{"id":47,"date":"2018-10-24T17:57:50","date_gmt":"2018-10-24T17:57:50","guid":{"rendered":"http:\/\/news.nucleon.sh\/?p=47"},"modified":"2019-01-16T10:46:12","modified_gmt":"2019-01-16T10:46:12","slug":"xx-cyber-intelligence-news","status":"publish","type":"post","link":"https:\/\/news.nucleon.sh\/ko\/2018\/10\/24\/xx-cyber-intelligence-news\/","title":{"rendered":"25-10-18 Cyber Intelligence news"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">This article will give you a brief summary of the latest news related to cyber intelligence and proactive cyber security.<\/span><\/p>\n\n\n\n<figure class=\"wp-block-embed-soundcloud wp-block-embed is-type-rich is-provider-soundcloud wp-embed-aspect-4-3 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<a href=\"https:\/\/soundcloud.com\/user-705652236\/cybercure9-mixdown-1\" rel=\"nofollow\">https:\/\/soundcloud.com\/user-705652236\/cybercure9-mixdown-1<\/a>\n<\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><em><strong>The bitcoin network vulnerability<\/strong><\/em><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">Everyone knows about bitcoin, and almost everyone has their own strong opinion about it. Some love it, some hate it, but nobody is apathetic toward it.<\/span><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignleft\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"660\" height=\"495\" data-attachment-id=\"49\" data-permalink=\"https:\/\/news.nucleon.sh\/ko\/2018\/10\/24\/xx-cyber-intelligence-news\/achievement-bank-bitcoin-730567\/\" data-orig-file=\"https:\/\/i0.wp.com\/news.nucleon.sh\/wp-content\/uploads\/2018\/10\/achievement-bank-bitcoin-730567.jpg?fit=4032%2C3024&amp;ssl=1\" data-orig-size=\"4032,3024\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"achievement-bank-bitcoin-730567\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/news.nucleon.sh\/wp-content\/uploads\/2018\/10\/achievement-bank-bitcoin-730567.jpg?fit=660%2C495&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/news.nucleon.sh\/wp-content\/uploads\/2018\/10\/achievement-bank-bitcoin-730567.jpg?resize=660%2C495&#038;ssl=1\" alt=\"achievement-bank-bitcoin-730567.jpg\" class=\"wp-image-49\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">Many people have concerns about digital currency, and what might happen if hackers were to abuse it.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">Last month we saw the potential of this happening.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">Bitcoins are generated by computers running complicated algorithms that require lots of computing power and resources. The people\/companies who produce the bitcoins are called miners, since they \u2018mine\u2019 the Bitcoins using algorithms, then pass them along the network to what are known as nodes.<\/span><span style=\"font-weight:400;\"><br>\n<\/span><span style=\"font-weight:400;\">It was discovered that a Distributed-Denial-of-Service (DDoS) vulnerability had the potential to bring down the entire Bitcoin network by allowing miners to send transaction data to the nodes too many times.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">This scenario would create a situation where the nodes would try to validate duplicate transaction values, causing the network to be crippled.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">Taking advantage of this vulnerability requires the use real Bitcoins, which makes it a very expensive attack for small attackers, but probably not too expensive for state-sponsored attacks that have much more resources.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">Luckily for us, the patch has already been released and the Bitcoin network is once again safe from the threats we know about.<\/span><\/p>\n\n\n\n<!--more-->\n\n\n\n<h3 class=\"wp-block-heading\"><em><strong>Bristol Airport Ransomware Attack<\/strong><\/em><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">During September 2018 the display screens showing the flight schedule in Bristol airport displayed a technical error with a blue screen behind it. If you remember, in a previous <\/span><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignleft\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"660\" height=\"495\" data-attachment-id=\"51\" data-permalink=\"https:\/\/news.nucleon.sh\/ko\/2018\/10\/24\/xx-cyber-intelligence-news\/aeroplane-aircraft-airplane-46148-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/news.nucleon.sh\/wp-content\/uploads\/2018\/10\/aeroplane-aircraft-airplane-461481.jpg?fit=3000%2C2250&amp;ssl=1\" data-orig-size=\"3000,2250\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"aeroplane-aircraft-airplane-46148\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/news.nucleon.sh\/wp-content\/uploads\/2018\/10\/aeroplane-aircraft-airplane-461481.jpg?fit=660%2C495&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/news.nucleon.sh\/wp-content\/uploads\/2018\/10\/aeroplane-aircraft-airplane-461481.jpg?resize=660%2C495&#038;ssl=1\" alt=\"aeroplane-aircraft-airplane-46148.jpg\" class=\"wp-image-51\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">podcast related to airport security we discussed multiple attacks like this in Vietnam, Iran, and more international airports.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">At the time, The airport tweeted a message to its clients, saying that they were experiencing technical problems and flights were not affected by it.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">A few days after getting back online, the airport spokesman revealed to the BBC that <\/span><span style=\"font-weight:400;\">the information screens were taken offline to contain an attack similar to so-called &#8220;ransomware&#8221;.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">Ransomware is a form of malware in which computer viruses threaten to delete files unless a ransom is paid.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">The system went back on functioning after 3 days, during which the digital screens were replaced with good old whiteboard papers.