Search this show’s transcripts

CyberWire Daily

en us
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
More details
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
Sources and links

Episodes

Page 24 · 50 per page

This interview from October 20th, 2023 originally aired as a shortened version on the CyberWire Daily Podcast. In this extended interview, our very own Simone Petrella is speaking with Tatyana Bolton from Google about ways to tackle the cyber talent gap.

More description

This interview from October 20th, 2023 originally aired as a shortened version on the CyberWire Daily Podcast. In this extended interview, our very own Simone Petrella is speaking with Tatyana Bolton from Google about ways to tackle the cyber talent gap.

Extract Knowledge
Listen elsewhere

Thanks for joining us again for another episode of fun project brought to you by the team of Hacking Humans, the CyberWire's social engineering podcast. Hacking Humans co-host Dave Bittner is joined by Rick Howard in this series where they view clips from their favorite movies and television shows with examples of the social engineering scams and schemes you hear Dave and co-host Joe Carrigan talk about on Hacking Humans. In this episode, Dave and Rick watch each of the selected scenes, describe the on-screen action for you, and then they deconstruct what they saw. Grab your bowl of popcorn and join us for some fantastic scams and frauds.

Links to this episode's clips if you'd like to watch along:

More description

Thanks for joining us again for another episode of fun project brought to you by the team of Hacking Humans, the CyberWire's social engineering podcast. Hacking Humans co-host Dave Bittner is joined by Rick Howard in this series where they view clips from their favorite movies and television shows with examples of the social engineering scams and schemes you hear Dave and co-host Joe Carrigan talk about on Hacking Humans. In this episode, Dave and Rick watch each of the selected scenes, describe the on-screen action for you, and then they deconstruct what they saw. Grab your bowl of popcorn and join us for some fantastic scams and frauds.

Links to this episode's clips if you'd like to watch along:

Extract Knowledge
Listen elsewhere

CISA issues joint Cybersecurity Advisory on Citrix Bleed. Law enforcement takes down "pig butchering" operations. Altman will return to OpenAI. Israeli honeypots deployed during the war. A renaissance in electronic warfare. And a response in the form of countermeasures. Ihab Shraim, Chief Technology Officer at CSC, shares how the growing popularity of AI is giving cybercriminals a new avenue to take advantage of some of the largest companies in the world. And online safety during the holidays.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/223


Selected reading.

CISA issues joint Cybersecurity Advisory on Citrix Bleed. (CyberWire)

Cyber Scam Organization Disrupted Through Seizure of Nearly $9M in Crypto (U.S. Department of Justice)

China Rounds Up 31,000 Suspects in Sweeping ‘Pig-Butchering’ Crackdown (Wall Street Journal)

OpenAI Says Sam Altman to Return as CEO (Wall Street Journal)

Altman Agrees to Internal Investigation Upon Return to OpenAI (Information)

Sam Altman, OpenAI Board Open Talks to Negotiate His Possible Return (Bloomberg)

Before Altman’s Ouster, OpenAI’s Board Was Divided and Feuding (New York Times)

Altman Argued With OpenAI Board Member Toner Before Ouster (Information)

The Invisible War in Ukraine Being Fought Over Radio Waves (New York Times)

Exclusive: This pizza box-sized equipment could be key to Ukraine keeping the lights on this winter (CNN)

Commercial Flights Are Experiencing 'Unthinkable' GPS Attacks and Nobody Knows What to Do (Vice)

Shopping securely on Black Friday (and beyond). (CyberWire)

More description

CISA issues joint Cybersecurity Advisory on Citrix Bleed. Law enforcement takes down "pig butchering" operations. Altman will return to OpenAI. Israeli honeypots deployed during the war. A renaissance in electronic warfare. And a response in the form of countermeasures. Ihab Shraim, Chief Technology Officer at CSC, shares how the growing popularity of AI is giving cybercriminals a new avenue to take advantage of some of the largest companies in the world. And online safety during the holidays.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/223


Selected reading.

CISA issues joint Cybersecurity Advisory on Citrix Bleed. (CyberWire)

Cyber Scam Organization Disrupted Through Seizure of Nearly $9M in Crypto (U.S. Department of Justice)

China Rounds Up 31,000 Suspects in Sweeping ‘Pig-Butchering’ Crackdown (Wall Street Journal)

OpenAI Says Sam Altman to Return as CEO (Wall Street Journal)

Altman Agrees to Internal Investigation Upon Return to OpenAI (Information)

Sam Altman, OpenAI Board Open Talks to Negotiate His Possible Return (Bloomberg)

Before Altman’s Ouster, OpenAI’s Board Was Divided and Feuding (New York Times)

Altman Argued With OpenAI Board Member Toner Before Ouster (Information)

The Invisible War in Ukraine Being Fought Over Radio Waves (New York Times)

Exclusive: This pizza box-sized equipment could be key to Ukraine keeping the lights on this winter (CNN)

Commercial Flights Are Experiencing 'Unthinkable' GPS Attacks and Nobody Knows What to Do (Vice)

Shopping securely on Black Friday (and beyond). (CyberWire)

Extract Knowledge
Listen elsewhere

OpenAI's continuing turmoil. Crypto firm sustains API attack. Konni campaign phishes with a Russian document as bait. LockBit's third-party compromise of Canadian government personnel data. Ukraine removes senior security officials under suspicion of graft. Dave Bittner sits down with Steve Winterfeld from Akamai to discuss emerging threats in the financial services sector. And Idaho National Laboratory sustains data breach.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/222


Selected reading.

Company that created ChatGPT is thrown into turmoil after Microsoft hires its ousted CEO (AP News)

The Doomed Mission Behind Sam Altman’s Shock Ouster From OpenAI (Bloomberg)

Briefing: OpenAI Execs to Continue Discussions With Altman, Board: Memo (The Information)

OpenAI in ‘Intense Discussions’ to Quell Potential Staff Mutiny (Bloomberg)

Microsoft Wants to Work With Altman, No Matter What, Says CEO (Bloomberg)

Briefing: Microsoft CEO Nadella Says Altman Could End Up at Microsoft or OpenAI; Board Governance Should Change (The Information)

Sam Altman's AI 'mission continues' at Microsoft, future of OpenAI and ChatGPT uncertain (ZDNET)

OpenAI’s Customers Consider Defecting to Anthropic, Microsoft, Google (The Information)

OpenAI’s Board Approached Anthropic About Merger (The Information)

The Vast Majority of OpenAI Employees Ask the Board to Resign (The Information)

Konni Campaign Distributed Via Malicious Document (Fortinet Blog) 

Ukraine sacks top cyber defence officials amid graft probe (Reuters)

Two top Ukrainian cyber officials dismissed amid embezzlement probe (Record)

Ukraine fires top cybersecurity officials (TechCrunch)

Ukraine-Russia war: Ukraine sacks 'corrupt' cyber defence chiefs (The Telegraph)

Kronos Research halts trading amid $25M API key hack investigation (Cointelegraph)

Kronos Research Loses $26 Million in Unauthorized API Access Incident (Bitcoin News)

Canadian government discloses data breach after contractor hacks (BleepingComputer)

Idaho National Laboratory experiences massive data breach; employee information leaked online (East Idaho News)

Detailed data on employees of U.S. national security lab leak online (CyberScoop)

More description

OpenAI's continuing turmoil. Crypto firm sustains API attack. Konni campaign phishes with a Russian document as bait. LockBit's third-party compromise of Canadian government personnel data. Ukraine removes senior security officials under suspicion of graft. Dave Bittner sits down with Steve Winterfeld from Akamai to discuss emerging threats in the financial services sector. And Idaho National Laboratory sustains data breach.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/222


Selected reading.

Company that created ChatGPT is thrown into turmoil after Microsoft hires its ousted CEO (AP News)

The Doomed Mission Behind Sam Altman’s Shock Ouster From OpenAI (Bloomberg)

Briefing: OpenAI Execs to Continue Discussions With Altman, Board: Memo (The Information)

OpenAI in ‘Intense Discussions’ to Quell Potential Staff Mutiny (Bloomberg)

Microsoft Wants to Work With Altman, No Matter What, Says CEO (Bloomberg)

Briefing: Microsoft CEO Nadella Says Altman Could End Up at Microsoft or OpenAI; Board Governance Should Change (The Information)

Sam Altman's AI 'mission continues' at Microsoft, future of OpenAI and ChatGPT uncertain (ZDNET)

OpenAI’s Customers Consider Defecting to Anthropic, Microsoft, Google (The Information)

OpenAI’s Board Approached Anthropic About Merger (The Information)

The Vast Majority of OpenAI Employees Ask the Board to Resign (The Information)

Konni Campaign Distributed Via Malicious Document (Fortinet Blog) 

Ukraine sacks top cyber defence officials amid graft probe (Reuters)

Two top Ukrainian cyber officials dismissed amid embezzlement probe (Record)

Ukraine fires top cybersecurity officials (TechCrunch)

Ukraine-Russia war: Ukraine sacks 'corrupt' cyber defence chiefs (The Telegraph)

Kronos Research halts trading amid $25M API key hack investigation (Cointelegraph)

Kronos Research Loses $26 Million in Unauthorized API Access Incident (Bitcoin News)

Canadian government discloses data breach after contractor hacks (BleepingComputer)

Idaho National Laboratory experiences massive data breach; employee information leaked online (East Idaho News)

Detailed data on employees of U.S. national security lab leak online (CyberScoop)

Extract Knowledge
Listen elsewhere

Leadership turmoil at OpenAI. Citrix Bleed vulnerability implicated in ransomware attacks. QakBot seems to have a successor. The FSB deploys LitterDrifter in cyberespionage against Ukraine. Russian security firm says China and North Korea are the source of most cyberattacks against Russia. Privateers and auxiliaries engage targets of opportunity. Ann Johnson from Afternoon Cyber Tea talks about leading edge cyber innovation with Nadav Zafrir. And alleged war crimes may include cyber operations conducted in support of other, conventional, kinetic war crimes.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/221


Selected reading.

OpenAI announces leadership transition (OpenAI)

A statement from Microsoft Chairman and CEO Satya Nadella (The Official Microsoft Blog)

A timeline of Sam Altman’s ouster from OpenAI and Microsoft appointment (Reuters) 

Sam Altman leaves OpenAI: Everything you need to know (Computing)

OpenAI Employees Threaten to Quit Unless Board Resigns (Wall Street Journal)

Sam Altman to Join Microsoft Following OpenAI Ouster (Wall Street Journal)

Dozens of Staffers Quit OpenAI After Sutskever Says Altman Won’t Return (The Information)

AI to accelerate your security defenses (IBM)

OpenAI’s Board Set Back the Promise of Artificial Intelligence (The Information)

A New AI Lexicon: Existential Risk (AI Now)

Hackers Are Exploiting a Flaw in Citrix Software Despite Fix (Bloomberg)

Medusa ransomware gang claims Toyota Financial Services hack (Security Affairs) 

CitrixBleed Vulnerability Exploitation Suspected in Toyota Ransomware Attack (SecurityWeek) 

Yamaha and WellLife Network confirm cyber incidents after ransomware gang claims attacks (Record)

Are DarkGate and PikaBot the New QakBot? (Cofense)

Decrypting Danger: Check Point Research deep-dive into cyber espionage tactics by Russian-origin attackers targeting Ukrainian entities (Check Point Blog)

Malware Spotlight - Into the Trash: Analyzing LitterDrifter (Check Point Research) 

Russian APT Gamaredon uses USB worm LitterDrifter against Ukraine (Security Affairs) 

Russian Cyber Espionage Group Deploys LitterDrifter USB Worm in Targeted Attacks (The Hacker News) 

Remarks by Assistant Secretary Graham Steele at the Federal Insurance Office and NYU Stern Volatility and Risk Institute Conference on Catastrophic Cyber Risk and a Potential Federal Insurance Response (U.S. Department of the Treasury) 

Russian analysts point finger at China, North Korea over cyber activity (Record) 

How Pro-Ukrainian Hackers Have Undermined Russia's War Every Step Of The Way (WorldCrunch)

Ukraine says it has evidence of 109,000 Russian war crimes (POLITICO)

More description

Leadership turmoil at OpenAI. Citrix Bleed vulnerability implicated in ransomware attacks. QakBot seems to have a successor. The FSB deploys LitterDrifter in cyberespionage against Ukraine. Russian security firm says China and North Korea are the source of most cyberattacks against Russia. Privateers and auxiliaries engage targets of opportunity. Ann Johnson from Afternoon Cyber Tea talks about leading edge cyber innovation with Nadav Zafrir. And alleged war crimes may include cyber operations conducted in support of other, conventional, kinetic war crimes.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/221


Selected reading.

OpenAI announces leadership transition (OpenAI)

A statement from Microsoft Chairman and CEO Satya Nadella (The Official Microsoft Blog)

A timeline of Sam Altman’s ouster from OpenAI and Microsoft appointment (Reuters) 

Sam Altman leaves OpenAI: Everything you need to know (Computing)

OpenAI Employees Threaten to Quit Unless Board Resigns (Wall Street Journal)

Sam Altman to Join Microsoft Following OpenAI Ouster (Wall Street Journal)

Dozens of Staffers Quit OpenAI After Sutskever Says Altman Won’t Return (The Information)

AI to accelerate your security defenses (IBM)

OpenAI’s Board Set Back the Promise of Artificial Intelligence (The Information)

A New AI Lexicon: Existential Risk (AI Now)

Hackers Are Exploiting a Flaw in Citrix Software Despite Fix (Bloomberg)

Medusa ransomware gang claims Toyota Financial Services hack (Security Affairs) 

CitrixBleed Vulnerability Exploitation Suspected in Toyota Ransomware Attack (SecurityWeek) 

Yamaha and WellLife Network confirm cyber incidents after ransomware gang claims attacks (Record)

Are DarkGate and PikaBot the New QakBot? (Cofense)

Decrypting Danger: Check Point Research deep-dive into cyber espionage tactics by Russian-origin attackers targeting Ukrainian entities (Check Point Blog)

Malware Spotlight - Into the Trash: Analyzing LitterDrifter (Check Point Research) 

Russian APT Gamaredon uses USB worm LitterDrifter against Ukraine (Security Affairs) 

Russian Cyber Espionage Group Deploys LitterDrifter USB Worm in Targeted Attacks (The Hacker News) 

Remarks by Assistant Secretary Graham Steele at the Federal Insurance Office and NYU Stern Volatility and Risk Institute Conference on Catastrophic Cyber Risk and a Potential Federal Insurance Response (U.S. Department of the Treasury) 

Russian analysts point finger at China, North Korea over cyber activity (Record) 

How Pro-Ukrainian Hackers Have Undermined Russia's War Every Step Of The Way (WorldCrunch)

Ukraine says it has evidence of 109,000 Russian war crimes (POLITICO)

Extract Knowledge
Listen elsewhere

Ian Blumenfeld, a Research Director from Two Six Technologies sits down to share his story with us. Ian begins his story by sharing he wanted to be a scientist, slowly he began to figure out and pinpoint more of what he liked about science, which ended up being math. Ian explains how math began to become a passion for him, and he eventually tried to pursue a career in it by teaching. He discovered teaching was not the thing for him and then started to move into the direction he wanted too, taking on more and more challenging roles until he landed where he is today. Ian says "If you're a smart person and you have skills in coding, you can swim. So it's okay to jump. It's okay to jump into the lake, you can swim. Something will get you out. You will have, you will be able to find a job. So, if you see something that looks cool, if you see something that advances you to the next stage of your career, if you have to take a little bit of a risk, it's okay." Ian wants to be someone who helped make the world a little better when it comes to code and wants to shares his desires and passions with the community. We thank Ian for sharing his story with us.

More description

Ian Blumenfeld, a Research Director from Two Six Technologies sits down to share his story with us. Ian begins his story by sharing he wanted to be a scientist, slowly he began to figure out and pinpoint more of what he liked about science, which ended up being math. Ian explains how math began to become a passion for him, and he eventually tried to pursue a career in it by teaching. He discovered teaching was not the thing for him and then started to move into the direction he wanted too, taking on more and more challenging roles until he landed where he is today. Ian says "If you're a smart person and you have skills in coding, you can swim. So it's okay to jump. It's okay to jump into the lake, you can swim. Something will get you out. You will have, you will be able to find a job. So, if you see something that looks cool, if you see something that advances you to the next stage of your career, if you have to take a little bit of a risk, it's okay." Ian wants to be someone who helped make the world a little better when it comes to code and wants to shares his desires and passions with the community. We thank Ian for sharing his story with us.

Extract Knowledge
Listen elsewhere

In the dynamic field of cybersecurity, it’s well established that creating more opportunities for diversity and inclusion is essential for developing a highly skilled workforce. As an industry, we are starting to see the fruits of that labor, but there is a growing need for diverse leadership to nurture continuous innovation and resilience in cybersecurity.

As part of N2K’s 2023 Women in Cyber content series, we’re excited to host an engaging virtual panel discussion moderated by N2K's President Simone Petrella featuring insights, experiences, and strategies for advancing more women into leadership roles within the field.

This virtual discussion explores different areas including:

  • Navigating the Cybersecurity Landscape: Gain insights into our guests' career journeys, including mentors, challenges, and success, and how the evolving landscape may present different challenges and opportunities for women.
  • Building a Supportive Ecosystem: Explore the importance of mentorship, allyship, and a strong network in propelling women into leadership, and how to create an environment where everyone can thrive.
  • Closing the Gender Gap: Delve into actionable strategies and best practices for organizations to promote gender diversity in their cybersecurity leadership teams.
  • The Future of Cybersecurity Leadership: Gain a forward-looking perspective on the evolving role of women in shaping the future of cybersecurity.

This panel discussion is a must-listen event for professionals, leaders, and aspiring cybersecurity experts who are committed to promoting diversity and empowering women to excel in cybersecurity leadership. Don't miss the opportunity to be part of this inspiring conversation and drive positive change in the industry.

Panelists:
More description

In the dynamic field of cybersecurity, it’s well established that creating more opportunities for diversity and inclusion is essential for developing a highly skilled workforce. As an industry, we are starting to see the fruits of that labor, but there is a growing need for diverse leadership to nurture continuous innovation and resilience in cybersecurity.

As part of N2K’s 2023 Women in Cyber content series, we’re excited to host an engaging virtual panel discussion moderated by N2K's President Simone Petrella featuring insights, experiences, and strategies for advancing more women into leadership roles within the field.

This virtual discussion explores different areas including:

  • Navigating the Cybersecurity Landscape: Gain insights into our guests' career journeys, including mentors, challenges, and success, and how the evolving landscape may present different challenges and opportunities for women.
  • Building a Supportive Ecosystem: Explore the importance of mentorship, allyship, and a strong network in propelling women into leadership, and how to create an environment where everyone can thrive.
  • Closing the Gender Gap: Delve into actionable strategies and best practices for organizations to promote gender diversity in their cybersecurity leadership teams.
  • The Future of Cybersecurity Leadership: Gain a forward-looking perspective on the evolving role of women in shaping the future of cybersecurity.

This panel discussion is a must-listen event for professionals, leaders, and aspiring cybersecurity experts who are committed to promoting diversity and empowering women to excel in cybersecurity leadership. Don't miss the opportunity to be part of this inspiring conversation and drive positive change in the industry.

Panelists:
Extract Knowledge
Listen elsewhere

Asheer Malhotra from Cisco Talos discussing their research and findings on "Kazakhstan-associated YoroTrooper disguises origin of attacks as Azerbaijan." Cisco Talos' research team, released research attributing the work of the espionage-focused threat actor, YoroTrooper, to individuals based in Kazakhstan.

The research states "YoroTrooper attempts to obfuscate the origin of their operations, employing various tactics to make its malicious activity appear to emanate from Azerbaijan, such as using VPN exit nodes local to that region." They also found that the YoroTrooper continues to rely heavily on phishing emails that direct victims to credential harvesting sites.

The research can be found here:

More description

Asheer Malhotra from Cisco Talos discussing their research and findings on "Kazakhstan-associated YoroTrooper disguises origin of attacks as Azerbaijan." Cisco Talos' research team, released research attributing the work of the espionage-focused threat actor, YoroTrooper, to individuals based in Kazakhstan.

The research states "YoroTrooper attempts to obfuscate the origin of their operations, employing various tactics to make its malicious activity appear to emanate from Azerbaijan, such as using VPN exit nodes local to that region." They also found that the YoroTrooper continues to rely heavily on phishing emails that direct victims to credential harvesting sites.

The research can be found here:

Extract Knowledge
Listen elsewhere

Buffy Wajvoda is the Global Leader for Space Solutions Architecture at AWS Aerospace and Satellite. In this extended conversation, we dive into how AWS is supporting cybersecurity in the space domain. You can learn more at AWS re:Invent.

AWS in Orbit is a podcast collaboration between N2K and AWS to offer listeners an in-depth look at the transformative intersection of cloud computing, space technologies, and generative AI. You can learn more about AWS in Orbit at space.n2k.com/aws.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our weekly intelligence roundup, Signals and Space, and you’ll never miss a beat. And be sure to follow T-Minus on LinkedIn and Instagram.

Selected Reading

AWS re:Invent

The security attendee’s guide to AWS re:Invent 2023- AWS Blog

Viasat Deploys Resilient Tactical Edge Capability with AWS- YouTube

How We Sent an AWS Snowcone into Orbit- AWS Blog

How to improve your security incident response processes with Jupyter notebooks- AWS Blog 

Supporting security assessors in the Canadian public sector with AWS and Deloitte- AWS Blog

Establishing hybrid connectivity within a Canadian Centre for Cyber Security Medium Cloud reference architecture- AWS Blog  

Evolving cyber threats demand new security approaches – The benefits of a unified and global IT/OT SOC- AWS Blog

Audience Survey

We want to hear from you! Please complete our short survey. It’ll help us get better and deliver you the most mission-critical space intel every day.

Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at space@n2k.com to request more info.

Want to join us for an interview?

Please send your pitch to space-editor@n2k.com and include your name, affiliation, and topic proposal.

T-Minus is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

Buffy Wajvoda is the Global Leader for Space Solutions Architecture at AWS Aerospace and Satellite. In this extended conversation, we dive into how AWS is supporting cybersecurity in the space domain. You can learn more at AWS re:Invent.

AWS in Orbit is a podcast collaboration between N2K and AWS to offer listeners an in-depth look at the transformative intersection of cloud computing, space technologies, and generative AI. You can learn more about AWS in Orbit at space.n2k.com/aws.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our weekly intelligence roundup, Signals and Space, and you’ll never miss a beat. And be sure to follow T-Minus on LinkedIn and Instagram.

Selected Reading

AWS re:Invent

The security attendee’s guide to AWS re:Invent 2023- AWS Blog

Viasat Deploys Resilient Tactical Edge Capability with AWS- YouTube

How We Sent an AWS Snowcone into Orbit- AWS Blog

How to improve your security incident response processes with Jupyter notebooks- AWS Blog 

Supporting security assessors in the Canadian public sector with AWS and Deloitte- AWS Blog

Establishing hybrid connectivity within a Canadian Centre for Cyber Security Medium Cloud reference architecture- AWS Blog  

Evolving cyber threats demand new security approaches – The benefits of a unified and global IT/OT SOC- AWS Blog

Audience Survey

We want to hear from you! Please complete our short survey. It’ll help us get better and deliver you the most mission-critical space intel every day.

Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at space@n2k.com to request more info.

Want to join us for an interview?

Please send your pitch to space-editor@n2k.com and include your name, affiliation, and topic proposal.

T-Minus is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

Scattered Spider prompts warnings from CISA and the FBI. Phobos ransomware is an affiliate crimeware-as-a-service program. A "hack-for-hire" contractor. “Scama” in the C2C market. Our guest is Lee Clark from the RH-ISAC with a look at Holiday Season Cyber Threat Trends. Tim Eades from Cyber Mentor Fund shares recent trends in cyber venture capital, with tips on finding a good match. And the tempo of cyber operations in Russia's hybrid war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/220


Selected reading.

FBI and CISA Release Advisory on Scattered Spider Group (Cybersecurity and Infrastructure Security Agency | CISA) 

FBI warns on Scattered Spider hackers, urges victims to come forward (Reuters) 

U.S. officials urge more information sharing on prolific cybercrime group (CyberScoop) 

A deep dive into Phobos ransomware, recently deployed by 8Base group (Cisco Talos Blog) 

Understanding the Phobos affiliate structure and activity (Cisco Talos Blog)

Elephant Hunting | Inside an Indian Hack-For-Hire Group (SentinelOne) 

How an Indian startup hacked the world (Reuters) 

Scama: Uncovering the Dark Marketplace for Phishing Kits (Vade Secure)

Ukraine Tracks a Record Number of Cyber Incidents During War (Bank Info Security) 

Russia will target other countries for web attacks, Ukraine cyber defence chief warns (The Irish Times) 

Sandworm Linked to Attack on Danish Critical Infrastructure (Infosecurity Magazine) 

Why cyber war readiness is critical for democracies (Help Net Security) 

More description

Scattered Spider prompts warnings from CISA and the FBI. Phobos ransomware is an affiliate crimeware-as-a-service program. A "hack-for-hire" contractor. “Scama” in the C2C market. Our guest is Lee Clark from the RH-ISAC with a look at Holiday Season Cyber Threat Trends. Tim Eades from Cyber Mentor Fund shares recent trends in cyber venture capital, with tips on finding a good match. And the tempo of cyber operations in Russia's hybrid war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/220


Selected reading.

FBI and CISA Release Advisory on Scattered Spider Group (Cybersecurity and Infrastructure Security Agency | CISA) 

FBI warns on Scattered Spider hackers, urges victims to come forward (Reuters) 

U.S. officials urge more information sharing on prolific cybercrime group (CyberScoop) 

A deep dive into Phobos ransomware, recently deployed by 8Base group (Cisco Talos Blog) 

Understanding the Phobos affiliate structure and activity (Cisco Talos Blog)

Elephant Hunting | Inside an Indian Hack-For-Hire Group (SentinelOne) 

How an Indian startup hacked the world (Reuters) 

Scama: Uncovering the Dark Marketplace for Phishing Kits (Vade Secure)

Ukraine Tracks a Record Number of Cyber Incidents During War (Bank Info Security) 

Russia will target other countries for web attacks, Ukraine cyber defence chief warns (The Irish Times) 

Sandworm Linked to Attack on Danish Critical Infrastructure (Infosecurity Magazine) 

Why cyber war readiness is critical for democracies (Help Net Security) 

Extract Knowledge
Listen elsewhere
Published 2023-11-16

Shopping during wartime? Focus, people.

29 min
View

Cyber safety for the holidays. Using regulatory risk to pressure a ransomware victim. A call for regulatory action against a supply chain threat. Rhysida malware: a warning and a description. Extending local breaches in Google Workspace. Protestware in open-source products. GRU's Sandworm implicated in campaign against Danish electrical power providers. Jason Meller, Founder & CEO of Kolide joins us as part of our sponsored Industry Voices segment to discuss the findings from The Shadow IT Report. In this Threat Vector segment, David Moulton sits down with Sama Manchanda, a consultant at Unit 42 to discuss the fascinating world of social engineering attacks. And donation scams: exploiting sympathy.

In this Threat Vector segment, David Moulton engages in an enlightening conversation with Sama Manchanda, a consultant at Unit 42. The duo embarks on an exploration of the fascinating world of social engineering attacks, delving into the distinct characteristics of phishing, smishing, and vishing.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/219


Threat Vector

Please share your thoughts with us for future Threat Vector segments by taking our brief survey.

To learn what is top of mind each month from the experts at Unit 42 sign up for their Threat Intel Bulletin


Selected reading.

New Visa Report Tells Consumers to Stay Alert this Holiday Shopping Season (Business Wire)

Ransomware gang files SEC complaint over victim’s undisclosed breach (BleepingComputer)

11-14-2023 EFF Letter to FTC re: Malware on Android TV Set-Top Boxes (EFF)

#StopRansomware: Rhysida Ransomware (Cybersecurity and Infrastructure Security Agency | CISA)

Investigating the New Rhysida Ransomware (Fortinet Blog)

Analyzing Rhysida Ransomware Intrusion (Fortinet Blog)

The Chain Reaction: New Methods for Extending Local Breaches in Google Workspace (Bitdefender)

Protestware taps npm to call out wars in Ukraine, Gaza (ReversingLabs)

Russia's Sandworm Linked to Unprecedented Danish Energy Hack (Bloomberg).

Russian Hackers Linked to 'Largest Ever Cyber Attack' on Danish Critical Infrastructure (The Hacker News)

Denmark hit with largest cyberattack on record (Cybernews)

Attackers Exploit Crisis for Fraudulent Crypto Donations (Abnormal)

More description

Cyber safety for the holidays. Using regulatory risk to pressure a ransomware victim. A call for regulatory action against a supply chain threat. Rhysida malware: a warning and a description. Extending local breaches in Google Workspace. Protestware in open-source products. GRU's Sandworm implicated in campaign against Danish electrical power providers. Jason Meller, Founder & CEO of Kolide joins us as part of our sponsored Industry Voices segment to discuss the findings from The Shadow IT Report. In this Threat Vector segment, David Moulton sits down with Sama Manchanda, a consultant at Unit 42 to discuss the fascinating world of social engineering attacks. And donation scams: exploiting sympathy.

In this Threat Vector segment, David Moulton engages in an enlightening conversation with Sama Manchanda, a consultant at Unit 42. The duo embarks on an exploration of the fascinating world of social engineering attacks, delving into the distinct characteristics of phishing, smishing, and vishing.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/219


Threat Vector

Please share your thoughts with us for future Threat Vector segments by taking our brief survey.

To learn what is top of mind each month from the experts at Unit 42 sign up for their Threat Intel Bulletin


Selected reading.

New Visa Report Tells Consumers to Stay Alert this Holiday Shopping Season (Business Wire)

Ransomware gang files SEC complaint over victim’s undisclosed breach (BleepingComputer)

11-14-2023 EFF Letter to FTC re: Malware on Android TV Set-Top Boxes (EFF)

#StopRansomware: Rhysida Ransomware (Cybersecurity and Infrastructure Security Agency | CISA)

Investigating the New Rhysida Ransomware (Fortinet Blog)

Analyzing Rhysida Ransomware Intrusion (Fortinet Blog)

The Chain Reaction: New Methods for Extending Local Breaches in Google Workspace (Bitdefender)

Protestware taps npm to call out wars in Ukraine, Gaza (ReversingLabs)

Russia's Sandworm Linked to Unprecedented Danish Energy Hack (Bloomberg).

Russian Hackers Linked to 'Largest Ever Cyber Attack' on Danish Critical Infrastructure (The Hacker News)

Denmark hit with largest cyberattack on record (Cybernews)

Attackers Exploit Crisis for Fraudulent Crypto Donations (Abnormal)

Extract Knowledge
Listen elsewhere

In this episode of CyberWire-X, N2K’s CSO, Chief Analyst, and Senior Fellow, Rick Howard, is joined by guest Rohit Dhamankar, Fortra's Vice President of Product Strategy, and Hash Table member Steve Winterfeld, Akamai's Advisory CISO to discuss CISO initiatives such as vendor consolidation, automation, and attack surface management as a way to determine if it’s possible to achieve both increased security maturity and decreased operational load. This session covers common mistakes when adopting security technologies, including the pros and cons of AI, and how to better collaborate together.

More description

In this episode of CyberWire-X, N2K’s CSO, Chief Analyst, and Senior Fellow, Rick Howard, is joined by guest Rohit Dhamankar, Fortra's Vice President of Product Strategy, and Hash Table member Steve Winterfeld, Akamai's Advisory CISO to discuss CISO initiatives such as vendor consolidation, automation, and attack surface management as a way to determine if it’s possible to achieve both increased security maturity and decreased operational load. This session covers common mistakes when adopting security technologies, including the pros and cons of AI, and how to better collaborate together.

Extract Knowledge
Listen elsewhere

A look back at Patch Tuesday. BlackCat uses malicious Google ads. Social engineering in the third quarter of 2023. Are small businesses in denial about ransomware? Molerats have some new tools. Israel turns to NSO Group's Pegasus to search for hostages taken by Hamas. Tim Starks from the Washington Post examines the potential aftermath of a Russian group hitting a Chinese bank. In our Learning Layer, Sam Meisenberg helps a student understand and create a strategy for the CISSP CAT. And a cyberespionage campaign is attributed to Russia's SVR.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/218


Selected reading.

Adobe Releases Security Updates for Multiple Products | CISA (Cybersecurity and Infrastructure Security Agency CISA) 

Fortinet Releases Security Updates for FortiClient and FortiGate (Cybersecurity and Infrastructure Security Agency | CISA) 

VMware Releases Security Update for Cloud Director Appliance (Cybersecurity and Infrastructure Security Agency | CISA) 

CISA Releases Two Industrial Control Systems Advisories (Cybersecurity and Infrastructure Security Agency | CISA) 

Microsoft Releases October 2023 Security Updates (Cybersecurity and Infrastructure Security Agency | CISA) 

Microsoft November 2023 Patch Tuesday fixes 5 zero-days, 58 flaws (BleepingComputer)

SAP Security Patch Day for November 2023 (Onapsis)

The ALPHV/BlackCat Ransomware Gang is Using Google Ads to Conduct… (eSentire)

Q3 2023 Threat Landscape Report: Social Engineering Takes Center Stage (Kroll) 

OpenText Cybersecurity 2023 Global Ransomware Survey: The risk perception gap (OpenText Blogs)

TA402 Uses Complex IronWind Infection Chains to Target Middle East-Based Government Entities (Proofpoint) 

Israel's NSO unleashes controversial spyware in Gaza conflict (Axios) 

APT29 Attacks Embassies Using CVE-2023-38831 (NCSCC)

Cyber-espionage operation on embassies linked to Russia’s Cozy Bear hackers (Record)

More description

A look back at Patch Tuesday. BlackCat uses malicious Google ads. Social engineering in the third quarter of 2023. Are small businesses in denial about ransomware? Molerats have some new tools. Israel turns to NSO Group's Pegasus to search for hostages taken by Hamas. Tim Starks from the Washington Post examines the potential aftermath of a Russian group hitting a Chinese bank. In our Learning Layer, Sam Meisenberg helps a student understand and create a strategy for the CISSP CAT. And a cyberespionage campaign is attributed to Russia's SVR.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/218


Selected reading.

Adobe Releases Security Updates for Multiple Products | CISA (Cybersecurity and Infrastructure Security Agency CISA) 

Fortinet Releases Security Updates for FortiClient and FortiGate (Cybersecurity and Infrastructure Security Agency | CISA) 

VMware Releases Security Update for Cloud Director Appliance (Cybersecurity and Infrastructure Security Agency | CISA) 

CISA Releases Two Industrial Control Systems Advisories (Cybersecurity and Infrastructure Security Agency | CISA) 

Microsoft Releases October 2023 Security Updates (Cybersecurity and Infrastructure Security Agency | CISA) 

Microsoft November 2023 Patch Tuesday fixes 5 zero-days, 58 flaws (BleepingComputer)

SAP Security Patch Day for November 2023 (Onapsis)

The ALPHV/BlackCat Ransomware Gang is Using Google Ads to Conduct… (eSentire)

Q3 2023 Threat Landscape Report: Social Engineering Takes Center Stage (Kroll) 

OpenText Cybersecurity 2023 Global Ransomware Survey: The risk perception gap (OpenText Blogs)

TA402 Uses Complex IronWind Infection Chains to Target Middle East-Based Government Entities (Proofpoint) 

Israel's NSO unleashes controversial spyware in Gaza conflict (Axios) 

APT29 Attacks Embassies Using CVE-2023-38831 (NCSCC)

Cyber-espionage operation on embassies linked to Russia’s Cozy Bear hackers (Record)

Extract Knowledge
Listen elsewhere

CISA and the FBI issue an update on Royal Ransomware. A look at Smash-and-grab ransomware attacks as well as Cloud vulnerabilities. A pre-Black Friday look at card skimmers. Fences, and their place in organized cybercrime. DP World Australia restores port operations. Joe Carrigan on scammers taking advantage of the Bitrex crypto market being shut down. In our Industry Voices segment, Usama Houlila from CrossRealms International shares his insights on the pivotal role of AI in cybersecurity. And LockBit may be drawing unwelcome attention to itself. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/217


Selected reading.

