Tag Archive for: Dozens

Critical bugs in dozens of Zyxel and Lilin IoT models under active exploit

The word

Enlarge (credit: Frank Lindecke / Flickr)

Criminals are exploiting critical flaws to corral Internet-of-things devices from two different manufacturers into botnets that wage distributed denial-of-service attacks, researchers said this week. Both DVRs from Lilin and storage devices from Zyxel are affected, and users should install updates as soon as possible.

Multiple attack groups are exploiting the Lilin DVR vulnerability to conscript them into DDoS botnets known as FBot, Chalubo, and Moobot, researchers from security firm Qihoo 360 said on Friday. The latter two botnets are spinoffs of Mirai, the botnet that used hundreds of thousand of IoT devices to bombard sites with record-setting amounts of junk traffic.

The DVR vulnerability stems from three flaws that allow attackers to remotely inject malicious commands into the device. The bugs are: (1) hard-coded login credentials present in the device, (2) command-injection flaws, and (3) arbitrary file reading weaknesses. The injected parameters affect the device capabilities for file transfer protocol, network time protocol, and the update mechanism for network time protocol.

Read 4 remaining paragraphs | Comments

Biz & IT – Ars Technica

Millions downloaded dozens of Android apps from Google Play that were infected with adware – TechCrunch

  1. Millions downloaded dozens of Android apps from Google Play that were infected with adware  TechCrunch
  2. New Google Android Malware Warning Issued To 8 Million Play Store Users  Forbes
  3. Tracking down the developer of Android adware affecting millions of users  We Live Security
  4. Malicious Android Apps Hide Ads From Google Employees  BleepingComputer
  5. Vietnamese student behind Android adware strain that infected millions  ZDNet
  6. View full coverage on read more

“android security news” – read more

Dozens of Lawyers Vie to Lead Data Breach Case Against Marriott – Law.com

Dozens of Lawyers Vie to Lead Data Breach Case Against Marriott  Law.com

The fight over who will lead class actions brought over Marriott’s data breach began Friday, when dozens of lawyers submitted applications for leadership …

“data breach” – read more