Posts

Cybersecurity News & Trends – 05-22-20

This week, cybersecurity news was thrust into the fray, with clashes between scammers and vigilante hackers, between conspiracy theorists and cell-phone towers, and between REvil and a number of high-profile celebrities.


SonicWall Spotlight

DeskFlix: SonicWall channel director on COVID-19 cybersecurity challenges — CRN UK

  • Mike Awford discusses the ways SonicWall has supported partners through the migration to remote working.

EasyJet Hack: Passenger Data Could be Sold on Dark Web After Major Cyber Attack, Experts Warn — The Independent

  • Based on similar attacks in the past, SonicWall’s VP EMEA Terry Greer-King discusses what could happen to customers’ data once it hits the Dark Web.

SonicWall Capture Labs Threat Research Teams Uncovers New Variant of Raccoon Stealer — CXO Today

  • SonicWall has reported a new variant of Raccoon stealer malware, version 1.5, which has been used in a malicious COVID-19 campaign.

Cybersecurity News

ShinyHunters Is a Hacking Group on a Data Breach Spree — Wired

  • In May, ShinyHunters began selling 200 million stolen records from over a dozen companies … and they claim this is just Stage 1.

Beware of phishing emails urging for a LogMeIn security update — Help-Net Security

  • The email appears to be legitimate correspondence from LogMeIn, including company logo, spoofed sender identity and a link that appears legitimate.

Vigilante hackers target scammers with ransomware, DDoS attacks — Bleeping Computer

  • A hacker has been taking justice into their own hands by targeting “scam” companies with ransomware and denial of service attacks.

Tech Chiefs Press Cloud Suppliers for Consistency on Security Data — The Wall Street Journal

  • Each cloud company offers its own process on cybersecurity and governance, creating added work for customers.

Cell-tower attacks by idiots who claim 5G spreads COVID-19 reportedly hit US — Ars Technica

  • Wireless telecom providers are being warned to boost security as 5G conspiracy theorists ramp up attacks on cell towers and telecommunications workers.

Microsoft warns of ‘massive’ phishing attack pushing legit RAT — Bleeping Computer

  • Microsoft is warning of an ongoing COVID-19 themed phishing campaign that spreads via malicious Excel attachments.

Supercomputers hacked across Europe to mine cryptocurrency — ZDNet

  • Multiple supercomputers across Europe have been shut down to investigate cryptocurrency mining malware infections.

Microsoft opens up coronavirus threat data to the public — Cyberscoop

  • Microsoft has announced plans to make threat intelligence it collected on COVID-19-related hacking campaigns public.

NetWalker adjusts ransomware operation to only target enterprise — Bleeping Computer

  • NetWalker ransomware group is moving away from phishing for malware distribution and has adopted a network-intrusion model focusing on huge businesses only.

REvil Ransomware found buyer for Trump data, now targeting Madonna — Bleeping Computer

  • After breaching a prominent law firm, the REvil ransomware group is holding the personal information of high-profile celebrities for ransom.

In Case You Missed It

Cybersecurity News & Trends – 05-14-20

This week, we spotlight 5G conspiracy theorists, government-linked attacks, and two young hackers–one who “saved the internet,” the other an “evil genius.”


SonicWall Spotlight

What are the security priorities for the post-coronavirus world? — Computer Weekly

  • Terry Greer-King, EMEA vice-president at SonicWall, believes the pandemic has accelerated an ongoing transformational shift in cybersecurity, which was driven by the continued adoption of cloud-based resources.

Maintaining Business Continuity in Cyber Threat Environment — CIO Review

  • A Q&A on cybercrimes that have spiked during the current pandemic, the impact on different sectors and recommended strategies for businesses to handle the situation.

Lurking Cyber Threats on Social Media — Dataquest

  • Debasish Mukherjee, VP Regional Sales-APAC at SonicWall, discusses the current threats on social media — including misinformation campaigns, fake profiles, data mining and social engineering — that are posing an increasing threat to users.

