Showing posts with label Misc. Show all posts
Showing posts with label Misc. Show all posts

Friday, April 3, 2015

Yesterday's Activity

We are testing out some new products. We thought we would share what we are seeing in our platforms.


Thursday, March 26, 2015

Under Attack - This Pattern Looks Familiar

Just like in previous disclosures that we have provided information within a few hours we end up coming under attack and just like the last time we say please by all means hit us so we can map out your networks and infected host...

This is a lesson in how to map out a botnet in real time. Thanks guys!

Wednesday, March 25, 2015

Following the News - Intelligence Agency's Lacking Actionable Data

It goes without saying that the number of terrorist events over the past 2 weeks is quite alarming and as of the last 2 months the activity worldwide has increased. The number of attacks outside of traditional unstable areas has risen as well as the Iran and Israel debacle has some intelligence analyst shaking their heads.

With the revelation that the pilot of the Germanwings crash was locked out of the cockpit, US terror attack of TSA agents and many other incidents not being covered in the mainstream media we have to take note. In addition a constant barrage of hacking from China's "PANDA" crew, Iran hashing deals with long reaching effects in the middle east and many areas of instability. Things are about to get interesting.

The recent revelation that the US is supporting Iranian fighters in the region with air strikes things lately have seemed to be turned on their heads. What's next? We can tell you that we have picked up additional activity with some well financed groups in the middle east, messages hidden in images (stenography) with cryptic messages from the middle east and plenty more items that just cause us to wonder what is really going on out there.

Keep your eyes and ears open folks. Things are changing quicker than intelligence agency's can keep up and private entities are also struggling to keep up with changing conditions to keep our travelers and employees safe.

There are many types of terror related activities to be aware of in addition to the theft of your corporate secrets and we will be expanding the scope of intelligence that we post in the coming weeks. No longer will we simply focus on data leaks (although we will continue to provide the information we have been providing). There comes a time when information needs to be put out there so that business leaders and enterprises can maintain situational awareness and security of personnel and assets. While there are many organizations out there that claim to provide these types of service and Government bulletins and advisories come out often time this information is released to the public well after the fact so our goal is to get you actionable intelligence before it's too late.

We thank you all for your continued support. We recommend that if you read out blog frequently and find the information useful that you subscribe to our alerts mailing list. We will only mail you once a day or when critical information needs to be put out in a timely fashion and we include much more granular details in our mailing list that may assist you in making smarter and safer business decisions in an effective manner.

NC REN - North Carolina Research and Eduation Network - Public Proxy

Why on earth would NC REN be running a publicly accessible proxy server on their networks? This would definitely indicate either a misconfiguration or an attempt to research what Internet users would do with such a system.

Interesting to say the least...

SOURCE:
Information was researched by Maxmind as part of this statement.

Wednesday, February 11, 2015

Obama Launches Cyberthreat Intel-Sharing Center

Long-awaited central repository for cyber threat information and intelligence created by The White House.

The concept of a federal government-led center for coordinating cyberthreat intelligence has been discussed by the Obama administration for some time, and that concept became a reality yesterday when the White House announced the formation of the Cyber Threat Intelligence Integration Center (CTIIC).

That's all fine and dandy but how do we integrate with this initiative? The last Google search we did showed NOTHING!

Monday, February 2, 2015

University of Chicago Still Leaking Information and Vulnerable

During a recent review of some incidents being covered by databreaches.net I was able to do some additional research and confirm that even as recent as an hour ago that information is still being offered in the underground community. In addition server IP addresses owned by the organization are attacking other colleges and universities in the US and elsewhere.

In Addition:
The following organizations are also compromised.

Illinois Institute of Technology
Northwestern University