Business email compromise (BEC) attacks have overtaken both ransomware and data breaches as the main reason companies filed a cyber-insurance claim in the EMEA region last year according to new research from insurance giant AIG.Statistics published by the firm in July revealed that BEC-related insurance filings accounted for 23 percent of all cyber-insurance claims received by … [Read more...] about Email attacks are now the biggest threat for businesses
Attacks
BitDefender Antivirus Free 2020 Vulnerable to Privilege Escalation Attacks
SafeBreach discovers yet another privilege escalation vulnerability on a security product. The flaw has similar grounds and method of exploitation as with last week’s news about Trend Micro. The root cause is again the lack of control in the DLL loading path and the absence of certificate validation. As reported by SafeBreach Labs and its security researcher, Peleg Hadar, … [Read more...] about BitDefender Antivirus Free 2020 Vulnerable to Privilege Escalation Attacks
Google’s OpenWeave and Nest Cameras Vulnerable to Takeover Attacks
Talos researchers discovered eight flaws that plague Nest IQ Indoor and the weaver binary. The attacks are not entirely easy or simple to carry out with success, but they are still possible. Users are urged to apply the latest patch that fixed all eight of the reported security flaws. Cisco Talos researchers Lilith Wyatt and Claudio Bozzato have discovered multiple security … [Read more...] about Google’s OpenWeave and Nest Cameras Vulnerable to Takeover Attacks
Trend Micro Password Manager Vulnerable to Privilege Escalation Attacks
Trend Micro Password Manager version 5.0 is found to be plagued by a privilege escalation flaw. An attacker could use an unsigned arbitrary DLL to execute code as a privileged user through the app. This would result in a complete Windows system takeover with incredibly serious consequences. If you are using the Trend Micro Password Manager v5.0 standalone, or the one that is … [Read more...] about Trend Micro Password Manager Vulnerable to Privilege Escalation Attacks
Valve Fixes Flaw in Steam That Allows Privilege Escalation Attacks
Valve fixed a Steam privilege escalation zero-day that they first deemed as “non-applicable” and “out of scope”. The hacker who reported the flaw to them thinks that the fix isn’t really effective, and can be bypassed. Gamers are urged to think about the launchers they are using, and run games as unprivileged users. Security researcher Vasily Kravets has sent an urgent … [Read more...] about Valve Fixes Flaw in Steam That Allows Privilege Escalation Attacks
