Infosecurity News

Hidden Cobra Coils and Strikes at Turkish Banks
The campaign is using the Bankshot malware implant.

Memcached Flaw Kill Switch Could Foil DDoS-ers
Countermeasure said to be 100% effective on attacking servers

US DHS Slammed for Infosecurity Deficiencies
OIG report highlights systemic weaknesses

EFF: FBI Paid Geek Squad Employees as Informants
Rights group has concerns over possible Fourth Amendment violations

Half of All Orgs Hit with Ransomware in 2017
Of the companies that refused to pay the ransom, a full 87% recovered their data.

FlawedAmmyy RAT Takes Over Desktops
The RAT creates opportunities for actors to steal customer data, proprietary information and more.

Mobile Ad Trojans Evolve to Maximize Profits
With root privileges, they can secretly install various applications or bombard an infected device with ads to make use of the smartphone impossible.

Experts: UK Gov’s IoT Security Guidelines Must Go Further
Security industry wants more than voluntary guidelines

Two-Thirds of IT Leaders Consider Consumer-Grade Access to Workplace Cloud Services
Nine in 10 IT decision makers think ineffective cloud access management creates issues for the business

Dark Web Experts: ID Fraudsters Unaffected by Police Efforts
AlphaBay/Hansa takedown has forced scammers to be more creative, says Terbium Labs

New Record 1.7Tbps DDoS Also Abused Memcached Servers
Experts urge organizations to correct insecurely configured systems

Kaspersky Lab Adds $100K Payout to Bug Bounty Program
The new top-end award will be for the discovery and responsible disclosure of severe vulnerabilities in some of the firm’s flagship products.

Gozi Trojan Turns to Dark Cloud Botnet
The campaigns are relatively low volume and targeted to specific organizations, with some of the mails even being localized.

Poor User Practice at the Root of Most Medical Device Security Risks
Use of unauthorized applications (22%) and browsers (18%) are the leading security risks.

Applebee’s Hit by POS Malware
Over 160 US restaurants in RMH franchise are affected

Non-Profit Aims to Bring More Military Vets into Cyber Roles
TechVets could help reduce chronic skills shortages

Crypto-Mining Attacks Jump 50% to Net Hackers Millions in 2017
Kaspersky Lab claims attackers are using increasingly sophisticated tactics

NIS America Suffers Card Breach, Offers Store Credit
The attack resulted in the theft of payment-card details and address information.

Malware Authors Turn to DNS Protocol as a Covert Channel
DNS command and control (C&C) and DNS exfiltration can be successful because DNS is an integral part of the internet's infrastructure.

It Could Happen to Anyone: FS-ISAC Falls for a Phish
The financial industry's forum for collaboration on critical security threats was compromised with an unsophisticated phish.



