Search this show’s transcripts

CyberWire Daily

en us
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
More details
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
Sources and links

Episodes

Page 27 · 50 per page

Earlier this month, the White House released the National Cybersecurity Strategy, the first issued since 2018. The strategy refocuses roles, responsibilities, and resource allocations in the digital ecosystem, with a five pillar approach. Those pillars are: defending critical infrastructure, disrupting threat actors, shaping market forces to drive security and resilience, investing in a resilient future, and forging international partnerships.

We wanted to delve into the strategy and its intended effects further, so Dave Bittner spoke with representatives from industry and inside government. Dave first speaks with Adam Isles, Principal and Head of Cybersecurity Practice at The Chertoff Group, sharing industry's take on the strategy. Following that conversation, Dave had a discussion with Steve Kelly, Special Assistant to the President and Senior Director for Cybersecurity and Emerging Technology at the National Security Council, for a look at the strategy from inside the White House.

Links to resources:

More description

Earlier this month, the White House released the National Cybersecurity Strategy, the first issued since 2018. The strategy refocuses roles, responsibilities, and resource allocations in the digital ecosystem, with a five pillar approach. Those pillars are: defending critical infrastructure, disrupting threat actors, shaping market forces to drive security and resilience, investing in a resilient future, and forging international partnerships.

We wanted to delve into the strategy and its intended effects further, so Dave Bittner spoke with representatives from industry and inside government. Dave first speaks with Adam Isles, Principal and Head of Cybersecurity Practice at The Chertoff Group, sharing industry's take on the strategy. Following that conversation, Dave had a discussion with Steve Kelly, Special Assistant to the President and Senior Director for Cybersecurity and Emerging Technology at the National Security Council, for a look at the strategy from inside the White House.

Links to resources:

Extract Knowledge
Listen elsewhere

This interview from June 16th, 2023 originally aired as a shortened version on the CyberWire Daily Podcast. In this extended interview, Simone Petrella sits down with Will Markow, VP of Applied Research from Lightcast, to discuss how to use data to make strategic workforce decisions.

You can also view the video of the full interview here: Simone Petrella and Will Markow discuss workforce management.

More description

This interview from June 16th, 2023 originally aired as a shortened version on the CyberWire Daily Podcast. In this extended interview, Simone Petrella sits down with Will Markow, VP of Applied Research from Lightcast, to discuss how to use data to make strategic workforce decisions.

You can also view the video of the full interview here: Simone Petrella and Will Markow discuss workforce management.

Extract Knowledge
Listen elsewhere

Liji Samuel from NSA sits down to share her exciting career path through the years until she found a job working for as Chief of Standards and Certification at NSA's Cyber Collaboration Center. She starts by sharing that she had always wanted to work in the STEM field, explaining that growing up she was surrounded with older cousins who were choosing STEM careers and it became an interesting topic for her. She accounts working for a number of companies that helped her grow into the role she is in now. Cybersecurity became a big buzzword for her, causing her to step out of the agency into US cyber command to help take up a management position for the architecture and engineering division. From there, she continued her cybersecurity journey first as the exploration director before moving into where she is now. Liji shares that there were barriers along the way that she had to endure and hop over to get to the right path. She says "So there are challenges and barriers that come across constantly with our work. Um, one just has to pause and reflect on how we can work with it, around it, or influence like our stakeholders and jointly create a vision around it." We thank Liji for sharing her story with us.

More description

Liji Samuel from NSA sits down to share her exciting career path through the years until she found a job working for as Chief of Standards and Certification at NSA's Cyber Collaboration Center. She starts by sharing that she had always wanted to work in the STEM field, explaining that growing up she was surrounded with older cousins who were choosing STEM careers and it became an interesting topic for her. She accounts working for a number of companies that helped her grow into the role she is in now. Cybersecurity became a big buzzword for her, causing her to step out of the agency into US cyber command to help take up a management position for the architecture and engineering division. From there, she continued her cybersecurity journey first as the exploration director before moving into where she is now. Liji shares that there were barriers along the way that she had to endure and hop over to get to the right path. She says "So there are challenges and barriers that come across constantly with our work. Um, one just has to pause and reflect on how we can work with it, around it, or influence like our stakeholders and jointly create a vision around it." We thank Liji for sharing her story with us.

Extract Knowledge
Listen elsewhere

Daniel dos Santos, Forescout's Head of Security Research is sharing insights from a recent exercise his team conducted on AI-assisted attacks for OT and unmanaged devices. Using ChatGPT, Forescout’s research team converted an existing OT exploit developed in Python to run on Windows to demonstrate how easy it is to create an AI-assisted attack that converts the original exploit into alternative programming languages.

The research states "our goal was to convert an existing OT exploit developed in Python to run on Windows to the Go language using ChatGPT." This would then allow it to run faster on Windows and run easily on a variety of embedded devices.

The research can be found here:

More description

Daniel dos Santos, Forescout's Head of Security Research is sharing insights from a recent exercise his team conducted on AI-assisted attacks for OT and unmanaged devices. Using ChatGPT, Forescout’s research team converted an existing OT exploit developed in Python to run on Windows to demonstrate how easy it is to create an AI-assisted attack that converts the original exploit into alternative programming languages.

The research states "our goal was to convert an existing OT exploit developed in Python to run on Windows to the Go language using ChatGPT." This would then allow it to run faster on Windows and run easily on a variety of embedded devices.

The research can be found here:

Extract Knowledge
Listen elsewhere

US Federal Government working to secure management interfaces. NoName057(16)’s DDoSia campaign grows, and targets Wagner, post-insurrection. Update: Unidentified hackers attack Russian satellite communications company, claiming to be Wagner. The role of OSINT in tracking Russia's war. Manoj Sharma of Symantec discusses trends he's hearing about generative AI. Becky Weiss from AWS talks with Rick Howard about the math behind their security. Cyber awareness over a holiday.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/125


Selected reading.

CISA Wants Exposed Government Devices Remediated In 14 Days (Dark Reading)

50 US Agencies Using Unsecured Devices, Violating Policy (Bank Info Security)

CISA working with agencies to pull exposed network tools from public internet (Record)

Following NoName057(16) DDoSia Project’s Targets (Sekoia.io Blog)

Pro-Russia DDoSia hacktivist project sees 2,400% membership increase (BleepingComputer)

Hackers attack Russian satellite telecom provider, claim affiliation with Wagner Group (CyberScoop)

Hackers claim to take down Russian satellite communications provider (Record)

Days of Chaos: How OSINT Helps Us Understand the Putin-Prigozhin Schism (Flashpoint) 

Preparing for cyber threats over the Fourth of July. (CyberWire)

More description

US Federal Government working to secure management interfaces. NoName057(16)’s DDoSia campaign grows, and targets Wagner, post-insurrection. Update: Unidentified hackers attack Russian satellite communications company, claiming to be Wagner. The role of OSINT in tracking Russia's war. Manoj Sharma of Symantec discusses trends he's hearing about generative AI. Becky Weiss from AWS talks with Rick Howard about the math behind their security. Cyber awareness over a holiday.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/125


Selected reading.

CISA Wants Exposed Government Devices Remediated In 14 Days (Dark Reading)

50 US Agencies Using Unsecured Devices, Violating Policy (Bank Info Security)

CISA working with agencies to pull exposed network tools from public internet (Record)

Following NoName057(16) DDoSia Project’s Targets (Sekoia.io Blog)

Pro-Russia DDoSia hacktivist project sees 2,400% membership increase (BleepingComputer)

Hackers attack Russian satellite telecom provider, claim affiliation with Wagner Group (CyberScoop)

Hackers claim to take down Russian satellite communications provider (Record)

Days of Chaos: How OSINT Helps Us Understand the Putin-Prigozhin Schism (Flashpoint) 

Preparing for cyber threats over the Fourth of July. (CyberWire)

Extract Knowledge
Listen elsewhere

8base ransomware is overlooked and spiking. GuLoader targets law firms. Akira ransomware for Linux systems targets VMs. Kaspersky tracks the Lazarus group: typos and mistakes indicating an active human operator. Charming Kitten goes spearphishing. Securing continuous integration/continuous delivery operations. No emojis for the SEC, please.Unconfirmed reports say the Wagner Group hacked a Russian satellite communications provider. Our guest is Hanan Hibshi from Carnegie Mellon's picoCTF team. Chris Novak from Verizon discusses their 2023 Data Breach Investigations Report (DBIR). And Anonymous Sudan wants you to know that they’re not just a bunch of deniable Russian crooks–where’s the love, man?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/124


Selected reading.

8Base Ransomware: A Heavy Hitting Player (VMware Security Blog) 

GuLoader Campaign Targets Law Firms in the US (Morphisec) 

Akira Ransomware Extends Reach to Linux Platform (Cyble) 

Andariel’s Mistakes Uncover New Malware in Lazarus Group Campaign (Infosecurity Magazine)

Charming Kitten Updates POWERSTAR with an InterPlanetary Twist (Volexity)

CISA and NSA Release Joint Guidance on Defending Continuous Integration/Continuous Delivery (CI/CD) Environments | CISA (Cybersecurity and Infrastructure Security Agency CISA)

NSA and CISA Best Practices to Secure Cloud Continuous Integration/Continuous Delivery Environments (National Security Agency/Central Security Service)

Wall Street Regulators’ New Target: Emojis (Wall Street Journal) 

Russian satellite telecom Dozor allegedly hit by hackers (Cybernews)

Hacking Group Says It Attacked Microsoft for Sudan. Experts Say Russia’s Behind It (Bloomberg) 

‘Hactivists’ who targeted Microsoft claim they’re working for Sudan (Fortune)

More description

8base ransomware is overlooked and spiking. GuLoader targets law firms. Akira ransomware for Linux systems targets VMs. Kaspersky tracks the Lazarus group: typos and mistakes indicating an active human operator. Charming Kitten goes spearphishing. Securing continuous integration/continuous delivery operations. No emojis for the SEC, please.Unconfirmed reports say the Wagner Group hacked a Russian satellite communications provider. Our guest is Hanan Hibshi from Carnegie Mellon's picoCTF team. Chris Novak from Verizon discusses their 2023 Data Breach Investigations Report (DBIR). And Anonymous Sudan wants you to know that they’re not just a bunch of deniable Russian crooks–where’s the love, man?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/124


Selected reading.

8Base Ransomware: A Heavy Hitting Player (VMware Security Blog) 

GuLoader Campaign Targets Law Firms in the US (Morphisec) 

Akira Ransomware Extends Reach to Linux Platform (Cyble) 

Andariel’s Mistakes Uncover New Malware in Lazarus Group Campaign (Infosecurity Magazine)

Charming Kitten Updates POWERSTAR with an InterPlanetary Twist (Volexity)

CISA and NSA Release Joint Guidance on Defending Continuous Integration/Continuous Delivery (CI/CD) Environments | CISA (Cybersecurity and Infrastructure Security Agency CISA)

NSA and CISA Best Practices to Secure Cloud Continuous Integration/Continuous Delivery Environments (National Security Agency/Central Security Service)

Wall Street Regulators’ New Target: Emojis (Wall Street Journal) 

Russian satellite telecom Dozor allegedly hit by hackers (Cybernews)

Hacking Group Says It Attacked Microsoft for Sudan. Experts Say Russia’s Behind It (Bloomberg) 

‘Hactivists’ who targeted Microsoft claim they’re working for Sudan (Fortune)

Extract Knowledge
Listen elsewhere

JokerSpy afflicts Macs. ThirdEye (not so blind). Mockingjay process injection as proof-of-concept. Switzerland expects Russia to increase cyberespionage as agent networks are disrupted. The fracturing of Conti, and the rise of its successors. The Washington Post’s Tim Starks explains the security of undersea cables. Our guest is ​​Brian Johnson of Armorblox to discuss Social Security Administration impersonation scams. And the "UserSec Collective" says it's recruiting hacktivists for the Russian cause. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/123


Selected reading.

JokerSpy macOS malware used to attack Japanese crypto exchange (AppleInsider) 

Prominent cryptocurrency exchange infected with previously unseen Mac malware (Ars Technica)

New Fast-Developing ThirdEye Infostealer Pries Open System Information (Fortinet Blog)

Process Mockingjay: Echoing RWX In Userland To Achieve Code Execution (Security Joes)

New Mockingjay Process Injection Technique Could Let Malware Evade Detection (The Hacker News)

New Mockingjay process injection technique evades EDR detection (BleepingComputer)

Ukraine war made Switzerland hub for Chinese, Russian spies: Swiss intelligence (South China Morning Post) 

Swiss intelligence warns of fallout in cyberspace as West clamps down on spies (Record) 

The rise and fall of the Conti ransomware group (Global Initiative) 

The Trickbot/Conti Crypters: Where Are They Now? (Security Intelligence)                                                                                                                       

Ukraine at D+489: An influence contest, post-mutiny. (CyberWire) 

More description

JokerSpy afflicts Macs. ThirdEye (not so blind). Mockingjay process injection as proof-of-concept. Switzerland expects Russia to increase cyberespionage as agent networks are disrupted. The fracturing of Conti, and the rise of its successors. The Washington Post’s Tim Starks explains the security of undersea cables. Our guest is ​​Brian Johnson of Armorblox to discuss Social Security Administration impersonation scams. And the "UserSec Collective" says it's recruiting hacktivists for the Russian cause. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/123


Selected reading.

JokerSpy macOS malware used to attack Japanese crypto exchange (AppleInsider) 

Prominent cryptocurrency exchange infected with previously unseen Mac malware (Ars Technica)

New Fast-Developing ThirdEye Infostealer Pries Open System Information (Fortinet Blog)

Process Mockingjay: Echoing RWX In Userland To Achieve Code Execution (Security Joes)

New Mockingjay Process Injection Technique Could Let Malware Evade Detection (The Hacker News)

New Mockingjay process injection technique evades EDR detection (BleepingComputer)

Ukraine war made Switzerland hub for Chinese, Russian spies: Swiss intelligence (South China Morning Post) 

Swiss intelligence warns of fallout in cyberspace as West clamps down on spies (Record) 

The rise and fall of the Conti ransomware group (Global Initiative) 

The Trickbot/Conti Crypters: Where Are They Now? (Security Intelligence)                                                                                                                       

Ukraine at D+489: An influence contest, post-mutiny. (CyberWire) 

Extract Knowledge
Listen elsewhere

Anatsa Trojan reveals new capabilities. Airlines report employee data stolen in a third-party breach. Canadian energy company SUNCOR reports a cyberattack. What of the Internet Research Agency? Microsoft warns of a rising threat to infrastructure. Joe Carrigan describes an ill-advised phishing simulation. Mr. Security Answer Person John Pescatore takes on zero days. And DDoS grows more sophisticated.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/122


Selected reading.

