Search this show’s transcripts

CyberWire Daily

en us
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
More details
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
Sources and links

Episodes

Page 26 · 50 per page

The DPRK's Kimsuky attempts to hit joint military exercises. Australian domain administrator auDA (OW-duh) may have been breached. WoofLocker's version of a tech support scam. The US Intelligence Community warns of cyber threats to space systems. Rick Howard looks at forecasting cyber risk. Deepen Desai from Zscaler shares ransomware trends. And more wartime disinformation out of Russia.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/159


Selected reading.

Suspected N. Korean Hackers Target S. Korea-US Drills (SecurityWeek)

N. Korean Kimsuky APT targets S. Korea-US military exercises (Security Affairs) 

North Korean hackers target US-South Korea military drills, police say (The Economic Times

Cyber incident update (auDA) 

Australia’s .au domain administrator denies data breach after ransomware posting (Record) 

Hackers claim to have breached auDA (iTnews)

Catching up with WoofLocker, the most elaborate traffic redirection scheme to tech support scams (Malwarebytes) 

WoofLocker Toolkit Hides Malicious Codes in Images to Run Tech Support Scams (The Hacker News)

US warns space companies about foreign spying (Reuters) 

Intelligence Agencies Warn Foreign Spies Are Targeting U.S. Space Companies (New York Times) 

US Warns Space Industry of Growing Risks of Spying and Satellite Attacks (Bloomberg) 

Foreign countries targeting tech from US space companies, intel agencies warn (The HIll) 

Pentagon urges US space companies to stay vigilant against foreign intelligence (TechCrunch) 

Safeguarding the US Space Industry: Keeping Your Intellectual Property in Orbit (DNI) 

What To Do About The U.S. Intelligence Community Warning on Safeguarding The Space Industry (OODA Loop) 

Countering disinformation with facts - Russian invasion of Ukraine (Government of Canada)

Sergey Lavrov: Throwing Russia off balance is ultimate aim (TASS)

Moscow says US unwillingness to end Ukraine conflict (Merh News Agency)

Russian invaders sending threats to Kherson region’s residents via social media - watchdog (Ukrinform)

More description

The DPRK's Kimsuky attempts to hit joint military exercises. Australian domain administrator auDA (OW-duh) may have been breached. WoofLocker's version of a tech support scam. The US Intelligence Community warns of cyber threats to space systems. Rick Howard looks at forecasting cyber risk. Deepen Desai from Zscaler shares ransomware trends. And more wartime disinformation out of Russia.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/159


Selected reading.

Suspected N. Korean Hackers Target S. Korea-US Drills (SecurityWeek)

N. Korean Kimsuky APT targets S. Korea-US military exercises (Security Affairs) 

North Korean hackers target US-South Korea military drills, police say (The Economic Times

Cyber incident update (auDA) 

Australia’s .au domain administrator denies data breach after ransomware posting (Record) 

Hackers claim to have breached auDA (iTnews)

Catching up with WoofLocker, the most elaborate traffic redirection scheme to tech support scams (Malwarebytes) 

WoofLocker Toolkit Hides Malicious Codes in Images to Run Tech Support Scams (The Hacker News)

US warns space companies about foreign spying (Reuters) 

Intelligence Agencies Warn Foreign Spies Are Targeting U.S. Space Companies (New York Times) 

US Warns Space Industry of Growing Risks of Spying and Satellite Attacks (Bloomberg) 

Foreign countries targeting tech from US space companies, intel agencies warn (The HIll) 

Pentagon urges US space companies to stay vigilant against foreign intelligence (TechCrunch) 

Safeguarding the US Space Industry: Keeping Your Intellectual Property in Orbit (DNI) 

What To Do About The U.S. Intelligence Community Warning on Safeguarding The Space Industry (OODA Loop) 

Countering disinformation with facts - Russian invasion of Ukraine (Government of Canada)

Sergey Lavrov: Throwing Russia off balance is ultimate aim (TASS)

Moscow says US unwillingness to end Ukraine conflict (Merh News Agency)

Russian invaders sending threats to Kherson region’s residents via social media - watchdog (Ukrinform)

Extract Knowledge
Listen elsewhere

This week, our guest is Luke Vander Linden, Vice President of Membership & Marketing from RH-ISAC and host of the RH-ISAC podcast here at the CyberWire. Luke sits down to share his story all the way back to when he was a very young age where he was a child model and actor to where he is now working in the cyber industry. Luke fell into the marketing field after his time as a child actor, where he really started to find his passion. After finding his passion, he decided to branch out to different areas in the field, working in public libraries and advocacy groups, this is where he started to really enjoy the prospect of working with individuals who support organizations, which got him started in the RH-ISAC world. Luke shares that he wears many hats these days, working in the podcast business while also working on the leadership team at RH-ISAC. His advice for people getting into this industry is "I think with age comes this knowledge, but also with experiences. So, I mean, to that point, don't be afraid to go out there and fail, give it a shot." We thank Luke for sharing his story with us.

More description

This week, our guest is Luke Vander Linden, Vice President of Membership & Marketing from RH-ISAC and host of the RH-ISAC podcast here at the CyberWire. Luke sits down to share his story all the way back to when he was a very young age where he was a child model and actor to where he is now working in the cyber industry. Luke fell into the marketing field after his time as a child actor, where he really started to find his passion. After finding his passion, he decided to branch out to different areas in the field, working in public libraries and advocacy groups, this is where he started to really enjoy the prospect of working with individuals who support organizations, which got him started in the RH-ISAC world. Luke shares that he wears many hats these days, working in the podcast business while also working on the leadership team at RH-ISAC. His advice for people getting into this industry is "I think with age comes this knowledge, but also with experiences. So, I mean, to that point, don't be afraid to go out there and fail, give it a shot." We thank Luke for sharing his story with us.

Extract Knowledge
Listen elsewhere

Dmitry Bestuzhev from Blackberry joins to discuss their work on "RomCom Resurfaces: Targeting Politicians in Ukraine and U.S.-Based Healthcare Providing Aid to Refugees from Ukraine." Research suggests that the RomCom threat team has been tracked carefully following the geopolitical events surrounding the war in Ukraine, and are now targeting politicians in Ukraine who are working closely with Western countries.

This group is different from others in that their focus is more on secrets or information which can be useful in geopolitics and specifically the war in Ukraine, instead of financial gain. The research says "Although it is unclear at this point what initial infection vector was used to kick off the execution chain, previous RomCom attacks used targeted phishing emails to point a victim to a cloned website hosting Trojanized versions of popular software."

The research can be found here:

More description

Dmitry Bestuzhev from Blackberry joins to discuss their work on "RomCom Resurfaces: Targeting Politicians in Ukraine and U.S.-Based Healthcare Providing Aid to Refugees from Ukraine." Research suggests that the RomCom threat team has been tracked carefully following the geopolitical events surrounding the war in Ukraine, and are now targeting politicians in Ukraine who are working closely with Western countries.

This group is different from others in that their focus is more on secrets or information which can be useful in geopolitics and specifically the war in Ukraine, instead of financial gain. The research says "Although it is unclear at this point what initial infection vector was used to kick off the execution chain, previous RomCom attacks used targeted phishing emails to point a victim to a cloned website hosting Trojanized versions of popular software."

The research can be found here:

Extract Knowledge
Listen elsewhere

Phishing for Zimbra credentials. PlayCrypt ransomware described. The Cuba ransomware group adopts new tools. #NoFilter. Cyber criminals threaten security researchers. Our guest is Kevin Paige from Uptycs with thoughts on the Blackhat conference. Eric Goldstein, Executive Assistant Director at CISA joins us discussing next steps on the Secure by Design journey. And Russian disinformation takes on "Anglo-Saxonia."


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/158


Selected reading.

Mass-spreading campaign targeting Zimbra users (We Live Security)

PlayCrypt Ransomware Group Wreaks Havoc in Campaign Against Managed Service Providers (Adlumin SaaS Security)

Cuba Ransomware Deploys New Tools: Targets Critical Infrastructure Sector in the U.S. and IT Integrator in Latin America (BlackBerry)

NoFilter Attack: Sneaky Privilege Escalation Method Bypasses Windows Security (The Hacker News)

Cyber security researchers become target of criminal hackers (Financial Times)

Britain plotting to assassinate pro-Russian leaders in Africa, says Moscow (The Telegraph) 

Ukraine at D+540: Russification and disinformation. (CyberWire) 

More description

Phishing for Zimbra credentials. PlayCrypt ransomware described. The Cuba ransomware group adopts new tools. #NoFilter. Cyber criminals threaten security researchers. Our guest is Kevin Paige from Uptycs with thoughts on the Blackhat conference. Eric Goldstein, Executive Assistant Director at CISA joins us discussing next steps on the Secure by Design journey. And Russian disinformation takes on "Anglo-Saxonia."


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/158


Selected reading.

Mass-spreading campaign targeting Zimbra users (We Live Security)

PlayCrypt Ransomware Group Wreaks Havoc in Campaign Against Managed Service Providers (Adlumin SaaS Security)

Cuba Ransomware Deploys New Tools: Targets Critical Infrastructure Sector in the U.S. and IT Integrator in Latin America (BlackBerry)

NoFilter Attack: Sneaky Privilege Escalation Method Bypasses Windows Security (The Hacker News)

Cyber security researchers become target of criminal hackers (Financial Times)

Britain plotting to assassinate pro-Russian leaders in Africa, says Moscow (The Telegraph) 

Ukraine at D+540: Russification and disinformation. (CyberWire) 

Extract Knowledge
Listen elsewhere

Building a proxy botnet. Active flaws in PowerShell Gallery. A cyber incident disrupts Clorox. Scams lure would-be mobile beta-testers. Lessons learned from the Russian cyberattack on Viasat. An update on cyber threats to Starlink. Robert M. Lee from Dragos shares his thoughts on the waves of layoffs that have gone through the industry. Steve Leeper of Datadobi explains mitigating risks associated with illegal data on your network. And hey, world leader: it’s never too late to stop manifesting a chronic cranio-urological condition, as they more-or-less say in the Quantum Realm.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/157


Selected reading.

ProxyNation: The dark nexus between proxy apps and malware (AT&T Alien Labs) 

Massive 400,000 proxy botnet built with stealthy malware infections (BleepingComputer) 

PowerHell: Active Flaws in PowerShell Gallery Expose Users to Attacks (Aqua Security) 

Clorox Operations Disrupted By Cyber-Attack (Infosecurity Magazine) 

Cyber Criminals Targeting Victims through Mobile Beta-Testing Applications (IC3) 

FBI warns about scams that lure you in as a mobile beta-tester (Naked Security)

Incident response lessons learned from the Russian attack on Viasat (CSO Online)

Recent Intel Report Reveals New Starlink Vulnerabilities, Increasing Concerns About the Future of Global Satellite Internet (Debrief)

Hacked electronic sign declares “Putin is a dickhead” as Russian ruble slumps (Graham Cluley) 

More description

Building a proxy botnet. Active flaws in PowerShell Gallery. A cyber incident disrupts Clorox. Scams lure would-be mobile beta-testers. Lessons learned from the Russian cyberattack on Viasat. An update on cyber threats to Starlink. Robert M. Lee from Dragos shares his thoughts on the waves of layoffs that have gone through the industry. Steve Leeper of Datadobi explains mitigating risks associated with illegal data on your network. And hey, world leader: it’s never too late to stop manifesting a chronic cranio-urological condition, as they more-or-less say in the Quantum Realm.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/157


Selected reading.

ProxyNation: The dark nexus between proxy apps and malware (AT&T Alien Labs) 

Massive 400,000 proxy botnet built with stealthy malware infections (BleepingComputer) 

PowerHell: Active Flaws in PowerShell Gallery Expose Users to Attacks (Aqua Security) 

Clorox Operations Disrupted By Cyber-Attack (Infosecurity Magazine) 

Cyber Criminals Targeting Victims through Mobile Beta-Testing Applications (IC3) 

FBI warns about scams that lure you in as a mobile beta-tester (Naked Security)

Incident response lessons learned from the Russian attack on Viasat (CSO Online)

Recent Intel Report Reveals New Starlink Vulnerabilities, Increasing Concerns About the Future of Global Satellite Internet (Debrief)

Hacked electronic sign declares “Putin is a dickhead” as Russian ruble slumps (Graham Cluley) 

Extract Knowledge
Listen elsewhere

China accuses the US of installing backdoors in a Wuhan lab. NetScaler backdoors are found. A Phishing scam targets executives. LinkedIn sees a surge in account hijacking. Raccoon Stealer gets an update. Cryptocurrency recovery scams. We kick off our new Learning Layer segment with N2K’s Sam Meisenberg. And a Moscow court fines Reddit and Wikipedia, for unwelcome content about Russia's war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/156


Selected reading.

Ministry warns of data security risks after US agencies identified behind cyberattack on Wuhan Earthquake Monitoring Center (Global Times)

China accuses U.S. intelligence agencies as source behind Wuhan cybersecurity attack (ZDNET) 

China teases imminent exposé of seismic US spying scheme (Register) 

2,000 Citrix NetScaler Instances Backdoored via Recent Vulnerability (SecurityWeek) 

Cloud Account Takeover Campaign Leveraging EvilProxy Targets Top-Level Executives at over 100 Global Organizations (Proofpoint)

LinkedIn Accounts Under Attack (Cyberint)

LinkedIn faces surge of account hijacking (Computing)

LinkedIn accounts hacked in widespread hijacking campaign (BleepingComputer)

Raccoon Stealer malware returns with new stealthier version (BleepingComputer)

FBI warns of increasing cryptocurrency recovery scams (BleepingComputer) 

Russia slaps Reddit, Wikipedia with fines (Cybernews)

More description

China accuses the US of installing backdoors in a Wuhan lab. NetScaler backdoors are found. A Phishing scam targets executives. LinkedIn sees a surge in account hijacking. Raccoon Stealer gets an update. Cryptocurrency recovery scams. We kick off our new Learning Layer segment with N2K’s Sam Meisenberg. And a Moscow court fines Reddit and Wikipedia, for unwelcome content about Russia's war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/156


Selected reading.

Ministry warns of data security risks after US agencies identified behind cyberattack on Wuhan Earthquake Monitoring Center (Global Times)

China accuses U.S. intelligence agencies as source behind Wuhan cybersecurity attack (ZDNET) 

China teases imminent exposé of seismic US spying scheme (Register) 

2,000 Citrix NetScaler Instances Backdoored via Recent Vulnerability (SecurityWeek) 

Cloud Account Takeover Campaign Leveraging EvilProxy Targets Top-Level Executives at over 100 Global Organizations (Proofpoint)

LinkedIn Accounts Under Attack (Cyberint)

LinkedIn faces surge of account hijacking (Computing)

LinkedIn accounts hacked in widespread hijacking campaign (BleepingComputer)

Raccoon Stealer malware returns with new stealthier version (BleepingComputer)

FBI warns of increasing cryptocurrency recovery scams (BleepingComputer) 

Russia slaps Reddit, Wikipedia with fines (Cybernews)

Extract Knowledge
Listen elsewhere

New targets of Chinese cyberespionage are uncovered. Monti ransomware is back. An evasive phishing campaign exposed. A Realtors' network taken down by cyberattack. A closer look at NoName057(16). Perspective on cyberwar - remember Pearl Harbor, but don’t see it everywhere. Ben Yelin on the Consumer Financial Protection Bureau’s plans to regulate surveillance tech. Microsoft’s Ann Johnson and Charlie Bell ponder the future of security. And scammers are targeting kids playing Fortnite and Roblox.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/155


Selected reading.

Chinese spies who read State Dept. email also hacked GOP congressman (Washington Post) 

Binary Ballet: China’s Espionage Tango with Microsoft (SecurityHQ)

Microsoft Exchange hack to be investigated by US Cyber Safety Board (Computing)

Monti ransomware targets VMware ESXi servers with new Linux locker (BleepingComputer) 

Evasive Phishing Campaign Steals Cloud Credentials Using Cloudflare R2 and Turnstile (Netskope)

Cyberattack on Bay area vendor cripples real estate industry (The Real Deal)

Intel insiders go undercover revealing fresh details into NoName hacktivist operations (Cybernews) 

Why the US Military Wants You To Rethink the Idea of 'Cyber War' (The Messenger) 

A Huge Scam Targeting Kids With Roblox and Fortnite 'Offers' Has Been Hiding in Plain Sight (WIRED)

More description

New targets of Chinese cyberespionage are uncovered. Monti ransomware is back. An evasive phishing campaign exposed. A Realtors' network taken down by cyberattack. A closer look at NoName057(16). Perspective on cyberwar - remember Pearl Harbor, but don’t see it everywhere. Ben Yelin on the Consumer Financial Protection Bureau’s plans to regulate surveillance tech. Microsoft’s Ann Johnson and Charlie Bell ponder the future of security. And scammers are targeting kids playing Fortnite and Roblox.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/155


Selected reading.

