Report: Zoho’s domain regularly exploited to move keylogger data

After a messy domain takedown last week in response to phishing complaints, new research suggests that an Indian IT company’s domain is being exploited to exfiltrate the bulk of keylogger data collected by malicious programs. Zoho, an Indian company that provides office tools and IT management platforms, had its domain taken down temporarily last week as a result of complaints about phishing abuse. Domain registrar TierraNet told ZDNet that it took down the domain after repeatedly asking Zoho to mitigate the phishing issues. Zoho’s domain has since been brought back online, but anyone using Zoho was out of luck while it was down. A report released Tuesday by Cofense, a company that provides phishing protection services, suggests that the complaints of abuse were not unfounded. Cofense says that, based on an analysis of keylogger data theft where email is used for to exfiltrate the data, domains owned by Zoho account for moving […]

The post Report: Zoho’s domain regularly exploited to move keylogger data appeared first on Cyberscoop.

Continue reading Report: Zoho’s domain regularly exploited to move keylogger data

Smashing Security #097: Dash cam surveillance, robocall plague, and Zoho woe

Why was Zoho’s website taken offline by its own domain registrar? How are dash cams making you less secure? And why are robocalls on the rise in the United States?
All this and much more is discussed in the latest edition of the award-winning “Smashing… Continue reading Smashing Security #097: Dash cam surveillance, robocall plague, and Zoho woe

Does LocalAccountTokenFilterPolicy registry value completely mitigate Windows pass-the-hash (PtH)?

I’ve been sitting for hours trying to get PsExec and windows/smb/psexec to work without luck, always getting the “Access is denied.” error, until I came across the following article on Windows Vista:

https://support.microsof… Continue reading Does LocalAccountTokenFilterPolicy registry value completely mitigate Windows pass-the-hash (PtH)?

Australia’s Commonwealth Bank leaks data of 10,000 customers over domain misspelling

Just last month, Australia’s Commonwealth Bank admitted losing the financial history of some 20 million customers. Now, the financial institution drops the ball again, this time mistakenly sending the data of some 10,000 customers to the wrong em… Continue reading Australia’s Commonwealth Bank leaks data of 10,000 customers over domain misspelling