Skip to main content

Posts

More than half of Russian companies are concerned about the protection of personal data of employees and customers

The antivirus company ESET studied the state of information security in the Russian business sector, interviewing dozens of IT Directors and business owners. According to ESET research, different types of cyber threats affected 90% of Russian businesses. 60% of Russian IT managers are seriously concerned about the safety of personal data. "The discontinuation of Windows 7 will play a role. Many Russian companies, despite the risks, will continue to use the operating system in the workplace. This will increase the risk of infection with new viruses, compromise and loss of corporate data," said the ESET representative. In addition, on January 14, 2020, support for the Windows 2008 and Windows 2008 R2 server systems was completed. They are used by many small and medium businesses. According to Ruslan Suleymanov, the Director of Information Technology Department of ESET Russia, this year, powerful and frequent DDoS attacks on the corporate sector and deepfakes will remain a ...

Railway Protection Force (RPF) bust a multi-crore ticket fraud

Bengaluru: The Railway Protection Force busted a multi crore ticket booking fraud and apprehended two miscreants who hacked the railway booking website and used the ANMS Tatkal software to book tickets. The ticketing racket seems to have been working all around the nation and the police as well as RPF are making all efforts to snub the fraud and catch all the agents involved in the fraudulent scheme. The accused arrested by the police are Gulam Mustafa (26), a from Jharkhand, and Hanumantharaju M (37), a from Peenya. Akhilesh Kumar Tiwari, post commander RPF, South Western Railway told that Hanumantharaju was arrested last year and Mustafa on Jan 8th. Upon questioning, Mustafa said to deccanherald that, "in 2017, he had created an Indian Railway Catering and Tourism Corporation (IRCTC) agent ID to book an e-ticket. He later joined hands with the other accused and hacked the booking portal through ANMS software and created 563 fake IDs and started booking e-tickets ill...

Google Maps…Creepy or Useful?

Whether Android or iPhone there is no denying that Google is there for all of us, keeping a track log of our data in a "Timeline" that unequivocally shows wherever we've been, which while in some cases is amazingly valuable and helpful yet for the rest it’s downright creepy. The creepy degree of details range from like precisely the time at which the user left for home, arrival at home, the exact route taken along the way, pictures taken in specific locations and then some. It'll show them if they were driving, strolling or on a train, and any pit stops they may have made during their journey. Like here is an example including a user's stop for lunch, and a meeting they took with Snapchat on the Upper West side earlier in the day. Zoomed in, one can see the exact course taken to arrive and where the car was parked. And hence there's no reason as to why Google has to know this much information about any user, except if they truly care about thi...

Bot List Containing Telnet Credentials for More than 500,000 Servers, Routers and IoT Devices Leaked Online

This week, a hacker published a list on a popular hacking forum containing Telnet credentials for over 515,000 servers, home routers and IoT (Internet of Things) "smart" devices. The massive list which reportedly was concluded by browsing the whole internet in search of devices that left their Telnet port exposed, included IP addresses of all the devices, username and password for the Telnet service and a remote access protocol that can be employed to control devices over the internet. After scanning the Internet in search of devices exposing their Telnet port, the hacker attempts to use either factory-set default usernames and passwords or custom but guessable combinations, as per the statements by the leaker himself. These lists, generally kept private – are known as 'bot lists' that are built after hackers scan the Internet and then employed them to connect to the devices and install malware. Sources say that although there have been some leaks in the past, ...

Citrix Releases Patches for Critical ADC Vulnerability Under Active Attack

Citrix has finally started rolling out security patches for a critical vulnerability in ADC and Gateway software that attackers started exploiting in the wild earlier this month after the company announced the existence of the issue without releasing any permanent fix. I wish I could say, "better late than never," but since hackers don't waste time or miss any opportunity to exploit

Evaluating Your Security Controls? Be Sure to Ask the Right Questions

Testing security controls is the only way to know if they are truly defending your organization. With many different testing frameworks and tools to choose from, you have lots of options. But what do you specifically want to know? And how are the findings relevant to the threat landscape you face at this moment? "Decide what you want to know and then choose the best tool for the job."

Website Puts 12 Billion User Records Up For Sale and Gets Seized By US Authorities

Are you fond of buying stolen'/leaked data? Because, one such domain, named ‘WeLeakInfo.com’ recently got seized by the US authorities. WeLeakInfo, with its absolutely convenient name, had been selling stolen data from other hacked websites, online for the past three years. The website provided an online service where hacked data was made available to people willing to pay for it. Per sources, hackers were made available people’s “cleartext passwords” which aided them to purchase a subscription on the site in order to attain access to tons of user credentials. Apparently, this illegal website was doing so well that it had gotten quite a popular fan-base for itself in the hacking “underworld”. Reportedly, people were even providing them with consignments to execute recon on targeted individuals and organizations alike. The modus operandi was in the way, that hackers would buy access to the site. They’d then search for names, emails and usernames of people they want to...