πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Stealthy New DDoS Attacks Target Internet Service Providers πŸ•΄

Adversaries took advantage of the large attack surface of large communications networks to spread small volumes of junk traffic across hundreds of IP prefixes in Q3 2018, Nexusguard says.

πŸ“– Read

via "Dark Reading: ".
<b>&#9000; Bomb Threat, Sextortion Spammers Abused Weakness at GoDaddy.com &#9000;</b>

<code>Two of the most disruptive and widely-received spam email campaigns over the past few months β€” including an ongoing sextortion email scam and a bomb threat hoax that shut down dozens of schools, businesses and government buildings late last year β€” were made possible thanks to an authentication weakness at GoDaddy.com, the world’s largest domain name registrar, KrebsOnSecurity has learned.</code><code>Perhaps more worryingly, experts warn this same weakness that let spammers hijack domains registered through GoDaddy also affects a great many other major Internet service providers, and is actively being abused to launch phishing and malware attacks which leverage dormant Web site names currently owned and controlled by some of the world’s most trusted corporate names and brands.</code><code>Media</code><code>In July 2018, email users around the world began complaining of receiving spam which began with a password the recipient used at some point in the past and threatened to release embarrassing videos of the recipient unless a bitcoin ransom was paid. On December 13, 2018, a similarly large spam campaign was blasted out, threatening that someone had planted bombs within the recipient’s building that would be detonated unless a hefty bitcoin ransom was paid by the end of the business day.</code><code>Experts at Cisco Talos and other security firms quickly drew parallels between the two mass spam campaigns, pointing to a significant overlap in Russia-based Internet addresses used to send the junk emails. Yet one aspect of these seemingly related campaigns that has been largely overlooked is the degree to which each achieved an unusually high rate of delivery to recipients.</code><code>Large-scale spam campaigns often are conducted using newly-registered or hacked email addresses, and/or throwaway domains. The trouble is, spam sent from these assets is trivial to block because anti-spam and security systems tend to discard or mark as spam any messages that appear to come from addresses which have no known history or reputation attached to them.</code><code>However, in both the sextortion and bomb threat spam campaigns, the vast majority of the email was being sent through Web site names that had already existed for some time, and indeed even had a trusted reputation. Not only that, new research shows many of these domains were registered long ago and are still owned by dozens of Fortune 500 and Fortune 1000 companies. </code><code>That’s according to Ron Guilmette, a dogged anti-spam researcher who has made a living suing spammers and helping law enforcement officials apprehend online scammers. Researching the history and reputation of more than 5,000 Web site names used in each of the extortionist spam campaigns, Guilmette made a startling discovery: Virtually all of them had at one time been registered via GoDaddy.com, a Scottsdale, Ariz. based domain name registrar and hosting provider.</code><code>Guilmette told KrebsOnSecurity he initially considered the possibility that GoDaddy had been hacked, or that thousands of the registrar’s customers perhaps had their GoDaddy usernames and passwords stolen.</code><code>But as he began digging deeper, Guilmette came to the conclusion that the spammers were exploiting an obscure β€” albeit widespread β€” weakness among hosting companies, cloud providers and domain registrars that was first publicly detailed in 2016.</code><code>EARLY WARNING SIGNS</code><code>In August 2016, security researcher Matthew Bryant wrote about spammers hijacking some 20,000 established domain names to blast out junk email. A few months later, Bryant documented the same technique being used to take over more than 120,000 trusted domains for spam campaigns. And Guilmette says he now believes the attack method detailed by Bryant also explains what’s going on in the more recent sextortion and bomb threat spams.</code><code>Grasping…
⚠ Hijacked Nest cam broadcasts bogus warning about incoming missiles ⚠

A hacked Nest camera broadcast the fake warning about incoming North Korean missiles, sending a family into β€œfive minutes of sheer terror.”

πŸ“– Read

via "Naked Security".
⚠ Google fined $57m for data protection violations ⚠

In a landmark ruling, France’s data protection commissioner has fined Google 50 million Euros (around $57m) for violating Europe’s privacy laws.

πŸ“– Read

via "Naked Security".
❌ RogueRobin Malware Uses Google Drive as C2 Channel ❌

The RogueRobin uses a mix of novel techniques.

πŸ“– Read

via "Threatpost | The first stop for security news".
❌ Microsoft Windows RCE Flaw Gets Temporary Micropatch ❌

0patch released the fix for the remote code execution vulnerability in Windows, which has a CVSS score of 7.8.

πŸ“– Read

via "Threatpost | The first stop for security news".
⚠ PewDiePie-spammers and whale-flingers exploit hole in Atlas game ⚠

Last week hackers allegedly compromised an admin’s Steam account and used it to spawn planes, tanks, and whales in Atlas.

πŸ“– Read

via "Naked Security".
⚠ 100 million online bets exposed by leaky database ⚠

Online gamblers lose their private data as yet another unsecured Elasticsearch database is discovered.

πŸ“– Read

via "Naked Security".
⚠ Ep. 016 – Email fraud, Android apps, Collection #1 and the 10 year challenge [PODCAST] ⚠

Here's the latest Naked Security podcast. Enjoy!

πŸ“– Read

via "Naked Security".
πŸ” Trojan malware is back and it's the biggest hacking threat to your business πŸ”

Old school but effective, hackers are shifting aware from in-your-face ransomware to attacks that are much more subtle.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Discover New Tools for Network Testing & Defense at Black Hat Asia πŸ•΄

Find yourself some of the latest and most exciting cybersecurity tools at the Arsenal, where you can meet and chat with their creators.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Enterprise Malware Detections Up 79% as Attackers Refocus πŸ•΄

A new report on the state of malware shows a spike in B2B malware, with former banking Trojans Emotet and TrickBot topping the list.

πŸ“– Read

via "Dark Reading: ".
πŸ” Hackers impersonate these 10 brands the most in phishing attacks πŸ”

Phishers often spoof major tech brands in their efforts to gain payments from individuals and businesses, according to a Vade Secure report.

πŸ“– Read

via "Security on TechRepublic".
❌ U.S. Gov Issues Urgent Warning of DNS Hijacking Attacks ❌

An emergency directive from the Department of Homeland Security provides "required actions" for U.S. government agencies to prevent widespread DNS hijacking attacks.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ” How to authenticate a Linux client with LDAP server πŸ”

If you've ever wanted to authenticate a Linux desktop to an OpenLDAP server, here's how it's done.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to authenticate a Linux client with LDAP server πŸ”

With OpenLDAP, you can manage users on a centralized directory server and then configure each desktop to authenticate to that server.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Think Twice Before Paying a Ransom πŸ•΄

Why stockpiling cryptocurrency or paying cybercriminals is not the best response.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Cybercriminals Home in on Ultra-High Net Worth Individuals πŸ•΄

Research shows that better corporate security has resulted in some hackers shifting their sights to the estates and businesses of wealthy families.

πŸ“– Read

via "Dark Reading: ".
πŸ” Security is the no. 1 IT barrier to cloud and SaaS adoption πŸ”

More than 70% of tech professionals said security spending has increased in the past year, according to a Ping Identity report.

πŸ“– Read

via "Security on TechRepublic".
❌ β€˜Chaos’ iPhone X Attack Alleges Remote Jailbreak ❌

The attack makes use of previously disclosed critical vulnerabilities in the Apple Safari web browser and iOS.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ” How to Lock a User Account After X Number of Incorrect Logins on Cent OS 7 πŸ”

Jack Wallen shows you how to lock out users after failed login attempts in CentOS 7.

πŸ“– Read

via "Security on TechRepublic".