Security News

ScarCruft APT Mounts Desktop/Mobile Double-Pronged Spy Attacks
2021-11-29 19:08

The North Korea-linked ScarCruft advanced persistent threat group has developed a fresh, multiplatform malware family for attacking North Korean defectors, journalists and government organizations involved in Korean Peninsula affairs. ScarCruft specifically controls the malware using a PHP script on a compromised web server, directing the binaries based on HTTP parameters.

Dark web market Cannazon shuts down after massive DDoS attack
2021-11-29 18:26

Cannazon, one of the largest dark web marketplaces for buying marijuana products, shut down last week after suffering a debilitating distributed denial of service attack. The admins posted that message on November 23, 2021, and today, Cannazon went offline, allegedly forever.

Phishing attacks top 260,000 in Q3 2021
2021-11-29 04:30

An APWG's report reveals that it saw 260,642 phishing attacks in July 2021 - the highest monthly total observed since APWG began its reporting program in 2004. Overall, the number of phishing attacks has doubled from early 2020.

Cloud Security: Don’t wait until your next bill to find out about an attack!
2021-11-26 19:58

Firstly, crooks show up fast: occasionally, it takes them days to find newly-started, insecure cloud instances and break in, but Google wrote that discover-break-and-enter times were "As little as 30 minutes." Importantly, in our research, the cloud instances we used weren't the sort of cloud server that a typical company would set up, given that they were never actually named via DNS, advertised, linked to, or used for any real-world purpose.

Defense contractors are highly susceptible to ransomware attacks
2021-11-25 03:30

Twenty percent of America's largest 100 defense contractors are highly susceptible to a ransomware attack, according to a research from Black Kite. Nearly 43% of federal defense contractors have out-of-date systems, contributing to a "D+" rating in patch management.

Ukraine arrests ‘Phoenix’ hackers behind Apple phishing attacks
2021-11-24 14:57

The Security Service of Ukraine has arrested five members of the international 'Phoenix' hacking group who specialize in the remote hacking of mobile devices. The goal of 'Phoenix' was to gain remote access to the accounts of mobile device users and then monetize them by hijacking their e-payment or bank accounts or selling their private information to third parties.

Ransomware attacks surge, but victims are recovering quickly
2021-11-24 06:00

Cymulate announced the results of a survey, revealing that despite the increase in the number of ransomware attacks this past year, overall victims suffered limited damage in both severity and duration. Key highlights More than half - whether previously hit by ransomware or not - don't feel confident they can fend off a ransomware attack.

Researchers warn of severe risks from ‘Printjack’ printer attacks
2021-11-23 18:05

A team of Italian researchers has compiled a set of three attacks called 'Printjack,' warning users of the significant consequences of over-trusting their printer. The first type of Printjack attack is to recruit the printer in a DDoS swarm, and threat actors can do this by exploiting a known RCE vulnerability with a publicly available PoC. The researchers use CVE-2014-3741 as an example but underline that at least a few dozen other vulnerabilities are available in the MITRE database.

Guarding against DCSync attacks
2021-11-23 06:30

Threat actors can launch DCSync attacks using tools like Mimikatz or the Get-ADReplAccount cmdlet from DSInternals. Stopping DCSync attacks is not as easy.

As digital shopping surges, researchers predict 8 million daily attacks
2021-11-22 06:00

"Based on intelligence garnered from the Arkose Labs Network, we predict a 60 percent increase in attacks for the upcoming 2021 holiday shopping season. No digital business is immune to this threat." It is estimated that eight million attacks will occur daily during the 2021 holiday shopping season that is now underway.