Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the accelerated-mobile-pages domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Deprecated: Optional parameter $options declared before required parameter $ad is implicitly treated as a required parameter in /www/cisomagcom_810/public/wp-content/plugins/advanced-ads/classes/display-conditions.php on line 208

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the easy-digital-downloads domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the edd_cfm domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the edds domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the edd-recurring domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Deprecated: Optional parameter $params declared before required parameter $secretWord is implicitly treated as a required parameter in /www/cisomagcom_810/public/wp-content/plugins/edd-2checkout/sdk/lib/Twocheckout/TwocheckoutReturn.php on line 6

Deprecated: Optional parameter $insMessage declared before required parameter $secretWord is implicitly treated as a required parameter in /www/cisomagcom_810/public/wp-content/plugins/edd-2checkout/sdk/lib/Twocheckout/TwocheckoutNotification.php on line 6

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the edd-recurring domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the Newsmag domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Warning: Cannot modify header information - headers already sent by (output started at /www/cisomagcom_810/public/wp-includes/functions.php:6121) in /www/cisomagcom_810/public/wp-content/themes/Newsmag/functions.php on line 616

Warning: Cannot modify header information - headers already sent by (output started at /www/cisomagcom_810/public/wp-includes/functions.php:6121) in /www/cisomagcom_810/public/wp-includes/feed-rss2.php on line 8
Spain Archives - CISO MAG | Cyber Security Magazine Beyond Cyber Security Fri, 12 Mar 2021 11:00:40 +0000 en-US hourly 1 https://wordpress.org/?v=6.8.1 Ryuk Ransomware Takes Down Systems of Spanish Government Agency, SEPE https://staging-cisomagcom.kinsta.cloud/ryuk-ransomware-takes-down-systems-of-spanish-government-agency-sepe/ Fri, 12 Mar 2021 11:00:40 +0000 https://staging-cisomagcom.kinsta.cloud/?p=10682 The network systems of the State Public Employment Service (SEPE) were taken down temporarily after a ransomware attack hit more than 700 agency offices across Spain. In an official statement, the SEPE director Gerardo Guitérrez claimed that Ryuk ransomware operators were behind the security incident. Reportedly, the attackers encrypted the systems with Ryuk ransomware. However, Guitérrez clarified […]

The post Ryuk Ransomware Takes Down Systems of Spanish Government Agency, SEPE appeared first on CISO MAG | Cyber Security Magazine.

]]>
The network systems of the State Public Employment Service (SEPE) were taken down temporarily after a ransomware attack hit more than 700 agency offices across Spain. In an official statement, the SEPE director Gerardo Guitérrez claimed that Ryuk ransomware operators were behind the security incident. Reportedly, the attackers encrypted the systems with Ryuk ransomware. However, Guitérrez clarified that payroll information, unemployment benefits, and other personal data were not affected by the ransomware attack.

SEPE is a Spanish government agency for labor that provides employment opportunities to the public. The ransomware attack disrupted hundreds of thousands of users who had their appointment scheduled with the agency. The ransomware is said to have spread beyond SEPE’s workstations and also targeted the agency’s remote working employees’ devices.

“Currently, work is being done to restore priority services as soon as possible, among which is the portal of the State Public Employment Service, and then gradually other services to citizens, companies, benefit and employment offices. The application deadlines for benefits are extended by as many days as the applications are out of service. In no case will this situation affect the rights of applicants for benefits. Confidential data is safe. The payroll generation system is not affected and the payment of unemployment benefits and ERTE will be paid normally,” Guitérrez said.

Ryuk Ransomware Gang Made Over $150 Mn

Ryuk is a ransomware-as-a-service (RaaS) active since August 2018. The group attacked more than 20 health care organizations last year. A series of Ryuk ransomware attacks targeted multiple hospitals in the U.S. Cybercriminals compromised critical network systems across six hospitals in a single day. A recent analysis found that the Ryuk ransomware operators earned more than $150 million worth of Bitcoins from ransom payments after their cyber intrusions globally.

The post Ryuk Ransomware Takes Down Systems of Spanish Government Agency, SEPE appeared first on CISO MAG | Cyber Security Magazine.

]]>
Cerberus – A Banking Trojan Disguised as Currency Converter https://staging-cisomagcom.kinsta.cloud/cerberus-banking-trojan/ Wed, 08 Jul 2020 15:10:42 +0000 https://staging-cisomagcom.kinsta.cloud/?p=6303 Researchers from Avast discovered a malicious Android app “Cerberus” on the Google Play store spreading a banking Trojan. The Trojan was being spread via a Spanish currency converter app “Calculadora de Moneda” targeting Android users in Spain since March 2020, with 10,000 downloads already. The researchers stated that Cerberus Trojan, if downloaded, can steal banking […]

The post Cerberus – A Banking Trojan Disguised as Currency Converter appeared first on CISO MAG | Cyber Security Magazine.

]]>
Researchers from Avast discovered a malicious Android app “Cerberus” on the Google Play store spreading a banking Trojan. The Trojan was being spread via a Spanish currency converter app “Calculadora de Moneda” targeting Android users in Spain since March 2020, with 10,000 downloads already. The researchers stated that Cerberus Trojan, if downloaded, can steal banking credentials, bypass security measures, access text messages, and even alter two-factor authentication (2FA).