Chinese spies who read State Dept. email also hacked GOP congressman (Washington Post) 

Binary Ballet: China’s Espionage Tango with Microsoft (SecurityHQ)

Microsoft Exchange hack to be investigated by US Cyber Safety Board (Computing)

Monti ransomware targets VMware ESXi servers with new Linux locker (BleepingComputer) 

Evasive Phishing Campaign Steals Cloud Credentials Using Cloudflare R2 and Turnstile (Netskope)

Cyberattack on Bay area vendor cripples real estate industry (The Real Deal)

Intel insiders go undercover revealing fresh details into NoName hacktivist operations (Cybernews) 

Why the US Military Wants You To Rethink the Idea of 'Cyber War' (The Messenger) 

A Huge Scam Targeting Kids With Roblox and Fortnite 'Offers' Has Been Hiding in Plain Sight (WIRED)

Extract Knowledge
Listen elsewhere

An African power generator has been targeted by ransomware. The APT31 group is believed to be responsible for attacks on industrial systems in Eastern Europe. There have been arrests related to the takedown of LolekHosted. Ukraine's SBU has alleged that Russia's GRU is using specialized malware to attack Starlink. Microsoft has decided not to extend licenses for its products in Russia. Rick Howard opens his toolbox on DDOS. In our Solution Spotlight: Simone Petrella and Camille Stewart Gloster discuss the White House release of its cybersecurity workforce and education strategy. And the Cyber Safety Review Board will be investigating cases of cyberespionage against Exchange.


Watch the full video of Simone and Camille here: Solution Spotlight: Simone Petrella and Camille Stewart Gloster


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/154


Selected reading.

DroxiDat-Cobalt Strike Duo Targets Power Generator Network (Infosecurity Magazine)

New SystemBC Malware Variant Targets Southern African Power Company (The Hacker News)

Power Generator in South Africa hit with DroxiDat and Cobalt Strike (Security Affairs) 

Southern African power generator targeted with DroxiDat malware (Record) 

Common TTPs of attacks against industrial organizations. Implants for uploading data (Kaspersky ICS CERT)

APT31 Linked to Recent Industrial Attacks in Eastern Europe (Infosecurity Magazine) 

Researchers Shed Light on APT31's Advanced Backdoors and Data Exfiltration Tactics (The Hacker News) 

LOLEKHosted admin arrested for aiding Netwalker ransomware gang (BleepingComputer)

Russian spy agencies targeting Starlink with custom malware, Ukraine warns (The Telegraph)

Russia Bans iPhones And iPads For Official Use: Report (BW Businessworld)

Microsoft Suspends Extending Licenses For Companies in Russia (RadioFreeEurope/RadioLiberty) 

Department of Homeland Security’s Cyber Safety Review Board to Conduct Review on Cloud Security (US Department of Homeland Security)

Microsoft Exchange hack is focus of cyber board’s next review (Record) 

Microsoft is under scrutiny after a recent attack by suspected Chinese hackers (Windows Central) 

The DHS’s CSRB to review cloud security practices following the hack of Microsoft Exchange govt email accounts (Security Affairs)

Microsoft's role in data breach by Chinese hackers to be part of US cyber inquiry (Firstpost)

More description

An African power generator has been targeted by ransomware. The APT31 group is believed to be responsible for attacks on industrial systems in Eastern Europe. There have been arrests related to the takedown of LolekHosted. Ukraine's SBU has alleged that Russia's GRU is using specialized malware to attack Starlink. Microsoft has decided not to extend licenses for its products in Russia. Rick Howard opens his toolbox on DDOS. In our Solution Spotlight: Simone Petrella and Camille Stewart Gloster discuss the White House release of its cybersecurity workforce and education strategy. And the Cyber Safety Review Board will be investigating cases of cyberespionage against Exchange.


Watch the full video of Simone and Camille here: Solution Spotlight: Simone Petrella and Camille Stewart Gloster


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/154


Selected reading.

DroxiDat-Cobalt Strike Duo Targets Power Generator Network (Infosecurity Magazine)

New SystemBC Malware Variant Targets Southern African Power Company (The Hacker News)

Power Generator in South Africa hit with DroxiDat and Cobalt Strike (Security Affairs) 

Southern African power generator targeted with DroxiDat malware (Record) 

Common TTPs of attacks against industrial organizations. Implants for uploading data (Kaspersky ICS CERT)

APT31 Linked to Recent Industrial Attacks in Eastern Europe (Infosecurity Magazine) 

Researchers Shed Light on APT31's Advanced Backdoors and Data Exfiltration Tactics (The Hacker News) 

LOLEKHosted admin arrested for aiding Netwalker ransomware gang (BleepingComputer)

Russian spy agencies targeting Starlink with custom malware, Ukraine warns (The Telegraph)

Russia Bans iPhones And iPads For Official Use: Report (BW Businessworld)

Microsoft Suspends Extending Licenses For Companies in Russia (RadioFreeEurope/RadioLiberty) 

Department of Homeland Security’s Cyber Safety Review Board to Conduct Review on Cloud Security (US Department of Homeland Security)

Microsoft Exchange hack is focus of cyber board’s next review (Record) 

Microsoft is under scrutiny after a recent attack by suspected Chinese hackers (Windows Central) 

The DHS’s CSRB to review cloud security practices following the hack of Microsoft Exchange govt email accounts (Security Affairs)

Microsoft's role in data breach by Chinese hackers to be part of US cyber inquiry (Firstpost)

Extract Knowledge
Listen elsewhere

Dr. Georgianna Shea, the Chief Technologist at the Transformative Cyber Innovation Lab at the Foundations for Defensive Democracies (FDD) sits down to share her incredible story, moving around to different roles and how that has lead her to where she is today. Her careers have taken her to many different states throughout the years, as she has learned and grew into the roles she took on, from Hawaii to D.C., Dr. Shea has done it all. Sharing some advice, Dr. Shea says "My words of wisdom are take advantage of every opportunity and don't wait for anybody. I try to mentor people and I talk to young people a lot, you know, trying to get into the field and, and I see a lot of waiting on other people." She explains that you are able to work on your own to become an expert, and taking that initiative will be the thing to get you to where you want to be. We thank Dr. Georgianna Shea for sharing her story with us.

More description

Dr. Georgianna Shea, the Chief Technologist at the Transformative Cyber Innovation Lab at the Foundations for Defensive Democracies (FDD) sits down to share her incredible story, moving around to different roles and how that has lead her to where she is today. Her careers have taken her to many different states throughout the years, as she has learned and grew into the roles she took on, from Hawaii to D.C., Dr. Shea has done it all. Sharing some advice, Dr. Shea says "My words of wisdom are take advantage of every opportunity and don't wait for anybody. I try to mentor people and I talk to young people a lot, you know, trying to get into the field and, and I see a lot of waiting on other people." She explains that you are able to work on your own to become an expert, and taking that initiative will be the thing to get you to where you want to be. We thank Dr. Georgianna Shea for sharing her story with us.

Extract Knowledge
Listen elsewhere

Alex Delamotte from SentinelLabs joins Dave to discuss their work on "Cloudy With a Chance of Credentials | AWS-Targeting Cred Stealer Expands to Azure, GCP." As actors find more ways to profit from compromising services, SentinelLabs finds that cloud service credentials are becoming increasingly targeted.

The lack of threats explicitly targeting Azure and GCP credentials up to this point means there are likely many fresh targets. The research states "These campaigns share similarity with tools attributed to the notorious TeamTNT cryptojacking crew. However, attribution remains challenging with script-based tools, as anyone can adapt the code for their own use."

The research can be found here:

More description

Alex Delamotte from SentinelLabs joins Dave to discuss their work on "Cloudy With a Chance of Credentials | AWS-Targeting Cred Stealer Expands to Azure, GCP." As actors find more ways to profit from compromising services, SentinelLabs finds that cloud service credentials are becoming increasingly targeted.

The lack of threats explicitly targeting Azure and GCP credentials up to this point means there are likely many fresh targets. The research states "These campaigns share similarity with tools attributed to the notorious TeamTNT cryptojacking crew. However, attribution remains challenging with script-based tools, as anyone can adapt the code for their own use."

The research can be found here:

Extract Knowledge
Listen elsewhere

Charming Kitten collects against Iranian expatriate dissidents. The Cyber Safety Review Board reports on Lapsus$. A Call for comment on open-source, memory-safe standards. How NSA is coping with the cyber labor market. Yandex is restructuring. The Washington Post’s Tim Starks joins us with the latest cyber security efforts from the DOD. Our guest is Dan L. Dodson, CEO of Fortified Health Security with insights on protecting patient data. And How Viasat was hacked.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/153


Selected reading.

Germany says Charming Kitten hackers target Iran dissidents (Deutsche Welle)

Cyber Safety Review Board Releases Report on Activities of Global Extortion-Focused Hacker Group Lapsus$ (US Department of Homeland Security) 

Review Of The Attacks Associated with Lapsus$ And Related Threat Groups Report (Cybersecurity and Infrastructure Security Agency CISA)

Fact Sheet: Office of the National Cyber Director Requests Public Comment on Open-Source Software Security and Memory Safe Programming Languages (ONCD | The White House) 

Amid historic hiring surge, NSA considers hybrid, unclassified work options (Federal News Network)

Exclusive: Fear of tech 'brain drain' prevents Russia from seizing Yandex for now, sources say (Reuters)

Yandex co-founder Volozh slams Russia's 'barbaric' invasion of Ukraine (Reuters) 

Satellite hack on eve of Ukraine war was a coordinated, multi-pronged assault (CyberScoop)

More description

Charming Kitten collects against Iranian expatriate dissidents. The Cyber Safety Review Board reports on Lapsus$. A Call for comment on open-source, memory-safe standards. How NSA is coping with the cyber labor market. Yandex is restructuring. The Washington Post’s Tim Starks joins us with the latest cyber security efforts from the DOD. Our guest is Dan L. Dodson, CEO of Fortified Health Security with insights on protecting patient data. And How Viasat was hacked.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/153


Selected reading.

Germany says Charming Kitten hackers target Iran dissidents (Deutsche Welle)

Cyber Safety Review Board Releases Report on Activities of Global Extortion-Focused Hacker Group Lapsus$ (US Department of Homeland Security) 

Review Of The Attacks Associated with Lapsus$ And Related Threat Groups Report (Cybersecurity and Infrastructure Security Agency CISA)

Fact Sheet: Office of the National Cyber Director Requests Public Comment on Open-Source Software Security and Memory Safe Programming Languages (ONCD | The White House) 

Amid historic hiring surge, NSA considers hybrid, unclassified work options (Federal News Network)

Exclusive: Fear of tech 'brain drain' prevents Russia from seizing Yandex for now, sources say (Reuters)

Yandex co-founder Volozh slams Russia's 'barbaric' invasion of Ukraine (Reuters) 

Satellite hack on eve of Ukraine war was a coordinated, multi-pronged assault (CyberScoop)

Extract Knowledge
Listen elsewhere

A New Magento campaign is discovered. Gootloader malware-as-a-service afflicts law firms. Researchers find security flaws affecting cryptowallets. Panasonic warns of increasing attacks against IoT. A Belarusian cyberespionage campaign outlined. The five cyber phases of Russia's hybrid war, and lessons in resilience from Ukraine's experience. In our Threat Vector segment, Kristopher Russo, Senior Threat Researcher for Unit 42 joins David Moulton to discuss Muddled Libra. Kayla Williams from Devo describes their work benefiting the community at BlackHat. And a new DARPA challenge seeks to bring artificial intelligence to cybersecurity.

On this segment of Threat Vector, Kristopher Russo, Senior Threat Researcher for Unit 42, joins host David Moulton to discuss part one of two Muddled Libra.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/152


Threat Vector links.

Threat Group Assessment: Muddled Libra

Guest: Kristopher Russo: From practitioner to researcher Kristopher Russo has spent years entrenched in various specializations of cybersecurity. As a researcher focused on ransomware and cybercrime he brings a from the trenches perspective to cyber threat intelligence.


Selected reading.

Xurum: New Magento Campaign Discovered (Akamai)

Gootloader: Why your Legal Document Search May End in Misery (Trustwave)

Fireblocks Researchers Uncover Vulnerabilities Impacting Dozens of Major Wallet Providers (Fireblocks)

New BitForge cryptocurrency wallet flaws lets hackers steal crypto (BleepingCompute

Panasonic Warns That IoT Malware Attack Cycles Are Accelerating (WIRED) 

MoustachedBouncer: Espionage against foreign diplomats in Belarus (We Live Security) 

Belarus hackers target foreign diplomats with help of local ISPs, researchers say (TechCrunch) 

Pro-Russian hackers claim attacks on French, Dutch websites (Record) 

Zhora: Russia's cyber 'war crimes' will outlast invasion (Register)

The Power of Resilience (Cybersecurity and Infrastructure Security Agency CISA)

Biden-Harris Administration Launches Artificial Intelligence Cyber Challenge to Protect America’s Critical Software (The White House)

AIxCC (AIxCC)

The Biden administration wants to put AI to the test for cybersecurity (Washington Post)

More description

A New Magento campaign is discovered. Gootloader malware-as-a-service afflicts law firms. Researchers find security flaws affecting cryptowallets. Panasonic warns of increasing attacks against IoT. A Belarusian cyberespionage campaign outlined. The five cyber phases of Russia's hybrid war, and lessons in resilience from Ukraine's experience. In our Threat Vector segment, Kristopher Russo, Senior Threat Researcher for Unit 42 joins David Moulton to discuss Muddled Libra. Kayla Williams from Devo describes their work benefiting the community at BlackHat. And a new DARPA challenge seeks to bring artificial intelligence to cybersecurity.

On this segment of Threat Vector, Kristopher Russo, Senior Threat Researcher for Unit 42, joins host David Moulton to discuss part one of two Muddled Libra.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/152


Threat Vector links.

Threat Group Assessment: Muddled Libra

Guest: Kristopher Russo: From practitioner to researcher Kristopher Russo has spent years entrenched in various specializations of cybersecurity. As a researcher focused on ransomware and cybercrime he brings a from the trenches perspective to cyber threat intelligence.


Selected reading.

Xurum: New Magento Campaign Discovered (Akamai)

Gootloader: Why your Legal Document Search May End in Misery (Trustwave)

Fireblocks Researchers Uncover Vulnerabilities Impacting Dozens of Major Wallet Providers (Fireblocks)

New BitForge cryptocurrency wallet flaws lets hackers steal crypto (BleepingCompute

Panasonic Warns That IoT Malware Attack Cycles Are Accelerating (WIRED) 

MoustachedBouncer: Espionage against foreign diplomats in Belarus (We Live Security) 

Belarus hackers target foreign diplomats with help of local ISPs, researchers say (TechCrunch) 

Pro-Russian hackers claim attacks on French, Dutch websites (Record) 

Zhora: Russia's cyber 'war crimes' will outlast invasion (Register)

The Power of Resilience (Cybersecurity and Infrastructure Security Agency CISA)

Biden-Harris Administration Launches Artificial Intelligence Cyber Challenge to Protect America’s Critical Software (The White House)

AIxCC (AIxCC)

The Biden administration wants to put AI to the test for cybersecurity (Washington Post)

Extract Knowledge
Listen elsewhere

Reports of a Wide-ranging cyberespionage campaign by China's Ministry of State Security. EvilProxy phishing tool targets executives, and defeats multifactor authentication. Vulnerabilities in CPUs. Yashma ransomware targets a wide range of countries. MacOS threat trends. Is there a Russian attempt to disrupt British elections? Rob Boyce from Accenture checks in from the Blackhat conference. Maria Varmazis talking with Black Hat Aerospace Village's Kaylin Trychon and Steve Luczynski. Ukraine claims to have stopped a Russian spyware campaign. And Patch Tuesday has come and gone, but the vulnerabilities remain–unless, of course, you’ve applied the patches.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/151


Selected reading.

Chinese hackers targeted at least 17 countries across Asia, Europe and North America (Record)

RedHotel: A Prolific, Chinese State-Sponsored Group Operating at a Global Scale (Recorded Future)

Cloud Account Takeover Campaign Leveraging EvilProxy Targets Top-Level Executives at over 100 Global Organizations (Proofpoint) 

‘Downfall’ vulnerability leaves billions of Intel CPUs at risk  (CyberScoop) 

New Inception attack leaks sensitive data from all AMD Zen CPUs (BleepingComputer)

New Yashma Ransomware Variant Targets Multiple English-Speaking Countries (The Hacker News) 

Suspected Vietnamese hacker targets Chinese, Bulgarian organizations with new ransomware (Record)

Black Hat USA 2023 – Bitdefender macOS Threat Report Reveals Key Dangers for Mac Users (Bitdefender) 

Russia ‘tops list of suspects’ in cyber attack which exposed data of 40m UK voters (The Telegraph)

Electoral Commission hack: Five things you need to know (Computing)

‘Hostile actors’ hacked British voter registry, electoral agency says (Washington Post)

Electoral Commission apologises for security breach involving UK voters’ data (the Guardian) 

Ukraine says it prevented Russian hacking of armed forces combat system (Reuters) 

Ukraine says it thwarted attempt to breach military tablets (Record)

Russian secret services try to penetrate operation planning electronic system of Ukraine's army (Ukrainska Pravda)

Patch Tuesday: Adobe Patches 30 Acrobat, Reader Vulns (SecurityWeek) 

Patch Tuesday: Microsoft (Finally) Patches Exploited Office Zero-Days (SecurityWeek)

Microsoft Releases August 2023 Security Updates (Cybersecurity and Infrastructure Security Agency CISA)

Fortinet Releases Security Update for FortiOS (Cybersecurity and Infrastructure Security Agency CISA)

Adobe Releases Security Updates for Multiple Products (Cybersecurity and Infrastructure Security Agency CISA) 

Patch Tuesday review: August 2023. (CyberWire)

More description

Reports of a Wide-ranging cyberespionage campaign by China's Ministry of State Security. EvilProxy phishing tool targets executives, and defeats multifactor authentication. Vulnerabilities in CPUs. Yashma ransomware targets a wide range of countries. MacOS threat trends. Is there a Russian attempt to disrupt British elections? Rob Boyce from Accenture checks in from the Blackhat conference. Maria Varmazis talking with Black Hat Aerospace Village's Kaylin Trychon and Steve Luczynski. Ukraine claims to have stopped a Russian spyware campaign. And Patch Tuesday has come and gone, but the vulnerabilities remain–unless, of course, you’ve applied the patches.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/151


Selected reading.

