[ Team Cymru Community Services ] [ Team Cymru Commercial Services ] [ Dragon Research Group ]
State Bank launches Virtual card to curb online frauds "For people who are scared of using their debit and credit cards or Internet banking for online shopping due to fear of fraud, the State Bank of India(SBI) has introduced a virtual debit card called State Bank Virtual that addresses all such concerns...." (more) | SSCC 91 - Utah explains data breach, Facebook hacker jailed, FlashBack removal for Leopard, "Gary Korhonen joined me on this week's Chet Chat as we return to our normal format of covering the most important security news of the week...." (more) | CISO 2.0: Enterprise Umpire or Wide Receiver? "CISO 2...." (more) | Dutch Military Intelligence Dives into Cyber "The Dutch Military Intelligence agency (MIVD) recently released its 2011 yearly report (in Dutch)...." (more) | Twitter Commits to Respecting Do Not Track with New Policy "Under a new policy announced recently, Twitter will be suggesting accounts for Twitter users to follow based on data collected from an individuals browsing habits on websites that have embedded Twitter buttons...." (more) | US vs. China: Is the Cyber Warfare Gap Increasing? "Chinese offensive capabilities in cyberspace are more than ever the subject of great interest by the international community which fears the rise of China as a technological colossus...." (more) | Off Topic: What to do about Conspiracy Theorists? "I received an alert recently about an article dealing with Electronic Warfare or EW...." (more) | Security Developments Involving the Peoples Republic of China "The Department of Defense has released the annual report regarding "Military and Security Developments Involving the Peoples Republic of China 2012" in accordance with the National Defense Authorization Act...." (more) | Incorporating security concepts into hospital construction "Lauris Freidenfelds, security director at Rush University Medical Center, discusses how he incorporated security concerns into the construction of a brand new hospital facility, and offers advice for security managers looking for buy-in from administrators...." (more) | Why profiling at airports is a bad idea "Bruce Schneier makes a strong argument against the case for profiling at U.S. airports in his column for Forbes...." (more) | RCMP dismantle international crime ring responsible for C$ 100 million fraud "On 9th May 2012 the Royal Canadian Mounted Police (RCMP) executed 61 arrest warrants in the Greater Montreal and northern fringe areas for alleged involvement in a major international payment card fraud ring...." (more) | MasterCard to foster industry collaboration in preparation for EMV switch "MasterCard today suggested the creation of a cross-industry group aimed at fostering collaboration and alignment between issuers, merchants, networks, processors, card and terminal manufacturers along with other groups in the implementation of EMV technology in the US (view press release)...." (more) | Bank of China launches online banking system using Customer Enterprise "Bank of China has launched an online banking system powered by Customer Enterprise, a solution provided by China Systems (view press release)...." (more) | Protecting SCADA Systems with Air Gaps is a Myth "SCADA security expert Eric Byres of Tofino Security had harsh words for the proponents of "air gapping" networks that control critical infrastructure and production at the recent AusCERT conference...." (more) | WikiLeaks Announces 'New Encrypted Facebook' "The WikiLeaks Twitter feed announced on 20 May 2012 that the WL Friends/Friends of WikiLeaks (FoWL) network is ready to launch an 'encrypted Facebook'...." (more) | Hard Power, Soft Power, and the Power of Digital Espionage ""Hard power is a term used in international relations...." (more) | Online Fraudsters Exposed: Learn How to Investigate Cyber Crimes on