Everything posted by reporter
-
The Meta Quest 3S VR Headset Is the Cheapest It’s Ever Been (2025)
The Quest 3S is down to $249 at different retailers for Cyber Monday, but pay attention to how they’re bundled.View the full article
-
Best Thuma Cyber Monday Deal: Signature Bed Frame (2025)
Thuma's Japanese-style joinery has earned its bed frames rave reviews. If you've had your eye on one, the Thuma Cyber Monday sale is the perfect time to shop.View the full article
-
Cyber Monday Electric Toothbrush Deals (2025)
Prevent cavities and keep your budget in check with the best deals we've found on electric toothbrushes.View the full article
-
Best Cyber Monday Coffee Subscription Deals (2025): Atlas, Trade
Coffee subscriptions offer their steepest discounts around Cyber Monday and Black Friday. Here are the best deals WIRED has found.View the full article
-
15 Best Cyber Monday Phone Deals (2025)
Now is a great time to upgrade your phone. This Cyber Monday has discounts ranging from the Google Pixel 9a to Samsung's Galaxy Z Fold7.View the full article
-
Why Don’t Norwegians Hate Tesla Like the Rest of Europe Does?
November’s Tesla registrations were down in France, Sweden, Denmark, and Germany. Norway, however, is bucking the trend—thanks to a tax incentive system that will soon be rolled back.View the full article
-
The Best Cyber Monday Mattress and Bedding Deals (2025)
Some of the best sales of the year on mattresses, mattress toppers, and pillows are happening right now.View the full article
-
The Best Therabody and Theragun Cyber Monday Deals (2025)
Therabody's Cyber Monday sale is live—and it's good.View the full article
-
48 Best Cyber Monday Deals Under $100 (2025)
These Cyber Monday deals won't break your budget, proving that you don't need to spend a lot to save on WIRED-approved gear.View the full article
-
Best Hyperice Cyber Monday Deals (2025)
Here are the Hyperice deals worth your money this Cyber Monday.View the full article
-
India Orders Phone Makers to Pre-Install Government App to Tackle Telecom Fraud
India's telecommunications ministry has ordered major mobile device manufacturers to preload a government-backed cybersecurity app named Sanchar Saathi on all new phones within 90 days. According to a report from Reuters, the app cannot be deleted or disabled from users' devices. Sanchar Saathi, available on the web and via mobile apps for Android and iOS, allows users to report suspected fraud,View the full article
-
Best Digital Notebook Cyber Monday Sales (2025): ReMarkable, Kobo, Kindle
These handy e-paper devices let you write notes, sketch ideas, and even read books—and they're on sale for Cyber Monday.View the full article
-
ShadyPanda Turns Popular Browser Extensions with 4.3 Million Installs Into Spyware
A threat actor known as ShadyPanda has been linked to a seven-year-long browser extension campaign that has amassed over 4.3 million installations over time. Five of these extensions started off as legitimate programs before malicious changes were introduced in mid-2024, according to a report from Koi Security, attracting 300,000 installs. These extensions have since been taken down. "TheseView the full article
-
NETSCOUT wins “Overall Network Security Solution of the Year”
When it comes to cybersecurity, visibility is everything. Without it, even the most advanced tools can’t help teams detect, investigate, or respond effectively to threats lurking in their networks. That’s why we’re proud to announce that NETSCOUT’s Omnis Cyber Intelligence has been named “Overall Network Security Solution of the Year” in the ninth annual CyberSecurity Breakthrough Awards. This recognition honors the most innovative companies and technologies shaping the future of cybersecurity, and we’re thrilled to be counted among them. What sets us apart The challenge: Visibility gaps create risk Modern enterprises face expanding attack surfaces, hybrid cloud environments, and increasing operational complexity. Security teams are flooded with alerts but lack the visibility to see what’s truly happening behind them. Many tools promise detection, but few deliver the clarity and confidence that come from true visibility. Without that clarity, investigations stall, threats linger, and response times grow longer, creating risk that no organization can afford. The innovation: Always-on, packet-based intelligence Omnis Cyber Intelligence changes that dynamic by delivering a continuous, comprehensive view of network activity. Built on NETSCOUT’s industry-leading deep packet inspection (DPI) at scale, Omnis Cyber Intelligence continuously captures, analyzes, and stores high-fidelity network metadata, independent of detections. This always-on visibility ensures nothing slips through the cracks. Security teams gain full context into every connection, even before an alert fires. Omnis Cyber Intelligence’s on-sensor storage architecture minimizes data movement, helping organizations meet compliance and data-sovereignty requirements by keeping sensitive data close to its source. The impact: Bridging the gap between detection and response While most solutions stop at detection, Omnis Cyber Intelligence goes further. By combining real-time analytics with historical network context, it bridges the critical gap between alert and action, empowering analysts to understand how and why an attack occurred. Whether hunting zero-day threats, analyzing encrypted traffic, or investigating suspicious behavior across