[ Team Cymru Community Services ] [ Team Cymru Commercial Services ] [ Dragon Research Group ]
Department of Homeland Security website hacked by Anonymous "Only hours after two of its biggest releases ever, the online collective Anonymous is taking credit for crashing the website of the US Department of Homeland Security...." (more) | Anonymous says it will leak giant cache of Iraq war e-mails "Anonymous has struck and struck again...." (more) | U.S. government, military to get secure Android phones "Some U.S. officials this year are expected to get smartphones capable of handling classified government documents over cellular networks, according to people involved in the project...." (more) | Big firms put customers at risk by keeping cyber attacks secret "Major international companies are concealing from customers that their details are at risk after cyber attacks...." (more) | Girlhood threatened by terrors of the web "LOG OFF your daughters...." (more) | Accused WikiLeaker Manning sent to court-martial "The commander of the Military District of Washington has ordered a court-martial for Pfc...." (more) | German gov't endorses Chrome as most secure browser "Germany's cyber security agency today recommended that Windows 7 users run Google's Chrome browser, citing the application's sandbox and auto-update features...." (more) | Attention, Citizens! The FBI's Unfortunate Guide to Spotting Terrorists at the Internet Cafe "To anyone thinking about beefing up their computer security, a new see something, say, something memo from the U.S. Department of Justice might be a little disconcerting...." (more) | Hacking off the Feds: Anonymous intercepts FBI conference call aboutthemselves (AUDIO) "In an audio recording made and posted online by the internet hacktivists Anonymous, a number of Federal agents both in the US and the UK can be heard discussing ways to apprehend members of the group...." (more) | Rick Falkvinge at Bitcoin Conference Banks: The Fourth Victim of Citizens empowerment "Rick Falkvinge at Bitcoin Conference Banks: The Fourth Victim of Citizens empowerment...." (more) | Illegal foreign gambling websites threatening Turkey "Turkey's strict stance against gambling is being undermined by foreign gambling websites that are cashing in on this illegal market by providing online gambling opportunities to Turkish citizens in Internet cafes and other, similar venues specially set up for the purpose...." (more) | Google Rejects EU Request On Privacy Policy Consolidation "A European regulatory group focused on data protection has asked Google to delay its planned privacy policy consolidation, which is scheduled to take effect on March 1, 2012...." (more) | Neil Young: Piracy Is The New Radio (But The Quality Sucks) "from the well,-there's-that... deptNeil Young apparently isn't too concerned about copyright infringement these days, according to his comments at the D: Dive into Media conference: It doesn't affect me because I look at the internet as the new radio...." (more) | Cyber security and the real world "The VIKING project held its final dissemination workshop late last year, the day before the start of the SANS SCADA conference in Rome...." (more) | House Subcommittee Approves Cybersecurity Legislation, Concerns Remain About Critical Infrastructure Oversight "On February 1, the House Homeland Security Subcommittee on Cybersecurity approved by voice vote an amended version of HR 3674, the Promoting and Enhancing Cybersecurity and Information Sharing Effectiveness (PRECISE) Act of 2011...." (more) | Data Loss Doesnt Always Mean Getting Hacked "Recently UCLA announced 16,000 patients were potential victims of identity theft because a doctors home office was broken into and burglarized...." (more) | Video: Anonymous Claims Hack of FBI Conference Call "The rogue collective Anonymous claims to have hacked into and monitored an FBI conference call with British law enforcement officials, and have posted a video of the exploit...." (more) | Driving