Chinese hackers targeted at least 17 countries across Asia, Europe and North America (Record)

RedHotel: A Prolific, Chinese State-Sponsored Group Operating at a Global Scale (Recorded Future)

Cloud Account Takeover Campaign Leveraging EvilProxy Targets Top-Level Executives at over 100 Global Organizations (Proofpoint) 

‘Downfall’ vulnerability leaves billions of Intel CPUs at risk  (CyberScoop) 

New Inception attack leaks sensitive data from all AMD Zen CPUs (BleepingComputer)

New Yashma Ransomware Variant Targets Multiple English-Speaking Countries (The Hacker News) 

Suspected Vietnamese hacker targets Chinese, Bulgarian organizations with new ransomware (Record)

Black Hat USA 2023 – Bitdefender macOS Threat Report Reveals Key Dangers for Mac Users (Bitdefender) 

Russia ‘tops list of suspects’ in cyber attack which exposed data of 40m UK voters (The Telegraph)

Electoral Commission hack: Five things you need to know (Computing)

‘Hostile actors’ hacked British voter registry, electoral agency says (Washington Post)

Electoral Commission apologises for security breach involving UK voters’ data (the Guardian) 

Ukraine says it prevented Russian hacking of armed forces combat system (Reuters) 

Ukraine says it thwarted attempt to breach military tablets (Record)

Russian secret services try to penetrate operation planning electronic system of Ukraine's army (Ukrainska Pravda)

Patch Tuesday: Adobe Patches 30 Acrobat, Reader Vulns (SecurityWeek) 

Patch Tuesday: Microsoft (Finally) Patches Exploited Office Zero-Days (SecurityWeek)

Microsoft Releases August 2023 Security Updates (Cybersecurity and Infrastructure Security Agency CISA)

Fortinet Releases Security Update for FortiOS (Cybersecurity and Infrastructure Security Agency CISA)

Adobe Releases Security Updates for Multiple Products (Cybersecurity and Infrastructure Security Agency CISA) 

Patch Tuesday review: August 2023. (CyberWire)

Extract Knowledge
Listen elsewhere

Reports on a 2020 Chinese penetration of Japan's defense networks. MOVEit-connected supply chain issues aren't over. Akamai looks at the current state of ransomware. Mallox ransomware continues its evolution. Machine identities and shadow access. Ukrainian hacktivist auxiliaries hit Russian websites. Joe Carrigan unpacks statistics recently released by CISA. Our guest is Jeffrey Wheatman from Black Kite discussing the market shift from SRS to cyber risk intelligence. And radiation sensor reports from Chernobyl may have been manipulated.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/150


Selected reading.

China hacked Japan’s sensitive defense networks, officials say (Washington Post) 

Japan says cannot confirm leakage after report says China hacked defence networks (Reuters)

MOVEit hack spawned around 600 breaches but isn't done yet - cyber analysts (Reuters)

Mallox Ransomware Group Revamps Malware Variants, Evasion Tactics (Dark Reading)

TargetCompany Ransomware Abuses FUD Obfuscator Packers (Trend Micro)

New IAM Research by Stack Identity Finds Machine Identities Dominate Shadow Access in the Cloud, Revealing Easy Attack Vector for Hackers (Business Wire)

Ukraine-Linked Group Claims It Hacked Website Of Moscow Property Registration Bureau (RadioFreeEurope/RadioLiberty)

Ukraine-linked group claims it hacked Moscow property registration bureau website – RFE/RL (Euromaidan Press)

Pro-Ukrainian hackers breach Moscow engineering service website (New Voice of Ukraine)

Ukrainian state agencies targeted with open-source malware MerlinAgent (Record)

The Mystery of Chernobyl’s Post-Invasion Radiation Spikes (WIRED) 

More description

Reports on a 2020 Chinese penetration of Japan's defense networks. MOVEit-connected supply chain issues aren't over. Akamai looks at the current state of ransomware. Mallox ransomware continues its evolution. Machine identities and shadow access. Ukrainian hacktivist auxiliaries hit Russian websites. Joe Carrigan unpacks statistics recently released by CISA. Our guest is Jeffrey Wheatman from Black Kite discussing the market shift from SRS to cyber risk intelligence. And radiation sensor reports from Chernobyl may have been manipulated.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/150


Selected reading.

China hacked Japan’s sensitive defense networks, officials say (Washington Post) 

Japan says cannot confirm leakage after report says China hacked defence networks (Reuters)

MOVEit hack spawned around 600 breaches but isn't done yet - cyber analysts (Reuters)

Mallox Ransomware Group Revamps Malware Variants, Evasion Tactics (Dark Reading)

TargetCompany Ransomware Abuses FUD Obfuscator Packers (Trend Micro)

New IAM Research by Stack Identity Finds Machine Identities Dominate Shadow Access in the Cloud, Revealing Easy Attack Vector for Hackers (Business Wire)

Ukraine-Linked Group Claims It Hacked Website Of Moscow Property Registration Bureau (RadioFreeEurope/RadioLiberty)

Ukraine-linked group claims it hacked Moscow property registration bureau website – RFE/RL (Euromaidan Press)

Pro-Ukrainian hackers breach Moscow engineering service website (New Voice of Ukraine)

Ukrainian state agencies targeted with open-source malware MerlinAgent (Record)

The Mystery of Chernobyl’s Post-Invasion Radiation Spikes (WIRED) 

Extract Knowledge
Listen elsewhere

North Korean cyberespionage against a Russian aerospace firm. The Reptile rootkit is used against South Korean systems. An update on Cloudzy. Cl0p is using torrents to move data stolen in MOVEit exploitation. Andrea Little Limbago from Interos wonders about the dangers of jumping head first into new technologies? Rick Howard ponders quantum computing. And Meduza is back on Apple Podcasts.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/149


Selected reading.

Exclusive: North Korean hackers breached top Russian missile maker (Reuters)

North Korean hackers stole secrets of Russian hypersonic missile maker (Euractiv) 

Comrades in Arms? | North Korea Compromises Sanctioned Russian Missile Engineering Company (SentinelOne)

Reptile Rootkit: Advanced Linux Malware Targeting South Korean Systems (The Hacker News) 

UPDATE: Cloudzy Command and Control Provider Report (Halcyon)

Reptile Rootkit: Advanced Linux Malware Targeting South Korean Systems (The Hacker News)

Clop ransomware now uses torrents to leak data and evade takedowns (BleepingComputer)

Ukraine may be winning ‘world’s first cyberwar’ (The Kyiv Independent)

Apple has removed Meduza’s flagship news podcast ‘What Happened’ from Apple Podcasts, without explaining the reason (Meduza)

More description

North Korean cyberespionage against a Russian aerospace firm. The Reptile rootkit is used against South Korean systems. An update on Cloudzy. Cl0p is using torrents to move data stolen in MOVEit exploitation. Andrea Little Limbago from Interos wonders about the dangers of jumping head first into new technologies? Rick Howard ponders quantum computing. And Meduza is back on Apple Podcasts.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/149


Selected reading.

Exclusive: North Korean hackers breached top Russian missile maker (Reuters)

North Korean hackers stole secrets of Russian hypersonic missile maker (Euractiv) 

Comrades in Arms? | North Korea Compromises Sanctioned Russian Missile Engineering Company (SentinelOne)

Reptile Rootkit: Advanced Linux Malware Targeting South Korean Systems (The Hacker News) 

UPDATE: Cloudzy Command and Control Provider Report (Halcyon)

Reptile Rootkit: Advanced Linux Malware Targeting South Korean Systems (The Hacker News)

Clop ransomware now uses torrents to leak data and evade takedowns (BleepingComputer)

Ukraine may be winning ‘world’s first cyberwar’ (The Kyiv Independent)

Apple has removed Meduza’s flagship news podcast ‘What Happened’ from Apple Podcasts, without explaining the reason (Meduza)

Extract Knowledge
Listen elsewhere

Manuel Hepfer a cybersecurity researcher from ISTARI sits down to share his story with us. Manuel shares as a kid he was very interested in STEM, and in school he remembered a programming class that he fell in love which made him want to pursue a career in cyber. Studying at the University of Oxford he began working towards acquiring a degree in Cybersecurity and Strategic Management. He found research to be a passion and wanted to share his passion, he decided he wanted to publish, so Manuel published an article in MIT Sloan management review that's titled "Make Cybersecurity a Strategic Asset." He shares that finding a passion, like he did, is the key to working in cyber, saying "I think what I learned at the time is the value of discipline and self motivation. And now you can always come up with a lot of discipline and self motivation, but you'll run out of steam at some point if you're not very passionate about some of the things that you're doing." We thank Manuel for sharing his story with us.

More description

Manuel Hepfer a cybersecurity researcher from ISTARI sits down to share his story with us. Manuel shares as a kid he was very interested in STEM, and in school he remembered a programming class that he fell in love which made him want to pursue a career in cyber. Studying at the University of Oxford he began working towards acquiring a degree in Cybersecurity and Strategic Management. He found research to be a passion and wanted to share his passion, he decided he wanted to publish, so Manuel published an article in MIT Sloan management review that's titled "Make Cybersecurity a Strategic Asset." He shares that finding a passion, like he did, is the key to working in cyber, saying "I think what I learned at the time is the value of discipline and self motivation. And now you can always come up with a lot of discipline and self motivation, but you'll run out of steam at some point if you're not very passionate about some of the things that you're doing." We thank Manuel for sharing his story with us.

Extract Knowledge
Listen elsewhere

Aleksandar Milenkoski from SentinelOne joins to discuss their work on "Kimsuky Strikes Again | New Social Engineering Campaign Aims to Steal Credentials and Gather Strategic Intelligence." Researchers have been tracking the North Korean APT group Kimsuky and their attempt at a social engineering campaign targeting experts in North Korean affairs.

The research states "The campaign has the objective of stealing Google and subscription credentials of a reputable news and analysis service focusing on North Korea, as well as delivering reconnaissance malware." Kimsuky has been tracked engaging in extensive email correspondence using spoofed URLs and extensive email correspondence, along with Office documents weaponized with the ReconShark malware.

The research can be found here:

More description

Aleksandar Milenkoski from SentinelOne joins to discuss their work on "Kimsuky Strikes Again | New Social Engineering Campaign Aims to Steal Credentials and Gather Strategic Intelligence." Researchers have been tracking the North Korean APT group Kimsuky and their attempt at a social engineering campaign targeting experts in North Korean affairs.

The research states "The campaign has the objective of stealing Google and subscription credentials of a reputable news and analysis service focusing on North Korea, as well as delivering reconnaissance malware." Kimsuky has been tracked engaging in extensive email correspondence using spoofed URLs and extensive email correspondence, along with Office documents weaponized with the ReconShark malware.

The research can be found here:

Extract Knowledge
Listen elsewhere

The Five Eyes warn against top exploited vulnerabilities. The Rilide info stealer in the wild. Malicious PyPI packages. Valerie Abend, Global Cyber Strategy Lead from Accenture, unpacks the Securities and Exchange Commission’s recently announced cyber regulations. In our Solution spotlight: Our own Simone Patrella speaks with Microsoft’s Ann Johnson on how Microsoft is attracting and retaining top cyber talent. And cyber attacks continue to gutter on both sides of Russia's war against Ukraine.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/148


Selected reading.

CISA, NSA, FBI, and International Partners Release Joint CSA on Top Routinely Exploited Vulnerabilities of 2022 | CISA (Cybersecurity and Infrastructure Security Agency CISA)

CISA, NSA, FBI and International Partners Issue Advisory on the Top Routinely Exploited Vu (National Security Agency/Central Security Service)

New Rilide Stealer Version Targets Banking Data and Works Around Google Chrome Manifest V3 (Trustwave)

Tunnel Vision: CloudflareD AbuseD in the WilD (GuidePoint Security) 

VMConnect: Malicious PyPI packages imitate popular open source modules (ReversingLabs) 

Bilyana Lilly on how cybersecurity assistance to Ukraine has helped thwart Russian cyberattacks (CyberScoop)

Microsoft says Russia-linked hackers behind dozens of Teams phishing attacks (Reuters)

Ukraine's invisible battle to jam Russian weapons (BBC News)

How Ukraine’s cyberwarriors are upending everyday life in Russia (Times)

More description

The Five Eyes warn against top exploited vulnerabilities. The Rilide info stealer in the wild. Malicious PyPI packages. Valerie Abend, Global Cyber Strategy Lead from Accenture, unpacks the Securities and Exchange Commission’s recently announced cyber regulations. In our Solution spotlight: Our own Simone Patrella speaks with Microsoft’s Ann Johnson on how Microsoft is attracting and retaining top cyber talent. And cyber attacks continue to gutter on both sides of Russia's war against Ukraine.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/148


Selected reading.

CISA, NSA, FBI, and International Partners Release Joint CSA on Top Routinely Exploited Vulnerabilities of 2022 | CISA (Cybersecurity and Infrastructure Security Agency CISA)

CISA, NSA, FBI and International Partners Issue Advisory on the Top Routinely Exploited Vu (National Security Agency/Central Security Service)

New Rilide Stealer Version Targets Banking Data and Works Around Google Chrome Manifest V3 (Trustwave)

Tunnel Vision: CloudflareD AbuseD in the WilD (GuidePoint Security) 

VMConnect: Malicious PyPI packages imitate popular open source modules (ReversingLabs) 

Bilyana Lilly on how cybersecurity assistance to Ukraine has helped thwart Russian cyberattacks (CyberScoop)

Microsoft says Russia-linked hackers behind dozens of Teams phishing attacks (Reuters)

Ukraine's invisible battle to jam Russian weapons (BBC News)

How Ukraine’s cyberwarriors are upending everyday life in Russia (Times)

Extract Knowledge
Listen elsewhere

Open Bullet malware is seen in the wild. Threat actors exploit a Salesforce vulnerability for phishing. BlueCharlie (that’s Russia’s FSB) shakes up its infrastructure. Midnight Blizzard (and that’s Russia’s SVR) uses targeted social engineering. How NoName057(16) moved on to Spanish targets. Robert M. Lee from Dragos shares his reaction to the White House’s national cybersecurity strategy. Our guest Raj Ananthanpillai of Trua warns against oversharing with ChatGPT. And NSA releases guidance on hardening Cisco next-generation firewalls.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/147


Selected reading.

No Honour Amongst Thieves: A New OpenBullet Malware Campaign (Kasada)

“PhishForce” — Vulnerability Uncovered in Salesforce’s Email Services Exploited for Phishing… (Medium)

Hackers exploited Salesforce zero-day in Facebook phishing attack (BleepingComputer)

Hackers exploit Salesforce email zero-day for Facebook phishing campaign (Computing) 

Russia-based hackers building new attack infrastructure to stay ahead of public reporting (Record) 

Midnight Blizzard conducts targeted social engineering over Microsoft Teams (Microsoft Security) 

Unraveling Russian Multi-Sector DDoS Attacks Across Spain (Radware)

Pro-Russian Hackers Claim Cyberattacks on Italian Banks (MarketWatch) 

NSA Releases Guide to Harden Cisco Next Generation Firewalls (National Security Agency/Central Security Service)

Cisco Firepower Hardening Guide (US National Security Agency)

More description

Open Bullet malware is seen in the wild. Threat actors exploit a Salesforce vulnerability for phishing. BlueCharlie (that’s Russia’s FSB) shakes up its infrastructure. Midnight Blizzard (and that’s Russia’s SVR) uses targeted social engineering. How NoName057(16) moved on to Spanish targets. Robert M. Lee from Dragos shares his reaction to the White House’s national cybersecurity strategy. Our guest Raj Ananthanpillai of Trua warns against oversharing with ChatGPT. And NSA releases guidance on hardening Cisco next-generation firewalls.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/147


Selected reading.

