Menu Close
  • Phish-Friendly Domain Registry “.top” Put on Notice
    by BrianKrebs on July 23, 2024 at 7:41 pm

    The Chinese company in charge of handing out domain names ending in “.top” has been given until mid-August 2024 to show that it has put in place systems for managing phishing reports and suspending abusive domains, or else forfeit its license to sell domains. The warning comes amid the release of new findings that .top was the most common suffix in phishing websites over the past year, second only to domains ending in “.com.”

  • Global Microsoft Meltdown Tied to Bad Crowdstrike Update
    by BrianKrebs on July 19, 2024 at 2:24 pm

    A faulty software update from cybersecurity vendor Crowdstrike crippled countless Microsoft Windows computers across the globe today, disrupting everything from airline travel and financial institutions to hospitals and businesses online. Crowdstrike said a fix has been deployed, but experts say the recovery from this outage could take some time, as Crowdstrike’s solution needs to be applied manually on a per-machine basis.

  • Researchers: Weak Security Defaults Enabled Squarespace Domains Hijacks
    by BrianKrebs on July 15, 2024 at 3:24 pm

    At least a dozen organizations with domain names at domain registrar Squarespace saw their websites hijacked last week. Squarespace bought all assets of Google Domains a year ago, but many customers still haven’t set up their new accounts. Experts say malicious hackers learned they could commandeer any migrated Squarespace accounts that hadn’t yet been registered, merely by supplying an email address tied to an existing domain.

  • Crooks Steal Phone, SMS Records for Nearly All AT&T Customers
    by BrianKrebs on July 12, 2024 at 6:12 pm

    AT&T Corp. disclosed today that a new data breach has exposed phone call and text message records for roughly 110 million people — nearly all of its customers. AT&T said it delayed disclosing the incident in response to “national security and public safety concerns,” noting that some of the records included data that could be used to determine where a call was made or text message sent. AT&T also acknowledged the customer records were exposed in a cloud database that was protected only by a username and password (no multi-factor authentication needed).

  • The Stark Truth Behind the Resurgence of Russia’s Fin7
    by BrianKrebs on July 10, 2024 at 4:22 pm

    The Russia-based cybercrime group dubbed “Fin7,” known for phishing and malware attacks that have cost victim organizations an estimated $3 billion in losses since 2013, was declared dead last year by U.S. authorities. But experts say Fin7 has roared back to life in 2024 — setting up thousands of websites mimicking a range of media and technology companies — with the help of Stark Industries Solutions, a sprawling hosting provider is a persistent source of cyberattacks against enemies of Russia.

  • Microsoft Patch Tuesday, July 2024 Edition
    by BrianKrebs on July 9, 2024 at 7:50 pm

    Microsoft Corp. today issued software updates to plug 139 security holes in various flavors of Windows and other Microsoft products. Redmond says attackers are already exploiting at least two of the vulnerabilities in active attacks against Windows users.

  • The Not-So-Secret Network Access Broker x999xx
    by BrianKrebs on July 3, 2024 at 4:41 pm

    Most accomplished cybercriminals go out of their way to separate their real names from their hacker handles. But among certain old-school Russian hackers it is not uncommon to find major players who have done little to prevent people from figuring out who they are in real life. A case study in this phenomenon is “x999xx,” the nickname chosen by a venerated Russian hacker who specializes in providing the initial network access to various ransomware groups.

  • Cyber Security Operation Center Guidelines for best practices SOC Design
    by Cyber Security Consultant on January 30, 2024 at 4:32 pm

    Cyber Security is become most needed services for all business and industries in 2024. Every business is concerned about Cyber Security. Security operations (SecOps) leaders face a multifaceted challenge: detecting elusive and novel threats using outdated tools, mitigating the risks posed by unexplored dark data, and managing the resource-intensive nature of staying ahead of evolving

  • HOW TO BECOME CERTIFIED LEAD IMPLEMENTER – ISO 27001
    by Cyber Security Consultant on January 26, 2023 at 11:21 am

    ABOUT CERTIFIED LEAD IMPLEMENTER TRAINING AND EXAMINATION FOR INFORMATION SECURITY MANAGEMENT SYSTEM ISO / IEC 27001 Learn and get certified as a professional in implementation of ISO 27001 standard through our self-paced E-learning interactive course which comprises of 4 modules. Upon completion of these modules, you can appear for an examination and get certified as

  • YouTube disrupted in Pakistan as former PM Imran Khan streams speech
    by Cyber Security Consultant on August 22, 2022 at 5:04 am

    NetBlocks metrics confirm the disruption of YouTube on multiple internet providers in Pakistan on Sunday 21 August 2022. The disruption comes as former Prime Minister Imran Khan makes a live broadcast to the public, despite a ban issued by the Pakistan Electronic Media Regulatory Authority (PEMRA). Real-time network data show the disruption in effect on

  • Recommendations for Parents about Cyber Bullying
    by Cyber Security Consultant on October 20, 2021 at 6:36 am

    Here are some dedicated tips for keeping younger children safe online. One of these training tips goes into the risks of young children on the Internet, covers cyber bullying and other risky Internet behavior. Here are the suggestions parents should take into account regarding kids online. • Talk with your kids about online safety and

  • WhatsApp, Facebook, Instagram server down in Pakistan?
    by Cyber Security Consultant on October 4, 2021 at 5:32 pm

    Facebook-owned social media platforms, WhatsApp, Facebook, and Instagram are facing a worldwide outage, according to Downdetector, which offers real-time status and outage information for all kinds of services. .https://d-31038805491725975734.ampproject.net/2109102127000/frame.html Downdetector showed that WhatsApp outage was reported at 8:23 pm (Pakistan Standard Time) and it shot up to 1,082 complaints by 8:38 pm. The website mentioned that

  • Cloudflare reports record-breaking HTTP-request DDoS attack
    by Cyber Security Consultant on August 22, 2021 at 7:26 pm

    Cloudflare reports thwarting the largest known HTTP-request distributed denial of service attack in history, approximately three times larger than any other previously reported. The attack in July reached 17.2 million requests per second, the company wrote in a blog post. For scale, the entirety of the Cloudflare network typically sees around 25 million requests per second

  • Microsoft announces recipients of academic grants for AI research on combating phishing
    by Cyber Security Consultant on June 19, 2021 at 3:34 pm

    Every day in the ever-changing technology landscape, we see boundaries shift as new ideas challenge the old status quo. This constant shift is observed in the increasingly sophisticated and connected tools, products, and services people and organizations use on a daily basis, but also in the security that needs to be built into these technologies