This malvertising campaign targeted Russian organizations with an aim to compromise accountants’ computers. The six different malware families such include Buhtrap banking trojan, RTM banking trojan, Clipbanker trojan, VegaLocker ransomware, and cryptocurrency miners. ESET researchers have observed a new malvertising campaign that leverages Yandex.Direct network to distribute malware onto victims’ computers and steal cryptocurrency. Yandex.Direct is an online advertising network ...
Read More »Author Archives: firewallfirmadmin
New phishing scam impersonating Chase bank asks for sensitive data including selfies
A new phishing scam pretending to be from Chase bank targets customers’ PII, login credentials, banking details, as well as selfies. This way, the scammers have collected all the details right from basic details and credentials such as Chase account login credentials, email credentials, names, dates of birth, addresses, phone numbers, to sensitive information such as payment card details, Social ...
Read More »Asia-Pacific Supplants North America as Most Breached Region
The Asia-Pacific region led in the number of data compromises investigated in 2017, accounting for 35% of instances and overtaking North America at 30%, down from 43%. Europe, Middle East and Africa (EMEA) came in third at 27%, followed by Latin America & Caribbean (LAC) at 8%. The retail sector experienced the highest number of incidences at 18%. The finance ...
Read More »Fortinet – FortiGate Firewalls & Security Products
Fortinet – FortiGate Firewalls & Security Products FortiGate® Network Security Platform Single vendor, comprehensive portfolio Fortinet Consolidated Security Platform delivers unmatched performance and protection while simplifying your network. Fortinet’s Network Security Appliances offer models to satisfy any deployment requirement from the FortiGate-20 series for Small Offices to the FortiGate-5000 series for very Large Enterprises, Service Providers and Carriers. FortiGate platforms integrate ...
Read More »Firewall Checklist
Firewall Hardening Checklist This checklist should be used to audit a firewall. This checklist does not provide vendor specific security considerations but rather attempts to provide a generic listing of security considerations to be used when auditing a firewall.Only technical aspects of security are addressed in this checklist. Manual elements like physical protection for the firewall server is not considered. ...
Read More »Click Rates in Phishing Simulations = Major Cybersecurity Risks
A recent study found that healthcare organizations are most susceptible to phishing attempts, with employees clicking one in seven simulated emails sent. The research report, Assessment of Employee Susceptibility to Phishing Attacks at U.S. Healthcare Facilities, reveals current click rates in phishing simulations at U.S. healthcare organizations indicate a major cybersecurity risk. Under simulation, a large number of employees clicked on ...
Read More »Ransomware attack hits Cleveland Airport crippling email services and information screens
A ransomware attack hit Cleveland Hopkins International Airport disabling information screens displaying in-airport flight arrivals, departures and baggage claims. The City of Cleveland calls this attack as an isolated technical issue that has impacted a limited number of systems. What is the issue – On April 22, 2019, a ransomware attack hit Cleveland Hopkins Internation Airport disabling information screens that display ...
Read More »New Emotet trojan variant uses different POST-infection traffic to infect users
The malware variant is tracked as Trojan.W97M.POWLOAD and spreads via phishing emails. The email contains a malicious ZIP file, which if opened, results in the download of the malware. A new variant of Emotet trojan that leverages a new POST-infection traffic technique has been discovered recently. The malware variant is tracked as Trojan.W97M.POWLOAD and spreads via phishing emails. How does ...
Read More »New SMBdoor malware include characteristics of Double Pulsar and DarkPulsar exploit kits
The malware has been created with a purpose to help academicians in their research. The source code of the malware is neither weaponized for cybercrime nor released on GitHub. Two leaked NSA exploit kits have been used to create a malware named SMBdoor. The malware’s characteristics are similar to that of DoublePulsar and DarkPulsar. What’s the matter – SMBdoor is ...
Read More »Context-aware phishing campaign delivers Qbot trojan
A context-aware phishing email that includes a link to an online document is sent to the target. The phishing emails are disguised as delivery emails which are replies to existing email threads. What is the issue – A phishing campaign disguised as delivery emails which are replies to existing email threads, delivers the Qbot trojan. The big picture JASK SpecOps security ...
Read More »