Vadokrist: A wolf in sheep’s clothing

ESET researchers published today another installment in their ongoing series of Latin American banking trojans. Since 2018 they have investigated Vadokrist, a trojan that is specifically focused on Brazil. The malware utilizes backdoor functionality and is distributed via malicious spam emails targeting financial institutions. Unlike most other Latin American banking trojans, Vadokrist does not collect … More Vadokrist: A wolf in sheep’s clothing

DNSpooq bugs expose millions of devices to DNS cache poisoning

Security flaws in a widely used DNS software package could allow attackers to send users to malicious websites or to remotely hijack their devices. Millions of devices could be vulnerable to Domain Name System (DNS) cache poisoning and remote code execution attacks due to seven security flaws in dnsmasq, DNS forwarding and caching software commonly found in smartphones, … More DNSpooq bugs expose millions of devices to DNS cache poisoning

ESET discovers Operation Spalax: Colombian government and industry sector under targeted attack

In 2020, ESET researchers observed several attacks exclusively targeting Colombian entities, which have collectively been dubbed Operation Spalax. These attacks are ongoing and are focused on both government institutions and private companies, especially in the energy and metallurgical industries. The attackers rely on the use of remote access trojans, most likely to conduct cyber-espionage activities.  … More ESET discovers Operation Spalax: Colombian government and industry sector under targeted attack

WhatsApp delays privacy policy update after confusion, backlash

Millions of people flock to Signal and Telegram as WhatsApp scrambles to assuage users’ concerns. A little more than a week after announcing changes to its Privacy Policy and Terms of Service, WhatsApp is now postponing the enforcement of its new data sharing rules until May 15th. “We’re now moving back the date on which people will be asked to … More WhatsApp delays privacy policy update after confusion, backlash