Up the Cost of Exploit Development Becomes a Key Defensive Strategy "The skill of attackers, combined with the difficulty and cost of finding and fixing vulnerabilities in software--especially after deployment--has reached the point that it's now more effective and efficient for vendors to concentrate on making life more difficult for those attackers looking to exploit bugs...." (more) | Met's email hack probe turns spotlight on The Times - MP "Scotland Yard officers investigating allegations of computer hacking by News International staff have declined to "give a running commentary" on their probe, batting away MP Tom Watson's narration of the saga...." (more) | Mythbusters Banned From Discussing RFID By Visa And Mastercard "Host Adam Savage of Mythbusters tells how Visa, Mastercard, and Discover had the Discovery Channel put the kibosh on an episode that would have revealed just how trackable and hackable the RFID chips found in many credit cards are...." (more) | Hey Advertisers! Stop Believing The NFL's Lies About Trademark Law And Call The Super Bowl The Super Bowl "For years now, we've mocked how the NFL insists that no one can use the term "Super Bowl" in an advertisement unless they're an official sponsor of the event...." (more) | First ENISA-EuroPol meeting taking place in Crete "On the Monday 30/01, the first ENISA-EuroPol meeting which was taking place in Crete took place...." (more) | Over 60% Brits Confused about 'Data Roaming' "Nearly two-thirds of UK's mobile users are not fully aware of what the term data roaming' actually means, a new reports revealed...." (more) | British Student Unveils ADzero, A Smartphone Made from Bamboo "A young lad from the UK's Middlesex University is soon going to unveil the first ever mobile phone in the world, to be made largely from bamboo, according to new reports...." (more) | UK MPs ask Government to Raise Cybercrime Awareness Instead of Scaring Web Users "According to Andrew Miller MP, chair of the Commons Science and Technology Committee, the government should stop scaring web users over cyber crime and should instead concentrate on spreading awareness of how to stay safe online...." (more) |
we're doing an Internet Forensics and Malware Analysis workshop in Sri Lanka in 2 weeks time if you're nearby... http://t.co/fS86FqyQ | German researchers: we can break GMR-1,2 satellite voice ciphers w/$2k h/ware and 30 mins http://t.co/Tf3LRgoX | Great progress in cooperation: European ‘cyber security’ Agency ENISA meeting with EuroPol in Crete http://t.co/YHXiXOzN | #hacked companies still not telling investors despite new guidance from securities regulators http://t.co/JyGM29i7 | Analysis of Apples pack of 39 patches addressing 52 CVE issues, revoking DigiCert Malaysia http://t.co/Ab9Mcr1Q | Verisign admits 2010 DNS #hack attack; concern about future use of stolen info http://t.co/ZoUjVFGD | 4 'no-brainer' ways to prevent your domain name from being hijacked http://t.co/QS8JsqVN | 'Malware as a Service' business just like legit ones: organized, scaleable, great support and life cycles http://t.co/MRK6c5Fu | TinKode=20 y/old Razvan Manole Cernaianu of Romania, arrested for #hacks on NASA, .mil, published bragging videos http://t.co/6oE3jssI | .UA LEOs raid ex.ua for warez, seizing 200 servers (6k Tb), 16 questioned at request of US s/ware firms http://t.co/Umu6AAVw | Kaspersky: Kelihos/Hlux #botnet is back, spamming despite Microsoft's valiant efforts http://t.co/FvWSz3Pv | summary of the 6th PwC Global Economic Crime Survey: 40% see cybercrime rising, 28% expect to be victims http://t.co/jPrKJbQx | "Stripper Touch girl" #Android game infected w/Counterclank? Shocked....here's 13 more: http://t.co/jZnLLv4L | Sarah Palin #hacker loses appeal against evidence deletion http://t.co/KgLk35zK | Our own Marcel van den Berg on addons to protect yourself from yourself? Unfortunately they don't exist yet: http://t.co/60YqVsHc |
Episode 106: Security Scripting, DDoS Tuning & Animations YouTube RSS Feed Twitter

