Malware
U.S. Can Expect to see more Ransomware Attacks
In the cybersecurity space, there are many things we do not all agree on, but one thing I have noticed in the past year is that we all agree that the U.S. can expect to see more ransomware attacks as the nation recover from recent attacks which included the District of Columbia Police Department, The Colonial Pipeline and now the JBS meat plant. These will continue to increase, especially in the state, local environment, as well as in the critical infrastructure and manufacturing space.
There are two main reasons for this trend:
1. Organizations are not implementing the basic security controls thus allowing attackers to take advantage of easy attack vectors. A major of the critical infrastructure in the U.S. are operated by private organizations with very little IT and security regulations.
2. Many organizations are frequently deciding to pay the ransom after they have been attacked. Security researchers and law enforcement often recommend organizations not to pay the ransoms, but when stakeholders and the media are applying pressure, organizational leader must do what is best for the organization. This validates the ransomware industry and their frequency and tactics become more sophisticated.
This recent attack seems to have a Russian’s group fingerprint associated to it just like the pipeline event. Many security researchers, law enforcement officials and politicians are recommending in conjunction to increasing regulations on U.S. based organizations, the U.S. must also impose sanctions against countries that allow these types of activities to occur inside their borders.
The Software Engineering Institute (SEI) Issues Advice on Ransomware
The Software Engineering Institute (SEI) of Carnegie Mellon University has released a blog post on best practices for preventing and responding to ransomware. This common malware captures, encrypts, and holds your data to extort a ransom. SEI’s top recommendation to thwart ransomware attacks is to back up your important files regularly. US-CERT recommends that users […]
Researchers Enlist Machine Learning In Malware Detection
A posting from dark reading by Kelly Jackson Higgins titled "Researchers Enlist Machine Learning In Malware Detection " No sandbox required for schooling software to speedily spot malware, researchers will demonstrate at Black Hat USA. In 100 milliseconds or less, researchers are now able to determine whether a piece of code is malware or not -- and […]
Windows 10 Will Use Virtualization For Extra Security
An interesting article from informationweek by Kelly Sheridan titled " Windows 10 Will Use Virtualization For Extra Security" When we're talking about Windows 10features, security upgrades are often edged out of the spotlight by flashy additions like Cortana for desktop, Microsoft Edge, and Universal Apps. Perhaps this is because Microsoft is targeting a broad consumer audience with […]
100,000+ WordPress Sites Compromised by SoakSoak
100,000+ WordPress Sites Compromised by SoakSoak
CryptoLocker Malware Can Locks Your Files Forever
CryptoLocker, a new and nasty piece of malicious software is infecting computers around the world – encrypting important files and demanding a ransom to unlock them.
Botnets Unearthed – The ZEUS BOT - InfoSec Institute
Zeus, also known as ZBot/WSNPoem, is famous for stealing banking information by using man in the browser keystroke logging and form grabbing. As the term suggests, man in the browser (MITB) is basically a proxy Trojan horse which uses man in the middle techniques to attack users.
Google adds (some) malware and phishing info to Transparency Report
Google adds (some) malware and phishing info to Transparency Report
'BinaryPig' Uses Hadoop To Sniff Out Patterns In Malware
A Posting from Dark Reading in there Threat Intelligence section: As the menagerie of malware collected by security firms continues to multiply, researchers are looking for new ways to analyze the massive data sets to find interesting information in their malware zoos. At the Black Hat Security Briefings in late July, one trio of researchers […]
Taking a closer look at the Glazunov exploit kit
A posting from Naked Security on Glazunov exploit kit: The one I have chosen has been quite active of late, and has a few interesting characteristics I wanted to highlight. As it happens, I do not actually know its "official" name (as in the name assigned by the author), but it was originallychristened Glazunov by another researcher tracking […]