How credential stuffing works (and how to stop it)

In December 2022, Norton users were put on high alert after threat actors compromised the security application with a credential-stuffing attack. Norton’s security team locked down about 925,000 accounts after detecting a suspicious flurry of login attempts from Norton Password Manager users. After the investigation, news broke that the cyber criminals successfully cracked the codes […]

The post How credential stuffing works (and how to stop it) appeared first on Security Intelligence.

Continue reading How credential stuffing works (and how to stop it)

Mukashi: A New Mirai IoT Botnet Variant Targeting Zyxel NAS Devices

A new version of the infamous Mirai botnet is exploiting a recently uncovered critical vulnerability in network-attached storage (NAS) devices in an attempt to remotely infect and control vulnerable machines.

Called “Mukashi,” the new variant of the m… Continue reading Mukashi: A New Mirai IoT Botnet Variant Targeting Zyxel NAS Devices

Cathay Pacific fined over crooks slurping its database for over 4 years

The ICO found a “catalog of errors,” including backups without passwords, unpatched servers, no-longer-supported OSes and feeble anti-virus. Continue reading Cathay Pacific fined over crooks slurping its database for over 4 years

What the Explosive Growth in ICS-Infrastructure Targeting Means for Security Leaders

The IBM X-Force Threat Intelligence Index 2020 found that industrial control systems became a popular target for specialized actors in 2019. Find out what this means for the future of cybersecurity.

The post What the Explosive Growth in ICS-Infrastructure Targeting Means for Security Leaders appeared first on Security Intelligence.

Continue reading What the Explosive Growth in ICS-Infrastructure Targeting Means for Security Leaders

Lottery hacker gets 9 months for his £5 cut of the loot

We don’t care how little you made from your crimes, the judge said. We care that you went after an outfit that gives a ton to charities. Continue reading Lottery hacker gets 9 months for his £5 cut of the loot

New Brute-Force Botnet Targeting Over 1.5 Million RDP Servers Worldwide

Security researchers have discovered an ongoing sophisticated botnet campaign that is currently brute-forcing more than 1.5 million publicly accessible Windows RDP servers on the Internet.

Dubbed GoldBrute, the botnet scheme has been designed in a way… Continue reading New Brute-Force Botnet Targeting Over 1.5 Million RDP Servers Worldwide