Cybersecurity News

Merkel cites ‘hard evidence’ she was targeted by Russian hackers — The Hill

  • German Chancellor Angela Merkel told lawmakers Wednesday that she has seen “hard evidence” of Russia-based hacking attempts targeting her emails and those of the nation’s lawmakers.

The Confessions of Marcus Hutchins, the Hacker Who Saved the Internet — Wired

  • At 22, he single-handedly put a stop to the worst cyberattack the world had ever seen. Then he was arrested by the FBI. This is his untold story.

ProLock Ransomware teams up with QakBot trojan for network access — Bleeping Computer

  • ProLock is a relatively new form of ransomware, but it has quickly attracted attention by targeting businesses and local governments and demanding huge ransoms for file decryption.

Ransomware Reminder: Paying Ransoms Doesn’t Pay — Bank Info Security

  • Still don’t believe that paying the ransoms demanded by cybercriminals is a bad idea? A recent survey presents further proof.

Researchers expose new malware designed to steal data from air-gapped networks — Cyberscoop

  • ESET is hoping publicizing the malware will shake loose clues in their hunt for the enigmatic hackers.

Hackers Target WHO by Posing as Think Tank, Broadcaster — Bloomberg

  • Employees of the World Health Organization have been targeted with coronavirus-related emails purporting to be from news organizations and researchers — but which actually originate with an Iranian hacker group.

U.S. accuses China-linked hackers of stealing coronavirus research — Reuters

  • According to U.S. officials, China-linked hackers are breaking into American organizations researching COVID-19. The report warns scientists and public health officials to be on the lookout for cyber theft.

The 5G Coronavirus Conspiracy Theory Has Taken a Dark Turn — Wired

  • Though social networks have pledged to take more concerted action against conspiracy theories, the 5G hoax has continued to spread, inspiring a surge of attacks.

Sodinokibi ransomware can now encrypt open and locked files — Bleeping Computer

  • The Sodinokibi (REvil) ransomware has added a new feature that makes it easier to encrypt all files, even those that are opened and locked by another process.

Teen Hacker and Crew of ‘Evil Geniuses’ Accused of $24 Million Crypto Theft — Bloomberg

  • An adviser to blockchain companies is claiming a 15-year-old and his crew of “evil computer geniuses” stole $24 million in cryptocurrency from him by hacking into his phone.

In Case You Missed It

Cybersecurity News & Trends – 05-07-20

This week, healthcare continues to be in the crosshairs and ransomware-for-hire continues to mean big paydays for cybercriminals.


SonicWall Spotlight

Hackers Are Calling In The Raccoons — Fudzilla

  • Hackers are exploiting anxiety around Covid-19 to create new hooks for their malware, such as the new Raccoon Stealer variant uncovered by SonicWall’s Threat Research team

SonicWall Called Upon by Health Giant GNC to Rapidly Provide Protection of Remote, Mobile Workforce — CXOToday

  • SonicWall and GNC Holdings (GNC), a leading global health and wellness brand, are working closely to increase capacity of the company’s existing Secure Mobile Access (SMA) deployment to connect and secure the company’s growing volume of work-from-home employees.

Web-applications Attacks, Including SQL Injection Attacks, More Than Doubled In 2019, According To Data From Sonicwall — Security Boulevard

  • What is an SQL injection attack? How common are they? And why are they so devastating? Security Boulevard weighs in on these nefarious attacks, and gives tips on how to prevent them.

Cybersecurity News

It Has Been 20 Years Since Cybercrime Woke Up To Social Engineering With An Intriguing Little Email Titled ‘ILOVEYOU’ — The Register

  • Two decades have passed since cybercrooks demonstrated the role exploiting human psychology could play in spreading malware.

