News

Latest news about B2B cyber security >>> PR agencies: add us to your mailing list - see contact! >>> Book an exclusive PartnerChannel for your news!

Cloud security according to BSI criteria: C5 attestation for Trend Micro 
Trend Micro News

Trend Micro, one of the world's leading providers of cyber security solutions, received the attestation according to the criteria of the C2023:5 standard (Cloud Computing Compliance Criteria Catalogue) in January 2020. These are based on the catalog of requirements of the Federal Office for Information Security (BSI) and have become the recognized security standard for cloud computing in Germany. The Japanese company thus offers its customers cloud security based on Software as a Service (SaaS) solutions for a modern and up-to-date level of security that meets the strict and demanding criteria of the BSI. C5: Cloud security according to BSI criteria The C5 catalog has been around since 2016. It…

Read more

Chrome: New patches for security vulnerabilities
B2B Cyber ​​Security ShortNews

All Chrome users should take the time to update to version 109.0.5414.119 /.120. With the update, Google closes 4 security gaps, 2 of which are considered highly dangerous. An update is done quickly. A user and experts have found new vulnerabilities in Chrome and reported them to Google. There they reacted immediately and incorporated the patches into a new version. The official or stable build is 109.0.5414.119 /.120 for Windows, for Mac and Linux Mac and Linux to 109.0.5414.119. Two Serious Vulnerabilities While the first vulnerability was found in the WebTransport (CVE-2023-0471) of the client-server transfer engine…

Read more

Business Email Compromise: more than just phishing
B2B Cyber ​​Security ShortNews

Business email compromise (BEC) is big business for cybercriminals. According to the 2021 FBI Cybercrime Study, BEC was responsible for nearly $2021 billion in losses in 2,4. With the proliferation of smartphones and tablets, attackers are now going far beyond email. They are now also using other platforms such as text messages, messaging apps like Signal and WhatsApp, and social media apps to attack and compromise their targets. With so many SaaS applications employees use every day, a single successful phishing attack could impact the entire organization...

Read more

ALPHV-BlackCat puts data from Meyer & Meyer on the dark web
B2B Cyber ​​Security ShortNews

Behind the attack on the Osnabrück logistics company Meyer & Meyer is the APT group ALPHV or BlackCat. Various company documents are published on their leak page on the dark web. Already on December 6th there was a successful cyber attack on the systems of the well-known textile logistics company Meyer & Meyer. When visiting its website, the company still states that it is working on the consequences of the cyber attack. Meyer & Meyer openly communicated the attack on its systems, but did not provide any further information on the scope and the exact effects. Individual data on the dark web…

Read more

Medium-sized company Fritzmeier Group hit by cyber attack
B2B Cyber ​​Security ShortNews

The manufacturer of plastic assemblies, metalworking and environmental technology, the Fritzmeier Group, was hit by a cyber attack. So far, the provider has only informed its customers with a note on the homepage that everything is continuing in emergency mode. The list of attacked companies is getting longer and longer. A few days ago, the Fritzmeier Group, the manufacturer of complete cabins, plastic assemblies, metalworking and environmental technology, was also hit. The Fritzmeier Group has several German locations and employs around 2.200 people worldwide. Company continues to work in emergency mode On the website of the Fritzmeier Group there is currently only one…

Read more

OpenAI: Cyber ​​criminals use ChatGPT
B2B Cyber ​​Security ShortNews

Security researchers performed a full infection flow using ChatGPT in December, from crafting a convincing spear-phishing email to running a reverse shell capable of accepting English-language commands. At the time, the question arose whether this was just a hypothetical threat or whether there were already threat actors using OpenAI technologies for malicious purposes. Analysis of several major underground hacking communities conducted by Check Point Research (CPR) shows that cybercriminals are already beginning to use OpenAI to develop malicious tools. As suspected by the security experts,…

Read more

3 million insecure Windows computers in Germany
Eset_News

Support for Windows 10 ended on January 2023, 8.1, as did extended paid support for Windows 7. From this point on, no more security updates will be released. Microsoft also does not offer an Esu (Extended Security Update) program for Windows 8.1. The result: almost 3 million insecure Windows computers. In German private households, around one million computers are still running Windows 8.1 and almost twice as many are running Windows 7 (1,7 million). All in all, almost three million computers with an insecure operating system are still regularly online. It is high time for users to make the switch...

Read more

Ransomware hit fleet management for 1.000 ships
B2B Cyber ​​Security ShortNews

DNV, the provider of the fleet management software ShipManager, was hit by a ransomware attack and had to shut down large parts of its IT systems. This affects 70 DNV customers and their 1.000 ships. DNV's ShipManager servers fell victim to a ransomware cyberattack on the evening of January 7th. DNV experts immediately shut down the servers in response to the incident. DNV is in regular contact with all ShipManager users regarding the situation. Around 70 customers who operate around 1.000 ships are affected. All affected customers have been advised, depending on the type of data they are uploading to the system...

Read more

BSI: Critical vulnerability in Control Web Panel
B2B Cyber ​​Security ShortNews

The well-known and widely used Web Hosting Control Web Panel (CWP) has a critical security vulnerability from 9.8 to CVSSv3.1. Attackers can install shells on the server or collect and extract information. On January 3, 2023, IT security researcher Numan Türle from Gais Cyber ​​Security published a proof of concept for a vulnerability in the server management software Control Web Panel (CWP) - formerly CentOS Web Panel. The vulnerability allows a remote, unauthenticated attacker to execute code on the affected system based on a lack of input neutralization. The information was released...

Read more

Data from the University of Duisburg-Essen on the dark web
B2B Cyber ​​Security ShortNews

The University of Duisburg-Essen (UDE) recently became the victim of a cyber attack, which it is still struggling with. It is now clear that the ViceSociety group is blackmailing the UDE, but that they are not paying the ransom. Now the data is available on the Darknet for everyone. Immediately after the attack was discovered, the university shut down the entire IT infrastructure and disconnected it from the network. Only a small part of the data got into the hands of the criminal organization. The uni states “Data protection and the protection of personal data are top priorities for the UDE…

Read more