Are they including SSH port scanning and attempts on port 22?
Are they including SSH port scanning and attempts on port 22?
A billion "hacks" per day seems a bit far fetched. At that point, it's either a visible act of war (if external to the US) or the FBI would be much more involved (if internal). Both of those would be much larger news.
Russia allows its cyber-criminals free-reign when it comes to the rest of the world, as long as they're not interfering with official interests. Consider the difference in Letters of Marque vs the Admiralty in British history.
I hope that whoever is attempting to hack the Utah voting system has no nefarious purpose greater than changing "Mitt" to "Mittens.
In other words, it's marketing language designed to scare people who have no understanding of computer security.
(you get those regardless of the technology on the backend, a lot of malicious vuln. scanners around test for that)
In fact, I've long wondered whether this isn't a great opportunity; I'd like to make a script that went through logs and got every IP trying to access such a path, and adds those IPs to a blacklist that gets dropped at the firewall. Not even a honeypot (since they try even when there's nothing there at all), but still a way to catch (really stupid) bad actors / compromised systems.
Would it be ok to ban an entire IP just because someone from that IP has a compromised machine? I remember this argument that if there is obviously malicious traffic coming from an IP address, the right solution is to block traffic at the next stop, usually the ISP supplying Internet access to that connection. Failing that, the back end should disconnect the ISP and failing that, the other peers should disconnect from the malicious peer. But I don't know how practical it is...