Dragonfly 2.0 Attack Campaign Targets Western Energy Sector

An attack campaign known as Dragonfly 2.0 is currently targeting Western energy companies with a variety of infection vectors. The series of attacks constitutes the latest push from Dragonfly, a threat actor which has been around since at least 2011 but then reemerged in 2014. Available evidence suggests the Dragonfly 2.0 attack campaign has been […]… Read More

The post Dragonfly 2.0 Attack Campaign Targets Western Energy Sector appeared first on The State of Security.

Continue reading Dragonfly 2.0 Attack Campaign Targets Western Energy Sector

Malware Campaign Exploits 2012 Windows Bug to Install NewCore Trojan

A malware campaign is exploiting a 2012 Windows flaw in order to infect a vulnerable machine with the NewCore remote access trojan (RAT). The campaign begins when a recipient receives an attack email that comes with an Rich Text Format (RTF) attachment. When opened, these documents exploit a 2012 remote code execution vulnerability affecting the […]… Read More

The post Malware Campaign Exploits 2012 Windows Bug to Install NewCore Trojan appeared first on The State of Security.

Continue reading Malware Campaign Exploits 2012 Windows Bug to Install NewCore Trojan

46.5M Attempted Phishing Attacks Detected by Kaspersky Lab in Q2 2017

Anti-malware providers see a lot of spam and phishing attempts through their users’ experiences. For its part, Kaspersky Lab understands how these encounters reveal the ever-evolving toolset of bad actors and their efforts to prey upon unsuspecting users. But it also knows users and security professionals alike can leverage information of these attacks to help […]… Read More

The post 46.5M Attempted Phishing Attacks Detected by Kaspersky Lab in Q2 2017 appeared first on The State of Security.

Continue reading 46.5M Attempted Phishing Attacks Detected by Kaspersky Lab in Q2 2017

Over 28 Million Taringa! User Records Exposed in Data Breach

Social networking platform Taringa! has confirmed a data breach that exposed nearly every record in its 28 million registered user base. On 4 September, data breach notification LeakBase disclosed a hack where attackers allegedly stole the records for 28,722,877 registered users of Taringa!, a popular Latin American social media site. The Hacker News obtained a […]… Read More

The post Over 28 Million Taringa! User Records Exposed in Data Breach appeared first on The State of Security.

Continue reading Over 28 Million Taringa! User Records Exposed in Data Breach

10 Essential Bug Bounty Programs of 2017

In 2015, The State of Security published a list of 11 essential bug bounty frameworks. Numerous organizations and even some government entities have launched their own vulnerability reward programs (VRPs) since then. With that in mind, I think it’s time for an updated list. Here are 10 essential bug bounty programs for 2017. 1. Apple […]… Read More

The post 10 Essential Bug Bounty Programs of 2017 appeared first on The State of Security.

Continue reading 10 Essential Bug Bounty Programs of 2017

Cancer Treatment Center Notifies 19K Patients of Ransomware Attack

A cancer treatment center has notified more than 19,000 patients of a ransomware attack that might have affected their personal and medical information. Medical Oncology Hematology Consultants, P.A. (“the Practice), which is located in the Helen F. Graham Cancer Center & Research Institute, detected the infection on 7 July 2017. Its analysis reveals the unknown […]… Read More

The post Cancer Treatment Center Notifies 19K Patients of Ransomware Attack appeared first on The State of Security.

Continue reading Cancer Treatment Center Notifies 19K Patients of Ransomware Attack

Should Security Researchers Protect Organizations by Any Means Necessary?

Responsible disclosure is the gold standard for fixing security vulnerabilities. But as we all know, sometimes at least one stakeholder doesn’t hold up their end of the agreement. Parties violate a responsible disclosure timeline for many reasons. Take the Zero Day Initiative, for instance. One of its security researchers discovered a vulnerability in Foxit’s PDF […]… Read More

The post Should Security Researchers Protect Organizations by Any Means Necessary? appeared first on The State of Security.

Continue reading Should Security Researchers Protect Organizations by Any Means Necessary?