Security Leftovers
-
GRU: Rise of the (Telegram) MinIOns | Mandiant
Mandiant is tracking multiple self-proclaimed hacktivist groups working in support of Russian interests. These groups have primarily conducted distributed denial-of-service (DDoS) attacks and leaked stolen data from victim organizations. Although some of these actors are almost certainly operating independently of the Russian state, we have identified multiple so-called hacktivist groups whose moderators we suspect are either a front for, or operating in coordination with, the Russian state.
-
Authenticated SMTP and IMAP authentication attacks and attempts we see here
A while back I wrote about how large scale SSH brute force attacks seem to have stopped here. SSH isn't the only form of authentication that we have exposed to the Internet; we also have both an IMAP server and an authenticated SMTP server, and unsurprisingly they also seem activity. To my surprise, the activity patterns are quite different (which took some time to discover, since they both actually authenticate through Dovecot).
Our authenticated SMTP server sees widespread and determined probes from a wide range of IP addresses that appear to be attempting to brute force email addresses here; basically the kind of activity that I expected to see for SSH. However, many of these brute force attacks have no chance of success because they're being directed against either logins that no longer exist or email addresses that were never logins in the first place, and were only aliases or mailing lists. The obvious guess is that attackers targeting authenticated SMTP simply scrape every From: address from your domain that they can find and then set their hordes loose on brute force attacks.
-
First Alpha Release of PowerDNS Recursor 4.8.0 | PowerDNS Blog
We are proud to announce the first alpha release of PowerDNS Recursor 4.8.0.