Security News

So Wait, What Exactly IS the Dark Web?
2020-09-24 11:00

Some claim that the Dark Web is another definition of the anonymizing network TOR, while others claim that the Dark Web is mainly comprised of dissident sites, with illegal activity only being a small part of it. Considering the fact that in the security industry, the Dark Web is mainly referenced in the context of intelligence work, to best define the scope of the Dark Web we need to look at it from that perspective - with the eyes of an intelligence operation.

FBI boasts of dark-web drug bust: 179 collared around the world, $6.5m in cash and 500kg of narcotics seized
2020-09-23 05:08

A nine-month international operation spearheaded by the FBI has led to the arrest of 179 people across the world for selling drugs on the dark web. Operation DisrupTor, announced on Tuesday, also resulted in the seizure of $6.5m in cash and cryptocurrency as well as a 500kg haul of illegal drugs and 63 guns.

Global Police Sting Nets 179 Dark Web Sellers
2020-09-22 14:22

A global police sting has netted 179 vendors selling illegal goods online and seized millions in currency, drugs and guns, heralding an end to the "Golden age" of dark web markets, Europol said Tuesday. Led by the German federal criminal police "This takedown provided investigators with... data and materials to identify suspects behind dark web accounts used for illegal activity", Europol said.

Trustwave Fusion platform now also hosted on Amazon Web Services GovCloud
2020-09-18 00:00

Trustwave announced the Trustwave Fusion platform is now also hosted on Amazon Web Services GovCloud, providing U.S. government agencies and suppliers threat detection and response services to help address the constantly shifting threat landscape while meeting stringent U.S. Federal government security requirements. The cloud-native Trustwave Fusion platform delivers the first U.S.-only managed threat detection and response services hosted on AWS GovCloud and is in the process of FedRAMP authorization.

Zenscrape: A Simple Web Scraping Solution for Penetration Testers
2020-09-17 07:14

The Basics of Web Scraping First, some common terms you'll need to know:The Crawler: The web crawler or popularly known as a 'spider,' is an automated website scraping tool that skims through the internet for information. The Scraper: A scraper or web scraper is a comprehensive website scraper tool that quickly gathers unambiguous data from several web pages.

CISA Shares Details on Web Shells Employed by Iranian Hackers
2020-09-16 11:02

The U.S. Cybersecurity and Infrastructure Security Agency this week released a malware analysis report detailing web shells employed by Iranian hackers. Web shells provide the hackers with the ability to execute code on the victim systems, enumerate directories, deploy additional payloads, steal data, and navigate the victim network.

Report: 97% of Cybersecurity Companies Have Leaked Data on the Dark Web
2020-09-15 04:30

In a new report into the global cybersecurity industry's exposure on the Dark Web this year, global application security company, ImmuniWeb, uncovered that 97% of leading cybersecurity companies have data leaks or other security incidents exposed on the Dark Web, while on average, there are over 4,000 stolen credentials and other sensitive data exposed per cybersecurity company. Key findings that the research found relating to the leading global cybersecurity companies' exposure on the Dark Web included:97% of companies have data leaks and other security incidents exposed on the Dark Web.

Review: Web Security for Developers: Real Threats, Practical Defense
2020-09-15 03:30

After a short lesson in internet history, the author puts the reader in the shoes of the attacker and explains how simple it is to hack a website, as well as how easy it is to obtain and apply hacking tools. The author proceeds to offer basic knowledge about how the internet, browsers, web servers and programmers work.

Adtech's bogeymen are tracking everything - even your web visits to mental health charities, claim campaigners
2020-09-11 12:01

British charities are sharing information about people visiting their websites with adtech data brokers, according to a report. The alleged badness boils down to charity websites having tracking beacons embedded within them, little snippets of code that tell an advertiser who opened a particular website or webpage.

Fake web alerts – how to spot and stop them
2020-09-09 13:00

At SophosLabs we recently researched a collection of scams that exploit web advertising networks to pop up fake system alerts on both computers and mobile devices. The latest variations find other ways to cash in on fake alerts: using them as the entry point to technical support scams or prompting their victims to purchase fraudulent apps or "Fleeceware" off a mobile app store.