InfoSec News 20190910

  • Publicado: Ter, 10/09/2019 - 11:07

Top News


  • Police dismantled Europe’s second-largest counterfeit currency network on the dark web

"The European authorities announced to have dismantled Europe’s second-largest counterfeit currency network on the dark web."

Link

TLP1 : Green

  • Telnet Backdoor Opens More Than 1M IoT Radios to Hijack

"Attackers can drop malware, add the device to a botnet or send their own audio streams to compromised devices."

Link

TLP1 : Green

  • Google Finally Confirms Security Problem For 1.5 Billion Gmail And Calendar Users

"Way back in 2017, two researchers at Black Hills Information Security disclosed how a vulnerability in the Google Calendar app was leaving more than a billion users open to a credential-stealing exploit."

Link

TLP1 : Green

Cybersecurity State: Surveillance, Cyberwarfare, Cybercriminality and Hacktivism


  • Americans Deserve Their Day in Court About NSA Mass Surveillance Programs

"EFF continues our fight to have the U.S. courts protect you from mass government surveillance. Today in our landmark Jewel v. NSA case, we filed our opening brief in the Ninth Circuit Court of Appeals, asserting that the courts don’t have to turn a blind eye to the government’s actions."

Link

TLP1 : Green

  • Cyber Warfare And The Future Of Cyber Security

"In 2019, though, cyber warfare is no longer science fiction. States are increasingly seeing the cyber realm as an important military theater and deploying considerable resources to develop new types of attacks and ways to defend against them."

Link

TLP1 : Green

  • OpenCTI - Open Cyber Threat Intelligence Platform

"OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observables. It has been created in order to structure, store, organize and visualize technical and non-technical information about cyber threats."

Link

TLP1 : Green

Breaches: Data Breaches and Hacks


  • Secret Service Investigates Breach at U.S. Govt IT Contractor

"The U.S. Secret Service is investigating a breach at a Virginia-based government technology contractor that saw access to several of its systems put up for sale in the cybercrime underground, KrebsOnSecurity has learned."

Link

TLP1 : Green

Vulnerabilities: Vulnerability Advisories, Zero-Days,Patches and Exploits


  • Phishing Attack Prevention: Best 10 Ways To Prevent Email Phishing Attacks

"No one wants to believe they’d fall victim to phishing attacks. However, phishing attacks are on the rise and are more sophisticated than ever."

Link

TLP1 : Green

  • 7 most common application backdoors

"The popular adage “we often get in quicker by the back door than the front” has withstood the test of time even in our advanced, modern world. Application backdoors have become rampant in today’s business environment, making it mandatory for us to take the same level of precaution we’d do to safeguard the backdoor of our homes"

Link

TLP1 : Green

Incident Response: Infrastructure, Training, SIEM and Incident Handling


  • Social media security: Tips from an Army special agent

"WASHINGTON -- Even the most innocuous data posted to a social media feed can be married up with other publicly available information to provide online criminals the tools they need to exploit members of the military or general public, an Army special agent said."

Link

TLP1 : Green

Technical Articles: Forensics, Reverse Engineering, Malware, Phishing, Pentesting, Software Security and Cryptography


  • Wikipedia suffers DDoS attack causing worldwide service disruption

"The popular online encyclopedia Wikipedia has suffered a DDoS attack over the weekend that crippled its service preventing millions of users from accessing the platform."

Link

TLP1 : Green

 

 

1Traffic Light Protocol (TLP) [1] for information sharing:

 

 

  • Red:Not for disclosure, restricted to participants only.
  • Amber: Limited disclosure, restricted to participants organizations.
  • Green: Limited disclosure, restricted to the community.

 


[1]https://www.first.org/tlp