Author Archives: CSIRT

xHunt Campaign: Newly Discovered Backdoors Using Deleted Email Drafts and DNS Tunneling for Command and Control

Executive Summary The xHunt campaign has been active since at least July 2018 and we have seen this group target Kuwait government and shipping and transportation organizations. Recently, we observed evidence that the threat actors compromised a Microsoft Exchange Server at an organization in Kuwait. We do not have visibility into how the actors gained […]

OneClass unsecured S3 bucket exposes PII on more than one million students, instructors

from www.scmagazine.com An unsecured database belonging remote learning platform OneClass has exposed information associated with more than a million students in North America who use the platform to access study guides and educational assistance. “By not securing its users’ data, OneClass has created a goldmine for criminal hackers, jeopardizing the privacy and security of over […]

Most malware in Q1 2020 was delivered via encrypted HTTPS connections

from www.helpnetsecurity.com 67% of all malware in Q1 2020 was delivered via encrypted HTTPS connections and 72% of encrypted malware was classified as zero day, so would have evaded signature-based antivirus protection, according to WatchGuard. These findings show that without HTTPS inspection of encrypted traffic and advanced behavior-based threat detection and response, organizations are missing […]

33% Surge in Financial Fraud Attempts During #COVID19 Lockdown

from www.infosecurity-magazine.com Financial fraud attempts rose by 33% in April as the UK entered lockdown due to the COVID-19 pandemic, new analysis from Experian and the National Hunter Fraud Prevention Service has revealed. Fraudsters targeted a myriad of financial products, including current and savings accounts, as they sought to take advantage of the disruption to […]

NCSC: One Million Phishing Messages Reported in Two Months

from www.infosecurity-magazine.com The National Cyber Security Centre (NCSC) has announced that in just two months of its Suspicious Email Reporting Service being launched, it has received one million reports. According to a statement, the service, which was launched in April as part of the Government’s Cyber Aware campaign, receives a daily average of 16,500 emails. […]