Recent Data

[ Data Page 1 ] [ Data Page 2 ] [ Data Page 3 ] [ Data Page 4 ] [ Data Page 5 ]

Top 10 UDP Ports (logarithmic scale)

This chart shows the top 10 UDP ports seen in sampled global Internet traffic in our most recent hourly data sample. This chart is on a logarithmic scale, so the difference between the top port (usually UDP/53) and the bottom port may be more significant than it appears to the naked eye.

View all available monitoring graphs

Sampled DNS Request Rate (daily)

Our insight into Internet traffic around the globe allows us to sample and estimate trends in Domain Name System (DNS) requests, one of the key pieces of Internet infrastructure. This chart provides a glimpse into that sampled rate over the past 30 days, aggregated daily, for both TCP and UDP DNS requests (though the TCP request rate is so low it is difficult to discern).

View all available monitoring graphs

Average Daily Botnet Traffic

This chart shows the average amount of traffic we see to each botnet command and control (C&C) server we are monitoring daily. This is the actual bandwidth consumed by the bots as they check in with the controller and receive commands. This data is based on a sampled view of traffic, and shouldn't be treated as hard numbers, but can give you an idea of the rates of usage involved in running a botnet.

View all available monitoring graphs

Underground Economy Activity

This chart shows a very general sampled indicator of the average number of messages per hour seen each day in various underground economy forums for the past 30 days. The numbers should not be taken as absolutes, and have considerable sampling error, but are believed to be a reasonable indicator of overall trends.

View all available monitoring graphs

Internet Malicious Activity Maps

Internet Malicious Activity Hilbert Map The map to the left shows network locations of malicious activity on the Internet within the past 30 days, plotted using a Hilbert curve. Check out our Internet Malicious Activity Maps page for full details and a larger view of this and other maps.

Recent Releases

Our contribution to Operation Ghost Click

[17 NOV 2011] On 09 November 2011, US law enforcement released details of a major series of arrests as part of Operation Ghost Click. Team Cymru is proud to have been able to add details of victim computers that were part of this criminal infrastructure into one of our daily feeds of data that is provided at no cost to providers around the world. These lists of affected IP addresses enable network managers to identify and remediate computers infected by malware that are taking part in criminal activities.

This has a direct impact on people: it disrupts criminals and improves the lives of legitimate Internet users everywhere; we're honored to have been able to contribute to this effort. Our great thanks to all who contributed to this team effort.

Details of the case and our commentary can be found in this darkreading.com article. Images of the data we provided to our partners can be found via Twitter here and here.


Unexpected and unsubstantiated blog post

[25 OCT 2011] A recent blog post appeared to draw the unsubstantiated conclusion that more than 760 organizations were compromised with some of the same resources used to hit RSA earlier this year. Team Cymru was one of the organizations named in the posting.

We have no evidence of compromise related to incidents at RSA or anywhere else. The source of the report, and those who revealed and posted it, didn't take the time to contact us, or to share incident details with us. Thus we are unable to investigate further. We hope that those who gathered this data will responsibly disclose it to the potential victims.

Please note that without more details on the methodology used to determine the list of organizations, and a scientific review of the same, it's not safe to assume that an entry on the list means either "victim" or "false positive". We've seen no data or methodology description that would support either case.


New Underground Insight: A Criminal Perspective on Exploit Packs

[05 MAY 2011] The Team Cymru Business Intelligence Team is pleased to announce the release of their latest paper, entitled "A Criminal Perspective on Exploit Packs". This paper chronicles the genesis and historical eveolution of the Browser Exploit Pack (BEP). We discuss our research into the installation and usage of 40 different packs. Most notably, the paper discusses dishonor among coding thieves and the entrenched practice of "statistics shaving". Finally, we examine the monetization, code protection, and overall effectiveness of the various packs. For full details, check out the whitepaper, and don't forget to look at the rest of our whitepapers as well!


Team Cymru moving to Florida

[04 MAY 2011] Team Cymru today announced that they are relocating their headquarters staff from Chicago, Illinois, to Central Florida over the summer. The majority of our Chicago staff will move and are excited at the prospect of continuing to use our insight to improve lives, but from a significantly warmer location.

We do not forsee any disruption to our community or commercial feeds and services during this transition and we will continue to update our partners with news as appropriate. If you have any questions or concerns in the meantime, please e-mail outreach@cymru.com and we will be happy to discuss them with you!


View older news items in our news archives.

Friends of Team Cymru  
  CSIRT-MU Dyn, Inc. F-Secure FIRST  
  GoDaddy.com Interoute Communications REN-ISAC Savvis Communications  
  Support Intelligence Tata Communications Verizon Business  
 

Team Cymru Community Services