="0" id="blubrryplayer-2" class="blubrryplayer" title="Blubrry Podcast Player"&gt;&lt;/iframe&gt;</rawvoice:embed>
      <post-id xmlns="com-wordpress:feed-additions:1">476705</post-id>
      <feedburner:origEnclosureLink xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">https://media.blubrry.com/the_security_ledger_podcasts/content.blubrry.com/the_security_ledger_podcasts/Episode_231_Rodney_Petersen_of_NIST.mp3</feedburner:origEnclosureLink>
      <description>&lt;p&gt;Rodney Petersen, the director of the National Initiative for Cybersecurity Education (NICE) talks about the massive shortage of information security workers at the United States - estimated at more than 400,000 workers.&lt;/p&gt;
&lt;p&gt;The post &lt;a rel="NOFOLLOW" href="https://feeds.feedblitz.com/~/674843258/_/thesecurityledger~Episode-Solving-the-US%e2%80%99s-Endemic-Cybersecurity-Worker-Shortage/"&gt;Episode 231: Solving the US’s Endemic Cybersecurity Worker Shortage&lt;/a&gt; appeared first on &lt;a rel="NOFOLLOW" href="https://securityledger.com"&gt;The Security Ledger with Paul F....&lt;/a&gt;&lt;/p&gt;&lt;p style="clear:left"&gt;&lt;span class="fbz_teasertext"&gt;&lt;a href="https://feeds.feedblitz.com/~/674843258/_/thesecurityledger"&gt;&lt;b&gt;Read the whole entry...&lt;/b&gt;&lt;/a&gt;&amp;#160;&lt;!-- _!fbztxtlnk!_ https://feeds.feedblitz.com/~/674843258/_/thesecurityledger --&gt;&lt;b&gt;&amp;#187;&lt;/b&gt;&lt;/p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="fbz_enclosure" style="clear:left"&gt;&lt;audio controls="controls" style="display:block;padding:0.5em 0;max-width:100%;"&gt;&lt;source src="https://feeds.feedblitz.com/-/674843314/_/thesecurityledger.mp3"&gt;Click the icon below to listen.&lt;/audio&gt;&lt;a href="https://feeds.feedblitz.com/-/674843314/_/thesecurityledger.mp3" title="Play audio"&gt;&lt;img border="0" width="40" height="40" src="https://assets.feedblitz.com/i/podplay.png"/&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/12/spotlight-how-secrets-sprawl-undermines-software-supply-chain-security/"&gt;Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/episode-228-cisas-eric-goldstein-and-the-challenge-of-being-everyones-friend-in-cyber/"&gt;Episode 228: CISA&amp;#x2019;s Eric Goldstein and the Challenge of Being Everyone&amp;#x2019;s Friend in Cyber&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/episode-227-whats-fueling-cyber-attacks-on-agriculture/"&gt;Episode 227: What&amp;#x2019;s Fueling Cyber Attacks on Agriculture ?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
      <content:encoded>&lt;p&gt;Rodney Petersen, the director of the National Initiative for Cybersecurity Education (NICE) talks about the massive shortage of information security workers at the United States - estimated at more than 400,000 workers.&lt;/p&gt;
&lt;p&gt;The post &lt;a rel="nofollow" href="https://feeds.feedblitz.com/~/t/0/_/thesecurityledger/~https://securityledger.com/2021/12/episode-231-solving-the-us-endemic-cybersecurity/"&gt;Episode 231: Solving the US’s Endemic Cybersecurity Worker Shortage&lt;/a&gt; appeared first on &lt;a rel="nofollow" href="https://feeds.feedblitz.com/~/t/0/_/thesecurityledger/~https://securityledger.com"&gt;The Security Ledger with Paul F....&lt;/a&gt;&lt;/p&gt;&lt;p style="clear:left"&gt;&lt;span class="fbz_teasertext"&gt;&lt;a href="https://feeds.feedblitz.com/~/674843258/_/thesecurityledger"&gt;&lt;b&gt;Read the whole entry...&lt;/b&gt;&lt;/a&gt;&amp;#160;&lt;!-- _!fbztxtlnk!_ https://feeds.feedblitz.com/~/674843258/_/thesecurityledger --&gt;&lt;b&gt;&amp;#187;&lt;/b&gt;&lt;/p&gt;&lt;/span&gt;&lt;Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.feedblitz.com/~/i/674843258/_/thesecurityledger"&gt;
&lt;/p&gt;&lt;div class="fbz_enclosure" style="clear:left"&gt;&lt;audio controls="controls" style="display:block;padding:0.5em 0;max-width:100%;"&gt;&lt;source src="https://feeds.feedblitz.com/-/674843314/_/thesecurityledger.mp3"&gt;Click the icon below to listen.&lt;/audio&gt;&lt;a href="https://feeds.feedblitz.com/-/674843314/_/thesecurityledger.mp3" title="Play audio"&gt;&lt;img border="0" width="40" height="40" src="https://assets.feedblitz.com/i/podplay.png"/&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/12/spotlight-how-secrets-sprawl-undermines-software-supply-chain-security/"&gt;Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/episode-228-cisas-eric-goldstein-and-the-challenge-of-being-everyones-friend-in-cyber/"&gt;Episode 228: CISA&amp;#x2019;s Eric Goldstein and the Challenge of Being Everyone&amp;#x2019;s Friend in Cyber&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/episode-227-whats-fueling-cyber-attacks-on-agriculture/"&gt;Episode 227: What&amp;#x2019;s Fueling Cyber Attacks on Agriculture ?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded>
      <enclosure url="https://feeds.feedblitz.com/-/674843314/_/thesecurityledger.mp3" length="37883661" type="audio/mpeg" />
      <category>Biden Administration</category>
      <category>Business</category>
      <category>Government</category>
      <category>NIST</category>
      <category>Podcasts</category>
      <category>Spotlight</category>
      <category>women in the workforce</category>
      <category>workforce development</category>
      <category>cybersecurity</category>
      <category>hiring</category>
      <pubDate>Fri, 10 Dec 2021 19:30:07 GMT</pubDate>
      <comments>https://feeds.feedblitz.com/~/674843258/_/thesecurityledger~Episode-Solving-the-US%e2%80%99s-Endemic-Cybersecurity-Worker-Shortage/#respond</comments>
      <guid isPermaLink="false">https://securityledger.com/?p=476705</guid>
      <dc:creator>Paul Roberts</dc:creator>
      <dc:date>2021-12-10T19:30:07Z</dc:date>
    </item>
    <item>
      <title>“Log4Shell” Java vulnerability – how to safeguard your servers</title>
      <link>https://nakedsecurity.sophos.com/2021/12/10/log4shell-java-vulnerability-how-to-safeguard-your-servers/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://nakedsecurity.sophos.com/2021/12/10/log4shell-java-vulnerability-how-to-safeguard-your-servers/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">19</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/l4j.png?w=230&amp;h=130&amp;crop=1" medium="image" />
      <post-id xmlns="com-wordpress:feed-additions:1">647436</post-id>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/l4j.png" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/12/l4j.png?w=170&amp;h=90&amp;crop=1" medium="image" />
      <description>Just when you thought it was safe to relax for the weekend... a critical bug showed up in Apache's Log4j product</description>
      <category>Vulnerability</category>
      <category>Apache</category>
      <category>CVE-2021-44228</category>
      <category>Exploit</category>
      <category>Java</category>
      <category>Log4Shell</category>
      <category>LOGJAM</category>
      <category>rce</category>
      <pubDate>Fri, 10 Dec 2021 19:22:03 GMT</pubDate>
      <comments>https://nakedsecurity.sophos.com/2021/12/10/log4shell-java-vulnerability-how-to-safeguard-your-servers/#comments</comments>
      <guid isPermaLink="false">https://nakedsecurity.sophos.com/?p=647436</guid>
      <dc:creator>Paul Ducklin</dc:creator>
      <dc:date>2021-12-10T19:22:03Z</dc:date>
    </item>
    <item>
      <title>Identity Authentication Access Market Set to Hit $28.9B in 2021</title>
      <link>https://www.darkreading.com/omdia/identity-authentication-access-market-set-to-hit-28-9b-in-2021</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt2370149aa096adb9/61b38ac689fca95dc5b45fc0/Tait_211213_Featured_Image.png" type="image/*" />
      <description>With more staff working remotely, identity, authentication, and access (IAA) has never been more important. Market forecasts, drivers, and trends are explored.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt62cab7382fbc3f7d/60d4475fa7307e39e4d4b784/Don-Tait.png" type="image/*" />
      <pubDate>Fri, 10 Dec 2021 18:48:59 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/omdia/identity-authentication-access-market-set-to-hit-28-9b-in-2021</guid>
      <dc:creator>Don Tait, Senior Analyst, Omdia</dc:creator>
      <dc:date>2021-12-10T18:48:59Z</dc:date>
    </item>
    <item>
      <title>Five steps to prevent burnout in SOC teams | Kaspersky official blog</title>
      <link>https://www.kaspersky.com/blog/burnout-guide-for-ciso/43118/</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/10123200/burnout-guide-for-ciso-featured.jpg" width="1460" height="960">
        <media:keywords>full</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/10123200/burnout-guide-for-ciso-featured-1024x673.jpg" width="1024" height="673">
        <media:keywords>large</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/10123200/burnout-guide-for-ciso-featured-300x197.jpg" width="300" height="197">
        <media:keywords>medium</media:keywords>
      </media:content>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2021/12/10123200/burnout-guide-for-ciso-featured-150x150.jpg" width="150" height="150">
        <media:keywords>thumbnail</media:keywords>
      </media:content>
      <description>Kaspersky’s security operations center head explains his approach to burnout prevention in SOC teams.</description>
      <content:encoded>&lt;p&gt;Between the monotony of painstakingly searching for anomalies and the enormous responsibility of ensuring a company&amp;#8217;s security, security operations center (SOC) employees endure constant stress. My hope is that sharing my experience as the head of a SOC that provides managed detection and response &lt;a href="https://www.kaspersky.com/enterprise-security/managed-detection-and-response?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder____" target="_blank"&gt;(MDR) service&lt;/a&gt; can help shed some light on SOCs in general, so I&amp;#8217;d like to share my five steps to minimize stress and prevent &lt;a href="https://www.kaspersky.com/blog/soc-burnout/25463/" target="_blank" rel="noopener"&gt;burnout in the SOC&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Step one: Complete the team&lt;/h2&gt;
&lt;p&gt;Organizing your team is key. You need enough people to keep up with the work but not so many that they end up bored. You&amp;#8217;re looking for a balance, and finding it is no mystery.&lt;/p&gt;
&lt;p&gt;To begin, define the scope of the work you need and then break down the roles you need to fill: what security services you need in house and what to outsource. Use that breakdown to sketch out your target head count, keeping in mind that you&amp;#8217;ll need internal professionals to manage outsourced functions;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Start with six people, which is really the minimum a SOC needs to operate. That&amp;#8217;s two for monitoring, one for investigation, one to function as architect and engineer, an administrator, and a SOC manager;&lt;/li&gt;
&lt;li&gt;Think in advance about mitigating the negative impact of turnover to minimize the effects of workload increases on team members.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Step two: Make work rewarding&lt;/h2&gt;
&lt;p&gt;Effective work tends to require motivation. Of course, you need to provide the conditions for growth and comfortable work, but also consider the very obtrusive potential of demotivating factors — so, for example, think about ways to make goals transparent and assessments clear and reasonable. People strive to reach new professional heights, and they excel when they find the work rewarding.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Encourage leaders and reward effort rather than silencing newcomers or punishing failure;&lt;/li&gt;
&lt;li&gt;Ensure good working conditions, including adequate wages and benefits, social programs, time for physical activities, and healthy team relationships;&lt;/li&gt;
&lt;li&gt;Clarify goals, objectives, and the metrics by which you and the company measure employees&amp;#8217; work;&lt;/li&gt;
&lt;li&gt;Specify a transparent career path, making sure colleagues understand which team is responsible for what and how to achieve promotions or transfers.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Step three: Relieve stress&lt;/h2&gt;
&lt;p&gt;The job of a SOC analyst is stressful all by itself, making any pressure reduction particularly important. You can&amp;#8217;t make the job a cakewalk, but you can take a few simple steps to help ease SOC workers&amp;#8217; loads.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Let employees manage their own time. As long as having flexible hours doesn&amp;#8217;t affect performance — which you addressed in step two — it shouldn&amp;#8217;t cause any trouble;&lt;/li&gt;
&lt;li&gt;Exchange feedback with your team. Transparency and trust go both ways;&lt;/li&gt;
&lt;li&gt;Support your team. Workers should feel confident in the face of difficult situations and expect help from management or dedicated experts.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Step four: Inspire your teammates&lt;/h2&gt;
&lt;p&gt;Working in a SOC means being part of a team. Devote some time to analyzing the team, seeking optimal combinations of employees, understanding what tasks each of them performs best, and bolstering team spirit.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Give employees varied, nonstandard tasks from time to time. That serves the dual purpose of keeping them interested and helping you learn each team member&amp;#8217;s strengths and preferences; &lt;/li&gt;
&lt;li&gt;Give each team member a sphere of responsibility so they know their contributions are important and valuable;&lt;/li&gt;
&lt;li&gt;Provide opportunities for professional development, including networking and participation in training courses or webinars;&lt;/li&gt;
&lt;li&gt;Conduct collaborative team-building activities. As a manager, you may find the different structure of collaboration outside of a work environment reveals qualities that contribute to the team&amp;#8217;s productivity.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Step five: Minimize routine&lt;/h2&gt;
&lt;p&gt;Overreliance on routine is a major contributor to burnout. Now, as I said at the start, monotony is part of the job, and you cannot get rid of most routine processes. That said, you can at least minimize the harm with a bit of intelligent outsourcing and task automation.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Engage outside specialists in routine activities or tasks where sensible and productive;&lt;/li&gt;
&lt;li&gt;Implement tools and services to facilitate common IT security practices;&lt;/li&gt;
&lt;li&gt;Continuously research new areas, and automate everything you can.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Reallocating resources and tasks is never easy or automatic. Although offloading work sounds appealing, first consider the importance of keeping employees interested and motivated. Some functions may need to stay in-house for legal or other reasons, and for those that can move outside, you&amp;#8217;ll need to ensure contracts clarify liability and consequences, not just responsibility. And before automating certain tasks, analyze the relevant work processes, consider user feedback, and identify any problems on the team to develop a realistic and appropriate plan.&lt;/p&gt;
&lt;input type="hidden" class="category_for_banner" value="mdr" /&gt;
&lt;p&gt;&amp;#160;&lt;br /&gt;
You can find more advice on achieving a better balance between employee well-being, productivity and safety in our study &lt;a href="https://www.kaspersky.com/blog/employee-wellbeing-2021/?from=burnout-guide-for-ciso" target="_blank" rel="noopener"&gt;Employee wellbeing 2021: Learning from the new reality&lt;/a&gt;.&lt;/p&gt;</content:encoded>
      <category>Business</category>
      <category>Enterprise</category>
      <category>burnout</category>
      <category>motivation</category>
      <category>SOC</category>
      <pubDate>Fri, 10 Dec 2021 17:37:23 GMT</pubDate>
      <guid isPermaLink="false">https://www.kaspersky.com/blog/?p=43118</guid>
      <dc:creator>Sergey Soldatov</dc:creator>
      <dc:date>2021-12-10T17:37:23Z</dc:date>
    </item>
    <item>
      <title>Dark Reading Reflects on a Legacy and Life Well-Written: Tim Wilson</title>
      <link>https://www.darkreading.com/threat-intelligence/dark-reading-reflects-on-a-legacy-and-life-well-written-tim-wilson</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt167e685ebcfcaac3/61afadf3f57b8073cccb6acf/teampic.jpg" type="image/*" />
      <description>The Dark Reading editorial team, along with contributing writers and editors, share their favorite stories and memories of co-founder and editor-in-chief Tim Wilson, an influential editor and well-respected thought leader in the cybersecurity industry.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte161b23f0fd3a84b/60b1ea374e7eb868c4c6a293/dr_staff_125x125.jpg" type="image/*" />
      <pubDate>Fri, 10 Dec 2021 17:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/threat-intelligence/dark-reading-reflects-on-a-legacy-and-life-well-written-tim-wilson</guid>
      <dc:creator>Dark Reading Staff, Dark Reading</dc:creator>
      <dc:date>2021-12-10T17:00:00Z</dc:date>
    </item>
    <item>
      <title>'Especially dangerous' Java zero day discovered, same type as used in Equifax breach</title>
      <link>https://www.computing.co.uk/news/4041918/especially-dangerous-java-zero-day-discovered-type-equifax-breach</link>
      <description>&lt;img alt="&amp;#39;Especially dangerous&amp;#39; Java zero day discovered, same type as used in Equifax breach" src="https://www.computing.co.uk/api/v1/wps/a62105b/61bebcaf-604a-410e-aec2-0d4b282e1759/7/software-bug-185x114.jpeg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Patch Log4j urgently admins urged, as memories of 2017 Equifax hack loom large &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Fri, 10 Dec 2021 15:27:53 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4041918/especially-dangerous-java-zero-day-discovered-type-equifax-breach</guid>
      <dc:date>2021-12-10T15:27:53Z</dc:date>
    </item>
    <item>
      <title>The Vulnerability Lag: Cut Ransomware Risks Resulting From Digital Transformation</title>
      <link>https://www.darkreading.com/vulnerabilities-threats/the-vulnerability-lag-cut-ransomware-risks-resulting-from-digital-transformation</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt6576c7282a2fd7e1/6197baad01638259ffd7230a/Ransomware_Ton_Snoei_Alamy.jpg" type="image/*" />
      <description>Exploring ransomware and other data integrity risks from accelerated digital transformation in the wake of COVID-19.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt3dc8e4a0193d32d0/61acf88b1333f257e64c10ef/Sonya_Duffin_Headshot_5.Square.png" type="image/*" />
      <pubDate>Fri, 10 Dec 2021 15:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/vulnerabilities-threats/the-vulnerability-lag-cut-ransomware-risks-resulting-from-digital-transformation</guid>
      <dc:creator>Sonya Duffin, Ransomware and Data Protection Expert, Veritas Technologies</dc:creator>
      <dc:date>2021-12-10T15:00:00Z</dc:date>
    </item>
    <item>
      <title>New Firefox Sandbox Isolates Third-Party Libraries</title>
      <link>https://www.darkreading.com/emerging-tech/new-firefox-sandbox-isolates-third-party-libraries</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt02daf86336f38505/60e3d5caee9c2f2205344164/firefox.jpg" type="image/*" />
      <description>RLBox can be used to protect web browsers and other software applications from vulnerabilities in subcomponents and libraries.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt93784ffee79538e7/60d4371522d24e38a3806ecf/fahmida.png" type="image/*" />
      <pubDate>Fri, 10 Dec 2021 12:38:27 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/emerging-tech/new-firefox-sandbox-isolates-third-party-libraries</guid>
      <dc:creator>Fahmida Y. Rashid, Features Editor, Dark Reading</dc:creator>
      <dc:date>2021-12-10T12:38:27Z</dc:date>
    </item>
    <item>
      <title>Law Enforcement Access to Chat Data and Metadata</title>
      <link>https://www.schneier.com/blog/archives/2021/12/law-enforcement-access-to-chat-data-and-metadata.html</link>
      <thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">26</thr:total>
      <description>&lt;p&gt;A January 2021 FBI &lt;a href="https://propertyofthepeople.org/document-detail/?doc-id=21114562"&gt;document&lt;/a&gt; outlines what types of data and metadata can be lawfully obtained by the FBI from messaging apps. &lt;i&gt;Rolling Stone&lt;/i&gt; &lt;a href="https://www.rollingstone.com/politics/politics-features/whatsapp-imessage-facebook-apple-fbi-privacy-1261816/"&gt;broke&lt;/a&gt; the story and it&amp;#8217;s been written about &lt;a href="https://reason.com/2021/12/07/secret-documents-show-which-message-apps-are-the-most-fbi-proof/"&gt;elsewhere&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;I don&amp;#8217;t see a lot of surprises in the document. Lots of apps leak all sorts of metadata: iMessage and WhatsApp seem to be the worst. Signal protects the most metadata. End-to-end encrypted message content can be available if the user uploads it to an unencrypted backup server.&lt;/p&gt;
&lt;p&gt;EDITED TO ADD (12/13): &lt;a href="https://therecord.media/fbi-document-shows-what-data-can-be-obtained-from-encrypted-messaging-apps/"&gt;Here&amp;#8217;s&lt;/a&gt; a more legible copy of the text.&lt;/p&gt;
...</description>
      <content:encoded>&lt;p&gt;A January 2021 FBI &lt;a href="https://propertyofthepeople.org/document-detail/?doc-id=21114562"&gt;document&lt;/a&gt; outlines what types of data and metadata can be lawfully obtained by the FBI from messaging apps. &lt;i&gt;Rolling Stone&lt;/i&gt; &lt;a href="https://www.rollingstone.com/politics/politics-features/whatsapp-imessage-facebook-apple-fbi-privacy-1261816/"&gt;broke&lt;/a&gt; the story and it&amp;#8217;s been written about &lt;a href="https://reason.com/2021/12/07/secret-documents-show-which-message-apps-are-the-most-fbi-proof/"&gt;elsewhere&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;I don&amp;#8217;t see a lot of surprises in the document. Lots of apps leak all sorts of metadata: iMessage and WhatsApp seem to be the worst. Signal protects the most metadata. End-to-end encrypted message content can be available if the user uploads it to an unencrypted backup server.&lt;/p&gt;
&lt;p&gt;EDITED TO ADD (12/13): &lt;a href="https://therecord.media/fbi-document-shows-what-data-can-be-obtained-from-encrypted-messaging-apps/"&gt;Here&amp;#8217;s&lt;/a&gt; a more legible copy of the text.&lt;/p&gt;</content:encoded>
      <category domain="https://www.schneier.com">Uncategorized</category>
      <category domain="https://www.schneier.com">cell phones</category>
      <category domain="https://www.schneier.com">FBI</category>
      <category domain="https://www.schneier.com">law enforcement</category>
      <category domain="https://www.schneier.com">metadata</category>
      <category domain="https://www.schneier.com">privacy</category>
      <pubDate>Fri, 10 Dec 2021 12:37:29 GMT</pubDate>
      <guid isPermaLink="false">https://www.schneier.com/?p=64627</guid>
      <dc:creator>Bruce Schneier</dc:creator>
      <dc:date>2021-12-10T12:37:29Z</dc:date>
    </item>
    <item>
      <title>Hackers are targeting over a million WordPress sites in ongoing attacks</title>
      <link>https://www.computing.co.uk/news/4041899/hackers-targeting-million-wordpress-sites-ongoing-attacks</link>
      <description>&lt;img alt="Hackers are targeting over a million WordPress sites in ongoing attacks" src="https://www.computing.co.uk/api/v1/wps/83d51ba/ac5519d8-a0fc-46cc-a201-ecdf2310dea8/10/wordpress-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; They are exploiting security bugs in four WordPress plugins and 15 Epsilon Framework themes &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Fri, 10 Dec 2021 12:37:01 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4041899/hackers-targeting-million-wordpress-sites-ongoing-attacks</guid>
      <dc:date>2021-12-10T12:37:01Z</dc:date>
    </item>
    <item>
      <title>This Week in Security News - December 10, 2021</title>
      <link>https://www.trendmicro.com/en_us/research/21/l/this-week-in-security-news-december-10-2021.html</link>
      <description>This week, read about Trend Micro’s predictions for security in the coming year. Also, learn about the Biden administration’s latest initiatives for curtailing attacks on the transport infrastructure.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/week-in-security-news_lrg.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Cloud</category>
      <category>Trend Micro Research : Cyber Crime</category>
      <category>Trend Micro Research : Expert Perspective</category>
      <category>Trend Micro Research : Cyber Threats</category>
      <category>Trend Micro Research : Connected Car</category>
      <category>Trend Micro Research : Ransomware</category>
      <category>Trend Micro Research : Mobile</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <pubDate>Fri, 10 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:97bd92ad-bea5-3fd7-73ad-aeeaa5fec351</guid>
      <dc:creator>Jon Clay</dc:creator>
      <dc:date>2021-12-10T00:00:00Z</dc:date>
    </item>
    <item>
      <title>New Yanluowang Ransomware Found to be Code-Signed, Terminates Database-Related Processes</title>
      <link>https://www.trendmicro.com/en_us/research/21/l/yanluowang-ransomware-code-signed-terminates-database-processes.html</link>
      <description>We analyzed new samples of the Yanluowang ransomware. One interesting aspect of these samples is that the files are code-signed. They also terminate various processes which are related to database and backup management.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/l/new-yanluowang-ransomware-found-to-be-code-signed-terminates-database-related-processes/yanluowang-banner.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Articles, News, Reports</category>
      <category>Trend Micro Research : Ransomware</category>
      <category>Trend Micro Research : Research</category>
      <pubDate>Fri, 10 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:c59d8450-c5ba-923e-e9ef-aaa68cc0f435</guid>
      <dc:creator>Don Ovid Ladores</dc:creator>
      <dc:date>2021-12-10T00:00:00Z</dc:date>
    </item>
    <item>
      <title>How Zero Trust and XDR Work Together</title>
      <link>https://www.trendmicro.com/en_us/ciso/21/l/how-zero-trust-and-xdr-work-together.html</link>
      <description>As the Zero Trust approach gains momentum, more organizations are looking to apply it to their security strategy. Learn how XDR and Zero Trust work together to enhance your security posture.</description>
      <source url="https://www.trendmicro.com/en_us/ciso.html">CISO Resource Center</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/ciso/21/l/how-zero-trust-and-xdr-work-together/zero-trust.jpg" type="image/jpeg" />
      <category>Trend Micro CISO : Article</category>
      <category>Trend Micro CISO : Digital Transformation</category>
      <category>Trend Micro CISO : Cloud</category>
      <category>Trend Micro CISO : Expert Perspective</category>
      <category>Trend Micro CISO : Risk Management</category>
      <category>Trend Micro CISO : Detection and Response</category>
      <pubDate>Fri, 10 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:77d68e91-3060-ceab-29be-449f4bce7538</guid>
      <dc:date>2021-12-10T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Broadcom Inc. Announces $10 Billion Share Repurchase Authorization</title>
      <link>https://www.darkreading.com/perimeter/broadcom-inc-announces-10-billion-share-repurchase-authorization</link>
      <description>The authorization is effective until December 31, 2022.</description>
      <pubDate>Thu, 09 Dec 2021 23:58:26 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/perimeter/broadcom-inc-announces-10-billion-share-repurchase-authorization</guid>
      <dc:date>2021-12-09T23:58:26Z</dc:date>
    </item>
    <item>
      <title>Emotet Is Back and More Dangerous Than Before</title>
      <link>https://www.darkreading.com/threat-intelligence/emotet-is-back-and-it-s-more-dangerous-than-before</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt2fe52065bdd9a2e3/61b28fb7165ecc7460180096/emotet_peter_jesche_shutterstock.jpg" type="image/*" />
      <description>Volume of traffic associated with the malware is now back at 50% of the volume before law enforcement took the botnet operation down in January 2021, security vendor says.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt02d79fb9a44a4258/60b1e9dd2a25046b35110696/Jai-Vijayan.jpeg" type="image/*" />
      <pubDate>Thu, 09 Dec 2021 23:30:22 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/threat-intelligence/emotet-is-back-and-it-s-more-dangerous-than-before</guid>
      <dc:creator>Jai Vijayan, Contributing Writer</dc:creator>
      <dc:date>2021-12-09T23:30:22Z</dc:date>
    </item>
    <item>
      <title>Why Red Teaming While Black Can Be Risky</title>
      <link>https://www.darkreading.com/edge-articles/why-red-teaming-while-black-can-be-risky</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt87e91cab6b2d9bc4/61b321d253798c73d0d28344/securitypros-ukblacktech.jpg" type="image/*" />
      <description>Penetration audits can be dangerous for people of color. Here is how to keep Black and brown cybersecurity professionals safe during red team engagements.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltbab71d9749999b2c/613a31bc17eade265c707e13/williesha-morris.jpg" type="image/*" />
      <pubDate>Thu, 09 Dec 2021 23:27:18 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/edge-articles/why-red-teaming-while-black-can-be-risky</guid>
      <dc:creator>Williesha Morris, Contributing Writer</dc:creator>
      <dc:date>2021-12-09T23:27:18Z</dc:date>
    </item>
    <item>
      <title>Researchers Explore Microsoft Outlook Phishing Techniques</title>
      <link>https://www.darkreading.com/threat-intelligence/researchers-explore-outlook-phishing-techniques</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltd2c78b07c0279fd3/61b2769ea3ccd576cd75b8b7/phish.jpg" type="image/*" />
      <description>Outlook features intended to improve collaboration and productivity may make social engineering attacks more effective, researchers find.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt1d62bf1a6a54fdcf/60b1e9ed2d381b69fb11e95e/Sheridan-IWK-125x125.jpg" type="image/*" />
      <pubDate>Thu, 09 Dec 2021 22:30:53 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/threat-intelligence/researchers-explore-outlook-phishing-techniques</guid>
      <dc:creator>Kelly Sheridan, Senior Editor</dc:creator>
      <dc:date>2021-12-09T22:30:53Z</dc:date>
    </item>
    <item>
      <title>Lack of Patching Leaves 300,000 Routers at Risk for Attack</title>
      <link>https://www.darkreading.com/attacks-breaches/lack-of-patching-leaves-300-000-routers-at-risk-for-attack</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt9600ad38b092f806/61b27393a3ccd576cd75b8b3/mikrotik_map-3-2048x1517.png" type="image/*" />
      <description>A significant percentage of the 2 million consumer and small-business routers produced by a Latvian firm are vulnerable and being used by attackers, a security firm says.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt58481326324d6911/60b1e9a55d34de550780a990/Robert-Lemos.png" type="image/*" />
      <pubDate>Thu, 09 Dec 2021 22:25:49 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/attacks-breaches/lack-of-patching-leaves-300-000-routers-at-risk-for-attack</guid>
      <dc:creator>Robert Lemos, Contributing Writer</dc:creator>
      <dc:date>2021-12-09T22:25:49Z</dc:date>
    </item>
    <item>
      <title>S3 Ep62: The S in IoT stands for security (and much more) [Podcast+Transcript]</title>
      <link>https://nakedsecurity.sophos.com/2021/12/09/s3-ep62-the-s-in-iot-stands-for-security-and-much-more-podcasttranscript/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://nakedsecurity.sophos.com/2021/12/09/s3-ep62-the-s-in-iot-stands-for-security-and-much-more-podcasttranscript/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/09/ns-1200-logo-podcast-with-mic.png?w=230&amp;h=130&amp;crop=1" medium="image" />
      <post-id xmlns="com-wordpress:feed-additions:1">647407</post-id>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/09/ns-1200-logo-podcast-with-mic.png" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://nakedsecurity.sophos.com/wp-content/uploads/sites/2/2021/09/ns-1200-logo-podcast-with-mic.png?w=170&amp;h=90&amp;crop=1" medium="image" />
      <description>Listen now or read as an article! (Full transcript inside.)</description>
      <category>IoT</category>
      <category>Law &amp; order</category>
      <category>Podcast</category>
      <category>Vulnerability</category>
      <category>Cybercrime</category>
      <category>hacking</category>
      <category>iot</category>
      <category>Naked Security Podcast</category>
      <pubDate>Thu, 09 Dec 2021 19:40:01 GMT</pubDate>
      <comments>https://nakedsecurity.sophos.com/2021/12/09/s3-ep62-the-s-in-iot-stands-for-security-and-much-more-podcasttranscript/#respond</comments>
      <guid isPermaLink="false">https://nakedsecurity.sophos.com/?p=647407</guid>
      <dc:creator>Paul Ducklin</dc:creator>
      <dc:date>2021-12-09T19:40:01Z</dc:date>
    </item>
    <item>
      <title>One-Third of Phishing Pages Active Less Than a Day</title>
      <link>https://www.darkreading.com/endpoint/one-third-of-phishing-pages-active-less-than-a-day</link>
      <description>Security experts say the first hours in a phishing page's life are the most dangerous for users.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte161b23f0fd3a84b/60b1ea374e7eb868c4c6a293/dr_staff_125x125.jpg" type="image/*" />
      <pubDate>Thu, 09 Dec 2021 18:15:34 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/endpoint/one-third-of-phishing-pages-active-less-than-a-day</guid>
      <dc:creator>Dark Reading Staff, Dark Reading</dc:creator>
      <dc:date>2021-12-09T18:15:34Z</dc:date>
    </item>
    <item>
      <title>LastPass Announces New Integration with Google Workspace</title>
      <link>https://www.darkreading.com/cloud/lastpass-announces-new-integration-with-google-workspace</link>
      <description>The latest integration furthers the company’s mission to provide an unmatched security model for businesses, without adding complexity for users.</description>
      <pubDate>Thu, 09 Dec 2021 16:47:51 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/cloud/lastpass-announces-new-integration-with-google-workspace</guid>
      <dc:date>2021-12-09T16:47:51Z</dc:date>
    </item>
    <item>
      <title>Google Shuts Down Glupteba Botnet, Sues Operators</title>
      <link>https://www.schneier.com/blog/archives/2021/12/google-shuts-down-glupteba-botnet-sues-operators.html</link>
      <thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">23</thr:total>
      <description>&lt;p&gt;Google &lt;a href="https://blog.google/technology/safety-security/new-action-combat-cyber-crime/"&gt;took&lt;/a&gt; &lt;a href="https://www.cnet.com/tech/google-breaks-up-botnet-infecting-1-million-devices/"&gt;steps&lt;/a&gt; to shut down the Glupteba botnet, at least for now. (The botnet uses the bitcoin blockchain as a backup command-and-control mechanism, making it hard to get rid of it permanently.) So Google is &lt;a href="https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/1_Complaint.pdf"&gt;also&lt;/a&gt; &lt;a href="https://www.bbc.com/news/world-us-canada-59571417"&gt;suing&lt;/a&gt; the botnet&amp;#8217;s operators.&lt;/p&gt;
&lt;p&gt;It&amp;#8217;s an interesting strategy. Let&amp;#8217;s see if it&amp;#8217;s successful.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Google &lt;a href="https://blog.google/technology/safety-security/new-action-combat-cyber-crime/"&gt;took&lt;/a&gt; &lt;a href="https://www.cnet.com/tech/google-breaks-up-botnet-infecting-1-million-devices/"&gt;steps&lt;/a&gt; to shut down the Glupteba botnet, at least for now. (The botnet uses the bitcoin blockchain as a backup command-and-control mechanism, making it hard to get rid of it permanently.) So Google is &lt;a href="https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/1_Complaint.pdf"&gt;also&lt;/a&gt; &lt;a href="https://www.bbc.com/news/world-us-canada-59571417"&gt;suing&lt;/a&gt; the botnet&amp;#8217;s operators.&lt;/p&gt;
&lt;p&gt;It&amp;#8217;s an interesting strategy. Let&amp;#8217;s see if it&amp;#8217;s successful.&lt;/p&gt;</content:encoded>
      <category domain="https://www.schneier.com">Uncategorized</category>
      <category domain="https://www.schneier.com">bitcoin</category>
      <category domain="https://www.schneier.com">blockchain</category>
      <category domain="https://www.schneier.com">botnets</category>
      <category domain="https://www.schneier.com">cybersecurity</category>
      <category domain="https://www.schneier.com">Google</category>
      <pubDate>Thu, 09 Dec 2021 15:36:22 GMT</pubDate>
      <guid isPermaLink="false">https://www.schneier.com/?p=64623</guid>
      <dc:creator>Bruce Schneier</dc:creator>
      <dc:date>2021-12-09T15:36:22Z</dc:date>
    </item>
    <item>
      <title>How to Build a Better Internal Fraud Protection Program</title>
      <link>https://www.darkreading.com/vulnerabilities-threats/how-to-build-a-better-internal-fraud-protection-program</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt8fb23000be31e05b/61ad04dff1b49856b7fc6edf/Fraud_photobyphotoboy_Adobe.jpeg" type="image/*" />
      <description>Fraud awareness training is just the beginning.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/bltd9e6c0fc053186dc/61ad01a539b865681b0dc014/Tim_Ball.jpg" type="image/*" />
      <pubDate>Thu, 09 Dec 2021 14:00:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/vulnerabilities-threats/how-to-build-a-better-internal-fraud-protection-program</guid>
      <dc:creator>Timothy Ball, Executive Vice President, The Bonadio Group</dc:creator>
      <dc:date>2021-12-09T14:00:00Z</dc:date>
    </item>
    <item>
      <title>The Executive Women's Forum on Information Security, Risk Management &amp; Privacy Presents the Leadership Scholarship</title>
      <link>https://www.darkreading.com/risk/the-executive-women-s-forum-on-information-security-risk-management-privacy-presents-the-leadership-scholarship</link>
      <description>Scholarship's goal is to advance women in cybersecurity, risk, and privacy.</description>
      <pubDate>Thu, 09 Dec 2021 13:50:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/risk/the-executive-women-s-forum-on-information-security-risk-management-privacy-presents-the-leadership-scholarship</guid>
      <dc:date>2021-12-09T13:50:00Z</dc:date>
    </item>
    <item>
      <title>IRONSCALES Raises $64 Million in Series C Funding Round Led by PSG</title>
      <link>https://www.darkreading.com/endpoint/-ironscales-raises-64-million-in-series-c-funding-round-led-by-psg</link>
      <description>Investment aims to accelerate growth through continued product innovation and global expansion.</description>
      <pubDate>Thu, 09 Dec 2021 13:45:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/endpoint/-ironscales-raises-64-million-in-series-c-funding-round-led-by-psg</guid>
      <dc:date>2021-12-09T13:45:00Z</dc:date>
    </item>
    <item>
      <title>Intel 471 Forms Tech Alliance With CyCognito</title>
      <link>https://www.darkreading.com/threat-intelligence/intel-471-forms-tech-alliance-with-cycognito</link>
      <description>Enterprises will see improved access to data and more relevant insights that will enable them to further strengthen their cybersecurity postures.</description>
      <pubDate>Thu, 09 Dec 2021 13:40:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/threat-intelligence/intel-471-forms-tech-alliance-with-cycognito</guid>
      <dc:date>2021-12-09T13:40:00Z</dc:date>
    </item>
    <item>
      <title>(ISC)² Welcomes Students to Apply for its Undergraduate, Graduate, and Women's Cybersecurity Scholarships</title>
      <link>https://www.darkreading.com/careers-and-people/-isc-welcomes-students-to-apply-for-its-undergraduate-graduate-and-women-s-cybersecurity-scholarships</link>
      <description>Scholarships are part of an effort to bridge the cybersecurity workforce gap.</description>
      <pubDate>Thu, 09 Dec 2021 13:35:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/careers-and-people/-isc-welcomes-students-to-apply-for-its-undergraduate-graduate-and-women-s-cybersecurity-scholarships</guid>
      <dc:date>2021-12-09T13:35:00Z</dc:date>
    </item>
    <item>
      <title>Zscaler Extends Zero Trust Exchange Platform to Deliver Zero Trust for Workloads</title>
      <link>https://www.darkreading.com/cloud/zscaler-extends-zero-trust-exchange-platform-to-deliver-zero-trust-for-workloads</link>
      <description>Solution secures cloud-to-Internet, cloud-to-cloud, cloud-to-data center, and intra-cloud communications.</description>
      <pubDate>Thu, 09 Dec 2021 13:30:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/cloud/zscaler-extends-zero-trust-exchange-platform-to-deliver-zero-trust-for-workloads</guid>
      <dc:date>2021-12-09T13:30:00Z</dc:date>
    </item>
    <item>
      <title>Smashing Security podcast #255: Revolting receipts, a Twitter fandango, and shopkeeper cyber tips</title>
      <link>https://grahamcluley.com/smashing-security-podcast-255/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://grahamcluley.com/smashing-security-podcast-255/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <description>"Demonically" possessed devices print out antiwork propaganda, advice on how to secure your store, and is Twitter's new photo privacy policy practical?

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Dinah Davis.</description>
      <enclosure url="https://aphid.fireside.fm/d/1437767933/dd3252a8-95c3-41f8-a8a0-9d5d2f9e0bc6/e3b3fae5-7da9-4d9a-b36d-addac62815ed.mp3" type="audio/mpeg" />
      <category>Podcast</category>
      <category>Privacy</category>
      <category>Security threats</category>
      <category>Twitter</category>
      <category>printer</category>
      <category>Smashing Security</category>
      <category>vulnerability</category>
      <pubDate>Thu, 09 Dec 2021 13:13:38 GMT</pubDate>
      <comments>https://grahamcluley.com/smashing-security-podcast-255/#respond</comments>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333569</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-12-09T13:13:38Z</dc:date>
    </item>
    <item>
      <title>UK and US seek to develop deeper data-sharing partnership</title>
      <link>https://www.computing.co.uk/news/4041852/uk-us-seek-develop-deeper-sharing-partnership</link>
      <description>&lt;img alt="UK and US seek to develop deeper data-sharing partnership" src="https://www.computing.co.uk/api/v1/wps/c2f6fc3/1b1e4aca-43ba-48a4-be62-e38d676b7b62/6/UKUSflags-185x114.png" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Nations want to collaborate on the creation of next-gen tools that shape new global rules on data use &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Thu, 09 Dec 2021 12:59:49 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4041852/uk-us-seek-develop-deeper-sharing-partnership</guid>
      <dc:date>2021-12-09T12:59:49Z</dc:date>
    </item>
    <item>
      <title>Ransomware damages expected to exceed £15 billion by end of year, report</title>
      <link>https://www.computing.co.uk/news/4041825/ransomware-damages-expected-exceed-gbp-billion-end-report</link>
      <description>&lt;img alt="Ransomware damages expected to exceed £15 billion by end of year, report" src="https://www.computing.co.uk/api/v1/wps/dde746e/13648aa5-357a-423e-965d-23c25b829026/9/ransomware-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Cybercriminals now try to use MSPs' own internal tools against them &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Thu, 09 Dec 2021 10:27:38 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4041825/ransomware-damages-expected-exceed-gbp-billion-end-report</guid>
      <dc:date>2021-12-09T10:27:38Z</dc:date>
    </item>
    <item>
      <title>Microsoft seizes control of 42 domains used by China-based Nickel hacking group</title>
      <link>https://www.computing.co.uk/news/4041815/microsoft-seizes-control-domains-china-nickel-hacking-group</link>
      <description>&lt;img alt="Microsoft seizes control of 42 domains used by China-based Nickel hacking group" src="https://www.computing.co.uk/api/v1/wps/7711397/a3bf7d89-c59f-4b83-9bd8-ff89fd1215fa/7/hackers-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; The company is now directing Nickel's traffic to its own servers &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Thu, 09 Dec 2021 07:50:06 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4041815/microsoft-seizes-control-domains-china-nickel-hacking-group</guid>
      <dc:date>2021-12-09T07:50:06Z</dc:date>
    </item>
    <item>
      <title>The Evolution of IoT Linux Malware Based on MITRE ATT&amp;CK TTPs</title>
      <link>https://www.trendmicro.com/en_us/research/21/l/the-evolution-of-iot-linux-malware-based-on-mitre-att&amp;ck-ttps.html</link>
      <description>In our study, we relied on the tactics, techniques, and procedures of MITRE ATT&amp;CK to define the malware capabilities and characteristics of IoT Linux malware. We describe our findings and how IoT malware has been evolving.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/l/the-evolution-of-iot-linux-malware-based-on-mitre-att-ck-ttps/the%20evolution%20of%20IoT%20linux%20malware%20based%20on%20mitre%20attack%20ttps.jpg" type="image/jpeg" />
      <category>Trend Micro Research : IoT</category>
      <category>Trend Micro Research : Research</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <category>Trend Micro Research : Cyber Threats</category>
      <pubDate>Thu, 09 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:f5c98506-269f-4359-1a87-bb1040838eb8</guid>
      <dc:creator>Veronica Chierzi</dc:creator>
      <dc:date>2021-12-09T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Top 10 Azure Cloud Configuration Mistakes</title>
      <link>https://www.trendmicro.com/en_us/devops/21/l/top-10-azure-cloud-configuration-mistakes.html</link>
      <description>Trend Micro Research determined the top 10 Azure services with the highest configuration rates.</description>
      <source url="https://www.trendmicro.com/en_us/devops.html">DevOps Resource Center</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/devops/21/l/top-10-azure-cloud-configuration-mistakes/devops-top-10-azure.jpg" type="image/jpeg" />
      <category>Trend Micro DevOps : Cloud Native</category>
      <category>Trend Micro DevOps : Azure</category>
      <category>Trend Micro DevOps : Article</category>
      <category>Trend Micro DevOps : Compliance</category>
      <category>Trend Micro DevOps : Conformity</category>
      <category>Trend Micro DevOps : Expert Perspective</category>
      <pubDate>Thu, 09 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:74a654c9-e36c-21e5-7131-dd6386a4e706</guid>
      <dc:date>2021-12-09T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Canada Charges Its “Most Prolific Cybercriminal”</title>
      <link>https://krebsonsecurity.com/2021/12/canada-charges-its-most-prolific-cybercriminal/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://krebsonsecurity.com/2021/12/canada-charges-its-most-prolific-cybercriminal/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">17</slash:comments>
      <description>A 31-year-old Canadian man has been arrested and charged with fraud in connection with numerous ransomware attacks against businesses, government agencies and private citizens throughout Canada and the United States. Canadian authorities describe him as "the most prolific cybercriminal we've identified in Canada," but so far they've released few other details about the investigation or the defendant. Helpfully, an email address and nickname apparently connected to the accused offer some additional clues.</description>
      <content:encoded>&lt;p&gt;A 31-year-old Canadian man has been arrested and charged with fraud in connection with numerous ransomware attacks against businesses, government agencies and private citizens throughout Canada and the United States. Canadian authorities describe him as &amp;#8220;the most prolific cybercriminal we&amp;#8217;ve identified in Canada,&amp;#8221; but so far they&amp;#8217;ve released few other details about the investigation or the defendant. Helpfully, an email address and nickname apparently connected to the accused offer some additional clues.&lt;/p&gt;
&lt;div id="attachment_57827" style="width: 292px" class="wp-caption alignright"&gt;&lt;img aria-describedby="caption-attachment-57827" loading="lazy" class="wp-image-57827" src="https://krebsonsecurity.com/wp-content/uploads/2021/12/philbertapril2016.png" alt="" width="282" height="284" /&gt;&lt;p id="caption-attachment-57827" class="wp-caption-text"&gt;Matthew Philbert, in 2016.&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Matthew Philbert&lt;/strong&gt; of Ottawa, Ontario was charged with fraud and conspiracy in a joint law enforcement action by Canadian and U.S. authorities dubbed &amp;#8220;Project CODA.&amp;#8221; The &lt;strong&gt;Ontario Provincial Police&lt;/strong&gt; (OPP) on Tuesday &lt;a href="https://twitter.com/OPP_News/status/1468294251867824129" target="_blank" rel="noopener"&gt;said&lt;/a&gt; the investigation began in January 2020 when the &lt;strong&gt;U.S. Federal Bureau of Investigation&lt;/strong&gt; (FBI) contacted them regarding ransomware attacks that were based in Canada.&lt;/p&gt;
&lt;p&gt;&amp;#8220;During the course of this investigation, OPP investigators determined an individual was responsible for numerous ransomware attacks affecting businesses, government agencies and private individuals throughout Canada as well as cyber-related offenses in the United States,&amp;#8221; reads an OPP statement.&lt;/p&gt;
&lt;p&gt;&amp;#8220;A quantity of evidentiary materials was seized and held for investigation, including desktop and laptop computers, a tablet, several hard drives, cellphones, a Bitcoin seed phrase and a quantity of blank cards with magnetic stripes,&amp;#8221; the statement continues.&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://krebsonsecurity.com/wp-content/uploads/2021/12/PhilbertIndictment.pdf" target="_blank" rel="noopener"&gt;U.S. indictment of Philbert&lt;/a&gt; (PDF) is unusually sparse, but it does charge him with conspiracy, suggesting the defendant was part of a group. In an interview with KrebsOnSecurity, &lt;strong&gt;OPP Detective Inspector Matt Watson&lt;/strong&gt; declined to say whether other defendants were being sought in connection with the investigation, but said the inquiry is ongoing.&lt;/p&gt;
&lt;p&gt;&amp;#8220;I will say this, Philbert is the most prolific cybercriminal we&amp;#8217;ve identified to date in Canada,&amp;#8221; Watson said. &amp;#8220;We&amp;#8217;ve identified in excess of a thousand of his victims. And a lot of these were small businesses that were just holding on by their fingernails during COVID.&amp;#8221;&lt;/p&gt;
&lt;h2&gt;A DARK CLOUD&lt;/h2&gt;
&lt;p&gt;There is a now-dormant &lt;strong&gt;Myspace&lt;/strong&gt; account for a Matthew Philbert from Orleans, a suburb of Ottawa, Ontario. The information tied to the Myspace account matches the age and town of the defendant. The Myspace account was registered under the nickname &amp;#8220;&lt;strong&gt;Darkcloudowner&lt;/strong&gt;,&amp;#8221; and to the email address &lt;strong&gt;dark_cl0ud6@hotmail.com&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;A search in &lt;a href="https://www.domaintools.com" target="_blank" rel="noopener"&gt;DomainTools&lt;/a&gt; on that email address reveals multiple domains registered to a Matthew Philbert and to the Ottawa phone number &lt;strong&gt;6138999251&lt;/strong&gt; [DomainTools is a frequent advertiser on this site]. That same phone number is tied to a Facebook account for a 31-year-old Matthew Philbert from Orleans, who describes himself as a self-employed &amp;#8220;broke bitcoin baron.&amp;#8221;&lt;/p&gt;
&lt;p&gt;Mr. Philbert did not respond to multiple requests for comment.&lt;/p&gt;
&lt;p&gt;According to cyber intelligence firm &lt;a href="https://www.intel471.com" target="_blank" rel="noopener"&gt;Intel 471&lt;/a&gt;, that dark_cl0ud6@hotmail.com address has been used in conjunction with the handle &amp;#8220;&lt;strong&gt;DCReavers2&lt;/strong&gt;&amp;#8221; to register user accounts on a half-dozen English-language cybercrime forums since 2008, including &lt;a href="https://krebsonsecurity.com/?s=hackforums" target="_blank" rel="noopener"&gt;Hackforums&lt;/a&gt;, Blackhatworld, and Ghostmarket.&lt;/p&gt;
&lt;p&gt;Perhaps the earliest and most important cybercrime forum DCReavers2 frequented was &lt;strong&gt;Darkode&lt;/strong&gt;, where he was among the first two-dozen members. Darkode was &lt;a href="https://krebsonsecurity.com/2015/07/the-darkode-cybercrime-forum-up-close/" target="_blank" rel="noopener"&gt;taken down in 2015 as part of an FBI investigation sting operation&lt;/a&gt;, but screenshots of the community saved by this author show that DCReavers2 was already well known to the Darkode founders when his membership to the forum was accepted in May 2009.&lt;/p&gt;
&lt;div id="attachment_57823" style="width: 739px" class="wp-caption aligncenter"&gt;&lt;img aria-describedby="caption-attachment-57823" loading="lazy" class="size-full wp-image-57823" src="https://krebsonsecurity.com/wp-content/uploads/2021/12/DCmemberlist.png" alt="" width="729" height="670" /&gt;&lt;p id="caption-attachment-57823" class="wp-caption-text"&gt;DCReavers2 was just the 22nd account to register on the Darkode cybercrime forum.&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;Most of DCReavers&amp;#8217;s posts on Darkode appear to have been removed by forum administrators early on (likely at DCReavers&amp;#8217; request), but the handful of posts that survived the purge show that more than a decade ago DCReavers2 was involved in running botnets, or large collections of hacked computers.&lt;/p&gt;
&lt;p&gt;&amp;#8220;My exploit pack is hosted there with 0 problems,&amp;#8221; DCReaver2 &lt;a href="https://krebsonsecurity.com/wp-content/uploads/2021/12/dcreavers2-dk.png" target="_blank" rel="noopener"&gt;says&lt;/a&gt; of a shady online provider that another member asked about in May 2010.&lt;span id="more-57819"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Searching the Web on &amp;#8220;DCreavers2&amp;#8221; brings up &lt;a href="https://www.exposedbotnets.com/2012/05/remember-h1t3mlo.html" target="_blank" rel="noopener"&gt;a fascinating chat conversation&lt;/a&gt; allegedly between DCReavers2 and an individual in Australia who was selling access to an &amp;#8220;&lt;a href="https://krebsonsecurity.com/2010/01/a-peek-inside-the-eleonore-browser-exploit-kit/" target="_blank" rel="noopener"&gt;exploit kit&lt;/a&gt;,&amp;#8221; commercial crimeware designed to be stitched into hacked or malicious sites and exploit a variety of Web-browser vulnerabilities for the purposes of installing malware of the customer’s choosing.&lt;/p&gt;
&lt;p&gt;In that 2009 chat, indexed by the researchers behind the website &lt;strong&gt;exposedbotnets.com&lt;/strong&gt;, DCReavers2 uses the Dark_Cl0ud6 email address and actually shares his real name as Matthew Philbert. DCReavers2 also says his partner uses the nickname &amp;#8220;&lt;strong&gt;The Rogue&lt;/strong&gt;,&amp;#8221; which corresponds to a former Darkode administrator who was the second user ever registered on the forum (see screenshot above).&lt;/p&gt;
&lt;p&gt;In that same conversation, DCReavers2 discusses managing a botnet built on &lt;strong&gt;ButterFly Bot&lt;/strong&gt;. Also known as &amp;#8220;&lt;strong&gt;Mariposa&lt;/strong&gt;,&amp;#8221; ButterFly was a plug-and-play malware strain that allowed even the most novice of would-be cybercriminals to set up a global operation capable of harvesting data from thousands of infected PCs, and using the enslaved systems for crippling attacks on Web sites. The ButterFly Bot kit sold for prices ranging from $500 to $2,000.&lt;/p&gt;
&lt;div id="attachment_1451" style="width: 771px" class="wp-caption aligncenter"&gt;&lt;img aria-describedby="caption-attachment-1451" loading="lazy" class=" wp-image-1451" src="https://krebsonsecurity.com/wp-content/uploads/2010/03/Screen-shot-2010-03-03-at-7.08.09-PM.png" alt="" width="761" height="419" srcset="https://krebsonsecurity.com/wp-content/uploads/2010/03/Screen-shot-2010-03-03-at-7.08.09-PM.png 962w, https://krebsonsecurity.com/wp-content/uploads/2010/03/Screen-shot-2010-03-03-at-7.08.09-PM-300x165.png 300w" sizes="(max-width: 761px) 100vw, 761px" /&gt;&lt;p id="caption-attachment-1451" class="wp-caption-text"&gt;An advertisement for the ButterFly Bot.&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;The author of ButterFly Bot &amp;#8212; Slovenian hacker &lt;strong&gt;Matjaz &amp;#8220;Iserdo&amp;#8221; Skorjanc&lt;/strong&gt; &amp;#8212; was Darkode&amp;#8217;s original founder back in 2008. Arrested in 2010, Skorjanc was sentenced to nearly five years in prison for selling and supporting Mariposa, which was used to compromise millions of Microsoft Windows computers.&lt;/p&gt;
&lt;p&gt;Upon release from prison, Skorjanc became chief technology officer for &lt;strong&gt;NiceHash&lt;/strong&gt;, a cryptocurrency mining service. In December 2017, $52 million worth of Bitcoin &lt;a href="https://krebsonsecurity.com/2017/12/former-botmaster-darkode-founder-is-cto-of-hacked-bitcoin-mining-firm-nicehash/" target="_blank" rel="noopener"&gt;mysteriously disappeared from NiceHash coffers&lt;/a&gt;. In October 2019, Skorjanc was &lt;a href="https://krebsonsecurity.com/2019/10/mariposa-botnet-author-darkcode-crime-forum-admin-arrested-in-germany/" target="_blank" rel="noopener"&gt;arrested in Germany&lt;/a&gt; in response to a U.S.-issued international arrest warrant for his extradition.&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://krebsonsecurity.com/wp-content/uploads/2021/12/skorjanc2018indict.pdf" target="_blank" rel="noopener"&gt;indictment&lt;/a&gt; (PDF) tied to Skorjanc&amp;#8217;s 2019 arrest also names several other alleged founding members of Darkode, including &lt;strong&gt;Thomas &amp;#8220;Fubar&amp;#8221; McCormick&lt;/strong&gt;, a Massachusetts man who was allegedly one of the last administrators of Darkode. Prosecutors say McCormick also was a reseller of the Mariposa botnet, the &lt;a href="https://krebsonsecurity.com/?s=zeus+trojan" target="_blank" rel="noopener"&gt;ZeuS banking trojan&lt;/a&gt;, and a bot malware he allegedly helped create called &amp;#8220;Ngrbot.&amp;#8221; The U.S. federal prosecution against Skorjanc and McCormick is ongoing.&lt;/p&gt;
&lt;p&gt;At the time the FBI dismantled Darkode in 2015, the Justice Department said that out of 800 or so crime forums worldwide, Darkode was the most sophisticated English-language forum, and that it represented &amp;#8220;&lt;em&gt;one of the gravest threats to the integrity of data on computers in the United States and around the world&lt;/em&gt;.&amp;#8221;&lt;/p&gt;
&lt;p&gt;Some of Darkode&amp;#8217;s core members were either customers or sellers of various &amp;#8220;locker&amp;#8221; kits, which were basically web-based exploits that would lock the victim&amp;#8217;s screen into a webpage spoofing the FBI or Justice Department and warning that victims had been caught accessing child sexual abuse material. Victims who agreed to pay a &amp;#8220;fine&amp;#8221; of several hundred dollars worth of GreenDot prepaid cards could then be rid of the PC locker program.&lt;/p&gt;
&lt;div id="attachment_57824" style="width: 768px" class="wp-caption aligncenter"&gt;&lt;img aria-describedby="caption-attachment-57824" loading="lazy" class=" wp-image-57824" src="https://krebsonsecurity.com/wp-content/uploads/2021/12/dk-locker.png" alt="" width="758" height="544" srcset="https://krebsonsecurity.com/wp-content/uploads/2021/12/dk-locker.png 1198w, https://krebsonsecurity.com/wp-content/uploads/2021/12/dk-locker-768x551.png 768w, https://krebsonsecurity.com/wp-content/uploads/2021/12/dk-locker-782x561.png 782w" sizes="(max-width: 758px) 100vw, 758px" /&gt;&lt;p id="caption-attachment-57824" class="wp-caption-text"&gt;A 2012 sales thread on Darkode for Rev Locker.&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;In many ways, lockers were the precursors to the modern cybercrime scourge we now know as ransomware. The main reason lockers never took off as an existential threat to organizations worldwide was that there is only so much money locker users could reasonably demand via GreenDot cards.&lt;/p&gt;
&lt;p&gt;But with the ascendance and broader acceptance of virtual currencies like Bitcoin, suddenly criminal hackers could start demanding millions of dollars from victims. And it stands to reason that a great many Darkode members who were never caught have since transitioned from lockers, exploit kits and GreenDot cards to doing what every other self-respecting cybercrook seems to be involved with these days: Locking entire companies and industries for ransomware payments.&lt;/p&gt;
&lt;p&gt;One final observation about the Philbert indictment: It&amp;#8217;s good to see the Canadian authorities working closely with the FBI on important cybercrime cases. Indeed, this investigation is remarkable for that fact alone. For years I&amp;#8217;ve been wondering aloud why more American cybercriminals don&amp;#8217;t just move to Canada, because historically there has been almost no probability that they will ever get caught &amp;#8212; let alone prosecuted there. With any luck, this case will be the start of something new.&lt;/p&gt;</content:encoded>
      <category>A Little Sunshine</category>
      <category>Ne'er-Do-Well News</category>
      <category>Ransomware</category>
      <category>darkcloudowner</category>
      <category>Darkode</category>
      <category>DCReavers2</category>
      <category>fbi</category>
      <category>fubar</category>
      <category>Iserdo</category>
      <category>Matt Watson</category>
      <category>Matthew Philbert</category>
      <category>Ontario Provincial Police</category>
      <category>Project CODA</category>
      <pubDate>Wed, 08 Dec 2021 23:27:40 GMT</pubDate>
      <comments>https://krebsonsecurity.com/2021/12/canada-charges-its-most-prolific-cybercriminal/#comments</comments>
      <guid isPermaLink="false">https://krebsonsecurity.com/?p=57819</guid>
      <dc:creator>BrianKrebs</dc:creator>
      <dc:date>2021-12-08T23:27:40Z</dc:date>
    </item>
    <item>
      <title>How to Stop Hackers From Turning Your Systems Against You</title>
      <link>https://www.darkreading.com/dr-tech/how-to-stop-hackers-from-turning-your-systems-against-you</link>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt641f6868cdbceffa/614b444579be080fa4994827/data-tools-maradon-333-shutterstock_266338532.jpg" type="image/*" />
      <description>Cybercriminals are increasingly adopting "living-off-the-land’ techniques, leveraging commonly used tools to fly under the radar of conventional detection tools. But with AI, thousands of organizations have regained the upper hand.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt70603175844e086d/6184269d7ac5c16804c6a841/Oakley_Cox_Headshot.JPG" type="image/*" />
      <pubDate>Wed, 08 Dec 2021 22:55:00 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/dr-tech/how-to-stop-hackers-from-turning-your-systems-against-you</guid>
      <dc:creator>Oakley Cox, Director of Analysis, Darktrace</dc:creator>
      <dc:date>2021-12-08T22:55:00Z</dc:date>
    </item>
    <item>
      <title>Claroty Raises $400M More, Acquires Healthcare IoT Security Firm Medigate</title>
      <link>https://www.darkreading.com/iot/claroty-raises-400m-more-acquires-healthcare-iot-security-firm-medigate</link>
      <description>Industrial control systems security firm reaches $635M in funding with this Series E round.</description>
      <enclosure url="https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blte161b23f0fd3a84b/60b1ea374e7eb868c4c6a293/dr_staff_125x125.jpg" type="image/*" />
      <pubDate>Wed, 08 Dec 2021 22:04:32 GMT</pubDate>
      <guid isPermaLink="false">https://www.darkreading.com/iot/claroty-raises-400m-more-acquires-healthcare-iot-security-firm-medigate</guid>
      <dc:creator>Dark Reading Staff, Dark Reading</dc:creator>
      <dc:date>2021-12-08T22:04:32Z</dc:date>
    </item>
    <item>
      <title>How to Overcome Threat Detection and Response Challenges</title>
      <link>https://feeds.feedblitz.com/~/674672746/_/thesecurityledger~How-to-Overcome-Threat-Detection-and-Response-Challenges/</link>
      <feedburner:origLink xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">https://securityledger.com/2021/12/how-to-overcome-threat-detection-and-response-challenges/</feedburner:origLink>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://feeds.feedblitz.com/~/674672746/_/thesecurityledger~How-to-Overcome-Threat-Detection-and-Response-Challenges/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <post-id xmlns="com-wordpress:feed-additions:1">476701</post-id>
      <description>&lt;p&gt;In this Expert Insight, Jack Naglieri, the founder and CEO of Panther Labs, talks about the many challenges of enterprise-scale threat detection and response. Jack provides some steps organizations can take to prepare themselves for the future. &lt;/p&gt;
&lt;p&gt;The post &lt;a rel="NOFOLLOW" href="https://feeds.feedblitz.com/~/674672746/_/thesecurityledger~How-to-Overcome-Threat-Detection-and-Response-Challenges/"&gt;How to Overcome Threat Detection and Response Challenges&lt;/a&gt; appeared first on &lt;a rel="NOFOLLOW" href="https://securityledger.com"&gt;The Security Ledger...&lt;/a&gt;&lt;/p&gt;&lt;p style="clear:left"&gt;&lt;span class="fbz_teasertext"&gt;&lt;a href="https://feeds.feedblitz.com/~/674672746/_/thesecurityledger"&gt;&lt;b&gt;Read the whole entry...&lt;/b&gt;&lt;/a&gt;&amp;#160;&lt;!-- _!fbztxtlnk!_ https://feeds.feedblitz.com/~/674672746/_/thesecurityledger --&gt;&lt;b&gt;&amp;#187;&lt;/b&gt;&lt;/p&gt;&lt;/span&gt;&lt;/p&gt;&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/07/spotting-hackers-at-the-pace-of-xdr-from-alerts-to-incidents/"&gt;Spotting Hackers at the Pace of XDR &amp;#x2013; From Alerts to Incidents&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/12/spotlight-how-secrets-sprawl-undermines-software-supply-chain-security/"&gt;Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/11/episode-230-are-vaccine-passports-cyber-secure/"&gt;Episode 230: Are Vaccine Passports Cyber Secure?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
      <content:encoded>&lt;p&gt;In this Expert Insight, Jack Naglieri, the founder and CEO of Panther Labs, talks about the many challenges of enterprise-scale threat detection and response. Jack provides some steps organizations can take to prepare themselves for the future. &lt;/p&gt;
&lt;p&gt;The post &lt;a rel="nofollow" href="https://feeds.feedblitz.com/~/t/0/_/thesecurityledger/~https://securityledger.com/2021/12/how-to-overcome-threat-detection-and-response-challenges/"&gt;How to Overcome Threat Detection and Response Challenges&lt;/a&gt; appeared first on &lt;a rel="nofollow" href="https://feeds.feedblitz.com/~/t/0/_/thesecurityledger/~https://securityledger.com"&gt;The Security Ledger...&lt;/a&gt;&lt;/p&gt;&lt;p style="clear:left"&gt;&lt;span class="fbz_teasertext"&gt;&lt;a href="https://feeds.feedblitz.com/~/674672746/_/thesecurityledger"&gt;&lt;b&gt;Read the whole entry...&lt;/b&gt;&lt;/a&gt;&amp;#160;&lt;!-- _!fbztxtlnk!_ https://feeds.feedblitz.com/~/674672746/_/thesecurityledger --&gt;&lt;b&gt;&amp;#187;&lt;/b&gt;&lt;/p&gt;&lt;/span&gt;&lt;Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.feedblitz.com/~/i/674672746/_/thesecurityledger"&gt;
&lt;/p&gt;&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/07/spotting-hackers-at-the-pace-of-xdr-from-alerts-to-incidents/"&gt;Spotting Hackers at the Pace of XDR &amp;#x2013; From Alerts to Incidents&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/12/spotlight-how-secrets-sprawl-undermines-software-supply-chain-security/"&gt;Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/11/episode-230-are-vaccine-passports-cyber-secure/"&gt;Episode 230: Are Vaccine Passports Cyber Secure?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded>
      <category>contributed</category>
      <category>incident response</category>
      <category>Panther Labs</category>
      <category>Reports</category>
      <category>security orchestration and automation</category>
      <category>SIEM</category>
      <category>threat intelligence</category>
      <category>Top Stories</category>
      <category>application security</category>
      <category>cloud computing</category>
      <category>cybersecurity</category>
      <category>process automation</category>
      <category>threat detection</category>
      <pubDate>Wed, 08 Dec 2021 17:50:44 GMT</pubDate>
      <comments>https://feeds.feedblitz.com/~/674672746/_/thesecurityledger~How-to-Overcome-Threat-Detection-and-Response-Challenges/#respond</comments>
      <guid isPermaLink="false">https://securityledger.com/?p=476701</guid>
      <dc:creator>Jack Naglieri</dc:creator>
      <dc:date>2021-12-08T17:50:44Z</dc:date>
    </item>
    <item>
      <title>Leaked Downing Street video footage exposes staff laughing about party</title>
      <link>https://grahamcluley.com/leaked-downing-street-video-footage-exposes-staff-laughing-about-party/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://grahamcluley.com/leaked-downing-street-video-footage-exposes-staff-laughing-about-party/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">8</slash:comments>
      <description>Once again video has leaked from inside the UK Government that has put it in hot water.</description>
      <category>Data loss</category>
      <category>Law &amp; order</category>
      <category>Privacy</category>
      <category>Coronavirus</category>
      <category>data breach</category>
      <category>Downing Street</category>
      <pubDate>Tue, 07 Dec 2021 19:16:16 GMT</pubDate>
      <comments>https://grahamcluley.com/leaked-downing-street-video-footage-exposes-staff-laughing-about-party/#comments</comments>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333553</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-12-07T19:16:16Z</dc:date>
    </item>
    <item>
      <title>Ransomware hits Spar supermarkets and petrol stations</title>
      <link>https://grahamcluley.com/ransomware-hits-spar-supermarkets-and-petrol-stations/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://grahamcluley.com/ransomware-hits-spar-supermarkets-and-petrol-stations/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">1</slash:comments>
      <description>Supermarket chain Spar has had more than 300 of its convenience stores in the UK affected by a ransomware attack, which has forced some to close their doors or only accept cash payments.</description>
      <category>Malware</category>
      <category>Ransomware</category>
      <category>ransomware</category>
      <category>supermarket</category>
      <pubDate>Tue, 07 Dec 2021 18:32:05 GMT</pubDate>
      <comments>https://grahamcluley.com/ransomware-hits-spar-supermarkets-and-petrol-stations/#comments</comments>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333544</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-12-07T18:32:05Z</dc:date>
    </item>
    <item>
      <title>Spar forced to close a number of stores following cyber attack</title>
      <link>https://www.computing.co.uk/news/4041673/spar-forced-close-stores-following-cyber-attack</link>
      <description>&lt;img alt="Spar forced to close a number of stores following cyber attack" src="https://www.computing.co.uk/api/v1/wps/28c84d0/dd21af48-f7af-47e2-9d03-bae3a76cbd11/10/Spar-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; More than 300 branches have been affected as a result of the attack &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 07 Dec 2021 08:01:32 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4041673/spar-forced-close-stores-following-cyber-attack</guid>
      <dc:date>2021-12-07T08:01:32Z</dc:date>
    </item>
    <item>
      <title>Cambridge Quantum launches cloud key generation service, with claim of perfect randomness</title>
      <link>https://www.computing.co.uk/news/4041671/cambridge-quantum-launches-cloud-key-generation-service-claim-perfect-randomness</link>
      <description>&lt;img alt="Cambridge Quantum launches cloud key generation service, with claim of perfect randomness " src="https://www.computing.co.uk/api/v1/wps/4b3ef8d/5415fefd-fee8-42dc-87e7-103bcc994633/5/quantum-origin-185x114.png" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Never been done before, the company says &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 07 Dec 2021 05:16:02 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4041671/cambridge-quantum-launches-cloud-key-generation-service-claim-perfect-randomness</guid>
      <dc:date>2021-12-07T05:16:02Z</dc:date>
    </item>
    <item>
      <title>Virtual Patching 101</title>
      <link>https://www.trendmicro.com/en_us/devops/21/l/virtual-patching-101.html</link>
      <description>Get the lowdown on virtual patching: a simplified, automated solution to shielding vulnerabilities from exploits.</description>
      <source url="https://www.trendmicro.com/en_us/devops.html">DevOps Resource Center</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/devops/21/l/virtual-patching-101/virtual-patching.png" type="image/png" />
      <category>Trend Micro DevOps : Workload Security</category>
      <category>Trend Micro DevOps : Cloud Native</category>
      <category>Trend Micro DevOps : Network Security</category>
      <category>Trend Micro DevOps : Infographic</category>
      <category>Trend Micro DevOps : Multi Cloud</category>
      <category>Trend Micro DevOps : Expert Perspective</category>
      <pubDate>Tue, 07 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:d3a6d4e0-7e36-df5e-52e9-be0bcccdb58e</guid>
      <dc:date>2021-12-07T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Ransomware – how to stop it, and how to survive an attack. Free eBook by Recorded Future</title>
      <link>https://grahamcluley.com/feed-sponsor-recorded-future-29/</link>
      <description>Graham Cluley Security News is sponsored this week by the folks at Recorded Future. Thanks to the great team there for their support! Ransomware attacks dominate the cybersecurity news headlines, with businesses all over the world wondering if they will be the next victim. It’s a legitimate, and growing fear, as the attackers get more &amp;#8230; &lt;a href="https://grahamcluley.com/feed-sponsor-recorded-future-29/" class="more-link"&gt;Continue reading&lt;span class="screen-reader-text"&gt; "Ransomware &amp;#8211; how to stop it, and how to survive an attack. Free eBook by Recorded Future"&lt;/span&gt;&lt;/a&gt;</description>
      <category>Feed only</category>
      <pubDate>Mon, 06 Dec 2021 11:12:14 GMT</pubDate>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333535</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-12-06T11:12:14Z</dc:date>
    </item>
    <item>
      <title>NSO spyware used to hack US State Department phones</title>
      <link>https://www.computing.co.uk/news/4041606/nso-spyware-hack-us-department-phones</link>
      <description>&lt;img alt="NSO spyware used to hack US State Department phones" src="https://www.computing.co.uk/api/v1/wps/626d2cd/e60c6f6c-7e12-4d0e-acb2-81a6493d469b/9/iphonebackdoor-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; The officials targeted were either based in Uganda or worked on matters related to the country &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Mon, 06 Dec 2021 10:22:29 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4041606/nso-spyware-hack-us-department-phones</guid>
      <dc:date>2021-12-06T10:22:29Z</dc:date>
    </item>
    <item>
      <title>Criminals now phishing verified Twitter accounts</title>
      <link>https://www.computing.co.uk/news/4041598/criminals-phishing-verified-twitter-accounts</link>
      <description>&lt;img alt="Criminals now phishing verified Twitter accounts" src="https://www.computing.co.uk/api/v1/wps/e680bff/69962af7-caad-440f-a0ca-590cfc4ee93b/9/Twitter-final-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; It follows Twitter's recent removal of checkmarks from many verified accounts &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Mon, 06 Dec 2021 05:02:43 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4041598/criminals-phishing-verified-twitter-accounts</guid>
      <dc:date>2021-12-06T05:02:43Z</dc:date>
    </item>
    <item>
      <title>Who Is the Network Access Broker ‘Babam’?</title>
      <link>https://krebsonsecurity.com/2021/12/who-is-the-network-access-broker-babam/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://krebsonsecurity.com/2021/12/who-is-the-network-access-broker-babam/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">33</slash:comments>
      <description>Rarely do cybercriminal gangs that deploy ransomware gain the initial access to the target themselves. More commonly, that access is purchased from a cybercriminal broker who specializes in stealing remote access credentials -- such as usernames and passwords needed to remotely connect to the target's network. In this post we'll look at the clues left behind by "Babam," the handle chosen by a cybercriminal who has sold such access to ransomware groups on many occasions over the past few years.</description>
      <content:encoded>&lt;p&gt;Rarely do cybercriminal gangs that deploy ransomware gain the initial access to the target themselves. More commonly, that access is purchased from a cybercriminal broker who specializes in acquiring remote access credentials &amp;#8212; such as usernames and passwords needed to remotely connect to the target&amp;#8217;s network. In this post we&amp;#8217;ll look at the clues left behind by &amp;#8220;&lt;strong&gt;Babam&lt;/strong&gt;,&amp;#8221; the handle chosen by a cybercriminal who has sold such access to ransomware groups on many occasions over the past few years.&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" class="aligncenter size-full wp-image-53514" src="https://krebsonsecurity.com/wp-content/uploads/2020/11/ransomware.png" alt="" width="1016" height="761" srcset="https://krebsonsecurity.com/wp-content/uploads/2020/11/ransomware.png 1016w, https://krebsonsecurity.com/wp-content/uploads/2020/11/ransomware-768x575.png 768w" sizes="(max-width: 1016px) 100vw, 1016px" /&gt;&lt;/p&gt;
&lt;p&gt;Since the beginning of 2020, Babam has set up numerous auctions on the Russian-language cybercrime forum &lt;strong&gt;Exploit&lt;/strong&gt;, mainly selling virtual private networking (VPN) credentials stolen from various companies. Babam has authored more than 270 posts since joining Exploit in 2015, including dozens of sales threads. However, none of Babam&amp;#8217;s posts on Exploit include any personal information or clues about his identity.&lt;/p&gt;
&lt;p&gt;But in February 2016, Babam joined &lt;strong&gt;Verified&lt;/strong&gt;, another Russian-language crime forum. Verified was hacked at least twice in the past five years, and its user database posted online. That information shows that Babam joined Verified using the email address &amp;#8220;&lt;strong&gt;operns@gmail.com&lt;/strong&gt;.&amp;#8221; The latest Verified leak also exposed private messages exchanged by forum members, including more than 800 private messages that Babam sent or received on the forum over the years.&lt;/p&gt;
&lt;p&gt;In early 2017, Babam confided to another Verified user via private message that he is from Lithuania. In virtually all of his forum posts and private messages, Babam can be seen communicating in transliterated Russian rather than by using the Cyrillic alphabet. This is common among cybercriminal actors for whom Russian is not their native tongue.&lt;/p&gt;
&lt;p&gt;Cyber intelligence platform &lt;a href="https://www.constellaintelligence.com" target="_blank" rel="noopener"&gt;Constella Intelligence&lt;/a&gt; told KrebsOnSecurity that the operns@gmail.com address was used in 2016 to register an account at &lt;strong&gt;filmai.in&lt;/strong&gt;, which is a movie streaming service catering to Lithuanian speakers. The username associated with that account was &amp;#8220;&lt;strong&gt;bo3dom&lt;/strong&gt;.&amp;#8221;&lt;/p&gt;
&lt;p&gt;A reverse WHOIS search via &lt;a href="https://www.domaintools.com" target="_blank" rel="noopener"&gt;DomainTools.com&lt;/a&gt; says operns@gmail.com was used to register two domain names: bonnjoeder[.]com back in 2011, and sanjulianhotels[.]com (2017). It&amp;#8217;s unclear whether these domains ever were online, but the street address on both records was &amp;#8220;&lt;strong&gt;24 Brondeg St.&lt;/strong&gt;&amp;#8221; in the United Kingdom. [Full disclosure: DomainTools is a frequent advertiser on this website.]&lt;/p&gt;
&lt;p&gt;A reverse search at DomainTools on &amp;#8220;24 Brondeg St.&amp;#8221; reveals one other domain: &lt;strong&gt;wwwecardone[.]com&lt;/strong&gt;. The use of domains that begin with &amp;#8220;www&amp;#8221; is fairly common among phishers, and by passive &amp;#8220;&lt;a href="https://krebsonsecurity.com/2018/04/dot-cm-typosquatting-sites-visited-12m-times-so-far-in-2018/" target="_blank" rel="noopener"&gt;typosquatting&lt;/a&gt;&amp;#8221; sites that seek to siphon credentials from legitimate websites when people mistype a domain, such as accidentally omitting the &amp;#8220;.&amp;#8221; after typing &amp;#8220;www&amp;#8221;.&lt;/p&gt;
&lt;div id="attachment_49523" style="width: 771px" class="wp-caption aligncenter"&gt;&lt;img aria-describedby="caption-attachment-49523" loading="lazy" class=" wp-image-49523" src="https://krebsonsecurity.com/wp-content/uploads/2019/11/verified.png" alt="" width="761" height="125" /&gt;&lt;p id="caption-attachment-49523" class="wp-caption-text"&gt;A banner from the homepage of the Russian language cybercrime forum Verified.&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;Searching DomainTools for the phone number in the WHOIS records for wwwecardone[.]com  &amp;#8212; +44.0774829141 &amp;#8212; leads to a handful of similar typosquatting domains, including &lt;strong&gt;wwwebuygold[.]com &lt;/strong&gt;and&lt;strong&gt; wwwpexpay[.]com&lt;/strong&gt;. A different UK phone number in a more recent record for the wwwebuygold[.]com domain &amp;#8212; 44.0472882112 &amp;#8212; is tied to two more domains &amp;#8211; &lt;strong&gt;howtounlockiphonefree[.]com&lt;/strong&gt;, and &lt;strong&gt;portalsagepay[.]com&lt;/strong&gt;. All of these domains date back to between 2012 and 2013.&lt;/p&gt;
&lt;p&gt;The original registration records for the iPhone, Sagepay and Gold domains share an email address: &lt;strong&gt;devrian26@gmail.com&lt;/strong&gt;. A search on the username &amp;#8220;bo3dom&amp;#8221; using Constella&amp;#8217;s service reveals an account at &lt;strong&gt;ipmart-forum.com&lt;/strong&gt;, a now-defunct forum concerned with IT products, such as mobile devices, computers and online gaming. That search shows the user bo3dom registered at ipmart-forum.com with the email address &lt;strong&gt;devrian27@gmail.com&lt;/strong&gt;, and from an Internet address in Vilnius, Lithuania.&lt;/p&gt;
&lt;p&gt;Devrian27@gmail.com was used to register multiple domains, including &lt;strong&gt;wwwsuperchange.ru&lt;/strong&gt; back in 2008 (notice again the suspect &amp;#8220;www&amp;#8221; as part of the domain name). Gmail&amp;#8217;s password recovery function says the backup email address for devrian27@gmail.com is&lt;strong&gt; bo3*******@gmail.com&lt;/strong&gt;. Gmail accepts the address &lt;strong&gt;bo3domster@gmail.com&lt;/strong&gt; as the recovery email for that devrian27 account.&lt;/p&gt;
&lt;p&gt;According to Constella, the bo3domster@gmail.com address was exposed in multiple data breaches over the years, and in each case it used one of two passwords: &amp;#8220;&lt;strong&gt;lebeda1&lt;/strong&gt;&amp;#8221; and &amp;#8220;&lt;strong&gt;a123456&lt;/strong&gt;&amp;#8220;.&lt;/p&gt;
&lt;p&gt;Searching in Constella for accounts using those passwords reveals a slew of additional &amp;#8220;bo3dom&amp;#8221; email addresses, including &lt;strong&gt;bo3dom@gmail.com&lt;/strong&gt;.  Pivoting on that address in Constella reveals that someone with the name &lt;strong&gt;Vytautas Mockus &lt;/strong&gt;used it to register an account at mindjolt.com, a site featuring dozens of simple puzzle games that visitors can play online.&lt;/p&gt;
&lt;p&gt;At some point, mindjolt.com apparently also was hacked, because a copy of its database at Constella says the bo3dom@gmail.com used two passwords at that site: &lt;strong&gt;lebeda1&lt;/strong&gt; and &lt;strong&gt;a123456.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;A reverse WHOIS search on &amp;#8220;Vytautas Mockus&amp;#8221; at DomainTools shows the email address &lt;strong&gt;devrian25@gmail.com&lt;/strong&gt; was used in 2010 to register the domain name &lt;strong&gt;perfectmoney[.]co&lt;/strong&gt;. This is one character off of &lt;a href="https://en.bitcoin.it/wiki/Perfect_Money" target="_blank" rel="noopener"&gt;perfectmoney[.]com&lt;/a&gt;, which is an early virtual currency that was quite popular with cybercriminals at the time. The phone number tied to that domain registration was &amp;#8220;&lt;strong&gt;86.7273687&lt;/strong&gt;&amp;#8220;.&lt;/p&gt;
&lt;p&gt;A Google search for &amp;#8220;Vytautas Mockus&amp;#8221; says there&amp;#8217;s a person by that name who runs a mobile food service company in Lithuania called &amp;#8220;&lt;strong&gt;Palvisa&lt;/strong&gt;.&amp;#8221; A &lt;a href="https://krebsonsecurity.com/wp-content/uploads/2021/12/302610044-2559-e71f3.pdf" target="_blank" rel="noopener"&gt;report on Palvisa&lt;/a&gt; (PDF) purchased from &lt;strong&gt;Rekvizitai.vz&lt;/strong&gt; &amp;#8212; an official online directory of Lithuanian companies &amp;#8212; says Palvisa was established in 2011 by a Vytautaus Mockus, using the phone number &lt;strong&gt;86.7273687&lt;/strong&gt;, and the email address bo3dom@gmail.com. The report states that Palvisa is active, but has had no employees other than its founder.&lt;/p&gt;
&lt;p&gt;Reached via the bo3dom@gmail.com address, the 36-year-old Mr. Mockus expressed mystification as to how his personal information wound up in so many records. &amp;#8220;I am not involved in any crime,&amp;#8221; Mockus wrote in reply.&lt;/p&gt;
&lt;div id="attachment_57797" style="width: 769px" class="wp-caption aligncenter"&gt;&lt;a href="https://krebsonsecurity.com/wp-content/uploads/2021/12/babam-simple.png" target="_blank" rel="noopener"&gt;&lt;img aria-describedby="caption-attachment-57797" loading="lazy" class="wp-image-57797" src="https://krebsonsecurity.com/wp-content/uploads/2021/12/babam-simple.png" alt="" width="759" height="453" srcset="https://krebsonsecurity.com/wp-content/uploads/2021/12/babam-simple.png 1572w, https://krebsonsecurity.com/wp-content/uploads/2021/12/babam-simple-768x458.png 768w, https://krebsonsecurity.com/wp-content/uploads/2021/12/babam-simple-1536x917.png 1536w, https://krebsonsecurity.com/wp-content/uploads/2021/12/babam-simple-782x467.png 782w" sizes="(max-width: 759px) 100vw, 759px" /&gt;&lt;/a&gt;&lt;p id="caption-attachment-57797" class="wp-caption-text"&gt;A rough mind map of the connections mentioned in this story.&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;&lt;span id="more-57745"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;The domains apparently registered by Babam over nearly 10 years suggest he started off mainly stealing from other cybercrooks. By 2015, Babam was heavily into &amp;#8220;carding,&amp;#8221; the sale and use of stolen payment card data. By 2020, he&amp;#8217;d shifted his focus almost entirely to selling access to companies.&lt;/p&gt;
&lt;p&gt;A profile produced by threat intelligence firm &lt;a href="https://www.flashpoint-intel.com" target="_blank" rel="noopener"&gt;Flashpoint&lt;/a&gt; says Babam has received at least four positive feedback reviews on the Exploit cybercrime forum from crooks associated with the &lt;a href="https://www.cybereason.com/blog/rising-threat-from-lockbit-ransomware" target="_blank" rel="noopener"&gt;LockBit ransomware gang&lt;/a&gt;.&lt;/p&gt;
&lt;div id="attachment_57751" style="width: 736px" class="wp-caption aligncenter"&gt;&lt;img aria-describedby="caption-attachment-57751" loading="lazy" class="size-full wp-image-57751" src="https://krebsonsecurity.com/wp-content/uploads/2021/12/babamfeedback.png" alt="" width="726" height="278" /&gt;&lt;p id="caption-attachment-57751" class="wp-caption-text"&gt;The ransomware collective LockBit giving Babam positive feedback for selling access to different victim organizations. Image: Flashpoint&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;According to Flashpoint, in April 2021 Babam advertised the sale of Citrix credentials for an international company that is active in the field of laboratory testing, inspection and certification, and that has more than $5 billion in annual revenues and more than 78,000 employees.&lt;/p&gt;
&lt;p&gt;Flashpoint says Babam initially announced he&amp;#8217;d sold the access, but later reopened the auction because the prospective buyer backed out of the deal. Several days later, Babam reposted the auction, adding more information about the depth of the illicit access and lowering his asking price. The access sold less than 24 hours later.&lt;/p&gt;
&lt;p&gt;&amp;#8220;Based on the provided statistics and sensitive source reporting, Flashpoint analysts assess with high confidence that the compromised organization was likely &lt;strong&gt;Bureau Veritas&lt;/strong&gt;, an organization headquartered in France that operates in a variety of sectors,&amp;#8221; the company concluded.&lt;/p&gt;
&lt;p&gt;In November, Bureau Veritas acknowledged that it &lt;a href="https://www.maritime-executive.com/article/bureau-veritas-is-latest-target-of-cyber-attack" target="_blank" rel="noopener"&gt;shut down its network in response to a cyber attack&lt;/a&gt;. The company hasn&amp;#8217;t said whether the incident involved ransomware and if so what strain of ransomware, but its response to the incident is straight out of the playbook for responding to ransomware attacks. Bureau Veritas has not yet responded to requests for comment; its &lt;a href="https://group.bureauveritas.com/newsroom/update-cyber-attack" target="_blank" rel="noopener"&gt;latest public statement on Dec. 2&lt;/a&gt; provides no additional details about the cause of the incident.&lt;/p&gt;
&lt;p&gt;Flashpoint notes that Babam&amp;#8217;s use of transliterated Russian persists on both Exploit and Verified until around March 2020, when he switches over to using mostly Cyrillc in his forum comments and sales threads. Flashpoint said this could be an indication that a different person started using the Babam account since then, or more likely that Babam had only a tenuous grasp of Russian to begin with and that his language skills and confidence improved over time.&lt;/p&gt;
&lt;p&gt;Lending credence to the latter theory is that Babam still makes linguistic errors in his postings that suggest Russian is not his original language, Flashpoint found.&lt;/p&gt;
&lt;p&gt;&amp;#8220;The use of double &amp;#8220;n&amp;#8221; in such words as &amp;#8220;проданно&amp;#8221; (correct &amp;#8211; продано) and &amp;#8220;сделанны&amp;#8221; (correct &amp;#8211; сделаны) by the threat actor proves that this style of writing is not possible when using machine translation since this would not be the correct spelling of the word,&amp;#8221; Flashpoint analysts wrote.&lt;/p&gt;
&lt;p&gt;&amp;#8220;These types of grammatical errors are often found among people who did not receive sufficient education at school or if Russian is their second language,&amp;#8221; the analysis continues. &amp;#8220;In such cases, when someone tries to spell a word correctly, then by accident or unknowingly, they overdo the spelling and make these types of mistakes. At the same time, colloquial speech can be fluent or even native. This is often typical for a person who comes from the former Soviet Union states.&amp;#8221;&lt;/p&gt;</content:encoded>
      <category>Breadcrumbs</category>
      <category>Ne'er-Do-Well News</category>
      <category>Ransomware</category>
      <category>Babam</category>
      <category>bo3dom bo3domster</category>
      <category>Bureau Veritas</category>
      <category>Constella Intelligence</category>
      <category>domaintools</category>
      <category>Flashpoint</category>
      <category>LockBit</category>
      <category>ransomware</category>
      <category>Rekvizitai.vz</category>
      <pubDate>Fri, 03 Dec 2021 21:53:44 GMT</pubDate>
      <comments>https://krebsonsecurity.com/2021/12/who-is-the-network-access-broker-babam/#comments</comments>
      <guid isPermaLink="false">https://krebsonsecurity.com/?p=57745</guid>
      <dc:creator>BrianKrebs</dc:creator>
      <dc:date>2021-12-03T21:53:44Z</dc:date>
    </item>
    <item>
      <title>UK Government fined £500,000 after revealing home addresses in New Year honours data breach</title>
      <link>https://grahamcluley.com/uk-government-fined-500000-after-revealing-home-addresses-in-new-year-honours-data-breach/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://grahamcluley.com/uk-government-fined-500000-after-revealing-home-addresses-in-new-year-honours-data-breach/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">1</slash:comments>
      <description>The UK Government has been fined £500,000 after the addresses of over 1,000 New Years Honours recipients were mistakenly published online, potentially putting some of them at serious risk.</description>
      <category>Celebrities</category>
      <category>Data loss</category>
      <category>Privacy</category>
      <category>data breach</category>
      <category>New Years Honours</category>
      <category>UK government</category>
      <pubDate>Fri, 03 Dec 2021 14:47:43 GMT</pubDate>
      <comments>https://grahamcluley.com/uk-government-fined-500000-after-revealing-home-addresses-in-new-year-honours-data-breach/#comments</comments>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333525</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-12-03T14:47:43Z</dc:date>
    </item>
    <item>
      <title>Man charged with Ubiquiti data breach and extortion was employee assigned to investigate hack</title>
      <link>https://www.bitdefender.com/blog/hotforsecurity/man-charged-with-ubiquiti-data-breach-and-extortion-was-employee-assigned-to-investigate-hack/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://www.bitdefender.com/blog/hotforsecurity/man-charged-with-ubiquiti-data-breach-and-extortion-was-employee-assigned-to-investigate-hack/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <description>A former employee of Ubiquiti Networks has been arrested and charged in connection with a hack that stole gigabytes of data and attempted to extort US $2 million from the firm.

