Tag Archive for: Poorly

Russian hackers exploiting ‘poorly maintained’ Cisco routers for malware, security agencies warn


Pixabay


RESEARCH TRIANGLE PARK –  A group of Russian hackers known as APT28 also known as Fancy Bear is deploying malware in the West by exploiting what cybersecurity agencies in the U.S. and U.K.  call “poorly maintained Cisco routers.”

The group is described as a “highly skilled threat actor.”

Here is the joint warning announcement and explanation:

“The UK National Cyber Security Centre (NCSC), the US National Security Agency (NSA), US Cybersecurity and Infrastructure Security Agency (CISA) and US Federal Bureau of Investigation (FBI) are releasing this joint advisory to provide details of tactics, techniques and procedures (TTPs) associated with APT28’s exploitation of Cisco routers in 2021.

“We assess that APT28 is almost certainly the Russian General Staff Main Intelligence Directorate (GRU) 85th special Service Centre (GTsSS) Military Intelligence Unit 26165. APT28 (also known as Fancy Bear, STRONTIUM, Pawn Storm, the Sednit Gang and Sofacy) is a highly skilled threat actor.”

To download the UK PDF version of this report:

To download the US PDF version of this report:

Earlier Activity

Previously attributed the following activity to APT28:

Related APT28 links

 

Source…

Google Play Store’s Security System Continues to Fare Poorly at Identifying Android Malware / Digital Information World


AV-TEST has recently conducted a detailed analysis of antivirus software available for the Android, coming to the conclusion that Google Play Protect might serve as the worst of the lot. This, compounded upon by other malware breaches across Google products, might spell issues for the company.

AV-TEST, an independent antivirus evaluation agency, has made its living out of researching the effectivity certain products have against malware. Based in Magdeburg, Germany, the organisation particularly deals with software catering to Windows and Android. Software that meets a certain standard established by AV-TEST is also granted certification by them, which carries a significant amount of weight.

Their most recent list, amassing data from November, graded software on the basis of 3 categories: protection, performance, and usability. These 3 give a comprehensive report as to the level of security your device is offered, how smooth the antivirus runs, and how accessible it is to the general public. Each category was further scored out of 6. Google Play Protect, while given a supring zero in usability and a 6 in performance, was, sadly, granted zero in protection. Which might raise an eyebrow or two, especially considering past events with Google products. It also shows, relying solely on Google’s protection systems can be a risky decision for security-savvy Android users.

Avast reported, rather recently, that over 3 million users across Google Chrome and Microsoft Edge may have been exposed to malware via add-ons, extensions, and plugins that the browsers were unable to filter through. While this itself is no reason to hold Google accountable as even Avast antivirus itself was unable to nail down the threat in time, the Play Store tells a different story.

Malware often makes it onto the Store, particularly marketed towards demographics that would typically not know any better than to download it. Kaspersky Labs, an cybersecurity firm, recently highlighted 20 different malware containing apps disguised as Minecraft mods targeted towards young children unaware of the dangers such sources pose. Recently, a fake Cyberpunk 2077 mobile app was also spotted, which would hold user data at random…

Source…

Misconfigurations, Poorly Managed Access Help Drive Data Breach Risks – Security Boulevard

Misconfigurations, Poorly Managed Access Help Drive Data Breach Risks  Security Boulevard
“data breach” – read more

Poorly Written Blog Post Hides Google+ Data Breach

  1. Poorly Written Blog Post Hides Google+ Data Breach  PR News – For Smart Communicators (blog)
  2. Google to shut Google Plus after failing to disclose user data breach  MediaNama.com
  3. Google limits third-party app access to users’ data  Economic Times
  4. Google API Services: User Data Policy | Google Developers  Google Developers
  5. Google Exposed User Data, Feared Repercussions of Disclosing to Public  Wall Street Journal
  6. Full coverage

data breach – read more