Skip to main content

Security Blog

Filter by:

HKCERT Urges Users of Remote Access Tools and NAS Devices to Beware of Ransomware Attacks

(Hong Kong, 19 October 2021) The Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT) of the Hong Kong Productivity Council is urging local users of remote access tools and network-attached storage (NAS) devices to step up security to fend off...
Release Date: 21 Oct 2021 3671 Views

OWASP Top 10-2021 is Now Released

Introduction   Open Web Application Security Project (OWASP), a non-profit foundation dedicated to web application security, has recently published its latest Top 10 web application security (AppSec) risks (OWASP Top 10). Widely recognized in the IT industry, OWASP Top 10...
Release Date: 4 Oct 2021 9961 Views

“HKT Hong Kong Enterprise Cyber Security Readiness Index 2021” Up 2.7 Points to 49.6 Both Enterprises and Employees Are Urged to Strengthen Cyber Security Awareness to Defend Against Cyber Attacks Amid Rampant Phishing Emails

Updated on 27-October-2021: The full report of “HKT HK Enterprise Cyber Security Readiness Index 2021” has been added below.   The Hong Kong Productivity Council (HKPC) released the results of the “HKT Hong Kong Enterprise Cyber Security Readiness Index 2021...
Release Date: 29 Sep 2021 9461 Views

HKCERT Urges Microsoft Windows Users to be Vigilant Against Malicious Exploit of Critical Vulnerability

Updated on 15-September-2021: Microsoft has released patch to fix this vulnerability in Monthly Security Update on 15-September-2021, please refer to Microsoft Monthly Security Update (September 2021) for details.   (Hong Kong, 13 September 2021) The Hong...
Release Date: 15 Sep 2021 8586 Views

Introducing “Check Your Cyber Security Readiness” Online Self-Assessment Tools

The Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT) had previously complied  the “Seven Habits of Cyber Security for SMEs” guideline to improve cyber defence of SMEs through seven cyber security aspects. The guideline came with a simple self-assessment checklist for...
Release Date: 7 Sep 2021 16320 Views

Patch Vulnerabilities in Remote Access and Remote Storage Now

The COVID-19 pandemic has seen a surge in the adoption of remote access solutions such as virtual private networks (VPNs), remote storage and cloud-based technologies in remote office scenarios. However, these solutions have also exposed a new attack surface to the Internet...
Release Date: 1 Sep 2021 10446 Views

Beware of Malicious or Vulnerable Third Party Dependencies

Rapid growth in third-party dependencies (including open-source libraries, packages and container images, etc.) has significantly changed the modern software development process. Most applications nowadays are built on a combination of in-house and external code. Public open-source...
Release Date: 4 Aug 2021 8326 Views

Ransomware Keep Evolving: Multiple Extortion

Ransomware attacks are currently causing extensive havoc worldwide, becoming one of the biggest cyber threats nowadays. More and more companies and organisations have been materially affected. According to a ransomware report, the average ransomware payment in 2021 Q1 was US$ 220,298, (HK...
Release Date: 22 Jun 2021 7037 Views

Beware of Flash Phishing Attacks

In the first quarter of this year, HKCERT has processed over 300 phishing attack incidents per month on average, up about 30% from same period last year. Apart from the increase in cases, HKCERT has also noticed that hackers have been using new techniques, ...
Release Date: 7 Jun 2021 8119 Views

Protect sensitive information in the use of social media and beware of potential cyber attacks arising from data leakages

The security issue of placing personal information on social media platforms heightened once again after reports of serious data leakages at three of the world’s biggest operators in early April this year:   Data of 533 million Facebook users were exposed publicly [1]; Data of 500...
Release Date: 27 Apr 2021 9346 Views