Search this show’s transcripts

CyberWire Daily

en us
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
More details
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
Sources and links

Episodes

Page 25 · 50 per page

Susie Squier, President of the Retail and Hospitality ISAC, or Information Sharing and Analysis Center, sits down to share her incredible story starting to get her into the cyber community. She first started getting into PR through an internship she did in college, then moved around a few times gaining experience everywhere she went. Susie shares some wise advice, discussing not only her managing style, but also how she handles situations, along with how she deals with adversity. She says "I also have realized over time that I'm never in this alone, whether that's your personal life or your work life and even here, uh, in addition to a great team, all great team." She hopes people will jump in to the world of cyber with an open mind, and though it may be frightening at first, she says you just need to dive in anyway and not be afraid to try new things. We thank Susie for sharing her story with us.

More description

Susie Squier, President of the Retail and Hospitality ISAC, or Information Sharing and Analysis Center, sits down to share her incredible story starting to get her into the cyber community. She first started getting into PR through an internship she did in college, then moved around a few times gaining experience everywhere she went. Susie shares some wise advice, discussing not only her managing style, but also how she handles situations, along with how she deals with adversity. She says "I also have realized over time that I'm never in this alone, whether that's your personal life or your work life and even here, uh, in addition to a great team, all great team." She hopes people will jump in to the world of cyber with an open mind, and though it may be frightening at first, she says you just need to dive in anyway and not be afraid to try new things. We thank Susie for sharing her story with us.

Extract Knowledge
Listen elsewhere
Published 2023-10-07

Targets from DuckTail. [Research Saturday]

15 min
View

Deepen Desai from Zscaler joins to take a look into their research about "DuckTail." In May of 2023, Zscaler ThreatLabz began an intelligence collection operation to decode DuckTail’s maneuvers. Through an intensive three-month period of monitoring, Zscaler was able obtain unprecedented visibility into DuckTail’s end-to-end operations, spanning the entire kill chain from reconnaissance to post-compromise.

The research states "DuckTail threat actors primarily target users working in the digital marketing and advertising space. Unfortunately, the tech layoffs occurring in 2022 and 2023 introduced more eager candidates into the digital market - meaning more prime targets for DuckTail."

The research can be found here:

More description

Deepen Desai from Zscaler joins to take a look into their research about "DuckTail." In May of 2023, Zscaler ThreatLabz began an intelligence collection operation to decode DuckTail’s maneuvers. Through an intensive three-month period of monitoring, Zscaler was able obtain unprecedented visibility into DuckTail’s end-to-end operations, spanning the entire kill chain from reconnaissance to post-compromise.

The research states "DuckTail threat actors primarily target users working in the digital marketing and advertising space. Unfortunately, the tech layoffs occurring in 2022 and 2023 introduced more eager candidates into the digital market - meaning more prime targets for DuckTail."

The research can be found here:

Extract Knowledge
Listen elsewhere

NSA and CISA release a list of the ten most common misconfigurations along with Identity and access management guidelines. The Predator Files. Cyber cooperation between Russia and North Korea. Hacktivist auxiliaries hit Australia. Hacktivists and hacktivist auxiliaries scorn the application of international humanitarian law. The direction of Russian cyber operations. Dave Bittner speaks with Andrea Little Limbago from Interos to talk about geopolitics, cyber and the C-suite. Rick Howard talks with John Hultquist, Chief Analyst at Mandiant, at the mWISE 2023 Cybersecurity Conference about cyber threat intelligence. And, finally, adventures in catphishing: “LoveGPT.”


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/192


Selected reading.

NSA and CISA Release Advisory on Top Ten Cybersecurity Misconfigurations (Cybersecurity and Infrastructure Security Agency CISA)

CISA and NSA Release New Guidance on Identity and Access Management (Cybersecurity and Infrastructure Security Agency CISA)

Microsoft Digital Defense Report 2023 (Microsoft)

Predator Files | EIC (European Investigative Collaborations)

Meet the ‘Predator Files,’ the latest investigative project looking into spyware (Washington Post)

NORTH KOREA–RUSSIA SUMMIT : A NEW ALLIANCE IN CYBERSPACE? - CYFIRMA (CYFIRMA) 

Australia’s home affairs department hit by DDoS attack claimed by pro-Russia hackers (the Guardian) 

Pro-Russia hacktivist group targets Australian government agencies over support for Ukraine (Cyberdaily.au) 

Home Affairs, Administrative Appeals Tribunal websites hit by cyber attacks (SBS News) 

‘War has no rules’: Hacktivists scorn Red Cross’ new guidelines (Record) 

Espionage fuels global cyberattacks (Microsoft On the Issues) 

LoveGPT: How “single ladies” looking for your data upped their game with ChatGPT (Avast Threat Labs)

More description

NSA and CISA release a list of the ten most common misconfigurations along with Identity and access management guidelines. The Predator Files. Cyber cooperation between Russia and North Korea. Hacktivist auxiliaries hit Australia. Hacktivists and hacktivist auxiliaries scorn the application of international humanitarian law. The direction of Russian cyber operations. Dave Bittner speaks with Andrea Little Limbago from Interos to talk about geopolitics, cyber and the C-suite. Rick Howard talks with John Hultquist, Chief Analyst at Mandiant, at the mWISE 2023 Cybersecurity Conference about cyber threat intelligence. And, finally, adventures in catphishing: “LoveGPT.”


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/192


Selected reading.

NSA and CISA Release Advisory on Top Ten Cybersecurity Misconfigurations (Cybersecurity and Infrastructure Security Agency CISA)

CISA and NSA Release New Guidance on Identity and Access Management (Cybersecurity and Infrastructure Security Agency CISA)

Microsoft Digital Defense Report 2023 (Microsoft)

Predator Files | EIC (European Investigative Collaborations)

Meet the ‘Predator Files,’ the latest investigative project looking into spyware (Washington Post)

NORTH KOREA–RUSSIA SUMMIT : A NEW ALLIANCE IN CYBERSPACE? - CYFIRMA (CYFIRMA) 

Australia’s home affairs department hit by DDoS attack claimed by pro-Russia hackers (the Guardian) 

Pro-Russia hacktivist group targets Australian government agencies over support for Ukraine (Cyberdaily.au) 

Home Affairs, Administrative Appeals Tribunal websites hit by cyber attacks (SBS News) 

‘War has no rules’: Hacktivists scorn Red Cross’ new guidelines (Record) 

Espionage fuels global cyberattacks (Microsoft On the Issues) 

LoveGPT: How “single ladies” looking for your data upped their game with ChatGPT (Avast Threat Labs)

Extract Knowledge
Listen elsewhere

Apple patches actively exploited iOS 17 vulnerability. Qakbot's survival of a major takedown. BADBOX puts malware into the device supply chain. LoonyTunables and a privilege-escalation risk. Scattered Spider believed responsible for cyberattack against Clorox. Sony discloses information on its data breach. In today’s Threat Vector segment, Chris Tillett, Senior Research Engineer at Palo Alto Networks and member of the Advisory Board at Titaniam Labs, joins host David Moulton to delve inside the mind of an insider threat. Dave Bittner sits down with Eric Goldstein, Executive Assistant Director at CISA, to discuss shared progress against the ransomware threat. And the Kremlin tightens control over the Russian information space.


On this segment of Threat Vector, Chris Tillett, Senior Research Engineer at Palo Alto Networks and member of the Advisory Board at Titaniam Labs, joins host David Moulton to delve inside the mind of an insider threat.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/191


Selected reading.

Apple emergency update fixes new zero-day used to hack iPhones (BleepingComputer)

Apple releases iOS 17.0.3 to address iPhone 15 overheating issues (Computing) 

Apple Warns of Newly Exploited iOS 17 Kernel Zero-Day (SecurityWeek) 

Qakbot-affiliated actors distribute Ransom Knight malware despite infrastructure takedown (Cisco Talos Blog)

HUMAN Disrupts Digital Supply Chain Threat Actor Scheme Originating from China (HUMAN)

Trojans All the Way Down: BADBOX and PEACHPIT (Human)

'Looney Tunables' Bug Opens Millions of Linux Systems to Root Takeover (Dark Reading)

Looney Tunables: New Linux Flaw Enables Privilege Escalation on Major Distributions (The Hacker News) 

Clorox Security Breach Linked to Group Behind Casino Hacks (Bloomberg) 

Clorox Warns of a Sales Mess After Cyberattack (Wall Street Journal)

Sony confirms data breach impacting thousands in the U.S. (BleepingComputer)

Sony sent data breach notifications to about 6,800 individuals (Security Affairs) 

Russian Offensive Campaign Assessment, October 4, 2023 (Institute for the Study of War)

More description

Apple patches actively exploited iOS 17 vulnerability. Qakbot's survival of a major takedown. BADBOX puts malware into the device supply chain. LoonyTunables and a privilege-escalation risk. Scattered Spider believed responsible for cyberattack against Clorox. Sony discloses information on its data breach. In today’s Threat Vector segment, Chris Tillett, Senior Research Engineer at Palo Alto Networks and member of the Advisory Board at Titaniam Labs, joins host David Moulton to delve inside the mind of an insider threat. Dave Bittner sits down with Eric Goldstein, Executive Assistant Director at CISA, to discuss shared progress against the ransomware threat. And the Kremlin tightens control over the Russian information space.


On this segment of Threat Vector, Chris Tillett, Senior Research Engineer at Palo Alto Networks and member of the Advisory Board at Titaniam Labs, joins host David Moulton to delve inside the mind of an insider threat.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/191


Selected reading.

Apple emergency update fixes new zero-day used to hack iPhones (BleepingComputer)

Apple releases iOS 17.0.3 to address iPhone 15 overheating issues (Computing) 

Apple Warns of Newly Exploited iOS 17 Kernel Zero-Day (SecurityWeek) 

Qakbot-affiliated actors distribute Ransom Knight malware despite infrastructure takedown (Cisco Talos Blog)

HUMAN Disrupts Digital Supply Chain Threat Actor Scheme Originating from China (HUMAN)

Trojans All the Way Down: BADBOX and PEACHPIT (Human)

'Looney Tunables' Bug Opens Millions of Linux Systems to Root Takeover (Dark Reading)

Looney Tunables: New Linux Flaw Enables Privilege Escalation on Major Distributions (The Hacker News) 

Clorox Security Breach Linked to Group Behind Casino Hacks (Bloomberg) 

Clorox Warns of a Sales Mess After Cyberattack (Wall Street Journal)

Sony confirms data breach impacting thousands in the U.S. (BleepingComputer)

Sony sent data breach notifications to about 6,800 individuals (Security Affairs) 

Russian Offensive Campaign Assessment, October 4, 2023 (Institute for the Study of War)

Extract Knowledge
Listen elsewhere

EvilProxy phishes for executives. Typosquatting to deliver a rootkit. Stream-jacking on YouTube. A global look at risk management. Assistance from a diverse set of international partners. In our Solution Spotlight segment, Simone Petrella speaks with Diane Janosek, Executive Director of Capitol Technology University's Center for Women in Cyber, about paths to cybersecurity and ways to address cybersecurity workforce intelligence through education. Dave Bittner previews the 3rd annual SOC Analyst Appreciation Day with Kayla Williams of Devo. And some guidelines for hacktivists engaged in hybrid war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/190


Selected reading.

EvilProxy Phishing Attack Strikes Indeed (Menlo Security)

Typosquatting campaign delivers r77 rootkit via npm (ReversingLabs)

A Deep Dive into Stream-Jacking Attacks on YouTube and Why They're So Popular (Bitdefender Labs) 

The C-suite playbook: Putting security at the epicenter of innovation (PwC)

European Peace Foundation (EPF) opens cyber classroom for Ukrainian Armed Forces - EU NEIGHBOURS east (EU NEIGHBOURS east) 

Rethinking Security When So Many Threats Are Invisible (New York Times)

8 rules for “civilian hackers” during war, and 4 obligations for states to restrain them (EJIL: Talk!)

More description

EvilProxy phishes for executives. Typosquatting to deliver a rootkit. Stream-jacking on YouTube. A global look at risk management. Assistance from a diverse set of international partners. In our Solution Spotlight segment, Simone Petrella speaks with Diane Janosek, Executive Director of Capitol Technology University's Center for Women in Cyber, about paths to cybersecurity and ways to address cybersecurity workforce intelligence through education. Dave Bittner previews the 3rd annual SOC Analyst Appreciation Day with Kayla Williams of Devo. And some guidelines for hacktivists engaged in hybrid war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/190


Selected reading.

EvilProxy Phishing Attack Strikes Indeed (Menlo Security)

Typosquatting campaign delivers r77 rootkit via npm (ReversingLabs)

A Deep Dive into Stream-Jacking Attacks on YouTube and Why They're So Popular (Bitdefender Labs) 

The C-suite playbook: Putting security at the epicenter of innovation (PwC)

European Peace Foundation (EPF) opens cyber classroom for Ukrainian Armed Forces - EU NEIGHBOURS east (EU NEIGHBOURS east) 

Rethinking Security When So Many Threats Are Invisible (New York Times)

8 rules for “civilian hackers” during war, and 4 obligations for states to restrain them (EJIL: Talk!)

Extract Knowledge
Listen elsewhere

Nearly 100,000 ICS services exposed to the Internet. BunnyLoader in the C2C market. Phantom Hacker scams. API risks. Cybersecurity attitudes and behaviors. Homeland Security IG finds flaws in TSA pipeline security programs, and privacy issues with CBP, ICE, and USSS use of commercial telemetry. Kyiv prepares for Russian attacks on Ukraine's power grid. Ben Yelin on the Department of Commerce placing guardrails on semi-conductor companies. As part of our sponsored Industry Voices segment, Dave Bittner sits down with Nick Ascoli, Founder and CTO at Foretrace, to discuss the last year in data leaks. And Russian disinformation is expected to aim at undermining US support for Ukraine.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/189


Selected reading.

Bitsight identifies nearly 100,000 exposed industrial control systems (Bitsight) 

New BunnyLoader threat emerges as a feature-rich malware-as-a-service (BleepingComputer) 

"Phantom Hacker" Scams Target Senior Citizens and Result in Victims Losing their Life Savings (FBI)

FBI warns of surge in 'phantom hacker' scams impacting elderly (BleepingComputer)

APIs: Unveiling the Silent Killer of Cyber Security Risk Across Industries (Hacker News)

Oh Behave! The Annual Cybersecurity Attitudes and Behaviors Report 2023 (National Cybersecurity Alliance)

Watchdog says pipeline security regulations, data collection safeguards not up to snuff at DHS (Washington Post) 

Better TSA Tracking and Follow-up for the 2021 Security Directives Implementation Should Strengthen Pipeline Cybersecurity (REDACTED) (Office of Inspector General, Department of Homeland Security) 

CBP, ICE, and Secret Service Did Not Adhere to Privacy Policies or Develop Sufficient Policies Before Procuring and Using Commercial Telemetry Data (REDACTED) (Office of Inspector General, Department of Homeland Security) 

Ukraine prepares for winter again as Russia targets its power grid (The Economist) 

Putin’s Next Target: U.S. Support for Ukraine, Officials Say (New York Times

More description

Nearly 100,000 ICS services exposed to the Internet. BunnyLoader in the C2C market. Phantom Hacker scams. API risks. Cybersecurity attitudes and behaviors. Homeland Security IG finds flaws in TSA pipeline security programs, and privacy issues with CBP, ICE, and USSS use of commercial telemetry. Kyiv prepares for Russian attacks on Ukraine's power grid. Ben Yelin on the Department of Commerce placing guardrails on semi-conductor companies. As part of our sponsored Industry Voices segment, Dave Bittner sits down with Nick Ascoli, Founder and CTO at Foretrace, to discuss the last year in data leaks. And Russian disinformation is expected to aim at undermining US support for Ukraine.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/189


Selected reading.

Bitsight identifies nearly 100,000 exposed industrial control systems (Bitsight) 

New BunnyLoader threat emerges as a feature-rich malware-as-a-service (BleepingComputer) 

"Phantom Hacker" Scams Target Senior Citizens and Result in Victims Losing their Life Savings (FBI)

FBI warns of surge in 'phantom hacker' scams impacting elderly (BleepingComputer)

APIs: Unveiling the Silent Killer of Cyber Security Risk Across Industries (Hacker News)

Oh Behave! The Annual Cybersecurity Attitudes and Behaviors Report 2023 (National Cybersecurity Alliance)

Watchdog says pipeline security regulations, data collection safeguards not up to snuff at DHS (Washington Post) 

Better TSA Tracking and Follow-up for the 2021 Security Directives Implementation Should Strengthen Pipeline Cybersecurity (REDACTED) (Office of Inspector General, Department of Homeland Security) 

CBP, ICE, and Secret Service Did Not Adhere to Privacy Policies or Develop Sufficient Policies Before Procuring and Using Commercial Telemetry Data (REDACTED) (Office of Inspector General, Department of Homeland Security) 

Ukraine prepares for winter again as Russia targets its power grid (The Economist) 

Putin’s Next Target: U.S. Support for Ukraine, Officials Say (New York Times

Extract Knowledge
Listen elsewhere

Double-tapping ransomware hits the same victim twice. Exim mail servers are found exposed to attack. Iran's OilRig deploys Menorah malware against Saudi targets. North Korea's Lazarus Group targets a Spanish aerospace firm. Update your ransomware scorecards: LostTrust is a rebrand of MetaEncryptor. Increased domestic surveillance in Russia, done partly so propaganda can be more effectively targeted. Killnet claims to have hit the British Royal family with a DDoS attack. Michael Denning, CEO at SecureG for Blu Ventures, shares developments in zero trust as a part of our Industry Voices segment. Rob Boyce from Accenture Security talks about Dark Web threat actors targeting macOS. And Cybersecurity Awareness Month begins this week.


Learn more about the Blu Ventures Conference here: https://www.bluventureinvestors.com/cyber-venture-forum


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/188


Selected reading.

Two or More Ransomware Variants Impacting the Same Victims and Data Destruction Trends (FBI) 

FBI: Ransomware Actors Launching 'Dual' Attacks (Decipher) 

A still unpatched 0-day RCE impacts more than 3.5M Exim servers (Security Affairs) 

New Critical Security Flaws Expose Exim Mail Servers to Remote Attacks (The Hacker News)

APT34 deploys new Menorah malware in targeted phishing attack (Candid.Technology) 

APT34 Deploys Phishing Attack With New Malware (Trend Micro) 

Iranian APT Group OilRig Using New Menorah Malware for Covert Operations (The Hacker News) 

Alleged Iranian hackers target victims in Saudi Arabia with new spying malware (Record) 

North Korean hackers posed as Meta recruiter on LinkedIn (CyberScoop)

Lazarus APT Exploiting LinkedIn to Target Spanish Aerospace Firm (Hackread)

North Korean Lazarus targeted a Spanish aerospace company (Security Affairs)

Meet LostTrust ransomware — A likely rebrand of the MetaEncryptor gang (BleepingComputer)

Ukraine at D+585: Trench fighting in the south. (CyberWire)

Royal Family's official website targeted in cyber attack (Sky News)

Royal family website hit by cyber attack (The Independent)

The country ‘dodged a bullet’ after shutdown avoided, but the cyber threat still hovers (Washington Post)

US Federal shutdown averted (or postponed): effects on cybersecurity. (CyberWire)

Cybersecurity Awareness Month: perspectives from the cyber sector. (CyberWire)

Kicking off NIST's Cybersecurity Awareness Month Celebration & Our Cybersecurity Awareness Month 2023 Blog Series (NIST) 

More description

Double-tapping ransomware hits the same victim twice. Exim mail servers are found exposed to attack. Iran's OilRig deploys Menorah malware against Saudi targets. North Korea's Lazarus Group targets a Spanish aerospace firm. Update your ransomware scorecards: LostTrust is a rebrand of MetaEncryptor. Increased domestic surveillance in Russia, done partly so propaganda can be more effectively targeted. Killnet claims to have hit the British Royal family with a DDoS attack. Michael Denning, CEO at SecureG for Blu Ventures, shares developments in zero trust as a part of our Industry Voices segment. Rob Boyce from Accenture Security talks about Dark Web threat actors targeting macOS. And Cybersecurity Awareness Month begins this week.


Learn more about the Blu Ventures Conference here: https://www.bluventureinvestors.com/cyber-venture-forum


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/188


Selected reading.

Two or More Ransomware Variants Impacting the Same Victims and Data Destruction Trends (FBI) 

FBI: Ransomware Actors Launching 'Dual' Attacks (Decipher) 

A still unpatched 0-day RCE impacts more than 3.5M Exim servers (Security Affairs) 

New Critical Security Flaws Expose Exim Mail Servers to Remote Attacks (The Hacker News)

APT34 deploys new Menorah malware in targeted phishing attack (Candid.Technology) 

APT34 Deploys Phishing Attack With New Malware (Trend Micro) 

Iranian APT Group OilRig Using New Menorah Malware for Covert Operations (The Hacker News) 

Alleged Iranian hackers target victims in Saudi Arabia with new spying malware (Record) 

North Korean hackers posed as Meta recruiter on LinkedIn (CyberScoop)

Lazarus APT Exploiting LinkedIn to Target Spanish Aerospace Firm (Hackread)

North Korean Lazarus targeted a Spanish aerospace company (Security Affairs)

Meet LostTrust ransomware — A likely rebrand of the MetaEncryptor gang (BleepingComputer)

Ukraine at D+585: Trench fighting in the south. (CyberWire)

Royal Family's official website targeted in cyber attack (Sky News)

Royal family website hit by cyber attack (The Independent)

The country ‘dodged a bullet’ after shutdown avoided, but the cyber threat still hovers (Washington Post)

US Federal shutdown averted (or postponed): effects on cybersecurity. (CyberWire)

Cybersecurity Awareness Month: perspectives from the cyber sector. (CyberWire)

Kicking off NIST's Cybersecurity Awareness Month Celebration & Our Cybersecurity Awareness Month 2023 Blog Series (NIST) 

Extract Knowledge
Listen elsewhere

This week, we are joined by Ted Wagner, Chief Information Security Officer at SAP National Security Services, or SAP NS2. Ted sits down to share his story on how he got introduced into the industry and why he chose this as a career path. He went straight into the Armyas a second lieutenant in the artillery field after high school, which after his time was up he decided to move on and started working for a company that allowed him to do a management training program. After that he found himself working on IT projects which got him interested in the field. Ted shares that one thing that has helped him throughout his career is teaching about very technical terms and turning it into more operational or business like terms for his students at MIT. He shares that people getting into this field should get as much hands on experience as they can, saying "I think those are all things that can really help someone who may not have all the experience, but this is a pathway to, to learn." We thank Ted for sharing his story with us.

More description

This week, we are joined by Ted Wagner, Chief Information Security Officer at SAP National Security Services, or SAP NS2. Ted sits down to share his story on how he got introduced into the industry and why he chose this as a career path. He went straight into the Armyas a second lieutenant in the artillery field after high school, which after his time was up he decided to move on and started working for a company that allowed him to do a management training program. After that he found himself working on IT projects which got him interested in the field. Ted shares that one thing that has helped him throughout his career is teaching about very technical terms and turning it into more operational or business like terms for his students at MIT. He shares that people getting into this field should get as much hands on experience as they can, saying "I think those are all things that can really help someone who may not have all the experience, but this is a pathway to, to learn." We thank Ted for sharing his story with us.

Extract Knowledge
Listen elsewhere

David Liebenberg from Cisco Talos joins to discussing Talos' discovery of cracked Microsoft Windows software being downloaded by enterprise users across the globe. Downloading and running this compromised software not only serves as an entry point for threat actors, but can serve as a gateway to access control systems and establish backdoors.

Talos identified additional malware, including RATs, on endpoints running this cracked software, which allows an attacker to gain unauthorized remote access to the compromised system, providing the attacker with various capabilities, such as controlling the system, capturing screenshots, recording keystrokes and exfiltrating sensitive information.

This research article was not published by Cisco Talos' team.

More description

David Liebenberg from Cisco Talos joins to discussing Talos' discovery of cracked Microsoft Windows software being downloaded by enterprise users across the globe. Downloading and running this compromised software not only serves as an entry point for threat actors, but can serve as a gateway to access control systems and establish backdoors.

Talos identified additional malware, including RATs, on endpoints running this cracked software, which allows an attacker to gain unauthorized remote access to the compromised system, providing the attacker with various capabilities, such as controlling the system, capturing screenshots, recording keystrokes and exfiltrating sensitive information.

This research article was not published by Cisco Talos' team.

Extract Knowledge
Listen elsewhere

Malicious ads in a chatbot. Google provides clarification on a recent vulnerability. Cl0p switches from Tor to torrents. Influence operations as an adjunct to weapons of mass destruction. Our guest Jeffrey Wells, former Maryland cyber czar and partner at Sigma7 shares his thoughts on what the looming US government shutdown will mean for the nation’s cybersecurity. Tim Eades from Cyber Mentor Fund discussing the 3 who’s a cybersecurity entrepreneur needs to consider. And NSA has a new AI Security Center.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/187


Selected reading.

Malicious ad served inside Bing's AI chatbot (Malwarebytes)

Critical Vulnerability: WebP Heap Buffer Overflow (CVE-2023-4863) (Huntress) 

Google gives WebP library heap buffer overflow a critical score, but NIST rates it as high-severity (SC Media) 

A new Chrome 0-day is sending the Internet into a new chapter of Groundhog Day (Ars Technica) 

Google "confirms" that exploited Chrome zero-day is actually in libwebp (CVE-2023-5129) (Help Net Security) 

Google quietly corrects previously submitted disclosure for critical webp 0-day (Ars Technica)

CL0P Seeds ^_- Gotta Catch Em All! (Unit 42) 

A ransomware gang innovates, putting pressure on victims but also exposing itself (Washington Post) 

2023 Department of Defense Strategy for Countering Weapons of Mass Destruction (US Department of Defense)

NSA chief announces new AI Security Center, 'focal point' for AI use by government, defense industry (Breaking Defense)

NSA starts AI security center with eye on China and Russia (Fortune) 

NSA is creating a hub for AI security, Nakasone says (Record)

More description

Malicious ads in a chatbot. Google provides clarification on a recent vulnerability. Cl0p switches from Tor to torrents. Influence operations as an adjunct to weapons of mass destruction. Our guest Jeffrey Wells, former Maryland cyber czar and partner at Sigma7 shares his thoughts on what the looming US government shutdown will mean for the nation’s cybersecurity. Tim Eades from Cyber Mentor Fund discussing the 3 who’s a cybersecurity entrepreneur needs to consider. And NSA has a new AI Security Center.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/187


Selected reading.

Malicious ad served inside Bing's AI chatbot (Malwarebytes)

Critical Vulnerability: WebP Heap Buffer Overflow (CVE-2023-4863) (Huntress) 

Google gives WebP library heap buffer overflow a critical score, but NIST rates it as high-severity (SC Media) 

A new Chrome 0-day is sending the Internet into a new chapter of Groundhog Day (Ars Technica) 

Google "confirms" that exploited Chrome zero-day is actually in libwebp (CVE-2023-5129) (Help Net Security) 

Google quietly corrects previously submitted disclosure for critical webp 0-day (Ars Technica)

CL0P Seeds ^_- Gotta Catch Em All! (Unit 42) 

A ransomware gang innovates, putting pressure on victims but also exposing itself (Washington Post) 

2023 Department of Defense Strategy for Countering Weapons of Mass Destruction (US Department of Defense)

NSA chief announces new AI Security Center, 'focal point' for AI use by government, defense industry (Breaking Defense)

NSA starts AI security center with eye on China and Russia (Fortune) 

NSA is creating a hub for AI security, Nakasone says (Record)

Extract Knowledge
Listen elsewhere

The Budworm APT's bespoke tools. Johnson Controls sustains a cyberattack. The US Privacy and Civil Liberties Oversight Board reports on Section 702. The looming government shutdown and cyber risk. Cybersecurity in the US industrial base. X cuts back content moderation capabilities. In our Industry Voices segment, Nicholas Kathmann from LogicGate describes the struggle when facing low cost attacks. Sam Crowther from Kasada shares his team's findings on Stolen Auto Accounts. And Ukrainian hacktivists target Russian airline check-in systems.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/186


Selected reading.

Budworm: APT Group Uses Updated Custom Tool in Attacks on Government and Telecoms Org (Symantec Enterprise Blogs)

Johnson Controls reports data breach after severe ransomware attack (BeyondMachines) 

Report on the Surveillance Program Operated Pursuant to Section 702 of the Foreign Intelligence Surveillance Act (U.S. Privacy and Civil Liberties Oversight Board) 

Split privacy board urges big changes to Section 702 surveillance law (Washington Post)

Democrats fear cyberattacks as government shutdown looms (Nextgov.com) 

Aprio Releases U.S. National Manufacturing Survey, Highlighting the Need for Improved Operational Excellence, Digitization and Cybersecurity Practices (Aprio) 

Musk's X disabled feature for reporting electoral misinformation - researcher (Reuters) 

Musk’s X Cuts Half of Election Integrity Team After Promising to Expand It (The Information)

Aeroflot, other airlines’ flights delayed over DDoS attack (Cybernews)

More description

The Budworm APT's bespoke tools. Johnson Controls sustains a cyberattack. The US Privacy and Civil Liberties Oversight Board reports on Section 702. The looming government shutdown and cyber risk. Cybersecurity in the US industrial base. X cuts back content moderation capabilities. In our Industry Voices segment, Nicholas Kathmann from LogicGate describes the struggle when facing low cost attacks. Sam Crowther from Kasada shares his team's findings on Stolen Auto Accounts. And Ukrainian hacktivists target Russian airline check-in systems.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/186


Selected reading.

Budworm: APT Group Uses Updated Custom Tool in Attacks on Government and Telecoms Org (Symantec Enterprise Blogs)

Johnson Controls reports data breach after severe ransomware attack (BeyondMachines) 

Report on the Surveillance Program Operated Pursuant to Section 702 of the Foreign Intelligence Surveillance Act (U.S. Privacy and Civil Liberties Oversight Board) 

Split privacy board urges big changes to Section 702 surveillance law (Washington Post)

Democrats fear cyberattacks as government shutdown looms (Nextgov.com) 

Aprio Releases U.S. National Manufacturing Survey, Highlighting the Need for Improved Operational Excellence, Digitization and Cybersecurity Practices (Aprio) 

Musk's X disabled feature for reporting electoral misinformation - researcher (Reuters) 

Musk’s X Cuts Half of Election Integrity Team After Promising to Expand It (The Information)

Aeroflot, other airlines’ flights delayed over DDoS attack (Cybernews)

Extract Knowledge
Listen elsewhere

A Joint Advisory warns of Beijing's "BlackTech" threat activity. ShadowSyndicate is a new ransomware as a service operation. A Smishing Triad in the UAE. Openfire flaw actively exploited against servers. AtlasCross is technically capable and, above all, "cautious." Xenomorph malware in the wild. DDoS and API attacks hit the financial sector. In our Industry Voices segment, Joe DePlato from Bluestone Analytics demystified dark net drug markets. Our guest is Richard Hummel from Netscout with the latest trending DDoS vectors. And the FCC chair announces plans to restore net neutrality.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/185


Selected reading.

CISA, NSA, FBI and Japan Release Advisory Warning of BlackTech, PRC-Linked Cyber Activity (Cybersecurity and Infrastructure Security Agency) 

Dusting for fingerprints: ShadowSyndicate, a new RaaS player? (Group-IB)

Smishing Triad Stretches Its Tentacles into the United Arab Emirates (Security Affairs)

Hackers actively exploiting Openfire flaw to encrypt servers (BleepingComputer) 

Vulnerability in Openfire messaging software allows unauthorized access to compromised servers (Dr.Web) 

Suspicious New Ransomware Group Claims Sony Hack (Dark Reading) 

Sony investigates cyberattack as hackers fight over who's responsible (BleepingComputer) 

Sony Investigating After Hackers Offer to Sell Stolen Data (SecurityWeek) 

Xenomorph Malware Strikes Again: Over 30+ US Banks Now Targeted (Threat Fabric)

The High Stakes of Innovation: Attack Trends in Financial Services (Akamai)

FACT SHEET: FCC Chairwoman Rosenworcel Proposes to Restore Net Neutrality Rules (Federal Communications Commission) 

Ukraine: Russian hackers infiltrating software supply chains (Computing)

Russian hacking operations target Ukrainian law enforcement (CyberScoop) 

Ukraine accuses Russian spies of hacking law enforcement (Register) 

Russian hackers target Ukrainian government systems involved in war crimes investigations (Record) 

Ukraine Cyber Defenders Prepare for Winter (Bank Info Security) 

More description

A Joint Advisory warns of Beijing's "BlackTech" threat activity. ShadowSyndicate is a new ransomware as a service operation. A Smishing Triad in the UAE. Openfire flaw actively exploited against servers. AtlasCross is technically capable and, above all, "cautious." Xenomorph malware in the wild. DDoS and API attacks hit the financial sector. In our Industry Voices segment, Joe DePlato from Bluestone Analytics demystified dark net drug markets. Our guest is Richard Hummel from Netscout with the latest trending DDoS vectors. And the FCC chair announces plans to restore net neutrality.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/185


Selected reading.

CISA, NSA, FBI and Japan Release Advisory Warning of BlackTech, PRC-Linked Cyber Activity (Cybersecurity and Infrastructure Security Agency) 

Dusting for fingerprints: ShadowSyndicate, a new RaaS player? (Group-IB)

Smishing Triad Stretches Its Tentacles into the United Arab Emirates (Security Affairs)

Hackers actively exploiting Openfire flaw to encrypt servers (BleepingComputer) 

Vulnerability in Openfire messaging software allows unauthorized access to compromised servers (Dr.Web) 

Suspicious New Ransomware Group Claims Sony Hack (Dark Reading) 

Sony investigates cyberattack as hackers fight over who's responsible (BleepingComputer) 

Sony Investigating After Hackers Offer to Sell Stolen Data (SecurityWeek) 

Xenomorph Malware Strikes Again: Over 30+ US Banks Now Targeted (Threat Fabric)

The High Stakes of Innovation: Attack Trends in Financial Services (Akamai)

FACT SHEET: FCC Chairwoman Rosenworcel Proposes to Restore Net Neutrality Rules (Federal Communications Commission) 

Ukraine: Russian hackers infiltrating software supply chains (Computing)

Russian hacking operations target Ukrainian law enforcement (CyberScoop) 

Ukraine accuses Russian spies of hacking law enforcement (Register) 

Russian hackers target Ukrainian government systems involved in war crimes investigations (Record) 

Ukraine Cyber Defenders Prepare for Winter (Bank Info Security) 

Extract Knowledge
Listen elsewhere

An advanced phishing campaign hits hospitality industry. An information-stealing campaign deploys ZenRAT. More MOVEit-related data breaches are disclosed. Mixin Network suspends deposits and withdrawals. The OpenSea NFT market warns of third-party risk to its API. Phishing for Ukrainian military drone operators. Mr. Security Answer Person John Pescatore shares thoughts in Cisco acquiring Splunk. Ann Johnson from the Afternoon Cyber Tea podcast interviews Deb Cupp sharing a lesson in leadership. And the UK adopts a hunt-forward approach to cyber war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/184


Selected reading.