No Honour Amongst Thieves: A New OpenBullet Malware Campaign (Kasada)

“PhishForce” — Vulnerability Uncovered in Salesforce’s Email Services Exploited for Phishing… (Medium)

Hackers exploited Salesforce zero-day in Facebook phishing attack (BleepingComputer)

Hackers exploit Salesforce email zero-day for Facebook phishing campaign (Computing) 

Russia-based hackers building new attack infrastructure to stay ahead of public reporting (Record) 

Midnight Blizzard conducts targeted social engineering over Microsoft Teams (Microsoft Security) 

Unraveling Russian Multi-Sector DDoS Attacks Across Spain (Radware)

Pro-Russian Hackers Claim Cyberattacks on Italian Banks (MarketWatch) 

NSA Releases Guide to Harden Cisco Next Generation Firewalls (National Security Agency/Central Security Service)

Cisco Firepower Hardening Guide (US National Security Agency)

Extract Knowledge
Listen elsewhere

An illicit market in account restoration. Resilience and the cyber workforce. New post-exploitation techniques in Amazon Web Services. Incursions into Norwegian government networks went on for four months. Rob Boyce from Accenture Security describes a “Perfect Storm” in the Dark Web threat landscape. Carole Theriault shares mental health social media warnings for teens. And the Russian legislation seeks to reduce or eliminate online privacy.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/146


Selected reading.

Amazon employees leak secret info that marketplace sellers can buy on Telegram (CNBC)

Cyber Workforce Benchmark Report (Immersive Labs)

Mitiga Security Advisory: Abusing the SSM Agent as a Remote Access Trojan (Mitiga)

Cado Security Labs 2023 Threat Findings Report (Cado Security)

Cyberattack on Norway Ministries Lasted at Least Four Months (Bloomberg)

CISA and International Partner NCSC-NO Release Joint Cybersecurity Advisory on Threat Actors Exploiting Ivanti EPMM Vulnerabilities (Cybersecurity and Infrastructure Security Agency)

Putin Outlaws Anonymity: Identity Verification For Online Services, VPN Bypass Advice a Crime (TorrentFreak)

Russia Is Returning to Its Totalitarian Past (Foreign Policy)

More description

An illicit market in account restoration. Resilience and the cyber workforce. New post-exploitation techniques in Amazon Web Services. Incursions into Norwegian government networks went on for four months. Rob Boyce from Accenture Security describes a “Perfect Storm” in the Dark Web threat landscape. Carole Theriault shares mental health social media warnings for teens. And the Russian legislation seeks to reduce or eliminate online privacy.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/146


Selected reading.

Amazon employees leak secret info that marketplace sellers can buy on Telegram (CNBC)

Cyber Workforce Benchmark Report (Immersive Labs)

Mitiga Security Advisory: Abusing the SSM Agent as a Remote Access Trojan (Mitiga)

Cado Security Labs 2023 Threat Findings Report (Cado Security)

Cyberattack on Norway Ministries Lasted at Least Four Months (Bloomberg)

CISA and International Partner NCSC-NO Release Joint Cybersecurity Advisory on Threat Actors Exploiting Ivanti EPMM Vulnerabilities (Cybersecurity and Infrastructure Security Agency)

Putin Outlaws Anonymity: Identity Verification For Online Services, VPN Bypass Advice a Crime (TorrentFreak)

Russia Is Returning to Its Totalitarian Past (Foreign Policy)

Extract Knowledge
Listen elsewhere

C2-as-a-service with APTs as the customers. Cyberespionage activity by Indian APTs. Gamers under attack. StarLink limits Ukrainian access to its systems. The EU levies new sanctions against “digital information manipulation.” Ukraine's Security Service takes down money-laundering exchanges. Ben Yelin unpacks fediverse security risks. Our guests are Mike Marty, CEO of The Retired Investigators Guild, & Tom Brennan, executive director of CREST, discussing their efforts on cybercrime investigation and cold case resolution. And Nozomi's OT IoT security report, sees a lot of opportunistic, low-grade whacking at industrial organizations.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/145


Selected reading.

Cloudzy with a Chance of Ransomware: Unmasking Command-and-Control Providers (C2Ps) (Halcyon) 

APT Bahamut Targets Individuals with Android Malware Using Spear Messaging - CYFIRMA (CYFIRMA) 

Hackers steal Signal, WhatsApp user data with fake Android chat app (BleepingComputer)

Patchwork Hackers Target Chinese Research Organizations Using EyeShell Backdoor (The Hacker News)

Hackers exploit BleedingPipe RCE to target Minecraft servers, players (BleepingComputer) 

Call of Duty Self-Spreading Worm Takes Aim at Player Lobbies (Dark Reading) 

Call of Duty worm malware used to hack players exploits years-old bug  (TechCrunch) 

Elon Musk 'refuses to turn on Starlink' for Crimea drone attack (The Telegraph)

How Elon Musk Was Able to Exert Control in Ukraine War (The Street)

EU strikes Russia again as digital infowar rages on (Cybernews) 

Ukraine Cracks Down on Illicit Financing Network (Gov Info Security) 

Unpacking the OT & IoT Threat Landscape with Unique Telemetry Data (Nozomi Networks) 

China's Volt Typhoon APT Burrows Deeper Into US Critical Infrastructure (Dark Reading)

More description

C2-as-a-service with APTs as the customers. Cyberespionage activity by Indian APTs. Gamers under attack. StarLink limits Ukrainian access to its systems. The EU levies new sanctions against “digital information manipulation.” Ukraine's Security Service takes down money-laundering exchanges. Ben Yelin unpacks fediverse security risks. Our guests are Mike Marty, CEO of The Retired Investigators Guild, & Tom Brennan, executive director of CREST, discussing their efforts on cybercrime investigation and cold case resolution. And Nozomi's OT IoT security report, sees a lot of opportunistic, low-grade whacking at industrial organizations.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/145


Selected reading.

Cloudzy with a Chance of Ransomware: Unmasking Command-and-Control Providers (C2Ps) (Halcyon) 

APT Bahamut Targets Individuals with Android Malware Using Spear Messaging - CYFIRMA (CYFIRMA) 

Hackers steal Signal, WhatsApp user data with fake Android chat app (BleepingComputer)

Patchwork Hackers Target Chinese Research Organizations Using EyeShell Backdoor (The Hacker News)

Hackers exploit BleedingPipe RCE to target Minecraft servers, players (BleepingComputer) 

Call of Duty Self-Spreading Worm Takes Aim at Player Lobbies (Dark Reading) 

Call of Duty worm malware used to hack players exploits years-old bug  (TechCrunch) 

Elon Musk 'refuses to turn on Starlink' for Crimea drone attack (The Telegraph)

How Elon Musk Was Able to Exert Control in Ukraine War (The Street)

EU strikes Russia again as digital infowar rages on (Cybernews) 

Ukraine Cracks Down on Illicit Financing Network (Gov Info Security) 

Unpacking the OT & IoT Threat Landscape with Unique Telemetry Data (Nozomi Networks) 

China's Volt Typhoon APT Burrows Deeper Into US Critical Infrastructure (Dark Reading)

Extract Knowledge
Listen elsewhere

The US issues a National Cyber Workforce and Education strategy. Hunting Chinese malware staged in US networks. CISA warns of Barracuda backdoor. WikiLoader malware is discovered. P2Pinfect is a malware botnet targeting publicly-accessible Redis servers. Johannes Ullrich from SANS describes attacks against YouTube content creators. Rick Howard previews his conversation with AWS Ciso CJ Moses. And Russia’s SVR continues cyberespionage against Ukrainian and European diplomatic services.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/144


Selected reading.

FACT SHEET: Biden-Harris Administration Announces National Cyber Workforce and Education Strategy, Unleashing America’s Cyber Talent (The White House) 

National Cyber Workforce and Education Strategy: Unleashing America’s Cyber Talent (The White House)

The White House releases the US National Cyber Workforce and Education Strategy. (CyberWire)

US hunts Chinese malware staged to interfere with US military operations. (CyberWire)

U.S. Hunts Chinese Malware That Could Disrupt American Military Operations (New York Times)

CISA Releases Malware Analysis Reports on Barracuda Backdoors (Cybersecurity and Infrastructure Security Agency CISA)CISA: New Submarine malware found on hacked Barracuda ESG appliances (BleepingComputer) 

Out of the Sandbox: WikiLoader Digs Sophisticated Evasion (Proofpoint) 

Cado Security Labs Encounter Novel Malware, Redis P2Pinfect (Cado Security) 

P2PInfect: The Rusty Peer-to-Peer Self-Replicating Worm (Unit 42)

BlueBravo Adapts to Target Diplomatic Entities with GraphicalProton Malware (Recorded Future)

BlueBravo Adapts to Target Diplomatic Entities with GraphicalProton Malware (Recorded Future Insikt Group) 

BlueBravo Deploys GraphicalProton Backdoor Against European Diplomatic Entities (The Hacker News)

More description

The US issues a National Cyber Workforce and Education strategy. Hunting Chinese malware staged in US networks. CISA warns of Barracuda backdoor. WikiLoader malware is discovered. P2Pinfect is a malware botnet targeting publicly-accessible Redis servers. Johannes Ullrich from SANS describes attacks against YouTube content creators. Rick Howard previews his conversation with AWS Ciso CJ Moses. And Russia’s SVR continues cyberespionage against Ukrainian and European diplomatic services.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/144


Selected reading.

FACT SHEET: Biden-Harris Administration Announces National Cyber Workforce and Education Strategy, Unleashing America’s Cyber Talent (The White House) 

National Cyber Workforce and Education Strategy: Unleashing America’s Cyber Talent (The White House)

The White House releases the US National Cyber Workforce and Education Strategy. (CyberWire)

US hunts Chinese malware staged to interfere with US military operations. (CyberWire)

U.S. Hunts Chinese Malware That Could Disrupt American Military Operations (New York Times)

CISA Releases Malware Analysis Reports on Barracuda Backdoors (Cybersecurity and Infrastructure Security Agency CISA)CISA: New Submarine malware found on hacked Barracuda ESG appliances (BleepingComputer) 

Out of the Sandbox: WikiLoader Digs Sophisticated Evasion (Proofpoint) 

Cado Security Labs Encounter Novel Malware, Redis P2Pinfect (Cado Security) 

P2PInfect: The Rusty Peer-to-Peer Self-Replicating Worm (Unit 42)

BlueBravo Adapts to Target Diplomatic Entities with GraphicalProton Malware (Recorded Future)

BlueBravo Adapts to Target Diplomatic Entities with GraphicalProton Malware (Recorded Future Insikt Group) 

BlueBravo Deploys GraphicalProton Backdoor Against European Diplomatic Entities (The Hacker News)

Extract Knowledge
Listen elsewhere

Morgan Adamski from the National Security Agency (NSA) sits down to talk about her path to getting into cybersecurity. Remembering back to when she was a kid, she recalls using old technology to chat with friends online, that's where it all began for Morgan. She shares how in high school she fell in love with the concept of debating and being on a team. During her high school career, 9/11 occurred, and she became fascinated with who was behind the biggest attack America had seen in the 21st century, driving her to pursue a degree in National Security. Coming out of college, she was able to get a job in the DIA, after working there for two years, she found herself at the NSA, where she is now. Morgan shares how her leadership style helps her to not only connect dots on problems, but also see around corners, saying "it's not just about connecting the dots, it's about seeing around the corners and so that helps me better predict, um, how do I build an organization that's successful three to five years down the road." We thank Morgan for sharing her story with us.

More description

Morgan Adamski from the National Security Agency (NSA) sits down to talk about her path to getting into cybersecurity. Remembering back to when she was a kid, she recalls using old technology to chat with friends online, that's where it all began for Morgan. She shares how in high school she fell in love with the concept of debating and being on a team. During her high school career, 9/11 occurred, and she became fascinated with who was behind the biggest attack America had seen in the 21st century, driving her to pursue a degree in National Security. Coming out of college, she was able to get a job in the DIA, after working there for two years, she found herself at the NSA, where she is now. Morgan shares how her leadership style helps her to not only connect dots on problems, but also see around corners, saying "it's not just about connecting the dots, it's about seeing around the corners and so that helps me better predict, um, how do I build an organization that's successful three to five years down the road." We thank Morgan for sharing her story with us.

Extract Knowledge
Listen elsewhere
Published 2023-07-29

Phishing for leeches. [Research Saturday]

19 min
View

Ashlee Benge from ReversingLabs discussing their research titled "Operation Brainleeches: Malicious npm packages fuel supply chain and phishing attacks." Researchers recently discovered over a dozen malicious packages published to the npm open source repository. These packages are targeting Microsoft 365 users and appear to target application end users while also supporting email phishing campaigns.

Research supports that the malicious campaign encompassed more than a dozen files designed to steal sensitive user credentials. The research states "This most recent campaign caught our attention because of a number of features and characteristics in related npm packages that correlate with malicious intent."

The research can be found here:

More description

Ashlee Benge from ReversingLabs discussing their research titled "Operation Brainleeches: Malicious npm packages fuel supply chain and phishing attacks." Researchers recently discovered over a dozen malicious packages published to the npm open source repository. These packages are targeting Microsoft 365 users and appear to target application end users while also supporting email phishing campaigns.

Research supports that the malicious campaign encompassed more than a dozen files designed to steal sensitive user credentials. The research states "This most recent campaign caught our attention because of a number of features and characteristics in related npm packages that correlate with malicious intent."

The research can be found here:

Extract Knowledge
Listen elsewhere

A joint warning on IDOR vulnerabilities. IcedID’s BackConnect protocol evolves over one year. Cl0p claims to have accessed data from another Big Four accounting firm. Ransomware victims increased significantly in 2023. Cyberattacks support influence operations. Deputy National Security Advisor for Cyber and Emerging Technology Anne Neuberger joins us to discuss the Biden Administration's recent cyber initiatives. Eric Goldstein, Executive Assistant Director at CISA, looks at cybersecurity performance goals. And spelling counts.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/143


Selected reading.

Preventing Web Application Access Control Abuse (Joint Cybersecurity Advisory: ACSC, NSA, CISA) 

Inside the IcedID BackConnect Protocol (Part 2) (Team Cymru) 

Deloitte denies Cl0p data breach impacted client data in wake of MOVEit attack (ITPro) 

Ransomware Report: Q2 2023 (ReliaQuest)

Kenya ICT minister admits cyber-attack on eCitizen portal, insists data secure (The East African)

Anonymous Sudan: the group behind recent anti-Kenya cyberattacks (TechCabal) 

Kenya President Ruto to skip Russia-Africa Summit (The East African)

UK accidentally sent military emails meant for US to Russian ally (POLITICO)

More description

A joint warning on IDOR vulnerabilities. IcedID’s BackConnect protocol evolves over one year. Cl0p claims to have accessed data from another Big Four accounting firm. Ransomware victims increased significantly in 2023. Cyberattacks support influence operations. Deputy National Security Advisor for Cyber and Emerging Technology Anne Neuberger joins us to discuss the Biden Administration's recent cyber initiatives. Eric Goldstein, Executive Assistant Director at CISA, looks at cybersecurity performance goals. And spelling counts.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/143


Selected reading.

Preventing Web Application Access Control Abuse (Joint Cybersecurity Advisory: ACSC, NSA, CISA) 

Inside the IcedID BackConnect Protocol (Part 2) (Team Cymru) 

Deloitte denies Cl0p data breach impacted client data in wake of MOVEit attack (ITPro) 

Ransomware Report: Q2 2023 (ReliaQuest)

Kenya ICT minister admits cyber-attack on eCitizen portal, insists data secure (The East African)

Anonymous Sudan: the group behind recent anti-Kenya cyberattacks (TechCabal) 

Kenya President Ruto to skip Russia-Africa Summit (The East African)

UK accidentally sent military emails meant for US to Russian ally (POLITICO)

Extract Knowledge
Listen elsewhere

The Mirai botnet afflicts Tomcat. CardioComm services are downed by cyberattack. Uptycs calls infostealers “organization killers" as related security incidents double in a year. Legacy third-party risk management practices meet with dissatisfaction. Cyber skill gaps reported in the UK's workforce. Our guest is George Prichici of OPSWAT with a look at a Microsoft Teams vulnerability. Our new Threat Vector segment features a conversation with David Moulton and Michael Sikorski on the potential threats from LLMs and AI. And SiegedSec hits NATO sites.

On this first segment of Threat Vector, Michael "Siko" Sikorski, CTO & VP of Engineering for Unit 42, joins host David Moulton to discuss LLMs & AI and the impacts to expect on social engineering, phishing, and more.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/142


Threat Vector links.

Palo Alto Networks Unit 42


Selected reading.

Tomcat Under Attack: Exploring Mirai Malware and Beyond (Aquasec)

CardioComm, a provider of ECG monitoring devices, confirms cyberattack downed its services (TechCrunch) 

Detecting the Silent Threat: 'Stealers are Organization Killers' (Uptycs)

Cyber security skills in the UK labour market 2023 (DSIT)

NATO investigates alleged data theft by SiegedSec hackers (BleepingComputer)

NATO investigating apparent breach of unclassified information sharing platform (CyberScoop) 

SiegedSec Compromise NATO (Cyberint)

More description

The Mirai botnet afflicts Tomcat. CardioComm services are downed by cyberattack. Uptycs calls infostealers “organization killers" as related security incidents double in a year. Legacy third-party risk management practices meet with dissatisfaction. Cyber skill gaps reported in the UK's workforce. Our guest is George Prichici of OPSWAT with a look at a Microsoft Teams vulnerability. Our new Threat Vector segment features a conversation with David Moulton and Michael Sikorski on the potential threats from LLMs and AI. And SiegedSec hits NATO sites.