“As is common with banking malware, Cerberus disguised itself as a genuine app in order to access the banking details of unsuspecting users. What is not so common is that a banking Trojan managed to sneak onto the Google Play Store. To avoid initial detection, the app hid its malicious intentions for the first few weeks while being available on Google Play. During this time, the app acted normally as a legitimate converter, and it does not steal any data or cause any harm. This was possibly to stealthily acquire users before starting any malicious activities, which could have grabbed the attention of malware researchers or Google’s Play Protect team,” the researchers said in a statement.

The Cerberus Trojan app operates stealthily to gain the trust of users and steals their banking data later. The app executes itself in three different stages:

  • In the first stage, the Calculadora de Moneda app appears normal and does not steal any data from users who have downloaded it.
  • In the second stage, the normal looking app turns into a malicious dropper, which is intended to download another malicious app onto a device, without the user’s knowledge.
  • In the final stage, the app activates the malicious Trojan to access the existing genuine banking app on the victim’s device and wait for the user to log in. The Trojan creates a layover on the login screen to capture the credentials.

Avast stated that the malicious app has been taken down after it reported the findings to Google.

Protection Against Banking Trojans

Avast recommended users certain mitigation measures to protect themselves from mobile banking Trojans, these include:

  • Confirm that the app you are using is a verified banking app. If the interface looks unfamiliar or odd, double-check with the bank’s customer service team.
  • Use two-factor authentication if your bank offers it as an option.
  • Only rely on trusted app stores, such as Google Play or Apple’s App Store. Even though the malware slipped into Google Play, its payload was downloaded from an external source. If you deactivate the option to download apps from other sources, you will be safe from this type of banking Trojan activating on your phone.
  • Before downloading a new app, check its user ratings. If other users are complaining about a bad user experience, it might be an app to avoid.
  • Pay attention to the permissions an app requests. If you feel that the app is requesting more than it promises to deliver, treat this as a red flag.
  • Often, malware will ask to become a device administrator to get control over your device. Don’t give this permission to an app unless you know this really is necessary for an app to work.

Not the First Time

In 2019, Kaspersky discovered the Ginp Banking Trojan, which lures Android users to steal their credit card credentials.

For more information, read, “Ginp Banking Trojan Lures Android Users Amidst COVID-19 Outbreak

 

 

The post Cerberus – A Banking Trojan Disguised as Currency Converter appeared first on CISO MAG | Cyber Security Magazine.

]]>
GDPR Data Breach Notifications Rise by 66% Across Europe https://staging-cisomagcom.kinsta.cloud/gdpr-data-breach-notifications/ Tue, 30 Jun 2020 11:13:41 +0000 https://staging-cisomagcom.kinsta.cloud/?p=6197 A survey by multinational law firm Linklaters revealed that GDPR-related data breach notifications across European countries have increased by 66%, compared to the first year of the GDPR (from May 25, 2018 to May 24, 2019). However, the U.K. witnessed a decline in notifications, with a 17% drop compared to the notifications reported in the […]

The post GDPR Data Breach Notifications Rise by 66% Across Europe appeared first on CISO MAG | Cyber Security Magazine.

]]>
A survey by multinational law firm Linklaters revealed that GDPR-related data breach notifications across European countries have increased by 66%, compared to the first year of the GDPR (from May 25, 2018 to May 24, 2019). However, the U.K. witnessed a decline in notifications, with a 17% drop compared to the notifications reported in the first year of the GDPR (11,499 notifications). The numbers doubled in France, with a total of 2,287 notifications (97% increase). Spain reported 1,608 data breach notifications, with a 58% increase. It is also found that Poland reported a high number of notifications when compared to other EU countries with 6,039 data breach notifications in 2019.

The analysis stated that the surge in data breach notifications in both France and Spain is because the companies were aware of their data security obligations. The reasons for  the decline in data breach notifications in the U.K. include:

  • Organizations over-reporting data breaches after the initial implementation of the GDPR
  • The U.K.’s Information Commissioner’s Office (ICO) issued a warning on the over-reporting of data breaches
  • The U.K. is having high breach notifications compared to other countries in the first year of the GDPR

Most of the data breach notifications stemmed from breach of confidential data or access by unauthorized third parties. The survey also highlighted that attackers mostly targeted on clients and employees to steal data with various hacking activities like malware attacks, phishing e-mails, and compromising victims’ unsecured devices.

In addition, the analysis also highlighted the number of fines ordered under the GDPR in the last year. It said that only one fine was reported in the U.K., while 112 fines were ordered by the Spanish DPA, 10 by the Italian DPA, 9 by the Belgian DPA, 6 by the CNIL in France, 13 in Germany, and 5 in Poland. The findings are based on the data analysis across seven European countries, namely Belgium, France, Germany, Italy, Poland, Spain, and the U.K.

Tanguy Van Overstraeten, Partner and Global Head of Linklaters’ Privacy and Data Protection Practice, said, “The harmonization of data protection rules across the EU has been largely successful under the GDPR; however, there are still significant differences among Member States – impacting uniformity of enforcement across the EU. Only harmonizing the approach towards the determination of sanctions will not be sufficient, the interpretation of the rules should also be common to all the Member States. Businesses need certainty and a more unified approach across the EU.”

Overstraeten added “There is also a danger of GDPR fatigue amongst businesses and the Covid-19 crisis is impacting budgets which could limit resources to ensure compliance going forward. The further simplification and harmonization of data protection rules across the EU will be key to ensure companies can sustain this effort.”

 

The post GDPR Data Breach Notifications Rise by 66% Across Europe appeared first on CISO MAG | Cyber Security Magazine.

]]>