TA15-240A: Controlling Outbound DNS Access

Original release date: August 28, 2015 Systems Affected Networked systems Overview US-CERT has observed an increase in Domain Name System (DNS) traffic from client systems within internal networks to publically hosted DNS servers. Direct client access to Internet DNS servers, rather than controlled access through enterprise DNS servers, can expose an organization to unnecessary security…

Read More

Regin: Further unravelling the mysteries of a cyberespionage threat

Symantec’s investigation uncovers additional modules for the Regin spying tool and finds advanced infrastructure supporting it. Twitter Card Style:  summary Symantec’s continuing investigation into the Regin Trojan has cast new light on the cyberespionage tool, revealing a wider range of capabilities and a complex infrastructure supporting the threat.  read more Source: Symantec

Read More

Sundown exploit kit adds Internet Explorer exploit before any other kit

The Sundown exploit kit has been the first to integrate an exploit for the CVE 2015-2444 bug, using it in a recent watering-hole attack. Twitter Card Style:  summary While tracking exploit activity, Symantec found that the Sundown exploit kit (EK) has started to take advantage of a recent Internet Explorer vulnerability known as CVE-2015-2444. read…

Read More