Auction Platforms "The McAfee Institute brings to you this exciting comprehensive course, E-Crime Online Investigation Methodologies, brings together 15 years of cyber intelligence, loss prevention and law enforcement experience to illustrate and teach you the necessary skills to conduct successful online investigations in an effort to isolate organized retail crime rings, fraudsters, and employee theft...." (more) | T-Mobile slip exposes 1,100 punters' email addresses "Subscribers to T-Mobile's Hothouse - a focus group-like mailing list - got an added benefit this morning: the email addresses of everyone else on the list...." (more) | Telecoms accused of ambushing internet through rule change "Telecommunications regulations, set for an overhaul later this year, could be expanded to give the mobile sector sweeping new powers over the internet, international leading players representing the web have claimed...." (more) | Who is attacking WikiLeaks and The Pirate Bay? The private revenge "Who is attacking WikiLeaks and The Pirate Bay?..." (more) | Another NHS trust coughs up 90k fine for lax fax acts "The taxpayer-backed NHS has suffered another fine from the Information Commissioner's Office (ICO) for outing patients' private information to the wrong people...." (more) | Thomson's high-tech conspiracy claims questioned "Phone cloning and identity theft were two offerings made by suspended MP Craig Thomson in his attempt to explain how escorts were booked through his mobile phone during a statement to Parliament...." (more) | Measuring Security? In the Electric Sector? Are you Serious? Someone Is "Tried making the case most recently with Time for Electric Sector to Measure Up on Security and Smart Grid Security Truth: You Can't Do What You Don't Measure but couldn't detect a measurable response...." (more) | HSBC IT failure hits ATMs and card payments, tests social media strategy "Some UK HSBC customers were left unable to make card payments or withdraw cash from ATMs yesterday thanks to an IT hardware failure...." (more) | US student jailed over Tyler Clementi webcam case "A former Rutgers University student who used a webcam to watch his roommate kiss another man days before the roommate killed himself has been sentenced to 30 days in jail...." (more) |
The @dragonresearch guide to using PGP: http://t.co/s0rnzvDO | #infosec art: list of great tools to creating meaningful and beautiful data visualizations http://t.co/IyrZVYYZ | SANS: Windows PHP 5.4 Remote Exploit PoC in the wild http://t.co/S7mW5z4o | Check if you are IPv6 Ready, better late than never... http://t.co/E20Cwo1l | very bad news: how to clone RSA SecureID software tokens http://t.co/fWfJLVbl | Imperva releases HULK (Http Unbearable Load King): Python-based DOS tool for 'educational and research purposes only' http://t.co/kRKTGYFi | did Iran's 'Cyber Warriors Team' compromise an SSL cert got NASA's Research and Education Support Dept, last week? http://t.co/blh7rZQs | UK's Gareth Crosskey sent to prison for a year for #hacking a Facebook account http://t.co/eFKYPYnP | our take on #malware risks whilst traveling: sometimes they ARE out to get you, here are some easy tips http://t.co/OEBq1ydN | paper: Prolexic's "play book" on how to respond to a DDoS attack http://t.co/13xQywyS | various Podcasts from AusCert 2012 conference here: http://t.co/BMiemvk1 | does Pastebin worry you? If so, then you'd better not see this list of alternatives: http://t.co/PIEVFcdc | Microsoft: we just added a SCADA/smart-grid supplier + Indian govt to Secure Development Lifecycle (SDL) program http://t.co/fmhM1nEo | Are you in Geneva at the ITU's WSIS2012 event? We're presenting on Satellite imagery and the risks of illicit use in about 20 minutes! | writing #malware reports 101: what goes in? http://t.co/dLmWkPvx |
Episode 107: DDoS mitigation & visualization + conference and training updates YouTube RSS Feed Twitter

