Thursday, January 30, 2020

We might not be up-to-date on current events but, cybercriminals are and they are quick to capitalize on them. The latest being "CoronaVirus"



One important behaviour pattern cybercriminals depend on is that if, an email sounds scary / urgent then we might click on the link or attachment. The new botnet campaign targets geographic regions that may be more impacted by the outbreak given their locations in Asia to spread Emotet trojan.IBM X-Force warned that Emotet operators will probably expand their targeting beyond Japan soon.

https://threatpost.com/coronavirus-propagate-emotet/152404/

Trickbot trojan gets dangerous as it can now run in stealth mode

. It uses Wsreset.exe , which when executing a command it will not display a UAC prompt and users will have no idea that a program has been executed.


https://www.bleepingcomputer.com/news/security/trickbot-uses-a-new-windows-10-uac-bypass-to-launch-quietly/

Monday, January 27, 2020

Finally, UK has an IoT Law



The Law Mandates:
  1. IoT device passwords must be unique. 
  2. Manufacturers must also provide a public point of contact so that anyone can report a flaw. 
  3. Manufacturers must also explicitly state the minimum length of time for which devices will receive security updates.


https://threatpost.com/mandatory-iot-security-uk-proposal/152217/

Friday, January 24, 2020

Interesting Attack Technique - Ransomware can now infect any Active directory connected windows system if the user profile is setup to execute a login script when a user logs in.

The attacker weaponized AD by putting not Trickbot, but Ryuk, into the AD [roaming] login script. So anybody who logged into that AD server was immediately infected.
So as soon as an engineer, for example, logged in from his or her workstation, the payload would drop, execute, and lock the user out of the machine.

https://www.darkreading.com/threat-intelligence/ryuk-ransomware-hit-multiple-oil-and-gas-facilities-ics-security-expert-says-/d/d-id/1336865

Thursday, January 23, 2020

I am dumbstruck - Microsoft exposed (in clear-text) 14 years worth of data with 250 million CSS records

. This means records from 2005 to December 2019 were leaked online and left without any security authentication allowing the public to access it with just a web browser.


https://www.hackread.com/250-million-microsoft-customer-support-records-leaked-plain-text/

Extortionists find new victims - "Plastic surgery patients"

Hackers not only know their personal information, but also might have photographs of their “before” and “after”. One can easily imagine that things become even more uncomfortable if it’s other parts of your body that you’ve had “tweaked”.

The Center for Facial Recognition says that within three weeks of being threatened by the extortionists, up to 20 patients have been contacted by the criminals with individual demands for payment.

https://www.grahamcluley.com/plastic-surgery-patients-ransomware/

Wednesday, January 15, 2020