Infosecurity.US

Information Security & Occasional Forays Into Adjacent Realms

  • Web Log

Bangkok Click Agriculture →

June 15, 2017 by Marc Handelman in Criminal Enterprise, Crime

...meanwhile, in clickfarming news, comes word - via The Bangkok Post - of a Thai law enforcement action targeting clickfarm miscreants, consequently, no clickfarm for you!.

June 15, 2017 /Marc Handelman
Criminal Enterprise, Crime

Just 'Kuzz →

May 22, 2017 by Marc Handelman in All is Information, Criminal Enterprise, Crime, Alternate Attack Analysis, Information Security, Cybernetic Crime, Resource Theft

via Phys.org, comes a brief news item targeting the trojan exploit dubbed 'Adylkuzz', and it's mining feature. Additionally, read the highly detailed Proofpoint post, of which, contains the true gist of this trojan, as it were..

'Instead of completely disabling an infected computer by encrypting data and seeking a ransom payment, Adylkuzz uses the machines it infects to "mine" in a background task a virtual currency, Monero, and transfer the money created to the authors of the virus.' - via Phys.org

May 22, 2017 /Marc Handelman
All is Information, Criminal Enterprise, Crime, Alternate Attack Analysis, Information Security, Cybernetic Crime, Resource Theft

ATM Equals 'All The Money' →

May 03, 2017 by Marc Handelman in All is Information, Attack Analysis, Attack Vectors, Bank Security, Crime, Criminal Enterprise, Hardware Security, Information Security, Financial Security

John Leyden, writing at El Reg, tells the tale of the latest ATM SNAFU. All based on CVE-2017-6968... Astonishing, indeed.

"To exploit the vulnerability, a criminal would need to pose as the control server, which is possible via ARP spoofing, or by simply connecting the ATM to a criminal-controlled network connection," said Georgy Zaytsev, a researcher with Positive Technologies. "During the process of generating the public key for traffic encryption, the rogue server can cause a buffer overflow on the ATM due to failure on the client side to limit the length of response parameters and send a command for remote code execution." - via John Leyden, at El Reg

May 03, 2017 /Marc Handelman
All is Information, Attack Analysis, Attack Vectors, Bank Security, Crime, Criminal Enterprise, Hardware Security, Information Security, Financial Security

DDoS Attackers Offer Customer Loyalty Points →

April 24, 2017 by Marc Handelman in All is Information, Crime, Criminal Enterprise, Network Security, Information Security

via El Reg's John Leyden, comes the astonishing tale of the commercialization of crime - in this case, DDoS attacks; and don't miss the Loyalty Points! Today's Must Read.

April 24, 2017 /Marc Handelman
All is Information, Crime, Criminal Enterprise, Network Security, Information Security

Shrinkage... →

March 13, 2017 by Marc Handelman in All is Information, Dark Web, Criminal Enterprise

Apparently, the Dark Web has shrunk... via CircleID, comes this interesting report detailing the notion.

March 13, 2017 /Marc Handelman
All is Information, Dark Web, Criminal Enterprise
  • Newer
  • Older