The botnet that scouts before it strikes. [Research Saturday]

The botnet that scouts before it strikes. [Research Saturday]

Today we are joined by Ian Goldin, Senior Lead Information Security Engineer, and Mike Horka, Principal Information Security Engineer, from Lumen's Black Lotus Labs, discussing their research entitled "Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation." Black Lotus Labs has uncovered a major resurgence of the JDY botnet, a China-nexus reconnaissance network now comprising more than 1,500 compromised SOHO and IoT devices. The botnet uses these devices to conduct targeted scanning and fingerprinting, helping threat actors rapidly identify vulnerable infrastructure—sometimes within hours of a new vulnerability disclosure—and appears to have a particular focus on U.S. military-related networks. The research highlights how compromised routers and IoT devices can be turned into distributed reconnaissance infrastructure that evades traditional IP-based defenses and supports follow-on exploitation. The research and executive brief can be found here: Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(3725)

Apple has a message for you.

Apple has a message for you.

Apple sends out threat notifications to users targeted by spyware. Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack. French tax authority confirms data breach....

14 Aug 22min

Please hack responsibly.

Please hack responsibly.

President Trump deputizes private-sector companies to target cybercriminals. The LiteLLM supply-chain attack exposed credentials belonging to thousands of organizations. Data-theft campaign targets mi...

13 Aug 24min

A flurry of fixes.

A flurry of fixes.

We got your Patch Tuesday notes. Attackers target Microsoft SharePoint vulnerability following PoC release. Cyberattack on CEVA Logistics causes ongoing supply chain disruptions. Wesco confirms data b...

12 Aug 26min

A private route to public risk.

A private route to public risk.

Poland’s CERT describes winter cyberattack against heat-and-power plant. Russian military hackers target Ukrainian IT workers in fake recruitment scheme. Chinese IP connections spark security review i...

11 Aug 20min

Now with extra vulnerabilities.

Now with extra vulnerabilities.

Researchers find that only a quarter of AI-generated patches are fully successful. Ransomware attacks exploit critical N-able flaw. Atlassian fixes critical flaw in Rovo AI. LexisNexis disables some s...

10 Aug 27min

Designing space systems for the AI era. [T-Minus: Space-Cyber Briefing]

Designing space systems for the AI era. [T-Minus: Space-Cyber Briefing]

As commercial space activity accelerates, satellite manufacturers are rethinking how spacecraft are designed, built, and secured. In this week's episode, host Maria Varmazis sits down with Jason Robe...

9 Aug 22min

A little help from your search engine. [Research Saturday]

A little help from your search engine. [Research Saturday]

Today we are joined by Brian Hussey, SVP of Howler Cell Threat Services at Cyderes, discussing their work on "Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer." Howler Cell identi...

8 Aug 19min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
forklart
aftenpodden-usa
popradet
stopp-verden
rss-gukild-johaug
hanna-de-heldige
det-store-bildet
nokon-ma-ga
rss-ness
dine-penger-pengeradet
e24-podden
lydartikler-fra-aftenposten
rss-penger-polser-og-politikk
fotballpodden-2
aftenbla-bla
frokostshowet-pa-p5
unitedno
rss-utenrikskomiteen-med-bogen-og-grasvik