Tag Archive for: detected

Massive Equifax hack reportedly started 4 months before it was detected

Enlarge / A monitor displays Equifax Inc. signage on the floor of the New York Stock Exchange (NYSE) in New York, US, on Friday, Sept. 15, 2017. (credit: Michael Nagle/Bloomberg via Getty Images)

Hackers behind the massive Equifax data breach began their attack no later than early March, more than four months before company officials discovered the intrusion, according to a report published Wednesday by the Wall Street Journal.

The first evidence of the hackers’ “interaction” with the Equifax network occurred on March 10, according to the report, which cited a confidential note that security firm FireEye sent to some Equifax customers. By then, a critical vulnerability in the Apache Struts Web application framework was already under active exploit on the Internet. Equifax officials have said the Struts flaw was the opening that gave attackers an initial hold in the targeted network.

Equifax has said that the breach that exposed sensitive data for as many as 143 million US consumers started on May 13 and lasted until July 30. The company didn’t disclose the breach until September 7.

Read 3 remaining paragraphs | Comments

Biz & IT – Ars Technica

Quick Heal detected millions of malware samples on Windows and on Android platform in Q1 2017 – PCQuest


PCQuest

Quick Heal detected millions of malware samples on Windows and on Android platform in Q1 2017
PCQuest
Third-party app stores were found to be the most common source of malware in the top 10 Android malware list. Q1 2017 registered a massive growth of 200% of Android ransomware as compared to Q1 2016. It was observed that the growth of Android …

android ransomware – read more

Rombertik malware destroys computers if detected

A new type of malware resorts to crippling a computer if it is detected during security checks, a particularly catastrophic blow to its victims.

The malware, nicknamed Rombertik by Cisco Systems, is designed to intercept any plain text entered into a browser window. It is being spread through spam and phishing messages, according to Cisco’s Talos Group blog on Monday.

Rombertik goes through several checks once it is up and running on a Windows computer to see if it has been detected.

That behavior is not unusual for some types of malware, but Rombertik “is unique in that it actively attempts to destroy the computer if it detects certain attributes associated with malware analysis,” wrote Ben Baker and Alex Chiu of the Talos Group.

To read this article in full or to leave a comment, please click here

Network World Security

Report: 31 percent of detected threats in 2014 attributed to Conficker – SC Magazine


SC Magazine

Report: 31 percent of detected threats in 2014 attributed to Conficker
SC Magazine
“If you take his botnet away in the future, and he builds up another botnet with Cryptolocker embedded, he could tell his botnet to self-destruct if they haven't connected to their home in a week,” Sullivan said. “Then, they could encrypt everything

and more »

android botnet – read more