Wednesday, October 13, 2021

Microsoft Hit with 2.4 Tbps DDoS Attack – 2nd Largest Attack Ever Recorded

Microsoft recently proclaimed that they have witnessed a 2.4 Tbps DDoS attack in August this year, and it’s the largest attack ever recorded till now. Since the early one was recorded with a volume of 2.3 Tbps, which was already mitigated by AWS. This huge attack was targeted on Microsoft Azure clients in Europe and […] The post Microsoft Hit with 2.4 Tbps DDoS Attack – 2nd Largest Attack Ever Recorded appeared first on Cyber Security News.
https://cybersecuritynews.com/microsoft-hit-with-2-4-tbps-ddos-attack/?utm_source=dlvr.it&utm_medium=blogger

Indian Made Spyware That Linked With Notorious Hacker Group Attacking Activist

Researchers from Amnesty International have uncovered a new wave of spyware that is believed to be developed from an India-based cybersecurity company and utilized by the notorious hacker group to target human rights activists in Tago. The threat group is known as Donot Team that was connected to various attacks in south Asia, now linked […] The post Indian Made Spyware That Linked With Notorious Hacker Group Attacking Activist appeared first on Cyber Security News.
https://cybersecuritynews.com/indian-made-spyware/?utm_source=dlvr.it&utm_medium=blogger

Critical Flaw in OpenSea Could Have Let Hackers Steal Cryptocurrency From Wallets

A now-patched critical vulnerability in OpenSea, the world's largest non-fungible token (NFT) marketplace, could've been abused by malicious actors to drain cryptocurrency funds from a victim by sending a specially-crafted token, opening a new attack vector for exploitation. The findings come from cybersecurity firm Check Point Research, which began an investigation into the platform following
https://thehackernews.com/2021/10/critical-flaw-in-opensea-could-have-let.html?utm_source=dlvr.it&utm_medium=blogger

[eBook] The Guide for Reducing SaaS Applications Risk for Lean IT Security Teams

The Software-as-a-service (SaaS) industry has gone from novelty to an integral part of today’s business world in just a few years. While the benefits to most organizations are clear – more efficiency, greater productivity, and accessibility – the risks that the SaaS model poses are starting to become visible. It’s not an overstatement to say that most companies today run on SaaS. This poses an
https://thehackernews.com/2021/10/ebook-guide-for-reducing-saas.html?utm_source=dlvr.it&utm_medium=blogger

Update Your Windows PCs Immediately to Patch New 0-Day Under Active Attack

Microsoft on Tuesday rolled out security patches to contain a total of 71 vulnerabilities in Microsoft Windows and other software, including a fix for an actively exploited privilege escalation vulnerability that could be exploited in conjunction with remote code execution bugs to take control over vulnerable systems. Two of the addressed security flaws are rated Critical, 68 are rated Important
https://thehackernews.com/2021/10/update-your-windows-pcs-immediately-to.html?utm_source=dlvr.it&utm_medium=blogger

Tuesday, October 12, 2021

GitHub Revoked Insecure SSH Keys Generated by a Popular git Client

Code hosting platform GitHub has revoked weak SSH authentication keys that were generated via the GitKraken git GUI client due to a vulnerability in a third-party library that increased the likelihood of duplicated SSH keys. As an added precautionary measure, the Microsoft-owned company also said it's building safeguards to prevent vulnerable versions of GitKraken from adding newly generated
https://thehackernews.com/2021/10/github-revoked-insecure-ssh-keys.html?utm_source=dlvr.it&utm_medium=blogger

Microsoft Fended Off a Record 2.4 Tbps DDoS Attack Targeting Azure Customers

Microsoft on Monday revealed that its Azure cloud platform mitigated a 2.4 Tbps distributed denial-of-service (DDoS) attack in the last week of August targeting an unnamed customer in Europe, surpassing a 2.3 Tbps attack stopped by Amazon Web Services in February 2020. "This is 140 percent higher than 2020's 1 Tbps attack and higher than any network volumetric event previously detected on Azure,
https://thehackernews.com/2021/10/microsoft-fended-off-record-24-tbps.html?utm_source=dlvr.it&utm_medium=blogger

Microsoft Warns of Iran-Linked Hackers Targeting US and Israeli Defense Firms

An emerging threat actor likely supporting Iranian national interests has been behind a password spraying campaign targeting US, EU, and Israeli defense technology companies, with additional activity observed against regional ports of entry in the Persian Gulf as well as maritime and cargo transportation companies focused in the Middle East. Microsoft is tracking the hacking crew under the
https://thehackernews.com/2021/10/microsoft-warns-of-iran-linked-hackers.html?utm_source=dlvr.it&utm_medium=blogger

Ukraine Arrests Operator of DDoS Botnet with 100,000 Compromised Devices

Ukrainian law enforcement authorities on Monday disclosed the arrest of a hacker responsible for the creation and management of a "powerful botnet" consisting of over 100,000 enslaved devices that was used to carry out distributed denial-of-service (DDoS) and spam attacks on behalf of paid customers. The unnamed individual, from the Ivano-Frankivsk region of the country, is also said to have
https://thehackernews.com/2021/10/ukraine-arrests-operator-of-ddos-botnet.html?utm_source=dlvr.it&utm_medium=blogger

Verify End-Users at the Helpdesk to Prevent Social Engineering Cyber Attack

Although organizations commonly go to great lengths to address security vulnerabilities that may exist within their IT infrastructure, an organization's helpdesk might pose a bigger threat due to social engineering attacks. Social engineering is "the art of manipulating people so they give up confidential information," according to Webroot. There are many different types of social engineering
https://thehackernews.com/2021/10/verify-end-users-at-helpdesk-to-prevent.html?utm_source=dlvr.it&utm_medium=blogger