Industrial Cyberattacks Get Rarer but More Complex

The first half of 2020 saw decreases in attacks on most ICS sectors, but oil/gas firms and building automation saw upticks. Continue reading Industrial Cyberattacks Get Rarer but More Complex

Fileless worm builds cryptomining, backdoor-planting P2P botnet

A fileless worm dubbed FritzFrog has been found roping Linux devices running SSH servers – corporate servers, routers and IoT devices – into a P2P botnet whose apparent goal is to mine cryptocurrency. Simultaneously, though, the malware cre… Continue reading Fileless worm builds cryptomining, backdoor-planting P2P botnet

Updated cryptojacking worm steals AWS credentials

A malicious cryptocurrency miner and DDoS worm that has been targeting Docker systems for months now also steals Amazon Web Services (AWS) credentials. What’s more, TeamTNT – the attackers wielding it – have also begun targeting Kuber… Continue reading Updated cryptojacking worm steals AWS credentials

Nearly half of hospital Windows systems still vulnerable to RDP bugs

Almost half of connected hospital devices are still exposed to the wormable BlueKeep Windows flaw nearly a year after it was announced, according to a report released this week. Continue reading Nearly half of hospital Windows systems still vulnerable to RDP bugs

Cryptojacking worm compromised over 2,000 Docker hosts

Security researchers have discovered a cryptojacking worm that propagates using containers in the Docker Engine (Community Edition) and has spread to more than 2,000 vulnerable Docker hosts. “The attacker compromised an unsecured Docker daemon, r… Continue reading Cryptojacking worm compromised over 2,000 Docker hosts

MacOS Catalina, OpenShift, & Pink Floyd – Application Security Weekly #64

    “Waiting for the worms to come.” — Pink Floyd and RDP’s CVE-2019-0708. Even the NSA warns about the population of exposed systems, A patch commands attention for mail servers, In macOS Catalina and iOS 13, Apples finds a way… Continue reading MacOS Catalina, OpenShift, & Pink Floyd – Application Security Weekly #64