read.cash Log in
@ircrp more from that month

Cyber Threat On The Rise

In the year dominated by the pandemic during which the cyber world has been significantly active, security experts are revealing that the cyber crime has gone through the roof with some techniques getting scarely clever and efficient. Microsoft's security department has recently released a Digital Defense annual report with some interesting findings. https://www.microsoft.com/en/security/business/security-intelligence-report In addition to the attacks getting more clever and sophisticated the hackers are showing a clear preference towards ransomware and credential harvesting attacks. Microsoft reports that is has blocked over 13 billion suspicious and malicious mails in previous year, with 1 billion of those containing a phising link targeted for credential harvesting. Credential harvesting in most cases was the first step into Business Email Compromise (BEC) related attacks. Attackers would typically target accounts of payroll employees, with clear preference towards Accounting and C-Suites. The research also highlights that in the past months hackers are advancing their attacks against legacy email protocols such as SMTP and IMAP with significant rise of password reuse and spray attacks.  The rise on attacks of the legacy email protocols has been mainly contributed to the rise of Multi-Factor Authentication (MFA) adoption, with the SMTP and IMAP protocols not supporting MFA allowing attackers to target users protected by MFA solutions. The most troublesome threat throughout the past year has notably been related to ransomware infections with the most common, troublesome and time taking security incident response in Microsoft has been dealing with problems caused by notorious ransomware gangs. The attackers typically rely on discovering newly disclosed vulnerabilities and exploiting those through a range of initial access attacks. In most cases once the attackers exploit the vulnerability and grant an access into the victim's system time is taken to acquire the intelligence and perfect out their attack. In some cases the attacks were crafted with mass disruption in mind, with automated solutions being able to achieve a full network ransomware attacks within 45 minutes.   **Related Reading** Zerologon vulnerability exploitation on the rise https://www.publish0x.com/ircrp/zerologon-vulnerability-exploitation-on-the-rise-xpjoevl?a=M7e5yEPRe2&tid=rr Firefox bug allows hijacking mobile browsers https://www.publish0x.com/ircrp/firefox-bug-allows-hijacking-mobile-browsers-xxoxjxo?a=M7e5yEPRe2&tid=rr Zerologon Vulnerability https://www.publish0x.com/ircrp/zerologon-security-newsletter-xvrqdok?a=M7e5yEPRe2&tid=rr Tronlink Wallet uses weak encryption https://www.publish0x.com/ircrp/tronlink-wallet-uses-weak-encryption-xpjopnd?a=M7e5yEPRe2&tid=rr     **Ongoing crypto free earn campaigns:** *Coinbase* *Earn $50 of XLM* https://www.coinbase.com/earn/stellar/invite/ztr3sqh7 *Coinbase* *Earn $50 of EOS* https://www.coinbase.com/earn/eos/invite/g9r8n305   **Ongoing crypto non-free earn campaigns:** *Crypto.com* *$50 of CRO* *once 1000 CRO staked* https://crypto.com/app/msagh7w9qq Resources https://www.microsoft.com/en/security/business/security-intelligence-report

No comments yet

Log in to join in Reading is open to everyone. Replying needs an account.