TSUBAME Report Overflow (Jan-Mar 2024)
ID: 737a60e0-a966-57ff-a0e3-5d46a143c2a3
STIX ID: report--737a60e0-a966-57ff-a0e3-5d46a143c2a3
Feed Name: JPCERT Blog
JPCERT/CC’s TSUMABE Report Overflow (Jan–Mar 2024) summarizes global sensor observations showing sustained, widespread scanning with 23/TCP dominating—approximately 70% Mirai-type traffic—alongside frequent probes to 6379/TCP, 22/TCP, 8080/TCP, 80/TCP, and ICMP; it identifies commonly affected Internet-exposed devices (surveillance cameras, DVRs, NAS, routers), notes evolving attack patterns leveraging newly discovered vulnerabilities, compares Japan vs. overseas sensor trends, and provides practical hardening guidance (e.g., Internet access rules, post-installation port scans, SHODAN checks) while reporting ongoing vendor coordination and no special alerts this quarter.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
