Cookie Consent by Free Privacy Policy Generator Update cookies preferences 📌 How Wi-Fi Spy Drones Snooped On Financial Firm

🏠 Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeiträge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden Überblick über die wichtigsten Aspekte der IT-Sicherheit in einer sich ständig verändernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch übersetzen, erst Englisch auswählen dann wieder Deutsch!

Google Android Playstore Download Button für Team IT Security



📚 How Wi-Fi Spy Drones Snooped On Financial Firm


💡 Newskategorie: IT Security Nachrichten
🔗 Quelle: mobile.slashdot.org

An anonymous reader quotes a report from The Register: Modified off-the-shelf drones have been found carrying wireless network-intrusion kit in a very unlikely place. Greg Linares, a security researcher, recently recounted an incident that he said occurred over the summer at a US East Coast financial firm focused on private investment. He told The Register that he was not involved directly with the investigation but interacted with those involved as part of his work in the finance sector. In a Twitter thread, Linares said the hacking incident was discovered when the financial firm spotted unusual activity on its internal Atlassian Confluence page that originated from within the company's network. The company's security team responded and found that the user whose MAC address was used to gain partial access to the company Wi-Fi network was also logged in at home several miles away. That is to say, the user was active off-site but someone within Wi-Fi range of the building was trying to wirelessly use that user's MAC address, which is a red flag. The team then took steps to trace the Wi-Fi signal and used a Fluke system to identify the Wi-Fi device. "This led the team to the roof, where a 'modified DJI Matrice 600' and a 'modified DJI Phantom' series were discovered," Linares explained. The Phantom drone was in fine condition and had a modified Wi-Fi Pineapple device, used for network penetration testing, according to Linares. The Matrice drone was carrying a case that contained a Raspberry Pi, several batteries, a GPD mini laptop, a 4G modem, and another Wi-Fi device. It had landed near the building's heating and ventilation system and appeared to be damaged but still operable. "During their investigation, they determined that the DJI Phantom drone had originally been used a few days prior to intercept a worker's credentials and Wi-Fi," Linares said. "This data was later hard coded into the tools that were deployed with the Matrice." According to Linares, the tools on the drones were used to target the company's internal Confluence page in order to reach other internal devices using the credentials stored there. The attack, he said, had limited success and is the third cyberattack involving a drone he's seen over the past two years. "The attackers specifically targeted a limited access network, used by both a third-party and internally, that was not secure due to recent changes at the company (e.g. restructuring/rebranding, new building, new building lease, new network setup or a combination of any of these scenarios)," Linares told The Register. "This is the reason why this temporary network unfortunately had limited access in order to login (credentials + MAC security). The attackers were using the attack in order to access an internal IT confluence server that contained other credentials for accessing other resources and storing IT procedures." [...] While the identity of the attacker has not been disclosed, Linares believes those responsible did their homework. "This was definitely a threat actor who likely did internal reconnaissance for several weeks, had physical proximity to the target environment, had a proper budget and knew their physical security limitations," he said.

Read more of this story at Slashdot.

...



📌 How Wi-Fi spy drones snooped on financial firm


📈 65.73 Punkte

📌 How Wi-Fi Spy Drones Snooped On Financial Firm


📈 65.73 Punkte

📌 Taylor's gonna spy, spy, spy, spy, spy... fans can't shake cam off, shake cam off


📈 50.67 Punkte

📌 2018 Unmanned Security Expo Review - Drones, Drones, and more Drones.


📈 39.69 Punkte

📌 Discord dismantles Spy.pet site that snooped on millions of users


📈 34.81 Punkte

📌 Judge to interview Assange over claims Spanish security firm snooped on him during Ecuador embassy stint


📈 33.45 Punkte

📌 Spy vs Spy vs Spy as Israel Watches Russian Hackers: NYT


📈 30.4 Punkte

📌 Mozilla Removes 23 Firefox Add-Ons That Snooped on Users


📈 24.67 Punkte

📌 Mozilla Removes 23 Firefox Add-Ons That Snooped on Users


📈 24.67 Punkte

📌 Popular Wireless Keyboards From HP, Toshiba and Others Don't Use Encryption, Can Be Easily Snooped On


📈 24.67 Punkte

📌 Bandersnatch to gander snatched: Black Mirror choices can be snooped on, thanks to privacy-leaking Netflix streams


📈 24.67 Punkte

📌 Cop awarded $585K after colleagues snooped on her via license database


📈 24.67 Punkte

📌 Amazon Ring employees snooped on users’ security videos


📈 24.67 Punkte

📌 Wi-Fi of more than a billion PCs, phones, gadgets can be snooped on. But you're using HTTPS, SSH, VPNs... right?


📈 24.67 Punkte

📌 S3 Ep24: How not to get snooped, scammed or hoaxed [Podcast]


📈 24.67 Punkte

📌 Popular Wireless Keyboards From HP, Toshiba and Others Don't Use Encryption, Can Be Easily Snooped On


📈 24.67 Punkte

📌 HipChat Got Hacked, Some Conversations Got Snooped On


📈 24.67 Punkte

📌 Compromised Chrome Extension Snooped on Users’ Credentials, Cryptocurrency Private Keys


📈 24.67 Punkte

📌 YouTube Acquisition Nearly Fell Apart When Cofounder Found That a Google Employee Snooped on Revenue Figures


📈 24.67 Punkte

📌 France to tack weapons onto spy drones – reports


📈 23.36 Punkte

📌 NYPD Spy Drones Fly into Privacy Headwinds


📈 23.36 Punkte

📌 As Uncle Sam flies spy drones over protest-packed cities, Homeland Security asks the public if that's a good idea


📈 23.36 Punkte

📌 Airborne Drones Are Dropping Cyber-Spy Exploits in the Wild


📈 23.36 Punkte

📌 How Spy Agencies Hacked into Israeli Military Drones to Collect Live Video Feeds


📈 23.36 Punkte

📌 How Spy Agencies Hacked into Israeli Military Drones to Collect Live Video Feeds


📈 23.36 Punkte

📌 DJI fixes vulnerability that let potential hackers spy on drones


📈 23.36 Punkte

📌 Vulnerability Could Make DJI Drones a Spy In the Sky


📈 23.36 Punkte

📌 'We're Not Being Paranoid': US Warns Of Spy Dangers Of Chinese-Made Drones


📈 23.36 Punkte

📌 Spy vs spy vs hacker vs... who is THAT? Everyone's hacking each other


📈 20.27 Punkte

📌 34C3 - Spy vs. Spy: A Modern Study Of Microphone Bugs Operation And Detection - La traducción españ


📈 20.27 Punkte

📌 34C3 - Spy vs. Spy: A Modern Study Of Microphone Bugs Operation And Detection - deutsche Übersetzun


📈 20.27 Punkte

📌 34C3 - Spy vs. Spy: A Modern Study Of Microphone Bugs Operation And Detection


📈 20.27 Punkte

📌 Spy vs. Spy – “Cozy Bear” election hackers undone by hackable security camera


📈 20.27 Punkte

📌 Hack to Spy: Building a Raspberry Spy Pi


📈 20.27 Punkte

📌 DEF CON 27 IoT Village - Michael Raggo - Spy versus Spy who is watching who


📈 20.27 Punkte











matomo