Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
New Malware Found Hiding Inside Image Files
Newest First  |  Oldest First  |  Threaded View
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/22/2015 | 1:23:27 PM
Re: Nothing new here?
I agree. We just need to know what paths do these malwares are coming so we can take more precise preventive actions instead of playing catchup game.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/22/2015 | 1:21:52 PM
Re: Ingenuity
I agree it starts with simple root cause and goes into a bigger problem. That is the main reason whatever we do we have to a have layered approach.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/22/2015 | 1:20:26 PM
Re: Ingenuity
Sure. They have incentive to outsmart security professionals in a way that they are always ahead of all of us. That is the main problem with the security measures it is always trying to catch up.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/22/2015 | 1:18:03 PM
steganography
 

One of the oldest technique to hide information inside an image.  They do it in a way that the checksum on the image is not resulting into a different number so it is really hard to catch.
GwenGo
50%
50%
GwenGo,
User Rank: Apprentice
6/18/2015 | 7:06:49 AM
Re: Ingenuity
Thank you for this article on malwares.
I really hope to protect myself against these intrusions but it's hard ...
BertrandW414
50%
50%
BertrandW414,
User Rank: Strategist
6/17/2015 | 4:39:25 PM
Re: Ingenuity
Yes Whoopty, now that would be a great use of our H1B visa system! It is too bad that some of these people working in hacker groups or cartels would probably feel that trying to leave and become legit would put their lives or physical well-being in jeopardy. They might also be worried about getting abducted by an organization in our intelligence community and getting "aggreessively interviewed" for contacts, techniques, and other useful information. 
savoiadilucania
50%
50%
savoiadilucania,
User Rank: Moderator
6/17/2015 | 11:52:56 AM
Nothing new here?
While a novel way to effect a network attack, the attack vector and countermeasures remain the same. The adversary has to introduce and execute malcode. Whether that malcode is obfuscated using steganography or appended to a legitimate document is largely irrelevant. And making that determination is quite frankly a fruitless endeavor granted the panoply of evasion mechanisms available. The focus needs to be on the execution chain.
Mark532010
50%
50%
Mark532010,
User Rank: Moderator
6/17/2015 | 11:03:19 AM
Re: Ingenuity
you are right on in that statement. While zero-day and these super-sophisticated attacks gain all the media and keep people awake at night, the reality is that 90+% of breakins are simple basic security 101 problems. users with admin rights, default passwords, no encryption, lax controls or controls that are never actually used, home-grown apps that have never been pen-tested, etc.
Whoopty
100%
0%
Whoopty,
User Rank: Ninja
6/17/2015 | 6:26:37 AM
Ingenuity
The ingenuity of malware makers always impresses me. I'm sure many of them could secure gigs at security outfits or firms that require high-end digital security. They wouldn't even need to be world class, as so many firms seem to have such lax digital defences. 


News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-3493
PUBLISHED: 2021-04-17
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivile...
CVE-2021-3492
PUBLISHED: 2021-04-17
Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (ker...
CVE-2020-2509
PUBLISHED: 2021-04-17
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later Q...
CVE-2020-36195
PUBLISHED: 2021-04-17
An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia C...
CVE-2021-29445
PUBLISHED: 2021-04-16
jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDe...