720-891-1663

Attacks on (Critical) Industrial Infrastructure Increase as Defenders Struggle

In 2022 security companies that track these attacks saw a rise in the number and sophistication of attacks on critical infrastructure. They also saw the introduction of a malware toolkit with plugins to attack tens of thousands of control systems across every industry. Responders discovered, not surprisingly, that the vast majority (more than 75%) of […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Security News Update for the Week Ending February 10, 2023

If You Think the Chinese Balloon Incident is a Major Wake-up call … China has been spying on the US for decades. And we have been spying on them. Kind of like Spy vs. Spy in Mad Magazine when we were kids. If you think that the balloon gave China important information – above the […]

Continue reading → [DISPLAY_ACURAX_ICONS]

State-Sponsored Hackers Changing Tactics to Put Companies at Risk

State-sponsored threat groups increasingly use ransomware-like attacks as cover to hide more insidious activities. Russian advanced persistent threat (APT) group Sandworm used ransomware programs to destroy data multiple times over the past six months while North Korea’s Lazarus group used infrastructure previously associated with a ransomware group for intelligence gathering campaigns. Chinese state sponsored hackers […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Hacker Uses Verified Microsoft Account to Compromise Users

Microsoft has a badge, sort of like Twitter and just like Twitter, apparently these badges can be hacked. Security firm Proofpoint first discovered the attack involving three rogue apps which were impersonating single signon and online meeting apps. If the user installs these rogue apps, they ask for permissions to their Microsoft 365 account, which […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Password Managers

Simple title; not necessarily a simple question. The current spotlight is on LastPass and its parent company GoTo. As we know, LastPass was compromised over the summer, but, it appears from what we know, that even though the hackers stole some of the password vaults, assuming your master password was strong, we think you are […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Security News for the Week Ending January 20, 2023

New York Gov Signs Right to Repair Law While industry lobbyists have done their best to water down New York’s right to repair law (and they were relatively successful at it), it is a start. It goes into effect in July, 2023 and while it excludes electronics used in government and schools, has other ridiculous […]

Continue reading → [DISPLAY_ACURAX_ICONS]