Anatsa banking Trojan hits UK, US and DACH with new campaign (TreatFabric) 

Anatsa Android trojan now steals banking info from users in US, UK (BleepingComputer) 

Thousands of American Airlines and Southwest pilots impacted by third-party data breach (Bitdefender)

American Airlines, Southwest Airlines disclose data breaches affecting pilots (BleepingComputer) 

American Airlines, Southwest Airlines Impacted by Data Breach at Third-Party Provider (SecurityWeek)

Recruitment portal exposes data of US pilot candidates (Register) 

Suncor Energy says it experienced a cybersecurity incident (Reuters)

Suncor Energy cyberattack impacts Petro-Canada gas stations (BleepingComputer) 

Canadian oil giant Suncor confirms cyberattack after countrywide outages (Record) 

Wagner and the troll factories (POLITICO)

Cyber risks to critical infrastructure are on the rise (CEE Multi-Country News Center)

The lowly DDoS attack is showing signs of being anything but (Washington Post)

More description

Anatsa Trojan reveals new capabilities. Airlines report employee data stolen in a third-party breach. Canadian energy company SUNCOR reports a cyberattack. What of the Internet Research Agency? Microsoft warns of a rising threat to infrastructure. Joe Carrigan describes an ill-advised phishing simulation. Mr. Security Answer Person John Pescatore takes on zero days. And DDoS grows more sophisticated.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/122


Selected reading.

Anatsa banking Trojan hits UK, US and DACH with new campaign (TreatFabric) 

Anatsa Android trojan now steals banking info from users in US, UK (BleepingComputer) 

Thousands of American Airlines and Southwest pilots impacted by third-party data breach (Bitdefender)

American Airlines, Southwest Airlines disclose data breaches affecting pilots (BleepingComputer) 

American Airlines, Southwest Airlines Impacted by Data Breach at Third-Party Provider (SecurityWeek)

Recruitment portal exposes data of US pilot candidates (Register) 

Suncor Energy says it experienced a cybersecurity incident (Reuters)

Suncor Energy cyberattack impacts Petro-Canada gas stations (BleepingComputer) 

Canadian oil giant Suncor confirms cyberattack after countrywide outages (Record) 

Wagner and the troll factories (POLITICO)

Cyber risks to critical infrastructure are on the rise (CEE Multi-Country News Center)

The lowly DDoS attack is showing signs of being anything but (Washington Post)

Extract Knowledge
Listen elsewhere

Russian ISPs blocked Google News as tension with the Wagner Group mounted Friday. Ukrainian hacktivist auxiliaries break into Russian radio broadcasts. New EU sanctions are directed against Russian IT firms. Transparent Tribe resurfaces against Indian military and academic targets. Unauthorized access is the leading cause of data breaches for the fifth year in a row. Trojanized Super Mario Brothers game spreads SupremeBot malware. Today, guests discuss the cybersecurity skills gap. Paul Rebasti of Lockheed Martin shares what they are doing to fill cybersecurity skills gap. Jenny Brinkley joins us from AWS Re:Inforce discusses opportunities from the cybersecurity skills gap. And law enforcement agencies seize BreachForums' web domain. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/121


Selected reading.

Ukraine at D+487: After the march on Moscow. (CyberWire)

Ukraine at D+486: The march on Moscow is over. (CyberWire)

Ukraine at D+485: “We are dying for the Russian people.” (CyberWire)

U.S. spies learned in mid-June Prigozhin was planning armed action in Russia (Washington Post) 

Google News Blocked in Russia as Feud With Mercenary Leader Intensifies (New York Times)

Air War: Pro-Ukraine Hackers Increasingly Breaking Into Russian Broadcasts With Anti-Kremlin Messages (RadioFreeEurope/RadioLiberty)

Fresh EU sanctions hit Russian IT firms (Computing)

Pakistan based hackers target Indian Army, education sector in new cyber attack (Telangana Today)

Pakistan-based hackers target Indian Army, education sector in new cyber attack (PGURUS)

‘Transparent Tribe’ comes out of hiding (Pune Times Mirror) 

2023 ForgeRock Identity Breach Report (ForgeRock)

Trojanized Super Mario Game Installer Spreads SupremeBot Malware (Cyble)

Trojanized Super Mario game used to install Windows malware (BleepingComputer)

FBI seizes BreachForums after arresting its owner Pompompurin in March (BleepingComputer)

More description

Russian ISPs blocked Google News as tension with the Wagner Group mounted Friday. Ukrainian hacktivist auxiliaries break into Russian radio broadcasts. New EU sanctions are directed against Russian IT firms. Transparent Tribe resurfaces against Indian military and academic targets. Unauthorized access is the leading cause of data breaches for the fifth year in a row. Trojanized Super Mario Brothers game spreads SupremeBot malware. Today, guests discuss the cybersecurity skills gap. Paul Rebasti of Lockheed Martin shares what they are doing to fill cybersecurity skills gap. Jenny Brinkley joins us from AWS Re:Inforce discusses opportunities from the cybersecurity skills gap. And law enforcement agencies seize BreachForums' web domain. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/121


Selected reading.

Ukraine at D+487: After the march on Moscow. (CyberWire)

Ukraine at D+486: The march on Moscow is over. (CyberWire)

Ukraine at D+485: “We are dying for the Russian people.” (CyberWire)

U.S. spies learned in mid-June Prigozhin was planning armed action in Russia (Washington Post) 

Google News Blocked in Russia as Feud With Mercenary Leader Intensifies (New York Times)

Air War: Pro-Ukraine Hackers Increasingly Breaking Into Russian Broadcasts With Anti-Kremlin Messages (RadioFreeEurope/RadioLiberty)

Fresh EU sanctions hit Russian IT firms (Computing)

Pakistan based hackers target Indian Army, education sector in new cyber attack (Telangana Today)

Pakistan-based hackers target Indian Army, education sector in new cyber attack (PGURUS)

‘Transparent Tribe’ comes out of hiding (Pune Times Mirror) 

2023 ForgeRock Identity Breach Report (ForgeRock)

Trojanized Super Mario Game Installer Spreads SupremeBot Malware (Cyble)

Trojanized Super Mario game used to install Windows malware (BleepingComputer)

FBI seizes BreachForums after arresting its owner Pompompurin in March (BleepingComputer)

Extract Knowledge
Listen elsewhere

Slavik Markovich, CEO of Descope joins Dave to discuss his career as a serial entrepreneur. Before Descope, he co-founded and was the CEO of Demisto, a leader in the SOAR industry, which was acquired by Palo Alto Networks in 2019 for $560M, where he then served as SVP of Products. Before co-founding Demisto, Slavik was VP & CTO of database technologies at McAfee. He joined McAfee via the acquisition of Sentrigo, a database security startup he co-founded and served as CTO for. He goes into depth of his career changes throughout the years and how that has helped lead him to where he is now in his career. He shares that as a CEO and found of multiple companies he values time and hard workers. He says " I think we really stress the importance of, uh, of responsibility. So if, if you kinda take something, you, you make sure to finish it and on time, if you promise to do something, you do that. And so that's really important for us." We thank Slavik for sharing his story with us.

More description

Slavik Markovich, CEO of Descope joins Dave to discuss his career as a serial entrepreneur. Before Descope, he co-founded and was the CEO of Demisto, a leader in the SOAR industry, which was acquired by Palo Alto Networks in 2019 for $560M, where he then served as SVP of Products. Before co-founding Demisto, Slavik was VP & CTO of database technologies at McAfee. He joined McAfee via the acquisition of Sentrigo, a database security startup he co-founded and served as CTO for. He goes into depth of his career changes throughout the years and how that has helped lead him to where he is now in his career. He shares that as a CEO and found of multiple companies he values time and hard workers. He says " I think we really stress the importance of, uh, of responsibility. So if, if you kinda take something, you, you make sure to finish it and on time, if you promise to do something, you do that. And so that's really important for us." We thank Slavik for sharing his story with us.

Extract Knowledge
Listen elsewhere

Ian Ahl from Permiso's PØ Labs joins Dave to discuss their research on "Unmasking GUI-Vil: Financially Motivated Cloud Threat Actor." First observing the group in 2021, they discovered GUI-vil is a financially motivated threat group primarily focused on unauthorized cryptocurrency mining activities.

The research states "the group has been observed exploiting Amazon Web Services (AWS) EC2 instances to facilitate their illicit crypto mining operations." This group is dangerous because unlike many groups focused on crypto mining, GUI-Vil apply a personal touch when establishing a foothold in an environment.

The research can be found here:

More description

Ian Ahl from Permiso's PØ Labs joins Dave to discuss their research on "Unmasking GUI-Vil: Financially Motivated Cloud Threat Actor." First observing the group in 2021, they discovered GUI-vil is a financially motivated threat group primarily focused on unauthorized cryptocurrency mining activities.

The research states "the group has been observed exploiting Amazon Web Services (AWS) EC2 instances to facilitate their illicit crypto mining operations." This group is dangerous because unlike many groups focused on crypto mining, GUI-Vil apply a personal touch when establishing a foothold in an environment.

The research can be found here:

Extract Knowledge
Listen elsewhere

An update on Barracuda ESG exploitation. Camaro Dragon’s current cyberespionage tools spread through infected USB drives. The Mirai botnet is spreading through new vectors. Midnight Blizzard is out and about . Ukraine is experiencing a "wave" of cyberattacks during its counteroffensive. Karen Worstell from VMware shares her experience with technical debt. Rick Howard speaks with CJ Moses, CISO of Amazon Web Services. And Anonymous Sudan turns out to be no more anonymous or Sudanese than your Uncle Louie.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/120


Selected reading.

Barracuda ESG exploitation (Proofpoint)

Beyond the Horizon: Traveling the World on Camaro Dragon’s USB Flash Drives (Check Point Research)

Chinese malware accidentally infects networked storage (Register)

Akamai SIRT Security Advisory: CVE-2023-26801 Exploited to Spread Mirai Botnet Malware (Akamai).

Mirai botnet targets 22 flaws in D-Link, Zyxel, Netgear devices (BleepingComputer) 

Neuberger: Ukraine experiencing a ‘surge’ in cyberattacks as it executes counteroffensive (Record) 

Microsoft warns of rising NOBELIUM credential attacks on defense sector (HackRead).

Anonymous Sudan: neither anonymous nor Sudanese (Cybernews)

More description

An update on Barracuda ESG exploitation. Camaro Dragon’s current cyberespionage tools spread through infected USB drives. The Mirai botnet is spreading through new vectors. Midnight Blizzard is out and about . Ukraine is experiencing a "wave" of cyberattacks during its counteroffensive. Karen Worstell from VMware shares her experience with technical debt. Rick Howard speaks with CJ Moses, CISO of Amazon Web Services. And Anonymous Sudan turns out to be no more anonymous or Sudanese than your Uncle Louie.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/120


Selected reading.

Barracuda ESG exploitation (Proofpoint)

Beyond the Horizon: Traveling the World on Camaro Dragon’s USB Flash Drives (Check Point Research)

Chinese malware accidentally infects networked storage (Register)

Akamai SIRT Security Advisory: CVE-2023-26801 Exploited to Spread Mirai Botnet Malware (Akamai).

Mirai botnet targets 22 flaws in D-Link, Zyxel, Netgear devices (BleepingComputer) 

Neuberger: Ukraine experiencing a ‘surge’ in cyberattacks as it executes counteroffensive (Record) 

Microsoft warns of rising NOBELIUM credential attacks on defense sector (HackRead).

Anonymous Sudan: neither anonymous nor Sudanese (Cybernews)

Extract Knowledge
Listen elsewhere

North Korea's APT37 deploys FadeStealer to steal information from its targets. Apple patches vulnerabilities under active exploitation. Access to a US satellite is being hawked in a Russophone cybercrime forum. Russian hacktivist auxiliaries say they’ve disrupted IFC.org. Unmasking pig-butchering scams. Social engineering as a method of account takeover. Fraudsters seen abusing generative AI. Sergey Medved from Quest Software describes the “Great Cloud Repatriation”. Mark Ryland of AWS speaks with Rick Howard about software defined perimeters. And embedded URLs in malware.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/119


Selected reading.

RedEyes Group Wiretapping Individuals (APT37) (Ahn Lab)

Apple fixes iPhone software flaws used in widespread hacks of Russians (The Washington Post)

Apple issues emergency patch to address alleged spyware vulnerability (Cyberscoop)

Apple patch fixes zero-day kernel hole reported by Kaspersky – update now! (Sophos)

Military Satellite Access Sold on Russian Hacker Forum for $15,000 (HackRead)

Well done. Russian hackers shut down the IMF (Dzen.ru)

Why Malware Crypting Services Deserve More Scrutiny (KrebsOnSecurity)

Unmasking Pig-Butchering Scams And Protecting Your Financial Future (Trend Micro)

Classic Account Takeover via the Direct Deposit Change (Avanan)

Q2 2023 Digital Trust & Safety Index (Sift)

Compromised Domains account for over 50% of Embedded URLs in Malware Phishing Campaigns (Cofense)

More description

North Korea's APT37 deploys FadeStealer to steal information from its targets. Apple patches vulnerabilities under active exploitation. Access to a US satellite is being hawked in a Russophone cybercrime forum. Russian hacktivist auxiliaries say they’ve disrupted IFC.org. Unmasking pig-butchering scams. Social engineering as a method of account takeover. Fraudsters seen abusing generative AI. Sergey Medved from Quest Software describes the “Great Cloud Repatriation”. Mark Ryland of AWS speaks with Rick Howard about software defined perimeters. And embedded URLs in malware.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/119


Selected reading.

RedEyes Group Wiretapping Individuals (APT37) (Ahn Lab)

Apple fixes iPhone software flaws used in widespread hacks of Russians (The Washington Post)

Apple issues emergency patch to address alleged spyware vulnerability (Cyberscoop)

Apple patch fixes zero-day kernel hole reported by Kaspersky – update now! (Sophos)

Military Satellite Access Sold on Russian Hacker Forum for $15,000 (HackRead)

Well done. Russian hackers shut down the IMF (Dzen.ru)

Why Malware Crypting Services Deserve More Scrutiny (KrebsOnSecurity)

Unmasking Pig-Butchering Scams And Protecting Your Financial Future (Trend Micro)

Classic Account Takeover via the Direct Deposit Change (Avanan)

Q2 2023 Digital Trust & Safety Index (Sift)

Compromised Domains account for over 50% of Embedded URLs in Malware Phishing Campaigns (Cofense)

Extract Knowledge
Listen elsewhere

The Flea APT sets its sights on diplomatic targets. An update on the Cl0p gang’s exploitation of a MOVEit vulnerability. Unpatched TP-Link Archer routers are meeting their match in the Condi botnet. The Muddled Libra threat group compromises companies in a variety of industries. A look into passwordless authentication. Derek Manky of Fortinet describes the Global Threat Landscape. Rick Howard speaks with Rod Wallace from AWS about data lakes. And Fancy Bear noses its way into Ukrainian servers.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/118


Selected reading.

Graphican: Flea Uses New Backdoor in Attacks Targeting Foreign Ministries (Symantec)

Ke3chang (MITRE)

Third MOVEit vulnerability raises alarms as US Agriculture Department says it may be impacted (The Record)

PwC and EY impacted by MOVEit cyber attack (Cybersecurity Hub)

Norton Parent Says Employee Data Stolen in MOVEit Ransomware Attack (SecurityWeek)

MOVEit hack: Gang claims not to have BBC, BA and Boots data (BBC)

US govt offers $10 million bounty for info on Clop ransomware (BleepingComputer)

Condi DDoS Botnet Spreads via TP-Link's CVE-2023-1389 (Fortinet)

CVE-2023-1389 Detail (NIST)

Download for Archer AX21 V3 (TP-Link)

Threat Group Assessment: Muddled Libra (Unit 42)

Axiad and ESG Survey: 82% of Respondents Indicate Passwordless Authentication is a Top Five Priority (PR Newswire)

APT28 group used three Roundcube exploits (CVE-2020-35730, CVE-2021-44026, CVE-2020-12641) during another espionage campaign (CERT-UA#6805) (CERT-UA)

BlueDelta Exploits Ukrainian Government Roundcube Mail Servers to Support Espionage Activities (The Record)

CVE-2020-35730 Detail (NIST)

CVE-2023-23397 Detail (NIST)

More description

The Flea APT sets its sights on diplomatic targets. An update on the Cl0p gang’s exploitation of a MOVEit vulnerability. Unpatched TP-Link Archer routers are meeting their match in the Condi botnet. The Muddled Libra threat group compromises companies in a variety of industries. A look into passwordless authentication. Derek Manky of Fortinet describes the Global Threat Landscape. Rick Howard speaks with Rod Wallace from AWS about data lakes. And Fancy Bear noses its way into Ukrainian servers.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/118


Selected reading.

Graphican: Flea Uses New Backdoor in Attacks Targeting Foreign Ministries (Symantec)

Ke3chang (MITRE)

Third MOVEit vulnerability raises alarms as US Agriculture Department says it may be impacted (The Record)

PwC and EY impacted by MOVEit cyber attack (Cybersecurity Hub)

Norton Parent Says Employee Data Stolen in MOVEit Ransomware Attack (SecurityWeek)

MOVEit hack: Gang claims not to have BBC, BA and Boots data (BBC)

US govt offers $10 million bounty for info on Clop ransomware (BleepingComputer)

Condi DDoS Botnet Spreads via TP-Link's CVE-2023-1389 (Fortinet)

CVE-2023-1389 Detail (NIST)

Download for Archer AX21 V3 (TP-Link)

Threat Group Assessment: Muddled Libra (Unit 42)

Axiad and ESG Survey: 82% of Respondents Indicate Passwordless Authentication is a Top Five Priority (PR Newswire)

APT28 group used three Roundcube exploits (CVE-2020-35730, CVE-2021-44026, CVE-2020-12641) during another espionage campaign (CERT-UA#6805) (CERT-UA)

BlueDelta Exploits Ukrainian Government Roundcube Mail Servers to Support Espionage Activities (The Record)

CVE-2020-35730 Detail (NIST)

CVE-2023-23397 Detail (NIST)

Extract Knowledge
Listen elsewhere

The BlackCat gang crosses Reddit’s path, threatening to leak stolen data. Mystic Stealer malware evades and creates a feedback loop in the C2C market. RDStealer is a new cyberespionage tool, seen in the wild. The United States offers a reward for information on the Cl0p ransomware gang. KillNet, REvil, and Anonymous Sudan form a "DARKNET Parliament" and “sanction” the European banking system. The British Government commits £25 million in cybersecurity aid to Ukraine. Ben Yelin explains cyber disclosure rules proposed by the SEC. Rick Howard speaks with Nancy Wang of AWS about the importance of backups and restores. And what researchers are turning up in cloud honeypots.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/117


Selected reading.

Reddit: Hackers demand $4.5 million and API policy changes (Computing)

Mystic Stealer – Evolving “stealth” Malware (Cyfirma)

Mystic Stealer: The New Kid on the Block (Zscaler)

Unpacking RDStealer: An Exfiltration Malware Targeting RDP Workloads (Bitdefender)

MOVEit Transfer and MOVEit Cloud Vulnerability (Progress Software)

CVE-2023-35708 Detail (NIST)

U.S. Energy Dept gets two ransom notices as MOVEit hack claims more victims (Reuters)

US govt offers $10 million bounty for info on Clop ransomware (BleepingComputer)

Ransomware Group Starts Naming Victims of MOVEit Zero-Day Attacks (SecurityWeek)

A bear in wolf’s clothing: Insights into the infrastructure used by Anonymous Sudan to attack Australian organisations (CyberCX)

Anonymous Sudan: Religious Hacktivists or Russian Front Group? (Trustwave)

UK to give Ukraine major boost to mount counteroffensive (UK Government)

2023 Honeypotting in the Cloud Report: Attackers Discover and Weaponize Exposed Cloud Assets and Secrets in Minutes (Orca Security)

More description

The BlackCat gang crosses Reddit’s path, threatening to leak stolen data. Mystic Stealer malware evades and creates a feedback loop in the C2C market. RDStealer is a new cyberespionage tool, seen in the wild. The United States offers a reward for information on the Cl0p ransomware gang. KillNet, REvil, and Anonymous Sudan form a "DARKNET Parliament" and “sanction” the European banking system. The British Government commits £25 million in cybersecurity aid to Ukraine. Ben Yelin explains cyber disclosure rules proposed by the SEC. Rick Howard speaks with Nancy Wang of AWS about the importance of backups and restores. And what researchers are turning up in cloud honeypots.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/117


Selected reading.

Reddit: Hackers demand $4.5 million and API policy changes (Computing)

Mystic Stealer – Evolving “stealth” Malware (Cyfirma)

Mystic Stealer: The New Kid on the Block (Zscaler)

Unpacking RDStealer: An Exfiltration Malware Targeting RDP Workloads (Bitdefender)

MOVEit Transfer and MOVEit Cloud Vulnerability (Progress Software)

CVE-2023-35708 Detail (NIST)

U.S. Energy Dept gets two ransom notices as MOVEit hack claims more victims (Reuters)

US govt offers $10 million bounty for info on Clop ransomware (BleepingComputer)

Ransomware Group Starts Naming Victims of MOVEit Zero-Day Attacks (SecurityWeek)

A bear in wolf’s clothing: Insights into the infrastructure used by Anonymous Sudan to attack Australian organisations (CyberCX)

Anonymous Sudan: Religious Hacktivists or Russian Front Group? (Trustwave)

UK to give Ukraine major boost to mount counteroffensive (UK Government)

2023 Honeypotting in the Cloud Report: Attackers Discover and Weaponize Exposed Cloud Assets and Secrets in Minutes (Orca Security)

Extract Knowledge
Listen elsewhere

Major General Lorna Mahlock, Deputy Director for Combat Support from the National Security Agency (NSA) sits down with Dave to discuss her long and impressive career leading up to he working for one of the most prestigious security agencies. Originally born in Kingston, Jamaica, Lorna immigrated to Brooklyn, New York and enlisted in the United States Marine Corps as a field radio operator. She shares how eye opening the military was for her, moving through ranks, and eventually landing into working at the Pentagon for the Chairman of the Joint Chiefs of staff. She moved around widening her array of paths, landing in her current role. Lorna shares some wisdom, mentioning how she likes to talk about ladders and how useful creating ladders in life can be, she says "I think about ladders in terms of horizontal component, in that you can create bridges, right? And, um, ways over obstacles, uh, for, for not only, uh, for yourself, but for others and an entire organization." We thank Lorna for sharing her story with us.

More description

Major General Lorna Mahlock, Deputy Director for Combat Support from the National Security Agency (NSA) sits down with Dave to discuss her long and impressive career leading up to he working for one of the most prestigious security agencies. Originally born in Kingston, Jamaica, Lorna immigrated to Brooklyn, New York and enlisted in the United States Marine Corps as a field radio operator. She shares how eye opening the military was for her, moving through ranks, and eventually landing into working at the Pentagon for the Chairman of the Joint Chiefs of staff. She moved around widening her array of paths, landing in her current role. Lorna shares some wisdom, mentioning how she likes to talk about ladders and how useful creating ladders in life can be, she says "I think about ladders in terms of horizontal component, in that you can create bridges, right? And, um, ways over obstacles, uh, for, for not only, uh, for yourself, but for others and an entire organization." We thank Lorna for sharing her story with us.

Extract Knowledge
Listen elsewhere

Our guest, Johannes Ullrich from SANS Institute, joins Dave to discuss their research on "Machine Learning Risks: Attacks Against Apache NiFi." Using their honeypot network, researchers were able to collect some interesting data about a threat actor who is currently going after exposed Apache NiFi servers.

Researchers state “On May 19th, our distributed sensor network detected a notable spike in requests for ‘/nifi.’” Investigating further, they instructed a subset of their sensors to forward requests to an actual Apache NiFi instance and within a couple of hours the honeypot was completely compromised.

The research can be found here:

More description

Our guest, Johannes Ullrich from SANS Institute, joins Dave to discuss their research on "Machine Learning Risks: Attacks Against Apache NiFi." Using their honeypot network, researchers were able to collect some interesting data about a threat actor who is currently going after exposed Apache NiFi servers.

Researchers state “On May 19th, our distributed sensor network detected a notable spike in requests for ‘/nifi.’” Investigating further, they instructed a subset of their sensors to forward requests to an actual Apache NiFi instance and within a couple of hours the honeypot was completely compromised.

The research can be found here:

Extract Knowledge
Listen elsewhere

The US Government discloses exploitations of MOVEit vulnerabilities, and the Department of Energy is targeted by the Cl0p gang. CISA releases an updated advisory for Telerik vulnerabilities affecting Government servers. Shampoo malware emerges with multiple persistence mechanisms. How the IT Army of Ukraine can exemplify a cyber auxiliary. Russophone gamers are being targeted with ransomware. An alleged LockBit operator has been arrested. The FBI’s Deputy Assistant Director for cyber Cynthia Kaiser joins us with cybercriminal trends and recent successes. Our guest is Will Markow from Lightcast, speaking with Simone Petrella about data-driven strategic workforce decisions. And a federal grand jury indicts the alleged Discord Papers leaker.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/116


Selected reading.

US government hit by Russia's Clop in MOVEit mass attack (The Register)

Energy Department among ‘several’ federal agencies hit by MOVEit breach (Federal News Network)

Threat Actors Exploit Progress Telerik Vulnerabilities in Multiple U.S. Government IIS Servers (CISA)

CVE-2019-18935 Detail (NIST)

CVE-2017-9248 Detail (NIST)

Cryptographic Weakness (Telerik)

Shampoo: A New ChromeLoader Campaign (HP)

Cyber attacks on Rotterdam and Groningen websites (World Cargo News)

The Dynamics of the Ukrainian IT Army’s Campaign in Russia (Lawfare)

Watch: Why early failures in Ukraine's counter-offensive aren't Russian victories (The Telegraph)

Russian War Report: Anti-Ukrainian counteroffensive narratives fail to go viral (Atlantic Council)

Threat Actor Targets Russian Gaming Community With WannaCry-Imitator (Cyble)

Hackers infect Russian-speaking gamers with fake WannaCry ransomware (The Record)

Russian national arrested in Arizona, charged for alleged role in LockBit ransomware attacks (CyberScoop)

Suspected LockBit ransomware affiliate arrested, charged in US (BleepingComputer)

Russian national arrested in US for deploying LockBit ransomware (The Record)

Guardsman indicted on charges of disclosing classified national defense information (AP News)

Charges Against Alleged Pentagon Leaker Jack Teixeira Explained (Newsweek)

Jack Teixeira, Pentagon leaks suspect, indicted by federal grand jury (The Guardian)

More description

The US Government discloses exploitations of MOVEit vulnerabilities, and the Department of Energy is targeted by the Cl0p gang. CISA releases an updated advisory for Telerik vulnerabilities affecting Government servers. Shampoo malware emerges with multiple persistence mechanisms. How the IT Army of Ukraine can exemplify a cyber auxiliary. Russophone gamers are being targeted with ransomware. An alleged LockBit operator has been arrested. The FBI’s Deputy Assistant Director for cyber Cynthia Kaiser joins us with cybercriminal trends and recent successes. Our guest is Will Markow from Lightcast, speaking with Simone Petrella about data-driven strategic workforce decisions. And a federal grand jury indicts the alleged Discord Papers leaker.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/116


Selected reading.

US government hit by Russia's Clop in MOVEit mass attack (The Register)

Energy Department among ‘several’ federal agencies hit by MOVEit breach (Federal News Network)

Threat Actors Exploit Progress Telerik Vulnerabilities in Multiple U.S. Government IIS Servers (CISA)

CVE-2019-18935 Detail (NIST)

CVE-2017-9248 Detail (NIST)

Cryptographic Weakness (Telerik)

Shampoo: A New ChromeLoader Campaign (HP)

Cyber attacks on Rotterdam and Groningen websites (World Cargo News)

The Dynamics of the Ukrainian IT Army’s Campaign in Russia (Lawfare)

Watch: Why early failures in Ukraine's counter-offensive aren't Russian victories (The Telegraph)

Russian War Report: Anti-Ukrainian counteroffensive narratives fail to go viral (Atlantic Council)

Threat Actor Targets Russian Gaming Community With WannaCry-Imitator (Cyble)

Hackers infect Russian-speaking gamers with fake WannaCry ransomware (The Record)

Russian national arrested in Arizona, charged for alleged role in LockBit ransomware attacks (CyberScoop)

Suspected LockBit ransomware affiliate arrested, charged in US (BleepingComputer)

Russian national arrested in US for deploying LockBit ransomware (The Record)

Guardsman indicted on charges of disclosing classified national defense information (AP News)

Charges Against Alleged Pentagon Leaker Jack Teixeira Explained (Newsweek)

Jack Teixeira, Pentagon leaks suspect, indicted by federal grand jury (The Guardian)

Extract Knowledge
Listen elsewhere

A Chinese threat actor exploits a Barracuda vulnerability. The upgraded version of the Android GravityRAT can exfiltrate WhatsApp messages. Cybercriminals pose as security researchers to propagate malware. Updates on the Vidar threat operation. A new Romanian hacking group has emerged. Shuckworm collects intelligence, and may support targeting. The Washington Post’s Tim Starks explains the section 702 debate. Our guest is Rotem Iram from At-Bay with insights on email security. And Russia's Cadet Blizzard.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/115


Selected reading.

Android GravityRAT goes after WhatsApp backups (ESET)

Quarterly Adversarial Threat Report (Facebook)

Barracuda ESG Zero-Day Vulnerability (CVE-2023-2868) Exploited Globally by Aggressive and Skilled Actor, Suspected Links to China (Mandiant)

GravityRAT - The Two-Year Evolution Of An APT Targeting India (Cisco Talos)

Fake Security Researcher GitHub Repositories Deliver Malicious Implant (VulnCheck)

Darth Vidar: The Aesir Strike Back (Team Cymru)

Tracking Diicot: an emerging Romanian threat actor (Cado Security)

Shuckworm: Inside Russia’s Relentless Cyber Campaign Against Ukraine (Symantec)

Cadet Blizzard emerges as a novel and distinct Russian threat actor (Microsoft)

Destructive malware targeting Ukrainian organizations (Microsoft)

More description

A Chinese threat actor exploits a Barracuda vulnerability. The upgraded version of the Android GravityRAT can exfiltrate WhatsApp messages. Cybercriminals pose as security researchers to propagate malware. Updates on the Vidar threat operation. A new Romanian hacking group has emerged. Shuckworm collects intelligence, and may support targeting. The Washington Post’s Tim Starks explains the section 702 debate. Our guest is Rotem Iram from At-Bay with insights on email security. And Russia's Cadet Blizzard.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/115


Selected reading.