Read more in my article on the Hot for Security blog.</description>
      <category>Data loss</category>
      <category>Guest blog</category>
      <category>Law &amp; order</category>
      <category>data breach</category>
      <category>extortion</category>
      <category>insider threat</category>
      <category>Ubiquiti</category>
      <pubDate>Fri, 03 Dec 2021 10:26:13 GMT</pubDate>
      <comments>https://www.bitdefender.com/blog/hotforsecurity/man-charged-with-ubiquiti-data-breach-and-extortion-was-employee-assigned-to-investigate-hack/#respond</comments>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333519</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-12-03T10:26:13Z</dc:date>
    </item>
    <item>
      <title>Cabinet Office fined £500,000 by ICO over New Year Honours data breach</title>
      <link>https://www.computing.co.uk/news/4041517/cabinet-office-fined-gbp500-ico-honours-breach</link>
      <description>&lt;img alt="Cabinet Office fined £500,000 by ICO over New Year Honours data breach" src="https://www.computing.co.uk/api/v1/wps/7f3f7ee/183c800e-02c2-4e5e-baef-62c75e9a2186/6/cabinet-office-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Sir Elton John and cricketer Ben Stokes are among individuals affected by the breach &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Fri, 03 Dec 2021 03:28:47 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4041517/cabinet-office-fined-gbp500-ico-honours-breach</guid>
      <dc:date>2021-12-03T03:28:47Z</dc:date>
    </item>
    <item>
      <title>This Week in Security News - December 3, 2021</title>
      <link>https://www.trendmicro.com/en_us/research/21/l/this-week-in-security-news-dec-3-2021.html</link>
      <description>This week, learn about how Squirrelwaffle utilized ProxyLogon and ProxyShell to hack email chains. Also, read on a recent data breach of the Los Angeles Planned Parenthood Network.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/week-in-security-news_lrg.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Cloud</category>
      <category>Trend Micro Research : Cyber Crime</category>
      <category>Trend Micro Research : Exploits &amp; Vulnerabilities</category>
      <category>Trend Micro Research : Expert Perspective</category>
      <category>Trend Micro Research : Ransomware</category>
      <category>Trend Micro Research : Smart Factories</category>
      <category>Trend Micro Research : Network</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <pubDate>Fri, 03 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:f014e173-1ae9-cdbb-7ac9-8376c6b20d8c</guid>
      <dc:creator>Jon Clay</dc:creator>
      <dc:date>2021-12-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vulnerabilities Exploited for Monero Mining Malware Delivered via GitHub, Netlify</title>
      <link>https://www.trendmicro.com/en_us/research/21/l/vulnerabilities-exploited-for-monero-mining-malware-delivered-via-gitHub-netlify.html</link>
      <description>We looked into exploitation attempts we observed in the wild and the abuse of legitimate platforms Netlify and GitHub as repositories for malware.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/l/vulnerabilities-exploited-for-monero-mining-malware-delivered-via-github-netlify/cover-vulnerabilities-exploited-monero-mining-malware-delivered-github-netlify-650.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Malware</category>
      <category>Trend Micro Research : Endpoints</category>
      <category>Trend Micro Research : Cyber Crime</category>
      <category>Trend Micro Research : Exploits &amp; Vulnerabilities</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <category>Trend Micro Research : Cyber Threats</category>
      <pubDate>Fri, 03 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:5ca58cd1-e3b4-64be-f85d-4390816f27e7</guid>
      <dc:creator>Nitesh Surana</dc:creator>
      <dc:date>2021-12-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>FluBot malware warning after 70,000 attacks launched over SMS</title>
      <link>https://www.tripwire.com/state-of-security/security-data-protection/flubot-malware-warning-after-70000-attacks-launched-over-sms/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://www.tripwire.com/state-of-security/security-data-protection/flubot-malware-warning-after-70000-attacks-launched-over-sms/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <description>Finland’s National Cyber Security Centre has issued a warning about malicious SMS messages that have been spammed out to mobile users, directing iPhone owners to phishing sites and Android users to download malware.

Read more in my article on the Tripwire State of Security blog.</description>
      <category>Android</category>
      <category>Guest blog</category>
      <category>iOS</category>
      <category>Malware</category>
      <category>Phishing</category>
      <category>FluBot</category>
      <category>SMS</category>
      <pubDate>Thu, 02 Dec 2021 17:09:50 GMT</pubDate>
      <comments>https://www.tripwire.com/state-of-security/security-data-protection/flubot-malware-warning-after-70000-attacks-launched-over-sms/#respond</comments>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333515</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-12-02T17:09:50Z</dc:date>
    </item>
    <item>
      <title>1Password 8 for Windows – improved productivity, and enhanced security &amp; privacy</title>
      <link>https://grahamcluley.com/feed-sponsor-1password-14/</link>
      <description>Graham Cluley Security News is sponsored this week by the folks at 1Password. Thanks to the great team there for their support! 1Password 8 for Windows is the most modern, productive, and secure version of 1Password yet, helping you manage, access, and protect your sensitive information more easily and securely than ever before. Modern Design &amp;#8230; &lt;a href="https://grahamcluley.com/feed-sponsor-1password-14/" class="more-link"&gt;Continue reading&lt;span class="screen-reader-text"&gt; "1Password 8 for Windows &amp;#8211; improved productivity, and enhanced security &amp;#038; privacy"&lt;/span&gt;&lt;/a&gt;</description>
      <category>Feed only</category>
      <pubDate>Thu, 02 Dec 2021 17:05:13 GMT</pubDate>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333511</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-12-02T17:05:13Z</dc:date>
    </item>
    <item>
      <title>Ubiquiti Developer Charged With Extortion, Causing 2020 “Breach”</title>
      <link>https://krebsonsecurity.com/2021/12/ubiquiti-developer-charged-with-extortion-causing-2020-breach/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://krebsonsecurity.com/2021/12/ubiquiti-developer-charged-with-extortion-causing-2020-breach/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">45</slash:comments>
      <description>In January 2021, technology vendor Ubiquiti Inc. [NYSE:UI] disclosed that a breach at a third party cloud provider had exposed customer account credentials. In March, a Ubiquiti employee warned that the company had drastically understated the scope of the incident, and that the third-party cloud provider claim was a fabrication. On Wednesday, a former Ubiquiti developer was arrested and charged with stealing data and trying to extort his employer while pretending to be a whistleblower.</description>
      <content:encoded>&lt;p&gt;In January 2021, technology vendor &lt;strong&gt;&lt;a href="https://www.ui.com/" target="_blank" rel="noopener"&gt;Ubiquiti Inc.&lt;/a&gt;&lt;/strong&gt; [NYSE:UI] disclosed that a breach at a third party cloud provider had exposed customer account credentials. In March, a Ubiquiti employee &lt;a href="https://krebsonsecurity.com/2021/03/whistleblower-ubiquiti-breach-catastrophic/" target="_blank" rel="noopener"&gt;warned&lt;/a&gt; that the company had drastically understated the scope of the incident, and that the third-party cloud provider claim was a fabrication. On Wednesday, a former Ubiquiti developer was arrested and charged with stealing data and trying to extort his employer while pretending to be a whistleblower.&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" class="aligncenter size-full wp-image-55018" src="https://krebsonsecurity.com/wp-content/uploads/2021/03/ubiquiti.png" alt="" width="519" height="145" /&gt;&lt;/p&gt;
&lt;p&gt;Federal prosecutors say &lt;strong&gt;Nickolas Sharp&lt;/strong&gt;, a senior developer at Ubiquiti, actually caused the &amp;#8220;breach&amp;#8221; that forced Ubiquiti to disclose a cybersecurity incident in January. They allege that in late December 2020, Sharp applied for a job at another technology company, and then abused his privileged access to Ubiquiti&amp;#8217;s systems at Amazon&amp;#8217;s AWS cloud service and the company&amp;#8217;s GitHub accounts to download large amounts of proprietary data.&lt;/p&gt;
&lt;p&gt;Sharp&amp;#8217;s indictment doesn&amp;#8217;t specify how much data he allegedly downloaded, but it says some of the downloads took hours, and that he cloned approximately 155 Ubiquiti data repositories via multiple downloads over nearly two weeks.&lt;/p&gt;
&lt;p&gt;On Dec. 28, other Ubiquiti employees spotted the unusual downloads, which had leveraged internal company credentials and a &lt;strong&gt;Surfshark VPN&lt;/strong&gt; connection to hide the downloader&amp;#8217;s true Internet address. Assuming an external attacker had breached its security, Ubiquiti quickly launched an investigation.&lt;/p&gt;
&lt;p&gt;But Sharp was a member of the team doing the forensic investigation, the indictment alleges.&lt;/p&gt;
&lt;p&gt;&amp;#8220;At the time the defendant was part of a team working to assess the scope and damage caused by the incident and remediate its effects, all while concealing his role in committing the incident,&amp;#8221; wrote prosecutors with the Southern District of New York.&lt;/p&gt;
&lt;p&gt;According to the indictment, on January 7 a senior Ubiquiti employee received a ransom email. The message was sent through an IP address associated with the same Surfshark VPN. The ransom message warned that internal Ubiquiti data had been stolen, and that the information would not be used or published online as long as Ubiquiti agreed to pay 25 Bitcoin.&lt;/p&gt;
&lt;p&gt;The ransom email also offered to identify a purportedly still unblocked &amp;#8220;backdoor&amp;#8221; used by the attacker for the sum of another 25 Bitcoin (the total amount requested was equivalent to approximately $1.9 million at the time). Ubiquiti did not pay the ransom demands.&lt;/p&gt;
&lt;p&gt;Investigators say they were able to tie the downloads to Sharp and his work-issued laptop because his Internet connection briefly failed on several occasions while he was downloading the Ubiquiti data. Those outages were enough to prevent Sharp&amp;#8217;s Surfshark VPN connection from functioning properly &amp;#8212; thus exposing his Internet address as the source of the downloads. &lt;span id="more-57755"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;When FBI agents raided Sharp&amp;#8217;s residence on Mar. 24, he reportedly maintained his innocence and told agents someone else must have used his Paypal account to purchase the Surfshark VPN subscription.&lt;/p&gt;
&lt;p&gt;Several days after the FBI executed its search warrant, Sharp &amp;#8220;caused false or misleading news stories to be published about the incident,&amp;#8221; prosecutors say. Among the claims made in those news stories was that Ubiquiti had neglected to keep access logs that would allow the company to understand the full scope of the intrusion. In reality, the indictment alleges, Sharp had shortened to one day the amount of time Ubiquiti&amp;#8217;s systems kept certain logs of user activity in AWS.&lt;/p&gt;
&lt;p&gt;&amp;#8220;Following the publication of these articles, between Tuesday, March 30, 2021 and Wednesday March 31, [Ubiquiti&amp;#8217;s] stock price fell approximately 20 percent, losing over four billion dollars in market capitalization,&amp;#8221; the indictment states.&lt;/p&gt;
&lt;p&gt;Sharp faces four criminal counts, including wire fraud, intentionally damaging protected computers, transmission of interstate communications with intent to extort, and making false statements to the FBI.&lt;/p&gt;
&lt;p&gt;News of Sharp&amp;#8217;s arrest was first reported by &lt;a href="https://www.bleepingcomputer.com/news/security/former-ubiquiti-dev-charged-for-trying-to-extort-his-employer/" target="_blank" rel="noopener"&gt;BleepingComputer&lt;/a&gt;, which wrote that while the Justice Department didn&amp;#8217;t name Sharp&amp;#8217;s employer in its press release or indictment, all of the details align with previous reporting on the Ubiquiti incident and information presented in &lt;a href="https://www.linkedin.com/in/nickolassharp" target="_blank" rel="noopener noreferrer" data-ss1638417087="1"&gt;Sharp&amp;#8217;s LinkedIn account&lt;/a&gt;. A link to the indictment is &lt;a href="https://www.justice.gov/usao-sdny/press-release/file/1452706/download" target="_blank" rel="noopener"&gt;here&lt;/a&gt; (PDF).&lt;/p&gt;</content:encoded>
      <category>A Little Sunshine</category>
      <category>Nickolas Sharp</category>
      <category>Surfshark</category>
      <category>Ubiquiti</category>
      <pubDate>Thu, 02 Dec 2021 16:11:07 GMT</pubDate>
      <comments>https://krebsonsecurity.com/2021/12/ubiquiti-developer-charged-with-extortion-causing-2020-breach/#comments</comments>
      <guid isPermaLink="false">https://krebsonsecurity.com/?p=57755</guid>
      <dc:creator>BrianKrebs</dc:creator>
      <dc:date>2021-12-02T16:11:07Z</dc:date>
    </item>
    <item>
      <title>What one thing should you do to secure your Kubernetes environment?</title>
      <link>https://www.computing.co.uk/sponsored/4041421/secure-kubernetes-environment</link>
      <description>&lt;img alt="What one thing should you do to secure your Kubernetes environment?" src="https://www.computing.co.uk/api/v1/wps/e4c4a55/319f1db9-e6e3-449a-8014-cff0016a6f67/5/iStock-Data-protection-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Lack of resources is a massive blocker, so you'll need to prioritise &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Thu, 02 Dec 2021 11:11:10 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/sponsored/4041421/secure-kubernetes-environment</guid>
      <dc:date>2021-12-02T11:11:10Z</dc:date>
    </item>
    <item>
      <title>FBI seized Bitcoins worth $2.3 million from REvil affiliate</title>
      <link>https://www.computing.co.uk/news/4041425/fbi-seized-bitcoins-worth-usd-million-revil-affiliate</link>
      <description>&lt;img alt="FBI seized Bitcoins worth $2.3 million from REvil affiliate" src="https://www.computing.co.uk/api/v1/wps/d898b46/54d60668-833f-4004-b1ca-ddfd8561fb42/8/FBI-185x114.jpeg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; The cash comes from ransomware payouts to mitigate REvil attacks &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Thu, 02 Dec 2021 07:11:39 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4041425/fbi-seized-bitcoins-worth-usd-million-revil-affiliate</guid>
      <dc:date>2021-12-02T07:11:39Z</dc:date>
    </item>
    <item>
      <title>Smashing Security podcast #254: A dead hamster, a brass pen, and The Beatles</title>
      <link>https://grahamcluley.com/smashing-security-podcast-254/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://grahamcluley.com/smashing-security-podcast-254/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <description>Cryptocurrency traders suffer a hamster-related loss, beware of charity scammers this holiday season, and do you have the patience to sit through Peter Jackson's eight-hour Beatles documentary?

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.</description>
      <enclosure url="https://aphid.fireside.fm/d/1437767933/dd3252a8-95c3-41f8-a8a0-9d5d2f9e0bc6/2c54e0f9-7adb-4d60-bd1e-d439b68e6e9c.mp3" type="audio/mpeg" />
      <category>Podcast</category>
      <category>charity</category>
      <category>cryptocurrency</category>
      <category>Scam</category>
      <category>Smashing Security</category>
      <pubDate>Thu, 02 Dec 2021 00:37:03 GMT</pubDate>
      <comments>https://grahamcluley.com/smashing-security-podcast-254/#respond</comments>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333503</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-12-02T00:37:03Z</dc:date>
    </item>
    <item>
      <title>Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security</title>
      <link>https://feeds.feedblitz.com/~/674078076/_/thesecurityledger~Spotlight-How-Secrets-Sprawl-Undermines-Software-Supply-Chain-Security/</link>
      <feedburner:origLink xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">https://securityledger.com/2021/12/spotlight-how-secrets-sprawl-undermines-software-supply-chain-security/</feedburner:origLink>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://feeds.feedblitz.com/~/674078076/_/thesecurityledger~Spotlight-How-Secrets-Sprawl-Undermines-Software-Supply-Chain-Security/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">2</slash:comments>
      <itunes:subtitle xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">Mackenzie Jackson, the Developer Advocate at GitGuardian joins Paul to discuss how “secrets sprawl” on sites like GitHub threatens software supply chains.</itunes:subtitle>
      <itunes:summary xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><![CDATA[<br />
In this&#160;<a rel="NOFOLLOW" href="#sponsor">Spotlight</a>&#160;edition of the podcast, we’re joined by <a rel="NOFOLLOW" href="https://www.linkedin.com/in/advocatemack/">Mackenzie Jackson</a>, the Developer Advocate at the firm <a rel="NOFOLLOW" href="https://www.gitguardian.com">GitGuardian</a>. Mackenzie and I discuss the problem of so-called “secrets sprawl” &#8211; the migration of all manner of sensitive information, from credentials to private keys -into public source code repositories on sites like GitHub. <br />
<br />
<br />
<br />
As always, &#160;you can check our full conversation in&#160;<a rel="NOFOLLOW" href="https://www.blubrry.com/the_security_ledger_podcasts/">our latest Security Ledger podcast at Blubrry</a>. You&#160;<a rel="NOFOLLOW" rel="noreferrer noopener" href="https://itunes.apple.com/us/podcast/the-security-ledger-podcast/id680045866?mt=2" target="_blank">can also listen to it on iTunes</a>&#160;and&#160;<a rel="NOFOLLOW" rel="noreferrer noopener" href="https://open.spotify.com/show/5YZ0iBx5uwjbqRWeR7bHcQ?si=41x7hihbSAuQ21YbII-CDQ&#38;dl_branch=1" target="_blank">Spotify</a>. Or, check us out on&#160;<a rel="NOFOLLOW" rel="noreferrer noopener" href="https://podcasts.google.com/feed/aHR0cHM6Ly9mZWVkcy5mZWVkYmxpdHouY29tL3RoZXNlY3VyaXR5bGVkZ2Vy" target="_blank">Google Podcasts</a>,&#160;<a rel="NOFOLLOW" href="https://www.stitcher.com/podcast/the-security-ledger-4/the-security-ledger-podcast">Stitcher</a>,&#160;<a rel="NOFOLLOW" href="https://radiopublic.com/the-security-ledger-WDR2Z9">Radio Public</a>&#160;and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to&#160;<a rel="NOFOLLOW" href="http://securityledger.com/subscribe">securityledger.com/subscribe</a>&#160;to get notified whenever a new podcast is posted.&#160;<br />
<br />
<br />
<br />
[<a rel="NOFOLLOW" href="https://feeds.feedblitz.com/-/674078074/_/thesecurityledger.mp3">MP3</a>]<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
“Given enough eyeballs, all bugs are shallow.” That is “<a rel="NOFOLLOW" rel="noreferrer noopener" href="https://en.wikipedia.org/wiki/Linus%27s_law" target="_blank">Linus’s Law</a>.” First formulated by Eric Raymond in his 1999 book “<a rel="NOFOLLOW" href="https://www.amazon.com/Cathedral-Bazaar-Musings-Accidental-Revolutionary/dp/0596001088">The Cathedral and the Bazaar,</a>” and named after Linus Torvalds, the creator of Linux. It speaks to a hidden value of open source code: with an unbounded population of developers given access to source code, security and quality issues will quickly bubble up and be discovered, improving security rather than undermining it.&#160;<br />
<br />
<br />
<br />
Mackenzie&#160;Jackson is a Developer Advocate at GitGuardian<br />
<br />
<br />
<br />
All Secrets Are Shallow, Too!<br />
<br />
<br />
<br />
Two decades later, open source culture is now firmly entrenched, open source code and libraries are part and parcel of nearly every software development project, and massive, online repositories like GitHub put code at the fingertips of a population of millions of developers and billions of Internet users. <br />
<br />
<br />
<br />
In that new milieu, something like a corollary to Linus’s Law has emerged: given enough eyeballs, all secrets are shallow, too.&#160;<br />
<br />
<br />
<br />
In other words: having thousands of developers crawling over your source code may expose hidden flaws in your application code. (Though there is <a rel="NOFOLLOW" href="https://www.synopsys.com/blogs/software-security/heartbleed-vulnerability/">ample reason</a> to <a rel="NOFOLLOW" href="https://securityledger.com/2020/11/exploitable-flaw-in-npm-private-ip-app-lurks-everywhere-anywhere/">doubt</a> that <a rel="NOFOLLOW" href="https://securityledger.com/2021/03/critical-flaws-found-in-widely-used-netmask-open-source-library/">happens</a>.) But it may also reveal secrets you weren’t aware were buried in your code, or that you hoped nobody would notice.&#160;<br />
<br />
<br />
<br />
Credentials: Gone in 60 Seconds<br />
<br />]]></itunes:summary>
      <itunes:author xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">Paul F. Roberts</itunes:author>
      <itunes:duration xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">32:55</itunes:duration>
      <rawvoice:embed xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/">&lt;iframe src="https://player.blubrry.com/?media_url=https%3A%2F%2Fmedia.blubrry.com%2Fthe_security_ledger_podcasts%2Fcontent.blubrry.com%2Fthe_security_ledger_podcasts%2FSpotlight_GitGuardians_Mackenzie_Jackson_on_GitHub_Secrets_Sprawl_.mp3&amp;amp;podcast_link=https%3A%2F%2Fsecurityledger.com%2F2021%2F12%2Fspotlight-how-secrets-sprawl-undermines-software-supply-chain-security%2F#darkOrLight-light&amp;shownotes-ffffff&amp;shownotesBackground-444444&amp;download-ffffff&amp;downloadBackground-003366&amp;subscribe-ffffff&amp;subscribeBackground-fb8c00&amp;share-ffffff&amp;shareBackground-1976d2" scrolling="no" width="100%" height="138px" frameborder="0" id="blubrryplayer-3" class="blubrryplayer" title="Blubrry Podcast Player"&gt;&lt;/iframe&gt;</rawvoice:embed>
      <post-id xmlns="com-wordpress:feed-additions:1">476688</post-id>
      <feedburner:origEnclosureLink xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">https://media.blubrry.com/the_security_ledger_podcasts/content.blubrry.com/the_security_ledger_podcasts/Spotlight_GitGuardians_Mackenzie_Jackson_on_GitHub_Secrets_Sprawl_.mp3</feedburner:origEnclosureLink>
      <description>&lt;p&gt;Mackenzie Jackson, the Developer Advocate at GitGuardian joins Paul to discuss how “secrets sprawl” on sites like GitHub threatens software supply chains.&lt;/p&gt;
&lt;p&gt;The post &lt;a rel="NOFOLLOW" href="https://feeds.feedblitz.com/~/674078076/_/thesecurityledger~Spotlight-How-Secrets-Sprawl-Undermines-Software-Supply-Chain-Security/"&gt;Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security&lt;/a&gt; appeared first on &lt;a rel="NOFOLLOW" href="https://securityledger.com"&gt;The Security Ledger with Paul F. Roberts&lt;/a&gt;.&lt;/p&gt;
&lt;!-- --&gt;&lt;/p&gt;&lt;div class="fbz_enclosure" style="clear:left"&gt;&lt;audio controls="controls" style="display:block;padding:0.5em 0;max-width:100%;"&gt;&lt;source src="https://feeds.feedblitz.com/-/674078074/_/thesecurityledger.mp3"&gt;Click the icon below to listen.&lt;/audio&gt;&lt;a href="https://feeds.feedblitz.com/-/674078074/_/thesecurityledger.mp3" title="Play audio"&gt;&lt;img border="0" width="40" height="40" src="https://assets.feedblitz.com/i/podplay.png"/&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/12/episode-232-log4j-wont-go-away-and-what-to-do-about-it/"&gt;Episode 232: Log4j Won&amp;#x2019;t Go Away (And What To Do About It.)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/episode-227-whats-fueling-cyber-attacks-on-agriculture/"&gt;Episode 227: What&amp;#x2019;s Fueling Cyber Attacks on Agriculture ?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/spotlight-your-iot-risk-is-bigger-than-you-think-and-what-to-do-about-it/"&gt;Spotlight: Your IoT Risk Is Bigger Than You Think. (And What To Do About It.)&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
      <content:encoded>&lt;p&gt;Mackenzie Jackson, the Developer Advocate at GitGuardian joins Paul to discuss how “secrets sprawl” on sites like GitHub threatens software supply chains.&lt;/p&gt;
&lt;p&gt;The post &lt;a rel="nofollow" href="https://feeds.feedblitz.com/~/t/0/_/thesecurityledger/~https://securityledger.com/2021/12/spotlight-how-secrets-sprawl-undermines-software-supply-chain-security/"&gt;Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security&lt;/a&gt; appeared first on &lt;a rel="nofollow" href="https://feeds.feedblitz.com/~/t/0/_/thesecurityledger/~https://securityledger.com"&gt;The Security Ledger with Paul F. Roberts&lt;/a&gt;.&lt;Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.feedblitz.com/~/i/674078076/_/thesecurityledger"&gt;
&lt;/p&gt;&lt;div class="fbz_enclosure" style="clear:left"&gt;&lt;audio controls="controls" style="display:block;padding:0.5em 0;max-width:100%;"&gt;&lt;source src="https://feeds.feedblitz.com/-/674078074/_/thesecurityledger.mp3"&gt;Click the icon below to listen.&lt;/audio&gt;&lt;a href="https://feeds.feedblitz.com/-/674078074/_/thesecurityledger.mp3" title="Play audio"&gt;&lt;img border="0" width="40" height="40" src="https://assets.feedblitz.com/i/podplay.png"/&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/12/episode-232-log4j-wont-go-away-and-what-to-do-about-it/"&gt;Episode 232: Log4j Won&amp;#x2019;t Go Away (And What To Do About It.)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/episode-227-whats-fueling-cyber-attacks-on-agriculture/"&gt;Episode 227: What&amp;#x2019;s Fueling Cyber Attacks on Agriculture ?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/spotlight-your-iot-risk-is-bigger-than-you-think-and-what-to-do-about-it/"&gt;Spotlight: Your IoT Risk Is Bigger Than You Think. (And What To Do About It.)&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded>
      <enclosure url="https://feeds.feedblitz.com/-/674078074/_/thesecurityledger.mp3" length="47409177" type="audio/mpeg" />
      <category>API</category>
      <category>application development</category>
      <category>application security</category>
      <category>Business</category>
      <category>Companies</category>
      <category>GitGuardian</category>
      <category>GitHub</category>
      <category>open source</category>
      <category>Podcasts</category>
      <category>Software</category>
      <category>Spotlight</category>
      <category>supply chain</category>
      <category>cybersecurity</category>
      <category>software supply chain</category>
      <pubDate>Wed, 01 Dec 2021 20:40:36 GMT</pubDate>
      <comments>https://feeds.feedblitz.com/~/674078076/_/thesecurityledger~Spotlight-How-Secrets-Sprawl-Undermines-Software-Supply-Chain-Security/#comments</comments>
      <guid isPermaLink="false">https://securityledger.com/?p=476688</guid>
      <dc:creator>Paul Roberts</dc:creator>
      <dc:date>2021-12-01T20:40:36Z</dc:date>
    </item>
    <item>
      <title>MI6 chief seeks help from tech firms to counter hostile state threats</title>
      <link>https://www.computing.co.uk/news/4041352/mi6-chief-seeks-help-tech-firms-tohostile-threats</link>
      <description>&lt;img alt="MI6 chief seeks help from tech firms to counter hostile state threats" src="https://www.computing.co.uk/api/v1/wps/562dcd1/bd83253c-f631-49d8-bd3e-fc83087e75cb/6/MI6-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Unlike James Bond's Q, the spy agency cannot develop all the technologies it needs in-house &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 01 Dec 2021 10:02:28 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4041352/mi6-chief-seeks-help-tech-firms-tohostile-threats</guid>
      <dc:date>2021-12-01T10:02:28Z</dc:date>
    </item>
    <item>
      <title>Analyzing How TeamTNT Used Compromised Docker Hub Accounts</title>
      <link>https://www.trendmicro.com/en_us/research/21/l/more-tools-in-the-arsenal-how-teamtnt-used-compromised-docker-hu.html</link>
      <description>Following our previous disclosure of compromised Docker hub accounts delivering cryptocurrency miners, we analyze these accounts and discover more malicious actions that you need to be aware of.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/l/more-tools-in-the-arsenal/compromiseddocker-main.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Cloud</category>
      <category>Trend Micro Research : Research</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <category>Trend Micro Research : Cyber Threats</category>
      <pubDate>Wed, 01 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:793e0b07-8f81-8d81-fc6d-8c1059de513c</guid>
      <dc:creator>Nitesh Surana</dc:creator>
      <dc:date>2021-12-01T00:00:00Z</dc:date>
    </item>
    <item>
      <title>What to do at AWS re:Invent 2021 - Day 3</title>
      <link>https://www.trendmicro.com/en_us/research/21/l/aws-reinvent-2021-agenda.html</link>
      <description>Welcome to your complete guide to AWS re:Invent 2021 Day 3, where you will find tips on how to get the most out of your conference experience both in Las Vegas and virtually.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/k/aws-re-invent-2021-guide-checklist-key-sessions/blog-image-option.png" type="image/png" />
      <category>Trend Micro Research : Cloud</category>
      <category>Trend Micro Research : Compliance &amp; Risks</category>
      <category>Trend Micro Research : Expert Perspective</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <category>Trend Micro Research : Cyber Threats</category>
      <pubDate>Wed, 01 Dec 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:cb8f25a2-2de8-c849-a01c-a2c01edc98b5</guid>
      <dc:date>2021-12-01T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Panasonic confirms data breach, says hackers accessed the company's internal network</title>
      <link>https://www.computing.co.uk/news/4041310/panasonic-confirms-breach-hackers-accessed-company-internal-network</link>
      <description>&lt;img alt="Panasonic confirms data breach, says hackers accessed the company&amp;#39;s internal network" src="https://www.computing.co.uk/api/v1/wps/1c2d93c/88719f2f-3a24-4259-ba47-4e3d087783de/6/Panasonic-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; The breach reportedly started on 22 June and ended on 3 November &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 30 Nov 2021 12:41:58 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4041310/panasonic-confirms-breach-hackers-accessed-company-internal-network</guid>
      <dc:date>2021-11-30T12:41:58Z</dc:date>
    </item>
    <item>
      <title>The state of DevSecOps - where are we at with application security?</title>
      <link>https://www.computing.co.uk/feature/4041211/devsecops-application-security</link>
      <description>&lt;img alt="The state of DevSecOps - where are we at with application security? " src="https://www.computing.co.uk/api/v1/wps/ff541b9/55947317-f56a-430f-ba83-b2fe096d1f3d/12/devsecops-iStock-1197640540-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Merging the security function into DevOps won't happen overnight, but it's a vital step and the barriers aren't as high as sometimes believed &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 30 Nov 2021 11:00:25 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/feature/4041211/devsecops-application-security</guid>
      <dc:date>2021-11-30T11:00:25Z</dc:date>
    </item>
    <item>
      <title>Clearview AI faces possible £17m fine for violating Britain's privacy laws</title>
      <link>https://www.computing.co.uk/news/4041292/clearview-ai-gbp17m-fine-violating-britain-privacy-laws</link>
      <description>&lt;img alt="Clearview AI faces possible £17m fine for violating Britain&amp;#39;s privacy laws" src="https://www.computing.co.uk/api/v1/wps/01fcc70/c6258a25-fa4c-4f15-91b5-f5693971d281/7/ClearView-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; The ICO has issued a provisional notice to the company to stop further processing of the personal data of people in the UK  &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 30 Nov 2021 10:01:51 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4041292/clearview-ai-gbp17m-fine-violating-britain-privacy-laws</guid>
      <dc:date>2021-11-30T10:01:51Z</dc:date>
    </item>
    <item>
      <title>What You Can Do to Mitigate Cloud Misconfigurations</title>
      <link>https://www.trendmicro.com/en_us/research/21/k/what-can-you-do-to-mitigate-cloud-misconfigurations.html</link>
      <description>Cloud misconfigurations can become opportunities for cyberattacks or lead to data breaches. Organizations must mitigate them before incurring significant and costly consequences.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/k/what-you-can-do-to-mitigate-cloud-misconfigurations-/what-you-can-do-to-mitigate-cloud-misconfigurations.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Cloud</category>
      <category>Trend Micro Research : Compliance &amp; Risks</category>
      <category>Trend Micro Research : Research</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <category>Trend Micro Research : Cyber Threats</category>
      <pubDate>Tue, 30 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:80417c3e-eb3e-bb53-6906-f31038a55e14</guid>
      <dc:creator>Aaron Ansari</dc:creator>
      <dc:date>2021-11-30T00:00:00Z</dc:date>
    </item>
    <item>
      <title>ESG Economic Value Validation of XDR</title>
      <link>https://www.trendmicro.com/en_us/ciso/21/k/esg-values-xdr-solutions.html</link>
      <description>Hear leading analyst firm ESG and Chase Renes, system administrator at Vision Bank, discuss the operational, business, and financial value of Trend Micro’s industry-leading XDR solution.</description>
      <source url="https://www.trendmicro.com/en_us/ciso.html">CISO Resource Center</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/ciso/21/k/esg-economic-value-validation-of-xdr/esg-economic-value-validation-xdr-thmb.png" type="image/png" />
      <category>Trend Micro CISO : Expert Perspective</category>
      <category>Trend Micro CISO : Skills Gap</category>
      <category>Trend Micro CISO : Risk Management</category>
      <category>Trend Micro CISO : Detection and Response</category>
      <category>Trend Micro CISO : Article</category>
      <category>Trend Micro CISO : Digital Transformation</category>
      <category>Trend Micro CISO : Cloud</category>
      <pubDate>Tue, 30 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:9b3f59de-3ba7-f1ff-d25d-14f45f682a4e</guid>
      <dc:date>2021-11-30T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Top 10 AWS Security Misconfiguration</title>
      <link>https://www.trendmicro.com/en_us/devops/21/k/top-10-aws-security-misconfigurations.html</link>
      <description>Misconfigurations pose the biggest threat to cloud security. We compiled the top 10 AWS services with the highest misconfiguration rates.</description>
      <source url="https://www.trendmicro.com/en_us/devops.html">DevOps Resource Center</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/devops/21/k/top-10-aws-security-misconfigurations/top-10-aws-security-misconfigurations.png" type="image/png" />
      <category>Trend Micro DevOps : Article</category>
      <category>Trend Micro DevOps : Compliance</category>
      <category>Trend Micro DevOps : Conformity</category>
      <category>Trend Micro DevOps : AWS</category>
      <category>Trend Micro DevOps : Expert Perspective</category>
      <pubDate>Tue, 30 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:6598d5f9-9f86-cc8b-2b3b-408870f9c4e7</guid>
      <dc:date>2021-11-30T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Social media firms will be forced to unmask online trolls, says Australia</title>
      <link>https://www.bitdefender.com/blog/hotforsecurity/social-media-firms-forced-unmask-online-trolls-australia/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://www.bitdefender.com/blog/hotforsecurity/social-media-firms-forced-unmask-online-trolls-australia/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <description>The Prime Minister of Australia has said his government will introduce legislation which will compel social media companies to "unmask anonymous online trolls," and allow victims to launch defamation proceedings.

Read more in my article on the Hot for Security blog.</description>
      <category>Guest blog</category>
      <category>Law &amp; order</category>
      <category>Privacy</category>
      <category>Social networks</category>
      <category>australia</category>
      <category>social media</category>
      <category>troll</category>
      <pubDate>Mon, 29 Nov 2021 10:32:14 GMT</pubDate>
      <comments>https://www.bitdefender.com/blog/hotforsecurity/social-media-firms-forced-unmask-online-trolls-australia/#respond</comments>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333486</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-11-29T10:32:14Z</dc:date>
    </item>
    <item>
      <title>IKEA's email system under attack, report</title>
      <link>https://www.computing.co.uk/news/4041155/ikea-email-attack-report</link>
      <description>&lt;img alt="IKEA&amp;#39;s email system under attack, report" src="https://www.computing.co.uk/api/v1/wps/a672b1e/41058798-433d-4e48-a687-7371600e37af/7/ikea-store-front-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Reply-chain attacks allow hackers to send malicious emails from genuine accounts &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Mon, 29 Nov 2021 10:06:39 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4041155/ikea-email-attack-report</guid>
      <dc:date>2021-11-29T10:06:39Z</dc:date>
    </item>
    <item>
      <title>AWS re:Invent 2021 Guide: Checklist &amp; Key Sessions</title>
      <link>https://www.trendmicro.com/en_us/research/21/k/aws-re-Invent-2021-guide-checklist-key-sessions.html</link>
      <description>Welcome to your complete guide to AWS re:Invent 2021, where you will find tips on how to get the most out of your conference experience both in Las Vegas and virtually.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/k/aws-re-invent-2021-guide-checklist-key-sessions/blog-image-option.png" type="image/png" />
      <category>Trend Micro Research : Cloud</category>
      <category>Trend Micro Research : Cyber Crime</category>
      <category>Trend Micro Research : Exploits &amp; Vulnerabilities</category>
      <category>Trend Micro Research : Expert Perspective</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <category>Trend Micro Research : Cyber Threats</category>
      <pubDate>Mon, 29 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:68796fe5-fa76-3362-c60d-79f9664a5d7d</guid>
      <dc:creator>Aaron Ansari</dc:creator>
      <dc:date>2021-11-29T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Trend Micro Cloud One Network Security-as-a-Service</title>
      <link>https://www.trendmicro.com/en_us/research/21/k/trend-micro-cloud-one-network-security-as-a-service.html</link>
      <description>Trend Micro, alongside Amazon Web Services, provides the latest in cloud-native deployment options. We have simplified network security, protecting customers across Virtual Private Clouds (VPCs) without needing agents to be installed on instances.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/a/the-top-worry-in-cloud-security-for-2021/the-worry-in-cloud-security-for-2021.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Cloud</category>
      <category>Trend Micro Research : Latest News</category>
      <category>Trend Micro Research : Privacy &amp; Risks</category>
      <category>Trend Micro Research : Network</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <category>Trend Micro Research : Cyber Threats</category>
      <pubDate>Mon, 29 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:d754335a-a923-7deb-a977-36c64fac80e2</guid>
      <dc:creator>Laura Roantree</dc:creator>
      <dc:date>2021-11-29T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Campaign Abusing Legitimate Remote Administrator Tools Uses Fake Cryptocurrency Websites</title>
      <link>https://www.trendmicro.com/en_us/research/21/k/campaign-abusing-rats-uses-fake-websites.html</link>
      <description>We have been tracking a campaign involving the SpyAgent malware that abuses well-known remote access tools (RATs) for some time now. While previous versions of the malware have been covered by other researchers, our blog entry focuses on the malicious actor’s latest attacks.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/k/campaign-abusing-legitimate-remote-administrator-tools-uses-fake-cryptocurrency-websites/spyagent-main.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Malware</category>
      <category>Trend Micro Research : Research</category>
      <category>Trend Micro Research : Phishing</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <pubDate>Mon, 29 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:1b110ee0-0a06-4b7f-a3ae-004c7dd06cd1</guid>
      <dc:creator>Jaromir Horejsi</dc:creator>
      <dc:date>2021-11-29T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Couple arrested for secretly installing cryptomining software on department store PCs</title>
      <link>https://www.bitdefender.com/blog/hotforsecurity/couple-arrested-for-secretly-installing-cryptomining-software-on-department-store-pcs/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://www.bitdefender.com/blog/hotforsecurity/couple-arrested-for-secretly-installing-cryptomining-software-on-department-store-pcs/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <description>Police in Tarragona, Spain, have arrested a man and a woman after they allegedly infected computers at high-street stores with malware with the intention of mining cryptocurrency on them.

