Independent

IndependentKrebs

Powerful New DDoS Method Adds Extortion

Credit to Author: BrianKrebs| Date: Fri, 02 Mar 2018 22:41:55 +0000

Attackers have seized on a relatively new method for executing distributed denial-of-service (DDoS) attacks of unprecedented disruptive power, using it to launch record-breaking DDoS assaults over the past week. Now evidence suggests this novel attack method is fueling digital shakedowns in which victims are asked to pay a ransom to call off crippling cyberattacks.

Read More
ComputerWorldIndependent

SEC eyes crackdown on cryptocurrencies

Credit to Author: Lucas Mearian| Date: Thu, 01 Mar 2018 14:24:00 -0800

The Securities and Exchange Commission (SEC) is cracking down on FinTech companies issuing initial coin offerings (ICOs), and has served dozens of subpoenas and information requests.

The regulatory action is the latest in a series of warnings related to the multi-billion cryptocurrency market and the sale of digital tokens, which in some cases may violate federal laws, according to the Wall Street Journal.

The SEC declined comment on the report.

Cryptocurrencies, or digial tokens such as bitcoin, Ether and Ripple, are based on blockchain technology and have existed in a gray area that allows for cross-border transactions that are far more efficient than traditional fiat-based currencies such as dollars or euros.

To read this article in full, please click here

Read More
IndependentKrebs

Financial Cyber Threat Sharing Group Phished

Credit to Author: BrianKrebs| Date: Thu, 01 Mar 2018 19:04:34 +0000

The Financial Services Information Sharing and Analysis Center (FS-ISAC), an industry forum for sharing data about critical cybersecurity threats facing the banking and finance industries, said today that a successful phishing attack on one of its employees was used to launch additional phishing attacks against FS-ISAC members. The fallout from the back-to-back phishing attacks appears to have been limited and contained, as many FS-ISAC members who received the phishing attack quickly detected and reported it as suspicious. But the incident is a good reminder to be on your guard, remember that anyone can get phished, and that most phishing attacks succeed by abusing the sense of trust already established between the sender and recipient.

Read More
IndependentKrebs

How to Fight Mobile Number Port-out Scams

Credit to Author: BrianKrebs| Date: Wed, 28 Feb 2018 14:46:30 +0000

T-Mobile, AT&T and other mobile carriers are reminding customers to take advantage of free services that can block identity thieves from easily “porting” your mobile number out to another provider, which allows crooks to intercept your calls and messages while your phone goes dark. Tips for minimizing the risk of number porting fraud are available below for customers of all four major mobile providers, including Sprint and Verizon.

Read More
ComputerWorldIndependent

Microsoft Patch day brings bug warnings, another Office CtR, and the return of KB 2952664

Credit to Author: Woody Leonhard| Date: Wed, 28 Feb 2018 05:54:00 -0800

Once upon a time, the fourth Tuesday of the month was reserved by Microsoft for non-security patches. How times have changed. Yesterday, we saw a bunch of new bug warnings — including an admonition to uninstall a previous buggy .Net Preview patch — and an unexpected fourth update this month for Office 365’s reputedly stable Monthly Channel.

New .Net Preview warning to uninstall

The Feb. 2018 .Net Framework Previews — which were pulled last Thursday — got new warnings. Each of these updated KB articles:

To read this article in full, please click here

Read More
IndependentKrebs

Bot Roundup: Avalanche, Kronos, NanoCore

Credit to Author: BrianKrebs| Date: Tue, 27 Feb 2018 19:10:52 +0000

It’s been a busy few weeks in cybercrime news, justifying updates to a couple of cases we’ve been following closely at KrebsOnSecurity. In Ukraine, the alleged ringleader of the Avalanche malware spam botnet was arrested after eluding authorities in the wake of a global cybercrime crackdown there in 2016. Separately, a case that was hailed as a test of whether programmers can be held accountable for how customers use their product turned out poorly for 27-year-old programmer Taylor Huddleston, who was sentenced to almost three years in prison for making and marketing a complex spyware program.

Read More
IndependentKrebs

USPS Finally Starts Notifying You by Mail If Someone is Scanning Your Snail Mail Online

Credit to Author: BrianKrebs| Date: Mon, 26 Feb 2018 19:28:41 +0000

In October 2017, KrebsOnSecurity warned that ne’er-do-wells could take advantage of a relatively new service offered by the U.S. Postal Service that provides scanned images of all incoming mail before it is slated to arrive at its destination address. We advised that stalkers or scammers could abuse this service by signing up as anyone in the household, because the USPS wasn’t at that point set up to use its own unique communication system — the U.S. mail — to alert residents when someone had signed up to receive these scanned images. The USPS recently told this publication that beginning Feb. 16 it started alerting all households by mail whenever anyone signs up to receive these scanned notifications of mail delivered to that address. The notification program, dubbed “Informed Delivery,” includes a scan of the front and back of each envelope or package destined for a specific address.

Read More