Tag Archive for: Service

US Dismantles IPStorm Botnet Proxy Service


The US authorities have shut down a major botnet comprising tens of thousands of infected endpoints, which cyber-criminals hired to launch various attacks anonymously.

The IPStorm botnet and its infrastructure were dismantled earlier this year, according to the Department of Justice (DoJ).

Its alleged administrator, Russian and Moldovan national Sergei Makinin, pleaded guilty back in September to three counts of fraud and related activity in connection with computers. Each count carries a maximum sentence of 10 years.

The botnet operated from June 2019 to December 2022, turning compromised Windows, Linux, Mac and Android devices from around the world into proxies. These could then be rented out by cyber-criminals through two of Makinin’s websites: proxx.io and proxx.net.

Read more on proxies: FBI: Beware Residential IPs Hiding Credential Stuffing

The proxies enabled threat actors to bypass security filters and anonymize their traffic as they launched various cyber-attacks on victims. According to the DoJ, a single customer could pay hundreds of dollars a month to route their traffic through the botnet.

Makinin is said to have run around 23,000 such proxies as part of the botnet and admitted making at least $550,000 from the scheme.

“It is no secret that in present times, much criminal activity is conducted or enabled through cybernetic means. Cyber-criminals seek to remain anonymous and derive a sense of security because they hide behind keyboards, often thousands of miles away from their victims,” said Joseph González, special agent in charge of the FBI’s San Juan Field Office.

“The FBI’s cyber mission has been to impose risk and consequences on our adversaries, ensuring cyberspace is no safe space for criminal activity. This case is one example of how we are doing just that.”

The FBI urged device owners to keep up to date with the latest security and software patches to mitigate the risk of their machines becoming compromised and conscripted into such a botnet.

Source…

Malware deployed by Android security evading SecuriDropper service


Stealthier Jupyter infostealer discovered Attacks leveraging a new version of the Jupyter information-stealing malware, also known as Yellow Cockatoo, SolarMarker, and Polazert, with increased stealth capabilities have emerged, according to The Hacker News.

Source…

Kyndryl Introduces Experience Management as a Service to Help Customers Monitor, Measure and Achieve Business Outcomes IT Voice








Kyndryl Introduces Experience Management as a Service to Help Customers Monitor, Measure and Achieve Business Outcomes IT Voice | IT in Depth

















































Go toTop









Source…

What’s Holding Managed Security Service Providers Back?


As CEO of Logpoint, Jesper is an expert on business and cybersecurity innovation.

Managed security service providers (MSSPs) enable organizations to outsource their security operations cost-effectively. Rather than devoting spend to building and maintaining an in-house security operations center (SOC), organizations can obtain such services from the MSSP and benefit from their scalability and expertise.

However, to obtain their business, MSSPs must compete effectively by delivering real-time managed detection and response SOC services. All indications are that they are currently struggling to do that.

We conducted a survey of MSSPs and found that 65% thought their SOC operations might be losing time due to inefficient processes, creating an increased risk to their customers through slower incident response times. Some SOCs were not integrated with other technologies, for instance, and only 25% were using automated playbooks or procedures for alert response—meaning the vast majority were manually reviewing their system alerts.

Consequently, over half (57%) said the gap between mean time to detect (MTTD) and mean time to respond (MTTR) was below expectations. It’s a gap being widened by SOC operations failing to automatically feed threat intelligence to security solutions such as endpoint detection and response (EDR), firewalls and user management—delaying detection and response further. Moreover, a third of those questioned (35%) said they did not have the best processes or tools for building detection patterns, preventing them from identifying emerging threats.

Forward-Thinking

There is a clear understanding of where MSSPs are today versus where they want to be, with most stating they intend to create new services over the next 12 to 24 months—including EDR, network detection and response (NDR), managed computer security incident response team (CSIRT), security orchestration and response (SOAR), managed detection and response (MDR), and SOC for small and medium-sized businesses. In order to roll out such services, MSSPs need to reassess their business processes now and explore how they can implement automation and orchestration.

Automation sees technology used…

Source…