Apple fixes macOS zero‑day bug that let malware take secret screenshots

Apple fixes macOS zero‑day bug that let malware take secret screenshots

You would do well to update to macOS Big Sur 11.4 post-haste Apple has rolled out updates to address a bevy of security flaws, including three zero-day vulnerabilities that are being actively exploited in the wild. Two of the loopholes affect tvOS used for the Apple TV 4k and Apple TV HD offerings, whereas the…
Bluetooth bugs could allow attackers to impersonate devices

Bluetooth bugs could allow attackers to impersonate devices

Patches to remedy the vulnerabilities should be released over the coming weeks Cybercriminals could exploit several vulnerabilities in Bluetooth to carry out impersonation attacks and masquerade as a legitimate device during the pairing process, according to the Bluetooth Special Interest Group (SIG). The security flaws, which affect the Bluetooth Core and Mesh Profile specifications, were discovered by researchers…
I hacked my friend’s website after a SIM swap attack

I hacked my friend’s website after a SIM swap attack

Here’s how easily your phone number could be stolen, why a successful SIM swap scam is only the beginning of your problems, and how you can avoid becoming a victim of the attack Just how easy is it to conduct a SIM swap attack and what can the attacker do once they have taken control…
Don’t feed the trolls and other tips for avoiding online drama

Don’t feed the trolls and other tips for avoiding online drama

You may not be able to escape internet trolls, but you have a choice about how you will deal with them – here’s how you can handle trolls without losing your cool The term “internet troll” is widely associated with an online commenter or discussion participant whose sole aim is to stir up havoc by…
European police bust major online investment fraud ring

European police bust major online investment fraud ring

The operation was carried out against an organized group that used online trading platforms to swindle victims out of US$36 million Europol and several national law enforcement agencies have teamed up to take down an investment fraud and money laundering ring that caused losses of approximately €30 million (US$36 million) to hundreds of victims, according…
Verizon’s 2021 DBIR: Phishing and ransomware threats looming ever larger

Verizon’s 2021 DBIR: Phishing and ransomware threats looming ever larger

The report provides unique insights into how the COVID-19 pandemic affected the data breach landscape Verizon has released the 14th installment of its annual Data Breach Investigations Report (DBIR) that analyzed 5,258 confirmed data breaches, an increase from 3,950 in the report’s previous issue. As might be expected, the 2021 edition, which used input from…
Android stalkerware threatens victims further and exposes snoopers themselves

Android stalkerware threatens victims further and exposes snoopers themselves

ESET research reveals that common Android stalkerware apps are riddled with vulnerabilities that further jeopardize victims and expose the privacy and security of the snoopers themselves Mobile stalkerware, also known as spouseware, is monitoring software silently installed by a stalker onto a victim’s device without the victim’s knowledge. Generally, the stalker needs to have physical…
ESET Research goes to RSA Conference 2021 with two presentations

ESET Research goes to RSA Conference 2021 with two presentations

We will explore two threats – Android stalkerware and XP exploits UPDATE (May 13th, 2021): This article was updated to clarify information about the sessions that ESET researchers will host. We are just a few days away from RSA Conference 2021 (May 17-20), an important annual event for the IT security industry and research. ESET…
1 million risky apps rejected or removed from Apple’s App Store in 2020

1 million risky apps rejected or removed from Apple’s App Store in 2020

Apple also claims to have foiled US$1.5 billion worth of potentially fraudulent transactions Apple says that it thwarted more than US$1.5 billion in potentially fraudulent transactions and prevented almost a million vulnerable and otherwise risky apps from making their way into the App Store in 2020, according to a new report highlighting the company’s efforts…
DDoS attack knocks Belgian government websites offline

DDoS attack knocks Belgian government websites offline

The attack overwhelmed the systems of a Belgian ISP, leading to widespread service outages and disruptions Many government websites and services in Belgium were knocked offline on Tuesday after Belnet, the internet service provider (ISP) for the country’s public sector, was hit by a massive distributed denial-of-service (DDoS) attack. According to Belnet, the attack started…