Blog

by Chris H Chris H No Comments

New Attack Technique Exploits Microsoft Management Console Files

Threat actors are exploiting a novel attack technique in the wild that leverages specially crafted management saved console (MSC) files to gain full code execution using Microsoft Management Console (MMC) and evade security defenses.
Elastic Security Labs has codenamed the approach GrimResource after identifying an artifact (“sccm-updater.msc”) that was uploaded to the VirusTotal malware
by Chris H Chris H No Comments

How to Cut Costs with a Browser Security Platform

Browser security is becoming increasingly popular, as organizations understand the need to protect at the point of risk – the browser. Network and endpoint solutions are limited in their ability to protect from web-borne threats like phishing websites or malicious browser extensions. They also do not protect from internal data exfiltration, like employees pasting sensitive data to ChatGPT. As it
by Chris H Chris H No Comments

New Cyberthreat ‘Boolka’ Deploying BMANAGER Trojan via SQLi Attacks

A previously undocumented threat actor dubbed Boolka has been observed compromising websites with malicious scripts to deliver a modular trojan codenamed BMANAGER.
“The threat actor behind this campaign has been carrying out opportunistic SQL injection attacks against websites in various countries since at least 2022,” Group-IB researchers Rustam Mirkasymov and Martijn van den Berk said in a
by Chris H Chris H No Comments

Wikileaks’ Julian Assange Released from U.K. Prison, Heads to Australia

WikiLeaks founder Julian Assange has been freed in the U.K. and has departed the country after serving more than five years in a maximum security prison at Belmarsh for what was described by the U.S. government as the “largest compromises of classified information” in its history.
Capping off a 14-year legal saga, Assange, 52, pleaded guilty to one criminal count of conspiring to obtain and
by Chris H Chris H No Comments

4 FIN9-linked Vietnamese Hackers Indicted in $71M U.S. Cybercrime Spree

Four Vietnamese nationals with ties to the FIN9 cybercrime group have been indicted in the U.S. for their involvement in a series of computer intrusions that caused over $71 million in losses to companies.
The defendants, Ta Van Tai (aka Quynh Hoa and Bich Thuy), Nguyen Viet Quoc (aka Tien Nguyen), Nguyen Trang Xuyen, and Nguyen Van Truong (aka Chung Nguyen), have been accused of conducting
by Chris H Chris H No Comments

Ukrainian Military says they hacked Russia’s federal tax agency

The Ukrainian government’s military intelligence service says it hacked the Russian Federal Taxation Service (FNS), wiping the agency’s database and backup copies.

Following this operation, carried out by cyber units within Ukraine’s Defense Intelligence, military intelligence officers breached Russia’s federal taxation service central servers and 2,300 regional servers across Russia and occupied Ukrainian territories.

Read more: https://www.bleepingcomputer.com/news/security/ukrainian-military-says-it-hacked-russias-federal-tax-agency/

by Chris H Chris H No Comments

World’s Fastest Academic Supercomputer Unveiled in Texas

The Texas Advanced Computing Center at the University of Texas at Austin unveiled Frontera—the fastest supercomputer at any university and the fifth most powerful supercomputing system in the world. 

Funded through a $60 million award from the National Science Foundation and officially launched Tuesday, the system will support U.S. and international research teams as they work to solve some of the world’s most massive advanced computational challenges.

“The system itself is a remarkable system,” John West, TACC’s director of strategic initiatives and co-principal investigator on Frontera, told Nextgov. “It’s an incredible opportunity for open science to have access to a resource at this scale so that investment by the National Science Foundation is going to be incredibly important for discovery and innovation going forward.”

West, who previously led the Defense Department’s high-performance computing modernization program and was once responsible for supercomputing research and development across the agency’s enterprise, explained that NSF works with a variety of cyber-infrastructure providers across the country because running such state-of-the-art systems is incredibly resourced and facility intensive. It also requires a great deal of floor space and immense amounts of power and cooling. 

TACC already has several large-scale computing systems—including the 19th fastest system in the world, Stampede2—that solve a variety of highly complex computational jobs. But Frontera— Spanish for “frontier” and an allusion to the title of a 1945 report to President Harry Truman that led to the creation of NSF—will power even more cutting-edge discoveries. 

“Frontera is different,” West said. “Its audience is really those scientists that need the most capable computational resources, so it will run less of a mix of jobs, focusing instead on scientists at the very tip of computational capability that we can provide today.” 

Through a solicitation first awarded in 2018, the system aims to act as a resource not just to UT students but to the entire open science community, meeting the needs of some of the most massive science and engineering computational experiments that need to be performed. West and his team at TACC have been constructing the system all year. The system will operate for at least five years and in that time it will likely be used by thousands of researchers across nearly all fields of science. 

“The focus is on supporting the entire research enterprise so it is across all the scientific disciplines,” West said. “And this is not just a UT resource, this is a resource for scientists all over the world to use.”

Those who want to run research on the system—and who can prove that they require a computer at Frontera’s scale to solve their problems—will be selected to use it through a competitive application process. The gigantic machines are fairly specialized to run and are highly complex in their analysis and applications, so TACC has specialists on hand to support researchers who will work directly with it. Faculty from the university’s Oden Institute for Computational Engineering and Sciences, with partners from other schools including the California Institute of Technology, Ohio State University, Princeton University, the University of Chicago, the University of Utah and others will lead Frontera’s science applications and technology team.

“The idea here is not only provide the machine but provide the expertise that science needs to make use of the machine,” he said. 

Read the rest: https://www.nextgov.com/emerging-tech/2019/09/worlds-fastest-academic-supercomputer-unveiled-texas/159603/

by Chris H Chris H No Comments

IRS Warns of New Imposter Scam That Spreads Malware

Online bad actors are impersonating tax collectors to spread malware and potentially gain access to people’s computers, according to the IRS.

Last week, agency officials warned taxpayers to watch out for a new phishing campaign involving fraudsters disguised as IRS agents. The agency does not send taxpayers emails out of the blue, they said, so all unsolicited messages should be viewed with suspicion.

As part of the scam, imposters send taxpayers emails claiming to contain information about their refunds, electronic returns or online accounts, according to agency officials. The emails include links to websites that closely resemble IRS.gov, as well as temporary passwords that supposedly allow recipients to access their relevant files. 

When people access those files, however, they release malware that could allow fraudsters to gain control of users’ computer or covertly download spyware that obtains sensitive passwords and accounts. The scam relies on dozens of spoofed web addresses, which makes difficult to shut down, officials said.

Officials noted the IRS doesn’t request personal or financial information—including PINs, passwords or other account credentials—from taxpayers through email, text message or social media. The agency also doesn’t contact people demanding immediate payment through gift cards, prepaid debit cards or wire transfers, they said, so taxpayers should be wary of any such attempts.

While the agency has made significant strides in reducing taxpayer identity theft in recent years, officials said phone and email scams by IRS imposters still pose a significant threat to taxpayers.

“This latest scheme is yet another reminder that tax scams are a year-round business for thieves,” IRS Commissioner Chuck Rettig said in a statement. “We urge you to be on-guard at all times.”

From: https://www.nextgov.com/cybersecurity/2019/08/irs-warns-new-imposter-scam-spreads-malware/159445/

Top