Menu

Blog

Archive for the ‘cybercrime/malcode’ category: Page 27

Oct 12, 2023

Internet companies report biggest-ever denial of service operation

Posted by in categories: cybercrime/malcode, internet

WASHINGTON, Oct 11 (Reuters) — Internet companies Google, Amazon and Cloudflare say they have weathered the internet’s largest-known denial of service attack and are sounding the alarm over a new technique they warn could easily cause widespread disruption.

Alphabet Inc-owned Google (GOOGL.O)said in a blog post published Tuesday that its cloud services had parried an avalanche of rogue traffic more than seven times the size of the previous record-breaking attack thwarted last year.

Internet protection company Cloudflare Inc (NET.N)said the attack was “three times larger than any previous attack we’ve observed.” Amazon.com Inc’s (AMZN.O) web services division also confirmed being hit by “a new type of distributed denial of service (DDoS) event.”

Oct 12, 2023

Researchers Uncover Malware Posing as WordPress Caching Plugin

Posted by in category: cybercrime/malcode

A new malware disguises as a WordPress caching plugin, secretly creating admin accounts to control your site.

Oct 12, 2023

Researchers Uncover Ongoing Attacks Targeting Asian Governments and Telecom Giants

Posted by in categories: cybercrime/malcode, government

Cybersecurity experts uncover an ongoing threat to government and telecom entities in Asia. Learn how a campaign named “Stayin’ Alive” is deploying #malware.

Check out the details:

Oct 12, 2023

HTTP/2 Rapid Reset Zero-Day Vulnerability Exploited to Launch Record DDoS Attacks

Posted by in category: cybercrime/malcode

⚡ Beware of the HTTP/2 Rapid Reset attack!

A novel zero-day flaw is being exploited to launch record-breaking distributed #DDoS attacks.

Find out more here: https://thehackernews.com/2023/10/http2-rapid-reset-zero-day.html.

Continue reading “HTTP/2 Rapid Reset Zero-Day Vulnerability Exploited to Launch Record DDoS Attacks” »

Oct 11, 2023

Data Thieves Test-Drive Unique Certificate Abuse Tactic

Posted by in categories: cryptocurrencies, cybercrime/malcode

https://informatech.co/3RVp6BM by Elizabeth Montalbano.


Attackers are employing a new type of certificate abuse in an attempt to spread info-stealing malware, with the aim of collecting credentials and other sensitive data. In some instances, the goal is to steal cryptocurrency from Windows systems.

The campaign uses search engine optimization (SEO) poisoning to deliver search results featuring malicious pages promoting illegal software cracks and downloads. In the background, the pages deliver remote access Trojans (RATs) known as LummaC2, and RecordBreaker (aka Raccoon Stealer V2) researchers from South Korea-based AhnLab revealed in a blog post on Oct. 10.

Continue reading “Data Thieves Test-Drive Unique Certificate Abuse Tactic” »

Oct 11, 2023

Badbox Operation Targets Android Devices in Fraud Schemes

Posted by in categories: cybercrime/malcode, robotics/AI

After a researcher discovered that an Android TV streaming box, known as T95, was infected with preloaded malware, researchers at Human Security released information regarding the extent of infected devices and how malicious schemes are connected to these corrupted products.

Daniel Milisic, a systems security consultant, created a script alongside instructions to help other users mitigate the threat after first coming across the issue. Now, Human Security’s threat intelligence and research team has dubbed the operation “Bandbox,” which it characterizes as a complex, interconnected series of ad fraud schemes on a massive scale.

Human Security describes the operation as “a global network of consumer products with firmware backdoors installed and sold through a normal hardware supply chain.” Once activated, the malware on the devices connect to a command-and-control (C2) server for further instructions. In tandem, a botnet known as Peachpit is integrated with Badbox, and engages in ad fraud, residential proxy services, fake email/messaging accounts, and unauthorized remote code installation.

Oct 10, 2023

Preparing for the Unexpected: A Proactive Approach to Operational Resilience

Posted by in categories: cybercrime/malcode, finance

FS-ISAC executive shares tips on operational resilience in the face of cyber threats. #cyberattacks


Preparing for the unexpected may be a contradiction in terms, but for financial firms it is essential for survival. The sector has long been a target for threat actors, given that this is where the world’s money is. And as the financial ecosystem becomes increasingly interconnected, threats to its security and resilience are rapidly evolving and increasing.

Operational resilience is not just about responding with agility to risks but also maintaining continuity of operations with minimal or — even better — no disruptions. So, whereas cybersecurity is about preventing and defending against cyberattacks, resilience focuses on sustaining operations despite attacks.

Continue reading “Preparing for the Unexpected: A Proactive Approach to Operational Resilience” »

Oct 7, 2023

Attacks on Maximum Severity WS_FTP Bug Have Been Limited — So Far

Posted by in category: cybercrime/malcode

After an early flurry of exploit activity, attacks targeting a maximum-severity flaw that Progress Software disclosed in its WS_FTP Server file transfer product last week appear to have been somewhat limited so far.

However, that’s no reason for organizations to delay patching the vulnerability as soon as possible, given how widely attackers exploited a similarly critical zero-day flaw that Progress reported in its MOVEit file transfer software in May.

CVE-2023–40044 is a. NET deserialization vulnerability in WS_FTP that researchers have shown can be exploited with a single HTTPS POST and some specific multi-part data. Progress disclosed the bug on Sept. 27, with a recommendation for organizations to apply the company’s update for it as soon as possible.

Oct 6, 2023

23andMe Cyberbreach Exposes DNA Data, Potential Family Ties

Posted by in categories: biotech/medical, cybercrime/malcode, genetics

23andMe, the popular DNA testing company, has launched an investigation after client information was listed for sale on a cybercrime forum this week.

On Oct. 1, a post was published on the forum with a link to a sample of allegedly “20 million pieces of data” from the genetic testing company, claiming that it was “the most valuable data you’ll ever see.” The first leak included 1 million lines of data, but on Oct. 4, the threat actor began offering bulk data profiles ranging from $1 to $10 per account in batches of 100, 1,000, 10,000, and 100,000 profiles.

The information leaked in the breach includes names, usernames, profile photos, gender, birthdays, geographical location, and genetic ancestry results.

Oct 6, 2023

AI and Emerging Tech Challenges Call for Collaborative Solutions

Posted by in categories: cybercrime/malcode, policy, robotics/AI

Artificial intelligence (AI) and emerging technologies have ushered in a new era, bringing unprecedented opportunities and challenges. In today’s rapidly evolving digital landscape, addressing these multifaceted challenges necessitates a collaborative effort spanning various sectors and calls for policy reforms while emphasizing global cooperation.

The rapid advancement of technologies, particularly artificial intelligence, has introduced transformative possibilities alongside a range of concerns. While AI holds the potential to revolutionize industries and enhance our daily lives, it also raises pressing issues related to data privacy, misinformation, and cybersecurity.

Experts have proposed adopting the “information environment” framework to address these multifaceted challenges. This framework comprises three essential components:

Page 27 of 212First2425262728293031Last