Malware from notorious FIN7 group is being delivered by snail mail

While hackers all over the world rely on emails and text messages to breach networks, one infamous criminal group appears to be turning to the mailman to deliver their malicious code. Malware authored by FIN7, which researchers say has stolen over $1 billion in recent years, has been delivered by the U.S. Postal Service to multiple organizations in recent months, according to security company FireEye. The code comes on USB sticks that, once inserted into a computer, install a “backdoor,” called Griffon, capable of stealing sensitive information. The malicious code, which multiple security companies have attributed to FIN7, burrows into the target computer and beacons back to the group for further instructions. How many of the USB deliveries led to network breaches remains unclear. The hacking attempts raise questions about how a group thought to be based in Eastern Europe, and one that U.S. officials have hunted for years, has been […]

The post Malware from notorious FIN7 group is being delivered by snail mail appeared first on CyberScoop.

Continue reading Malware from notorious FIN7 group is being delivered by snail mail

Trustwave releases consulting and managed security services for Palo Alto Networks Prisma Cloud

Trustwave unveiled a new portfolio of consulting and managed security services for Palo Alto Networks Prisma Cloud, the industry’s most comprehensive cloud native security platform (CNSP) designed to govern access, protect data and secure applications…. Continue reading Trustwave releases consulting and managed security services for Palo Alto Networks Prisma Cloud

‘Windows Update’ Installs Cyborg Ransomware

A malicious spam campaign that informs victims it contains a “critical Windows update” instead leads to the installation of Cyborg ransomware, researchers have found. Further, they were able to access its builder, which can be used to creat… Continue reading ‘Windows Update’ Installs Cyborg Ransomware

When is the right time to red team?

It takes a thief to catch a thief. Despite being hundreds of years old, this idiom holds perfectly true for that most modern of thieves, the cybercriminal. With adversaries consistently evolving their tools and techniques to overcome defensive solution… Continue reading When is the right time to red team?

Trustwave offers threat detection and response capabilities for Microsoft Azure

Trustwave announced the launch of services to bolster threat monitoring, detection and response natively in Microsoft Azure. As a preferred global managed security services provider (MSSP) partner, Trustwave is offering consulting and professional serv… Continue reading Trustwave offers threat detection and response capabilities for Microsoft Azure

New infosec products of the week: October 18, 2019

Pradeo Secure Private Store facilitates and expands safe BYOD usage Pradeo launched a unique Secure Private Store solution that allows organizations to distribute mobile services to their collaborators (public and private apps, documents), that they ca… Continue reading New infosec products of the week: October 18, 2019

Trustwave Security Testing Services connects organizations to security resources

Trustwave announced Trustwave Security Testing Services, a comprehensive portfolio that gives enterprises and government agencies the unprecedented ability to acquire, apply and fully manage security scanning and testing across diverse environments thr… Continue reading Trustwave Security Testing Services connects organizations to security resources

New infosec products of the week: September 6, 2019

Trustwave launches Trustwave Fusion, a new cloud-based cybersecurity platform The Trustwave Fusion platform connects the digital footprints of enterprises and government agencies to a robust security cloud comprised of the Trustwave data lake, advanced… Continue reading New infosec products of the week: September 6, 2019

Trustwave launches Trustwave Fusion, a new cloud-based cybersecurity platform

Trustwave announced a cloud-based cybersecurity platform that serves as the foundation for the company’s managed security services, products and other cybersecurity offerings. The Trustwave Fusion platform is purpose built to meet the enterprise where … Continue reading Trustwave launches Trustwave Fusion, a new cloud-based cybersecurity platform