Show more

A new malware campaign of based theme is ongoing with a very low detection rate. Don't hesitate to contact us to get access to our private sector MISP information sharing community and get the IOCs.

51eab875208923d82953fd3492b2efab3dc1d234c555a2db9dcd45e840a9040cpic.twitter.com/f3ja7EMe0J

ALERT: : If you installed malicious Coronavirus Tracker app that locked your smartphone and requested ransom, use "4865083501" code to unlock it. Key is hardcoded. @LukasStefanko Details:
domaintools.com/resources/blog …pic.twitter.com/ojkRkGznPN

Criminals never miss a chance to scam you Amid fears over the outbreak, they are after your & money.

Make sure you:
Check the sender's email address
Don't click on suspicious attachments
Don't be rushed into making a purchase

.twitter.com/L2ULbDXIzh

"Vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows remote attackers to stop the network functions or execute malware via a specially crafted packet."

cve.circl.lu/cve/CVE-2020-5547 …

EX 2020, conference and upcoming courses for 1st half of 2020 are cancelled. Safety of our community and contributors is priority

"Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker to MITM osquery traffic in the absence of a configured root chain of trust."

cve.circl.lu/cve/CVE-2020-1887 …

"A vulnerability allows remote attackers to execute arbitrary code via a susceptible version of DiskStation Manager (DSM) or Synology Router Manager (SRM)."

synology.com/en-global/securit …

MISP 2.4.123 released with a new flexible internal dashboard features, various improvements and security fixes. We strongly recommend to wash our hands and do an update of your MISP instance.
misp-project.org/2020/03/10/MI … .twitter.com/rEeVfj5d0I

"TR-58 - CVE-2020-0796 - Critical vulnerability in Microsoft SMBv3 - status and mitigation" Check the mitigation, it's really important.

circl.lu/pub/tr-58/ pic.twitter.com/DWj7bsvbbw

Bash script using Nmap to detect server systems vulnerable to CVE-2020-0796 aka

- use it to scan the internet range, networks with attack surface (shared zones with providers / suppliers) etc.
gist.github.com/nikallass/40f3 …

We saw an increase of Tor hidden services related to such as criminals selling fake vaccine or masks. Collected via the open source AIL framework
github.com/CIRCL/AIL-framework …pic.twitter.com/nz6W8skU75

CVE-2020-0796 - a "wormable" SMBv3 vulnerability.
Great...
pic.twitter.com/E3uPZkOyQN

"BWA DiREX-Pro 1.2181 devices allow remote attackers to discover passwords via a direct request to val_users.php3."

cve.circl.lu/cve/CVE-2020-1024 …

"Dell Security Management Server versions prior to 10.2.10 contain a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated attacker may exploit this vulnerability by sending a crafted RMI request to execute RCE"

cve.circl.lu/cve/CVE-2020-5327 …

"An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the date parameter in a system_time.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected."

cve.circl.lu/cve/CVE-2020-1021 …

Welcome to 1995 > RT @circl_lu: “The secret key used to make the Initial Sequence Number in the TCP SYN packet could be brute forced and therefore can be predicted” in Qualcomm Snapdragon and others.

cve.circl.lu/cve/CVE-2019-2317 …

Analysing TCP port scan of Mirai-based botnets. By analysing the TCP initial sequence number from black-hole monitoring from the D4 project, we discover interesting insights about the targeted equipments.
d4-project.org/2020/03/06/anal …pic.twitter.com/zHYRMFQ2nj

Show more
OpenCloud Luxembourg Mastodon instance

A Mastodon instance for Luxembourg and beyond.