Read more in my article on the Hot for Security blog.</description>
      <category>Guest blog</category>
      <category>Law &amp; order</category>
      <category>Malware</category>
      <category>cryptomining</category>
      <category>Spain</category>
      <pubDate>Fri, 26 Nov 2021 20:41:32 GMT</pubDate>
      <comments>https://www.bitdefender.com/blog/hotforsecurity/couple-arrested-for-secretly-installing-cryptomining-software-on-department-store-pcs/#respond</comments>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333479</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-11-26T20:41:32Z</dc:date>
    </item>
    <item>
      <title>The Internet is Held Together With Spit &amp; Baling Wire</title>
      <link>https://krebsonsecurity.com/2021/11/the-internet-is-held-together-with-spit-baling-wire/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://krebsonsecurity.com/2021/11/the-internet-is-held-together-with-spit-baling-wire/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">36</slash:comments>
      <description>Imagine being able to disconnect or redirect Internet traffic destined for some of the world's largest companies -- just by spoofing an email. This is the nature of a threat vector recently removed by a Fortune 500 firm that operates one of the world's largest Internet backbones.</description>
      <content:encoded>&lt;div id="attachment_57711" style="width: 925px" class="wp-caption aligncenter"&gt;&lt;img aria-describedby="caption-attachment-57711" loading="lazy" class="size-full wp-image-57711" src="https://krebsonsecurity.com/wp-content/uploads/2021/11/blyon-netmap.png" alt="" width="915" height="704" srcset="https://krebsonsecurity.com/wp-content/uploads/2021/11/blyon-netmap.png 915w, https://krebsonsecurity.com/wp-content/uploads/2021/11/blyon-netmap-768x591.png 768w, https://krebsonsecurity.com/wp-content/uploads/2021/11/blyon-netmap-782x602.png 782w" sizes="(max-width: 915px) 100vw, 915px" /&gt;&lt;p id="caption-attachment-57711" class="wp-caption-text"&gt;A visualization of the Internet made using network routing data. Image: Barrett Lyon, opte.org.&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;Imagine being able to disconnect or redirect Internet traffic destined for some of the world&amp;#8217;s biggest companies &amp;#8212; just by spoofing an email. This is the nature of a threat vector recently removed by a Fortune 500 firm that operates one of the largest Internet backbones.&lt;/p&gt;
&lt;p&gt;Based in Monroe, La., &lt;strong&gt;Lumen Technologies Inc.&lt;/strong&gt; [&lt;a href="https://www.google.com/finance/quote/LUMN:NYSE" target="_blank" rel="noopener"&gt;NYSE: LUMN&lt;/a&gt;] (formerly &lt;strong&gt;CenturyLink&lt;/strong&gt;) is one of more than two dozen entities that operate what&amp;#8217;s known as an &lt;a href="http://www.irr.net/docs/list.html" target="_blank" rel="noopener"&gt;Internet Routing Registry&lt;/a&gt; (IRR). These IRRs maintain routing databases used by network operators to register their assigned network resources &amp;#8212; i.e., the Internet addresses that have been allocated to their organization.&lt;/p&gt;
&lt;p&gt;The data maintained by the IRRs help keep track of which organizations have the right to access what Internet address space in the global routing system. Collectively, the information voluntarily submitted to the IRRs forms a distributed database of Internet routing instructions that helps connect a vast array of individual networks.&lt;/p&gt;
&lt;p&gt;There are about 70,000 distinct networks on the Internet today, ranging from huge broadband providers like &lt;strong&gt;AT&amp;#38;T&lt;/strong&gt;, &lt;strong&gt;Comcast&lt;/strong&gt; and &lt;strong&gt;Verizon&lt;/strong&gt; to many thousands of enterprises that connect to the edge of the Internet for access. Each of these so-called &amp;#8220;Autonomous Systems&amp;#8221; (ASes) make their own decisions about how and with whom they will connect to the larger Internet.&lt;/p&gt;
&lt;p&gt;Regardless of how they get online, each AS uses the same language to specify which Internet IP address ranges they control: It&amp;#8217;s called the &lt;strong&gt;Border Gateway Protocol&lt;/strong&gt;, or BGP. Using BGP, an AS tells its directly connected neighbor AS(es) the addresses that it can reach. That neighbor in turn passes the information on to its neighbors, and so on, until the information has propagated everywhere [1].&lt;/p&gt;
&lt;p&gt;A key function of the BGP data maintained by IRRs is preventing rogue network operators from claiming another network&amp;#8217;s addresses and hijacking their traffic. In essence, an organization can use IRRs to declare to the rest of the Internet, &amp;#8220;These specific Internet address ranges are ours, should only originate from our network, and you should ignore any other networks trying to lay claim to these address ranges.&amp;#8221;&lt;/p&gt;
&lt;p&gt;In the early days of the Internet, when organizations wanted to update their records with an IRR, the changes usually involved some amount of human interaction &amp;#8212; often someone manually editing the new coordinates into an Internet backbone router. But over the years the various IRRs made it easier to automate this process via email.&lt;/p&gt;
&lt;p&gt;For a long time, any changes to an organization&amp;#8217;s routing information with an IRR could be processed via email as long as one of the following authentication methods was successfully used:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;strong&gt;-CRYPT-PW:&lt;/strong&gt; A password is added to the text of an email to the IRR containing the record they wish to add, change or delete (the IRR then compares that password to a hash of the password);&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;-PGPKEY:&lt;/strong&gt; The requestor signs the email containing the update with an encryption key the IRR recognizes;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;-MAIL-FROM:&lt;/strong&gt; The requestor sends the record changes in an email to the IRR, and the authentication is based solely on the &amp;#8220;From:&amp;#8221; header of the email.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Of these, MAIL-FROM has long been considered insecure, for the simple reason that it&amp;#8217;s not difficult to spoof the return address of an email. And virtually all IRRs have disallowed its use since at least 2012, said &lt;strong&gt;Adam Korab&lt;/strong&gt;, a network engineer and security researcher based in Houston.&lt;/p&gt;
&lt;p&gt;All except &lt;a href="https://en.wikipedia.org/wiki/Level_3_Communications" target="_blank" rel="noopener"&gt;Level 3 Communications&lt;/a&gt;, a major Internet backbone provider acquired by Lumen/CenturyLink.&lt;/p&gt;
&lt;p&gt;&amp;#8220;LEVEL 3 is the last IRR operator which allows the use of this method, although they have discouraged its use since at least 2012,&amp;#8221; Korab told KrebsOnSecurity. &amp;#8220;Other IRR operators have fully deprecated MAIL-FROM.&amp;#8221;&lt;/p&gt;
&lt;p&gt;Importantly, the name and email address of each Autonomous System&amp;#8217;s official contact for making updates with the IRRs is public information.&lt;/p&gt;
&lt;p&gt;Korab filed a vulnerability report with Lumen demonstrating how a simple spoofed email could be used to disrupt Internet service for banks, telecommunications firms and even government entities.&lt;/p&gt;
&lt;p&gt;&lt;span class="pullquote pqright"&gt;&amp;#8220;If such an attack were successful, it would result in customer IP address blocks being filtered and dropped, making them unreachable from some or all of the global Internet,&amp;#8221; Korab said&lt;/span&gt;, noting that he found more than 2,000 Lumen customers were potentially affected. &amp;#8220;This would effectively cut off Internet access for the impacted IP address blocks.&amp;#8221;&lt;/p&gt;
&lt;p&gt;The recent outage that took &lt;strong&gt;Facebook&lt;/strong&gt;, &lt;strong&gt;Instagram&lt;/strong&gt; and &lt;strong&gt;WhatsApp&lt;/strong&gt; offline for the better part of a day was caused by &lt;a href="https://krebsonsecurity.com/2021/10/what-happened-to-facebook-instagram-whatsapp/" target="_blank" rel="noopener"&gt;an erroneous BGP update submitted by Facebook&lt;/a&gt;. That update took away the map telling the world&amp;#8217;s computers how to find its various online properties.&lt;/p&gt;
&lt;p&gt;Now consider the mayhem that would ensue if someone spoofed IRR updates to remove or alter routing entries for multiple e-commerce providers, banks and telecommunications companies at the same time.&lt;/p&gt;
&lt;p&gt;&amp;#8220;Depending on the scope of an attack, this could impact individual customers, geographic market areas, or potentially the [Lumen] backbone,&amp;#8221; Korab continued. &amp;#8220;This attack is trivial to exploit, and has a difficult recovery. Our conjecture is that any impacted Lumen or customer IP address blocks would be offline for 24-48 hours. In the worst-case scenario, this could extend much longer.&amp;#8221;&lt;/p&gt;
&lt;p&gt;Lumen told KrebsOnSecurity that it continued offering MAIL-FROM: authentication because many of its customers still relied on it due to legacy systems. Nevertheless, after receiving Korab&amp;#8217;s report the company decided the wisest course of action was to disable MAIL-FROM: authentication altogether.&lt;/p&gt;
&lt;p&gt;&amp;#8220;We recently received notice of a known insecure configuration with our Route Registry,&amp;#8221; reads a statement Lumen shared with KrebsOnSecurity. &amp;#8220;We already had mitigating controls in place and to date we have not identified any additional issues. As part of our normal cybersecurity protocol, we carefully considered this notice and took steps to further mitigate any potential risks the vulnerability may have created for our customers or systems.&amp;#8221;&lt;/p&gt;
&lt;div id="attachment_57733" style="width: 773px" class="wp-caption aligncenter"&gt;&lt;img aria-describedby="caption-attachment-57733" loading="lazy" class=" wp-image-57733" src="https://krebsonsecurity.com/wp-content/uploads/2021/11/level3-mailfrom.png" alt="" width="763" height="315" srcset="https://krebsonsecurity.com/wp-content/uploads/2021/11/level3-mailfrom.png 1306w, https://krebsonsecurity.com/wp-content/uploads/2021/11/level3-mailfrom-768x317.png 768w, https://krebsonsecurity.com/wp-content/uploads/2021/11/level3-mailfrom-782x323.png 782w" sizes="(max-width: 763px) 100vw, 763px" /&gt;&lt;p id="caption-attachment-57733" class="wp-caption-text"&gt;Level3, now part of Lumen, has long urged customers to avoid using &amp;#8220;Mail From&amp;#8221; for authentication, but until very recently they still allowed it.&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;&lt;span id="more-57596"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;KC Claffy &lt;/strong&gt;is the founder and director of the &lt;a href="https://www.caida.org" target="_blank" rel="noopener"&gt;Center for Applied Internet Data Analysis&lt;/a&gt; (CAIDA), and a resident research scientist of the San Diego Supercomputer Center at the University of California, San Diego. Claffy said there is scant public evidence of a threat actor using the weakness now fixed by Lumen to hijack Internet routes.&lt;/p&gt;
&lt;p&gt;&amp;#8220;People often don&amp;#8217;t notice, and a malicious actor certainly works to achieve this,&amp;#8221; Claffy said in an email to KrebsOnSecurity. &amp;#8220;But also, if a victim does notice, they generally aren&amp;#8217;t going to release details that they&amp;#8217;ve been hijacked. This is why we need mandatory reporting of such breaches, as &lt;a href="https://en.wikipedia.org/wiki/Dan_Geer" target="_blank" rel="noopener"&gt;Dan Geer&lt;/a&gt; &lt;a href="http://geer.tinho.net/geer.blackhat.6viii14.txt" target="_blank" rel="noopener"&gt;has been saying for years&lt;/a&gt;.&amp;#8221;&lt;/p&gt;
&lt;p&gt;But there are &lt;a href="https://krebsonsecurity.com/2018/07/notorious-hijack-factory-shunned-from-web/" target="_blank" rel="noopener"&gt;plenty of&lt;/a&gt; &lt;a href="https://krebsonsecurity.com/2011/02/spammers-hijack-internet-space-assigned-to-egyptian-presidents-wife/" target="_blank" rel="noopener"&gt;examples&lt;/a&gt; of cybercriminals hijacking IP address blocks after a domain name associated with an email address in an IRR record has expired. In those cases, the thieves simply register the expired domain and then send email from it to an IRR specifying any route changes.&lt;/p&gt;
&lt;p&gt;While it&amp;#8217;s nice that Lumen is no longer the weakest link in the IRR chain, the remaining authentication mechanisms aren&amp;#8217;t great. Claffy said after years of debate over approaches to improving routing security, the operator community deployed an alternative known as the &lt;a href="https://en.wikipedia.org/wiki/Resource_Public_Key_Infrastructure" target="_blank" rel="noopener"&gt;Resource Public Key Infrastructure&lt;/a&gt; (RPKI).&lt;/p&gt;
&lt;p&gt;&amp;#8220;The RPKI includes cryptographic attestation of records, including expiration dates, with each Regional Internet Registry (RIR) operating as a &amp;#8216;root&amp;#8217; of trust,&amp;#8221; wrote Claffy and two other UC San Diego researchers in a paper that is still undergoing peer review. &amp;#8220;Similar to the IRR, operators can use the RPKI to discard routing messages that do not pass origin validation checks.&amp;#8221;&lt;/p&gt;
&lt;p&gt;However, the additional integrity RPKI brings also comes with a fair amount of added complexity and cost, the researchers found.&lt;/p&gt;
&lt;p&gt;&amp;#8220;Operational and &lt;a href="https://scholarship.law.upenn.edu/cgi/viewcontent.cgi?article=3037&amp;#38;context=faculty_scholarship" target="_blank" rel="noopener"&gt;legal implications of potential malfunctions&lt;/a&gt; have limited registration in and use of the RPKI,&amp;#8221; the study observed (link added). &amp;#8220;In response, some networks have redoubled their efforts to improve the accuracy of IRR registration data. These two technologies are now operating in parallel, along with the option of doing nothing at all to validate routes.&amp;#8221;&lt;/p&gt;
&lt;p&gt;[1]: I borrowed some descriptive text in the 5th and 6th paragraphs from a CAIDA/UCSD draft paper &amp;#8212; &lt;a href="https://www.caida.org/catalog/papers/2021_irr_hygiene_rpki_era/irr_hygiene_rpki_era.pdf" target="_blank" rel="noopener"&gt;IRR Hygiene in the RPKI Era&lt;/a&gt; (PDF).&lt;/p&gt;
&lt;p&gt;Further reading:&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.caida.org/catalog/papers/2021_trust_zones_jip/trust_zones_jip.pdf" target="_blank" rel="noopener"&gt;Trust Zones: A Path to a More Secure Internet Infrastructure&lt;/a&gt; (PDF).&lt;/p&gt;
&lt;p&gt;&lt;a href="https://people.csail.mit.edu/ctestart/publications/BGPhist.pdf" target="_blank" rel="noopener"&gt;Reviewing a historical Internet vulnerability: Why isn’t BGP more secure and what can we do about it?&lt;/a&gt; (PDF)&lt;/p&gt;</content:encoded>
      <category>A Little Sunshine</category>
      <category>The Coming Storm</category>
      <category>Adam Korab</category>
      <category>BGP</category>
      <category>Border Gateway Protocol</category>
      <category>CenturyLink</category>
      <category>Internet Routing Registry</category>
      <category>IRR</category>
      <category>kc claffy</category>
      <category>Level3 Communications</category>
      <category>Lumen Technologies</category>
      <pubDate>Fri, 26 Nov 2021 19:03:53 GMT</pubDate>
      <comments>https://krebsonsecurity.com/2021/11/the-internet-is-held-together-with-spit-baling-wire/#comments</comments>
      <guid isPermaLink="false">https://krebsonsecurity.com/?p=57596</guid>
      <dc:creator>BrianKrebs</dc:creator>
      <dc:date>2021-11-26T19:03:53Z</dc:date>
    </item>
    <item>
      <title>Reduce Friction Between IT Leaders and C-suite</title>
      <link>https://www.trendmicro.com/en_us/ciso/21/k/reduce-friction-between-it-leaders-and-c-suite.html</link>
      <description>As we creep toward a post-pandemic world, organizations need to plan accordingly. Explore Trend Micro’s latest cyber risk research to enable your business to maximize its growth and potential.</description>
      <source url="https://www.trendmicro.com/en_us/ciso.html">CISO Resource Center</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/ciso/21/k/reduce-friction-between-it-leaders-and-c-suite/CISO-reduce-friction.jpg" type="image/jpeg" />
      <category>Trend Micro CISO : Article</category>
      <category>Trend Micro CISO : Digital Transformation</category>
      <category>Trend Micro CISO : Expert Perspective</category>
      <category>Trend Micro CISO : Skills Gap</category>
      <category>Trend Micro CISO : Risk Management</category>
      <pubDate>Fri, 26 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:328e24aa-9ce8-5ae9-426e-54951b078bb3</guid>
      <dc:date>2021-11-26T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Try out 1Password 8 for Windows, where security meets productivity</title>
      <link>https://grahamcluley.com/feed-sponsor-1password-13/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://grahamcluley.com/feed-sponsor-1password-13/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <description>Graham Cluley Security News is sponsored this week by the folks at 1Password. Thanks to the great team there for their support! 1Password 8 for Windows has been reimagined with productivity improvements, enhanced security and privacy features, and a new, modern design. 1Password 8 helps you manage, access, and protect your sensitive information more easily &amp;#8230; &lt;a href="https://grahamcluley.com/feed-sponsor-1password-13/" class="more-link"&gt;Continue reading&lt;span class="screen-reader-text"&gt; "Try out 1Password 8 for Windows, where security meets productivity"&lt;/span&gt;&lt;/a&gt;</description>
      <category>Feed only</category>
      <pubDate>Thu, 25 Nov 2021 17:49:09 GMT</pubDate>
      <comments>https://grahamcluley.com/feed-sponsor-1password-13/#respond</comments>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333476</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-11-25T17:49:09Z</dc:date>
    </item>
    <item>
      <title>Sophisticated Tardigrade malware launches attacks on vaccine manufacturing infrastructure</title>
      <link>https://www.tripwire.com/state-of-security/security-data-protection/sophisticated-tardigrade-malware-launches-attacks-on-vaccine-manufacturing-infrastructure/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://www.tripwire.com/state-of-security/security-data-protection/sophisticated-tardigrade-malware-launches-attacks-on-vaccine-manufacturing-infrastructure/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <description>Security researchers are warning biomanufacturing facilities around the world that they are being targeted by a sophisticated new strain of malware, known as Tardigrade.

Read more in my article on the Tripwire State of Security blog.</description>
      <category>Data loss</category>
      <category>Guest blog</category>
      <category>Malware</category>
      <category>Ransomware</category>
      <category>Coronavirus</category>
      <category>data breach</category>
      <category>ransomware</category>
      <pubDate>Thu, 25 Nov 2021 16:54:04 GMT</pubDate>
      <comments>https://www.tripwire.com/state-of-security/security-data-protection/sophisticated-tardigrade-malware-launches-attacks-on-vaccine-manufacturing-infrastructure/#respond</comments>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333472</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-11-25T16:54:04Z</dc:date>
    </item>
    <item>
      <title>Smashing Security podcast #253: Cybercrime unicorns, HVAC hacks, and NFT piracy – with Mikko Hyppönen</title>
      <link>https://grahamcluley.com/smashing-security-podcast-253/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://grahamcluley.com/smashing-security-podcast-253/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <description>Heating systems are left vulnerable to attack in the high courts, cybercrime unicorns have become a reality (but what are they?), over 15 Terabytes of NFTs are made available for anyone to download ... and Carole reveals her Pick of the Year.

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mikko Hyppönen.</description>
      <enclosure url="https://aphid.fireside.fm/d/1437767933/dd3252a8-95c3-41f8-a8a0-9d5d2f9e0bc6/25022dad-b7b6-4d23-9147-f5facf6a9980.mp3" type="audio/mpeg" />
      <category>Law &amp; order</category>
      <category>Podcast</category>
      <category>Privacy</category>
      <category>Security threats</category>
      <category>Vulnerability</category>
      <category>HVAC</category>
      <category>NFT</category>
      <category>Royal Courts of Justice</category>
      <category>Smashing Security</category>
      <category>unicorn</category>
      <category>vulnerability</category>
      <category>Wi-fi</category>
      <pubDate>Thu, 25 Nov 2021 13:26:24 GMT</pubDate>
      <comments>https://grahamcluley.com/smashing-security-podcast-253/#respond</comments>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333465</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-11-25T13:26:24Z</dc:date>
    </item>
    <item>
      <title>New UK IoT law means huge fines and a ban on default passwords</title>
      <link>https://www.bitdefender.com/blog/hotforsecurity/new-uk-iot-law-means-huge-fines-and-a-ban-on-default-passwords/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://www.bitdefender.com/blog/hotforsecurity/new-uk-iot-law-means-huge-fines-and-a-ban-on-default-passwords/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <description>The United Kingdom government has introduced new legislation designed to improve the security of "smart" internet-connected devices used in people's homes.

Read more in my article on the Hot for Security blog.</description>
      <category>Guest blog</category>
      <category>Vulnerability</category>
      <category>IoT</category>
      <category>vulnerability</category>
      <pubDate>Thu, 25 Nov 2021 13:22:58 GMT</pubDate>
      <comments>https://www.bitdefender.com/blog/hotforsecurity/new-uk-iot-law-means-huge-fines-and-a-ban-on-default-passwords/#respond</comments>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333461</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-11-25T13:22:58Z</dc:date>
    </item>
    <item>
      <title>Exchange Server admins advised to patch vulnerable machines after POC exploit released for high-severity bug</title>
      <link>https://www.computing.co.uk/news/4040963/exchange-server-admins-advised-patch-vulnerable-machines-poc-exploit-released-severity-bug</link>
      <description>&lt;img alt="Exchange Server admins advised to patch vulnerable machines after POC exploit released for high-severity bug" src="https://www.computing.co.uk/api/v1/wps/351e098/4278b9b9-2934-408d-a297-0bb1c65858a8/4/exploit-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Microsoft has described the flaw as having a high impact on data integrity, confidentiality and availability &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 24 Nov 2021 12:37:32 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4040963/exchange-server-admins-advised-patch-vulnerable-machines-poc-exploit-released-severity-bug</guid>
      <dc:date>2021-11-24T12:37:32Z</dc:date>
    </item>
    <item>
      <title>Apple sues NSO Group for targeting its users with spyware</title>
      <link>https://www.computing.co.uk/news/4040937/apple-sues-nso-group-targeting-users-spyware</link>
      <description>&lt;img alt="Apple sues NSO Group for targeting its users with spyware" src="https://www.computing.co.uk/api/v1/wps/d723772/e9127959-5b7b-475d-a1b0-f4bacb787af3/8/Apple-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Seeks to bar the Israeli firm from using its products  &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 24 Nov 2021 10:06:46 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4040937/apple-sues-nso-group-targeting-users-spyware</guid>
      <dc:date>2021-11-24T10:06:46Z</dc:date>
    </item>
    <item>
      <title>NCSC alerts 4,000 online retailers about Magecart attacks</title>
      <link>https://www.computing.co.uk/news/4040934/ncsc-alerts-online-retailers-about-magecart-attacks</link>
      <description>&lt;img alt="NCSC alerts 4,000 online retailers about Magecart attacks" src="https://www.computing.co.uk/api/v1/wps/2976d37/799b0ecd-1582-494e-857c-76cb24e8028b/6/hack-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Hackers will attempt to target online shoppers on Black Friday and Cyber Monday, it warns &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 24 Nov 2021 07:41:59 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4040934/ncsc-alerts-online-retailers-about-magecart-attacks</guid>
      <dc:date>2021-11-24T07:41:59Z</dc:date>
    </item>
    <item>
      <title>GoDaddy data breach affects nearly 1.2 million WordPress users</title>
      <link>https://www.computing.co.uk/news/4040866/godaddy-breach-affects-nearly-million-wordpress-users</link>
      <description>&lt;img alt="GoDaddy data breach affects nearly 1.2 million WordPress users" src="https://www.computing.co.uk/api/v1/wps/99e9a4b/931fc8b6-db38-45a1-9599-7e13898432f2/6/GoDaddy-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; The attacker used a compromised password to access the company's provisioning system for Managed WordPress &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 23 Nov 2021 09:59:19 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4040866/godaddy-breach-affects-nearly-million-wordpress-users</guid>
      <dc:date>2021-11-23T09:59:19Z</dc:date>
    </item>
    <item>
      <title>GoDaddy hack exposes accounts of 1.2 million customers</title>
      <link>https://www.bitdefender.com/blog/hotforsecurity/godaddy-hack-exposes-accounts-of-1-2-million-customers/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://www.bitdefender.com/blog/hotforsecurity/godaddy-hack-exposes-accounts-of-1-2-million-customers/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments>
      <description>Web-hosting firm and domain registrar GoDaddy has revealed that it has suffered cyber attack which saw a hacker gain access to details of over one million customers.

Read more in my article on the Hot for Security blog.</description>
      <category>Data loss</category>
      <category>Guest blog</category>
      <category>Phishing</category>
      <category>data breach</category>
      <category>GoDaddy</category>
      <category>phishing</category>
      <category>Wordpress</category>
      <pubDate>Tue, 23 Nov 2021 08:29:16 GMT</pubDate>
      <comments>https://www.bitdefender.com/blog/hotforsecurity/godaddy-hack-exposes-accounts-of-1-2-million-customers/#respond</comments>
      <guid isPermaLink="false">https://grahamcluley.com/?p=9333457</guid>
      <dc:creator>Graham Cluley</dc:creator>
      <dc:date>2021-11-23T08:29:16Z</dc:date>
    </item>
    <item>
      <title>A Complete Guide to Cloud-Native Application Security</title>
      <link>https://www.trendmicro.com/en_us/devops/21/k/a-complete-guide-to-cloud-native-application-security.html</link>
      <description>Explore this comprehensive guide to application security, which provides an overview of the importance of embedding runtime application security controls in the application build workflow to protect cloud-native web applications and APIs.</description>
      <source url="https://www.trendmicro.com/en_us/devops.html">DevOps Resource Center</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/devops/21/k/complete-guide-to-application-security/complete-guide-to-application-security.jpg" type="image/jpeg" />
      <category>Trend Micro DevOps : Cloud Native</category>
      <category>Trend Micro DevOps : Serverless Security</category>
      <category>Trend Micro DevOps : Article</category>
      <category>Trend Micro DevOps : Best Practices</category>
      <category>Trend Micro DevOps : Multi Cloud</category>
      <pubDate>Tue, 23 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:568253c3-e0ad-af57-ca7f-29f044f4ecaa</guid>
      <dc:creator>Melanie Tafelski</dc:creator>
      <dc:date>2021-11-23T00:00:00Z</dc:date>
    </item>
    <item>
      <title>BazarLoader Adds Compromised Installers, ISO to Arrival and Delivery Vectors</title>
      <link>https://www.trendmicro.com/en_us/research/21/k/bazarloader-adds-compromised-installers-iso-to-arrival-delivery-vectors.html</link>
      <description>We observed BazarLoader adding two new arrival mechanisms to their current roster of malware delivery techniques.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/k/bazarloader-adds-compromised-installers-iso-to-arrival-delivery-vectors/cover-bazarloader-adds-compromised-installers-iso-arrival-and-delivery-vectors.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Malware</category>
      <category>Trend Micro Research : Cyber Crime</category>
      <category>Trend Micro Research : Cyber Threats</category>
      <category>Trend Micro Research : Endpoints</category>
      <category>Trend Micro Research : Ransomware</category>
      <category>Trend Micro Research : Spam</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <pubDate>Tue, 23 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:b3de07b3-b8a7-ab0e-2f70-29d49ee98dd0</guid>
      <dc:creator>Ian Kenefick</dc:creator>
      <dc:date>2021-11-23T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Defend Against Cyber Espionage Attacks</title>
      <link>https://www.trendmicro.com/en_us/ciso/21/k/defend-against-cybermercenary-attacks.html</link>
      <description>Explore Trend Micro’s latest research into Void Balaur, a prolific cybermercenary group, to learn how to defend against attacks launched by this growing group of threat actors.</description>
      <source url="https://www.trendmicro.com/en_us/ciso.html">CISO Resource Center</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/ciso/21/k/defend-against-cybermercenary-attacks/cybermecenary.png" type="image/png" />
      <category>Trend Micro CISO : Article</category>
      <category>Trend Micro CISO : Expert Perspective</category>
      <category>Trend Micro CISO : Risk Management</category>
      <pubDate>Tue, 23 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:4e69b1c2-5711-5644-3c84-34094d4fd93c</guid>
      <dc:date>2021-11-23T00:00:00Z</dc:date>
    </item>
    <item>
      <title>COP26 Backs Electric Vehicles to Reduce Climate Change</title>
      <link>https://www.trendmicro.com/en_us/research/21/k/cop26-rallies-behind-evs-to-mitigate-climate-change.html</link>
      <description>The 26 United Nations Climate Change Conference pushes for countries of parties to adopt more widespread EV use in order to reduce the looming threats of climate change.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/k/cop26-rallies-behind-evs-to-mitigate-climate-change/climate-change.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Latest News</category>
      <category>Trend Micro Research : Compliance &amp; Risks</category>
      <category>Trend Micro Research : IoT</category>
      <category>Trend Micro Research : Exploits &amp; Vulnerabilities</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <category>Trend Micro Research : Connected Car</category>
      <pubDate>Tue, 23 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:01a86480-2c34-5910-df5a-bf0fe41e7ac3</guid>
      <dc:date>2021-11-23T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Arrest in ‘Ransom Your Employer’ Email Scheme</title>
      <link>https://krebsonsecurity.com/2021/11/arrest-in-ransom-your-employer-email-scheme/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://krebsonsecurity.com/2021/11/arrest-in-ransom-your-employer-email-scheme/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">36</slash:comments>
      <description>In August, KrebsOnSecurity warned that scammers were contacting people and asking them to unleash ransomware inside their employer's network, in exchange for a percentage of any ransom amount paid by the victim company. This week, authorities in Nigeria arrested a suspect in connection with the scheme -- a young man who said he was trying to save up money to help fund a new social network.</description>
      <content:encoded>&lt;p&gt;In August, KrebsOnSecurity &lt;a href="https://krebsonsecurity.com/2021/08/wanted-disgruntled-employees-to-deploy-ransomware/" target="_blank" rel="noopener"&gt;warned&lt;/a&gt; that scammers were contacting people and asking them to unleash ransomware inside their employer&amp;#8217;s network, in exchange for a percentage of any ransom amount paid by the victim company. This week, authorities in Nigeria arrested a suspect in connection with the scheme &amp;#8212; a young man who said he was trying to save up money to help fund a new social network.&lt;/p&gt;
&lt;div id="attachment_56671" style="width: 766px" class="wp-caption aligncenter"&gt;&lt;img aria-describedby="caption-attachment-56671" loading="lazy" class=" wp-image-56671" src="https://krebsonsecurity.com/wp-content/uploads/2021/08/madalin.png" alt="" width="756" height="302" /&gt;&lt;p id="caption-attachment-56671" class="wp-caption-text"&gt;Image: Abnormal Security.&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;The brazen approach targeting disgruntled employees was first spotted by threat intelligence firm &lt;strong&gt;Abnormal Security&lt;/strong&gt;, which &lt;a href="https://abnormalsecurity.com/blog/nigerian-ransomware-soliciting-employees-demonware/" target="_blank" rel="noopener"&gt;described&lt;/a&gt; what happened after they adopted a fake persona and responded to the proposal in the screenshot above.&lt;/p&gt;
&lt;p&gt;&amp;#8220;According to this actor, he had originally intended to send his targets—all senior-level executives—phishing emails to compromise their accounts, but after that was unsuccessful, he pivoted to this ransomware pretext,&amp;#8221; Abnormal&amp;#8217;s &lt;strong&gt;Crane Hassold&lt;/strong&gt; wrote.&lt;/p&gt;
&lt;p&gt;Abnormal Security documented how it tied the email back to a Nigerian man who acknowledged he was trying to save up money to help fund a new social network he is building called &lt;strong&gt;Sociogram&lt;/strong&gt;. In June 2021, the Nigerian government officially &lt;a href="https://www.washingtonpost.com/world/2021/06/04/nigeria-suspends-twitter-buhari/" target="_blank" rel="noopener"&gt;placed an indefinite ban on Twitter&lt;/a&gt;, restricting it from operating in Nigeria after the social media platform deleted tweets by the Nigerian president.&lt;/p&gt;
&lt;p&gt;Reached via LinkedIn, Sociogram founder &lt;a href="https://www.linkedin.com/in/oluwameda/" target="_blank" rel="noopener"&gt;Oluwaseun Medayedupin&lt;/a&gt; asked to have his startup’s name removed from the story, although he did not respond to questions about whether there were any inaccuracies in Hassold’s report.&lt;/p&gt;
&lt;p&gt;“Please don’t harm Sociogram’s reputation,” Medayedupin pleaded. “I beg you as a promising young man.”&lt;/p&gt;
&lt;p&gt;After he deleted his LinkedIn profile, I received the following message through the &amp;#8220;contact this domain holder&amp;#8221; link at KrebsOnSecurity&amp;#8217;s domain registrar [curiously, the date of that missive reads &amp;#8220;Dec. 31, 1969.&amp;#8221;]. Apparently, Mr. Krebson is a clout-chasing monger.&lt;/p&gt;
&lt;div id="attachment_57663" style="width: 766px" class="wp-caption aligncenter"&gt;&lt;img aria-describedby="caption-attachment-57663" loading="lazy" class=" wp-image-57663" src="https://krebsonsecurity.com/wp-content/uploads/2021/11/sociogramgram.png" alt="" width="756" height="484" srcset="https://krebsonsecurity.com/wp-content/uploads/2021/11/sociogramgram.png 782w, https://krebsonsecurity.com/wp-content/uploads/2021/11/sociogramgram-768x492.png 768w" sizes="(max-width: 756px) 100vw, 756px" /&gt;&lt;p id="caption-attachment-57663" class="wp-caption-text"&gt;A love letter from the founder of the ill-fated Sociogram.&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;Mr. Krebson also heard from an investigator representing the Nigeria Finance CERT on behalf of the Central Bank Of Nigeria. While the Sociogram founder&amp;#8217;s approach might seem amateurish to some, the financial community in Nigeria did not consider it a laughing matter.&lt;/p&gt;
&lt;p&gt;On Friday, Nigerian police arrested Medayedupin. The investigator says formal charges will be levied against the defendant sometime this week.&lt;/p&gt;

&lt;a href='https://krebsonsecurity.com/nigfincert/'&gt;&lt;img width="64" height="96" src="https://krebsonsecurity.com/wp-content/uploads/2021/11/nigfincert.png" class="attachment-thumbnail size-thumbnail" alt="" loading="lazy" /&gt;&lt;/a&gt;
&lt;a href='https://krebsonsecurity.com/2021/11/arrest-in-ransom-your-employer-email-scheme/medayepupin/'&gt;&lt;img width="79" height="96" src="https://krebsonsecurity.com/wp-content/uploads/2021/11/medayepupin.png" class="attachment-thumbnail size-thumbnail" alt="" loading="lazy" /&gt;&lt;/a&gt;
&lt;a href='https://krebsonsecurity.com/2021/11/arrest-in-ransom-your-employer-email-scheme/mdell/'&gt;&lt;img width="121" height="96" src="https://krebsonsecurity.com/wp-content/uploads/2021/11/mdell.png" class="attachment-thumbnail size-thumbnail" alt="" loading="lazy" srcset="https://krebsonsecurity.com/wp-content/uploads/2021/11/mdell.png 896w, https://krebsonsecurity.com/wp-content/uploads/2021/11/mdell-768x607.png 768w, https://krebsonsecurity.com/wp-content/uploads/2021/11/mdell-782x618.png 782w" sizes="(max-width: 121px) 100vw, 121px" /&gt;&lt;/a&gt;

&lt;p&gt;KrebsOnSecurity spoke with a fraud investigator who is performing the forensic analysis of the devices seized from Medayedupin&amp;#8217;s home. The investigator spoke on condition of anonymity out of concern for his physical safety.&lt;/p&gt;
&lt;p&gt;The investigator &amp;#8212; we&amp;#8217;ll call him &amp;#8220;George&amp;#8221; &amp;#8212; said the 23-year-old Medayedupin lives with his extended family in an extremely impoverished home, and that the young man told investigators he&amp;#8217;d just graduated from college but turned to cybercrime at first with ambitions of merely scamming the scammers.&lt;/p&gt;
&lt;p&gt;George&amp;#8217;s team confirmed that Medayedupin had around USD $2,000 to his name, which he&amp;#8217;d recently stolen from a group of Nigerian fraudsters who were scamming people for gift cards. Apparently, he admitted to creating a phishing website that tricked a member of this group into providing access to the money they&amp;#8217;d made from their scams.&lt;/p&gt;
&lt;p&gt;Medayedupin reportedly told investigators that for almost a week after he started emailing his ransom-your-employer scheme, nobody took him up on the offer. But after his name appeared in the news media, &lt;em&gt;he received thousands of inquiries from people interested in his idea&lt;/em&gt;.&lt;span id="more-57657"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;George described Medayedupin as smart, a quick learner, and fairly dedicated to his work.&lt;/p&gt;
&lt;p&gt;&amp;#8220;He seems like he could be a fantastic [employee] for a company,&amp;#8221; George said. &amp;#8220;But there is no employment here, so he chose to do this.&amp;#8221;&lt;/p&gt;
&lt;p&gt;What&amp;#8217;s interesting about this case &amp;#8212; and indeed likely why anyone thought this guy worthy of arrest &amp;#8212; is that the Nigerian authorities were fairly swift to take action when a domestic cybercriminal raised the specter of causing financial losses for its own banks.&lt;/p&gt;
&lt;p&gt;After all, the majority of the cybercrime that originates from Africa &amp;#8212; think romance scams, &lt;a href="https://krebsonsecurity.com/2015/08/fbi-1-2b-lost-to-business-email-scams/" target="_blank" rel="noopener"&gt;Business Email Compromise (BEC) fraud&lt;/a&gt;, and &lt;a href="https://krebsonsecurity.com/tag/unemployment-insurance-fraud/" target="_blank" rel="noopener"&gt;unemployment/pandemic loan fraud&lt;/a&gt; &amp;#8212; does not target Nigerian citizens, nor does it harm African banks. On the contrary: This activity pumps a great deal of Western money into Nigeria.&lt;/p&gt;
&lt;p&gt;How much money are we talking about? The financial losses from these scams dwarf other fraud categories &amp;#8212; such as identity theft or credit card fraud. According to the FBI&amp;#8217;s Internet Crime Complaint Center (&lt;a href="https://www.ic3.gov" target="_blank" rel="noopener"&gt;IC3&lt;/a&gt;), consumers and businesses &lt;a href="https://www.ic3.gov/Media/PDF/AnnualReport/2020_IC3Report.pdf" target="_blank" rel="noopener"&gt;reported&lt;/a&gt; more than $4.2 billion in losses tied to cybercrime in 2020, and BEC fraud and romance scams alone accounted for nearly 60 percent of those losses.&lt;/p&gt;
&lt;div id="attachment_57679" style="width: 687px" class="wp-caption aligncenter"&gt;&lt;img aria-describedby="caption-attachment-57679" loading="lazy" class="size-full wp-image-57679" src="https://krebsonsecurity.com/wp-content/uploads/2021/11/fbi-ic3-losses2020.png" alt="" width="677" height="446" /&gt;&lt;p id="caption-attachment-57679" class="wp-caption-text"&gt;Source: FBI/IC3 2020 Internet Crime Report.&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;If the influx of a few billion US dollars into the Nigerian economy each year from cybercrime seems somehow insignificant, consider that (according to George) the average police officer in the country makes the equivalent of less than USD $100 a month.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Ronnie Tokazowski &lt;/strong&gt;is a threat researcher at the security firm &lt;a href="http://www.cofense.com"&gt;Cofense&lt;/a&gt;. Tokazowski maintains he has been one of the more vocal proponents of the idea that trying to fight these problems by arresting those involved is something of a Sisyphean task, and that it makes way more sense to focus on changing the economic realities in places like Nigeria.&lt;/p&gt;
&lt;p&gt;Nigeria has the world’s second-highest unemployment rate — rising from 27.1 percent in 2019 to 33 percent in 2020, according to the &lt;strong&gt;National Bureau of Statistics&lt;/strong&gt;. The nation also is among the world’s most corrupt, according to 2020 findings from&lt;strong&gt; Transparency International&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&amp;#8220;Education is definitely one piece, as raising awareness is hands down the best way to get ahead of this,” Tokazowski said, in &lt;a href="https://krebsonsecurity.com/2021/06/we-infiltrated-a-counterfeit-check-ring-now-what/" target="_blank" rel="noopener"&gt;a June 2021 interview&lt;/a&gt;. &amp;#8220;But we also need to think about ways to create more business opportunities there so that people who are doing this to put food on the table have more legitimate opportunities. Unfortunately, thanks to the level of corruption of government officials, there are a lot of cultural reasons that fighting this type of crime at the source is going to be difficult.&amp;#8221;&lt;/p&gt;</content:encoded>
      <category>Ne'er-Do-Well News</category>
      <category>Ransomware</category>
      <category>Abnormal Security</category>
      <category>Cofense</category>
      <category>Crane Hassold</category>
      <category>CyberLab</category>
      <category>Oluwaseun Medayedupin</category>
      <category>ransomware</category>
      <category>Ronnie Tokazowski</category>
      <category>Sociogram</category>
      <pubDate>Mon, 22 Nov 2021 21:57:18 GMT</pubDate>
      <comments>https://krebsonsecurity.com/2021/11/arrest-in-ransom-your-employer-email-scheme/#comments</comments>
      <guid isPermaLink="false">https://krebsonsecurity.com/?p=57657</guid>
      <dc:creator>BrianKrebs</dc:creator>
      <dc:date>2021-11-22T21:57:18Z</dc:date>
    </item>
    <item>
      <title>Meta delays plans to encrypt messages on Facebook and Instagram until 2023</title>
      <link>https://www.computing.co.uk/news/4040806/meta-delays-plans-encrypt-messages-facebook-instagram-2023</link>
      <description>&lt;img alt="Meta delays plans to encrypt messages on Facebook and Instagram until 2023" src="https://www.computing.co.uk/api/v1/wps/d50557d/db73234c-7f2a-41e1-aa6f-594182389d2c/10/facebook-185x114.png" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Meanwhile WhatsApp has published a new privacy policy for users in Ireland and across Europe &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Mon, 22 Nov 2021 12:59:23 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4040806/meta-delays-plans-encrypt-messages-facebook-instagram-2023</guid>
      <dc:date>2021-11-22T12:59:23Z</dc:date>
    </item>
    <item>
      <title>The ‘Zelle Fraud’ Scam: How it Works, How to Fight Back</title>
      <link>https://krebsonsecurity.com/2021/11/the-zelle-fraud-scam-how-it-works-how-to-fight-back/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://krebsonsecurity.com/2021/11/the-zelle-fraud-scam-how-it-works-how-to-fight-back/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">76</slash:comments>
      <description>One of the more common ways cybercriminals cash out access to bank accounts involves draining the victim's funds via Zelle, a "peer-to-peer" (P2P) payment service used by many financial institutions that allows customers to quickly send cash to friends and family. Naturally, a great deal of phishing schemes that precede these bank account takeovers begin with a spoofed text message from the target's bank warning about a suspicious Zelle transfer. What follows is a deep dive into how this increasingly clever Zelle fraud scam typically works, and what victims can do about it.</description>
      <content:encoded>&lt;p&gt;One of the more common ways cybercriminals cash out access to bank accounts involves draining the victim&amp;#8217;s funds via&lt;strong&gt; Zelle&lt;/strong&gt;, a &amp;#8220;peer-to-peer&amp;#8221; (P2P) payment service used by many financial institutions that allows customers to quickly send cash to friends and family. Naturally, a great deal of phishing schemes that precede these bank account takeovers begin with a spoofed text message from the target&amp;#8217;s bank warning about a suspicious Zelle transfer. What follows is a deep dive into how this increasingly clever Zelle fraud scam typically works, and what victims can do about it.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://krebsonsecurity.com/2021/11/sms-about-bank-fraud-as-a-pretext-for-voice-phishing/" target="_blank" rel="noopener"&gt;Last week&amp;#8217;s story&lt;/a&gt; warned that scammers are blasting out text messages about suspicious bank transfers as a pretext for immediately calling and scamming anyone who responds via text. Here&amp;#8217;s what one of those scam messages looks like:&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" class="aligncenter wp-image-57519" src="https://krebsonsecurity.com/wp-content/uploads/2021/11/zelletext.png" alt="" width="761" height="414" srcset="https://krebsonsecurity.com/wp-content/uploads/2021/11/zelletext.png 1244w, https://krebsonsecurity.com/wp-content/uploads/2021/11/zelletext-768x418.png 768w, https://krebsonsecurity.com/wp-content/uploads/2021/11/zelletext-782x426.png 782w, https://krebsonsecurity.com/wp-content/uploads/2021/11/zelletext-370x200.png 370w" sizes="(max-width: 761px) 100vw, 761px" /&gt;&lt;/p&gt;
&lt;p&gt;Anyone who responds &amp;#8220;yes,&amp;#8221; &amp;#8220;no&amp;#8221; or at all will very soon after receive a phone call from a scammer pretending to be from the financial institution&amp;#8217;s fraud department. The caller&amp;#8217;s number will be spoofed so that it appears to be coming from the victim&amp;#8217;s bank.&lt;/p&gt;
&lt;p&gt;To &amp;#8220;verify the identity&amp;#8221; of the customer, the fraudster asks for their online banking username, and then tells the customer to read back a passcode sent via text or email. In reality, the fraudster initiates a transaction &amp;#8212; such as the &amp;#8220;forgot password&amp;#8221; feature on the financial institution&amp;#8217;s site &amp;#8212; which is what generates the authentication passcode delivered to the member.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Ken Otsuka &lt;/strong&gt;is a senior risk consultant at &lt;strong&gt;CUNA Mutual Group&lt;/strong&gt;, an insurance company that provides financial services to credit unions. Otsuka said a phone fraudster typically will say something like, &amp;#8220;Before I get into the details, I need to verify that I&amp;#8217;m speaking to the right person. What&amp;#8217;s your username?&amp;#8221;&lt;/p&gt;
&lt;p&gt;&amp;#8220;In the background, they&amp;#8217;re using the username with the forgot password feature, and that&amp;#8217;s going to generate one of these two-factor authentication passcodes,&amp;#8221; Otsuka said. &amp;#8220;Then the fraudster will say, &amp;#8216;I&amp;#8217;m going to send you the password and you&amp;#8217;re going to read it back to me over the phone.'&amp;#8221;&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" class="alignright size-full wp-image-16248" src="https://krebsonsecurity.com/wp-content/uploads/2012/08/phonefraud.jpg" alt="" width="283" height="424" srcset="https://krebsonsecurity.com/wp-content/uploads/2012/08/phonefraud.jpg 283w, https://krebsonsecurity.com/wp-content/uploads/2012/08/phonefraud-266x400.jpg 266w" sizes="(max-width: 283px) 100vw, 283px" /&gt;The fraudster then uses the code to complete the password reset process, and then changes the victim&amp;#8217;s online banking password. The fraudster then uses Zelle to transfer the victim&amp;#8217;s funds to others.&lt;/p&gt;
&lt;p&gt;An important aspect of this scam is that &lt;em&gt;the fraudsters never even need to know or phish the victim&amp;#8217;s password&lt;/em&gt;. By sharing their username and reading back the one-time code sent to them via email, the victim is allowing the fraudster to reset their online banking password.&lt;/p&gt;
&lt;p&gt;Otsuka said in far too many account takeover cases, the victim has never even heard of Zelle, nor did they realize they could move money that way.&lt;/p&gt;
&lt;p&gt;&amp;#8220;The thing is, many credit unions offer it by default as part of online banking,&amp;#8221; Otsuka said. &amp;#8220;Members don&amp;#8217;t have to request to use Zelle. It&amp;#8217;s just there, and with a lot of members targeted in these scams, although they&amp;#8217;d legitimately enrolled in online banking, they&amp;#8217;d never used Zelle before.&amp;#8221; [Curious if your financial institution uses Zelle? Check out their partner list &lt;a href="https://www.zellepay.com/get-started" target="_blank" rel="noopener"&gt;here&lt;/a&gt;].&lt;/p&gt;
&lt;p&gt;Otsuka said credit unions offering other peer-to-peer banking products have also been targeted, but that fraudsters prefer to target Zelle due to the speed of the payments.&lt;/p&gt;
&lt;p&gt;&amp;#8220;The fraud losses can escalate quickly due to the sheer number of members that can be targeted on a single day over the course of consecutive days,&amp;#8221; Otsuka said.&lt;/p&gt;
&lt;p&gt;To combat this scam Zelle introduced out-of-band authentication with transaction details. This involves sending the member a text containing the details of a Zelle transfer &amp;#8211; payee and dollar amount – that is initiated by the member. The member must authorize the transfer by replying to the text.&lt;/p&gt;
&lt;p&gt;Unfortunately, Otsuka said, the scammers are defeating this layered security control as well.&lt;span id="more-57594"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;#8220;The fraudsters follow the same tactics except they may keep the members on the phone after getting their username and 2-step authentication passcode to login to the accounts,&amp;#8221; he said. &amp;#8220;The fraudster tells the member they will receive a text containing details of a Zelle transfer and the member must authorize the transaction under the guise that it is for reversing the fraudulent debit card transaction(s).&amp;#8221;&lt;/p&gt;
&lt;p&gt;In this scenario, the fraudster actually enters a Zelle transfer that triggers the following text to the member, which the member is asked to authorize: For example:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&amp;#8220;Send $200 Zelle payment to Boris Badenov? Reply YES to send, NO to cancel. ABC Credit Union . STOP to end all messages.&amp;#8221;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;&amp;#8220;My team has consulted with several credit unions that rolled Zelle out or are planning to introduce Zelle,&amp;#8221; Otsuka said. &amp;#8220;We found that several credit unions were hit with the scam the same month they rolled it out.&amp;#8221;&lt;/p&gt;
&lt;p&gt;The upshot of all this is that many financial institutions will claim they&amp;#8217;re not required to reimburse the customer for financial losses related to these voice phishing schemes. &lt;strong&gt;Bob Sullivan&lt;/strong&gt;, a veteran journalist who writes about fraud and consumer issues, says in many cases banks are giving customers incorrect and self-serving opinions after the thefts.&lt;/p&gt;
&lt;p&gt;&amp;#8220;Consumers &amp;#8212; many who never ever realized they had a Zelle account &amp;#8211; then call their banks, expecting they&amp;#8217;ll be covered by credit-card-like protections, only to face disappointment and in some cases, financial ruin,&amp;#8221; Sullivan &lt;a href="https://bobsullivan.net/cybercrime/zelle-hackers-improve-their-scam-banks-wont-help-but-victim-have-new-place-to-complain/" target="_blank" rel="noopener"&gt;wrote&lt;/a&gt; in a recent Substack post. &amp;#8220;Consumers who suffer unauthorized transactions are entitled to Regulation E protection, and banks are required to refund the stolen money. This isn’t a controversial opinion, and it was &lt;a href="https://www.consumerfinance.gov/compliance/compliance-resources/deposit-accounts-resources/electronic-fund-transfers/electronic-fund-transfers-faqs/" target="_blank" rel="noopener"&gt;recently affirmed by the CFPB here&lt;/a&gt;. If you are reading this story and fighting with your bank, start by providing that link to the financial institution.&amp;#8221;&lt;/p&gt;
&lt;p&gt;&amp;#8220;If a criminal initiates a Zelle transfer — even if the criminal manipulates a victim into sharing login credentials — that fraud is covered by Regulation E, and banks should restore the stolen funds,&amp;#8221; Sullivan said. &amp;#8220;If a consumer initiates the transfer under false pretenses, the case for redress is more weak.&amp;#8221;&lt;/p&gt;
&lt;p&gt;Sullivan notes that the &lt;strong&gt;Consumer Financial Protection Bureau&lt;/strong&gt; (CFPB) recently announced it was &lt;a href="https://www.consumerfinance.gov/about-us/newsroom/cfpb-orders-tech-giants-to-turn-over-information-on-their-payment-system-plans/" target="_blank" rel="noopener"&gt;conducting a probe&lt;/a&gt; into companies operating payments systems in the United States, with a special focus on platforms that offer fast, person-to-person payments.&lt;/p&gt;
&lt;p&gt;&amp;#8220;Consumers expect certain assurances when dealing with companies that move their money,&amp;#8221; the CFPB said in its Oct. 21 notice. &amp;#8220;They expect to be protected from fraud and payments made in error, for their data and privacy to be protected and not shared without their consent, to have responsive customer service, and to be treated equally under relevant law. The orders seek to understand the robustness with which payment platforms prioritize consumer protection under law.&amp;#8221;&lt;/p&gt;
&lt;p&gt;Anyone interested in letting the CFPB know about a fraud scam that abused a P2P payment platform like Zelle, Cashapp, or Venmo, for example, should send an email describing the incident to BigTechPaymentsInquiry@cfpb.gov. Be sure to include Docket No. CFPB-2021-0017 in the subject line of the message.&lt;/p&gt;
&lt;p&gt;In the meantime, remember the mantra: &lt;a href="https://krebsonsecurity.com/2020/04/when-in-doubt-hang-up-look-up-call-back/" target="_blank" rel="noopener"&gt;Hang up, Look Up, and Call Back&lt;/a&gt;. If you receive a call from someone warning about fraud, hang up. If you believe the call might be legitimate, look up the number of the organization supposedly calling you, and call them back.&lt;/p&gt;</content:encoded>
      <category>A Little Sunshine</category>
      <category>Latest Warnings</category>
      <category>Web Fraud 2.0</category>
      <category>Bob Sullivan</category>
      <category>Consumer Financial Protection Bureau</category>
      <category>CUNA Mutual Insurance</category>
      <category>Ken Otsuka</category>
      <category>Zelle scam</category>
      <pubDate>Fri, 19 Nov 2021 21:36:30 GMT</pubDate>
      <comments>https://krebsonsecurity.com/2021/11/the-zelle-fraud-scam-how-it-works-how-to-fight-back/#comments</comments>
      <guid isPermaLink="false">https://krebsonsecurity.com/?p=57594</guid>
      <dc:creator>BrianKrebs</dc:creator>
      <dc:date>2021-11-19T21:36:30Z</dc:date>
    </item>
    <item>
      <title>Squirrelwaffle Exploits ProxyShell and ProxyLogon to Hijack Email Chains</title>
      <link>https://www.trendmicro.com/en_us/research/21/k/Squirrelwaffle-Exploits-ProxyShell-and-ProxyLogon-to-Hijack-Email-Chains.html</link>
      <description>Squirrelwaffle is known for using the tactic of sending malicious spam as replies to existing email chains. We look into how by investigating its exploit of Microsoft Exchange Server vulnerabilities, ProxyLogon and ProxyShell.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/k/squirrelwaffle-exploits-proxyshell-and-proxylogon-vulnerabilities-in-microsoft-exchange-to-hijack-email-chains/squirrelwaffle-exploits-proxyshell-and-proxylogon-microsoft-exchange-vulnerabilities-to-hijack-email-chains.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Exploits &amp; Vulnerabilities</category>
      <category>Trend Micro Research : Research</category>
      <category>Trend Micro Research : Spam</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <category>Trend Micro Research : Cyber Threats</category>
      <pubDate>Fri, 19 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:adf1d65e-1d83-abe8-5ae3-46c97e85e29e</guid>
      <dc:creator>Mohamed Fahmy</dc:creator>
      <dc:date>2021-11-19T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Ransomware as a Service 101</title>
      <link>https://www.trendmicro.com/en_us/ciso/21/k/ransomware-as-a-service-101.html</link>
      <description>To help you enhance your defense against ransomware, Trend Micro Research shares key insights on how ransomware as a service (RaaS) operators work.</description>
      <source url="https://www.trendmicro.com/en_us/ciso.html">CISO Resource Center</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/ciso/21/k/ransomware-as-a-service-101/ransomware-as-a-service-101.jpg" type="image/jpeg" />
      <category>Trend Micro CISO : Article</category>
      <category>Trend Micro CISO : Expert Perspective</category>
      <category>Trend Micro CISO : Risk Management</category>
      <pubDate>Fri, 19 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:d59f7d48-190b-30ad-0baa-c7bdda2adecd</guid>
      <dc:date>2021-11-19T00:00:00Z</dc:date>
    </item>
    <item>
      <title>N-Day Exploit Protection Strategies</title>
      <link>https://www.trendmicro.com/en_us/ciso/21/k/n-day-exploit-protection-strategies.html</link>
      <description>Over two years, Trend Micro Research scoured the underground forums for insight into the N-day exploit market. Discover their findings and how you can secure your organization against exploits.</description>
      <source url="https://www.trendmicro.com/en_us/ciso.html">CISO Resource Center</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/ciso/21/k/strategies-to-protect-against-n-day-exploits/strategies-protect-against-n-day-exploits.jpg" type="image/jpeg" />
      <category>Trend Micro CISO : Article</category>
      <category>Trend Micro CISO : Expert Perspective</category>
      <category>Trend Micro CISO : Risk Management</category>
      <pubDate>Fri, 19 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:66d2df4e-a1bb-4ee4-994e-1d68f90fde3c</guid>
      <dc:date>2021-11-19T00:00:00Z</dc:date>
    </item>
    <item>
      <title>This Week in Security News - November 19, 2021</title>
      <link>https://www.trendmicro.com/en_us/research/21/k/this-week-in-security-news-nov-19-21.html</link>
      <description>This week, learn about how the QAKBOT Loader malware has evolved its techniques and strategies over time. Also, read about the most recent initiative by the legislation to further cybersecurity protection.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/week-in-security-news_lrg.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Cloud</category>
      <category>Trend Micro Research : Expert Perspective</category>
      <category>Trend Micro Research : Web</category>
      <category>Trend Micro Research : Social Media</category>
      <category>Trend Micro Research : Exploits &amp; Vulnerabilities</category>
      <category>Trend Micro Research : Phishing</category>
      <category>Trend Micro Research : Cyber Threats</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <pubDate>Fri, 19 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:8d85097f-a280-09cc-50e7-ca5944e685b5</guid>
      <dc:creator>Jon Clay</dc:creator>
      <dc:date>2021-11-19T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Cybercriminals discuss 'Exploit-as-a-Service' model to lower the barrier for accessing dangerous zero-day exploits</title>
      <link>https://www.computing.co.uk/news/4040655/cybercriminals-discuss-exploit-service-model-lower-barrier-accessing-dangerous-zero-day-exploits</link>
      <description>&lt;img alt="Cybercriminals discuss &amp;#39;Exploit-as-a-Service&amp;#39; model to lower the barrier for accessing dangerous zero-day exploits" src="https://www.computing.co.uk/api/v1/wps/dc1512d/62c47df8-ee20-4284-9111-ff7edb0ff7d6/6/hacker-185x114.jpg" /&gt;
         &lt;p&gt;&lt;!--summary start--&gt; Ransomware gangs have amassed big fortunes to compete with traditional buyers of zero-days, researchers find &lt;!--summary end--&gt;&lt;/p&gt;</description>
      <pubDate>Thu, 18 Nov 2021 12:51:06 GMT</pubDate>
      <guid isPermaLink="false">https://www.computing.co.uk/news/4040655/cybercriminals-discuss-exploit-service-model-lower-barrier-accessing-dangerous-zero-day-exploits</guid>
      <dc:date>2021-11-18T12:51:06Z</dc:date>
    </item>
    <item>
      <title>A Guide to Ransomware: Prevention and Response</title>
      <link>https://www.trendmicro.com/en_us/devops/21/k/ransomware-prevention.html</link>
      <description>This article will provide guidelines aimed at helping readers understand how to detect and prevent ransomware and limit its effect.</description>
      <source url="https://www.trendmicro.com/en_us/devops.html">DevOps Resource Center</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/devops/21/k/ransomware-prevention/guide-ransomware-preparation.jpg" type="image/jpeg" />
      <category>Trend Micro DevOps : Workload Security</category>
      <category>Trend Micro DevOps : Article</category>
      <category>Trend Micro DevOps : Best Practices</category>
      <category>Trend Micro DevOps : Multi Cloud</category>
      <pubDate>Thu, 18 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:e81e939e-3677-dc02-91e2-d844bf209821</guid>
      <dc:creator>Melanie Tafelski</dc:creator>
      <dc:date>2021-11-18T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Tech CEO Pleads to Wire Fraud in IP Address Scheme</title>
      <link>https://krebsonsecurity.com/2021/11/tech-ceo-pleads-to-wire-fraud-in-ip-address-scheme/</link>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://krebsonsecurity.com/2021/11/tech-ceo-pleads-to-wire-fraud-in-ip-address-scheme/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">24</slash:comments>
      <description>The CEO of a South Carolina technology firm has pleaded guilty to 20 counts of wire fraud in connection with an elaborate network of phony companies set up to obtain more than 735,000 Internet Protocol (IP) addresses from the nonprofit organization that leases the digital real estate to entities in North America.</description>
      <content:encoded>&lt;p&gt;The CEO of a South Carolina technology firm has pleaded guilty to 20 counts of wire fraud in connection with an elaborate network of phony companies set up to obtain more than 735,000 Internet Protocol (IP) addresses from the nonprofit organization that leases the digital real estate to entities in North America.&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" class="aligncenter wp-image-47720" src="https://krebsonsecurity.com/wp-content/uploads/2019/05/ips.jpg" alt="" width="764" height="525" /&gt;&lt;/p&gt;
&lt;p&gt;In 2018, the &lt;strong&gt;American Registry for Internet Numbers&lt;/strong&gt; (ARIN), which oversees IP addresses assigned to entities in the U.S., Canada, and parts of the Caribbean, notified Charleston, S.C. based &lt;strong&gt;Micfo LLC&lt;/strong&gt; that it intended to revoke 735,000 addresses.&lt;/p&gt;
&lt;p&gt;ARIN said they wanted the addresses back because the company and its owner &amp;#8212; 38-year-old &lt;strong&gt;Amir Golestan&lt;/strong&gt; &amp;#8212; had obtained them under false pretenses. A global &lt;a href="https://en.wikipedia.org/wiki/IPv4_address_exhaustion" rel="noopener" target="_blank"&gt;shortage of IPv4 addresses&lt;/a&gt; has massively driven up the price of these resources over the years: At the time of this dispute, a single IP address could fetch between $15 and $25 on the open market.&lt;/p&gt;
&lt;p&gt;Micfo responded by suing ARIN to try to stop the IP address seizure. Ultimately, ARIN and Micfo settled the dispute in arbitration, with Micfo returning most of the addresses that it hadn&amp;#8217;t already sold.&lt;/p&gt;
&lt;p&gt;But the legal tussle caught the attention of &lt;strong&gt;South Carolina U.S. Attorney Sherri Lydon&lt;/strong&gt;, who in May 2019 &lt;a href="https://krebsonsecurity.com/2019/05/a-tough-week-for-ip-address-scammers/" target="_blank" rel="noopener"&gt;filed criminal wire fraud charges against Golestan&lt;/a&gt;, alleging he&amp;#8217;d orchestrated a network of shell companies and fake identities to prevent ARIN from knowing the addresses were all going to the same buyer.&lt;/p&gt;
&lt;p&gt;Each of those shell companies involved the production of notarized affidavits in the names of people who didn&amp;#8217;t exist. As a result, Lydon was able to charge Golestan with 20 counts of wire fraud &amp;#8212; one for each payment made by the phony companies that bought the IP addresses from ARIN.&lt;/p&gt;
&lt;div id="attachment_48758" style="width: 760px" class="wp-caption aligncenter"&gt;&lt;img aria-describedby="caption-attachment-48758" loading="lazy" class=" wp-image-48758" src="https://krebsonsecurity.com/wp-content/uploads/2019/08/amirgolestan-image.png" alt="" width="750" height="477" /&gt;&lt;p id="caption-attachment-48758" class="wp-caption-text"&gt;Amir Golestan, CEO of Micfo.&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;On Nov. 16, just two days into his trial, Golestan changed his &amp;#8220;not guilty&amp;#8221; plea, agreeing to plead guilty to all 20 wire fraud charges. KrebsOnSecurity interviewed Golestan about his case at length last year, but he has not responded to requests for comment on his plea change.&lt;/p&gt;
&lt;p&gt;By 2013, a number of Micfo&amp;#8217;s customers had landed on the radar of &lt;strong&gt;Spamhaus&lt;/strong&gt;, a group that many network operators rely upon to help block junk email. But shortly after Spamhaus began blocking Micfo&amp;#8217;s IP address ranges, Micfo shifted gears and began reselling IP addresses mainly to companies marketing &amp;#8220;virtual private networking&amp;#8221; or VPN services that help customers hide their real IP addresses online.&lt;/p&gt;
&lt;p&gt;In a 2020 interview, Golestan told KrebsOnSecurity that Micfo was at one point responsible for brokering roughly 40 percent of the IP addresses used by the world&amp;#8217;s largest VPN providers. Throughout that conversation, Golestan maintained his innocence, even as he explained that the creation of the phony companies was necessary to prevent entities like Spamhaus from interfering with his business going forward.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Stephen Ryan&lt;/strong&gt;, an attorney representing ARIN, said Golestan changed his plea after the court heard from a former Micfo employee and public notary who described being instructed by Golestan to knowingly certify false documents.&lt;/p&gt;
&lt;p&gt;&amp;#8220;Her testimony made him appear bullying and unsavory,&amp;#8221; Ryan said. &amp;#8220;Because it turned out he had also sued her to try to prevent her from disclosing the actions he&amp;#8217;d directed.&amp;#8221;&lt;/p&gt;
&lt;p&gt;Golestan&amp;#8217;s &lt;a href="https://krebsonsecurity.com/wp-content/uploads/2021/11/golestanplea.pdf" target="_blank" rel="noopener"&gt;rather sparse plea agreement&lt;/a&gt; (&lt;a href="https://www.wsj.com/articles/executive-pleads-guilty-in-internet-address-fraud-case-11637101781" rel="noopener" target="_blank"&gt;first reported by The Wall Street Journal&lt;/a&gt;) does not specify any sort of leniency he might gain from prosecutors for agreeing to end the trial prematurely. But it&amp;#8217;s worth noting that a conviction on a single act of wire fraud can result in fines and up to 20 years in prison.&lt;span id="more-57598"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;The courtroom drama comes as ARIN&amp;#8217;s counterpart in Africa is embroiled in a similar, albeit much larger dispute over millions of African IP addresses. In July 2021, the &lt;strong&gt;African Network Information Centre&lt;/strong&gt; (AFRINIC) &lt;a href="https://mybroadband.co.za/news/internet/405640-internet-addresses-worth-r1-8-billion-seized.html" target="_blank" rel="noopener"&gt;took back more than six million IP addresses&lt;/a&gt; from &lt;strong&gt;Cloud Innovation&lt;/strong&gt;, a company incorporated in the African offshore entity haven of Seychelles (pronounced, quite aptly &amp;#8212; &amp;#8220;say shells&amp;#8221;).&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" class="aligncenter wp-image-49907" src="https://krebsonsecurity.com/wp-content/uploads/2019/12/africa.png" alt="" width="764" height="422" /&gt;&lt;/p&gt;
&lt;p&gt;AFRINIC revoked the addresses &amp;#8212; valued at around USD $120 million &amp;#8212; after an internal review found that most of them were being used outside of Africa by various entities in China and Hong Kong. Like ARIN, AFRINIC&amp;#8217;s policies require those who are leasing IP addresses to demonstrate that the addresses are being used by entities within their geographic region.&lt;/p&gt;
&lt;p&gt;But just weeks later, Cloud Innovation convinced a judge in AFRINIC&amp;#8217;s home country of Mauritius &lt;a href="https://mybroadband.co.za/news/internet/407770-afrinic-bank-accounts-frozen-after-r740-million-damages-claim.html" target="_blank" rel="noopener"&gt;to freeze $50 million in AFRINIC bank accounts&lt;/a&gt;, &lt;a href="https://cloudinnovation.org/press-release.html" target="_blank" rel="noopener"&gt;arguing&lt;/a&gt; that AFRINIC had &amp;#8220;acted in bad faith and upon frivolous grounds to tarnish the reputation of Cloud Innovation,&amp;#8221; and that it was obligated to protect its customers from disruption of service.&lt;/p&gt;
&lt;p&gt;That financial freeze has since been partially lifted, but the legal wrangling between AFRINIC and Cloud Innovation continues. The company&amp;#8217;s CEO is also suing the CEO and board chair of AFRINIC in an $80 million defamation case.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Ron Guilmette &lt;/strong&gt;is a security researcher who spent several years tracing how tens of millions of dollars worth of AFRINIC IP addresses were &lt;a href="https://krebsonsecurity.com/2019/12/the-great-50m-african-ip-address-heist/" target="_blank" rel="noopener"&gt;privately sold to address brokers by a former AFRINIC executive&lt;/a&gt;. Guilmette said Golestan&amp;#8217;s guilty plea is a positive sign for AFRINIC, ARIN and the three other &lt;a href="https://www.nro.net/about/rirs/" target="_blank" rel="noopener"&gt;Regional Internet Registries&lt;/a&gt; (RIRs).&lt;/p&gt;
&lt;p&gt;&amp;#8220;It&amp;#8217;s good news for the rule of law,&amp;#8221; Guilmette said. &amp;#8220;It has implications for the AFRINIC case because it reaffirms the authority of all RIRs, including AFRINIC and ARIN.&amp;#8221;&lt;/p&gt;</content:encoded>
      <category>Ne'er-Do-Well News</category>
      <category>African Network Information Centre</category>
      <category>AFRINIC</category>
      <category>American Registry for Internet Numbers</category>
      <category>Amir Golestan</category>
      <category>ARIN</category>
      <category>Micfo LLC</category>
      <category>Ron Guilmette</category>
      <category>Sherri Lydon</category>
      <category>spamhaus</category>
      <category>Stephen Ryan</category>
      <pubDate>Wed, 17 Nov 2021 23:56:07 GMT</pubDate>
      <comments>https://krebsonsecurity.com/2021/11/tech-ceo-pleads-to-wire-fraud-in-ip-address-scheme/#comments</comments>
      <guid isPermaLink="false">https://krebsonsecurity.com/?p=57598</guid>
      <dc:creator>BrianKrebs</dc:creator>
      <dc:date>2021-11-17T23:56:07Z</dc:date>
    </item>
    <item>
      <title>Analyzing ProxyShell-related Incidents via Trend Micro Managed XDR</title>
      <link>https://www.trendmicro.com/en_us/research/21/k/analyzing-proxyshell-related-incidents-via-trend-micro-managed-x.html</link>
      <description>In this blog entry, we will take a look at the ProxyShell vulnerabilities that were being exploited in these events, and dive deeper into the notable post-exploitation routines that were used in four separate incidents involving these web shell attacks.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/k/analyzing-proxyshell-related-incidents-via-trend-micro-managed-xdr/proxyshell-xdr-641.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Cyber Threats</category>
      <category>Trend Micro Research : Research</category>
      <category>Trend Micro Research : Exploits &amp; Vulnerabilities</category>
      <pubDate>Wed, 17 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:234a19b6-a76b-eec1-12d0-1c06d6df6cca</guid>
      <dc:creator>Mohamed Fahmy</dc:creator>
      <dc:date>2021-11-17T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Application Security 101</title>
      <link>https://www.trendmicro.com/en_us/devops/21/k/application-security.html</link>
      <description>Everything DevOps teams need to know about web application security risks and best practices.</description>
      <source url="https://www.trendmicro.com/en_us/devops.html">DevOps Resource Center</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/k/application-security-101/thb-application-security-101.jpg" type="image/jpeg" />
      <category>Trend Micro DevOps : Cloud Native</category>
      <category>Trend Micro DevOps : Serverless Security</category>
      <category>Trend Micro DevOps : Research</category>
      <category>Trend Micro DevOps : Infographic</category>
      <category>Trend Micro DevOps : Multi Cloud</category>
      <pubDate>Wed, 17 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:5130a635-ed7d-ba7b-faac-3078841ea239</guid>
      <dc:date>2021-11-17T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Global Operations Lead to Arrests of Alleged Members of GandCrab/REvil and Cl0p Cartels</title>
      <link>https://www.trendmicro.com/en_us/research/21/k/global-operations-lead-to-arrests-of-alleged-members-of-gandcrab.html</link>
      <description>A total of 13 suspects believed to be members of two prolific cybercrime rings were arrested as a global coalition across five continents involving law enforcement and private partners, including Trend Micro, sought to crack down on big ransomware operators.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/k/global-operations-lead-to-arrests-of-alleged-members-of-gandcrab-revil-and-cl0p-cartels/gandcrab-revil-clop-main.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Latest News</category>
      <category>Trend Micro Research : Ransomware</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <category>Trend Micro Research : Cyber Threats</category>
      <pubDate>Tue, 16 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:eac41070-f95a-b17f-0e36-045cd9641fb8</guid>
      <dc:date>2021-11-16T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Post-pandemic growth starts with understanding risk</title>
      <link>https://www.trendmicro.com/en_us/research/21/k/post-pandemic-growth-starts-with-understanding-risk.html</link>
      <description>The digital transformations that accompanied the pandemic are here to stay. To succeed in the post-pandemic era, organizations must come to a shared understanding about cybersecurity as a critical element of business risk.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/k/post-pandemic-growth-starts-with-understanding-risk/psychology-of-risk-blog.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Cloud</category>
      <category>Trend Micro Research : Exploits &amp; Vulnerabilities</category>
      <category>Trend Micro Research : Expert Perspective</category>
      <category>Trend Micro Research : Cyber Threats</category>
      <category>Trend Micro Research : Compliance &amp; Risks</category>
      <category>Trend Micro Research : Network</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <pubDate>Tue, 16 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:aaf96e15-a9a5-54af-d76c-4c76f25cf3ae</guid>
      <dc:creator>Bharat Mistry</dc:creator>
      <dc:date>2021-11-16T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Groups Target Alibaba ECS Instances for Cryptojacking</title>
      <link>https://www.trendmicro.com/en_us/research/21/k/groups-target-alibaba-ecs-instances-for-cryptojacking.html</link>
      <description>We looked at how some malicious groups disable features in Alibaba Cloud ECS instances for illicit mining of Monero.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/k/groups-target-alibaba-ecs-instances-for-cryptojacking/cover-groups-target-alibaba-ecs-cryptojacking-641.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Cloud</category>
      <category>Trend Micro Research : Malware</category>
      <category>Trend Micro Research : Exploits &amp; Vulnerabilities</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <category>Trend Micro Research : Privacy &amp; Risks</category>
      <category>Trend Micro Research : Cyber Threats</category>
      <pubDate>Mon, 15 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:58ecee94-fb14-ebe1-ef07-02c977c99ba0</guid>
      <dc:creator>David Fiser</dc:creator>
      <dc:date>2021-11-15T00:00:00Z</dc:date>
    </item>
    <item>
      <title>QAKBOT Loader Returns With New Techniques and Tools</title>
      <link>https://www.trendmicro.com/en_us/research/21/k/qakbot-loader-returns-with-new-techniques-and-tools.html</link>
      <description>QAKBOT operators resumed email spam operations towards the end of September after an almost three-month hiatus. QAKBOT detection has become a precursor to many critical and widespread ransomware attacks. Our report shares some insight into the new techniques and tools this threat is using.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/k/qakbot-loader-returns-with-new-techniques-and-tools/qakbot%20banner.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Endpoints</category>
      <category>Trend Micro Research : Ransomware</category>
      <category>Trend Micro Research : Research</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <pubDate>Sat, 13 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:0d762be2-d6d8-16f1-e028-fb1415e7479c</guid>
      <dc:creator>Ian Kenefick</dc:creator>
      <dc:date>2021-11-13T00:00:00Z</dc:date>
    </item>
    <item>
      <title>This Week in Security News - November 12, 2021</title>
      <link>https://www.trendmicro.com/en_us/research/21/k/this-week-in-security-news-november-12-2021.html</link>
      <description>This week, learn about the prolific cybermercenaries, Void Balaur, and their recent attacks. Also, read on the 80-country agreement to mobilize safeguards against cyberattacks.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/week-in-security-news_lrg.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Cloud</category>
      <category>Trend Micro Research : Cyber Crime</category>
      <category>Trend Micro Research : Exploits &amp; Vulnerabilities</category>
      <category>Trend Micro Research : Expert Perspective</category>
      <category>Trend Micro Research : Endpoints</category>
      <category>Trend Micro Research : Ransomware</category>
      <category>Trend Micro Research : Network</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <pubDate>Fri, 12 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:d400ef6d-22ed-c94d-8801-ad4b4a78bac2</guid>
      <dc:creator>Jon Clay</dc:creator>
      <dc:date>2021-11-12T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Private 5G Security Risks in Manufacturing Part 4</title>
      <link>https://www.trendmicro.com/en_us/research/21/k/private-5g-security-risks-in-manufacturing-part-4.html</link>
      <description>We can see signs of increased activity in areas of business that use 5G around the world. 5G technology will usher in new personal services through smartphones, and it will also play a large part in industry.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/k/security-risks-with-private-5g-in-manufacturing-companies-part-4/security-risks-5g-manufacturing-part.4.jpg" type="image/jpeg" />
      <category>Trend Micro Research : IoT</category>
      <category>Trend Micro Research : Exploits &amp; Vulnerabilities</category>
      <category>Trend Micro Research : Smart Factories</category>
      <category>Trend Micro Research : Research</category>
      <category>Trend Micro Research : Mobile</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <pubDate>Fri, 12 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:0a4e4616-b28d-caf9-8603-8d1a11b20df0</guid>
      <dc:creator>Yohei Ishihara</dc:creator>
      <dc:date>2021-11-12T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Episode 230: Are Vaccine Passports Cyber Secure?</title>
      <link>https://feeds.feedblitz.com/~/672693428/_/thesecurityledger~Episode-Are-Vaccine-Passports-Cyber-Secure/</link>
      <feedburner:origLink xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">https://securityledger.com/2021/11/episode-230-are-vaccine-passports-cyber-secure/</feedburner:origLink>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://feeds.feedblitz.com/~/672693428/_/thesecurityledger~Episode-Are-Vaccine-Passports-Cyber-Secure/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">1</slash:comments>
      <itunes:subtitle xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">In this episode of the podcast (#230) Siddarth Adukia, a regional Director at NCC Group, joins host Paul Roberts to talk about the (cyber) risks and (public health) rewards of vaccine passport systems: how they work,</itunes:subtitle>
      <itunes:summary xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><![CDATA[<br />
In this episode of the podcast (#230) Siddarth Adukia, a regional Director at NCC Group, joins host Paul Roberts to talk about the (cyber) risks and (public health) rewards of vaccine passport systems: how they work, how they can be compromised and what to do about it. <br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
As the world struggles to emerge from the COVID 19 pandemic, countries face one of two distinct challenges. Many poor and developing nations still struggle to obtain vaccines to inoculate their citizens and halt spread of the virus. However, in industrial nations in North America, Europe and parts of asia where vaccines are readily available, a secondary challenge has emerged: how to manage large and strident populations of unvaccinated residents who harbor doubts about the vaccines themselves, or are hostile to government and private sector vaccine mandates.&#160;<br />
<br />
<br />
<br />
In many of those countries, vaccine passports have emerged as a popular tool to help manage the spread of COVID. In much of Western Europe as well as some U.S. states, residents have had to present proof of vaccination to receive a digital pass &#8211; often in the form of a QR code &#8211; that then grants them access to stores, restaurants and entertainment venues. &#160;<br />
<br />
<br />
<br />
<a rel="NOFOLLOW" href="https://securityledger.com/2020/03/episode-179-ciso-eye-on-the-virus-guy-assessing-covids-cyber-risks/" target="_blank" rel="noreferrer noopener">Episode 179: CISO Eye on the Virus Guy &#8211; Assessing COVID&#8217;s Cyber Risks</a><br />
<br />
<br />
<br />
But &#8211; like any technology &#8211; vaccine passports can, themselves, become a target of those who wish to siphon off sensitive information,&#160; create forged credentials or merely sow chaos and distrust in the passport system.&#160;<br />
<br />
<br />
<br />
That was the case last week after security researchers discovered valid, signed vaccine passports issued in the name of Adolph Hitler and Mickey Mouse were passing checks by state-run vaccine passport scanning apps like Germany’s Green Pass and Italy’s VerificaC19. The forged passports immediately led to speculation that digital keys for signing vaccine passports had been leaked &#8211; potentially undermining the entire European vaccine passport system.&#160;<br />
<br />
<br />
<br />
<a rel="NOFOLLOW" href="https://securityledger.com/2017/08/the-spectrum-of-mobile-risk-protecting-your-corporate-data/" target="_blank" rel="noreferrer noopener">The Spectrum of Mobile Risk: Protecting Your Corporate Data</a><br />
<br />
<br />
<br />
That begs the question of how vaccine passport systems work and what risks exist as countries look to implement vaccine passports to help them curtail the spread of COVID 19 amid populations of vaccinated and unvaccinated citizens.&#160;<br />
<br />
<br />
<br />
To help us understand the vaccine passport landscape a bit better, we invited Siddarth Adukia, Regional Director at NCC Group into the studio. Siddarth recently authored a blog post that <a rel="NOFOLLOW" rel="noreferrer noopener" href="https://research.nccgroup.com/2021/10/04/assessing-the-security-and-privacy-of-vaccine-passports/" target="_blank">explored both the security features and associated threats of vaccine passports</a>. He says that risks abound: from dodgy mobile applications that siphon off sensitive data, to attacks on core passport infrastructure like cryptographic signing keys.&#160;<br />
<br />
<br />
<br />
Check out my full conversation with Siddarth above, or by clicking the download link below. <br />
<br />
<br />
<br />
<br />
<a rel="NOFOLLOW" class="wp-block-button__link has-vivid-red-background-color has-background" href="https://content.blubrry.com/the_security_ledger_podcasts/Episode_230_Siddarth_Adukia_on_Privacy_Security_and_Vaccine_Passports.mp3" target="_blank" rel="noreferrer noopener">Download the MP3</a><br />
<br />]]></itunes:summary>
      <itunes:author xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">Paul F. Roberts</itunes:author>
      <itunes:duration xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">28:13</itunes:duration>
      <rawvoice:embed xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/">&lt;iframe src="https://player.blubrry.com/?media_url=https%3A%2F%2Fmedia.blubrry.com%2Fthe_security_ledger_podcasts%2Fcontent.blubrry.com%2Fthe_security_ledger_podcasts%2FEpisode_230_Siddarth_Adukia_on_Privacy_Security_and_Vaccine_Passports.mp3&amp;amp;podcast_link=https%3A%2F%2Fsecurityledger.com%2F2021%2F11%2Fepisode-230-are-vaccine-passports-cyber-secure%2F#darkOrLight-light&amp;shownotes-ffffff&amp;shownotesBackground-444444&amp;download-ffffff&amp;downloadBackground-003366&amp;subscribe-ffffff&amp;subscribeBackground-fb8c00&amp;share-ffffff&amp;shareBackground-1976d2" scrolling="no" width="100%" height="138px" frameborder="0" id="blubrryplayer-4" class="blubrryplayer" title="Blubrry Podcast Player"&gt;&lt;/iframe&gt;</rawvoice:embed>
      <post-id xmlns="com-wordpress:feed-additions:1">476662</post-id>
      <feedburner:origEnclosureLink xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">https://media.blubrry.com/the_security_ledger_podcasts/content.blubrry.com/the_security_ledger_podcasts/Episode_230_Siddarth_Adukia_on_Privacy_Security_and_Vaccine_Passports.mp3</feedburner:origEnclosureLink>
      <description>&lt;p&gt;In this episode of the podcast (#230) Siddarth Adukia, a regional Director at NCC Group, joins host Paul Roberts to talk about the (cyber) risks and (public health) rewards of vaccine passport systems: how they work, how they can be compromised and what to do about it. &lt;/p&gt;
&lt;p&gt;The post &lt;a rel="NOFOLLOW" href="https://feeds.feedblitz.com/~/672693428/_/thesecurityledger~Episode-Are-Vaccine-Passports-Cyber-Secure/"&gt;Episode 230: Are Vaccine Passports Cyber Secure?&lt;/a&gt; appeared first on &lt;a rel="NOFOLLOW" href="https://securityledger.com"&gt;...&lt;/a&gt;&lt;/p&gt;&lt;p style="clear:left"&gt;&lt;span class="fbz_teasertext"&gt;&lt;a href="https://feeds.feedblitz.com/~/672693428/_/thesecurityledger"&gt;&lt;b&gt;Read the whole entry...&lt;/b&gt;&lt;/a&gt;&amp;#160;&lt;!-- _!fbztxtlnk!_ https://feeds.feedblitz.com/~/672693428/_/thesecurityledger --&gt;&lt;b&gt;&amp;#187;&lt;/b&gt;&lt;/p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="fbz_enclosure" style="clear:left"&gt;&lt;audio controls="controls" style="display:block;padding:0.5em 0;max-width:100%;"&gt;&lt;source src="https://feeds.feedblitz.com/-/672693426/_/thesecurityledger.mp3"&gt;Click the icon below to listen.&lt;/audio&gt;&lt;a href="https://feeds.feedblitz.com/-/672693426/_/thesecurityledger.mp3" title="Play audio"&gt;&lt;img border="0" width="40" height="40" src="https://assets.feedblitz.com/i/podplay.png"/&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/spotlight-covid-broke-security-can-we-fix-it-in-2022/"&gt;Spotlight: COVID Broke Security. Can We Fix It In 2022?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/spotlight-operationalizing-mdr-with-pondurance-ciso-dustin-hutchison/"&gt;Spotlight: Operationalizing MDR with Pondurance CISO Dustin Hutchison&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/spotlight-your-iot-risk-is-bigger-than-you-think-and-what-to-do-about-it/"&gt;Spotlight: Your IoT Risk Is Bigger Than You Think. (And What To Do About It.)&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
      <content:encoded>&lt;p&gt;In this episode of the podcast (#230) Siddarth Adukia, a regional Director at NCC Group, joins host Paul Roberts to talk about the (cyber) risks and (public health) rewards of vaccine passport systems: how they work, how they can be compromised and what to do about it. &lt;/p&gt;
&lt;p&gt;The post &lt;a rel="nofollow" href="https://feeds.feedblitz.com/~/t/0/_/thesecurityledger/~https://securityledger.com/2021/11/episode-230-are-vaccine-passports-cyber-secure/"&gt;Episode 230: Are Vaccine Passports Cyber Secure?&lt;/a&gt; appeared first on &lt;a rel="nofollow" href="https://feeds.feedblitz.com/~/t/0/_/thesecurityledger/~https://securityledger.com"&gt;...&lt;/a&gt;&lt;/p&gt;&lt;p style="clear:left"&gt;&lt;span class="fbz_teasertext"&gt;&lt;a href="https://feeds.feedblitz.com/~/672693428/_/thesecurityledger"&gt;&lt;b&gt;Read the whole entry...&lt;/b&gt;&lt;/a&gt;&amp;#160;&lt;!-- _!fbztxtlnk!_ https://feeds.feedblitz.com/~/672693428/_/thesecurityledger --&gt;&lt;b&gt;&amp;#187;&lt;/b&gt;&lt;/p&gt;&lt;/span&gt;&lt;Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.feedblitz.com/~/i/672693428/_/thesecurityledger"&gt;
&lt;/p&gt;&lt;div class="fbz_enclosure" style="clear:left"&gt;&lt;audio controls="controls" style="display:block;padding:0.5em 0;max-width:100%;"&gt;&lt;source src="https://feeds.feedblitz.com/-/672693426/_/thesecurityledger.mp3"&gt;Click the icon below to listen.&lt;/audio&gt;&lt;a href="https://feeds.feedblitz.com/-/672693426/_/thesecurityledger.mp3" title="Play audio"&gt;&lt;img border="0" width="40" height="40" src="https://assets.feedblitz.com/i/podplay.png"/&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/spotlight-covid-broke-security-can-we-fix-it-in-2022/"&gt;Spotlight: COVID Broke Security. Can We Fix It In 2022?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/spotlight-operationalizing-mdr-with-pondurance-ciso-dustin-hutchison/"&gt;Spotlight: Operationalizing MDR with Pondurance CISO Dustin Hutchison&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/spotlight-your-iot-risk-is-bigger-than-you-think-and-what-to-do-about-it/"&gt;Spotlight: Your IoT Risk Is Bigger Than You Think. (And What To Do About It.)&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded>
      <enclosure url="https://feeds.feedblitz.com/-/672693426/_/thesecurityledger.mp3" length="40636699" type="audio/mpeg" />
      <category>Companies</category>
      <category>Consumer</category>
      <category>COVID</category>
      <category>digital certificate</category>
      <category>fraud</category>
      <category>Identity Theft</category>
      <category>NCC Group</category>
      <category>PKI</category>
      <category>Podcasts</category>
      <category>Spotlight</category>
      <category>Technologies</category>
      <category>Threats</category>
      <category>Top Stories</category>
      <category>COVID 19</category>
      <category>cybersecurity</category>
      <category>identity theft</category>
      <category>vaccine passport</category>
      <pubDate>Thu, 11 Nov 2021 17:37:37 GMT</pubDate>
      <comments>https://feeds.feedblitz.com/~/672693428/_/thesecurityledger~Episode-Are-Vaccine-Passports-Cyber-Secure/#comments</comments>
      <guid isPermaLink="false">https://securityledger.com/?p=476662</guid>
      <dc:creator>Paul Roberts</dc:creator>
      <dc:date>2021-11-11T17:37:37Z</dc:date>
    </item>
    <item>
      <title>TeamTNT Upgrades Arsenal, Refines Focus on Kubernetes and GPU Environments</title>
      <link>https://www.trendmicro.com/en_us/research/21/k/teamtnt-upgrades-arsenal-refines-focus-on-kubernetes-and-gpu-env.html</link>
      <description>Using a new batch of campaign samples, we take a look at its more recent cybercrime contributions and compare them with its previous deployments to demonstrate the group’s use of upgraded tools and payloads.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/k/teamtnt-upgrades-arsenal-refines-focus-on-kubernetes-and-gpu-environments-/TeamTNT%20Upgrades%20Arsenal%20Refines%20Focus%20on%20Kubernetes%20and%20GPU%20Environments_641.jpg" type="image/jpeg" />
      <category>Trend Micro Research : Cloud</category>
      <category>Trend Micro Research : Research</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <category>Trend Micro Research : Cyber Threats</category>
      <pubDate>Thu, 11 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:25af24ea-5b92-c4d5-e866-33577b2ffdf9</guid>
      <dc:creator>David Fiser</dc:creator>
      <dc:date>2021-11-11T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Void Balaur and the Rise of the Cybermercenary Industry</title>
      <link>https://www.trendmicro.com/en_us/research/21/k/void-balaur-and-the-rise-of-the-cybermercenary-industry.html</link>
      <description>One of the most prolific cybermercenaries is Void Balaur, a Russian-speaking threat actor group that has launched attacks against different sectors and industries all over the world.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/k/void-balaur-and-the-rise-of-the-cybermercenary-industry/void-balaur-cybermercenary-641.png" type="image/png" />
      <category>Trend Micro Research : APT &amp; Targeted Attacks</category>
      <category>Trend Micro Research : Cyber Crime</category>
      <category>Trend Micro Research : Research</category>
      <category>Trend Micro Research : Articles, News, Reports</category>
      <pubDate>Wed, 10 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:043c2bdf-bf91-5498-7dae-66c8d61ea36b</guid>
      <dc:creator>Trend Micro Research</dc:creator>
      <dc:date>2021-11-10T00:00:00Z</dc:date>
    </item>
    <item>
      <title>November Continues Streak of Quiet Patch Tuesdays</title>
      <link>https://www.trendmicro.com/en_us/research/21/k/november-continues-streak-of-quiet-patch-tuesdays.html</link>
      <description>November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November.</description>
      <source url="https://www.trendmicro.com/en_us/research.html">Research, News, and Perspective</source>
      <enclosure url="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/patch-tuesday.png" type="image/png" />
      <category>Trend Micro Research : Articles, News, Reports</category>
      <category>Trend Micro Research : Research</category>
      <category>Trend Micro Research : Exploits &amp; Vulnerabilities</category>
      <pubDate>Wed, 10 Nov 2021 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">urn:uuid:e97f7d7e-cd9e-169d-ddc0-ac1d1c7c6ca6</guid>
      <dc:date>2021-11-10T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Episode 229: BugCrowd’s Casey Ellis On What’s Hot In Bug Hunting</title>
      <link>https://feeds.feedblitz.com/~/672116630/_/thesecurityledger~Episode-BugCrowd%e2%80%99s-Casey-Ellis-On-What%e2%80%99s-Hot-In-Bug-Hunting/</link>
      <feedburner:origLink xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">https://securityledger.com/2021/11/episode-229-bugcrowds-casey-ellis-on-whats-hot-in-bug-hunting/</feedburner:origLink>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://feeds.feedblitz.com/~/672116630/_/thesecurityledger~Episode-BugCrowd%e2%80%99s-Casey-Ellis-On-What%e2%80%99s-Hot-In-Bug-Hunting/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">1</slash:comments>
      <itunes:subtitle xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">We talk with Casey Ellis, founder and CTO of BugCrowd about how the market for software bugs has changed since the first bug bounty programs emerged nearly 20 years ago, and what’s hot in bug hunting in 2021.</itunes:subtitle>
      <itunes:summary xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><![CDATA[<br />
When the first bugs for cash programs emerged almost two&#160; decades ago, they were controversial. Programs like&#160; iDefense Labs <a rel="NOFOLLOW" rel="noreferrer noopener" href="https://lwn.net/Articles/124292/" target="_blank">Vulnerability Contributor Program </a>(VCP) (launched in 2002) and TippingPoint’s<a rel="NOFOLLOW" rel="noreferrer noopener" href="https://www.zerodayinitiative.com/" target="_blank"> Zero Day Initiative</a> (2005) were accused -at the time- of incentivizing the work of criminals and bad actors.&#160;<br />
<br />
<br />
<br />
Today, however, bug bounty programs are part and parcel of the software industry. Companies like <a rel="NOFOLLOW" rel="noreferrer noopener" href="https://www.microsoft.com/en-us/msrc/bounty" target="_blank">Microsoft</a>, <a rel="NOFOLLOW" rel="noreferrer noopener" href="https://bughunters.google.com/about/rules/6625378258649088" target="_blank">Google</a> and <a rel="NOFOLLOW" rel="noreferrer noopener" href="https://developer.apple.com/security-bounty/" target="_blank">Apple</a> all offer them, as well as countless other software firms. In recent years, even “old economy” industrial and manufacturing firms like Ford, GM and John Deere got into the act. <br />
<br />
<br />
<br />
Careers Built on Bugs<br />
<br />
<br />
<br />
That has spurred growth in the demand for vulnerability hunters. These days, talented bug hunters and pen testers can make six figure salaries &#8211; or higher &#8211; on crowdsourced bug bounty marketplaces: finding and reporting flaws in software in accordance with corporate bug bounty programs.&#160;<br />
<br />
<br />
<br />
<a rel="NOFOLLOW" href="https://securityledger.com/2020/11/security-holes-opened-back-door-to-tcl-android-smart-tvs/" target="_blank" rel="noreferrer noopener">Security Holes Opened Back Door To TCL Android Smart TVs</a><br />
<br />
<br />
<br />
Casey Ellis is the CTO and Founder of BugCrowd. <br />
<br />
<br />
<br />
But standing up a bug bounty program is no easy task. Apple, for example, has <a rel="NOFOLLOW" rel="noreferrer noopener" href="https://www.washingtonpost.com/technology/2021/09/09/apple-bug-bounty/" target="_blank">faced criticism</a> for how it manages its disclosure program, with many vulnerability researchers claiming the company is too slow to address issues they report. For the countless other companies without big budgets and deep roots in the information security community, the logistics of standing up a bounty program and managing the flow of submissions are daunting. For those firms, bug bounty platforms have been a critical bridge to the global community of “white hat” security pros.<br />
<br />
<br />
<br />
<a rel="NOFOLLOW" href="https://securityledger.com/2020/10/report-critical-infrastructure-cyber-attacks-a-global-crisis/" target="_blank" rel="noreferrer noopener">Report: Critical Infrastructure Cyber Attacks A Global Crisis</a><br />
<br />
<br />
<br />
In the last decade, such programs have become a staple of countless software security and software assurance programs: crowd sourcing the work of finding and reporting software flaws that leverages the “wisdom of the crowd.” <br />
<br />
<br />
<br />
BugCrowd: Bug Bounty Programs 10 Years On <br />
<br />
<br />
<br />
What does it take to stand up a bounty program? And what skills are in demand on the bug bounty marketplaces today? To answer those questions, we invited <a rel="NOFOLLOW" href="https://www.linkedin.com/in/caseyjohnellis/" target="_blank" rel="noreferrer noopener">Casey John Ellis</a> into the studio. Casey is the founder and Chief Technology Officer at <a rel="NOFOLLOW" href="https://www.bugcrowd.com" target="_blank" rel="noreferrer noopener">BugCrowd</a>, an online marketplace that helps connect independent bug hunters, pen testers and software security experts with software publishers of every stripe.&#160;<br />
<br />
<br />
<br />
<a rel="NOFOLLOW" href="https://securityledger.com/2021/01/episode-200-sakura-samurai-wants-to-make-hacking-groups-cool-again-and-automating-our-way-out-of-pki-chaos/" target="_blank" rel="noreferrer noopener">Episode 200: Sakura Samurai...]]></itunes:summary>
      <itunes:author xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">Paul F. Roberts</itunes:author>
      <itunes:duration xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">48:29</itunes:duration>
      <rawvoice:embed xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/">&lt;iframe src="https://player.blubrry.com/?media_url=https%3A%2F%2Fmedia.blubrry.com%2Fthe_security_ledger_podcasts%2Fcontent.blubrry.com%2Fthe_security_ledger_podcasts%2FEpisode_229_Casey_Ellis_of_BugCrowd_10_Years_On.mp3&amp;amp;podcast_link=https%3A%2F%2Fsecurityledger.com%2F2021%2F11%2Fepisode-229-bugcrowds-casey-ellis-on-whats-hot-in-bug-hunting%2F#darkOrLight-light&amp;shownotes-ffffff&amp;shownotesBackground-444444&amp;download-ffffff&amp;downloadBackground-003366&amp;subscribe-ffffff&amp;subscribeBackground-fb8c00&amp;share-ffffff&amp;shareBackground-1976d2" scrolling="no" width="100%" height="138px" frameborder="0" id="blubrryplayer-5" class="blubrryplayer" title="Blubrry Podcast Player"&gt;&lt;/iframe&gt;</rawvoice:embed>
      <post-id xmlns="com-wordpress:feed-additions:1">476648</post-id>
      <feedburner:origEnclosureLink xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">https://media.blubrry.com/the_security_ledger_podcasts/content.blubrry.com/the_security_ledger_podcasts/Episode_229_Casey_Ellis_of_BugCrowd_10_Years_On.mp3</feedburner:origEnclosureLink>
      <description>&lt;p&gt;We talk with Casey Ellis, founder and CTO of BugCrowd about how the market for software bugs has changed since the first bug bounty programs emerged nearly 20 years ago, and what’s hot in bug hunting in 2021. &lt;/p&gt;
&lt;p&gt;The post &lt;a rel="NOFOLLOW" href="https://feeds.feedblitz.com/~/672116630/_/thesecurityledger~Episode-BugCrowd%e2%80%99s-Casey-Ellis-On-What%e2%80%99s-Hot-In-Bug-Hunting/"&gt;Episode 229: BugCrowd’s Casey Ellis On What’s Hot In Bug Hunting&lt;/a&gt; appeared first on &lt;a rel="NOFOLLOW" href="https://securityledger.com"&gt;The Security Ledger with Paul F. Roberts&lt;/a&gt;.&lt;/p&gt;
&lt;!-- --&gt;&lt;/p&gt;&lt;div class="fbz_enclosure" style="clear:left"&gt;&lt;audio controls="controls" style="display:block;padding:0.5em 0;max-width:100%;"&gt;&lt;source src="https://feeds.feedblitz.com/-/672116628/_/thesecurityledger.mp3"&gt;Click the icon below to listen.&lt;/audio&gt;&lt;a href="https://feeds.feedblitz.com/-/672116628/_/thesecurityledger.mp3" title="Play audio"&gt;&lt;img border="0" width="40" height="40" src="https://assets.feedblitz.com/i/podplay.png"/&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/09/spotlight-when-ransomware-comes-calling/"&gt;Spotlight: When Ransomware Comes Calling&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/12/episode-232-log4j-wont-go-away-and-what-to-do-about-it/"&gt;Episode 232: Log4j Won&amp;#x2019;t Go Away (And What To Do About It.)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/spotlight-automation-beckons-as-devops-iot-drive-pki-explosion/"&gt;Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
      <content:encoded>&lt;p&gt;We talk with Casey Ellis, founder and CTO of BugCrowd about how the market for software bugs has changed since the first bug bounty programs emerged nearly 20 years ago, and what’s hot in bug hunting in 2021. &lt;/p&gt;
&lt;p&gt;The post &lt;a rel="nofollow" href="https://feeds.feedblitz.com/~/t/0/_/thesecurityledger/~https://securityledger.com/2021/11/episode-229-bugcrowds-casey-ellis-on-whats-hot-in-bug-hunting/"&gt;Episode 229: BugCrowd’s Casey Ellis On What’s Hot In Bug Hunting&lt;/a&gt; appeared first on &lt;a rel="nofollow" href="https://feeds.feedblitz.com/~/t/0/_/thesecurityledger/~https://securityledger.com"&gt;The Security Ledger with Paul F. Roberts&lt;/a&gt;.&lt;Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.feedblitz.com/~/i/672116630/_/thesecurityledger"&gt;
&lt;/p&gt;&lt;div class="fbz_enclosure" style="clear:left"&gt;&lt;audio controls="controls" style="display:block;padding:0.5em 0;max-width:100%;"&gt;&lt;source src="https://feeds.feedblitz.com/-/672116628/_/thesecurityledger.mp3"&gt;Click the icon below to listen.&lt;/audio&gt;&lt;a href="https://feeds.feedblitz.com/-/672116628/_/thesecurityledger.mp3" title="Play audio"&gt;&lt;img border="0" width="40" height="40" src="https://assets.feedblitz.com/i/podplay.png"/&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/09/spotlight-when-ransomware-comes-calling/"&gt;Spotlight: When Ransomware Comes Calling&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/12/episode-232-log4j-wont-go-away-and-what-to-do-about-it/"&gt;Episode 232: Log4j Won&amp;#x2019;t Go Away (And What To Do About It.)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/spotlight-automation-beckons-as-devops-iot-drive-pki-explosion/"&gt;Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded>
      <enclosure url="https://feeds.feedblitz.com/-/672116628/_/thesecurityledger.mp3" length="69832946" type="audio/mpeg" />
      <category>bounty</category>
      <category>bugcrowd</category>
      <category>Companies</category>
      <category>Interview</category>
      <category>Podcasts</category>
      <category>Spotlight</category>
      <category>Threats</category>
      <category>Vulnerabilities</category>
      <category>Government</category>
      <category>software</category>
      <category>software bug</category>
      <category>trends</category>
      <category>vulnerabilities</category>
      <pubDate>Wed, 03 Nov 2021 13:59:41 GMT</pubDate>
      <comments>https://feeds.feedblitz.com/~/672116630/_/thesecurityledger~Episode-BugCrowd%e2%80%99s-Casey-Ellis-On-What%e2%80%99s-Hot-In-Bug-Hunting/#comments</comments>
      <guid isPermaLink="false">https://securityledger.com/?p=476648</guid>
      <dc:creator>Paul Roberts</dc:creator>
      <dc:date>2021-11-03T13:59:41Z</dc:date>
    </item>
    <item>
      <title>Spotlight: Your IoT Risk Is Bigger Than You Think. (And What To Do About It.)</title>
      <link>https://feeds.feedblitz.com/~/671351780/_/thesecurityledger~Spotlight-Your-IoT-Risk-Is-Bigger-Than-You-Think-And-What-To-Do-About-It/</link>
      <feedburner:origLink xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">https://securityledger.com/2021/10/spotlight-your-iot-risk-is-bigger-than-you-think-and-what-to-do-about-it/</feedburner:origLink>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://feeds.feedblitz.com/~/671351780/_/thesecurityledger~Spotlight-Your-IoT-Risk-Is-Bigger-Than-You-Think-And-What-To-Do-About-It/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">1</slash:comments>
      <itunes:subtitle xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">In this Spotlight edition of the podcast, we’re joined by Curtis Simpson, the Chief Information Security Officer at Armis. Curtis and I discuss the growing cyber risks posed by Internet of Things devices within enterprise networks.</itunes:subtitle>
      <itunes:summary xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><![CDATA[<br />
In this&#160;Spotlight&#160;edition of the podcast, we’re joined by Curtis Simpson, the Chief Information Security Officer at <a rel="NOFOLLOW" rel="noreferrer noopener" href="https://www.armis.com/" target="_blank">Armis</a>. Curtis and I discuss the growing cyber risks posed by Internet of Things devices within enterprise networks. IoT and OT (operation technology) deployments are growing and pose challenges to organizations that are still focused on conventional IT systems and threats, and that struggle to detect such devices in their environments. <br />
<br />
<br />
<br />
As always, &#160;you can check our full conversation in&#160;<a rel="NOFOLLOW" href="https://www.blubrry.com/the_security_ledger_podcasts/">our latest Security Ledger podcast at Blubrry</a>. You&#160;<a rel="NOFOLLOW" rel="noreferrer noopener" href="https://itunes.apple.com/us/podcast/the-security-ledger-podcast/id680045866?mt=2" target="_blank">can also listen to it on iTunes</a>&#160;and&#160;<a rel="NOFOLLOW" rel="noreferrer noopener" href="https://open.spotify.com/show/5YZ0iBx5uwjbqRWeR7bHcQ?si=41x7hihbSAuQ21YbII-CDQ&#38;dl_branch=1" target="_blank">Spotify</a>. Or, check us out on&#160;<a rel="NOFOLLOW" rel="noreferrer noopener" href="https://podcasts.google.com/feed/aHR0cHM6Ly9mZWVkcy5mZWVkYmxpdHouY29tL3RoZXNlY3VyaXR5bGVkZ2Vy" target="_blank">Google Podcasts</a>,&#160;<a rel="NOFOLLOW" href="https://www.stitcher.com/podcast/the-security-ledger-4/the-security-ledger-podcast">Stitcher</a>,&#160;<a rel="NOFOLLOW" href="https://radiopublic.com/the-security-ledger-WDR2Z9">Radio Public</a>&#160;and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to&#160;<a rel="NOFOLLOW" href="http://securityledger.com/subscribe">securityledger.com/subscribe</a>&#160;to get notified whenever a new podcast is posted.&#160;<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
In the past decade, security threats posed by the “Internet of Things” have gone from a curious “what if” to an urgent problem affecting national security. Earlier this month, for example, CISA warned of ongoing cyber attacks targeting water and wastewater facilities. Those attacks are targeting both IT and OT &#8211; or operational technology &#8211; networks and systems including industrial control system (ICS) and SCADA systems, CISA said. (<a rel="NOFOLLOW" href="https://us-cert.cisa.gov/sites/default/files/publications/AA21-287A-Ongoing_Cyber_Threats_to_U.S._Water_and_Wastewater_Systems.pdf" target="_blank" rel="noreferrer noopener">PDF</a>)<br />
<br />
<br />
<br />
But, in truth, IoT risk is something that affects organizations of all types &#8211; from critical infrastructure owners and operators down to small businesses. Network connected printers, door/badge and HVAC systems, CCTV installations &#8211; all are common fixtures of modern workplaces &#8211; from defense contractors to doctors’ offices. <br />
<br />
<br />
<br />
Curtis Simpson is the Chief Information Security Officer at Armis.<br />
<br />
<br />
<br />
Still, the vast majority of security technology available to these organizations to manage their cybersecurity was designed to fight the “last war”: securing mostly Windows laptops, desktops and servers, even as non-traditional endpoints proliferate &#8211; most running operating systems other than Windows has cropped up on corporate networks.&#160;Consider, for example, the so-called <a rel="NOFOLLOW" href="https://www.armis.com/research/urgent11/">“Urgent11” software vulnerabilities</a> that were discovered to impact real time operating systems including VxWorks, OSE, Integrity and ThreadX RTOSs that, collectively, run billions of connected devices. <br />
<br />
<br />
<br />
Identifying these devices is critical if they are to be managed and secured. But what does that take? In this episode of the podcast we are joined by <a rel="NOFOLLOW" href="https://www.linkedin.com/in/curtis-simpson-8156326b/">Curtis Simpson</a>, the CISO at Armis, a cybersecurity firm that offers a knowledge base and tools for fingerprinting IoT devices and then monitoring and sec...]]></itunes:summary>
      <itunes:author xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">Paul F. Roberts</itunes:author>
      <itunes:duration xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">28:20</itunes:duration>
      <rawvoice:embed xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/">&lt;iframe src="https://player.blubrry.com/?media_url=https%3A%2F%2Fmedia.blubrry.com%2Fthe_security_ledger_podcasts%2Fcontent.blubrry.com%2Fthe_security_ledger_podcasts%2FSpotlight_Curtis_Simpson_of_Armis_on_finding_and_securing_IoT.mp3&amp;amp;podcast_link=https%3A%2F%2Fsecurityledger.com%2F2021%2F10%2Fspotlight-your-iot-risk-is-bigger-than-you-think-and-what-to-do-about-it%2F#darkOrLight-light&amp;shownotes-ffffff&amp;shownotesBackground-444444&amp;download-ffffff&amp;downloadBackground-003366&amp;subscribe-ffffff&amp;subscribeBackground-fb8c00&amp;share-ffffff&amp;shareBackground-1976d2" scrolling="no" width="100%" height="138px" frameborder="0" id="blubrryplayer-6" class="blubrryplayer" title="Blubrry Podcast Player"&gt;&lt;/iframe&gt;</rawvoice:embed>
      <post-id xmlns="com-wordpress:feed-additions:1">476644</post-id>
      <feedburner:origEnclosureLink xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">https://media.blubrry.com/the_security_ledger_podcasts/content.blubrry.com/the_security_ledger_podcasts/Spotlight_Curtis_Simpson_of_Armis_on_finding_and_securing_IoT.mp3</feedburner:origEnclosureLink>
      <description>&lt;p&gt;In this Spotlight edition of the podcast, we’re joined by Curtis Simpson, the Chief Information Security Officer at Armis. Curtis and I discuss the growing cyber risks posed by Internet of Things devices within enterprise networks. IoT and OT (operation technology) deployments are growing and pose challenges to organizations that are still...&lt;/p&gt;&lt;p style="clear:left"&gt;&lt;span class="fbz_teasertext"&gt;&lt;a href="https://feeds.feedblitz.com/~/671351780/_/thesecurityledger"&gt;&lt;b&gt;Read the whole entry...&lt;/b&gt;&lt;/a&gt;&amp;#160;&lt;!-- _!fbztxtlnk!_ https://feeds.feedblitz.com/~/671351780/_/thesecurityledger --&gt;&lt;b&gt;&amp;#187;&lt;/b&gt;&lt;/p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="fbz_enclosure" style="clear:left"&gt;&lt;audio controls="controls" style="display:block;padding:0.5em 0;max-width:100%;"&gt;&lt;source src="https://feeds.feedblitz.com/-/671351778/_/thesecurityledger.mp3"&gt;Click the icon below to listen.&lt;/audio&gt;&lt;a href="https://feeds.feedblitz.com/-/671351778/_/thesecurityledger.mp3" title="Play audio"&gt;&lt;img border="0" width="40" height="40" src="https://assets.feedblitz.com/i/podplay.png"/&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/spotlight-automation-beckons-as-devops-iot-drive-pki-explosion/"&gt;Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/12/spotlight-how-secrets-sprawl-undermines-software-supply-chain-security/"&gt;Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/11/episode-230-are-vaccine-passports-cyber-secure/"&gt;Episode 230: Are Vaccine Passports Cyber Secure?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
      <content:encoded>&lt;p&gt;In this Spotlight edition of the podcast, we’re joined by Curtis Simpson, the Chief Information Security Officer at Armis. Curtis and I discuss the growing cyber risks posed by Internet of Things devices within enterprise networks. IoT and OT (operation technology) deployments are growing and pose challenges to organizations that are still...&lt;/p&gt;&lt;p style="clear:left"&gt;&lt;span class="fbz_teasertext"&gt;&lt;a href="https://feeds.feedblitz.com/~/671351780/_/thesecurityledger"&gt;&lt;b&gt;Read the whole entry...&lt;/b&gt;&lt;/a&gt;&amp;#160;&lt;!-- _!fbztxtlnk!_ https://feeds.feedblitz.com/~/671351780/_/thesecurityledger --&gt;&lt;b&gt;&amp;#187;&lt;/b&gt;&lt;/p&gt;&lt;/span&gt;&lt;Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.feedblitz.com/~/i/671351780/_/thesecurityledger"&gt;
&lt;/p&gt;&lt;div class="fbz_enclosure" style="clear:left"&gt;&lt;audio controls="controls" style="display:block;padding:0.5em 0;max-width:100%;"&gt;&lt;source src="https://feeds.feedblitz.com/-/671351778/_/thesecurityledger.mp3"&gt;Click the icon below to listen.&lt;/audio&gt;&lt;a href="https://feeds.feedblitz.com/-/671351778/_/thesecurityledger.mp3" title="Play audio"&gt;&lt;img border="0" width="40" height="40" src="https://assets.feedblitz.com/i/podplay.png"/&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/spotlight-automation-beckons-as-devops-iot-drive-pki-explosion/"&gt;Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/12/spotlight-how-secrets-sprawl-undermines-software-supply-chain-security/"&gt;Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/11/episode-230-are-vaccine-passports-cyber-secure/"&gt;Episode 230: Are Vaccine Passports Cyber Secure?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded>
      <enclosure url="https://feeds.feedblitz.com/-/671351778/_/thesecurityledger.mp3" length="40821563" type="audio/mpeg" />
      <category>Armis</category>
      <category>Cisco</category>
      <category>Companies</category>
      <category>Internet of Things</category>
      <category>operating system</category>
      <category>Podcasts</category>
      <category>RTOS</category>
      <category>Software</category>
      <category>Spotlight</category>
      <category>Technologies</category>
      <category>VxWorks</category>
      <category>cybersecurity</category>
      <category>podcast</category>
      <pubDate>Thu, 28 Oct 2021 21:38:33 GMT</pubDate>
      <comments>https://feeds.feedblitz.com/~/671351780/_/thesecurityledger~Spotlight-Your-IoT-Risk-Is-Bigger-Than-You-Think-And-What-To-Do-About-It/#comments</comments>
      <guid isPermaLink="false">https://securityledger.com/?p=476644</guid>
      <dc:creator>Paul Roberts</dc:creator>
      <dc:date>2021-10-28T21:38:33Z</dc:date>
    </item>
    <item>
      <title>Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion</title>
      <link>https://feeds.feedblitz.com/~/670451720/_/thesecurityledger~Spotlight-Automation-Beckons-as-DevOps-IoT-Drive-PKI-Explosion/</link>
      <feedburner:origLink xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">https://securityledger.com/2021/10/spotlight-automation-beckons-as-devops-iot-drive-pki-explosion/</feedburner:origLink>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://feeds.feedblitz.com/~/670451720/_/thesecurityledger~Spotlight-Automation-Beckons-as-DevOps-IoT-Drive-PKI-Explosion/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">2</slash:comments>
      <itunes:subtitle xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">Brian Trzupek of DigiCert joins Paul to talk about the findings of a recent State of PKI Automation survey and the challenges of managing fast-growing population of tens of thousands of PKI certificates.</itunes:subtitle>
      <itunes:summary xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><![CDATA[<br />
In this <a rel="NOFOLLOW" href="#sponsor">Spotlight</a> edition of the podcast, we’re joined by Brian Trzupek the Senior Vice President of Product at <a rel="NOFOLLOW" href="https://www.digicert.com">DigiCert</a>. Brian and I take a look at the findings of a recent State of PKI Automation survey and the challenges organizations face as they look to manage a fast-growing population of tens of thousands of PKI certificates.<br />
<br />
<br />
<br />
As always, &#160;you can check our full conversation in&#160;<a rel="NOFOLLOW" href="https://www.blubrry.com/the_security_ledger_podcasts/">our latest Security Ledger podcast at Blubrry</a>. You&#160;<a rel="NOFOLLOW" rel="noreferrer noopener" href="https://itunes.apple.com/us/podcast/the-security-ledger-podcast/id680045866?mt=2" target="_blank">can also listen to it on iTunes</a>&#160;and&#160;<a rel="NOFOLLOW" rel="noreferrer noopener" href="https://open.spotify.com/show/5YZ0iBx5uwjbqRWeR7bHcQ?si=41x7hihbSAuQ21YbII-CDQ&#38;dl_branch=1" target="_blank">Spotify</a>. Or, check us out on&#160;<a rel="NOFOLLOW" rel="noreferrer noopener" href="https://podcasts.google.com/feed/aHR0cHM6Ly9mZWVkcy5mZWVkYmxpdHouY29tL3RoZXNlY3VyaXR5bGVkZ2Vy" target="_blank">Google Podcasts</a>,&#160;<a rel="NOFOLLOW" href="https://www.stitcher.com/podcast/the-security-ledger-4/the-security-ledger-podcast">Stitcher</a>,&#160;<a rel="NOFOLLOW" href="https://radiopublic.com/the-security-ledger-WDR2Z9">Radio Public</a>&#160;and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to&#160;<a rel="NOFOLLOW" href="http://securityledger.com/subscribe">securityledger.com/subscribe</a>&#160;to get notified whenever a new podcast is posted.&#160;<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
Twenty years ago, <a rel="NOFOLLOW" rel="noreferrer noopener" href="https://www.digicert.com/what-is-pki" target="_blank">Public Key Infrastructure</a>, or PKI, had a pretty limited remit. Its first applications were securing email and physical access systems in security conscious environments like the military, intelligence community and government. With the explosion of the Internet, PKI became a foundational technology for securing web traffic and authenticating users to applications via technologies like SSL and TLS. <br />
<br />
<br />
<br />
<a rel="NOFOLLOW" href="https://securityledger.com/wp-content/uploads/2020/09/Brian-Trzupek.jpeg"></a>Brian Trzupek is SVP of Products at DigiCert<br />
<br />
<br />
<br />
Since then, both the scale and applications of PKI have transformed. Today, PKI and digital certificates are used to sign and secure electronic documents and &#8211; increasingly &#8211; to secure communications and interactions between billions of connected devices on the <a rel="NOFOLLOW" href="https://securityledger.com/?s=%E2%80%9CInternet+of+Things%E2%80%9D" target="_blank" rel="noreferrer noopener">Internet of Things</a>.&#160; Moreover, as digital transformation and DEVOPS has taken hold within the enterprise, the demand for PKI to secure critical development and production infrastructure has exploded.&#160;<br />
<br />
<br />
<br />
Survey: 50,000 Certs on Average<br />
<br />
<br />
<br />
In fact, a recent <a rel="NOFOLLOW" href="https://www.prnewswire.com/news-releases/digicert-2021-state-of-pki-automation-survey-finds-companies-are-struggling-with-reliance-on-manual-processes-amid-growing-volume-of-digital-certificates-301386125.html" target="_blank" rel="noreferrer noopener">survey of PKI use in 400 enterprises worldwide</a> found that the typical enterprise is managing more than 50,000 digital certificates, with most dedicated to securing users, servers, web applications, email and mobile devices. That’s a 43% jump year over year, according to the survey.<br />
<br />
<br />
<br />
Not surprisingly, IT managers are feeling overwhelmed by the sudden growth in the population of certificates. 61% of those surveyed said they were concerned about the time required to manage certificates in their environment, while 47% reported having encountered “rogue” (or unmanaged) certificates.&#160;<br />
<br />
<br />
<br />]]></itunes:summary>
      <itunes:author xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">Paul F. Roberts</itunes:author>
      <itunes:duration xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">34:38</itunes:duration>
      <rawvoice:embed xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/">&lt;iframe src="https://player.blubrry.com/?media_url=https%3A%2F%2Fmedia.blubrry.com%2Fthe_security_ledger_podcasts%2Fcontent.blubrry.com%2Fthe_security_ledger_podcasts%2FSpotlight_Digicert_s_State_of_PKI_Automation_Survey_with_Brian_Trzupek.mp3&amp;amp;podcast_link=https%3A%2F%2Fsecurityledger.com%2F2021%2F10%2Fspotlight-automation-beckons-as-devops-iot-drive-pki-explosion%2F#darkOrLight-light&amp;shownotes-ffffff&amp;shownotesBackground-444444&amp;download-ffffff&amp;downloadBackground-003366&amp;subscribe-ffffff&amp;subscribeBackground-fb8c00&amp;share-ffffff&amp;shareBackground-1976d2" scrolling="no" width="100%" height="138px" frameborder="0" id="blubrryplayer-7" class="blubrryplayer" title="Blubrry Podcast Player"&gt;&lt;/iframe&gt;</rawvoice:embed>
      <post-id xmlns="com-wordpress:feed-additions:1">476634</post-id>
      <feedburner:origEnclosureLink xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">https://media.blubrry.com/the_security_ledger_podcasts/content.blubrry.com/the_security_ledger_podcasts/Spotlight_Digicert_s_State_of_PKI_Automation_Survey_with_Brian_Trzupek.mp3</feedburner:origEnclosureLink>
      <description>&lt;p&gt;Brian Trzupek of DigiCert joins Paul to talk about the findings of a recent State of PKI Automation survey and the challenges of managing fast-growing population of tens of thousands of PKI certificates.&lt;/p&gt;
&lt;p&gt;The post &lt;a rel="NOFOLLOW" href="https://feeds.feedblitz.com/~/670451720/_/thesecurityledger~Spotlight-Automation-Beckons-as-DevOps-IoT-Drive-PKI-Explosion/"&gt;Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion&lt;/a&gt; appeared first on &lt;a rel="NOFOLLOW" href="https://securityledger.com"&gt;The Security Ledger with Paul F. Roberts&lt;/a&gt;.&lt;/p&gt;
&lt;!-- --&gt;&lt;/p&gt;&lt;div class="fbz_enclosure" style="clear:left"&gt;&lt;audio controls="controls" style="display:block;padding:0.5em 0;max-width:100%;"&gt;&lt;source src="https://feeds.feedblitz.com/-/670451718/_/thesecurityledger.mp3"&gt;Click the icon below to listen.&lt;/audio&gt;&lt;a href="https://feeds.feedblitz.com/-/670451718/_/thesecurityledger.mp3" title="Play audio"&gt;&lt;img border="0" width="40" height="40" src="https://assets.feedblitz.com/i/podplay.png"/&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/06/episode-216-signed-sealed-and-delivered-the-future-of-supply-chain-security/"&gt;Episode 216: Signed, Sealed and Delivered: The Future of Supply Chain Security&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/spotlight-covid-broke-security-can-we-fix-it-in-2022/"&gt;Spotlight: COVID Broke Security. Can We Fix It In 2022?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/11/episode-229-bugcrowds-casey-ellis-on-whats-hot-in-bug-hunting/"&gt;Episode 229: BugCrowd&amp;#x2019;s Casey Ellis On What&amp;#x2019;s Hot In Bug Hunting&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
      <content:encoded>&lt;p&gt;Brian Trzupek of DigiCert joins Paul to talk about the findings of a recent State of PKI Automation survey and the challenges of managing fast-growing population of tens of thousands of PKI certificates.&lt;/p&gt;
&lt;p&gt;The post &lt;a rel="nofollow" href="https://feeds.feedblitz.com/~/t/0/_/thesecurityledger/~https://securityledger.com/2021/10/spotlight-automation-beckons-as-devops-iot-drive-pki-explosion/"&gt;Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion&lt;/a&gt; appeared first on &lt;a rel="nofollow" href="https://feeds.feedblitz.com/~/t/0/_/thesecurityledger/~https://securityledger.com"&gt;The Security Ledger with Paul F. Roberts&lt;/a&gt;.&lt;Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.feedblitz.com/~/i/670451720/_/thesecurityledger"&gt;
&lt;/p&gt;&lt;div class="fbz_enclosure" style="clear:left"&gt;&lt;audio controls="controls" style="display:block;padding:0.5em 0;max-width:100%;"&gt;&lt;source src="https://feeds.feedblitz.com/-/670451718/_/thesecurityledger.mp3"&gt;Click the icon below to listen.&lt;/audio&gt;&lt;a href="https://feeds.feedblitz.com/-/670451718/_/thesecurityledger.mp3" title="Play audio"&gt;&lt;img border="0" width="40" height="40" src="https://assets.feedblitz.com/i/podplay.png"/&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/06/episode-216-signed-sealed-and-delivered-the-future-of-supply-chain-security/"&gt;Episode 216: Signed, Sealed and Delivered: The Future of Supply Chain Security&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/spotlight-covid-broke-security-can-we-fix-it-in-2022/"&gt;Spotlight: COVID Broke Security. Can We Fix It In 2022?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/11/episode-229-bugcrowds-casey-ellis-on-whats-hot-in-bug-hunting/"&gt;Episode 229: BugCrowd&amp;#x2019;s Casey Ellis On What&amp;#x2019;s Hot In Bug Hunting&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded>
      <enclosure url="https://feeds.feedblitz.com/-/670451718/_/thesecurityledger.mp3" length="49878635" type="audio/mpeg" />
      <category>application development</category>
      <category>Companies</category>
      <category>DevOps</category>
      <category>DigiCert</category>
      <category>Internet of Things</category>
      <category>Interview</category>
      <category>PKI</category>
      <category>Podcasts</category>
      <category>Reports</category>
      <category>Software</category>
      <category>Spotlight</category>
      <category>survey</category>
      <category>Technologies</category>
      <category>DEVOPS</category>
      <category>Digicert</category>
      <category>trends</category>
      <pubDate>Thu, 21 Oct 2021 13:57:53 GMT</pubDate>
      <comments>https://feeds.feedblitz.com/~/670451720/_/thesecurityledger~Spotlight-Automation-Beckons-as-DevOps-IoT-Drive-PKI-Explosion/#comments</comments>
      <guid isPermaLink="false">https://securityledger.com/?p=476634</guid>
      <dc:creator>Paul Roberts</dc:creator>
      <dc:date>2021-10-21T13:57:53Z</dc:date>
    </item>
    <item>
      <title>Episode 228: CISA’s Eric Goldstein on being Everyone’s Friend in Cyber</title>
      <link>https://feeds.feedblitz.com/~/670200030/_/thesecurityledger~Episode-CISA%e2%80%99s-Eric-Goldstein-on-being-Everyone%e2%80%99s-Friend-in-Cyber/</link>
      <feedburner:origLink xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">https://securityledger.com/2021/10/episode-228-cisas-eric-goldstein-and-the-challenge-of-being-everyones-friend-in-cyber/</feedburner:origLink>
      <wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">https://feeds.feedblitz.com/~/670200030/_/thesecurityledger~Episode-CISA%e2%80%99s-Eric-Goldstein-on-being-Everyone%e2%80%99s-Friend-in-Cyber/feed/</wfw:commentRss>
      <slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">1</slash:comments>
      <itunes:subtitle xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">Eric Goldstein,  Executive Assistant Director for Cybersecurity for the Cybersecurity and Infrastructure Security Agency (CISA), says the agency is all about helping companies and local government to keep hackers at bay.</itunes:subtitle>
      <itunes:summary xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><![CDATA[<br />
In this episode of the podcast (#228) we’re joined by Eric Goldstein, Executive Assistant Director for Cybersecurity for the Cybersecurity and Infrastructure Security Agency (CISA) to talk about how the US government’s lead cybersecurity agency is helping companies and local government to keep hackers at bay. But are organizations ready to ask for help?<br />
<br />
<br />
<br />
As always, &#160;you can check our full conversation in&#160;<a rel="NOFOLLOW" href="https://www.blubrry.com/the_security_ledger_podcasts/">our latest Security Ledger podcast at Blubrry</a>. You&#160;<a rel="NOFOLLOW" rel="noreferrer noopener" href="https://itunes.apple.com/us/podcast/the-security-ledger-podcast/id680045866?mt=2" target="_blank">can also listen to it on iTunes</a>&#160;and&#160;<a rel="NOFOLLOW" rel="noreferrer noopener" href="https://open.spotify.com/show/5YZ0iBx5uwjbqRWeR7bHcQ?si=41x7hihbSAuQ21YbII-CDQ&#38;dl_branch=1" target="_blank">Spotify</a>. Or, check us out on&#160;<a rel="NOFOLLOW" rel="noreferrer noopener" href="https://podcasts.google.com/feed/aHR0cHM6Ly9mZWVkcy5mZWVkYmxpdHouY29tL3RoZXNlY3VyaXR5bGVkZ2Vy" target="_blank">Google Podcasts</a>,&#160;<a rel="NOFOLLOW" href="https://www.stitcher.com/podcast/the-security-ledger-4/the-security-ledger-podcast">Stitcher</a>,&#160;<a rel="NOFOLLOW" href="https://radiopublic.com/the-security-ledger-WDR2Z9">Radio Public</a>&#160;and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to&#160;<a rel="NOFOLLOW" href="http://securityledger.com/subscribe">securityledger.com/subscribe</a>&#160;to get notified whenever a new podcast is posted.&#160;<br />
<br />
<br />
<br />
[<a rel="NOFOLLOW" href="https://content.blubrry.com/the_security_ledger_podcasts/Episode_228_CISAs_Eric_Goldstein_on_being_everyones_friend_in_cyber.mp3" target="_blank" rel="noreferrer noopener">MP3</a>]<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
October is the 18th annual <a rel="NOFOLLOW" rel="noreferrer noopener" href="https://www.cisa.gov/cybersecurity-awareness-month" target="_blank">Cybersecurity Awareness Month</a> &#8211; a month dedicated to educating the public and the private sector about cyber risks. What better time, then, to check in with our friends at CISA, the Cybersecurity and Infrastructure Security Agency.&#160;<br />
<br />
<br />
<br />
CISA: A Different Kind of Agency<br />
<br />
<br />
<br />
Eric Goldstein (CISA)<br />
<br />
<br />
<br />
As the U.S. government’s newest agency and the tip of the spear for government response to cyber risks and cyber threats, CISA has its hands full. The agency is responsible for coordinating and informing the cybersecurity practices of the federal government, which employs more than 4 million Americans and has a budget of close to $5 trillion. It also is the go-to for cybersecurity intelligence and security services for state and local governments. The agency offers a series of “<a rel="NOFOLLOW" href="https://www.cisa.gov/cyber-hygiene-services">cyber hygiene services</a>” that local and state governments can use to interrogate their infrastructure. CISA also helps coordinate with the private sector around emerging threats, such as<a rel="NOFOLLOW" rel="noreferrer noopener" href="https://us-cert.cisa.gov/ncas/alerts/aa21-131a" target="_blank"> ransomware gangs</a> and the hack of key providers like <a rel="NOFOLLOW" href="https://www.cisa.gov/news/2020/12/13/cisa-issues-emergency-directive-mitigate-compromise-solarwinds-orion-network">SolarWinds</a>, <a rel="NOFOLLOW" rel="noreferrer noopener" href="https://us-cert.cisa.gov/kaseya-ransomware-attack" target="_blank">Kaseya</a>, the Colonial pipeline and more.&#160;<br />
<br />
<br />
<br />
CISA executives are quick to point out that the agency is not a regulator nor is it law enforcement. Indeed: CISA is “a different kind of agency:” less bureaucratic, more agile and more willing to embrace technologic change. CISA’s most important objective is to be a friend to the agencies and organizations that it serves: involving itself in cyber incident response not to assign blame or mete out punishment,]]></itunes:summary>
      <itunes:author xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">Paul F. Roberts</itunes:author>
      <itunes:duration xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">37:44</itunes:duration>
      <rawvoice:embed xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/">&lt;iframe src="https://player.blubrry.com/?media_url=https%3A%2F%2Fmedia.blubrry.com%2Fthe_security_ledger_podcasts%2Fcontent.blubrry.com%2Fthe_security_ledger_podcasts%2FEpisode_228_CISAs_Eric_Goldstein_on_being_everyones_friend_in_cyber.mp3&amp;amp;podcast_link=https%3A%2F%2Fsecurityledger.com%2F2021%2F10%2Fepisode-228-cisas-eric-goldstein-and-the-challenge-of-being-everyones-friend-in-cyber%2F#darkOrLight-light&amp;shownotes-ffffff&amp;shownotesBackground-444444&amp;download-ffffff&amp;downloadBackground-003366&amp;subscribe-ffffff&amp;subscribeBackground-fb8c00&amp;share-ffffff&amp;shareBackground-1976d2" scrolling="no" width="100%" height="138px" frameborder="0" id="blubrryplayer-8" class="blubrryplayer" title="Blubrry Podcast Player"&gt;&lt;/iframe&gt;</rawvoice:embed>
      <post-id xmlns="com-wordpress:feed-additions:1">476624</post-id>
      <feedburner:origEnclosureLink xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">https://media.blubrry.com/the_security_ledger_podcasts/content.blubrry.com/the_security_ledger_podcasts/Episode_228_CISAs_Eric_Goldstein_on_being_everyones_friend_in_cyber.mp3</feedburner:origEnclosureLink>
      <description>&lt;p&gt;Eric Goldstein, Executive Assistant Director for Cybersecurity for the Cybersecurity and Infrastructure Security Agency (CISA), says the agency is all about helping companies and local government to keep hackers at bay. But are organizations ready to ask for help? &lt;/p&gt;
&lt;p&gt;The post &lt;a rel="NOFOLLOW" href="https://feeds.feedblitz.com/~/670200030/_/thesecurityledger~Episode-CISA%e2%80%99s-Eric-Goldstein-on-being-Everyone%e2%80%99s-Friend-in-Cyber/"&gt;Episode 228: CISA’s Eric Goldstein on being Everyone’s Friend in Cyber&lt;/a&gt;...&lt;/p&gt;&lt;p style="clear:left"&gt;&lt;span class="fbz_teasertext"&gt;&lt;a href="https://feeds.feedblitz.com/~/670200030/_/thesecurityledger"&gt;&lt;b&gt;Read the whole entry...&lt;/b&gt;&lt;/a&gt;&amp;#160;&lt;!-- _!fbztxtlnk!_ https://feeds.feedblitz.com/~/670200030/_/thesecurityledger --&gt;&lt;b&gt;&amp;#187;&lt;/b&gt;&lt;/p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="fbz_enclosure" style="clear:left"&gt;&lt;audio controls="controls" style="display:block;padding:0.5em 0;max-width:100%;"&gt;&lt;source src="https://feeds.feedblitz.com/-/670200028/_/thesecurityledger.mp3"&gt;Click the icon below to listen.&lt;/audio&gt;&lt;a href="https://feeds.feedblitz.com/-/670200028/_/thesecurityledger.mp3" title="Play audio"&gt;&lt;img border="0" width="40" height="40" src="https://assets.feedblitz.com/i/podplay.png"/&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/11/episode-229-bugcrowds-casey-ellis-on-whats-hot-in-bug-hunting/"&gt;Episode 229: BugCrowd&amp;#x2019;s Casey Ellis On What&amp;#x2019;s Hot In Bug Hunting&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/episode-227-whats-fueling-cyber-attacks-on-agriculture/"&gt;Episode 227: What&amp;#x2019;s Fueling Cyber Attacks on Agriculture ?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/spotlight-operationalizing-mdr-with-pondurance-ciso-dustin-hutchison/"&gt;Spotlight: Operationalizing MDR with Pondurance CISO Dustin Hutchison&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
      <content:encoded>&lt;p&gt;Eric Goldstein, Executive Assistant Director for Cybersecurity for the Cybersecurity and Infrastructure Security Agency (CISA), says the agency is all about helping companies and local government to keep hackers at bay. But are organizations ready to ask for help? &lt;/p&gt;
&lt;p&gt;The post &lt;a rel="nofollow" href="https://feeds.feedblitz.com/~/t/0/_/thesecurityledger/~https://securityledger.com/2021/10/episode-228-cisas-eric-goldstein-and-the-challenge-of-being-everyones-friend-in-cyber/"&gt;Episode 228: CISA’s Eric Goldstein on being Everyone’s Friend in Cyber&lt;/a&gt;...&lt;/p&gt;&lt;p style="clear:left"&gt;&lt;span class="fbz_teasertext"&gt;&lt;a href="https://feeds.feedblitz.com/~/670200030/_/thesecurityledger"&gt;&lt;b&gt;Read the whole entry...&lt;/b&gt;&lt;/a&gt;&amp;#160;&lt;!-- _!fbztxtlnk!_ https://feeds.feedblitz.com/~/670200030/_/thesecurityledger --&gt;&lt;b&gt;&amp;#187;&lt;/b&gt;&lt;/p&gt;&lt;/span&gt;&lt;Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.feedblitz.com/~/i/670200030/_/thesecurityledger"&gt;
&lt;/p&gt;&lt;div class="fbz_enclosure" style="clear:left"&gt;&lt;audio controls="controls" style="display:block;padding:0.5em 0;max-width:100%;"&gt;&lt;source src="https://feeds.feedblitz.com/-/670200028/_/thesecurityledger.mp3"&gt;Click the icon below to listen.&lt;/audio&gt;&lt;a href="https://feeds.feedblitz.com/-/670200028/_/thesecurityledger.mp3" title="Play audio"&gt;&lt;img border="0" width="40" height="40" src="https://assets.feedblitz.com/i/podplay.png"/&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h3 style="clear:left;padding-top:10px"&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/11/episode-229-bugcrowds-casey-ellis-on-whats-hot-in-bug-hunting/"&gt;Episode 229: BugCrowd&amp;#x2019;s Casey Ellis On What&amp;#x2019;s Hot In Bug Hunting&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/episode-227-whats-fueling-cyber-attacks-on-agriculture/"&gt;Episode 227: What&amp;#x2019;s Fueling Cyber Attacks on Agriculture ?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel="NOFOLLOW" href="https://securityledger.com/2021/10/spotlight-operationalizing-mdr-with-pondurance-ciso-dustin-hutchison/"&gt;Spotlight: Operationalizing MDR with Pondurance CISO Dustin Hutchison&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded>
      <enclosure url="https://feeds.feedblitz.com/-/670200028/_/thesecurityledger.mp3" length="54340327" type="audio/mpeg" />
      <category>CISA</category>
      <category>Event</category>
      <category>Government</category>
      <category>Interview</category>
      <category>local government</category>
      <category>National Cybersecurity Awareness Month</category>
      <category>Podcasts</category>
      <category>ransomware</category>
      <category>Spotlight</category>
      <category>Threats</category>
      <category>critical infrastructure</category>
      <category>hacks</category>
      <category>podcast</category>
      <category>trends</category>
      <pubDate>Mon, 18 Oct 2021 20:01:19 GMT</pubDate>
      <comments>https://feeds.feedblitz.com/~/670200030/_/thesecurityledger~Episode-CISA%e2%80%99s-Eric-Goldstein-on-being-Everyone%e2%80%99s-Friend-in-Cyber/#comments</comments>
      <guid isPermaLink="false">https://securityledger.com/?p=476624</guid>
      <dc:creator>Paul Roberts</dc:creator>
      <dc:date>2021-10-18T20:01:19Z</dc:date>
    </item>
    <item>
      <title>Hackers Can Now Bypass PIN Codes on Mastercard and Maestro Contactless Cards</title>
      <link>https://news.softpedia.com/news/hackers-can-now-bypass-pin-codes-on-mastercard-and-maestro-contactless-cards-533911.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/hackers-can-now-bypass-pin-codes-on-mastercard-and-maestro-contactless-cards-533911.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/hackers-can-now-bypass-pin-codes-on-mastercard-and-maestro-contactless-cards-533911.jpg" />
      <description>Contacless Mastercard and Maestro PINs can be bypasses due to a new vulnerability discovered by Swiss College of Engineering in Zurich, according to Cybersecurity News. 