cloud and on-prem environments, Omnis Cyber Intelligence provides the context, clarity, and confidence teams need to act decisively. And with integrations across major ecosystems, including AWS, Microsoft, Google Cloud, and more, Omnis Cyber Intelligence delivers end-to-end visibility for today’s distributed enterprises. Recognition of innovation The CyberSecurity Breakthrough Awards program received thousands of nominations from more than 20 countries. Winners were selected for redefining how we safeguard the digital world through innovation, performance, and measurable impact. As Steve Johansson, managing director at CyberSecurity Breakthrough, noted, “Modern network complexities create blind spots that limit understanding, insight, and automation based on network behavior. Omnis Cyber Intelligence addresses these complexities and delivers complete network transparency, accelerating incident response and improving overall security posture.” Setting the standard for network security For decades, NETSCOUT has delivered packet-level visibility at scale, helping the world’s largest enterprises and service providers maintain performance and security across the most demanding environments. This award validates what our customers already know: When you can see everything, you can stop anything. We’re honored by this recognition and even more committed to helping organizations around the world defend with clarity, respond with confidence, and continuously outsmart evolving threats. Learn more about how NETSCOUT Omnis Cyber Intelligence can help by providing comprehensive network visibility with scalable deep packet inspection (DPI) to detect, investigate, and respond to threats more efficiently. View the full article
-
What are zero-day attacks and why do they work?
Zero-day attacks have become a significant concern in the realm of cybersecurity, posing a formidable challenge to individuals and organizations alike. These attacks exploit vulnerabilities that are unknown to the software vendor, leaving systems exposed to potential breaches. As cyberthreats evolve, understanding zero-day attacks and implementing effective protection strategies is crucial for maintaining security. Understanding zero-day attacks What is a zero-day vulnerability, exploit, and attack? A zero-day vulnerability refers to a software security flaw that is unknown to the vendor. When attackers exploit this vulnerability, it becomes a zero-day exploit. A zero-day attack occurs when malicious actors use this exploit to compromise a system before a patch is available. Why “zero-day”? The term “zero-day” signifies that the vendor has zero days to address the vulnerability before it is exploited. This urgency highlights the critical nature of these threats because they can be leveraged by attackers immediately upon discovery. Common targets of zero-day attacks Zero-day attacks often target operating systems, web browsers, enterprise software, and Internet of Things (IoT) devices. These platforms are integral to daily operations, making them attractive targets for attackers seeking to maximize impact. Why zero-day attacks are so effective Zero-day attacks have several advantages in the cybersecurity landscape. Due to their novel nature, they can be challenging to detect and understand. Here are some common reasons they work when deployed against unsuspecting targets: No available patch: These exploits are unknown to both vendors and defenders, meaning they have not been identified and patched yet, leaving the door open for attackers. High-value targets: These attacks are often used in cyber espionage, ransomware campaigns, and advanced persistent threats (APTs) to target high-value assets with sensitive data. Difficult to detect: These exploits often are missed by traditional detection tools, especially those relying on signature-based detection, allowing adversaries to operate undetected. Speed and stealth: Successful breaches are more likely with zero-day attacks because attackers act quickly and quietly, allowing them to exploit vulnerabilities before they are identified and patched. Precision targeting: The target of these exploits is often a specific individual or organization. Spear-phishing and zero-click attacks are common tactics used to initiate the breach. Real-world zero-day attack examples No organization is immune to being targeted by a zero-day attack. In the real world, many key services, organizations, and platforms can be targeted by zero-day exploits: Nation-state sabotage: State-sponsored attackers can target critical infrastructure and utilities with zero-day exploits, rendering key services and life-saving utilities unavailable. Mobile surveillance: In telecommunications, carriers have witnessed zero-click exploits being used in mobile surveillance. This leads to compromised devices without any user interaction. Supply chain attacks: Global supply chains are appealing targets because they have a wide impact. In exploiting zero-day vulnerabilities, attackers can impact several groups in one attack, such as consumers, manufacturers, employees, and more. Frequently targeted platforms: Web browsers and email servers are common targets of zero-day attacks. These are widely used, increasing the potential for significant disruption. How zero-day vulnerabilities are discovered and used There are multiple groups and methodologies that work to discover, use, and inform organizations of zero-day vulnerabilities. These include: White-hat researchers: Often ethical hackers, also known as white-hat researchers, discover zero-day vulnerabilities via bug bounty programs and responsible disclosure. This helps vendors identify and address these issues. Black-hat hackers: On the flip side, if a black-hat hacker identifies a vulnerability before it is patched, the hacker can leverage it for gain, often selling exploits on the dark web. Government agencies: Some government agencies engage in offensive cyber operations, stockpiling exploits for strategic purposes. They also can inform organizations and vendors of these exploits, much like white-hat researchers. Thorough investigation: Internal security teams can leverage investigation capabilities, such as packet-level insights, to discover and understand zero-day threats, preventing future occurrences. How to defend against zero-day attacks There are several measures security and network teams can take to more effectively avoid zero-day attacks. Some examples include: Leverage threat investigation: Detection alone often misses the unknown. Thorough investigation, leveraging deep packet inspection (DPI) at scale and forensic analysis, is key to identifying and preventing zero-day attacks from being successful now and in the future. Patch quickly: Prioritizing updates and effective vulnerability management is essential to mitigating the risk of zero-day attacks. Use behavior-based detection: Employing solutions such as endpoint detection and response (EDR), network detection and response (NDR), and extended detection and response (XDR) in combination with a strong investigation focus can help identify anomalous behavior that can signify zero-day exploits are being leveraged. Adopt zero-trust principles: Implementing a zero-trust security architecture, limiting user access, and continuously verifying identities can reduce the risk of unauthorized access to sensitive data. Segment the network: Strategic network segmentation helps contain breaches and minimizes lateral movement within a compromised system. Stay informed: Subscribing to security advisories and threat intelligence feeds helps keep organizations informed on emerging threats and vulnerabilities. FAQs about zero-day attacks What makes zero-day attacks different from other cyberthreats? Zero-day attacks exploit unknown vulnerabilities, making them particularly challenging to defend against compared with threats targeting known vulnerabilities. Can antivirus software detect zero-day exploits? Traditional antivirus software may struggle to detect zero-day exploits due to its reliance on signature-based detection methods. Are zero-day vulnerabilities illegal to sell or use? Although selling or using zero-day vulnerabilities for malicious purposes is illegal, ethical disclosure through bug bounty programs is encouraged. How long do zero-day exploits typically remain undetected? The duration for which a zero-day exploit remains undetected varies, but it can range from days to months, depending on the complexity of the exploit and the vigilance of security teams. Staying ahead of emerging threats with investigation Zero-day attacks represent a significant threat in the cybersecurity landscape, exploiting unknown vulnerabilities to devastating effect. Understanding these attacks and implementing proactive defensive strategies is essential for staying ahead of emerging threats. Detection alone is not enough. Detection-focused tools such as EDR, NDR, and XDR on their own miss the unknown, allowing zero-day attacks to have a better chance of success. Leveraging investigation, powered by packet data, empowers teams with the actionable data to detect, understand, and prevent future attacks. Packets do not lie, and the network is the only place adversaries cannot hide. Learn more about Omnis Cyber Intelligence. View the full article
-
The Best Cyber Monday Streaming Deals (2025): HBO Max, Disney+, Apple
Hulu and HBO Max and Disney are all offering terrific Cyber Monday streaming deals in 2025. Time to make a burner email?View the full article
-
The first line of defense is still the network. But that’s only the beginning
For years, the security industry has been captivated by the promises of new acronyms: EDR, XDR, CDR. Each wave has promised broader coverage, better detection, and faster responses. And although each of these tools provides value, recent research from Enterprise Strategy Group (ESG) reveals something the industry conversation often overlooks: When real threats emerge, organizations still turn first to the network. According to ESG, 53% of organizations rely on network visibility and telemetry as their primary line of defense. In fact, nearly two-thirds use the network in some capacity to kick off their threat detection and response processes. Even more telling, 93% of SecOps and NetOps teams now share the same network visibility tools, which is a sign that the network has become the unifying language of operations. So, why in an era dominated by extended detection and response (XDR) and cloud-native tooling does the network remain the first place security teams look? The answer is simple: Packets don’t lie. Why packets still matter Endpoints can be tampered with. Logs can be incomplete. Cloud providers can limit visibility. But network packets capture every transaction, every communication, and every anomaly, without bias. This is why, despite some vendors dismissing network detection