#StopRansomware: Royal Ransomware (Cybersecurity and Infrastructure Security Agency | CISA) 

FBI: Royal ransomware asked 350 victims to pay $275 million (BleepingComputer) 

The Song Remains the Same: The 2023 Active Adversary Report for Security Practitioners (Sophos)

Why 93% of Security Leaders Say Cloud Security Requires Zero Trust Segmentation (Illumio Cybersecurity Blog)

Malwarebytes Labs Reveals 50% Uptick in Credit Card Skimming in Advance of the Holiday Shopping Season (PR Newswire) 

Credit card skimming on the rise for the holiday shopping season (Malwarebytes)

The Fencers: The Lynchpin of Organized Retail Crime Enterprise (Nisos)

DP World cyberattack blocks thousands of containers in ports (BleepingComputer)

Operations at Major Australian Ports Significantly Disrupted by Cyberattack (SecurityWeek) 

Australian Ports Recover From Cyber Incident (Bank Info Security)

DP World: Australia sites back online after cyber-attack (BBC News)

Australian ports resume some operations after major cyberattack (CNN)

Australia Cyberattack Leaves 30,000 Containers Stuck at Ports (Bloomberg) 

Hacking Gang Behind Attack on Largest Global Lender Says It Got Ransom Payment (Bloomberg)

Gang says ICBC paid ransom over hack that disrupted US Treasury market (Reuters) 

After a surprise cyberattack, the world's largest bank had to shuffle a USB stick around Manhattan to do business (PC Gamer)

WSJ News Exclusive | ICBC Hackers Used Methods Previously Flagged by U.S. Authorities (Wall Street Journal) 

Inside Wall Street's scramble after ICBC hack (Reuters) 

Did a ransomware gang mess up by attacking a U.S. arm of China’s biggest bank? (Washington Post)

More description

CISA and the FBI issue an update on Royal Ransomware. A look at Smash-and-grab ransomware attacks as well as Cloud vulnerabilities. A pre-Black Friday look at card skimmers. Fences, and their place in organized cybercrime. DP World Australia restores port operations. Joe Carrigan on scammers taking advantage of the Bitrex crypto market being shut down. In our Industry Voices segment, Usama Houlila from CrossRealms International shares his insights on the pivotal role of AI in cybersecurity. And LockBit may be drawing unwelcome attention to itself. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/217


Selected reading.

#StopRansomware: Royal Ransomware (Cybersecurity and Infrastructure Security Agency | CISA) 

FBI: Royal ransomware asked 350 victims to pay $275 million (BleepingComputer) 

The Song Remains the Same: The 2023 Active Adversary Report for Security Practitioners (Sophos)

Why 93% of Security Leaders Say Cloud Security Requires Zero Trust Segmentation (Illumio Cybersecurity Blog)

Malwarebytes Labs Reveals 50% Uptick in Credit Card Skimming in Advance of the Holiday Shopping Season (PR Newswire) 

Credit card skimming on the rise for the holiday shopping season (Malwarebytes)

The Fencers: The Lynchpin of Organized Retail Crime Enterprise (Nisos)

DP World cyberattack blocks thousands of containers in ports (BleepingComputer)

Operations at Major Australian Ports Significantly Disrupted by Cyberattack (SecurityWeek) 

Australian Ports Recover From Cyber Incident (Bank Info Security)

DP World: Australia sites back online after cyber-attack (BBC News)

Australian ports resume some operations after major cyberattack (CNN)

Australia Cyberattack Leaves 30,000 Containers Stuck at Ports (Bloomberg) 

Hacking Gang Behind Attack on Largest Global Lender Says It Got Ransom Payment (Bloomberg)

Gang says ICBC paid ransom over hack that disrupted US Treasury market (Reuters) 

After a surprise cyberattack, the world's largest bank had to shuffle a USB stick around Manhattan to do business (PC Gamer)

WSJ News Exclusive | ICBC Hackers Used Methods Previously Flagged by U.S. Authorities (Wall Street Journal) 

Inside Wall Street's scramble after ICBC hack (Reuters) 

Did a ransomware gang mess up by attacking a U.S. arm of China’s biggest bank? (Washington Post)

Extract Knowledge
Listen elsewhere

Australian ports are recovering from a cyberattack. SysAid is hit by Cl0p user Lace Tempest. Ransomware targets China's largest bank. LockBit doxes Boeing as Boeing hangs tough on paying ransom. Docker Engine for DDoS. Rick Howard looks at the SEC’s targeting of SolarWinds’ CISO. And Anonymous Sudan claims attacks on ChatGPT and Cloudflare.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/216


Selected reading.

Freight giant DP World recovers from cyber attack, but warns investigation and remediation is 'ongoing' (ABC)

DP World port operations in Australia recovering after cyber-attack (The Loadstar) 

Ransomware attack against China's largest bank. (CyberWire)

China's biggest lender ICBC hit by ransomware attack (Reuters)

Ransomware attack on ICBC disrupts trades in US Treasury market (Financial Times) 

Hackers Hit Wall Street Arm of Chinese Banking Giant ICBC (Wall Street Journal)

LockBit finally publishes its proof-of-hack as Boeing hangs tough. (CyberWire)

SysAid On-Prem Software CVE-2023-47246 Vulnerability (SysAid) 

Critical Vulnerability: SysAid CVE-2023-47246 (Huntress)

SysAid Zero-Day Vulnerability Exploited By Lace Tempest (Rapid7)

SysAid vulnerability exploited. (CyberWire)

OracleIV - A Dockerised DDoS Botnet (Cado Security)

Anonymous Sudan and OpenAI. (CyberWire)

Russia-Linked Hackers Claim Credit for OpenAI Outage This Week (Bloomberg) 

Major ChatGPT Outage Caused by DDoS Attack (SecurityWeek) 

Anonymous Sudan and Skynet claim Cloudflare DDoS takedown (Cyber Daily)

Cloudflare website downed by DDoS attack claimed by Anonymous Sudan (BleepingComputer)

More description

Australian ports are recovering from a cyberattack. SysAid is hit by Cl0p user Lace Tempest. Ransomware targets China's largest bank. LockBit doxes Boeing as Boeing hangs tough on paying ransom. Docker Engine for DDoS. Rick Howard looks at the SEC’s targeting of SolarWinds’ CISO. And Anonymous Sudan claims attacks on ChatGPT and Cloudflare.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/216


Selected reading.

Freight giant DP World recovers from cyber attack, but warns investigation and remediation is 'ongoing' (ABC)

DP World port operations in Australia recovering after cyber-attack (The Loadstar) 

Ransomware attack against China's largest bank. (CyberWire)

China's biggest lender ICBC hit by ransomware attack (Reuters)

Ransomware attack on ICBC disrupts trades in US Treasury market (Financial Times) 

Hackers Hit Wall Street Arm of Chinese Banking Giant ICBC (Wall Street Journal)

LockBit finally publishes its proof-of-hack as Boeing hangs tough. (CyberWire)

SysAid On-Prem Software CVE-2023-47246 Vulnerability (SysAid) 

Critical Vulnerability: SysAid CVE-2023-47246 (Huntress)

SysAid Zero-Day Vulnerability Exploited By Lace Tempest (Rapid7)

SysAid vulnerability exploited. (CyberWire)

OracleIV - A Dockerised DDoS Botnet (Cado Security)

Anonymous Sudan and OpenAI. (CyberWire)

Russia-Linked Hackers Claim Credit for OpenAI Outage This Week (Bloomberg) 

Major ChatGPT Outage Caused by DDoS Attack (SecurityWeek) 

Anonymous Sudan and Skynet claim Cloudflare DDoS takedown (Cyber Daily)

Cloudflare website downed by DDoS attack claimed by Anonymous Sudan (BleepingComputer)

Extract Knowledge
Listen elsewhere

Grace Cassy, and Associate Fellow from Ten Eleven Ventures sits down to share her career path, getting her to where she is now. Grace spent 10 years in the UK Diplomatic Service, working on global security policy in Asia, Europe, and the Americas. Earlier in her career she was an advisor to Prime Minister Tony Blair, specializing in Asia and national security. She also co-founded Epsilon Advisory Partners, a strategy and growth firm working with world-leading global technology companies and investors. Now she is a Co-founder at CyLon and is an Early Stage Investor in cybersecurity companies. She says "I think we probably don't need too many more words, but we definitely need a bit more action." We thank Grace for sharing her story with us.

More description

Grace Cassy, and Associate Fellow from Ten Eleven Ventures sits down to share her career path, getting her to where she is now. Grace spent 10 years in the UK Diplomatic Service, working on global security policy in Asia, Europe, and the Americas. Earlier in her career she was an advisor to Prime Minister Tony Blair, specializing in Asia and national security. She also co-founded Epsilon Advisory Partners, a strategy and growth firm working with world-leading global technology companies and investors. Now she is a Co-founder at CyLon and is an Early Stage Investor in cybersecurity companies. She says "I think we probably don't need too many more words, but we definitely need a bit more action." We thank Grace for sharing her story with us.

Extract Knowledge
Listen elsewhere

CISA, FEMA, and Shields Ready. Ransomware operators exploit 3rd-party tools. A Bittrex bankruptcy phishing campaign. Spammers abuse Google Forms quizzes. Imperial Kitten in action against Israeli targets. Iranian cyberattacks against Israel are called "reactive and opportunistic." In our sponsored Industry Voices segment, Adam Bateman from Push Security outlines how attackers are targeting cloud identities. Luke Vander Linden from RH-ISAC speaks with Target's Ryan Miller and Leah Schwartzman about the evolving fraud landscape retailers are facing with the holidays approaching. And Sandworm and Ukraine's power grid: 2022 attacks may foreshadow the winter of 2023 and 2024.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/215


Selected reading.

Shields Ready | CISA (Cybersecurity and Infrastructure Security Agency CISA) 

DHS Unveils New Shields Ready Campaign to Promote Critical Infrastructure Security and Resilience (FEMA) 

US Urges Critical Infrastructure Firms to Get “Shields Ready” (Infosecurity Magazine) 

US launches “Shields Ready” campaign to secure critical infrastructure (CSO Online) 

DHS Launches New Critical Infrastructure Security and Resilience Campaign (SecurityWeek) 

Ransomware Actors Continue to Gain Access through Third Parties and Legitimate System Tools (FBI) 

Phishing Attack Driven by Bittrex Bankruptcy (Abnormal) 

Spammers abuse Google Forms’ quiz to deliver scams (Cisco Talos Blog)

IMPERIAL KITTEN Deploys Novel Malware Families in Middle East-Focused Operations (CrowdStrike)

Microsoft shares threat intelligence at CYBERWARCON 2023 (Microsoft Security)

Iran and Hamas showed no signs of cyber coordination in run-up to war, researchers say (Washington Post) 

Sandworm Disrupts Power in Ukraine Using a Novel Attack Against Operational Technology (Mandiant)

Russian spies behind cyber attack on Ukraine power grid in 2022 - researchers (Reuters) 

Hackers Linked To Russian Intelligence Blamed For 2022 Ukraine Grid Disruption (RadioFreeEurope/RadioLiberty) 

Ukraine updates: Russia hacked Kyiv's power grid — report – DW – 11/09/2023 (Deutsche Welle) 

Russian Hackers Used OT Attack to Disrupt Power in Ukraine Amid Mass Missile Strikes (SecurityWeek) 

Energy security at forefront of NATO-Ukraine Council meeting (NATO)

More description

CISA, FEMA, and Shields Ready. Ransomware operators exploit 3rd-party tools. A Bittrex bankruptcy phishing campaign. Spammers abuse Google Forms quizzes. Imperial Kitten in action against Israeli targets. Iranian cyberattacks against Israel are called "reactive and opportunistic." In our sponsored Industry Voices segment, Adam Bateman from Push Security outlines how attackers are targeting cloud identities. Luke Vander Linden from RH-ISAC speaks with Target's Ryan Miller and Leah Schwartzman about the evolving fraud landscape retailers are facing with the holidays approaching. And Sandworm and Ukraine's power grid: 2022 attacks may foreshadow the winter of 2023 and 2024.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/215


Selected reading.

Shields Ready | CISA (Cybersecurity and Infrastructure Security Agency CISA) 

DHS Unveils New Shields Ready Campaign to Promote Critical Infrastructure Security and Resilience (FEMA) 

US Urges Critical Infrastructure Firms to Get “Shields Ready” (Infosecurity Magazine) 

US launches “Shields Ready” campaign to secure critical infrastructure (CSO Online) 

DHS Launches New Critical Infrastructure Security and Resilience Campaign (SecurityWeek) 

Ransomware Actors Continue to Gain Access through Third Parties and Legitimate System Tools (FBI) 

Phishing Attack Driven by Bittrex Bankruptcy (Abnormal) 

Spammers abuse Google Forms’ quiz to deliver scams (Cisco Talos Blog)

IMPERIAL KITTEN Deploys Novel Malware Families in Middle East-Focused Operations (CrowdStrike)

Microsoft shares threat intelligence at CYBERWARCON 2023 (Microsoft Security)

Iran and Hamas showed no signs of cyber coordination in run-up to war, researchers say (Washington Post) 

Sandworm Disrupts Power in Ukraine Using a Novel Attack Against Operational Technology (Mandiant)

Russian spies behind cyber attack on Ukraine power grid in 2022 - researchers (Reuters) 

Hackers Linked To Russian Intelligence Blamed For 2022 Ukraine Grid Disruption (RadioFreeEurope/RadioLiberty) 

Ukraine updates: Russia hacked Kyiv's power grid — report – DW – 11/09/2023 (Deutsche Welle) 

Russian Hackers Used OT Attack to Disrupt Power in Ukraine Amid Mass Missile Strikes (SecurityWeek) 

Energy security at forefront of NATO-Ukraine Council meeting (NATO)

Extract Knowledge
Listen elsewhere

CISA claims "No credible threats" to yesterday's US elections. Criminals seek to profit from the .ai top level domain. A Singapore resort sustains a cyberattack. A look ahead at holiday cyber threats. A major Chinese cyberespionage effort against Cambodia. The four cyber phases of a hybrid war. Robert M. Lee from Dragos explains how outside forces affect OT and critical infrastructure security.  Our guest is Dan Neault of Imperva sharing how organizations are behind the eight-ball when relying upon real-time analytics. Cyber and electronic threats to space systems.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/214


Selected reading.

CISA Sees Smooth Election Day Operations, No ‘Credible’ Threats (Meritalk) 

The rise of .ai: cyber criminals (and Anguilla) look to profit (Netcraft) 

Singapore’s Marina Bay Sands Says It Was Hit in Data Breach (Bloomberg)

Marina Bay Sands discloses data breach impacting 665,000 customers (BleepingComputer)

Personal data of 665,000 Marina Bay Sands lifestyle rewards members accessed in data security breach (CNA)

Report Examines Cyber Threat Trends Facing Retail and Hospitality This Holiday Season (RH-ISAC)

Chinese APT Targeting Cambodian Government (Unit 42) 

Chinese cyberspies have widely penetrated networks of ally Cambodia (Washington Post) 

Cyber Escalation in Modern Conflict: Exploring Four Possible Phases of the Digital Battlefield (Flashpoint)

Cyber Security of Space Systems ‘Crucial,’ As US Space Force Official Notes Recent Attacks (Via Satellite)

More description

CISA claims "No credible threats" to yesterday's US elections. Criminals seek to profit from the .ai top level domain. A Singapore resort sustains a cyberattack. A look ahead at holiday cyber threats. A major Chinese cyberespionage effort against Cambodia. The four cyber phases of a hybrid war. Robert M. Lee from Dragos explains how outside forces affect OT and critical infrastructure security.  Our guest is Dan Neault of Imperva sharing how organizations are behind the eight-ball when relying upon real-time analytics. Cyber and electronic threats to space systems.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/214


Selected reading.

CISA Sees Smooth Election Day Operations, No ‘Credible’ Threats (Meritalk) 

The rise of .ai: cyber criminals (and Anguilla) look to profit (Netcraft) 

Singapore’s Marina Bay Sands Says It Was Hit in Data Breach (Bloomberg)

Marina Bay Sands discloses data breach impacting 665,000 customers (BleepingComputer)

Personal data of 665,000 Marina Bay Sands lifestyle rewards members accessed in data security breach (CNA)

Report Examines Cyber Threat Trends Facing Retail and Hospitality This Holiday Season (RH-ISAC)

Chinese APT Targeting Cambodian Government (Unit 42) 

Chinese cyberspies have widely penetrated networks of ally Cambodia (Washington Post) 

Cyber Escalation in Modern Conflict: Exploring Four Possible Phases of the Digital Battlefield (Flashpoint)

Cyber Security of Space Systems ‘Crucial,’ As US Space Force Official Notes Recent Attacks (Via Satellite)

Extract Knowledge
Listen elsewhere

Data brokers offer information on active US military personnel. Current BlueNoroff activity. A new Gootloader variant is active in the wild. Atlassian vulnerabilities actively exploited. The prevalence of breaches. Update on a Barracuda vulnerability. Hacktivism and the cyber course of the Hamas-Israel war. Bot-hunting in Ukraine. Microsoft’s Ann Johnson from Afternoon Cyber Tea speaks with Sharon Barber, Chief Information Officer at Lloyds Banking Group, about cyber trends in financial services. Ben Yelin looks at the ease of purchasing US military personnel data from data brokers And election security is in the news–an off-year election is an election nonetheless.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/213


Selected reading.

Researchers find sensitive personal data of US military personnel is for sale online (CNN)

How foreigners can buy data on US military members, for the right price (POLITICO)

GootBot - Gootloader's new approach to post-exploitation (Security Intelligence)

BlueNoroff strikes again with new macOS malware (Jamf)

GootBot - Gootloader's new approach to post-exploitation (Security Intelligence)

Rapid7-Observed Exploitation of Atlassian Confluence CVE-2023-22518 (Rapid7) 

Armis Research Finds One-Third of Global Organizations Experienced Multiple Security Breaches in Last 12 Months (Armis)

Technical analysis: Barracuda Email Security Gateway by Quentin Olagne (Vectra) 

Maccabi Tel Aviv basketball team website comes under cyber attack (The Jerusalem Post) 

The Digital Frontline of the Israel-Hamas Conflict Could Extend Long After the War (Inkstick) 

Five attack vectors that businesses should focus on in the wake of the Israel-Hamas war (SC Media) 

Israel’s cyber defense chief tells CNN he is concerned Iran could increase severity of its cyberattacks (CNN)

SBU blocks 76 bot farms with 3 mln fake accounts since start of full-scale war (Interfax-Ukraine) 

On Election Day, CISA and Partners Coordinate on Security Operations (Cybersecurity and Infrastructure Security Agency)

Cerby Releases “Threat Briefing: Social Media Security and Elections Volume II,” Providing a Detailed Analysis of Security Gaps in Social Media Platforms (Cerby)

More description

Data brokers offer information on active US military personnel. Current BlueNoroff activity. A new Gootloader variant is active in the wild. Atlassian vulnerabilities actively exploited. The prevalence of breaches. Update on a Barracuda vulnerability. Hacktivism and the cyber course of the Hamas-Israel war. Bot-hunting in Ukraine. Microsoft’s Ann Johnson from Afternoon Cyber Tea speaks with Sharon Barber, Chief Information Officer at Lloyds Banking Group, about cyber trends in financial services. Ben Yelin looks at the ease of purchasing US military personnel data from data brokers And election security is in the news–an off-year election is an election nonetheless.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/213


Selected reading.

