Q: “Will I Get Hacked?” is Wrong Question

The question should be “When will I get Hacked?” Internet Storm center went to Threat level Yellow today: Internet Storm Center threat status: (this morning on 17th threat level went back to Green) – threat Activity died down fortunately and enough of us are patching.   The reason it went yellow for a day is … Read more

Infosec Researchers Hacking New DLink Routers

The AC5300 Ultra WiFi router looks “Ultra” and new. Looks interesting right? lots of new specs and capabilities. Now let’s check out security researcher at /dev/TTYS0   So, while Dlink was busy with their marketing campaign and trying to sell more routers with flashy products and images (after a certain engineering effort), the security researcher … Read more

FBI: Watch for Fake Government Sites

ISIL is defacing web Sites using WordPress vulnerabilities http://www.ic3.gov/media/2015/150407-1.aspx  ic3=Internet Crime Complaint Center recommendation is to update your WordPress website as much as possible when necessary: check the following sites: http://www.securityfocus.com/bid, http://cve.mitre.org/index.html, https://www.us-cert.gov/ for vulnerabilities and update your site as needed.   In practicality it means updating your WordPress site as the plugins are updated … Read more

Have You Been Hacked? How Do You Know?

The following news story highlights stolen Uber email accounts which are worth $1 on the dark net (the criminal bazaar on the Internet where criminals buy and sell their wares) http://www.nydailynews.com/news/national/stolen-uber-accounts-sale-1-dark-net-article-1.2167072 (Image from Nypost. {A user on AlphaBay is selling log in credentials for $1 and a user on ThinkingForward-another dark web marketplace-is selling them … Read more

GitHub DDoS Attack Meaning

https://status.github.com/messages The status messages from the weekend state the problems GitHub had. We discussed a feint DDoS attack last week on blogpost: http://oversitesentry.com/ddos-not-only-for-disruption/   There are cases of DDoS that PCI compliance asks you to place the risk in a low category: Risk  level: Severity is low for Denial-of-service attack, abnormal termination   So the low risks are … Read more