and response (NDR) as “old-school” or “on-premises,” ESG found that 41% of organizations actually see network tools as the best-equipped technology for providing visibility across hybrid, multicloud environments. The truth is that the network has evolved right alongside the environments it protects. It’s no longer just about physical appliances watching traffic at the perimeter. Today’s NDR solutions scale across data centers, virtual servers, and multicloud ecosystems, providing a single vantage point where everything converges. Detection is only step one But here’s where we believe the conversation needs to change. Detection, while critical, is just the first step. The real challenge, and the real value, lies in understanding a threat through the investigation phase. Think about it: an alert tells you something happened. But only investigation tells you what it was, how it happened, and what to do about it. That’s the gap where attackers thrive and where security operations center (SOC) teams often lose valuable time. And this is where network visibility proves its worth beyond being just a “first line of defense.” With full packet capture and deep network intelligence, security teams can pivot from “we detected something” to “we understand everything about it.” That shift is the difference between chasing alerts and actually stopping adversaries in their tracks. Why NETSCOUT Omnis Cyber Intelligence At NETSCOUT, we’ve seen this shift firsthand. Omnis Cyber Intelligence isn’t just about spotting anomalies; it’s about giving analysts the complete, packet-level context they need to investigate confidently. By unifying SecOps and NetOps on a shared foundation of visibility, Omnis Cyber Intelligence helps eliminate blind spots that attackers exploit. Because at the end of the day, detection will always be table stakes. Investigation is where the real impact is made. Network packets provide the single source of truth across on-premises, hybrid, and cloud environments, serving as the foundation that makes it all possible. Learn more about the ESG report. Learn how NETSCOUT Omnis Cyber Intelligence can help by providing comprehensive network visibility with scalable deep packet inspection (DPI) to detect, investigate, and respond to threats more efficiently. View the full article
-
Aura Frame Cyber Monday Sale (2025): Carver, Walden, Aspen
Aura's digital picture frames are the most complimented item in my house, and now you can get your own during the Cyber Monday sale.View the full article
-
The 74 Best REI Cyber Monday Outdoor Deals (2025)
Gear up for next year with these great deals on tents, packs, sleeping bags, and merino wool.View the full article
-
Cyber Monday Grill Deals: A Bunch of Favorites Are on Sale Today (2025)
It's the end of the season for outdoor living, which means you can save big on Cyber Monday grill deals.View the full article
-
Microsoft gives Windows admins a legacy migration headache with WINS sunset
Microsoft has given system administrators until 2034 to stop using WINS (Windows Internet Name Service) NetBIOS name resolution technology in their networks — but even nine years may not be enough notice for some: WINS is very much still in use, supporting a niche range of difficult-to-replace legacy systems. WINS dates from Windows NT in 1994 and has long since been displaced by the more modern Domain Name System (DNS). It was deprecated in 2021 to coincide with the appearance of Windows Server 2022. This meant it would be supported but no longer developed, a clear signal that the clock was ticking. Now, Microsoft has said, the last operating system to support WINS will be Windows Server 2025. That’s what determines the nine-year final migration deadline — the lifespan of Windows Server 2025 on the Long-Term Servicing Channel (LTSC). “Organizations using WINS are strongly encouraged to migrate to modern DNS-based name resolution solutions,” the company said, perhaps stating the obvious, in a Windows Message Center advisory in early November. According to Microsoft, the timescale is generous. “Our goal is to make planning and migrations as predictable and low-stress as possible. With advanced notice and a support runway, organizations can confidently modernize their environments at their own pace,” it said. Cutting out WINS Future versions of Windows without support for WINS will lose the WINS Server role and associated binaries, the WINS Microsoft Management Console (MMC) snap-in, and WINS automation APIs and related management interfaces, the company added. WINS migration is yet another legacy issue inherited from the creative ferment of computer networking in the 1980s and 1990s. That era needed solutions to lots of networking problems in a hurry, especially how to turn a desktop PC operating system such as DOS or Windows into a practical server platform. WINS solved an important challenge: how to connect the names used to identify computers using the 1980s’ NetBIOS network naming system with modern IP addresses. DNS, a hierarchical system that worked for Internet as well as network addresses, had rendered NetBIOS obsolete. But both ended up co-existing, examples of how the industry delivered more than one answer to the same problem. Today, the arguments for getting rid of WINS extend beyond its obsolescence. It is also a security risk. In 2017, Fortinet’s FortiGuard Labs discovered a WINS Server remote memory corruption vulnerability in Windows Server 2008, 