Recent Data

[ Data Page 1 ] [ Data Page 2 ] [ Data Page 3 ] [ Data Page 4 ] [ Data Page 5 ]

Sampled Internet Traffic Rate (hourly)

We receive sampled and generalized information about Internet traffic flow rates from many partners, and this chart reflects those rates over the past week, aggregated hourly. This is by no means the "full speed" of the Internet, but a way of seeing trends and patterns within the overall mix of traffic.

View all available monitoring graphs

Top 10 TCP Ports (logarithmic scale)

This chart shows the top 10 TCP ports seen in sampled global Internet traffic in our most recent hourly data sample. This chart is on a logarithmic scale, so the difference between the top port (usually TCP/80) and the bottom port may be more significant than it appears to the naked eye.

View all available monitoring graphs

Daily DDoS Attacks

Our malicious activity monitoring includes insight into distributed denial of service (DDoS) attacks launched by various botnets around the globe. This chart indicates the number of attacks seen each day across a subset of our monitoring infrastructure, giving some insight into trends and patterns in miscreant activity.

View all available monitoring graphs

Bot Activity, Top 10 Countries

This chart lists the top 10 countries seen contributing to botnet activity online in the last 24 hours, as a percentage relative to total malicious activity in the same period. IP geolocation isn't perfect, so this data isn't exact, but we believe it should be representative of the current global picture.

View all available monitoring graphs

Internet Malicious Activity Maps

Internet Malicious Activity Hilbert Map The map to the left shows network locations of malicious activity on the Internet within the past 30 days, plotted using a Hilbert curve. Check out our Internet Malicious Activity Maps page for full details and a larger view of this and other maps.

Recent Releases

Our contribution to Operation Ghost Click

[17 NOV 2011] On 09 November 2011, US law enforcement released details of a major series of arrests as part of Operation Ghost Click. Team Cymru is proud to have been able to add details of victim computers that were part of this criminal infrastructure into one of our daily feeds of data that is provided at no cost to providers around the world. These lists of affected IP addresses enable network managers to identify and remediate computers infected by malware that are taking part in criminal activities.

This has a direct impact on people: it disrupts criminals and improves the lives of legitimate Internet users everywhere; we're honored to have been able to contribute to this effort. Our great thanks to all who contributed to this team effort.

Details of the case and our commentary can be found in this darkreading.com article. Images of the data we provided to our partners can be found via Twitter here and here.


Unexpected and unsubstantiated blog post

[25 OCT 2011] A recent blog post appeared to draw the unsubstantiated conclusion that more than 760 organizations were compromised with some of the same resources used to hit RSA earlier this year. Team Cymru was one of the organizations named in the posting.

We have no evidence of compromise related to incidents at RSA or anywhere else. The source of the report, and those who revealed and posted it, didn't take the time to contact us, or to share incident details with us. Thus we are unable to investigate further. We hope that those who gathered this data will responsibly disclose it to the potential victims.

Please note that without more details on the methodology used to determine the list of organizations, and a scientific review of the same, it's not safe to assume that an entry on the list means either "victim" or "false positive". We've seen no data or methodology description that would support either case.


New Underground Insight: A Criminal Perspective on Exploit Packs

[05 MAY 2011] The Team Cymru Business Intelligence Team is pleased to announce the release of their latest paper, entitled "A Criminal Perspective on Exploit Packs". This paper chronicles the genesis and historical eveolution of the Browser Exploit Pack (BEP). We discuss our research into the installation and usage of 40 different packs. Most notably, the paper discusses dishonor among coding thieves and the entrenched practice of "statistics shaving". Finally, we examine the monetization, code protection, and overall effectiveness of the various packs. For full details, check out the whitepaper, and don't forget to look at the rest of our whitepapers as well!


Team Cymru moving to Florida

[04 MAY 2011] Team Cymru today announced that they are relocating their headquarters staff from Chicago, Illinois, to Central Florida over the summer. The majority of our Chicago staff will move and are excited at the prospect of continuing to use our insight to improve lives, but from a significantly warmer location.

We do not forsee any disruption to our community or commercial feeds and services during this transition and we will continue to update our partners with news as appropriate. If you have any questions or concerns in the meantime, please e-mail outreach@cymru.com and we will be happy to discuss them with you!


View older news items in our news archives.

Friends of Team Cymru  
  CSIRT-MU Dyn, Inc. F-Secure FIRST  
  GoDaddy.com Interoute Communications REN-ISAC Savvis Communications  
  Support Intelligence Tata Communications Verizon Business  
 

Team Cymru Community Services