Android GravityRAT goes after WhatsApp backups (ESET)

Quarterly Adversarial Threat Report (Facebook)

Barracuda ESG Zero-Day Vulnerability (CVE-2023-2868) Exploited Globally by Aggressive and Skilled Actor, Suspected Links to China (Mandiant)

GravityRAT - The Two-Year Evolution Of An APT Targeting India (Cisco Talos)

Fake Security Researcher GitHub Repositories Deliver Malicious Implant (VulnCheck)

Darth Vidar: The Aesir Strike Back (Team Cymru)

Tracking Diicot: an emerging Romanian threat actor (Cado Security)

Shuckworm: Inside Russia’s Relentless Cyber Campaign Against Ukraine (Symantec)

Cadet Blizzard emerges as a novel and distinct Russian threat actor (Microsoft)

Destructive malware targeting Ukrainian organizations (Microsoft)

Extract Knowledge
Listen elsewhere

CISA, FBI, the MS-ISAC, and international partners are releasing this Cybersecurity Advisory to detail LockBit ransomware incidents and provide recommended mitigations to enable network defenders to proactively improve their organization’s defenses against this ransomware operation.

AA23-165A Alert, Technical Details, and Mitigations

Stopransomware.gov is a whole-of-government approach that gives one central location for ransomware resources and alerts.

See the Center for Internet Security (CIS) Critical Security Controls (CIS Controls) https://www.cisecurity.org/insights/white-papers/cis-community-defense-model-2-0 for information on strengthening an organization’s cybersecurity posture through implementing a prescriptive, prioritized, and simplified set of best.

See the CIS Community Defense Model 2.0 (CDM 2.0) for the effectiveness of the CIS Controls against the most prevalent types of attacks and how CDM 2.0 can be used to design, prioritize, implement, and improve an organization’s cybersecurity program.

See Blueprint for Ransomware Defense for a clear, actionable framework for ransomware mitigation, response, and recovery built around the CIS Controls.

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

More description

CISA, FBI, the MS-ISAC, and international partners are releasing this Cybersecurity Advisory to detail LockBit ransomware incidents and provide recommended mitigations to enable network defenders to proactively improve their organization’s defenses against this ransomware operation.

AA23-165A Alert, Technical Details, and Mitigations

Stopransomware.gov is a whole-of-government approach that gives one central location for ransomware resources and alerts.

See the Center for Internet Security (CIS) Critical Security Controls (CIS Controls) https://www.cisecurity.org/insights/white-papers/cis-community-defense-model-2-0 for information on strengthening an organization’s cybersecurity posture through implementing a prescriptive, prioritized, and simplified set of best.

See the CIS Community Defense Model 2.0 (CDM 2.0) for the effectiveness of the CIS Controls against the most prevalent types of attacks and how CDM 2.0 can be used to design, prioritize, implement, and improve an organization’s cybersecurity program.

See Blueprint for Ransomware Defense for a clear, actionable framework for ransomware mitigation, response, and recovery built around the CIS Controls.

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge
Listen elsewhere

The Five Eyes, alongside a couple of allies, issue a LockBit advisory. AI aids in proofreading phishing attacks. Anonymous Sudan mounts nuisance-level DDoS attacks against US companies. France alleges a disinformation campaign conducted by Russian actors. KillNet says it's partnered with the less-well-known Devil Sec. The private cybersecurity industry's effect on the war in Ukraine. Carole Theriault ponders oversharing on social media. Our guest is Duncan Jones from Quantinuum on the threats of Harvest Now, Decrypt Later tactics. And a note on this month’s Patch Tuesday.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/114


Selected reading.

Understanding Ransomware Threat Actors: LockBit (Joint Cybersecurity Advisory)

U.S. Measures in Response to the Crisis in Sudan (US Department of State)

Generative AI Enables Threat Actors to Create More (and More Sophisticated) Email Attacks (Abnormal Security)

France Accuses Russia of Online Disinformation Campaign (Bloomberg)

The Private Sector’s Evolving Role in Conflict—From Cyber Assistance to Intelligence (R Street)

Microsoft Patches Critical Windows Vulns, Warns of Code Execution Risks (SecurityWeek)

Patch Tuesday: Critical Flaws in Adobe Commerce Software (SecurityWeek)

Patch Tuesday fixes 4 critical RCE bugs, and a bunch of Office holes (Naked Security)

More description

The Five Eyes, alongside a couple of allies, issue a LockBit advisory. AI aids in proofreading phishing attacks. Anonymous Sudan mounts nuisance-level DDoS attacks against US companies. France alleges a disinformation campaign conducted by Russian actors. KillNet says it's partnered with the less-well-known Devil Sec. The private cybersecurity industry's effect on the war in Ukraine. Carole Theriault ponders oversharing on social media. Our guest is Duncan Jones from Quantinuum on the threats of Harvest Now, Decrypt Later tactics. And a note on this month’s Patch Tuesday.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/114


Selected reading.

Understanding Ransomware Threat Actors: LockBit (Joint Cybersecurity Advisory)

U.S. Measures in Response to the Crisis in Sudan (US Department of State)

Generative AI Enables Threat Actors to Create More (and More Sophisticated) Email Attacks (Abnormal Security)

France Accuses Russia of Online Disinformation Campaign (Bloomberg)

The Private Sector’s Evolving Role in Conflict—From Cyber Assistance to Intelligence (R Street)

Microsoft Patches Critical Windows Vulns, Warns of Code Execution Risks (SecurityWeek)

Patch Tuesday: Critical Flaws in Adobe Commerce Software (SecurityWeek)

Patch Tuesday fixes 4 critical RCE bugs, and a bunch of Office holes (Naked Security)

Extract Knowledge
Listen elsewhere

CISA issues a new Binding Operational Directive. An update on CosmicEnergy. Hackers’ homage to fromage in attacks against the Swiss government. Ukraine's Cyber Police shut down a pro-Russian bot farm. Clothing and footwear retailers see impersonation and online fraud. A 2021 ransomware attack contributed to a hospital closing. A proof-of-concept exploit of a patched MOVEit vulnerability. An industry letter calls for a new framework on the White House cybersecurity strategy. Joe Carrigan examines a ChatGPT fueled phishing scam. Our guest is Neha Rungta, Applied Science Director at AWS Identity discussing Amazon Verified Permissions. And trends in cyber risks for small and medium businesses.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/113


Selected reading.

Binding Operational Directive 23-02 (US Cybersecurity and Infrastructure Security Agency)

COSMICENERGY: New OT Malware Possibly Related To Russian Emergency Response Exercises (Mandiant)

Dragos Analysis Determines COSMICENERGY Is Not an Immediate Threat (Dragos)

More than 4,000 bots to discredit the Defense Forces of Ukraine and spread propaganda in favor of Russia: the police of Vinnytsia eliminated a large-scale bot farm (Ukraine Cyber Police)

Ukraine police raid social media bot farm accused of pro-Russia propaganda (The Record)

Widespread Brand Impersonation Scam Campaign Targeting Hundreds of the Most Popular Apparel Brands (Bolster)

An Illinois hospital is the first health care facility to link its closing to a ransomware attack (NBC News)

Ransomware attack causes Illinois hospital to close (Becker’s Hospital Review)

New BlackFog research: 61% of SMBs were victims of a cyberattack in the last year (BlackFog)

Switzerland warns that a ransomware gang may have accessed government data (The Record)

Swiss government warns of ongoing DDoS attacks, data leak (BleepingComputer)

Swiss Government Targeted by Series of Cyber-Attacks (Infosecurity Magazine)

DDoS attack on Federal Administration: various Federal Administration websites and applications unavailable (The Federal Council of the Swiss Government)

More description

CISA issues a new Binding Operational Directive. An update on CosmicEnergy. Hackers’ homage to fromage in attacks against the Swiss government. Ukraine's Cyber Police shut down a pro-Russian bot farm. Clothing and footwear retailers see impersonation and online fraud. A 2021 ransomware attack contributed to a hospital closing. A proof-of-concept exploit of a patched MOVEit vulnerability. An industry letter calls for a new framework on the White House cybersecurity strategy. Joe Carrigan examines a ChatGPT fueled phishing scam. Our guest is Neha Rungta, Applied Science Director at AWS Identity discussing Amazon Verified Permissions. And trends in cyber risks for small and medium businesses.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/113


Selected reading.

Binding Operational Directive 23-02 (US Cybersecurity and Infrastructure Security Agency)

COSMICENERGY: New OT Malware Possibly Related To Russian Emergency Response Exercises (Mandiant)

Dragos Analysis Determines COSMICENERGY Is Not an Immediate Threat (Dragos)

More than 4,000 bots to discredit the Defense Forces of Ukraine and spread propaganda in favor of Russia: the police of Vinnytsia eliminated a large-scale bot farm (Ukraine Cyber Police)

Ukraine police raid social media bot farm accused of pro-Russia propaganda (The Record)

Widespread Brand Impersonation Scam Campaign Targeting Hundreds of the Most Popular Apparel Brands (Bolster)

An Illinois hospital is the first health care facility to link its closing to a ransomware attack (NBC News)

Ransomware attack causes Illinois hospital to close (Becker’s Hospital Review)

New BlackFog research: 61% of SMBs were victims of a cyberattack in the last year (BlackFog)

Switzerland warns that a ransomware gang may have accessed government data (The Record)

Swiss government warns of ongoing DDoS attacks, data leak (BleepingComputer)

Swiss Government Targeted by Series of Cyber-Attacks (Infosecurity Magazine)

DDoS attack on Federal Administration: various Federal Administration websites and applications unavailable (The Federal Council of the Swiss Government)

Extract Knowledge
Listen elsewhere

Attacks against unpatched versions of Visual Studio and win32k continue. Progress Software patches two MOVEit vulnerabilities. The Cyber Anarchy Squad claims to have taken down a Russian telecommunications provider's infrastructure. RomCom resumes its activity in the Russian interest. Deepen Desai of Zscaler describes Nevada ransomware. Our guest is Clarke Rodgers from Amazon Web services with insights on what CISOs say to each other when no one else is listening?. And the Mt. Gox hacking indictment has been unsealed.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/112


Selected reading.

Online muggers make serious moves on unpatched Microsoft bugs (The Register)

Analysis of CVE-2023-29336 Win32k Privilege Escalation Vulnerability (with POC) (Numen)

MOVEit Transfer and MOVEit Cloud Vulnerability (Progress Software)

MDE Affected by Global Data Breach (Minnesota Department of Education)

Hackers Use Stolen Student Data Against Minneapolis Schools in Brazen New Threat (The 74)

Ofcom statement on MOVEit cyber attack (Ofcom)

Ukrainian hackers take down service provider for Russian banks (BleepingComputer)

Pro-Ukraine hackers claim to take down Russian internet provider (The Record)

Pro-Ukraine Cyber Anarchy Squad claims the hack of the Russian telecom provider Infotel JSC (Security Affairs)

RomCom Resurfaces: Targeting Politicians in Ukraine and U.S.-Based Healthcare Providing Aid to Refugees from Ukraine (BlackBerry)

Mt. Gox's Hackers Are 2 Russian Nationals, U.S. DOJ Alleges in Indictment (CoinDesk)

Russian nationals accused of Mt. Gox bitcoin heist, shifting stolen funds to BTC-e (The Record)

Russian Nationals Charged With Hacking One Cryptocurrency Exchange and Illicitly Operating Another (US Department of Justice)

More description

Attacks against unpatched versions of Visual Studio and win32k continue. Progress Software patches two MOVEit vulnerabilities. The Cyber Anarchy Squad claims to have taken down a Russian telecommunications provider's infrastructure. RomCom resumes its activity in the Russian interest. Deepen Desai of Zscaler describes Nevada ransomware. Our guest is Clarke Rodgers from Amazon Web services with insights on what CISOs say to each other when no one else is listening?. And the Mt. Gox hacking indictment has been unsealed.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/112


Selected reading.

Online muggers make serious moves on unpatched Microsoft bugs (The Register)

Analysis of CVE-2023-29336 Win32k Privilege Escalation Vulnerability (with POC) (Numen)

MOVEit Transfer and MOVEit Cloud Vulnerability (Progress Software)

MDE Affected by Global Data Breach (Minnesota Department of Education)

Hackers Use Stolen Student Data Against Minneapolis Schools in Brazen New Threat (The 74)

Ofcom statement on MOVEit cyber attack (Ofcom)

Ukrainian hackers take down service provider for Russian banks (BleepingComputer)

Pro-Ukraine hackers claim to take down Russian internet provider (The Record)

Pro-Ukraine Cyber Anarchy Squad claims the hack of the Russian telecom provider Infotel JSC (Security Affairs)

RomCom Resurfaces: Targeting Politicians in Ukraine and U.S.-Based Healthcare Providing Aid to Refugees from Ukraine (BlackBerry)

Mt. Gox's Hackers Are 2 Russian Nationals, U.S. DOJ Alleges in Indictment (CoinDesk)

Russian nationals accused of Mt. Gox bitcoin heist, shifting stolen funds to BTC-e (The Record)

Russian Nationals Charged With Hacking One Cryptocurrency Exchange and Illicitly Operating Another (US Department of Justice)

Extract Knowledge
Listen elsewhere

Nadir Izrael, co-founder and CTO from Armis, sits down to share his story. Nadir started his love of cyber when he became a software developer at the age of 12. He always had a passion for making things work better and asking questions. Once he joined the 8200 unit in Israel, he was able to focus his interests on physics, which led him to making the discovery of wanting to start his own business. After he started building his company is when he learned to take smart and innovative risks at work and making it a way of life. Nadir shares advice, saying "Playing to your strengths, maximizes the odds of success and every other consideration lowers them inevitably, or at least, uh, um, kind of shrinks, I guess the, the probability space for success." He thinks playing to ones strengths is the best a leader can do to create the most success for their team. We thank Nadir for sharing his story with us.

More description

Nadir Izrael, co-founder and CTO from Armis, sits down to share his story. Nadir started his love of cyber when he became a software developer at the age of 12. He always had a passion for making things work better and asking questions. Once he joined the 8200 unit in Israel, he was able to focus his interests on physics, which led him to making the discovery of wanting to start his own business. After he started building his company is when he learned to take smart and innovative risks at work and making it a way of life. Nadir shares advice, saying "Playing to your strengths, maximizes the odds of success and every other consideration lowers them inevitably, or at least, uh, um, kind of shrinks, I guess the, the probability space for success." He thinks playing to ones strengths is the best a leader can do to create the most success for their team. We thank Nadir for sharing his story with us.

Extract Knowledge
Listen elsewhere

Our guest, Allen West from Akamai's SIRT team, joins Dave to discuss their research on "The Dark Frost Enigma: An Unexpectedly Prevalent Botnet Author Profile." Akamai found this new botnet was targeting the gaming industry, modeled after Qbot, Mirai, and other malware strains. The botnet has expanded to encompass hundreds of compromised devices.

The research states "through reverse engineering and patching the malware binary, our analysis determined the botnet's attack potential at approximately 629.28 Gbps with its UDP flood attacks." Akamai researchers do a deep dive into the motives behind the attacks, the effectiveness of the attack, and how the law has been handling similar cases.

The research can be found here:

More description

Our guest, Allen West from Akamai's SIRT team, joins Dave to discuss their research on "The Dark Frost Enigma: An Unexpectedly Prevalent Botnet Author Profile." Akamai found this new botnet was targeting the gaming industry, modeled after Qbot, Mirai, and other malware strains. The botnet has expanded to encompass hundreds of compromised devices.

The research states "through reverse engineering and patching the malware binary, our analysis determined the botnet's attack potential at approximately 629.28 Gbps with its UDP flood attacks." Akamai researchers do a deep dive into the motives behind the attacks, the effectiveness of the attack, and how the law has been handling similar cases.

The research can be found here:

Extract Knowledge
Listen elsewhere

Barracuda Networks urges replacement of their gear. Fractureiser infects Minecraft mods. ChatGPT sees a court date over hallucinations and defamation. Asylum Ambuscade engages in both crime and espionage. The US delivers Ukraine Starlink connectivity. DDoS attacks hit the Swiss parliament's website. My conversation with Eric Goldstein, Executive Assistant Director for Cybersecurity at CISA. Our guest is Delilah Schwartz from Cybersixgill discussing how the Dark Web is evolving with new technologies like ChatGPT. And BEC crooks see their day in court.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/111


Selected reading.

Barracuda Email Security Gateway Appliance (ESG) Vulnerability (Barracuda)

CVE-2023-2868 (MITRE)

ACT government falls victim to Barracuda’s ESG vulnerability (CSO Online)

CVE-2023-2868: Total Compromise of Physical Barracuda ESG Appliances (Rapid7)

CVE-2023-2868 Detail (National Institute of Standards and Technology)

Infected Minecraft Mods Lead to Multi-Stage, Multi-Platform Infostealer Malware (Bitdefender)

New Fractureiser malware used CurseForge Minecraft mods to infect Windows, Linux (BleepingComputer)

IN THE SUPERIOR COURT OF FULTON COUNTY (Superior Court of Fulton County)

OpenAI Hit With First Defamation Suit Over ChatGPT Hallucination (Bloomberg Law)

More description

Barracuda Networks urges replacement of their gear. Fractureiser infects Minecraft mods. ChatGPT sees a court date over hallucinations and defamation. Asylum Ambuscade engages in both crime and espionage. The US delivers Ukraine Starlink connectivity. DDoS attacks hit the Swiss parliament's website. My conversation with Eric Goldstein, Executive Assistant Director for Cybersecurity at CISA. Our guest is Delilah Schwartz from Cybersixgill discussing how the Dark Web is evolving with new technologies like ChatGPT. And BEC crooks see their day in court.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/111


Selected reading.

Barracuda Email Security Gateway Appliance (ESG) Vulnerability (Barracuda)

CVE-2023-2868 (MITRE)

ACT government falls victim to Barracuda’s ESG vulnerability (CSO Online)

CVE-2023-2868: Total Compromise of Physical Barracuda ESG Appliances (Rapid7)

CVE-2023-2868 Detail (National Institute of Standards and Technology)

Infected Minecraft Mods Lead to Multi-Stage, Multi-Platform Infostealer Malware (Bitdefender)

New Fractureiser malware used CurseForge Minecraft mods to infect Windows, Linux (BleepingComputer)

IN THE SUPERIOR COURT OF FULTON COUNTY (Superior Court of Fulton County)

OpenAI Hit With First Defamation Suit Over ChatGPT Hallucination (Bloomberg Law)

Extract Knowledge
Listen elsewhere

FBI and CISA are releasing this joint CSA to disseminate known CL0P ransomware IOCs and TTPs identified through FBI investigations as recently as June 2023.

AA23-158A Alert, Technical Details, and Mitigations

Stopransomware.gov is a whole-of-government approach that gives one central location for ransomware resources and alerts.

Resource to mitigate a ransomware attack: CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide.

Zero-Day Vulnerability in MOVEit Transfer Exploited for Data Theft | Mandiant

MOVEit Transfer Critical Vulnerability (May 2023) - Progress Community

MOVEit Transfer Critical Vulnerability CVE-2023-34362 Rapid Response (huntress.com)

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

More description

FBI and CISA are releasing this joint CSA to disseminate known CL0P ransomware IOCs and TTPs identified through FBI investigations as recently as June 2023.

AA23-158A Alert, Technical Details, and Mitigations

Stopransomware.gov is a whole-of-government approach that gives one central location for ransomware resources and alerts.

Resource to mitigate a ransomware attack: CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide.

Zero-Day Vulnerability in MOVEit Transfer Exploited for Data Theft | Mandiant

MOVEit Transfer Critical Vulnerability (May 2023) - Progress Community

MOVEit Transfer Critical Vulnerability CVE-2023-34362 Rapid Response (huntress.com)

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge
Listen elsewhere

ChatGPT takes an unexpectedly human turn in having its own version of hallucinations. Updates on Cl0p’s ransom note, background, and recent promises. Researchers look at Instagram’s role in promoting CSAM. A look at KillNet's reboot. Andrea Little Limbago from Interos shares insight on cyber’s human element. Our guest is Aleksandr Yampolskiy from SecurityScorecard on how CISOs can effectively communicate cyber risk to their board. And a hacktivist auxiliary’s stellar advice for protecting your data.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/110


Selected reading.

Can you trust ChatGPT’s package recommendations? (Vulcan)

Ransomware group Clop issues extortion notice to ‘hundreds’ of victims (The Record)

MOVEit cyber attack: Cl0p sparks speculation that it’s lost control of hack (ITpro)

Responding to the Critical MOVEit Transfer Vulnerability (CVE-2023-34362) (Kroll)

MOVEit Transfer Critical Vulnerability (May 2023) (Progress)

Cybergang behind N.S. breach says it erased stolen data, but experts urge caution (CBC Canada)

Most SMBs admit to paying ransomware demands - here's why (TechRadar)

Instagram Connects Vast Pedophile Network (Wall Street Journal)

Addressing the distribution of illicit sexual content by minors online (Stanford University)

Rebooting Killnet, a New World Order and the End of the Tesla Botnet (Radware)

More description

ChatGPT takes an unexpectedly human turn in having its own version of hallucinations. Updates on Cl0p’s ransom note, background, and recent promises. Researchers look at Instagram’s role in promoting CSAM. A look at KillNet's reboot. Andrea Little Limbago from Interos shares insight on cyber’s human element. Our guest is Aleksandr Yampolskiy from SecurityScorecard on how CISOs can effectively communicate cyber risk to their board. And a hacktivist auxiliary’s stellar advice for protecting your data.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/110


Selected reading.

Can you trust ChatGPT’s package recommendations? (Vulcan)

Ransomware group Clop issues extortion notice to ‘hundreds’ of victims (The Record)

MOVEit cyber attack: Cl0p sparks speculation that it’s lost control of hack (ITpro)

Responding to the Critical MOVEit Transfer Vulnerability (CVE-2023-34362) (Kroll)

MOVEit Transfer Critical Vulnerability (May 2023) (Progress)

Cybergang behind N.S. breach says it erased stolen data, but experts urge caution (CBC Canada)

Most SMBs admit to paying ransomware demands - here's why (TechRadar)

Instagram Connects Vast Pedophile Network (Wall Street Journal)

Addressing the distribution of illicit sexual content by minors online (Stanford University)

Rebooting Killnet, a New World Order and the End of the Tesla Botnet (Radware)

Extract Knowledge
Listen elsewhere

A new PowerShell remote access tool targets a US defense contractor. Current Russian cyber operations against Ukraine are honing in on espionage. CISA and its partners have released a Joint Guide to Securing Remote Access Software. A bug has been reported in Visual Studio’s UI. Awais Rashid from University of Bristol discussing Privacy in health apps. Our guest is Jim Lippie of SaaS Alerts with insights on software as a service Application Security. And are there disconnects between cybersecurity and the legal profession?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/109


Selected reading.

PowerDrop: A New Insidious PowerShell Script for Command and Control Attacks Targets U.S. Aerospace Defense Industry (Adlumin)

UAC-0099: cyberespionage against state organizations and media representatives of Ukraine (CERT-UA#6710) (CERT-UA)

Guide to Securing Remote Access Software (Joint Guide)

Imposter Syndrome: UI Bug in Visual Studio Lets Attackers Impersonate Publishers (Varonis)

Press Release | ILTA and Conversant Group Release First Cybersecurity Benchmarking Survey of the Legal Industry (International Legal Technology Association)

More description

A new PowerShell remote access tool targets a US defense contractor. Current Russian cyber operations against Ukraine are honing in on espionage. CISA and its partners have released a Joint Guide to Securing Remote Access Software. A bug has been reported in Visual Studio’s UI. Awais Rashid from University of Bristol discussing Privacy in health apps. Our guest is Jim Lippie of SaaS Alerts with insights on software as a service Application Security. And are there disconnects between cybersecurity and the legal profession?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/109


Selected reading.

PowerDrop: A New Insidious PowerShell Script for Command and Control Attacks Targets U.S. Aerospace Defense Industry (Adlumin)

UAC-0099: cyberespionage against state organizations and media representatives of Ukraine (CERT-UA#6710) (CERT-UA)

Guide to Securing Remote Access Software (Joint Guide)

Imposter Syndrome: UI Bug in Visual Studio Lets Attackers Impersonate Publishers (Varonis)

Press Release | ILTA and Conversant Group Release First Cybersecurity Benchmarking Survey of the Legal Industry (International Legal Technology Association)

Extract Knowledge
Listen elsewhere

The Cl0p gang claims responsibility for the MOVEit file transfer vulnerability. Verizon’s DBIR is out. Palo Alto Networks takes a snapshot of last year’s threat trends. A new criminal campaign targets Android users wishing to install modified apps. A smishing campaign is expanding into the Middle East. Cisco observes compromised vendor and contractor accounts as an access point for network penetration. Cyclops ransomware acts as a dual threat. Anonymous Sudan demands $1 million to stop attacks on Microsoft platforms. Ben Yelin explains a groundbreaking decision on border searches. Our guest is Matt Caulfield of Oort with insights on identity security. And a deepfaked martial law announcement airs on Russian provincial radio stations.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/108


Selected reading.

Clop ransomware claims responsibility for MOVEit extortion attacks (BleepingComputer)

CVE-2023-34362 Detail (National Institute of Standards and Technology)

Microsoft links Clop ransomware gang to MOVEit data-theft attacks (BleepingComputer)

BA, BBC and Boots hit by cyber security breach with contact and bank details exposed (Sky News)

2023 Data Breach Investigations Report (Verizon)

2023 Unit 42 Network Threat Trends Research Report (Unit 42)

Tens of Thousands of Compromised Android Apps Found by Bitdefender Anomaly Detection Technology (Bitdefender)

Chinese-speaking phishing ring behind latest fake fee scam targeting Middle East; another campaign exposed (Group-IB)

Adversaries increasingly using vendor and contractor accounts to infiltrate networks (Cisco Talos)

Cyclops Ransomware and Stealer Combo: Exploring a Dual Threat (Uptycs)

U.S. Measures in Response to the Crisis in Sudan (US Department of State)

Microsoft's Outlook.com is down again on mobile, web (BleepingComputer)

Kremlin: fake Putin address broadcast on Russian radio stations after 'hack' (Reuters)

Deep fake video of Putin declaring martial law is broadcast in parts of Russia (Semafor)

Peskov called "Putin's emergency appeal" shown on some TV networks as a hack (TASS)

Proceedings of the 2023 U.S.-Ukraine Cyber Dialogue (US Department of State)

More description

The Cl0p gang claims responsibility for the MOVEit file transfer vulnerability. Verizon’s DBIR is out. Palo Alto Networks takes a snapshot of last year’s threat trends. A new criminal campaign targets Android users wishing to install modified apps. A smishing campaign is expanding into the Middle East. Cisco observes compromised vendor and contractor accounts as an access point for network penetration. Cyclops ransomware acts as a dual threat. Anonymous Sudan demands $1 million to stop attacks on Microsoft platforms. Ben Yelin explains a groundbreaking decision on border searches. Our guest is Matt Caulfield of Oort with insights on identity security. And a deepfaked martial law announcement airs on Russian provincial radio stations.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/108


Selected reading.

Clop ransomware claims responsibility for MOVEit extortion attacks (BleepingComputer)

CVE-2023-34362 Detail (National Institute of Standards and Technology)

Microsoft links Clop ransomware gang to MOVEit data-theft attacks (BleepingComputer)

BA, BBC and Boots hit by cyber security breach with contact and bank details exposed (Sky News)

2023 Data Breach Investigations Report (Verizon)

2023 Unit 42 Network Threat Trends Research Report (Unit 42)

Tens of Thousands of Compromised Android Apps Found by Bitdefender Anomaly Detection Technology (Bitdefender)

Chinese-speaking phishing ring behind latest fake fee scam targeting Middle East; another campaign exposed (Group-IB)

Adversaries increasingly using vendor and contractor accounts to infiltrate networks (Cisco Talos)

Cyclops Ransomware and Stealer Combo: Exploring a Dual Threat (Uptycs)

U.S. Measures in Response to the Crisis in Sudan (US Department of State)

Microsoft's Outlook.com is down again on mobile, web (BleepingComputer)

Kremlin: fake Putin address broadcast on Russian radio stations after 'hack' (Reuters)

Deep fake video of Putin declaring martial law is broadcast in parts of Russia (Semafor)

Peskov called "Putin's emergency appeal" shown on some TV networks as a hack (TASS)

Proceedings of the 2023 U.S.-Ukraine Cyber Dialogue (US Department of State)

Extract Knowledge
Listen elsewhere

Anonymous Sudan responds to remarks from the US Secretary of State by targeting Lyft and American hospitals. NSA releases an advisory on North Korean spearphishing campaigns. The US government’s Moonlighter satellite will test cybersecurity in orbit. "Operation Triangulation" offers an occasion for Russia to move closer to IT independence. The SEC drops cases over improper access to Adjudication Memoranda. Executives and board members are easy targets for threat actors trolling for sensitive information. Rick Howard targets Zero Trust. The FBI’s Deputy Assistant Director for Cyber Cynthia Kaiser shares trends from the IC3 Annual Report. And KillNet seems to say it's disbanding…or is it?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/107


Selected reading.

U.S. Measures in Response to the Crisis in Sudan (US Department of State)

U.S., ROK Agencies Alert: DPRK Cyber Actors Impersonating Targets to Collect Intelligence (US National Security Agency)

North Korea Using Social Engineering to Enable Hacking of Think Tanks, Academia, and Media (Joint Cybersecurity Advisory)

CISA Adds One Known Exploited Vulnerability to Catalog (Cybersecurity and Infrastructure Security Agency)

CVE-2023-34362 Detail (National Institute of Standards and Technology)

Zero-Day Vulnerability in MOVEit Transfer Exploited for Data Theft (Mandiant)

SpaceX launch sends upgraded solar arrays to International Space Station (Spaceflight Now)

Moonlighter Fact Sheet (The Aerospace Corporation)

Uncle Sam wants DEF CON hackers to pwn this Moonlighter satellite in space (The Register)

Russia wants 2 million phones with home-grown Aurora OS for use by officials (The Record)

Russia accuses U.S. of hacking thousands of iPhones (Axios)

Operation Triangulation: iOS devices targeted with previously unknown malware (Kaspersky)

Operation Triangulation: Mysterious attack on iPhones (ComputerBild)

Killnet hacktivists say they’re disbanding (Cybernews)

Second Commission Statement Relating to Certain Administrative Adjudications (US Securities and Exchange Commission)

Ponemon: Understanding the Serious Risks to Executives’ Personal Cybersecurity & Digital Lives (BlackCloak)

More description

Anonymous Sudan responds to remarks from the US Secretary of State by targeting Lyft and American hospitals. NSA releases an advisory on North Korean spearphishing campaigns. The US government’s Moonlighter satellite will test cybersecurity in orbit. "Operation Triangulation" offers an occasion for Russia to move closer to IT independence. The SEC drops cases over improper access to Adjudication Memoranda. Executives and board members are easy targets for threat actors trolling for sensitive information. Rick Howard targets Zero Trust. The FBI’s Deputy Assistant Director for Cyber Cynthia Kaiser shares trends from the IC3 Annual Report. And KillNet seems to say it's disbanding…or is it?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/107


Selected reading.