The key aspect of the flaw is that it allows thieves to use a hacked Mastercard or Maestro card to make contactless payments without having to input the PIN to complete the transaction, if properly exploited.

Properly in this case entails first installing dedicated software on two Android smartphones. One device is used to simulate a point of sale terminal being installed, while the other acts as a card emulator that allows the modified transaction information to be transmitted to a real point-of-sale device. Once the card initiates a transaction, it reveals all related information.

To avert further attacks, security experts will not reveal the app in question 

Experts from ETH Zu...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/hackers-can-now-bypass-pin-codes-on-mastercard-and-maestro-contactless-cards-533911.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;Contacless Mastercard and Maestro PINs can be bypasses due to a new vulnerability discovered by Swiss College of Engineering in Zurich, according to &lt;a href="https://cybersecuritynews.com/new-vulnerability-in-mastercard-maestro/" target="_blank"&gt;Cybersecurity News&lt;/a&gt;. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
The key aspect of the flaw is that it allows thieves to use a hacked Mastercard or Maestro card to make contactless payments without having to input the PIN to complete the transaction, if properly exploited.&lt;br /&gt;
&lt;br /&gt;
Properly in this case entails first installing dedicated software on two Android smartphones. One device is used to simulate a point of sale terminal being installed, while the other acts as a card emulator that allows the modified transaction information to be transmitted to a real point-of-sale device. Once the card initiates a transaction, it reveals all related information.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;To avert further attacks, security experts will not reveal the app in question &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Experts from ETH Zu... (&lt;a href="https://news.softpedia.com/news/hackers-can-now-bypass-pin-codes-on-mastercard-and-maestro-contactless-cards-533911.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Tue, 31 Aug 2021 15:15:20 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/hackers-can-now-bypass-pin-codes-on-mastercard-and-maestro-contactless-cards-533911.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-31T15:15:20Z</dc:date>
    </item>
    <item>
      <title>Google, Microsoft To Invest $30B in Cybersecurity</title>
      <link>https://news.softpedia.com/news/google-microsoft-to-invest-30b-in-cybersecurity-533910.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/google-microsoft-to-invest-30b-in-cybersecurity-533910.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/google-microsoft-to-invest-30b-in-cybersecurity-533910.jpg" />
      <description>Following sophisticated cyberattacks that targeted critical infrastructure, organizations and governments around the world, Microsoft, Amazon, Apple, IBM and Google pledged to invest a total of $30 billion in cybersecurity advances over the next 5 years, according to The Hacker News.  

US plans to develop a framework to improve the supply chain technologies and broaden CISA's role in safeguarding natural gas pipelines. A meeting was held in this sense at the While House that included top representatives from various US companies who agreed to help improve cybersecurity.

The pledges come following repeated high-profile cyberattacks on SolarWinds, Microsoft, Colonial Pipeline,</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/google-microsoft-to-invest-30b-in-cybersecurity-533910.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;Following sophisticated cyberattacks that targeted critical infrastructure, organizations and governments around the world, Microsoft, Amazon, Apple, IBM and Google pledged to invest a total of $30 billion in cybersecurity advances over the next 5 years, according to &lt;a href="https://thehackernews.com/2021/08/microsoft-google-to-invest-30-billion.html" target="_blank"&gt;The Hacker News&lt;/a&gt;.  &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
US plans to develop a framework to improve the supply chain technologies and broaden CISA's role in safeguarding natural gas pipelines. A meeting was held in this sense at the While House that included top representatives from various US companies who agreed to help improve cybersecurity.&lt;br /&gt;
&lt;br /&gt;
The pledges come following repeated high-profile cyberattacks on SolarWinds, Microsoft, &lt;a href="https://news.softpedia.com/news/oil-rises-1-after-a-cyberattack-forces-the-shutdown-of-a-key-us-fuel-pipeline-532857.shtml" target="_blank"&gt;Colonial Pipeline&lt;/a&gt;, &lt;a href="https://news.softpedia.com... (&lt;a href="https://news.softpedia.com/news/google-microsoft-to-invest-30b-in-cybersecurity-533910.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Tue, 31 Aug 2021 14:58:00 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/google-microsoft-to-invest-30b-in-cybersecurity-533910.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-31T14:58:00Z</dc:date>
    </item>
    <item>
      <title>Microsoft Warns of Widespread Open Redirects Phishing Attacks</title>
      <link>https://news.softpedia.com/news/microsoft-warns-of-widespread-open-redirects-phishing-attacks-533909.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/microsoft-warns-of-widespread-open-redirects-phishing-attacks-533909.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/microsoft-warns-of-widespread-open-redirects-phishing-attacks-533909.jpg" />
      <description>Microsoft issued a warning about a huge phishing campaign that uses open email links to steal credentials, according to The Hacker News. 

An old idiom advises us to work smart, not hard and nobody applies it better than modern hackers. Using something as common as URLs, threat actors manage to trick numerous users into introducing sensitive information that could grant access to an organization's network, steal credit card information or personal data that can be used for blackmailing. Nowadays, some manage to perfect their campaigns to the point where they are not even detected by advanced and up-to-date anti-malware solutions.

