Four key points about the "sudden" emergence of this vulnerability - and how to mitigate it. On July 31st, security journalist Brian Krebs published an article about a DNS vulnerability dubbed "Sitting Duck", which claimed: "More than a million domain names — including many registered by Fortune 100 firms and brand protection companies — are vulnerable to takeover ... View Post
Ledger users lose 1.1M XRP via homoglyph attack
Many crypto-currency holders use Ledger hardware wallets to store their bitcoin off the exchanges. This is actually the safer way to play it, except when you fall prey to a phishing campaign to lure you to a fake site to update your firmware that instead, drains your wallet. Unfortunately even when employing a hardware wallet, you still have be on your guard ... View Post
How Cybercriminals Profit by Tapping Your Email
A few days ago I came across the CBC story on how a Canadian man had been defrauded out of $800,000 when cybercriminals inserted themselves into a real estate deal and had the funds diverted to themselves: ... View Post
Microsoft hoses own DNS causing global service outage
Yet another example of how nobody, regardless of size, resources nor expertise, is immune from DNS outages. Last week several Microsoft systems experienced a global outage when the company made a configuration error whilst migrating some legacy, infrastructure domains, to their own Azure platform. The errors had second-order effects within the Azure ecosystem ... View Post
Why You Must Learn to Love DNSSEC
(This is a reprint of an article originally run on our parent company's blog in June 2018). It’s been nearly two months since the high profile BGP hijack attack against MyEtherwallet, where crypto thieves used BGP leaks to hijack MEW’s name servers, which were on Amazon’s Route53, and inserted their own fake name servers which directed victims to ... View Post
A Deep Dive into the Mirai Botnet Attack
As we all know, on Friday Oct 21, 2016 DNS provider Dynect was severely impacted by a big DDoS attack which has since been attributed to the Mirai Botnet. (interesting to note that “Mirai” means “future” in Japanese). Briefly: The Mirai Botnet is constructed by commandeering network connected Internet of Things (IoT) devices such as remote cameras, or any other ... View Post