Sunday, March 8, 2015

Hacking tools that terrorise the internet

[google.com] If it's a really good tool, then you can sell the rights to a commercial cyber security company and retire (or work as a consultant). It's a career path [infosec,cyber,security]

Update: The Shed restaurant's website running again after cyber - attack claimed by ISIS

[google.com] The Shed Barbeque & Blues Joint confirmed on Saturday its website was hacked by a group claiming to be ISIS [infosec,cyber,security]

SANS Special Webcast: Forensic Update: What�s New and What�s Next - Monday September 16, 2013 (10:00 AM EST)

[sans.org] Please visit http://bit.ly/16wMPuf for complete information and to access this event [infosec,forensic,webcast,sans]

Mozilla Updates Firefox to Remove Superfish Certificate

[sans.org] A Firefox update released on Friday, February 27, scrubs the Superfish self-signed certificate from the browser [infosec,forensic,sans]

FREAK: Security Rollback Attack Against SSL

[schneier.com] This week we learned about an attack called "FREAK" -- "Factoring Attack on RSA-EXPORT Keys" -- that can break the encryption of many websites. Basically, some sites' implementations of secure sockets layer technology, or SSL, contain both strong encryption algorithms and weak encryption algorithms. Connections are supposed to use the strong algorithms, but in many cases an attacker can force [infosec]

The Message: Consent Matters

[f-secure.com] Go read this: Privacy is non-negotiable: We have the right to cover our arse — or expose it A post by Laura — whom I'm very proud to have as a colleague. On 02/02/15 At 05:15 PM

CTB-Locker Infections on the Rise

[f-secure.com] We have recently observed a significant increase in infections from a nasty strain of file-encrypting ransomware called CTB-Locker. Daily CTB-Locker infections in relation to the total number of such infections this year. CTB-Locker is most commonly spread through email spam. These emails usually contain an attached .zip file that contains a second .zip file that finally contains an .scr executable file. This executable is a malicious downloader known as Dalexis. If the use…

The Ear of Sauron

[f-secure.com] A recent story by The Daily Beast seems to have ignited a real firestorm over Samsung's "smart" television terms and conditions. Which is somewhat surprising to us as we read about it months ago via Mikko. But anyway, things that listen are topical. So… do the words "always-listening voice search" sound good to you? Or do they give you the creeps? Because that's the potential future of Google's Chrome browser: Image: How-To Geek The "always-listening" feature is curr…

Ransomware Report: The Rise of BandarChor

[f-secure.com] This week, we have received a number of reports on yet another ransomware, BandarChor. This ransomware is not exactly fresh. The first infections that we've noticed related to this family came in already last November. We have had reports of BandarChor being spread via email and have seen indicators that it may have been distributed by exploit kits. Upon execution, the malware drops a copy of itself in Startup directory as well as the ransom notification image. Then it proc…

Analysis of a Cybercrime Infrastructure

[techworld_security] Security researchers have finally published an analysis that exposes the inner workings of Cybrecrime operations targeting online banking credentials for banks in the US and Europe. Download this white paper get a rare glimpse at the inside view of the infrastructure, tools and techniques used by cybercriminals [infosec]

SANS Using Oracle Audit Vault and Database Firewall for Data Protection - Thursday September 12, 2013 (1:00 PM EDT)

[sans.org] Featuring: Tanya Baccam, SANS Analyst Sponsored By: Oracle (http://bit.ly/15cuZgf) Please visit http://bit.ly/15cuZge for complete information and to access this event [infosec,forensic,webcast,sans]

Malicious DNS Servers Deliver Fareit

[f-secure.com] Last year we wrote about Fareit being massively spammed. A couple of months later, they added another means of infecting systems - via malicious DNS servers. When the DNS server settings has been changed to point to a malicious server used by Fareit, the unsuspecting user visiting common websites gets an alert saying "WARNING! Your Flash Player may be out of date. Please update to continue" . A "Flash Player Pro" download page will be shown pretending to be served from the …

Hackers in Butte credit union cyber attack claim ISIS affiliation

[google.com] The Southwest Montana Community Federal Credit Union was the target of a cyber attack Saturday by hackers claiming to be affiliated with ISIS [infosec,cyber,security]

Saturday, March 7, 2015

Dutch Semi-Conductor Company Admits Breach

[sans.org] computer chip company ASML has acknowledged that its systems were breached [infosec,forensic,sans]

Cyber cop demand to rise

[google.com] Calcutta, March 7: Demand for skilled cyber security professionals in India is likely to rise following the adoption of the Internet of Things (IoT) policy [infosec,cyber,security]

ACLU Obtains Warrant Revealing FBI Knew Stingray Disrupted Devices Near Target

[sans.org] The US Justice Department has maintained that the secrecy surrounding stingray cell phone surveillance technology was necessary to prevent criminals from figuring out how to elude its reach [infosec,forensic,sans]

Fareit trojan pwns punters with devious DNS devilry

[theregister.com] These are NOT the Flash updates you are looking for DNS tricks used by the Fareit trojan mean users are tricked into downloading malware, seemingly from Google or Facebook… [infosec]

Pharming Attack Targeting Brazilian Home Router Users

[sans.org] Attackers are targeting Brazilian Internet users, spying on web traffic by exploiting vulnerabilities in home routers [infosec,forensic,sans]

Litecoin-mining code found in BitTorrent app, freeloaders hit the roof

[theregister.com] Maybe buying that Blu-Ray in the first place was the better option, huh? μTorrent users are furious after discovering their favorite file-sharing app is quietly bundled with a Litecoin mining program.… [infosec]

Data and Goliath's Big Idea

[schneier.com] Goliath is a book about surveillance, both government and corporate. It's an exploration in three parts: what's happening, why it matters, and what to do about it. This is a big and important issue, and one that I've been working on for decades now. We've been on a headlong path of more and more surveillance, fueled by fear­--of [infosec]