Lucian Constantin Lucian has been covering computer security and the hacker culture for almost a decade, his work appearing in many technology publications including PCWorld, Computerworld, Network World, CIO, CSO, Forbes and The Inquirer. He has a bachelor's degree in political science, but has been passionate about computers and cybersecurity from an early age. Before he chose a career in journalism, Lucian worked as a system and network administrator. He enjoys attending security conferences and delving into interesting research papers. You can reach him at lucian@constantinsecurity.com or @lconstantin on Twitter. For encrypted email, his PGP key's fingerprint is: 7A66 4901 5CDA 844E 8C6D 04D5 2BB4 6332 FC52 6D42
Lucian Constantin
Destructive Shamoon Malware Hits Italian Oil and Gas Firm
Lucian Constantin | | disk wiper, office 365, Oil and Gas, Phishing, Saipem, saudi arabia, Saudi Aramco, Shamoon
Hackers hit the IT infrastructure of an Italian oil and gas company with a new version of a destructive malware program called Shamoon. Shamoon, also known as Disttrack, was first used in 2012 in attacks against Saudi Aramco, Saudi Arabia’s national oil and gas company, and then again in 2016 ... Read More
Security Boulevard
Microsoft Patches Another Actively Exploited Zero-Day Vulnerability
Microsoft released security updates for its products Dec. 11, fixing 38 vulnerabilities including a privilege escalation flaw in the Windows kernel that has been exploited by cyberespionage groups since October. The zero-day vulnerability, tracked as CVE-2018-8611, was reported to Microsoft by researchers from Kaspersky Lab who saw it being used ... Read More
Security Boulevard
Attack Kit Hijacks DNS of Home and Business Routers
Lucian Constantin | | adobe, arbitrary code execution, CSRF attack, DNS hijacking, Exploit Kit, Novidade, router compromise, security update
For the past year, attackers have been using an exploit kit that changes the DNS settings of home and small-business routers through users’ browsers. The tool, dubbed Novidade, was first used in Brazil in August 2017, but researchers from antivirus firm Trend Micro have identified multiple variants since then and ... Read More
Security Boulevard
Two Dozen Click Fraud Apps Found in Google Play
Lucian Constantin | | android malware, click-fraud, cryptomining, Google Play, IoT botnet, linux malware, rabbit, Rabbot
Attackers managed to pass Google’s defenses and place 22 Android apps on Google Play that engaged in sophisticated advertising click fraud when installed on users’ phones. The majority of the apps were created after June 2018 and were collectively downloaded more than 2 million times until their removal around Nov ... Read More
Security Boulevard
Email Spam Campaign Targets U.S. Retail, Restaurant Sectors
Lucian Constantin | | botnet, FlawedAmmyy, malicious document, phishing email, Remote Manipulator System, retail sector, trojan program, wordpress
A cybercriminal group has launched a malware campaign via personalized spear-phishing emails against large retail, restaurant and grocery chains in the United States, as well as against other organizations from the food and beverage industries. The spam campaigns, which distributed several Trojans including Remote Manipulator System (RMS) and FlawedAmmyy, were ... Read More
Security Boulevard
North Korean APT Group Targets Academia via Malicious Chrome Extensions
Lucian Constantin | | APT group, Chrome extension, credential theft, Flash Player, Remote Desktop Protocol, Stolen Pencil, Zero-day Exploit
Security researchers have uncovered an APT group with possible ties to North Korea that has targeted academic institutions since May. The group, dubbed Stolen Pencil by researchers from Netscout, send spear-phishing emails which direct users to a website that asks them to install a “font manager” Chrome extension in order ... Read More
Security Boulevard
Business Email Compromise Gang Targeted 50,000 Company Executives
Lucian Constantin | | business email compromise, compute node, container orchestration, Kubernetes, London Blue, Phishing, Privilege Escalation
A Nigerian gang with members based in the U.K. is perpetrating a business email compromise operation aimed squarely at executives at companies with locations worldwide. The gang has compiled a target list of 50,000 email addresses belonging to company executives, the majority of them chief financial officers. Researchers from email ... Read More
Security Boulevard
Czech Republic Blames Russia for Yearlong Email Breach
Lucian Constantin | | APT28, APT29, CozyBear, cyberespionage, Czech Republic, intelligence service, Russia, Sofacy, Turla
The Czech government’s Security Information Service (BIS) revealed in a report that hackers associated with the Russian government are responsible for an email breach, compromising the email system of the country’s Ministry of Foreign Affairs (MFA) and reading sensitive communications for more than a year. According to the new report, ... Read More
Security Boulevard
Hackers Exploit UPnP in Routers to Expose Private Networks to Attacks
Lucian Constantin | | EternalSilence, network video recorder, NVRMini2, SMB exploit, UPnP, UPnP injection, UPnProxy
Hackers are exploiting insecure UPnP implementations in routers to expose millions of computers from inside private networks to SMB attacks. Universal Plug and Play (UPnP) is a service that allows devices to discover each other inside local networks and automatically open ports for data sharing, media streaming and other services ... Read More
Security Boulevard
U.S. Charges Two Iranians for SamSam Ransomware Attacks
The U.S. Department of Justice has charged two Iranian men for creating and distributing a ransomware program called SamSam that caused massive disruptions in hospitals, municipalities and public institutions over the past few years. SamSam appeared in late 2015 and immediately stood out because, unlike most ransomware at the time ... Read More
Security Boulevard
