Remove 11
article thumbnail

A threat actor exploited 11 zero-day flaws in 2020 campaigns

Security Affairs

A hacking group has employed at least 11 zero-day flaws as part of an operation that took place in 2020 and targeted Android, iOS, and Windows users. Google researchers observed two separate waves of attacks that took place in February and October 2020, respectively. The exploit chains targeted Android, Windows, and iOS devices.

Security 135
article thumbnail

11 cyber security predictions for 2020

IT Governance

With that in mind, Geraint Williams, IT Governance’s chief information security officer, discusses his cyber security predictions in the upcoming year. However, many enterprise and large organisations and tech-savvy individuals will realise the benefits of multifactor authentication to secure their accounts.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

CJEU’s Judgment on Validity of EU Standard Contractual Clauses Due July 16, 2020

Hunton Privacy

Further, such a ruling would impact preparations for transferring personal data from the EU to the UK following termination of the Brexit transition period on December 31, 2020. View our previous blog posts on the progression of the case in May 2016 , October 2017 , August 2018 , July 2019 and May 2020. in the U.S.

article thumbnail

Threat actors are actively exploiting Zerologon flaw, Microsoft warns

Security Affairs

The CVE-2020-1472 flaw is an elevation of privilege that resides in the Netlogon. ” Microsoft strongly encourages administrators of enterprise Windows Servers to install the August 2020 Patch Tuesday as soon as possible to protect their systems from Zerologon attack that exploits the CVE-2020-1472. .”

article thumbnail

NAIC Insurance Data Security Law Annual Certifications: Is Yours Due By February 15?

Data Matters

The National Association of Insurance Commissioners’ (NAIC) Insurance Data Security Model Law has been adopted in at least 11 states, with several others (including New York) having implemented either older or similar laws or administrative guidance. See State Legislative Brief, NAIC, June 2020.

Insurance 114
article thumbnail

3CX Breach Was a Double Supply Chain Compromise

Krebs on Security

“Eventually, the threat actor was able to compromise both the Windows and macOS build environments,” 3CX said in an April 20 update on their blog. In many cases, the phony profiles spoofed chief information security officers at major corporations , and some attracted quite a few connections before their accounts were terminated.

Security 287
article thumbnail

Grandoreiro Malware implements new features in Q2 2020

Security Affairs

The updated Grandoreiro Malware equipped with latenbot-C2 features in Q2 2020 now extended to Portuguese banks. Cybercriminals attempt to compromise computers to generate revenue by exfiltrating information from victims’ devices, typically banking-related information. Figure 1: Grandoreiro email template Q2 2020 (Portugal).