Researchers find sensitive personal data of US military personnel is for sale online (CNN)

How foreigners can buy data on US military members, for the right price (POLITICO)

GootBot - Gootloader's new approach to post-exploitation (Security Intelligence)

BlueNoroff strikes again with new macOS malware (Jamf)

GootBot - Gootloader's new approach to post-exploitation (Security Intelligence)

Rapid7-Observed Exploitation of Atlassian Confluence CVE-2023-22518 (Rapid7) 

Armis Research Finds One-Third of Global Organizations Experienced Multiple Security Breaches in Last 12 Months (Armis)

Technical analysis: Barracuda Email Security Gateway by Quentin Olagne (Vectra) 

Maccabi Tel Aviv basketball team website comes under cyber attack (The Jerusalem Post) 

The Digital Frontline of the Israel-Hamas Conflict Could Extend Long After the War (Inkstick) 

Five attack vectors that businesses should focus on in the wake of the Israel-Hamas war (SC Media) 

Israel’s cyber defense chief tells CNN he is concerned Iran could increase severity of its cyberattacks (CNN)

SBU blocks 76 bot farms with 3 mln fake accounts since start of full-scale war (Interfax-Ukraine) 

On Election Day, CISA and Partners Coordinate on Security Operations (Cybersecurity and Infrastructure Security Agency)

Cerby Releases “Threat Briefing: Social Media Security and Elections Volume II,” Providing a Detailed Analysis of Security Gaps in Social Media Platforms (Cerby)

Extract Knowledge
Listen elsewhere

A precautionary shutdown at a major US mortgage lender. Call centers as targets. A push to decouple data and identity. The cyber front in the Hamas-Israeli war. Hacktivism and state-sponsored cyberattacks against Israel. The instructive case of TASS and managing influence operations. Deepen Desai from Zscaler talking about the TOITOIN Trojan. Our guest is Joe Nocera, of PwC sharing their latest Global Digital Trust Insights survey and the impact of the SEC's new cybersecurity disclosure rules. And cybercrime on the side of Ukraine (or at least, cybercrime against Russia).


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/212


Selected reading.

Mortgage Giant Mr. Cooper Shuts Down Systems Following Cyberattack (SecurityWeek)

TransUnion Report Shows Fraud Attacks on Financial Industry Call Centers Rising (Transunion)

A Bold New Plan to Make Cloud Computing More Secure (IEEE Spectrum) 

The Cyberwarfare Front of the Israel-Gaza War (The National Interest)

Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors (Unit 42)

GhostSec offers Ransomware-as-a-Service Possibly Used to Target Israel (Uptycs) 

Kremlin Sacks TASS Chief for Wagner Mutiny Coverage (The Moscow Times) 

Russia's 2nd-Largest Insurer Rosgosstrakh Hacked; 400GB of Data Sold Online (Hackread - Latest Cybersecurity News, Press Releases & Technology Today)

More description

A precautionary shutdown at a major US mortgage lender. Call centers as targets. A push to decouple data and identity. The cyber front in the Hamas-Israeli war. Hacktivism and state-sponsored cyberattacks against Israel. The instructive case of TASS and managing influence operations. Deepen Desai from Zscaler talking about the TOITOIN Trojan. Our guest is Joe Nocera, of PwC sharing their latest Global Digital Trust Insights survey and the impact of the SEC's new cybersecurity disclosure rules. And cybercrime on the side of Ukraine (or at least, cybercrime against Russia).


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/212


Selected reading.

Mortgage Giant Mr. Cooper Shuts Down Systems Following Cyberattack (SecurityWeek)

TransUnion Report Shows Fraud Attacks on Financial Industry Call Centers Rising (Transunion)

A Bold New Plan to Make Cloud Computing More Secure (IEEE Spectrum) 

The Cyberwarfare Front of the Israel-Gaza War (The National Interest)

Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors (Unit 42)

GhostSec offers Ransomware-as-a-Service Possibly Used to Target Israel (Uptycs) 

Kremlin Sacks TASS Chief for Wagner Mutiny Coverage (The Moscow Times) 

Russia's 2nd-Largest Insurer Rosgosstrakh Hacked; 400GB of Data Sold Online (Hackread - Latest Cybersecurity News, Press Releases & Technology Today)

Extract Knowledge
Listen elsewhere

As we progress in this technological age, both cybersecurity and critical infrastructure continue to be at the forefront of prevention, protection, mitigation, and recovery conversation topics. From a frontline worker to the top of the C-Suite, security is something we all should be aware of and concerned about. The CyberCon event began in 2018 and provides an opportunity to learn more about cybersecurity and critical infrastructure as well as collaborate with fellow security professionals. 

Dave Bittner recently spoke at CyberCon 2023 at Bismarck State College in North Dakota. While there, he had the opportunity to interview 4 members of the conference planning committee (all past or current chairs of the event) for a better understanding of the event, its focus on a mix of critical infrastructure and cybersecurity, and how the event has evolved over the years.

Dave speaks with:

  • Troy Walker, Director of Sales and Marketing at Dakota Carrier Network & 2023 conference chair, sharing the history of CyberCon its unique focus on critical infrastructure and cybersecurity.
  • Tony Aukland, Technology Outreach Manager for the State of North Dakota IT & previous conference chair, giving us the truth about CyberCon and its origin story.
  • Bill Heinzen, Information Security Team Lead at National Information Solutions Cooperative and previous event chair, talking about developing the cybersecurity candidate pool in North Dakota.
  • John Nagel, CEO and Founder of CYBERNET SECURITY and past event chair, discussing sustainability of the CyberCon and its critical infrastructure focus.
More description

As we progress in this technological age, both cybersecurity and critical infrastructure continue to be at the forefront of prevention, protection, mitigation, and recovery conversation topics. From a frontline worker to the top of the C-Suite, security is something we all should be aware of and concerned about. The CyberCon event began in 2018 and provides an opportunity to learn more about cybersecurity and critical infrastructure as well as collaborate with fellow security professionals. 

Dave Bittner recently spoke at CyberCon 2023 at Bismarck State College in North Dakota. While there, he had the opportunity to interview 4 members of the conference planning committee (all past or current chairs of the event) for a better understanding of the event, its focus on a mix of critical infrastructure and cybersecurity, and how the event has evolved over the years.

Dave speaks with:

  • Troy Walker, Director of Sales and Marketing at Dakota Carrier Network & 2023 conference chair, sharing the history of CyberCon its unique focus on critical infrastructure and cybersecurity.
  • Tony Aukland, Technology Outreach Manager for the State of North Dakota IT & previous conference chair, giving us the truth about CyberCon and its origin story.
  • Bill Heinzen, Information Security Team Lead at National Information Solutions Cooperative and previous event chair, talking about developing the cybersecurity candidate pool in North Dakota.
  • John Nagel, CEO and Founder of CYBERNET SECURITY and past event chair, discussing sustainability of the CyberCon and its critical infrastructure focus.
Extract Knowledge
Listen elsewhere

Jeffrey Wheatman, Cyber Risk Evangelist, from Black Kite joins to share his amazing story. As a strategic thought leader with extensive expertise in cybersecurity, Jeffrey Wheatman is regarded foremost as an expert in guiding public sector clients and Fortune 500 companies in connection with their cyber risk management programs. In his current role as Cyber Risk Evangelist at Black Kite, Jeffrey works to get the message out about the business impact of third-party risk and solutions to treat those risks. Jeffrey shared his career, along with is passion for cyber by explaining some of the roles he did moving up into his role today. He says as a leader we all need to be aware of the fact that "We make mistakes and I I'm a, I'm a big believer in sharing those mistakes and I think it's important to open the raincoat as it were, and let people understand that we're not perfect, we all need help and then that way they feel comfortable coming to you and asking for help" We thank Jeffrey for sharing his story with us.

More description

Jeffrey Wheatman, Cyber Risk Evangelist, from Black Kite joins to share his amazing story. As a strategic thought leader with extensive expertise in cybersecurity, Jeffrey Wheatman is regarded foremost as an expert in guiding public sector clients and Fortune 500 companies in connection with their cyber risk management programs. In his current role as Cyber Risk Evangelist at Black Kite, Jeffrey works to get the message out about the business impact of third-party risk and solutions to treat those risks. Jeffrey shared his career, along with is passion for cyber by explaining some of the roles he did moving up into his role today. He says as a leader we all need to be aware of the fact that "We make mistakes and I I'm a, I'm a big believer in sharing those mistakes and I think it's important to open the raincoat as it were, and let people understand that we're not perfect, we all need help and then that way they feel comfortable coming to you and asking for help" We thank Jeffrey for sharing his story with us.

Extract Knowledge
Listen elsewhere

Aleksandar Milenkoski and JAGS from SentinelOne sits down to share their work on "Sandman APT | A Mystery Group Targeting Telcos with a LuaJIT Toolkit." After observing a new threat activity cluster by an unknown threat actor in August of this year, SentinelLabs dubbed it Sandman.

The research states "Sandman has been primarily targeting telecommunication providers in the Middle East, Western Europe, and the South Asian subcontinent." Sandman has deployed a novel modular backdoor utilizing the LuaJIT platform, they call this malware "LuaDream," which exfiltrates system and user information, paving the way for further precision attacks.

The research can be found here:

More description

Aleksandar Milenkoski and JAGS from SentinelOne sits down to share their work on "Sandman APT | A Mystery Group Targeting Telcos with a LuaJIT Toolkit." After observing a new threat activity cluster by an unknown threat actor in August of this year, SentinelLabs dubbed it Sandman.

The research states "Sandman has been primarily targeting telecommunication providers in the Middle East, Western Europe, and the South Asian subcontinent." Sandman has deployed a novel modular backdoor utilizing the LuaJIT platform, they call this malware "LuaDream," which exfiltrates system and user information, paving the way for further precision attacks.

The research can be found here:

Extract Knowledge
Listen elsewhere

An Apache vulnerability is being used to install ransomware. Exploitation of Citrix vulnerability in the wild. AP sustains DDoS attack. HHS reaches settlement in HIPAA data breach incident. More evidence of OSINT's reach. On the Solution Spotlight: Simone Petrella and Rick Howard speak with Ben Rothke about his article and thoughts on "Is there really an information security jobs crisis?" Andrea Little Limbago from Interos joins us to discuss SEC and the disclosure rules. And, Microsoft draws a lesson from Russia's war: cyber defense now has the advantage over cyber offense.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/211


Selected reading.

Critical Apache ActiveMQ Vulnerability Exploited to Deliver Ransomware (SecurityWeek) 

HelloKitty ransomware now exploiting Apache ActiveMQ flaw in attacks (BleepingComputer) 

Critical Vulnerability: Exploitation of Apache ActiveMQ CVE-2023-46604 (Huntress) 

Suspected Exploitation of Apache ActiveMQ CVE-2023-46604 (Rapid7) 

HHS’ Office for Civil Rights Settles Ransomware Cyber-Attack Investigation (U.S. Department of Health and Human Services)

AP news site hit by apparent denial-of-service attack (AP News) 

Associated Press hit by Anonymous Sudan DDoS attack? (Tech Monitor)

Satellites and social media offer hints about Israel's ground war strategy in Gaza (NPR) 

Revisiting the Gaza Hospital Explosion (New York Times)

Microsoft Vows to Revamp Security Products After Repeated Hacks (Bloomberg) 

A new world of security: Microsoft’s Secure Future Initiative (Microsoft On the Issues) 

Announcing Microsoft Secure Future Initiative to advance security engineering (Microsoft Security) 

Ukraine at D+617: Advantage defense. (CyberWire)

More description

An Apache vulnerability is being used to install ransomware. Exploitation of Citrix vulnerability in the wild. AP sustains DDoS attack. HHS reaches settlement in HIPAA data breach incident. More evidence of OSINT's reach. On the Solution Spotlight: Simone Petrella and Rick Howard speak with Ben Rothke about his article and thoughts on "Is there really an information security jobs crisis?" Andrea Little Limbago from Interos joins us to discuss SEC and the disclosure rules. And, Microsoft draws a lesson from Russia's war: cyber defense now has the advantage over cyber offense.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/211


Selected reading.

Critical Apache ActiveMQ Vulnerability Exploited to Deliver Ransomware (SecurityWeek) 

HelloKitty ransomware now exploiting Apache ActiveMQ flaw in attacks (BleepingComputer) 

Critical Vulnerability: Exploitation of Apache ActiveMQ CVE-2023-46604 (Huntress) 

Suspected Exploitation of Apache ActiveMQ CVE-2023-46604 (Rapid7) 

HHS’ Office for Civil Rights Settles Ransomware Cyber-Attack Investigation (U.S. Department of Health and Human Services)

AP news site hit by apparent denial-of-service attack (AP News) 

Associated Press hit by Anonymous Sudan DDoS attack? (Tech Monitor)

Satellites and social media offer hints about Israel's ground war strategy in Gaza (NPR) 

Revisiting the Gaza Hospital Explosion (New York Times)

Microsoft Vows to Revamp Security Products After Repeated Hacks (Bloomberg) 

A new world of security: Microsoft’s Secure Future Initiative (Microsoft On the Issues) 

Announcing Microsoft Secure Future Initiative to advance security engineering (Microsoft Security) 

Ukraine at D+617: Advantage defense. (CyberWire)

Extract Knowledge
Listen elsewhere

Bletchley Declaration represents a consensus starting point for AI governance. Lazarus Group prospects blockchain engineers with KANDYKORN. Boeing investigates ‘cyber incident’ affecting parts business. NodeStealer’s use in attacks against Facebook accounts. Citrix Bleed vulnerability exploited in the wild. MuddyWater spearphishes Israeli targets in the interest of Hamas. India to investigate alleged attacks on iPhones. Tim Starks from the Washington Post on the SEC’s case against Solar Winds. In today’s Threat Vector segment David Moulton from Unit 42 is joined by Matt Kraning of the Cortex Expanse Team for a look at Attack Surface Management. And Venomous Bear rolls out some new tools.

On the Threat Vector segment, David Moulton, Director of Thought Leadership for Unit 42, is joined by Matt Kraning, CTO of the Cortex Expanse Team. They dive into the latest Attack Surface Management Report.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/210


Threat Vector

Read the Attack Surface Management Report.

Please share your thoughts with us for future Threat Vector segments by taking our brief survey.

To learn what is top of mind each month from the experts at Unit 42 sign up for their Threat Intel Bulletin


Selected reading.

The Bletchley Declaration by Countries Attending the AI Safety Summit, 1-2 November 2023 (GOV.UK)

US Vice President Harris calls for action on "full spectrum" of AI risks (Reuters) 

Elastic catches DPRK passing out KANDYKORN (Elastic Security Labs)

North Korean Hackers Targeting Crypto Experts with KANDYKORN macOS Malware (The Hacker News)

Lazarus used ‘Kandykorn’ malware in attempt to compromise exchange — Elastic (Cointelegraph) 

An info-stealer campaign is now targeting Facebook users with revealing photos (Record)

Mass Exploitation of 'Citrix Bleed' Vulnerability Underway (SecurityWeek)

MuddyWater eN-Able spear-phishing with new TTPs | Deep Instinct Blog (Deep Instinct) 

Centre's Cyber Watchdog CERT-In To Probe iPhone "Hacking" Attempt Charges (NDTV.com)

Over the Kazuar’s Nest: Cracking Down on a Freshly Hatched Backdoor Used by Pensive Ursa (Aka Turla) (Unit 42)

More description

Bletchley Declaration represents a consensus starting point for AI governance. Lazarus Group prospects blockchain engineers with KANDYKORN. Boeing investigates ‘cyber incident’ affecting parts business. NodeStealer’s use in attacks against Facebook accounts. Citrix Bleed vulnerability exploited in the wild. MuddyWater spearphishes Israeli targets in the interest of Hamas. India to investigate alleged attacks on iPhones. Tim Starks from the Washington Post on the SEC’s case against Solar Winds. In today’s Threat Vector segment David Moulton from Unit 42 is joined by Matt Kraning of the Cortex Expanse Team for a look at Attack Surface Management. And Venomous Bear rolls out some new tools.

On the Threat Vector segment, David Moulton, Director of Thought Leadership for Unit 42, is joined by Matt Kraning, CTO of the Cortex Expanse Team. They dive into the latest Attack Surface Management Report.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/210


Threat Vector

Read the Attack Surface Management Report.

Please share your thoughts with us for future Threat Vector segments by taking our brief survey.

To learn what is top of mind each month from the experts at Unit 42 sign up for their Threat Intel Bulletin


Selected reading.

The Bletchley Declaration by Countries Attending the AI Safety Summit, 1-2 November 2023 (GOV.UK)

US Vice President Harris calls for action on "full spectrum" of AI risks (Reuters) 

Elastic catches DPRK passing out KANDYKORN (Elastic Security Labs)

North Korean Hackers Targeting Crypto Experts with KANDYKORN macOS Malware (The Hacker News)

Lazarus used ‘Kandykorn’ malware in attempt to compromise exchange — Elastic (Cointelegraph) 

An info-stealer campaign is now targeting Facebook users with revealing photos (Record)

Mass Exploitation of 'Citrix Bleed' Vulnerability Underway (SecurityWeek)

MuddyWater eN-Able spear-phishing with new TTPs | Deep Instinct Blog (Deep Instinct) 

Centre's Cyber Watchdog CERT-In To Probe iPhone "Hacking" Attempt Charges (NDTV.com)

Over the Kazuar’s Nest: Cracking Down on a Freshly Hatched Backdoor Used by Pensive Ursa (Aka Turla) (Unit 42)

Extract Knowledge
Listen elsewhere

The Hamas-Israel war continues to be marked by hacktivism. Arid Viper's exploitation of Arabic speaker's Android devices. Iran shows improved cyberespionage capabilities. A URL shortener in the C2C market. Taking down the Mozi botnet. Ransomware in healthcare. Two are Russians arrested on treason charges, accused of hacking for Ukraine. In our sponsored Industry Voices segment, Anna Belak from Sysdig shares a new threat framework for the cloud. Rick Howard previews his new online course on cyber security first principles. And no, Russia hasn’t really replaced its currency with Arctic Ocean gastropods.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/209


Selected reading.

‘Hacktivists’ join the front lines in Israel-Hamas war (C4ISRNet) 

The global cyber divide between Gaza and Israel - IT-Online (IT-Online)

Arid Viper disguising mobile spyware as updates for non-malicious Android applications (Cisco Talos Blog)

In Cyberattacks, Iran Shows Signs of Improved Hacking Capabilities (New York Times)

FBI ‘keeping a close eye’ on Iranian hackers as Israel-Hamas war intensifies (Record)

Why Iran Is Gambling on Hamas (Foreign Affairs)

To Aid and Abet: Prolific Puma Helps Cybercriminals Evade Detection (Infoblox Blog)

Who killed Mozi? Finally putting the IoT zombie botnet in its grave (ESET)

The State of Ransomware in Healthcare 2023 (Sophos)

Russian security service detains two hackers allegedly working for Ukraine (Record) 

Pro-Ukraine group says it breached Russian card payment system (Record) 

More description

The Hamas-Israel war continues to be marked by hacktivism. Arid Viper's exploitation of Arabic speaker's Android devices. Iran shows improved cyberespionage capabilities. A URL shortener in the C2C market. Taking down the Mozi botnet. Ransomware in healthcare. Two are Russians arrested on treason charges, accused of hacking for Ukraine. In our sponsored Industry Voices segment, Anna Belak from Sysdig shares a new threat framework for the cloud. Rick Howard previews his new online course on cyber security first principles. And no, Russia hasn’t really replaced its currency with Arctic Ocean gastropods.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/209


Selected reading.

‘Hacktivists’ join the front lines in Israel-Hamas war (C4ISRNet) 

The global cyber divide between Gaza and Israel - IT-Online (IT-Online)

Arid Viper disguising mobile spyware as updates for non-malicious Android applications (Cisco Talos Blog)

In Cyberattacks, Iran Shows Signs of Improved Hacking Capabilities (New York Times)

FBI ‘keeping a close eye’ on Iranian hackers as Israel-Hamas war intensifies (Record)

Why Iran Is Gambling on Hamas (Foreign Affairs)

To Aid and Abet: Prolific Puma Helps Cybercriminals Evade Detection (Infoblox Blog)

Who killed Mozi? Finally putting the IoT zombie botnet in its grave (ESET)

The State of Ransomware in Healthcare 2023 (Sophos)

Russian security service detains two hackers allegedly working for Ukraine (Record) 

Pro-Ukraine group says it breached Russian card payment system (Record) 

Extract Knowledge
Listen elsewhere

Malicious packages are found attached to NuGet. Russia will establish its own substitute for VirusTotal. Commodity tools empower low-grade Russian cybercriminals. Malware mealkits, and other notes from the cyber underground. Insights from a Cybersecurity workforce study. Mr Security Answer Person John Pescatore looks at MFA. Drew Rose from Living Security on the very scary human side of cyber attacks. And more details from President Biden’s Executive Order on artificial intelligence.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/208


Selected reading.

IAmReboot: Malicious NuGet packages exploit loophole in MSBuild integrations (ReversingLabs) 

Russia to launch its own version of VirusTotal due to US snooping fears (Record).

Russian hacking tool floods social networks with bots, researchers say (Record) 

How Kopeechka, an Automated Social Media Accounts Creation Service, Can Facilitate Cybercrime (Trend Micro)

HP Wolf Security Threat Insights Report Q3 2023 (HP Wolf Security)

How the Economy, Skills Gap and Artificial Intelligence are Challenging the Global Cybersecurity Workforce (ISC2)

Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence (The White House)

More description

Malicious packages are found attached to NuGet. Russia will establish its own substitute for VirusTotal. Commodity tools empower low-grade Russian cybercriminals. Malware mealkits, and other notes from the cyber underground. Insights from a Cybersecurity workforce study. Mr Security Answer Person John Pescatore looks at MFA. Drew Rose from Living Security on the very scary human side of cyber attacks. And more details from President Biden’s Executive Order on artificial intelligence.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/208


Selected reading.

IAmReboot: Malicious NuGet packages exploit loophole in MSBuild integrations (ReversingLabs) 

Russia to launch its own version of VirusTotal due to US snooping fears (Record).

Russian hacking tool floods social networks with bots, researchers say (Record) 

How Kopeechka, an Automated Social Media Accounts Creation Service, Can Facilitate Cybercrime (Trend Micro)

HP Wolf Security Threat Insights Report Q3 2023 (HP Wolf Security)

How the Economy, Skills Gap and Artificial Intelligence are Challenging the Global Cybersecurity Workforce (ISC2)

Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence (The White House)

Extract Knowledge
Listen elsewhere

The Hive ransomware gang may be back, and rebranded. Coinminers exploit AWS IAM credentials. LockBit claims to have obtained sensitive information from Boeing. Ukrainian auxiliaries disrupt Internet service in Russian-occupied territory, while internet and telecoms are down in Gaza. Deepfakes have an effect even when they're not used. Joe Carrigan explains executive impersonations on social media. Our guest is David Brumley, cybersecurity professor at Carnegie Mellon and CEO of software security firm, ForAllSecure, discussing spooky zero days and vulnerabilities. And President Biden releases a US Executive Order on artificial intelligence.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/207


Selected reading.

New Hunters International ransomware possible rebrand of Hive (BleepingComputer) 

CloudKeys in the Air: Tracking Malicious Operations of Exposed IAM Keys (Palo Alto Networks Unit 42)

Boeing assessing Lockbit hacking gang threat of sensitive data leak (Reuters)

Ukrainian hackers disrupt internet providers in Russia-occupied territories (Record) 

Israel steps up air and ground attacks in Gaza and cuts off the territory's communications (AP News) 

The Destruction of Gaza’s Internet Is Complete (WIRED)

Rocket Alert Apps Warn Israelis of Incoming Attacks While Gaza Is Left in the Dark (WIRED).

Elon Musk’s Starlink to help Gaza amid internet blackout (Record)

Families of Hostages Kidnapped by Hamas Turn to Phone Pings for Proof of Life (WIRED)

Israel Taps Blacklisted Pegasus Maker to Track Hostages in Gaza (Bloomberg)

A.I. Muddies Israel-Hamas War in Unexpected Way (New York Times) 

FACT SHEET: President Biden Issues Executive Order on Safe, Secure, and Trustworthy Artificial Intelligence (The White House)

Administration Actions on AI (AI.gov) 

The US Executive Order on artificial intelligence is out. (CyberWire)

More description

The Hive ransomware gang may be back, and rebranded. Coinminers exploit AWS IAM credentials. LockBit claims to have obtained sensitive information from Boeing. Ukrainian auxiliaries disrupt Internet service in Russian-occupied territory, while internet and telecoms are down in Gaza. Deepfakes have an effect even when they're not used. Joe Carrigan explains executive impersonations on social media. Our guest is David Brumley, cybersecurity professor at Carnegie Mellon and CEO of software security firm, ForAllSecure, discussing spooky zero days and vulnerabilities. And President Biden releases a US Executive Order on artificial intelligence.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/207


Selected reading.

New Hunters International ransomware possible rebrand of Hive (BleepingComputer) 

CloudKeys in the Air: Tracking Malicious Operations of Exposed IAM Keys (Palo Alto Networks Unit 42)

Boeing assessing Lockbit hacking gang threat of sensitive data leak (Reuters)

Ukrainian hackers disrupt internet providers in Russia-occupied territories (Record) 

Israel steps up air and ground attacks in Gaza and cuts off the territory's communications (AP News) 

The Destruction of Gaza’s Internet Is Complete (WIRED)

Rocket Alert Apps Warn Israelis of Incoming Attacks While Gaza Is Left in the Dark (WIRED).

Elon Musk’s Starlink to help Gaza amid internet blackout (Record)

Families of Hostages Kidnapped by Hamas Turn to Phone Pings for Proof of Life (WIRED)

Israel Taps Blacklisted Pegasus Maker to Track Hostages in Gaza (Bloomberg)

A.I. Muddies Israel-Hamas War in Unexpected Way (New York Times) 

FACT SHEET: President Biden Issues Executive Order on Safe, Secure, and Trustworthy Artificial Intelligence (The White House)

Administration Actions on AI (AI.gov) 

The US Executive Order on artificial intelligence is out. (CyberWire)

Extract Knowledge
Listen elsewhere
Published 2023-10-30

The Malware Mash! [Bonus]

3 min
View

Enjoy this CyberWire classic.

They did the Mash...they did the Malware Mash...

More description

Enjoy this CyberWire classic.

They did the Mash...they did the Malware Mash...

Extract Knowledge
Listen elsewhere

Nicole Sundin, a Chief Product Officer from Axio sits down to discuss her career path and what it is like to be a woman in the cybersecurity field. As a UX leader, Nicole has devoted her entire career to building awareness around the benefits of usable security and human-centered security to the broader cybersecurity community. She also shares some of her background as she moved her way up the later to get to where she is today. As a female in a male-dominated industry, Nicole shares her unique insights on embracing the responsibility of serving as a role model to women aspiring to contribute to the cybersecurity field, and the importance of building a diverse team. She says "Really, it's about building community in your organization and outside your organization of strong women or strong friends that you have that you can lean on when you know you're the only person in the room." We thank Nicole for sharing her story with us.

More description

Nicole Sundin, a Chief Product Officer from Axio sits down to discuss her career path and what it is like to be a woman in the cybersecurity field. As a UX leader, Nicole has devoted her entire career to building awareness around the benefits of usable security and human-centered security to the broader cybersecurity community. She also shares some of her background as she moved her way up the later to get to where she is today. As a female in a male-dominated industry, Nicole shares her unique insights on embracing the responsibility of serving as a role model to women aspiring to contribute to the cybersecurity field, and the importance of building a diverse team. She says "Really, it's about building community in your organization and outside your organization of strong women or strong friends that you have that you can lean on when you know you're the only person in the room." We thank Nicole for sharing her story with us.

Extract Knowledge
Listen elsewhere

Danny Adamitis from Lumen's Black Lotus Labs sits down to discuss their work on "No Rest For The Wicked: HiatusRAT Takes Little Time Off In A Return To Action." Last March Lumen's Black Lotus Lab researchers discovered a novel malware called HiatusRAT that targeted business-grade routers.

The research states "In the latest campaign, we observed a shift in reconnaissance and targeting activity; in June we observed reconnaissance against a U.S. military procurement system, and targeting of Taiwan-based organizations." This shift in information gathering and targeting preference exhibited in the latest campaign is synonymous with the strategic interest of the People’s Republic of China according to the 2023 ODNI threat assessment.

The research can be found here:

More description

Danny Adamitis from Lumen's Black Lotus Labs sits down to discuss their work on "No Rest For The Wicked: HiatusRAT Takes Little Time Off In A Return To Action." Last March Lumen's Black Lotus Lab researchers discovered a novel malware called HiatusRAT that targeted business-grade routers.

The research states "In the latest campaign, we observed a shift in reconnaissance and targeting activity; in June we observed reconnaissance against a U.S. military procurement system, and targeting of Taiwan-based organizations." This shift in information gathering and targeting preference exhibited in the latest campaign is synonymous with the strategic interest of the People’s Republic of China according to the 2023 ODNI threat assessment.

The research can be found here:

Extract Knowledge
Listen elsewhere

Eastern European gangs overcome their reservations about working with anglophone criminals. Mirth Connect is vulnerable to a critical flaw. A look at a mercenary spyware strain. “PepsiCo” as phishbait. Ben Yelin explains the FCC’s renewed interest in Net Neutrality. Our guest is Wade Baker from the Cyentia Institute with insights on measuring risk. And Europol thinks police should take a good look at quantum computing and law enforcement.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/206


Selected reading.

Octo Tempest crosses boundaries to facilitate extortion, encryption, and destruction (Microsoft Security)

MGM Resorts hackers 'one of the most dangerous financial criminal groups’ (Record)

Critical Mirth Connect Vulnerability Could Expose Sensitive Healthcare Data (SecurityWeek) 

Examining Predator Mercenary Spyware (HYAS)

Fresh Phish: The Case of the PepsiCo Procurement Ploy (INKY) 

U.S. Tries New Tack on Russian Disinformation: Pre-Empting It (New York Times) 

ESET APT Activity Report Q2–Q3 2023 (We Live Security) 

Russian hackers claim takedown of WA’s Transperth transport agency with DDoS attack (Cyber Daily) 

The Second Quantum Revolution: The impact of quantum computing and quantum technologies on law enforcement (Europol Innovation Lab) 

More description

Eastern European gangs overcome their reservations about working with anglophone criminals. Mirth Connect is vulnerable to a critical flaw. A look at a mercenary spyware strain. “PepsiCo” as phishbait. Ben Yelin explains the FCC’s renewed interest in Net Neutrality. Our guest is Wade Baker from the Cyentia Institute with insights on measuring risk. And Europol thinks police should take a good look at quantum computing and law enforcement.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/206


Selected reading.

Octo Tempest crosses boundaries to facilitate extortion, encryption, and destruction (Microsoft Security)

MGM Resorts hackers 'one of the most dangerous financial criminal groups’ (Record)

Critical Mirth Connect Vulnerability Could Expose Sensitive Healthcare Data (SecurityWeek) 

Examining Predator Mercenary Spyware (HYAS)

Fresh Phish: The Case of the PepsiCo Procurement Ploy (INKY) 

U.S. Tries New Tack on Russian Disinformation: Pre-Empting It (New York Times) 

ESET APT Activity Report Q2–Q3 2023 (We Live Security) 

Russian hackers claim takedown of WA’s Transperth transport agency with DDoS attack (Cyber Daily) 

The Second Quantum Revolution: The impact of quantum computing and quantum technologies on law enforcement (Europol Innovation Lab) 

Extract Knowledge
Listen elsewhere

StripedFly gets reclassified. YoroTrooper is interested in the Commonwealth of Independent States. The current state of DDoS attacks. Ukrainian hacktivists deface Russian artists' Spotify pages. Trolls amplify a Musky meme. In our Industry Voices segment, Matt Howard from Virtru explains securing data at the employee edge. Our guest is Seth Blank from Valimail, to discuss email security and DMARC. And while trolls might like Mr.Musk, the crooks heart Mr. Gosling.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/205


Selected reading.

Sophisticated StripedFly Spy Platform Masqueraded for Years as Crypto Miner (Zeroday)

Kazakhstan-associated YoroTrooper disguises origin of attacks as Azerbaijan (Cisco Talos Blog)

DDoS threat report for 2023 Q3 (The Cloudflare Blog) 

Russian artists’ Spotify accounts defaced by pro-Ukraine hackers (Record) 

Elon Musk Mocked Ukraine, and Russian Trolls Went Wild (WIRED)

Ryan Gosling Tops McAfee’s 2023 Hacker Celebrity Hot List (Business Wire)

More description

StripedFly gets reclassified. YoroTrooper is interested in the Commonwealth of Independent States. The current state of DDoS attacks. Ukrainian hacktivists deface Russian artists' Spotify pages. Trolls amplify a Musky meme. In our Industry Voices segment, Matt Howard from Virtru explains securing data at the employee edge. Our guest is Seth Blank from Valimail, to discuss email security and DMARC. And while trolls might like Mr.Musk, the crooks heart Mr. Gosling.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/205


Selected reading.

Sophisticated StripedFly Spy Platform Masqueraded for Years as Crypto Miner (Zeroday)

Kazakhstan-associated YoroTrooper disguises origin of attacks as Azerbaijan (Cisco Talos Blog)

DDoS threat report for 2023 Q3 (The Cloudflare Blog) 

Russian artists’ Spotify accounts defaced by pro-Ukraine hackers (Record) 

Elon Musk Mocked Ukraine, and Russian Trolls Went Wild (WIRED)

Ryan Gosling Tops McAfee’s 2023 Hacker Celebrity Hot List (Business Wire)

Extract Knowledge
Listen elsewhere

Teaching AI to misbehave. Ransomware's effect on healthcare downtime. Two reports on the state of cybersecurity in the financial services sector. Possible connections between Hamas and Quds Force. Ukrainian cyber authorities report a rise in privateering Smokeloader attacks. Russian hacktivist auxiliaries strike Czech targets. My conversation with Sherrod DeGrippo, host of The Microsoft Threat Intelligence Podcast. Jay Bhalodia from Microsoft Federal shares insights on multi-cloud security. And Winter Vivern exploits a mail service 0-day.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/204


Selected reading.

AI vs. human deceit: Unravelling the new age of phishing tactics (Security Intelligence)

Ransomware attacks on US healthcare organizations cost $20.8bn in 2020 (Comparitech) 

Cyberattack at 5 southwestern Ontario hospitals leaves patients awaiting care (CBC News) 

State of Security for Financial Services (Swimlane)

Veracode Reveals Automation and Training Are Key Drivers of Software Security for Financial Services (Business Wire)

Hamas’ online infrastructure reveals ties to Iran APT, researchers say (CSO Online) 

Hamas Application Infrastructure Reveals Possible Overlap With TAG-63 and Iranian Threat Activity | Recorded Future (Recorded Future)

Ukraine cyber officials warn of a ‘surge’ in Smokeloader attacks on financial, government entities (Record) 

Bloomberg: Russia steps up cyberattacks to disrupt Ukraine’s key services (Euromaidan) 

Pro-Russia group behind today’s mass cyberattack against Czech institutions (Expats.cz)

Winter Vivern exploits zero-day vulnerability in Roundcube Webmail servers (We Live Security)

More description

Teaching AI to misbehave. Ransomware's effect on healthcare downtime. Two reports on the state of cybersecurity in the financial services sector. Possible connections between Hamas and Quds Force. Ukrainian cyber authorities report a rise in privateering Smokeloader attacks. Russian hacktivist auxiliaries strike Czech targets. My conversation with Sherrod DeGrippo, host of The Microsoft Threat Intelligence Podcast. Jay Bhalodia from Microsoft Federal shares insights on multi-cloud security. And Winter Vivern exploits a mail service 0-day.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/204


Selected reading.

AI vs. human deceit: Unravelling the new age of phishing tactics (Security Intelligence)

Ransomware attacks on US healthcare organizations cost $20.8bn in 2020 (Comparitech) 

Cyberattack at 5 southwestern Ontario hospitals leaves patients awaiting care (CBC News) 

State of Security for Financial Services (Swimlane)

Veracode Reveals Automation and Training Are Key Drivers of Software Security for Financial Services (Business Wire)

Hamas’ online infrastructure reveals ties to Iran APT, researchers say (CSO Online) 

Hamas Application Infrastructure Reveals Possible Overlap With TAG-63 and Iranian Threat Activity | Recorded Future (Recorded Future)

Ukraine cyber officials warn of a ‘surge’ in Smokeloader attacks on financial, government entities (Record) 

Bloomberg: Russia steps up cyberattacks to disrupt Ukraine’s key services (Euromaidan) 

Pro-Russia group behind today’s mass cyberattack against Czech institutions (Expats.cz)

Winter Vivern exploits zero-day vulnerability in Roundcube Webmail servers (We Live Security)

Extract Knowledge
Listen elsewhere

DDoS activity during the Hamas-Israeli war. Insurance firm reports cyber incident. Recent arrests in cybercrime sweeps. Ukrainian hacktivist auxiliaries compromise customer data at Russia's Alfa Bank. How long does it take to read the fine print? Ann Johnson from Afternoon Cyber Tea talks with Noopur Davis from Comcast about building secure tech from the start. Antonio Sanchez of Fortra shares cybersecurity challenges for enterprises including why having too many tools creates too much complexity. And hey, Marianne–don’t let the bedbugs bite. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/203


Selected reading.

Cyber attacks in the Israel-Hamas war (The Cloudflare Blog)

China's crackdown on cyber scams in Southeast Asia ensnares thousands but leaves the networks intact (AP News) 

12 people arrested for bank malware scam, youngest being just 17 (The Independent Singapore News) 

Spain arrests 34 cybercriminals who stole data of 4 million people (BleepingComputer) 

Police Disrupt Ragnar Locker Ransomware Group (Infosecurity Magazine) 

Ragnar Locker Ransomware Boss Arrested in Paris (Dark Reading) 

E-Root marketplace credential-selling admin extradited to US (Register)

Ukraine security services involved in hack of Russia’s largest private bank (Record)

NordVPN study: Privacy policy awareness (NordVPN)

Russia spread bedbug panic in France, intelligence services suspect (The Telegraph) 

More description

DDoS activity during the Hamas-Israeli war. Insurance firm reports cyber incident. Recent arrests in cybercrime sweeps. Ukrainian hacktivist auxiliaries compromise customer data at Russia's Alfa Bank. How long does it take to read the fine print? Ann Johnson from Afternoon Cyber Tea talks with Noopur Davis from Comcast about building secure tech from the start. Antonio Sanchez of Fortra shares cybersecurity challenges for enterprises including why having too many tools creates too much complexity. And hey, Marianne–don’t let the bedbugs bite. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/203


Selected reading.

Cyber attacks in the Israel-Hamas war (The Cloudflare Blog)

China's crackdown on cyber scams in Southeast Asia ensnares thousands but leaves the networks intact (AP News) 

12 people arrested for bank malware scam, youngest being just 17 (The Independent Singapore News) 

Spain arrests 34 cybercriminals who stole data of 4 million people (BleepingComputer) 

Police Disrupt Ragnar Locker Ransomware Group (Infosecurity Magazine) 

Ragnar Locker Ransomware Boss Arrested in Paris (Dark Reading) 

E-Root marketplace credential-selling admin extradited to US (Register)

Ukraine security services involved in hack of Russia’s largest private bank (Record)

NordVPN study: Privacy policy awareness (NordVPN)

Russia spread bedbug panic in France, intelligence services suspect (The Telegraph) 

Extract Knowledge
Listen elsewhere

Okta discloses a data exposure incident. Cisco works to fix a zero-day. DPRK threat actors pose as IT workers. The Five Eyes warn of AI-enabled Chinese espionage. Job posting as phishbait. The risk of first-party fraud. Hacktivists trouble humanitarian organizations with nuisance attacks. Content moderation during wartime. Malek Ben Salem of Accenture describes code models. Our guest is Joe Oregon from CISA, discussing the tabletop exercise that CISA, the NFL, and local partners conducted in preparation for the next Super BowI. And the International Criminal Court confirms that it’s sustained a cyberespionage incident.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/202


Selected reading.

Okta says hackers used stolen credentials to view customer files (Record)

Cisco discloses new IOS XE zero-day exploited to deploy malware implant (BleepingComputer)

Additional Guidance on the Democratic People's Republic of Korea Information Technology Workers (IC3)

A stern glance from all Five Eyes. (CyberWire) 

DarkGate malware campaign (WithSecure) 

The Fraud Next Door: First-Party Fraud Runs Rampant in America (PR Newswire)

Cyberattacks Intensify on Israeli and Palestinian Human Rights Groups (Wall Street Journal) 

Israel's burial society website comes under cyberattack (Jerusalem Post) 

Sheba Medical Center Hit by Cyber Attack (Jewish Press) 

Health Ministry disconnects the remote connection of several hospitals following cyber attack (Jerusalem Post)

EU asks Meta, TikTok to account for their response to Israel-Hamas disinformation (Record) 

Pro-Palestinian creators use secret spellings, code words to evade social media algorithms (Washington Post) 

Web Summit CEO resigns after comments on Israel-Hamas conflict (Reuters) 

YouTube is Autogenerating Videos for Songs Advocating the Expulsion of Muslims from India (bellingcat) 

Palestinians Claim Social Media 'Censorship' Is Endangering Lives (WIRED) 

International Criminal Court says cyberattack was attempted espionage (TechCrunch) 

War crimes tribunal says September cyberattack was act of espionage (Record) 

International Criminal Court investigating “unprecedented” cyberattack (Cybernews) 

More description

Okta discloses a data exposure incident. Cisco works to fix a zero-day. DPRK threat actors pose as IT workers. The Five Eyes warn of AI-enabled Chinese espionage. Job posting as phishbait. The risk of first-party fraud. Hacktivists trouble humanitarian organizations with nuisance attacks. Content moderation during wartime. Malek Ben Salem of Accenture describes code models. Our guest is Joe Oregon from CISA, discussing the tabletop exercise that CISA, the NFL, and local partners conducted in preparation for the next Super BowI. And the International Criminal Court confirms that it’s sustained a cyberespionage incident.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/202


Selected reading.

Okta says hackers used stolen credentials to view customer files (Record)

Cisco discloses new IOS XE zero-day exploited to deploy malware implant (BleepingComputer)

Additional Guidance on the Democratic People's Republic of Korea Information Technology Workers (IC3)

A stern glance from all Five Eyes. (CyberWire) 

DarkGate malware campaign (WithSecure) 

The Fraud Next Door: First-Party Fraud Runs Rampant in America (PR Newswire)

Cyberattacks Intensify on Israeli and Palestinian Human Rights Groups (Wall Street Journal) 

Israel's burial society website comes under cyberattack (Jerusalem Post) 

Sheba Medical Center Hit by Cyber Attack (Jewish Press) 

Health Ministry disconnects the remote connection of several hospitals following cyber attack (Jerusalem Post)

EU asks Meta, TikTok to account for their response to Israel-Hamas disinformation (Record) 

Pro-Palestinian creators use secret spellings, code words to evade social media algorithms (Washington Post) 

Web Summit CEO resigns after comments on Israel-Hamas conflict (Reuters) 

YouTube is Autogenerating Videos for Songs Advocating the Expulsion of Muslims from India (bellingcat) 

Palestinians Claim Social Media 'Censorship' Is Endangering Lives (WIRED) 

International Criminal Court says cyberattack was attempted espionage (TechCrunch) 

War crimes tribunal says September cyberattack was act of espionage (Record) 

International Criminal Court investigating “unprecedented” cyberattack (Cybernews) 

Extract Knowledge
Listen elsewhere

This week, we welcome Jennifer Reed, a Principal Solutions Architect at Amazon Web Services (AWS) to sit down and share her amazing story. After Jennifer graduated high school, she immediately went into Marine Corps training, which she shared was a shock to her because she was the only woman when she got out into the fleet and every single place that she went. She eventually moved on from the military after learning some programming tools, and went into the financial services industry doing systems engineering. She got called back to active duty, and then afterwards landed at AWS. She shares that being a woman in this industry can be challenging at time, but she says "I do feel, um, good about the things I've overcome, but I also don't want it to be so hard for the next person, if that makes sense. I don't want them to have to have those same struggles to kind of overcome any perceptions that someone might have due to their their gender or their background." We thank Jennifer for sharing her story with us.

More description

This week, we welcome Jennifer Reed, a Principal Solutions Architect at Amazon Web Services (AWS) to sit down and share her amazing story. After Jennifer graduated high school, she immediately went into Marine Corps training, which she shared was a shock to her because she was the only woman when she got out into the fleet and every single place that she went. She eventually moved on from the military after learning some programming tools, and went into the financial services industry doing systems engineering. She got called back to active duty, and then afterwards landed at AWS. She shares that being a woman in this industry can be challenging at time, but she says "I do feel, um, good about the things I've overcome, but I also don't want it to be so hard for the next person, if that makes sense. I don't want them to have to have those same struggles to kind of overcome any perceptions that someone might have due to their their gender or their background." We thank Jennifer for sharing her story with us.

Extract Knowledge
Listen elsewhere

Sysdig's Alessandro Brucato and Michael Clark join Dave to discuss their work on "AWS's Hidden Threat: AMBERSQUID Cloud-Native Cryptojacking Operation." Attackers are targeting what are typically considered secure AWS services, like AWS Fargate and Amazon SageMaker. This means that defenders generally aren’t as concerned with their security from end-to-end.

The research states "The AMBERSQUID operation was able to exploit cloud services without triggering the AWS requirement for approval of more resources, as would be the case if they only spammed EC2 instances." This poses additional challenges targeting multiple services since it requires finding and killing all miners in each exploited service.

The research can be found here:

More description

Sysdig's Alessandro Brucato and Michael Clark join Dave to discuss their work on "AWS's Hidden Threat: AMBERSQUID Cloud-Native Cryptojacking Operation." Attackers are targeting what are typically considered secure AWS services, like AWS Fargate and Amazon SageMaker. This means that defenders generally aren’t as concerned with their security from end-to-end.

The research states "The AMBERSQUID operation was able to exploit cloud services without triggering the AWS requirement for approval of more resources, as would be the case if they only spammed EC2 instances." This poses additional challenges targeting multiple services since it requires finding and killing all miners in each exploited service.

The research can be found here:

Extract Knowledge
Listen elsewhere

Hacktivism and influence operations in the Hamas-Israel war. An OilRig cyberespionage campaign prospects a Middle Eastern government. Emailed bomb threats in the Baltic. Darkweb advertising yields insight into ExelaStealer malware. Casio discloses breach of customer data. The FCC proposes a return to net neutrality, while Consumer Financial Protection Bureau proposes data-handling rules under Dodd-Frank. Deepen Desai from ZScaler shares insights on MOVEit transfer vulnerabilities. Our own Simone Petrella speaks with Google’s Tatyana Bolton about the challenges of bridging the cyber talent gap. And RagnarLocker has been taken down by international law enforcement. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/201


Selected reading.

Intel, defense officials tell senators that Israel did not strike hospital  (The Hill)

Early U.S. and Israeli Intelligence Says Palestinian Group Caused Hospital Blast.

Cyberattacks linked to Israel-Hamas war are soaring (Fast Company) 

NSO, Israeli cyber firms help track missing Israelis and hostages (Haaretz) 

Lithuanian interior minister says emailed bomb threats are coordinated regional cyber-attack (Baltic Times)

Another InfoStealer Enters the Field, ExelaStealer (Fortinet Blog)

Q3 Report: Email Threat Trends Latest edition: PDF Popularity, Callback Phishing and Redline Malware (VIPRE)

Casio Issues Apology and Notice Concerning Personal Information Leak Due to Unauthorized Access to Server | CASIO (CASIO Official Website) 

Human Error: Casio ClassPad Data Breach Impacting 148 Countries (Hackread) 

Casio data breach 2023 caused worldwide panic (Dataconomy)

Casio discloses data breach impacting customers in 149 countries (BleepingComputer) 

FCC Revives ‘Net Neutrality,’ Proposes New Regulations for Internet Service (Wall Street Journal) 

FCC begins second quest for net neutrality (TechCrunch)

CFPB Proposes Rule to Jumpstart Competition and Accelerate Shift to Open Banking (Consumer Financial Protection Bureau)

RagnarLocker ransomware dark web site seized in international sting (TechCrunch) 

Ragnar Locker ransomware site taken down by FBI, Europol (Record) 

One of the most destructive ransomware gangs is being taken down by law enforcement (Axios)

More description

Hacktivism and influence operations in the Hamas-Israel war. An OilRig cyberespionage campaign prospects a Middle Eastern government. Emailed bomb threats in the Baltic. Darkweb advertising yields insight into ExelaStealer malware. Casio discloses breach of customer data. The FCC proposes a return to net neutrality, while Consumer Financial Protection Bureau proposes data-handling rules under Dodd-Frank. Deepen Desai from ZScaler shares insights on MOVEit transfer vulnerabilities. Our own Simone Petrella speaks with Google’s Tatyana Bolton about the challenges of bridging the cyber talent gap. And RagnarLocker has been taken down by international law enforcement. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/201


Selected reading.

Intel, defense officials tell senators that Israel did not strike hospital  (The Hill)

Early U.S. and Israeli Intelligence Says Palestinian Group Caused Hospital Blast.

Cyberattacks linked to Israel-Hamas war are soaring (Fast Company) 

NSO, Israeli cyber firms help track missing Israelis and hostages (Haaretz) 

Lithuanian interior minister says emailed bomb threats are coordinated regional cyber-attack (Baltic Times)

Another InfoStealer Enters the Field, ExelaStealer (Fortinet Blog)

Q3 Report: Email Threat Trends Latest edition: PDF Popularity, Callback Phishing and Redline Malware (VIPRE)

Casio Issues Apology and Notice Concerning Personal Information Leak Due to Unauthorized Access to Server | CASIO (CASIO Official Website) 

Human Error: Casio ClassPad Data Breach Impacting 148 Countries (Hackread) 

Casio data breach 2023 caused worldwide panic (Dataconomy)

Casio discloses data breach impacting customers in 149 countries (BleepingComputer) 

FCC Revives ‘Net Neutrality,’ Proposes New Regulations for Internet Service (Wall Street Journal) 

FCC begins second quest for net neutrality (TechCrunch)

CFPB Proposes Rule to Jumpstart Competition and Accelerate Shift to Open Banking (Consumer Financial Protection Bureau)

RagnarLocker ransomware dark web site seized in international sting (TechCrunch) 

Ragnar Locker ransomware site taken down by FBI, Europol (Record) 

One of the most destructive ransomware gangs is being taken down by law enforcement (Axios)

Extract Knowledge
Listen elsewhere

Nation-states exploit the WinRAR vulnerability. Criminals leak more stolen 23andMe data. QR codes as a risk. NSA and partners offer anti-phishing guidance. A Ukrainian hacktivist auxiliary takes down Trigona privateers. Hacktivism and influence operations remain the major cyber features of the Hamas-Israeli war. On today’s Threat Vector, David Moulton speaks with Kate Naunheim, Cyber Risk Management Director at Unit 42, about the new cybersecurity regulations introduced by the SEC. Our own Rick Howard talks with Jen Miller Osborn about the 10th anniversary of ATT&CKcon. And the epistemology of open source intelligence: tweets, TikToks, Instagrams–they’re not necessarily ground truth.

Threat Vector

To delve further into this topic, check out this upcoming webinar by Palo Alto's Unit 42 team on November 9, 2023, "The Ransomware Landscape: Threats Driving the SEC Rule and Other Regulations."


Please share your thoughts with us for future Threat Vector segments by taking our brief survey.


To learn what is top of mind each month from the experts at Unit 42 sign up for their Threat Intel Bulletin


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/200


Selected reading.

Government-backed actors exploiting WinRAR vulnerability (Google) 

The forgotten malvertising campaign (Malwarebytes)

Hacker leaks millions of new 23andMe genetic data profiles (BleepingComputer) 

Exploring The Malicious Usage of QR Codes (SlashNext |) 

How to Protect Against Evolving Phishing Attacks (National Security Agency/Central Security Service)

GuidePoint Research and Intelligence Team’s (GRIT) 2023 Q3 Ransomware Report Examines the Continued Surge of Ransomware Activity (GuidePoint)

Ukrainian activists hack Trigona ransomware gang, wipe servers (BleepingComputer) 

Navigating the Mis- and Disinformation Minefield in the Current Israel-Hamas War (ZeroFox)

War Tests Israeli Cyber Defenses as Hack Attempts Soar (Bloomberg)

U.S. says Israel ‘not responsible’ for Gaza hospital blast; Biden announces ‘unprecedented’ aid package in speech (Washington Post)

Three clues the Ahli Arab Hospital strike came from Gaza (The Telegraph) 

Who’s Responsible for the Gaza Hospital Explosion? Here’s Why It’s Hard to Know What’s Real (WIRED) 

‘Verified’ OSINT Accounts Are Destroying the Israel-Palestine Information Ecosystem (404 Media)

More description

Nation-states exploit the WinRAR vulnerability. Criminals leak more stolen 23andMe data. QR codes as a risk. NSA and partners offer anti-phishing guidance. A Ukrainian hacktivist auxiliary takes down Trigona privateers. Hacktivism and influence operations remain the major cyber features of the Hamas-Israeli war. On today’s Threat Vector, David Moulton speaks with Kate Naunheim, Cyber Risk Management Director at Unit 42, about the new cybersecurity regulations introduced by the SEC. Our own Rick Howard talks with Jen Miller Osborn about the 10th anniversary of ATT&CKcon. And the epistemology of open source intelligence: tweets, TikToks, Instagrams–they’re not necessarily ground truth.

Threat Vector

To delve further into this topic, check out this upcoming webinar by Palo Alto's Unit 42 team on November 9, 2023, "The Ransomware Landscape: Threats Driving the SEC Rule and Other Regulations."


Please share your thoughts with us for future Threat Vector segments by taking our brief survey.


To learn what is top of mind each month from the experts at Unit 42 sign up for their Threat Intel Bulletin


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/200


Selected reading.

Government-backed actors exploiting WinRAR vulnerability (Google) 

The forgotten malvertising campaign (Malwarebytes)

Hacker leaks millions of new 23andMe genetic data profiles (BleepingComputer) 

Exploring The Malicious Usage of QR Codes (SlashNext |) 

How to Protect Against Evolving Phishing Attacks (National Security Agency/Central Security Service)

GuidePoint Research and Intelligence Team’s (GRIT) 2023 Q3 Ransomware Report Examines the Continued Surge of Ransomware Activity (GuidePoint)

Ukrainian activists hack Trigona ransomware gang, wipe servers (BleepingComputer) 

Navigating the Mis- and Disinformation Minefield in the Current Israel-Hamas War (ZeroFox)

War Tests Israeli Cyber Defenses as Hack Attempts Soar (Bloomberg)

U.S. says Israel ‘not responsible’ for Gaza hospital blast; Biden announces ‘unprecedented’ aid package in speech (Washington Post)

Three clues the Ahli Arab Hospital strike came from Gaza (The Telegraph) 

Who’s Responsible for the Gaza Hospital Explosion? Here’s Why It’s Hard to Know What’s Real (WIRED) 

‘Verified’ OSINT Accounts Are Destroying the Israel-Palestine Information Ecosystem (404 Media)

Extract Knowledge
Listen elsewhere

Hamas and Israel exchange accusations in a hospital strike. Using Gazan cell data to develop intelligence, and using hostages' devices to spread fear. Black Basta ransomware is out and about, again. Qubitstrike is a newly discovered cryptojacking campaign. Preparing for post-quantum security. Tim Starks from the Washington Post looks at one US Senator’s ability to gum up cyber legislation. In the Learning Layer, N2K's Sam Meisenberg explores the challenges and best practices of rolling out a large-scale corporate re-skilling program. And attention people of Pompei: that volcano alert is bogus. Probably.

Learning Layer.

On this segment of Learning Layer, N2K's Sam Meisenberg is joined by Phil, an N2K client who leads Talent Development at a large telecommunication company. They discuss the challenges and best practices of rolling out a large-scale corporate re-skilling program, including increasing learner engagement, accountability, and the importance of internal talent development and recognition.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/199


Selected reading.

Blast kills hundreds at Gaza hospital; Hamas and Israel trade blame, as Biden heads to Mideast (AP News)

In deadly day for Gaza, hospital strike kills hundreds (Reuters) 

Hacktivist attacks against Israeli websites mirror attacks following Russian invasion of Ukraine (ComputerWeekly.com) 

Growing Concern Over Role of Hacktivism in Israel-Hamas Conflict (Infosecurity Magazine) 

Israel-Hamas war illuminates trouble with political hacking groups (Axios) 

ISRAEL GAZA CONFLICT : THE CYBER PERSPECTIVE (CYFIRMA) 

Tracking Cellphone Data by Neighborhood, Israel Gauges Gaza Evacuation (New York Times) 

Hamas Hijacked Victims’ Social Media Accounts to Spread Terror (New York Times)

TV advertising sales giant affected by ransomware attack (Record)

Chilean government warns of Black Basta ransomware attacks after customs incident (Record)

Qubitstrike - An Emerging Malware Campaign Targeting Jupyter Notebooks (Cado Security)

DigiCert Global Study: Preparing for a Safe Post-Quantum Computing Future (DigiCert) 

SpyNote Android malware spreads via fake volcano eruption alerts (BleepingComputer) 

More description

Hamas and Israel exchange accusations in a hospital strike. Using Gazan cell data to develop intelligence, and using hostages' devices to spread fear. Black Basta ransomware is out and about, again. Qubitstrike is a newly discovered cryptojacking campaign. Preparing for post-quantum security. Tim Starks from the Washington Post looks at one US Senator’s ability to gum up cyber legislation. In the Learning Layer, N2K's Sam Meisenberg explores the challenges and best practices of rolling out a large-scale corporate re-skilling program. And attention people of Pompei: that volcano alert is bogus. Probably.

Learning Layer.

On this segment of Learning Layer, N2K's Sam Meisenberg is joined by Phil, an N2K client who leads Talent Development at a large telecommunication company. They discuss the challenges and best practices of rolling out a large-scale corporate re-skilling program, including increasing learner engagement, accountability, and the importance of internal talent development and recognition.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/199


Selected reading.

Blast kills hundreds at Gaza hospital; Hamas and Israel trade blame, as Biden heads to Mideast (AP News)

In deadly day for Gaza, hospital strike kills hundreds (Reuters) 

Hacktivist attacks against Israeli websites mirror attacks following Russian invasion of Ukraine (ComputerWeekly.com) 

Growing Concern Over Role of Hacktivism in Israel-Hamas Conflict (Infosecurity Magazine) 

Israel-Hamas war illuminates trouble with political hacking groups (Axios) 

ISRAEL GAZA CONFLICT : THE CYBER PERSPECTIVE (CYFIRMA) 

Tracking Cellphone Data by Neighborhood, Israel Gauges Gaza Evacuation (New York Times) 

Hamas Hijacked Victims’ Social Media Accounts to Spread Terror (New York Times)

TV advertising sales giant affected by ransomware attack (Record)

Chilean government warns of Black Basta ransomware attacks after customs incident (Record)

Qubitstrike - An Emerging Malware Campaign Targeting Jupyter Notebooks (Cado Security)

DigiCert Global Study: Preparing for a Safe Post-Quantum Computing Future (DigiCert) 

SpyNote Android malware spreads via fake volcano eruption alerts (BleepingComputer) 

Extract Knowledge
Listen elsewhere

A bogus RedAlert app delivered spyware as well as panic. BloodAlchemy backdoors ASEAN southeast asian targets. A serious Cisco zero-day is being exploited. Valve implements additional security measures for Steam. A warning on Atlassian vulnerability exploitation. Allies update their security-by-design guide. Ukrainian telecommunications providers hit by cyberattack. Ben Yelin explains attempts to tamp down pornographic deepfakes. Our guest is Ashley Rose from Living Security with a look at measuring human risk. And, as always, criminals see misery as opportunity.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/198


Selected reading.

Malicious “RedAlert - Rocket Alerts” Application Targets Israeli Phone Calls, SMS, and User Information (The Cloudflare Blog)

Disclosing the BLOODALCHEMY backdoor (Elastic Security Labs) 

BLOODALCHEMY provides backdoor to ASEAN secrets (Register) 

Active exploitation of Cisco IOS XE Software Web Management User Interface vulnerability (Cisco Talos Blog)

Actively exploited Cisco 0-day with maximum 10 severity gives full network control (Ars Technica)

Cisco warns of actively exploited zero-day in IOS XE software (Computing) 

Widespread Cisco IOS XE Implants in the Wild (VulnCheck)

Steam enforces SMS verification to curb malware-ridden updates (BleepingComputer)

Threat Actors Exploit Atlassian Confluence CVE-2023-22515 for Initial Access to Networks | CISA (Cybersecurity and Infrastructure Security Agency CISA) 

CISA, U.S. and International Partners Announce Updated Secure by Design Principles Joint Guide (Cybersecurity and Infrastructure Security Agency) 

CERT-UA Reports: 11 Ukrainian Telecom Providers Hit by Cyberattacks (The Hacker News) 

CVE-2023-38831 Exploited by Pro-Russia Hacking Groups in RU-UA Conflict Zone for Credential Harvesting Operations (Cluster25) 

Pro-Russian Hackers Exploiting Recent WinRAR Vulnerability in New Campaign (The Hacker News) 

Cyberattack targets Belgian public service websites for second time in a week (Brussels Times) 

Spam trends of the week: Spammers piggyback on the Israel-Gaza war to plunder donations (Hot for Security)

More description

A bogus RedAlert app delivered spyware as well as panic. BloodAlchemy backdoors ASEAN southeast asian targets. A serious Cisco zero-day is being exploited. Valve implements additional security measures for Steam. A warning on Atlassian vulnerability exploitation. Allies update their security-by-design guide. Ukrainian telecommunications providers hit by cyberattack. Ben Yelin explains attempts to tamp down pornographic deepfakes. Our guest is Ashley Rose from Living Security with a look at measuring human risk. And, as always, criminals see misery as opportunity.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/198


Selected reading.

Malicious “RedAlert - Rocket Alerts” Application Targets Israeli Phone Calls, SMS, and User Information (The Cloudflare Blog)

Disclosing the BLOODALCHEMY backdoor (Elastic Security Labs) 

BLOODALCHEMY provides backdoor to ASEAN secrets (Register) 

Active exploitation of Cisco IOS XE Software Web Management User Interface vulnerability (Cisco Talos Blog)

Actively exploited Cisco 0-day with maximum 10 severity gives full network control (Ars Technica)

Cisco warns of actively exploited zero-day in IOS XE software (Computing) 

Widespread Cisco IOS XE Implants in the Wild (VulnCheck)

Steam enforces SMS verification to curb malware-ridden updates (BleepingComputer)

Threat Actors Exploit Atlassian Confluence CVE-2023-22515 for Initial Access to Networks | CISA (Cybersecurity and Infrastructure Security Agency CISA) 

CISA, U.S. and International Partners Announce Updated Secure by Design Principles Joint Guide (Cybersecurity and Infrastructure Security Agency) 

CERT-UA Reports: 11 Ukrainian Telecom Providers Hit by Cyberattacks (The Hacker News) 

CVE-2023-38831 Exploited by Pro-Russia Hacking Groups in RU-UA Conflict Zone for Credential Harvesting Operations (Cluster25) 

Pro-Russian Hackers Exploiting Recent WinRAR Vulnerability in New Campaign (The Hacker News) 

Cyberattack targets Belgian public service websites for second time in a week (Brussels Times) 

Spam trends of the week: Spammers piggyback on the Israel-Gaza war to plunder donations (Hot for Security)

Extract Knowledge
Listen elsewhere

Hacktivism and disinformation in the war between Hamas and Israel. LockBit claims an attack on CDW. Shadow PC's breach. Void Rabisu deploys a lightweight RomCom backdoor against the Brussels conference. Rick Howard describes Radical Asymmetric Distribution. Our guest is Jason Birmingham from Broadridge Financial Solutions with a look at asset management. And coin mining as a potential front for espionage or a staging area for sabotage.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/197


Selected reading.

How hackers piled onto the Israeli-Hamas conflict (POLITICO) 

Israel-Gaza War Now Includes Accompanying Cyber Warfare (Channel Futures) 

How Cyberattacks Could Affect the Israel-Hamas War (Bank Info Security) 

Medical aid for Palestinians website under cyber attack affecting relief efforts (mint) 

Rumors of a ‘Global Day of Jihad’ Have Unleashed a Dangerous Wave of Disinformation (WIRED) 

Hamas in rare English ‘press conference’ as it tries to counter global condemnation (The Telegraph) 

In Israel-Hamas conflict, social media become tools of propaganda and disinformation (DFRLab)  

A flood of misinformation is shaping how panicked citizens, global public view the war (Washington Post) 

How Israel-Hamas War Misinformation Is Spreading Online (TIME)

Misinformation Is Warfare (TIME) 

Meta responds to EU misinformation concerns regarding Israel-Hamas conflict (Engadget) 

Briefing: Meta Details Efforts to Remove War-Related Disinformation (The Information)

Cloud gaming firm Shadow says hackers stole customers' personal data (TechCrunch) 

PC streaming service Shadow discloses security breach (The Verge) 

Shadow silent on data breach as hacked data appears genuine (TechCrunch) 

530K people's info stolen from cloud PC gaming's Shadow (Register) 

CDW investigating ransomware gang claims of data theft (Record) 

Lockbit ransomware gang demanded an 80 million ransom to CDW (Security Affairs) 

Void Rabisu Targets Female Political Leaders with New Slimmed-Down ROMCOM Variant (Trend Micro)

Women Political Leaders Summit targeted in RomCom malware phishing (BleepingComputer) 

Across U.S., Chinese Bitcoin Mines Draw National Security Scrutiny (New York Times)

More description

Hacktivism and disinformation in the war between Hamas and Israel. LockBit claims an attack on CDW. Shadow PC's breach. Void Rabisu deploys a lightweight RomCom backdoor against the Brussels conference. Rick Howard describes Radical Asymmetric Distribution. Our guest is Jason Birmingham from Broadridge Financial Solutions with a look at asset management. And coin mining as a potential front for espionage or a staging area for sabotage.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/197


Selected reading.

How hackers piled onto the Israeli-Hamas conflict (POLITICO) 

Israel-Gaza War Now Includes Accompanying Cyber Warfare (Channel Futures) 

How Cyberattacks Could Affect the Israel-Hamas War (Bank Info Security) 

Medical aid for Palestinians website under cyber attack affecting relief efforts (mint) 

Rumors of a ‘Global Day of Jihad’ Have Unleashed a Dangerous Wave of Disinformation (WIRED) 

Hamas in rare English ‘press conference’ as it tries to counter global condemnation (The Telegraph) 

In Israel-Hamas conflict, social media become tools of propaganda and disinformation (DFRLab)  

A flood of misinformation is shaping how panicked citizens, global public view the war (Washington Post) 

How Israel-Hamas War Misinformation Is Spreading Online (TIME)

Misinformation Is Warfare (TIME) 

Meta responds to EU misinformation concerns regarding Israel-Hamas conflict (Engadget) 

Briefing: Meta Details Efforts to Remove War-Related Disinformation (The Information)

Cloud gaming firm Shadow says hackers stole customers' personal data (TechCrunch) 

PC streaming service Shadow discloses security breach (The Verge) 

Shadow silent on data breach as hacked data appears genuine (TechCrunch) 

530K people's info stolen from cloud PC gaming's Shadow (Register) 

CDW investigating ransomware gang claims of data theft (Record) 

Lockbit ransomware gang demanded an 80 million ransom to CDW (Security Affairs) 

Void Rabisu Targets Female Political Leaders with New Slimmed-Down ROMCOM Variant (Trend Micro)

Women Political Leaders Summit targeted in RomCom malware phishing (BleepingComputer) 

Across U.S., Chinese Bitcoin Mines Draw National Security Scrutiny (New York Times)

Extract Knowledge
Listen elsewhere

Susan Hinrichs, Chief Scientist at Aviatrix sits down to share her story, with over 30 years in experience spanning a variety of networking and security disciplines and has held leadership and academic roles, she sits down to discuss her amazing career. Earlier in her career, Susan served as System Architect at Cisco where she spent nine years designing and developing Centri Firewall and a variety of network security management tools. She worked as a Lecturer, Computer and Network Security for eight years at the University of Illinois at Urbana-Champaign (UIUC) where she developed a hands-on Security Lab introduction course for students in her first year, and later in her tenure, along with two colleagues, created a malware analysis course designed for senior students. With all of the amazing things she's done in her career, she shares the advice to new comers into the field, saying "I think also as you're trying to get that next job either as a student or as a professional trying to change direction a little bit, if you're coming into interviews being able to talk about a project that you worked on, even if it's not a project that really anyone uses, but if it's something that's interesting that you have in depth understanding of, uh, I think is super valuable to get you noticed." We thank Susan for sharing her story with us.

More description

Susan Hinrichs, Chief Scientist at Aviatrix sits down to share her story, with over 30 years in experience spanning a variety of networking and security disciplines and has held leadership and academic roles, she sits down to discuss her amazing career. Earlier in her career, Susan served as System Architect at Cisco where she spent nine years designing and developing Centri Firewall and a variety of network security management tools. She worked as a Lecturer, Computer and Network Security for eight years at the University of Illinois at Urbana-Champaign (UIUC) where she developed a hands-on Security Lab introduction course for students in her first year, and later in her tenure, along with two colleagues, created a malware analysis course designed for senior students. With all of the amazing things she's done in her career, she shares the advice to new comers into the field, saying "I think also as you're trying to get that next job either as a student or as a professional trying to change direction a little bit, if you're coming into interviews being able to talk about a project that you worked on, even if it's not a project that really anyone uses, but if it's something that's interesting that you have in depth understanding of, uh, I think is super valuable to get you noticed." We thank Susan for sharing her story with us.

Extract Knowledge
Listen elsewhere

Amit Malik from Uptycs joins us to discuss their research titled "Unwanted Guests: Mitigating Remote Access Trojan Infection Risk." Uptycs threat research team identified a new threat referred to as QwixxRAT. The Uptycs team discovered this tool being widely distributed by the threat actor through Telegram and Discord platforms.

The research states "QwixxRAT is meticulously designed to harvest an expansive range of information from browser histories and credit card details, to keylogging insights." This newly found tool poses a risk to both businesses and individual users

More description

Amit Malik from Uptycs joins us to discuss their research titled "Unwanted Guests: Mitigating Remote Access Trojan Infection Risk." Uptycs threat research team identified a new threat referred to as QwixxRAT. The Uptycs team discovered this tool being widely distributed by the threat actor through Telegram and Discord platforms.

The research states "QwixxRAT is meticulously designed to harvest an expansive range of information from browser histories and credit card details, to keylogging insights." This newly found tool poses a risk to both businesses and individual users

Extract Knowledge
Listen elsewhere

Hacktivism and nation-state involvement in the cyber phases of war in the Middle East, and the use of Telegram. Russian groups squabble online. Healthcare cybersecurity and its implications for patient care. The Looting of FTX on the day of its bankruptcy. Joe Carrigan shares research from the Johns Hopkins University Information Security Institute. Our guest is Mike Walters from Action1, marking the 20th anniversary of Patch Tuesday. And CISA releases two new resources against ransomware.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/196


Selected reading.

Israeli Cyber Companies Rally as Digital, Physical Assaults Continue (Wall Street Journal)

Israel Sees Cyber Incursions Across Digital Systems (Wall Street Journal) 

Hackers infiltrated Israeli smart billboards to post pro-Hamas messages, reports say (Business Insider) 

THE HAMAS ISRAEL : CONFLICT EXPLAINER - CYFIRMA (CYFIRMA)

The First 72 Hours of the Israel-Hamas War: Hamas and PIJ Activity on Telegram (Flashpoint) 

Cyber Aggression Rises Following the October 2023 Israel-Hamas Conflict (Radware) 

EU opens probe into X over Israel-Hamas war misinformation (Financial Times) 

EU opens formal investigation into illegal content on X (Computing) 

X removes hundreds of Hamas-affiliated accounts since attack, CEO says (Reuters) 

US cyber agencies in 'very close contact' with Israel after unprecedented Hamas attacks (Nextgov.com) 

Five threats security pros everywhere need to focus on as the Middle East war escalates (SC Media) 

Cyber Insecurity in Healthcare: The Cost and Impact on Patient Safety and Care 2023 (Proofpoint) 

New Clues Suggest Stolen FTX Funds Went to Russia-Linked Money Launderers (WIRED) 

CISA Releases New Resources Identifying Known Exploited Vulnerabilities and Misconfigurations Linked to Ransomware | CISA (Cybersecurity and Infrastructure Security Agency CISA)

More description

Hacktivism and nation-state involvement in the cyber phases of war in the Middle East, and the use of Telegram. Russian groups squabble online. Healthcare cybersecurity and its implications for patient care. The Looting of FTX on the day of its bankruptcy. Joe Carrigan shares research from the Johns Hopkins University Information Security Institute. Our guest is Mike Walters from Action1, marking the 20th anniversary of Patch Tuesday. And CISA releases two new resources against ransomware.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/196


Selected reading.

Israeli Cyber Companies Rally as Digital, Physical Assaults Continue (Wall Street Journal)

Israel Sees Cyber Incursions Across Digital Systems (Wall Street Journal) 

Hackers infiltrated Israeli smart billboards to post pro-Hamas messages, reports say (Business Insider) 

THE HAMAS ISRAEL : CONFLICT EXPLAINER - CYFIRMA (CYFIRMA)

The First 72 Hours of the Israel-Hamas War: Hamas and PIJ Activity on Telegram (Flashpoint) 

Cyber Aggression Rises Following the October 2023 Israel-Hamas Conflict (Radware) 

EU opens probe into X over Israel-Hamas war misinformation (Financial Times) 

EU opens formal investigation into illegal content on X (Computing) 

X removes hundreds of Hamas-affiliated accounts since attack, CEO says (Reuters) 

US cyber agencies in 'very close contact' with Israel after unprecedented Hamas attacks (Nextgov.com) 

Five threats security pros everywhere need to focus on as the Middle East war escalates (SC Media) 

Cyber Insecurity in Healthcare: The Cost and Impact on Patient Safety and Care 2023 (Proofpoint) 

New Clues Suggest Stolen FTX Funds Went to Russia-Linked Money Launderers (WIRED) 

CISA Releases New Resources Identifying Known Exploited Vulnerabilities and Misconfigurations Linked to Ransomware | CISA (Cybersecurity and Infrastructure Security Agency CISA)

Extract Knowledge
Listen elsewhere

Hacktivists join both sides of Hamas's renewed war. Disinformation and content control in social media. Storm-0062 exploits an Atlassian 0-day. Curl and Libcurl vulnerabilities. Betsy Carmelite from Booz Allen on how to expand and diversify the Cyber Talent Pool. Our guest is Kuldip Mohanty, CIO of North Dakota. And some further reflections on hacktivism and the laws of war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/195


Selected reading.

False Alarm of Hezbollah Aircraft Infiltration Underlines Israeli Concern of Multi-Front War (FDD)

Israel-Hamas conflict extends to cyberspace (CSO Online)

Hamas-Israel Cyber War Escalates: What We Know So Far (Technopedia) 

Israeli Cyber Companies Rally as Digital, Physical Assaults Continue (Wall Street Journal) 

X promises 'highest level' response on posts about Israel-Hamas war. Misinformation still flourishes (AP News) 

Europe gives Mark Zuckerberg 24 hours to respond about Israel-Hamas conflict and election misinformation (CNBC)

Elon Musk Is Shitposting His Way Through the Israel-Hamas War (WIRED)

Facebook video of Biden prompts probe into Meta content policy (Financial Times) 

MIDDLE EAST : A CYBER ARMS RACE (CYFIRMA) 

Storm0062 exploits Atlassian 0-day. (CyberWire)

Curl and Libcurl vulnerabilities. (CyberWire)

Ukraine at D+595: Sabotage in the Baltic Sea. (CyberWire)

A Hacktivist Code of Conduct May Be Too Little Too Late (OODA Loop)

More description

Hacktivists join both sides of Hamas's renewed war. Disinformation and content control in social media. Storm-0062 exploits an Atlassian 0-day. Curl and Libcurl vulnerabilities. Betsy Carmelite from Booz Allen on how to expand and diversify the Cyber Talent Pool. Our guest is Kuldip Mohanty, CIO of North Dakota. And some further reflections on hacktivism and the laws of war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/195


Selected reading.

False Alarm of Hezbollah Aircraft Infiltration Underlines Israeli Concern of Multi-Front War (FDD)

Israel-Hamas conflict extends to cyberspace (CSO Online)

Hamas-Israel Cyber War Escalates: What We Know So Far (Technopedia) 

Israeli Cyber Companies Rally as Digital, Physical Assaults Continue (Wall Street Journal) 

X promises 'highest level' response on posts about Israel-Hamas war. Misinformation still flourishes (AP News) 

Europe gives Mark Zuckerberg 24 hours to respond about Israel-Hamas conflict and election misinformation (CNBC)

Elon Musk Is Shitposting His Way Through the Israel-Hamas War (WIRED)

Facebook video of Biden prompts probe into Meta content policy (Financial Times) 

MIDDLE EAST : A CYBER ARMS RACE (CYFIRMA) 

Storm0062 exploits Atlassian 0-day. (CyberWire)

Curl and Libcurl vulnerabilities. (CyberWire)

Ukraine at D+595: Sabotage in the Baltic Sea. (CyberWire)

A Hacktivist Code of Conduct May Be Too Little Too Late (OODA Loop)

Extract Knowledge
Listen elsewhere

Cyber operations in Hamas's war, Cryptocurrency as a source of funding, and Russian hacktivist auxiliaries shifting their focus. Not all influence operations involve disinformation. Rapid Reset is a Novel DDoS attack. A resurgent credential phishing campaign. Ann Johnson from Afternoon Cyber Tea speaks with Ram Shankar Siva Kumar and Dr. Hyrum Anderson about the promise, peril, and impact of AI. Our own Rick Howard talks cyber intelligence in the medical vertical with Taylor Lehmann of Google. And a quick look back at Patch Tuesday.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/194


Selected reading.

Hackers make their mark in Israel-Hamas conflict (Axios) 

Hacktivists take sides in Israel-Palestinian war (Record) 

Cyberattacks Targeting Israel Are Rising After Hamas Assault (Time) 

Hacktivists stoke Israel-Gaza conflict online (Reuters) 

Hackers, some tied to Russia, target Israeli media and government websites (MSN) 

Hamas Militants Behind Israel Attack Raised Millions in Crypto (Wall Street Journal) 

Cryptocurrency fueled Hamas' war machine (Quartz) 

The Israeli police cyber unit, Lahav 433, has frozen the cryptocurrency accounts of Hamas (Odessa Journal) 

U.S. surging cyber support to Israel (POLITICO Pro) 

Savvy Israel-linked hacking group reemerges amid Gaza fighting (CyberScoop) 

Israeli Cyber Companies Rally as Digital, Physical Assaults Continue (Wall Street Journal) 

Hamas Seeds Violent Videos on Sites With Little Moderation (New York Times) 

Social media platforms foment disinformation about war in Israel (Record) 

Hamas terrorists post murder of Israeli grandmother on her Facebook page (The Telegraph) 

How to limit graphic social media images from the Israel-Hamas war (Washington Post) 

Briefing: EU Commissioner Asks Musk for Information on “Illegal Content and Disinformation” Spreading on X (The Information)

EU warns Elon Musk of 'penalties' for disinformation circulating on X amid Israel-Hamas war (CNN) 

Hamas Got Around Israel’s Surveillance Prowess by Going Dark (Bloomberg) 

‘HTTP/2 Rapid Reset’ Zero-Day Exploited to Launch Largest DDoS Attacks in History (SecurityWeek)

New 'HTTP/2 Rapid Reset' zero-day attack breaks DDoS records (BleepingComputer) 

The largest cyberattack of its kind recently happened. Here’s how. (Washington Post) 

New technique leads to largest DDoS attacks ever, Google and Amazon say (Record) 

HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 (Cybersecurity and Infrastructure Security Agency CISA)

LinkedIn Smart Links Fuel Credential Phishing Campaign (Cofense)

Microsoft Fixes Exploited Zero-Days in WordPad, Skype for Business (SecurityWeek) 

Microsoft's October Patch Tuesday update resolves three zero-days (Computing) 

Microsoft Releases October 2023 Security Updates (Cybersecurity and Infrastructure Security Agency CISA) 

Patch Tuesday: Code Execution Flaws in Adobe Commerce, Photoshop (SecurityWeek) 

Citrix Releases Security Updates for Multiple Products (Cybersecurity and Infrastructure Security Agency CISA)

More description

Cyber operations in Hamas's war, Cryptocurrency as a source of funding, and Russian hacktivist auxiliaries shifting their focus. Not all influence operations involve disinformation. Rapid Reset is a Novel DDoS attack. A resurgent credential phishing campaign. Ann Johnson from Afternoon Cyber Tea speaks with Ram Shankar Siva Kumar and Dr. Hyrum Anderson about the promise, peril, and impact of AI. Our own Rick Howard talks cyber intelligence in the medical vertical with Taylor Lehmann of Google. And a quick look back at Patch Tuesday.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/194


Selected reading.

Hackers make their mark in Israel-Hamas conflict (Axios) 

Hacktivists take sides in Israel-Palestinian war (Record) 

Cyberattacks Targeting Israel Are Rising After Hamas Assault (Time) 

Hacktivists stoke Israel-Gaza conflict online (Reuters) 

Hackers, some tied to Russia, target Israeli media and government websites (MSN) 

Hamas Militants Behind Israel Attack Raised Millions in Crypto (Wall Street Journal) 

Cryptocurrency fueled Hamas' war machine (Quartz) 

The Israeli police cyber unit, Lahav 433, has frozen the cryptocurrency accounts of Hamas (Odessa Journal) 

U.S. surging cyber support to Israel (POLITICO Pro) 

Savvy Israel-linked hacking group reemerges amid Gaza fighting (CyberScoop) 

Israeli Cyber Companies Rally as Digital, Physical Assaults Continue (Wall Street Journal) 

Hamas Seeds Violent Videos on Sites With Little Moderation (New York Times) 

Social media platforms foment disinformation about war in Israel (Record) 

Hamas terrorists post murder of Israeli grandmother on her Facebook page (The Telegraph) 

How to limit graphic social media images from the Israel-Hamas war (Washington Post) 

Briefing: EU Commissioner Asks Musk for Information on “Illegal Content and Disinformation” Spreading on X (The Information)

EU warns Elon Musk of 'penalties' for disinformation circulating on X amid Israel-Hamas war (CNN) 

Hamas Got Around Israel’s Surveillance Prowess by Going Dark (Bloomberg) 

‘HTTP/2 Rapid Reset’ Zero-Day Exploited to Launch Largest DDoS Attacks in History (SecurityWeek)

New 'HTTP/2 Rapid Reset' zero-day attack breaks DDoS records (BleepingComputer) 

The largest cyberattack of its kind recently happened. Here’s how. (Washington Post) 

New technique leads to largest DDoS attacks ever, Google and Amazon say (Record) 

HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 (Cybersecurity and Infrastructure Security Agency CISA)

LinkedIn Smart Links Fuel Credential Phishing Campaign (Cofense)

Microsoft Fixes Exploited Zero-Days in WordPad, Skype for Business (SecurityWeek) 

Microsoft's October Patch Tuesday update resolves three zero-days (Computing) 

Microsoft Releases October 2023 Security Updates (Cybersecurity and Infrastructure Security Agency CISA) 

Patch Tuesday: Code Execution Flaws in Adobe Commerce, Photoshop (SecurityWeek) 

Citrix Releases Security Updates for Multiple Products (Cybersecurity and Infrastructure Security Agency CISA)

Extract Knowledge
Listen elsewhere

Disinformation and Hacktivism in the war between Hamas and Israel. KillNet and the IT Army of Ukraine say they'll follow ICRC guidelines. The current state of DPRK cyber operations. The Grayling cyberespionage group is active against Taiwan. A Magecart campaign abuses 404 pages. 23andMe suffers abreach. Voter records in Washington, DC, have been compromised. In our Solution Spotlight, Simone Petrella speaks with Raytheon’s Jon Check about supporting and shaping the next generation of the cyber workforce. Grady Summers from SailPoint outlines the importance of organizations managing and protecting access to critical data. And a look at CISOs willingness to pay ransom. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/193


Selected reading.

The Israel-Hamas War Is Drowning X in Disinformation (WIRED) 

As false war information spreads on X, Musk promotes unvetted accounts (Washington Post) 

Elon Musk’s X Cut Disinformation-Fighting Tool Ahead of Israel-Hamas Conflict (The Information) 

US opinion divided amid battle for narrative over Hamas attack on Israel (the Guardian) Zelensky Compares Assault by Hamas on Israel to Moscow’s Invasion of Ukraine (New York Times) 

Russia cites ‘concern’ but does not condemn Hamas attack on Israel (Washington Post) 

The Israel–Hamas Conflict: Implications for the Cyber Threat Landscape (ReliaQuest) 

Hackers Send Fake Rocket Alerts to Israelis via Hacked Red Alert App 

Hacktivism erupts in Middle East as Israel declares war (Register) 

The Israel-Hamas War Erupts in Digital Chaos (WIRED) 

Hacktivists in Palestine and Israel after SCADA and other industrial control systems (Cybernews) 

Hackers Join In on Israel-Hamas War With Disruptive Cyberattacks  (SecurityWeek)

Israel’s government, media websites hit with cyberattacks (Cybernews) 

Website of Jerusalem Post crashes after multiple cyberattacks (OpIndia) 

Ukraine cyber-conflict: Hacking gangs vow to de-escalate (BBC News) 

North Korea Suspected in Massive Hack of DeFi Project Mixin (OODA Loop) 

Assessed Cyber Structure and Alignments of North Korea in 2023 (Mandiant) 

Grayling: Previously Unseen Threat Actor Targets Multiple Organizations in Taiwan (Symantec)

The Art of Concealment: A New Magecart Campaign That’s Abusing 404 Pages (Akamai) 

Hacker Claims to Have Data of 7 Million 23andMe Users from DNA Service (Hack Read) 

23andMe user data breached in credential-stuffing attack (Engadget) 

‘Your DNA is for sale on the black market’: 23andMe data breach exposes customers (The Daily Dot) 

23andMe User Data Stolen in Targeted Attack on Ashkenazi Jews (WIRED) 

23andMe data breach affects a million users with Jewish heritage (Dataconomy)

D.C. voter records for sale in cybercrime forum (CyberScoop) 

Hackers access voter information in DC Board of Elections data breach (WTOP News) 

DC Board of Elections investigates voter data breach (NBC4 Washington) 

The CISO Report (Splunk)

October 2023 Patch Tuesday forecast: Operating system updates and zero-days aplenty (Help Net Security)

More description

Disinformation and Hacktivism in the war between Hamas and Israel. KillNet and the IT Army of Ukraine say they'll follow ICRC guidelines. The current state of DPRK cyber operations. The Grayling cyberespionage group is active against Taiwan. A Magecart campaign abuses 404 pages. 23andMe suffers abreach. Voter records in Washington, DC, have been compromised. In our Solution Spotlight, Simone Petrella speaks with Raytheon’s Jon Check about supporting and shaping the next generation of the cyber workforce. Grady Summers from SailPoint outlines the importance of organizations managing and protecting access to critical data. And a look at CISOs willingness to pay ransom. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/193


Selected reading.

The Israel-Hamas War Is Drowning X in Disinformation (WIRED) 

As false war information spreads on X, Musk promotes unvetted accounts (Washington Post) 

Elon Musk’s X Cut Disinformation-Fighting Tool Ahead of Israel-Hamas Conflict (The Information) 

US opinion divided amid battle for narrative over Hamas attack on Israel (the Guardian) Zelensky Compares Assault by Hamas on Israel to Moscow’s Invasion of Ukraine (New York Times) 

Russia cites ‘concern’ but does not condemn Hamas attack on Israel (Washington Post) 

The Israel–Hamas Conflict: Implications for the Cyber Threat Landscape (ReliaQuest) 

Hackers Send Fake Rocket Alerts to Israelis via Hacked Red Alert App 

Hacktivism erupts in Middle East as Israel declares war (Register) 

The Israel-Hamas War Erupts in Digital Chaos (WIRED) 

Hacktivists in Palestine and Israel after SCADA and other industrial control systems (Cybernews) 

Hackers Join In on Israel-Hamas War With Disruptive Cyberattacks  (SecurityWeek)

Israel’s government, media websites hit with cyberattacks (Cybernews) 

Website of Jerusalem Post crashes after multiple cyberattacks (OpIndia) 

Ukraine cyber-conflict: Hacking gangs vow to de-escalate (BBC News) 

North Korea Suspected in Massive Hack of DeFi Project Mixin (OODA Loop) 

Assessed Cyber Structure and Alignments of North Korea in 2023 (Mandiant) 

Grayling: Previously Unseen Threat Actor Targets Multiple Organizations in Taiwan (Symantec)

The Art of Concealment: A New Magecart Campaign That’s Abusing 404 Pages (Akamai) 

Hacker Claims to Have Data of 7 Million 23andMe Users from DNA Service (Hack Read) 

23andMe user data breached in credential-stuffing attack (Engadget) 

‘Your DNA is for sale on the black market’: 23andMe data breach exposes customers (The Daily Dot) 

23andMe User Data Stolen in Targeted Attack on Ashkenazi Jews (WIRED) 

23andMe data breach affects a million users with Jewish heritage (Dataconomy)

D.C. voter records for sale in cybercrime forum (CyberScoop) 

Hackers access voter information in DC Board of Elections data breach (WTOP News) 

DC Board of Elections investigates voter data breach (NBC4 Washington) 

The CISO Report (Splunk)

October 2023 Patch Tuesday forecast: Operating system updates and zero-days aplenty (Help Net Security)

Extract Knowledge
Listen elsewhere

Solution Spotlight: Simone Petrella is talking with Diane Janosek, Executive Director of Capitol Technology University's Center for Women in Cyber, about paths to cybersecurity and ways to address cybersecurity workforce intelligence through education.

You can view the video of this interview here.

More description

Solution Spotlight: Simone Petrella is talking with Diane Janosek, Executive Director of Capitol Technology University's Center for Women in Cyber, about paths to cybersecurity and ways to address cybersecurity workforce intelligence through education.

You can view the video of this interview here.

Extract Knowledge
Listen elsewhere
Show details
Episodes
3784
Transcripts
67
2% coverage
Missing transcripts
3717
With chapters
0