Microsoft 365 Defender Threat Intelligence Team explained in a report "Attackers co...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/microsoft-warns-of-widespread-open-redirects-phishing-attacks-533909.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;Microsoft issued a warning about a huge phishing campaign that uses open email links to steal credentials, according to &lt;a href="https://thehackernews.com/2021/08/microsoft-warns-of-widespread-phishing.html" target="_blank"&gt;The Hacker News&lt;/a&gt;. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
An old idiom advises us to work smart, not hard and nobody applies it better than modern hackers. Using something as common as URLs, threat actors manage to trick numerous users into introducing sensitive information that could grant access to an organization's network, steal credit card information or personal data that can be used for blackmailing. Nowadays, some manage to perfect their campaigns to the point where they are not even detected by advanced and up-to-date anti-malware solutions.&lt;br /&gt;
&lt;br /&gt;
Microsoft 365 Defender Threat Intelligence Team explained in a &lt;a href="https://www.microsoft.com/security/blog/2021/08/26/widespread-credential-phishing-campaign-abuses-open-redirector-links/" target="_blank"&gt;report&lt;/a&gt; "Attackers co... (&lt;a href="https://news.softpedia.com/news/microsoft-warns-of-widespread-open-redirects-phishing-attacks-533909.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Tue, 31 Aug 2021 14:43:59 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/microsoft-warns-of-widespread-open-redirects-phishing-attacks-533909.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-31T14:43:59Z</dc:date>
    </item>
    <item>
      <title>Legal Consequences Possible by Cybersecurity Standards Non-Compliance</title>
      <link>https://news.softpedia.com/news/legal-consequences-possible-by-cybersecurity-standards-non-compliance-533908.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/legal-consequences-possible-by-cybersecurity-standards-non-compliance-533908.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/legal-consequences-possible-by-cybersecurity-standards-non-compliance-533908.jpg" />
      <description>With an average cost of a data breach reaching an all-time high of $4.24 million, still some companies fail to see the full picture and don't meet modern cybersecurity standards, according to Tripwire.  

Despite the fact that online threats are increasing on a daily basis, numerous firms fail to recognize the importance of proper cybersecurity. Interestingly enough, many companies are not aware that they are bound by state, industry, and international laws. Although there is no uniform national or global cybersecurity law in place, companies that fail to meet certain legislation can face legal consequences.

As cybersecurity becomes more of a serious concern, the need for online defense is starting to worry more governments around the world. Aside from the potential data loss, companies that...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/legal-consequences-possible-by-cybersecurity-standards-non-compliance-533908.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;With an average cost of a data breach reaching an all-time high of $4.24 million, still some companies fail to see the full picture and don't meet modern cybersecurity standards, according to &lt;a href="https://www.tripwire.com/state-of-security/regulatory-compliance/failing-to-meet-cybersecurity-standards-can-have-legal-consequences-for-companies/" target="_blank"&gt;Tripwire&lt;/a&gt;.  &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Despite the fact that online threats are increasing on a daily basis, numerous firms fail to recognize the importance of proper cybersecurity. Interestingly enough, many companies are not aware that they are bound by state, industry, and international laws. Although there is no uniform national or global cybersecurity law in place, companies that fail to meet certain legislation can face legal consequences.&lt;br /&gt;
&lt;br /&gt;
As cybersecurity becomes more of a serious concern, the need for online defense is starting to worry more governments around the world. Aside from the potential data loss, companies that... (&lt;a href="https://news.softpedia.com/news/legal-consequences-possible-by-cybersecurity-standards-non-compliance-533908.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Tue, 31 Aug 2021 14:27:41 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/legal-consequences-possible-by-cybersecurity-standards-non-compliance-533908.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-31T14:27:41Z</dc:date>
    </item>
    <item>
      <title>Critical Cosmos Database Flaw Affecting Microsoft Azure Customers</title>
      <link>https://news.softpedia.com/news/critical-cosmos-database-flaw-affecting-microsoft-azure-customers-533894.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/critical-cosmos-database-flaw-affecting-microsoft-azure-customers-533894.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/critical-cosmos-database-flaw-affecting-microsoft-azure-customers-533894.jpg" />
      <description>Microsoft sent out a warning to thousands of cloud computing customers regarding threat actors that can view, modify, or even delete master databases if they gain access to their systems, according to Reuters.

Wiz announced that Microsoft Azure's flagship Cosmos database contain a vulnerability that allows access to keys that control access to the databases of hundreds of companies. Unable to update those keys itself, Microsoft sent an email to its customers Thursday asking them to create new keys. The software giant compensated Wiz with $40,000 in cash for discovering and reporting the security flaw.

Microsoft said, "Microsoft recently became aware of a vulnerability in Azure Cosmos DB that could potentially allow a user to gain access to another customer's resources by using the account's primary read-w...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/critical-cosmos-database-flaw-affecting-microsoft-azure-customers-533894.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;Microsoft sent out a warning to thousands of cloud computing customers regarding threat actors that can view, modify, or even delete master databases if they gain access to their systems, according to &lt;a href="https://www.reuters.com/technology/exclusive-microsoft-warns-thousands-cloud-customers-exposed-databases-emails-2021-08-26/" target="_blank"&gt;Reuters&lt;/a&gt;.&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Wiz announced that Microsoft Azure's flagship Cosmos database contain a vulnerability that allows access to keys that control access to the databases of hundreds of companies. Unable to update those keys itself, Microsoft sent an email to its customers Thursday asking them to create new keys.&lt;em&gt; &lt;/em&gt;The software giant compensated Wiz with $40,000 in cash for discovering and reporting the security flaw.&lt;br /&gt;
&lt;br /&gt;
Microsoft said, "Microsoft recently became aware of a vulnerability in Azure Cosmos DB that could potentially allow a user to gain access to another customer's resources by using the account's primary read-w... (&lt;a href="https://news.softpedia.com/news/critical-cosmos-database-flaw-affecting-microsoft-azure-customers-533894.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Tue, 31 Aug 2021 14:02:30 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/critical-cosmos-database-flaw-affecting-microsoft-azure-customers-533894.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-31T14:02:30Z</dc:date>
    </item>
    <item>
      <title>Chinese Developers Reveal Android Gamers' Data</title>
      <link>https://news.softpedia.com/news/chinese-developers-reveal-android-gamers-data-533891.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/chinese-developers-reveal-android-gamers-data-533891.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/chinese-developers-reveal-android-gamers-data-533891.jpg" />
      <description>A vpnMentor investigation found that a 134 GB server owned by EskyFun is exposed and user data was leaked for game titles such as Metamorph M, The Three Kingdoms Legend, Adventure Story, Rainbow Story, and Fantasy MMORPG.

The aforementioned games were downloaded 1.6 million times, whereas the leaked information had more than 365 million records. An intriguing aspect is that developers increased the amount of analytics, monitoring and authorization options available for the games, some needing more permissions even before they were installed.

Data disclosed includes IP and IMEI numbers, mobile device event logs, device information, phone numbers, EskyFun network passwords, current operating system, rooted or otherwise rooted phones, player acquisition and transaction reports, mailing, and support requests. Various data points were also used to identify profile individuals as well as tw...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/chinese-developers-reveal-android-gamers-data-533891.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;A &lt;a href="https://www.vpnmentor.com/blog/report-eskyfun-leak/" target="_blank"&gt;vpnMentor&lt;/a&gt; investigation found that a 134 GB server owned by EskyFun is exposed and user data was leaked for game titles such as Metamorph M, The Three Kingdoms Legend, Adventure Story, Rainbow Story, and Fantasy MMORPG.&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
The aforementioned games were downloaded 1.6 million times, whereas the leaked information had more than 365 million records. An intriguing aspect is that developers increased the amount of analytics, monitoring and authorization options available for the games, some needing more permissions even before they were installed.&lt;br /&gt;
&lt;br /&gt;
Data disclosed includes IP and IMEI numbers, mobile device event logs, device information, phone numbers, EskyFun network passwords, current operating system, rooted or otherwise rooted phones, player acquisition and transaction reports, mailing, and support requests. Various data points were also used to identify profile individuals as well as tw... (&lt;a href="https://news.softpedia.com/news/chinese-developers-reveal-android-gamers-data-533891.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Tue, 31 Aug 2021 13:57:42 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/chinese-developers-reveal-android-gamers-data-533891.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-31T13:57:42Z</dc:date>
    </item>
    <item>
      <title>Kaspersky: Kanye's Upcoming Album is a Scam Magnet</title>
      <link>https://news.softpedia.com/news/kaspersky-kanye-s-upcoming-album-is-a-scam-magnet-533889.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/kaspersky-kanye-s-upcoming-album-is-a-scam-magnet-533889.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/kaspersky-kanye-s-upcoming-album-is-a-scam-magnet-533889.jpg" />
      <description>Cybercriminals are launching a new scam to take advantage of the release of Kanye West's Donda album by distributing malicious fake downloads on the Internet, according to Tech Republic.

Cybersecurity firm Kaspersky proactively studied the event to see if threat actors were spreading any malware across the Internet. They emphasized that one of the scams is to target the release of highly anticipated media (movies, music), as they can place the malicious code in fake files that can be easily downloaded.

This particular scam attempt involves the uploading of fake malicious files to the Internet that are similar to those that were identified prior to the introduction of Black Widow. Kanye's fans are given a link to download the album and then asked to participate in a survey to confirm they are not robots. Afterwards, customers are redirected to a...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/kaspersky-kanye-s-upcoming-album-is-a-scam-magnet-533889.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;Cybercriminals are launching a new scam to take advantage of the release of Kanye West's Donda album by distributing malicious fake downloads on the Internet, according to &lt;a href="https://www.techrepublic.com/article/kanyes-upcoming-album-is-a-scam-magnet-kaspersky-finds/" target="_blank"&gt;Tech Republic&lt;/a&gt;.&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Cybersecurity firm Kaspersky proactively studied the event to see if threat actors were spreading any malware across the Internet. They emphasized that one of the scams is to target the release of highly anticipated media (movies, music), as they can place the malicious code in fake files that can be easily downloaded.&lt;br /&gt;
&lt;br /&gt;
This particular scam attempt involves the uploading of fake malicious files to the Internet that are similar to those that were identified prior to the introduction of Black Widow. Kanye's fans are given a link to download the album and then asked to participate in a survey to confirm they are not robots. Afterwards, customers are redirected to a... (&lt;a href="https://news.softpedia.com/news/kaspersky-kanye-s-upcoming-album-is-a-scam-magnet-533889.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Tue, 31 Aug 2021 13:41:17 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/kaspersky-kanye-s-upcoming-album-is-a-scam-magnet-533889.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-31T13:41:17Z</dc:date>
    </item>
    <item>
      <title>Work from Home Increased Worldwide Phishing Attacks</title>
      <link>https://news.softpedia.com/news/work-from-home-increased-worldwide-phishing-attacks-533890.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/work-from-home-increased-worldwide-phishing-attacks-533890.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/work-from-home-increased-worldwide-phishing-attacks-533890.jpg" />
      <description>Over the course of September 2019 to April 2021, Palo Alto Network's Unit 42 monitored firewall traffic and phishing sites detected by URL filters. The number of new phishing pages per week increased significantly when individuals began working from home. 

Threat actors improved and intensified their phishing attacks by exploiting remote work environments where employees were not protected by corporate firewalls. Cybersecurity experts noticed a sudden and significant drop in traffic between March and April 2020, when COVID began spreading across the United States, forcing companies to switch to remote work. 

Education and high-tech industries saw significant declines in traffic during this period, with the latter having the steepest drop: education (a 46% drop), most likely due to school closures, and high-tech (a 35% drop), probably because more employees starting working from home...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/work-from-home-increased-worldwide-phishing-attacks-533890.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;Over the course of September 2019 to April 2021, &lt;a href="https://unit42.paloaltonetworks.com/phishing-attacks/" target="_blank"&gt;Palo Alto Network's Unit 42&lt;/a&gt; monitored firewall traffic and phishing sites detected by URL filters. The number of new phishing pages per week increased significantly when individuals began working from home. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Threat actors improved and intensified their phishing attacks by exploiting remote work environments where employees were not protected by corporate firewalls. Cybersecurity experts noticed a sudden and significant drop in traffic between March and April 2020, when COVID began spreading across the United States, forcing companies to switch to remote work. &lt;br /&gt;
&lt;br /&gt;
Education and high-tech industries saw significant declines in traffic during this period, with the latter having the steepest drop: education (a 46% drop), most likely due to school closures, and high-tech (a 35% drop), probably because more employees starting working from home... (&lt;a href="https://news.softpedia.com/news/work-from-home-increased-worldwide-phishing-attacks-533890.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Sat, 28 Aug 2021 05:40:47 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/work-from-home-increased-worldwide-phishing-attacks-533890.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-28T05:40:47Z</dc:date>
    </item>
    <item>
      <title>Kaseya Patches New 0-Day Vulnerabilities Affecting Unitrends Servers</title>
      <link>https://news.softpedia.com/news/kaseya-patches-new-0-day-vulnerabilities-affecting-unitrends-servers-533893.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/kaseya-patches-new-0-day-vulnerabilities-affecting-unitrends-servers-533893.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/kaseya-patches-new-0-day-vulnerabilities-affecting-unitrends-servers-533893.jpg" />
      <description>Two zero-day vulnerabilities affecting Unitrends backup and continuity service have been patches by Kaseya recently, according to The Hacker News. 

Dutch Institute for Vulnerability Disclosure (DIVD) informed that the provider of IT infrastructure management solutions has solved server software bugs 10.5.5-2 reported on August 12. Both vulnerabilities are part of a trio of flaws discovered and reported on July 3, 2021. The issues encompass both an authenticated vulnerability to remote code execution and a privilege escalation fault on Unitrends servers from the read-only user to the administrator.

Users of unpatched software should avoid connecting the affected servers to the Internet 

A previously unknown client vulnerability in Kaseya Unitrends has not yet been patched. Then again, the company issues some firewall rules recommendations to...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/kaseya-patches-new-0-day-vulnerabilities-affecting-unitrends-servers-533893.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;Two zero-day vulnerabilities affecting Unitrends backup and continuity service have been patches by Kaseya recently, according to &lt;a href="https://thehackernews.com/2021/08/kaseya-issues-patches-for-two-new-0-day.html" target="_blank"&gt;The Hacker News&lt;/a&gt;. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Dutch Institute for Vulnerability Disclosure (DIVD) informed that the provider of IT infrastructure management solutions has solved server software bugs 10.5.5-2 reported on August 12. Both vulnerabilities are part of a trio of flaws discovered and reported on July 3, 2021. The issues encompass both an authenticated vulnerability to remote code execution and a privilege escalation fault on Unitrends servers from the read-only user to the administrator.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Users of unpatched software should avoid connecting the affected servers to the Internet &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
A previously unknown client vulnerability in Kaseya Unitrends has not yet been patched. Then again, the company issues some firewall rules recommendations to... (&lt;a href="https://news.softpedia.com/news/kaseya-patches-new-0-day-vulnerabilities-affecting-unitrends-servers-533893.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Fri, 27 Aug 2021 11:00:03 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/kaseya-patches-new-0-day-vulnerabilities-affecting-unitrends-servers-533893.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-27T11:00:03Z</dc:date>
    </item>
    <item>
      <title>Engineering PCs Are Concerning Initial Access Vector in OT Attacks</title>
      <link>https://news.softpedia.com/news/engineering-pcs-are-concerning-initial-access-vector-in-ot-attacks-533892.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/engineering-pcs-are-concerning-initial-access-vector-in-ot-attacks-533892.png" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/engineering-pcs-are-concerning-initial-access-vector-in-ot-attacks-533892.png" />
      <description>A new report titled SANS 2021 OT/ICS Cybersecurity Report contains alarming information gathered from 480 individuals in various industries. Organizations that use operational technology (OT) and industrial control systems (ICS) are very concerned about cyber attacks. 

The findings highlight the need for businesses to improve the ability to anticipate and respond to emerging threats and opportunities. While many are taking precautions to reduce risks, they are unaware if the breaches already occurred within their organization. To summarize the findings:	Approximately 70% of respondents indicated that the risk to their operational technology environment was high or severe.	With many companies concerned about cyber risk in their operating environment, 48% of respondents did not know whether they had encountered a breach of o...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/engineering-pcs-are-concerning-initial-access-vector-in-ot-attacks-533892.png" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;A new report titled &lt;a href="https://www.nozominetworks.com/downloads/SANS-Survey-2021-OT-ICS-Cybersecurity-Nozomi-Networks.pdf" target="_blank"&gt;SANS 2021 OT/ICS Cybersecurity Report&lt;/a&gt; contains alarming information gathered from 480 individuals in various industries. Organizations that use operational technology (OT) and industrial control systems (ICS) are very concerned about cyber attacks. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
The findings highlight the need for businesses to improve the ability to anticipate and respond to emerging threats and opportunities. While many are taking precautions to reduce risks, they are unaware if the breaches already occurred within their organization. To summarize the findings:&lt;ul&gt;	&lt;li&gt;Approximately 70% of respondents indicated that the risk to their operational technology environment was high or severe.&lt;/li&gt;	&lt;li&gt;With many companies concerned about cyber risk in their operating environment, 48% of respondents did not know whether they had encountered a breach of o... (&lt;a href="https://news.softpedia.com/news/engineering-pcs-are-concerning-initial-access-vector-in-ot-attacks-533892.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Fri, 27 Aug 2021 10:46:00 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/engineering-pcs-are-concerning-initial-access-vector-in-ot-attacks-533892.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-27T10:46:00Z</dc:date>
    </item>
    <item>
      <title>Top Linux Vulnerabilities Exploited by Hackers</title>
      <link>https://news.softpedia.com/news/top-linux-vulnerabilities-exploited-by-hackers-533888.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/top-linux-vulnerabilities-exploited-by-hackers-533888.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/top-linux-vulnerabilities-exploited-by-hackers-533888.jpg" />
      <description>Linux-based machines that are directly connected to the Internet can be targets for attackers who can quickly push potentially dangerous web-based shells, ransomware, Trojans, and other malicious software, according to The Hacker News. 

Trend Micro produced a comprehensive analysis of the Linux threat landscape, highlighting the barriers and vulnerabilities that have plagued the operating system in the first half of the year. The information was gathered using honeypots, sensors and anonymous telemetry.

According to the company, which has detected about 15 million malware attacks targeting Linux-based cloud environments, ransomware and coin miners account for 54% of all malware, while web shells represent 29% of all recorded events. 

Researchers evaluated over 50 million events from 100,000 unique Linux servers and identified 15 separate vulnerabilities used in th...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/top-linux-vulnerabilities-exploited-by-hackers-533888.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;Linux-based machines that are directly connected to the Internet can be targets for attackers who can quickly push potentially dangerous web-based shells, ransomware, Trojans, and other malicious software, according to&lt;a href="https://thehackernews.com/2021/08/top-15-vulnerabilities-attackers.html" target="_blank"&gt; The Hacker News&lt;/a&gt;. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Trend Micro produced a comprehensive analysis of the Linux threat landscape, highlighting the barriers and vulnerabilities that have plagued the operating system in the first half of the year. The information was gathered using honeypots, sensors and anonymous telemetry.&lt;br /&gt;
&lt;br /&gt;
According to the company, which has detected about 15 million malware attacks targeting Linux-based cloud environments, ransomware and coin miners account for 54% of all malware, while web shells represent 29% of all recorded events. &lt;br /&gt;
&lt;br /&gt;
Researchers evaluated over 50 million events from 100,000 unique Linux servers and identified 15 separate vulnerabilities used in th... (&lt;a href="https://news.softpedia.com/news/top-linux-vulnerabilities-exploited-by-hackers-533888.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Thu, 26 Aug 2021 13:29:00 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/top-linux-vulnerabilities-exploited-by-hackers-533888.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-26T13:29:00Z</dc:date>
    </item>
    <item>
      <title>Personal Information of Entire Swiss Town Leaked Following Cyberattack</title>
      <link>https://news.softpedia.com/news/personal-information-of-entire-swiss-town-leaked-following-cyberattack-533887.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/personal-information-of-entire-swiss-town-leaked-following-cyberattack-533887.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/personal-information-of-entire-swiss-town-leaked-following-cyberattack-533887.jpg" />
      <description>Following reports of personal data leaked online from the entire population, a small Swiss town revealed that it had misjudged the seriousness of the cyber attack late in the day before, according to Security Week. 

Rolle, a small, lovely town on the beaches of Lake Geneva, acknowledged that it had been targeted by a ransomware attack and that sensitive information on some administrative systems had been compromised. The attack took place on May 30 and the city government said that only modest amounts of data were compromised at the time. Moreover, all information was restored from backup copies of the original files. However, according to an investigation published Wednesday by the French daily Le Temps, the attack was considerably larger.

Cybercriminals stole names, residences, and social security numbers

Le Temps cites an unidentified ...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/personal-information-of-entire-swiss-town-leaked-following-cyberattack-533887.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;Following reports of personal data leaked online from the entire population, a small Swiss town revealed that it had misjudged the seriousness of the cyber attack late in the day before, according to &lt;a href="https://www.securityweek.com/hack-exposes-personal-data-entire-swiss-town-report" target="_blank"&gt;Security Week&lt;/a&gt;. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Rolle, a small, lovely town on the beaches of Lake Geneva, acknowledged that it had been targeted by a ransomware attack and that sensitive information on some administrative systems had been compromised. The attack took place on May 30 and the city government said that only modest amounts of data were compromised at the time. Moreover, all information was restored from backup copies of the original files. However, according to an investigation published Wednesday by the French daily Le Temps, the attack was considerably larger.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Cybercriminals stole names, residences, and social security numbers&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Le Temps cites an unidentified ... (&lt;a href="https://news.softpedia.com/news/personal-information-of-entire-swiss-town-leaked-following-cyberattack-533887.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Thu, 26 Aug 2021 12:48:26 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/personal-information-of-entire-swiss-town-leaked-following-cyberattack-533887.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-26T12:48:26Z</dc:date>
    </item>
    <item>
      <title>Top IT Firms CEOs to Attend White House Cybersecurity Meeting</title>
      <link>https://news.softpedia.com/news/top-it-firms-ceos-to-attend-white-house-cybersecurity-meeting-533876.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/top-it-firms-ceos-to-attend-white-house-cybersecurity-meeting-533876.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/top-it-firms-ceos-to-attend-white-house-cybersecurity-meeting-533876.jpg" />
      <description>On Wednesday, President Joe Biden will meet with top executives from some of the country's largest technology and financial companies, as the White House seeks private sector backing for a unified cyber defense against emerging threats, according to MCU Times. 

The gathering comes amid an increase in ransomware attacks on critical infrastructure, extorting multi-million dollar payments from large corporations, and other illicit cyber operations linked to foreign hackers by US authorities. According to a senior government official, the purpose of the conversation is to identify the root causes of hostile cyber activity as well as ways in which the private sector may contribute to enhancing cybersecurity.

The President Biden proposed an infrastructure bill would provide about $1 trillion in cybersecurity subsidies to state, local and tribal governmen...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/top-it-firms-ceos-to-attend-white-house-cybersecurity-meeting-533876.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;On Wednesday, President Joe Biden will meet with top executives from some of the country's largest technology and financial companies, as the White House seeks private sector backing for a unified cyber defense against emerging threats, according to &lt;a href="https://mcutimes.com/amazon-apple-microsoft-ceos-come-to-the-white-house-what-to-expect/" target="_blank"&gt;MCU Times&lt;/a&gt;. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
The gathering comes amid an increase in ransomware attacks on critical infrastructure, extorting multi-million dollar payments from large corporations, and other illicit cyber operations linked to foreign hackers by US authorities. According to a senior government official, the purpose of the conversation is to identify the root causes of hostile cyber activity as well as ways in which the private sector may contribute to enhancing cybersecurity.&lt;br /&gt;
&lt;br /&gt;
The President Biden proposed an infrastructure bill would provide about $1 trillion in cybersecurity subsidies to state, local and tribal governmen... (&lt;a href="https://news.softpedia.com/news/top-it-firms-ceos-to-attend-white-house-cybersecurity-meeting-533876.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Thu, 26 Aug 2021 12:32:38 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/top-it-firms-ceos-to-attend-white-house-cybersecurity-meeting-533876.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-26T12:32:38Z</dc:date>
    </item>
    <item>
      <title>New SideWalk Backdoor Targeting U.S. Computer Retailers</title>
      <link>https://news.softpedia.com/news/new-sidewalk-backdoor-targeting-u-s-computer-retailers-533875.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/new-sidewalk-backdoor-targeting-u-s-computer-retailers-533875.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/new-sidewalk-backdoor-targeting-u-s-computer-retailers-533875.jpg" />
      <description>Chinese advanced persistent threat (APT) gangs have resumed their hacking activities, with one of the attacks targeting an American computer retailer using an unknown backdoor referred to as Sidewalk, according to The Hacker News. 

In a report, ESET Cybersecurity Researchers Mathieu Tartare and Thibaut Passilly describe the fresh backdoor as modular, allowing the dynamic loading of additional modules from specific control and command servers. The malware is also designed to target Cloudflare workers as C&amp;C servers and Google Docs as dead drop resolvers. 

Security researchers describe SideWalk as "responsible for reading the encrypted shellcode from disk, decrypting it and injecting it into a legitimate process using the process hollowing techniqu...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/new-sidewalk-backdoor-targeting-u-s-computer-retailers-533875.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;Chinese advanced persistent threat (APT) gangs have resumed their hacking activities, with one of the attacks targeting an American computer retailer using an unknown backdoor referred to as Sidewalk, according to &lt;a href="https://thehackernews.com/2021/08/new-sidewalk-backdoor-targets-us-based.html" target="_blank"&gt;The Hacker News&lt;/a&gt;. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
In a &lt;a href="https://www.welivesecurity.com/2021/08/24/sidewalk-may-be-as-dangerous-as-crosswalk/" target="_blank"&gt;report&lt;/a&gt;, ESET Cybersecurity Researchers Mathieu Tartare and Thibaut Passilly describe the fresh backdoor as modular, allowing the dynamic loading of additional modules from specific control and command servers. The malware is also designed to target Cloudflare workers as C&amp;C servers and Google Docs as dead drop resolvers. &lt;br /&gt;
&lt;br /&gt;
Security researchers describe SideWalk as "responsible for reading the encrypted shellcode from disk, decrypting it and injecting it into a legitimate process using the process hollowing techniqu... (&lt;a href="https://news.softpedia.com/news/new-sidewalk-backdoor-targeting-u-s-computer-retailers-533875.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Thu, 26 Aug 2021 11:31:55 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/new-sidewalk-backdoor-targeting-u-s-computer-retailers-533875.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-26T11:31:55Z</dc:date>
    </item>
    <item>
      <title>FluBot Malware Strikes Again</title>
      <link>https://news.softpedia.com/news/flubot-malware-strikes-again-533873.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/flubot-malware-strikes-again-533873.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/flubot-malware-strikes-again-533873.jpg" />
      <description>FluBot Android malware is back and already launched several attacks outside the regular geographical region of impact, according to Cyware. 

Recently conducted research into the FluBot banking malware has revealed an upsurge in the number of dangerous distribution pages in a variety of Australian, Polish, and German financial institutions.  

Numerous intriguing elements were incorporated by the threat actors in the new operations that now collected user credentials by overlaying several popular banking applications. The design of the malicious web pages is devised to disseminate text messages that appear to be voicemail notifications or shipment tracking information, but are actually scams. 

It is worth noting that the cybercriminals were able to accomplish all of this while remaining undetected during the infection process thanks to a Domain Generation Algorithm (D...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/flubot-malware-strikes-again-533873.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;FluBot Android malware is back and already launched several attacks outside the regular geographical region of impact, according to &lt;a href="https://cyware.com/news/resurgence-in-flubot-malware-attacks-f10f1ca6" target="_blank"&gt;Cyware&lt;/a&gt;. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Recently conducted research into the FluBot banking malware has revealed an upsurge in the number of dangerous distribution pages in a variety of Australian, Polish, and German financial institutions.  &lt;br /&gt;
&lt;br /&gt;
Numerous intriguing elements were incorporated by the threat actors in the new operations that now collected user credentials by overlaying several popular banking applications. The design of the malicious web pages is devised to disseminate text messages that appear to be voicemail notifications or shipment tracking information, but are actually scams. &lt;br /&gt;
&lt;br /&gt;
It is worth noting that the cybercriminals were able to accomplish all of this while remaining undetected during the infection process thanks to a Domain Generation Algorithm (D... (&lt;a href="https://news.softpedia.com/news/flubot-malware-strikes-again-533873.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Thu, 26 Aug 2021 11:28:17 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/flubot-malware-strikes-again-533873.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-26T11:28:17Z</dc:date>
    </item>
    <item>
      <title>Medical Data for 12,000 Patients Leaked Following Revere Health Attack</title>
      <link>https://news.softpedia.com/news/medical-data-for-12-000-patients-leaked-following-revere-health-attack-533870.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/medical-data-for-12-000-patients-leaked-following-revere-health-attack-533870.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/medical-data-for-12-000-patients-leaked-following-revere-health-attack-533870.jpg" />
      <description>A mistake by a health care worker resulted in the leaking of medical information of about 12,000 patients. The phishing attack took place on June 21 and lasted only 45 minutes, according to The Spectrum. 

While he breach exposed medical record numbers, birth dates, procedures, and insurance provider names, provider names, the two-month investigation determined that the breach posed a negligible risk to the patients affected. Moreover, Revere Health believes that the hacker is not attempting to publish the patient medical information, but rather is using the incident as a platform to conduct more sophisticated phishing email attacks against other employees. 

Bob Freeze, the director of marketing and communications, stated that the stolen data affected patients of the Heart of Dixie Cardiology Department in St. Georg...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/medical-data-for-12-000-patients-leaked-following-revere-health-attack-533870.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;A mistake by a health care worker resulted in the leaking of medical information of about 12,000 patients. The phishing attack took place on June 21 and lasted only 45 minutes, according to &lt;a href="https://eu.thespectrum.com/story/news/2021/08/23/phishing-attack-exposes-information-12-000-patients-st-george/8214230002/" target="_blank"&gt;The Spectrum&lt;/a&gt;. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
While he breach exposed medical record numbers, birth dates, procedures, and insurance provider names, provider names, the two-month investigation determined that the breach posed a negligible risk to the patients affected. Moreover, Revere Health believes that the hacker is not attempting to publish the patient medical information, but rather is using the incident as a platform to conduct more sophisticated phishing email attacks against other employees. &lt;br /&gt;
&lt;br /&gt;
Bob Freeze, the director of marketing and communications, stated that the stolen data affected patients of the Heart of Dixie Cardiology Department in St. Georg... (&lt;a href="https://news.softpedia.com/news/medical-data-for-12-000-patients-leaked-following-revere-health-attack-533870.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Thu, 26 Aug 2021 05:11:59 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/medical-data-for-12-000-patients-leaked-following-revere-health-attack-533870.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-26T05:11:59Z</dc:date>
    </item>
    <item>
      <title>38 Million Records Exposed from Microsoft Power Apps</title>
      <link>https://news.softpedia.com/news/38-million-records-exposed-from-microsoft-power-apps-533864.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/38-million-records-exposed-from-microsoft-power-apps-533864.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/38-million-records-exposed-from-microsoft-power-apps-533864.jpg" />
      <description>In an unexpected data leak, more than 38 million records from 47 organizations using Microsoft's gateway platform Power Apps were accidentally published online, according to The Hacker News. 

The unfortunate incident resulted in the leakage of sensitive information on servers of corporations such as Microsoft, J.B. Hunt, and American Airlines along with government agencies from Indiana, Maryland, and New York City.

Power Apps are mostly used for developing custom low-code applications for mobile devices as well as websites. The programs created by Microoft have a number of advantages, such as APIs that allow other applications to access data, templates as well as managing and collecting information and storage.

Key information that went missing: 

The misconfiguration of a port could lead to making the stored data public and this is what happened h...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/38-million-records-exposed-from-microsoft-power-apps-533864.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;In an unexpected data leak, more than 38 million records from 47 organizations using Microsoft's gateway platform Power Apps were accidentally published online, according to &lt;a href="https://thehackernews.com/2021/08/38-million-records-exposed-from.html" target="_blank"&gt;The Hacker News&lt;/a&gt;. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
The unfortunate incident resulted in the leakage of sensitive information on servers of corporations such as Microsoft, J.B. Hunt, and American Airlines along with government agencies from Indiana, Maryland, and New York City.&lt;br /&gt;
&lt;br /&gt;
Power Apps are mostly used for developing custom low-code applications for mobile devices as well as websites. The programs created by Microoft have a number of advantages, such as APIs that allow other applications to access data, templates as well as managing and collecting information and storage.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Key information that went missing: &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
The misconfiguration of a port could lead to making the stored data public and this is what happened h... (&lt;a href="https://news.softpedia.com/news/38-million-records-exposed-from-microsoft-power-apps-533864.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Thu, 26 Aug 2021 02:55:33 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/38-million-records-exposed-from-microsoft-power-apps-533864.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-26T02:55:33Z</dc:date>
    </item>
    <item>
      <title>Mr. White Returns All $610 Crypto Assets Stolen in Cyberattack</title>
      <link>https://news.softpedia.com/news/mr-white-returns-all-610-crypto-assets-stolen-in-cyberattack-533858.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/mr-white-returns-all-610-crypto-assets-stolen-in-cyberattack-533858.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/mr-white-returns-all-610-crypto-assets-stolen-in-cyberattack-533858.jpg" />
      <description>The hacker known as Mr. White found a way to resolve one of the biggest cryptocurrency thefts of all time, according to CNBC. 

Earlier this week, Poly Network, a decentralized financial network, announced that about $600 million in bitcoin had been stolen from its vaults due to a coding error. The sum was changed immediately to other cryptocurrencies, namely a total of $273 million in Ethereum tokens, $253 million in Binance Smart Chain tokens, and $85 million in USDC.

Surprisingly, the thief known as Mr. White Hat, began recovering assets almost shortly after the discovery and distributed t...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/mr-white-returns-all-610-crypto-assets-stolen-in-cyberattack-533858.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;The hacker known as &lt;a href="https://news.softpedia.com/news/hacker-has-job-offer-following-the-610m-crypto-heist-533817.shtml" target="_blank"&gt;Mr. White&lt;/a&gt; found a way to resolve one of the &lt;a href="https://news.softpedia.com/news/hackers-steal-over-600m-worth-of-crypto-from-poly-network-533748.shtml" target="_blank"&gt;biggest cryptocurrency thefts&lt;/a&gt; of all time, according to &lt;a href="https://www.cnbc.com/2021/08/23/poly-network-hacker-returns-remaining-cryptocurrency.html" target="_blank"&gt;CNBC&lt;/a&gt;. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Earlier this week, Poly Network, a decentralized financial network, announced that about $600 million in bitcoin had been stolen from its vaults due to a coding error. The sum was changed immediately to other cryptocurrencies, namely a total of $273 million in Ethereum tokens, $253 million in Binance Smart Chain tokens, and $85 million in USDC.&lt;br /&gt;
&lt;br /&gt;
Surprisingly, the thief known as Mr. White Hat, began recovering assets almost shortly after the discovery and distributed t... (&lt;a href="https://news.softpedia.com/news/mr-white-returns-all-610-crypto-assets-stolen-in-cyberattack-533858.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Tue, 24 Aug 2021 16:53:08 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/mr-white-returns-all-610-crypto-assets-stolen-in-cyberattack-533858.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-24T16:53:08Z</dc:date>
    </item>
    <item>
      <title>WhatsApp New Modified Version Installs Triada Trojan</title>
      <link>https://news.softpedia.com/news/new-modified-version-of-whatsapp-emerge-deploying-triada-trojan-533862.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/new-modified-version-of-whatsapp-emerge-deploying-triada-trojan-533862.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/new-modified-version-of-whatsapp-emerge-deploying-triada-trojan-533862.jpg" />
      <description>A customized version of the WhatsApp Messaging App for Android has been found to display full-screen advertising, register device users for unwanted premium subscriptions without their agreement and deliver dangerous payloads, says The Hacker News. 

Generally speaking, modifications of legitimate Android apps are launched to perform functions that were not originally intended. For instance, you can customize icons, disable video calls, add themes or hide features like Recently Seen with FMWhatsApp. Then again, not all mods are launched with good intentions and this is another case of why you should be wary of too-good-to-be-true free services.

The FMWhatsApp version discovered by</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/new-modified-version-of-whatsapp-emerge-deploying-triada-trojan-533862.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;A customized version of the &lt;a href="https://www.softpedia.com/get/Internet/Chat/Instant-Messaging/WhatsApp.shtml" target="_blank"&gt;WhatsApp&lt;/a&gt; Messaging App for Android has been found to display full-screen advertising, register device users for unwanted premium subscriptions without their agreement and deliver dangerous payloads, says &lt;a href="https://thehackernews.com/2021/08/modified-version-of-whatsapp-for.html" target="_blank"&gt;The Hacker News&lt;/a&gt;. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Generally speaking, modifications of legitimate Android apps are launched to perform functions that were not originally intended. For instance, you can customize icons, disable video calls, add themes or hide features like Recently Seen with FMWhatsApp. Then again, not all mods are launched with good intentions and this is another case of why you should be wary of too-good-to-be-true free services.&lt;br /&gt;
&lt;br /&gt;
The FMWhatsApp version discovered by &lt;a href="https://securelist.com/triada-trojan-in-whatsapp-mod/103679/" target="_b... (&lt;a href="https://news.softpedia.com/news/new-modified-version-of-whatsapp-emerge-deploying-triada-trojan-533862.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Tue, 24 Aug 2021 16:43:47 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/new-modified-version-of-whatsapp-emerge-deploying-triada-trojan-533862.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-24T16:43:47Z</dc:date>
    </item>
    <item>
      <title>Researchers Warn of 4 Emerging Ransomware Groups</title>
      <link>https://news.softpedia.com/news/researchers-warn-of-4-emerging-ransomware-groups-533866.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/researchers-warn-of-4-emerging-ransomware-groups-533866.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/researchers-warn-of-4-emerging-ransomware-groups-533866.jpg" />
      <description>Researchers identified 4 new ransomware gangs that are targeting businesses and key infrastructure, according to The Hacker News. 

Ransomware attacks nowadays did not only increase in frequency and intensity, but went beyond financial gain, posing a threat to the national security of firms, hospitals, schools, and governments worldwide. Palo Alto Networks' Unit 42 threat intelligence team notes "While the ransomware crisis appears poised to get worse before it gets better, the cast of cybercrime groups that cause the most damage is constantly changing".

While we did not hear too much of them lately compared to previous years, Unit 42 says this is just the calm before the storm. Let's explore the latest ransomware kits on the market and the groups behind them.

AvosLocker

AvosLocker is a late-June ransomware company that exploits press announce...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/researchers-warn-of-4-emerging-ransomware-groups-533866.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;Researchers identified 4 new ransomware gangs that are targeting businesses and key infrastructure, according to &lt;a href="https://thehackernews.com/2021/08/researchers-warn-of-4-new-ransomware.html" target="_blank"&gt;The Hacker News&lt;/a&gt;. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks nowadays did not only increase in frequency and intensity, but went beyond financial gain, posing a threat to the national security of firms, hospitals, schools, and governments worldwide. Palo Alto Networks' Unit 42 threat intelligence team notes "While the ransomware crisis appears poised to get worse before it gets better, the cast of cybercrime groups that cause the most damage is constantly changing".&lt;br /&gt;
&lt;br /&gt;
While we did not hear too much of them lately compared to previous years, Unit 42 says this is just the calm before the storm. Let's explore the latest ransomware kits on the market and the groups behind them.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;AvosLocker&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
AvosLocker is a late-June ransomware company that exploits press announce... (&lt;a href="https://news.softpedia.com/news/researchers-warn-of-4-emerging-ransomware-groups-533866.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Tue, 24 Aug 2021 16:14:00 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/researchers-warn-of-4-emerging-ransomware-groups-533866.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-24T16:14:00Z</dc:date>
    </item>
    <item>
      <title>Singapore and the U.S. Will Work More Closely on Cybersecurity</title>
      <link>https://news.softpedia.com/news/singapore-and-the-u-s-will-work-more-closely-on-cybersecurity-533849.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/singapore-and-the-u-s-will-work-more-closely-on-cybersecurity-533849.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/singapore-and-the-u-s-will-work-more-closely-on-cybersecurity-533849.jpg" />
      <description>Singapore and the U.S. signed several Memorandums of Understanding (MOUs) to expand their cybersecurity cooperation in areas such as defense, banking, and research and development, according to ZDNet. These activities include increased information sharing, team building, training and skills development. 

Three MOUs were signed on Monday during the US' three-day visit to Asia Vice President Kamala Harris. One was an agreement between Singapore and the U.S. Cyber Security and Infrastructure Security Agency (CISA) aimed at expanding the cybersecurity partnership beyond data sharing and exchange. Both government agencies will explore new areas of cooperation, such as important technological research and development. 	The first MOU will allow both partners to strengthen existing partnerships between the countries so that they are able to work clo...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/singapore-and-the-u-s-will-work-more-closely-on-cybersecurity-533849.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;Singapore and the U.S. signed several Memorandums of Understanding (MOUs) to expand their cybersecurity cooperation in areas such as defense, banking, and research and development, according to &lt;a href="https://www.zdnet.com/article/singapore-us-pledge-deeper-collaboration-in-cybersecurity/" target="_blank"&gt;ZDNet&lt;/a&gt;. These activities include increased information sharing, team building, training and skills development. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Three MOUs were signed on Monday during the US' three-day visit to Asia Vice President Kamala Harris. One was an agreement between Singapore and the U.S. Cyber Security and Infrastructure Security Agency (CISA) aimed at expanding the cybersecurity partnership beyond data sharing and exchange. Both government agencies will explore new areas of cooperation, such as important technological research and development. &lt;ul&gt;	&lt;li&gt;The first MOU will allow both partners to strengthen existing partnerships between the countries so that they are able to work clo... (&lt;a href="https://news.softpedia.com/news/singapore-and-the-u-s-will-work-more-closely-on-cybersecurity-533849.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Tue, 24 Aug 2021 15:15:26 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/singapore-and-the-u-s-will-work-more-closely-on-cybersecurity-533849.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-24T15:15:26Z</dc:date>
    </item>
    <item>
      <title>State Department Allegedly Hit by Cyberattack</title>
      <link>https://news.softpedia.com/news/state-department-allegedly-hit-by-cyberattack-533845.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/state-department-allegedly-hit-by-cyberattack-533845.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/state-department-allegedly-hit-by-cyberattack-533845.jpg" />
      <description>The Department of Defense's Cyber Command issued warnings about a possibly significant cyberattack against the United States Department of State that may have occurred in recent weeks.  

According to yesterday's report from Fox News, it is still unclear how much damage has been done following the security incident, who the perpetrator was and whether the operations of the institutions have been affected. Given the nature of the Department, the information cannot be divulged, making things more complicated.

A department spokesperson told Fox News, "The Department takes seriously its responsibility to safeguard its information and continuously takes steps to ensure information is protected" [...] "For security reasons, we are not in a position to discuss the nature or scope of any alleged cybersecurity incidents at this time".

T...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/state-department-allegedly-hit-by-cyberattack-533845.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;The Department of Defense's Cyber Command issued warnings about a possibly significant cyberattack against the United States Department of State that may have occurred in recent weeks.  &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
According to yesterday's report from &lt;a href="https://www.foxbusiness.com/politics/state-department-hit-with-cyberattack-in-possible-serious-breach" target="_blank"&gt;Fox News&lt;/a&gt;, it is still unclear how much damage has been done following the security incident, who the perpetrator was and whether the operations of the institutions have been affected. Given the nature of the Department, the information cannot be divulged, making things more complicated.&lt;br /&gt;
&lt;br /&gt;
A department spokesperson told Fox News, "The Department takes seriously its responsibility to safeguard its information and continuously takes steps to ensure information is protected" [...] "For security reasons, we are not in a position to discuss the nature or scope of any alleged cybersecurity incidents at this time".&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;T... (&lt;a href="https://news.softpedia.com/news/state-department-allegedly-hit-by-cyberattack-533845.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Mon, 23 Aug 2021 14:46:14 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/state-department-allegedly-hit-by-cyberattack-533845.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-23T14:46:14Z</dc:date>
    </item>
    <item>
      <title>T-Mobile Customers Sueing the Company Over Data Breach</title>
      <link>https://news.softpedia.com/news/t-mobile-customers-are-sueing-the-company-over-data-breach-533848.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/t-mobile-customers-are-sueing-the-company-over-data-breach-533848.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/t-mobile-customers-are-sueing-the-company-over-data-breach-533848.jpg" />
      <description>With each passing day, the fallout from T-Mobile's recent data breach grows more serious. An update released Friday suggests hacking firms unlawfully obtained the personal information of another 5.3 million postpaid customers, including names, addresses, birthdates, IMSIs, IMEIs, and phone numbers, according to Fox Business. 

The firm recently declared it discovered an additional 667,000 accessible user accounts that included addresses, phone numbers, customer names, and dates of birth. The latest figures put the total number of people affected by the security breach at more than 50 million, an increase from...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/t-mobile-customers-are-sueing-the-company-over-data-breach-533848.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;With each passing day, the fallout from T-Mobile's recent &lt;a href="https://news.softpedia.com/news/t-mobile-investigates-massive-data-breach-claims-533781.shtml" target="_blank"&gt;data breach&lt;/a&gt; grows more serious. An update released Friday suggests hacking firms unlawfully obtained the personal information of another 5.3 million postpaid customers, including names, addresses, birthdates, IMSIs, IMEIs, and phone numbers, according to &lt;a href="https://www.foxbusiness.com/technology/t-mobile-hit-with-class-action-lawsuits-over-data-breach" target="_blank"&gt;Fox Business&lt;/a&gt;. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
The firm recently &lt;a href="http://www.t-mobile.com/news/network/additional-information-regarding-2021-cyberattack-investigation"&gt;declared&lt;/a&gt; it discovered an additional 667,000 accessible user accounts that included addresses, phone numbers, customer names, and dates of birth. The latest figures put the total number of people affected by the security breach at more than 50 million, an increase from... (&lt;a href="https://news.softpedia.com/news/t-mobile-customers-are-sueing-the-company-over-data-breach-533848.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Mon, 23 Aug 2021 14:28:57 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/t-mobile-customers-are-sueing-the-company-over-data-breach-533848.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-23T14:28:57Z</dc:date>
    </item>
    <item>
      <title>Report: Cyberattacks on Education Increased by 29% Worldwide</title>
      <link>https://news.softpedia.com/news/report-cyberattacks-on-education-increased-by-29-worldwide-533846.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/report-cyberattacks-on-education-increased-by-29-worldwide-533846.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/report-cyberattacks-on-education-increased-by-29-worldwide-533846.jpg" />
      <description>Cybersecurity firm Check Point discovered disturbing statistics concerning the significant growth in the weekly number of cyber attacks directed against firms and organizations in the world of education, according to Times of Israel. 

Schools, colleges, and research institutions are among the organizations that have been targeted. In July 2021, there was an average of 1,739 attacks per organization per week, a 29% increase from the same month last year. The top 3 countries affected by the issue include:	India - average of 5,196 assaults and 29% increase from 2020	Italy - average of 5,016 assaults and 70% increase from 2020	Israel - average o...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/report-cyberattacks-on-education-increased-by-29-worldwide-533846.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;Cybersecurity firm &lt;a href="https://blog.checkpoint.com/2021/08/18/check-point-research-education-sector-sees-29-increase-in-attacks-against-organizations-globally/" target="_blank"&gt;Check Point&lt;/a&gt; discovered disturbing statistics concerning the significant growth in the weekly number of cyber attacks directed against firms and organizations in the world of education, according to &lt;a href="https://www.timesofisrael.com/education-sector-sees-29-global-increase-in-cyberattacks-check-point-reports/" target="_blank"&gt;Times of Israel&lt;/a&gt;. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Schools, colleges, and research institutions are among the organizations that have been targeted. In July 2021, there was an average of 1,739 attacks per organization per week, a 29% increase from the same month last year. The top 3 countries affected by the issue include:&lt;ul&gt;	&lt;li&gt;India - average of 5,196 assaults and 29% increase from 2020&lt;/li&gt;	&lt;li&gt;Italy - average of 5,016 assaults and 70% increase from 2020&lt;/li&gt;	&lt;li&gt;Israel - average o... (&lt;a href="https://news.softpedia.com/news/report-cyberattacks-on-education-increased-by-29-worldwide-533846.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Mon, 23 Aug 2021 14:15:52 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/report-cyberattacks-on-education-increased-by-29-worldwide-533846.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-23T14:15:52Z</dc:date>
    </item>
    <item>
      <title>Indra Group and Iran Railway Attacks May Be Related</title>
      <link>https://news.softpedia.com/news/research-shows-links-between-indra-group-and-iran-railway-attacks-533838.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/research-shows-links-between-indra-group-and-iran-railway-attacks-533838.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/research-shows-links-between-indra-group-and-iran-railway-attacks-533838.jpg" />
      <description>The cyberattack that crippled Iranian trains last month was recently attributed to the cybercriminal group Indra. The group is known for a series of attacks on several Syrian organizations using a wiper on the hacked networks, according to Cyware. 

As expected, Indra denies any involvement in the latest attack on Iran. Then again, a large body of evidence suggests that the attackers were aware and had prior knowledge of the targeted networks. The attackers have distributed three different versions of Comet, Stardust, and Meteor wipers across victims' social media networks in the past couple of years.

According to CheckPoint</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/research-shows-links-between-indra-group-and-iran-railway-attacks-533838.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;The cyberattack that &lt;a href="https://news.softpedia.com/news/massive-cyberattack-led-to-khaos-in-iranian-train-system-533615.shtml" target="_blank"&gt;crippled Iranian trains&lt;/a&gt; last month was recently attributed to the cybercriminal group Indra. The group is known for a series of attacks on several Syrian organizations using a wiper on the hacked networks, according to &lt;a href="https://cyware.com/news/indra-group-associated-with-attacks-on-iran-076b5372" target="_blank"&gt;Cyware&lt;/a&gt;. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
As expected, Indra denies any involvement in the latest attack on Iran. Then again, a large body of evidence suggests that the attackers were aware and had prior knowledge of the targeted networks. The attackers have distributed three different versions of Comet, Stardust, and Meteor wipers across victims' social media networks in the past couple of years.&lt;br /&gt;
&lt;br /&gt;
According to &lt;a href="https://research.checkpoint.com/2021/indra-hackers-behind-recent-attacks-on-iran/" target="_blank"&gt;CheckPoint&lt;... (&lt;a href="https://news.softpedia.com/news/research-shows-links-between-indra-group-and-iran-railway-attacks-533838.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Mon, 23 Aug 2021 14:06:28 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/research-shows-links-between-indra-group-and-iran-railway-attacks-533838.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-23T14:06:28Z</dc:date>
    </item>
    <item>
      <title>New Links Between Diavol Ransomware and TrickBot Gang Revealed</title>
      <link>https://news.softpedia.com/news/new-links-between-diavol-ransomware-and-trickbot-gang-revealed-533836.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/new-links-between-diavol-ransomware-and-trickbot-gang-revealed-533836.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/new-links-between-diavol-ransomware-and-trickbot-gang-revealed-533836.jpg" />
      <description>IBM X-Force published the specifics of an early variant of an emerging ransomware strain dubbed Diavol, according to Security Intelligence. 

Several months ago, Fortinet discovered an unsuccessful ransomware attempt employing the Diavol payload that was targeting a client of the firm. When the experts from the security business investigated the incident, they discovered a ransomware strain that was capable of launching successful attacks. However, IBM's security specialists disagree, stating that the malware is still in the early stages of development and that it was built solely for the purpose of research and development.

The Diavol ransomware sample uses RSA encryption, an algorithm that can prioritize the file types ...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/new-links-between-diavol-ransomware-and-trickbot-gang-revealed-533836.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;IBM X-Force published the specifics of an early variant of an emerging ransomware strain dubbed Diavol, according to &lt;a href="https://securityintelligence.com/posts/analysis-of-diavol-ransomware-link-trickbot-gang/" target="_blank"&gt;Security Intelligence&lt;/a&gt;. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Several months ago, Fortinet discovered an unsuccessful ransomware attempt employing the Diavol payload that was targeting a client of the firm. When the experts from the security business investigated the incident, they discovered a ransomware strain that was capable of launching successful attacks. However, IBM's security specialists disagree, stating that the malware is still in the early stages of development and that it was built solely for the purpose of research and development.&lt;br /&gt;
&lt;br /&gt;
The &lt;a href="https://news.softpedia.com/news/diavol-ransomware-allegedly-developed-by-wizard-spider-533442.shtml" target="_blank"&gt;Diavol ransomware&lt;/a&gt; sample uses RSA encryption, an algorithm that can prioritize the file types ... (&lt;a href="https://news.softpedia.com/news/new-links-between-diavol-ransomware-and-trickbot-gang-revealed-533836.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Mon, 23 Aug 2021 14:04:53 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/new-links-between-diavol-ransomware-and-trickbot-gang-revealed-533836.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-23T14:04:53Z</dc:date>
    </item>
    <item>
      <title>More Than 600 ICS Flaws Spotted in H1 2021</title>
      <link>https://news.softpedia.com/news/more-than-600-ics-flaws-spotted-in-h1-2021-533835.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/more-than-600-ics-flaws-spotted-in-h1-2021-533835.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/more-than-600-ics-flaws-spotted-in-h1-2021-533835.jpg" />
      <description>In the first six months of this year, 600 vulnerabilities were discovered in ICS products (Industrial Control Systems), impacting 76 vendors. The number of vulnerabilities increased by 41% in the same period, according to Claroty's ICS Risk &amp; Vulnerability Report: H1 2021. 

As the need to connect devices to the internet increases, so does the risk of being attacked by cybercriminals. Companies need to drive their business and invest in Operational Technology (OT) devices, and threat actors are using this growth to their advantage, seeking to launch hacking campaigns by taking advantage of companies that have vulnerable IT systems. 

Advantech (22), WAGO (23), Rockwell Automation (35), Schneider Electric (65) and Siemens (146 vulnerabilities) are the most affected manufacturers. An important aspect is that the list of affected manufacturers also includes 20 companies whose product...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/more-than-600-ics-flaws-spotted-in-h1-2021-533835.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;In the first six months of this year, 600 vulnerabilities were discovered in ICS products (Industrial Control Systems), impacting 76 vendors. The number of vulnerabilities increased by 41% in the same period, according to &lt;a href="https://security.claroty.com/1H-vulnerability-report-2021" target="_blank"&gt;Claroty's ICS Risk &amp; Vulnerability Report: H1 2021&lt;/a&gt;. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
As the need to connect devices to the internet increases, so does the risk of being attacked by cybercriminals. Companies need to drive their business and invest in Operational Technology (OT) devices, and threat actors are using this growth to their advantage, seeking to launch hacking campaigns by taking advantage of companies that have vulnerable IT systems. &lt;br /&gt;
&lt;br /&gt;
Advantech (22), WAGO (23), Rockwell Automation (35), Schneider Electric (65) and Siemens (146 vulnerabilities) are the most affected manufacturers. An important aspect is that the list of affected manufacturers also includes 20 companies whose product... (&lt;a href="https://news.softpedia.com/news/more-than-600-ics-flaws-spotted-in-h1-2021-533835.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Sat, 21 Aug 2021 06:31:24 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/more-than-600-ics-flaws-spotted-in-h1-2021-533835.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-21T06:31:24Z</dc:date>
    </item>
    <item>
      <title>Hackers Steal More Than $97M from Liquid Crypto Exchange</title>
      <link>https://news.softpedia.com/news/hackers-stal-more-than-97m-from-liquid-crypto-exchange-533830.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/hackers-stal-more-than-97m-from-liquid-crypto-exchange-533830.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/hackers-stal-more-than-97m-from-liquid-crypto-exchange-533830.jpg" />
      <description>In recent months, more crypto exchange platforms have been targeted by hackers. The most recent attack resulted in the theft of $97 million worth of digital assets from the Japanese cryptocurrency exchange Liquid, according to ZDNet.  

Liquid did not provide an estimate of damages because it is subject to analyses of the Financial Services Agency from Japan. Nevertheless, the attack affected many users, as Liquid is among the top 20 crypto exchanges in the world in terms of daily trading volume, sums estimated at more than $133 million per day on CoinMarketCap.

On the other hand. blockchain analytics firm Elliptic, claimed hackers obtained more than $97 million in cryptoc...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/hackers-stal-more-than-97m-from-liquid-crypto-exchange-533830.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;In recent months, more crypto exchange platforms have been targeted by hackers. The most recent attack resulted in the theft of $97 million worth of digital assets from the Japanese cryptocurrency exchange Liquid, according to &lt;a href="https://www.zdnet.com/article/more-than-97-million-stolen-from-liquid-cryptocurency-exchange/" target="_blank"&gt;ZDNet&lt;/a&gt;.  &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://blog.liquid.com/warm-wallet-incident" target="_blank"&gt;Liquid&lt;/a&gt; did not provide an estimate of damages because it is subject to analyses of the Financial Services Agency from Japan. Nevertheless, the attack affected many users, as Liquid is among the top 20 crypto exchanges in the world in terms of daily trading volume, sums estimated at more than $133 million per day on CoinMarketCap.&lt;br /&gt;
&lt;br /&gt;
On the other hand. blockchain analytics firm &lt;a href="https://www.elliptic.co/blog/liquid-exchange-hacked-94-million-stolen" target="_blank"&gt;Elliptic,&lt;/a&gt; claimed hackers obtained more than $97 million in cryptoc... (&lt;a href="https://news.softpedia.com/news/hackers-stal-more-than-97m-from-liquid-crypto-exchange-533830.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Sat, 21 Aug 2021 06:11:46 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/hackers-stal-more-than-97m-from-liquid-crypto-exchange-533830.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-21T06:11:46Z</dc:date>
    </item>
    <item>
      <title>Pakistani Military Targeted by Confucius with Pegasus Spyware Lures</title>
      <link>https://news.softpedia.com/news/pakistani-military-targeted-by-confucius-with-pegasus-spyware-lures-533823.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/pakistani-military-targeted-by-confucius-with-pegasus-spyware-lures-533823.jpg" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/pakistani-military-targeted-by-confucius-with-pegasus-spyware-lures-533823.jpg" />
      <description>Trend Micro spotted recent malicious activity conducted by cybercriminal group Confucius. The hackers launched a spear-phishing campaign using Pegasus lures to trick users into clicking on a malicious document that downloads a data theft code.  

The attack begins with a clean email that contains a text copied from a legitimate Pakistani newspaper article.Two days later, the victim receives a new email with a warning from a Pakistani military official about the Pegasus spyware that includes a cutt.ly link to encrypted Word document and a decryption password.

Regardless of the action taken by the victim, clicking on either of the links leads to downloading the Word document. If the target makes the mistake of entering...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/pakistani-military-targeted-by-confucius-with-pegasus-spyware-lures-533823.jpg" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;&lt;a href="https://www.trendmicro.com/en_us/research/21/h/confucius-uses-pegasus-spyware-related-lures-to-target-pakistani.html" target="_blank"&gt;Trend Micro&lt;/a&gt; spotted recent malicious activity conducted by cybercriminal group Confucius. The hackers launched a spear-phishing campaign using Pegasus lures to trick users into clicking on a malicious document that downloads a data theft code.  &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
The attack begins with a clean email that contains a text copied from a legitimate Pakistani newspaper article.Two days later, the victim receives a new email with a warning from a Pakistani military official about the Pegasus spyware that includes a cutt.ly link to encrypted &lt;a href="https://www.softpedia.com/get/Office-tools/Text-editors/Microsoft-Word.shtml" target="_blank"&gt;Word&lt;/a&gt; document and a decryption password.&lt;br /&gt;
&lt;br /&gt;
Regardless of the action taken by the victim, clicking on either of the links leads to downloading the Word document. If the target makes the mistake of entering... (&lt;a href="https://news.softpedia.com/news/pakistani-military-targeted-by-confucius-with-pegasus-spyware-lures-533823.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Sat, 21 Aug 2021 05:45:33 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/pakistani-military-targeted-by-confucius-with-pegasus-spyware-lures-533823.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-21T05:45:33Z</dc:date>
    </item>
    <item>
      <title>CISA Issues Ransomware Defense and Response Guidance</title>
      <link>https://news.softpedia.com/news/cisa-issues-ransomware-defense-and-response-guidance-533814.shtml</link>
      <media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://news-cdn.softpedia.com/images/fitted/340x180/cisa-issues-ransomware-defense-and-response-guidance-533814.png" />
      <media:content xmlns:media="http://search.yahoo.com/mrss/" type="image" width="620" url="https://news-cdn.softpedia.com/images/fitted/620x/cisa-issues-ransomware-defense-and-response-guidance-533814.png" />
      <description>Following a series of disruptive and headline-grabbing ransomware attacks on corporations in the United States over the past several months, the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA) has released a list of suggestions to prevent and respond to these sorts of attacks. 

The information sheet called Protecting Sensitive and Personal Information from Ransomware-Caused Data Breaches contains numerous recommendations. In addition, the paper advises companies not to pay a ransom if they are the target of a ransomware attack. 

The fact sheet reads “Ransomware is a serious and increasing threat to all government and private sector organizations, including critical infrastructure organizations. In response, the U.S. government launched...</description>
      <content:encoded>&lt;img src="https://news-cdn.softpedia.com/images/fitted/340x180/cisa-issues-ransomware-defense-and-response-guidance-533814.png" style="margin: 0 0 20px 0;" width="340" height="180" /&gt;&lt;strong&gt;Following a series of disruptive and headline-grabbing ransomware attacks on corporations in the United States over the past several months, the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA) has released a list of suggestions to prevent and respond to these sorts of attacks. &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
The information sheet called &lt;a href="https://www.cisa.gov/sites/default/files/publications/CISA_Fact_Sheet-Protecting_Sensitive_and_Personal_Information_from_Ransomware-Caused_Data_Breaches-508C.pdf" target="_blank"&gt;Protecting Sensitive and Personal Information from Ransomware-Caused Data Breaches&lt;/a&gt; contains numerous recommendations. In addition, the paper advises companies not to pay a ransom if they are the target of a ransomware attack. &lt;br /&gt;
&lt;br /&gt;
The fact sheet reads “Ransomware is a serious and increasing threat to all government and private sector organizations, including critical infrastructure organizations. In response, the U.S. government launched... (&lt;a href="https://news.softpedia.com/news/cisa-issues-ransomware-defense-and-response-guidance-533814.shtml" rel="nofollow"&gt;read more&lt;/a&gt;)</content:encoded>
      <source url="https://news.softpedia.com/newsRSS/x-5.xml">Softpedia News / Security</source>
      <category>Security</category>
      <pubDate>Fri, 20 Aug 2021 06:30:42 GMT</pubDate>
      <guid isPermaLink="false">https://news.softpedia.com/news/cisa-issues-ransomware-defense-and-response-guidance-533814.shtml</guid>
      <dc:creator>Softpedia News (George Dascalu)</dc:creator>
      <dc:date>2021-08-20T06:30:42Z</dc:date>
    </item>
    <item>
      <title>Fisher Price's Bluetooth reboot of pre-school play phone has adult privacy flaw</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/23/fisher_prices_bluetooth_reboot_of/</link>
      <description>&lt;h4&gt;‘Chatter’ can be bugged thanks to kindergarten-grade security&lt;/h4&gt; &lt;p&gt;A Bluetooth phone designed to evoke the carefree days of early childhood has been found to instead threaten the very adult prospect of being surveilled in your home.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218845</guid>
      <dc:creator>Simon Sharwood</dc:creator>
    </item>
    <item>
      <title>Alibaba Cloud slapped by Chinese ministry for mishandling Log4j</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/23/alibaba_cloud_in_trouble_with/</link>
      <description>&lt;h4&gt;Beijing's not saying what cloudy contender did wrong&lt;/h4&gt; &lt;p&gt;China's Ministry of Industry and Information Technology has suspended Alibaba Cloud's membership of an influential security board to protest its handling of the Log4j flaw.…&lt;/p&gt; &lt;p&gt;&lt;!--#include virtual='/data_centre/_whitepaper_textlinks_top.html' --&gt;&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218846</guid>
      <dc:creator>Laura Dobberstein</dc:creator>
    </item>
    <item>
      <title>Of course a Bluetooth-using home COVID test was cracked to fake results</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/22/ellume_home_covid_test_cracked/</link>
      <description>&lt;h4&gt;The Ellume COVID-19 Home Test was connected to the internet of woefully insecure things for a while&lt;/h4&gt; &lt;p&gt;Security vendor F-Secure has faked a COVID test result on a Bluetooth-equipped home COVID Test. Thankfully the vendor’s since fixed the device.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218835</guid>
      <dc:creator>Simon Sharwood</dc:creator>
    </item>
    <item>
      <title>How to tackle hybrid cloud security and DevSecOps</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/21/devsecops_hybrid_cloud_security/</link>
      <description>&lt;h4&gt;Putting the Sec into DevOps is key, says Red Hat&lt;/h4&gt; &lt;p&gt;&lt;strong&gt;Paid Feature&lt;/strong&gt;  Of all the ideas to surface in the 20-year history of cloud computing, few have proved as compelling as the hybrid cloud. Organizations understand on-premises data centers and how computing power can be rented through public clouds or accessed through dedicated private clouds.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218779</guid>
      <dc:creator>John E Dunn</dc:creator>
    </item>
    <item>
      <title>Belgian defence ministry admits attackers accessed its computer network by exploiting Log4j vulnerability</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/21/belgium_defence_ministry_log4j_exploited/</link>
      <description>&lt;h4&gt;Perpetrators' ID unknown, however&lt;/h4&gt; &lt;p&gt;The Belgian Ministry of Defence has suffered a cyber attack after miscreants exploited one of the vulnerabilities in Log4j. The attack marks the first occasion that a NATO country's defence ministry has fallen victim to the flaws.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218828</guid>
      <dc:creator>Gareth Corfield</dc:creator>
    </item>
    <item>
      <title>UK National Crime Agency finds 225 million previously unexposed passwords</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/21/nca_finds_255m_fresh_stolen_passwords/</link>
      <description>&lt;h4&gt;Shares them with Troy Hunt’s Have I Been Pwned after sweeping them up from ‘compromised cloud storage’&lt;/h4&gt; &lt;p&gt;The United Kingdom’s National Crime Agency and National Cyber Crime Unit have uncovered a colossal trove of stolen passwords.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218826</guid>
      <dc:creator>Simon Sharwood</dc:creator>
    </item>
    <item>
      <title>US bags Russian accused of stealing millions after stealing pre-release financial filings</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/20/russian_insider_trading/</link>
      <description>&lt;h4&gt;Swiss cough up accused crim while Russia is 'deeply disappointed'&lt;/h4&gt; &lt;p&gt;The US Attorney's Office of Massachusetts on Monday announced the extradition of Vladislav Klyushin, a Russian business executive with ties to the Kremlin, on charges of hacking US computer networks and committing securities fraud by trading on undisclosed financial data.…&lt;/p&gt; &lt;p&gt;&lt;!--#include virtual='/data_centre/_whitepaper_textlinks_top.html' --&gt;&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218822</guid>
      <dc:creator>Thomas Claburn</dc:creator>
    </item>
    <item>
      <title>Police National Computer not pwned by Clop ransomware crims, insists Home Office</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/20/dacoll_ransomware_clop_pnc_claims/</link>
      <description>&lt;h4&gt;Scottish MSP Dacoll was hit, however&lt;/h4&gt; &lt;p&gt;The Clop ransomware gang pwned a managed service provider with access to the UK's Police National Computer, dumping data on its dark web leaks site – but officials deny that police data was compromised.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218820</guid>
      <dc:creator>Gareth Corfield</dc:creator>
    </item>
    <item>
      <title>How to keep on top of cloud security best practices</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/20/cloud_security_common_misconfigurations/</link>
      <description>&lt;h4&gt;Trend Micro outlines common misconfigurations and how to avoid them&lt;/h4&gt; &lt;p&gt;&lt;strong&gt;Paid Feature&lt;/strong&gt;  In an era beset by hackers at every turn, it’s no small irony that the fastest growing security threat to business data might now be the self-inflicted wound of cloud service misconfiguration.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218774</guid>
      <dc:creator>John E Dunn</dc:creator>
    </item>
    <item>
      <title>VMware 2FA flaw can divulge that vital second credential to malicious actors</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/20/in_brief_security/</link>
      <description>&lt;h4&gt;Plus: Deep dive into the NSO Group's zero-click exploit and 'Hack the DHS!'&lt;/h4&gt; &lt;p&gt;&lt;strong&gt;In Brief&lt;/strong&gt;  VMware has warned users a flaw in its VMware Verify two-factor authentication product could allow a malicious actor with a first-factor authentication credential to obtain a second factor from its VMware Verify product.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218810</guid>
      <dc:creator>Iain Thomson</dc:creator>
    </item>
    <item>
      <title>Bad things come in threes: Apache reveals &lt;i&gt;another&lt;/i&gt; Log4J bug</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/19/log4j_new_flaw_cve_2021_45105/</link>
      <description>&lt;h4&gt;Third major fix in ten days is an infinite recursion flaw rated 7.5/10&lt;/h4&gt; &lt;p&gt;The Apache Software Foundation (ASF) has revealed a third bug in its Log4 Java-based open-source logging library Log4j.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218811</guid>
      <dc:creator>Simon Sharwood</dc:creator>
    </item>
    <item>
      <title>US distrust of Huawei linked in part to malicious software update in 2012</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/18/us_huawei_malware/</link>
      <description>&lt;h4&gt;Report claims Huawei techs working for Chinese intelligence compromised Australian telco&lt;/h4&gt; &lt;p&gt;Suspicions about the integrity of Huawei products among US government officials can be attributed in part to a 2012 incident involving a Huawei software update that compromised the network of a major Australian telecom company with malicious code, according to a report published by Bloomberg.…&lt;/p&gt; &lt;p&gt;&lt;!--#include virtual='/data_centre/_whitepaper_textlinks_top.html' --&gt;&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218809</guid>
      <dc:creator>Thomas Claburn</dc:creator>
    </item>
    <item>
      <title>CISA issues emergency directive to fix Log4j vulnerability</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/17/cisa_issues_emergency_directive_to/</link>
      <description>&lt;h4&gt;Federal agencies have a week to get their systems patched&lt;/h4&gt; &lt;p&gt;The US government's Cybersecurity and Infrastructure Security Agency (CISA) on Friday escalated its call to fix the Apache Log4j vulnerability with an emergency directive requiring federal agencies to take corrective action by 5 pm EST on December 23, 2021.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218808</guid>
      <dc:creator>Thomas Claburn</dc:creator>
    </item>
    <item>
      <title>RAF shoots down 'terrorist drone' over US-owned special ops base in Syria</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/17/raf_shoots_down_drone_syria/</link>
      <description>&lt;h4&gt;£200k Anglo-French heat-seeking missile does its thing&lt;/h4&gt; &lt;p&gt;The RAF has scored its first air-to-air "kill" – where an aircraft downs an enemy aircraft – for almost 40 years after shooting down a drone over Syria.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218801</guid>
      <dc:creator>Gareth Corfield</dc:creator>
    </item>
    <item>
      <title>Over Log4j? VMware has another critical flaw for you to patch</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/17/vmware_criticial_uem_flaw/</link>
      <description>&lt;h4&gt;Workspace ONE Unified Endpoint Management can leak info via server-side request forgery&lt;/h4&gt; &lt;p&gt;VMware customers have probably had a busy week because &lt;a target="_blank" href="https://www.vmware.com/security/advisories/VMSA-2021-0028.html"&gt;more than 100&lt;/a&gt; of the IT giant's products are impacted by the &lt;a target="_blank" href="https://www.theregister.com/2021/12/13/log4j_rce_latest/"&gt;Log4j bug&lt;/a&gt;.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218794</guid>
      <dc:creator>Simon Sharwood</dc:creator>
    </item>
    <item>
      <title>Facebook locks out 1,500 fake accounts used by cyber-spy firms to snoop on people, alerts 50k potential targets</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/17/cyber_spying_firms_facebook_meta/</link>
      <description>&lt;h4&gt;Meta adverse to internet mercenaries using its social networks to help governments violate human rights&lt;/h4&gt; &lt;p&gt;Facebook successor Meta on Thursday said it canceled 1,500 social media accounts used by seven surveillance-for-hire firms to conduct online attacks against government critics and members of civil society.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218793</guid>
      <dc:creator>Thomas Claburn</dc:creator>
    </item>
    <item>
      <title>Why ransomware attacks happen out of hours or during the holidays</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/16/out_of_hours_ransomware_attacks/</link>
      <description>&lt;h4&gt;Security teams have a choice to make – and doing nothing is not an option&lt;/h4&gt; &lt;p&gt;&lt;strong&gt;Paid Feature&lt;/strong&gt;  Time waits for no one. But ransomware attackers do. Increasingly, cybercriminals are timing their attacks, detonating them when their victims are out of the office. This gives them the chance to inflict maximum damage, and explains why ransomware attacks surge on public holidays like Thanksgiving and Christmas. How do they do it, and what can under-staffed security teams do about it?…&lt;/p&gt; &lt;p&gt;&lt;!--#include virtual='/data_centre/_whitepaper_textlinks_top.html' --&gt;&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218663</guid>
      <dc:creator>Robin Birtstone</dc:creator>
    </item>
    <item>
      <title>East Londoners nicked under Computer Misuse Act after NHS vaccine passport app sprouted clump of fake entries</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/16/fake_nhs_vaccine_passport_arrests_met_police/</link>
      <description>&lt;h4&gt;App runs off a database, and databases are run by humans&lt;/h4&gt; &lt;p&gt;British police have made a series of arrests over the past few months after people with apparent access to NHS databases allegedly sold fake vaccination status entries on the NHS vaccine passport app.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218782</guid>
      <dc:creator>Gareth Corfield</dc:creator>
    </item>
    <item>
      <title>Move fast, break security: Why CISOs must push back against Agile IT</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/16/move_fast_break_security_why/</link>
      <description>&lt;h4&gt;The Vectra Masked CISO series gives security leaders a place to expose the biggest issues in security and advise peers on how to overcome them&lt;/h4&gt; &lt;p&gt;&lt;strong&gt;Advertorial&lt;/strong&gt;  &lt;i&gt;The Vectra Masked CISO series gives security leaders a place to expose the biggest issues in security and advise peers on how to overcome them.&lt;/i&gt;…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218700</guid>
      <dc:creator>The Masked CISO</dc:creator>
    </item>
    <item>
      <title>National Cyber Strategy will lead to BritChip for mobile devices by 2025, claims UK.gov</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/16/national_cyber_strategy_uk_launched/</link>
      <description>&lt;h4&gt;And potentially an increase in UK state-backed hacks&lt;/h4&gt; &lt;p&gt;The British government has launched a £2.6bn &lt;a target="_blank" href="https://www.gov.uk/government/publications/national-cyber-strategy-2022"&gt;National Cyber Strategy&lt;/a&gt;, intended to steer the state's thinking on cyber attack, defence and technology for the next three years – and there's some good news if you run a tech company.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218754</guid>
      <dc:creator>Gareth Corfield</dc:creator>
    </item>
    <item>
      <title>Japan draws a LINE: web giants must reveal where they store user data</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/16/japan_data_location_requirement/</link>
      <description>&lt;h4&gt;Looks a lot like a response to messaging services passing data through China&lt;/h4&gt; &lt;p&gt;Social media and search engine operators in Japan will be required to specify the countries in which users' data is physically stored, under a planned tweak to local laws.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218769</guid>
      <dc:creator>Laura Dobberstein</dc:creator>
    </item>
    <item>
      <title>Facebook expands bug bounty program to include scraping attacks, two years after it was scraped – hard</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/16/facebook_scraping_bug_bounties/</link>
      <description>&lt;h4&gt;But still allows limited harvesting&lt;/h4&gt; &lt;p&gt;Meta has expanded its bug bounty program to include payouts for reports of scraping attacks on Facebook – but hold your applause.…&lt;/p&gt; &lt;p&gt;&lt;!--#include virtual='/data_centre/_whitepaper_textlinks_top.html' --&gt;&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218763</guid>
      <dc:creator>Simon Sharwood</dc:creator>
    </item>
    <item>
      <title>As CISA tells US govt agencies to squash Log4j bug by Dec 24, fingers start pointing at China, Iran, others</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/15/log4j_latest_cisa/</link>
      <description>&lt;h4&gt;Microsoft says cyber-spies linked to Beijing, Tehran are getting busy with security flaw along with world + dog&lt;/h4&gt; &lt;p&gt;Microsoft reckons government cyber-spies in China, Iran, North Korea, and Turkey are actively exploiting the Log4j 2.x remote-code execution hole.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218762</guid>
      <dc:creator>Chris Williams</dc:creator>
    </item>
    <item>
      <title>US lawmakers want to put NSO Group, 3 other spyware makers out of business with fresh severe sanctions</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/15/magnitsky_act_nso_group/</link>
      <description>&lt;h4&gt;Export controls aren't enough, Dems say: Bring on the Global Magnitsky Act&lt;/h4&gt; &lt;p&gt;Eighteen US Democratic lawmakers have asked the Treasury Department and State Department to punish Israel-based spyware maker NSO Group and three other surveillance software firms for enabling human rights abuses.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218761</guid>
      <dc:creator>Thomas Claburn</dc:creator>
    </item>
    <item>
      <title>Pen Test Partners: Anyone could view Gumtree users' GPS location by pressing F12</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/15/gumtree_data_breach_idor_f12_badness/</link>
      <description>&lt;h4&gt;And online flea market had IDOR in an iOS-focused API&lt;/h4&gt; &lt;p&gt;UK online used goods bazaar Gumtree exposed its users' home addresses in the source code of its webpages, and then tried to squirm out of a bug bounty after infosec bods alerted it to the flaw.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218755</guid>
      <dc:creator>Gareth Corfield</dc:creator>
    </item>
    <item>
      <title>Microsoft closes installer hole abused by Emotet malware, Google splats Chrome bug exploited in the wild</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/15/patch_tesuday/</link>
      <description>&lt;h4&gt;Round off the year with a large crop of fixes for programming blunders&lt;/h4&gt; &lt;p&gt;&lt;strong&gt;Patch Tuesday&lt;/strong&gt;  It's not just &lt;a target="_blank" href="https://www.theregister.com/2021/12/14/apache_log4j_v2_16_jndi_disabled_default/"&gt;Log4j&lt;/a&gt; you need to worry about this week. It's the final Patch Tuesday of the year.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218742</guid>
      <dc:creator>Chris Williams</dc:creator>
    </item>
    <item>
      <title>Apache takes off, nukes insecure feature at the heart of Log4j from orbit with v2.16</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/14/apache_log4j_2_16_jndi_disabled/</link>
      <description>&lt;h4&gt;Now open-source logging library's JNDI disabled entirely by default, message lookups removed&lt;/h4&gt; &lt;p&gt;Last week, version 2.15 of the widely used open-source logging library Log4j was released to tackle a critical security hole, dubbed Log4Shell, which could be trivially abused by miscreants to hijack servers and apps over the internet.…&lt;/p&gt; &lt;p&gt;&lt;!--#include virtual='/data_centre/_whitepaper_textlinks_top.html' --&gt;&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218735</guid>
      <dc:creator>Gareth Corfield</dc:creator>
    </item>
    <item>
      <title>You may have cracked serverless development, but it’s almost certain you haven’t solved serverless security</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/14/you_may_have_cracked_serverless/</link>
      <description>&lt;h4&gt;Here’s how to secure that ever-expanding attack surface&lt;/h4&gt; &lt;p&gt;&lt;strong&gt;Paid Post&lt;/strong&gt;  Serverless is revolutionizing software development, allowing organizations to produce applications which consume cloud resources only when they need to. Developing applications this way also dramatically reduces the amount of code to write while increasing the velocity of completed applications.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218433</guid>
      <dc:creator>David Gordon</dc:creator>
    </item>
    <item>
      <title>Popular password manager LastPass to be spun out from LogMeIn</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/14/lastpass_spinout/</link>
      <description>&lt;h4&gt;Private equity owners play pass the parcel&lt;/h4&gt; &lt;p&gt;One of the biggest beasts in the password management world, LastPass, is being spun out from parent LogMeIn as a "standalone cloud security" organisation.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218728</guid>
      <dc:creator>Jude Karabus</dc:creator>
    </item>
    <item>
      <title>MPs charged with analysing Online Safety Bill say end-to-end encryption should be called out as 'specific risk factor'</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/14/online_safety_bill_report/</link>
      <description>&lt;h4&gt;Too far? Committee thinks it doesn't go far enough&lt;/h4&gt; &lt;p&gt;Britain's Online Safety Bill is being enthusiastically endorsed in a "manifesto" issued today by MPs who were tasked with scrutinising its controversial contents.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218731</guid>
      <dc:creator>Gareth Corfield</dc:creator>
    </item>
    <item>
      <title>Log4j RCE latest: In case you hadn't noticed, this is Really Very Bad, exploited in the wild, needs urgent patching</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/13/log4j_rce_latest/</link>
      <description>&lt;h4&gt;This might be the bug that deserves the website, logo and book deal&lt;/h4&gt; &lt;p&gt;&lt;strong&gt;Updated&lt;/strong&gt;  Miscreants are wasting no time in using the widespread Log4j vulnerability to compromise systems, with waves and waves of live exploit attempts focused mainly – for now – on turning infected devices into cryptocurrency-mining botnet drones.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218703</guid>
      <dc:creator>Gareth Corfield</dc:creator>
    </item>
    <item>
      <title>When disaster strikes, data recovery really is a race against time</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/13/race_for_data_recovery/</link>
      <description>&lt;h4&gt;But exactly how much time are we talking about?&lt;/h4&gt; &lt;p&gt;&lt;strong&gt;Webinar&lt;/strong&gt;  When it comes to recovering after a catastrophic event such as a ransomware attack or data center failure, time is necessarily of the essence.…&lt;/p&gt; &lt;p&gt;&lt;!--#include virtual='/data_centre/_whitepaper_textlinks_top.html' --&gt;&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218587</guid>
      <dc:creator>David Gordon</dc:creator>
    </item>
    <item>
      <title>Is VPOTUS Bluetooth-phobic or sensible? The answer's pretty clear</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/13/in_brief_security/</link>
      <description>&lt;h4&gt;Plus: bugs found on Mars! Of the software kind, of course&lt;/h4&gt; &lt;p&gt;&lt;strong&gt;In Brief&lt;/strong&gt;  The vice-president of the United States, Kamala Harris, was mocked by commentators this week for her aversion to Bluetooth on security grounds. Security professionals think she has a point – given her position.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218690</guid>
      <dc:creator>Iain Thomson</dc:creator>
    </item>
    <item>
      <title>Timekeeping biz Kronos hit by ransomware and warns customers to engage biz continuity plans</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/13/ultimate_kronos_group_ransomware_attack/</link>
      <description>&lt;h4&gt;Big implications for millions of staffers' Christmas pay packets&lt;/h4&gt; &lt;p&gt;&lt;strong&gt;Updated&lt;/strong&gt;  Kronos Private Cloud has been hit by a ransomware attack. The company, also known as Ultimate Kronos Group (UKG), provides timekeeping services to companies employing millions of people across the world.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218698</guid>
      <dc:creator>Gareth Corfield</dc:creator>
    </item>
    <item>
      <title>Ooh, an update. Let's install it. What could possibly go wro-</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/13/who_me/</link>
      <description>&lt;h4&gt;Patching the patch&lt;/h4&gt; &lt;p&gt;&lt;strong&gt;Who, Me?&lt;/strong&gt;  Welcome to another &lt;a target="_blank" href="https://www.theregister.com/Tag/who-me"&gt;Who, Me?&lt;/a&gt; confession from the &lt;i&gt;Register&lt;/i&gt; readership, and a reminder of the unexpected side effects of software updates.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218656</guid>
      <dc:creator>Richard Speed</dc:creator>
    </item>
    <item>
      <title>Irish Health Service ransomware attack happened after one staffer opened malware-ridden email</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/10/ireland_health_conti_ransomware_attack_report/</link>
      <description>&lt;h4&gt;PWC report shows long list of missed opportunities to shut out extortion crims&lt;/h4&gt; &lt;p&gt;Ireland's Health Service Executive (HSE) was almost paralysed by ransomware after a single user opened a malicious file attached to a phishing email, a consultancy's damning report has revealed.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218683</guid>
      <dc:creator>Gareth Corfield</dc:creator>
    </item>
    <item>
      <title>Log4j RCE: Emergency patch issued to plug critical auth-free code execution hole in widely used logging utility</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/10/log4j_remote_code_execution_vuln_patch_issued/</link>
      <description>&lt;h4&gt;Prepare to have a very busy weekend of mitigating and patching&lt;/h4&gt; &lt;p&gt;&lt;strong&gt;Updated&lt;/strong&gt;  An unauthenticated remote code execution vulnerability in Apache's Log4j Java-based logging tool is being actively exploited, researchers have warned after it was used to execute code on &lt;i&gt;Minecraft&lt;/i&gt; servers.…&lt;/p&gt; &lt;p&gt;&lt;!--#include virtual='/data_centre/_whitepaper_textlinks_top.html' --&gt;&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218682</guid>
      <dc:creator>Gareth Corfield</dc:creator>
    </item>
    <item>
      <title>Revealed: Remember the Sony rootkit rumpus? It was almost oh so much worse</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/10/autorunning_away/</link>
      <description>&lt;h4&gt;That time Rootkitting for Dummies might as well have been in Microsoft's Plus! Pack&lt;/h4&gt; &lt;p&gt;Retired Microsoft engineer, Dave Plummer, &lt;a target="_blank" rel="nofollow" href="https://youtu.be/PqWjq2SdzpI"&gt;offered a blast from the past&lt;/a&gt; last week with a look back at the infamous Sony Windows "rootkit" scandal.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218615</guid>
      <dc:creator>Richard Speed</dc:creator>
    </item>
    <item>
      <title>Ransomwared payroll provider leaks data on 38,000 Australian government workers</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/10/frontier_software_ransomware_incindent/</link>
      <description>&lt;h4&gt;Frontier Software admitted attack three weeks ago, said data was safe … now it's on the dark web&lt;/h4&gt; &lt;p&gt;Personal information describing names, addresses, bank account details, and taxation IDs of 38,000 Australian government employees has been leaked to the dark web after a ransomware attack.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218670</guid>
      <dc:creator>Simon Sharwood</dc:creator>
    </item>
    <item>
      <title>A third of you slackers out there still aren't using HTTPS by default</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/09/top_1_million_report_scott_helme/</link>
      <description>&lt;h4&gt;And it's really bad news for EV cert vendors in Top 1 Million report&lt;/h4&gt; &lt;p&gt;Almost a third of the world wide web's top million sites are still not using HTTPS by default, according to infosec researcher Scott Helme's analysis.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218658</guid>
      <dc:creator>Gareth Corfield</dc:creator>
    </item>
    <item>
      <title>Resistance is ... cheap? Cloudflare, Mandiant, and pals form incident response 'n' cyber insurance borg</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/09/cloudflare_mandiant_cyber_protection_borg/</link>
      <description>&lt;h4&gt;Trust us with everything, croons septuple-strong partnership&lt;/h4&gt; &lt;p&gt;Cyber insurance premiums are increasing and so is infosec's determination to get a slice of that pie: Cloudflare is partnering with Mandiant, Secureworks, and Crowdstrike in a "rapid referral" partnership for under-attack companies.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218652</guid>
      <dc:creator>Gareth Corfield</dc:creator>
    </item>
    <item>
      <title>Ransomware giving you sleepless nights? Here’s how to insure a good night’s sleep</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/09/cyber_insurance_guide/</link>
      <description>&lt;h4&gt;This guide to cyber insurance will help you rest easy&lt;/h4&gt; &lt;p&gt;&lt;strong&gt;Paid Post&lt;/strong&gt;  Why do CISOs and CIOs endure so many sleepless nights? Because they’re either worrying about cyber attacks in general, and ransomware in particular, or because they’re actually dealing with them.…&lt;/p&gt; &lt;p&gt;&lt;!--#include virtual='/data_centre/_whitepaper_textlinks_top.html' --&gt;&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218591</guid>
      <dc:creator>David Gordon</dc:creator>
    </item>
    <item>
      <title>Oz Feds reveal distribution model behind backdoored 'An0m' chat app spread by crims</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/09/feds_reveal_distribution_model_behind/</link>
      <description>&lt;h4&gt;Resellers were given exclusive territories to target, and offered tech support&lt;/h4&gt; &lt;p&gt;Australia's Federal Police force has revealed more about how it distributed a backdoored chat app to criminals.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218643</guid>
      <dc:creator>Simon Sharwood</dc:creator>
    </item>
    <item>
      <title>Canadian charged with running ransomware attack on US state of Alaska</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/08/canadian_man_ransomware_alaska_charged/</link>
      <description>&lt;h4&gt;Cross-border op nabbed our man, boast cops and prosecutors&lt;/h4&gt; &lt;p&gt;A Canadian man is accused of masterminding ransomware attacks that caused "damage" to systems belonging to the US state of Alaska.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218632</guid>
      <dc:creator>Gareth Corfield</dc:creator>
    </item>
    <item>
      <title>Not all tech disasters are ‘all hands’ events. But how do you tell which is which?</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/08/preventing_cyber_disaster/</link>
      <description>&lt;h4&gt;This webinar shows you how to measure the blast radius&lt;/h4&gt; &lt;p&gt;&lt;strong&gt;Webinar&lt;/strong&gt;  This isn’t surprising. The prospect of having all your data and applications compromised, whether due to ransomware or other cyberattacks, or any of the more traditional disaster scenarios is so horrifying, that it’s natural to throw everything you have at it.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218586</guid>
      <dc:creator>David Gordon</dc:creator>
    </item>
    <item>
      <title>Virgin Media fined £50,000 after spamming 451,000 who didn't want marketing emails</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/08/virgin_media_pecr_fine_415000_customers_spammed/</link>
      <description>&lt;h4&gt;Data watchdog shows it's keeping its PECR up&lt;/h4&gt; &lt;p&gt;British telco Virgin Media is facing a £50k financial penalty after spamming more than 400,000 opted-out customers urging them to sign back up to receive marketing bumf.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218634</guid>
      <dc:creator>Gareth Corfield</dc:creator>
    </item>
    <item>
      <title>What’s the right amount of trust to build into your network? Less than Zero</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/08/iomart_zero_trust/</link>
      <description>&lt;h4&gt;It’s tricky but manageable, says Iomart&lt;/h4&gt; &lt;p&gt;&lt;strong&gt;Paid Feature&lt;/strong&gt;  “The trust of the innocent is the liar's most useful tool,” Stephen King wrote. At least that’s what the internet claims.…&lt;/p&gt; &lt;p&gt;&lt;!--#include virtual='/data_centre/_whitepaper_textlinks_top.html' --&gt;&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218459</guid>
      <dc:creator>Joseph Martins</dc:creator>
    </item>
    <item>
      <title>Microsoft extends Secured-core concept to servers</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/08/microsoft_extends_securedcore_concept_to_servers/</link>
      <description>&lt;h4&gt;Certifies hardware with malware-crimping spec, already common in PCs, for Azure Stack and Windows Server&lt;/h4&gt; &lt;p&gt;Microsoft has extended the Secured-core concept it applied to PCs in &lt;a target="_blank" href="https://www.theregister.com/2019/10/22/microsoft_securecore_pcs/"&gt;2019&lt;/a&gt; to servers, and to Windows Server and Azure Stack HCI.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218621</guid>
      <dc:creator>Simon Sharwood</dc:creator>
    </item>
    <item>
      <title>Cryptominers aren't just a headache – they're a big neon sign that Bad Things are on your network</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/07/sophos_tor2mine_research_cryptominer_warning/</link>
      <description>&lt;h4&gt;So says Sophos in warning about Tor2Mine Monero malware&lt;/h4&gt; &lt;p&gt;Cryptominer malware removal is a routine piece of the cybersecurity landscape these days. Yet if criminals are hijacking your compute cycles to mine cryptocurrencies, chances are there's something worse lurking on your network too.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218607</guid>
      <dc:creator>Gareth Corfield</dc:creator>
    </item>
    <item>
      <title>Foreign Office IT chaos: Shocking testimony reveals poor tech support hindered Afghan evac attempts</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2021/12/07/foreign_office_it_chaos_testimony/</link>
      <description>&lt;h4&gt;Contributed to dysfunction as diplomats and soldiers struggled to get Afghan helpers out of reach of Taliban&lt;/h4&gt; &lt;p&gt;Diplomats and soldiers were left grappling with appallingly inadequate IT and secure communications support as thousands of Afghans struggled to get help from the UK during the fall of the capital Kabul in August.…&lt;/p&gt;</description>
      <guid isPermaLink="false">tag:theregister.com,2005:story218605</guid>
      <dc:creator>Lindsay Clark</dc:creator>
    </item>
  </channel>
</rss>
