Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Holy Teamviewer Batman

Holy crap this is a big and devastating attack. This is definitely escalating things. 

https://www.bleepingcomputer.com/news/security/teamviewers-corporate-network-was-breached-in-alleged-apt-hack/

If it does turn out to be apt-29, then this is a brilliant attack on their part because it would give them potential access to just about any environment that they could want to investigate.  

However on second thought I think that the group is more interested in the source code to TeamViewer so that they can find their own vulnerabilities that they keep to themselves.

This is going to greatly escalate the stakes in the security world for all vendors. I can see a lot of vendor Management Programs becoming a lot healthier all of a sudden, for those that can understand the trend.
https://www.nytimes.com/2019/05/06/us/politics/china-hacking-cyber.html
https://www.symantec.com/blogs/threat-intelligence/buckeye-windows-zero-day-exploit


Windows zero day was exploited by Buckeye alongside Equation Group tools during 2016 attacks. Exploit and tools continued to be used after Buckeye's apparent disappearance in 2017.

Key Findings

  • The Buckeye attack group was using Equation Group tools to gain persistent access to target organizations at least a year prior to the Shadow Brokers leak.
  • Variants of Equation Group tools used by Buckeye appear to be different from those
    released by Shadow Brokers, potentially indicating that they didn't originate from that leak.
  • Buckeye's use of Equation Group tools also involved the exploit of a previously unknown Windows zero-day vulnerability. This zero day was reported by Symantec to Microsoft in September 2018 and patched in March 2019.
  • While Buckeye appeared to cease operations in mid-2017, the Equation Group tools it used continued to be used in attacks until late 2018. It is unknown who continued to use the tools. They may have been passed to another group or Buckeye may have continued operating longer than supposed.

Timehop has a turn now

Timehop Hacked — Hackers Stole Personal Data Of All 21 Million Users. This awesome probably includes the login details for all of these social media apps. Considering that those are now used to login to other sites, this breach is going to be bigger than first reported.

https://thehackernews.com/2018/07/timehop-data-breach.html

My Heritage breach

92 Million User Accounts Compromised in MyHeritage Security Breach https://securityzap.com/myheritage-security-breach/

The IoT strikes

http://www.businessinsider.de/hackers-stole-a-casinos-database-through-a-thermometer-in-the-lobby-fish-tank-2018-4?r=UK&IR=T

More on SEC breach

Here's The Latest About What The SEC Hackers Stole, but not a whole lot really

https://packetstormsecurity.com/news/view/28207/Heres-The-Latest-About-What-The-SEC-Hackers-Stole.html

Qatar state news agency hacked

http://www.securityweek.com/qatar-begins-probe-after-state-news-agency-hacked

GameStop breach

GameStop Confirms Possible Breach Of Customer Credit Card Info https://packetstormsecurity.com/news/view/27657/GameStop-Confirms-Possible-Breach-Of-Customer-Credit-Card-Info.html

ASLR flaw

A Chip Flaw Strips Away a Key Hacking Safeguard for Millions of Devices | WIRED https://www.wired.com/2017/02/flaw-millions-chips-strips-away-key-hacking-defense-software-cant-fully-fix/

CIA Evidence of hacking kept secret

nice little pragmatic article, IMO

Why the CIA won’t want to go public with evidence of Russia’s hacking

https://www.washingtonpost.com/posteverything/wp/2016/12/27/why-its-so-hard-to-prove-russia-was-behind-the-election-hacks/

Navy hacked through HP

http://mobile.reuters.com/article/idUSKBN13J001

Third party supplier strikes again. My guess is the was no FDE on the laptop.

New hacker bounty

Army Bug Bounty Building New Relationships with Hackers https://threatpost.com/army-bug-bounty-building-new-relationships-with-hackers/121924/

not so new way to keylog

https://www.cyberpointllc.com/srt/posts/srt-logging-keystrokes-with-event-tracing-for-windows-etw.html

New mega-breach

http://thehackernews.com/2016/09/plaintext-passwords-leaked.html

More Practice Sites

https://hackerlists.com/hacking-sites/


to safely practice hacking.

New data exfiltration method

Clever Attack Uses the Sound of a Computer’s Fan to Steal Data

https://www.wired.com/2016/06/clever-attack-uses-sound-computers-fan-steal-data/

Tactical Exploitation

was a nice quick read.
Good to refer to every once and a while.

https://www.defcon.org/images/defcon-15/dc15-presentations/Moore_and_Valsmith/Whitepaper/dc-15-moore_and_valsmith-WP.pdf