Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 1 / 3
52 résultats taggé krebsonsecurity  ✕
KrebsOnSecurity Hit With Near-Record 6.3 Tbps DDoS – https://krebsonsecurity.com/2025/05/krebsonsecurity-hit-with-near-record-6-3-tbps-ddos/
21/05/2025 08:31:22
QRCode
archive.org

KrebsOnSecurity last week was hit by a near record distributed denial-of-service (DDoS) attack that clocked in at more than 6.3 terabits of data per second (a terabit is one trillion bits of data). The brief attack appears to have been…
For reference, the 6.3 Tbps attack last week was ten times the size of the assault launched against this site in 2016 by the Mirai IoT botnet, which held KrebsOnSecurity offline for nearly four days. The 2016 assault was so large that Akamai – which was providing pro-bono DDoS protection for KrebsOnSecurity at the time — asked me to leave their service because the attack was causing problems for their paying customers.

Since the Mirai attack, KrebsOnSecurity.com has been behind the protection of Project Shield, a free DDoS defense service that Google provides to websites offering news, human rights, and election-related content. Google Security Engineer Damian Menscher told KrebsOnSecurity the May 12 attack was the largest Google has ever handled. In terms of sheer size, it is second only to a very similar attack that Cloudflare mitigated and wrote about in April.

After comparing notes with Cloudflare, Menscher said the botnet that launched both attacks bears the fingerprints of Aisuru, a digital siege machine that first surfaced less than a year ago. Menscher said the attack on KrebsOnSecurity lasted less than a minute, hurling large UDP data packets at random ports at a rate of approximately 585 million data packets per second.

“It was the type of attack normally designed to overwhelm network links,” Menscher said, referring to the throughput connections between and among various Internet service providers (ISPs). “For most companies, this size of attack would kill them.”

krebsonsecurity EN 2025 Hit DDoS Mirai Cloudflare Aisuru botnet
Funding Expires for Key Cyber Vulnerability Database https://krebsonsecurity.com/2025/04/funding-expires-for-key-cyber-vulnerability-database/
16/04/2025 09:09:25
QRCode
archive.org

A critical resource that cybersecurity professionals worldwide rely on to identify, mitigate and fix security vulnerabilities in software and hardware is in danger of breaking down. The federally funded, non-profit research and development organization MITRE warned today that its contract…

krebsonsecurity EN 2025 Vulnerability Database MITRE CVE CWE non-profit expired
Microsoft Patch Tuesday, February 2025 Edition https://krebsonsecurity.com/2025/02/microsoft-patch-tuesday-february-2025-edition/
12/02/2025 08:56:33
QRCode
archive.org

Microsoft today issued security updates to fix at least 56 vulnerabilities in its Windows operating systems and supported software, including two zero-day flaws that are being actively exploited.

krebsonsecurity EN 2025 PatchTuesday
MasterCard DNS Error Went Unnoticed for Years https://krebsonsecurity.com/2025/01/mastercard-dns-error-went-unnoticed-for-years/
22/01/2025 22:39:48
QRCode
archive.org

The payment card giant MasterCard just fixed a glaring error in its domain name server settings that could have allowed anyone to intercept or divert Internet traffic for the company by registering an unused domain name. The misconfiguration persisted for…

krebsonsecurity EN 2025 MasterCard DNS Error Misconfiguration DNS
U.S. Army Soldier Arrested in AT&T, Verizon Extortions – Krebs on Security https://krebsonsecurity.com/2024/12/u-s-army-soldier-arrested-in-att-verizon-extortions/
01/01/2025 22:23:33
QRCode
archive.org

Federal authorities have arrested and indicted a 20-year-old U.S. Army soldier on suspicion of being Kiberphant0m, a cybercriminal who has been selling and leaking sensitive customer call records stolen earlier this year from AT&T and Verizon. As first reported by…

krebsonsecurity EN 2024 U.S. Army Soldier busted arrested Verizon Extortions AT&T
How to Lose a Fortune with Just One Bad Click https://krebsonsecurity.com/2024/12/how-to-lose-a-fortune-with-just-one-bad-click/
19/12/2024 16:26:57
QRCode
archive.org

