Menu

Blog

Archive for the ‘cybercrime/malcode’ category: Page 99

Dec 25, 2021

Stealthy BLISTER malware slips in unnoticed on Windows systems

Posted by in category: cybercrime/malcode

Security researchers have uncovered a malicious campaign that relies on a valid code-signing certificate to disguise malicious code as legitimate executables.

One of the payloads that the researchers called Blister, acts as a loader for other malware and appears to be a novel threat that enjoys a low detection rate.

The threat actor behind Blister has been relying on multiple techniques to keep their attacks under the radar, the use of code-signing certificates being only one of their tricks.

Dec 24, 2021

Tetris Handheld Powered By Tritium Cell, Eventually

Posted by in categories: cybercrime/malcode, mathematics, nuclear energy, solar power, sustainability

The idea of a tritium power cell is pretty straightforward: stick enough of the tiny glowing tubes to a photovoltaic panel and your DIY “nuclear battery” will generate energy for the next decade or so. Only problem is that the power produced, measured in a few microwatts, isn’t enough to do much with. But as [Ian Charnas] demonstrates in his latest video, you can eke some real-world use out of such a cell by storing up its power over a long enough period.

As with previous projects we’ve seen, [Ian] builds his cell by sandwiching an array of keychain-sized tritium tubes between two solar panels. Isolated from any outside light, power produced by the panels is the result of the weak green glow given off by the tube’s phosphorus coating as it gets bombarded with electrons. The panels are then used to charge a bank of thin-film solid state batteries, which are notable for their exceptionally low self-discharge rate.

Continue reading “Tetris Handheld Powered By Tritium Cell, Eventually” »

Dec 24, 2021

Global IT services provider Inetum hit by ransomware attack

Posted by in categories: business, cybercrime/malcode, energy, finance, transportation

Less than a week before the Christmas holiday, French IT services company Inetum Group was hit by a ransomware attack that had a limited impact on the business and its customers.

Inetum is active in more than 26 countries, providing digital services to companies in various sectors: aerospace and defense, banking, automotive, energy and utilities, healthcare, insurance, retail, public sector, transportation, telecom and media.

Dec 24, 2021

Half-Billion Compromised Credentials Lurking on Open Cloud Server

Posted by in category: cybercrime/malcode

A quarter-billion of those passwords were not seen in previous breaches that have been added to Have I Been Pwned.

According to the National Crime Agency’s National Cyber Crime Unit in the U.K., nearly 586 million sets of credentials had been collected in a compromised cloud storage facility, free for the taking by any cybercrime yahoo who happened to stop by.

The credentials were a mixed bag in terms of sources, and it’s not clear how these passwords became compromised. But because they couldn’t be linked to a specific company, the NCA tapped Troy Hunt, creator of the Have I Been Pwned (HIBP) website and a Microsoft regional director, to check the passwords against the HIBP database of compromised passwords.

Dec 23, 2021

CISA, FBI and NSA Publish Joint Advisory and Scanner for Log4j Vulnerabilities

Posted by in categories: cybercrime/malcode, electronics

Cybersecurity agencies from Australia, Canada, New Zealand, the U.S., and the U.K. on Wednesday released a joint advisory in response to widespread exploitation of multiple vulnerabilities in Apache’s Log4j software library by nefarious adversaries.

“These vulnerabilities, especially Log4Shell, are severe,” the intelligence agencies said in the new guidance. “Sophisticated cyber threat actors are actively scanning networks to potentially exploit Log4Shell, CVE-2021–45046, and CVE-2021–45105 in vulnerable systems. These vulnerabilities are likely to be exploited over an extended period.”

Dec 23, 2021

CISA releases Apache Log4j scanner to find vulnerable apps

Posted by in categories: cybercrime/malcode, electronics, robotics/AI

The Cybersecurity and Infrastructure Security Agency (CISA) has announced the release of a scanner for identifying web services impacted by two Apache Log4j remote code execution vulnerabilities, tracked as CVE-2021–44228 and CVE-2021–45046.

“log4j-scanner is a project derived from other members of the open-source community by CISA’s Rapid Action Force team to help organizations identify potentially vulnerable web services affected by the log4j vulnerabilities,” the cybersecurity agency explains.

This scanning solution builds upon similar tools, including an automated scanning framework for the CVE-2021–44228 bug (dubbed& Log4Shell)& developed by cybersecurity company FullHunt.

Dec 23, 2021

Web 3.0 Is Coming, But Not Everyone Will Love It

Posted by in categories: bitcoin, business, cybercrime/malcode, internet, privacy, robotics/AI

Go beyond the hype.

Dubbed as the internet of tomorrow, Web 3.0 seems to be the next big thing that’s going to change our lives by fundamentally reshaping the internet.

Continue reading “Web 3.0 Is Coming, But Not Everyone Will Love It” »

Dec 23, 2021

Criticizing Starship (Part Three)

Posted by in categories: cybercrime/malcode, finance, government, internet, mathematics, space travel

He has done his math. The questions seem to be: How to put together viable payloads to make use of Stsrship launches? How to build new markets in space?


This again?! Game Over? Busted? We’re doing Starship again so soon because I’m an unoriginal hack. There’s also been new developments in Starship and I think it’s a perfect time to revisit the launch system. Get as mad as you wish.

Continue reading “Criticizing Starship (Part Three)” »

Dec 23, 2021

Phishing incident causes data breach at West Virginia hospitals

Posted by in categories: biotech/medical, cybercrime/malcode

Attackers accessed email accounts containing Social Security numbers, medical treatment information, and more.

Dec 21, 2021

Over 500,000 Android Users Downloaded a New Joker Malware App from Play Store

Posted by in categories: cybercrime/malcode, robotics/AI

A new Joker malware app on the Play Store infected more than 500,000 Android users.