2012, and 2016. Microsoft’s reply to Fortinet made interesting reading: “A fix would require a complete overhaul of the code to be considered comprehensive. The functionality provided by WINS was replaced by DNS and Microsoft has advised customers to migrate away from it.” In short, Microsoft had no plans to patch the issue. Its solution was that customers migrate away from WINS, a process it has since become clear could still be ongoing for some customers into the 2030s. Why WINS is still in use Organizations still using WINS are likely to fall into one of two categories: those using it to support old technologies with long lifecycles such as operational technology (OT) systems, and those that have simply half-forgotten that they are still using it. “For OT stacks built around WINS/NetBIOS, replacing them isn’t trivial because changing name resolution touches safety‑critical systems and bespoke integrations,” said Kieran Bhardwaj, head of security engineering at UK cyber security consultancy Bridewell, which specializes in advising on critical infrastructure. “Legacy technologies persist because some niche systems like industrial/OT environments are engineered for multi‑decade lifecycles. Many control systems are architecturally fixed and can’t be re‑platformed,” he said. “It’s also hard for Microsoft: WINS sits deep in the networking stack which means removing a once‑core component demands exhaustive regression to avoid unintended breakage.” Equally, according to William Wright of pen-testing company Closed Door Security, WINS was still running on some networks for the same reason that many legacy technologies overstay their usefulness: migration apathy. “Most organizations running WINS today probably aren’t actively using it for anything critical. They’ve just never had a compelling reason to turn it off,” he said. “It’s been quietly replicating in the background, consuming minimal resources, causing no obvious problems. That’s the nature of legacy infrastructure: It persists not because it’s needed, but because removing it requires effort and carries risk, while leaving it alone is free,” said Wright. WINS is a security risk WINS had major design limitations that made it a security risk, said Wright. “WINS has no mechanism to verify the legitimacy of name registrations, which makes it vulnerable to spoofing attacks,” said Wright. “An attacker on the network can register malicious entries, including Web Proxy Auto-Discovery (WPAD) records to intercept web traffic, or redirect connections to systems they control. It’s a straightforward path for lateral movement,” he said. Finding WINS still turned on inside a network was a godsend to hackers using open-source tools such as Responder to conduct name resolution poisoning attacks against legacy Windows protocols such as Link-Local Multicast Name Resolution (LLMNR) and the NetBIOS Name Service (NBT-NS), Wright added. Worse, the presence of WINS often indicated that a target was using other vulnerable legacy protocols. “Systems often fall back to NetBIOS broadcast queries when WINS isn’t available, which are spoofable on local networks. This is exactly what tools like Responder exploit, and it remains a common technique in penetration testing and real-world attacks alike.” Network inventory Organizations looking to rip WINS out should start with an inventory to find out where it is being used, Bhardwaj said: “Many organizations don’t realize a legacy asset still relies on WINS, so proactively inventory older segments and OT/ICS networks and verify resolution paths before the next upgrade window.” “The trade-off is that customers still using WINS must put in the work to move to DNS by auditing dependencies, modernizing or isolating legacy workloads, and implementing DNS. But the payoff is a simpler, more secure platform. In the end, even the brightest and best-performing technologies will one day be legacy. Migrating from WINS is a test of how well organizations are dealing with this wider problem. “There’s way too much legacy that is unused and that presents an attack surface for no reason,” said Bhardwaj. This article first appeared on Computerworld. View the full article
-
Bin ich Teil eines Botnets? Jetzt kostenlos nachprüfen
Zu Weihnachten die Rechner der Verwandtschaft auf Botnet-Aktivitäten überprüfen – der kostenlose GreyNoise IP Check machts möglich. Jaiz Anuar – Shutterstock.com Hacks greifen immer stärker Unternehmen an, weil die Beute in Form von Lösegeld und Daten dort aussichtreicher ist als bei Privatpersonen. Das bedeutet jedoch nicht, dass eine Einzelperson kein lohnendes Opfer ist. Im Gegenteil – Computer von Individuen zu infizieren kann sich für Kriminelle auszahlen, insbesondere wenn sie Botnetze oder Residential-Proxy-Netzwerke einrichten. Doch wie kann man herausfinden, ob der eigene Rechner infiziert ist, selbst ohne Vorkenntnisse und Fachwissen? Ein kostenloses Tool GreyNoise IP Check von GreyNoise Labs hilft zu überprüfen, ob die eigene IP-Adresse bei schädlichen Scans erfasst wurde. Diese Vorsichtsmaßnahme begründen die Experten so: „Manchmal installieren Nutzer wissentlich Software, die solche Aktionen ausführt, und verdienen damit ein paar Euro. Häufiger jedoch schleicht sich Malware unbemerkt auf Geräte ein, meist über schädliche Apps oder Browsererweiterungen, und verwandelt diese im Hintergrund in Knotenpunkte in der Infrastruktur anderer.