Report: the anatomy of tech support scams
https://blog.malwarebytes.com/cybercrime/social-engineering-cybercrime/2016/10/report-the-anatomy-of-tech-support-scams/

pdf report
https://www.malwarebytes.com/pdf/white-papers/AnatomyTechSupportScams.pdf?utm_source=blog&utm_medium=social

Cybercriminal skimmers find creative solution: creditcard data hidden inside image:
https://blog.sucuri.net/2016/10/magento-credit-card-swiper-exports-image.html

Scan your webshop that has Magento here to be alerted to insecurity: magereport.com/scan/?s=

We see that the so-called Willem de G. list made some researchers look a bit sharper for e-commerce site’s insecurity.
All reported to Google Safe Browsing that cooperates firmly with Sucuri’s.

polonus (volunteer website security analyst and website error-hunter)

Tens of millions of websites at risk in latest mega breach
https://www.leakedsource.com/blog/weebly/

WTF >:(!!! For one of my uni papers at my institute uses weebly as a source for giving us (students) lecture notes, notices, timetable, and etc etc. I will pass this info to my uni IT support and let them know. Thanks Asyn for posting this

Interesting when WOT doesn’t trust/like leakedsource.com.

One thing for sure when I come across sites like this there is absolutely no way I would check user name and passwords. As soon as you do that you have pretty much compromised your information and can’t/shouldn’t use that data again.

Who would trust that the data wouldn’t be harvested, certainly not me and I’m a trusting sort NOT.

I won’t even use sites to check the strength of my passwords, for the very same reasons.

Hi DavidR,

Striking again that a Russian source seems to come with a bad web reputation,
lots of that demonizing going on lately.

The leakedsource dot com organization is into data harvesting, so it sits on big pile of cloud data.

At the moment for whatever reason there is a concerted action going on to make Russia look like the evil empire of cyberwarfare?

In this case: JSC DBA RU-CENTER, privacy protection service.
Comodo Certification - PositiveSSL Multi-Domain,Domain Control Validate seems OK.

What is CloudFlare’s role in all this.
The bad side of it all is that CloudFlare seems indifferent to what they have in that cloud traffic they are facilitating.
The good, the bad and the ugly as long as it brings them big profits.
Big data cloud security is bad.
For the majority of big enterprise do not have protection as it should be implemented.

This will not be the last of such big data-breaches, where and when we may find them.

polonus

You’re welcome. :slight_smile:

Unprotected IoT devices killed the US Internet for hours
http://www.bitdefender.com/box/mirai-IOT-security-alert.html

Locky Adds Support for a New ā€œS**Tā€ Extension
Security researcher MalwareHunterTeam tells Softpedia that the infamous Locky ransomware has returned today with a new spam campaign that’s spreading a new version of the ransomware.
http://news.softpedia.com/news/locky-adds-support-for-a-new-s-t-extension-509588.shtml

There are being warnings given out about a new spam botnet.
Important is the advice that shortened urls in an e-mail should always be frowned upon as suspicious.
Do not click such links.

Here is the information link given on a Dutch news forum, use Google translate to be able to read on this new spam botnet:
https://www.security.nl/posting/490176/Nieuw+spam+botnet%3F

Be aware of the obfuscated 146&… look out for patters like e.g. 146&AGTfVq or 146&cc4by etc. in the URL address link.
This could create a handle for blocking this smut-spam
with domain names found to be like:
-hookupclub4[.]com
-flirthookup5[.]com
-flirthookup6[.]com
-flirthookup4[.]com
-claimyourprize2[.]com
-claimyourprize1[.]com

-Info credits here go to : SecGuru_OTX & NSG

polonus

@Asyn: It’s all good. The IT department at my uni, they knew about this problem and had already taken precautions. Thanks again :slight_smile:

Trying to halt Mirai through a security hole: https://www.invincealabs.com/blog/2016/10/killing-mirai/
link author = Scott Tenaglia.

pol

Effective regular expression to be used against new spam botnet:

/[a-z]+\.php\?[a-z]\=146\&[\w]+\=[\w]+\&J9p\=[\w]{3}\&/

Spambot linked to SEO Spam and social media abuse, zie https://www.mywot.com/en/scorecard/urlrate.net?utm_source=addon&utm_content=popup
The important Joomla update seems almost too late for mentioned website, re: code error: undefined function window.addEvent → htxp://tivaen.com/templates/ZAjax_Temp/js/roksortable.js

info credits security.nl anonymous posts 25-10-2016, 01:05 & Yesterday, 21:28

Remarkable is that people who have ISP mail accounts with good and decent working spam filters might not see it
or may get it only as junk mail ready to be deleted. I for instance have not seen these mails with obfuscated shortened url link spam.

pol

Inside the Gootkit C&C server
https://securelist.com/blog/research/76433/inside-the-gootkit-cc-server/

The Super-Dangerous Rex Botnet Has Only Around 150 Bots
http://news.softpedia.com/news/the-super-dangerous-rex-botnet-has-only-around-150-bots-509768.shtml

AtomBombing: A Code Injection that Bypasses Current Security Solutions
http://blog.ensilo.com/atombombing-a-code-injection-that-bypasses-current-security-solutions

Grand scale attacks on outdated Joomla almost a certainty. according to Sucuri’s:
https://blog.sucuri.net/2016/10/joomla-mass-exploits-privilege-vulnerability.html

This is so for those who haven’t found this Joomla update icon yet:
https://docs.joomla.org/Where_is_the_auto_update_for_Joomla%3F

polonus

P.S. How to block malicious account creation for vuln. Joomla: https://github.com/fcoulter/accountblocker

The Internet of Things Ecosystem is Broken. How Do We Fix It?
http://blog.trendmicro.com/trendlabs-security-intelligence/internet-things-ecosystem-broken-fix/

I think that when the IoT (idea) came into being there was little or no thought given to security.

There is no way I would give internet access to a bloody fridge, etc. I have a so called Smart TV (and that is over 7 years old) and there is absolutely no way I would hook it up to the internet.

I have a chrome device hooked into one TV and enjoy some of the smart things available on the new ā€œsmart TVā€.
Different strokes for different folks. :slight_smile: