Jeffrey Burt, Author at Security Boulevard https://securityboulevard.com/author/jeffrey-burt/ The Home of the Security Bloggers Network Mon, 26 Aug 2024 03:37:12 +0000 en-US hourly 1 https://wordpress.org/?v=6.6.1 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png Jeffrey Burt, Author at Security Boulevard https://securityboulevard.com/author/jeffrey-burt/ 32 32 133346385 Event Logging Key to Detecting LOTL Attacks, Security Agencies Say https://securityboulevard.com/2024/08/event-logging-key-to-detecting-lotl-attacks-security-agencies-say/ Mon, 26 Aug 2024 03:37:12 +0000 https://securityboulevard.com/?p=2028835 event logging, CISA, living off the land

A report by CISA, the FBI, the NSA, and international agencies lay out the argument that event logging tools help enterprises better detect attacks that rely on LOTL techniques used by threat groups to evade security protections during an attack.

The post Event Logging Key to Detecting LOTL Attacks, Security Agencies Say appeared first on Security Boulevard.

]]>
2028835
Audit: FBI is Losing Track of Storage Devices Holding Sensitive Data https://securityboulevard.com/2024/08/audit-fbi-is-losing-track-of-storage-devices-holding-sensitive-data/ Fri, 23 Aug 2024 19:58:52 +0000 https://securityboulevard.com/?p=2028784 FBI data storage devices

DOJ inspectors have found the FBI is not labeling hard drives and other storage devices holding sensitive that are slated for destruction, making them hard to track, and that boxes of them can sit in a poorly secured facility for months.

The post Audit: FBI is Losing Track of Storage Devices Holding Sensitive Data appeared first on Security Boulevard.

]]>
2028784
Backdoor in RFID Cards for Offices, Hotels Can Lead to Instant Cloning https://securityboulevard.com/2024/08/backdoor-in-rfid-cards-for-offices-hotels-can-lead-to-instant-cloning/ Wed, 21 Aug 2024 18:47:52 +0000 https://securityboulevard.com/?p=2028500 backdoor RFID contactless card

A backdoor found in millions of Chinese-made RFID cards that are used by hotels and other businesses around the world can let bad actors instantly clone the cards to gain unauthorized access into rooms or run supply chain attacks, say researchers with Paris-based Quarkslab.

The post Backdoor in RFID Cards for Offices, Hotels Can Lead to Instant Cloning appeared first on Security Boulevard.

]]>
2028500
Extortion Group Exploits Cloud Misconfigurations, Targets 110,000 Domains https://securityboulevard.com/2024/08/extortion-group-exploits-cloud-misconfigurations-targets-110000-domains/ Mon, 19 Aug 2024 18:30:39 +0000 https://securityboulevard.com/?p=2028114 cloud security, extortion, Palo Alto, AWS

An unknown threat group leveraged publicly exposed environment variables in organizations' AWS accounts to exfiltrate sensitive data and demand ransoms in a wide-ranging extortion campaign that targeted 110,000 domains.

The post Extortion Group Exploits Cloud Misconfigurations, Targets 110,000 Domains appeared first on Security Boulevard.

]]>
2028114
Mandatory MFA is Coming to Microsoft Azure https://securityboulevard.com/2024/08/mandatory-mfa-is-coming-to-microsoft-azure/ Mon, 19 Aug 2024 14:38:21 +0000 https://securityboulevard.com/?p=2028096 Microsoft Google 2FA MFA Azure

Microsoft is making MFA mandatory for signing into Azure accounts, the latest step in the IT vendor's Secure Future Initiative that it expanded in May in the wake of two embarrassing breaches by Russian and Chinese threat groups.

The post Mandatory MFA is Coming to Microsoft Azure appeared first on Security Boulevard.

]]>
2028096
Lawmakers Ask for Probe of Chinese Router Maker TP-Link https://securityboulevard.com/2024/08/lawmakers-ask-for-probe-of-chinese-router-maker-tp-link/ Fri, 16 Aug 2024 18:04:34 +0000 https://securityboulevard.com/?p=2028009 China, threats, scams, CISA TP-Link Volt Typhoon

Two U.S. lawmakers are asking the Commerce Department to investigate whether the Wi-Fi routers built by Chinese company TP-Link could be used by Chinese-sponsored threat groups to infiltrate U.S. government and private networks, posing a security risk to the country.

The post Lawmakers Ask for Probe of Chinese Router Maker TP-Link appeared first on Security Boulevard.

]]>
2028009
ReliaQuest: Watch Out for Info-Stealers and RATs https://securityboulevard.com/2024/08/reliaquest-watch-out-for-info-stealers-and-rats/ Thu, 15 Aug 2024 17:53:41 +0000 https://securityboulevard.com/?p=2027880 infostealer RATs Reliaquest

ReliaQuest ranked LummaC2 and SocGholish among the top malware seen in Q2 and rounded out the top five list with AsyncRat, Oyster, and the growing numbers of info-stealers that were built using the Rust programming language.

The post ReliaQuest: Watch Out for Info-Stealers and RATs appeared first on Security Boulevard.

]]>
2027880
Google: Iranian Group APT42 Behind Trump, Biden Hack Attempts https://securityboulevard.com/2024/08/google-iranian-group-apt42-behind-trump-biden-hack-attempts/ Thu, 15 Aug 2024 12:59:45 +0000 https://securityboulevard.com/?p=2027787 U.S. Election Meddling Iran Biden Trump

Google cybersecurity researchers confirm that the Iranian-sponsored APT42 threat group is being ongoing phishing campaigns against President Biden, Vice President Harris, and ex-President Trump in an attempt to influence the upcoming presidential elections.

The post Google: Iranian Group APT42 Behind Trump, Biden Hack Attempts appeared first on Security Boulevard.

]]>
2027787
FBI Disrupts Operations of the Dispossessor Ransomware Group https://securityboulevard.com/2024/08/fbi-disrupts-operations-of-the-dispossessor-ransomware-group/ Tue, 13 Aug 2024 20:07:26 +0000 https://securityboulevard.com/?p=2027535 ransomware Dispossessor takedown

The FBI and law enforcement agencies from the UK and Germany seized servers and domains belonging to the Dispossessor ransomware gang, which had emerged into the spotlight following a similar operation against the notorious LockBit gang in February.

The post FBI Disrupts Operations of the Dispossessor Ransomware Group appeared first on Security Boulevard.

]]>
2027535
Biden-Harris Campaign, Trump Operative Stone Also Target of Hackers https://securityboulevard.com/2024/08/biden-harris-campaign-trump-operative-stone-also-target-of-hackers/ Tue, 13 Aug 2024 16:52:48 +0000 https://securityboulevard.com/?p=2027506 Iran Trump Biden Harris campaign hack cybersecurity

Hackers, possibly from Iran, sent phishing emails to the Biden-Harris campaign and Trump operative Roger Stone hoping to gain access into the systems of both presidential campaigns. It worked with Stone, who compromised email account opened the door to the Trump campaign infrastructure.

The post Biden-Harris Campaign, Trump Operative Stone Also Target of Hackers appeared first on Security Boulevard.

]]>
2027506