Probes for recent ABUS Security Camera Vulnerability: Attackers keep an eye on everything., (Mon, May 22nd)

ABUS is usually better known for its “old-fashioned” mechanical locks. But as part of its b “Industry Solution” portfolio of products, ABUS is offering some more high-tech solutions, like, for example, network-connected cameras [;1];. Sadly, these cameras suffer from some of the same vulnerabilities as many similar cameras.

Continue reading Probes for recent ABUS Security Camera Vulnerability: Attackers keep an eye on everything., (Mon, May 22nd)→

Posted in Uncategorized

Phishing Kit Collecting Victim’s IP Address, (Sat, May 20th)

While reviewing my last findings today, I found a phishing email that delivered a classic .shtml file called “PROFORMA INVOICE.shtml”. Right now, nothing special, emails like this one are widespread. When you open the file in a sandbox, it reveals a classic form:

Continue reading Phishing Kit Collecting Victim’s IP Address, (Sat, May 20th)→

Posted in Uncategorized

A Quick Survey of .zip Domains: Your highest risk is running into Rick Astley., (Thu, May 18th)

A week ago, I wrote about Google starting to offer “.zip” domains and the possible risks associated with this [1]. Earlier today, I quickly surveyed registered .zip domains to see what people are doing with them.

Continue reading A Quick Survey of .zip Domains: Your highest risk is running into Rick Astley., (Thu, May 18th)→

Posted in Uncategorized

Increase in Malicious RAR SFX files, (Wed, May 17th)

This isn&#;x26;#;39;t a new attack vector, but I’ve found many malicious RAR SFX files in the wild for a few weeks. An “SFX” file is a self-extracting archive that contains compressed files and is wrapped up with some executable code to decompress them on the fly. The final user receives an executable file (PE file) that can be launched with the need to install a specific tool to decompress the content. This technique has been used for a while by attackers, and even more interesting, the self-decompression routine can launch any executable (another executable, a script, …)[1]

Continue reading Increase in Malicious RAR SFX files, (Wed, May 17th)→

Posted in Uncategorized