Posts


Mar. 2, 2018

Putin boasts new strategic weapons will make US missile defense “useless”

Putin boasts new strategic weapons will make US missile defense “useless”

In his State of the Nation speech today, Russian president Vladimir Putin showed computer animations and videos demonstrating three new classes of strategic weapons under development that are specifically intended to defeat the United States’ ballistic missile defenses. Among them were two weapons powered by miniaturized nuclear reactors: a drone submarine ‘torpedo’ previously revealed in a Russian news leak and a cruise ‘missile’ drone with what Putin described as a virtually unlimited range. The third was a new non-ballistic, hypersonic ICBM capable of evading US missile interceptors.

Mar. 2, 2018

Memcrashed – Major amplification attacks from UDP port 11211

Memcrashed – Major amplification attacks from UDP port 11211

Over last couple of days we’ve seen a big increase in an obscure amplification attack vector – using the memcached protocol, coming from UDP port 11211. In the past, we have talked a lot about amplification attacks happening on the internet.

Source: cloudflare.com

Mar. 2, 2018

Memcached-fueled 1.3 Tbps attacks

Memcached-fueled 1.3 Tbps attacks

At 17:28 GMT, February 28th, Akamai experienced a 1.3 Tbps DDoS attack against one of our customers, a software development company, driven by memcached reflection. This attack was the largest attack seen to date by Akamai, more than twice the size of the September, 2016 attacks that announced the Mirai botnet and possibly the largest DDoS attack publicly disclosed. Because of memcached reflection capabilities, it is highly likely that this record attack will not be the biggest for long.

Mar. 2, 2018

Equifax finds ANOTHER 2.4 million Americans hit by breach

Equifax finds ANOTHER 2.4 million Americans hit by breach

Just when you thought the Equifax clustermuck couldn’t get any muckier, the credit broker found another 2.4 million Americans affected by its 2017 breach.

Source: sophos.com

Mar. 2, 2018

The Powerful Global Spy Alliance You Never Knew Existed

The Powerful Global Spy Alliance You Never Knew Existed

The “SIGINT Seniors” is a spy agency coalition that meets annually to collaborate on global security issues. It has two divisions, each focusing on different parts of the world: SIGINT Seniors Europe and SIGINT Seniors Pacific. Both are led by the U.S. National Security Agency, and together they include representatives from at least 17 other countries.

Members of the group are from spy agencies that eavesdrop on communications – a practice known as “signals intelligence,” or SIGINT.

Mar. 2, 2018

Norway Used NSA Technology for Potentially Illegal Spying

Norway Used NSA Technology for Potentially Illegal Spying

Behind an abandoned military facility 40 miles northwest of Oslo, Norway built a surveillance base in close collaboration with the National Security Agency. Its bright, white satellite dishes, some of them 60 feet in diameter, stand out against the backdrop of pine-covered hills and red-roofed buildings that scatter the area.

Source: theintercept.com

Mar. 2, 2018

A 1.3Tbs DDoS Hit GitHub, the Largest Yet Recorded

A 1.3Tbs DDoS Hit GitHub, the Largest Yet Recorded

On Wednesday, at about 12:15 pm ET, 1.35 terabits per second of traffic hit the developer platform GitHub all at once. It was the most powerful distributed denial of service attack recorded to date—and it used an increasingly popular DDoS method, no botnet required.

Source: wired.com

Mar. 2, 2018

GitHub February 28th DDoS Incident Report

GitHub February 28th DDoS Incident Report

On Wednesday, February 28, 2018 GitHub.com was unavailable from 17:21 to 17:26 UTC and intermittently unavailable from 17:26 to 17:30 UTC due to a distributed denial-of-service (DDoS) attack. We understand how much you rely on GitHub and we know the availability of our service is of critical importance to our users. To note, at no point was the confidentiality or integrity of your data at risk.

Mar. 2, 2018

New Study Shows 20% of Public AWS S3 Buckets are Writable

New Study Shows 20% of Public AWS S3 Buckets are Writable

Data exposure reports have reached a dizzying pace in the past few months, and the security community has been focused on the risk from multiple angles. Now, a new study from HTTPCS gives us new insight into rates of vulnerable S3 configurations.