10 Questions With Tech Data Security Guru Alex Ryals On Security Trends And Training In Isolation — CRN

  • Learning about cybersecurity has never been more important — but with an abundance of styles and modules to choose from, it’s also never been easier.

Cyber-spies seek coronavirus vaccine secrets — BBC

  • The U.S. has seen foreign spy agencies carry out reconnaissance of research into a coronavirus vaccine, a senior U.S. intelligence official told the BBC — and similar reports have come from the UK as well.

Healthcare Targeted By More Attacks But Less Sophistication — Dark Reading

  • An increase in attacks targeting healthcare organizations suggests that perhaps new cybercriminals are getting into the game.

Sodinokibi, Ryuk ransomware drive up average ransom to $111,000 — Bleeping Computer

  • The first quarter of the year saw a 33% increase of the average amount ransomware operators demand from their victims compared to the previous quarter.

LockBit, the new ransomware for hire: a sad and cautionary tale — Ars Technica

  • A ransomware infection involving a recent strain called LockBit ransacked one company’s poorly secured network in a matter of hours, leaving leaders no viable choice other than to pay the ransom.

New Kaiji Botnet Targets IoT, Linux Devices — Threat Post

  • The botnet uses SSH brute-force attacks to infect devices and a custom implant written in the Go Language.

Phishing Attacks Against Banks Jump With Pandemic Used as Lure — Bloomberg

  • Cyber-attacks trying to trick bank employees into clicking on malicious links jumped in the first quarter, with criminals attempting to take advantage of fear and confusion caused by the coronavirus pandemic, Bloomberg reports.

SilverTerrier BEC scammers target US govt healthcare agencies — Bleeping Computer

  • Government healthcare agencies, COVID-19 response organizations, and medical research facilities from across the globe were the targets of Business Email Compromise (BEC) phishing campaigns coordinated by multiple Nigerian BEC actors during the last three months.

In Case You Missed It

Cybersecurity News & Trends – 05-01-20

This week, COVID-19 continued to be a boon for opportunistic hackers, who targeted everything from federal stimulus funds, to package recipients, to John Wick 3.


SonicWall Spotlight

Cutting Business Expenses Shouldn’t Include Cybersecurity – Channel Futures

  • HoJin Kim explains how Boundless Cybersecurity’s emphasis on scalable economics is helping companies secure their networks during the current economic downturn.

Social Distancing For IoT—No, You Aren’t Paranoid When You Say It! – PC Quest

  • Debasish Mukherjee, VP of regional sales APAC at SonicWall, discusses how the world of cybersecurity compares to the race to find a cure for the novel coronavirus.

COVID-19 Impact: Health and Wellbeing of Employees Have Taken Precedence – Arabian Reseller

  • Mohamad Abdallah, regional director for META, speaks about how COVID-19 has impacted business at SonicWall and the contingency plans the company has put into place in case the crisis persists or continues to worsen.

Cybersecurity News

Scammers pounce as stimulus checks start flowing – The Hill

  • The ongoing taxpayer stimulus is increasingly being targeted by scammers, who see the funds as easy pickings during the ongoing crisis.

FCC Only Partially Improved Its Cybersecurity Posture, GAO Says – Security Week

  • The Federal Communications Commission (FCC) has yet to fully address security weaknesses in its systems, a newly published report from the United States Government Accountability Office (GAO) reveals.

Shade Ransomware shuts down, releases 750K decryption keys – Bleeping Computer

  • The operators behind the Shade Ransomware (Troldesh) have shut down their operations, released over 750,000 decryption keys, and apologized for the harm they caused their victims.

Hackers spoof SBA to try to compromise companies’ computers – Cyberscoop

  • It isn’t just the taxpayer stimulus being targeted by bad actors—the funds distributed by the U.S. Small Business Administration to companies affected by COVID-19 are also in their crosshairs.

The Covid-19 Pandemic Reveals Ransomware’s Long Game – Wired

  • Hackers laid the groundwork months ago for attacks. Now they’re flipping the game.

Lucy malware for Android adds file-encryption for ransomware ops – Bleeping Computer

  • A threat actor focusing on Android systems has expanded their malware-as-a-service (MaaS) business with file-encrypting capabilities for ransomware operations.

COVID-19’s impact on package deliveries creates golden opportunity for scammers  – SC Magazine

  • Cybercriminals are using the disruption caused by COVID-19 to pose as delivery companies, as they attempt to swindle businesses into opening malicious emails or handing over their credentials.

Microsoft warns of malware-laced ‘John Wick 3,’ ‘Contagion’ movie torrents – Cyberscoop

  • Tens of thousands of internet users have been infected with malware as they attempt to torrent popular movies and wind up downloading more than they intended.

In Case You Missed It

Cybersecurity News & Trends – 04-24-20

This week, hackers continued to capitalize on the COVID-19 pandemic, targeting the healthcare industry, oil companies and remote workers.


SonicWall Spotlight

Czech Cyber Officials Warn Of Serious Threat To Health Care Sector – Cyberscoop

  • Cybersecurity authorities in the Czech Republic have warned of an “extensive campaign of cyberattacks” on IT systems and health care facilities. At least one of the malicious files in the Czech advisory is part of a batch of code used in a remote access hacking tool, which SonicWall reported last month.

SonicWall Boundless Cybersecurity Platform for Remote Working – CRN

  • SonicWall’s new Boundless Cybersecurity model is designed to protect and mobilize large enterprises, small- and medium-sized businesses, and government agencies from the risks of a remote workforce.

2,000 Coronavirus Scammers Taken Offline in NCSC Phishing Crackdown – Experts Reaction –  Information Security Buzz

  • The UK’s National Cyber Security Centre, along with the City of London Police and several other government agencies, has launched a ‘Suspicious email reporting service’ for members of the public to alert the authorities to potential cyber-attacks.

Cybersecurity News

Hacking against corporations surges as workers take computers home – Reuters

  • Hackers are targeting remote workers, particularly in highly impacted areas where users’ confusion and anxiety makes them more susceptible to phishing.

FBI enlists internet domain registries in fight against coronavirus scams – Cyberscoop

  • Ongoing cooperation between the government and technology companies has resulted in the removal of hundreds of fraudulent websites that included “coronavirus,” “covid19” and related phrases in their names.

Creative Skype phishing campaign uses Google’s .app gTLD – Bleeping Computer

  • Attackers have deployed a phishing campaign against remote workers using Skype, luring them with emails that mimic notifications from the service.

Hackers Target Top Officials at World Health Organization – Bloomberg

  • The WHO’s security team has been the target of an increasing number of attempted cyber-attacks since mid-March. According to officials, WHO itself has not been hacked, but employee passwords have leaked through other websites.

Hackers Target Oil Companies as Prices Plunge – Wired

  • Espionage hackers have commenced a sophisticated spear-phishing campaign concentrated on U.S.-based energy companies. The goal: install a notorious trojan to siphon their most sensitive communications and data.

Virtual army rising up to protect healthcare groups from hackers – The Hill

  • A new network of white hat hackers—made up of more than 1,400 volunteers in 76 countries, from sectors including information security, telecommunications and law enforcement—has banded together under the name COVID-19 CTI League to help protect the healthcare industry. 

Apple iPhone May Be Vulnerable to Email Hack – The Wall Street Journal

  • Sophisticated hackers may be attacking Apple iPhones by exploiting a previously unknown flaw in the smartphone’s email software.

Customer complaint phishing pushes network hacking malware – Bleeping Computer

  • A new phishing campaign is targeting remote employees, using fake customer complaints to install a backdoor that will compromise the corporate network.

Hackers Can Exfiltrate Data From Air-Gapped Computers Via Fan Vibrations – Security Week

  • With the use of new malware and a smartphone, researcher Mordechai Guri was able to exfiltrate data from air-gapped computers using vibrations from the machines’ internal fans.

