After AlphaBay’s Demise, Customers Flocked to Dark Market Run by Dutch Police

Credit to Author: BrianKrebs| Date: Thu, 20 Jul 2017 16:23:23 +0000

Earlier this month, news broke that authorities had seized the Dark Web marketplace AlphaBay, an online black market that peddled everything from heroin to stolen identity and credit card data. But it wasn’t until today, when the U.S. Justice Department held a press conference to detail the AlphaBay takedown that the other shoe dropped: Police in The Netherlands for the past month have been operating Hansa Market, a competing Dark Web bazaar that enjoyed a massive influx of new customers immediately after the AlphaBay takedown.

Read more

Trump Hotels Hit By 3rd Card Breach in 2 Years

Credit to Author: BrianKrebs| Date: Wed, 19 Jul 2017 15:43:36 +0000

Maybe some of you missed this amid all the breach news recently (I know I did), but Trump International Hotels Management LLC last week announced its third credit-card data breach in the past two years. I thought it might be useful to see these events plotted on a timeline, because it suggests that virtually anyone who used a credit card at a Trump property in the past two years likely has had their card data stolen and put on sale in the cybercrime underground as a result.

Read more

Experts in Lather Over ‘gSOAP’ Security Flaw

Credit to Author: BrianKrebs| Date: Tue, 18 Jul 2017 14:30:11 +0000

Axis Communications — a maker of high-end security cameras whose devices can be found in many high-security areas — recently patched a dangerous coding flaw in virtually all of its products that an attacker could use to remotely seize control over or crash the devices. The problem wasn’t specific to Axis, which seems to have reacted far more quickly than competitors to quash the bug. Rather, the vulnerability resides in open-source, third-party computer code that has been used in countless products and technologies (including a great many security cameras), meaning it may be some time before most vulnerable vendors ship out a fix — and even longer before users install it.

Read more

Porn Spam Botnet Has Evil Twitter Twin

Credit to Author: BrianKrebs| Date: Sun, 16 Jul 2017 12:11:35 +0000

Last month KrebsOnSecurity published research into a large distributed network of apparently compromised systems being used to relay huge blasts of junk email promoting “online dating” programs — affiliate-driven schemes traditionally overrun with automated accounts posing as women. New research suggests that another bot-promoting botnet of more than 80,000 automated female Twitter accounts has been pimping the same dating scheme and ginning up millions of clicks from Twitter users in the process.

Read more

Thieves Used Infrared to Pull Data from ATM ‘Insert Skimmers’

Credit to Author: BrianKrebs| Date: Thu, 13 Jul 2017 15:28:08 +0000

A greater number of ATM skimming incidents now involve so-called “insert skimmers,” wafer-thin fraud devices made to fit snugly and invisibly inside a cash machine’s card acceptance slot. New evidence suggests that at least some of these insert skimmers — which record card data and store it on a tiny embedded flash drive are — equipped with technology allowing it to transmit stolen card data wirelessly via infrared, the same technology built into a television remote control.

Read more

Self-Service Food Kiosk Vendor Avanti Hacked

Credit to Author: BrianKrebs| Date: Sat, 08 Jul 2017 15:09:48 +0000

Avanti Markets, a company whose self-service payment kiosks sit beside shelves of snacks and drinks in thousands of corporate breakrooms across America, has suffered of breach of its internal networks in which hackers were able to push malicious software out to those payment devices, the company has acknowledged. The breach may have jeopardized customer credit card accounts as well as biometric data, Avanti warned.

Read more

B&B Theatres Hit in 2-Year Credit Card Breach

Credit to Author: BrianKrebs| Date: Fri, 07 Jul 2017 15:26:07 +0000

B&B Theatres, a company that owns and operates the 7th-largest theater chain in America, says it is investigating a breach of its credit card systems. The acknowledgment comes just days after KrebsOnSecurity reached out to the company for comment on reports from financial industry sources who said they suspected the cinema chain has been leaking customer credit card data to cyber thieves for the past two years.

Read more

Who is the GovRAT Author and Mirai Botmaster ‘Bestbuy’?

Credit to Author: BrianKrebs| Date: Wed, 05 Jul 2017 11:25:14 +0000

In February 2017, authorities in the United Kingdom arrested a 29-year-old U.K. man on suspicion of knocking more than 900,000 Germans offline in an attack tied to Mirai, a malware strain that enslaves Internet of Things (IoT) devices like security cameras and Internet routers for use in large-scale cyberattacks. Investigators haven’t yet released the man’s name, but news reports suggest he may be better known by the hacker handle “Bestbuy.” This post will follow a trail of clues back to one likely real-life identity of Bestbuy.

Read more