Skip to main content

Search

Items tagged with: threatintel


Wild ass day in the Tor node operator world. Got an email from my VPS, forwarding a complaint from WatchDog CyberSecurity saying that my box was scanning SSH ports!

> Oh no, oh no, I knew I should have set up fail2ban, oh god why was I so lackadaisical!

So I remote in to the machine: no unusual network activity, no unusual processes, users, logins, command history, no sign that anything is doing anything I didn't tell it to do.

So what's up? Turns out there's been a widespread campaign where some actor is spoofing IPs to make it look like systems running Tor are scanning port 22: forum.torproject.org/t/tor-rel…

Operators from all over are saying they're getting nastygrams from their VPS providers because WatchDog is fingering their source IPs (which are being spoofed and NOT part of a global portscanning botnet).

@delroth did an amazing writeup of the whole thing here: delroth.net/posts/spoofed-mass…

#tor #infosec #cybersecurity #threatintel #privacy


Lottie-Player saga playing out here: github.com/LottieFiles/lottie-…

3 new versions were published today but the threat actor infected them. Appears to be a stolen token.

#threatintel


Lottiefiles sent me a statement about their supply chain security incident. #threatintel


Lottiefiles Lottieplayer JavaScript library has been compromised forum.lottiefiles.com/t/the-pr…

Somebody also made the first change to the GitHub repo for months 10 minutes ago, reasons unclear.

You may want to proxy block *.web3modal.org

#threatintel