VM: Protecting Known Assets against Known Vulnerabilities

Two security controls, file integrity monitoring (FIM) and security configuration management (SCM), help organizations manage change. The former monitors for unauthorized changes to a system’s state, whereas the latter looks for configuration changes that introduce security risk. Both components are crucial to a company’s strategy for defending against digital threats. But on their own, they […]… Read More

The post VM: Protecting Known Assets against Known Vulnerabilities appeared first on The State of Security.

Continue reading VM: Protecting Known Assets against Known Vulnerabilities

Attackers Physically Drilling into ATMs to Steal Thousands of Dollars from Banks

Attackers are using drills to physically compromise ATMs so that they can steal thousands of dollars from the financial institutions operating them. In the fall of 2016, a bank client revealed one of their ATMs that attackers had emptied to Kaspersky Lab. The only indication of physical tampering was a golf ball-sized hole someone had […]… Read More

The post Attackers Physically Drilling into ATMs to Steal Thousands of Dollars from Banks appeared first on The State of Security.

Continue reading Attackers Physically Drilling into ATMs to Steal Thousands of Dollars from Banks

Disttrack Malware Distribution Suggests Link between Shamoon 2 and Magic Hound

In November 2016, the security community first learned of a series of attacks known as “Shamoon 2.” The campaign has launched three waves as of this writing. In the first wave, bad actors infected an organization in Saudi Arabia with Disttrack. This trojan used a wiper component to overwrite protected parts of a system, including […]… Read More

The post Disttrack Malware Distribution Suggests Link between Shamoon 2 and Magic Hound appeared first on The State of Security.

Continue reading Disttrack Malware Distribution Suggests Link between Shamoon 2 and Magic Hound

Malspam Campaign Personalizes Emails with Recipient’s Name and Address

A spam campaign is personalizing its emails with the recipient’s name and address so that more people will feel inclined to open the malicious attachment. Sophos Labs has seen several versions of this scam pop up in recent weeks. But although the text differs across samples, all the emails generally follow the same format. The […]… Read More

The post Malspam Campaign Personalizes Emails with Recipient’s Name and Address appeared first on The State of Security.

Continue reading Malspam Campaign Personalizes Emails with Recipient’s Name and Address

Russian Man Pleads Guilty to Orchestrating Ebury Botnet Conspiracy

A Russian man has pleaded guilty to helping to create and operate a botnet of tens of thousands of machines infected with Ebury malware. On 28 March 2017, Maxim Senakh, 41, of Velikii Novgorod, Russia pleaded guilty to a conspiracy to violate the Computer Fraud and Abuse Act and conspiracy to commit wire fraud. Law […]… Read More

The post Russian Man Pleads Guilty to Orchestrating Ebury Botnet Conspiracy appeared first on The State of Security.

Continue reading Russian Man Pleads Guilty to Orchestrating Ebury Botnet Conspiracy