U.S. Measures in Response to the Crisis in Sudan (US Department of State)

U.S., ROK Agencies Alert: DPRK Cyber Actors Impersonating Targets to Collect Intelligence (US National Security Agency)

North Korea Using Social Engineering to Enable Hacking of Think Tanks, Academia, and Media (Joint Cybersecurity Advisory)

CISA Adds One Known Exploited Vulnerability to Catalog (Cybersecurity and Infrastructure Security Agency)

CVE-2023-34362 Detail (National Institute of Standards and Technology)

Zero-Day Vulnerability in MOVEit Transfer Exploited for Data Theft (Mandiant)

SpaceX launch sends upgraded solar arrays to International Space Station (Spaceflight Now)

Moonlighter Fact Sheet (The Aerospace Corporation)

Uncle Sam wants DEF CON hackers to pwn this Moonlighter satellite in space (The Register)

Russia wants 2 million phones with home-grown Aurora OS for use by officials (The Record)

Russia accuses U.S. of hacking thousands of iPhones (Axios)

Operation Triangulation: iOS devices targeted with previously unknown malware (Kaspersky)

Operation Triangulation: Mysterious attack on iPhones (ComputerBild)

Killnet hacktivists say they’re disbanding (Cybernews)

Second Commission Statement Relating to Certain Administrative Adjudications (US Securities and Exchange Commission)

Ponemon: Understanding the Serious Risks to Executives’ Personal Cybersecurity & Digital Lives (BlackCloak)

Extract Knowledge
Listen elsewhere

Galit Lubetzky Sharon, Co-Founder and CTO of Wing Security sits down to share her story and how years in the business lead her to be where she is now. Galit shares her insights from her experiences co-founding her company and bringing it out of stealth mode in early 2022, including why she saw the need for Wing Security and what lessons she learned in the process of founding and launching the company. She started her career as a Colonel in the 8200 Unit gives her a unique perspective on the cyber industry. Galit also shares what she does when things get stressful to help calm her down in the moment and help her clear her head. She says "I think it's very important to do things that you love. It should be something that you come and you bring yourself and your passion and, uh, finding yourself the occupation, the chores, the, the tasks that you love to do brings the, the best out of you." We thank Galit for sharing her story with us.

More description

Galit Lubetzky Sharon, Co-Founder and CTO of Wing Security sits down to share her story and how years in the business lead her to be where she is now. Galit shares her insights from her experiences co-founding her company and bringing it out of stealth mode in early 2022, including why she saw the need for Wing Security and what lessons she learned in the process of founding and launching the company. She started her career as a Colonel in the 8200 Unit gives her a unique perspective on the cyber industry. Galit also shares what she does when things get stressful to help calm her down in the moment and help her clear her head. She says "I think it's very important to do things that you love. It should be something that you come and you bring yourself and your passion and, uh, finding yourself the occupation, the chores, the, the tasks that you love to do brings the, the best out of you." We thank Galit for sharing her story with us.

Extract Knowledge
Listen elsewhere
Published 2023-06-03

Lancefly screams bloody Merdoor.

16 min
View

Brigid O Gorman from Symantec joins Dave to discuss their research, “Lancefly: Group Uses Custom Backdoor to Target Orgs in Government, Aviation, Other Sectors." Researchers discovered in 2020 that Lancefly, an APT group, is using a custom-written backdoor in attacks targeting government, aviation, educations, and telecoms organizations in South and Southeast Asia.

The research states "The backdoor is used very selectively, appearing on just a handful of networks and a small number of machines over the years, with its use appearing to be highly targeted." These targets, though observed in some activity in 2020 and 2021, started in 2022 and have continued into 2023.

The research can be found here:

More description

Brigid O Gorman from Symantec joins Dave to discuss their research, “Lancefly: Group Uses Custom Backdoor to Target Orgs in Government, Aviation, Other Sectors." Researchers discovered in 2020 that Lancefly, an APT group, is using a custom-written backdoor in attacks targeting government, aviation, educations, and telecoms organizations in South and Southeast Asia.

The research states "The backdoor is used very selectively, appearing on just a handful of networks and a small number of machines over the years, with its use appearing to be highly targeted." These targets, though observed in some activity in 2020 and 2021, started in 2022 and have continued into 2023.

The research can be found here:

Extract Knowledge
Listen elsewhere

MOVEit Transfer software sees exploitation. A website skimmer has been employed against targets in the Americas and Europe. A look into XeGroup's recent criminal activity. Apple denies the FSB’s allegations of collusion with NSA. Kaspersky investigates compromised devices. Johannes Ullrich from SANS describes phony YouTube "live streams". Our guest is Sherry Huang from William and Flora Hewlett Foundation to discuss their grants funding cyber policy studies. And the US Department of Defense provides Starlink services to Ukraine.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/106


Selected reading.

MOVEit Transfer Critical Vulnerability (May 2023) (Progress Software)

Rapid7 Observed Exploitation of Critical MOVEit Transfer Vulnerability (Rapid7)

New MOVEit Transfer zero-day mass-exploited in data theft attacks (BleepingComputer)

Hackers use flaw in popular file transfer tool to steal data, researchers say (Reuters)

New Magecart-Style Campaign Abusing Legitimate Websites to Attack Others (Akamai)

Not your average Joe: An analysis of the XeGroup’s attack techniques (Menlo Security)

Unmasking XE Group: Experts Reveal Identity of Suspected Cybercrime Kingpin (The Hacker News)

Apple denies surveillance claims made by Russia's FSB (Reuters)

FSB uncovers US intelligence operation via malware on Apple mobile phones (TASS)

Kaspersky Says New Zero-Day Malware Hit iPhones—Including Its Own (WIRED)

Operation Triangulation: iOS devices targeted with previously unknown malware (Kaspersky)

Lithuania becomes first to designate Russia as terrorist state (CSCE)

Pentagon confirms SpaceX deal for Ukraine Starlink services (C4ISRNET)

More description

MOVEit Transfer software sees exploitation. A website skimmer has been employed against targets in the Americas and Europe. A look into XeGroup's recent criminal activity. Apple denies the FSB’s allegations of collusion with NSA. Kaspersky investigates compromised devices. Johannes Ullrich from SANS describes phony YouTube "live streams". Our guest is Sherry Huang from William and Flora Hewlett Foundation to discuss their grants funding cyber policy studies. And the US Department of Defense provides Starlink services to Ukraine.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/106


Selected reading.

MOVEit Transfer Critical Vulnerability (May 2023) (Progress Software)

Rapid7 Observed Exploitation of Critical MOVEit Transfer Vulnerability (Rapid7)

New MOVEit Transfer zero-day mass-exploited in data theft attacks (BleepingComputer)

Hackers use flaw in popular file transfer tool to steal data, researchers say (Reuters)

New Magecart-Style Campaign Abusing Legitimate Websites to Attack Others (Akamai)

Not your average Joe: An analysis of the XeGroup’s attack techniques (Menlo Security)

Unmasking XE Group: Experts Reveal Identity of Suspected Cybercrime Kingpin (The Hacker News)

Apple denies surveillance claims made by Russia's FSB (Reuters)

FSB uncovers US intelligence operation via malware on Apple mobile phones (TASS)

Kaspersky Says New Zero-Day Malware Hit iPhones—Including Its Own (WIRED)

Operation Triangulation: iOS devices targeted with previously unknown malware (Kaspersky)

Lithuania becomes first to designate Russia as terrorist state (CSCE)

Pentagon confirms SpaceX deal for Ukraine Starlink services (C4ISRNET)

Extract Knowledge
Listen elsewhere

A backdoor-like issue has been found in Gigabyte firmware. A credential harvesting campaign impersonates Adobe. The Dark Pink gang is active in southeastern Asia. Mitiga discovers a “significant forensic discrepancy” in Google Drive. "Spyboy" is for sale in the C2C market. A look at Cuba ransomware. Ukrainian hacktivists target the Skolkovo Foundation. The FSB says NSA breached iPhones in Russia. Carole Theriault examines Utah's social media bills aimed at kids online. Our guest is Tucker Callaway of Mezmo to discuss the rise of telemetry pipelines. And spoofing positions and evading sanctions.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/105


Selected reading.

Supply Chain Risk from Gigabyte App Center backdoor (Eclypsium)

Ado-be-gone: Armorblox Stops Adobe Impersonation Attack (Armorblox)

Dark Pink back with a bang: 5 new organizations in 3 countries added to victim list (Group-IB)

Southeast Asian hacking crew racks up victims, rapidly expands criminal campaign (CyberScoop)

Suspected State-Backed Hackers Hit Series of New Targets in Europe, SE Asia (Insurance Journal)

Mitiga Security Advisory: Lack of Forensic Visibility with the Basic License in Google Drive (Mitiga)

2023-05-31 // SITUATIONAL AWARENESS // Spyboy Defense Evasion Tool Advertised Online (Reddit)

An In-Depth Look at Cuba Ransomware (Avertium)

Russia’s ‘Silicon Valley’ hit by cyberattack; Ukrainian group claims deep access (The Record)

Russia says U.S. accessed thousands of Apple phones in spy plot (Reuters)

Fake Signals and American Insurance: How a Dark Fleet Moves Russian Oil (The New York Times

More description

A backdoor-like issue has been found in Gigabyte firmware. A credential harvesting campaign impersonates Adobe. The Dark Pink gang is active in southeastern Asia. Mitiga discovers a “significant forensic discrepancy” in Google Drive. "Spyboy" is for sale in the C2C market. A look at Cuba ransomware. Ukrainian hacktivists target the Skolkovo Foundation. The FSB says NSA breached iPhones in Russia. Carole Theriault examines Utah's social media bills aimed at kids online. Our guest is Tucker Callaway of Mezmo to discuss the rise of telemetry pipelines. And spoofing positions and evading sanctions.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/105


Selected reading.

Supply Chain Risk from Gigabyte App Center backdoor (Eclypsium)

Ado-be-gone: Armorblox Stops Adobe Impersonation Attack (Armorblox)

Dark Pink back with a bang: 5 new organizations in 3 countries added to victim list (Group-IB)

Southeast Asian hacking crew racks up victims, rapidly expands criminal campaign (CyberScoop)

Suspected State-Backed Hackers Hit Series of New Targets in Europe, SE Asia (Insurance Journal)

Mitiga Security Advisory: Lack of Forensic Visibility with the Basic License in Google Drive (Mitiga)

2023-05-31 // SITUATIONAL AWARENESS // Spyboy Defense Evasion Tool Advertised Online (Reddit)

An In-Depth Look at Cuba Ransomware (Avertium)

Russia’s ‘Silicon Valley’ hit by cyberattack; Ukrainian group claims deep access (The Record)

Russia says U.S. accessed thousands of Apple phones in spy plot (Reuters)

Fake Signals and American Insurance: How a Dark Fleet Moves Russian Oil (The New York Times

Extract Knowledge
Listen elsewhere

SeroXen is a new elusive evolution of the Quasar RAT that seems to live up to its hype, and DogeRAT is a cheap Trojan targeting Indian Android users. Salesforce ghost sites see abuse by malicious actors. A look into identity security trends. People may be overconfident in their ability to detect deepfakes. Deepen Desai from Zscaler describes a campaign targeting Facebook users. CW Walker from Spycloud outlines identity exposure in the Fortune 1000. And a blurring of the lines between criminal, hacktivist, and strategic motivations.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/104


Selected reading.

SeroXen RAT for sale (AT&T Cybersecurity)

Sneaky DogeRAT Trojan Poses as Popular Apps, Targets Indian Android Users (The Hacker News)

DogeRAT: The Android Malware Campaign Targeting Users Across Multiple Industries (CloudSek)

Ghost Sites: Stealing Data From Deactivated Salesforce Communities (Varonis)

2023 Trends in Securing Digital Identities (Identity Defined Security Alliance)

Jumio 2023 Online Identity Consumer Study (Jumio)

Void Rabisu’s Use of RomCom Backdoor Shows a Growing Shift in Threat Actors’ Goals (Trend Micro)

Ukraine's DELTA Military System Users Under Attack from Info Stealing Malware (The Hacker News)

More description

SeroXen is a new elusive evolution of the Quasar RAT that seems to live up to its hype, and DogeRAT is a cheap Trojan targeting Indian Android users. Salesforce ghost sites see abuse by malicious actors. A look into identity security trends. People may be overconfident in their ability to detect deepfakes. Deepen Desai from Zscaler describes a campaign targeting Facebook users. CW Walker from Spycloud outlines identity exposure in the Fortune 1000. And a blurring of the lines between criminal, hacktivist, and strategic motivations.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/104


Selected reading.

SeroXen RAT for sale (AT&T Cybersecurity)

Sneaky DogeRAT Trojan Poses as Popular Apps, Targets Indian Android Users (The Hacker News)

DogeRAT: The Android Malware Campaign Targeting Users Across Multiple Industries (CloudSek)

Ghost Sites: Stealing Data From Deactivated Salesforce Communities (Varonis)

2023 Trends in Securing Digital Identities (Identity Defined Security Alliance)

Jumio 2023 Online Identity Consumer Study (Jumio)

Void Rabisu’s Use of RomCom Backdoor Shows a Growing Shift in Threat Actors’ Goals (Trend Micro)

Ukraine's DELTA Military System Users Under Attack from Info Stealing Malware (The Hacker News)

Extract Knowledge
Listen elsewhere

New Mirai malware uses low-complexity exploits to expand its botnet in IoT devices. The latest on Volt Typhoon. DDoS hits government sites in Senegal. The Pentagon's cyber strategy incorporates lessons from Russia's war, while the EU draws lessons from Ukraine's performance against Russia. Joe Carrigan explains Mandiant research on URL obfuscation. Mr. Security Answer Person John Pescatore plays security whack-a-mole. And NoName disrupts a British airport.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/103


Selected reading.

Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices (Unit 42)

US officials believe Chinese hackers may still have access to key US computer networks (CNN)

Chinese state-sponsored hackers infiltrated U.S. naval infrastructure, secretary of the Navy says (CNBC)

US military intelligence also targeted by Chinese hackers behind critical infrastructure compromise (SC Magazine)

Senegalese government websites hit with cyber attack (Reuters)

DOD Transmits 2023 Cyber Strategy (US Department of Defense)

Fact Sheet: 2023 DOD Cyber Strategy (US Department of Defense)

Lessons from the war in Ukraine for the future of EU defence (European Union External Action)

Investigation Launched After London City Airport Website Hacked (Simple Flying)

Maryland high school listed on Zillow for $42K in ‘creative’ senior prank (New York Post)

More description

New Mirai malware uses low-complexity exploits to expand its botnet in IoT devices. The latest on Volt Typhoon. DDoS hits government sites in Senegal. The Pentagon's cyber strategy incorporates lessons from Russia's war, while the EU draws lessons from Ukraine's performance against Russia. Joe Carrigan explains Mandiant research on URL obfuscation. Mr. Security Answer Person John Pescatore plays security whack-a-mole. And NoName disrupts a British airport.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/103


Selected reading.

Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices (Unit 42)

US officials believe Chinese hackers may still have access to key US computer networks (CNN)

Chinese state-sponsored hackers infiltrated U.S. naval infrastructure, secretary of the Navy says (CNBC)

US military intelligence also targeted by Chinese hackers behind critical infrastructure compromise (SC Magazine)

Senegalese government websites hit with cyber attack (Reuters)

DOD Transmits 2023 Cyber Strategy (US Department of Defense)

Fact Sheet: 2023 DOD Cyber Strategy (US Department of Defense)

Lessons from the war in Ukraine for the future of EU defence (European Union External Action)

Investigation Launched After London City Airport Website Hacked (Simple Flying)

Maryland high school listed on Zillow for $42K in ‘creative’ senior prank (New York Post)

Extract Knowledge
Listen elsewhere

Stacy Dunn, a Senior Solutions Engineer from the SANS Institute sits down and shares what it is like to work through her own adversity to get to be where she is today. Stacy shares some of her experiences as a woman with ADHD working in an IT career and explains her tips for other neurodiverse people in the field. After working in a wide array of positions in different fields, she wanted to go back to school to get her degree in management information systems and information assurance. Eventually she started working her way up the ladder, and became a very successful woman in the IT world. She shares her struggles with ADHD as she was making the climb and says "It's both a superpower and kryptonite because I think something that is a fundamental misunderstanding of most people, and maybe even some people that do have ADHD, is that it's not just the aspect of not being able to focus, it's also an aspect of focusing too much." We thank Stacy for sharing her story with us.

More description

Stacy Dunn, a Senior Solutions Engineer from the SANS Institute sits down and shares what it is like to work through her own adversity to get to be where she is today. Stacy shares some of her experiences as a woman with ADHD working in an IT career and explains her tips for other neurodiverse people in the field. After working in a wide array of positions in different fields, she wanted to go back to school to get her degree in management information systems and information assurance. Eventually she started working her way up the ladder, and became a very successful woman in the IT world. She shares her struggles with ADHD as she was making the climb and says "It's both a superpower and kryptonite because I think something that is a fundamental misunderstanding of most people, and maybe even some people that do have ADHD, is that it's not just the aspect of not being able to focus, it's also an aspect of focusing too much." We thank Stacy for sharing her story with us.

Extract Knowledge
Listen elsewhere

This week, our guests are Emily Austin and Himaja Motheram from Censys and their sharing their research - "Months after first GoAnywhere MFT zero-day attacks, Censys still sees about 180 public admin panels." In early February 2023, Censys researchers discovered a zero-day RCE vulnerability in Fortra’s “GoAnywhere MFT” (Managed File Transfer) software.

After finding this the Clop ransomware gang claimed that they exploited this vulnerability to breach the data of 130 organizations and Censys found other ransomware groups were jumping on the bandwagon. They said " A single vulnerable instance has the potential to serve as a gateway to a data breach that could potentially impact millions of individuals."

The research can be found here:

More description

This week, our guests are Emily Austin and Himaja Motheram from Censys and their sharing their research - "Months after first GoAnywhere MFT zero-day attacks, Censys still sees about 180 public admin panels." In early February 2023, Censys researchers discovered a zero-day RCE vulnerability in Fortra’s “GoAnywhere MFT” (Managed File Transfer) software.

After finding this the Clop ransomware gang claimed that they exploited this vulnerability to breach the data of 130 organizations and Censys found other ransomware groups were jumping on the bandwagon. They said " A single vulnerable instance has the potential to serve as a gateway to a data breach that could potentially impact millions of individuals."

The research can be found here:

Extract Knowledge
Listen elsewhere

CosmicEnergy is OT and ICS malware from Russia, maybe for red teaming, maybe for attack. Updates on Volt Typhoon, China’s battlespace preparation in Guam and elsewhere. In the criminal underworld, Legion malware has been upgraded for the cloud. Johannes Ullrich from SANS examines time gaps in logging. Our guest is Kevin Kirkwood from LogRhythm with a look at extortion attempts and ransomware. And Atlantic hurricane season officially opens next week: time to batten down those digital hatches. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/102


Selected reading.

COSMICENERGY: New OT Malware Possibly Related To Russian Emergency Response Exercises (Mandiant)

People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection (Joint Advisory)

Volt Typhoon targets US critical infrastructure with living-off-the-land techniques (Microsoft) 

China hits back at 'the empire of hacking' over Five Eyes US cyber attack claims (ABC)

Updates to Legion: A Cloud Credential Harvester and SMTP Hijacker (Cado)

Legion Malware Upgraded to Target SSH Servers and AWS Credentials (Hacker News)

CISA Warns of Hurricane/Typhoon-Related Scams (Cybersecurity and Infrastructure Security Agency CISA)

More description

CosmicEnergy is OT and ICS malware from Russia, maybe for red teaming, maybe for attack. Updates on Volt Typhoon, China’s battlespace preparation in Guam and elsewhere. In the criminal underworld, Legion malware has been upgraded for the cloud. Johannes Ullrich from SANS examines time gaps in logging. Our guest is Kevin Kirkwood from LogRhythm with a look at extortion attempts and ransomware. And Atlantic hurricane season officially opens next week: time to batten down those digital hatches. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/102


Selected reading.

COSMICENERGY: New OT Malware Possibly Related To Russian Emergency Response Exercises (Mandiant)

People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection (Joint Advisory)

Volt Typhoon targets US critical infrastructure with living-off-the-land techniques (Microsoft) 

China hits back at 'the empire of hacking' over Five Eyes US cyber attack claims (ABC)

Updates to Legion: A Cloud Credential Harvester and SMTP Hijacker (Cado)

Legion Malware Upgraded to Target SSH Servers and AWS Credentials (Hacker News)

CISA Warns of Hurricane/Typhoon-Related Scams (Cybersecurity and Infrastructure Security Agency CISA)

Extract Knowledge
Listen elsewhere

China's Volt Typhoon snoops into US infrastructure, with special attention paid to Guam. Iranian cybercriminals are seen conducting ops against Israeli targets. A new ransomware gang uses recycled ransomware. A persistent Brazilian campaign targets Portuguese financial institutions. A new botnet targets the gaming industry. Phishing attempts impersonate OpenAI. Pro-Russian geolocation graffiti. Andrea Little Limbago from Interos addresses the policy implications of ChatGPT. Our guest is Jon Check from Raytheon Intelligence & Space, on cybersecurity and workforce strategy for the space community. And KillNet says no to slacker hackers.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/101


Selected reading.

People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection (Joint Advisory)

Volt Typhoon targets US critical infrastructure with living-off-the-land techniques (Microsoft)

Chinese hackers spying on US critical infrastructure, Western intelligence says (Reuters)

Agrius Deploys Moneybird in Targeted Attacks Against Israeli Organizations (Check Point)

Iran-linked hackers Agrius deploying new ransomware against Israeli orgs (The Record)

Iranian Hackers Set Sights On Israeli Shipping & Logistics Firms (Information Security Buzz)

Fata Morgana: Watering hole attack on shipping and logistics websites (ClearSky Security)

Iran suspect in cyberattack targeting Israeli shipping, financial firms (Al-Monitor)

Buhti: New Ransomware Operation Relies on Repurposed Payloads (Symantec)

Operation Magalenha | Long-Running Campaign Pursues Portuguese Credentials and PII (SentinelOne)

The Dark Frost Enigma: An Unexpectedly Prevalent Botnet Author Profile (Akamai)

Fresh Phish: ChatGPT Impersonation Fuels a Clever Phishing Scam (INKY)

More description

China's Volt Typhoon snoops into US infrastructure, with special attention paid to Guam. Iranian cybercriminals are seen conducting ops against Israeli targets. A new ransomware gang uses recycled ransomware. A persistent Brazilian campaign targets Portuguese financial institutions. A new botnet targets the gaming industry. Phishing attempts impersonate OpenAI. Pro-Russian geolocation graffiti. Andrea Little Limbago from Interos addresses the policy implications of ChatGPT. Our guest is Jon Check from Raytheon Intelligence & Space, on cybersecurity and workforce strategy for the space community. And KillNet says no to slacker hackers.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/101


Selected reading.

People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection (Joint Advisory)

Volt Typhoon targets US critical infrastructure with living-off-the-land techniques (Microsoft)

Chinese hackers spying on US critical infrastructure, Western intelligence says (Reuters)

Agrius Deploys Moneybird in Targeted Attacks Against Israeli Organizations (Check Point)

Iran-linked hackers Agrius deploying new ransomware against Israeli orgs (The Record)

Iranian Hackers Set Sights On Israeli Shipping & Logistics Firms (Information Security Buzz)

Fata Morgana: Watering hole attack on shipping and logistics websites (ClearSky Security)

Iran suspect in cyberattack targeting Israeli shipping, financial firms (Al-Monitor)

Buhti: New Ransomware Operation Relies on Repurposed Payloads (Symantec)

Operation Magalenha | Long-Running Campaign Pursues Portuguese Credentials and PII (SentinelOne)

The Dark Frost Enigma: An Unexpectedly Prevalent Botnet Author Profile (Akamai)

Fresh Phish: ChatGPT Impersonation Fuels a Clever Phishing Scam (INKY)

Extract Knowledge
Listen elsewhere

Cybersecurity authorities are issuing this joint Cybersecurity Advisory to highlight a recent cluster of activity associated with a People’s Republic of China state-sponsored cyber actor, also known as Volt Typhoon. 

AA23-144A Alert, Technical Details, and Mitigations

Active Directory and domain controller hardening: Best Practices for Securing Active Directory | Microsoft Learn

CISA regional cyber threats: China Cyber Threat Overview and Advisories

Microsoft Threat Intelligence blog: Volt Typhoon targets US critical infrastructure with living-off-the-land techniques | Microsoft Security Blog

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

More description

Cybersecurity authorities are issuing this joint Cybersecurity Advisory to highlight a recent cluster of activity associated with a People’s Republic of China state-sponsored cyber actor, also known as Volt Typhoon. 

AA23-144A Alert, Technical Details, and Mitigations

Active Directory and domain controller hardening: Best Practices for Securing Active Directory | Microsoft Learn

CISA regional cyber threats: China Cyber Threat Overview and Advisories

Microsoft Threat Intelligence blog: Volt Typhoon targets US critical infrastructure with living-off-the-land techniques | Microsoft Security Blog

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge
Listen elsewhere

Kimsuky's tailored reconnaissance tools. GoldenJackal is an APT quietly active since 2019. Criminals target Youtube viewers with free cracked software. Rheinmetall’s data was posted to BlackBasta's extortion site. The "Cuba" gang claims credit for the attack on the Philadelphia Inquirer. CERT-UA identifies a probable Russian cyberespionage campaign. Ireland views cyber assistance to Ukraine as a contribution to collective security. Ann Johnson from Afternoon Cyber Tea speaks with Tyrance Billingsley about Black Tech. Our guest is Oz Alashe from CybSafe on raising VC money amidst a down economy. And KillNet's underperforming hacktivists.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/100


Selected reading.

Kimsuky | Ongoing Campaign Using Tailored Reconnaissance Toolkit (SentinelOne)

North Korean Kimsuky Hackers Strike Again with Advanced Reconnaissance Malware (The Hacker News)

Meet the GoldenJackal APT group. Don’t expect any howls (Kaspersky)

Follina — a Microsoft Office code execution vulnerability (DoublePulsar)

YouTube Pirated Software Videos Deliver Triple Threat: Vidar Stealer, Laplas Clipper, XMRig Miner (FortiGuard Labs)

Arms maker Rheinmetall confirms BlackBasta ransomware attack (Bleeping Computer)

Inquirer and forensics team investigating computer disruptions to publishing (Philadelphia Inquirer)

Cuba ransomware claims cyberattack on Philadelphia Inquirer (Bleeping Computer)

Espionage activity UAC-0063 in relation to Ukraine, Kazakhstan, Kyrgyzstan, Mongolia, Israel, India (CERT-UA#6549) (CERT-UA)

Ukraine Identifies Central Asian Cyberespionage Campaign (BankInfoSecurity)

Ireland’s cyber security agency has been providing ‘non-lethal aid’ to Ukraine (Irish Times)

More description

Kimsuky's tailored reconnaissance tools. GoldenJackal is an APT quietly active since 2019. Criminals target Youtube viewers with free cracked software. Rheinmetall’s data was posted to BlackBasta's extortion site. The "Cuba" gang claims credit for the attack on the Philadelphia Inquirer. CERT-UA identifies a probable Russian cyberespionage campaign. Ireland views cyber assistance to Ukraine as a contribution to collective security. Ann Johnson from Afternoon Cyber Tea speaks with Tyrance Billingsley about Black Tech. Our guest is Oz Alashe from CybSafe on raising VC money amidst a down economy. And KillNet's underperforming hacktivists.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/100


Selected reading.

Kimsuky | Ongoing Campaign Using Tailored Reconnaissance Toolkit (SentinelOne)

North Korean Kimsuky Hackers Strike Again with Advanced Reconnaissance Malware (The Hacker News)

Meet the GoldenJackal APT group. Don’t expect any howls (Kaspersky)

Follina — a Microsoft Office code execution vulnerability (DoublePulsar)

YouTube Pirated Software Videos Deliver Triple Threat: Vidar Stealer, Laplas Clipper, XMRig Miner (FortiGuard Labs)

Arms maker Rheinmetall confirms BlackBasta ransomware attack (Bleeping Computer)

Inquirer and forensics team investigating computer disruptions to publishing (Philadelphia Inquirer)

Cuba ransomware claims cyberattack on Philadelphia Inquirer (Bleeping Computer)

Espionage activity UAC-0063 in relation to Ukraine, Kazakhstan, Kyrgyzstan, Mongolia, Israel, India (CERT-UA#6549) (CERT-UA)

Ukraine Identifies Central Asian Cyberespionage Campaign (BankInfoSecurity)

Ireland’s cyber security agency has been providing ‘non-lethal aid’ to Ukraine (Irish Times)

Extract Knowledge
Listen elsewhere

AhRat exfiltrates files and records audio on Android devices. The BlackCat ransomware group uses a signed kernel driver to evade detection. GUI-Vil in the cloud. Unwitting money mules. Ben Yelin unpacks the Supreme Court’s section 230 rulings. Our guest is Mike DeNapoli from Cymulate with insights on cybersecurity effectiveness. And a trio of commercial spyware cases.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/99


Selected reading.

Android app breaking bad: From legitimate screen recording to file exfiltration within a year (ESET)

Love scam or espionage? Transparent Tribe lures Indian and Pakistani officials (ESET)

BlackCat Ransomware Deploys New Signed Kernel Driver (Trend Micro)

Unmasking GUI-Vil: Financially Motivated Cloud Threat Actor (Permiso)

Uncle Sam strangles criminals' cashflow by reining in money mules (The Register)

German prosecutors charge four over violating trade act to sell spyware to Turkey (Washington Post)

Israel Torpedoed Morocco Spyware Deal - and NSO Competitor QuaDream Shut Down (Haaretz)

He Was Investigating Mexico’s Military. Then the Spying Began. (New York Times)

More description

AhRat exfiltrates files and records audio on Android devices. The BlackCat ransomware group uses a signed kernel driver to evade detection. GUI-Vil in the cloud. Unwitting money mules. Ben Yelin unpacks the Supreme Court’s section 230 rulings. Our guest is Mike DeNapoli from Cymulate with insights on cybersecurity effectiveness. And a trio of commercial spyware cases.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/99


Selected reading.