On this first segment of Threat Vector, Michael "Siko" Sikorski, CTO & VP of Engineering for Unit 42, joins host David Moulton to discuss LLMs & AI and the impacts to expect on social engineering, phishing, and more.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/142


Threat Vector links.

Palo Alto Networks Unit 42


Selected reading.

Tomcat Under Attack: Exploring Mirai Malware and Beyond (Aquasec)

CardioComm, a provider of ECG monitoring devices, confirms cyberattack downed its services (TechCrunch) 

Detecting the Silent Threat: 'Stealers are Organization Killers' (Uptycs)

Cyber security skills in the UK labour market 2023 (DSIT)

NATO investigates alleged data theft by SiegedSec hackers (BleepingComputer)

NATO investigating apparent breach of unclassified information sharing platform (CyberScoop) 

SiegedSec Compromise NATO (Cyberint)

Extract Knowledge
Listen elsewhere

FraudGPT is a chatbot with malign intent. Stealer logs in the C2C market. Signs in the blockchain that some Conti alumni are working with the Akira gang. Tim Starks from Washington Post's Cybersecurity 202 on the White House’s new National Cyber Director nominee. Maria Varmazis speaks with David Luber, Deputy Director of NSA's Cybersecurity Directorate, on space systems as critical infrastructure. And a kinetic strike against a cyber target: Ukrainian drones may have hit Fancy Bear’s Moscow digs.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/141


Selected reading.

FraudGPT: The Villain Avatar of ChatGPT (Netenrich) 

Stealer Logs & Corporate Access (Flare)

Over 400,000 corporate credentials stolen by info-stealing malware (BleepingComputer)

The Alarming Rise of Infostealers: How to Detect this Silent Threat (The Hacker News)

Conti and Akira: Chained Together (Arctic Wolf)

Ukraine-Russia war: Ukraine vows further drone strikes on Moscow and Crimea (The Telegraph) 

More description

FraudGPT is a chatbot with malign intent. Stealer logs in the C2C market. Signs in the blockchain that some Conti alumni are working with the Akira gang. Tim Starks from Washington Post's Cybersecurity 202 on the White House’s new National Cyber Director nominee. Maria Varmazis speaks with David Luber, Deputy Director of NSA's Cybersecurity Directorate, on space systems as critical infrastructure. And a kinetic strike against a cyber target: Ukrainian drones may have hit Fancy Bear’s Moscow digs.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/141


Selected reading.

FraudGPT: The Villain Avatar of ChatGPT (Netenrich) 

Stealer Logs & Corporate Access (Flare)

Over 400,000 corporate credentials stolen by info-stealing malware (BleepingComputer)

The Alarming Rise of Infostealers: How to Detect this Silent Threat (The Hacker News)

Conti and Akira: Chained Together (Arctic Wolf)

Ukraine-Russia war: Ukraine vows further drone strikes on Moscow and Crimea (The Telegraph) 

Extract Knowledge
Listen elsewhere

A zero-day attack of undetermined origin targets government offices in Norway. Russia accuses the US of cyber aggression. Data breaches exact a rising cost. 74% of survey respondents say their company would pay ransom to recover stolen or encrypted data. Executives and security teams differ in their perception of cyber threat readiness. Mr. Security Answer Person John Pescatore looks at risk metrics. Joe Carrigan on a new dark market AI tool called Worm GPT. And Apple issues urgent patches.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/140


Selected reading.

Norway says Ivanti zero-day was used to hack govt IT systems (BleepingComputer)

Norway investigates cyberattack affecting 12 government ministries (Record)

Norwegian government IT systems hacked using zero-day flaw (BleepingComputer)

Putin ally accuses US of planning cyberattacks on Russian critical infrastructure (Al Arabiya English) 

Cost of a Data Breach Report 2023 (IBM Security)

Ransom Monetization Rates Fall to Record Low Despite Jump In Average Ransom Payments (Coveware) 

2023 Cyber Threat Readiness Report (Swimlane) 

Apple Releases Security Updates for Multiple Products (Cybersecurity and Infrastructure Security Agency CISA)

Apple fixes 16 security flaws with iOS 16.6, two actively exploited (9to5Mac)

Apple Rolls Out Urgent Patches for Zero-Day Flaws Impacting iPhones, iPads and Macs (The Hacker News)

Apple fixes new zero-day used in attacks against iPhones, Macs (BleepingComputer) 

iOS 16.6: Apple Suddenly Releases Key iPhone Update With Urgent Fixes (Forbes) 

More description

A zero-day attack of undetermined origin targets government offices in Norway. Russia accuses the US of cyber aggression. Data breaches exact a rising cost. 74% of survey respondents say their company would pay ransom to recover stolen or encrypted data. Executives and security teams differ in their perception of cyber threat readiness. Mr. Security Answer Person John Pescatore looks at risk metrics. Joe Carrigan on a new dark market AI tool called Worm GPT. And Apple issues urgent patches.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/140


Selected reading.

Norway says Ivanti zero-day was used to hack govt IT systems (BleepingComputer)

Norway investigates cyberattack affecting 12 government ministries (Record)

Norwegian government IT systems hacked using zero-day flaw (BleepingComputer)

Putin ally accuses US of planning cyberattacks on Russian critical infrastructure (Al Arabiya English) 

Cost of a Data Breach Report 2023 (IBM Security)

Ransom Monetization Rates Fall to Record Low Despite Jump In Average Ransom Payments (Coveware) 

2023 Cyber Threat Readiness Report (Swimlane) 

Apple Releases Security Updates for Multiple Products (Cybersecurity and Infrastructure Security Agency CISA)

Apple fixes 16 security flaws with iOS 16.6, two actively exploited (9to5Mac)

Apple Rolls Out Urgent Patches for Zero-Day Flaws Impacting iPhones, iPads and Macs (The Hacker News)

Apple fixes new zero-day used in attacks against iPhones, Macs (BleepingComputer) 

iOS 16.6: Apple Suddenly Releases Key iPhone Update With Urgent Fixes (Forbes) 

Extract Knowledge
Listen elsewhere

North Korea's increasingly supple cyber offensives. A look at Cl0p. The NetSupport RAT's fake update vectors. HotRat is a Trojan that accompanies illegally pirated software and games. Crackable radio encryption standard: a bug or a feature? Chris Novak from Verizon discusses ransomware through the lens of the DBIR. Carole Theriault describes a ransomware attack that hit close to home. And an alleged money-laundering crypto-rapper is back in the news.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/139


Selected reading.

North Korea Leverages SaaS Provider in a Targeted Supply Chain Attack | Mandiant (Mandiant)

Ransomware Roundup - Cl0p (Fortinet Blog)

FakeSG enters the 'FakeUpdates' arena to deliver NetSupport RAT (Malwarebytes)

Researchers Find ‘Backdoor’ in Encrypted Police and Military Radios (Vice) 

Unmasking HotRat: The hidden dangers in your software downloads (Avast)

Researchers Find ‘Backdoor’ in Encrypted Police and Military Radios (Vice) 

Crypto rapper 'Razzlekhan,' husband reach plea deal over Bitfinex hack laundering (Reuters)

More description

North Korea's increasingly supple cyber offensives. A look at Cl0p. The NetSupport RAT's fake update vectors. HotRat is a Trojan that accompanies illegally pirated software and games. Crackable radio encryption standard: a bug or a feature? Chris Novak from Verizon discusses ransomware through the lens of the DBIR. Carole Theriault describes a ransomware attack that hit close to home. And an alleged money-laundering crypto-rapper is back in the news.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/139


Selected reading.

North Korea Leverages SaaS Provider in a Targeted Supply Chain Attack | Mandiant (Mandiant)

Ransomware Roundup - Cl0p (Fortinet Blog)

FakeSG enters the 'FakeUpdates' arena to deliver NetSupport RAT (Malwarebytes)

Researchers Find ‘Backdoor’ in Encrypted Police and Military Radios (Vice) 

Unmasking HotRat: The hidden dangers in your software downloads (Avast)

Researchers Find ‘Backdoor’ in Encrypted Police and Military Radios (Vice) 

Crypto rapper 'Razzlekhan,' husband reach plea deal over Bitfinex hack laundering (Reuters)

Extract Knowledge
Listen elsewhere

Don Welch, Chief Information Officer from New York University sits down to share his exciting start into his cyber career. Much like many other people who started in this industry, Don went into the military, which is where it all started for him. He was told he needed to take two specialties, and so along with mechanical engineering, he decided to go into computer science as well. After taking his two crafts, he decided to leave the Army and go into the civilian world where he took a couple jobs in cyber. He landed a few jobs at different prestigious universities, including Penn State University, University of Michigan, and now New York University. He shares that being a good leader will take you far in life, saying "I will say that if you are a great leader, ultimately, you sit in your office and do nothing because you have developed your team and empowered them, and they're making all the decisions, everything runs like clockwork and you have nothing to do." We thank Don for sharing is story with us.

More description

Don Welch, Chief Information Officer from New York University sits down to share his exciting start into his cyber career. Much like many other people who started in this industry, Don went into the military, which is where it all started for him. He was told he needed to take two specialties, and so along with mechanical engineering, he decided to go into computer science as well. After taking his two crafts, he decided to leave the Army and go into the civilian world where he took a couple jobs in cyber. He landed a few jobs at different prestigious universities, including Penn State University, University of Michigan, and now New York University. He shares that being a good leader will take you far in life, saying "I will say that if you are a great leader, ultimately, you sit in your office and do nothing because you have developed your team and empowered them, and they're making all the decisions, everything runs like clockwork and you have nothing to do." We thank Don for sharing is story with us.

Extract Knowledge
Listen elsewhere

With the relentless advancements in technology and a workforce more digitally-enabled than ever before, businesses today face an unprecedented challenge of protecting their sensitive information from cybercriminals. Infostealer malware, often disguised as innocuous files or hidden within legitimate-looking emails, stealthily infiltrate employee and contractor devices – managed and unmanaged – exfiltrating all manner of data for the purposes of executing follow-on attacks including ransomware. The data at risk includes customer details, financial information, intellectual property, and R&D plans stolen from compromised applications that were accessed from infostealer-exfiltrated authentication data like credentials and active session cookies/tokens. This episode digs into the proliferation of infostealers and provides actionable steps for businesses of any size or industry to mitigate the threat.

In this episode of CyberWire-X, N2K’s CSO, Chief Analyst, and Senior Fellow, Rick Howard, is joined in the first half by Hash Table member Rick Doten to discuss the early days of incident response and the current thinking of post-infection remediation (PIR) actions. In the second half of the show, CyberWire podcast host Dave Bittner talks with our episode sponsor SpyCloud’s Director of Security Research, Trevor Hilligoss. They chat about the challenges for enterprises and security leaders to identify what was stolen from malware-infected devices and how proper post-infection remediation implemented into existing incident response workflows can help prevent this data from causing ransomware. Trevor shares highlights from an industry report of over 300+ security leaders from North America and the UK on where they stand on malware identification and remediation, and what additional work can be done to minimize cybercriminals' access and impact.

More description

With the relentless advancements in technology and a workforce more digitally-enabled than ever before, businesses today face an unprecedented challenge of protecting their sensitive information from cybercriminals. Infostealer malware, often disguised as innocuous files or hidden within legitimate-looking emails, stealthily infiltrate employee and contractor devices – managed and unmanaged – exfiltrating all manner of data for the purposes of executing follow-on attacks including ransomware. The data at risk includes customer details, financial information, intellectual property, and R&D plans stolen from compromised applications that were accessed from infostealer-exfiltrated authentication data like credentials and active session cookies/tokens. This episode digs into the proliferation of infostealers and provides actionable steps for businesses of any size or industry to mitigate the threat.

In this episode of CyberWire-X, N2K’s CSO, Chief Analyst, and Senior Fellow, Rick Howard, is joined in the first half by Hash Table member Rick Doten to discuss the early days of incident response and the current thinking of post-infection remediation (PIR) actions. In the second half of the show, CyberWire podcast host Dave Bittner talks with our episode sponsor SpyCloud’s Director of Security Research, Trevor Hilligoss. They chat about the challenges for enterprises and security leaders to identify what was stolen from malware-infected devices and how proper post-infection remediation implemented into existing incident response workflows can help prevent this data from causing ransomware. Trevor shares highlights from an industry report of over 300+ security leaders from North America and the UK on where they stand on malware identification and remediation, and what additional work can be done to minimize cybercriminals' access and impact.

Extract Knowledge
Listen elsewhere

Joshua Miller from Proofpoint joins Dave to discuss findings on "Welcome to New York: Exploring TA453's Foray into LNKs and Mac Malware." In mid May, TA453, also known as Charming Kitten, APT42, Mint Sandstorm, and Yellow Garuda, was found sending a benign conversation lure masquerading as a senior fellow with the Royal United Services Institute (RUSI) to the public media contact for a nuclear security expert at a US-based think tank focused on foreign affairs.

The research states that "the email solicited feedback on a project called “Iran in the Global Security Context” and requested permission to send a draft for review." Proofpoint shares it's findings and what you can expect from the threat group.

The research can be found here:

More description

Joshua Miller from Proofpoint joins Dave to discuss findings on "Welcome to New York: Exploring TA453's Foray into LNKs and Mac Malware." In mid May, TA453, also known as Charming Kitten, APT42, Mint Sandstorm, and Yellow Garuda, was found sending a benign conversation lure masquerading as a senior fellow with the Royal United Services Institute (RUSI) to the public media contact for a nuclear security expert at a US-based think tank focused on foreign affairs.

The research states that "the email solicited feedback on a project called “Iran in the Global Security Context” and requested permission to send a draft for review." Proofpoint shares it's findings and what you can expect from the threat group.

The research can be found here:

Extract Knowledge
Listen elsewhere

The Lazarus Group targets developers. Threat actors target the banking sector with fake LinkedIn profiles and open source supply chain attacks. Vulnerabilities reported in OpenMeetings. HTML smuggling is sold in the C2C market. Johannes Ullrich from SANS describes attacks against niche web apps. Our guest is Damir Brecic of Inversion6 discussing the privacy and security concerns of Meta's new Threads app. And Romania's SVR reports a pattern of Russian cyberattacks.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/138


Selected reading.

GitHub warns of Lazarus hackers targeting devs with malicious projects (BleepingComputer)

Cyberattack on GitHub customers linked to North Korean hackers, Microsoft says (Record)

Security alert: social engineering campaign targets technology industry employees (The GitHub Blog)

First Known Targeted OSS Supply Chain Attacks Against the Banking Sector (Checkmarx)

A Twist in the Code: OpenMeetings Vulnerabilities through Unexpected Application State (Sonar) 

Fresh Phish: HTML Smuggling Made Easy, Thanks to a New Dark Web Phish Kit (INKY) 

KillNet Showcases New Capabilities While Repeating Older Tactics (Mandiant).

Pro-Russian hacktivists increase focus on Western targets. The latest is OnlyFans. (CyberScoop).

Anonymous Sudan DDoS strikes dominate attacks by KillNet collective (SC Media)

Romanian Intelligence General: All Russian secret services attempted cyber attacks against Romania (ACTMedia)

More description

The Lazarus Group targets developers. Threat actors target the banking sector with fake LinkedIn profiles and open source supply chain attacks. Vulnerabilities reported in OpenMeetings. HTML smuggling is sold in the C2C market. Johannes Ullrich from SANS describes attacks against niche web apps. Our guest is Damir Brecic of Inversion6 discussing the privacy and security concerns of Meta's new Threads app. And Romania's SVR reports a pattern of Russian cyberattacks.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/138


Selected reading.

GitHub warns of Lazarus hackers targeting devs with malicious projects (BleepingComputer)

Cyberattack on GitHub customers linked to North Korean hackers, Microsoft says (Record)

Security alert: social engineering campaign targets technology industry employees (The GitHub Blog)

First Known Targeted OSS Supply Chain Attacks Against the Banking Sector (Checkmarx)

A Twist in the Code: OpenMeetings Vulnerabilities through Unexpected Application State (Sonar) 

Fresh Phish: HTML Smuggling Made Easy, Thanks to a New Dark Web Phish Kit (INKY) 

KillNet Showcases New Capabilities While Repeating Older Tactics (Mandiant).

Pro-Russian hacktivists increase focus on Western targets. The latest is OnlyFans. (CyberScoop).

Anonymous Sudan DDoS strikes dominate attacks by KillNet collective (SC Media)

Romanian Intelligence General: All Russian secret services attempted cyber attacks against Romania (ACTMedia)

Extract Knowledge
Listen elsewhere

Sophos analyzes malvertising through purchased Google Ads. The MOVEit vulnerability is remediated faster than most. The DeliveryCheck backdoor is used against Ukrainian targets. SORM is under stress. Ukrainian police roll up another bot farm working in support of Russian influence operations. AJ Nash from ZeroFox provides insights on the White House cybersecurity labeling program. David Moulton from Palo Alto Networks Unit 42 introduces his new segment "Threat Vector." And we bid farewell to Kevin Mitnick.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/137


Selected reading.