“ Analysieren und scannen Grundsätzlich gibt es diverse Möglichkeiten, um festzustellen, ob jemand Teil eines schädlichen Botnetzes geworden ist, nämlich, indem Geräteprotokolle, Konfigurationen, Netzwerkverkehr und Aktivitätsmuster analysiert werden. Ein Tool, das lediglich die IP-Adresse überprüft, sei aber die schonendste Methode, erklärt GreyNoise. Interessenten wird beim Besuch der IP-Check-Webseite, eines von drei möglichen Ergebnissen angezeigt: Der Rechner ist sauber, es wurden also keine schädlichen Scan-Aktivitäten festgestellt. Etwas Schädliches beziehungsweise Verdächtiges wurde gefunden, die IP-Adresse wurde beim Scannen des Internets erfasst oder ist in der GreyNoice-Datenbank verzeichnet. User sollten Geräte in ihrem Netzwerk überprüfen. Die IP-Adresse des Users gehört zu einem VPN, einem Unternehmensnetzwerk oder einem Cloud-Anbieter, und die Scan-Aktivität ist für diese Umgebungen normal. Korrelationen zwischen Installationen und Scans Wenn eine Aktivität mit der angegebenen IP-Adresse korreliert wird, zeigt die Plattform auch einen 90-tägigen Verlauf an. Das soll helfen, einen potenziellen Infektionsherd zu identifizieren und Abwehrmaßnahmen vornehmen. Bei einem positiven Befund wird eine Zeitleiste mit den Aktivitäten der letzten 90 Tage ausgegeben. GreyNoise JSON-Option für Fortgeschrittene Für technisch versierte Nutzer bietet GreyNoise außerdem eine nicht authentifizierte, rate-limit-free JSON-API. Diese ist über curl zugänglich und kann in Skripte oder Prüfsysteme integriert werden. Dies liefert strukturierte Daten zur fraglichen IP-Adresse, die in MDM-Systeme, VPN-Verbindungsskripte oder Netzwerk-Onboarding-Prozesse integriert werden können. Der Hersteller merkt an, dass Entwickler die Informationen in jeder beliebigen Programmiersprache verwenden können – solange ein curl-ähnlicher User-Agent vorhanden ist. View the full article
-
Bin ich Teil eines Botnets? Jetzt kostenlos nachprüfen
Zu Weihnachten die Rechner der Verwandtschaft auf Botnet-Aktivitäten überprüfen – der kostenlose GreyNoise IP Check machts möglich. Jaiz Anuar – Shutterstock.com Hacks greifen immer stärker Unternehmen an, weil die Beute in Form von Lösegeld und Daten dort aussichtreicher ist als bei Privatpersonen. Das bedeutet jedoch nicht, dass eine Einzelperson kein lohnendes Opfer ist. Im Gegenteil – Computer von Individuen zu infizieren kann sich für Kriminelle auszahlen, insbesondere wenn sie Botnetze oder Residential-Proxy-Netzwerke einrichten. Doch wie kann man herausfinden, ob der eigene Rechner infiziert ist, selbst ohne Vorkenntnisse und Fachwissen? Ein kostenloses Tool GreyNoise IP Check von GreyNoise Labs hilft zu überprüfen, ob die eigene IP-Adresse bei schädlichen Scans erfasst wurde. Diese Vorsichtsmaßnahme begründen die Experten so: „Manchmal installieren Nutzer wissentlich Software, die solche Aktionen ausführt, und verdienen damit ein paar Euro. Häufiger jedoch schleicht sich Malware unbemerkt auf Geräte ein, meist über schädliche Apps oder Browsererweiterungen, und verwandelt diese im Hintergrund in Knotenpunkte in der Infrastruktur anderer.“ Analysieren und scannen Grundsätzlich gibt es diverse Möglichkeiten, um festzustellen, ob jemand Teil eines schädlichen Botnetzes geworden ist, nämlich, indem Geräteprotokolle, Konfigurationen, Netzwerkverkehr und Aktivitätsmuster analysiert werden. Ein Tool, das lediglich die IP-Adresse überprüft, sei aber die schonendste Methode, erklärt GreyNoise. Interessenten wird beim Besuch der IP-Check-Webseite, eines von drei möglichen Ergebnissen angezeigt: Der Rechner ist sauber, es wurden also keine schädlichen Scan-Aktivitäten festgestellt. Etwas Schädliches beziehungsweise Verdächtiges wurde gefunden, die IP-Adresse wurde beim Scannen des Internets erfasst oder ist in der GreyNoice-Datenbank verzeichnet. User sollten Geräte in ihrem Netzwerk überprüfen. Die IP-Adresse des Users gehört zu einem VPN, einem Unternehmensnetzwerk oder einem Cloud-Anbieter, und die Scan-Aktivität ist für diese Umgebungen normal. Korrelationen zwischen Installationen und Scans Wenn eine Aktivität mit der angegebenen IP-Adresse korreliert wird, zeigt die Plattform auch einen 90-tägigen Verlauf an. Das soll helfen, einen potenziellen Infektionsherd zu identifizieren und Abwehrmaßnahmen vornehmen. Bei einem positiven Befund wird eine Zeitleiste mit den Aktivitäten der letzten 90 Tage ausgegeben. GreyNoise JSON-Option für Fortgeschrittene Für technisch versierte Nutzer bietet GreyNoise außerdem eine nicht authentifizierte, rate-limit-free JSON-API. Diese ist über curl zugänglich und kann in Skripte oder Prüfsysteme integriert werden. Dies liefert strukturierte Daten zur fraglichen IP-Adresse, die in MDM-Systeme, VPN-Verbindungsskripte oder Netzwerk-Onboarding-Prozesse integriert werden können. Der Hersteller merkt an, dass Entwickler die Informationen in jeder beliebigen Programmiersprache verwenden können – solange ein curl-ähnlicher User-Agent vorhanden ist. View the full article
-
Contagious Interview attackers go ‘full stack’ to fool developers