 


In Case You Missed It

Cybersecurity News & Trends – 04-17-20

This week, SonicWall brings Boundless Cybersecurity to the remote workforce; Emotet, Ryuk and Trickbot deliver a 1-2-3 punch; and hackers use Apple for phishing bait.


SonicWall Spotlight

SonicWall Introduces Boundless Cyber Security Platform – Information Age

  • Boundless Cybersecurity aims to address a growing cybersecurity business gap and the complexity of securing remote workers compared to those working at company headquarters.

SonicWall: More Than 21,500 SecureFirst Partners Worldwide – MSSP Alert

  • SonicWall adds 1,100 SecureFirst partner in February and unveils a Boundless Cybersecurity model to protect mobile and remote workers against cyberthreats.

How to protect yourself against online COVID-19 scammers – Security Watch Info

  • As the COVID-19 pandemic continues to dominate the news cycle, cybercriminals are capitalizing on fear, stress and people’s desire for answers to gain access to personal information.

Cybersecurity News

North Korea hacking threatens U.S., other countries, international financial system: U.S. State Department – Reuters

  • The FBI joined the U.S. Departments of State, Treasury and Homeland Security in issuing an advisory about North Korean cyberthreats, warning the financial sector is particularly at risk.

Czechs Warn Hackers Are Preparing Cyber Attacks on Hospitals – Bloomberg

  • According to the Czech National Cyber and Information Security Agency, a campaign of cyberattacks on the country’s hospitals is expected in the coming days, Bloomberg reports.

The Pentagon Hasn’t Fixed Basic Cybersecurity Blind Spots – Wired

  • Five years ago, the Department of Defense set dozens of security hygiene goals. A new report finds that it has abandoned or lost track of most of them.

FBI warns of ongoing COVID-19 scams targeting govt, health care – Bleeping Computer

  • The U.S. Federal Bureau of Investigation has warned government agencies and health care organizations of ongoing BEC schemes exploiting the COVID-19 pandemic, as well as an overall increase in cryptocurrency and health care fraud scam activity targeting consumers.

The secret behind “unkillable” Android backdoor called xHelper has been revealed – Ars Technica

Emotet, Ryuk, TrickBot: ‘Loader-Ransomware-Banker Trifecta’ – Bank Info Security

  • The “loader-ransomware-banker” trifecta—Emotet, Ryuk and Trickbot—is stronger than the sum of its parts, causing millions of dollars in damages over the past few years.

Someone is passing around Valorant beta keys that are actually malware – Cyberscoop

  • Gamers hoping to access a closed beta for the video game Valorant are receiving keylogger software instead, as hackers attempt to capitalize on the hype surrounding the upcoming Riot Games release.

Apple Is Top Pick for Brand Phishing Attempts – Dark Reading

  • Have you received a suspicious-looking email purporting to be from Apple? You aren’t alone—10% of all brand phishing attempts in the first quarter of 2020 used the Apple brand in an attempt to deceive recipients.

In Case You Missed It

Cybersecurity News & Trends – 04-10-20

This week, SonicWall updates its MSSP program, the World Health Organization fends off phishing attempts, and hackers have a crisis of conscience… maybe.


SonicWall Spotlight

New SonicWall MSSP Program Boosts Pricing Options, Tech Support – CRN

  • SonicWall’s MSSP program has evolved from requiring customers to commit to an annual license from the get-go to offering both monthly and annual pricing options.

Addressing Cybersecurity Threats – Trending Business Insights

  • SonicWall’s VP of EMEA Sales, Terry Greer-King, talks about cybersecurity trends and SonicWall operations in the Middle East.

SonicWall Updates Its SecureFirst MSSP Program – Enterprise Times

  • Terry Greer-King, SonicWall VP of EMEA Sales, and Luca Taglioretti, SonicWall VP of Global MSSP & Carrier Sales, discuss spike licensing, the role training plays in the updated MSSP program, and more.

