Cyber information security jobs

Cybercriminals have taken advantage of Google’s cloud service to target several consumer routers to redirect DNS queries from legitimate sites to malicious ones.
According to security researcher Troy Mursch at Bad Packets, the attack is easy to carry out.
He said that anyone with a Google account can access a 'Google Cloud Shell' machine by simply visiting the Google Cloud console.
"This service provides users with the equivalent of a Linux VPS with root privileges directly in a web browser," he said. "Due to the ephemeral nature of these virtual machines coupled with Google’s slow response time to abuse reports, it’s difficult to prevent this kind of malicious behaviour."
There have been three waves of attacks since December last year. In all three waves, a reconnaissance scan was carried out using Masscan to check for active hosts on port 81/tcp prior to attempting the DNS hijacking exploits. The attacks targeted D-Link DSL-2640B, D-Link DSL-2740R, D-Link DSL-2780B and D-Link DSL-526B routers.
The hack intended to modify DNS settings in the routers to point to unauthorised webpages that scan user data.
The latest wave of attacks came from three distinct Google Cloud Platform hosts and targeted additional types of consumer routers not previously seen before including: ARG-W4 ADSL routers, DSLink 260E routers, Secutech routers, and TOTOLINK routers, according to Mursch.
"The rogue DNS servers used in this round, 195.128.126.165 and 195.128.124.131, are both hosted in Russia by Inoventica Services. Internet access is provided by their subsidiary Garant-Park-Internet Ltd (AS47196)," he added.
Mursch said that users should keep their home router firmware up-to-date.
"When security vulnerabilities are discovered, they are usually patched by the manufacturer to mitigate further attacks. It’s also advisable to review your router’s DNS settings to ensure they haven’t been tampered with," he added.
Mihai Vasilescu, security researcher at Ixia, told SC Media UK that for end users, simple precautions can mitigate many of the risks we face online.
"Making sure that our devices—in this case routers—are up-to-date and not exposing the admin interface online is important," he said.
"Also, be extra careful when accessing important websites, banking especially. Make sure that the connections are HTTPS, check the certificate. All of this is important to make sure that when you're entering your credentials, they don't get to someone else."
In a blog post, he added that hackers have also targeted Netflix, PayPal, Uber, Gmail, and others in phishing attacks.
Eoin Keary, CEO and co-founder of Edgescan, told SC Media UK that one of the prime factors to successful compromise is having the router Administration console exposed to the public Internet.
"Most routers can enable "Loopback only" so only local connections can connect to the router administration console. In addition, such attacks are a good reason to ensure default credentials and weak passwords are not used on consumer routers. In fairness, many router vendors now provide the hardware with complex credentials and secure defaults, but older routers are significantly more vulnerable and have few if no security controls enabled by default," he said.
source scmagazineuk

Latest Jobs
-
- Senior Presales Consultant | Managed Security Services | London
- London
- N/A
-
Senior Presales Consultant – Managed Security Services Location: London-commutable (Hybrid) A well-established cyber consultancy is seeking a Senior Presales Consultant to drive growth across its managed security services / advisory portfolio. This hybrid role bridges commercial and technical expertise supporting solution design, shaping customer proposals, and guiding conversations from scoping through to delivery. Key experience: Background in managed security services, including SOC operations and threat detection Strong knowledge of cloud and on-prem security tooling (SIEM, EDR, IAM) Penetration testing Proven ability to translate technical concepts into clear business value Confident in customer-facing engagements and pre-sales delivery Experience contributing to bids, proposals, and RFI/RFP responses To find out more contact me on 07884666351 Visa sponsorship is unfortunately not available for this role.
-
- Senior SOC Engineer - Microsoft | Splunk. Permanent. London
- London
- N/A
-
Senior SOC Engineer – Hybrid London Type: Full-Time A well-established cyber security provider is seeking a Senior SOC Engineer to strengthen its managed services function. This role is ideal for someone with a strong operational background in SIEM and EDR tools who can confidently lead customer onboarding, fine-tune detection strategies, and act as a senior point of contact for technical escalations. You will need to be SC clearable. Bonus points if you have SC clearance currently. You will be responsible for ensuring smooth integration of new clients into the service, optimising alerting capabilities and delivering meaningful outcomes during investigations. This is a hands-on position, working closely with internal teams and external stakeholders to maintain robust security operations across multiple environments. Prior experience in a cyber-focused MSP or MSSP Strong hands-on capability with platforms such as Microsoft Sentinel, Defender for Endpoint, or similar Proficiency in scripting and query languages such as KQL or PowerShell Knowledge of detection logic, investigation workflows, and cloud-based infrastructure Confident communicator with strong documentation and reporting skills Apply today for more information.