Android Devices With Misconfigured ADB, a Ripe Target for Cryptojacking Malware

Vendors have been shipping Android products with Android Debug Bridge enabled, making them attractive targets for hackers. Continue reading Android Devices With Misconfigured ADB, a Ripe Target for Cryptojacking Malware

VPNFilter Continues to Target Devices in Ukraine

The VPNFilter botnet that compromised more than 500,000 routers and network-attached storage devices from around the world was recently disrupted, but is trying to make a comeback in Ukraine. Researchers from security firms Jask and GreyNoise Intellig… Continue reading VPNFilter Continues to Target Devices in Ukraine

Microsoft Zero-Day, Mirai DDoS Attack, and GDPR – Paul’s Security Weekly #559

“Microsoft Patches Two Zero-Day Flaws Under Active Attack”, “5 Powerful Botnets Found Exploiting Unpatched GPON Router Flaws”, “Mirai DDoS attack against KrebsOnSecurity cost device owners $300,000”, and “The f… Continue reading Microsoft Zero-Day, Mirai DDoS Attack, and GDPR – Paul’s Security Weekly #559

Study: Attack on KrebsOnSecurity Cost IoT Device Owners $323K

A monster distributed denial-of-service attack (DDoS) against KrebsOnSecurity.com in 2016 knocked this site offline for nearly four days. The attack was executed through a network of hacked “Internet of Things” (IoT) devices such as Internet routers, security cameras and digital video recorders. A new study that tries to measure the direct cost of that one attack for IoT device users whose machines were swept up in the assault found that it may have cost device owners a total of $323,973.75 in excess power and added bandwidth consumption.

My bad. Continue reading Study: Attack on KrebsOnSecurity Cost IoT Device Owners $323K

Former Dyn exec spins up IoT security startup to avoid the next Mirai

The former head of the company that was at the center of the Mirai botnet attack is now jump-starting a new venture that aims to protect the devices which were co-opted into the attack. Minim, an internet of things security startup based in Manchester, N.H., announced on Monday that it has brought in $2.5 million in seed funding. The genesis of Minim is rooted in that 2016 distributed denial of service (DDoS) attack that targeted DNS provider Dyn and paralyzed several popular websites. Minim CEO Jeremy Hitchcock co-founded Dyn and served is its CEO until a few months before the attack. “The Dyn attack was a huge red flag,” Hitchcock told CyberScoop in an email. “It showed that IoT device hacking is easy (accomplished by a dorm room Minecraft scam for fun), undetectable by the average consumer, and a big problem for internet services such as Dyn.” Mirai leveraged hundreds of thousands […]

The post Former Dyn exec spins up IoT security startup to avoid the next Mirai appeared first on Cyberscoop.

Continue reading Former Dyn exec spins up IoT security startup to avoid the next Mirai

Mirai IoT botnet variant likely used in January DDoS attack against Dutch banks

A series of denial-of-service attacks against banks and government agencies in the Netherlands was carried out by an attacker using a Mirai botnet variant, according to new research from the cybersecurity firm Recorded Future. The late January attacks temporarily brought down the networks of the Netherlands national tax office as well online banking services for ABN Amro, ING and Rabobank. The attackers themselves have been subject to much speculation but remain unknown at this time. Researchers said the malware used in the attacks may be linked to IoTroop, code that infects Internet of Things (IoT) devices like routers, televisions and cameras in order to send a tsunami of data at a target until the network buckles under the weight. IoTroop also shares a lot of source code with the infamous Mirai malware. “This is the first time we have observed an IoT botnet being used since Mirai and it may be the first time IoTroop has been used to […]

The post Mirai IoT botnet variant likely used in January DDoS attack against Dutch banks appeared first on Cyberscoop.

Continue reading Mirai IoT botnet variant likely used in January DDoS attack against Dutch banks