Equifax’s Servers Reportedly Had Glaring Holes Long Before Data Breach

Equifax reportedly took six months to take down a publicly exposed web application that could have allowed anyone on the internet to search and download sensitive personal consumer data. VICE Motherboard reported Thursday that an unnamed security researcher alerted Equifax about the exposed application in December 2016, but the company didn’t take steps to secure..

The post Equifax’s Servers Reportedly Had Glaring Holes Long Before Data Breach appeared first on Security Boulevard.

Continue reading Equifax’s Servers Reportedly Had Glaring Holes Long Before Data Breach

BadRabbit runs out of steam – but be prepared for the next ransomware attack

Reports appeared on Tuesday that a new ransomware outbreak was hitting organisations in Russia and Ukraine. Victims included the Russian newswire Interfax, Ukraine’s Odessa airport, and the Kiev subway system. Media outlets like Fontanka.ru found their website’s disrupted by the attack, and urged readers to follow them on social media for updates while systems were […]… Read More

The post BadRabbit runs out of steam – but be prepared for the next ransomware attack appeared first on The State of Security.

The post BadRabbit runs out of steam – but be prepared for the next ransomware attack appeared first on Security Boulevard.

Continue reading BadRabbit runs out of steam – but be prepared for the next ransomware attack

Bad Rabbit Ransomware Highlights Perils of Poor Network Management

Companies in Russia and Eastern Europe have been battling a new ransomware outbreak since Tuesday that security researchers have dubbed Bad Rabbit. The malware can spread to Windows systems over local networks by using weak or stolen credentials for SM… Continue reading Bad Rabbit Ransomware Highlights Perils of Poor Network Management

Infrastructure for the ‘Bad Rabbit’ Ransomware Appears to Have Shut Down

Most of the servers and sites used by the hackers behind the ransomware are down just a day after the outbreak started. Continue reading Infrastructure for the ‘Bad Rabbit’ Ransomware Appears to Have Shut Down

Comparing EternalPetya and BadRabbit

I’ve created a table comparing the EternalPetya (ExPetr, NotPetya, etc.) outbreak from June, and the BadRabbit ransomware outbreak from yesterday (2017-10-24).
I have decided to not include WannaCry (WanaCrypt0r), as they are not related, while Eternal… Continue reading Comparing EternalPetya and BadRabbit

BadRabbit: a closer look at the new version of Petya/NotPetya

BadRabbit, a new version of NotPetya, also has an infector allowing for lateral movements. However, unlike NotPetya, it does not use EternalBlue and uses a website to drop its payload. We take a closer look at this new ransomware variant.
Categor… Continue reading BadRabbit: a closer look at the new version of Petya/NotPetya

BadRabbit: a closer look at the new version of Petya/NotPetya

BadRabbit, a new version of NotPetya, also has an infector allowing for lateral movements. However, unlike NotPetya, it does not use EternalBlue and uses a website to drop its payload. We take a closer look at this new ransomware variant.
Categor… Continue reading BadRabbit: a closer look at the new version of Petya/NotPetya