MosaicRegressor: Lurking in the Shadows of UEFI

We found a compromised UEFI firmware image that contained a malicious implant. To the best of our knowledge, this is the second known public case where malicious UEFI firmware in use by a threat actor was found in the wild. Continue reading MosaicRegressor: Lurking in the Shadows of UEFI

Zero Day Survival Guide | Everything You Need to Know Before Day One

0-days may be more common than you think, but you’re not defenseless against the unknown. Read all about 0-day attacks and how to protect against them.
The post Zero Day Survival Guide | Everything You Need to Know Before Day One appeared first on Secu… Continue reading Zero Day Survival Guide | Everything You Need to Know Before Day One

IT threat evolution Q1 2019

Zebrocy and GreyEnergy, four zero-day vulnerabilities in Windows, attacks on cryptocurrency exchanges, a very old bug in WinRAR, attacks on smart devices and other events of the first quarter of 2019. Continue reading IT threat evolution Q1 2019

Hacking Team’s New Owner: ‘We’re Starting From Scratch’

The head of Memento Labs, the new company that acquired infamous spyware vendor Hacking Team, admitted there’s a lot to do to recover after the 2015 breach and the damage to its reputation. But he believes it can compete against market leaders NSO Group. Continue reading Hacking Team’s New Owner: ‘We’re Starting From Scratch’

Adobe patches newly exploited Flash zero-day

Adobe has released an out-of-band security update for Flash Player that fixes two vulnerabilities, one of which is a zero-day (CVE-2018-15982) that has been spotted being exploited in the wild. About the vulnerability (CVE-2018-15982) CVE-2018-15982 is… Continue reading Adobe patches newly exploited Flash zero-day

It’s Amateur Hour in the World of Spyware and Victims Will Pay the Price

We’re living in the golden age of spyware and government hacking, with companies rushing to join a blossoming billion dollar market. The weakest among us—activists or journalists—will suffer the consequences if we don’t regulate it appropriately. Continue reading It’s Amateur Hour in the World of Spyware and Victims Will Pay the Price

Powerful Smartphone Malware Used to Target Amnesty International Researcher

Human rights charity Amnesty International has found hackers attempted to infect one of their researcher’s phones with malware from Israeli vendor NSO Group. Continue reading Powerful Smartphone Malware Used to Target Amnesty International Researcher