Luxury Hotels Major Target of Ongoing Social Engineering Attack (Cofense) 

ZenRAT: Malware Brings More Chaos Than Calm (Proofpoint) 

More MOVEit-related data breaches are disclosed. (CyberWire)

Mixin Network suspends deposits and withdrawals. (CyberWire)

OpenSea NFT market warns of third-party risk to its API. (CyberWire)

Threat Labs Security Advisory: New STARK#VORTEX Attack Campaign: Threat Actors Use Drone Manual Lures to Deliver MerlinAgent Payloads (Securonix) 

Ukrainian Military Targeted in Phishing Campaign Leveraging Drone Manuals (The Hacker News) 

British Army general says UK now conducting ‘hunt forward’ operations (Record)

More description

An advanced phishing campaign hits hospitality industry. An information-stealing campaign deploys ZenRAT. More MOVEit-related data breaches are disclosed. Mixin Network suspends deposits and withdrawals. The OpenSea NFT market warns of third-party risk to its API. Phishing for Ukrainian military drone operators. Mr. Security Answer Person John Pescatore shares thoughts in Cisco acquiring Splunk. Ann Johnson from the Afternoon Cyber Tea podcast interviews Deb Cupp sharing a lesson in leadership. And the UK adopts a hunt-forward approach to cyber war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/184


Selected reading.

Luxury Hotels Major Target of Ongoing Social Engineering Attack (Cofense) 

ZenRAT: Malware Brings More Chaos Than Calm (Proofpoint) 

More MOVEit-related data breaches are disclosed. (CyberWire)

Mixin Network suspends deposits and withdrawals. (CyberWire)

OpenSea NFT market warns of third-party risk to its API. (CyberWire)

Threat Labs Security Advisory: New STARK#VORTEX Attack Campaign: Threat Actors Use Drone Manual Lures to Deliver MerlinAgent Payloads (Securonix) 

Ukrainian Military Targeted in Phishing Campaign Leveraging Drone Manuals (The Hacker News) 

British Army general says UK now conducting ‘hunt forward’ operations (Record)

Extract Knowledge
Listen elsewhere

The Gelsemium APT is active against a Southeast Asian government. A multi-year campaign against Tibetan, Uighur, and Taiwanese targets. Stealth Falcon's new backdoor. Predator spyware is deployed against Apple zero-days. An update on Pegasus spyware found in Meduza devices. There’s a shift in Russian cyberespionage targeting. A rumor of cyberwar in occupied Crimea. In our Industry Voices segment, Amit Sinha, CEO of Digicert, describes digital trust for the software supply chain. Our guest is Arctic Wolf’s Ian McShane with insights on the MGM and Caesars ransomware incident. And if you’re looking for a Super Bowl pick, go with an egg-laying animal…and, oh, the NFL and CISA are noodling cyber defense for the big game.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/183


Selected reading.

Rare Backdoors Suspected to be Tied to Gelsemium APT Found in Targeted Attack in Southeast Asian Government (Unit 42)

Rare Backdoors Suspected to be Tied to Gelsemium APT Found in Targeted Attack in Southeast Asian Government (IBM X-Force Exchange)

Evasive Gelsemium hackers spotted in attack against Asian govt (BleepingComputer)

Unit 42 Researchers Discover Multiple Espionage Operations Targeting Southeast Asian Government (Unit 42)

EvilBamboo Targets Mobile Devices in Multi-year Campaign (Volexity) 

From Watering Hole to Spyware: EvilBamboo Targets Tibetans, Uyghurs, and Taiwanese (The Hacker News)

Stealth Falcon preying over Middle Eastern skies with Deadglyph (We Live Security) t

Deadglyph: Covertly preying over Middle Eastern skies (LABScon) 

New stealthy and modular Deadglyph malware used in govt attacks (BleepingComputer) 

Deadglyph: New Advanced Backdoor with Distinctive Malware Tactics (The Hacker News) 

0-days exploited by commercial surveillance vendor in Egypt (Google).

PREDATOR IN THE WIRES: Ahmed Eltantawy Targeted with Predator Spyware After Announcing Presidential Ambitions (The Citizen Lab) 

New Apple Zero-Days Exploited to Target Egyptian ex-MP with Predator Spyware (The Hacker News) 

Egyptian presidential hopeful targeted by Predator spyware (Washington Post)

Russian news outlet in Latvia believes European state behind phone hack (the Guardian) 

Exclusive: Russian hackers seek war crimes evidence, Ukraine cyber chief says (Reuters).

Russian hackers trying to steal evidence of Moscow’s war crimes in Ukraine - cyber chief (Ukrinform).

Large-scale cyberattack reported in occupied Crimea (The Kyiv Independent) 

NFL, CISA Look to Intercept Cyber Threats to Super Bowl LVIII (Dark Reading) 

More description

The Gelsemium APT is active against a Southeast Asian government. A multi-year campaign against Tibetan, Uighur, and Taiwanese targets. Stealth Falcon's new backdoor. Predator spyware is deployed against Apple zero-days. An update on Pegasus spyware found in Meduza devices. There’s a shift in Russian cyberespionage targeting. A rumor of cyberwar in occupied Crimea. In our Industry Voices segment, Amit Sinha, CEO of Digicert, describes digital trust for the software supply chain. Our guest is Arctic Wolf’s Ian McShane with insights on the MGM and Caesars ransomware incident. And if you’re looking for a Super Bowl pick, go with an egg-laying animal…and, oh, the NFL and CISA are noodling cyber defense for the big game.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/183


Selected reading.

Rare Backdoors Suspected to be Tied to Gelsemium APT Found in Targeted Attack in Southeast Asian Government (Unit 42)

Rare Backdoors Suspected to be Tied to Gelsemium APT Found in Targeted Attack in Southeast Asian Government (IBM X-Force Exchange)

Evasive Gelsemium hackers spotted in attack against Asian govt (BleepingComputer)

Unit 42 Researchers Discover Multiple Espionage Operations Targeting Southeast Asian Government (Unit 42)

EvilBamboo Targets Mobile Devices in Multi-year Campaign (Volexity) 

From Watering Hole to Spyware: EvilBamboo Targets Tibetans, Uyghurs, and Taiwanese (The Hacker News)

Stealth Falcon preying over Middle Eastern skies with Deadglyph (We Live Security) t

Deadglyph: Covertly preying over Middle Eastern skies (LABScon) 

New stealthy and modular Deadglyph malware used in govt attacks (BleepingComputer) 

Deadglyph: New Advanced Backdoor with Distinctive Malware Tactics (The Hacker News) 

0-days exploited by commercial surveillance vendor in Egypt (Google).

PREDATOR IN THE WIRES: Ahmed Eltantawy Targeted with Predator Spyware After Announcing Presidential Ambitions (The Citizen Lab) 

New Apple Zero-Days Exploited to Target Egyptian ex-MP with Predator Spyware (The Hacker News) 

Egyptian presidential hopeful targeted by Predator spyware (Washington Post)

Russian news outlet in Latvia believes European state behind phone hack (the Guardian) 

Exclusive: Russian hackers seek war crimes evidence, Ukraine cyber chief says (Reuters).

Russian hackers trying to steal evidence of Moscow’s war crimes in Ukraine - cyber chief (Ukrinform).

Large-scale cyberattack reported in occupied Crimea (The Kyiv Independent) 

NFL, CISA Look to Intercept Cyber Threats to Super Bowl LVIII (Dark Reading) 

Extract Knowledge
Listen elsewhere

In this extended interview, Simone Petrella sits down with Chris Krebs of the Krebs Stamos Group at the mWise 2023 Cybersecurity Conference to discuss threat intelligence .

More description

In this extended interview, Simone Petrella sits down with Chris Krebs of the Krebs Stamos Group at the mWise 2023 Cybersecurity Conference to discuss threat intelligence .

Extract Knowledge
Listen elsewhere

This week our guest is Merritt Baer, a Field CISO from Lacework, and a cloud security unicorn, sits down to share her incredible story working through the ranks to get to where she is today. Before working at Lacework Merritt served in the Office of the CISO at Amazon Web Services, as part of a small elite team that formed a Deputy CISO. She provided technical cloud security guidance to AWS’ largest customers, like the Fortune 100, on security as a bottom line proposition. She also has experience in all three branches of government and the private sector and served as Lead Cyber Advisor to the Federal Communications Commission. Merritt shares some amazing advice for up and comers into the field, saying "my personal philosophy is that no one has to go down for you to go up. I'm always encouraging my colleagues, um, and other executives to be thinking about how we can, you know, steal, sharpen, steal, how we can be good for each other, how we can collaborate, how we can, um, create more strengths in one another." We thank Merritt for sharing her story with us.

More description

This week our guest is Merritt Baer, a Field CISO from Lacework, and a cloud security unicorn, sits down to share her incredible story working through the ranks to get to where she is today. Before working at Lacework Merritt served in the Office of the CISO at Amazon Web Services, as part of a small elite team that formed a Deputy CISO. She provided technical cloud security guidance to AWS’ largest customers, like the Fortune 100, on security as a bottom line proposition. She also has experience in all three branches of government and the private sector and served as Lead Cyber Advisor to the Federal Communications Commission. Merritt shares some amazing advice for up and comers into the field, saying "my personal philosophy is that no one has to go down for you to go up. I'm always encouraging my colleagues, um, and other executives to be thinking about how we can, you know, steal, sharpen, steal, how we can be good for each other, how we can collaborate, how we can, um, create more strengths in one another." We thank Merritt for sharing her story with us.

Extract Knowledge
Listen elsewhere

Maxim Zavodchik from Akamai joins Dave to discuss their research on "Xurum: New Magento Campaign Discovered." Akamai researchers have discovered an ongoing server-side template injection campaign that is exploiting digital commerce websites. This campaign targets Magento 2 shops, and was dubbed Xurum in reference to the domain name of the attacker’s command and control (C2) server. 

The research states "The attacker uses an advanced web shell named “wso-ng” that is activated only when the attacker sends the cookie “magemojo000” to the backdoor “GoogleShoppingAds” component."

The research can be found here:

More description

Maxim Zavodchik from Akamai joins Dave to discuss their research on "Xurum: New Magento Campaign Discovered." Akamai researchers have discovered an ongoing server-side template injection campaign that is exploiting digital commerce websites. This campaign targets Magento 2 shops, and was dubbed Xurum in reference to the domain name of the attacker’s command and control (C2) server. 

The research states "The attacker uses an advanced web shell named “wso-ng” that is activated only when the attacker sends the cookie “magemojo000” to the backdoor “GoogleShoppingAds” component."

The research can be found here:

Extract Knowledge
Listen elsewhere

A new APT is found: enter Sandman. Tracking an initial access broker called Gold Melody. Iran’s OilRig group is active against Israeli targets. Cyber ops as an instrument of soft power. Recovery and investigation in the casino ransomware attacks. In our Solutions Spotlight, Simone Petrella speaks with MK Palmore from Google Cloud about talent retention and the cybersecurity skills gap. Our guest is Kristen Marquardt of Hakluyt with advice for cyber startups. And Bermuda points to Russian threat actors.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/182


Selected reading.

Sandman APT | A Mystery Group Targeting Telcos with a LuaJIT Toolkit (SentinelOne)

GOLD MELODY: Profile of an Initial Access Broker (Secureworks)

OilRig’s Outer Space and Juicy Mix: Same ol’ rig, new drill pipes (We Live Security)

Cyber Soft Power | China's Continental Takeover (SentinelOne)

MGM Resorts computers back up after 10 days as analysts eye effects of casino cyberattacks (AP News)

MGM Restores Casino Operations 10 Days After Cyberattack (Dark Reading)

MGM Resorts computers back up after being down 10 days due to casino cyberattacks (CBS News)

MGM says its recovered from cyberattack, employees tell different story (Cybernews)

'Power, influence, notoriety': The Gen-Z hackers who struck MGM, Caesars (Reuters)

Apple emergency updates fix 3 new zero-days exploited in attacks (BleepingComputer) 

Russia linked to cyberattack on government services (Royal Gazette)

More description

A new APT is found: enter Sandman. Tracking an initial access broker called Gold Melody. Iran’s OilRig group is active against Israeli targets. Cyber ops as an instrument of soft power. Recovery and investigation in the casino ransomware attacks. In our Solutions Spotlight, Simone Petrella speaks with MK Palmore from Google Cloud about talent retention and the cybersecurity skills gap. Our guest is Kristen Marquardt of Hakluyt with advice for cyber startups. And Bermuda points to Russian threat actors.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/182


Selected reading.

Sandman APT | A Mystery Group Targeting Telcos with a LuaJIT Toolkit (SentinelOne)

GOLD MELODY: Profile of an Initial Access Broker (Secureworks)

OilRig’s Outer Space and Juicy Mix: Same ol’ rig, new drill pipes (We Live Security)

Cyber Soft Power | China's Continental Takeover (SentinelOne)

MGM Resorts computers back up after 10 days as analysts eye effects of casino cyberattacks (AP News)

MGM Restores Casino Operations 10 Days After Cyberattack (Dark Reading)

MGM Resorts computers back up after being down 10 days due to casino cyberattacks (CBS News)

MGM says its recovered from cyberattack, employees tell different story (Cybernews)

'Power, influence, notoriety': The Gen-Z hackers who struck MGM, Caesars (Reuters)

Apple emergency updates fix 3 new zero-days exploited in attacks (BleepingComputer) 

Russia linked to cyberattack on government services (Royal Gazette)

Extract Knowledge
Listen elsewhere

CISA and the FBI warn of Snatch ransomware. A look at phishing trends. Ransomware is increasingly cited in cyber insurance claims. Trends in cyber threats to academic institutions. A Russian hacktivist auxiliary disrupts Canadian border control and airport sites. The ICC remains tight-lipped concerning cyberattack. N2K’s Simone Petrella sits down with Chris Krebs at the mWise conference. In today’s Threat Vector segment, David Moulton from Unit 42 takes a peek into the modern threat landscape with Wendi Whitmore, SVP of Unit 42. And MGM Resorts says it’s well on the way to recovery.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/181


Threat Vector links.

To learn what is top of mind each month from the experts at Unit 42 sign up for their Threat Intel Bulletin


Selected reading.

#StopRansomware: Snatch Ransomware (Cybersecurity and Infrastructure Security Agency CISA)

2023 .Phishing Trends (ZeroFox)

Cyber Insurance Claims Frequency and Severity Both Increased For Businesses in 1H 2023, Coalition Report Finds (Business Wire) 

2023 Cyber Claims Report: Mid-year Update (Coalition) 

Since 2018, ransomware attacks on the education sector have cost the world economy over $53 billion in downtime alone (Comparitech)

Canada blames border checkpoint outages on cyberattack (Record)

Cyberattack hits International Criminal Court (SC Media)

International Criminal Court hacked amid Russia probe (Register)

International Criminal Court under siege in cyberattack that could constitute world’s first cyber war crime (Yahoo News)

Our hotels and casinos are operating normally. (FAQ - MGM Resorts)

MGM Resorts computers back up after 10 days as analysts eye effects of casino cyberattacks (AP News - 09-20-2023)

More description

CISA and the FBI warn of Snatch ransomware. A look at phishing trends. Ransomware is increasingly cited in cyber insurance claims. Trends in cyber threats to academic institutions. A Russian hacktivist auxiliary disrupts Canadian border control and airport sites. The ICC remains tight-lipped concerning cyberattack. N2K’s Simone Petrella sits down with Chris Krebs at the mWise conference. In today’s Threat Vector segment, David Moulton from Unit 42 takes a peek into the modern threat landscape with Wendi Whitmore, SVP of Unit 42. And MGM Resorts says it’s well on the way to recovery.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/181


Threat Vector links.

To learn what is top of mind each month from the experts at Unit 42 sign up for their Threat Intel Bulletin


Selected reading.

#StopRansomware: Snatch Ransomware (Cybersecurity and Infrastructure Security Agency CISA)

2023 .Phishing Trends (ZeroFox)

Cyber Insurance Claims Frequency and Severity Both Increased For Businesses in 1H 2023, Coalition Report Finds (Business Wire) 

2023 Cyber Claims Report: Mid-year Update (Coalition) 

Since 2018, ransomware attacks on the education sector have cost the world economy over $53 billion in downtime alone (Comparitech)

Canada blames border checkpoint outages on cyberattack (Record)

Cyberattack hits International Criminal Court (SC Media)

International Criminal Court hacked amid Russia probe (Register)

International Criminal Court under siege in cyberattack that could constitute world’s first cyber war crime (Yahoo News)

Our hotels and casinos are operating normally. (FAQ - MGM Resorts)

MGM Resorts computers back up after 10 days as analysts eye effects of casino cyberattacks (AP News - 09-20-2023)

Extract Knowledge
Listen elsewhere

The International Criminal Court reports a "cybersecurity incident." ShroudedSnooper intrusion activity is both novel and simple. Criminal malware targets Chinese-speaking victims. The costs of insider risk. More on the casino attacks (and related social engineering capers). In our Learning Layer segment, Sam Meisenberg drops into a CISSP tutoring session and offers some test-taking tips. Our guest is Aaron Brazelton, Dean of Admissions and Advancement at the Alabama School of Cyber Technology and Engineering. And the Clorox incident shows how one company navigates unfamiliar new SEC rules.