Android app breaking bad: From legitimate screen recording to file exfiltration within a year (ESET)

Love scam or espionage? Transparent Tribe lures Indian and Pakistani officials (ESET)

BlackCat Ransomware Deploys New Signed Kernel Driver (Trend Micro)

Unmasking GUI-Vil: Financially Motivated Cloud Threat Actor (Permiso)

Uncle Sam strangles criminals' cashflow by reining in money mules (The Register)

German prosecutors charge four over violating trade act to sell spyware to Turkey (Washington Post)

Israel Torpedoed Morocco Spyware Deal - and NSO Competitor QuaDream Shut Down (Haaretz)

He Was Investigating Mexico’s Military. Then the Spying Began. (New York Times)

Extract Knowledge
Listen elsewhere

The EU fines Meta for transatlantic data transfers. FIN7 returns, bearing Cl0p ransomware. Python Package Index temporarily suspends new registrations due to a spike in malicious activity. Typosquatting and TurkoRAT. UNC3944 uses SIM swapping to gain access to Azure admin accounts. A Turla retrospective. Rick Howard tackles workforce development. Our guest is Andrew Peterson of Fastly to discuss the intricate challenges of secure software development. And the FBI was found overstepping its surveillance authorities.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/98


Selected reading.

Meta Fined $1.3 Billion Over Data Transfers to U.S. (Wall Street Journal)

Meta fined record $1.3 billion and ordered to stop sending European user data to US (AP News)

Notorious Cyber Gang FIN7 Returns With Cl0p Ransomware in New Wave of Attacks (The Hacker News)

Researchers tie FIN7 cybercrime family to Clop ransomware (The Record)

Cybercrime gang FIN7 returned and was spotted delivering Clop ransomware (Security Affairs)

PyPI new user and new project registrations temporarily suspended. (Python)

PyPI repository restored after temporarily suspending new activity (Computing)

RATs found hiding in the NPM attic (ReversingLabs)

Legitimate looking npm packages found hosting TurkoRat infostealer (CSO Online)

SIM Swapping and Abuse of the Microsoft Azure Serial Console: Serial Is Part of a Well Balanced Attack (Mandiant)

Mozilla Explains: SIM swapping (Mozilla)

The Underground History of Russia’s Most Ingenious Hacker Group (WIRED)

Justice Department Announces Court-Authorized Disruption of Snake Malware Network Controlled by Russia’s Federal Security Service (US Department of Justice)

Hunting Russian Intelligence “Snake” Malware (CISA)

FBI misused intelligence database in 278,000 searches, court says (Reuters)

FBI misused controversial surveillance tool to investigate Jan. 6 protesters (The Record)

FBI broke rules in scouring foreign intelligence on Jan. 6 riot, racial justice protests, court says (AP News)

More description

The EU fines Meta for transatlantic data transfers. FIN7 returns, bearing Cl0p ransomware. Python Package Index temporarily suspends new registrations due to a spike in malicious activity. Typosquatting and TurkoRAT. UNC3944 uses SIM swapping to gain access to Azure admin accounts. A Turla retrospective. Rick Howard tackles workforce development. Our guest is Andrew Peterson of Fastly to discuss the intricate challenges of secure software development. And the FBI was found overstepping its surveillance authorities.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/98


Selected reading.

Meta Fined $1.3 Billion Over Data Transfers to U.S. (Wall Street Journal)

Meta fined record $1.3 billion and ordered to stop sending European user data to US (AP News)

Notorious Cyber Gang FIN7 Returns With Cl0p Ransomware in New Wave of Attacks (The Hacker News)

Researchers tie FIN7 cybercrime family to Clop ransomware (The Record)

Cybercrime gang FIN7 returned and was spotted delivering Clop ransomware (Security Affairs)

PyPI new user and new project registrations temporarily suspended. (Python)

PyPI repository restored after temporarily suspending new activity (Computing)

RATs found hiding in the NPM attic (ReversingLabs)

Legitimate looking npm packages found hosting TurkoRat infostealer (CSO Online)

SIM Swapping and Abuse of the Microsoft Azure Serial Console: Serial Is Part of a Well Balanced Attack (Mandiant)

Mozilla Explains: SIM swapping (Mozilla)

The Underground History of Russia’s Most Ingenious Hacker Group (WIRED)

Justice Department Announces Court-Authorized Disruption of Snake Malware Network Controlled by Russia’s Federal Security Service (US Department of Justice)

Hunting Russian Intelligence “Snake” Malware (CISA)

FBI misused intelligence database in 278,000 searches, court says (Reuters)

FBI misused controversial surveillance tool to investigate Jan. 6 protesters (The Record)

FBI broke rules in scouring foreign intelligence on Jan. 6 riot, racial justice protests, court says (AP News)

Extract Knowledge
Listen elsewhere

Dawn Cappelli, OT CERT Director at Dragos, sits down to share what she has learned after her 25+ year career in the industry. She recalls wanting to have been a rockstar when she grew up, now she refers to herself as the fairy godmother of security. She shares some of the amazing things she got to work on throughout her career, including working with the Secret Service when the Olympics came to Salt Lake City, Utah in 2002. She shares how she was able to rise through the ranks to get to where she is now. Dawn talks about how she wasn't ready to retire quite yet because she loved the industry so much, saying "I retired, but I knew I still loved security. I have this passion for protection and so Dragos came along and they offered me this role of Director of OT CERT. I feel like I'm the security fairy godmother." She shares words of wisdom for all trying to get into the industry, saying that you need to always take the risk like she did when she first started her career. We thank Dawn for sharing her story with us.

More description

Dawn Cappelli, OT CERT Director at Dragos, sits down to share what she has learned after her 25+ year career in the industry. She recalls wanting to have been a rockstar when she grew up, now she refers to herself as the fairy godmother of security. She shares some of the amazing things she got to work on throughout her career, including working with the Secret Service when the Olympics came to Salt Lake City, Utah in 2002. She shares how she was able to rise through the ranks to get to where she is now. Dawn talks about how she wasn't ready to retire quite yet because she loved the industry so much, saying "I retired, but I knew I still loved security. I have this passion for protection and so Dragos came along and they offered me this role of Director of OT CERT. I feel like I'm the security fairy godmother." She shares words of wisdom for all trying to get into the industry, saying that you need to always take the risk like she did when she first started her career. We thank Dawn for sharing her story with us.

Extract Knowledge
Listen elsewhere

Willy R. Vasquez from The University of Texas at Austin discussing research on "The Most Dangerous Codec in the World - Finding and Exploiting Vulnerabilities in H.264 Decoders." Researchers are looking at the marvel that is modern video encoding standards such as H.264 for vulnerabilities and ultimately hidden security risks.

The research states "We introduce and evaluate H26FORGE, domain-specific infrastructure for analyzing, generating, and manipulating syntactically correct but semantically spec-non-compliant video files." Using H26FORCE, they were able to uncover insecurities in depth across the video decoder ecosystem, including kernel memory corruption bugs in iOS and video accelerator and application processor kernel memory bugs in Android devices.

The research can be found here:

More description

Willy R. Vasquez from The University of Texas at Austin discussing research on "The Most Dangerous Codec in the World - Finding and Exploiting Vulnerabilities in H.264 Decoders." Researchers are looking at the marvel that is modern video encoding standards such as H.264 for vulnerabilities and ultimately hidden security risks.

The research states "We introduce and evaluate H26FORGE, domain-specific infrastructure for analyzing, generating, and manipulating syntactically correct but semantically spec-non-compliant video files." Using H26FORCE, they were able to uncover insecurities in depth across the video decoder ecosystem, including kernel memory corruption bugs in iOS and video accelerator and application processor kernel memory bugs in Android devices.

The research can be found here:

Extract Knowledge
Listen elsewhere

Section 230 survives SCOTUS. Lemon Group's pre-infected devices. The IRS is sending cyber attachés to four countries in a new pilot program. A Wisconsin man is charged with stealing DraftKings credentials. Russian hacktivists conduct DDoS attacks against Polish news outlets. An update on RedStinger. Grayson Milbourne from OpenText Cybersecurity discusses IoT and the price we pay for convenience. Our guest is Matthew Keeley with info on an open source domain spoofing tool, Spoofy. And war principles and hacktivist auxiliaries.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/97


Selected reading.

“Honey, I’m Hacked”: Ethical Questions Raised by Ukrainian Cyber Deception of Russian Military Wives (Just Security)

A Mysterious Group Has Ties to 15 Years of Ukraine-Russia Hacks (Wired)

CloudWizard APT: the bad magic story goes on (SecureList)

Ukraine at D+441: Skirmishing along the line of contact, and in cyberspace. (The CyberWire)

Russian dissident gets three years in prison colony for DDoS attacks on military website (Cybernews)

Europe: The DDoS battlefield (Help Net Security)

Russian hackers hit Polish news sites in DDoS attack (Cybernews)

18-year-old charged with hacking 60,000 DraftKings betting accounts (Bleeping Computer)

Garrison Complaint (Department of Justice)

IRS-CI deploys 4 cyber attachés to locations abroad to combat cybercrime (IRS)

IRS deploys cyber attachés to fight cybercrime abroad (The Hill)

Cybercrime gang pre-infects millions of Android devices with malware (Bleeping Computer)

This Cybercrime Syndicate Pre-Infected Over 8.9 Million Android Phones Worldwide (The Hacker News)

Lemon Group’s Cybercriminal Businesses Built on Preinfected Devices (Trend Micro)

More description

Section 230 survives SCOTUS. Lemon Group's pre-infected devices. The IRS is sending cyber attachés to four countries in a new pilot program. A Wisconsin man is charged with stealing DraftKings credentials. Russian hacktivists conduct DDoS attacks against Polish news outlets. An update on RedStinger. Grayson Milbourne from OpenText Cybersecurity discusses IoT and the price we pay for convenience. Our guest is Matthew Keeley with info on an open source domain spoofing tool, Spoofy. And war principles and hacktivist auxiliaries.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/97


Selected reading.

“Honey, I’m Hacked”: Ethical Questions Raised by Ukrainian Cyber Deception of Russian Military Wives (Just Security)

A Mysterious Group Has Ties to 15 Years of Ukraine-Russia Hacks (Wired)

CloudWizard APT: the bad magic story goes on (SecureList)

Ukraine at D+441: Skirmishing along the line of contact, and in cyberspace. (The CyberWire)

Russian dissident gets three years in prison colony for DDoS attacks on military website (Cybernews)

Europe: The DDoS battlefield (Help Net Security)

Russian hackers hit Polish news sites in DDoS attack (Cybernews)

18-year-old charged with hacking 60,000 DraftKings betting accounts (Bleeping Computer)

Garrison Complaint (Department of Justice)

IRS-CI deploys 4 cyber attachés to locations abroad to combat cybercrime (IRS)

IRS deploys cyber attachés to fight cybercrime abroad (The Hill)

Cybercrime gang pre-infects millions of Android devices with malware (Bleeping Computer)

This Cybercrime Syndicate Pre-Infected Over 8.9 Million Android Phones Worldwide (The Hacker News)

Lemon Group’s Cybercriminal Businesses Built on Preinfected Devices (Trend Micro)

Extract Knowledge
Listen elsewhere

Business email compromise (BEC) exploits legitimate services. A hacktivist ransomware group demands charity donations for encrypted files. Trends and threats in API protection. The effects of hacktivism on Russia's war against Ukraine. Executive digital protection. Deepen Desai of Zscaler explains security risks in OneNote. Our guest is Ajay Bhatia of Veritas Technologies with advice for onboarding new employees. And news organizations as attractive targets.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/96


Selected reading.

Leveraging Dropbox to Soar Into Inbox (Avanan)

MalasLocker ransomware targets Zimbra servers, demands charity donation (Bleeping Computer)

Shadow API Usage Surges 900%, Revealing Alarming Lack of API Visibility Among Enterprises (Business Wire)

APIs are Top Cybersecurity Priority for Most Organizations, Yet 40% Do Not Have an API Security Solution (PR Newswire)

Evolving Cyber Operations and Capabilities (CSIS)

Following the long-running Russian aggression against Ukraine. (The CyberWire)

Executive Digital Protection whitepaper (Agency)

The Philadelphia Inquirer’s operations continue to be disrupted by a cyber incident (The Philadelphia Inquirer)

Cyberattack at the Philadelphia Inquirer. (The CyberWire)

More description

Business email compromise (BEC) exploits legitimate services. A hacktivist ransomware group demands charity donations for encrypted files. Trends and threats in API protection. The effects of hacktivism on Russia's war against Ukraine. Executive digital protection. Deepen Desai of Zscaler explains security risks in OneNote. Our guest is Ajay Bhatia of Veritas Technologies with advice for onboarding new employees. And news organizations as attractive targets.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/96


Selected reading.

Leveraging Dropbox to Soar Into Inbox (Avanan)

MalasLocker ransomware targets Zimbra servers, demands charity donation (Bleeping Computer)

Shadow API Usage Surges 900%, Revealing Alarming Lack of API Visibility Among Enterprises (Business Wire)

APIs are Top Cybersecurity Priority for Most Organizations, Yet 40% Do Not Have an API Security Solution (PR Newswire)

Evolving Cyber Operations and Capabilities (CSIS)

Following the long-running Russian aggression against Ukraine. (The CyberWire)

Executive Digital Protection whitepaper (Agency)

The Philadelphia Inquirer’s operations continue to be disrupted by a cyber incident (The Philadelphia Inquirer)

Cyberattack at the Philadelphia Inquirer. (The CyberWire)

Extract Knowledge
Listen elsewhere

FBI, CISA, and the Australian Cyber Security Centre are releasing this joint Cybersecurity Advisory to disseminate known BianLian ransomware and data extortion group IOCs and TTPs identified through FBI and ACSC investigations as of March 2023.

AA23-136A Alert, Technical Details, and Mitigations

AA23-136A.STIX_.xml

Stopransomware.gov, a whole-of-government approach with one central location for U.S. ransomware resources and alerts.

cyber.gov.au for the Australian Government’s central location to report cyber incidents, including ransomware, and to see advice and alerts. The site also provides ransomware advisories for businesses and organizations to help mitigate cyber threats.

CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide for guidance on mitigating and responding to a ransomware attack

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

More description

FBI, CISA, and the Australian Cyber Security Centre are releasing this joint Cybersecurity Advisory to disseminate known BianLian ransomware and data extortion group IOCs and TTPs identified through FBI and ACSC investigations as of March 2023.

AA23-136A Alert, Technical Details, and Mitigations

AA23-136A.STIX_.xml

Stopransomware.gov, a whole-of-government approach with one central location for U.S. ransomware resources and alerts.

cyber.gov.au for the Australian Government’s central location to report cyber incidents, including ransomware, and to see advice and alerts. The site also provides ransomware advisories for businesses and organizations to help mitigate cyber threats.

CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide for guidance on mitigating and responding to a ransomware attack

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge
Listen elsewhere
Show details
Episodes
3784
Transcripts
67
2% coverage
Missing transcripts
3717
With chapters
0