Category: Cybercrime

GNU Linux howto ssh sshd config hardening security guide
10.03.2024

ssh can be regarded as “critical core infrastructure” time spend on it’s security is time well spend time + money well invested: https://www.openssh.com https://github.com/openssh current manpage: ssh.man.txt WARNING: this howto guide IS MOST LIKELY INCOMPLETE! WARNING! WHEN RUNNING THE SCRIPT: […]

Fraud Betrug on (formals ebay) kleinanzeigen.de
19.10.2023

https://kleinanzeigen.de previously known as https://ebay-kleinanzeigen.de the most used second-hand platform in Germany was sold from ebay to an norwegian Investor Adevinta Also “ebay for cars” mobile.de was sold from ebay to Adevinta. “In June 2020, Adevinta won the bid to […]

the hardcore security challenge any app store faces
05.08.2023

No matter if docker repository called “hub”, Google’s App Store “PlayStore” or Apple’s App Store they are ALL facing the same security problems: https://www.bleepingcomputer.com/news/security/google-explains-how-android-malware-slips-onto-google-play-store/ plus: https://www.bleepingcomputer.com/news/security/thousands-of-android-apks-use-compression-trick-to-thwart-analysis/ what if… a malicious actor uploads an App or docker container that is totaly […]

2023-03 IT Cyber Security Updates – Unfixed Cisco routers, Google ads to distribute malware, Evil Dota 2 game mods, Reddit’s internal documents and source code stolen, Apple zero-day vulnerabilities, malware in images, stealthy malware, fileless malware, SIM-Swapping scammer, Street magic steals crypto, Gootkit malware is actively attacking medical and financial institutions, American Megatrends BMC vulnerabilities, publicly accessible QNAP NAS again at risk, worm via USB drives, first suggested attacks on quantum cryptography, hurray for the cloud: misconfigured cloud database leaked data on ALL Australien citizens (spell it “klaut” wich is German for “steal”), Hackers modify DNS settings to redirect victims to malicious via vulnerable WiFi routers
05.03.2023

(knowing that manually auto-translating Russian CyberSec news to English, is not a feasable concept and need to be automated, but as this blog is non-profit, it is for curiosity.) Booking.com found an authentication vulnerability that allows account hijacking A vulnerability […]

Rust vs Go – Open Source is about enabling users – Rust lang will complement C around the GNU Linux Kernel (for better safety) “Amazon, Microsoft, Google” and the White House, want to make Open Source more secure
16.05.2022

Open Source is about enabling users “Amazon, Microsoft, Google” and the White House, want to help make Open Source more secure… https://www.golem.de/news/openssf-150-millionen-us-dollar-sollen-open-source-absichern-2205-165382.html https://www.golem.de/news/openssf-linux-foundation-will-security-praxis-vereinheitlichen-2008-150036.html src of src: “White House OSS Mobilization Plan” 2022: https://openssf.org/blog/2022/05/11/testimony-to-the-us-house-committee-on-science-and-technology/ 2020: “The OpenSSF is a cross-industry collaboration […]

FreeBSD based Citrix VPN hacked in massive hostpital healthcare hack in Germany CVE 2019 19781 – hits healthcare hospital in Germany, causing death of (at least) 1 person
27.04.2022

https://cve.circl.lu/cve/CVE-2019-19781 https://www.healthcare-computing.de/bsi-warnt-vor-schwachstelle-bei-vpn-produkten-von-citrix-a-964940/ https://www.cnblogs.com/lsgxeva/p/12116150.html hits healthcare hospital in Germany, causing death of (at least) 1 person https://www.businessinsider.de/politik/deutschland/hacker-legen-uniklinik-duesseldorf-lahm-staatsanwaltschaft-ermittelt-wegen-todesfall-einer-patientin/

2021-11 Russian IT Security Updates – why it is impossible to turn off the Internet in Russia – what is the “Mitnick attack”? – are the odds against the defenders? Browser Sidechannel Attacks “We confirm that none of these approaches completely defend against our attacks” – 2010: AI amok: how AIs almost crashed wallstreet and why it can have real world consequences (1929)
04.11.2021

warning: no guarantee of completeness! contains ads! (but owner of blog get’s nothing, maybe source of source does) Are the odds against the (itsec) defenders? It certainly feels that way, because no human can ever find all bugs, so Fuzzing […]

What is Right – What is Wrong – with great powers comes great responsibility (aka the “Peter-Parker-principle” (Spiderman 2002)) – Big Tech with better and betters Tools and without better Ethics Morals unkowing what is Right or Wrong
17.07.2021

in short: humans per default, without an education might just be “better” apes. Some parts of mankind behave very primitive and clearly show no signs of higher intelligence or education. The troubles start, when the tools become more and more […]

Zehntausende Mail-Server wegen Exchange-Lücke gehackt – Cloud oder Klaut – com-magazin.de Security Newsletter
12.03.2021

scroll down to ENGLISH “Zehntausende Mail-Server wegen Exchange-Lücke gehackt.  Wegen einer vor wenigen Tagen bekanntgewordenen Sicherheitslücke sind laut US-Medienberichten Zehntausende E-Mail-Server von Unternehmen, Behörden und Bildungseinrichtungen Opfer von Hacker-Attacken geworden. “Deutsche Unternehmen sind im internationalen Vergleich besonders stark von dieser […]