article thumbnail

Security Affairs newsletter Round 240

Security Affairs

Experts warn of spike in TCP DDoS reflection attacks targeting Amazon, SoftLayer and telco infrastructure. Microsoft Patch Tuesday updates fix CVE-2019-1429 flaw exploited in the wild. CVE-2019-3648 flaw in all McAfee AV allows DLL Hijacking. DDoS-for-Hire Services operator sentenced to 13 months in prison.

DDOS 51
article thumbnail

Orcus RAT Author Charged in Malware Scheme

Krebs on Security

That user pointed to a March 2019 media advisory released by the Australian Federal Police , who said they’d executed search warrants there as part of an investigation into RAT technology conducted in tandem with the RCMP. Canadian investigators don’t appear to be buying Revesz’ claims. .

Malware 201
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Security Affairs newsletter Round 210 – News of the week

Security Affairs

A new DDoS technique abuses HTML5 Hyperlink Audit Ping in massive attacks. Locked Shields 2019 – Chapeau, France wins Cyber Defence Exercise. CVE-2019-0803 Windows flaw exploited to deliver PowerShell Backdoor. Scranos – A Cross Platform, Rootkit-Enabled Spyware rapidly spreading. Code execution – Evernote.

article thumbnail

Security Affairs newsletter Round 237

Security Affairs

Swedish Government grants police the use of spyware against violent crime suspects. DDoS Attack on Amazon Web Services caused intermittently outage. CVE-2019-11043 exposes Web servers using nginx and PHP-FPM to hack. Robots at HIS Group are vulnerable to hack. FBI and DHS CISA issue alerts on e-skimming attacks.

Spyware 41
article thumbnail

Canadian Police Raid ‘Orcus RAT’ Author

Krebs on Security

31, 2019, Rezvesz said his company recently was the subject of an international search warrant executed jointly by the Royal Canadian Mounted Police (RCMP) and the Canadian Radio-television and Telecommunications Commission (CRTC). In an “official press release” posted to pastebin.com on Mar. 2017 analysis of the RAT.

article thumbnail

Spam and phishing in 2020

SecureList

In most cases, scammers, as before, claimed to have used spyware to film the blackmail victim watching adult videos. A company was told to transfer a certain amount to a Bitcoin wallet to prevent a DDoS attack that the cybercriminals threatened to unleash upon it. Interestingly, the cybercriminals did not limit their threats to DDoS.

Phishing 140
article thumbnail

Cyber Threats to the FIFA World Cup Qatar 2022

Digital Shadows

Threat actors can develop fake mobile apps to install adware, steal PII and financial data, extract cookies and credentials, and download further payloads (such as spyware) from a remote-controlled domain. In 2019, the FBI dubbed this tactic as the “ $26 Billion scam ”, given the high losses associated with this social engineering method.