Bad ad fad leads to IcedID, Gozi infections (Sophos News)

New research reveals rapid remediation of MOVEit Transfer vulnerabilities (Bitsight) 

GRIT Ransomware Report-2023-Q2 (Guidepoint Security) 

Russia’s Turla hackers target Ukraine’s defense with spyware (Record) 

Russian Hackers Probe Ukrainian Defense Sector With Backdoor (Bank Info Security) 

Russia’s vast telecom surveillance system crippled by withdrawal of Western tech, report says (Record) 

Ukraine’s cyber police dismantled a massive bot farm spreading propaganda (Security Affairs)

Kevin David Mitnick, August 6, 1963 - July 16, 2023. (Dignity Memorial)

More description

Sophos analyzes malvertising through purchased Google Ads. The MOVEit vulnerability is remediated faster than most. The DeliveryCheck backdoor is used against Ukrainian targets. SORM is under stress. Ukrainian police roll up another bot farm working in support of Russian influence operations. AJ Nash from ZeroFox provides insights on the White House cybersecurity labeling program. David Moulton from Palo Alto Networks Unit 42 introduces his new segment "Threat Vector." And we bid farewell to Kevin Mitnick.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/137


Selected reading.

Bad ad fad leads to IcedID, Gozi infections (Sophos News)

New research reveals rapid remediation of MOVEit Transfer vulnerabilities (Bitsight) 

GRIT Ransomware Report-2023-Q2 (Guidepoint Security) 

Russia’s Turla hackers target Ukraine’s defense with spyware (Record) 

Russian Hackers Probe Ukrainian Defense Sector With Backdoor (Bank Info Security) 

Russia’s vast telecom surveillance system crippled by withdrawal of Western tech, report says (Record) 

Ukraine’s cyber police dismantled a massive bot farm spreading propaganda (Security Affairs)

Kevin David Mitnick, August 6, 1963 - July 16, 2023. (Dignity Memorial)

Extract Knowledge
Listen elsewhere

Vulnerabilities are identified and patched in Citrix Netscaler products and Adobe Coldfusion. The banking sector should be monitoring the dark web for leaked credentials and insider threats. Spyware vendors are added to the US Entity List. WhatsApp accounts may be at risk. Verizon’s Chris Novak shares insights on Log4j from this year’s DBIR. Our guest is Candid Wüest of Acronis discussing the findings of their Year-end Cyberthreats Report. Skirmishes in the cyber phases of Russia's war. And how do you demobilize cyber forces (especially the auxiliaries) once the war is over?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/136


Selected reading.

Exploited 0-days, an incomplete fix, and a botched disclosure: Infosec snafu reigns 

New critical Citrix ADC and Gateway flaw exploited as zero-day (BleepingComputer) 

Citrix alerts users to critical vulnerability in Citrix ADC and Gateway (Computing)

Adobe, Microsoft and Citrix vulnerabilities draw warnings from CISA (Record)

Active Exploitation of Multiple Adobe ColdFusion Vulnerabilities (Rapid7)

Dark Web Threats Against The Banking Sector › Searchlight Cyber (Searchlight Cyber)

WhatsApp Remote Deactivation Warning For 2 Billion Users (Forbes)

The United States Adds Foreign Companies to Entity List for Malicious Cyber Activities - United States Department of State (United States Department of State) 

Commerce Adds Four Entities to Entity List for Trafficking in Cyber Exploits (Bureau of Industry and Security) 

Russian hackers may be behind 'DDoS' attack on NZ Parliament website (Stuff) 

Russian medical lab suspends some services after ransomware attack (Record) 

If you want peace, prepare for… cyberwar - Friends of Europe (Friends of Europe) 

More description

Vulnerabilities are identified and patched in Citrix Netscaler products and Adobe Coldfusion. The banking sector should be monitoring the dark web for leaked credentials and insider threats. Spyware vendors are added to the US Entity List. WhatsApp accounts may be at risk. Verizon’s Chris Novak shares insights on Log4j from this year’s DBIR. Our guest is Candid Wüest of Acronis discussing the findings of their Year-end Cyberthreats Report. Skirmishes in the cyber phases of Russia's war. And how do you demobilize cyber forces (especially the auxiliaries) once the war is over?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/136


Selected reading.

Exploited 0-days, an incomplete fix, and a botched disclosure: Infosec snafu reigns 

New critical Citrix ADC and Gateway flaw exploited as zero-day (BleepingComputer) 

Citrix alerts users to critical vulnerability in Citrix ADC and Gateway (Computing)

Adobe, Microsoft and Citrix vulnerabilities draw warnings from CISA (Record)

Active Exploitation of Multiple Adobe ColdFusion Vulnerabilities (Rapid7)

Dark Web Threats Against The Banking Sector › Searchlight Cyber (Searchlight Cyber)

WhatsApp Remote Deactivation Warning For 2 Billion Users (Forbes)

The United States Adds Foreign Companies to Entity List for Malicious Cyber Activities - United States Department of State (United States Department of State) 

Commerce Adds Four Entities to Entity List for Trafficking in Cyber Exploits (Bureau of Industry and Security) 

Russian hackers may be behind 'DDoS' attack on NZ Parliament website (Stuff) 

Russian medical lab suspends some services after ransomware attack (Record) 

If you want peace, prepare for… cyberwar - Friends of Europe (Friends of Europe) 

Extract Knowledge
Listen elsewhere

The US Federal government issues voluntary security guidelines. Possible privilege escalation within Google Cloud. An APT compromises JumpCloud. FIN8 reworks its Sardonic backdoor and continues its shift to ransomware. Ben Yelin looks at privacy legislation coming out of Massachusetts. Our guest is Alastair Parr of Prevalent discussing GDPR and third party risk. And some noteworthy Russian cyber crime–they don’t seem to be serving any political masters; they just want to get paid.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/135


Selected reading.

Biden-Harris Administration Announces Cybersecurity Labeling Program for Smart Devices to Protect American Consumers (The White House)

The Biden administration announces a cybersecurity labeling program for smart devices (AP News)CISA Develops Factsheet for Free Tools for Cloud Environments (Cybersecurity and Infrastructure Security Agency CISA)

Free Tools for Cloud Environments (CISA)

NSA, CISA Release Guidance on Security Considerations for 5G Network Slicing (Cybersecurity and Infrastructure Security Agency CISA)

ESF Members NSA and CISA Publish Second Industry Paper on 5G Network Slicing (National Security Agency/Central Security Service)

Bad.Build: A Critical Privilege Escalation Design Flaw in Google Cloud Build Enables a Supply Chain Attack (Orca Security)

Orca: Google Cloud design flaw enables supply chain attacks (Security | TechTarget) 

Google fixes ‘Bad.Build’ vulnerability affecting Cloud Build service (Record)

JumpCloud discloses breach by state-backed APT hacking group (BleepingComputer)

JumpCloud: A 'state-sponsored threat actor' compromised our systems (Computing) 

JumpCloud says nation-state hackers breached its systems | TechCrunch (TechCrunch)

JumpCloud, an IT firm serving 200,000 orgs, says it was hacked by nation-state (Ars Technica)

[Security Update] Incident Details - JumpCloud (JumpCloud)

July 2023 Incident Indicators of Compromise (IoCs) (JumpCloud)

FIN8 Uses Revamped Sardonic Backdoor to Deliver Noberus Ransomware (Symantec by Broadcom)

RedCurl hackers return to spy on 'major Russian bank,' Australian company (Record) 

More description

The US Federal government issues voluntary security guidelines. Possible privilege escalation within Google Cloud. An APT compromises JumpCloud. FIN8 reworks its Sardonic backdoor and continues its shift to ransomware. Ben Yelin looks at privacy legislation coming out of Massachusetts. Our guest is Alastair Parr of Prevalent discussing GDPR and third party risk. And some noteworthy Russian cyber crime–they don’t seem to be serving any political masters; they just want to get paid.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/135


Selected reading.

Biden-Harris Administration Announces Cybersecurity Labeling Program for Smart Devices to Protect American Consumers (The White House)

The Biden administration announces a cybersecurity labeling program for smart devices (AP News)CISA Develops Factsheet for Free Tools for Cloud Environments (Cybersecurity and Infrastructure Security Agency CISA)

Free Tools for Cloud Environments (CISA)

NSA, CISA Release Guidance on Security Considerations for 5G Network Slicing (Cybersecurity and Infrastructure Security Agency CISA)

ESF Members NSA and CISA Publish Second Industry Paper on 5G Network Slicing (National Security Agency/Central Security Service)

Bad.Build: A Critical Privilege Escalation Design Flaw in Google Cloud Build Enables a Supply Chain Attack (Orca Security)

Orca: Google Cloud design flaw enables supply chain attacks (Security | TechTarget) 

Google fixes ‘Bad.Build’ vulnerability affecting Cloud Build service (Record)

JumpCloud discloses breach by state-backed APT hacking group (BleepingComputer)

JumpCloud: A 'state-sponsored threat actor' compromised our systems (Computing) 

JumpCloud says nation-state hackers breached its systems | TechCrunch (TechCrunch)

JumpCloud, an IT firm serving 200,000 orgs, says it was hacked by nation-state (Ars Technica)

[Security Update] Incident Details - JumpCloud (JumpCloud)

July 2023 Incident Indicators of Compromise (IoCs) (JumpCloud)

FIN8 Uses Revamped Sardonic Backdoor to Deliver Noberus Ransomware (Symantec by Broadcom)

RedCurl hackers return to spy on 'major Russian bank,' Australian company (Record) 

Extract Knowledge
Listen elsewhere

WormGPT is a new AI threat. TeamTNT seems to be back. Chinese intelligence services actively pursue British MPs. Gamaredon's quick info theft. Russia’s FSB bans Apple devices. The troll farmers of the Internet Research Agency may not yet be down for the count. Anonymous Sudan claims a "demonstration" attack against PayPal, with more to come. Carole Theriault looks at popular email lures. My conversation with N2K president Simone Petrella on the White House’s National Cybersecurity Strategy Implementation Plan. And, friends, don’t take this typo to Timbuktu.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/134


Selected reading.

WormGPT, an "ethics-free" text generator. (CyberWire)

TeamTNT (or someone a lot like them) may be preparing a major campaign. (CyberWire)

Chinese government hackers ‘frequently’ targeting MPs, warns new report (Record) 

Gamaredon hackers start stealing data 30 minutes after a breach (BleepingComputer) 

Russia-linked APT Gamaredon starts stealing data from victims between 30 and 50 minutes after the initial compromise (Security Affairs)

Armageddon in Ukraine – how one Russia-backed hacking group operates (CyberSecurity Connect)

Russian hacking group Armageddon increasingly targets Ukrainian state services (Record)

Russia bans officials from using iPhones in U.S. spying row (Apple Insider)

Prigozhin's Media Companies May Resume Work As Mutiny Fallout Dissipates, FT Reports (Radio Free Europe | Radio Liberty)

Anonymous Sudan claims it hit PayPal with 'warning' DDoS cyberattack (Tech Monitor) 

Typo leaks millions of US military emails to Mali web operator (Financial Times)

More description

WormGPT is a new AI threat. TeamTNT seems to be back. Chinese intelligence services actively pursue British MPs. Gamaredon's quick info theft. Russia’s FSB bans Apple devices. The troll farmers of the Internet Research Agency may not yet be down for the count. Anonymous Sudan claims a "demonstration" attack against PayPal, with more to come. Carole Theriault looks at popular email lures. My conversation with N2K president Simone Petrella on the White House’s National Cybersecurity Strategy Implementation Plan. And, friends, don’t take this typo to Timbuktu.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/134


Selected reading.

WormGPT, an "ethics-free" text generator. (CyberWire)

TeamTNT (or someone a lot like them) may be preparing a major campaign. (CyberWire)

Chinese government hackers ‘frequently’ targeting MPs, warns new report (Record) 

Gamaredon hackers start stealing data 30 minutes after a breach (BleepingComputer) 

Russia-linked APT Gamaredon starts stealing data from victims between 30 and 50 minutes after the initial compromise (Security Affairs)

Armageddon in Ukraine – how one Russia-backed hacking group operates (CyberSecurity Connect)

Russian hacking group Armageddon increasingly targets Ukrainian state services (Record)

Russia bans officials from using iPhones in U.S. spying row (Apple Insider)

Prigozhin's Media Companies May Resume Work As Mutiny Fallout Dissipates, FT Reports (Radio Free Europe | Radio Liberty)

Anonymous Sudan claims it hit PayPal with 'warning' DDoS cyberattack (Tech Monitor) 

Typo leaks millions of US military emails to Mali web operator (Financial Times)

Extract Knowledge
Listen elsewhere

Jennifer Addie, COO and CWO from VentureScope and MACH37 Cyber Accelerator sits down to share her incredible story, bringing creativity into the cyber community. Growing up Jennifer always loved the human side of things, and learning that she had a knack for computers helped her to realize what type of field she wanted to pursue as an adult. She started working jobs dealing in programming, database administration, product development, and it was there in the design of those products where she felt the deep need for security, emerging as critical in her consciousness. She shares how she likes to be on a personal level with the people she works with, always wondering where people came from and why they are passionate, being a very interactive leader. Jennifer also says that she believes bringing creativity into the field is what helps her solve any form of problem the best stating "I absolutely agree with the idea that, that creativity is far more than artistic capability. It is very much centered on problem solving and in fact, the master's degree that I received in creativity focuses on creative problem solving as a process." We thank Jennifer for sharing her story with us.

More description

Jennifer Addie, COO and CWO from VentureScope and MACH37 Cyber Accelerator sits down to share her incredible story, bringing creativity into the cyber community. Growing up Jennifer always loved the human side of things, and learning that she had a knack for computers helped her to realize what type of field she wanted to pursue as an adult. She started working jobs dealing in programming, database administration, product development, and it was there in the design of those products where she felt the deep need for security, emerging as critical in her consciousness. She shares how she likes to be on a personal level with the people she works with, always wondering where people came from and why they are passionate, being a very interactive leader. Jennifer also says that she believes bringing creativity into the field is what helps her solve any form of problem the best stating "I absolutely agree with the idea that, that creativity is far more than artistic capability. It is very much centered on problem solving and in fact, the master's degree that I received in creativity focuses on creative problem solving as a process." We thank Jennifer for sharing her story with us.

Extract Knowledge
Listen elsewhere

Michael Clark from Sysdig joins with Dave to discuss their research on SCARLETEEL 2.0: Fargate, Kubernetes, and Crypto. New research from Sysdig threat researchers found that the group continues to thrive with improved tactics. Most recently, they gained access to AWS Fargate, a more sophisticated environment to breach, thanks to their upgraded attack tools.

The research states "In their most recent activities, we saw a similar strategy to what was reported in the previous blog: compromise AWS accounts through exploiting vulnerable compute services, gain persistence, and attempt to make money using cryptominers." Had Sysdig not thwarted SCARLETEEL's attack, they estimated that they would have mined $4,000 per day until they were stopped.

The research can be found here:

More description

Michael Clark from Sysdig joins with Dave to discuss their research on SCARLETEEL 2.0: Fargate, Kubernetes, and Crypto. New research from Sysdig threat researchers found that the group continues to thrive with improved tactics. Most recently, they gained access to AWS Fargate, a more sophisticated environment to breach, thanks to their upgraded attack tools.

The research states "In their most recent activities, we saw a similar strategy to what was reported in the previous blog: compromise AWS accounts through exploiting vulnerable compute services, gain persistence, and attempt to make money using cryptominers." Had Sysdig not thwarted SCARLETEEL's attack, they estimated that they would have mined $4,000 per day until they were stopped.

The research can be found here:

Extract Knowledge
Listen elsewhere

Developments in the case of China's cyberespionage against government Exchange users. Industrial controller vulnerabilities pose a risk to critical infrastructure. USB attacks have risen three-fold in the first half of 2023. CISA adds two vulnerabilities to its Known Exploited Vulnerabilities Catalog. Ghostwriter's continued activity focuses on Poland and Ukraine. Hacktivist auxiliaries swap DDoS attacks. Awais Rashid from University of Bristol shares insights on threat modeling. Our guest is Chris Cochran from Huntress on the challenges small and medium sized businesses face with cyber security. And lessons learned from cyber warfare in Russia's war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/133


Selected reading.

UK says it's working with Microsoft to understand impact of Chinese email hack (Reuters) 

What we know (and don’t know) about the government email breach (Washington Post)

Yet Another MS CVE: Don’t Get Caught In The Storm! (Cynet)

China Hacking Was Undetectable for Some Who Had Less Expensive Microsoft Services (Wall Street Journal)

Security flaws in Honeywell devices could be used to disrupt critical industries (TechCrunch)

APT Exploit Targeting Rockwell Automation Flaws Threatens Critical Infrastructure (SecurityWeek)

Rockwell Automation ControlLogix Bugs Expose Industrial Systems to Remote Attacks (The Hacker News) 

USB drive malware attacks spiking again in first half of 2023 (BleepingComputer)

CISA Adds Two Known Vulnerabilities to Catalog (Cybersecurity and Infrastructure Security Agency CISA)

Malicious campaigns target government, military and civilian entities in Ukraine, Poland (Cisco Talos Blog)

Belarus-linked hacks on Ukraine, Poland began at least a year ago, report says (Record)

Crowdsourced Cyber Warfare: Russia and Ukraine Launch Fresh DDoS Offensives (CEPA).