Cybersecurity News

Microsoft Exchange: 355,000 Servers Lack Critical Patch – Bank Info Security

  • Less than 20 percent of vulnerable Microsoft Exchange servers have received a fix for a serious flaw that Microsoft first disclosed nearly two months ago, potentially leaving them open for a remote attacker “to turn any stolen Exchange user account into a complete system compromise.”

Hackers struggle morally and economically over coronavirus – Bleeping Computer

  • With the coronavirus pandemic in full swing, threat actors are torn about how they should operate during the pandemic—and like everyone else, are also seeing a downturn in the marketplace.

‘Coronavirus’ malware can wreck your PC: What to do – Tom’s Guide

  • SonicWall has discovered a ‘coronavirus’ malware that aims to disable computers amid the COVID-19 crisis—but it turns out there’s an easy fix.

Is Remote Working A Threat To Your Business? – Disruption Hub

  • The rapid spread of the coronavirus and the sudden implementation of lockdown measures gave companies little time to prepare secure working from home strategies—and little time to educate employees on the potential security pitfalls of remote work.

Exclusive: Hackers linked to Iran target WHO staff emails during coronavirus – sources – Reuters

  • Hackers working in the interests of the Iranian government have attempted to break into the personal email accounts of staff at the World Health Organization during the coronavirus outbreak, four people with knowledge of the matter told Reuters.

A researcher found zero-days in one city’s software. Then he realized the problem could be bigger. – Cyberscoop

  • “He unpacked the code, sifted through it, and found more than a dozen previously undisclosed vulnerabilities, or zero-days, that a hacker could exploit to manipulate data or dump user passwords. But it was more than just a catalog of bugs: Poring over the code, Rhoads-Herrera found the names of two other city governments that have used the software.”

DarkHotel hackers use VPN zero-day to breach Chinese government agencies – ZDNet

  • More than 200 VPN servers have been hacked in this campaign, 174 of which were located on the networks of government agencies in Beijing and Shanghai, and the networks of Chinese diplomatic missions operating abroad in several countries.

Phishing emails impersonate the White House and VP Mike Pence – Bleeping Computer

  • Phishing scammers have begun impersonating President Donald Trump and Vice President Mike Pence in emails that distribute malware or perform extortion scams.

In Case You Missed It

Cybersecurity News & Trends – 04-03-20

This week, while remote workers and hospitals alike struggled to adjust to the new realities brought by the COVID-19 pandemic, hackers looked to exploit the upheaval for ill-gotten profit.


SonicWall Spotlight

There’s now COVID-19 malware that will wipe your PC and rewrite your MBR – ZDNet

  • Amidst the COVID-19 pandemic, some malware authors are releasing coronavirus-themed malware that destroys infected systems by either wiping files or rewriting a computer’s master boot record (MBR). The first of the MBR-rewriters was discovered by security researcher MalwareHunterTeam, as detailed in a report from SonicWall this week.

Cyber Security Threats Loom Large as Employees Work Remotely – The Week

  • According to SonicWall’s Capture Labs Threat Research Team, the risks of engaging with any coronavirus app—some of which purport to track infections or point to a vaccine—is very high, as hackers target newly minted remote workers in general, and those concerned about the virus in particular.

SonicWall Research Team Flags off 5 Top Cyberattacks in Times of COVID-19 Pandemic – CXO Today

  • The rise in employees working from home due to the COVID-19 pandemic is requiring that businesses provide employees secure access to remote infrastructure, networks and devices—and help safeguard against opportunistic cybercriminals preying on this new pool of remote workers.

Cybersecurity News

Marriott International Confirms Data Breach of Guest Information – Intelligent CISO

  • Terry Greer-King, VP EMEA at SonicWall, commented on the breach: “The Information Commissioner’s Office’s £99 million fine for Marriott in 2019 for a breach of GDPR was supposed to create much-needed reform on how the company processes and secures data. It appears that certain lessons are yet to be learned.”