Adam Griffin is still in disbelief over how quickly he was robbed of nearly $500,000 in cryptocurrencies. A scammer called using a real Google phone number to warn his Gmail account was being hacked, sent email security alerts directly from…

krebsonsecurity EN 2024 robbed clicked fake google gnail crypto alerts
Why Phishers Love New TLDs Like .shop, .top and .xyz https://krebsonsecurity.com/2024/12/why-phishers-love-new-tlds-like-shop-top-and-xyz/
09/12/2024 13:54:53
QRCode
archive.org

Phishing attacks increased nearly 40 percent in the year ending August 2024, with much of that growth concentrated at a small number of new generic top-level domains (gTLDs) -- such as .shop, .top, .xyz -- that attract scammers with rock-bottom…

krebsonsecurity EN 2024 TLDs Phishing scammers
Fintech Giant Finastra Investigating Data Breach https://krebsonsecurity.com/2024/11/fintech-giant-finastra-investigating-data-breach/
24/11/2024 09:59:10
QRCode
archive.org

The financial technology firm Finastra is investigating the alleged large-scale theft of information from its internal file transfer platform, KrebsOnSecurity has learned. Finastra, which provides software and services to 45 of the world’s top 50 banks, notified customers of the security incident after a cybercriminal began selling more than 400 gigabytes of data purportedly stolen from the company.

krebsonsecurity 2024 EN Fintech Finastra Data-Breach
Feds Charge Five Men in ‘Scattered Spider’ Roundup – Krebs on Security https://krebsonsecurity.com/2024/11/feds-charge-five-men-in-scattered-spider-roundup/
22/11/2024 14:20:50
QRCode
archive.org

Federal prosecutors in Los Angeles this week unsealed criminal charges against five men alleged to be members of a hacking group responsible for dozens of cyber intrusions at major U.S. technology companies between 2021 and 2023, including LastPass, MailChimp, Okta,…

krebsonsecurity EN 2024 Scattered-Spider busted
Booking.com Phishers May Leave You With Reservations https://krebsonsecurity.com/2024/11/booking-com-phishers-may-leave-you-with-reservations/
11/11/2024 11:34:16
QRCode
archive.org

A number of cybercriminal innovations are making it easier for scammers to cash in on your upcoming travel plans. This story examines a recent spear-phishing campaign that ensued when a California hotel had its booking.com credentials stolen. We'll also explore…

krebsonsecurity EN 2024 Booking.com Phishers Reservations scam
The Global Surveillance Free-for-All in Mobile Ad Data – Krebs on Security https://krebsonsecurity.com/2024/10/the-global-surveillance-free-for-all-in-mobile-ad-data/
25/10/2024 09:11:35
QRCode
archive.org

Not long ago, the ability to remotely track someone’s daily movements just by knowing their home address, employer, or place of worship was considered a powerful surveillance tool that should only be in the purview of nation states. But a…

krebsonsecurity EN 2024 Global Surveillance Free-for-All BabelStreet Venntel
A Single Cloud Compromise Can Feed an Army of AI Sex Bots https://krebsonsecurity.com/2024/10/a-single-cloud-compromise-can-feed-an-army-of-ai-sex-bots/
06/10/2024 23:26:24
QRCode
archive.org

Organizations that get relieved of credentials to their cloud environments can quickly find themselves part of a disturbing new trend: Cybercriminals using stolen cloud credentials to operate and resell sexualized AI-powered chat services. Researchers say these illicit chat bots, which…

krebsonsecurity EN 2024 Cloud Compromise credentials Cybercriminals AI-powered chat services
U.S. Indicts 2 Top Russian Hackers, Sanctions Cryptex https://krebsonsecurity.com/2024/09/u-s-indicts-2-top-russian-hackers-sanctions-cryptex/
29/09/2024 19:01:56
QRCode
archive.org