Cyber Operations during the Russo-Ukrainian War (CSIS)

More description

Developments in the case of China's cyberespionage against government Exchange users. Industrial controller vulnerabilities pose a risk to critical infrastructure. USB attacks have risen three-fold in the first half of 2023. CISA adds two vulnerabilities to its Known Exploited Vulnerabilities Catalog. Ghostwriter's continued activity focuses on Poland and Ukraine. Hacktivist auxiliaries swap DDoS attacks. Awais Rashid from University of Bristol shares insights on threat modeling. Our guest is Chris Cochran from Huntress on the challenges small and medium sized businesses face with cyber security. And lessons learned from cyber warfare in Russia's war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/133


Selected reading.

UK says it's working with Microsoft to understand impact of Chinese email hack (Reuters) 

What we know (and don’t know) about the government email breach (Washington Post)

Yet Another MS CVE: Don’t Get Caught In The Storm! (Cynet)

China Hacking Was Undetectable for Some Who Had Less Expensive Microsoft Services (Wall Street Journal)

Security flaws in Honeywell devices could be used to disrupt critical industries (TechCrunch)

APT Exploit Targeting Rockwell Automation Flaws Threatens Critical Infrastructure (SecurityWeek)

Rockwell Automation ControlLogix Bugs Expose Industrial Systems to Remote Attacks (The Hacker News) 

USB drive malware attacks spiking again in first half of 2023 (BleepingComputer)

CISA Adds Two Known Vulnerabilities to Catalog (Cybersecurity and Infrastructure Security Agency CISA)

Malicious campaigns target government, military and civilian entities in Ukraine, Poland (Cisco Talos Blog)

Belarus-linked hacks on Ukraine, Poland began at least a year ago, report says (Record)

Crowdsourced Cyber Warfare: Russia and Ukraine Launch Fresh DDoS Offensives (CEPA).

Cyber Operations during the Russo-Ukrainian War (CSIS)

Extract Knowledge
Listen elsewhere

CISA and the FBI issue a joint Cybersecurity Advisory on exploitation of Microsoft Exchange Online. Implementing the US National Cybersecurity Strategy. FortiGuard discovers a new LokiBot campaign. Training code turns out to be malicious in a new proof-of-concept attack discovered on GitHub. Russia resumes its pursuit of a "sovereign Internet." The GRU's offensive cyber tactics. Chris Novak from Verizon discusses business email compromise and the 2023 DBIR. Our guest is Joy Beland of Summit 7 on the role of Managed Service Providers in the supply chain to the Defense Industrial Base. And a probable Ukrainian false-flag operation.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/132


Selected reading.

CISA and FBI Release Cybersecurity Advisory on Enhanced Monitoring to Detect APT Activity Targeting Outlook Online (Cybersecurity and Infrastructure Security Agency CISA)

Enhanced Monitoring to Detect APT Activity Targeting Outlook Online (Cybersecurity and Infrastructure Security Agency CISA)

How a Cloud Flaw Gave Chinese Spies a Key to Microsoft’s Kingdom (WIRED)

Chinese hackers breached U.S. and European government email through Microsoft bug (Record)

FACT SHEET: Biden-Harris Administration Publishes the National Cybersecurity Strategy Implementation Plan | The White House (The White House)

National Cybersecurity Strategy Implementation Plan (White House)

LokiBot Campaign Targets Microsoft Office Document Using Vulnerabilities and Macros (Fortinet Blog)

New PoC Exploit Found: Fake Proof of Concept with Backdoor Malware (Uptycs)

Russia Is Trying to Leave the Internet and Build Its Own (Scientific American)

The GRU's Disruptive Playbook (Mandiant) 

Hack Blamed on Wagner Group Had Another Culprit, Experts Say (Bloomberg) 

More description

CISA and the FBI issue a joint Cybersecurity Advisory on exploitation of Microsoft Exchange Online. Implementing the US National Cybersecurity Strategy. FortiGuard discovers a new LokiBot campaign. Training code turns out to be malicious in a new proof-of-concept attack discovered on GitHub. Russia resumes its pursuit of a "sovereign Internet." The GRU's offensive cyber tactics. Chris Novak from Verizon discusses business email compromise and the 2023 DBIR. Our guest is Joy Beland of Summit 7 on the role of Managed Service Providers in the supply chain to the Defense Industrial Base. And a probable Ukrainian false-flag operation.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/132


Selected reading.

CISA and FBI Release Cybersecurity Advisory on Enhanced Monitoring to Detect APT Activity Targeting Outlook Online (Cybersecurity and Infrastructure Security Agency CISA)

Enhanced Monitoring to Detect APT Activity Targeting Outlook Online (Cybersecurity and Infrastructure Security Agency CISA)

How a Cloud Flaw Gave Chinese Spies a Key to Microsoft’s Kingdom (WIRED)

Chinese hackers breached U.S. and European government email through Microsoft bug (Record)

FACT SHEET: Biden-Harris Administration Publishes the National Cybersecurity Strategy Implementation Plan | The White House (The White House)

National Cybersecurity Strategy Implementation Plan (White House)

LokiBot Campaign Targets Microsoft Office Document Using Vulnerabilities and Macros (Fortinet Blog)

New PoC Exploit Found: Fake Proof of Concept with Backdoor Malware (Uptycs)

Russia Is Trying to Leave the Internet and Build Its Own (Scientific American)

The GRU's Disruptive Playbook (Mandiant) 

Hack Blamed on Wagner Group Had Another Culprit, Experts Say (Bloomberg) 

Extract Knowledge
Listen elsewhere

A Chinese threat actor hits US organizations with a Microsoft cloud exploit. Open source tools allow threat actors to exploit a loophole in Microsoft's kernel driver authentication procedures. A RomCom update. Beamer phishbait, email extortion attacks and digital blackmail. A new report concludes companies allowing personal employee devices onto their network are opening themselves to attack. Tim Starks from the Washington Post looks at Microsoft’s recent woes. Our guest is Eyal Benishti from IRONSCALES with insights on business email compromise. And a July Patch Tuesday retrospective.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/131


Selected reading.

Mitigation for China-Based Threat Actor Activity (Microsoft On the Issues)

Microsoft mitigates China-based threat actor Storm-0558 targeting of customer email (Microsoft Security Response Center)

Chinese hackers breach U.S. government email through Microsoft cloud (Washington Post) 

U.S. Government Emails Hacked in Suspected Chinese Espionage Campaign (Wall Street Journal)

Old certificate, new signature: Open-source tools forge signature timestamps on Windows drivers (Cisco Talos Blog)

Storm-0978 attacks reveal financial and espionage motives (Microsoft Security) 

Microsoft: Unpatched Office zero-day exploited in NATO summit attacks (BleepingComputer) 

Diplomats Beware: Cloaked Ursa Phishing With a Twist (Unit 42)

Russian hackers lured embassy workers in Ukraine with ad for a cheap BMW (Reuters)

Threat spotlight: Extortion attacks (Barracuda)

The SpyCloud Malware Readiness And Defense Report (SpyCloud)

July 2023 Security Updates (Security Update Guide - Microsoft Security Response Center)

Microsoft Releases July 2023 Security Updates (Cybersecurity and Infrastructure Security Agency CISA) 

Microsoft July 2023 Patch Tuesday warns of 6 zero-days, 132 flaws (BleepingComputer) 

Fortinet Releases Security Update for FortiOS and FortiProxy (Cybersecurity and Infrastructure Security Agency CISA)

Adobe Releases Security Updates for ColdFusion and InDesign (Cybersecurity and Infrastructure Security Agency CISA) 

Apple's Rapid Security Response Patches Causing Website Access Issues (SecurityWeek) 

SAP Security Patch Day – July 2023 (SAP)

Return of the ICMAD Critical Vulnerabilities in 2023 (Onapsis)

More description

A Chinese threat actor hits US organizations with a Microsoft cloud exploit. Open source tools allow threat actors to exploit a loophole in Microsoft's kernel driver authentication procedures. A RomCom update. Beamer phishbait, email extortion attacks and digital blackmail. A new report concludes companies allowing personal employee devices onto their network are opening themselves to attack. Tim Starks from the Washington Post looks at Microsoft’s recent woes. Our guest is Eyal Benishti from IRONSCALES with insights on business email compromise. And a July Patch Tuesday retrospective.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/131


Selected reading.

Mitigation for China-Based Threat Actor Activity (Microsoft On the Issues)

Microsoft mitigates China-based threat actor Storm-0558 targeting of customer email (Microsoft Security Response Center)

Chinese hackers breach U.S. government email through Microsoft cloud (Washington Post) 

U.S. Government Emails Hacked in Suspected Chinese Espionage Campaign (Wall Street Journal)

Old certificate, new signature: Open-source tools forge signature timestamps on Windows drivers (Cisco Talos Blog)

Storm-0978 attacks reveal financial and espionage motives (Microsoft Security) 

Microsoft: Unpatched Office zero-day exploited in NATO summit attacks (BleepingComputer) 

Diplomats Beware: Cloaked Ursa Phishing With a Twist (Unit 42)

Russian hackers lured embassy workers in Ukraine with ad for a cheap BMW (Reuters)

Threat spotlight: Extortion attacks (Barracuda)

The SpyCloud Malware Readiness And Defense Report (SpyCloud)

July 2023 Security Updates (Security Update Guide - Microsoft Security Response Center)

Microsoft Releases July 2023 Security Updates (Cybersecurity and Infrastructure Security Agency CISA) 

Microsoft July 2023 Patch Tuesday warns of 6 zero-days, 132 flaws (BleepingComputer) 

Fortinet Releases Security Update for FortiOS and FortiProxy (Cybersecurity and Infrastructure Security Agency CISA)

Adobe Releases Security Updates for ColdFusion and InDesign (Cybersecurity and Infrastructure Security Agency CISA) 

Apple's Rapid Security Response Patches Causing Website Access Issues (SecurityWeek) 

SAP Security Patch Day – July 2023 (SAP)

Return of the ICMAD Critical Vulnerabilities in 2023 (Onapsis)

Extract Knowledge
Listen elsewhere

NATO considers Article 5 in cyberspace, while Cyberattacks conducted in the Russian interest target the NATO summit. Anonymous Sudan remains a nuisance-level irritant. Cl0p's surprising use of MOVEit exploits. Asylum Ambuscade is a case study in privateering. There are reports of a breach at Razer. An indictment in a cyber incident at a California water treatment facility. Genesis Market's fire sale. Carole Theriault on the data Amazon customers provide with some suggestions on curbing it. Our guest is Dmitry Bestuzhev, senior director in Cyber Threat Intelligence for Blackberry. And Amazon Prime Day is upon us–the crooks have noticed.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/130


Selected reading.

A Cybersecurity Wish List Ahead of NATO Summit (SecurityWeek)

NATO’s Christian-Marc Lifländer on how the alliance can take a ‘proactive’ cyber stance (Record)

Ukraine has set the standard on software power (POLITICO)

RomCom Threat Actor Suspected of Targeting Ukraine's NATO Membership Talks at the NATO Summit (BlackBerry)

Threat group testing more sophisticated DDoS hacks, authorities warn (Cybersecurity Dive)

Move It on Over: Reflecting on the MOVEit Exploitation (Huntress)

Cl0p has yet to deploy ransomware while exploiting MOVEit zero-day (SC Media) 

Asylum Ambuscade: crimeware or cyberespionage? (WeLiveSecurity)

Crimeware Group Asylum Ambuscade Ventures Into Cyber-Espionage (Infosecurity Magazine)

Razer investigates data breach claims, resets user sessions (BleepingComputer) 

Razer Data Breach: Alleged Database and Backend Access Sold for $100k (HackRead)

Alleged Razer data breach: Hacker demands US$100K in crypto in exchange for stolen data (Vulcan Post)

Razer gets pwned as hackers steal source code (Cyber Security Connect) 

Razer Cyber Attack: Gaming Hardware Giant Faces Data Breach (The Cyber Express) 

Amazon Prime Day: Buyers Beware of Phishing Campaigns Targeting Online Shoppers (Veriti)

Tracy Resident Charged With Computer Attack On Discovery Bay Water Treatment Facility (US Attorney for the Northern District of California)

Tracy man indicted for illegally accessing water treatment network (CBS News)

Technician Indicted for Hacking California Water Treatment Facility (HackRead)

Tracy Man Charged With Computer Attack On Discovery Bay Water Treatment Facility (Contra Costa News) 

Genesis Market gang tries to sell platform after FBI disruption (Record) 

Amazon Prime Day: Buyers Beware of Phishing Campaigns Targeting Online Shoppers (Veriti) 

More description

NATO considers Article 5 in cyberspace, while Cyberattacks conducted in the Russian interest target the NATO summit. Anonymous Sudan remains a nuisance-level irritant. Cl0p's surprising use of MOVEit exploits. Asylum Ambuscade is a case study in privateering. There are reports of a breach at Razer. An indictment in a cyber incident at a California water treatment facility. Genesis Market's fire sale. Carole Theriault on the data Amazon customers provide with some suggestions on curbing it. Our guest is Dmitry Bestuzhev, senior director in Cyber Threat Intelligence for Blackberry. And Amazon Prime Day is upon us–the crooks have noticed.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/130


Selected reading.

A Cybersecurity Wish List Ahead of NATO Summit (SecurityWeek)

NATO’s Christian-Marc Lifländer on how the alliance can take a ‘proactive’ cyber stance (Record)

Ukraine has set the standard on software power (POLITICO)

RomCom Threat Actor Suspected of Targeting Ukraine's NATO Membership Talks at the NATO Summit (BlackBerry)

Threat group testing more sophisticated DDoS hacks, authorities warn (Cybersecurity Dive)

Move It on Over: Reflecting on the MOVEit Exploitation (Huntress)

Cl0p has yet to deploy ransomware while exploiting MOVEit zero-day (SC Media) 

Asylum Ambuscade: crimeware or cyberespionage? (WeLiveSecurity)

Crimeware Group Asylum Ambuscade Ventures Into Cyber-Espionage (Infosecurity Magazine)

Razer investigates data breach claims, resets user sessions (BleepingComputer) 

Razer Data Breach: Alleged Database and Backend Access Sold for $100k (HackRead)

Alleged Razer data breach: Hacker demands US$100K in crypto in exchange for stolen data (Vulcan Post)

Razer gets pwned as hackers steal source code (Cyber Security Connect) 

Razer Cyber Attack: Gaming Hardware Giant Faces Data Breach (The Cyber Express) 

Amazon Prime Day: Buyers Beware of Phishing Campaigns Targeting Online Shoppers (Veriti)

Tracy Resident Charged With Computer Attack On Discovery Bay Water Treatment Facility (US Attorney for the Northern District of California)

Tracy man indicted for illegally accessing water treatment network (CBS News)

Technician Indicted for Hacking California Water Treatment Facility (HackRead)

Tracy Man Charged With Computer Attack On Discovery Bay Water Treatment Facility (Contra Costa News) 

Genesis Market gang tries to sell platform after FBI disruption (Record) 

Amazon Prime Day: Buyers Beware of Phishing Campaigns Targeting Online Shoppers (Veriti) 

Extract Knowledge
Listen elsewhere

New phishing campaigns afflict users of Microsoft 365 and Adobe. An analysis of Big Head ransomware. Multichain reports a crypto heist with over $100 million stolen. CISA makes an addition to the Known Exploited Vulnerability Catalog. Progress Software issues additional MOVEit patches. The FBI’s Deputy Assistant Director for Cyber Cynthia Kaiser joins us with examples of the agency’s technical disruption operations. Our guest is Scott Piper Principal Cloud Security Researcher at Wiz sharing findings of their State of the Cloud 2023 report. And Telegram's role in news about Russia's war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/129


Selected reading.

M365 Phishing Email Analysis – eevilcorp (Vade Secure)

New Phishing Attack Spoofs Microsoft 365 Authentication System (HackRead)

Tailing Big Head Ransomware’s Variants, Tactics, and Impact (Trend Micro)

New ‘Big Head’ ransomware displays fake Windows update alert (BleepingComputer)

Unfolding Cybersecurity Crisis: Aptos Network and Multichain Face Cyber-Attacks (CryptoMode)

More than $125 million taken from crypto platform Multichain (Record)

Exploit of Fantom, Moonriver and Dogechain Crypto Bridges Confirmed by Multichain Team (CoinDesk)

CISA Adds One Known Vulnerability to Catalog (CISA)

Google patches 43 Android Vulnerabilities Including 3 actively exploited zero-days (Cyber Security News) 

Progress Software Releases Service Pack for MOVEit Transfer Vulnerabilities (CISA)

After Zero-Day Attacks, MOVEit Turns to Security Service Packs (SecurityWeek)

Killnet as a private military hacking company? For now, it's probably just a dream (Record)

Telegram has become a window into war (The Verge)

More description

New phishing campaigns afflict users of Microsoft 365 and Adobe. An analysis of Big Head ransomware. Multichain reports a crypto heist with over $100 million stolen. CISA makes an addition to the Known Exploited Vulnerability Catalog. Progress Software issues additional MOVEit patches. The FBI’s Deputy Assistant Director for Cyber Cynthia Kaiser joins us with examples of the agency’s technical disruption operations. Our guest is Scott Piper Principal Cloud Security Researcher at Wiz sharing findings of their State of the Cloud 2023 report. And Telegram's role in news about Russia's war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/129


Selected reading.

M365 Phishing Email Analysis – eevilcorp (Vade Secure)

New Phishing Attack Spoofs Microsoft 365 Authentication System (HackRead)

Tailing Big Head Ransomware’s Variants, Tactics, and Impact (Trend Micro)

New ‘Big Head’ ransomware displays fake Windows update alert (BleepingComputer)

Unfolding Cybersecurity Crisis: Aptos Network and Multichain Face Cyber-Attacks (CryptoMode)

More than $125 million taken from crypto platform Multichain (Record)

Exploit of Fantom, Moonriver and Dogechain Crypto Bridges Confirmed by Multichain Team (CoinDesk)

CISA Adds One Known Vulnerability to Catalog (CISA)

Google patches 43 Android Vulnerabilities Including 3 actively exploited zero-days (Cyber Security News) 

Progress Software Releases Service Pack for MOVEit Transfer Vulnerabilities (CISA)

After Zero-Day Attacks, MOVEit Turns to Security Service Packs (SecurityWeek)

Killnet as a private military hacking company? For now, it's probably just a dream (Record)

Telegram has become a window into war (The Verge)

Extract Knowledge
Listen elsewhere

Eric Tillman, Chief Intelligence Officer at N2K Networks sits down and shares his incredibly creative journey. Eric loved being creative from a young age. When he started to think about a career he wanted to incorporate his love of creativity into his love for tech and turn it into an intelligence career. Eric started by joining the Navy, which set him on this path to work in cyber where he shared his talents with several big companies, including, Booz Allen Hamilton, Lockheed Martin, and Okta, eventually ending up at our very own N2K Networks. Eric shares the advice that there is something for everyone in this field, and even though he wanted to start his journey in a creative way, he found that combining his love for tech and art helped him to pave the way to where he is now. He says " A lot of people get here from a very technical background and um, it really almost doesn't matter um, where you came from, there is something in cybersecurity that takes advantage of the skills that you bring to the table and, um, either way, there's plenty of room here for everyone." We thank Eric for sharing his story with us.

More description

Eric Tillman, Chief Intelligence Officer at N2K Networks sits down and shares his incredibly creative journey. Eric loved being creative from a young age. When he started to think about a career he wanted to incorporate his love of creativity into his love for tech and turn it into an intelligence career. Eric started by joining the Navy, which set him on this path to work in cyber where he shared his talents with several big companies, including, Booz Allen Hamilton, Lockheed Martin, and Okta, eventually ending up at our very own N2K Networks. Eric shares the advice that there is something for everyone in this field, and even though he wanted to start his journey in a creative way, he found that combining his love for tech and art helped him to pave the way to where he is now. He says " A lot of people get here from a very technical background and um, it really almost doesn't matter um, where you came from, there is something in cybersecurity that takes advantage of the skills that you bring to the table and, um, either way, there's plenty of room here for everyone." We thank Eric for sharing his story with us.

Extract Knowledge
Listen elsewhere

Moez Kamel, Threat Management Specialist at IBM Security, joins us on T-Minus Deep Space for a special edition all about the cybersecurity ecosystem in the New Space industry.

You can follow Moez on LinkedIn and his work at IBM’s Security Intelligence blog.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our weekly intelligence roundup, Signals and Space, and you’ll never miss a beat. And be sure to follow T-Minus on Twitter and LinkedIn.

Selected Reading

Cybersecurity in the Next-Generation Space Age, Pt. 1: Introduction to New Space

Cybersecurity in the Next-Generation Space Age, Pt. 2: Cybersecurity Threats in the New Space

Cybersecurity in the Next-Generation Space Age, Pt. 3: Securing the New Space 

Cybersecurity in the Next-Generation Space Age, Pt. 4: New Space Future Development and Challenges    

Audience Survey

We want to hear from you! Please complete our 4 question survey. It’ll help us get better and deliver you the most mission-critical space intel every day.

Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at space@n2k.com to request more info.

Want to join us for an interview?

Please send your pitch to space-editor@n2k.com and include your name, affiliation, and topic proposal.

T-Minus is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

Moez Kamel, Threat Management Specialist at IBM Security, joins us on T-Minus Deep Space for a special edition all about the cybersecurity ecosystem in the New Space industry.

You can follow Moez on LinkedIn and his work at IBM’s Security Intelligence blog.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our weekly intelligence roundup, Signals and Space, and you’ll never miss a beat. And be sure to follow T-Minus on Twitter and LinkedIn.

Selected Reading

Cybersecurity in the Next-Generation Space Age, Pt. 1: Introduction to New Space

Cybersecurity in the Next-Generation Space Age, Pt. 2: Cybersecurity Threats in the New Space

Cybersecurity in the Next-Generation Space Age, Pt. 3: Securing the New Space 

Cybersecurity in the Next-Generation Space Age, Pt. 4: New Space Future Development and Challenges    

Audience Survey

We want to hear from you! Please complete our 4 question survey. It’ll help us get better and deliver you the most mission-critical space intel every day.

Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at space@n2k.com to request more info.

Want to join us for an interview?

Please send your pitch to space-editor@n2k.com and include your name, affiliation, and topic proposal.

T-Minus is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2023-07-08

Creating PANDA-monium. [Research Saturday]

17 min
View

Thomas Etheridge from CrowdStrike sits down to discuss their work on "Business as Usual: Falcon Complete MDR Thwarts Novel VANGUARD PANDA (Volt Typhoon) Tradecraft" In May of 2023, industry and government sources detailed China-nexus activity where they found the threat actor dubbed Volt Typhoon targeted U.S. based critical infrastructure entities. CrowdStrike's Intelligence team tracked this actor as VANGUARD PANDA. 

With CISA’s advisory on VANGUARD PANDA and its link to Chinese adversaries who are increasingly targeting US businesses and critical infrastructure, CrowdStrike’s blog dives deeper into the risks of VANGUARD PANDA. The research says "One specific VANGUARD PANDA incident stands out to review in detail. Falcon Complete responded to a detection that was triggered by suspicious reconnaissance commands executed under an Apache Tomcat web server running ManageEngine ADSelfService Plus."

The research can be found here:

More description

Thomas Etheridge from CrowdStrike sits down to discuss their work on "Business as Usual: Falcon Complete MDR Thwarts Novel VANGUARD PANDA (Volt Typhoon) Tradecraft" In May of 2023, industry and government sources detailed China-nexus activity where they found the threat actor dubbed Volt Typhoon targeted U.S. based critical infrastructure entities. CrowdStrike's Intelligence team tracked this actor as VANGUARD PANDA. 

With CISA’s advisory on VANGUARD PANDA and its link to Chinese adversaries who are increasingly targeting US businesses and critical infrastructure, CrowdStrike’s blog dives deeper into the risks of VANGUARD PANDA. The research says "One specific VANGUARD PANDA incident stands out to review in detail. Falcon Complete responded to a detection that was triggered by suspicious reconnaissance commands executed under an Apache Tomcat web server running ManageEngine ADSelfService Plus."

The research can be found here:

Extract Knowledge
Listen elsewhere

US and Canadian agencies warn of Truebot. A look at "Operation Brainleaches." Jumpcloud resets API keys. An update on the MOVEit vulnerability exploitation. Andrea Little Limbago from Interos shares insights on rising geopolitical instability. Our guest is Mike Hamilton from Critical Insight discussing what you need to know about NIST 2.0. OSCE trains Ukrainian students in cybersecurity.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/128


Selected reading.

CISA and Partners Release Joint Cybersecurity Advisory on Newly Identified Truebot Malware Variants (Cybersecurity and Infrastructure Security Agency CISA)

Increased Truebot Activity Infects U.S. and Canada Based Networks | CISA (Cybersecurity and Infrastructure Security Agency CISA) 

Operation Brainleeches: Malicious npm packages fuel supply chain and phishing attacks (ReversingLabs)

Mandatory JumpCloud API Key Rotation (JumpCloud)

JumpCloud resets admin API keys amid ‘ongoing incident’ (BleepingComputer)

JumpCloud Says All API Keys Invalidated to Protect Customers (SecurityWeek)

More organizations confirm MOVEit-related breaches as hackers claim to publish stolen data (TechCrunch)

Important information about MOVEit Transfer cyber security incident | Shell Global (Shell Global)

Shell Confirms MOVEit-Related Breach After Ransomware Group Leaks Data (SecurityWeek)

OSCE helps future generation of Ukraine’s law enforcers and emergency personnel build skills for safe work in cyberspace (OSCE)

More description

US and Canadian agencies warn of Truebot. A look at "Operation Brainleaches." Jumpcloud resets API keys. An update on the MOVEit vulnerability exploitation. Andrea Little Limbago from Interos shares insights on rising geopolitical instability. Our guest is Mike Hamilton from Critical Insight discussing what you need to know about NIST 2.0. OSCE trains Ukrainian students in cybersecurity.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/128


Selected reading.

CISA and Partners Release Joint Cybersecurity Advisory on Newly Identified Truebot Malware Variants (Cybersecurity and Infrastructure Security Agency CISA)

Increased Truebot Activity Infects U.S. and Canada Based Networks | CISA (Cybersecurity and Infrastructure Security Agency CISA) 

Operation Brainleeches: Malicious npm packages fuel supply chain and phishing attacks (ReversingLabs)

Mandatory JumpCloud API Key Rotation (JumpCloud)

JumpCloud resets admin API keys amid ‘ongoing incident’ (BleepingComputer)

JumpCloud Says All API Keys Invalidated to Protect Customers (SecurityWeek)

More organizations confirm MOVEit-related breaches as hackers claim to publish stolen data (TechCrunch)

Important information about MOVEit Transfer cyber security incident | Shell Global (Shell Global)

Shell Confirms MOVEit-Related Breach After Ransomware Group Leaks Data (SecurityWeek)

OSCE helps future generation of Ukraine’s law enforcers and emergency personnel build skills for safe work in cyberspace (OSCE)

Extract Knowledge
Listen elsewhere

LockBit 3.0 claims responsibility for Nagoya ransomware attack. Charming Kitten sighting. Spyware infested apps found in Google Play. Threats and risks to electric vehicle charging stations. Solar panels and cyberattacks. Dave Bittner speaks with Eric Goldstein, Executive Assistant Director for Cybersecurity at CISA, to talk about CISA’s effort for companies to build safety into tech products.Rick Howard sits down with Clarke Rodgers of AWS to discuss the mechanics of CISO roundtables. And Hacktivist auxiliaries remain active in Russia's hybrid war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/127


Selected reading.

Pro-Russian hackers target Port of Nagoya, disrupting loading of Toyota parts (The Japan Times) 

Port of Nagoya resumes operations later than planned after Russian hack (The Japan Times) 

Ransomware Halts Operations at Japan's Port of Nagoya (Dark Reading) 

Nagoya Port Faces Disruption After Ransomware Attack (Infosecurity Magazine) 

Welcome to New York: Exploring TA453's Foray into LNKs and Mac Malware | Proofpoint US (Proofpoint)

Two spyware tied with China found hiding on the Google Play Store (Pradeo)

EV Charger Hacking Poses a ‘Catastrophic’ Risk (WIRED) 

Exploited Solar Power Product Vulnerability Could Expose Energy Organizations to Attacks (SecurityWeek)

The Continued Expansion of Cyber Incidents by Non-State Actors in the War in Europe (OODA Loop).  

Russian railway site allegedly taken down by Ukrainian hackers (Record)

More description

LockBit 3.0 claims responsibility for Nagoya ransomware attack. Charming Kitten sighting. Spyware infested apps found in Google Play. Threats and risks to electric vehicle charging stations. Solar panels and cyberattacks. Dave Bittner speaks with Eric Goldstein, Executive Assistant Director for Cybersecurity at CISA, to talk about CISA’s effort for companies to build safety into tech products.Rick Howard sits down with Clarke Rodgers of AWS to discuss the mechanics of CISO roundtables. And Hacktivist auxiliaries remain active in Russia's hybrid war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/127


Selected reading.

Pro-Russian hackers target Port of Nagoya, disrupting loading of Toyota parts (The Japan Times) 

Port of Nagoya resumes operations later than planned after Russian hack (The Japan Times) 

Ransomware Halts Operations at Japan's Port of Nagoya (Dark Reading) 

Nagoya Port Faces Disruption After Ransomware Attack (Infosecurity Magazine) 

Welcome to New York: Exploring TA453's Foray into LNKs and Mac Malware | Proofpoint US (Proofpoint)

Two spyware tied with China found hiding on the Google Play Store (Pradeo)

EV Charger Hacking Poses a ‘Catastrophic’ Risk (WIRED) 

Exploited Solar Power Product Vulnerability Could Expose Energy Organizations to Attacks (SecurityWeek)

The Continued Expansion of Cyber Incidents by Non-State Actors in the War in Europe (OODA Loop).  

Russian railway site allegedly taken down by Ukrainian hackers (Record)

Extract Knowledge
Listen elsewhere

Chinese cyberespionage campaign against European governments. The Port of Nagoya closes over ransomware attack. BlackCat and SEO poisoning. LockBit seeks to extort a semiconductor manufacturer. Professionals in the cyber underworld. CISA issued a DDoS alert for US companies and government agencies. Microsoft debunks claims of data theft by Anonymous Sudan. Matt O'Neill from the US Secret Service speaks with Dave Bittner about sextortion. Rick Howard sits down with Michael Fuller of AWS to talk about the kill chain. And Avast releases a free decryptor for Akira.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/126


Selected reading.

Chinese Threat Actors Targeting Europe in SmugX Campaign - Check Point Research (Check Point Research)

Hackers target European government entities in SmugX campaign (BleepingComputer)

Chinese hackers target European embassies with HTML smuggling technique (Record)

Japan’s largest port stops operations after ransomware attack (BleepingComputer) 

BlackCat ransomware pushes Cobalt Strike via WinSCP search ads (BleepingComputer)

BlackCat Operators Distributing Ransomware Disguised as WinSCP via Malvertising (The Hacker News)

TSMC Says Supplier Hacked After Ransomware Group Claims Attack on Chip Giant (SecurityWeek)

TSMC confirms data breach after LockBit cyberattack on third-party supplier (TechCrunch)

Taiwan Semiconductor Denies LockBit's $70M Hack Claim (Bank Info Security)

Semiconductor giant says IT supplier was attacked; LockBit makes related claims (Record)

DoS and DDoS Attacks against Multiple Sectors (Cybersecurity and Infrastructure Security Agency CISA)

CISA issues DDoS warning after attacks hit multiple US orgs (BleepingComputer)

Microsoft denies data breach, theft of 30 million customer accounts (BleepingComputer)

Microsoft Denies Major 30 Million Customer-Breach (Infosecurity Magazine)

Decrypted: Akira Ransomware (Avast Threat Labs)

More description

Chinese cyberespionage campaign against European governments. The Port of Nagoya closes over ransomware attack. BlackCat and SEO poisoning. LockBit seeks to extort a semiconductor manufacturer. Professionals in the cyber underworld. CISA issued a DDoS alert for US companies and government agencies. Microsoft debunks claims of data theft by Anonymous Sudan. Matt O'Neill from the US Secret Service speaks with Dave Bittner about sextortion. Rick Howard sits down with Michael Fuller of AWS to talk about the kill chain. And Avast releases a free decryptor for Akira.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/126


Selected reading.

Chinese Threat Actors Targeting Europe in SmugX Campaign - Check Point Research (Check Point Research)

Hackers target European government entities in SmugX campaign (BleepingComputer)

Chinese hackers target European embassies with HTML smuggling technique (Record)

Japan’s largest port stops operations after ransomware attack (BleepingComputer) 

BlackCat ransomware pushes Cobalt Strike via WinSCP search ads (BleepingComputer)

BlackCat Operators Distributing Ransomware Disguised as WinSCP via Malvertising (The Hacker News)

TSMC Says Supplier Hacked After Ransomware Group Claims Attack on Chip Giant (SecurityWeek)

TSMC confirms data breach after LockBit cyberattack on third-party supplier (TechCrunch)

Taiwan Semiconductor Denies LockBit's $70M Hack Claim (Bank Info Security)

Semiconductor giant says IT supplier was attacked; LockBit makes related claims (Record)

DoS and DDoS Attacks against Multiple Sectors (Cybersecurity and Infrastructure Security Agency CISA)

CISA issues DDoS warning after attacks hit multiple US orgs (BleepingComputer)

Microsoft denies data breach, theft of 30 million customer accounts (BleepingComputer)

Microsoft Denies Major 30 Million Customer-Breach (Infosecurity Magazine)

Decrypted: Akira Ransomware (Avast Threat Labs)

Extract Knowledge
Listen elsewhere
Show details
Episodes
3784
Transcripts
67
2% coverage
Missing transcripts
3717
With chapters
0