Search this show’s transcripts

CyberWire Daily

en us
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
More details
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
Sources and links

Episodes

Page 29 · 50 per page

"Cylance" the ransomware (with no relation to Cylance, the security company). An update on the 3CX incident. The FSB's arrest of a Wall Street Journal reporter. Simone Petrella from N2K Networks unpacks 2023 cybersecurity training trends. Deepen Desai from Zscaler has the latest on cloud security. And Hacktivists claim to have tricked wives of Russian combat pilots into revealing personal information.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/63


Selected reading.

"Cylance" ransomware (no relation to Cylance). (CyberWire Pro)

New Cylance Ransomware Targets Linux and Windows, Warn Researchers (HackRead)

New Cylance Ransomware strain emerges, experts speculate about its notorious members (IT PRO) 

More evidence links 3CX supply-chain attack to North Korean hacking group (Record)

3CX supply chain attack: the unanswered questions (Computing)

3CX Desktop App Compromised (CVE-2023-29059) (Fortinet Blog) 

Evan Gershkovich Loved Russia, the Country That Turned on Him (Wall Street Journal)

The Ukrainian hoax that revealed the Russian pilots who bombed Mariupol theatre (The Telegraph)

Ukrainian Hacktivists Trick Russian Military Wives for Personal Info (HackRead)

More description

"Cylance" the ransomware (with no relation to Cylance, the security company). An update on the 3CX incident. The FSB's arrest of a Wall Street Journal reporter. Simone Petrella from N2K Networks unpacks 2023 cybersecurity training trends. Deepen Desai from Zscaler has the latest on cloud security. And Hacktivists claim to have tricked wives of Russian combat pilots into revealing personal information.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/63


Selected reading.

"Cylance" ransomware (no relation to Cylance). (CyberWire Pro)

New Cylance Ransomware Targets Linux and Windows, Warn Researchers (HackRead)

New Cylance Ransomware strain emerges, experts speculate about its notorious members (IT PRO) 

More evidence links 3CX supply-chain attack to North Korean hacking group (Record)

3CX supply chain attack: the unanswered questions (Computing)

3CX Desktop App Compromised (CVE-2023-29059) (Fortinet Blog) 

Evan Gershkovich Loved Russia, the Country That Turned on Him (Wall Street Journal)

The Ukrainian hoax that revealed the Russian pilots who bombed Mariupol theatre (The Telegraph)

Ukrainian Hacktivists Trick Russian Military Wives for Personal Info (HackRead)

Extract Knowledge
Listen elsewhere

Alon Jackson, chief executive and Co-founder of Astrix Security, sits down to share his story to rising success. Before being on the vendor side of things, Jackson served in various strategic roles in the Cyber Security Division of the Israeli Military Intel Unit 8200 for more than 8 years, including leading the Cloud Security division and serving as the Head of the Cyber Security R&D Department. His experience in the military inspired him to learn more about the industry and jump to the private sector. Fast forward years later, he co-founded his company to help address security gaps seen in the industry. He mentions how being a start up CEO can be difficult sometimes, and how it may feel as though you're an octopus with all the multitasking that comes with the job. Alon says that one of his main goals as a contributor in this industry is making sure people remember him and his company for years to come, saying he wants to help by " building a company that people kind of know about, remember, and is important in the world." We thank Alon for sharing his story with us.

More description

Alon Jackson, chief executive and Co-founder of Astrix Security, sits down to share his story to rising success. Before being on the vendor side of things, Jackson served in various strategic roles in the Cyber Security Division of the Israeli Military Intel Unit 8200 for more than 8 years, including leading the Cloud Security division and serving as the Head of the Cyber Security R&D Department. His experience in the military inspired him to learn more about the industry and jump to the private sector. Fast forward years later, he co-founded his company to help address security gaps seen in the industry. He mentions how being a start up CEO can be difficult sometimes, and how it may feel as though you're an octopus with all the multitasking that comes with the job. Alon says that one of his main goals as a contributor in this industry is making sure people remember him and his company for years to come, saying he wants to help by " building a company that people kind of know about, remember, and is important in the world." We thank Alon for sharing his story with us.

Extract Knowledge
Listen elsewhere

Dick O'Brien from Symantec’s Threat Hunter team discusses their research on "Blackfly - Espionage Group Targets Materials Technology." Researchers say the Blackfly espionage group (aka APT41), has been mounting attacks against Asian materials and composite organizations in attempts to steal intellectual property.

This group has been known as one of the longest known Chinese advanced persistent threat (APT) groups since at least 2010. The research shares that "early attacks were distinguished by the use of the PlugX/Fast (Backdoor.Korplug), Winnti/Pasteboy (Backdoor.Winnti), and Shadowpad (Backdoor.Shadowpad) malware families."

The research can be found here: 

More description

Dick O'Brien from Symantec’s Threat Hunter team discusses their research on "Blackfly - Espionage Group Targets Materials Technology." Researchers say the Blackfly espionage group (aka APT41), has been mounting attacks against Asian materials and composite organizations in attempts to steal intellectual property.

This group has been known as one of the longest known Chinese advanced persistent threat (APT) groups since at least 2010. The research shares that "early attacks were distinguished by the use of the PlugX/Fast (Backdoor.Korplug), Winnti/Pasteboy (Backdoor.Winnti), and Shadowpad (Backdoor.Shadowpad) malware families."

The research can be found here: 

Extract Knowledge
Listen elsewhere

The Vulkan papers offer a glimpse into Mr. Putin’s cyber war room. The 3CXDesktopApp vulnerability and supply chain risk. A cross site scripting flaw in Azure Service Fabric Explorer can lead to remote code execution. Rob Boyce from Accenture Security on threats toEV charging stations. Our guest is Steve Benton from Anomali Threat Research, sharing a ‘less is more’ approach to cybersecurity. And AlienFox targets misconfigured servers.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/62


Selected reading.

A Look Inside Putin's Secret Plans for Cyber-Warfare (Spiegel)

Secret trove offers rare look into Russian cyberwar ambitions (Washington Post) 

7 takeaways from the Vulkan Files investigation (Washington Post)

‘Vulkan files’ leak reveals Putin’s global and domestic cyberwarfare tactics (the Guardian)

Contracts Identify Cyber Operations Projects from Russian Company NTC Vulkan (Mandiant)

3CX DesktopApp Security Alert - Mandiant Appointed to Investigate (3CX)

Information on Attacks Involving 3CX Desktop App (Trend Micro)

3CX Confirms Supply Chain Attack as Researchers Uncover Mac Component  (SecurityWeek)

There’s a new supply chain attack targeting customers of a phone system with 12 million users (TechCrunch)

Super FabriXss: From XSS to an RCE in Azure Service Fabric Explorer by Abusing an Event Tab Cluster Toggle (CVE-2023-23383) (Orca Security)

Dissecting AlienFox | The Cloud Spammer’s Swiss Army Knife (SentinelOne)

More description

The Vulkan papers offer a glimpse into Mr. Putin’s cyber war room. The 3CXDesktopApp vulnerability and supply chain risk. A cross site scripting flaw in Azure Service Fabric Explorer can lead to remote code execution. Rob Boyce from Accenture Security on threats toEV charging stations. Our guest is Steve Benton from Anomali Threat Research, sharing a ‘less is more’ approach to cybersecurity. And AlienFox targets misconfigured servers.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/62


Selected reading.

A Look Inside Putin's Secret Plans for Cyber-Warfare (Spiegel)

Secret trove offers rare look into Russian cyberwar ambitions (Washington Post) 

7 takeaways from the Vulkan Files investigation (Washington Post)

‘Vulkan files’ leak reveals Putin’s global and domestic cyberwarfare tactics (the Guardian)

Contracts Identify Cyber Operations Projects from Russian Company NTC Vulkan (Mandiant)

3CX DesktopApp Security Alert - Mandiant Appointed to Investigate (3CX)

Information on Attacks Involving 3CX Desktop App (Trend Micro)

3CX Confirms Supply Chain Attack as Researchers Uncover Mac Component  (SecurityWeek)

There’s a new supply chain attack targeting customers of a phone system with 12 million users (TechCrunch)

Super FabriXss: From XSS to an RCE in Azure Service Fabric Explorer by Abusing an Event Tab Cluster Toggle (CVE-2023-23383) (Orca Security)

Dissecting AlienFox | The Cloud Spammer’s Swiss Army Knife (SentinelOne)

Extract Knowledge
Listen elsewhere

The 3CXDesktopApp is under exploitation in a supply chain campaign. An open letter asks for a pause in advanced AI development. All your grammar and usage are belong us. Combosquatting might fool even the wary. Defender had flagged Zoom and other safe sites as dangerous. Recognizing the importance of OSINT. Matt O'Neill from US Secret Service discussing his agency’s cybersecurity mission. Our guest is Ping Li from Signifydwith a look at online fraud. And the FSB arrests a US journalist.

For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/61


Selected reading.

3CX DesktopApp Security Alert (3CX)

Supply Chain Attack Against 3CXDesktopApp (CISA)

Pause Giant AI Experiments: An Open Letter (Future of Life Institute)

In Sudden Alarm, Tech Doyens Call for a Pause on ChatGPT (WIRED

AI chatbots making it harder to spot phishing emails, say experts (the Guardian)

The Most Common Combosquatting Keyword Is “Support” (Akamai)

False positives in Microsoft Defender. (CyberWire)

Exploitation is a Dish Best Served Cold: Winter Vivern Uses Known Zimbra Vulnerability to Target Webmail Portals of NATO-Aligned Governments in Europe (Proofpoint) 

ESET Research Podcast: A year of fighting rockets, soldiers, and wipers in Ukraine (WeLiveSecurity) 

Russia Ramping Up Cyberattacks Against Ukraine (VOA) 

A new age of spying gives Kyiv the upper hand (The Telegraph) 

Russia arrests Wall Street Journal reporter on spying charge (AP NEWS)

Russia detains a Wall Street Journal reporter, accusing him of espionage. (New York Times)

More description

The 3CXDesktopApp is under exploitation in a supply chain campaign. An open letter asks for a pause in advanced AI development. All your grammar and usage are belong us. Combosquatting might fool even the wary. Defender had flagged Zoom and other safe sites as dangerous. Recognizing the importance of OSINT. Matt O'Neill from US Secret Service discussing his agency’s cybersecurity mission. Our guest is Ping Li from Signifydwith a look at online fraud. And the FSB arrests a US journalist.

For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/61


Selected reading.

3CX DesktopApp Security Alert (3CX)

Supply Chain Attack Against 3CXDesktopApp (CISA)

Pause Giant AI Experiments: An Open Letter (Future of Life Institute)

In Sudden Alarm, Tech Doyens Call for a Pause on ChatGPT (WIRED

AI chatbots making it harder to spot phishing emails, say experts (the Guardian)

The Most Common Combosquatting Keyword Is “Support” (Akamai)

False positives in Microsoft Defender. (CyberWire)

Exploitation is a Dish Best Served Cold: Winter Vivern Uses Known Zimbra Vulnerability to Target Webmail Portals of NATO-Aligned Governments in Europe (Proofpoint) 

ESET Research Podcast: A year of fighting rockets, soldiers, and wipers in Ukraine (WeLiveSecurity) 

Russia Ramping Up Cyberattacks Against Ukraine (VOA) 

A new age of spying gives Kyiv the upper hand (The Telegraph) 

Russia arrests Wall Street Journal reporter on spying charge (AP NEWS)

Russia detains a Wall Street Journal reporter, accusing him of espionage. (New York Times)

Extract Knowledge
Listen elsewhere

Traffers and the threat to credentials. A newly discovered WiFi protocol flaw. Cross-chain bridge attacks. A shift in Russian cyber operations. Ann Johnson from Afternoon Cyber Tea chats with EY principal Adam Malone. Our guest is Toni Buhrke from Mimecast with a look at the State of Email Security. And is piracy patriotic?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/60


Selected reading.

Traffers and the growing threat against credentials (Outpost24 blog) 

WiFi protocol flaw allows attackers to hijack network traffic (BleepingComputer) 

Cross-chain bridge attacks. (CyberWire)

 2023 Annual State of Email Security Report (Cofense)

From Ukraine to the whole of Europe:cyber conflict reaches a turning point (Thales Group) 

Russia Ramps Up Cyberattacks On Ukraine Allies: Analysts (Barron's) 

Pro-Russian hackers shift focus from Ukraine to EU countries (Radio Sweden) 

Russian hackers attack Slovak governmental websites after country supplies Mig-29s to Ukraine (Ukrainska Pravda)

Ukraine's Defense Ministry says Russia is encouraging online piracy (The Jerusalem Post)

More description

Traffers and the threat to credentials. A newly discovered WiFi protocol flaw. Cross-chain bridge attacks. A shift in Russian cyber operations. Ann Johnson from Afternoon Cyber Tea chats with EY principal Adam Malone. Our guest is Toni Buhrke from Mimecast with a look at the State of Email Security. And is piracy patriotic?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/60


Selected reading.

Traffers and the growing threat against credentials (Outpost24 blog) 

WiFi protocol flaw allows attackers to hijack network traffic (BleepingComputer) 

Cross-chain bridge attacks. (CyberWire)

 2023 Annual State of Email Security Report (Cofense)

From Ukraine to the whole of Europe:cyber conflict reaches a turning point (Thales Group) 

Russia Ramps Up Cyberattacks On Ukraine Allies: Analysts (Barron's) 

Pro-Russian hackers shift focus from Ukraine to EU countries (Radio Sweden) 

Russian hackers attack Slovak governmental websites after country supplies Mig-29s to Ukraine (Ukrainska Pravda)

Ukraine's Defense Ministry says Russia is encouraging online piracy (The Jerusalem Post)

Extract Knowledge
Listen elsewhere

Twitter gets a subpoena for a source-code leaker’s information. The insider risk to data. Russian hacktivist auxiliaries target the French National Assembly. Recent trends in cyberattacks sustained by Ukraine. Ben Yelin unpacks the White House executive order on spyware. Mr. Security Answer Person John Pescatore ponders the permanence of ransomware. And Cyberespionage and cybercrime in the interest of Pyongyang’s weapons programs.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/59


Selected reading.

GitHub Suspends Repository Containing Leaked Twitter Source Code (SecurityWeek)

Twitter takes down source code leaked online, hunts for downloaders (BleepingComputer)

Annual Data Exposure Report 2023 (Code 42)

Russian Hackers Target French National Assembly Website (Privacy Affairs)

Pro-Russian Hacktivists: A Reaction to a Western Response to a Russian Aggression (Radware Blog)

Ukraine at D+397: Cyberespionage and battlespace preparation. (CyberWire)

APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations (Mandiant)

More description

Twitter gets a subpoena for a source-code leaker’s information. The insider risk to data. Russian hacktivist auxiliaries target the French National Assembly. Recent trends in cyberattacks sustained by Ukraine. Ben Yelin unpacks the White House executive order on spyware. Mr. Security Answer Person John Pescatore ponders the permanence of ransomware. And Cyberespionage and cybercrime in the interest of Pyongyang’s weapons programs.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/59


Selected reading.

GitHub Suspends Repository Containing Leaked Twitter Source Code (SecurityWeek)

Twitter takes down source code leaked online, hunts for downloaders (BleepingComputer)

Annual Data Exposure Report 2023 (Code 42)

Russian Hackers Target French National Assembly Website (Privacy Affairs)

Pro-Russian Hacktivists: A Reaction to a Western Response to a Russian Aggression (Radware Blog)

Ukraine at D+397: Cyberespionage and battlespace preparation. (CyberWire)

APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations (Mandiant)

Extract Knowledge
Listen elsewhere

IcedID is evolving away from its banking malware roots. An Emotet phishing campaign spoofs IRS W9s. The FBI warns of BEC scams. A Fake booter service as a law enforcement honeypot. Phishing in China's nuclear energy sector. Reports of an OpenAI and a ChatGPT data leak. Does Iran receive Russian support in cyberattacks against Albania? My conversation with Linda Gray Martin and Britta Glade from RSAC with a preview of this year's conference. Our own Rick Howard takes a field trip to the National Cryptologic Museum. And De-anonymizing Telegram.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/58


Selected reading.

Fork in the Ice: The New Era of IcedID (Proofpoint)

Emotet malware distributed as fake W-9 tax forms from the IRS (BleepingComputer)

Internet Crime Complaint Center (IC3) | Business Email Compromise Tactics Used to Facilitate the Acquisition of Commodities and Defrauding Vendors (IC3)

Phishing Campaign Targets Chinese Nuclear Energy Industry (Intezer) 

'Bitter' espionage hackers target Chinese nuclear energy orgs (BleepingComputer)

UK Sets Up Fake DDoS-for-Hire Sites to Trap Hackers (PCMag Middle East)

UK National Crime Agency reveals it ran fake DDoS-for-hire sites to collect users’ data (Record)

OpenAI: ChatGPT payment data leak caused by open-source bug (BleepingComputer)

OpenAI says a bug leaked sensitive ChatGPT user data (Engadget)

March 20 ChatGPT outage: Here’s what happened (OpenAI)

How Albania Became a Target for Cyberattacks (Foreign Policy) 

Russia’s Rostec allegedly can de-anonymize Telegram users (BleepingComputer)

More description

IcedID is evolving away from its banking malware roots. An Emotet phishing campaign spoofs IRS W9s. The FBI warns of BEC scams. A Fake booter service as a law enforcement honeypot. Phishing in China's nuclear energy sector. Reports of an OpenAI and a ChatGPT data leak. Does Iran receive Russian support in cyberattacks against Albania? My conversation with Linda Gray Martin and Britta Glade from RSAC with a preview of this year's conference. Our own Rick Howard takes a field trip to the National Cryptologic Museum. And De-anonymizing Telegram.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/58


Selected reading.

Fork in the Ice: The New Era of IcedID (Proofpoint)

Emotet malware distributed as fake W-9 tax forms from the IRS (BleepingComputer)

Internet Crime Complaint Center (IC3) | Business Email Compromise Tactics Used to Facilitate the Acquisition of Commodities and Defrauding Vendors (IC3)

Phishing Campaign Targets Chinese Nuclear Energy Industry (Intezer) 

'Bitter' espionage hackers target Chinese nuclear energy orgs (BleepingComputer)

UK Sets Up Fake DDoS-for-Hire Sites to Trap Hackers (PCMag Middle East)

UK National Crime Agency reveals it ran fake DDoS-for-hire sites to collect users’ data (Record)

OpenAI: ChatGPT payment data leak caused by open-source bug (BleepingComputer)

OpenAI says a bug leaked sensitive ChatGPT user data (Engadget)

March 20 ChatGPT outage: Here’s what happened (OpenAI)

How Albania Became a Target for Cyberattacks (Foreign Policy) 

Russia’s Rostec allegedly can de-anonymize Telegram users (BleepingComputer)

Extract Knowledge
Listen elsewhere

Rick Howard, N2K’s CSO and The CyberWire’s Chief Analyst and Senior Fellow, sits down with Director of the National Cryptologic Museum, Dr. Vince Houghton. The National Cryptologic Museum is the NSA's affiliated museum sharing the nation's best cryptologic secrets with the public. In this special episode, Rick interviews Dr. Houghton from within the walls of the National Cryptologic Museum, discussing the new and improved museum along with the new exhibits they uncovered during the pandemic.

More description

Rick Howard, N2K’s CSO and The CyberWire’s Chief Analyst and Senior Fellow, sits down with Director of the National Cryptologic Museum, Dr. Vince Houghton. The National Cryptologic Museum is the NSA's affiliated museum sharing the nation's best cryptologic secrets with the public. In this special episode, Rick interviews Dr. Houghton from within the walls of the National Cryptologic Museum, discussing the new and improved museum along with the new exhibits they uncovered during the pandemic.

Extract Knowledge
Listen elsewhere

Earlier this month, the White House released the National Cybersecurity Strategy, the first issued since 2018. The strategy refocuses roles, responsibilities, and resource allocations in the digital ecosystem, with a five pillar approach. Those pillars are: defending critical infrastructure, disrupting threat actors, shaping market forces to drive security and resilience, investing in a resilient future, and forging international partnerships.

We wanted to delve into the strategy and its intended effects further, so Dave Bittner spoke with representatives from industry and inside government. Dave first speaks with Adam Isles, Principal and Head of Cybersecurity Practice at The Chertoff Group, sharing industry's take on the strategy. Following that conversation, Dave had a discussion with Steve Kelly, Special Assistant to the President and Senior Director for Cybersecurity and Emerging Technology at the National Security Council, for a look at the strategy from inside the White House.

Links to resources:

More description

Earlier this month, the White House released the National Cybersecurity Strategy, the first issued since 2018. The strategy refocuses roles, responsibilities, and resource allocations in the digital ecosystem, with a five pillar approach. Those pillars are: defending critical infrastructure, disrupting threat actors, shaping market forces to drive security and resilience, investing in a resilient future, and forging international partnerships.

We wanted to delve into the strategy and its intended effects further, so Dave Bittner spoke with representatives from industry and inside government. Dave first speaks with Adam Isles, Principal and Head of Cybersecurity Practice at The Chertoff Group, sharing industry's take on the strategy. Following that conversation, Dave had a discussion with Steve Kelly, Special Assistant to the President and Senior Director for Cybersecurity and Emerging Technology at the National Security Council, for a look at the strategy from inside the White House.

Links to resources:

Extract Knowledge
Listen elsewhere

Tanya Janca, CEO and Founder of We Hack Purple, sits down to talk about her exciting path into the field of cybersecurity. Trying several different paths in high school, she soon found she was good at computer science. When it came to picking a college, she knew that was the field she wanted to get into. After college, she was able to use her skills to work at a couple of different organizations, eventually getting into the Canadian government. While there, she held the position of CISO for the Canadian election in 2015 when Justin Trudeau was elected, but she knew she wanted to try something new. She switched from programming to security and after working at Microsoft as a presenter, she eventually found that she wanted to start her own company, saying "at first it was just me presenting, but now we have community members present to each other and it's just been really beautiful to see that grow." She hopes that with her and her community's help, nobody is left feeling unsafe when it comes to being online.

More description

Tanya Janca, CEO and Founder of We Hack Purple, sits down to talk about her exciting path into the field of cybersecurity. Trying several different paths in high school, she soon found she was good at computer science. When it came to picking a college, she knew that was the field she wanted to get into. After college, she was able to use her skills to work at a couple of different organizations, eventually getting into the Canadian government. While there, she held the position of CISO for the Canadian election in 2015 when Justin Trudeau was elected, but she knew she wanted to try something new. She switched from programming to security and after working at Microsoft as a presenter, she eventually found that she wanted to start her own company, saying "at first it was just me presenting, but now we have community members present to each other and it's just been really beautiful to see that grow." She hopes that with her and her community's help, nobody is left feeling unsafe when it comes to being online.

Extract Knowledge
Listen elsewhere

On this episode, Jérôme Segura, senior threat researcher at Malwarebytes, shares his team's work, "WordPress sites backdoored with ad fraud plugin." WordPress is an immensely popular content management system (CMS) powering over 43% of all websites. Many webmasters will monetize their sites by running ads and need to draw particular attention to search engine optimization (SEO) techniques to maximize their revenues.

The Malwarebytes team discovered a few dozen WordPress blogs using the same plugin that mimics human activity by automatically scrolling a page and following links within it, all the while a number of ads were being loaded and refreshed. The blogs would only exhibit this invalid traffic behavior when launched from a specific URL created by this plugin, otherwise they appeared completely legitimate.

The research can be found here:

More description

On this episode, Jérôme Segura, senior threat researcher at Malwarebytes, shares his team's work, "WordPress sites backdoored with ad fraud plugin." WordPress is an immensely popular content management system (CMS) powering over 43% of all websites. Many webmasters will monetize their sites by running ads and need to draw particular attention to search engine optimization (SEO) techniques to maximize their revenues.

The Malwarebytes team discovered a few dozen WordPress blogs using the same plugin that mimics human activity by automatically scrolling a page and following links within it, all the while a number of ads were being loaded and refreshed. The blogs would only exhibit this invalid traffic behavior when launched from a specific URL created by this plugin, otherwise they appeared completely legitimate.

The research can be found here:

Extract Knowledge
Listen elsewhere

A CISA tool helps secure Microsoft clouds.JCDC and pre-ransomware notification. CISA releases six ICS advisories. Reply phishing. Cl0p goes everywhere exploiting GoAnywhere. Russian electronic warfare units show the ability to locate Starlink terminals. Betsy Carmelite from Booz Allen Hamilton on the DoD's zero trust journey. Analysis of the National Cybersecurity strategy from our special guests, Adam Isles, Principal at the Chertoff Group and Steve Kelly, Special Assistant to the President and Senior Director for Cybersecurity and Emerging Technology with the National Security Council.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/57


Selected reading.

JCDC Cultivates Pre-Ransomware Notification Capability (Cybersecurity and Infrastructure Security Agency CISA)

US cyber officials make urgent push to warn businesses about vulnerabilities to hackers (CNN)

Untitled Goose Tool Aids Hunt and Incident Response in Azure, Azure Active Directory, and Microsoft 365 Environments | CISA (Cybersecurity and Infrastructure Security Agency CISA)

New CISA tool detects hacking activity in Microsoft cloud services (BleepingComputer)

CISA Releases Six Industrial Control Systems Advisories (Cybersecurity and Infrastructure Security Agency CISA)

The Microsoft Reply Attack (Avanan)

More victims emerge from Fortra GoAnywhere zero-day attacks (Security | 

More Clop GoAnywhere attack victims emerge (SC Media) 

Mass-Ransomware Attack on GoAnywhere File Transfer Tool Exposes Companies Worldwide (Medium) 

City of Toronto confirms data theft, Clop claims responsibility (BleepingComputer) 

Canadian movie chain Cineplex among the victims of GoAnywhere MFT hack (Financial Post) 

Personal data of Rio Tinto's Aussie staff may have been hacked - memo (Reuters) 

Another GoAnywhere Attack Affects Japanese Giant Hitachi Energy (Heimdal Security Blog) 

Using Starlink Paints a Target on Ukrainian Troops (Defense One)

As CISA chief notes lack of Russian cyberattacks against US, experts focus on enhancing nuclear reactor security (Utility Dive)

Using Deception to Learn About Russian Threat Actors (Security Boulevard)

More description

A CISA tool helps secure Microsoft clouds.JCDC and pre-ransomware notification. CISA releases six ICS advisories. Reply phishing. Cl0p goes everywhere exploiting GoAnywhere. Russian electronic warfare units show the ability to locate Starlink terminals. Betsy Carmelite from Booz Allen Hamilton on the DoD's zero trust journey. Analysis of the National Cybersecurity strategy from our special guests, Adam Isles, Principal at the Chertoff Group and Steve Kelly, Special Assistant to the President and Senior Director for Cybersecurity and Emerging Technology with the National Security Council.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/57


Selected reading.

JCDC Cultivates Pre-Ransomware Notification Capability (Cybersecurity and Infrastructure Security Agency CISA)

US cyber officials make urgent push to warn businesses about vulnerabilities to hackers (CNN)

Untitled Goose Tool Aids Hunt and Incident Response in Azure, Azure Active Directory, and Microsoft 365 Environments | CISA (Cybersecurity and Infrastructure Security Agency CISA)

New CISA tool detects hacking activity in Microsoft cloud services (BleepingComputer)

CISA Releases Six Industrial Control Systems Advisories (Cybersecurity and Infrastructure Security Agency CISA)

The Microsoft Reply Attack (Avanan)

More victims emerge from Fortra GoAnywhere zero-day attacks (Security | 

More Clop GoAnywhere attack victims emerge (SC Media) 

Mass-Ransomware Attack on GoAnywhere File Transfer Tool Exposes Companies Worldwide (Medium) 

City of Toronto confirms data theft, Clop claims responsibility (BleepingComputer) 

Canadian movie chain Cineplex among the victims of GoAnywhere MFT hack (Financial Post) 

Personal data of Rio Tinto's Aussie staff may have been hacked - memo (Reuters) 

Another GoAnywhere Attack Affects Japanese Giant Hitachi Energy (Heimdal Security Blog) 

Using Starlink Paints a Target on Ukrainian Troops (Defense One)

As CISA chief notes lack of Russian cyberattacks against US, experts focus on enhancing nuclear reactor security (Utility Dive)

Using Deception to Learn About Russian Threat Actors (Security Boulevard)

Extract Knowledge
Listen elsewhere

DPRK threat actor Kimsuky uses a Chrome extension to exfiltrate emails, while ScarCruft prospects South Korean organizations. Hacktivists' claims of attacks on OT networks may be overstated. Ghostwriter remains active in social engineering attempts to target Ukrainian refugees. Joe Carrigan has cyber crime by the numbers. Our guest is Christian Sorensen from SightGain with analysis of the cyber effects of Russia’s war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/56


Selected reading.

North Korean hackers using Chrome extensions to steal Gmail emails (BleepingComputer)

Joint Cyber Security Advisory (Korean) (BundesamtfuerVerfassungsschutz)

North Korean APT group ‘Kimsuky’ targeting experts with new spearphishing campaign (Record)

ScarCruft's Evolving Arsenal: Researchers Reveal New Malware Distribution Techniques (The Hacker News)

The Unintentional Leak: A glimpse into the attack vectors of APT37 (Zscaler)

CHM Malware Disguised as Security Email from a Korean Financial Company: Redeyes (Scarcruft) (ASEC BLOG) 

A Propaganda Group is Using Fake Emails to Target Ukrainian Refugees (Bloomberg) 

We (Did!) Start the Fire: Hacktivists Increasingly Claim Targeting of OT Systems | Mandiant (Mandiant)

Fact or fiction, hacktivists' claims of industrial sabotage in Russia or Ukraine get attention online (CyberScoop)

The 5×5—Conflict in Ukraine's information environment (Atlantic Council)

How the Russia-Ukraine conflict has impacted cyber-warfare (teiss)

CommonMagic APT gang attacking organisations in Ukraine (Tech Monitor)

More description

DPRK threat actor Kimsuky uses a Chrome extension to exfiltrate emails, while ScarCruft prospects South Korean organizations. Hacktivists' claims of attacks on OT networks may be overstated. Ghostwriter remains active in social engineering attempts to target Ukrainian refugees. Joe Carrigan has cyber crime by the numbers. Our guest is Christian Sorensen from SightGain with analysis of the cyber effects of Russia’s war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/56


Selected reading.

North Korean hackers using Chrome extensions to steal Gmail emails (BleepingComputer)

Joint Cyber Security Advisory (Korean) (BundesamtfuerVerfassungsschutz)

North Korean APT group ‘Kimsuky’ targeting experts with new spearphishing campaign (Record)

ScarCruft's Evolving Arsenal: Researchers Reveal New Malware Distribution Techniques (The Hacker News)

The Unintentional Leak: A glimpse into the attack vectors of APT37 (Zscaler)

CHM Malware Disguised as Security Email from a Korean Financial Company: Redeyes (Scarcruft) (ASEC BLOG) 

A Propaganda Group is Using Fake Emails to Target Ukrainian Refugees (Bloomberg) 

We (Did!) Start the Fire: Hacktivists Increasingly Claim Targeting of OT Systems | Mandiant (Mandiant)

Fact or fiction, hacktivists' claims of industrial sabotage in Russia or Ukraine get attention online (CyberScoop)

The 5×5—Conflict in Ukraine's information environment (Atlantic Council)

How the Russia-Ukraine conflict has impacted cyber-warfare (teiss)

CommonMagic APT gang attacking organisations in Ukraine (Tech Monitor)

Extract Knowledge
Listen elsewhere

Malware could detect sandbox emulations. A VEC supply chain attack. A new APT is active in Russian-occupied sections of Ukraine. An alleged Russian patriot claims responsibility for the D.C. Health Link attack. CISA and NSA offer guidance on identity and access management (IAM). Tim Starks from the Washington Post has analysis on the BreachForums takedown. Our guest is Ryan Heidorn from C3 Integrated Solutions with a look at the CMMC compliance timeline. And Baphomet backs out.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/55


Selected reading.

ZenGo uncovers security vulnerabilities in popular Web3 Transaction Simulation solutions: The red pill attack (ZenGo)

Stopping a $36 Million Vendor Fraud Attack (Abnormal Intelligence) 

Bad magic: new APT found in the area of Russo-Ukrainian conflict (Securelist)

Unknown actors target orgs in Russia-occupied Ukraine (Register)

New 'Bad Magic' Cyber Threat Disrupt Ukraine's Key Sectors Amid War (The Hacker News)

Partisan suspects turn on the cyber-magic in Ukraine (Cybernews)

Hacker tied to D.C. Health Link breach says attack 'born out of Russian patriotism' (CyberScoop) 

CISA and NSA Release Enduring Security Framework Guidance on Identity and Access Management | CISA (Cybersecurity and Infrastructure Security Agency CISA) 

ESF Partners, NSA, and CISA Release Identity and Access Management Recommended Best Practi (National Security Agency/Central Security Service)

Identity and Access Management: Recommended Best Practices for Administrators (NSA and CISA) 

CISA Releases Updated Cybersecurity Performance Goals (Cybersecurity and Infrastructure Security Agency CISA) 

CISA Releases Eight Industrial Control Systems Advisories | CISA (Cybersecurity and Infrastructure Security Agency CISA)

End of BreachForums could take a bite out of cybercrime (Washington Post)

BreachForums says it is closing after suspected law enforcement access to backend (Record)

More description

Malware could detect sandbox emulations. A VEC supply chain attack. A new APT is active in Russian-occupied sections of Ukraine. An alleged Russian patriot claims responsibility for the D.C. Health Link attack. CISA and NSA offer guidance on identity and access management (IAM). Tim Starks from the Washington Post has analysis on the BreachForums takedown. Our guest is Ryan Heidorn from C3 Integrated Solutions with a look at the CMMC compliance timeline. And Baphomet backs out.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/55


Selected reading.

ZenGo uncovers security vulnerabilities in popular Web3 Transaction Simulation solutions: The red pill attack (ZenGo)

Stopping a $36 Million Vendor Fraud Attack (Abnormal Intelligence) 

Bad magic: new APT found in the area of Russo-Ukrainian conflict (Securelist)

Unknown actors target orgs in Russia-occupied Ukraine (Register)

New 'Bad Magic' Cyber Threat Disrupt Ukraine's Key Sectors Amid War (The Hacker News)

Partisan suspects turn on the cyber-magic in Ukraine (Cybernews)

Hacker tied to D.C. Health Link breach says attack 'born out of Russian patriotism' (CyberScoop) 

CISA and NSA Release Enduring Security Framework Guidance on Identity and Access Management | CISA (Cybersecurity and Infrastructure Security Agency CISA) 

ESF Partners, NSA, and CISA Release Identity and Access Management Recommended Best Practi (National Security Agency/Central Security Service)

Identity and Access Management: Recommended Best Practices for Administrators (NSA and CISA) 

CISA Releases Updated Cybersecurity Performance Goals (Cybersecurity and Infrastructure Security Agency CISA) 

CISA Releases Eight Industrial Control Systems Advisories | CISA (Cybersecurity and Infrastructure Security Agency CISA)

End of BreachForums could take a bite out of cybercrime (Washington Post)

BreachForums says it is closing after suspected law enforcement access to backend (Record)

Extract Knowledge
Listen elsewhere

Threat group with novel malware operates in Southeast Asia. Data theft extortion on the rise. Key findings of Cisco's Cybersecurity Readiness Index. iPhones are no longer welcome in the Kremlin. Russian cyber auxiliaries and privateers devote increased attention to the healthcare sector. Chris Eng from Veracode shares findings of their Annual Report on the State of Application Security. Johannes Ullrich from SANS Institute discusses scams after the failure of Silicon Valley Bank. And BreachForums seems to be under new management. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/54


Selected reading.