The United States today unveiled sanctions and indictments against the alleged proprietor of Joker's Stash, a now-defunct cybercrime store that peddled tens of millions of payment cards stolen in some of the largest data breaches of the past decade. The…

krebsonsecurity EN 2024 UK Joker-Stash cybercrime Taleon cryptex busted
Sextortion Scams Now Include Photos of Your Home https://krebsonsecurity.com/2024/09/sextortion-scams-now-include-photos-of-your-home/
07/09/2024 11:55:39
QRCode
archive.org

An old but persistent email scam known as "sextortion" has a new personalized touch: The missives, which claim that malware has captured webcam footage of recipients pleasuring themselves, now include a photo of the target's home in a bid to make…

krebsonsecurity EN 2024 Sextortion Scams Photos home
Owners of 1-Time Passcode Theft Service Plead Guilty https://krebsonsecurity.com/2024/09/owners-of-1-time-passcode-theft-service-plead-guilty/
03/09/2024 08:31:47
QRCode
archive.org

Three men in the United Kingdom have pleaded guilty to operating otp[.]agency, a once popular online service that helped attackers intercept the one-time passcodes (OTPs) that many websites require as a second authentication factor in addition to passwords. Launched in…

krebsonsecurity EN 2024 UK OTP Multi-Factor-Authentication One-time-Password OTP OTP.Agency MFA
New 0-Day Attacks Linked to China’s ‘Volt Typhoon’ https://krebsonsecurity.com/2024/08/new-0-day-attacks-linked-to-chinas-volt-typhoon/
27/08/2024 17:11:05
QRCode
archive.org

Malicious hackers are exploiting a zero-day vulnerability in Versa Director, a software product used by many Internet and IT service providers. Researchers believe the activity is linked to Volt Typhoon, a Chinese cyber espionage group focused on infiltrating critical U.S.…

krebsonsecurity EN 2024 Versa-Director zero-day vulnerability Volt-Typhoon
Don’t Let Your Domain Name Become a “Sitting Duck” https://krebsonsecurity.com/2024/07/dont-let-your-domain-name-become-a-sitting-duck/
03/08/2024 01:55:47
QRCode
archive.org

More than a million domain names -- including many registered by Fortune 100 firms and brand protection companies -- are vulnerable to takeover by cybercriminals thanks to authentication weaknesses at a number of large web hosting providers and domain registrars,…

krebsonsecurity EN 2024 abused DNS takeover weaknesses Duck domain
Crooks Bypassed Google’s Email Verification to Create Workspace Accounts, Access 3rd-Party Services https://krebsonsecurity.com/2024/07/crooks-bypassed-googles-email-verification-to-create-workspace-accounts-access-3rd-party-services/
29/07/2024 09:21:01
QRCode
archive.org

Google says it recently fixed an authentication weakness that allowed crooks to circumvent the email verification required to create a Google Workspace account, and leverage that to impersonate a domain holder at third-party services that allow logins through Google’s “Sign in with Google” feature.

krebsonsecurity EN 2024 Google authentication weakness Bypassed Workspace
‘Operation Endgame’ Hits Malware Delivery Platforms https://krebsonsecurity.com/2024/05/operation-endgame-hits-malware-delivery-platforms/
31/05/2024 09:17:02
QRCode
archive.org

Law enforcement agencies in the United States and Europe today announced Operation Endgame, a coordinated action against some of the most popular cybercrime platforms for delivering ransomware and data-stealing malware. Dubbed "the largest ever operation against botnets," the international effort…

krebsonsecurity EN 2024 Operation-Endgame
Stark Industries Solutions: An Iron Hammer in the Cloud https://krebsonsecurity.com/2024/05/stark-industries-solutions-an-iron-hammer-in-the-cloud/
24/05/2024 15:16:34
QRCode
archive.org

Two weeks before Russia invaded Ukraine in February 2022, a large, mysterious new Internet hosting firm called Stark Industries Solutions materialized and quickly became the epicenter of massive distributed denial-of-service (DDoS) attacks on government and commercial targets in Ukraine and…

krebsonsecurity EN 2024 Stark-Industries-Solutions
page 1 / 3
4366 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio