Search this show’s transcripts

CyberWire Daily

en us
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
More details
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
Sources and links

Episodes

Page 28 · 50 per page

Cyber agencies warn of BianLian ransomware. There’s a new gang using leaked Baduk-based ransomware. Chinese government-linked threat actors target TP-link routers with custom malware. ChatGPT-themed fleeceware is showing up in online stores. Ukraine is now a member of NATO's Cyber Centre. Tim Starks from the Washington Post shares insights on section 702 renewal. Our guest is Ismael Valenzuela from BlackBerry sharing the findings from their Global Threat Intelligence Report. And the CIA's offer to Russian officials may have had some takers.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/95


Selected reading.

#StopRansomware: BianLian Ransomware Group (Cybersecurity and Infrastructure Security Agency CISA) 

Newly identified RA Group compromises companies in U.S. and South Korea with leaked Babuk source code (Cisco Talos Blog) 

The Dragon Who Sold His Camaro: Analyzing Custom Router Implant (Check Point Research)

Fake ChatGPT Apps Scam Users Out of Thousands of Dollars, Sophos Reports (GlobeNewswire News Room) 

Ukraine joins NATO Cyber Centre (Computing) 

Russian Officials Unnerved by Ukraine Bloodshed Are Contacting CIA, Agency Says (Wall Street Journal)

More description

Cyber agencies warn of BianLian ransomware. There’s a new gang using leaked Baduk-based ransomware. Chinese government-linked threat actors target TP-link routers with custom malware. ChatGPT-themed fleeceware is showing up in online stores. Ukraine is now a member of NATO's Cyber Centre. Tim Starks from the Washington Post shares insights on section 702 renewal. Our guest is Ismael Valenzuela from BlackBerry sharing the findings from their Global Threat Intelligence Report. And the CIA's offer to Russian officials may have had some takers.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/95


Selected reading.

#StopRansomware: BianLian Ransomware Group (Cybersecurity and Infrastructure Security Agency CISA) 

Newly identified RA Group compromises companies in U.S. and South Korea with leaked Babuk source code (Cisco Talos Blog) 

The Dragon Who Sold His Camaro: Analyzing Custom Router Implant (Check Point Research)

Fake ChatGPT Apps Scam Users Out of Thousands of Dollars, Sophos Reports (GlobeNewswire News Room) 

Ukraine joins NATO Cyber Centre (Computing) 

Russian Officials Unnerved by Ukraine Bloodshed Are Contacting CIA, Agency Says (Wall Street Journal)

Extract Knowledge
Listen elsewhere

In today’s world, conventional cyber thinking remains largely focused on perimeter-centric security controls designed to govern how identities and endpoints utilize networks to access applications and data that organizations possess internally. Against this backdrop, a group of innovators and security thought leaders are exploring a new frontier and asking the question: shouldn’t there be a standard way to protect sensitive data regardless of where it resides or who it’s been shared with? It’s called “data-centric” security and it’s fundamentally different from “perimeter-centric” security models. Practicing it at scale requires a standard way to extend the value of “upstream” data governance (discovery, classification, tagging) into “downstream” collaborative workflows like email, file sharing, and SaaS apps.

In this episode of CyberWire-X, the CyberWire’s Rick Howard and Dave Bittner explore modern approaches for applying and enforcing policy and access controls to sensitive data which inevitably leaves your possession but still deserves just as much security as the data that you possess internally. Rick and Dave are joined by guests Bill Newhouse, Cybersecurity Engineer at National Institute of Standards and Technology (NIST) National Cybersecurity Center of Excellence (NCCoE), and Dana Morris, Senior Vice President for Product and Engineering of our episode sponsor Virtru. 

More description

In today’s world, conventional cyber thinking remains largely focused on perimeter-centric security controls designed to govern how identities and endpoints utilize networks to access applications and data that organizations possess internally. Against this backdrop, a group of innovators and security thought leaders are exploring a new frontier and asking the question: shouldn’t there be a standard way to protect sensitive data regardless of where it resides or who it’s been shared with? It’s called “data-centric” security and it’s fundamentally different from “perimeter-centric” security models. Practicing it at scale requires a standard way to extend the value of “upstream” data governance (discovery, classification, tagging) into “downstream” collaborative workflows like email, file sharing, and SaaS apps.

In this episode of CyberWire-X, the CyberWire’s Rick Howard and Dave Bittner explore modern approaches for applying and enforcing policy and access controls to sensitive data which inevitably leaves your possession but still deserves just as much security as the data that you possess internally. Rick and Dave are joined by guests Bill Newhouse, Cybersecurity Engineer at National Institute of Standards and Technology (NIST) National Cybersecurity Center of Excellence (NCCoE), and Dana Morris, Senior Vice President for Product and Engineering of our episode sponsor Virtru. 

Extract Knowledge
Listen elsewhere

DDoS "carpet bombing." Lancefly infests Asian targets. Cyber insurance trends. Infostealers in the C2C market. A Russian espionage service is masquerading as a criminal gang. KillNet’s running a psyop radio station of questionable quality. Joe Carrigan describes baiting fraudsters with fake crypto. Our guest is Gemma Moore of Cyberis talking about how red teaming can upskill detection and response teams. And geopolitical DDoS.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/94


Selected reading.

2023 DDoS Threat Intelligence Report (Corero)

Lancefly: Group Uses Custom Backdoor to Target Orgs in Government, Aviation, Other Sectors (Symantec)

2023 Cyber Claims Report (Coalition)

The Growing Threat from Infostealers (Secureworks)

Cybercriminals who targeted Ukraine are actually Russian government hackers, researchers say (TechCrunch)

DDoS Attacks Targeting NATO Members Increasing (Netscout)

Following the long-running Russian aggression against Ukraine. (The CyberWire)

More description

DDoS "carpet bombing." Lancefly infests Asian targets. Cyber insurance trends. Infostealers in the C2C market. A Russian espionage service is masquerading as a criminal gang. KillNet’s running a psyop radio station of questionable quality. Joe Carrigan describes baiting fraudsters with fake crypto. Our guest is Gemma Moore of Cyberis talking about how red teaming can upskill detection and response teams. And geopolitical DDoS.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/94


Selected reading.

2023 DDoS Threat Intelligence Report (Corero)

Lancefly: Group Uses Custom Backdoor to Target Orgs in Government, Aviation, Other Sectors (Symantec)

2023 Cyber Claims Report (Coalition)

The Growing Threat from Infostealers (Secureworks)

Cybercriminals who targeted Ukraine are actually Russian government hackers, researchers say (TechCrunch)

DDoS Attacks Targeting NATO Members Increasing (Netscout)

Following the long-running Russian aggression against Ukraine. (The CyberWire)

Extract Knowledge
Listen elsewhere

Discord sees a third-party data breach. Black Basta conducts a ransomware attack against technology company ABB. Intrusion Truth returns to dox APT41. Anonymous Sudan looks like a Russian front operation. Attribution and motivation of "RedStinger" remain murky. CISA summarizes Russian cyber offensives. Remote code execution exploits Ruckus in the wild. Our guest is Dave Russell from Veeam with insights on data protection. Matt O'Neill from the US Secret Service on their efforts to thwart email compromise and romance scams. And espionage by way of YouTube comments.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/93


Selected reading.

Discord discloses data breach after support agent got hacked (Bleeping Computer)

Discord suffered a data after third-party support agent was hacked (Security Affairs)

Multinational tech firm ABB hit by Black Basta ransomware attack (Bleeping Computer)

Breaking: ABB confirms cyberattack; work underway to restore operations (ET CISO)

Black Basta conducts ransomware attack against Swiss technology company ABB (The CyberWire)

They dox Chinese hackers. Now, they’re back. (Washington Post)

What’s Cracking at the Kerui Cracking Academy? (Intrusion Truth)

Posing as Islamists, Russian Hackers Take Aim at Sweden (Bloomberg)

Anonymous Sudan: Threat Intelligence Report (TrueSec)

Uncovering RedStinger - Undetected APT cyber operations in Eastern Europe since 2020 (Malwarebytes)

Russian ‘Red Stealer’ cyberattacks target breakaway territories in Ukraine (Cybernews)

Russia Cyber Threat Overview and Advisories (CISA)

Known Exploited Vulnerabilities Catalog (CISA)

CISA Adds Seven Known Exploited Vulnerabilities to Catalog (CISA)

CISA warns of critical Ruckus bug used to infect Wi-Fi access points (Bleeping Computer)

Security Bulletins (Ruckus)

ROK union leaders charged with spying for North Korea in ‘movie-like’ scheme (NK News)

More description

Discord sees a third-party data breach. Black Basta conducts a ransomware attack against technology company ABB. Intrusion Truth returns to dox APT41. Anonymous Sudan looks like a Russian front operation. Attribution and motivation of "RedStinger" remain murky. CISA summarizes Russian cyber offensives. Remote code execution exploits Ruckus in the wild. Our guest is Dave Russell from Veeam with insights on data protection. Matt O'Neill from the US Secret Service on their efforts to thwart email compromise and romance scams. And espionage by way of YouTube comments.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/93


Selected reading.

Discord discloses data breach after support agent got hacked (Bleeping Computer)

Discord suffered a data after third-party support agent was hacked (Security Affairs)

Multinational tech firm ABB hit by Black Basta ransomware attack (Bleeping Computer)

Breaking: ABB confirms cyberattack; work underway to restore operations (ET CISO)

Black Basta conducts ransomware attack against Swiss technology company ABB (The CyberWire)

They dox Chinese hackers. Now, they’re back. (Washington Post)

What’s Cracking at the Kerui Cracking Academy? (Intrusion Truth)

Posing as Islamists, Russian Hackers Take Aim at Sweden (Bloomberg)

Anonymous Sudan: Threat Intelligence Report (TrueSec)

Uncovering RedStinger - Undetected APT cyber operations in Eastern Europe since 2020 (Malwarebytes)

Russian ‘Red Stealer’ cyberattacks target breakaway territories in Ukraine (Cybernews)

Russia Cyber Threat Overview and Advisories (CISA)

Known Exploited Vulnerabilities Catalog (CISA)

CISA Adds Seven Known Exploited Vulnerabilities to Catalog (CISA)

CISA warns of critical Ruckus bug used to infect Wi-Fi access points (Bleeping Computer)

Security Bulletins (Ruckus)

ROK union leaders charged with spying for North Korea in ‘movie-like’ scheme (NK News)

Extract Knowledge
Listen elsewhere

Steve Benton, Vice President at Anomali Threat Research & GM Belfast, sits down to share his story as a cybersecurity expert with a surplus of strategic leadership experience across cyber and physical security rooted in substantial operational directorship and accountability. Steve shares his beginnings, where he wanted to grow up to be a rockstar, slowly moving into the world of tech with his first ever computer and falling in love with it. After graduating from Queens University with a degree in information technology, he joined British Telecommunications or BT, where he got to put his new found skills to use. Steve mentions how his job is kind of like being a DJ almost and says " a typical day for me is looking at the intelligence that we're bringing in, mixing it as it were to think of a slight, like DJs with a set of headphones on creating the right kind of mixes of intelligence for our clients." We thank Steve for sharing his story with us.

More description

Steve Benton, Vice President at Anomali Threat Research & GM Belfast, sits down to share his story as a cybersecurity expert with a surplus of strategic leadership experience across cyber and physical security rooted in substantial operational directorship and accountability. Steve shares his beginnings, where he wanted to grow up to be a rockstar, slowly moving into the world of tech with his first ever computer and falling in love with it. After graduating from Queens University with a degree in information technology, he joined British Telecommunications or BT, where he got to put his new found skills to use. Steve mentions how his job is kind of like being a DJ almost and says " a typical day for me is looking at the intelligence that we're bringing in, mixing it as it were to think of a slight, like DJs with a set of headphones on creating the right kind of mixes of intelligence for our clients." We thank Steve for sharing his story with us.

Extract Knowledge
Listen elsewhere

Aleksandar Milenkoski and Juan Andres Guerrero-Saade from SentinelOne's SentinelLabs join Dave to discuss their research "Operation Tainted Love | Chinese APTs Target Telcos in New Attacks." Researchers found initial phases of attacks against telecommunication providers in the Middle East in Q1 in 2023.

The research states "We assess that this activity represents an evolution of tooling associated with Operation Soft Cell." While the exact grouping is unclear, researchers think it is highly likely that the threat actor is a Chinese cyberespionage group in the nexus of Gallium and APT41.

The research can be found here:

More description

Aleksandar Milenkoski and Juan Andres Guerrero-Saade from SentinelOne's SentinelLabs join Dave to discuss their research "Operation Tainted Love | Chinese APTs Target Telcos in New Attacks." Researchers found initial phases of attacks against telecommunication providers in the Middle East in Q1 in 2023.

The research states "We assess that this activity represents an evolution of tooling associated with Operation Soft Cell." While the exact grouping is unclear, researchers think it is highly likely that the threat actor is a Chinese cyberespionage group in the nexus of Gallium and APT41.

The research can be found here:

Extract Knowledge
Listen elsewhere

FBI and CISA are releasing this joint Cybersecurity Advisory in response to the active exploitation of CVE-2023-27350. This vulnerability occurs in certain versions of PaperCut NG and PaperCut MF, software applications that help organizations manage printing services, and enables an unauthenticated actor to execute malicious code remotely without credentials. 

AA23-131A Alert, Technical Details, and Mitigations

PaperCut: URGENT | PaperCut MF/NG vulnerability bulletin (March 2023)

Huntress: Critical Vulnerabilities in PaperCut Print Management Software

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

More description

FBI and CISA are releasing this joint Cybersecurity Advisory in response to the active exploitation of CVE-2023-27350. This vulnerability occurs in certain versions of PaperCut NG and PaperCut MF, software applications that help organizations manage printing services, and enables an unauthenticated actor to execute malicious code remotely without credentials. 

AA23-131A Alert, Technical Details, and Mitigations

PaperCut: URGENT | PaperCut MF/NG vulnerability bulletin (March 2023)

Huntress: Critical Vulnerabilities in PaperCut Print Management Software

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge
Listen elsewhere

Babuk source code provides criminal inspiration. CISA and FBI release a joint report on PaperCut. There are more bad bots out there than anyone would like. Phishing-as-a-service tools in the C2C market. CISA’s Eric Goldstein advocates the adoption of strong controls, defensible networks and coordination of strategic cyber risks. Our cyberwire producer Liz Irvin speaks with Crystle-Day Villanueva, Learning and Development Specialist for Lumu Technologies. And KillNet’s short-lived venture, with a dash of regret.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/92


Selected reading.

Babuk code used by 9 ransomware gangs to encrypt VMWare ESXi servers (Bleeping Computer)

Ransomware actors adopt leaked Babuk code to hit Linux systems (Decipher)

Hypervisor Ransomware | Multiple Threat Actor Groups Hop on Leaked Babuk Code to Build ESXi Lockers (SentinelOne)

Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG (CISA)

CVE-2023-27350 Detail (NIST)

Proofpoint Emerging Threats Rules (Proofpoint)

2023 Imperva Bad Bot Report (Imperva)

New phishing-as-a-service tool “Greatness” already seen in the wild (Cisco Talos)

Ukraine at D+442: Russians say the Ukrainian counteroffensive has begun. (CyberWire)

More description

Babuk source code provides criminal inspiration. CISA and FBI release a joint report on PaperCut. There are more bad bots out there than anyone would like. Phishing-as-a-service tools in the C2C market. CISA’s Eric Goldstein advocates the adoption of strong controls, defensible networks and coordination of strategic cyber risks. Our cyberwire producer Liz Irvin speaks with Crystle-Day Villanueva, Learning and Development Specialist for Lumu Technologies. And KillNet’s short-lived venture, with a dash of regret.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/92


Selected reading.

Babuk code used by 9 ransomware gangs to encrypt VMWare ESXi servers (Bleeping Computer)

Ransomware actors adopt leaked Babuk code to hit Linux systems (Decipher)

Hypervisor Ransomware | Multiple Threat Actor Groups Hop on Leaked Babuk Code to Build ESXi Lockers (SentinelOne)

Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG (CISA)

CVE-2023-27350 Detail (NIST)

Proofpoint Emerging Threats Rules (Proofpoint)

2023 Imperva Bad Bot Report (Imperva)

New phishing-as-a-service tool “Greatness” already seen in the wild (Cisco Talos)

Ukraine at D+442: Russians say the Ukrainian counteroffensive has begun. (CyberWire)

Extract Knowledge
Listen elsewhere

A Ransomware report highlights targeting and classification. Phishing remains a major threat. Cisco addresses an expired certificate issue. LockBit and Medusa hit school districts with ransomware. US and Canadian cyber units wrap up a hunt-forward mission in Latvia. Ben Yelin on NYPD surveillance. Our CyberWire producer Liz Irvin interviews Damien Lewke, a graduate student at MIT. And an unknown threat actor is collecting against both Russia and Ukraine.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/91


Selected reading.

GRIT Ransomware Report: April 2023 (GuidePoint Security)

DNSFilter State of Internet Security - Q1 2023 (DNSFilter)

Identify vEdge Certificate Expired on May 9th 2023 (Cisco)

The State of Ransomware Attacks in Education 2023: Trends and Solutions (Veriti)

US Cyber Command 'Hunts Forward' in Latvia (Voice of America)

US cyber team unearths malware during ‘hunt-forward’ mission in Latvia (C4ISRNET)

Uncovering RedStinger - Undetected APT cyber operations in Eastern Europe since 2020 (Malwarebytes)

Bad magic: new APT found in the area of Russo-Ukrainian conflict (Kaspersky)

More description

A Ransomware report highlights targeting and classification. Phishing remains a major threat. Cisco addresses an expired certificate issue. LockBit and Medusa hit school districts with ransomware. US and Canadian cyber units wrap up a hunt-forward mission in Latvia. Ben Yelin on NYPD surveillance. Our CyberWire producer Liz Irvin interviews Damien Lewke, a graduate student at MIT. And an unknown threat actor is collecting against both Russia and Ukraine.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/91


Selected reading.

GRIT Ransomware Report: April 2023 (GuidePoint Security)

DNSFilter State of Internet Security - Q1 2023 (DNSFilter)

Identify vEdge Certificate Expired on May 9th 2023 (Cisco)

The State of Ransomware Attacks in Education 2023: Trends and Solutions (Veriti)

US Cyber Command 'Hunts Forward' in Latvia (Voice of America)

US cyber team unearths malware during ‘hunt-forward’ mission in Latvia (C4ISRNET)

Uncovering RedStinger - Undetected APT cyber operations in Eastern Europe since 2020 (Malwarebytes)

Bad magic: new APT found in the area of Russo-Ukrainian conflict (Kaspersky)

Extract Knowledge
Listen elsewhere

The Snake implant is considered the most sophisticated cyber espionage tool designed and used by Center 16 of Russia’s Federal Security Service, or FSB, for long-term intelligence collection on sensitive targets.

AA23-129A Alert, Technical Details, and Mitigations

For more information on FSB and Russian state-sponsored cyber activity, please see the joint advisory Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure and CISA’s Russia Cyber Threat Overview and Advisories webpage.

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

More description

The Snake implant is considered the most sophisticated cyber espionage tool designed and used by Center 16 of Russia’s Federal Security Service, or FSB, for long-term intelligence collection on sensitive targets.

AA23-129A Alert, Technical Details, and Mitigations

For more information on FSB and Russian state-sponsored cyber activity, please see the joint advisory Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure and CISA’s Russia Cyber Threat Overview and Advisories webpage.

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge
Listen elsewhere

The Five Eyes disrupt Russia’s FSB Snake cyberespionage infrastructure. Shifting gears: from DDoS to cryptojacking. Trends in ransomware. Our guest is Steve Benton from Anomali with insights on potential industry headwinds. Ann Johnson from Afternoon Cyber Tea speaks with Roland Cloutier about risk and resilience in the modern era. And yesterday’s Patch Tuesday is now in the books, including a work-around for a patch from this past March.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/90


Selected reading.

Patch Tuesday notes. (The CyberWire)

U.S. Agencies and Allies Partner to Identify Russian Snake Malware Infrastructure Worldwide (US National Security Agency)

Hunting Russian Intelligence “Snake” Malware (Joint Cybersecurity Advisory)

RapperBot DDoS Botnet Expands into Cryptojacking (Fortinet)

The State of Ransomware 2023 (Sophos)

From One Vulnerability to Another: Outlook Patch Analysis Reveals Important Flaw in Windows API (Akamai)

Windows MSHTML Platform Security Feature Bypass Vulnerability (Microsoft)

More description

The Five Eyes disrupt Russia’s FSB Snake cyberespionage infrastructure. Shifting gears: from DDoS to cryptojacking. Trends in ransomware. Our guest is Steve Benton from Anomali with insights on potential industry headwinds. Ann Johnson from Afternoon Cyber Tea speaks with Roland Cloutier about risk and resilience in the modern era. And yesterday’s Patch Tuesday is now in the books, including a work-around for a patch from this past March.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/90


Selected reading.

Patch Tuesday notes. (The CyberWire)

U.S. Agencies and Allies Partner to Identify Russian Snake Malware Infrastructure Worldwide (US National Security Agency)

Hunting Russian Intelligence “Snake” Malware (Joint Cybersecurity Advisory)

RapperBot DDoS Botnet Expands into Cryptojacking (Fortinet)

The State of Ransomware 2023 (Sophos)

From One Vulnerability to Another: Outlook Patch Analysis Reveals Important Flaw in Windows API (Akamai)

Windows MSHTML Platform Security Feature Bypass Vulnerability (Microsoft)

Extract Knowledge
Listen elsewhere

An analysis of Royal ransomware. PaperCut vulnerability detection methods can be bypassed. Man-in-the-middle phishing attacks are on the rise. A new wave of BEC attacks from an unexpected source. Thomas Etheridge from CrowdStrike, has the latest threat landscape trends. Our guest is Dan Amiga of Island with insights on the enterprise browser category. And a look into recent Russian cyberattacks against Ukraine.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/89


Selected reading.

Threat Assessment: Royal Ransomware (Unit 42)

PaperCut Exploitation - A Different Path to Code Execution (VulnCheck)

New PaperCut RCE exploit created that bypasses existing detections (Bleeping Computer)

Man-in-the-Middle (MitM) attacks reaching inboxes increase 35% since 2022 (Cofense)

Exploring the Rise of Israel-Based BEC Attacks (Abnormal Security)

Russians launch mass cyber attack on online service for queueing to cross border by trucks (Ukrainska Pravda)

Reverting UAC-0006: Mass distribution of SmokeLoader using the "accounts" theme (CERT-UA#6613) (CERT-UA)

More description

An analysis of Royal ransomware. PaperCut vulnerability detection methods can be bypassed. Man-in-the-middle phishing attacks are on the rise. A new wave of BEC attacks from an unexpected source. Thomas Etheridge from CrowdStrike, has the latest threat landscape trends. Our guest is Dan Amiga of Island with insights on the enterprise browser category. And a look into recent Russian cyberattacks against Ukraine.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/89


Selected reading.

Threat Assessment: Royal Ransomware (Unit 42)

PaperCut Exploitation - A Different Path to Code Execution (VulnCheck)

New PaperCut RCE exploit created that bypasses existing detections (Bleeping Computer)

Man-in-the-Middle (MitM) attacks reaching inboxes increase 35% since 2022 (Cofense)

Exploring the Rise of Israel-Based BEC Attacks (Abnormal Security)

Russians launch mass cyber attack on online service for queueing to cross border by trucks (Ukrainska Pravda)

Reverting UAC-0006: Mass distribution of SmokeLoader using the "accounts" theme (CERT-UA#6613) (CERT-UA)

Extract Knowledge
Listen elsewhere

ALPHV claims responsibility for a cyberattack on Constellation Software. A new Akira ransomware campaign spreads. CACTUS is a new ransomware leveraging VPNs to infiltrate its target. Many organizations are still vulnerable to the Go-Anywhere MFT vulnerability. Russian hacktivists interfere with the French Senate's website. Keith Mularski from EY, details their "State of the Hack" report. Emily Austin from Censys discusses the State of the Internet. And ransomware gangs target local governments in Texas and California. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/88


Selected reading.

ALPHV gang claims ransomware attack on Constellation Software (BleepingComputer) 

Constellation Software hit by cyber attack, some personal information stolen (IT World Canada) 

Press Release of Constellation Software Inc. (GlobeNewswire News Room)

Meet Akira — A new ransomware operation targeting the enterprise (BleepingComputer)

New Cactus ransomware encrypts itself to evade antivirus (BleepingComputer) 

Pro-Russian Hackers Claim Downing of French Senate Website (SecurityWeek)

Dallas cyberattack highlights ransomware’s risks to public safety, health (Washington Post) 

Hacked: Dallas Ransomware Attack Disrupts City Services (Dallas Observer) 

City of Dallas Continues Battling Ransomware Attack for Third Day (NBC 5 Dallas-Fort Worth) 

San Bernardino County pays hackers $1.1 million ransom after cyber attack (Victorville Daily Press) 

San Bernardino County pays $1.1M ransom after cyberattack disrupts Sheriff's Department systems (ABC7 Los Angeles)

Atomic Data devastated by the unexpected death of CEO and co-owner Jim Wolford (Atomic Data)

More description

ALPHV claims responsibility for a cyberattack on Constellation Software. A new Akira ransomware campaign spreads. CACTUS is a new ransomware leveraging VPNs to infiltrate its target. Many organizations are still vulnerable to the Go-Anywhere MFT vulnerability. Russian hacktivists interfere with the French Senate's website. Keith Mularski from EY, details their "State of the Hack" report. Emily Austin from Censys discusses the State of the Internet. And ransomware gangs target local governments in Texas and California. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/88


Selected reading.

ALPHV gang claims ransomware attack on Constellation Software (BleepingComputer) 

Constellation Software hit by cyber attack, some personal information stolen (IT World Canada) 

Press Release of Constellation Software Inc. (GlobeNewswire News Room)

Meet Akira — A new ransomware operation targeting the enterprise (BleepingComputer)

New Cactus ransomware encrypts itself to evade antivirus (BleepingComputer) 

Pro-Russian Hackers Claim Downing of French Senate Website (SecurityWeek)

Dallas cyberattack highlights ransomware’s risks to public safety, health (Washington Post) 

Hacked: Dallas Ransomware Attack Disrupts City Services (Dallas Observer) 

City of Dallas Continues Battling Ransomware Attack for Third Day (NBC 5 Dallas-Fort Worth) 

San Bernardino County pays hackers $1.1 million ransom after cyber attack (Victorville Daily Press) 

San Bernardino County pays $1.1M ransom after cyberattack disrupts Sheriff's Department systems (ABC7 Los Angeles)

Atomic Data devastated by the unexpected death of CEO and co-owner Jim Wolford (Atomic Data)

Extract Knowledge
Listen elsewhere

Shelley Ma, Incident Response Lead at Coalition sits down to share her story, starting all the way back when she was a kid and fell in love with playing the game "NeoPets" that ended up paving the way for her future in cybersecurity. After starting this journey, she shares how she became intrigued with crime and mystery shows, which ultimately spawned an interest in forensic science. She ended up signing up for an internship program that she was able to get into, which she says was a pivotal change for her that provided her the chance to begin her career. She shares the advice that if anyone is looking to get into this career, she highly recommends looking into the career before beginning. Following some advise given to her by a professor and mentor, she says that telling the truth helps her deal with adversity in the workplace. Shelley says "In our industry, there are so many opportunities for our opinions and testimonies to be coerced and swayed. I refuse to do that and every time I come back to what my professor said, if you don't want to spend the rest of your life looking over your shoulders, just simply tell the truth." We thank Shelley for sharing her story with us.

More description

Shelley Ma, Incident Response Lead at Coalition sits down to share her story, starting all the way back when she was a kid and fell in love with playing the game "NeoPets" that ended up paving the way for her future in cybersecurity. After starting this journey, she shares how she became intrigued with crime and mystery shows, which ultimately spawned an interest in forensic science. She ended up signing up for an internship program that she was able to get into, which she says was a pivotal change for her that provided her the chance to begin her career. She shares the advice that if anyone is looking to get into this career, she highly recommends looking into the career before beginning. Following some advise given to her by a professor and mentor, she says that telling the truth helps her deal with adversity in the workplace. Shelley says "In our industry, there are so many opportunities for our opinions and testimonies to be coerced and swayed. I refuse to do that and every time I come back to what my professor said, if you don't want to spend the rest of your life looking over your shoulders, just simply tell the truth." We thank Shelley for sharing her story with us.

Extract Knowledge
Listen elsewhere

Ryan Robinson from Intezer to discuss his team's work on "Phishing Campaign Targets Chinese Nuclear Energy Industry." The research team discovered activity targeting the nuclear energy industry in China. Researchers attributed the activity to Bitter APT, a South Asian APT that is known to target the energy, manufacturing and government sectors, mainly in Pakistan, China, Bangladesh, and Saudi Arabia.

The article states "We identified seven emails pretending to be from the Embassy of Kyrgyzstan, being sent to recipients in the nuclear energy industry in China. In some emails, people and entities in academia are also targeted, also related to nuclear energy." By luring recipients in, invites them to join conferences on subjects that are relevant to them, they are then able to social engineer the victims.

The research can be found here:

More description

Ryan Robinson from Intezer to discuss his team's work on "Phishing Campaign Targets Chinese Nuclear Energy Industry." The research team discovered activity targeting the nuclear energy industry in China. Researchers attributed the activity to Bitter APT, a South Asian APT that is known to target the energy, manufacturing and government sectors, mainly in Pakistan, China, Bangladesh, and Saudi Arabia.

The article states "We identified seven emails pretending to be from the Embassy of Kyrgyzstan, being sent to recipients in the nuclear energy industry in China. In some emails, people and entities in academia are also targeted, also related to nuclear energy." By luring recipients in, invites them to join conferences on subjects that are relevant to them, they are then able to social engineer the victims.

The research can be found here:

Extract Knowledge
Listen elsewhere

Kimsuki has a new reconnaissance tool. The Biden administration shares plans for AI. Reports on the ransomware taskforce report. KillNet recommits to turning a profit. Deepen Desai from Zscaler has the latest stats on Phishing. Our guest is Karen Worstell from VMware with a conversation about inclusivity. And the former CSO at Uber is sentenced.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/87


Selected reading.

Kimsuky Evolves Reconnaissance Capabilities in New Global Campaign (SentinelOne)

Ransomware Task Force Gaining Ground - May 2023 Progress Report (Ransomware Task Force)

Influential task force takes stock of progress against ransomware (Washington Post)

For Money and Attention: Killnet Apparently Reorganizes Again (Flashpoint)

Killnet Ostracizes Leader of Anonymous Russia, Adding New Chapter to Pro-Kremlin Hacktivist Drama (Flashpoint)

Former Uber CSO Joe Sullivan Avoids Prison Time Over Data Breach Cover-Up (Security Week)

Former Uber security chief Sullivan avoids prison in data breach case (Washington Post)

More description

Kimsuki has a new reconnaissance tool. The Biden administration shares plans for AI. Reports on the ransomware taskforce report. KillNet recommits to turning a profit. Deepen Desai from Zscaler has the latest stats on Phishing. Our guest is Karen Worstell from VMware with a conversation about inclusivity. And the former CSO at Uber is sentenced.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/87


Selected reading.

Kimsuky Evolves Reconnaissance Capabilities in New Global Campaign (SentinelOne)

Ransomware Task Force Gaining Ground - May 2023 Progress Report (Ransomware Task Force)

Influential task force takes stock of progress against ransomware (Washington Post)

For Money and Attention: Killnet Apparently Reorganizes Again (Flashpoint)

Killnet Ostracizes Leader of Anonymous Russia, Adding New Chapter to Pro-Kremlin Hacktivist Drama (Flashpoint)

Former Uber CSO Joe Sullivan Avoids Prison Time Over Data Breach Cover-Up (Security Week)

Former Uber security chief Sullivan avoids prison in data breach case (Washington Post)

Extract Knowledge
Listen elsewhere

An APT41 subgroup uses new techniques to bypass security products. Iranian cyberespionage group MuddyWater is using Managed Service Provider tools. Wipers reappear in Ukrainian networks. Meta observes and disrupts the new NodeStealer malware campaign. The City of Dallas is moderately affected by a ransomware attack. My conversation with Karin Voodla, part of the US State Department’s Cyber fellowship program. Lesley Carhart from Dragos shares Real World Stories of Incident Response and Threat Intelligence. And there’s been an indictment and a takedown in a major dark web carder case.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/86


Selected reading.

Attack on Security Titans: Earth Longzhi Returns With New Tricks (Trend Micro)

APT groups muddying the waters for MSPs (ESET)

Russian hackers use WinRAR to wipe Ukraine state agency’s data (BleepingComputer)

WinRAR as a "cyberweapon". Destructive cyberattack UAC-0165 (probably Sandworm) on the public sector of Ukraine using RoarBat (CERT-UA#6550) (CERT-UA) 

The malware threat landscape: NodeStealer, DuckTail, and more (Engineering at Meta) 

Facebook disrupts new NodeStealer information-stealing malware (BleepingComputer)

NodeStealer Malware Targets Gmail, Outlook, Facebook Credentials (Decipher)

City of Dallas likely targeted in ransomware attack, city official says (Dallas News) 

Cybercriminal Network Fueling the Global Stolen Credit Card Trade is Dismantled (US Department of Justice)

Secret Service, State Department Offer Up To $10 Million Dollar Reward For Information On Wanted International Fugitive (US Secret Service)

Police dismantles Try2Check credit card verifier used by dark web markets (BleepingComputer)

More description

An APT41 subgroup uses new techniques to bypass security products. Iranian cyberespionage group MuddyWater is using Managed Service Provider tools. Wipers reappear in Ukrainian networks. Meta observes and disrupts the new NodeStealer malware campaign. The City of Dallas is moderately affected by a ransomware attack. My conversation with Karin Voodla, part of the US State Department’s Cyber fellowship program. Lesley Carhart from Dragos shares Real World Stories of Incident Response and Threat Intelligence. And there’s been an indictment and a takedown in a major dark web carder case.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/86


Selected reading.

Attack on Security Titans: Earth Longzhi Returns With New Tricks (Trend Micro)

APT groups muddying the waters for MSPs (ESET)

Russian hackers use WinRAR to wipe Ukraine state agency’s data (BleepingComputer)

WinRAR as a "cyberweapon". Destructive cyberattack UAC-0165 (probably Sandworm) on the public sector of Ukraine using RoarBat (CERT-UA#6550) (CERT-UA) 

The malware threat landscape: NodeStealer, DuckTail, and more (Engineering at Meta) 

Facebook disrupts new NodeStealer information-stealing malware (BleepingComputer)

NodeStealer Malware Targets Gmail, Outlook, Facebook Credentials (Decipher)

City of Dallas likely targeted in ransomware attack, city official says (Dallas News) 

Cybercriminal Network Fueling the Global Stolen Credit Card Trade is Dismantled (US Department of Justice)

Secret Service, State Department Offer Up To $10 Million Dollar Reward For Information On Wanted International Fugitive (US Secret Service)

Police dismantles Try2Check credit card verifier used by dark web markets (BleepingComputer)

Extract Knowledge
Listen elsewhere

Iran integrates influence and cyber operations. ChatGPT use and misuse. Phishing reports increased significantly so far in 2023, while HTML attacks double. An update on the Discord Papers. Cyberstrikes against civilian targets. My conversation with our own Simone Petrella on emerging cyber workforce strategies. Tim Starks from the Washington Post joins me with reflections on the RSA conference. And, turns out, a war clause cannot be invoked in denying damage claims in the NotPetya attacks (at least not in the Garden State).


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/85


Selected reading.

Rinse and repeat: Iran accelerates its cyber influence operations worldwide (Microsoft On the Issues)

ChatGPT Confirms Data Breach, Raising Security Concerns (Security Intelligence) 

Samsung Bans Generative AI Use by Staff After ChatGPT Data Leak (Bloomberg) 

Malicious email campaigns abusing Telegram bots rise tremendously in Q1 2023, surpassing all of 2022 by 310% (Cofense)

Threat Spotlight: Proportion of malicious HTML attachments doubles within a year (Barracuda)

Zelensky says White House told him nothing about Discord intelligence leaks (Washington Post)

Russia attacks civilian infrastructure in cyberspace just as it does on ground - watchdog (Ukrinform)

Merck’s Insurers On the Hook in $1.4 Billion NotPetya Attack, Court Says (Wall Street Journal)

Merck entitled to $1.4B in cyberattack case after court rejects insurers' 'warlike action' claim (Fierce Pharma)

More description

Iran integrates influence and cyber operations. ChatGPT use and misuse. Phishing reports increased significantly so far in 2023, while HTML attacks double. An update on the Discord Papers. Cyberstrikes against civilian targets. My conversation with our own Simone Petrella on emerging cyber workforce strategies. Tim Starks from the Washington Post joins me with reflections on the RSA conference. And, turns out, a war clause cannot be invoked in denying damage claims in the NotPetya attacks (at least not in the Garden State).


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/85


Selected reading.

Rinse and repeat: Iran accelerates its cyber influence operations worldwide (Microsoft On the Issues)

ChatGPT Confirms Data Breach, Raising Security Concerns (Security Intelligence) 

Samsung Bans Generative AI Use by Staff After ChatGPT Data Leak (Bloomberg) 

Malicious email campaigns abusing Telegram bots rise tremendously in Q1 2023, surpassing all of 2022 by 310% (Cofense)

Threat Spotlight: Proportion of malicious HTML attachments doubles within a year (Barracuda)

Zelensky says White House told him nothing about Discord intelligence leaks (Washington Post)

Russia attacks civilian infrastructure in cyberspace just as it does on ground - watchdog (Ukrinform)

Merck’s Insurers On the Hook in $1.4 Billion NotPetya Attack, Court Says (Wall Street Journal)

Merck entitled to $1.4B in cyberattack case after court rejects insurers' 'warlike action' claim (Fierce Pharma)

Extract Knowledge
Listen elsewhere

LOBSHOT is a cryptowallet stealer abusing Google Ads. Coronation phishbait. A known CCTV vulnerability is currently being exploited. T-Mobile discloses another, smaller data breach. New Magecart exploits. Preliminary lessons from cyber operations during Russia's war. Rob Boyce from Accenture shares insights from RSA Conference. Our special guest is NSA Director of Cybersecurity Rob Joyce. And Europol announces a major dark web market takedown.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/84


Selected reading.

New LOBSHOT malware gives hackers hidden VNC access to Windows devices (BleepingComputer)

New 'Lobshot' hVNC Malware Used by Russian Cybercriminals (SecurityWeek)

Elastic Security Labs discovers the LOBSHOT malware (Elastic Blog)

Researchers see surge in scam websites linked to coronation (Computer Weekly) 

TBK DVR Authentication Bypass Attack (FortiGuard) 

T-Mobile discloses second data breach since the start of 2023 (BleepingComputer) 

T-Mobile discloses 2nd data breach of 2023, this one leaking account PINs and more (Ars Technica) 

T-Mobile Announces Another Data Breach (CNET)

Magecart threat actor rolls out convincing modal forms (Malwarebytes)

Cyber lessons from Ukraine: Prepare for prolonged conflict, not a knockout blow (Breaking Defense)

288 dark web vendors arrested in major marketplace seizure (Europol)

More description

LOBSHOT is a cryptowallet stealer abusing Google Ads. Coronation phishbait. A known CCTV vulnerability is currently being exploited. T-Mobile discloses another, smaller data breach. New Magecart exploits. Preliminary lessons from cyber operations during Russia's war. Rob Boyce from Accenture shares insights from RSA Conference. Our special guest is NSA Director of Cybersecurity Rob Joyce. And Europol announces a major dark web market takedown.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/84


Selected reading.

New LOBSHOT malware gives hackers hidden VNC access to Windows devices (BleepingComputer)

New 'Lobshot' hVNC Malware Used by Russian Cybercriminals (SecurityWeek)

Elastic Security Labs discovers the LOBSHOT malware (Elastic Blog)

Researchers see surge in scam websites linked to coronation (Computer Weekly) 

TBK DVR Authentication Bypass Attack (FortiGuard) 

T-Mobile discloses second data breach since the start of 2023 (BleepingComputer) 

T-Mobile discloses 2nd data breach of 2023, this one leaking account PINs and more (Ars Technica) 

T-Mobile Announces Another Data Breach (CNET)

Magecart threat actor rolls out convincing modal forms (Malwarebytes)

Cyber lessons from Ukraine: Prepare for prolonged conflict, not a knockout blow (Breaking Defense)

288 dark web vendors arrested in major marketplace seizure (Europol)

Extract Knowledge
Listen elsewhere

The FDA warns of a vulnerability affecting biomedical devices. Ransomware's effects continue to trouble the US Marshals Service. The US Justice Department shifts how it deals with large scale cybercrime. Fresh phish from the GRU. Caleb Barlow looks at unicorns and zombiecorns. Our guest Manoj Sharma from Symantec explains the differences between Zero Trust and SASE. And KillNet runs an ask-me-anything session.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/83


Selected reading.

Illumina cyber vulnerability may present risks for patient results (U.S. Food and Drug Administration)

CISA, FDA warn of new Illumina DNA device vulnerability (Record

Key law enforcement computers still down 10 weeks after breach (Washington Post)

Feds Prioritizing Disruptions Over Arrests in Cyberattack Cases (PCMAG) 

"Ashamed" LockBit ransomware gang apologises to hacked school, offers free decryption tool (Hot for Security) 

APT28 cyberattack: distribution of emails with "instructions" on "updating the operating system" (CERT-UA#6562) (CERT-UA)

Hackers use fake ‘Windows Update’ guides to target Ukrainian govt (BleepingComputer) 

Ukraine at D+431: Drone strikes and phishing expeditions. (CyberWire)

More description

The FDA warns of a vulnerability affecting biomedical devices. Ransomware's effects continue to trouble the US Marshals Service. The US Justice Department shifts how it deals with large scale cybercrime. Fresh phish from the GRU. Caleb Barlow looks at unicorns and zombiecorns. Our guest Manoj Sharma from Symantec explains the differences between Zero Trust and SASE. And KillNet runs an ask-me-anything session.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/83


Selected reading.

Illumina cyber vulnerability may present risks for patient results (U.S. Food and Drug Administration)

CISA, FDA warn of new Illumina DNA device vulnerability (Record

Key law enforcement computers still down 10 weeks after breach (Washington Post)

Feds Prioritizing Disruptions Over Arrests in Cyberattack Cases (PCMAG) 

"Ashamed" LockBit ransomware gang apologises to hacked school, offers free decryption tool (Hot for Security) 

APT28 cyberattack: distribution of emails with "instructions" on "updating the operating system" (CERT-UA#6562) (CERT-UA)

Hackers use fake ‘Windows Update’ guides to target Ukrainian govt (BleepingComputer) 

Ukraine at D+431: Drone strikes and phishing expeditions. (CyberWire)

Extract Knowledge
Listen elsewhere

Perry Carpenter, Chief Evangelist and Strategy Officer at KnowBe4 and host of the 8th Layer Insights podcast, sits down to share his story trying different paths, before ultimately switching over to the cyber industry. After trying to go down the paths of music and law and finding neither were what he wanted to do, he decided to take an internship to get more into computer programming. That led him to getting his first job. After his first job, he moved onto other big name companies like Walmart, Alltel, and Gartner, and landing finally with KnowBe4. He compares his work to working with music, when he initially wanted to begin making music early in his career. He says "I think for me, when it was the kind of the connection between music and computing is that whenever you're kind of joining things together or at a, a musical scale to make chords, or whenever you're adding different, um, instruments and octaves together or timbers together to get some kind of bigger result." We thank Perry for sharing his story.

More description

Perry Carpenter, Chief Evangelist and Strategy Officer at KnowBe4 and host of the 8th Layer Insights podcast, sits down to share his story trying different paths, before ultimately switching over to the cyber industry. After trying to go down the paths of music and law and finding neither were what he wanted to do, he decided to take an internship to get more into computer programming. That led him to getting his first job. After his first job, he moved onto other big name companies like Walmart, Alltel, and Gartner, and landing finally with KnowBe4. He compares his work to working with music, when he initially wanted to begin making music early in his career. He says "I think for me, when it was the kind of the connection between music and computing is that whenever you're kind of joining things together or at a, a musical scale to make chords, or whenever you're adding different, um, instruments and octaves together or timbers together to get some kind of bigger result." We thank Perry for sharing his story.

Extract Knowledge
Listen elsewhere

This week our guests are, Larry Cashdollar, Chad Seaman and Allen West from Akamai Technologies, and they are discussing their research on "Uncovering HinataBot: A Deep Dive into a Go-Based Threat." The team discovered a new Go-based, DDoS-focused botnet. They found it was named after the popular anime show "Naruto," they are calling it "HinataBot"

In the research it says "HinataBot was seen being distributed during the first three months of 2023 and is actively being updated by the authors/operators." Akamai was able to get a deep look into the malware works by using a combination of reverse engineering the malware and imitating the command and control (C2) server.

The research can be found here:

More description

This week our guests are, Larry Cashdollar, Chad Seaman and Allen West from Akamai Technologies, and they are discussing their research on "Uncovering HinataBot: A Deep Dive into a Go-Based Threat." The team discovered a new Go-based, DDoS-focused botnet. They found it was named after the popular anime show "Naruto," they are calling it "HinataBot"

In the research it says "HinataBot was seen being distributed during the first three months of 2023 and is actively being updated by the authors/operators." Akamai was able to get a deep look into the malware works by using a combination of reverse engineering the malware and imitating the command and control (C2) server.

The research can be found here:

Extract Knowledge
Listen elsewhere

Cl0p and LockBit exploit PaperCut vulnerability in ransomware campaigns. Infostealer traded in the C2C market. All ads are trying to get your money, but some just take it. CISA requests comment on software self-attestation form. Our guest is Marcin Kleczynski, CEO of Malwarebytes, sharing thoughts on the current threat landscape, attacks on students and academic institutions. Betsy Carmelite from Booz Allen, discussing themes from the RSAC tied into critical infrastructure resilience. Ukraine argues that cyberattacks against civilian infrastructure should be classified as war crimes. And are there any genuine disinterested hacktivists on Russia's side, or are they all fronts?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/82


Selected reading.

Microsoft Confirms PaperCut Servers Used to Deliver LockBit and Cl0p Ransomware (The Hacker News)

Microsoft: Clop and LockBit ransomware behind PaperCut server hacks (BleepingComputer) ​

New 'Atomic macOS Stealer' Malware Offered for $1,000 Per Month (SecurityWeek) 

“Malverposting” — With Over 500K Estimated Infections, Facebook Ads Fuel This Evolving Stealer… (Guardio)

Request for Comment on Secure Software Self-Attestation Common Form (CISA)

OMB, CISA set to release common form for software self-attestation (FCW)

Pro-Russian hacktivism isn’t real, top Ukrainian cyber official says (CyberScoop)

Pro-Russian hacktivism isn't real, top Ukrainian cyber official says (CyberScoop) 

More description

Cl0p and LockBit exploit PaperCut vulnerability in ransomware campaigns. Infostealer traded in the C2C market. All ads are trying to get your money, but some just take it. CISA requests comment on software self-attestation form. Our guest is Marcin Kleczynski, CEO of Malwarebytes, sharing thoughts on the current threat landscape, attacks on students and academic institutions. Betsy Carmelite from Booz Allen, discussing themes from the RSAC tied into critical infrastructure resilience. Ukraine argues that cyberattacks against civilian infrastructure should be classified as war crimes. And are there any genuine disinterested hacktivists on Russia's side, or are they all fronts?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/82


Selected reading.

Microsoft Confirms PaperCut Servers Used to Deliver LockBit and Cl0p Ransomware (The Hacker News)

Microsoft: Clop and LockBit ransomware behind PaperCut server hacks (BleepingComputer) ​

New 'Atomic macOS Stealer' Malware Offered for $1,000 Per Month (SecurityWeek) 

“Malverposting” — With Over 500K Estimated Infections, Facebook Ads Fuel This Evolving Stealer… (Guardio)

Request for Comment on Secure Software Self-Attestation Common Form (CISA)

OMB, CISA set to release common form for software self-attestation (FCW)

Pro-Russian hacktivism isn’t real, top Ukrainian cyber official says (CyberScoop)

Pro-Russian hacktivism isn't real, top Ukrainian cyber official says (CyberScoop) 

Extract Knowledge
Listen elsewhere

Google targets CryptBot malware infrastructure. FIN7 attacked Veeam servers to steal credentials. Ransomware-as-a-service offering threatens Linux systems. Evasive Panda targets NGOs in China. Anonymous Sudan is active against targets in Israel. Russian ransomware operations aim at disrupting supply chains into Ukraine. Our guest is Stuart McClure, CEO of Qwiet AI. Microsoft’s Ann Johnson stops by with her take on the RSA conference. And bots want new kicks.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/81


Selected reading.

Continuing our work to hold cybercriminal ecosystems accountable (Google)

Google Disrupts Massive CryptBot Malware Operation (Decipher)

Google disrupts malware that steals sensitive data from Chrome users (TechCrunch) 

FIN7 Hackers Caught Exploiting Recent Veeam Vulnerability (SecurityWeek)

RTM Locker Ransomware as a Service (RaaS) Now on Linux (Uptycs) 

Evasive Panda APT group delivers malware via updates for popular Chinese software (WeLiveSecurity) 

NSA sees 'significant' Russian intel gathering on European, U.S. supply chain entities (CyberScoop) 

Ukraine at D+427: Russian cyberattacks and disinformation before Ukraine's spring offensive. (CyberWire)

Releasing leak suspect a national security risk, feds say (AP NEWS)

Pentagon leak suspect may still have access to classified info, court filings allege (the Guardian) 

Netacea Quarterly Index: Top 5 Scalper Bot Targets of Q1 2023 (Netacea)

More description

Google targets CryptBot malware infrastructure. FIN7 attacked Veeam servers to steal credentials. Ransomware-as-a-service offering threatens Linux systems. Evasive Panda targets NGOs in China. Anonymous Sudan is active against targets in Israel. Russian ransomware operations aim at disrupting supply chains into Ukraine. Our guest is Stuart McClure, CEO of Qwiet AI. Microsoft’s Ann Johnson stops by with her take on the RSA conference. And bots want new kicks.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/81


Selected reading.

Continuing our work to hold cybercriminal ecosystems accountable (Google)

Google Disrupts Massive CryptBot Malware Operation (Decipher)

Google disrupts malware that steals sensitive data from Chrome users (TechCrunch) 

FIN7 Hackers Caught Exploiting Recent Veeam Vulnerability (SecurityWeek)

RTM Locker Ransomware as a Service (RaaS) Now on Linux (Uptycs) 

Evasive Panda APT group delivers malware via updates for popular Chinese software (WeLiveSecurity) 

NSA sees 'significant' Russian intel gathering on European, U.S. supply chain entities (CyberScoop) 

Ukraine at D+427: Russian cyberattacks and disinformation before Ukraine's spring offensive. (CyberWire)

Releasing leak suspect a national security risk, feds say (AP NEWS)

Pentagon leak suspect may still have access to classified info, court filings allege (the Guardian) 

Netacea Quarterly Index: Top 5 Scalper Bot Targets of Q1 2023 (Netacea)

Extract Knowledge
Listen elsewhere

BellaCiao is malware from Iran's IRGC, while PingPull is malware used by the Chinese government affiliated Tarus Group. Ransomware continues to be a pervasive international threat. An overview of hacktivism. Our guest is CyberMindz founder Peter Coroneos, discussing the importance of mental health in cybersecurity. Johannes Ullrich shares insights from his RSAC panel discussions. And Ukraine continues to collect evidence of Russian war crimes.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/80


Selected reading.

Unpacking BellaCiao: A Closer Look at Iran’s Latest Malware (Bitdefender Blog)

Chinese Alloy Taurus Updates PingPull Malware (Unit 42)

Abuse of the Service Location Protocol May Lead to DoS Attacks (Cybersecurity and Infrastructure Security Agency CISA)

#RSAC: Ransomware Poses Growing Threat to Five Eyes Nations (Infosecurity Magazine)

Hacktivism Unveiled, April 2023 Insights into the footprints of hacktivists (Radware)

FBI aiding Ukraine in collection of digital and physical war crime evidence (CyberScoop)

More description

BellaCiao is malware from Iran's IRGC, while PingPull is malware used by the Chinese government affiliated Tarus Group. Ransomware continues to be a pervasive international threat. An overview of hacktivism. Our guest is CyberMindz founder Peter Coroneos, discussing the importance of mental health in cybersecurity. Johannes Ullrich shares insights from his RSAC panel discussions. And Ukraine continues to collect evidence of Russian war crimes.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/80


Selected reading.

Unpacking BellaCiao: A Closer Look at Iran’s Latest Malware (Bitdefender Blog)

Chinese Alloy Taurus Updates PingPull Malware (Unit 42)

Abuse of the Service Location Protocol May Lead to DoS Attacks (Cybersecurity and Infrastructure Security Agency CISA)

#RSAC: Ransomware Poses Growing Threat to Five Eyes Nations (Infosecurity Magazine)

Hacktivism Unveiled, April 2023 Insights into the footprints of hacktivists (Radware)

FBI aiding Ukraine in collection of digital and physical war crime evidence (CyberScoop)

Extract Knowledge
Listen elsewhere

BlackCat (ALPHV) follows Cl0p, exploiting the GoAnywhere MFA vulnerability. The Mirai botnet exploits a vulnerability disclosed at Pwn2Own. An RSAC presentation describes US response to Russian prewar and wartime cyber operations. The US Department of Homeland Security outlines cyber priorities. Andrea Little Limbago from Interos shares insights from her RSAC 2023 panels. US indicts, sanctions DPRK operators in crypto-laundering campaign. Our guest is Marc van Zadelhoff, CEO of Devo, with insights from the conference. And the latest on KillNet.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/79


Selected reading.

BlackCat Ransomware Group Exploits GoAnywhere Vulnerability (At-Bay) 

Zero Day Initiative — TP-Link WAN-side Vulnerability CVE-2023-1389 Added to the Mirai Botnet Arsenal (Zero Day Initiative)

Years after discovery of SolarWinds breach, Russian hackers could be struggling (Washington Post) 

U.S. deploys more cyber forces abroad to help fight hackers (Reuters)

DHS Outlines Cyber Priorities in Release of Delayed Review (Nextgov.com) 

US sanctions supporters of North Korean hackers, Iranian cyberspace head (Record) 

North Korean Foreign Trade Bank Rep Charged for Role in Two Crypto Laundering Conspiracies (Department of Justice. U.S. Attorney's Office District of Columbia) 

Treasury Targets Actors Facilitating Illicit DPRK Financial Activity in Support of Weapons Programs (U.S. Department of the Treasury)

More description

BlackCat (ALPHV) follows Cl0p, exploiting the GoAnywhere MFA vulnerability. The Mirai botnet exploits a vulnerability disclosed at Pwn2Own. An RSAC presentation describes US response to Russian prewar and wartime cyber operations. The US Department of Homeland Security outlines cyber priorities. Andrea Little Limbago from Interos shares insights from her RSAC 2023 panels. US indicts, sanctions DPRK operators in crypto-laundering campaign. Our guest is Marc van Zadelhoff, CEO of Devo, with insights from the conference. And the latest on KillNet.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/79


Selected reading.

BlackCat Ransomware Group Exploits GoAnywhere Vulnerability (At-Bay) 

Zero Day Initiative — TP-Link WAN-side Vulnerability CVE-2023-1389 Added to the Mirai Botnet Arsenal (Zero Day Initiative)

Years after discovery of SolarWinds breach, Russian hackers could be struggling (Washington Post) 

U.S. deploys more cyber forces abroad to help fight hackers (Reuters)

DHS Outlines Cyber Priorities in Release of Delayed Review (Nextgov.com) 

US sanctions supporters of North Korean hackers, Iranian cyberspace head (Record) 

North Korean Foreign Trade Bank Rep Charged for Role in Two Crypto Laundering Conspiracies (Department of Justice. U.S. Attorney's Office District of Columbia) 

Treasury Targets Actors Facilitating Illicit DPRK Financial Activity in Support of Weapons Programs (U.S. Department of the Treasury)

Extract Knowledge
Listen elsewhere

3CX is not the only victim in the recent supply chain attack. The PaperCut critical vulnerability is under active exploitation. The Bumblebee malware loader is buzzing around in the wild. A new unique malware toolkit called Decoy Dog. Rick Howard, CSO from N2K Networks, shares RSA Conference predictions and talks about his new book, "Cybersecurity First Principles." Our guest Theresa Lanowitz from AT&T Cybersecurity shares insights on Securing the Edge. And the alleged Discord Papers leaker shared earlier and more widely than previously known.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/78


Selected reading.

3CX Hackers Also Compromised Critical Infrastructure Firms (Infosecurity Magazine)

That 3CX supply chain attack keeps getting worse (Register)

Energy sector orgs in US, Europe hit by same supply chain attack as 3CX (Record) 

Even more victims found in complex 3CX supply chain attack (CybersecurityConnect) 

X_Trader Supply Chain Attack Affects Critical Infrastructure Organizations in U.S. and Europe (Symantec Enterprise Blogs) 

URGENT | PaperCut MF/NG vulnerability bulletin (March 2023) (PaperCut)

PaperCut CVE-2023-27350 Deep Dive and Indicators of Compromise (Horizon3.ai) 

Russian Hackers Suspected in Ongoing Exploitation of Unpatched PaperCut Servers (The Hacker News) 

CISA KEV Breakdown | April 21, 2023 (Nucleus Security)

CISA Adds Three Known Exploited Vulnerabilities to Catalog (Cybersecurity and Infrastructure Security Agency CISA)

CISA Adds 3 Actively Exploited Flaws to KEV Catalog, including Critical PaperCut Bug (The Hacker News) 

CISA adds printer bug, Chrome zero-day and ChatGPT issue to exploited vulnerabilities catalog (Record)

Bumblebee Malware Distributed Via Trojanized Installer Downloads (Secureworks).

Google ads push BumbleBee malware used by ransomware gangs (BleepingComputer) 

Bumblebee malware infects victims via fake Zoom, Cisco and ChatGPT software installers (Record) 

Decoy Dog malware toolkit found after analyzing 70 billion DNS queries (BleepingComputer) 

Analyzing DNS Traffic for Anomalous Domains and Threat Detection (Infoblox Blog) 

Airman Shared Sensitive Intelligence More Widely and for Longer Than Previously Known (New York Times) 

FBI leak investigators home in on members of private Discord server (Washington Post)

From Discord to 4chan: The Improbable Journey of a US Intelligence Leak (bellingcat) 

Europe’s Planes Keep Flying Despite Cyberattack (Wall Street Journal)

More description

3CX is not the only victim in the recent supply chain attack. The PaperCut critical vulnerability is under active exploitation. The Bumblebee malware loader is buzzing around in the wild. A new unique malware toolkit called Decoy Dog. Rick Howard, CSO from N2K Networks, shares RSA Conference predictions and talks about his new book, "Cybersecurity First Principles." Our guest Theresa Lanowitz from AT&T Cybersecurity shares insights on Securing the Edge. And the alleged Discord Papers leaker shared earlier and more widely than previously known.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/78


Selected reading.

3CX Hackers Also Compromised Critical Infrastructure Firms (Infosecurity Magazine)

That 3CX supply chain attack keeps getting worse (Register)

Energy sector orgs in US, Europe hit by same supply chain attack as 3CX (Record) 

Even more victims found in complex 3CX supply chain attack (CybersecurityConnect) 

X_Trader Supply Chain Attack Affects Critical Infrastructure Organizations in U.S. and Europe (Symantec Enterprise Blogs) 

URGENT | PaperCut MF/NG vulnerability bulletin (March 2023) (PaperCut)

PaperCut CVE-2023-27350 Deep Dive and Indicators of Compromise (Horizon3.ai) 

Russian Hackers Suspected in Ongoing Exploitation of Unpatched PaperCut Servers (The Hacker News) 

CISA KEV Breakdown | April 21, 2023 (Nucleus Security)

CISA Adds Three Known Exploited Vulnerabilities to Catalog (Cybersecurity and Infrastructure Security Agency CISA)

CISA Adds 3 Actively Exploited Flaws to KEV Catalog, including Critical PaperCut Bug (The Hacker News) 

CISA adds printer bug, Chrome zero-day and ChatGPT issue to exploited vulnerabilities catalog (Record)

Bumblebee Malware Distributed Via Trojanized Installer Downloads (Secureworks).

Google ads push BumbleBee malware used by ransomware gangs (BleepingComputer) 

Bumblebee malware infects victims via fake Zoom, Cisco and ChatGPT software installers (Record) 

Decoy Dog malware toolkit found after analyzing 70 billion DNS queries (BleepingComputer) 

Analyzing DNS Traffic for Anomalous Domains and Threat Detection (Infoblox Blog) 

Airman Shared Sensitive Intelligence More Widely and for Longer Than Previously Known (New York Times) 

FBI leak investigators home in on members of private Discord server (Washington Post)

From Discord to 4chan: The Improbable Journey of a US Intelligence Leak (bellingcat) 

Europe’s Planes Keep Flying Despite Cyberattack (Wall Street Journal)

Extract Knowledge
Listen elsewhere
T-Minus Deep Space Guest

Scott Stalker, Command Senior Enlisted Leader at US Space Command, shares how the combatant command is adapting to new challenges in the digital era of space operations, new operational concepts, and building the force to deter aggression.

You can follow US Space Command on LinkedIn and Twitter, and you can follow MGySgt Scott Stalker on LinkedIn.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our weekly intelligence briefing, Signals and Space, and you’ll never miss a beat.

Audience Survey

We want to hear from you! Please complete our wicked fast 4 question survey. It’ll help us get better and deliver you the most mission-critical space intel every day.

Want to hear your company in the show?

You too can reach the most influential leaders in the industry. Here’s a link to our media kit. Contact us at space@n2k.com to request more info about sponsoring T-Minus.

Want to join us for an interview?

Please send your interview pitch to space-editor@n2k.com and include your name, affiliation, and topic proposal, and our editor will get back to you for scheduling.

T-Minus is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description
T-Minus Deep Space Guest

Scott Stalker, Command Senior Enlisted Leader at US Space Command, shares how the combatant command is adapting to new challenges in the digital era of space operations, new operational concepts, and building the force to deter aggression.

You can follow US Space Command on LinkedIn and Twitter, and you can follow MGySgt Scott Stalker on LinkedIn.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our weekly intelligence briefing, Signals and Space, and you’ll never miss a beat.

Audience Survey

We want to hear from you! Please complete our wicked fast 4 question survey. It’ll help us get better and deliver you the most mission-critical space intel every day.

Want to hear your company in the show?

You too can reach the most influential leaders in the industry. Here’s a link to our media kit. Contact us at space@n2k.com to request more info about sponsoring T-Minus.

Want to join us for an interview?

Please send your interview pitch to space-editor@n2k.com and include your name, affiliation, and topic proposal, and our editor will get back to you for scheduling.

T-Minus is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

Maria Varmazis, N2K's Space Correspondent and host of N2K's newest podcast T-Minus, sits down to share her journey on combining her two passions of space and cyber. Maria grew up wanting to be an astronomer, in school she focused on joining anything with technology and enjoyed the classes that made her think. After transferring to a new college, she went into journalism, absolutely falling in love with the new career path she had made for herself. She got herself a job at Sophos and that's where she learned about cybersecurity. Now she discusses cyber and space in her new podcast, combining her two passions into one for all to understand. Maria discusses some of the setbacks she overcame in this industry and shares the wise advice of "I would never pretend that failure isn't painful, but it is an incredible teaching tool. So if you feel like you've had a huge career fail or a really big misstep, you can still pivot from that and you can make that into something." We thank Maria for sharing her story with us.

More description

Maria Varmazis, N2K's Space Correspondent and host of N2K's newest podcast T-Minus, sits down to share her journey on combining her two passions of space and cyber. Maria grew up wanting to be an astronomer, in school she focused on joining anything with technology and enjoyed the classes that made her think. After transferring to a new college, she went into journalism, absolutely falling in love with the new career path she had made for herself. She got herself a job at Sophos and that's where she learned about cybersecurity. Now she discusses cyber and space in her new podcast, combining her two passions into one for all to understand. Maria discusses some of the setbacks she overcame in this industry and shares the wise advice of "I would never pretend that failure isn't painful, but it is an incredible teaching tool. So if you feel like you've had a huge career fail or a really big misstep, you can still pivot from that and you can make that into something." We thank Maria for sharing her story with us.

Extract Knowledge
Listen elsewhere

Shiran Guez from Akamai sits down with Dave to discuss their research on "Chatbots, Celebrities, and Victim Retargeting and Why Crypto Giveaway Scams Are Still So Successful." Researchers at Akamai have been on the lookout for crypto giveaway scams. These scams have been impersonating celebrities and brands, most notably Elon Musk and his associated companies.

The research states "the scams are delivered through various social media platforms as well as direct messaging apps such as WhatsApp or Telegram." These scams have helped add to the existing damages that exceed $1 billion caused by crypto fraud.

The research can be found here:

More description

Shiran Guez from Akamai sits down with Dave to discuss their research on "Chatbots, Celebrities, and Victim Retargeting and Why Crypto Giveaway Scams Are Still So Successful." Researchers at Akamai have been on the lookout for crypto giveaway scams. These scams have been impersonating celebrities and brands, most notably Elon Musk and his associated companies.

The research states "the scams are delivered through various social media platforms as well as direct messaging apps such as WhatsApp or Telegram." These scams have helped add to the existing damages that exceed $1 billion caused by crypto fraud.

The research can be found here:

Extract Knowledge
Listen elsewhere

Daggerfly APT targets an African telecommunications provider. EvilExtractor is an alleged teaching tool apparently gone bad. A Chinese speaking threat group is active against Taiwan and South Korea. Europe’s air traffic control is under attack. Cecilia Marinier from RSAC and Barmak Meftah, a judge of ISB, discuss the RSA innovation sandbox. Awais Rashid from University of Bristol on the cybersecurity of smart farming. Forget about those evil maids. What about these evil sys admins? 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/77


Selected reading.

Daggerfly: APT Actor Targets Telecoms Company in Africa (Symantec)

EvilExtractor – All-in-One Stealer (Fortinet Blog)

Chinese-language threat group targeted a dozen South Korean institutions (Record) 

Xiaoqiying/Genesis Day Threat Actor Group Targets South Korea, Taiwan (Recorded Future) 

WSJ News Exclusive | Europe’s Air-Traffic Agency Under Attack From Pro-Russian Hackers (Wall Street Journal) 

Intelligence Leaks Cast Spotlight on a Recurring Insider Threat: Tech Support (Wall Street Journal)

Russia’s invasion of Ukraine is also being fought in cyberspace (Atlantic Council) 

CFP European Cybersecurity Seminar 2023-2024 (European Cyber Conflict Research Initiative)

#CYBERUK23: Russian Cyber Offensive Exhibits ‘Unprecedented’ Speed and Agility (Infosecurity Magazine)

More description

Daggerfly APT targets an African telecommunications provider. EvilExtractor is an alleged teaching tool apparently gone bad. A Chinese speaking threat group is active against Taiwan and South Korea. Europe’s air traffic control is under attack. Cecilia Marinier from RSAC and Barmak Meftah, a judge of ISB, discuss the RSA innovation sandbox. Awais Rashid from University of Bristol on the cybersecurity of smart farming. Forget about those evil maids. What about these evil sys admins? 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/77


Selected reading.

Daggerfly: APT Actor Targets Telecoms Company in Africa (Symantec)

EvilExtractor – All-in-One Stealer (Fortinet Blog)

Chinese-language threat group targeted a dozen South Korean institutions (Record) 

Xiaoqiying/Genesis Day Threat Actor Group Targets South Korea, Taiwan (Recorded Future) 

WSJ News Exclusive | Europe’s Air-Traffic Agency Under Attack From Pro-Russian Hackers (Wall Street Journal) 

Intelligence Leaks Cast Spotlight on a Recurring Insider Threat: Tech Support (Wall Street Journal)

Russia’s invasion of Ukraine is also being fought in cyberspace (Atlantic Council) 

CFP European Cybersecurity Seminar 2023-2024 (European Cyber Conflict Research Initiative)

#CYBERUK23: Russian Cyber Offensive Exhibits ‘Unprecedented’ Speed and Agility (Infosecurity Magazine)

Extract Knowledge
Listen elsewhere

The 3CX compromise involved a two-stage supply-chain attack. Impersonating ChatGPT. Russia's security organs say they're cracking down on leaks. Updates on the Discord Papers case. Belarus arrests a pro-Russian hacktivist. Rob Boyce from Accenture Security on Dark Web cyber criminals targeting CRM systems. Our guest is Mike Loewy from the Tide Foundation, with an innovative approach to distributed key security. And, is Minsk going wobbly on Moscow?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/76


Selected reading.

3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible (Mandiant)

ChatGPT-Themed Scam Attacks Are on the Rise (Palo Alto Networks Unit 42)

Russian Offensive Campaign Assessment, April 19, 2023 (Institute for the Study of War)

Belarus-linked hacking group targets Poland with new disinformation campaign (Record)

Killnet Ostracizes Leader of Anonymous Russia, Adding New Chapter to Pro-Kremlin Hacktivist Drama (Flashpoint)

Belarus-linked hacking group targets Poland with new disinformation campaign (Record)

More description

The 3CX compromise involved a two-stage supply-chain attack. Impersonating ChatGPT. Russia's security organs say they're cracking down on leaks. Updates on the Discord Papers case. Belarus arrests a pro-Russian hacktivist. Rob Boyce from Accenture Security on Dark Web cyber criminals targeting CRM systems. Our guest is Mike Loewy from the Tide Foundation, with an innovative approach to distributed key security. And, is Minsk going wobbly on Moscow?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/76


Selected reading.

3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible (Mandiant)

ChatGPT-Themed Scam Attacks Are on the Rise (Palo Alto Networks Unit 42)

Russian Offensive Campaign Assessment, April 19, 2023 (Institute for the Study of War)

Belarus-linked hacking group targets Poland with new disinformation campaign (Record)

Killnet Ostracizes Leader of Anonymous Russia, Adding New Chapter to Pro-Kremlin Hacktivist Drama (Flashpoint)

Belarus-linked hacking group targets Poland with new disinformation campaign (Record)

Extract Knowledge
Listen elsewhere

The UK National Cyber Security Centre (NCSC), NSA, CISA, and FBI are releasing this joint advisory to provide TTPs associated with APT28’s exploitation of Cisco routers in 2021.

AA23-108A Alert, Technical Details, and Mitigations

Malware Analysis Report

Resource to mitigate a ransomware attack: CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide.

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

More description

The UK National Cyber Security Centre (NCSC), NSA, CISA, and FBI are releasing this joint advisory to provide TTPs associated with APT28’s exploitation of Cisco routers in 2021.

AA23-108A Alert, Technical Details, and Mitigations

Malware Analysis Report

Resource to mitigate a ransomware attack: CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide.

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge
Listen elsewhere

Play ransomware's new tools. Fancy Bear is out and about. Updates on Sandworm. Ransomware in Russia's war against Ukraine. The US Air Force opens an investigation into the alleged leaker's Air National Guard wing. The Washington Post’s Tim Starks joins us with insights on the Biden administration's attempts to better secure the water supply. Carole Theriault chats with Cisco Talos' Vanja Svacjer about the threat landscape, now and tomorrow. And KillNet’s in the education business with a new hacker course: “Dark School.” 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/75


Selected reading.

Play Ransomware Group Using New Custom Data-Gathering Tools (Symantec)

NCSC-UK, NSA, and Partners Advise about APT28 Exploitation of Cisco Routers (National Security Agency/Central Security Service)

APT28 exploits known vulnerability to carry out reconnaissance and deploy malware on Cisco routers (NCSC)

State-sponsored campaigns target global network infrastructure (Cisco Talos Blog) 

Ukraine remains Russia’s biggest cyber focus in 2023 (Google)

Fog of War: How the Ukraine Conflict Transformed the Cyber Threat Landscape (Google Threat Analysis Group)

M-Trends 2023: Cybersecurity Insights From the Frontlines (Mandiant)

Faltering against Ukraine, Russian hackers resort to ransomware: Researchers (Breaking Defense) 

Air Force unit in document leaks case loses intel mission (AP NEWS)

Pentagon Details Review of Policies for Handling Classified Information (New York Times) 

Ukraine at D+419: GRU cyber ops scrutinized. (CyberWire)

More description

Play ransomware's new tools. Fancy Bear is out and about. Updates on Sandworm. Ransomware in Russia's war against Ukraine. The US Air Force opens an investigation into the alleged leaker's Air National Guard wing. The Washington Post’s Tim Starks joins us with insights on the Biden administration's attempts to better secure the water supply. Carole Theriault chats with Cisco Talos' Vanja Svacjer about the threat landscape, now and tomorrow. And KillNet’s in the education business with a new hacker course: “Dark School.” 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/75


Selected reading.

Play Ransomware Group Using New Custom Data-Gathering Tools (Symantec)

NCSC-UK, NSA, and Partners Advise about APT28 Exploitation of Cisco Routers (National Security Agency/Central Security Service)

APT28 exploits known vulnerability to carry out reconnaissance and deploy malware on Cisco routers (NCSC)

State-sponsored campaigns target global network infrastructure (Cisco Talos Blog) 

Ukraine remains Russia’s biggest cyber focus in 2023 (Google)

Fog of War: How the Ukraine Conflict Transformed the Cyber Threat Landscape (Google Threat Analysis Group)

M-Trends 2023: Cybersecurity Insights From the Frontlines (Mandiant)

Faltering against Ukraine, Russian hackers resort to ransomware: Researchers (Breaking Defense) 

Air Force unit in document leaks case loses intel mission (AP NEWS)

Pentagon Details Review of Policies for Handling Classified Information (New York Times) 

Ukraine at D+419: GRU cyber ops scrutinized. (CyberWire)

Extract Knowledge
Listen elsewhere

Brace yourselves, it’s Space Symposium week! Wet dress rehearsal for Starship. UK launches the International Bilateral Fund. Orbit Fab gets a series A round. Boeing announces their anti-jam payload for WGS. The FAA wants to balance air travel and space travel. Our interview with Steve Luczynski, Board Chair of the Aerospace Village, on their mission, programs, and upcoming activities at the RSA Conference next week. All this and more.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our weekly intelligence briefing, Signals and Space, and you’ll never miss a beat.

T-Minus Guest

Our featured guest is Steve Luczynski, Board Chair of the Aerospace Village, on the Aerospace Village nonprofit, their mission, their programs, and their upcoming activities at the RSA Conference next week.

You can follow Steve on LinkedIn and Twitter.

Selected Reading

SpaceX's launch of Starship could remake space exploration | Washington Post 

UK Space Agency funding for international space partnerships | GOV.UK

SpaceX launches seventh Transporter rideshare mission | SpaceNews

Exolaunch’s 21 rideshare smallsats deployed during the SpaceX Transporter-7 mission | SatNews

HawkEye 360’s nexgen Cluster 7 smallsats are successfully launched | SatNews   

TrustPoint Announces Launch of First Commercially-Funded, Purpose-Built PNT Microsatellite | Business Wire 

China claims its Space Station has achieved 100% oxygen regeneration in orbit | Interesting Engineering 

Boeing Unveils Anti-Jam Payload For Next Space Force Wideband Global SATCOM Satellite | Via Satellite

As counterspace weapons ‘proliferate,’ the new cold war for space races forward: studies | Breaking Defense

The Moon is the Best Place to Transport Rocket Fuel | Universe Today 

US aviation authorities may delay some space launches to avoid air traffic disruption | Reuters 

NASA launches stadium-sized balloon from New Zealand | SpaceConnect  

Audience Survey

We want to hear from you! Please complete our wicked fast 4 question survey. It’ll help us get better and deliver you the most mission-critical space intel every day.

Want to hear your company in the show?

You too can reach the most influential leaders in the industry. Here’s a link to our media kit. Contact us at space@n2k.com to request more info about sponsoring T-Minus.

Want to join us for an interview?

Please send your interview pitch to space-editor@n2k.com and include your name, affiliation, and topic proposal, and our editor will get back to you for scheduling.

T-Minus is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

Brace yourselves, it’s Space Symposium week! Wet dress rehearsal for Starship. UK launches the International Bilateral Fund. Orbit Fab gets a series A round. Boeing announces their anti-jam payload for WGS. The FAA wants to balance air travel and space travel. Our interview with Steve Luczynski, Board Chair of the Aerospace Village, on their mission, programs, and upcoming activities at the RSA Conference next week. All this and more.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our weekly intelligence briefing, Signals and Space, and you’ll never miss a beat.

T-Minus Guest

Our featured guest is Steve Luczynski, Board Chair of the Aerospace Village, on the Aerospace Village nonprofit, their mission, their programs, and their upcoming activities at the RSA Conference next week.

You can follow Steve on LinkedIn and Twitter.

Selected Reading

SpaceX's launch of Starship could remake space exploration | Washington Post 

UK Space Agency funding for international space partnerships | GOV.UK

SpaceX launches seventh Transporter rideshare mission | SpaceNews

Exolaunch’s 21 rideshare smallsats deployed during the SpaceX Transporter-7 mission | SatNews

HawkEye 360’s nexgen Cluster 7 smallsats are successfully launched | SatNews   

TrustPoint Announces Launch of First Commercially-Funded, Purpose-Built PNT Microsatellite | Business Wire 

China claims its Space Station has achieved 100% oxygen regeneration in orbit | Interesting Engineering 

Boeing Unveils Anti-Jam Payload For Next Space Force Wideband Global SATCOM Satellite | Via Satellite

As counterspace weapons ‘proliferate,’ the new cold war for space races forward: studies | Breaking Defense

The Moon is the Best Place to Transport Rocket Fuel | Universe Today 

US aviation authorities may delay some space launches to avoid air traffic disruption | Reuters 

NASA launches stadium-sized balloon from New Zealand | SpaceConnect  

Audience Survey

We want to hear from you! Please complete our wicked fast 4 question survey. It’ll help us get better and deliver you the most mission-critical space intel every day.

Want to hear your company in the show?

You too can reach the most influential leaders in the industry. Here’s a link to our media kit. Contact us at space@n2k.com to request more info about sponsoring T-Minus.

Want to join us for an interview?

Please send your interview pitch to space-editor@n2k.com and include your name, affiliation, and topic proposal, and our editor will get back to you for scheduling.

T-Minus is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

An Iranian threat actor exploits N-day vulnerabilities. CSC exposes subdomain hijacking vulnerabilities. More on the Discord Papers. An update on Russia’s NTC Vulkan. Joe Carrigan on the aftermath of a $98M online investment fraud. Our guest is Blake Sobczak from Synack , host of the podcast WE'RE IN! And threat actor nomenclature: a scorecard, and a Periodic Table no more.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/74


Selected reading.

Nation-state threat actor Mint Sandstorm refines tradecraft to attack high-value targets (Microsoft Security)

An Iranian hacking group went on the offensive against U.S. targets, Microsoft says (Washington Post) 

New CSC Research Finds One in Five DNS Records are Susceptible to Subdomain Hijacking Due to Insufficient Cyber Hygiene | CSC (CSC)

DOD Assessing Document Disclosures and Implementing Mitigation Measures (U.S. Department of Defense)

After leak, Pentagon purges some users' access to classified programs, launches security review (Breaking Defense)

Why Did a 21-Year-Old Guardsman Have Access to State Secrets? (Vice)

U.S. officials have examined whether alleged doc leaker had foreign links (POLITICO) 

The Air Force Loves War Gamers Like Alleged Leaker Teixeira (Military.com) 

FBI Investigating Ex-Navy Noncommissioned Officer Linked to Pro-Russia Social-Media Account (Wall Street Journal)

Pentagon leak suggests Russia honing disinformation drive – report (the Guardian)

Dragos Analyzes Russian Programs Threatening Critical Civilian Infrastructure (Dragos) 

Microsoft shifts to a new threat actor naming taxonomy (Microsoft)

More description

An Iranian threat actor exploits N-day vulnerabilities. CSC exposes subdomain hijacking vulnerabilities. More on the Discord Papers. An update on Russia’s NTC Vulkan. Joe Carrigan on the aftermath of a $98M online investment fraud. Our guest is Blake Sobczak from Synack , host of the podcast WE'RE IN! And threat actor nomenclature: a scorecard, and a Periodic Table no more.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/74


Selected reading.

Nation-state threat actor Mint Sandstorm refines tradecraft to attack high-value targets (Microsoft Security)

An Iranian hacking group went on the offensive against U.S. targets, Microsoft says (Washington Post) 

New CSC Research Finds One in Five DNS Records are Susceptible to Subdomain Hijacking Due to Insufficient Cyber Hygiene | CSC (CSC)

DOD Assessing Document Disclosures and Implementing Mitigation Measures (U.S. Department of Defense)

After leak, Pentagon purges some users' access to classified programs, launches security review (Breaking Defense)

Why Did a 21-Year-Old Guardsman Have Access to State Secrets? (Vice)

U.S. officials have examined whether alleged doc leaker had foreign links (POLITICO) 

The Air Force Loves War Gamers Like Alleged Leaker Teixeira (Military.com) 

FBI Investigating Ex-Navy Noncommissioned Officer Linked to Pro-Russia Social-Media Account (Wall Street Journal)

Pentagon leak suggests Russia honing disinformation drive – report (the Guardian)

Dragos Analyzes Russian Programs Threatening Critical Civilian Infrastructure (Dragos) 

Microsoft shifts to a new threat actor naming taxonomy (Microsoft)

Extract Knowledge
Listen elsewhere

The alleged Discord Papers leaker has been charged. We look at how the Papers spread online. A life lived online as a security risk. US tax season scams, at the 11th filing hour. Caleb Barlow from Cylete on the layoffs in security that many thought would never happen. Maria Varmazis and Brandon Karpf share the launch of the new space podcast, T-Minus. And KillNet says it’s open for business.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/73


Selected reading.

Inside the furious week-long scramble to hunt down a massive Pentagon leak (CNN Politics) 

Massachusetts Air National Guard’s Intelligence Mission in the Spotlight (New York Times) 

Leaker of U.S. secret documents worked on military base, friend says (Washington Post) 

WSJ News Exclusive | Social-Media Account Overseen by Former Navy Noncommissioned Officer Helped Spread Secrets (Wall Street Journal).

A Russian Disinformation Empire in Oak Harbor, Washington (Malcontent News) 

Pro-Russia propagandist unmasked as New Jersey tropical fish seller (The Telegraph) 

Suspect charged in case involving leaked classified military documents (Washington Post) 

Jack Teixeira, suspect in Pentagon leaks, charged under Espionage Act (the Guardian)

Leak suspect appears in court as US spells out its case (AP NEWS) 

Airman in Pentagon intel leak charged (Military Times) 

Airman charged in Pentagon intel leak regretted joining the military (Military Times) 

He’s from a military family — and allegedly leaked U.S. secrets (Washington Post)

Jack Teixeira's alleged Discord leaks show why the US should stop showering Top Secret clearances on 21-year-old keyboard warriors (Business Insider).

The military loved Discord for Gen Z recruiting. Then the leaks began. (Washington Post) 

A new kind of leaker: Spilling state secrets to impress online buddies (Washington Post) 

Was the Gen-Z Pentagon leaker motivated by social media clout? (the Guardian) 

Microsoft president claims Russian intelligence is trying to "penetrate gaming communities" (GamesIndustry.biz)

How Gamers Eclipsed Spies as an Intelligence Threat (Foreign Policy)

Crafty PDF link is part of another tax-season malware campaign (Record)

Tax season scams. (CyberWire)

Ukraine at D+414: Discord Papers arrest, cyberespionage, and hacktivist DDoS. (CyberWire)

More description

The alleged Discord Papers leaker has been charged. We look at how the Papers spread online. A life lived online as a security risk. US tax season scams, at the 11th filing hour. Caleb Barlow from Cylete on the layoffs in security that many thought would never happen. Maria Varmazis and Brandon Karpf share the launch of the new space podcast, T-Minus. And KillNet says it’s open for business.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/73


Selected reading.

Inside the furious week-long scramble to hunt down a massive Pentagon leak (CNN Politics) 

Massachusetts Air National Guard’s Intelligence Mission in the Spotlight (New York Times) 

Leaker of U.S. secret documents worked on military base, friend says (Washington Post) 

WSJ News Exclusive | Social-Media Account Overseen by Former Navy Noncommissioned Officer Helped Spread Secrets (Wall Street Journal).

A Russian Disinformation Empire in Oak Harbor, Washington (Malcontent News) 

Pro-Russia propagandist unmasked as New Jersey tropical fish seller (The Telegraph) 

Suspect charged in case involving leaked classified military documents (Washington Post) 

Jack Teixeira, suspect in Pentagon leaks, charged under Espionage Act (the Guardian)

Leak suspect appears in court as US spells out its case (AP NEWS) 

Airman in Pentagon intel leak charged (Military Times) 

Airman charged in Pentagon intel leak regretted joining the military (Military Times) 

He’s from a military family — and allegedly leaked U.S. secrets (Washington Post)

Jack Teixeira's alleged Discord leaks show why the US should stop showering Top Secret clearances on 21-year-old keyboard warriors (Business Insider).

The military loved Discord for Gen Z recruiting. Then the leaks began. (Washington Post) 

A new kind of leaker: Spilling state secrets to impress online buddies (Washington Post) 

Was the Gen-Z Pentagon leaker motivated by social media clout? (the Guardian) 

Microsoft president claims Russian intelligence is trying to "penetrate gaming communities" (GamesIndustry.biz)

How Gamers Eclipsed Spies as an Intelligence Threat (Foreign Policy)

Crafty PDF link is part of another tax-season malware campaign (Record)

Tax season scams. (CyberWire)

Ukraine at D+414: Discord Papers arrest, cyberespionage, and hacktivist DDoS. (CyberWire)

Extract Knowledge
Listen elsewhere

Jack Chapman, VP of Threat Intelligence at Egress sits down to share his story on how he found his way into the cybersecurity field as well as his journey creating a cybersecurity company that was successfully acquired. Jack previously co-founded anti-phishing company Aquilai and served as its Chief Technology Officer, working closely with the UK’s intelligence and cyber agency GCHQ to develop cutting-edge product capabilities. Aquilai was acquired by Egress in 2021. Now he is working with Egress as what he calls their "chief bad guy," helping to shield his team from threats. He says "I'm probably what you call a servant leader, my mission is to enable and shield my teams from things that will prevent them from succeeding in their missions, whatever that might look like." Jack hopes to be remembered for making a meaningful impact to help drive the field forward. We thank Jack for sharing his story with us.

More description

Jack Chapman, VP of Threat Intelligence at Egress sits down to share his story on how he found his way into the cybersecurity field as well as his journey creating a cybersecurity company that was successfully acquired. Jack previously co-founded anti-phishing company Aquilai and served as its Chief Technology Officer, working closely with the UK’s intelligence and cyber agency GCHQ to develop cutting-edge product capabilities. Aquilai was acquired by Egress in 2021. Now he is working with Egress as what he calls their "chief bad guy," helping to shield his team from threats. He says "I'm probably what you call a servant leader, my mission is to enable and shield my teams from things that will prevent them from succeeding in their missions, whatever that might look like." Jack hopes to be remembered for making a meaningful impact to help drive the field forward. We thank Jack for sharing his story with us.

Extract Knowledge
Listen elsewhere

Scott Fanning, Senior Director of Product Management, Cloud Security at CrowdStrike, sits down to talk about the first-ever Dero cryptojacking operation targeting Kubernetes infrastructure. The research defines Dero as "a cryptocurrency that claims to offer improved privacy, anonymity and higher and faster monetary rewards compared to Monero, which is a commonly used cryptocurrency in cryptojacking operations."

CrowdStrike was the first organization to discover Dero, and has been observing the cryptojacking operation since the beginning of February 2023. The operation focuses mainly on locating Kubernetes clusters with anonymous access enabled on a Kubernetes API and listening on non-standard ports accessible from the internet.

The research can be found here:

More description

Scott Fanning, Senior Director of Product Management, Cloud Security at CrowdStrike, sits down to talk about the first-ever Dero cryptojacking operation targeting Kubernetes infrastructure. The research defines Dero as "a cryptocurrency that claims to offer improved privacy, anonymity and higher and faster monetary rewards compared to Monero, which is a commonly used cryptocurrency in cryptojacking operations."

CrowdStrike was the first organization to discover Dero, and has been observing the cryptojacking operation since the beginning of February 2023. The operation focuses mainly on locating Kubernetes clusters with anonymous access enabled on a Kubernetes API and listening on non-standard ports accessible from the internet.

The research can be found here:

Extract Knowledge
Listen elsewhere

"Read the Manual" and the ransomware-as-a-service market. Bitter APT may be targeting Asia-Pacific energy companies. A Cozy Bear sighting. Hacktivist auxiliaries hit Canadian targets. Deepen Desai of Zscaler describes job scams following tech layoffs. Our guest is Kelly Shortridge from Fastly with insights on the risks from bots. And there’s been an arrest in the Discord Papers case.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/72


Selected reading.

Read The Manual Locker: A Private RaaS Provider (Trellix)

Phishing Campaign Targets Chinese Nuclear Energy Industry (Intezer)

Espionage campaign linked to Russian intelligence services (Baza wiedzy)

Russian cyberspies hit NATO and EU organizations with new malware toolset (CSO Online)

Pro-Russia hackers say they were behind Hydro-Quebec cyberattack (Montreal CTV News - 04-13-2023)

Cyberattack knocks out website and mobile app for Quebec’s hydro utility (Toronto Star)

F.B.I. Arrests National Guardsman in Leak of Classified Document (New York Times)

DOD Calls Document Leak 'a Criminal Act' (U.S. Department of Defense)

More description

"Read the Manual" and the ransomware-as-a-service market. Bitter APT may be targeting Asia-Pacific energy companies. A Cozy Bear sighting. Hacktivist auxiliaries hit Canadian targets. Deepen Desai of Zscaler describes job scams following tech layoffs. Our guest is Kelly Shortridge from Fastly with insights on the risks from bots. And there’s been an arrest in the Discord Papers case.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/72


Selected reading.

Read The Manual Locker: A Private RaaS Provider (Trellix)

Phishing Campaign Targets Chinese Nuclear Energy Industry (Intezer)

Espionage campaign linked to Russian intelligence services (Baza wiedzy)

Russian cyberspies hit NATO and EU organizations with new malware toolset (CSO Online)

Pro-Russia hackers say they were behind Hydro-Quebec cyberattack (Montreal CTV News - 04-13-2023)

Cyberattack knocks out website and mobile app for Quebec’s hydro utility (Toronto Star)

F.B.I. Arrests National Guardsman in Leak of Classified Document (New York Times)

DOD Calls Document Leak 'a Criminal Act' (U.S. Department of Defense)

Extract Knowledge
Listen elsewhere

Transparent Tribe expands its activity against India's education sector. A Lazarus sub-group is after defense sector targets. The FBI's Denver office warns of potential juicejacking. Legion: a Python-based credential harvester. The source of leaked US intelligence may be closer to identification. Johannes Ullrich from SANS explains upwork scams. Our guest is Charlie "Tuna" Moore of Vanderbilt University on the cyber lessons from Russia’s war on Ukraine. Canada responds to claims of Russian cyberattacks.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/71


Selected reading.

Transparent Tribe (APT36) | Pakistan-Aligned Threat Actor Expands Interest in Indian Education Sector (SentinelOne)

Following the Lazarus group by tracking DeathNote campaign (Securelist)

DPRK threat actors target C3X and defense sector at large. (CyberWire)

FBI office warns against using public phone charging stations at airports or malls, citing malware risk (CBS News)

The FBI warns of juicejacking and other risks of public tech. (CyberWire)

Legion: an AWS Credential Harvester and SMTP Hijacker (Cado Security) 

The Legion credential harvester. (CyberWire)

Leaker of U.S. secret documents worked on military base, friend says (Washington Post)

U.S. may change how it monitors the web after missing leaked documents for weeks (NBC News)

Cyberattacks on Canada’s gas infrastructure left ‘no physical damage,’ Trudeau says (Global News)

Russian attacks on Ukrainian infrastructure cause internet outages, cutting off a valuable wartime tool (CyberScoop)

US Warns Russia Getting Creative in Cyberspace (VOA)

APT Winter Vivern Resurfaces (Avertium)

More description

Transparent Tribe expands its activity against India's education sector. A Lazarus sub-group is after defense sector targets. The FBI's Denver office warns of potential juicejacking. Legion: a Python-based credential harvester. The source of leaked US intelligence may be closer to identification. Johannes Ullrich from SANS explains upwork scams. Our guest is Charlie "Tuna" Moore of Vanderbilt University on the cyber lessons from Russia’s war on Ukraine. Canada responds to claims of Russian cyberattacks.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/71


Selected reading.

Transparent Tribe (APT36) | Pakistan-Aligned Threat Actor Expands Interest in Indian Education Sector (SentinelOne)

Following the Lazarus group by tracking DeathNote campaign (Securelist)

DPRK threat actors target C3X and defense sector at large. (CyberWire)

FBI office warns against using public phone charging stations at airports or malls, citing malware risk (CBS News)

The FBI warns of juicejacking and other risks of public tech. (CyberWire)

Legion: an AWS Credential Harvester and SMTP Hijacker (Cado Security) 

The Legion credential harvester. (CyberWire)

Leaker of U.S. secret documents worked on military base, friend says (Washington Post)

U.S. may change how it monitors the web after missing leaked documents for weeks (NBC News)

Cyberattacks on Canada’s gas infrastructure left ‘no physical damage,’ Trudeau says (Global News)

Russian attacks on Ukrainian infrastructure cause internet outages, cutting off a valuable wartime tool (CyberScoop)

US Warns Russia Getting Creative in Cyberspace (VOA)

APT Winter Vivern Resurfaces (Avertium)

Extract Knowledge
Listen elsewhere

Patch Tuesday update. Another commercial surveillance company is outed. Voice security and the challenge of fraud. CISA updates its Zero Trust Maturity Model. Effects of the US intelligence leaks. Our guest Eric Goldstein, Executive Assistant Director for Cybersecurity at CISA, outlines CISA's role in the cybersecurity community. André Keartland of Netsurit makes the case for DevSecOps. Russian cyber auxiliaries believed responsible for disrupting the Canadian PM's website.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/70


Selected reading.

Patch Tuesday overview. (CyberWire)

DEV-0196: QuaDream’s “KingsPawn” malware used to target civil society in Europe, North America, the Middle East, and Southeast Asia (Microsoft Threat Intelligence) 

Threat Report on the Surveillance-for-Hire Industry (Meta)

Sweet QuaDreams: A First Look at Spyware Vendor QuaDream’s Exploits, Victims, and Customers (The Citizen Lab)

Voice Intelligence and Security Report (Pindrop)

CISA Releases updated Zero Trust Maturity Model (Cybersecurity and Infrastructure Security Agency)

CISA Releases Zero Trust Maturity Model Version 2 (Cybersecurity and Infrastructure Security Agency CISA)

A leak of files could be America’s worst intelligence breach in a decade (The Economist)

Interagency Effort Assessing Impact of Leaked Documents, Strategizing Way Forward (U.S. Department of Defense)

What we know about the Pentagon document leak (Axios)

The ongoing scandal over leaked US intel documents, explained (Vox)

Pentagon leak threatens Biden's foreign policy doctrine ahead of overseas trip (Axios)

Schumer calls for all-senator briefing on leaked Ukraine documents (The Hill)

The key countries and revelations from the Pentagon document leak (Washington Post) 

Exclusive: Leaked U.S. intel document claims Serbia agreed to arm Ukraine (Reuters) 

Up to 50 UK special forces present in Ukraine this year, US leak suggests (the Guardian)

Egypt denies leak about supplying Russia with 40,000 rockets (Al Jazeera)

DDoS attacks block PM Trudeau’s web site (IT World Canada)

More description

Patch Tuesday update. Another commercial surveillance company is outed. Voice security and the challenge of fraud. CISA updates its Zero Trust Maturity Model. Effects of the US intelligence leaks. Our guest Eric Goldstein, Executive Assistant Director for Cybersecurity at CISA, outlines CISA's role in the cybersecurity community. André Keartland of Netsurit makes the case for DevSecOps. Russian cyber auxiliaries believed responsible for disrupting the Canadian PM's website.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/70


Selected reading.

Patch Tuesday overview. (CyberWire)

DEV-0196: QuaDream’s “KingsPawn” malware used to target civil society in Europe, North America, the Middle East, and Southeast Asia (Microsoft Threat Intelligence) 

Threat Report on the Surveillance-for-Hire Industry (Meta)

Sweet QuaDreams: A First Look at Spyware Vendor QuaDream’s Exploits, Victims, and Customers (The Citizen Lab)

Voice Intelligence and Security Report (Pindrop)

CISA Releases updated Zero Trust Maturity Model (Cybersecurity and Infrastructure Security Agency)

CISA Releases Zero Trust Maturity Model Version 2 (Cybersecurity and Infrastructure Security Agency CISA)

A leak of files could be America’s worst intelligence breach in a decade (The Economist)

Interagency Effort Assessing Impact of Leaked Documents, Strategizing Way Forward (U.S. Department of Defense)

What we know about the Pentagon document leak (Axios)

The ongoing scandal over leaked US intel documents, explained (Vox)

Pentagon leak threatens Biden's foreign policy doctrine ahead of overseas trip (Axios)

Schumer calls for all-senator briefing on leaked Ukraine documents (The Hill)

The key countries and revelations from the Pentagon document leak (Washington Post) 

Exclusive: Leaked U.S. intel document claims Serbia agreed to arm Ukraine (Reuters) 

Up to 50 UK special forces present in Ukraine this year, US leak suggests (the Guardian)

Egypt denies leak about supplying Russia with 40,000 rockets (Al Jazeera)

DDoS attacks block PM Trudeau’s web site (IT World Canada)

Extract Knowledge
Listen elsewhere

Key trends in Identity Access Management. RagnarLocker and critical infrastructure. Cyber criminals capitalize on the AI hype. Updates on the leaked US classified documents, and speculation of whether Russian hackers compromised a Canadian gas pipeline. Ben Yelin describes a multimillion dollar settlement over biometric data. Microsoft’s Ann Johnson from Afternoon Cyber Tea talking about cyber paradigm shifts with Samir Kapuria. And a welcome to GCHQ's new boss.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/69


Selected reading.

4 key trends from the Gartner IAM Summit 2023 (Venture Beat)

Threat Actor Spotlight: Ragnarlocker Ransomware (Sygnia)

From Chatgpt To Redline Stealer: The Dark Side Of Openai And Google Bard (Veriti)

Biden administration doesn't know extent of classified Pentagon document leak (CBS News) 

Ukraine ‘alters counter-offensive plans’ after Pentagon leak (The Telegraph) 

Ukraine had to change military plans because of US Pentagon leak, source says (CNN) 

Leaked Pentagon documents claim that hackers breached a Canadian gas network. Here’s what to know. (Washington Post)

Pro-Russia Hackers Say They Breached Canadian Pipeline, but Experts Are Skeptical (Wall Street Journal)

Leaked US intel: Russia operatives claimed new ties with UAE (AP NEWS)

Egypt secretly planned to supply rockets to Russia, leaked U.S. document says (Washington Post)

How the Latest Leaked Documents Are Different From Past Breaches (New York Times)

How U.S. friends and foes have responded to leaked Pentagon documents (Washington Post) 

Pentagon leaks: US seeks to mend ties after claims Washington spied on key allies (the Guardian)

Pentagon Probe Under Way in Leaks Case (Wall Street Journal)

Pentagon assessing damage after 'highly classified' US secrets leaked online (Breaking Defense) 

The Pentagon’s Purported Classified-Document Leak: The Biggest Takeaways and Questions So Far (Wall Street Journal)

The ongoing scandal over leaked US intel documents, explained (Vox)

Leaked documents a 'very serious' risk to security: Pentagon (AP NEWS)

The Discord servers at the center of a massive US intelligence leak (CyberScoop) 

Social-Media Platform Discord Emerges at Center of Classified U.S. Documents Leak (Wall Street Journal)

Why Leaked Pentagon Documents Are Still Circulating on Social Media (New York Times)

Clues Left Online Might Aid Leak Investigation, Officials Say (New York Times

Ukraine at D+411: US leaks remain under investigation. (CyberWire)

New Director GCHQ announced (GCHQ)

More description

Key trends in Identity Access Management. RagnarLocker and critical infrastructure. Cyber criminals capitalize on the AI hype. Updates on the leaked US classified documents, and speculation of whether Russian hackers compromised a Canadian gas pipeline. Ben Yelin describes a multimillion dollar settlement over biometric data. Microsoft’s Ann Johnson from Afternoon Cyber Tea talking about cyber paradigm shifts with Samir Kapuria. And a welcome to GCHQ's new boss.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/69


Selected reading.

4 key trends from the Gartner IAM Summit 2023 (Venture Beat)

Threat Actor Spotlight: Ragnarlocker Ransomware (Sygnia)

From Chatgpt To Redline Stealer: The Dark Side Of Openai And Google Bard (Veriti)

Biden administration doesn't know extent of classified Pentagon document leak (CBS News) 

Ukraine ‘alters counter-offensive plans’ after Pentagon leak (The Telegraph) 

Ukraine had to change military plans because of US Pentagon leak, source says (CNN) 

Leaked Pentagon documents claim that hackers breached a Canadian gas network. Here’s what to know. (Washington Post)

Pro-Russia Hackers Say They Breached Canadian Pipeline, but Experts Are Skeptical (Wall Street Journal)

Leaked US intel: Russia operatives claimed new ties with UAE (AP NEWS)

Egypt secretly planned to supply rockets to Russia, leaked U.S. document says (Washington Post)

How the Latest Leaked Documents Are Different From Past Breaches (New York Times)

How U.S. friends and foes have responded to leaked Pentagon documents (Washington Post) 

Pentagon leaks: US seeks to mend ties after claims Washington spied on key allies (the Guardian)

Pentagon Probe Under Way in Leaks Case (Wall Street Journal)

Pentagon assessing damage after 'highly classified' US secrets leaked online (Breaking Defense) 

The Pentagon’s Purported Classified-Document Leak: The Biggest Takeaways and Questions So Far (Wall Street Journal)

The ongoing scandal over leaked US intel documents, explained (Vox)

Leaked documents a 'very serious' risk to security: Pentagon (AP NEWS)

The Discord servers at the center of a massive US intelligence leak (CyberScoop) 

Social-Media Platform Discord Emerges at Center of Classified U.S. Documents Leak (Wall Street Journal)

Why Leaked Pentagon Documents Are Still Circulating on Social Media (New York Times)

Clues Left Online Might Aid Leak Investigation, Officials Say (New York Times

Ukraine at D+411: US leaks remain under investigation. (CyberWire)

New Director GCHQ announced (GCHQ)

Extract Knowledge
Listen elsewhere

An Iranian APT MERCURY exploits known vulnerabilities. The US investigates apparent leaks of classified information about Russia's war against Ukraine. KillNet claims it has paralyzed NATO websites. More apparent doxing of the GRU. Britta Glade and Monica Koshgarian of RSA Conference talking about content curation. Grayson Milbourne from OpenText Cybersecurity hopes to remove shame from cyber attacks. And, finally, some notes on cloud security trends.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/68


Selected reading.

MERCURY and DEV-1084: Destructive attack on hybrid environment (Microsoft Threat Intelligence)

Leaked US battlefield intelligence on Ukraine is fake, says Kyiv (The Telegraph) 

Russia Claims Leaked Pentagon Intelligence on Ukraine is U.S. Disinformation (US News and World Report) 

Leaked US secret NATO-Ukraine war docs likely altered, say experts (SC Media) 

Ukraine’s air defences could soon run out of missiles, apparent Pentagon leak suggests (the Guardian) 

Russia nearly shot down British spy plane near Ukraine, leaked document says (Washington Post) 

Justice Dept. will investigate leak of classified Pentagon documents (Washington Post) 

US investigating whether Ukraine war documents were leaked (Military Times)

U.S. Reviewing Online Appearance Of Sensitive Documents Related To Ukraine, Pentagon Says (RadioFreeEurope/RadioLiberty) 

WSJ News Exclusive | Pentagon Investigates More Social-Media Posts Purporting to Include Secret U.S. Documents (Wall Street Journal) 

New Details on Intelligence Leak Show It Circulated for Weeks Before Raising Alarm (Wall Street Journal) 

Intelligence leak exposes U.S. spying on adversaries and allies (Washington Post) 

Secret US Documents on Ukraine War Plan Spill Onto Internet: Report (SecurityWeek) 

US hit by ‘worst leak of secret documents since Edward Snowden’ (The Telegraph)

Ukraine at D+410: Static, sanguinary lines. (CyberWire)

Report Finds 90% of IT Professionals Have Experienced a Cybersecurity Breach (Skyhigh Security)

More description

An Iranian APT MERCURY exploits known vulnerabilities. The US investigates apparent leaks of classified information about Russia's war against Ukraine. KillNet claims it has paralyzed NATO websites. More apparent doxing of the GRU. Britta Glade and Monica Koshgarian of RSA Conference talking about content curation. Grayson Milbourne from OpenText Cybersecurity hopes to remove shame from cyber attacks. And, finally, some notes on cloud security trends.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/68


Selected reading.

MERCURY and DEV-1084: Destructive attack on hybrid environment (Microsoft Threat Intelligence)

Leaked US battlefield intelligence on Ukraine is fake, says Kyiv (The Telegraph) 

Russia Claims Leaked Pentagon Intelligence on Ukraine is U.S. Disinformation (US News and World Report) 

Leaked US secret NATO-Ukraine war docs likely altered, say experts (SC Media) 

Ukraine’s air defences could soon run out of missiles, apparent Pentagon leak suggests (the Guardian) 

Russia nearly shot down British spy plane near Ukraine, leaked document says (Washington Post) 

Justice Dept. will investigate leak of classified Pentagon documents (Washington Post) 

US investigating whether Ukraine war documents were leaked (Military Times)

U.S. Reviewing Online Appearance Of Sensitive Documents Related To Ukraine, Pentagon Says (RadioFreeEurope/RadioLiberty) 

WSJ News Exclusive | Pentagon Investigates More Social-Media Posts Purporting to Include Secret U.S. Documents (Wall Street Journal) 

New Details on Intelligence Leak Show It Circulated for Weeks Before Raising Alarm (Wall Street Journal) 

Intelligence leak exposes U.S. spying on adversaries and allies (Washington Post) 

Secret US Documents on Ukraine War Plan Spill Onto Internet: Report (SecurityWeek) 

US hit by ‘worst leak of secret documents since Edward Snowden’ (The Telegraph)

Ukraine at D+410: Static, sanguinary lines. (CyberWire)

Report Finds 90% of IT Professionals Have Experienced a Cybersecurity Breach (Skyhigh Security)

Extract Knowledge
Listen elsewhere

Karen Worstell, Senior Cybersecurity Strategist from VMware sits down to share her journey and discusses her experience as a woman in cyber. Starting her career off as a chemist, after graduating with a bachelor's degree in chemistry and a bachelor's degree in molecular biology, she took some time off to be with her family, she came back to a science field that was far more advanced than before she had left. She decided to go in another direction which led her to cyber. She started teaching herself programming and found she was very good at it. Now that she works in cyber, she says "You, you have to know yourself, know what you want, and know where you're, know where you plant your feet. I used to use a phrase a lot that said, uh, don't be afraid to take a stand but know where your feet are planted." We thank Karen for sharing her story with us.

More description

Karen Worstell, Senior Cybersecurity Strategist from VMware sits down to share her journey and discusses her experience as a woman in cyber. Starting her career off as a chemist, after graduating with a bachelor's degree in chemistry and a bachelor's degree in molecular biology, she took some time off to be with her family, she came back to a science field that was far more advanced than before she had left. She decided to go in another direction which led her to cyber. She started teaching herself programming and found she was very good at it. Now that she works in cyber, she says "You, you have to know yourself, know what you want, and know where you're, know where you plant your feet. I used to use a phrase a lot that said, uh, don't be afraid to take a stand but know where your feet are planted." We thank Karen for sharing her story with us.

Extract Knowledge
Listen elsewhere
Published 2023-04-08

A dark side to LLMs. [Research Saturday]

17 min
View

Sahar Abdelnabi from CISPA Helmholtz Center for Information Security sits down with Dave to discuss their work on "A Comprehensive Analysis of Novel Prompt Injection Threats to Application-Integrated Large Language Models." There is currently a large advance in the capabilities of Large Language Models or LLMs, as well as being integrated into many systems, including integrated development environments (IDEs) and search engines.

The research states, "The functionalities of current LLMs can be modulated via natural language prompts, while their exact internal functionality remains implicit and unassessable." This could lead them to be susceptible to targeted adversarial prompting, as well as making them adaptable to even unseen tasks. Researchers demonstrated these said attacks to see if the LLMs needed new techniques for more defense.

The research can be found here:

More description

Sahar Abdelnabi from CISPA Helmholtz Center for Information Security sits down with Dave to discuss their work on "A Comprehensive Analysis of Novel Prompt Injection Threats to Application-Integrated Large Language Models." There is currently a large advance in the capabilities of Large Language Models or LLMs, as well as being integrated into many systems, including integrated development environments (IDEs) and search engines.

The research states, "The functionalities of current LLMs can be modulated via natural language prompts, while their exact internal functionality remains implicit and unassessable." This could lead them to be susceptible to targeted adversarial prompting, as well as making them adaptable to even unseen tasks. Researchers demonstrated these said attacks to see if the LLMs needed new techniques for more defense.

The research can be found here:

Extract Knowledge
Listen elsewhere

Preventing abuse of the Cobalt Strike pentesting tool. US investigates a leak of sensitive documents related to the war in Ukraine. Hacktivist activity continues. Google's advice for boards. Electronic lockpicks for electronic locks. Nexx security devices may have security flaws. Tesla employees reportedly shared images and videos from Teslas in the wild. Matt O'Neill from US Secret Service discussing investment crypto scams. Our guest is James Campbell of Cado Security on the challenges of a cloud transition. And CISA releases seven ICS advisories.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/67


Selected reading.

Stopping cybercriminals from abusing security tools (Microsoft On the Issues) 

Microsoft leads effort to disrupt illicit use of Cobalt Strike, a dangerous hacking tool in the wrong hands (CyberScoop)

Ukraine War Plans Leak Prompts Pentagon Investigation (New York Times)

DDoS attacks rise as pro-Russia groups attack Finland, Israel (TechRepublic)

Perspectives on Security for the Board (Google Cloud)

Thieves Use CAN Injection Hack to Steal Cars (SecurityWeek)

How thieves steal cars using vehicle CAN bus (Register) 

Own a Nexx “smart” alarm or garage door opener? Get rid of it, or regret it (Graham Cluley).

Hack and enter! The “secure” garage doors that anyone can open from anywhere – what you need to know (Naked Security)

Special Report: Tesla workers shared sensitive images recorded by customer cars (Reuters)

CISA Releases Seven Industrial Control Systems Advisories (Cybersecurity and Infrastructure Security Agency CISA)

More description

Preventing abuse of the Cobalt Strike pentesting tool. US investigates a leak of sensitive documents related to the war in Ukraine. Hacktivist activity continues. Google's advice for boards. Electronic lockpicks for electronic locks. Nexx security devices may have security flaws. Tesla employees reportedly shared images and videos from Teslas in the wild. Matt O'Neill from US Secret Service discussing investment crypto scams. Our guest is James Campbell of Cado Security on the challenges of a cloud transition. And CISA releases seven ICS advisories.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/67


Selected reading.

Stopping cybercriminals from abusing security tools (Microsoft On the Issues) 

Microsoft leads effort to disrupt illicit use of Cobalt Strike, a dangerous hacking tool in the wrong hands (CyberScoop)

Ukraine War Plans Leak Prompts Pentagon Investigation (New York Times)

DDoS attacks rise as pro-Russia groups attack Finland, Israel (TechRepublic)

Perspectives on Security for the Board (Google Cloud)

Thieves Use CAN Injection Hack to Steal Cars (SecurityWeek)

How thieves steal cars using vehicle CAN bus (Register) 

Own a Nexx “smart” alarm or garage door opener? Get rid of it, or regret it (Graham Cluley).

Hack and enter! The “secure” garage doors that anyone can open from anywhere – what you need to know (Naked Security)

Special Report: Tesla workers shared sensitive images recorded by customer cars (Reuters)

CISA Releases Seven Industrial Control Systems Advisories (Cybersecurity and Infrastructure Security Agency CISA)

Extract Knowledge
Listen elsewhere

New phishing techniques. Arrests in the Genesis Market case. APT43’s Archipelago. Russia's turn in the Security Council chair immediately becomes an occasion for disinformation. Our guest is Nick Tausek from Swimlane to discuss supply chain attack trends. Tim Starks from the Washington Post has the latest on the DOJ’s attempts to disrupt cyber crime. And, make robo-love, not robo-war: nuisance-level hacktivism in the interest of Ukraine.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/66


Selected reading.

New Phishing Campaign Exploits YouTube Attribution Links, Cloudflare Captcha (Vade Security)

Criminal Marketplace Disrupted in International Cyber Operation (U.S. Department of Justice)

Takedown of notorious hacker marketplace selling your identity to criminals | Europol (Europol)

Notorious criminal marketplace selling victim identities taken down in international operation (National Crime Agency)

Check your hack (Politie)

Carr Announces Investigation into Suspected Users of Genesis Dark Web Marketplace Following FBI Takedown of Illicit Site (Office of Attorney General of Georgia Chris Carr)

U.S., European Police Shut Down Hacker Marketplace, Make 119 Arrests (Wall Street Journal)

120 Arrested as Cybercrime Website Genesis Market Seized by FBI (SecurityWeek)

 International cops put the squeeze on Genesis Market users (Register) 

FBI obtained detailed database exposing 60,000 users of the cybercrime bazaar Genesis Market (CyberScoop)

Genesis Black Market Dismantled, But Experts Warn of Potential Vacuum (Nextgov.com)

How we’re protecting users from government-backed attacks from North Korea (Google) 

Google TAG Warns of North Korean-linked ARCHIPELAGO Cyberattacks (The Hacker News)

‘Outrageous’: Russia Accused of Spreading Disinformation at U.N. Event (New York Times)

Des hackers ont acheté 23.000 euros de sex-toys avec de l’argent russe (20 minutes)

Thanks to Ukrainian hackers, war freak orders £20,000 worth drones for Russian soldiers, gets sex toys instead (First Post)

Ukrainian hackers exchange Russian fighter’s drone order for dildos (New York Post)

‘It’s bullshit’: Inside the weird, get-rich-quick world of dropshipping (WIRED)

More description

New phishing techniques. Arrests in the Genesis Market case. APT43’s Archipelago. Russia's turn in the Security Council chair immediately becomes an occasion for disinformation. Our guest is Nick Tausek from Swimlane to discuss supply chain attack trends. Tim Starks from the Washington Post has the latest on the DOJ’s attempts to disrupt cyber crime. And, make robo-love, not robo-war: nuisance-level hacktivism in the interest of Ukraine.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/66


Selected reading.

New Phishing Campaign Exploits YouTube Attribution Links, Cloudflare Captcha (Vade Security)

Criminal Marketplace Disrupted in International Cyber Operation (U.S. Department of Justice)

Takedown of notorious hacker marketplace selling your identity to criminals | Europol (Europol)

Notorious criminal marketplace selling victim identities taken down in international operation (National Crime Agency)

Check your hack (Politie)

Carr Announces Investigation into Suspected Users of Genesis Dark Web Marketplace Following FBI Takedown of Illicit Site (Office of Attorney General of Georgia Chris Carr)

U.S., European Police Shut Down Hacker Marketplace, Make 119 Arrests (Wall Street Journal)

120 Arrested as Cybercrime Website Genesis Market Seized by FBI (SecurityWeek)

 International cops put the squeeze on Genesis Market users (Register) 

FBI obtained detailed database exposing 60,000 users of the cybercrime bazaar Genesis Market (CyberScoop)

Genesis Black Market Dismantled, But Experts Warn of Potential Vacuum (Nextgov.com)

How we’re protecting users from government-backed attacks from North Korea (Google) 

Google TAG Warns of North Korean-linked ARCHIPELAGO Cyberattacks (The Hacker News)

‘Outrageous’: Russia Accused of Spreading Disinformation at U.N. Event (New York Times)

Des hackers ont acheté 23.000 euros de sex-toys avec de l’argent russe (20 minutes)

Thanks to Ukrainian hackers, war freak orders £20,000 worth drones for Russian soldiers, gets sex toys instead (First Post)

Ukrainian hackers exchange Russian fighter’s drone order for dildos (New York Post)

‘It’s bullshit’: Inside the weird, get-rich-quick world of dropshipping (WIRED)

Extract Knowledge
Listen elsewhere

Genesis Market gets taken down. Proxyjackers exploit Log4j vulnerabilities. Fast-encrypting Rorschach ransomware uses DLL sideloading. Killnet attempts DDoS attacks against the German ministry. Carole Theriault ponders AI assisted cheating. Johannes Ullrich tracks malware injected in a popular tax filing website. Soft power and Russia’s hybrid war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/65


Selected reading.

'Operation Cookie Monster': International police action seizes dark web market (Reuters) 

Stolen credential warehouse Genesis Market seized by FBI (Register)

FBI Seizes Bot Shop ‘Genesis Market’ Amid Arrests Targeting Operators, Suppliers (KrebsOnSecurity)

Genesis Market, one of world’s largest platforms for cyber fraud, seized by police (Record)

'Operation Cookie Monster': FBI seizes popular cybercrime forum used for large-scale identity theft (CNN)

Cybercrime marketplace Genesis Market shut by FBI, international law enforcement (CNBC)

FBI seizes stolen credentials market Genesis in Operation Cookie Monster (BleepingComputer)

Notorious Genesis Market cybercrime forum seized in international law enforcement operation (CyberScoop)

Proxyjacking has Entered the Chat (Sysdig)

Rorschach – A New Sophisticated and Fast Ransomware (Check Point Research)

Russian hackers attack German ministry’s website (TVP World)

Zimbra Flaw Exploited by Russia Against NATO Countries Added to CISA 'Must Patch' List (SecurityWeek)

Zimbra vulnerability exploited by Russian hackers targeting Nato countries - CISA (Tech Monitor) 

CISA Adds One Known Exploited Vulnerability to Catalog (Cybersecurity and Infrastructure Security Agency CISA)

NVD - CVE-2022-27926 (National Vulnerability Database)

The Interview - Russian cyber weapons 'could do a lot of damage' in the US: Former counterterrorism czar (France 24)

Biden cybersecurity chief 'surprised' Russia has not hit US targets amid Ukraine war (Washington Examiner)

Ukrainian Cyber War Confirms the Lesson: Cyber Power Requires Soft Power (Council on Foreign Relations)

More description

Genesis Market gets taken down. Proxyjackers exploit Log4j vulnerabilities. Fast-encrypting Rorschach ransomware uses DLL sideloading. Killnet attempts DDoS attacks against the German ministry. Carole Theriault ponders AI assisted cheating. Johannes Ullrich tracks malware injected in a popular tax filing website. Soft power and Russia’s hybrid war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/65


Selected reading.

'Operation Cookie Monster': International police action seizes dark web market (Reuters) 

Stolen credential warehouse Genesis Market seized by FBI (Register)

FBI Seizes Bot Shop ‘Genesis Market’ Amid Arrests Targeting Operators, Suppliers (KrebsOnSecurity)

Genesis Market, one of world’s largest platforms for cyber fraud, seized by police (Record)

'Operation Cookie Monster': FBI seizes popular cybercrime forum used for large-scale identity theft (CNN)

Cybercrime marketplace Genesis Market shut by FBI, international law enforcement (CNBC)

FBI seizes stolen credentials market Genesis in Operation Cookie Monster (BleepingComputer)

Notorious Genesis Market cybercrime forum seized in international law enforcement operation (CyberScoop)

Proxyjacking has Entered the Chat (Sysdig)

Rorschach – A New Sophisticated and Fast Ransomware (Check Point Research)

Russian hackers attack German ministry’s website (TVP World)

Zimbra Flaw Exploited by Russia Against NATO Countries Added to CISA 'Must Patch' List (SecurityWeek)

Zimbra vulnerability exploited by Russian hackers targeting Nato countries - CISA (Tech Monitor) 

CISA Adds One Known Exploited Vulnerability to Catalog (Cybersecurity and Infrastructure Security Agency CISA)

NVD - CVE-2022-27926 (National Vulnerability Database)

The Interview - Russian cyber weapons 'could do a lot of damage' in the US: Former counterterrorism czar (France 24)

Biden cybersecurity chief 'surprised' Russia has not hit US targets amid Ukraine war (Washington Examiner)

Ukrainian Cyber War Confirms the Lesson: Cyber Power Requires Soft Power (Council on Foreign Relations)

Extract Knowledge
Listen elsewhere

Did "appeasement" embolden Russia's cyber operators? Western Digital discloses a cyberattack. Rilide is a new strain of malware in active use. The Mantis cyberespionage group uses new, robust tools and tactics. The challenges of threat hunting. Joe Carrigan has thoughts on public school systems making cyber security part of the curriculum. Our guest May Mitchell of Open Systems addresses closing the talent gap. And when it comes to criminal enterprise, size matters.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/64


Selected reading.

Russia's shadow war: Vulkan files leak show how Putin's regime weaponises cyberspace (The Conversation)

Russia's Invasion of Ukraine Heralds New Era of Warfare (VOA)

West’s Cyber Appeasement Gave Putin Green Light: James Stavridis (Bloomberg Law)

Western Digital Provides Information on Network Security Incident (Business Wire) 

Western Digital confirms breach, shuts down systems (Computing)

Western Digital discloses network breach, My Cloud service down (BleepingComputer)

WD says law enforcement probing breach of internal systems (Register)

Western Digital investigating MyCloud data breach affecting Mac desktop drives (Macworld)

Users fume after My Cloud network breach locks them out of their data (Ars Technica)

Typhon Reborn V2: Updated stealer features enhanced anti-analysis and evasion capabilities (Cisco Talos Blog)

Mantis: New Tooling Used in Attacks Against Palestinian Targets (Symantec) 

Inside the Mind of a Threat Hunter: Team Cymru's Latest Report Sheds Light on Challenges Faced by Cybersecurity Analysts (Accesswire)

Wages Dominate Cybercrime Groups' Operating Expenses (PR Newswire)

Inside the Halls of a Cybercrime Business (Trend Micro)

Size Matters: Unraveling the Structure of Modern Cybercrime Organizations (Trend Micro)

More description

Did "appeasement" embolden Russia's cyber operators? Western Digital discloses a cyberattack. Rilide is a new strain of malware in active use. The Mantis cyberespionage group uses new, robust tools and tactics. The challenges of threat hunting. Joe Carrigan has thoughts on public school systems making cyber security part of the curriculum. Our guest May Mitchell of Open Systems addresses closing the talent gap. And when it comes to criminal enterprise, size matters.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/64


Selected reading.

Russia's shadow war: Vulkan files leak show how Putin's regime weaponises cyberspace (The Conversation)

Russia's Invasion of Ukraine Heralds New Era of Warfare (VOA)

West’s Cyber Appeasement Gave Putin Green Light: James Stavridis (Bloomberg Law)

Western Digital Provides Information on Network Security Incident (Business Wire) 

Western Digital confirms breach, shuts down systems (Computing)

Western Digital discloses network breach, My Cloud service down (BleepingComputer)

WD says law enforcement probing breach of internal systems (Register)

Western Digital investigating MyCloud data breach affecting Mac desktop drives (Macworld)

Users fume after My Cloud network breach locks them out of their data (Ars Technica)

Typhon Reborn V2: Updated stealer features enhanced anti-analysis and evasion capabilities (Cisco Talos Blog)

Mantis: New Tooling Used in Attacks Against Palestinian Targets (Symantec) 

Inside the Mind of a Threat Hunter: Team Cymru's Latest Report Sheds Light on Challenges Faced by Cybersecurity Analysts (Accesswire)

Wages Dominate Cybercrime Groups' Operating Expenses (PR Newswire)

Inside the Halls of a Cybercrime Business (Trend Micro)

Size Matters: Unraveling the Structure of Modern Cybercrime Organizations (Trend Micro)

Extract Knowledge
Listen elsewhere
Show details
Episodes
3784
Transcripts
67
2% coverage
Missing transcripts
3717
With chapters
0