Join Sam Meisenberg as he drops into a CISSP tutoring session talking about the difference between due diligence and due care along with some test-taking tips.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/180


Learning Layer.

Learning about the CISSP certification from (ISC)²


Selected reading.

War crimes tribunal ICC says it has been hacked (Reuters)

International Criminal Court says cybersecurity incident affected its information systems last week (AP News) 

Hackers breached International Criminal Court’s systems last week (BleepingComputer)

New ShroudedSnooper actor targets telecommunications firms in the Middle East with novel Implants (Cisco Talos)

ShroudedSnooper's HTTPSnoop Backdoor Targets Middle East Telecom Companies (The Hacker News)

Chinese Malware Appears in Earnest Across Cybercrime Threat Landscape (Proofpoint) 

Hackers who breached casino giants MGM, Caesars also hit 3 other firms, Okta says (Reuters)

Las Vegas casino ransomware attacks: Okta in the spotlight (The Stack) 

MGM losing up to $8.4M per day as cyberattack paralyzes slot machines, hotels for 8th straight day: analyst (New York Post) 

Caesars reports cyberattack but did not go offline (Top Class Actions) 

What Las Vegas tourists need to know about casino hacks (Washington Post) 

MGM, Caesars Face Regulatory, Legal Maze After Cyber Incidents (Dark Reading)

Clorox Cyberattack Brings Early Test of New SEC Cyber Rules (Wall Street Journal)

More description

The International Criminal Court reports a "cybersecurity incident." ShroudedSnooper intrusion activity is both novel and simple. Criminal malware targets Chinese-speaking victims. The costs of insider risk. More on the casino attacks (and related social engineering capers). In our Learning Layer segment, Sam Meisenberg drops into a CISSP tutoring session and offers some test-taking tips. Our guest is Aaron Brazelton, Dean of Admissions and Advancement at the Alabama School of Cyber Technology and Engineering. And the Clorox incident shows how one company navigates unfamiliar new SEC rules.

Join Sam Meisenberg as he drops into a CISSP tutoring session talking about the difference between due diligence and due care along with some test-taking tips.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/180


Learning Layer.

Learning about the CISSP certification from (ISC)²


Selected reading.

War crimes tribunal ICC says it has been hacked (Reuters)

International Criminal Court says cybersecurity incident affected its information systems last week (AP News) 

Hackers breached International Criminal Court’s systems last week (BleepingComputer)

New ShroudedSnooper actor targets telecommunications firms in the Middle East with novel Implants (Cisco Talos)

ShroudedSnooper's HTTPSnoop Backdoor Targets Middle East Telecom Companies (The Hacker News)

Chinese Malware Appears in Earnest Across Cybercrime Threat Landscape (Proofpoint) 

Hackers who breached casino giants MGM, Caesars also hit 3 other firms, Okta says (Reuters)

Las Vegas casino ransomware attacks: Okta in the spotlight (The Stack) 

MGM losing up to $8.4M per day as cyberattack paralyzes slot machines, hotels for 8th straight day: analyst (New York Post) 

Caesars reports cyberattack but did not go offline (Top Class Actions) 

What Las Vegas tourists need to know about casino hacks (Washington Post) 

MGM, Caesars Face Regulatory, Legal Maze After Cyber Incidents (Dark Reading)

Clorox Cyberattack Brings Early Test of New SEC Cyber Rules (Wall Street Journal)

Extract Knowledge
Listen elsewhere

Colombia continues its recovery from last week's cyberattacks. AI training data is accidentally published to GitHub. The cyberespionage techniques of Earth Lusca. Clorox blames product shortages on a cyber attack. Cybersecurity incidents in industrial environments. Where the wild bots are. Joe Carrigan looks at top level domain name exploitation. Our guest is Kristen Bell from GuidePoint Security with a look at vulnerability vs. exploitability. And there’s talk of potential Russia-DPRK cooperation in cyberspace.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/179


Selected reading.

More than 50 Colombian state, private entities hit by cyberattack -Petro (Reuters) 

Colombia Mulls Legal Action Against US Firm Targeted In Cyber Attack (Barron's)

Microsoft mitigated exposure of internal information in a storage account due to overly-permissive SAS token (Microsoft Security Response Center)

Microsoft AI Researchers Expose 38TB of Data, Including Keys, Passwords and Internal Messages (SecurityWeek)

Earth Lusca Employs New Linux Backdoor, Uses Cobalt Strike for Lateral Movement (Trend Micro) 

Chinese hackers have unleashed a never-before-seen Linux backdoor (Ars Technica)

The Clorox Company FORM 8-K (US Securities and Exchange Commission) 

Clorox Warns of Product Shortages Following Cyberattack (Wall Street Journal)

Clorox warns of product shortages, profit hit from August cyberattack (The Street) 

Can't find the right Clorox product? A recent cyberattack is causing some shortages (USA Today) 

Clorox warns of product shortages after cyberattack (Fox Business) 

As flu season looms, hackers force a shortage of Clorox products (Fortune)

New Research Finds Cyberattacks Against Critical Infrastructure on the Rise, State-affiliated Groups Responsible for Nearly 60% (Business Wire)

Death By a Billion Bots (Netacea)

Russian and North Korea artillery deal paves the way for dangerous cyberwar alliance (EconoTimes) 

More description

Colombia continues its recovery from last week's cyberattacks. AI training data is accidentally published to GitHub. The cyberespionage techniques of Earth Lusca. Clorox blames product shortages on a cyber attack. Cybersecurity incidents in industrial environments. Where the wild bots are. Joe Carrigan looks at top level domain name exploitation. Our guest is Kristen Bell from GuidePoint Security with a look at vulnerability vs. exploitability. And there’s talk of potential Russia-DPRK cooperation in cyberspace.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/179


Selected reading.

More than 50 Colombian state, private entities hit by cyberattack -Petro (Reuters) 

Colombia Mulls Legal Action Against US Firm Targeted In Cyber Attack (Barron's)

Microsoft mitigated exposure of internal information in a storage account due to overly-permissive SAS token (Microsoft Security Response Center)

Microsoft AI Researchers Expose 38TB of Data, Including Keys, Passwords and Internal Messages (SecurityWeek)

Earth Lusca Employs New Linux Backdoor, Uses Cobalt Strike for Lateral Movement (Trend Micro) 

Chinese hackers have unleashed a never-before-seen Linux backdoor (Ars Technica)

The Clorox Company FORM 8-K (US Securities and Exchange Commission) 

Clorox Warns of Product Shortages Following Cyberattack (Wall Street Journal)

Clorox warns of product shortages, profit hit from August cyberattack (The Street) 

Can't find the right Clorox product? A recent cyberattack is causing some shortages (USA Today) 

Clorox warns of product shortages after cyberattack (Fox Business) 

As flu season looms, hackers force a shortage of Clorox products (Fortune)

New Research Finds Cyberattacks Against Critical Infrastructure on the Rise, State-affiliated Groups Responsible for Nearly 60% (Business Wire)

Death By a Billion Bots (Netacea)

Russian and North Korea artillery deal paves the way for dangerous cyberwar alliance (EconoTimes) 

Extract Knowledge
Listen elsewhere

Cyber threats trending from East Asia. The Lazarus Group is suspected in the CoinEx crypto theft. Pig butchering, enabled by cryptocurrency. BlackCat is active against Azure storage. a Ukrainian view of cyber warfare. A US-Canadian water commission deals with a ransomware attack. Eric Goldstein from CISA shares insights on cyber threats from China. Neil Serebryany of Calypso explains the policies, tools and safeguards in place to enable the safe use of generative AI. And more details emerge in the Las Vegas casinos’ ransomware incidents. Danny Ocean, call your office.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/178


Selected reading.

Sophistication, scope, and scale: Digital threats from East Asia increase in breadth and effectiveness (Microsoft Security Compliance and Identity)

Evidence points to North Korea in CoinEx cryptocurrency hack, analysts say (Record) 

CoinEx invites hackers to negotiate after suffering data breach (The Times of India

BlackCat ransomware hits Azure Storage with Sphynx encryptor (BleepingComputer)

MGM websites up, but reservation systems still affected by hack (Las Vegas Review-Journal)

The chaotic and cinematic MGM casino hack, explained (Vox)

Massive MGM and Caesars Hacks Epitomize a Vicious Ransomware Cycle (WIRED)

US-Canada water commission confirms 'cybersecurity incident' (Register) 

Ukraine's Fusion of Cyber and Kinetic Warfare: Illia Vitiuk's Stand Against Russian Cyber Operations (AFCEA International)

More description

Cyber threats trending from East Asia. The Lazarus Group is suspected in the CoinEx crypto theft. Pig butchering, enabled by cryptocurrency. BlackCat is active against Azure storage. a Ukrainian view of cyber warfare. A US-Canadian water commission deals with a ransomware attack. Eric Goldstein from CISA shares insights on cyber threats from China. Neil Serebryany of Calypso explains the policies, tools and safeguards in place to enable the safe use of generative AI. And more details emerge in the Las Vegas casinos’ ransomware incidents. Danny Ocean, call your office.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/178


Selected reading.

Sophistication, scope, and scale: Digital threats from East Asia increase in breadth and effectiveness (Microsoft Security Compliance and Identity)

Evidence points to North Korea in CoinEx cryptocurrency hack, analysts say (Record) 

CoinEx invites hackers to negotiate after suffering data breach (The Times of India

BlackCat ransomware hits Azure Storage with Sphynx encryptor (BleepingComputer)

MGM websites up, but reservation systems still affected by hack (Las Vegas Review-Journal)

The chaotic and cinematic MGM casino hack, explained (Vox)

Massive MGM and Caesars Hacks Epitomize a Vicious Ransomware Cycle (WIRED)

US-Canada water commission confirms 'cybersecurity incident' (Register) 

Ukraine's Fusion of Cyber and Kinetic Warfare: Illia Vitiuk's Stand Against Russian Cyber Operations (AFCEA International)

Extract Knowledge
Listen elsewhere

Karl Mattson, CISO at Noname Security, joins us to share his story. Having started out as a "military brat," traveling the world as the child of a Marine, Karl later joined the Army not long after high school. In the Army, Karl was assigned the career field of intelligence analyst and started working with the NSA. He says that was a real career break. Following the Army, Karl worked in the financial services world as a CISO. At Noname, Karl began by building out internal risk and IT functions into a strong, what he calls spectacular team. Karl recommends "deferring gratification as long as possible" when building your career. He says, "People early in their career, looking at government service, those positions don't, you know, make anybody rich overnight, but they are amazing career cornerstones to build on." He closes sharing the importance of relationships. We thank Karl for sharing his story with us.

More description

Karl Mattson, CISO at Noname Security, joins us to share his story. Having started out as a "military brat," traveling the world as the child of a Marine, Karl later joined the Army not long after high school. In the Army, Karl was assigned the career field of intelligence analyst and started working with the NSA. He says that was a real career break. Following the Army, Karl worked in the financial services world as a CISO. At Noname, Karl began by building out internal risk and IT functions into a strong, what he calls spectacular team. Karl recommends "deferring gratification as long as possible" when building your career. He says, "People early in their career, looking at government service, those positions don't, you know, make anybody rich overnight, but they are amazing career cornerstones to build on." He closes sharing the importance of relationships. We thank Karl for sharing his story with us.

Extract Knowledge
Listen elsewhere

Guest Manuel Hepfer from ISTARI shares his research on cyber resilience which includes discussions with 37 CEOs to gain insight into how they manage cybersecurity risk. ISTARI and Oxford University's Saïd Business School dive into the minds and experiences of CEOs on how they manage cybersecurity risk.

Ask any CEO to name the issues that keep them awake at night and cybersecurity risk is likely near the top of the list – with good reason. With the accelerating digitalisation of business models comes vulnerability to cyberattack. And while spending on cybersecurity increases every year, so does the number of serious incidents. Even the largest and most technologically advanced companies are not immune.

CEOs must formally answer to regulators, shareholders and board members for their organisation’s cybersecurity. Yet the majority (72%) of CEOs we interviewed as part of our research said they were not comfortable making cybersecurity-related decisions.

The research and associated article can be found here:

More description

Guest Manuel Hepfer from ISTARI shares his research on cyber resilience which includes discussions with 37 CEOs to gain insight into how they manage cybersecurity risk. ISTARI and Oxford University's Saïd Business School dive into the minds and experiences of CEOs on how they manage cybersecurity risk.

Ask any CEO to name the issues that keep them awake at night and cybersecurity risk is likely near the top of the list – with good reason. With the accelerating digitalisation of business models comes vulnerability to cyberattack. And while spending on cybersecurity increases every year, so does the number of serious incidents. Even the largest and most technologically advanced companies are not immune.

CEOs must formally answer to regulators, shareholders and board members for their organisation’s cybersecurity. Yet the majority (72%) of CEOs we interviewed as part of our research said they were not comfortable making cybersecurity-related decisions.

The research and associated article can be found here:

Extract Knowledge
Listen elsewhere

"Peach Sandstorm" is an Iranian cyberespionage campaign. A Cyberattack against a telecom provider affects government and corporate online operations in Colombia. Python NodeStealer takes browser credentials. Caesars Entertainment files its 8-K. Some MGM Entertainment systems remain down. Betsy Carmelite from Booz Allen talking about how to leverage cyber psychology. Ron Reiter of Sentra outlines the threats for connected cars. And a third-party incident exposes personal data of the Manchester police.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/177


Selected reading.

Peach Sandstorm password spray campaigns enable intelligence collection at high-value targets (Microsoft)

Hackers Backed by Iran Caught in Apparent Global Spy Campaign (The Messenger)

BNamericas - Colombia cyberattack hits government, corpor... (BNamericas.com)

Colombia's judicial branch thrown offline in major cyber attack (Colombia Reports) 

Casino giant Caesars Entertainment reports cyberattack; MGM Resorts says some systems still down (AP News)

Casino Operators Caesars and MGM Still Reeling From Cyber Attacks (Kiplinger.com) 

Groups linked to Las Vegas cyber attacks are prolific criminal hacking gangs (CyberScoop) 

MGM still responding to wide-ranging cyberattack as rumors run rampant (Record)

Ransomware in the casinos. (CyberWire)

MGM Resorts shuts down some systems. (CyberWire)

Manchester police officers’ data stolen following ransomware attack on supplier (Record)

Contractor Data Breach Impacts 8k Greater Manchester Police Officers (Hackread) 

A Second Major British Police Force Suffers a Cyberattack in Less Than a Month (SecurityWeek) 

Who is behind the latest wave of UK ransomware attacks? (the Guardian) 

More description

"Peach Sandstorm" is an Iranian cyberespionage campaign. A Cyberattack against a telecom provider affects government and corporate online operations in Colombia. Python NodeStealer takes browser credentials. Caesars Entertainment files its 8-K. Some MGM Entertainment systems remain down. Betsy Carmelite from Booz Allen talking about how to leverage cyber psychology. Ron Reiter of Sentra outlines the threats for connected cars. And a third-party incident exposes personal data of the Manchester police.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/177


Selected reading.

Peach Sandstorm password spray campaigns enable intelligence collection at high-value targets (Microsoft)

Hackers Backed by Iran Caught in Apparent Global Spy Campaign (The Messenger)

BNamericas - Colombia cyberattack hits government, corpor... (BNamericas.com)

Colombia's judicial branch thrown offline in major cyber attack (Colombia Reports) 

Casino giant Caesars Entertainment reports cyberattack; MGM Resorts says some systems still down (AP News)

Casino Operators Caesars and MGM Still Reeling From Cyber Attacks (Kiplinger.com) 

Groups linked to Las Vegas cyber attacks are prolific criminal hacking gangs (CyberScoop) 

MGM still responding to wide-ranging cyberattack as rumors run rampant (Record)

Ransomware in the casinos. (CyberWire)

MGM Resorts shuts down some systems. (CyberWire)

Manchester police officers’ data stolen following ransomware attack on supplier (Record)

Contractor Data Breach Impacts 8k Greater Manchester Police Officers (Hackread) 

A Second Major British Police Force Suffers a Cyberattack in Less Than a Month (SecurityWeek) 

Who is behind the latest wave of UK ransomware attacks? (the Guardian) 

Extract Knowledge
Listen elsewhere

The MGM Resorts incident is now believed to be ransomware, and how does that inform our view of Materiality of a cyber incident? MetaStealer targets businesses. Cloud access with stolen credentials. The cloud as an expansive attack surface. Johannes Ullrich from SANS describes malware in dot-inf files. In our Industry Voices segment Dave speaks with Oliver Tavakoli, CTO at Vectra, on the complexity and challenges of cloud service security. And welcome back, or not, Your Highness the Large Language Model, Prince of Nigeria.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/176


Selected reading.

Caesars Entertainment Paid Millions to Hackers in Attack (Bloomberg) 

Caesars Paid Ransom After Suffering Cyberattack (Wall Street Journal) 

The Cyberattack That Sent Las Vegas Back in Time (Wall Street Journal) 

Pro Take: MGM Casino Hack Shows Challenge in Defending Connected Tech (Wall Street Journal) 

ALPHV Ransomware Used Vishing to Scam MGM Resorts Employee, Researchers (Hackread)

FBI probing MGM Resorts cyber incident as some casino systems still down (Reuters) 

MGM Resorts says cyberattack could have material effect on company (NBC News) 

MGM Resorts cybersecurity breach could cost millions, expert says (KLAS) 

MGM Resorts shuts down some systems because of a “cybersecurity issue.” (Updated.) (CyberWire)

macOS Info-Stealer Malware 'MetaStealer' Targeting Businesses (SecurityWeek) 

“Authorized” to break in: Adversaries use valid credentials to compromise cloud environments (Security Intelligence) 

Unit 42 Attack Surface Threat Report (Palo Alto Networks)

The Nigerian Prince is Alive and Well: Cybercriminals Use Generative… (Abnormal) 

More description

The MGM Resorts incident is now believed to be ransomware, and how does that inform our view of Materiality of a cyber incident? MetaStealer targets businesses. Cloud access with stolen credentials. The cloud as an expansive attack surface. Johannes Ullrich from SANS describes malware in dot-inf files. In our Industry Voices segment Dave speaks with Oliver Tavakoli, CTO at Vectra, on the complexity and challenges of cloud service security. And welcome back, or not, Your Highness the Large Language Model, Prince of Nigeria.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/176


Selected reading.

Caesars Entertainment Paid Millions to Hackers in Attack (Bloomberg) 

Caesars Paid Ransom After Suffering Cyberattack (Wall Street Journal) 

The Cyberattack That Sent Las Vegas Back in Time (Wall Street Journal) 

Pro Take: MGM Casino Hack Shows Challenge in Defending Connected Tech (Wall Street Journal) 

ALPHV Ransomware Used Vishing to Scam MGM Resorts Employee, Researchers (Hackread)

FBI probing MGM Resorts cyber incident as some casino systems still down (Reuters) 

MGM Resorts says cyberattack could have material effect on company (NBC News) 

MGM Resorts cybersecurity breach could cost millions, expert says (KLAS) 

MGM Resorts shuts down some systems because of a “cybersecurity issue.” (Updated.) (CyberWire)

macOS Info-Stealer Malware 'MetaStealer' Targeting Businesses (SecurityWeek) 

“Authorized” to break in: Adversaries use valid credentials to compromise cloud environments (Security Intelligence) 

Unit 42 Attack Surface Threat Report (Palo Alto Networks)

The Nigerian Prince is Alive and Well: Cybercriminals Use Generative… (Abnormal) 

Extract Knowledge
Listen elsewhere

An access broker's phishing facilitates ransomware. 3AM is fallback malware. Cross-site-scripting vulnerabilities are reported in Apache services. US agencies warn organizations to be alert for deepfakes. The US Department of Defense publishes its 2023 Cyber Strategy. Ann Johnson from the Afternoon Cyber Tea podcast speaks with with Jenny Radcliffe about the rise in social engineering. Deepen Desai from Zscaler shares a technical analysis of Bandit Stealer. And a quick reminder: yesterday was Patch Tuesday.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/175


Selected reading.

Malware distributor Storm-0324 facilitates ransomware access (Microsoft Security) 

3AM: New Ransomware Family Used As Fallback in Failed LockBit Attack (Symantec)

Azure HDInsight Riddled With XSS Vulnerabilities via Apache Services (Orca Security)

Contextualizing Deepfake Threats to Organizations (US Department of Defense) 

Bipartisan push to ban deceptive AI-generated ads in US elections (Reuters)

DOD Releases 2023 Cyber Strategy Summary (U.S. Department of Defense)

New Pentagon cyber strategy: Building new capabilities, expanding allied info-sharing (Breaking Defense)

New DOD cyber strategy notes limits of digital deterrence (DefenseScoop)

New Pentagon cyber strategy: Building new capabilities, expanding allied info-sharing (Breaking Defense)

CISA Releases Three Industrial Control Systems Advisories (Cybersecurity and Infrastructure Security Agency CISA) 

September 2023 Security Updates (Microsoft Security Response Center) 

Microsoft Releases September 2023 Updates (Cybersecurity and Infrastructure Security Agency CISA) 

Zero Day Summer: Microsoft Warns of Fresh New Software Exploits (SecurityWeek)

Microsoft Patch Tuesday: Two zero-days addressed in September update (Computing) 

Adobe Releases Security Updates for Multiple Products (Cybersecurity and Infrastructure Security Agency CISA)

Microsoft, Adobe fix zero-days exploited by attackers (CVE-2023-26369, CVE-2023-36761, CVE-2023-36802) (Help Net Security) 

Adobe fixed actively exploited zero-day in Acrobat and Reader (Security Affairs) 

Adobe warns of critical Acrobat and Reader zero-day exploited in attacks (BleepingComputer) 

Apple Releases Security Updates for iOS and macOS (Cybersecurity and Infrastructure Security Agency CISA) 

SAP Security Patch Day for September 2023 (Onapsis) 

Google Rushes to Patch Critical Chrome Vulnerability Exploited in the Wild - Update Now (The Hacker News) 

Critical Google Chrome Zero-Day Bug Exploited in the Wild (Dark Reading)

Zero-day affecting Chrome, Firefox and Thunderbird patched (Computer) 

More description

An access broker's phishing facilitates ransomware. 3AM is fallback malware. Cross-site-scripting vulnerabilities are reported in Apache services. US agencies warn organizations to be alert for deepfakes. The US Department of Defense publishes its 2023 Cyber Strategy. Ann Johnson from the Afternoon Cyber Tea podcast speaks with with Jenny Radcliffe about the rise in social engineering. Deepen Desai from Zscaler shares a technical analysis of Bandit Stealer. And a quick reminder: yesterday was Patch Tuesday.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/175


Selected reading.

Malware distributor Storm-0324 facilitates ransomware access (Microsoft Security) 

3AM: New Ransomware Family Used As Fallback in Failed LockBit Attack (Symantec)

Azure HDInsight Riddled With XSS Vulnerabilities via Apache Services (Orca Security)

Contextualizing Deepfake Threats to Organizations (US Department of Defense) 

Bipartisan push to ban deceptive AI-generated ads in US elections (Reuters)

DOD Releases 2023 Cyber Strategy Summary (U.S. Department of Defense)

New Pentagon cyber strategy: Building new capabilities, expanding allied info-sharing (Breaking Defense)

New DOD cyber strategy notes limits of digital deterrence (DefenseScoop)

New Pentagon cyber strategy: Building new capabilities, expanding allied info-sharing (Breaking Defense)

CISA Releases Three Industrial Control Systems Advisories (Cybersecurity and Infrastructure Security Agency CISA) 

September 2023 Security Updates (Microsoft Security Response Center) 

Microsoft Releases September 2023 Updates (Cybersecurity and Infrastructure Security Agency CISA) 

Zero Day Summer: Microsoft Warns of Fresh New Software Exploits (SecurityWeek)

Microsoft Patch Tuesday: Two zero-days addressed in September update (Computing) 

Adobe Releases Security Updates for Multiple Products (Cybersecurity and Infrastructure Security Agency CISA)

Microsoft, Adobe fix zero-days exploited by attackers (CVE-2023-26369, CVE-2023-36761, CVE-2023-36802) (Help Net Security) 

Adobe fixed actively exploited zero-day in Acrobat and Reader (Security Affairs) 

Adobe warns of critical Acrobat and Reader zero-day exploited in attacks (BleepingComputer) 

Apple Releases Security Updates for iOS and macOS (Cybersecurity and Infrastructure Security Agency CISA) 

SAP Security Patch Day for September 2023 (Onapsis) 

Google Rushes to Patch Critical Chrome Vulnerability Exploited in the Wild - Update Now (The Hacker News) 

Critical Google Chrome Zero-Day Bug Exploited in the Wild (Dark Reading)

Zero-day affecting Chrome, Firefox and Thunderbird patched (Computer) 

Extract Knowledge
Listen elsewhere

Phishing with Facebook Messenger accounts. Redfly cyberespionage targets a national grid. The exploit trade in the C2C underground market. Phishing attack exploits Baidu link. A repojacking vulnerability. A hacktivist auxiliary looks to its own interests. Ben Yelin marks the start of the Google antitrust trial. In our Industry Voices segment, Adam Bateman from Push Security explains how identities are the new perimeter. And MGM Resorts are dealing with a “cybersecurity issue.”


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/174


Selected reading.

Sponsor with batch-filed whiskers: Ballistic Bobcat’s scan and strike backdoor (ESET) 

Charming Kitten's New Backdoor 'Sponsor' Targets Brazil, Israel, and U.A.E. (The Hacker News) 

Iran's Charming Kitten Pounces on Israeli Exchange Servers (Dark Reading) 

Iranian hackers break into networks of more than 30 companies in Israel (ynetnews) 

“MrTonyScam” — Botnet of Facebook Users Launch High-Intent Messenger Phishing Attack on Business Accounts (Guardio Labs, via Medium)

Facebook Messenger phishing wave targets 100K business accounts per week (BleepingComputer) 

Vietnamese Hackers Deploy Python-Based Stealer via Facebook Messenger (The Hacker News) 

Redfly: Espionage Actors Continue to Target Critical Infrastructure (Symantec)

Sales and Purchases of Vulnerability Exploits (Flashpoint)

Phishing Attack Abuses Baidu Link Redirect, Cloudflare, and Microsoft (Vade)

New Exploit Puts Thousands of GitHub Repositories and Millions of Users at Risk (Checkmarx.com)

After Microsoft and X, Hackers Launch DDoS Attack on Telegram (SecurityWeek)

MGM Resorts shuts down some computer systems after cyber attack (Reuters) 

Cybersecurity issue prompts computer shutdowns at MGM Resorts properties across US (AP News) 

MGM Resorts shuts down IT systems after cyberattack (BleepingComputer)

MGM Resorts experiences 'cybersecurity issue' impacting operations and prompting investigation (Fox Business) 

MGM resorts says 'cybersecurity issue' may have widespread impact (NBC News) 

MGM Resorts blames 'cybersecurity issue' for ongoing outage (TechCrunch) 

FBI assisting in MGM cybersecurity investigation as slot machines, website, and emails rem (KSNV) 

MGM Resorts Says It Shut Down Some Systems Following Hack (Bloomberg) 

More description

Phishing with Facebook Messenger accounts. Redfly cyberespionage targets a national grid. The exploit trade in the C2C underground market. Phishing attack exploits Baidu link. A repojacking vulnerability. A hacktivist auxiliary looks to its own interests. Ben Yelin marks the start of the Google antitrust trial. In our Industry Voices segment, Adam Bateman from Push Security explains how identities are the new perimeter. And MGM Resorts are dealing with a “cybersecurity issue.”


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/174


Selected reading.

Sponsor with batch-filed whiskers: Ballistic Bobcat’s scan and strike backdoor (ESET) 

Charming Kitten's New Backdoor 'Sponsor' Targets Brazil, Israel, and U.A.E. (The Hacker News) 

Iran's Charming Kitten Pounces on Israeli Exchange Servers (Dark Reading) 

Iranian hackers break into networks of more than 30 companies in Israel (ynetnews) 

“MrTonyScam” — Botnet of Facebook Users Launch High-Intent Messenger Phishing Attack on Business Accounts (Guardio Labs, via Medium)

Facebook Messenger phishing wave targets 100K business accounts per week (BleepingComputer) 

Vietnamese Hackers Deploy Python-Based Stealer via Facebook Messenger (The Hacker News) 

Redfly: Espionage Actors Continue to Target Critical Infrastructure (Symantec)

Sales and Purchases of Vulnerability Exploits (Flashpoint)

Phishing Attack Abuses Baidu Link Redirect, Cloudflare, and Microsoft (Vade)

New Exploit Puts Thousands of GitHub Repositories and Millions of Users at Risk (Checkmarx.com)

After Microsoft and X, Hackers Launch DDoS Attack on Telegram (SecurityWeek)

MGM Resorts shuts down some computer systems after cyber attack (Reuters) 

Cybersecurity issue prompts computer shutdowns at MGM Resorts properties across US (AP News) 

MGM Resorts shuts down IT systems after cyberattack (BleepingComputer)

MGM Resorts experiences 'cybersecurity issue' impacting operations and prompting investigation (Fox Business) 

MGM resorts says 'cybersecurity issue' may have widespread impact (NBC News) 

MGM Resorts blames 'cybersecurity issue' for ongoing outage (TechCrunch) 

FBI assisting in MGM cybersecurity investigation as slot machines, website, and emails rem (KSNV) 

MGM Resorts Says It Shut Down Some Systems Following Hack (Bloomberg) 

Extract Knowledge
Listen elsewhere

UK's NCA and NCSC release a study of the cybercriminal underworld. HijackLoader's growing share of the C2C market. Russia's hacker diaspora in Turkey. Author David Hunt discusses his new book, “Irreducibly Complex Systems: An Introduction to Continuous Security Testing.” In our Industry Voices segment, Mike Anderson from Netskope outlines the challenges of managing Generative AI tools. And a senior Russian cyber diplomat warns against US escalation in cyberspace.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/173


Selected reading.

Ransomware, extortion and the cyber crime ecosystem (NCSC)

HijackLoader (Zscaler)

New HijackLoader malware is rapidly growing in popularity (Security Affairs)

New HijackLoader Modular Malware Loader Making Waves in the Cybercrime World (Hacker News)

Spyware Telegram mod distributed via Google Play (Secure List)

Millions Infected by Spyware Hidden in Fake Telegram Apps on Google Play (The Hacker News)

'Evil Telegram' Android apps on Google Play infected 60K with spyware (BleepingComputer)

Influx of Russian fraudsters gives Turkish cyber crime hub new lease of life (Financial Times)

Russia warns "all-out war" with US could erupt over worsening cyber clashes (Newsweek)

New strategy for global cybersecurity cooperation coming soon: State cyber ambassador (Breaking Defense) 

More description

UK's NCA and NCSC release a study of the cybercriminal underworld. HijackLoader's growing share of the C2C market. Russia's hacker diaspora in Turkey. Author David Hunt discusses his new book, “Irreducibly Complex Systems: An Introduction to Continuous Security Testing.” In our Industry Voices segment, Mike Anderson from Netskope outlines the challenges of managing Generative AI tools. And a senior Russian cyber diplomat warns against US escalation in cyberspace.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/173


Selected reading.

Ransomware, extortion and the cyber crime ecosystem (NCSC)

HijackLoader (Zscaler)

New HijackLoader malware is rapidly growing in popularity (Security Affairs)

New HijackLoader Modular Malware Loader Making Waves in the Cybercrime World (Hacker News)

Spyware Telegram mod distributed via Google Play (Secure List)

Millions Infected by Spyware Hidden in Fake Telegram Apps on Google Play (The Hacker News)

'Evil Telegram' Android apps on Google Play infected 60K with spyware (BleepingComputer)

Influx of Russian fraudsters gives Turkish cyber crime hub new lease of life (Financial Times)

Russia warns "all-out war" with US could erupt over worsening cyber clashes (Newsweek)

New strategy for global cybersecurity cooperation coming soon: State cyber ambassador (Breaking Defense) 

Extract Knowledge
Listen elsewhere

Caroline Wong, Chief Strategy Officer from Cobalt sits down to share her story of her 15+ years in cybersecurity leadership, including practitioner, product, and consulting roles. As well as being a member of our very own Hash Table, Caroline also authored the popular textbook, Security Metrics: A Beginner's Guide and teachers cybersecurity courses on LinkedIn Learning as well as hosts the Humans of InfoSec podcast. Caroline's father pushed her to start her career in engineering, she went to UC Berkeley and got accepted into their Electrical Engineering and Computer Sciences program. As a college student, she was looking for an internship and found eBay, where she says she worked an entry level position available on the information security team, and says the rest is history. She shares that she loves to teach her peers, and how she would like to be remembered for being a good teacher, saying "I think that my favorite part of the work that I get to do is teaching. Um, and in particular, um, being able to communicate about cybersecurity concepts to a wide audience. I have such tremendous gratitude." We thank Caroline for sharing her story with us.

More description

Caroline Wong, Chief Strategy Officer from Cobalt sits down to share her story of her 15+ years in cybersecurity leadership, including practitioner, product, and consulting roles. As well as being a member of our very own Hash Table, Caroline also authored the popular textbook, Security Metrics: A Beginner's Guide and teachers cybersecurity courses on LinkedIn Learning as well as hosts the Humans of InfoSec podcast. Caroline's father pushed her to start her career in engineering, she went to UC Berkeley and got accepted into their Electrical Engineering and Computer Sciences program. As a college student, she was looking for an internship and found eBay, where she says she worked an entry level position available on the information security team, and says the rest is history. She shares that she loves to teach her peers, and how she would like to be remembered for being a good teacher, saying "I think that my favorite part of the work that I get to do is teaching. Um, and in particular, um, being able to communicate about cybersecurity concepts to a wide audience. I have such tremendous gratitude." We thank Caroline for sharing her story with us.

Extract Knowledge
Listen elsewhere

This week, our guest is Reece Baldwin from Kasada discussing their work on "No Honour Amongst Thieves: Unpacking a New OpenBullet Malware Campaign." The Kasada Threat Intelligence team has recently identified a malware campaign targeting users of OpenBullet, a tool popular within criminal communities to conduct credential stuffing attacks.

This malware campaign was first uncovered when the team was digging around in a Telegram channel setup to share OpenBullet configurations. Reading through a few of the configurations they identified a function, ostensibly designed to bypass Google’s reCAPTCHA anti-bot solution. Th research states "While the versatility of OpenBullet’s configuration files enable complex attacks, they can also make it difficult for inexperienced attackers to fully understand what requests are being created and what data is being retrieved."

The research can be found here:

More description

This week, our guest is Reece Baldwin from Kasada discussing their work on "No Honour Amongst Thieves: Unpacking a New OpenBullet Malware Campaign." The Kasada Threat Intelligence team has recently identified a malware campaign targeting users of OpenBullet, a tool popular within criminal communities to conduct credential stuffing attacks.

This malware campaign was first uncovered when the team was digging around in a Telegram channel setup to share OpenBullet configurations. Reading through a few of the configurations they identified a function, ostensibly designed to bypass Google’s reCAPTCHA anti-bot solution. Th research states "While the versatility of OpenBullet’s configuration files enable complex attacks, they can also make it difficult for inexperienced attackers to fully understand what requests are being created and what data is being retrieved."

The research can be found here:

Extract Knowledge
Listen elsewhere

Apple issues emergency patches. "Multiple nation-state actors" target the aerospace sector. The DPRK targets security researchers. SpaceX interrupted service to block a Ukrainian attack against Russian naval units last year. The International Criminal Court will prosecute cyber war crimes. Operation KleptoCapture extends to professional service providers. Malek Ben Salem of Accenture ponders the long-term reliability of LLM-powered applications. Our guest is Elliott Champion from CSC on how cybercriminals are taking advantage of the Threads platform. And congratulations to the SINET 16.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/172


Selected reading.

BLASTPASS: NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild (The Citizen Lab) 

Apple issues software updates after spyware discoveries (Washington Post)

Apple patches two zero-days under attack (CVE-2023-41064, CVE-2023-41061) (Help Net Security)

CISA, FBI, and CNMF Release Advisory on Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475 | CISA (Cybersecurity and Infrastructure Security Agency CISA)

Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475 (Cybersecurity and Infrastructure Security Agency CISA) 

AA23-250A: Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475 (Tenable®) 

CISA Warning: Nation-State Hackers Exploit Fortinet and Zoho Vulnerabilities (The Hacker News)

Active North Korean campaign targeting security researchers (Google)

Rigged Software and Zero-Days: North Korean APT Caught Hacking Security Researchers (SecurityWeek)

Musk 'switched off Starlink in Ukraine over nuclear fears' (Computing)

CNN Exclusive: 'How am I in this war?': New Musk biography offers fresh details about the billionaire's Ukraine dilemma | CNN Politics (CNN) 

Ukraine, US Intelligence Suggest Russia Cyber Efforts Evolving, Growing (Voice of America)

The International Criminal Court Will Now Prosecute Cyberwar Crimes (WIRED)

Technology Will Not Exceed Our Humanity (Digital Front Lines) 

Justice Department’s Oligarch Hunters Widen Scope to Include Facilitators (Wall Street Journal) 

Apple issues emergency patches. APTs target aerospace sector. DPRK targets security researchers. New BEC phishing kit. Notes from the hybrid war. ICC will prosecute cyber war crimes. SINET 16 announced. (CyberWire)

More description

Apple issues emergency patches. "Multiple nation-state actors" target the aerospace sector. The DPRK targets security researchers. SpaceX interrupted service to block a Ukrainian attack against Russian naval units last year. The International Criminal Court will prosecute cyber war crimes. Operation KleptoCapture extends to professional service providers. Malek Ben Salem of Accenture ponders the long-term reliability of LLM-powered applications. Our guest is Elliott Champion from CSC on how cybercriminals are taking advantage of the Threads platform. And congratulations to the SINET 16.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/172


Selected reading.

BLASTPASS: NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild (The Citizen Lab) 

Apple issues software updates after spyware discoveries (Washington Post)

Apple patches two zero-days under attack (CVE-2023-41064, CVE-2023-41061) (Help Net Security)

CISA, FBI, and CNMF Release Advisory on Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475 | CISA (Cybersecurity and Infrastructure Security Agency CISA)

Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475 (Cybersecurity and Infrastructure Security Agency CISA) 

AA23-250A: Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475 (Tenable®) 

CISA Warning: Nation-State Hackers Exploit Fortinet and Zoho Vulnerabilities (The Hacker News)

Active North Korean campaign targeting security researchers (Google)

Rigged Software and Zero-Days: North Korean APT Caught Hacking Security Researchers (SecurityWeek)

Musk 'switched off Starlink in Ukraine over nuclear fears' (Computing)

CNN Exclusive: 'How am I in this war?': New Musk biography offers fresh details about the billionaire's Ukraine dilemma | CNN Politics (CNN) 

Ukraine, US Intelligence Suggest Russia Cyber Efforts Evolving, Growing (Voice of America)

The International Criminal Court Will Now Prosecute Cyberwar Crimes (WIRED)

Technology Will Not Exceed Our Humanity (Digital Front Lines) 

Justice Department’s Oligarch Hunters Widen Scope to Include Facilitators (Wall Street Journal) 

Apple issues emergency patches. APTs target aerospace sector. DPRK targets security researchers. New BEC phishing kit. Notes from the hybrid war. ICC will prosecute cyber war crimes. SINET 16 announced. (CyberWire)

Extract Knowledge
Listen elsewhere

Microsoft releases results of their investigation into cloud email compromise. A vulnerability affects a resort booking service. Adversary emulation for OT networks. Identity protection and identity attack surfaces. Sanctioning privateers (with a bonus on vacation ideas). Rob Boyce from Accenture Security tracks new trends in ransomware. Our Threat Vector segment features Mastering IR Sniping A Deliberate Approach to Cybersecurity Investigations with Chris Brewer. And Estonia warns of ongoing cyber threats.

On this segment of Threat Vector, Chris Brewer, a Director at Unit 42 and expert in digital forensics and incident response, joins host David Moulton discussing Mastering IR Sniping: A Deliberate Approach to Cybersecurity Investigations.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/171


Threat Vector links.

Sniper Incident Response from Cactus Con on GitHub

Sniper Incident Response presentation by Chris Brewer on YouTube


Selected reading.

Results of Major Technical Investigations for Storm-0558 Key Acquisition (Microsoft Security Response Center)

Check-Out With Extra Charges - Vulnerabilities in Hotel Booking Engine Explained (Bitdefender)

Deep Dive into Supply Chain Compromise: Hospitality's Hidden Risks (Bitdefender) 

MITRE and CISA release Caldera for OT attack emulation (Security Affairs) 

MITRE Caldera for OT now available as extension to open-source platform (Help Net Security)

Silverfort and Osterman Research Report Exposes Critical Gaps in Identity Threat Protection (Silverfort) 

United States and United Kingdom Sanction Additional Members of the Russia-Based Trickbot Cybercrime Gang (US Department of the Treasury)

Estonian PM: cyberspace is Ukraine war frontline (Euromaidan Press)

Cyberwar and Conventional Warfare in Ukraine (19FortyFive)

More description

Microsoft releases results of their investigation into cloud email compromise. A vulnerability affects a resort booking service. Adversary emulation for OT networks. Identity protection and identity attack surfaces. Sanctioning privateers (with a bonus on vacation ideas). Rob Boyce from Accenture Security tracks new trends in ransomware. Our Threat Vector segment features Mastering IR Sniping A Deliberate Approach to Cybersecurity Investigations with Chris Brewer. And Estonia warns of ongoing cyber threats.

On this segment of Threat Vector, Chris Brewer, a Director at Unit 42 and expert in digital forensics and incident response, joins host David Moulton discussing Mastering IR Sniping: A Deliberate Approach to Cybersecurity Investigations.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/171


Threat Vector links.

Sniper Incident Response from Cactus Con on GitHub

Sniper Incident Response presentation by Chris Brewer on YouTube


Selected reading.

Results of Major Technical Investigations for Storm-0558 Key Acquisition (Microsoft Security Response Center)

Check-Out With Extra Charges - Vulnerabilities in Hotel Booking Engine Explained (Bitdefender)

Deep Dive into Supply Chain Compromise: Hospitality's Hidden Risks (Bitdefender) 

MITRE and CISA release Caldera for OT attack emulation (Security Affairs) 

MITRE Caldera for OT now available as extension to open-source platform (Help Net Security)

Silverfort and Osterman Research Report Exposes Critical Gaps in Identity Threat Protection (Silverfort) 

United States and United Kingdom Sanction Additional Members of the Russia-Based Trickbot Cybercrime Gang (US Department of the Treasury)

Estonian PM: cyberspace is Ukraine war frontline (Euromaidan Press)

Cyberwar and Conventional Warfare in Ukraine (19FortyFive)

Extract Knowledge
Listen elsewhere

There’s a new Agent Tesla variant. Lost credentials and crypto wallet hacks. Tension between DevSecOps and AI. Fancy Bear makes an attempt on Ukrainian energy infrastructure. A look at NoName057(16). Tim Starks from the Washington Post's Cybersecurity 202. Simone Petrella and Helen Patton discuss People as a security first principle. And cybersecurity jobs seem to be getting tougher (say the people who are doing them).


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/170


Selected reading.

New Agent Tesla Variant Being Spread by Crafted Excel Document (Fortinet Blog) 

World's Largest Cryptocurrency Casino Stake Hacked for $41 Million (Hackread) 

Crypto casino Stake.com loses $41 million to hot wallet hackers (BleepingComputer) 

Experts Fear Crooks are Cracking Keys Stolen in LastPass Breach (KrebsOnSecurity) 

Global DevSecOps Report on AI Shows Cybersecurity and Privacy Concerns Create an Adoption Dilemma (GitLab)

APT28 cyberattack: msedge as a bootloader, TOR and mockbin.org/website.hook services as a control center (CERT-UA#7469) (CERT-UA)

Ukraine's CERT Thwarts APT28's Cyberattack on Critical Energy Infrastructure (The Hacker News)

Ukraine says an energy facility disrupted a Fancy Bear intrusion (Record)

What's in a NoName? Researchers see a lone-wolf DDoS group (Record) 

New Research from TechTarget’s Enterprise Strategy Group and the ISSA Reveals Continuous Struggles within Cybersecurity Professional Workforce - ISSA International (ISSA International) 

Life and Times 2023 Download Landing Page (ISSA International) 

E-book: The Life and Times of Cybersecurity Professionals Volume VI (ESG Global) 

Layoffs list extended by Malwarebytes, Fortinet, Veriff, SecureWorks (Cybernews) 

More description

There’s a new Agent Tesla variant. Lost credentials and crypto wallet hacks. Tension between DevSecOps and AI. Fancy Bear makes an attempt on Ukrainian energy infrastructure. A look at NoName057(16). Tim Starks from the Washington Post's Cybersecurity 202. Simone Petrella and Helen Patton discuss People as a security first principle. And cybersecurity jobs seem to be getting tougher (say the people who are doing them).


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/170


Selected reading.

New Agent Tesla Variant Being Spread by Crafted Excel Document (Fortinet Blog) 

World's Largest Cryptocurrency Casino Stake Hacked for $41 Million (Hackread) 

Crypto casino Stake.com loses $41 million to hot wallet hackers (BleepingComputer) 

Experts Fear Crooks are Cracking Keys Stolen in LastPass Breach (KrebsOnSecurity) 

Global DevSecOps Report on AI Shows Cybersecurity and Privacy Concerns Create an Adoption Dilemma (GitLab)

APT28 cyberattack: msedge as a bootloader, TOR and mockbin.org/website.hook services as a control center (CERT-UA#7469) (CERT-UA)

Ukraine's CERT Thwarts APT28's Cyberattack on Critical Energy Infrastructure (The Hacker News)

Ukraine says an energy facility disrupted a Fancy Bear intrusion (Record)

What's in a NoName? Researchers see a lone-wolf DDoS group (Record) 

New Research from TechTarget’s Enterprise Strategy Group and the ISSA Reveals Continuous Struggles within Cybersecurity Professional Workforce - ISSA International (ISSA International) 

Life and Times 2023 Download Landing Page (ISSA International) 

E-book: The Life and Times of Cybersecurity Professionals Volume VI (ESG Global) 

Layoffs list extended by Malwarebytes, Fortinet, Veriff, SecureWorks (Cybernews) 

Extract Knowledge
Listen elsewhere

A New variant of Chae$ malware is described. A "Smishing Triad" impersonates postal services. A MinIO storage exploit reported. Okta warns of attackers seeking senior admin privileges. LockBit compromises a UK security contractor. DDoS takes down a German financial regulator's site. Infamous Chisel as GRU combat support. Joe Carrigan on Meta uncovering a Chinese influence effort. Our guest is Connie Stack, CEO of Next DLP, discussing data breach notification procedure. And please -PLEASE- remember to change your default passwords.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/169


Selected reading.

Threat Profile: Chae$ 4 Malware (Morphisec)

"Smishing Triad" Targeted USPS and US Citizens for Data Theft (Resecurity) 

'Smishing Triad' Targeted USPS and US Citizens for Data Theft (Security Affairs) 

New Attack Vector In The Cloud: Attackers caught exploiting Object Storage Services (Security Joes)

Hackers exploit MinIO storage system to breach corporate networks (BleepingComputer) 

Okta Warns of Social Engineering Attacks Targeting Super Administrator Privileges (The Hacker News) 

More Okta customers trapped in Scattered Spider's web (Register) 

Cross-Tenant Impersonation: Prevention and Detection (Okta Security)

Breaking: UK MoD attacked by LockBit (Computing)

German financial agency site disrupted by DDoS attack since Friday (BleepingComputer) 

LogicMonitor customers hacked in reported ransomware attacks (BleepingComputer)

LogicMonitor customers hit by hackers, because of default passwords (TechCrunch)

More description

A New variant of Chae$ malware is described. A "Smishing Triad" impersonates postal services. A MinIO storage exploit reported. Okta warns of attackers seeking senior admin privileges. LockBit compromises a UK security contractor. DDoS takes down a German financial regulator's site. Infamous Chisel as GRU combat support. Joe Carrigan on Meta uncovering a Chinese influence effort. Our guest is Connie Stack, CEO of Next DLP, discussing data breach notification procedure. And please -PLEASE- remember to change your default passwords.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/169


Selected reading.

Threat Profile: Chae$ 4 Malware (Morphisec)

"Smishing Triad" Targeted USPS and US Citizens for Data Theft (Resecurity) 

'Smishing Triad' Targeted USPS and US Citizens for Data Theft (Security Affairs) 

New Attack Vector In The Cloud: Attackers caught exploiting Object Storage Services (Security Joes)

Hackers exploit MinIO storage system to breach corporate networks (BleepingComputer) 

Okta Warns of Social Engineering Attacks Targeting Super Administrator Privileges (The Hacker News) 

More Okta customers trapped in Scattered Spider's web (Register) 

Cross-Tenant Impersonation: Prevention and Detection (Okta Security)

Breaking: UK MoD attacked by LockBit (Computing)

German financial agency site disrupted by DDoS attack since Friday (BleepingComputer) 

LogicMonitor customers hacked in reported ransomware attacks (BleepingComputer)

LogicMonitor customers hit by hackers, because of default passwords (TechCrunch)

Extract Knowledge
Listen elsewhere

This interview from August 25th, 2023 originally aired as a shortened version on the CyberWire Daily Podcast. In this extended interview, Dave Bittner sits down with Jeff Welgan, Chief Learning Officer at N2K Networks, to expand on the NICE framework in strategic workforce intelligence.

More description

This interview from August 25th, 2023 originally aired as a shortened version on the CyberWire Daily Podcast. In this extended interview, Dave Bittner sits down with Jeff Welgan, Chief Learning Officer at N2K Networks, to expand on the NICE framework in strategic workforce intelligence.

Extract Knowledge
Listen elsewhere

This week's guest is Rick Doten, the VP of Information Security at Centene Corporation, he sits down to share his story and provide wise words of wisdom after conquering this industry for 30 years. Rick, like many others in the field started off not knowing what he wanted to do, so he tried out a few things, including doing in-user training and desktop support, eventually evolving to do systems analysis work and designing software. Rick shares that his main day to day roles are spending time helping out the corporate global CISO, CTO, and head of platform within the organization, he shares that his nickname is the neighborhood cat because he's everywhere. Rick shares advice for people getting into the industry for the first time, saying "There is a rainbow of different roles in cyber security, and I feel like I've done all of them in the last 30 years. So there are different things that, that you, the thing that like appeal to you the most because you're going to excel and want to hyper focus on the thing that you really, really are interested in and not the thing that you're not" We thank Rick for sharing his story with us.

