Showing posts with label ransomware. Show all posts
Showing posts with label ransomware. Show all posts

Wednesday, February 19, 2020

It's the Bucket Lady!



That's Boo-KAY.


Private photos leaked by PhotoSquare's unsecured cloud storage.
By this, of course I mean open buckets.



US Govt Warns Critical Industries After Ransomware Hits Gas Pipeline Facility
Ummm.... yeah.. it makes sense (to me) to secure infrastructure. Maybe I'm alone.


BingWall is —Yes, a Bing Wallpaper App for Ubuntu
As South Park says, Jesus Tapdancing Christ, was the dev drunk?


Firefox 73.0.1 released with fixes for Win, Mac, and linux.
But we're not going to tell you what they are 


ISPs sue Maine - web privacy law violates their free-speech rights
because customers would have to opt-in before the ISPs can share your data




LINUX   

How to create new groups with groupadd command
groupadd Led Zeppelin  


Give your firewall a security boost  
with new Security Meth!  
Is your HOSTS file over 16G too?



Tuesday, February 4, 2020

CLI Wireshark?



Wireshark-based Termshark 2.1
Not 100% sure why CLI, but here it is. Faster than a GUI-laden packet capture, more powerful than CAT, able to leap tall stack heaps in a single keypress....

Written in Go
(so it won't stop?)


Free Software (as in Copyleft/GPL) Will Eventually Win for the Same Reasons GNU/Linux Did

New ransomware doesn’t just encrypt data. It also meddles with critical infrastructureYes, kids, it triple encrypts and goes after hardcoded industrial systems.


Google may have shared your videos with strangers
And Twitter gave a person's account to his school.




LINUX  


How to use Nginx as an HTTP load balancer in linux
I'm more interested in how to pronounce Nginx


How to zip folder

  1. take folder
  2. zip



How to Monitor Log Files with Graylog v3.1 on Debian 10

Friday, January 17, 2020

Yet Another Win10 Vuln to be Patched



A new RDP vulnerability included in the WIN10 EMERGENCY PANIC PATCH!


Critical Cisco flaws now have PoC exploit


Satan ransomware born again
I love this title.


A comprehensive view of pen testing


So those thermal paste syringes?
No, parents, your kids aren't on drugs.
Keep one on your desk - people go mad






LINUX

df vs du commands

How to mount a drive

broot is an interactive treeview directory navigation tool for the CLI
inspired by tree

11 linux browsers
no, Goog Chrome, Opera are not open source
Falkon is pretty good, fast
(Web) Epiphany is a little silly and doesn't have many options, but this blog is put together on it
Links is the Stuff!




Monday, December 30, 2019

Wyze... Ain't



Security camera startup Wyze leaked data on millions of customers.
Email addresses, wi-fi network IDs, and body metrics exposed.
Are you still seriously using this crap?


CNET's Data breach hall of shame for 2019
Great progress has been made - it's only up 33% overall.


US Coast Guard says Ryuk ramsomware took out a maritime facility. It was most likely phishing. 30 hours downtime.  We won't learn.


The year in security debacles




LINUX


Just in case it skipped your mind, ClamAV works well on Debian/Ubuntu, CLI or GUI.


Do as much research as possible before buying hardware to make sure it's linux-compatible.


Simulate linux commands without blowing anything up. Find out what it's going to do before you do it.



Thursday, December 26, 2019

The Maze of Pensacola



The group behind the Maze ransomware that they stole from the city of Pensacola put out 2G of files to prove they were serious. In other words, the city has thus far refused to pay the ransom. And they don't have backups.


Multiple Chrome vulns exist in SQLite let hackers execute arbitrary code remotely.  Don't use Chrome.  Ok, don't use Chrome prior to 79.0.3945.79 (divided by pi, minus 13).


How orgs can defend against advanced persistent threats

  1. disconnect everything from the internet
  2. buy any antivirus company's advanced persistent threat module
  3. don't worry about it - they're rare
  4. the VP needs a new boat - maybe next year


Be careful of Christmas, Hanukkah, Kwaanza and New Years themed malware. The initial version comes via snail mail, with a phrase like Merry Christmas on it. DO NOT OPEN IT. Later versions come in the form of email, with similar phrases on the subject line. Don't open these either. The most virulent, nasty malware is marked by subject lines with emojis on them. Never open these. Jonathan McAfree, from McAfree Antivirus Division (MAD) explains that if you delete them immediately, the authors will get tired and not send anymore of them.




Tuesday, December 17, 2019

Malware for the Moon?

The Air Force is seeking proposals for technologies "for operations far beyond geosynchronous Earth orbit, near the moon's orbit: payloads for providing space domain awareness from the lunar surface, lightweight sensors for space-based space domain awareness, and methodologies for orbit determination and catalog maintenance in cislunar space.

They don't usually leak this kind of information.
So if you have these skills, give them a call.
For those of us who can't understand more than 2 words of the above (me): ask someone to tell you what Space Force is up to.


A New Jersey hospital 'had to' pay a fee after they got hit with ransomware.
Because, you know, backups are soooo hard.



Chinese e-commerce site lightinthebox.com operated in the sharing spirit: it shared 1.3TB of data, including server logs, user data, and more.


Snatch and Zeppelin ransomware recap.



Plundervolt: stealing secrets by 'undervolting'


The city of New Orleans, Louisiana, got themselves some ransomware. The mayor declared a state of emergency. It appears to be the threat actors behind Ryuk. The city is still working to recover data from the attack.

Hmmm.....  the city's emergency preparedness campaign is managed by the Office of Homeland Security and Emergency Preparedness. From the way the article is worded, the city and Homeland Security don't think much of backups.


A WhatsApp bug could have let anyone crash WhatsApp of all group members.
I have one word for you: Signal.


The writers of Nginx were interrogated at gunpoint, in their homes, at 7am because a former employer claims it was developed while one of them worked there.


VISA warns that hackers are scraping card details from gas pumps.




LINUX


How to use the uniq command - a unique command.

Tuesday, November 26, 2019

Faceyspaces, Twitter. Again.




Two third-party SDKs used by hundreds of thousands of #Android apps have been caught holding unauthorized access to users' personal data associated with their connected social media accounts. SHOCK - Faceyspaces and Twitter affected.

Not that this will affect a single login, but we Security Folk, who go running round in circles, waving our hands over our heads, have to make note of it.  Just wait til those video Faceyspaces interfaces hit homes. They will watch every facet of your life, including your sleep. Orwell was half right: Big Brother, yes - only it's not the government - it's Faceyspaces/Google/Amazon/Twitter.



Hot on the ransomware hit parade is DeathRansom.
Yeah, it didn't really encrypt your files at first, but it's back and does encrypt your files.



VCPI, an IT company, was hit with ransomware, preventing access to crucial patient records.  I think they call this irony.


How to mount your iDevice as an external drive in Ubuntu




Corona Malware

This blog has been suspended for a bit because it's practicing social distancing. Or no one reads it. Or I'm too lazy. Or the str...