Cyber Version of ‘Justice League’ Launches to Fight COVID-19 Related Hacks – Dark Reading

  • A group of cybersecurity experts from around the world—including from companies like Microsoft and Okta—have teamed to help organizations fight COVID-19-related hacking and phishing attacks, Dark Reading reports.

Hackers ‘Without Conscience’ Demand Ransom from Health Providers – Bloomberg

  • Bloomberg’s Ryan Gallagher reports on threats targeting the healthcare industry as healthcare providers deal with the massive influx of patients afflicted with COVID-19. Experts around the world are warning that hackers could keep doctors from vital patient data by encrypting records.

FBI warns Zoom, teleconference meetings vulnerable to hijacking – Cyberscoop

  • The warning comes after reports that Zoom—which is also under fire for leaking personal information to strangers and illegally selling user data to Facebook—isn’t securing communications as advertised.

Tech Giants Prepared for 2016-Style Meddling. But the Threat Has Changed. – The Wall Street Journal

  • The chairman of Huawei Technologies warned the U.S. to expect countermeasures from the Chinese government if it further restricts the technology giant’s access to suppliers, as the company’s profit last year grew at the slowest pace in three years.

Banking Malware Spreading via COVID-19 Relief Payment Phishing – Bleeping Computer

  • The Zeus Sphinx banking Trojan has recently resurfaced after a three years hiatus as part of a coronavirus-themed phishing campaign, one of many launched as hackers race to take advantage of the current pandemic.

FBI re-sends alert about supply chain attacks for the third time in three months – ZDNet

  • The FBI says a group state-sponsored hackers are now targeting the healthcare industry, which is currently grappling with the COVID-19 outbreak.

In Case You Missed It

Cybersecurity News & Trends – 03-27-20

This week, cybersecurity experts band together to tackle coronavirus-related cyberthreats, SonicWall traces scareware, and healthcare systems weather cyberattacks.


SonicWall Spotlight

How to Stay Cyber-Secure While Working From Home – Raconteur

  • Picking up on a recent SonicAlert about scareware Raconteur talks to SonicWall’s Terry Greer-King about the rise in Coronavirus-related malware as more and more people work from home.

Podcast #113 – Uber Knowledge

Elite Hackers Target WHO As Coronavirus Cyberattacks Spike – Information Security Buzz

  • With hackers reported to have tried to break into the World Health Organization earlier this month, SonicWall’s Terry Greer-King talks to Information Security Buzz about the ever-changing cyber threat landscape, explaining that real-time defense mechanisms are needed to deal with attacks that can also change in real-time.

Cybersecurity News

Coronavirus Hackers Face the Wrath of the Cybersecurity Community – Verdict

  • As COVID-19 continues to spread around the planet, cybersecurity professionals have started a grassroots fight against cybercriminals taking advantage. A group of over 600 expert volunteers is working to map and takedown the attack infrastructure, handing over to law enforcement anyone they can specifically identify.

Malware Disguised as Google Updates Pushed via Hacked News Sites – Bleepin Computer

  • Hacked corporate sites and news blogs running using the WordPress CMS are redirecting people who visit the websites to a fake Google-update phishing page that eventually installs malware on their computers.

Senator Sounds Alarm on Cyber Threats to Internet Connectivity During Coronavirus Crisis – The Hill

  • Senator Mark Warner, vice chairman on the Senate Intelligence Committee, is asking companies like Google to ensure that the cybersecurity on their products are absolutely of the highest possible standard, emphasizing that “it is… imperative that consumer Internet infrastructure not be used as attack vectors to consumer systems and workplace networks accessed from home.”

Hacker Selling Data of 538 Million Weibo Users – ZDNet

  • The personal details of more than 538 million users of Chinese social network Weibo have been put up for sale on the dark web. Personal details include real names, site usernames, gender, location, and some phone numbers, but not passwords.