NAPLISTENER: more bad dreams from developers of SIESTAGRAPH (Elastic Blog) 

Unit 42 Ransomware and Extortion Report Highlights: Multi-Extortion Tactics Continue to Rise (Palo Alto Network)

Ransomware and extortion trends. (CyberWire)

Cisco Cybersecurity Readiness Index (Cisco)

A look at resilience: companies' ability to fight off cyberattacks. (CyberWire)

Putin to staffers: throw out your iPhones over security (Register)

Black Basta, Killnet, LockBit groups targeting healthcare in force (SC Media)

After BreachForums arrest, new site administrator says the platform will live on (Record) 

More description

Threat group with novel malware operates in Southeast Asia. Data theft extortion on the rise. Key findings of Cisco's Cybersecurity Readiness Index. iPhones are no longer welcome in the Kremlin. Russian cyber auxiliaries and privateers devote increased attention to the healthcare sector. Chris Eng from Veracode shares findings of their Annual Report on the State of Application Security. Johannes Ullrich from SANS Institute discusses scams after the failure of Silicon Valley Bank. And BreachForums seems to be under new management. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/54


Selected reading.

NAPLISTENER: more bad dreams from developers of SIESTAGRAPH (Elastic Blog) 

Unit 42 Ransomware and Extortion Report Highlights: Multi-Extortion Tactics Continue to Rise (Palo Alto Network)

Ransomware and extortion trends. (CyberWire)

Cisco Cybersecurity Readiness Index (Cisco)

A look at resilience: companies' ability to fight off cyberattacks. (CyberWire)

Putin to staffers: throw out your iPhones over security (Register)

Black Basta, Killnet, LockBit groups targeting healthcare in force (SC Media)

After BreachForums arrest, new site administrator says the platform will live on (Record) 

Extract Knowledge
Listen elsewhere

Cl0p ransomware hits Hitachi Energy. The US Department of Justice investigates ByteDance in alleged surveillance of journalists. A Hacktivist auxiliary hits Indian healthcare records. Pirated software is used to carry malware. The Effects of cyberattack on Latitude persist. Adam Meyers from CrowdStrike shares findings from the 2023 CrowdStrike Global Threat Report. Rick Howard has the latest preview of CSO Perspectives. And Pompompurin is arrested for an alleged role in BreachForums.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/53


Selected reading.

Hitachi Energy confirms data breach after Clop GoAnywhere attacks (BleepingComputer)

Hitachi Energy Group hit by cyber-attack, says network operations not compromised (cnbctv18.com) 

Justice Department Probes TikTok’s Tracking of U.S. Journalists (Wall Street Journal) 

The FBI And DOJ Are Investigating ByteDance’s Use Of TikTok To Spy On Journalists (Forbes)

KillNet and affiliate hacktivist groups targeting healthcare with DDoS attacks (Azure Network Security Team)

Pro-Russia hackers are increasingly targeting hospitals, researchers warns (Record) 

Russian hacktivist group targets India’s health ministry (CSO Online)

Russian Hacktivist group Phoenix targets India’s Health Ministry Website (Threat Intelligence | CloudSEK) 

Ukraine warns that hacked software can be infected with Russian viruses (Kyiv Independent)

Russian hackers spread infected software through torrents (SSSCIP)

Australia's Latitude takes systems offline, Federal Police investigate cyberattack (Reuters)

FBI targets notorious cybercrime market with teen’s arrest (Washington Post) 

Dark Web ‘BreachForums’ Operator Charged With Computer Crime (Bloomberg) 

Feds arrest alleged BreachForums owner linked to FBI hacks (The Verge) 

NY Man Charged as 'Pompompurin,' the Boss of BreachForums (KrebsOnSecurity) 

Breach Forums Admin 'Pompompurin' Arrested in New York (Cyber Kendra) 

Pompompurin Unmasked: Infamous BreachForums Mastermind Arrested in New York (The Hacker News)

More description

Cl0p ransomware hits Hitachi Energy. The US Department of Justice investigates ByteDance in alleged surveillance of journalists. A Hacktivist auxiliary hits Indian healthcare records. Pirated software is used to carry malware. The Effects of cyberattack on Latitude persist. Adam Meyers from CrowdStrike shares findings from the 2023 CrowdStrike Global Threat Report. Rick Howard has the latest preview of CSO Perspectives. And Pompompurin is arrested for an alleged role in BreachForums.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/53


Selected reading.

Hitachi Energy confirms data breach after Clop GoAnywhere attacks (BleepingComputer)

Hitachi Energy Group hit by cyber-attack, says network operations not compromised (cnbctv18.com) 

Justice Department Probes TikTok’s Tracking of U.S. Journalists (Wall Street Journal) 

The FBI And DOJ Are Investigating ByteDance’s Use Of TikTok To Spy On Journalists (Forbes)

KillNet and affiliate hacktivist groups targeting healthcare with DDoS attacks (Azure Network Security Team)

Pro-Russia hackers are increasingly targeting hospitals, researchers warns (Record) 

Russian hacktivist group targets India’s health ministry (CSO Online)

Russian Hacktivist group Phoenix targets India’s Health Ministry Website (Threat Intelligence | CloudSEK) 

Ukraine warns that hacked software can be infected with Russian viruses (Kyiv Independent)

Russian hackers spread infected software through torrents (SSSCIP)

Australia's Latitude takes systems offline, Federal Police investigate cyberattack (Reuters)

FBI targets notorious cybercrime market with teen’s arrest (Washington Post) 

Dark Web ‘BreachForums’ Operator Charged With Computer Crime (Bloomberg) 

Feds arrest alleged BreachForums owner linked to FBI hacks (The Verge) 

NY Man Charged as 'Pompompurin,' the Boss of BreachForums (KrebsOnSecurity) 

Breach Forums Admin 'Pompompurin' Arrested in New York (Cyber Kendra) 

Pompompurin Unmasked: Infamous BreachForums Mastermind Arrested in New York (The Hacker News)

Extract Knowledge
Listen elsewhere

Kathleen Smith, CMO from ClearedJobs.Net, sits down to share her story as she remembers having big shoes to fill in her childhood. She strived for greatness at an early age, as her parents told her she would be going to college and would follow strong guidelines to become successful. Kathleen can remember being into the hard sciences when she was in school, which sparked an interest in becoming a biochemist and law student. Eventually she found her passion as a translator, saying that "doing the translator role, I wanted to get into international marketing and I was going on to get my degree on that." She found her way to ClearedJobs.Net and fell in love with it. She had sought to find a workplace that wouldn't burn her out, where she can also be a part of the team. Kathleen found what she was passionate about and made it a reality for herself, and now she just wants young women starting in the field to know the importance of finding something they are passionate about. We thank Kathleen for sharing her story.

More description

Kathleen Smith, CMO from ClearedJobs.Net, sits down to share her story as she remembers having big shoes to fill in her childhood. She strived for greatness at an early age, as her parents told her she would be going to college and would follow strong guidelines to become successful. Kathleen can remember being into the hard sciences when she was in school, which sparked an interest in becoming a biochemist and law student. Eventually she found her passion as a translator, saying that "doing the translator role, I wanted to get into international marketing and I was going on to get my degree on that." She found her way to ClearedJobs.Net and fell in love with it. She had sought to find a workplace that wouldn't burn her out, where she can also be a part of the team. Kathleen found what she was passionate about and made it a reality for herself, and now she just wants young women starting in the field to know the importance of finding something they are passionate about. We thank Kathleen for sharing her story.

Extract Knowledge
Listen elsewhere

CISA, FBI, and the Multi-State Information Sharing and Analysis Center are releasing this joint advisory to share known LockBit 3.0 ransomware IOCs and TTPs identified through FBI investigations as recently as March 2023.

AA23-075A Alert, Technical Details, and Mitigations

Stopransomware.gov is a whole-of-government approach that gives one central location for ransomware resources and alerts.

Resource to mitigate a ransomware attack: CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide.

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

More description

CISA, FBI, and the Multi-State Information Sharing and Analysis Center are releasing this joint advisory to share known LockBit 3.0 ransomware IOCs and TTPs identified through FBI investigations as recently as March 2023.

AA23-075A Alert, Technical Details, and Mitigations

Stopransomware.gov is a whole-of-government approach that gives one central location for ransomware resources and alerts.

Resource to mitigate a ransomware attack: CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide.

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge
Listen elsewhere

Bar Block, Threat Intelligence Researcher at Deep Instinct, joins Dave to discuss their work on "ChatGPT and Malware - Making Your Malicious Wishes Come True." Deep Instinct goes into depth on just how dangerous ChatGPT can be in the wrong hands as well as how artificial intelligence is better at creating malware than providing ways to detect it.

Researchers go on to explain how the AI app can be used in the wrong hands saying "Examples of malicious content created by the AI tool, such as phishing messages, information stealers, and encryption software, have all been shared online."

The research can be found here:

More description

Bar Block, Threat Intelligence Researcher at Deep Instinct, joins Dave to discuss their work on "ChatGPT and Malware - Making Your Malicious Wishes Come True." Deep Instinct goes into depth on just how dangerous ChatGPT can be in the wrong hands as well as how artificial intelligence is better at creating malware than providing ways to detect it.

Researchers go on to explain how the AI app can be used in the wrong hands saying "Examples of malicious content created by the AI tool, such as phishing messages, information stealers, and encryption software, have all been shared online."

The research can be found here:

Extract Knowledge
Listen elsewhere

BianLian gang’s pivot. HinataBot is a Go-based threat. The US Social Security Administration is impersonated in attempted vishing attacks. BlackSnake in the RaaS criminal market. More Silicon Valley Bank-themed phishing. Caleb Barlow from Cylete on security implications you need to consider now about Chat GPT. Our guest is Isaac Roth from LeakSignal with advice on securing the microservices application layer. And Russian operators exploit an Outlook vulnerability.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/52


Selected reading.

BianLian Ransomware Gang Continues to Evolve ([redacted])

Uncovering HinataBot: A Deep Dive into a Go-Based Threat (Akamai)

Social InSecurity: Armorblox Stops Attack Impersonating Social Security Administration (Armorblox)

Netskope Threat Coverage: BlackSnake Ransomware (Netskope) 

Fresh Phish: Silicon Valley Bank Phishing Scams in High Gear (INKY)

Outlook zero day linked to critical infrastructure attacks (Cybersecurity Dive)

CVE-2023-23397: Exploitations in the Wild – What You Need to Know (Deep Instinct) 

Everything We Know About CVE-2023-23397 (Huntress)

Microsoft Mitigates Outlook Elevation of Privilege Vulnerability (Microsoft Security Response Center)

More description

BianLian gang’s pivot. HinataBot is a Go-based threat. The US Social Security Administration is impersonated in attempted vishing attacks. BlackSnake in the RaaS criminal market. More Silicon Valley Bank-themed phishing. Caleb Barlow from Cylete on security implications you need to consider now about Chat GPT. Our guest is Isaac Roth from LeakSignal with advice on securing the microservices application layer. And Russian operators exploit an Outlook vulnerability.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/52


Selected reading.

BianLian Ransomware Gang Continues to Evolve ([redacted])

Uncovering HinataBot: A Deep Dive into a Go-Based Threat (Akamai)

Social InSecurity: Armorblox Stops Attack Impersonating Social Security Administration (Armorblox)

Netskope Threat Coverage: BlackSnake Ransomware (Netskope) 

Fresh Phish: Silicon Valley Bank Phishing Scams in High Gear (INKY)

Outlook zero day linked to critical infrastructure attacks (Cybersecurity Dive)

CVE-2023-23397: Exploitations in the Wild – What You Need to Know (Deep Instinct) 

Everything We Know About CVE-2023-23397 (Huntress)

Microsoft Mitigates Outlook Elevation of Privilege Vulnerability (Microsoft Security Response Center)

Extract Knowledge
Listen elsewhere

Telerik exploited, for carding (probably) and other purposes. Cloud storage re-up attacks. Cybercriminals use new measures to avoid detection of phishing campaigns. "Winter Vivern" seems aligned with Russian objectives. Microsoft warns of a possible surge in Russian cyber operations. Boss Sandworm. Johannes Ullrich from SANS talking about malware spread through Google Ads. Our guest is David Anteliz from Skybox Security with thoughts on federal government cybersecurity directives. And don't fear the Reaper.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/51


Selected reading.

