News

Latest news about B2B cyber security >>> PR agencies: add us to your mailing list - see contact! >>> Book an exclusive PartnerChannel for your news!

US government confiscates €3,6 billion worth of bitcoin
US government confiscates €3,6 billion worth of bitcoin

As the US government reports, it was able to confiscate stolen bitcoins worth 3,6 billion euros or 4,5 billion dollars. They come from a hack on the online trading platform Bitfinex, which traded cryptocurrencies. The hack happened back in 2016. But now the bitcoins should be washed. The hack on the online trading platform Bitfinex was not that big in 2016, since the maximum value of Bitcoin was still 1.000 euros. However, the value of the 120.000 stolen bitcoins has increased immensely in the meantime. At the highs of bitcoin, the stolen goods were even over 7 billion euros...

Read more

Box: MFA via SMS could also be bypassed by attackers
Box: MFA via SMS could also be bypassed by attackers

Varonis security researchers have discovered a way to bypass multi-factor authentication (MFA) via SMS for Box accounts. Attackers with stolen credentials were able to compromise an organization's Box account and exfiltrate sensitive data without having to access the victim's phone. Security researchers reported this vulnerability to Box on November 3, 2021 via HackerOne, which prompted it to be closed. Just last month, Varonis Thread Labs demonstrated how to bypass Box's TOTP-based MFA. Both gaps make it clear that cloud security, even when using seemingly secure technologies, is never...

Read more

Clubhouse data leak: 1,3 million user data leaked
B2B Cyber ​​Security ShortNews

The Clubhouse app and its exclusive service are increasingly being criticized in terms of data security. There is currently 1,3 million user data in a hacker forum and the app operators are not even shocked, as they themselves explain on Twitter. The portal cybernews.com currently reported that over 1,3 million records of clubhouse users have appeared in a hacker forum. And only days after data from more than a billion Facebook and LinkedIn profiles were offered for sale online. Now it's Clubhouse's turn: An SQL database with 1,3 million Clubhouse user data records was ...

Read more

Hack: 150.000 security cameras tapped
AvastNews

In a cyber attack on the security camera manufacturer Verkada, the data from over 150.000 cameras - with live feeds in hospitals, schools, prisons and companies (such as Tesla) - were tapped. A statement from Nick Viney, Avast Senior Vice President Partner. The cyber attack on the security camera provider Verkada is not an IoT hack in itself, but an attack on the company network. Nevertheless, this case shows once again how urgent it is to protect the data collected by IoT devices. The video surveillance market will grow to $ 2025 billion by 75, and companies that ...

Read more

SolarWinds hack: Kaspersky finds code similarities
Kaspersky_news

SolarWinds hack: Kaspersky experts find code similarities between Sunburst malware and Kazuar backdoor. Kaspersky experts have found specific code similarities between Sunburst and known versions of the Kazuar backdoor. This type of malware allows remote access to a victim's computer. IT security researchers can use the new findings to help them analyze the attack. In mid-December 2020, FireEye, Microsoft and SolarWinds announced the discovery of a large, highly complex supply chain attack that used the previously unknown malware 'Sunburst' against SolarWinds Orion customers. Analysis reveals similarities When analyzing the sunburst backdoor, the ...

Read more

Visa contactless payment tricked
Eset_News

A security loophole makes it possible to bypass the PIN request for a contactless Visa payment. Researchers at ETH Zurich have discovered a vulnerability that allows criminals to make payments with credit cards without knowing their PINs. A team of researchers from the Swiss Federal Institute of Technology in Zurich (ETH Zurich) has found a security flaw in the EMV protocol for contactless payments from the credit card provider Visa that could allow attackers to circumvent the PIN query and commit credit card fraud. With contactless payment, there is usually a limit to how much you can pay for goods or services. As soon as it is exceeded, the card terminal requests ...

Read more

Smart door lock with pitfalls
Bitdefender_News

According to Bitdefender, the smart door lock Smart Lock Pro from August is insufficiently secured and thus reveals the WiFi password. Online rental companies often use these door locks. The vulnerability has been known since December but is still open. The August brand Smart Lock Pro door lock allows attackers to access the WiFi password. According to Bitdefender, communication between the August hardware and the associated smartphone app is insufficiently secured: If the user enters the WiFi password during configuration so that he can control the door lock remotely, this password can be accessed by third parties ...

Read more

Attack on 4.000 databases
Eset_News

“Meow” attacks delete nearly 4.000 unsecured databases. The attackers and their intentions are so far unknown, but they are again showing the risks of inadequate data security. In the past few days, thousands of unsecured databases have been automatically attacked and the stored data has been deleted. The attacks are known as "Meow" attacks because the data is overwritten with the character string "Meow", among other things. In addition, no explanation is left for the data destruction. As a search in Shodan shows, the "Meow" attacks have spread in the past few days. Almost 4.000 databases have now been deleted. More than 97% of attacks ...

Read more

Mac hack via Office macros
News B2B Cyber ​​Security

Der Spiegel (spiegel.de) reports how a recent Mac hack shows how easily the Office package can be attacked on a Mac and thus also endanger companies - even if Office runs more under Windows there. Mac hacker Patrick Wardle has now presented his experiment in the virtual edition of the Black Hat IT security conference, which normally takes place every summer in Las Vegas. His attack on the Mac is actually a classic of the Windows hacks - namely the spread of malware via prepared office macros. The hack Wardle shows the black hat audience does not trigger a macro warning. He…

Read more