Paris Hospitals Target of Failed Cyber-Attack, Authority Says – Bloomberg

  • The Paris hospital authority, AP-HP, was the target of a thwarted cyberattack on March 22, according to France’s cybersecurity agency.

Singapore Most Exposed, but Also Most Prepared in Cybersecurity: Deloitte – ZDNet

  • A new study by Deloitte has found that Singapore, with its high internet adoption rate, is the modern city that is both the most exposed to cyber threats and also most prepared to deal with them.

In Case You Missed It

Cybersecurity News & Trends – 03-20-20

This week, coronavirus changes the cybersecurity landscape, and SonicWall examines how to expand your remote workforce.


SonicWall Spotlight

How to Protect Your Business During a Global Health Crisis – SonicWall Blog

  • As the world works to stop the spread of coronavirus (COVID-19), IT organizations everywhere are adjusting to the technology and security challenges faced due to the sudden need to support a fully remote workforce. SonicWall presents the best practices for expanding your remote workforce, securely.

Threats Across the World: Lessons from Three Years of Threat Reporting – CBR Online

  • SonicWall’s Terry-Grear King details the changing cyber threat landscape over the past three years, concluding that the only viable solution to ever changing threats is ever changing defensive measures and constant vigilance.

Here’s What to Look for in a Work-From-Home VPN – Fortune

  • SonicWall CEO Bill Conner talks to Fortune about the recent scramble for VPN offerings as they examine what to look for in a VPN if you need to work from home in the current climate.

Don’t Forget Viruses, the Computer Kind – The New Stack

  • With so much news airtime dedicated to the spread of coronavirus, New Stack reminds readers that viruses of the computer kind have not gone away, referring to malware figures from the SonicWall 2020 Cyber Threat Report to do so.

Review: Small Businesses Get Big Protection With SonicWall Cloud App Security Biz Tech Magazine

  • SonicWall’s Cloud App Security gets a spin by Biz Tech Magazine who consider it simple enough for non-tech pros to set up and use while also proactive in finding and preventing malware propagation across the cloud.

Cybersecurity News

Thousands of COVID-19 Scam and Malware Sites are Being Created on a Daily Basis – ZDNet

  • As several SonicWall SonicAlerts have detailed, cybercriminals have wasted no time in taking advantage of the COVID-19 crisis, creating thousands of scam and malware sites on a daily basis. According to one researcher 3,600 new domains that contain the “coronavirus” term were created between March 14 and March 18.

DDoS Attack Trends Reveal Stronger Shift to IoT, Mobile – Dark Reading

  • Distributed denial-of-service (DDoS) attacks remain a popular attack vector but new research is finding that that cybercriminals are increasingly turning to mobile and Internet of Things (IoT) technologies to launch their campaigns. With the growth of 5G researchers anticipate attackers will continue to find ways to leverage the IoT to launch these attacks.

Senator Calls for Cybersecurity Review at Health Agencies After Hacking Incident – The Hill

  • Following an attempted hack of the Department of Health and Human Services, at a time when it is under great strain, Senator Michael Bennet of Colorado calls for health agencies to allow the Cybersecurity and Infrastructure Security Agency (CISA) to complete a full cybersecurity review of their systems.

France Warns of new Ransomware Gang Targeting Local Governments – ZDNet

  • France’s cybersecurity agency, CERT, has issued an alert warning of a new active ransomware gang using a new version of the Mespinoza ransomware strain. The gang has been detected actively targeting local government systems, with the agency receiving reports of multiple infections.
And Finally

Skimming Code Battle on NutriBullet Website may Have Risked Customer Credit Card Data – ZDNet

  • A tough week around the world or not, nothing stops Magecart gangs from chalking up another victim, this time Nutribullet, who had the card skimming code on their website from mid-February until as late this week.

In Case You Missed It