Archive for the ‘cybercrime/malcode’ category: Page 97

Jul 16, 2020

New BlackRock Android malware can steal passwords and card data from 337 apps

Posted by in categories: cybercrime/malcode, finance, robotics/AI

Android apps targeted by this new trojan include banking, dating, social media, and instant messaging apps.

Jul 16, 2020

Russia trying to steal COVID-19 vaccine data, say UK, U.S. and Canada

Posted by in categories: biotech/medical, cybercrime/malcode

2020 is officially a movie:

Russian hackers are trying to steal COVID-19 vaccine and treatment research from pharmaceutical and academic institutions, according to Britain’s National Cyber Security Centre.

Hackers backed by the Russian state are trying to steal COVID-19 vaccine and treatment research from academic and pharmaceutical institutions around the world, Britain’s National Cyber Security Centre (NCSC) said on Thursday.

Continue reading “Russia trying to steal COVID-19 vaccine data, say UK, U.S. and Canada” »

Jul 15, 2020

Chainalysis Says Bitcoin Scammed From Twitter Users Is ‘On the Move’

Posted by in categories: bitcoin, cryptocurrencies, cybercrime/malcode

Scammers are everywhere now.

The defrauded bitcoin amassed during Wednesday’s monumental Twitter hack is already “on the move,” according to cryptocurrency tracing firm Chainalysis.

Jul 15, 2020

Scott Morrison targets cybercrime with $748m in new initiatives and expanded security workforce

Posted by in categories: cybercrime/malcode, employment, government

Scott Morrison will unveil $748m in new cyber security initiatives, with the planned reallocation of resources from within the defence portfolio rising to $1.35bn over a decade once the government unveils a new cyber security strategy in coming months.

Resources reallocated from defence portfolio are planned to rise to $1.35bn over a decade with 500 new jobs created.

Jul 14, 2020

Microsoft warns of critical Windows DNS Server vulnerability that’s “wormable”

Posted by in category: cybercrime/malcode

Microsoft is urging system administrators to urgently install updates to fix a 17-year-old Windows DNS Server vulnerability. Microsoft has rated the flaw at the highest level for remote code execution, but exploits haven’t yet been developed.

Jul 14, 2020

DARPA: Hack Our Hardware

Posted by in category: cybercrime/malcode

DARPA is running a bug bounty aimed at further hardening new malware-proof architectures.

Jul 9, 2020

PQShield raises $7M for quantum-ready cryptographic security solutions

Posted by in categories: cybercrime/malcode, quantum physics

A deep tech startup building cryptographic solutions to secure hardware, software, and communications systems for a future when quantum computers may render many current cybersecurity approaches useless is today emerging out of stealth mode with $7 million in funding and a mission to make cryptographic security something that cannot be hackable, even with the most sophisticated systems, by building systems today that will continue to be usable in a post-quantum future.

PQShield (PQ being short for “post-quantum”), a spin out from Oxford University, is being backed in a seed round led by Kindred Capital, with participation also Crane Venture Partners, Oxford Sciences Innovation and various angel investors, including Andre Crawford-Brunt, Deutsche Bank’s former global head of equities.

PQShield was founded in 2018, and its time in stealth has not been in vain.

Jul 9, 2020

Researchers determine how to accurately pinpoint malicious drone operators

Posted by in categories: cybercrime/malcode, drones, encryption, robotics/AI

Researchers at Ben-Gurion University of the Negev (BGU) have determined how to pinpoint the location of a drone operator who may be operating maliciously or harmfully near airports or protected airspace by analyzing the flight path of the drone.

Drones (small commercial unmanned ) pose significant security risks due to their agility, accessibility and low cost. As a result, there is a growing need to develop methods for detection, localization and mitigation of malicious and other harmful aircraft operation.

The paper, which was led by senior lecturer and expert Dr. Gera Weiss from BGU’s Department of Computer Science, was presented at the Fourth International Symposium on Cyber Security, Cryptography and Machine Learning (CSCML 2020) on July 3rd.

Jul 9, 2020

DARPA Announces First Bug Bounty Program to Hack SSITH Hardware Defenses

Posted by in categories: cybercrime/malcode, internet, mobile phones, robotics/AI

Electronic systems – from the processors powering smartphones to the embedded devices keeping the Internet of Things humming – have become a critical part of daily life. The security of these systems is of paramount importance to the Department of Defense (DoD), commercial industry, and beyond. To help protect these systems from common means of exploitation, DARPA launched the System Security Integration Through Hardware and Firmware (SSITH) program in 2017. Instead of relying on patches to ensure the safety of our software applications, SSITH seeks to address the underlying hardware vulnerabilities at the source. Research teams are developing hardware security architectures and tools that protect electronic systems against common classes of hardware vulnerabilities exploited through software.

To help harden the SSITH hardware security protections in development, DARPA today announced its first ever bug bounty program called, the Finding Exploits to Thwart Tampering (FETT) Bug Bounty. FETT aims to utilize hundreds of ethical researchers, analysts, and reverse engineers to deep dive into the hardware architectures in development and uncover potential vulnerabilities or flaws that could weaken their defenses. DARPA is partnering with the DoD’s Defense Digital Service (DDS) and Synack, a trusted crowdsourced security company on this effort. In particular, FETT will utilize Synack’s existing community of vetted, ethical researchers as well as artificial intelligence (AI) and machine learning (ML) enabled technology along with their established vulnerability disclosure process to execute the crowdsourced security engagement.

Bug bounty programs are commonly used to assess and verify the security of a given technology, leveraging monetary rewards to encourage hackers to report potential weaknesses, flaws, or bugs in the technology. This form of public Red Teaming allows organizations or individual developers to address the disclosed issues, potentially before they become significant security challenges.

Jul 9, 2020

Cyber Command will get a new version of its training platform this fall

Posted by in categories: cybercrime/malcode, health

U.S. Cyber Command’s new training platform is slated to deliver the second iteration this fall providing additional capabilities and user capacity, program officials said.

The Persistent Cyber Training Environment (PCTE) is an online client that allows Cyber Command’s warriors to log on from anywhere in the world to conduct individual or collective cyber training as well as mission rehearsal. The program is being run by the Army on behalf of the joint cyber force and Cyber Command.

Officials delivered the first version of the program to Cyber Command in February and the environment was used for the first time in Cyber Command’s premier annual tier 1 exercise Cyber Flag in June. The second version is expected to include additional capabilities, including allowing more users to conduct team or individual training.

Page 97 of 170First949596979899100101Last