Researchers at Socket have uncovered more details of a sophisticated software supply-chain operation linked to the Contagious Interview campaign attacking developers who rely on packages from NPM. They report finding a “full stack” operation behind the attacks, where code hosting, package distribution, staging servers and command-and control (C2) infrastructure are orchestrated much like a legitimate software development and delivery pipeline — and offer honest developers fresh advice on protecting themselves against the attacks. In the latest wave, threat actors uploaded almost 200 new malicious NPM packages, with more than 31,000 recorded downloads. The campaign lures victims with fake job interviews and coding assignments related to Web3 and blockchain projects, asking them to pull dependencies for a “test project”. But the NPM packages they install are Trojan horses. The latest packages identified by Socket ultimately deliver a new payload with upgraded credential theft, system monitoring and remote access capabilities, enabling them to take over developers’ accounts and machines. Point defense Based on its latest analysis, Socket advised developers to focus on the weak points this campaign exploits, and to treat every “npm install” as potential remote code execution, restrict what continuous-integration runners can access, enforce network egress controls, and review the code of any new templates or utilities pulled from GitHub. Teams should also scrutinize unfamiliar helper packages, pin known-good versions, and use lockfiles instead of auto-updating dependencies, it advised. Automated package analysis can further reduce risk, with real-time scans catching threats including import-time loaders, network probing, and bulk data exfiltration before they hit developer machines or CI systems. With these checks in place, dependency onboarding and code review become effective filters for blocking Contagious Interview-style attacks early, Socket said. Coding tasks lead to malware delivery These defensive measures are effective because Contagious Interview’s entry vector relies heavily on social engineering, using fake interview tasks to trick developers into installing compromised dependencies. The campaign exploits NPM, a widely used package registry for JavaScript and Node.js, by publishing packages that appear benign but carry hidden payloads. The malicious packages including one named “tailwind-magic” mimic legitimate libraries (in this case, a typosquatted version of the genuine “tailwind-merge” utility) to avoid suspicion. When an unsuspecting developer installs such a package, a post-install script triggers and reaches out to a staging endpoint hosted on Vercel. That endpoint in turn delivers a live payload fetched from a threat-actor controlled GitHub account named “stardev0914”. From there the payload, a variant of OtterCookie that also folds in capabilities from the campaign’s other signature payload, BeaverTail, executes and establishes a remote connection to the attackers’ control server. The malware then silently harvests credentials, crypto-wallet data, browser profiles and more. “Tracing the malicious npm package tailwind-magic led us to a Vercel-hosted staging endpoint, tetrismic[.]vercel[.]app,and from there to the threat actor controlled GitHub account which contained 18 repositories,” Socket’s senior threat intelligence analyst Kirill Boychenko said in a blog post, crediting related research by Kieran Miyamoto that helped confirm the malicious GitHub account stardev0914. A ‘full stack’adversary: GitHub, Vercel, and NPM What makes this campaign stand out is the layered infrastructure behind it. Socket’s analysis traced not just the NPM packages but also how the attackers built a complete delivery pipeline: malware serving repositories on GitHub, staging servers on Vercel, and separate C2 servers for exfiltration and remote command execution. Through this setup, attackers can rotate payloads, update malware unobtrusively, and tailor deployments per target—all while blending deeply into the legitimate developer ecosystem, according to Boychenko. Once installed, OtterCookie doesn’t just run and vanish: It remains persistent, capable of logging keystrokes, hijacking the clipboard, scanning the filesystem, capturing screenshots, and grabbing browser and wallet credentials across Windows, macOS and Linux. The campaign actors’ intensified NPM activity arrives at a worrying moment for the JavaScript and open-source ecosystem. In recent months, the community has seen a flurry of NPM-based attacks — including worm-style campaigns that transformed popular packages into Trojan horses, automated credential theft, and widespread supply chain compromise across both development and CI environments. This article was first published on Infoworld. View the full article
-
The CISO’s paradox: Enabling innovation while managing risk
We can keep it real here. One of the main jobs CISOs have is to stop being the “Department of No.” We have to figure out how to enable the rapid delivery of products and services for the business without introducing risks to the same business. That’s the paradox in a nutshell. In an environment where product teams must constantly test new technologies and ship updates at record speed, traditional end-of-line audits wouldn’t keep up. Security has to move upstream. It must be built into everyday operations, with proactive, actionable measures that empower innovation instead of slowing it down. CISOs, then, must work more closely with teams from the initial stages to establish clear and practical risk tolerances and build security into development workflows. Partner early to shape outcomes CISOs don’t get leverage by showing up at the finish line. They must ditch the gatekeeper mindset and become true partners from Day Zero. In the past, when security measures were only brought in at the final stage, decision-makers were left with a difficult choice: accept project delays or face unmitigated risks. When product cycles were quarterly and speed did not determine competition, this approach made sense. In today’s reality with AI-driven product development, such a process breaks in an environment now made up of weekly sprints, continuous delivery and vendor-driven dependencies. When security understands revenue goals, customer promises and regulatory exposure, guidance becomes specific and enabling. Begin by embedding a security liaison with each product squad so there is always a known face to engage in identity, data flows, logging and encryption decisions as they form. We should not want to see engineers opening two-week tickets for a simple question. There should be open “office hours,” chat channels and quick calls so they can get immediate feedback on decisions like API design, encryption requirements and regional data moves. Bureaucracy must be deprecated in our environment. Show up at sprint planning and early design reviews to ask the questions that matter — authentication paths, least-privilege access, logging coverage and how changes will be monitored in production through SIEM and EDR. When security officers sit at the same table, the conversation changes from “Can we do this?” to “How do we do this securely?” and better outcomes follow from day one. Set risk tolerances and guardrails Teams slow down when they are unsure how to proceed. Take away some of the decision-making and ensure an integration of authentication, authorization and accounting into the development process. For authentication, establish and leverage enterprise identity management solutions rather than allowing the development of accounts written to databases that can be easily compromised. CISOs must also ensure they define standard role-based access control levels that ensure clear separation of duties is in place in the solution design. For accounting, don’t just create logs; ensure high-cardinality data is being captured for anomaly detection and this data is being integrated into a central security operations center for threat detection and response. Product development teams should not be tasked with security operations responsibilities; other teams should maintain the eye-on-glass visibility into the threats facing the solutions in production. CISOs must define the organization’s risk appetite in business language that removes ambiguity. Specify which third-party profiles require deep assessment and which can run as bounded pilots with compensating controls. State which vulnerability severities must block a merge and which can proceed with a time-bound remediation plan. Clarify what data classifications may cross regions and what protections must travel with them. Then translate those choices into automation. Bake guardrails into CI/CD and infrastructure-as-code so enforcement is consistent and visible. Scan each code commit for vulnerabilities, and if a change breaches a critical policy, the build fails with a clear reason and a path to resolution. If it sits within tolerance, it moves forward without manual intervention. The result is governance as an accelerator: predictable, transparent and aligned with how design engineers work. Build secure-by-design into fast developer lifecycles When developers deploy code multiple times a day, a “final security review” before launch just wouldn’t work. This traditional, end-of-line gating model doesn’t just block innovation but also fails to catch real-world risks. To be effective, security must be embedded during development, not just inspected after. If the secure path is harder than the insecure path, developers will choose the easy way every single time. Our job isn’t to hand out a 50-page PDF; it’s to bake security right into their developer environment, giving them pre-vetted, hardened templates that are secure by default. This means offering standard service templates with authentication and authorization already built in. When the secure component is easier to use than the insecure alternative, developers can adopt it easily and will adopt it every time. Automation is the enforcement layer for this strategy. When security tools are integrated directly into the CI/CD pipeline, feedback becomes available almost in real-time. This allows the team to “fail fast” on critical risks while providing actionable fixes. This discipline must further extend into production. Even with world-class DevSecOps, we know a zero-day or configuration drift can happen. That’s why we rely on over-arching web application shielding solutions that integrate a robust web application firewall with runtime application attack mitigation and self-protection. These solutions mitigate vulnerabilities and risks in real-time while the application is running in production. They buy the development teams the crucial time they need to resolve the underlying issue without service interruption or breach, ensuring that even if all other controls fail, we have a way to block and tackle in the critical moment. Runtime telemetry and risk-based alerting are the final checks on this coverage. This promotes a cultural change that enables engineers to take full ownership of their applications, from the initial line of code all the way to production. Security, in turn, achieves thorough, lasting coverage without becoming a bottleneck. This article is published as part of the Foundry Expert Contributor Network. Want to join? View the full article