News

Latest news about B2B cyber security >>> PR agencies: add us to your mailing list - see contact! >>> Book an exclusive PartnerChannel for your news!

Special IIS malware for Windows web servers
Eset_News

Special malicious programs spy out governments and attack online shoppers. ESET publishes white papers on the latest IIS malware threats to Windows web servers. The vulnerabilities in Microsoft Exchange worried many IT administrators at the beginning of the year. Because hackers were able to exploit Microsoft's Internet Information Services (IIS). ESET researchers have now analyzed a total of ten previously unknown malware families that were used as malicious extensions for the IIS web server. These various threats target both government mailboxes and credit card transactions in e-commerce. They can eavesdrop on and manipulate the server's communication. According to…

Read more

Mainboard attack: UEFI malware remains a threat
Mainboard attack: UEFI malware remains a threat

UEFI malware remains a threat to home and business. Hackers have infiltrated the firmware on motherboards with innovative attack methods. ESET technologies protect against the latest malware. With the malware Lojax, the Unified Extensible Firmware Interface (UEFI) was on everyone's lips in autumn 2018. ESET researchers had found out that hackers can infiltrate the firmware on mainboards using new attack methods and use this to spy on the systems. The hardware and software supply chains are increasingly being targeted by cyber criminals. UEFI malware is used here again and again. It is therefore important to rely on security solutions ...

Read more

Contaminated advertising threatens Android and iOS devices
Eset_News

Nasty advertising threatens Android and iOS devices: malware is distributed via URL shorteners and the calendar function is abused. As a result, premium SMS are often sent and subscriptions are taken out. An analysis by ESET researchers. According to ESET researchers, aggressive advertising that distributes dangerous malware is currently up to mischief. In addition, the malware creates alleged events in iOS and Android calendars. These advertisements often cost victims money as premium SMS messages are sent and subscriptions are taken out. Android just like iOS devices affected With Android there is a risk of banking and SMS Trojans or malicious applications getting onto the devices. Android / FakeAdBlocker, so the ...

Read more

How secure is macOS from Apple?
Eset_News

Zero trust security: how secure is macOS from Apple? ESET researchers scrutinize well-known Mac myths, such as system immunity to malware and the allegedly few security flaws. Almost every day the media report on ever larger, constantly improved and highly successful hacker attacks on companies worldwide. That is why many company leaders are already rethinking their security strategy and are turning more and more to "Zero Trust Security". This also includes checking the operating systems used, such as macOS, more precisely for their security. Because there are many myths about the security of Apple's macOS: starting with the complete immunity to ...

Read more

Security concerns with the digital EU COVID certificate
Eset_News

The EU COVID certificate should be available since July 1, 2021. As before, the ESET experts still have security concerns. There are some weak points that can be exploited for abuse. In the opinion of ESET, however, abuse cannot be ruled out, as the procedures are identical to the existing ones. “It must be clearly stated, however, that the creation of screenshots on smartphones cannot be perfectly prevented from a technological point of view. This becomes even more problematic if the COVID vaccination document is simply printed out without security features. But that will be current at the exhibition ...

Read more

Proactive hazard prevention using Microsoft Exchange as an example
Eset_News

Inside view of the IT infrastructure enables proactive hazard prevention. What the security gap in Microsoft Exchange shows us afterwards. In the first quarter of this year, the Microsoft Exchange security gap that had become known rightly caused major headaches for many IT managers. In Germany alone, the CERT-Bund, which is part of the Federal Office for Information Security (BSI), assumed at least 2021 vulnerable Exchange servers in March 26.000. Over 26.000 Exchange servers affected How high the total damage was for the companies affected can hardly be quantified, as no information about this was made available to the general public. In individual cases,…

Read more

State actors and cyber criminals can hardly be distinguished
State actors and cyber criminals can hardly be distinguished

State actors or cyber criminals: the lines are blurring. According to the ESET security experts, the campaigns by state actors have increased. ESET reports on the current situation and gives forecasts for the future. Whether hackers who are supported by governments or financially motivated cyber criminals: It is no longer possible to differentiate between these actors. The boundaries between this and "classic" cyber crime are becoming increasingly blurred. Hacker groups who have drawn attention to themselves through Advanced Persistent Threat (APT) attacks also try to make financial profits from their activities. Conversely, cyber criminals sell their tools on the dark web, for example ...

Read more

ESET exposes new espionage activities by cyber criminals
Eset_News

ESET researchers have analyzed an espionage campaign targeting companies that is still active. The ongoing campaign, which bears the name Bandidos, is aimed specifically at IT infrastructures in Spanish-speaking countries. 90 percent of the detections are in Venezuela. In 2021 alone, ESET researchers saw more than 200 variants of the malware in Venezuela. However, the experts were unable to identify a specific economic sector that this campaign is targeting. Installed malicious Chrome extension "The Chrome Inject functionality is particularly interesting," says ESET researcher Fernando Tavella, who investigated the Bandidos campaign….

Read more

Open source intelligence increases IT security
Eset_News

ESET shows how the OSINT (Open Source Intelligence) model can be used to reduce the risk of cyber attacks if IT managers use the methodology for their company. Open Source Intelligence (OSINT) is a concept that is becoming increasingly important as an element of the IT security strategy in companies. Freely available sources such as media, TV or the Internet are used to collect information. Secret services rely on OSINT Secret services have been using this method successfully for decades. Hackers also use this method to prepare attacks on systems. However, companies can also use OSINT themselves to ...

Read more

Ransomware attack on Kaseya also affects German companies
Eset_News

ESET analyzes the ransomware attack on Kaseya: Researchers have so far identified attacks in 17 countries. This also includes Germany and German companies. Customers of the IT service provider Kaseya are currently the target of large-scale attacks with extortion Trojans. According to ESET analyzes, the hackers struck in at least 17 countries, including Germany, USA, Great Britain and Canada. The ransomware was distributed specifically via the IT management software of the service provider. This is often used in managed service provider (MSP) environments. ESET's security researchers are continuing to monitor what is happening. Attack in 17 countries - including Germany "So far ...

Read more