December 20, 2021
New phishing campaigns steal credentials through malicious QR codes, PowerPoint files
There are a number of ways to increase password strength, but it all means nothing if your credentials are stolen. A series of new phishing campaigns shows increased focus on info-stealing tactics.
December 15, 2021
HR management provider Kronos hit by ransomware
Kronos, the provider of workforce management and human capital management solutions, has suffered a significant ransomware attack that threatens to disrupt payroll and timesheet processing services for its customer organizations.
December 15, 2021
Malicious Notepad++ installers drop StrongPity malware
Notepad++, one of the most popular, and free, text and source code editors for Windows systems, is being used by attackers to distribute malware.
December 13, 2021
Critical Apache Log4j vulnerability discovered — here's what you need to know
Late last week, a critical zero-day vulnerability in the popular Java logging library Log4j surfaced when attackers were observed exploiting Minecraft servers via the game’s chat box. It has since become clear that the vulnerability in question poses perhaps the largest security threat we’ve seen in years.Details are still unfolding, but here’s what we know now.
December 05, 2021
Windows Defender generates numerous Emotet-related false positives
Shortly after Trickbot was observed dropping an updated version of the Emotet botnet malware, Windows Defender began incorrectly reporting certain executables and Microsoft Office documents as Emotet payloads.
December 04, 2021
Japanese hospital will rebuild computer systems after ransomware strike
Handa Hospital, in the Japanese town of Tsurugi, has announced that following a ransomware attack this past October, they will be spending around ¥200 million to build a new computer system instead of paying the demanded ransom.
December 01, 2021
Phishing attacks are booming, says Anti-Phishing Working Group
The Anti-Phishing Working Group (APWG), an international consortium (of which Acronis is a member) that aims to unify the global response against cybercrime, has released their Q3 2021 trend report.
November 30, 2021
VenomRAT: A remote access tool with dangerous consequences
The first messages about VenomRAT started to appear in June 2020. By analyzing the code, analysts concluded that this new threat is a modified fork of Quasar RAT. The malware itself was introduced on malware-oriented forums, in posts advertising it as an effective tool to remotely access computers for $150 per month.
November 26, 2021
Trojan-as-a-service: From Formbook to XLoader
Discovered in 2016, Formbook appeared on underground forums, advertised as an infostealer for Windows. In October 2020, Formbook was renamed XLoader; as its developers say, it has the same features, but has improved from the previous version. XLoader can steal users’ information from various browsers, email clients and messengers, and is available to cybercriminals as a service.
November 23, 2021
Conti ransomware rakes in over $25 million in just four months
Conti, one of the most prolific ransomware-as-a-service (RaaS) platforms, has earned its operators at least $25.5 million in payouts since July 2021.
November 22, 2021
Chrome version 96 includes fixes for multiple serious vulnerabilities
Google recently released Chrome version 96, the latest, most secure version of their highly popular web browser. This update introduces fixes for 25 security vulnerabilities, seven of which are considered to be high severity. Some have already been the cause of zero-day attacks.
November 14, 2021
Password-stealing malware found in two popular NPM libraries
Malware has been discovered hidden in Coa and RC, two popular libraries for JavaScript package manager NPM.