More description

This week's guest is Rick Doten, the VP of Information Security at Centene Corporation, he sits down to share his story and provide wise words of wisdom after conquering this industry for 30 years. Rick, like many others in the field started off not knowing what he wanted to do, so he tried out a few things, including doing in-user training and desktop support, eventually evolving to do systems analysis work and designing software. Rick shares that his main day to day roles are spending time helping out the corporate global CISO, CTO, and head of platform within the organization, he shares that his nickname is the neighborhood cat because he's everywhere. Rick shares advice for people getting into the industry for the first time, saying "There is a rainbow of different roles in cyber security, and I feel like I've done all of them in the last 30 years. So there are different things that, that you, the thing that like appeal to you the most because you're going to excel and want to hyper focus on the thing that you really, really are interested in and not the thing that you're not" We thank Rick for sharing his story with us.

Extract Knowledge
Listen elsewhere

Kristopher Russo and Stephanie Regan from Palo Alto Networks Unit 42 join Dave to talk about Threat Group Assessment: Muddled Libra. With an intimate knowledge of enterprise information technology, this threat group presents a significant risk even to organizations with well-developed legacy cyber defenses.

Posing threats to organizations in the software automation, BPO, telecommunications and technology industries, Muddled Libra is a threat group that favors targeting large outsourcing firms serving high-value cryptocurrency institutions and individuals.

The research can be found here:

More description

Kristopher Russo and Stephanie Regan from Palo Alto Networks Unit 42 join Dave to talk about Threat Group Assessment: Muddled Libra. With an intimate knowledge of enterprise information technology, this threat group presents a significant risk even to organizations with well-developed legacy cyber defenses.

Posing threats to organizations in the software automation, BPO, telecommunications and technology industries, Muddled Libra is a threat group that favors targeting large outsourcing firms serving high-value cryptocurrency institutions and individuals.

The research can be found here:

Extract Knowledge
Listen elsewhere

A VMConnect supply chain attack is connected to the DPRK. Reports of an aledgedly "fully undetectable information stealer." DB#JAMMER brute forces exposed MSSQL databases. A Cyberattack on a Canadian utility. The state of DevSecOps. A look at hacktivism, today and beyond. Betsy Carmelite from Booz Allen on threat intelligence as part of a third-party risk management program. Our guest is Adam Marré from Arctic Wolf Networks, with an analysis of Chinese cyber tactics. And a free decryptor is released for Key Group ransomware.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/168


Selected reading.

VMConnect supply chain attack continues, evidence points to North Korea (ReversingLabs) 

Securonix Threat Labs Security Advisory: Threat Actors Target MSSQL Servers in DB#JAMMER to Deliver FreeWorld Ransomware (Securonix)

Montreal electricity organization latest victim in LockBit ransomware spree (Record)

LockBit ransomware gang targets electrical infrastructure organization in Montreal (teiss)

[Analyst Report] SANS 2023 DevSecOps Survey (Synopsys)

SANS 2023 DevSecOps Survey (Application Security Blog)

Government Agencies Report New Russian Malware Targets Ukrainian Military (National Security Agency/Central Security Service)

Russian military hackers take aim at Ukrainian soldiers' battle plans, US and allies say (CNN)

Ukraine: The First Cyber Lessons (AFCEA International)

The Return of Hacktivism: A Temporary Reprise or Here for Good? (ReliaQuest)

Decrypting Key Group Ransomware: Emerging Financially Motivated Cyber Crime Gang (EclecticIQ)

More description

A VMConnect supply chain attack is connected to the DPRK. Reports of an aledgedly "fully undetectable information stealer." DB#JAMMER brute forces exposed MSSQL databases. A Cyberattack on a Canadian utility. The state of DevSecOps. A look at hacktivism, today and beyond. Betsy Carmelite from Booz Allen on threat intelligence as part of a third-party risk management program. Our guest is Adam Marré from Arctic Wolf Networks, with an analysis of Chinese cyber tactics. And a free decryptor is released for Key Group ransomware.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/168


Selected reading.

VMConnect supply chain attack continues, evidence points to North Korea (ReversingLabs) 

Securonix Threat Labs Security Advisory: Threat Actors Target MSSQL Servers in DB#JAMMER to Deliver FreeWorld Ransomware (Securonix)

Montreal electricity organization latest victim in LockBit ransomware spree (Record)

LockBit ransomware gang targets electrical infrastructure organization in Montreal (teiss)

[Analyst Report] SANS 2023 DevSecOps Survey (Synopsys)

SANS 2023 DevSecOps Survey (Application Security Blog)

Government Agencies Report New Russian Malware Targets Ukrainian Military (National Security Agency/Central Security Service)

Russian military hackers take aim at Ukrainian soldiers' battle plans, US and allies say (CNN)

Ukraine: The First Cyber Lessons (AFCEA International)

The Return of Hacktivism: A Temporary Reprise or Here for Good? (ReliaQuest)

Decrypting Key Group Ransomware: Emerging Financially Motivated Cyber Crime Gang (EclecticIQ)

Extract Knowledge
Listen elsewhere

China deploys tools used against Uyghurs in broader espionage. The Five Eyes call out a GRU cyberespionage campaign. Russian hacktivist auxiliaries hit Czech banks and the platform formerly known as Twitter. A Spring-Kafka zero-day is discovered. Deepen Desai from Zscaler explains RedEnergy Stealer-as-a-Ransomware attacks. Luke Nelson of UHY Consulting on ransomware’s impact on schools. And, hey, go Wolverines: the University of Michigan overcomes a cyberattack that delayed the academic year.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/167


Selected reading.

BadBazaar espionage tool targets Android users via trojanized Signal and Telegram apps (We Live Security) 

Earth Estries Targets Government, Tech for Cyberespionage (Trend Micro) 

Infamous Chisel Malware Analysis Report (Cybersecurity and Infrastructure Security Agency CISA)

UK and allies support Ukraine calling out Russia's GRU for new malware campaign (NCSC) 

Hackers Attack Czech Banks, Demanding End of Support For Ukraine (Brno Daily) 

More Russian attacks on Czech banks: Hackers call for end of support to Ukraine (Expats.cz)

Anonymous Sudan hacks X to put pressure on Elon Musk over Starlink (BBC News) 

Contrast Assess uncovers Spring-Kafka deserialization zero day (Contrast Security)

U. Michigan restores campus internet after cyberattack disrupts first week of classes (EdScoop)

Internet restored on University of Michigan campus, ongoing issues still expected (mlive)

University of Michigan isn't disclosing details of internet outage cyberattack (Detroit Free Press)

Expert weighs in on school cyberattacks as University of Michigan makes progress on internet outages (CBS News)

More description

China deploys tools used against Uyghurs in broader espionage. The Five Eyes call out a GRU cyberespionage campaign. Russian hacktivist auxiliaries hit Czech banks and the platform formerly known as Twitter. A Spring-Kafka zero-day is discovered. Deepen Desai from Zscaler explains RedEnergy Stealer-as-a-Ransomware attacks. Luke Nelson of UHY Consulting on ransomware’s impact on schools. And, hey, go Wolverines: the University of Michigan overcomes a cyberattack that delayed the academic year.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/167


Selected reading.

BadBazaar espionage tool targets Android users via trojanized Signal and Telegram apps (We Live Security) 

Earth Estries Targets Government, Tech for Cyberespionage (Trend Micro) 

Infamous Chisel Malware Analysis Report (Cybersecurity and Infrastructure Security Agency CISA)

UK and allies support Ukraine calling out Russia's GRU for new malware campaign (NCSC) 

Hackers Attack Czech Banks, Demanding End of Support For Ukraine (Brno Daily) 

More Russian attacks on Czech banks: Hackers call for end of support to Ukraine (Expats.cz)

Anonymous Sudan hacks X to put pressure on Elon Musk over Starlink (BBC News) 

Contrast Assess uncovers Spring-Kafka deserialization zero day (Contrast Security)

U. Michigan restores campus internet after cyberattack disrupts first week of classes (EdScoop)

Internet restored on University of Michigan campus, ongoing issues still expected (mlive)

University of Michigan isn't disclosing details of internet outage cyberattack (Detroit Free Press)

Expert weighs in on school cyberattacks as University of Michigan makes progress on internet outages (CBS News)

Extract Knowledge
Listen elsewhere

An international operation takes down Qakbot. Chinese threat actors anticipated Barracuda remediations. A look at adversary-in-the-middle attacks, making phishbait more effective and the emergence of a new ransomware threat. Narrative themes in Russian influence operations. My conversation with Natasha Eastman from (CISA), Bill Newhouse from (NIST), and Troy Lange from (NSA) to discuss their recent joint advisory on post-quantum readiness. Microsoft’s Ann Johnson from Afternoon Cyber Tea speaks with Cyber Threat Alliance President and CEO Michael Daniel about the current state of cybercrime. And when toilet bowls are outlawed, only outlaws will have toilet bowls.


Listen to the full conversation with Natasha Eastman, Bill Newhouse, and Troy Lange here: A joint advisory on post-quantum readiness.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/165


Selected reading.

Operation Duck Hunt bags Qakbot. (CyberWire)

FBI, Partners Dismantle Qakbot Infrastructure in Multinational Cyber Takedown (Federal Bureau of Investigation)

Qakbot Malware Disrupted in International Cyber Takedown (US Department of Justice)

Law Enforcement Takes Down Qakbot (Secureworks)

Qakbot: Takedown Operation Dismantles Botnet Infrastructure (Symantec) 

Chinese APT Was Prepared for Remediation Efforts in Barracuda ESG Zero-Day Attack (SecurityWeek) 

Phishing-as-a-Service Gets Smarter: Microsoft Sounds Alarm on AiTM Attacks (The Hacker News)

The Lure of Subject Lines in Phishing Emails - How Threat Actors Utilize Dates to Trick Victims (Cofense)

The Emergence of Ransomed: An Uncertain Cyber Threat in the Making (Flashpoint)

Cancelled flights: Air traffic disruption caused by flight data issue (BBC News)

Russian Offensive Campaign Assessment, August 29, 2023 (Institute for the Study of War)

More description

An international operation takes down Qakbot. Chinese threat actors anticipated Barracuda remediations. A look at adversary-in-the-middle attacks, making phishbait more effective and the emergence of a new ransomware threat. Narrative themes in Russian influence operations. My conversation with Natasha Eastman from (CISA), Bill Newhouse from (NIST), and Troy Lange from (NSA) to discuss their recent joint advisory on post-quantum readiness. Microsoft’s Ann Johnson from Afternoon Cyber Tea speaks with Cyber Threat Alliance President and CEO Michael Daniel about the current state of cybercrime. And when toilet bowls are outlawed, only outlaws will have toilet bowls.


Listen to the full conversation with Natasha Eastman, Bill Newhouse, and Troy Lange here: A joint advisory on post-quantum readiness.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/165


Selected reading.

Operation Duck Hunt bags Qakbot. (CyberWire)

FBI, Partners Dismantle Qakbot Infrastructure in Multinational Cyber Takedown (Federal Bureau of Investigation)

Qakbot Malware Disrupted in International Cyber Takedown (US Department of Justice)

Law Enforcement Takes Down Qakbot (Secureworks)

Qakbot: Takedown Operation Dismantles Botnet Infrastructure (Symantec) 

Chinese APT Was Prepared for Remediation Efforts in Barracuda ESG Zero-Day Attack (SecurityWeek) 

Phishing-as-a-Service Gets Smarter: Microsoft Sounds Alarm on AiTM Attacks (The Hacker News)

The Lure of Subject Lines in Phishing Emails - How Threat Actors Utilize Dates to Trick Victims (Cofense)

The Emergence of Ransomed: An Uncertain Cyber Threat in the Making (Flashpoint)

Cancelled flights: Air traffic disruption caused by flight data issue (BBC News)

Russian Offensive Campaign Assessment, August 29, 2023 (Institute for the Study of War)

Extract Knowledge
Listen elsewhere

In this extended interview, Dave Bittner sits down with Natasha Eastman from the Cybersecurity and Infrastructure Security Agency (CISA), Bill Newhouse from the National Institute of Standards and Technology (NIST), and Troy Lange from the National Security Agency (NSA) to discuss their their recent joint advisory on post-quantum readiness and how to prepare for post-quantum cryptography.

You can find the joint advisory here:

More description

In this extended interview, Dave Bittner sits down with Natasha Eastman from the Cybersecurity and Infrastructure Security Agency (CISA), Bill Newhouse from the National Institute of Standards and Technology (NIST), and Troy Lange from the National Security Agency (NSA) to discuss their their recent joint advisory on post-quantum readiness and how to prepare for post-quantum cryptography.

You can find the joint advisory here:

Extract Knowledge
Listen elsewhere

Name collision as a DNS risk. A LockBit derivative is active against targets in Spain. QR codes as phishbait. Cybersecurity trends in Healthcare. A Russian hacktivist auxiliary hits Polish organizations, while investigation of railroad incidents in Poland continues. Ben Yelin looks at the SEC cracking down on NFTs. Mr. Security Answer Person John Pescatore opens up the listener mail bag. And a look at a probably accidental glitch affecting air travel in the UK.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/164


Selected reading.

What's in a name? Strange behaviors at top-level domains creates uncertainty in DNS (Cisco Talos) 

Spain warns of LockBit Locker ransomware phishing attacks (BleepingComputer) 

Think Before You Scan: The Rise of QR Codes in Phishing (Trustwave SpiderLabs)

78% of Healthcare Organizations Experienced Cyber Incidents in Past Year, 60% of Which Impacted Patient Care (Claroty) 

Polish stock exchange, banks knocked offline by pro-Russian hackers (Cybernews) 

Two Men Arrested Following Poland Railway Hacking (SecurityWeek) 

Century-old technology hack brought 20 trains to a halt in Poland (Cybernews) 

Poland investigates train mishaps for possible Russian connection (Washington Post) 

Flight chaos ‘to last for days’ after air traffic control failure (The Telegraph) 

UK flight chaos could last for days, airline passengers warned (the Guardian) 

Government can’t rule out cyber attack caused air traffic chaos (MSN)

More description

Name collision as a DNS risk. A LockBit derivative is active against targets in Spain. QR codes as phishbait. Cybersecurity trends in Healthcare. A Russian hacktivist auxiliary hits Polish organizations, while investigation of railroad incidents in Poland continues. Ben Yelin looks at the SEC cracking down on NFTs. Mr. Security Answer Person John Pescatore opens up the listener mail bag. And a look at a probably accidental glitch affecting air travel in the UK.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/164


Selected reading.

What's in a name? Strange behaviors at top-level domains creates uncertainty in DNS (Cisco Talos) 

Spain warns of LockBit Locker ransomware phishing attacks (BleepingComputer) 

Think Before You Scan: The Rise of QR Codes in Phishing (Trustwave SpiderLabs)

78% of Healthcare Organizations Experienced Cyber Incidents in Past Year, 60% of Which Impacted Patient Care (Claroty) 

Polish stock exchange, banks knocked offline by pro-Russian hackers (Cybernews) 

Two Men Arrested Following Poland Railway Hacking (SecurityWeek) 

Century-old technology hack brought 20 trains to a halt in Poland (Cybernews) 

Poland investigates train mishaps for possible Russian connection (Washington Post) 

Flight chaos ‘to last for days’ after air traffic control failure (The Telegraph) 

UK flight chaos could last for days, airline passengers warned (the Guardian) 

Government can’t rule out cyber attack caused air traffic chaos (MSN)

Extract Knowledge
Listen elsewhere

The DPRK's Lazarus Group exploits ManageEngine issues. A Data breach at Kroll is traced to SIM swapping. Unusually destructive ransomware hits CloudNordic. Spawn of LockBit. Polish trains are disrupted by hacktivists. Rick Howard looks at the MITRE attack framework. Our guests are Andrew Hammond and Erin Dietrick from the International Spy Museum. And Influence laundering as a long-term disinformation tactic.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/163


Selected reading.

North Korean APT Hacks Internet Infrastructure Provider via ManageEngine Flaw (SecurityWeek)

Lazarus Group exploited ManageEngine vulnerability to target critical infrastructure (Help Net Security)

Cyber scams keep North Korean missiles flying (Radio Free Asia)

Claimant Data Breached in Genesis, FTX and BlockFi Bankruptcy Cases (Wall Street Journal)

Kroll data breach exposes info of FTX, BlockFi, Genesis creditors (BleepingComputer)

Crypto investor data exposed by a SIM swapping attack against a Kroll employee (Security Affairs)

Kroll Employee SIM-Swapped for Crypto Investor Data (KrebsOnSecurity)

Kroll Suffers Data Breach: Employee Falls Victim to SIM Swapping Attack (The Hacker News)

FTX bankruptcy handler Kroll discloses data breach (The Stack)

CloudNordic Faces Severe Data Loss After Ransomware Attack (Hackread) 

CloudNordic loses most customer data after ransomware attack | TechTarget (Security) 

Lockbit leak, research opportunities on tools leaked from TAs (SecureList)

LockBit 3.0 Ransomware Builder Leak Gives Rise to Hundreds of New Variants (The Hacker News)

Poland investigates cyber-attack on rail network (BBC News)

Poland investigates hacking attack on state railway network (Reuters)

Hackers bring down Poland’s train network in massive cyber attack (Ticker News) 

The Cheap Radio Hack That Disrupted Poland's Railway System (WIRED)

Russia Pushes Long-Term Influence Operations Aimed at the U.S. and Europe (New York Times)

Newly declassified US intel claims Russia is laundering propaganda through unwitting Westerners (CNN Politics)

More description

The DPRK's Lazarus Group exploits ManageEngine issues. A Data breach at Kroll is traced to SIM swapping. Unusually destructive ransomware hits CloudNordic. Spawn of LockBit. Polish trains are disrupted by hacktivists. Rick Howard looks at the MITRE attack framework. Our guests are Andrew Hammond and Erin Dietrick from the International Spy Museum. And Influence laundering as a long-term disinformation tactic.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/163


Selected reading.

North Korean APT Hacks Internet Infrastructure Provider via ManageEngine Flaw (SecurityWeek)

Lazarus Group exploited ManageEngine vulnerability to target critical infrastructure (Help Net Security)

Cyber scams keep North Korean missiles flying (Radio Free Asia)

Claimant Data Breached in Genesis, FTX and BlockFi Bankruptcy Cases (Wall Street Journal)

Kroll data breach exposes info of FTX, BlockFi, Genesis creditors (BleepingComputer)

Crypto investor data exposed by a SIM swapping attack against a Kroll employee (Security Affairs)

Kroll Employee SIM-Swapped for Crypto Investor Data (KrebsOnSecurity)

Kroll Suffers Data Breach: Employee Falls Victim to SIM Swapping Attack (The Hacker News)

FTX bankruptcy handler Kroll discloses data breach (The Stack)

CloudNordic Faces Severe Data Loss After Ransomware Attack (Hackread) 

CloudNordic loses most customer data after ransomware attack | TechTarget (Security) 

Lockbit leak, research opportunities on tools leaked from TAs (SecureList)

LockBit 3.0 Ransomware Builder Leak Gives Rise to Hundreds of New Variants (The Hacker News)

Poland investigates cyber-attack on rail network (BBC News)

Poland investigates hacking attack on state railway network (Reuters)

Hackers bring down Poland’s train network in massive cyber attack (Ticker News) 

The Cheap Radio Hack That Disrupted Poland's Railway System (WIRED)

Russia Pushes Long-Term Influence Operations Aimed at the U.S. and Europe (New York Times)

Newly declassified US intel claims Russia is laundering propaganda through unwitting Westerners (CNN Politics)

Extract Knowledge
Listen elsewhere

This week, we welcome Dina Haines, an Industry Partnership Manager with the National Security Agency's Cybersecurity Collaboration Center. Dina found from a young age, she was always interested in the field, taking after her father who worked in the space industry, paving the way for her to fall in love with the field. She worked in the private sector for a bit, moving around every now and again, eventually landing the position she works now. Dina says her day to day job is helping the NSA to bend and protect cyberspace by bringing in private industry. She says "I try to spend a lot of time listening and seeing where people, where they're coming from, where they're at, you know, potentially in their career, where they're at in their job that day, and then try to, um, support them and bring them up and, and float the entire boat." We thank Dina for sharing her story with us.

More description

This week, we welcome Dina Haines, an Industry Partnership Manager with the National Security Agency's Cybersecurity Collaboration Center. Dina found from a young age, she was always interested in the field, taking after her father who worked in the space industry, paving the way for her to fall in love with the field. She worked in the private sector for a bit, moving around every now and again, eventually landing the position she works now. Dina says her day to day job is helping the NSA to bend and protect cyberspace by bringing in private industry. She says "I try to spend a lot of time listening and seeing where people, where they're coming from, where they're at, you know, potentially in their career, where they're at in their job that day, and then try to, um, support them and bring them up and, and float the entire boat." We thank Dina for sharing her story with us.

Extract Knowledge
Listen elsewhere

Tal Skverer from Astrix Security joins to discuss their work on "GhostToken – Exploiting GCP application infrastructure to create invisible, unremovable trojan app on Google accounts." Astrix’s Security Research Group revealed a 0-day flaw in Google’s Cloud Platform (GCP) on June 19, 2022, which was found to affect all Google users.

The research states "The vulnerability, dubbed “GhostToken”, could allow threat actors to change a malicious application to be invisible and unremovable, effectively leaving the victim’s Google account infected with a trojan app forever." Google issued a patch to this vulnerability in April of this year, but researchers explain why this can be severe.

The research can be found here:

More description

Tal Skverer from Astrix Security joins to discuss their work on "GhostToken – Exploiting GCP application infrastructure to create invisible, unremovable trojan app on Google accounts." Astrix’s Security Research Group revealed a 0-day flaw in Google’s Cloud Platform (GCP) on June 19, 2022, which was found to affect all Google users.

The research states "The vulnerability, dubbed “GhostToken”, could allow threat actors to change a malicious application to be invisible and unremovable, effectively leaving the victim’s Google account infected with a trojan app forever." Google issued a patch to this vulnerability in April of this year, but researchers explain why this can be severe.

The research can be found here:

Extract Knowledge
Listen elsewhere

Telekopye and the rise of commodified phishing kits. Lazarus Group fields new malware. Implications of China's campaign against vulnerable Barracuda appliances. Abhubllka ransomware's targeting and low extortion demands. Malek Ben Salem of Accenture outlines generative AI Implications to spam detection. Jeff Welgan, Chief Learning Officer at N2K Networks, unpacks the NICE framework and strategic workforce intelligence. And a new hacktivist group emerges, and takes a particular interest in NATO members.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/162


Selected reading.

eBay Users Beware Russian 'Telekopye' Telegram Phishing Bot (Dark Reading)

Telekopye: Hunting Mammoths using Telegram bot (ESET)

Lazarus Group's infrastructure reuse leads to discovery of new malware (Cisco Talos Blog) 

FBI fingers China for attacks on Barracuda email appliances (Register)

Suspected PRC Cyber ActorsContinue to Globally Exploit Barracuda ESG Zero-Day Vulnerability (CVE-2023-2868) (FBI)

Identifying ADHUBLLKA Ransomware: LOLKEK, BIT, OBZ, U2K, TZW Variants (Netenrich)

Ransomware ecosystem targeting individuals, small firms remains robust (Record) 

Ransomware With an Identity Crisis Targets Small Businesses, Individuals (Dark Reading) 

Hacking group KittenSec claims to 'pwn anything we see' to expose corruption (CyberScoop)

More description

Telekopye and the rise of commodified phishing kits. Lazarus Group fields new malware. Implications of China's campaign against vulnerable Barracuda appliances. Abhubllka ransomware's targeting and low extortion demands. Malek Ben Salem of Accenture outlines generative AI Implications to spam detection. Jeff Welgan, Chief Learning Officer at N2K Networks, unpacks the NICE framework and strategic workforce intelligence. And a new hacktivist group emerges, and takes a particular interest in NATO members.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/162


Selected reading.

eBay Users Beware Russian 'Telekopye' Telegram Phishing Bot (Dark Reading)

Telekopye: Hunting Mammoths using Telegram bot (ESET)

Lazarus Group's infrastructure reuse leads to discovery of new malware (Cisco Talos Blog) 

FBI fingers China for attacks on Barracuda email appliances (Register)

Suspected PRC Cyber ActorsContinue to Globally Exploit Barracuda ESG Zero-Day Vulnerability (CVE-2023-2868) (FBI)

Identifying ADHUBLLKA Ransomware: LOLKEK, BIT, OBZ, U2K, TZW Variants (Netenrich)

Ransomware ecosystem targeting individuals, small firms remains robust (Record) 

Ransomware With an Identity Crisis Targets Small Businesses, Individuals (Dark Reading) 

Hacking group KittenSec claims to 'pwn anything we see' to expose corruption (CyberScoop)

Extract Knowledge
Listen elsewhere

There’s a new sophistication in BEC campaigns. Trends in brand impersonation–crooks still like to pretend they’re from Redmond. The future of Russian influence operations in the post-Prigozhin era. Andrea Little Limbago from Interos shares insights on the new cyber workforce strategy. In our latest Threat Vector segment David Moulton of Palo Alto Networks is joined by Stephanie Ragan, Senior Consultant at Unit 42 to discuss Muddled Libra. And more on the doxing of a deputy Duma chair, who seems to have been selling hot iPhones as a side hustle (maybe). And the growing problem of Synthetic identity fraud.


On this segment of Threat Vector, Stephanie Ragan, Senior Consultant at Unit 42, joins host David Moulton to discuss Muddled Libra.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/162


Selected reading.

BEC Trends: Payroll Diversion Dominates and Sneaky Multi-Persona Attacks Emerge (Trustwave)

Q2 2023 Threat Landscape Report: All Roads Lead to Supply Chain Infiltrations (Kroll)

Microsoft Impersonated Most in Phishing Attacks Among Nearly 350 Brands (Abnormal Security)

TransUnion Analysis Finds Synthetic Identity Fraud Growing to Record Levels (TransUnion)

Ukraine at D+546: Yevgeny Prigozhin dies in a plane crash. (CyberWire)

Without Prigozhin, expect some changes around the edges on Russian influence operations (Washington Post)

2023 H1 Global Threat Analysis Report (Radware)

Lapsus$: Court finds teenagers carried out hacking spree (BBC News)

British court convicts two teen Lapsus$ members of hacking tech firms (Record) 

Treasury Designates Roman Semenov, Co-Founder of Sanctioned Virtual Currency Mixer Tornado Cash (U.S. Department of the Treasury) 

Tornado Cash Founders Charged With Money Laundering And Sanctions Violations (U.S. Attorney for the Southern District of New York) 

Russian Duma leader’s emails hacked and leaked (Cybernews)

Ukrainian hackers expose money laundering and sanction evasion by senior Russian politician (teiss) 

More description

There’s a new sophistication in BEC campaigns. Trends in brand impersonation–crooks still like to pretend they’re from Redmond. The future of Russian influence operations in the post-Prigozhin era. Andrea Little Limbago from Interos shares insights on the new cyber workforce strategy. In our latest Threat Vector segment David Moulton of Palo Alto Networks is joined by Stephanie Ragan, Senior Consultant at Unit 42 to discuss Muddled Libra. And more on the doxing of a deputy Duma chair, who seems to have been selling hot iPhones as a side hustle (maybe). And the growing problem of Synthetic identity fraud.


On this segment of Threat Vector, Stephanie Ragan, Senior Consultant at Unit 42, joins host David Moulton to discuss Muddled Libra.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/162


Selected reading.

BEC Trends: Payroll Diversion Dominates and Sneaky Multi-Persona Attacks Emerge (Trustwave)

Q2 2023 Threat Landscape Report: All Roads Lead to Supply Chain Infiltrations (Kroll)

Microsoft Impersonated Most in Phishing Attacks Among Nearly 350 Brands (Abnormal Security)

TransUnion Analysis Finds Synthetic Identity Fraud Growing to Record Levels (TransUnion)

Ukraine at D+546: Yevgeny Prigozhin dies in a plane crash. (CyberWire)

Without Prigozhin, expect some changes around the edges on Russian influence operations (Washington Post)

2023 H1 Global Threat Analysis Report (Radware)

Lapsus$: Court finds teenagers carried out hacking spree (BBC News)

British court convicts two teen Lapsus$ members of hacking tech firms (Record) 

Treasury Designates Roman Semenov, Co-Founder of Sanctioned Virtual Currency Mixer Tornado Cash (U.S. Department of the Treasury) 

Tornado Cash Founders Charged With Money Laundering And Sanctions Violations (U.S. Attorney for the Southern District of New York) 

Russian Duma leader’s emails hacked and leaked (Cybernews)

Ukrainian hackers expose money laundering and sanction evasion by senior Russian politician (teiss) 

Extract Knowledge
Listen elsewhere

The Smoke Loader botnet has a creepy new payload. Ransomware gets faster. How AI has evolved in malicious directions. The Snatch ransomware gang threatens to snitch. The FSB continues to use both USBs and phishing emails as attack vectors. A ransomware attack shutters Belgian social service offices. Tim Starks from the Washington Post explains a Biden administration win in a DC court. Our guest Ben Sebree of CivicPlus describes how the public sector could combat cybercrime during cloud adoption. And the deadline for comment on US cybersecurity regulations? It’s been extended.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/161


Selected reading.

Smoke Loader Drops Whiffy Recon Wi-Fi Scanning and Geolocation Malware (SecureWorks) 

Time keeps on slippin’ slippin’ slippin’: The 2023 Active Adversary Report for Tech Leaders (Sophos News) 

HP Wolf Security Threat Insights Report Q2 2023 | HP Wolf Security (HP Wolf Security) 

Barracuda XDR Insights: How AI learns your patterns to protect you (Barracuda)

Deep Instinct Study Finds Significant Increase in Cybersecurity Attacks Fueled by Generative AI (Deep Instinct) 

Cyberattack on Belgian social service centers forces them to close (Record)

Ukraine’s Military Hacked by Russian Backed USB Malware (Ophtek)

Request for Information on Cyber Regulatory Harmonization; Request for Information: Opportunities for and Obstacles To Harmonizing Cybersecurity Regulations (Federal Register)

More description

The Smoke Loader botnet has a creepy new payload. Ransomware gets faster. How AI has evolved in malicious directions. The Snatch ransomware gang threatens to snitch. The FSB continues to use both USBs and phishing emails as attack vectors. A ransomware attack shutters Belgian social service offices. Tim Starks from the Washington Post explains a Biden administration win in a DC court. Our guest Ben Sebree of CivicPlus describes how the public sector could combat cybercrime during cloud adoption. And the deadline for comment on US cybersecurity regulations? It’s been extended.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/161


Selected reading.

Smoke Loader Drops Whiffy Recon Wi-Fi Scanning and Geolocation Malware (SecureWorks) 

Time keeps on slippin’ slippin’ slippin’: The 2023 Active Adversary Report for Tech Leaders (Sophos News) 

HP Wolf Security Threat Insights Report Q2 2023 | HP Wolf Security (HP Wolf Security) 

Barracuda XDR Insights: How AI learns your patterns to protect you (Barracuda)

Deep Instinct Study Finds Significant Increase in Cybersecurity Attacks Fueled by Generative AI (Deep Instinct) 

Cyberattack on Belgian social service centers forces them to close (Record)

Ukraine’s Military Hacked by Russian Backed USB Malware (Ophtek)

Request for Information on Cyber Regulatory Harmonization; Request for Information: Opportunities for and Obstacles To Harmonizing Cybersecurity Regulations (Federal Register)

Extract Knowledge
Listen elsewhere

HiatusRAT shifts its targets. Ecuador's difficulties with voting is attributed to cyberattacks. Carderbee is an APT targeting Hong Kong. auDA (OOO-duh) turns out not to have been breached. Ukrainian hacktivists claim to dox a senior member of Russia's Duma. Russian influence operations take aim at NATO's July summit. Joe Carrigan describes attacks on LinkedIn accounts. Our guest is John Hernandez from Quest to discuss why he believes the MOVEit flaw is a wakeup call for CISOs. Security, not by obscurity, but by typo.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/160


Selected reading.

HiatusRAT Malware Resurfaces: Taiwan Firms and U.S. Military Under Attack (The Hacker News) 

New HiatusRAT campaign targets Taiwan and U.S. military procurement system (Security Affairs)

HiatusRAT Returns after a Hiatus in a Fresh Wave of Attacks (Cyware Labs)

No rest for the wicked: HiatusRAT takes little time off in a return to action (Lumen)

Ecuador’s national election agency says cyberattacks caused absentee voting issues (Record)

Carderbee: APT Group use Legit Software in Supply Chain Attack Targeting Orgs in Hong Kong

Resolution of cyber incident (auDA) 

Ukrainian hackers claim to leak emails of Russian parliament deputy chief (Record) 

Summit Old, Summit New (Graphika)

Summit Old, Summit New: Russia-Linked Actors Leverage New and Old Tactics in Influence Operations Targeting Online Conversations About NATO Summit (Graphika)

The simple typo that stopped bank robbers from stealing $1 billion (LAD Bible)

More description

HiatusRAT shifts its targets. Ecuador's difficulties with voting is attributed to cyberattacks. Carderbee is an APT targeting Hong Kong. auDA (OOO-duh) turns out not to have been breached. Ukrainian hacktivists claim to dox a senior member of Russia's Duma. Russian influence operations take aim at NATO's July summit. Joe Carrigan describes attacks on LinkedIn accounts. Our guest is John Hernandez from Quest to discuss why he believes the MOVEit flaw is a wakeup call for CISOs. Security, not by obscurity, but by typo.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/160


Selected reading.

HiatusRAT Malware Resurfaces: Taiwan Firms and U.S. Military Under Attack (The Hacker News) 

New HiatusRAT campaign targets Taiwan and U.S. military procurement system (Security Affairs)

HiatusRAT Returns after a Hiatus in a Fresh Wave of Attacks (Cyware Labs)

No rest for the wicked: HiatusRAT takes little time off in a return to action (Lumen)

Ecuador’s national election agency says cyberattacks caused absentee voting issues (Record)

Carderbee: APT Group use Legit Software in Supply Chain Attack Targeting Orgs in Hong Kong

Resolution of cyber incident (auDA) 

Ukrainian hackers claim to leak emails of Russian parliament deputy chief (Record) 

Summit Old, Summit New (Graphika)

Summit Old, Summit New: Russia-Linked Actors Leverage New and Old Tactics in Influence Operations Targeting Online Conversations About NATO Summit (Graphika)

The simple typo that stopped bank robbers from stealing $1 billion (LAD Bible)

Extract Knowledge
Listen elsewhere
Show details
Episodes
3784
Transcripts
67
2% coverage
Missing transcripts
3717
With chapters
0