Sednit update: How Fancy Bear Spent the Year

The Sednit group — also known as Strontium, APT28, Fancy Bear or Sofacy — is a group of attackers operating since 2004, if not earlier, and whose main objective is to steal confidential information from specific targets. This article is a follow-up to ESET’s presentation at BlueHat in November 2017. Late in 2016 we published a white paper covering Sednit activity … More Sednit update: How Fancy Bear Spent the Year

All websites running WordPress urged to update NOW

Millions of websites running WordPress are being strongly urged to update to the latest version of the popular content management system as soon as possible, after a serious security vulnerability was uncovered. Anthony Ferrara, who discovered the WordPress flaw, starkly summed up the situation: “Today, a significant SQL-Injection vulnerability was fixed in WordPress 4.8.3. Before reading further, … More All websites running WordPress urged to update NOW

Money-making machine: Monero-mining malware

While the world is holding its breath, wondering where notorious cybercriminal groups like Lazarus or Telebots will strike next with another destructive malware such as WannaCryptor or Petya, there are many other, less aggressive, much stealthier and often very profitable operations going on. One such operation has been going on since at least May 2017, … More Money-making machine: Monero-mining malware

Trends 2017: Fewer vulnerabilities are being reported, but are we any safer?

The rapid global spread of technology, and the increasingly numerous types of interconnected devices routinely used, have greatly increased the number of attack vectors available to cybercriminals. This is why the exploitation of vulnerabilities is still one of our major concerns when it comes to corporate security incidents around the globe. For more detail, check out … More Trends 2017: Fewer vulnerabilities are being reported, but are we any safer?

ESET releases an EternalBlue Vulnerability Checker and a Crysis Variant Ransomware Decryptor

Both tools are available free on ESET webpage. ESET® has announced the release of two useful tools combating recent ransomware outbreaks, including WannaCry (WannaCryptor) and a variant of the infamous Crysis ransomware, which adds .wallet and .onion extensions to affected files. The first tool – EternalBlue Vulnerability Checker, inspects whether Windows is patched against the … More ESET releases an EternalBlue Vulnerability Checker and a Crysis Variant Ransomware Decryptor