News

Latest news about B2B cyber security >>> PR agencies: add us to your mailing list - see contact! >>> Book an exclusive PartnerChannel for your news!

Lexmark SMB printers with critical 9.0 vulnerability
B2B Cyber ​​Security ShortNews

Lexmark reports two vulnerabilities in over 120 relatively new printer models. Many devices are also for the SME sector and have network access. According to CVSSv3, a vulnerability has a base score of 9.0 and is therefore considered “critical”. Users of the models should urgently update the firmware, as remote attackers could run code. In the list of current safety instructions from Lexmark, there are two current entries for which a firmware update is recommended. According to the Common Vulnerability Scoring System Version 3.0 – CVSSv3 for short, the CVE-2023-22960 vulnerability has a score of…

Read more

GoTo Remote Work: Hackers steal backups and keys
B2B Cyber ​​Security ShortNews

The service provider GoTo for remote work - formerly LogMeIn - reports a hack on customer data and access to encrypted backups including keys that were stored on a cloud server. It probably also contained passwords, names, e-mails and more. Back in November there was a hacker attack on the cloud section of the online password service LastPass. This is a subsidiary of GoTo, which uses third-party cloud storage. Apparently GoTo data and backups were also accessed there, as the company had to admit almost 2 months later. The first GoTo post in November was…

Read more

Android malware infects WiFi routers and cell phones 
Kaspersky_news

A new DNS-changing Android malware allows cybercriminals to infect Android smartphones with malware via compromised Wi-Fi routers in cafes, airport hotels and other public places. Many users in South Korea are currently being infected, but the malware is spreading more and more in Germany and Austria via smishing. Kaspersky experts report. Roaming Mantis recently introduced DNS (Domain Name System) changer functionality in Wroba.o malware, also known as Agent.eq, Moqhao and XLoader - the malware is a core part of the campaign. DNS-Changer is a malicious program that steals the device connected to a compromised WiFi router…

Read more

PayPal: Hacker access to almost 35.000 accounts
B2B Cyber ​​Security ShortNews

According to various media, hackers had access to almost 35.000 PayPal accounts. The provider was not hacked, but the accounts were compromised via credential stuffing. This means that users were too lazy to use different passwords, didn't replace their leaked passwords and didn't use 2-factor authentication. The passwords were then simply tried out successfully by the hackers at PayPal. A successful hack and the stupidity of users are often confused. To access the PayPal accounts, the hackers filtered customer details and passwords from various other hacks of companies or password database providers and linked them to the…

Read more

Is HIVE behind the attack on the Potsdam administration?
B2B Cyber ​​Security ShortNews

It is not yet entirely clear whether HIVE is behind the cyber attack on the Potsdam administration. A message from the administration speaks of HIVE and that even after the APT group has been broken up, the systems are still being switched off. The misery does not end for the city administration of Potsdam. Although the IT experts restarted the attacked and then repaired systems in January, they shut everything down again on January 24th. After an expanded virus scanner was activated, there were a large number of automated communication attempts from the state capital's internal network...

Read more

SwiftSlicer wiper malware targets Ukraine
Eset_News

Recently, ESET security researchers observed cyberattacks using a novel wiper malware called SwiftSlicer. The new wiper malware from the APT group Sandworm is said to attack facilities in Ukraine and destroy data. The researchers at the European IT security manufacturer ESET suspect the Sandworm APT group to be behind the recently discovered attack with SwiftSlicer, which has already attacked a Ukrainian energy supplier with Industroyer2 and numerous other targets with the data deletion malware Caddywiper. The U.S. Department of Justice specifically identified Sandworm as military unit 74455 of the Russian Military Intelligence Service's Main Intelligence Unit (GRU). Nothing is known about the specific goals at the moment. What…

Read more

Webinar February 3, 2023: How SMEs protect themselves
Kaspersky_news

Kaspersky is hosting a free webinar in German on Friday, February 3, 2023, starting at 10:00 a.m. on the topic "New year, new cyber risks: How to protect small and medium-sized businesses". In the non-technical webinar, experts will shed light on the special risks for medium-sized companies. Small and medium-sized business (SMB) executives often think that their size doesn't make them a worthwhile target for cybercriminals. Not even close! Webinar February 3, 2023 from 10:00 a.m. "How small and medium-sized companies protect themselves" Current figures show that cyber attacks do not stop at SMEs. The experts…

Read more

Phishing Report shows the current email traps
B2B Cyber ​​Security ShortNews

In its new Brand Phishing Report for the fourth quarter of 2022, Check Point presents the new phishing threats. The report highlights the brands most frequently impersonated by hackers in their attempts to steal personal information or payment details in the months of October, November and December of the past year. In general, the technology sector was the industry most impersonated by brand phishing in the last quarter of 2022, followed by logistics and social media. DHL ranked second with 16 percent of all branded phishing attempts, ahead of Microsoft in third…

Read more

NIS2 is not sufficient
B2B Cyber ​​Security ShortNews

In view of the increasing discussion about cyber attacks on IT and OT environments, the need for stricter legal requirements for companies and organizations, especially in critical sectors, is being discussed in public. NIS2 will replace the existing EU cyber security law, the 2016 Directive on the Security of Network and Information Systems. According to NIS2, organizations in various sectors should ensure that the networks and systems they use to provide services and carry out their activities achieve a higher level of cyber security. Inadequate prescription Kay…

Read more

Wanted: Malware reverse engineering experts
Kaspersky_news

Malware Reverse Engineering was the most in-demand skill among security professionals in 2022. About half (45 percent) of the experts who took part in Kaspersky training courses wanted to improve and expand their knowledge in this area. The demand for cybersecurity professionals is growing exponentially, outstripping the available skilled labor force as organizations pay more attention to their overall cybersecurity needs. In order to acquire the necessary knowledge and skills, cyber experts rely on various training courses, including the courses in the Kaspersky Expert Training Portfolio. 45 percent interested in reverse engineering skills Statistics from these Kaspersky training courses show that…

Read more