Sponsor of the Day:
Jerkmate
https://threatpost.com/defending-intelligent-edge-evolving-attacks/162172/
Defending the Intelligent Edge from Evolving Attacks | Threatpost
Dec 21, 2020 - Fortinet’s Aamir Lakhani discusses best practices for securing company data against next-gen threats, like edge access trojans (EATs).
intelligent edgeattacks threatpostdefendingevolving
https://threatpost.com/fin6-and-trickbot-combine-forces-in-anchor-attacks/154508/
FIN6 and TrickBot Combine Forces in ‘Anchor’ Attacks | Threatpost
Apr 7, 2020 - FIN6 fingerprints were spotted in recent cyberattacks that initially infected victims with the TrickBot trojan, and then eventually downloaded the Anchor...
combine forcesattacks threatposttrickbot
https://threatpost.com/tiktok-flaw-phishing-attacks/163322/
TikTok Flaw Lay Bare Phone Numbers, User IDs For Phishing Attacks | Threatpost
Jan 25, 2021 - A security flaw in TikTok could have allowed attackers to query query the platform’s database – potentially opening up for privacy violations.
lay barephone numbersuser idsphishing attackstiktok
https://threatpost.com/lead-causes-of-q1-attacks/180096/
Patchable and Preventable Security Issues Lead Causes of Q1 Attacks | Threatpost
Jun 29, 2022 - Attacks against U.S. companies spike in Q1 2022 with patchable and preventable external vulnerabilities responsible for bulk of attacks.
security issuesattacks threatpostpreventableleadcauses
https://threatpost.com/threat-actors-can-exploit-windows-rdp-servers-to-amplify-ddos-attacks/163248/
Threat Actors Can Exploit Windows RDP Servers to Amplify DDoS Attacks | Threatpost
Jan 22, 2021 - Netscout researchers identify more than 14,000 existing servers that can be abused by ‘the general attack population’ to flood organizations’ networks with...
threat actorswindows rdpddos attacksexploitservers
https://threatpost.com/third-party-apis-enumeration-attacks/162589/
Third-Party APIs: How to Prevent Enumeration Attacks | Threatpost
Dec 23, 2020 - Jason Kent, hacker-in-residence at Cequence, walks through online-retail card fraud and what to do about it.
third party apisattacks threatpostpreventenumeration
https://threatpost.com/fbi-egregor-attacks-businesses-worldwide/162885/
FBI Warns of Egregor Attacks on Businesses Worldwide | Threatpost
Jan 8, 2021 - The agency said the malware has already compromised more than 150 organizations and provided insight into its ransomware-as-a-service behavior.
fbi warnsbusinesses worldwideegregorattacksthreatpost
https://threatpost.com/email-security-attacks-bec/163869/
How Email Attacks are Evolving in 2021 | Threatpost
Feb 11, 2021 - The money being wire transferred by business email compromise victims is on the rise, as cybersecurity criminals evolve their tactics.
email attacks2021 threatpostevolving
https://threatpost.com/new-collision-attacks-against-3des-blowfish-allow-for-cookie-decryption/120087/
New Collision Attacks Against 3DES, Blowfish Allow for Cookie Decryption | Threatpost
Aug 24, 2016 - New attacks recover and decrypt authentication cookies from 3DES and Blowfish protected traffic. OpenSSL will deprecate 3DES’ designation from high to medium.
newcollisionattacksblowfishallow
https://threatpost.com/watering-hole-attacks-push-scanbox-keylogger/180490/
Watering Hole Attacks Push ScanBox Keylogger | Threatpost
Aug 30, 2022 - Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
watering hole attackspushscanboxkeyloggerthreatpost
https://threatpost.com/ddos-attacks-prepared/180273/
IoT Botnets Fuel DDoS Attacks – Are You Prepared? | Threatpost
Aug 9, 2022 - The increased proliferation of IoT devices paved the way for the rise of IoT botnets that amplifies DDoS attacks today. Learn more.
iot botnetsddos attacksfuelpreparedthreatpost
https://threatpost.com/cyber-spike-attacks-high-log4j/177481/
Cyber-Spike: Orgs Suffer 925 Attacks per Week, an All-Time High | Threatpost
Jan 10, 2022 - Cyberattacks increased 50 percent YoY in 2021 and peaked in December due to a frenzy of Log4j exploits, researchers found.
per weektime highcyberspikeorgs
https://threatpost.com/podcast-ransomware-attacks-exploded-in-q4-2020/164285/
Podcast: Ransomware Attacks Exploded in Q4 2020 | Threatpost
Sep 16, 2021 - Researchers saw a seven-times increase in ransomware activity in the fourth quarter of 2020, across various families – from Ryuk to Egregor.
ransomware attacksq4 2020podcastexplodedthreatpost
https://threatpost.com/bec-attacks-nigeria-losses-snowball/160118/
BEC Attacks: Nigeria No Longer the Epicenter as Losses Top $26B | Threatpost
Oct 14, 2020 - BEC fraudsters now have bases of operation across at least 39 counties and are responsible for $26 billion in losses annually — and growing.
bec attackslosses topnigerialongerepicenter
https://threatpost.com/popular-bait-in-phishing-attacks/180281/
Phishing Attacks Skyrocket with Microsoft and Facebook as Most Abused Brands | Threatpost
Jul 26, 2022 - Instances of phishing attacks leveraging the Microsoft brand increased 266 percent in Q1 compared to the year prior.
phishing attacksskyrocketmicrosoftfacebookabused
https://threatpost.com/ransomware-attacks-are-on-the-rise/180481/
Ransomware Attacks are on the Rise | Threatpost
Aug 26, 2022 - Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
ransomware attacksrisethreatpost
https://threatpost.com/four-distinct-watering-hole-attacks-dropping-scanbox-keylogger/109061/
Four ScanBox APT Watering Hole Attacks Uncovered | Threatpost
Sep 16, 2021 - PwC has published research on four watering hole attacks likely carried out by different attackers, all connected by the ScanBox reconnaissance tool.
watering hole attacksfourscanboxaptuncovered