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">What caught our attention in this case is the fact the airport officially stated that a malware attack was able to break its defences and to solve the problem they paid the ransom.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">So it makes one wonder, if this airport got infected by simple malware, what other surprises do they already have in their systems that they don&#8217;t know about yet?<\/span><\/p>\n\n\n\n<!--more-->\n\n\n\n<h3 class=\"wp-block-heading\"><em>IRS phishing&nbsp;campaign<\/em><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">The Fortiguard research team reported a sophisticated phishing campaign targeting alien, or foreign US citizens.<\/span><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignleft\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"660\" height=\"441\" data-attachment-id=\"52\" data-permalink=\"https:\/\/news.nucleon.sh\/ko\/2018\/10\/24\/xx-cyber-intelligence-news\/ballpen-close-up-desk-955389\/\" data-orig-file=\"https:\/\/i0.wp.com\/news.nucleon.sh\/wp-content\/uploads\/2018\/10\/ballpen-close-up-desk-955389.jpg?fit=6016%2C4016&amp;ssl=1\" data-orig-size=\"6016,4016\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"ballpen-close-up-desk-955389\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/news.nucleon.sh\/wp-content\/uploads\/2018\/10\/ballpen-close-up-desk-955389.jpg?fit=660%2C441&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/news.nucleon.sh\/wp-content\/uploads\/2018\/10\/ballpen-close-up-desk-955389.jpg?resize=660%2C441&#038;ssl=1\" alt=\"ballpen-close-up-desk-955389.jpg\" class=\"wp-image-52\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">In law, an alien generally refers to any person who is not a citizen or national of a given country.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">To begin with, the email was aimed for people who are less familiar with how the bureaucracy works. This email looked like it was officially sent by the Department of the Treasury, with a form attached aimed at non citizens living in the USA to reduce its taxes, and trying to lure the user to fill out the details.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">The IRS never contacts tax payers by email, but this email was carrying what looked like an official W8 form, which is aimed at people for whom English is not thier first language. This made them an easier target, and they might not detect the small typos the email and form had.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">This campaign launched from servers located in Italy, but it is unknown who was behind this attack and if those servers were just used as the distribution point by someone else from different country.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">To avoid sophisticated scams like that you should pay attention to the small details.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">For example, the IRS will never threaten someone that they will go to jail, or that immigration authorities will be called. You can find more details about this on their website.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">The IRS released an official warning on their web site several months ago; you can read on it on their website for more details.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">That\u2019s it for this time.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">Stay safe and see you at the next podcast. Don\u2019t forget to visit&nbsp;<\/span><a href=\"http:\/\/www.cybercure.ai\"><span style=\"font-weight:400;\">www.cybercure.ai<\/span><\/a><span style=\"font-weight:400;\"> for the latest podcasts and cyber intelligence.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"font-weight:400;\">&#8212;-<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This podcast cover the following topics:<br \/>\n* The bitcoin network vulnerability<br \/>\n* Bristol Airport hack<br \/>\n*Sophisticated phishing campaign<\/p>\n","protected":false},"author":143072865,"featured_media":49,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","_crdt_document":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_wpas_customize_per_network":false,"jetpack_post_was_ever_published":false},"categories":[],"tags":[3556,36507086,70136,64500,7649,21013,1142],"class_list":["post-47","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","tag-airport","tag-bitcoin","tag-bristol","tag-ddos","tag-irs","tag-phishing","tag-podcast","entry-image--landscape"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/news.nucleon.sh\/wp-content\/uploads\/2018\/10\/achievement-bank-bitcoin-730567.jpg?fit=4032%2C3024&ssl=1","jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paa2yX-L","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/news.nucleon.sh\/ko\/wp-json\/wp\/v2\/posts\/47","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/news.nucleon.sh\/ko\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news.nucleon.sh\/ko\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news.nucleon.sh\/ko\/wp-json\/wp\/v2\/users\/143072865"}],"replies":[{"embeddable":true,"href":"https:\/\/news.nucleon.sh\/ko\/wp-json\/wp\/v2\/comments?post=47"}],"version-history":[{"count":5,"href":"https:\/\/news.nucleon.sh\/ko\/wp-json\/wp\/v2\/posts\/47\/revisions"}],"predecessor-version":[{"id":402,"href":"https:\/\/news.nucleon.sh\/ko\/wp-json\/wp\/v2\/posts\/47\/revisions\/402"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news.nucleon.sh\/ko\/wp-json\/wp\/v2\/media\/49"}],"wp:attachment":[{"href":"https:\/\/news.nucleon.sh\/ko\/wp-json\/wp\/v2\/media?parent=47"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news.nucleon.sh\/ko\/wp-json\/wp\/v2\/categories?post=47"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news.nucleon.sh\/ko\/wp-json\/wp\/v2\/tags?post=47"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}