Radware Threat Researchers Live - ep.13 - Mozi, Weaponizing Middleboxes, Hotcobalt, Dark.IoT



We are back! Join us this Thursday, August 26th. We go live at 4pm Paris, 10am New York, 7am Los Angeles, 11pm Tokyo. --- Links and Resources Mozi botnet gains the ability to tamper with its victim’s traffic https://twitter.com/360Netlab/status/1420390398825058313 https://therecord.media/mozi-botnet-gains-the-ability-to-tamper-with-its-victims-traffic/ https://www.microsoft.com/security/blog/2021/08/19/how-to-proactively-defend-against-mozi-iot-botnet/ Another World Record DDoS Attack https://blog.cloudflare.com/cloudflare-thwarts-17-2m-rps-ddos-attack-the-largest-ever-reported/ HTTP middlebox reflection/amplification https://geneva.cs.umd.edu/posts/usenix21-weaponizing-censors/ https://www.youtube.com/watch?v=OSfgTbjb3og https://geneva.cs.umd.edu/papers/usenix-weaponizing-ddos.pdf https://github.com/breakerspace/weaponizing-censors https://www.radware.com/security/ddos-threats-attacks/threat-advisories-attack-reports/tcp-reflection-attacks Hotcobalt https://labs.sentinelone.com/hotcobalt-new-cobalt-strike-dos-vulnerability-that-lets-you-halt-operations/ IPstress.in publishes press release https://www.digitaljournal.com/pr/ipstress-offers-one-of-the-finest-ddos-for-hire-service Dark.IoT botnet https://www.radware.com/security/threat-advisories-and-attack-reports/dark-iot-botnet https://www.theregister.com/2021/08/25/mirai_botnet_critical_vuln_realtek_radware/ https://blogs.juniper.net/en-us/security/freshly-disclosed-vulnerability-cve-2021-20090-exploited-in-the-wild https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/ https://www.tenable.com/security/research/tra-2021-13 https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain/ Azure PowerApp data leaks https://www.upguard.com/breaches/power-apps https://www.theregister.com/2021/08/23/power_shell_records/ FBI terrorist watchlist leaked online https://www.bleepingcomputer.com/news/security/secret-terrorist-watchlist-with-2-million-records-exposed-online/ https://therecord.media/1-9-million-records-from-the-fbis-terroris-watchlist-leaked-online/ --- Presentations and resources from past episodes: https://discover.radware.com/l/threat-intelligence Security reports, alerts, advisories and earlier episodes: https://www.radware.com/security/


Comments