Source: tripwire.com

Mar. 2, 2018

23,000 HTTPS certificates axed after CEO emails private keys

23,000 HTTPS certificates axed after CEO emails private keys

A major dust-up on an Internet discussion forum is touching off troubling questions about the security of some browser-trusted HTTPS certificates when it revealed the CEO of a certificate reseller emailed a partner the sensitive private keys for 23,000 TLS certificates.

Source: arstechnica.com

Mar. 2, 2018

The Rising Tide of China’s Human Intelligence

The Rising Tide of China’s Human Intelligence

On Jan. 15, FBI agents arrested Jerry Chun Shing Lee, a former CIA case officer, and charged him with unlawful retention of classified information. Lee is the sixth person charged by the Justice Department in the past two years for espionage-related offenses suspected to have been conducted on behalf of the People’s Republic of China. By comparison, prior to 2015, only one or two people on average per year were arrested for such offenses.

Mar. 2, 2018

Instagram image of Lego assault rifle, threat lead to 14-year-old’s arrest

Instagram image of Lego assault rifle, threat lead to 14-year-old’s arrest

According to a Wednesday statement released by the San Diego County Sheriff’s Department, the unnamed 14-year-old boy posted a picture around 10pm Tuesday evening on Instagram with the message, ‘Don’t come to school tomorrow.’ Another student asked him to take the image down, but he refused.

Source: arstechnica.com

Mar. 1, 2018

RedDrop: the blackmailing mobile malware family lurking in app stores

RedDrop: the blackmailing mobile malware family lurking in app stores

The latest zero-day threat to be discovered by Wandera’s mobile threat research team is RedDrop, a family of mobile malware inflicting financial cost and critical data loss on infected devices.

Source: wandera.com

Mar. 1, 2018

Massive Malspam Campaign Targets Unpatched Systems

Massive Malspam Campaign Targets Unpatched Systems

According to cybersecurity firm Morphisec, cybercriminals are blasting spam messages that urge recipients to click a link to download a Word document. And when a victim opens the document and enables macros, malware attempts to exploit an Adobe Flash Player bug (CVE-2018-4878)  patched by Adobe earlier this month.

 Victims who fall for the ploy could ultimately hand over control of their systems to an attacker, according to researchers.

Mar. 1, 2018

China using big data to detain people before crime is committed

China using big data to detain people before crime is committed

If the system flags anything suspicious – a large purchase of fertilizer, perhaps, or stockpiles of food considered a marker of terrorism – it notifies police, who are expected to respond the same day and act according to what they find. ‘Who ought to be taken, should be taken,’ says a work report located by the rights organization.

Source: theglobeandmail.com

Mar. 1, 2018

How to Turn Off Facebook’s Face Recognition Features

How to Turn Off Facebook’s Face Recognition Features

Facebook recently expanded its face recognition features—and you may have opted in without even realizing it.

Source: wired.com

Mar. 1, 2018

Single Sign-On authentication – the bug that lets you logon as someone else

Single Sign-On authentication – the bug that lets you logon as someone else

Duo found that buggy SAML libraries would read the NameID string in various ways, sometimes as [email protected] (treating the comment as a terminator for the data field), and sometimes as [email protected] (simply treating the comment as it it were not there at all).

Source: sophos.com

Mar. 1, 2018

Self-proclaimed Bitcoin creator accused of $5 billion crypto heist

Self-proclaimed Bitcoin creator accused of $5 billion crypto heist

In this new lawsuit, Wright is accused of effectively swindling Dave Kleiman’s estate—his brother Ira Kleiman is the one who has filed the case—out of a massive cache of bitcoins that today are worth more than $5 billion.

Source: arstechnica.com

Mar. 1, 2018

Encryption 101: ShiOne ransomware case study

Encryption 101: ShiOne ransomware case study

In part one of this series, Encryption 101: a malware analyst’s primer, we introduced some of the basic encryption concepts used in malware. If you haven’t read it, we suggest going back for a review, as it’s necessary in order to be able to fully follow part two, our case study. In this study, we will be reviewing the encryption of the ransomware ShiOne line by line.

Mar. 1, 2018

This Guy Made a Facial Recognition Device for His Cat

This Guy Made a Facial Recognition Device for His Cat

Welcome to the cat surveillance state.

Source: vice.com