Threat Actors Exploited Progress Telerik Vulnerability in U.S. Government IIS Server (Cybersecurity and Infrastructure Security Agency CISA)

Threat Actors Exploit Progress Telerik Vulnerability in U.S. Government IIS Server | CISA (Cybersecurity and Infrastructure Security Agency CISA)

CISA: Federal civilian agency hacked by nation-state and criminal hacking groups (CyberScoop) 

US govt web server attacked by 'multiple' criminal gangs (Register)

The Cloud Storage Re-Up Attack (Avanan)

Threat Spotlight: 3 novel phishing tactics (Barracuda)

Winter Vivern | Uncovering a Wave of Global Espionage (SentinelOne)

Is Russia regrouping for renewed cyberwar? (Microsoft On the Issues) 

A year of Russian hybrid warfare in Ukraine (Microsoft Threat Intelligence)

Russian hackers preparing new cyber assault against Ukraine - Microsoft report (Reuters)

Microsoft Warns Russia May Plan More Ransomware Attacks Beyond Ukraine (Bloomberg)

This Is the New Leader of Russia's Infamous Sandworm Hacking Unit (WIRED) 

What's known and not about US drone-Russian jet encounter (AP NEWS)

Russia tries to retrieve downed US drone in Black Sea (The Telegraph)

Downed U.S. drone points to cyber vulnerabilities (Washington Post)

More description

Telerik exploited, for carding (probably) and other purposes. Cloud storage re-up attacks. Cybercriminals use new measures to avoid detection of phishing campaigns. "Winter Vivern" seems aligned with Russian objectives. Microsoft warns of a possible surge in Russian cyber operations. Boss Sandworm. Johannes Ullrich from SANS talking about malware spread through Google Ads. Our guest is David Anteliz from Skybox Security with thoughts on federal government cybersecurity directives. And don't fear the Reaper.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/51


Selected reading.

Threat Actors Exploited Progress Telerik Vulnerability in U.S. Government IIS Server (Cybersecurity and Infrastructure Security Agency CISA)

Threat Actors Exploit Progress Telerik Vulnerability in U.S. Government IIS Server | CISA (Cybersecurity and Infrastructure Security Agency CISA)

CISA: Federal civilian agency hacked by nation-state and criminal hacking groups (CyberScoop) 

US govt web server attacked by 'multiple' criminal gangs (Register)

The Cloud Storage Re-Up Attack (Avanan)

Threat Spotlight: 3 novel phishing tactics (Barracuda)

Winter Vivern | Uncovering a Wave of Global Espionage (SentinelOne)

Is Russia regrouping for renewed cyberwar? (Microsoft On the Issues) 

A year of Russian hybrid warfare in Ukraine (Microsoft Threat Intelligence)

Russian hackers preparing new cyber assault against Ukraine - Microsoft report (Reuters)

Microsoft Warns Russia May Plan More Ransomware Attacks Beyond Ukraine (Bloomberg)

This Is the New Leader of Russia's Infamous Sandworm Hacking Unit (WIRED) 

What's known and not about US drone-Russian jet encounter (AP NEWS)

Russia tries to retrieve downed US drone in Black Sea (The Telegraph)

Downed U.S. drone points to cyber vulnerabilities (Washington Post)

Extract Knowledge
Listen elsewhere

CISA, FBI, and the Multi-State Information Sharing and Analysis Center are releasing this joint Cybersecurity Advisory to provide IT infrastructure defenders with TTPs, IOCs, and methods to detect and protect against recent exploitation against Microsoft Internet Information Services web servers.

AA23-074A Alert, Technical Details, and Mitigations

AA23-074A STIX XML

MAR-10413062-1.v1 Telerik Vulnerability in U.S. Government IIS Server

Telerik: Exploiting .NET JavaScriptSerializer Deserialization (CVE-2019-18935)

ACSC Advisory 2020-004

Bishop Fox CVE-2019-18935: Remote Code Execution via Insecure Deserialization in Telerik UI

Volexity Threat Research: XE Group

GitHub: Proof-of-Concept Exploit for CVE-2019-18935

Microsoft: Configure Logging in IIS

GitHub: CVE-2019-18935

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

More description

CISA, FBI, and the Multi-State Information Sharing and Analysis Center are releasing this joint Cybersecurity Advisory to provide IT infrastructure defenders with TTPs, IOCs, and methods to detect and protect against recent exploitation against Microsoft Internet Information Services web servers.

AA23-074A Alert, Technical Details, and Mitigations

AA23-074A STIX XML

MAR-10413062-1.v1 Telerik Vulnerability in U.S. Government IIS Server

Telerik: Exploiting .NET JavaScriptSerializer Deserialization (CVE-2019-18935)

ACSC Advisory 2020-004

Bishop Fox CVE-2019-18935: Remote Code Execution via Insecure Deserialization in Telerik UI

Volexity Threat Research: XE Group

GitHub: Proof-of-Concept Exploit for CVE-2019-18935

Microsoft: Configure Logging in IIS

GitHub: CVE-2019-18935

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge
Listen elsewhere

Patch Tuesday notes. Silicon Valley Bank's collapse and its effects on the cybersecurity sector. SVR's APT29 used a Polish state visit to the US as phishbait. Regularizing hacktivist auxiliaries. Our guest is Crane Hassold from Abnormal Security with a look at threats to email. Grayson Milbourne from OpenText Cybersecurity addresses chaos within the supply chain. And LockBit claims to have compromised an aerospace supply chain.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/50


Selected reading.

March 2023 Patch Tuesday: Updates and Analysis (CrowdStrike)

Microsoft Releases March 2023 Security Updates (Cybersecurity and Infrastructure Security Agency CISA)

Adobe Releases Security Updates for Multiple Products (Cybersecurity and Infrastructure Security Agency CISA)

Mozilla Releases Security Updates for Firefox 111 and Firefox ESR 102.9 (Cybersecurity and Infrastructure Security Agency CISA)

SAP Security Patch Day for March 2023 (Onapsis)

March Patch Tuesday review. (CyberWire)

What the collapse of Silicon Valley Bank means for cyber and the tech startup ecosystem. (CyberWire)

NOBELIUM Uses Poland's Ambassador’s Visit to the U.S. to Target EU Governments Assisting Ukraine (BlackBerry)

Ukraine Tracks Increased Russian Focus on Cyberespionage (Bank Info Security)

Ukraine scrambles to draft cyber law, legalizing its volunteer hacker army (Newsweek) 

Ransomware Group Claims Theft of Valuable SpaceX Data From Contractor (SecurityWeek)

More description

Patch Tuesday notes. Silicon Valley Bank's collapse and its effects on the cybersecurity sector. SVR's APT29 used a Polish state visit to the US as phishbait. Regularizing hacktivist auxiliaries. Our guest is Crane Hassold from Abnormal Security with a look at threats to email. Grayson Milbourne from OpenText Cybersecurity addresses chaos within the supply chain. And LockBit claims to have compromised an aerospace supply chain.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/50


Selected reading.

March 2023 Patch Tuesday: Updates and Analysis (CrowdStrike)

Microsoft Releases March 2023 Security Updates (Cybersecurity and Infrastructure Security Agency CISA)

Adobe Releases Security Updates for Multiple Products (Cybersecurity and Infrastructure Security Agency CISA)

Mozilla Releases Security Updates for Firefox 111 and Firefox ESR 102.9 (Cybersecurity and Infrastructure Security Agency CISA)

SAP Security Patch Day for March 2023 (Onapsis)

March Patch Tuesday review. (CyberWire)

What the collapse of Silicon Valley Bank means for cyber and the tech startup ecosystem. (CyberWire)

NOBELIUM Uses Poland's Ambassador’s Visit to the U.S. to Target EU Governments Assisting Ukraine (BlackBerry)

Ukraine Tracks Increased Russian Focus on Cyberespionage (Bank Info Security)

Ukraine scrambles to draft cyber law, legalizing its volunteer hacker army (Newsweek) 

Ransomware Group Claims Theft of Valuable SpaceX Data From Contractor (SecurityWeek)

Extract Knowledge
Listen elsewhere

Expect phishing, BEC scams, and other social engineering to use Silicon Valley Bank lures. An "attack superhighway." Unauthorized software in the workplace. A new cyberespionage group emerges. Squad up (but not IRL). Ben Yelin unpacks the FBI director’s recent admission of purchasing location data. Ann Johnson from Afternoon Cyber Tea speaks with Jason Barnett from HCA Healthcare about cyber resilience. And, not that you’d consider a life of crime, but what are the gangs paying cyber criminals, nowadays?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/49


Selected reading.

SVB's collapse and the potential for fraud. (CyberWire)

State-of-the-Internet: malicious DNS traffic. (CyberWire)

Unauthorized software in the workplace. (CyberWire)

Talos uncovers espionage campaigns targeting CIS countries, including embassies and EU health care agency (Cisco Talos Blog)

STALKER 2 game developer hacked by Russian hacktivists, data stolen (BleepingComputer)

GSC Game World suffers Stalker 2 leak after latest cyber attack (GamesIndustry.biz)

Threat Groups Offer $240k Salary to Tech Jobseekers (Security Intelligence)

More description

Expect phishing, BEC scams, and other social engineering to use Silicon Valley Bank lures. An "attack superhighway." Unauthorized software in the workplace. A new cyberespionage group emerges. Squad up (but not IRL). Ben Yelin unpacks the FBI director’s recent admission of purchasing location data. Ann Johnson from Afternoon Cyber Tea speaks with Jason Barnett from HCA Healthcare about cyber resilience. And, not that you’d consider a life of crime, but what are the gangs paying cyber criminals, nowadays?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/49


Selected reading.

SVB's collapse and the potential for fraud. (CyberWire)

State-of-the-Internet: malicious DNS traffic. (CyberWire)

Unauthorized software in the workplace. (CyberWire)

Talos uncovers espionage campaigns targeting CIS countries, including embassies and EU health care agency (Cisco Talos Blog)

STALKER 2 game developer hacked by Russian hacktivists, data stolen (BleepingComputer)

GSC Game World suffers Stalker 2 leak after latest cyber attack (GamesIndustry.biz)

Threat Groups Offer $240k Salary to Tech Jobseekers (Security Intelligence)

Extract Knowledge
Listen elsewhere

Coping with Silicon Valley Bank's collapse. BatLoader's abusing Google Search Ads. More on Emotet’s re-emergence. Reflections on Medusa rising. An international law enforcement action against NetWire. Rob Shapland from Falanx Cyber on ethical hacking and red teaming. Bryan Ware from LookingGlass looks at exploited vulnerabilities in the US financial sector. And in Ukraine, it’s more-or-less quiet on the cyber front (but in Estonia and Georgia, not so much).


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/48


Selected reading.

One of Silicon Valley's top banks fails; assets are seized (AP NEWS)

US, UK try to stem fallout from Silicon Valley Bank collapse (AP NEWS)

In abrupt reversal, regulators to cover Silicon Valley Bank, Signature uninsured deposits (American Banker)

Silicon Valley Bank collapse will not trigger new financial crisis, insists Sunak (The Telegraph)

‘Banking system is safe’: Joe Biden reassures markets in address on Silicon Valley Bank collapse – live updates (the Guardian) 

BatLoader Continues to Abuse Google Search Ads to Deliver Vidar Stealer and Ursnif (eSentire) 

BATLOADER Malware Uses Google Ads to Deliver Vidar Stealer and Ursnif Payloads (The Hacker News) 

Emotet Again! The First Malspam Wave of 2023 (Deep Instinct) 

Emotet attempts to sell access after infiltrating high-value networks (SC Media) 

Medusa ransomware gang picks up steam as it targets companies worldwide (BleepingComputer)

Alleged seller of NetWire RAT arrested in Croatia (Help Net Security)

FBI and international cops catch a NetWire RAT (Register)

How the FBI proved a remote admin tool was actually malware (TechCrunch)

Estonia’s Election Was More Than Just a Win for Kallas (World Politics Review) 

Estonian official says parliamentary elections were targeted by cyberattacks (Record)

More description

Coping with Silicon Valley Bank's collapse. BatLoader's abusing Google Search Ads. More on Emotet’s re-emergence. Reflections on Medusa rising. An international law enforcement action against NetWire. Rob Shapland from Falanx Cyber on ethical hacking and red teaming. Bryan Ware from LookingGlass looks at exploited vulnerabilities in the US financial sector. And in Ukraine, it’s more-or-less quiet on the cyber front (but in Estonia and Georgia, not so much).


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/48


Selected reading.

One of Silicon Valley's top banks fails; assets are seized (AP NEWS)

US, UK try to stem fallout from Silicon Valley Bank collapse (AP NEWS)

In abrupt reversal, regulators to cover Silicon Valley Bank, Signature uninsured deposits (American Banker)

Silicon Valley Bank collapse will not trigger new financial crisis, insists Sunak (The Telegraph)

‘Banking system is safe’: Joe Biden reassures markets in address on Silicon Valley Bank collapse – live updates (the Guardian) 

BatLoader Continues to Abuse Google Search Ads to Deliver Vidar Stealer and Ursnif (eSentire) 

BATLOADER Malware Uses Google Ads to Deliver Vidar Stealer and Ursnif Payloads (The Hacker News) 

Emotet Again! The First Malspam Wave of 2023 (Deep Instinct) 

Emotet attempts to sell access after infiltrating high-value networks (SC Media) 

Medusa ransomware gang picks up steam as it targets companies worldwide (BleepingComputer)

Alleged seller of NetWire RAT arrested in Croatia (Help Net Security)

FBI and international cops catch a NetWire RAT (Register)

How the FBI proved a remote admin tool was actually malware (TechCrunch)

Estonia’s Election Was More Than Just a Win for Kallas (World Politics Review) 

Estonian official says parliamentary elections were targeted by cyberattacks (Record)

Extract Knowledge
Listen elsewhere

Bat El Azerad, CEO and Co-founder of mobile phishing protection company novoShield, shares her personal account of her experience as a female leader in the cybersecurity field as well as some insights into how far the industry has come and where it is headed in terms of the gender gap. Bat El speaks about how she grew into her role of becoming a CEO, by sharing where she started and how she got involved with novoShield. She share's that being a woman in this industry can be tough and so she shares some advice, saying "so you have to be very focused and to find the right niche to bring something to the table because the competition in this industry and the level of innovation, um, is, is great." Bat El hopes that throughout her time in the industry she hopes people remember her for her vision, and the mission she is helping to create and maintain at her company. We thank Bat El for sharing her story.

More description

Bat El Azerad, CEO and Co-founder of mobile phishing protection company novoShield, shares her personal account of her experience as a female leader in the cybersecurity field as well as some insights into how far the industry has come and where it is headed in terms of the gender gap. Bat El speaks about how she grew into her role of becoming a CEO, by sharing where she started and how she got involved with novoShield. She share's that being a woman in this industry can be tough and so she shares some advice, saying "so you have to be very focused and to find the right niche to bring something to the table because the competition in this industry and the level of innovation, um, is, is great." Bat El hopes that throughout her time in the industry she hopes people remember her for her vision, and the mission she is helping to create and maintain at her company. We thank Bat El for sharing her story.

Extract Knowledge
Listen elsewhere

Ron Masas of Imperva discusses their work, the "Google Chrome “SymStealer” Vulnerability. How to Protect Your Files from Being Stolen." By reviewing the ways the browser handles file systems, specifically searching for common vulnerabilities relating to how browsers process symlinks, the Imperva Red Team discovered that when files are dropped onto a file input, it’s handled differently.

Dubbing it as CVE-2022-40764, researchers found a vulnerability that "allowed for the theft of sensitive files, such as crypto wallets and cloud provider credentials." In result, over 2.5 billion users of Google Chrome and Chromium-based browsers were affected.

The research can be found here:

More description

Ron Masas of Imperva discusses their work, the "Google Chrome “SymStealer” Vulnerability. How to Protect Your Files from Being Stolen." By reviewing the ways the browser handles file systems, specifically searching for common vulnerabilities relating to how browsers process symlinks, the Imperva Red Team discovered that when files are dropped onto a file input, it’s handled differently.

Dubbing it as CVE-2022-40764, researchers found a vulnerability that "allowed for the theft of sensitive files, such as crypto wallets and cloud provider credentials." In result, over 2.5 billion users of Google Chrome and Chromium-based browsers were affected.

The research can be found here:

Extract Knowledge
Listen elsewhere

New IceFire version is out. A DUCKTAIL tale. Social engineering by Tehran. DPRK's LIGHTSHOW cyberespionage. The President's Budget and cybersecurity. The US Department of Defense issues its cyber workforce strategy. Remcos surfaces in attacks against Ukrainian government agencies. DDoS at a Ukrainian radio station. Dave Bittner sits down with Beth Robinson of Bishop Fox to share their 2023 Offensive Security Resolutions. Caleb Barlow from Cylete on the security implications of gigapixel images. And CISA releases five ICS advisories.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/47


Selected reading.

IceFire Ransomware Returns | Now Targeting Linux Enterprise Networks (SentinelOne) 

DUCKTAIL: Threat Operation Re-emerges with New LNK, PowerShell, and Other Custom Tactics to Avoid Detection (Deep Instinct) 

Iran-linked hackers used fake Atlantic Council-affiliated persona to target human rights researchers (CyberScoop)

Iranian APT Targets Female Activists With Mahsa Amini Protest Lures (Dark Reading).

Iran threat group going after female activists, analyst warns (Cybernews) 

Stealing the LIGHTSHOW (Part One) — North Korea's UNC2970 (Mandiant) 

Stealing the LIGHTSHOW (Part Two) — LIGHTSHIFT and LIGHTSHOW (Mandiant)

Cybersecurity in the US President's Budget for Fiscal Year 2024. (CyberWire)

Biden’s budget proposal underscores cybersecurity priorities (Washington Post) 

Biden Budget Proposal: $200M for TMF, CISA With 4.9% Budget Boost (Meritalk)

Cybersecurity Poised for Spending Boost in Biden Budget (Gov Info Security)

Deputy Secretary of Defense Signs 2023-2027 DoD Cyber Workforce Strategy (U.S. Department of Defense)

In new cyber workforce strategy, DoD hopes 'bold' retention initiatives keep talent coming back (Breaking Defense)

Remcos Trojan Returns to Most Wanted Malware List After Ukraine Attacks (Infosecurity Magazine)

February 2023’s Most Wanted Malware: Remcos Trojan Linked to Cyberespionage Operations Against Ukrainian Government (Check Point Software)

Radio Halychyna cyber-attacked following appeal by Russian hacker group (International Press Institute)

CISA Releases Five Industrial Control Systems Advisories | CISA (Cybersecurity and Infrastructure Security Agency CISA)

More description

New IceFire version is out. A DUCKTAIL tale. Social engineering by Tehran. DPRK's LIGHTSHOW cyberespionage. The President's Budget and cybersecurity. The US Department of Defense issues its cyber workforce strategy. Remcos surfaces in attacks against Ukrainian government agencies. DDoS at a Ukrainian radio station. Dave Bittner sits down with Beth Robinson of Bishop Fox to share their 2023 Offensive Security Resolutions. Caleb Barlow from Cylete on the security implications of gigapixel images. And CISA releases five ICS advisories.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/47


Selected reading.

IceFire Ransomware Returns | Now Targeting Linux Enterprise Networks (SentinelOne) 

DUCKTAIL: Threat Operation Re-emerges with New LNK, PowerShell, and Other Custom Tactics to Avoid Detection (Deep Instinct) 

Iran-linked hackers used fake Atlantic Council-affiliated persona to target human rights researchers (CyberScoop)

Iranian APT Targets Female Activists With Mahsa Amini Protest Lures (Dark Reading).

Iran threat group going after female activists, analyst warns (Cybernews) 

Stealing the LIGHTSHOW (Part One) — North Korea's UNC2970 (Mandiant) 

Stealing the LIGHTSHOW (Part Two) — LIGHTSHIFT and LIGHTSHOW (Mandiant)

Cybersecurity in the US President's Budget for Fiscal Year 2024. (CyberWire)

Biden’s budget proposal underscores cybersecurity priorities (Washington Post) 

Biden Budget Proposal: $200M for TMF, CISA With 4.9% Budget Boost (Meritalk)

Cybersecurity Poised for Spending Boost in Biden Budget (Gov Info Security)

Deputy Secretary of Defense Signs 2023-2027 DoD Cyber Workforce Strategy (U.S. Department of Defense)

In new cyber workforce strategy, DoD hopes 'bold' retention initiatives keep talent coming back (Breaking Defense)

Remcos Trojan Returns to Most Wanted Malware List After Ukraine Attacks (Infosecurity Magazine)

February 2023’s Most Wanted Malware: Remcos Trojan Linked to Cyberespionage Operations Against Ukrainian Government (Check Point Software)

Radio Halychyna cyber-attacked following appeal by Russian hacker group (International Press Institute)

CISA Releases Five Industrial Control Systems Advisories | CISA (Cybersecurity and Infrastructure Security Agency CISA)

Extract Knowledge
Listen elsewhere

A wormable version of the PlugX USB malware is found. Compromised webcams as a security threat. Emotet botnet out of hibernation. Proof-of-concept: AI used to generate polymorphic keylogger. Turning to alternatives as conventional tactics fail. Dave Bittner speaks with Eve Maler of ForgeRock to discuss how digital identity can help create a more secure connected car experience. Johannes Ullrich from SANS on configuring a proper time server infrastructure. And Phishing messages via legitimate Google notifications.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/46


Selected reading.

A border-hopping PlugX USB worm takes its act on the road (Sophos News)

BitSight identifies thousands of global organizations using insecure webcams and other IoT devices, finding many susceptible to eavesdropping (BitSight) 

Emotet malware attacks return after three-month break (BleepingComputer)

BlackMamba: Using AI to Generate Polymorphic Malware (HYAS) 

Russian Cyberwar in Ukraine Stumbles Just Like Conventional One (Bloomberg)

Australian official demands Russia bring criminal hackers ‘to heel’ (The Record by Recorded Future)

Russia will have to rely on nukes, cyberattacks, and China since its military is being thrashed in Ukraine, US intel director says (Business Insider) 

BEC 3.0 - Legitimate Sites for Illegitimate Purposes  (Avanan)

More description

A wormable version of the PlugX USB malware is found. Compromised webcams as a security threat. Emotet botnet out of hibernation. Proof-of-concept: AI used to generate polymorphic keylogger. Turning to alternatives as conventional tactics fail. Dave Bittner speaks with Eve Maler of ForgeRock to discuss how digital identity can help create a more secure connected car experience. Johannes Ullrich from SANS on configuring a proper time server infrastructure. And Phishing messages via legitimate Google notifications.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/46


Selected reading.

A border-hopping PlugX USB worm takes its act on the road (Sophos News)

BitSight identifies thousands of global organizations using insecure webcams and other IoT devices, finding many susceptible to eavesdropping (BitSight) 

Emotet malware attacks return after three-month break (BleepingComputer)

BlackMamba: Using AI to Generate Polymorphic Malware (HYAS) 

Russian Cyberwar in Ukraine Stumbles Just Like Conventional One (Bloomberg)

Australian official demands Russia bring criminal hackers ‘to heel’ (The Record by Recorded Future)

Russia will have to rely on nukes, cyberattacks, and China since its military is being thrashed in Ukraine, US intel director says (Business Insider) 

BEC 3.0 - Legitimate Sites for Illegitimate Purposes  (Avanan)

Extract Knowledge
Listen elsewhere

CISA adds three known exploited vulnerabilities to its Catalog. A data breach at Acer exposes intellectual property. Sharp Panda deploys SoulSearcher malware in cyberespionage campaigns. US Cyber Command’s head warns against underestimating Russia in cyberspace. Dave Bittner sits down with Simone Petrella of N2K Networks to discuss the recently-released Defense Cyber Workforce Framework. Betsy Carmelite from Booz Allen Hamilton speaks about CISA's year ahead. And are large language models what the lawyers call an attractive nuisance.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/45


Selected reading.

CISA Adds Three Known Exploited Vulnerabilities to Catalog (Cybersecurity and Infrastructure Security Agency CISA)

March 7 CISA KEV Breakdown | Zoho, Teclib, Apache (Nucleus Security)

Acer Confirms Breach After Hacker Offers to Sell Stolen Data (SecurityWeek)

Acer confirms breach after 160GB of data for sale on hacking forum (BleepingComputer)

“Sharp Panda”: Check Point Research puts a spotlight on Chinese origined espionage attacks against southeast asian government entities (Check Point Software)

Pandas with a Soul: Chinese Espionage Attacks Against Southeast Asian Government Entities (Check Point Research)

What can security teams learn from a year of cyber warfare? (Computer Weekly)

Russian cyberattacks could intensify during spring offensives in Ukraine, US Cyber Command general says (Stars and Stripes)

US Bracing for Bolder, More Brazen Russian Cyberattacks (VOA)

Russia remains a ‘very capable’ cyber adversary, Nakasone says (C4ISRNet)

Employees Are Feeding Sensitive Business Data to ChatGPT (Dark Reading)

More description

CISA adds three known exploited vulnerabilities to its Catalog. A data breach at Acer exposes intellectual property. Sharp Panda deploys SoulSearcher malware in cyberespionage campaigns. US Cyber Command’s head warns against underestimating Russia in cyberspace. Dave Bittner sits down with Simone Petrella of N2K Networks to discuss the recently-released Defense Cyber Workforce Framework. Betsy Carmelite from Booz Allen Hamilton speaks about CISA's year ahead. And are large language models what the lawyers call an attractive nuisance.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/45


Selected reading.

CISA Adds Three Known Exploited Vulnerabilities to Catalog (Cybersecurity and Infrastructure Security Agency CISA)

March 7 CISA KEV Breakdown | Zoho, Teclib, Apache (Nucleus Security)

Acer Confirms Breach After Hacker Offers to Sell Stolen Data (SecurityWeek)

Acer confirms breach after 160GB of data for sale on hacking forum (BleepingComputer)

“Sharp Panda”: Check Point Research puts a spotlight on Chinese origined espionage attacks against southeast asian government entities (Check Point Software)

Pandas with a Soul: Chinese Espionage Attacks Against Southeast Asian Government Entities (Check Point Research)

What can security teams learn from a year of cyber warfare? (Computer Weekly)

Russian cyberattacks could intensify during spring offensives in Ukraine, US Cyber Command general says (Stars and Stripes)

US Bracing for Bolder, More Brazen Russian Cyberattacks (VOA)

Russia remains a ‘very capable’ cyber adversary, Nakasone says (C4ISRNet)

Employees Are Feeding Sensitive Business Data to ChatGPT (Dark Reading)

Extract Knowledge
Listen elsewhere

HiatusRAT exploits business-grade routers. International law enforcement action against the DoppelPaymer gang. Ransomware hits a major Barcelona hospital. Productivity suites are increasingly attractive as phishing grounds. Transparent Tribe’s romance scams. Cyberattacks briefly disrupt Russian websites and media outlets. Ashley Leonard, CEO of Syxsense, sits down with Dave to discuss their "Advancing Zero Trust Priorities'' report. Joe Carrigan on a warning from Microsoft about a surge in token theft. And trolling for disinfo raw material.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/44


Selected reading.

Black Lotus Labs uncovers another new malware that targets compromised routers (Lumen Newsroom)

Germany and Ukraine hit two high-value ransomware targets | Europol (Europol)

European Police, FBI Bust International Cybercrime Gang (VOA)

German police lift lid on worldwide cyber blackmail gang (Deutsche Welle)

Europol Hits Alleged Members of DoppelPaymer Ransomware Group (Decipher) 

An international sting brings another win against ransomware gangs (Washington Post)

European police move in on DoppelPaymer (Computing)

Police Looking for Russian Suspects Following DoppelPaymer Ransomware Crackdown (SecurityWeek)

Cyberattack hits major hospital in Spanish city of Barcelona (AP NEWS).

Cyberattack Hits Major Hospital in Spanish City of Barcelona (SecurityWeek)

Barcelona's Hospital Clinic hit by ransomware cyberattack 'from outside Spain' (Euro Weekly News)

Phishers’ Favorites 2022 Year-in-Review (Vade)

Kremlin Website Down Amid Reports of Cyber Attacks on Russia (The Daily Beast) 

Russian diplomat blames West for recruiting hackers for operations against Moscow (TASS)

Don’t Answer That! Russia-Aligned TA499 Beleaguers Targets with Video Call Requests (Proofpoint)

More description

HiatusRAT exploits business-grade routers. International law enforcement action against the DoppelPaymer gang. Ransomware hits a major Barcelona hospital. Productivity suites are increasingly attractive as phishing grounds. Transparent Tribe’s romance scams. Cyberattacks briefly disrupt Russian websites and media outlets. Ashley Leonard, CEO of Syxsense, sits down with Dave to discuss their "Advancing Zero Trust Priorities'' report. Joe Carrigan on a warning from Microsoft about a surge in token theft. And trolling for disinfo raw material.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/44


Selected reading.

Black Lotus Labs uncovers another new malware that targets compromised routers (Lumen Newsroom)

Germany and Ukraine hit two high-value ransomware targets | Europol (Europol)

European Police, FBI Bust International Cybercrime Gang (VOA)

German police lift lid on worldwide cyber blackmail gang (Deutsche Welle)

Europol Hits Alleged Members of DoppelPaymer Ransomware Group (Decipher) 

An international sting brings another win against ransomware gangs (Washington Post)

European police move in on DoppelPaymer (Computing)

Police Looking for Russian Suspects Following DoppelPaymer Ransomware Crackdown (SecurityWeek)

Cyberattack hits major hospital in Spanish city of Barcelona (AP NEWS).

Cyberattack Hits Major Hospital in Spanish City of Barcelona (SecurityWeek)

Barcelona's Hospital Clinic hit by ransomware cyberattack 'from outside Spain' (Euro Weekly News)

Phishers’ Favorites 2022 Year-in-Review (Vade)

Kremlin Website Down Amid Reports of Cyber Attacks on Russia (The Daily Beast) 

Russian diplomat blames West for recruiting hackers for operations against Moscow (TASS)

Don’t Answer That! Russia-Aligned TA499 Beleaguers Targets with Video Call Requests (Proofpoint)

Extract Knowledge
Listen elsewhere

Cranes as a security threat. EPA memo addresses cybersecurity risks to water systems. Oakland's ransomware incident becomes a data breach. Carding rises in the Russian underworld. Sandworm's record in Russia's war. Rick Howard sits down with Andy Greenberg from Wired to discuss how Ukraine suffered more data-wiping malware last year than anywhere, ever. Dave Bittner speaks with Kathleen Smith of ClearedJobs.Net to talk about hiring veterans and setting them (and yourself) up for success. And AI’s latest misuse: bogus investment schemes.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/43


Selected reading.

WSJ News Exclusive | Pentagon Sees Giant Cargo Cranes as Possible Chinese Spying Tools (Wall Street Journal)

EPA Takes Action to Improve Cybersecurity Resilience for Public Water Systems (US EPA)

EPA presses states to include cybersecurity in water safety reviews (SC Media) 

EPA Calls on States to Improve Public Water Systems’ Cybersecurity (Meritalk)

EPA issues water cybersecurity mandates, concerning industry and experts (CyberScoop)

City of Oakland Targeted by Ransomware Attack, Work Continues to… (City of Oakland).

Ransomware gang leaks data stolen from City of Oakland (BleepingComputer)

Ransomware hackers release some stolen Oakland data (CBS News)

Oakland officials say ransomware group may release personal data on Saturday (The Record from Recorded Future News) 

Cybercrime site shows off with a free leak of 2 million stolen card numbers (The Record from Recorded Future News)

A year of wipers: How the Kremlin-backed Sandworm has attacked Ukraine during the war (The Record from Recorded Future News)

Bitdefender Labs warns of fresh phishing campaign that uses copycat ChatGPT platform to swindle eager investors (Hot for Security)

More description

Cranes as a security threat. EPA memo addresses cybersecurity risks to water systems. Oakland's ransomware incident becomes a data breach. Carding rises in the Russian underworld. Sandworm's record in Russia's war. Rick Howard sits down with Andy Greenberg from Wired to discuss how Ukraine suffered more data-wiping malware last year than anywhere, ever. Dave Bittner speaks with Kathleen Smith of ClearedJobs.Net to talk about hiring veterans and setting them (and yourself) up for success. And AI’s latest misuse: bogus investment schemes.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/43


Selected reading.

WSJ News Exclusive | Pentagon Sees Giant Cargo Cranes as Possible Chinese Spying Tools (Wall Street Journal)

EPA Takes Action to Improve Cybersecurity Resilience for Public Water Systems (US EPA)

EPA presses states to include cybersecurity in water safety reviews (SC Media) 

EPA Calls on States to Improve Public Water Systems’ Cybersecurity (Meritalk)

EPA issues water cybersecurity mandates, concerning industry and experts (CyberScoop)

City of Oakland Targeted by Ransomware Attack, Work Continues to… (City of Oakland).

Ransomware gang leaks data stolen from City of Oakland (BleepingComputer)

Ransomware hackers release some stolen Oakland data (CBS News)

Oakland officials say ransomware group may release personal data on Saturday (The Record from Recorded Future News) 

Cybercrime site shows off with a free leak of 2 million stolen card numbers (The Record from Recorded Future News)

A year of wipers: How the Kremlin-backed Sandworm has attacked Ukraine during the war (The Record from Recorded Future News)

Bitdefender Labs warns of fresh phishing campaign that uses copycat ChatGPT platform to swindle eager investors (Hot for Security)

Extract Knowledge
Listen elsewhere

Gabriela Smith-Sherman, a former Federal agency CISO with over 15 years of experience in leading and implementing comprehensive enterprise cybersecurity programs and initiatives, sits down to share her journey. She is a U.S. combat disabled veteran who understands the importance of mission and is dedicated to delivering high-quality results and value to customers through innovative solutions. Gabriela shares about her time in the military and how her being apart of the service was one of the best decisions she made and dedicates all her hard work to her time in the military. She also shares how it was tough getting out of the routine of the military and being a civilian now was a hard transition, but she says that she thrives in the chaos of the IT world and that the military helped her to prepare for the cyber industry. She said "I think my military experience has prepared me, uh, to be in those kind of chaotic positions and be very calm about the approach." We thank Gabriela for sharing her story with us.

More description

Gabriela Smith-Sherman, a former Federal agency CISO with over 15 years of experience in leading and implementing comprehensive enterprise cybersecurity programs and initiatives, sits down to share her journey. She is a U.S. combat disabled veteran who understands the importance of mission and is dedicated to delivering high-quality results and value to customers through innovative solutions. Gabriela shares about her time in the military and how her being apart of the service was one of the best decisions she made and dedicates all her hard work to her time in the military. She also shares how it was tough getting out of the routine of the military and being a civilian now was a hard transition, but she says that she thrives in the chaos of the IT world and that the military helped her to prepare for the cyber industry. She said "I think my military experience has prepared me, uh, to be in those kind of chaotic positions and be very calm about the approach." We thank Gabriela for sharing her story with us.

Extract Knowledge
Listen elsewhere

Dor Zvi, Co-Founder and CEO from Red Access to discuss their work on "New Chrome Exploit Lets Attackers Completely Disable Browser Extensions." A recently patched exploit is tricking Chrome browsers on all popular OSs to not only give attackers visibility of their targets’ browser extensions, but also the ability to disable all of those extensions.

The research states the exploit consists of a bookmarklet exploit that allows threat actors to selectively force-disable Chrome extensions using a handy graphical user interface making Chrome mistakenly identify it as a legitimate request from the Chrome Web Store.

The research can be found here:

More description

Dor Zvi, Co-Founder and CEO from Red Access to discuss their work on "New Chrome Exploit Lets Attackers Completely Disable Browser Extensions." A recently patched exploit is tricking Chrome browsers on all popular OSs to not only give attackers visibility of their targets’ browser extensions, but also the ability to disable all of those extensions.

The research states the exploit consists of a bookmarklet exploit that allows threat actors to selectively force-disable Chrome extensions using a handy graphical user interface making Chrome mistakenly identify it as a legitimate request from the Chrome Web Store.

The research can be found here:

Extract Knowledge
Listen elsewhere

Implementing the US National Cybersecurity Strategy. The US National Cybersecurity Strategy was informed by lessons from Russia's war. Two threat actors from China up their game. Responding to a phishing campaign. #StopRansomware: Royal Ransomware. CISA releases five ICS advisories. Sameer Jaleel, Kent State University Associate CIO on closing functionality gaps and creating a safer digital environment for students.Johannes Ullrich from SANS on establishing an "End of Support" inventory.EPA issues a memo on water system cybersecurity.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/42


Selected reading.

National Cybersecurity Strategy (The White House)

US cyber leaders discuss the new National Cyber Strategy. (CyberWire)

Biden vows to wield ‘all instruments’ in fighting cyberthreats (Defense News)

Chinese state-backed hackers Iron Tiger target Linux devices with new malware (Tech Monitor)

Chinese hackers use new custom backdoor to evade detection (BleepingComputer) 

Scam alert: Trezor warns users of new phishing attack (Cointelegraph)

FBI and CISA Release #StopRansomware: Royal Ransomware | CISA (Cybersecurity and Infrastructure Security Agency CISA)

CISA Releases Five Industrial Control Systems Advisories | CISA (Cybersecurity and Infrastructure Security Agency CISA)

EPA Takes Action to Improve Cybersecurity Resilience for Public Water Systems (US EPA)

More description

Implementing the US National Cybersecurity Strategy. The US National Cybersecurity Strategy was informed by lessons from Russia's war. Two threat actors from China up their game. Responding to a phishing campaign. #StopRansomware: Royal Ransomware. CISA releases five ICS advisories. Sameer Jaleel, Kent State University Associate CIO on closing functionality gaps and creating a safer digital environment for students.Johannes Ullrich from SANS on establishing an "End of Support" inventory.EPA issues a memo on water system cybersecurity.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/42


Selected reading.

National Cybersecurity Strategy (The White House)

US cyber leaders discuss the new National Cyber Strategy. (CyberWire)

Biden vows to wield ‘all instruments’ in fighting cyberthreats (Defense News)

Chinese state-backed hackers Iron Tiger target Linux devices with new malware (Tech Monitor)

Chinese hackers use new custom backdoor to evade detection (BleepingComputer) 

Scam alert: Trezor warns users of new phishing attack (Cointelegraph)

FBI and CISA Release #StopRansomware: Royal Ransomware | CISA (Cybersecurity and Infrastructure Security Agency CISA)

CISA Releases Five Industrial Control Systems Advisories | CISA (Cybersecurity and Infrastructure Security Agency CISA)

EPA Takes Action to Improve Cybersecurity Resilience for Public Water Systems (US EPA)

Extract Knowledge
Listen elsewhere

CISA and FBI are releasing this joint advisory to disseminate known Royal ransomware IOCs and TTPs identified through recent FBI threat response activities.

AA23-061A Alert, Technical Details, and Mitigations

AA23-061A STIX XML

Royal Rumble: Analysis of Royal Ransomware (cybereason.com)

DEV-0569 finds new ways to deliver Royal ransomware, various payloads - Microsoft Security Blog

2023-01: ACSC Ransomware Profile - Royal | Cyber.gov.au

See Stopransomware.gov, a whole-of-government approach, for ransomware resources and alerts.

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

More description

CISA and FBI are releasing this joint advisory to disseminate known Royal ransomware IOCs and TTPs identified through recent FBI threat response activities.

AA23-061A Alert, Technical Details, and Mitigations

AA23-061A STIX XML

Royal Rumble: Analysis of Royal Ransomware (cybereason.com)

DEV-0569 finds new ways to deliver Royal ransomware, various payloads - Microsoft Security Blog

2023-01: ACSC Ransomware Profile - Royal | Cyber.gov.au

See Stopransomware.gov, a whole-of-government approach, for ransomware resources and alerts.

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge
Listen elsewhere

The Cybersecurity and Infrastructure Security Agency is releasing this Cybersecurity Advisory detailing activity and key findings from a recent CISA red team assessment—in coordination with the assessed organization—to provide network defenders recommendations for improving their organization's cyber posture.

AA23-059A Alert, Technical Details, and Mitigations

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

More description

The Cybersecurity and Infrastructure Security Agency is releasing this Cybersecurity Advisory detailing activity and key findings from a recent CISA red team assessment—in coordination with the assessed organization—to provide network defenders recommendations for improving their organization's cyber posture.

AA23-059A Alert, Technical Details, and Mitigations

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge
Listen elsewhere

CyberWire Daily podcast host Dave Bittner is joined by CyberWire editor John Petrik for an extended discussion about the Russian invasion of Ukraine and its effect on cybersecurity at the one year anniversary. John and his team have covered the Ukrainian conflict with daily news stories since the invasion began, and in fact, had quite a lot of coverage prior to the invasion. They take stock of where things stand, what has happened, and what we expected versus reality.

More description

CyberWire Daily podcast host Dave Bittner is joined by CyberWire editor John Petrik for an extended discussion about the Russian invasion of Ukraine and its effect on cybersecurity at the one year anniversary. John and his team have covered the Ukrainian conflict with daily news stories since the invasion began, and in fact, had quite a lot of coverage prior to the invasion. They take stock of where things stand, what has happened, and what we expected versus reality.

Extract Knowledge
Listen elsewhere

The White House releases its US National Cybersecurity Strategy. Red-teaming critical infrastructure. Redis cryptojacker discovered. Russia bans several messaging apps. Our guest is Kapil Raina from CrowdStrike with the latest on Threat Hunting. Dinah Davis from Arctic Wolf on the top healthcare industry cyber attacks. And hacktivist auxiliaries continue their nuisance-level activities.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/41


Selected reading.

National Cybersecurity Strategy (The White House)

FACT SHEET: Biden-Harris Administration Announces National Cybersecurity Strategy (The White House)

Biden administration releases new cybersecurity strategy (AP NEWS)

White House pushes for mandatory regulations, more offensive cyber action under National Cyber Strategy (The Record from Recorded Future News)

Here's why Biden's new cyber strategy is notable (Washington Post)

How the U.S. National Cyber Strategy Reaches Beyond Government Agencies (Wall Street Journal)

Biden National Cyber Strategy Seeks to Hold Software Firms Liable for Insecurity (Wall Street Journal)

CISA Red Team Shares Key Findings to Improve Monitoring and Hardening of Networks (Cybersecurity and Infrastructure Security Agency CISA)

CISA red-teamed a 'large critical infrastructure organization' and didn't get caught (The Record from Recorded Future News) 

Redis Miner Leverages Command Line File Hosting Service (Cado Security | Cloud Investigation)

Russia bans foreign messaging apps (Computing)

U.S. Consulate hacked by "Putin supporters" (Newsweek)

More description

The White House releases its US National Cybersecurity Strategy. Red-teaming critical infrastructure. Redis cryptojacker discovered. Russia bans several messaging apps. Our guest is Kapil Raina from CrowdStrike with the latest on Threat Hunting. Dinah Davis from Arctic Wolf on the top healthcare industry cyber attacks. And hacktivist auxiliaries continue their nuisance-level activities.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/41


Selected reading.

National Cybersecurity Strategy (The White House)

FACT SHEET: Biden-Harris Administration Announces National Cybersecurity Strategy (The White House)

Biden administration releases new cybersecurity strategy (AP NEWS)

White House pushes for mandatory regulations, more offensive cyber action under National Cyber Strategy (The Record from Recorded Future News)

Here's why Biden's new cyber strategy is notable (Washington Post)

How the U.S. National Cyber Strategy Reaches Beyond Government Agencies (Wall Street Journal)

Biden National Cyber Strategy Seeks to Hold Software Firms Liable for Insecurity (Wall Street Journal)

CISA Red Team Shares Key Findings to Improve Monitoring and Hardening of Networks (Cybersecurity and Infrastructure Security Agency CISA)

CISA red-teamed a 'large critical infrastructure organization' and didn't get caught (The Record from Recorded Future News) 

Redis Miner Leverages Command Line File Hosting Service (Cado Security | Cloud Investigation)

Russia bans foreign messaging apps (Computing)

U.S. Consulate hacked by "Putin supporters" (Newsweek)

Extract Knowledge
Listen elsewhere

The LastPass data breach built on an earlier attack. Forensic visibility and the Google Cloud Platform. An overview of hacktivist auxiliaries in Russia's war against Ukraine. Dish acknowledges sustaining a cyberattack. MKS Instruments discloses a ransomware incident. Carole Theriault has a lesson about ChatGPT and school systems. Ann Johnson from Afternoon Cyber Tea speaks with Stacy Hughes from Voya Financial about her journey to being CISO. And Bitdefender releases a decryptor for MortalKombat ransomware.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/40


Selected reading.

LastPass sustains a second data breach. (CyberWire)

Incident 2 – Additional details of the attack (LastPass Support) 

LastPass Says DevOps Engineer Home Computer Hacked (SecurityWeek) 

LastPass: Keylogger on home PC led to cracked corporate password vault (Naked Security) 

LastPass data was stolen by hacking an employee’s home computer (The Verge) 

LastPass says employee’s home computer was hacked and corporate vault taken (Ars Technica) 

LastPass is in Big Trouble (Gizmodo) 

LastPass: DevOps engineer hacked to steal password vault data in 2022 breach (BleepingComputer) 

The LastPass security breach is still going from bad to worse (Cybersecurity Connect) 

Mitiga on forensic visibility and the Google Cloud Platform. (CyberWire)

Mitiga Security Advisory: Insufficient Forensic Visibility in GCP Storage (Mitiga) 

Google Cloud Platform Exfiltration: A Threat Hunting Guide (Mitiga)

The Cyber Warfare Report (GroupSense) 

Dish Network confirms ransomware attack behind multi-day outage (BleepingComputer)

DISH tells SEC that ransomware attack caused outages; personal info may have been stolen (The Record from Recorded Future News)

Ransomware attack on chip supplier causes delays for semiconductor groups (Financial Times)

Bitdefender Releases Decryptor for MortalKombat Ransomware (Bitdefender Labs) 

Victims of MortalKombat ransomware can now decrypt their locked files for free (The Record from Recorded Future News)

More description

The LastPass data breach built on an earlier attack. Forensic visibility and the Google Cloud Platform. An overview of hacktivist auxiliaries in Russia's war against Ukraine. Dish acknowledges sustaining a cyberattack. MKS Instruments discloses a ransomware incident. Carole Theriault has a lesson about ChatGPT and school systems. Ann Johnson from Afternoon Cyber Tea speaks with Stacy Hughes from Voya Financial about her journey to being CISO. And Bitdefender releases a decryptor for MortalKombat ransomware.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/40


Selected reading.

LastPass sustains a second data breach. (CyberWire)

Incident 2 – Additional details of the attack (LastPass Support) 

LastPass Says DevOps Engineer Home Computer Hacked (SecurityWeek) 

LastPass: Keylogger on home PC led to cracked corporate password vault (Naked Security) 

LastPass data was stolen by hacking an employee’s home computer (The Verge) 

LastPass says employee’s home computer was hacked and corporate vault taken (Ars Technica) 

LastPass is in Big Trouble (Gizmodo) 

LastPass: DevOps engineer hacked to steal password vault data in 2022 breach (BleepingComputer) 

The LastPass security breach is still going from bad to worse (Cybersecurity Connect) 

Mitiga on forensic visibility and the Google Cloud Platform. (CyberWire)

Mitiga Security Advisory: Insufficient Forensic Visibility in GCP Storage (Mitiga) 

Google Cloud Platform Exfiltration: A Threat Hunting Guide (Mitiga)

The Cyber Warfare Report (GroupSense) 

Dish Network confirms ransomware attack behind multi-day outage (BleepingComputer)

DISH tells SEC that ransomware attack caused outages; personal info may have been stolen (The Record from Recorded Future News)

Ransomware attack on chip supplier causes delays for semiconductor groups (Financial Times)

Bitdefender Releases Decryptor for MortalKombat Ransomware (Bitdefender Labs) 

Victims of MortalKombat ransomware can now decrypt their locked files for free (The Record from Recorded Future News)

Extract Knowledge
Listen elsewhere

The US Marshals Service sustains a data breach. Blind Eagle is a phish hawk. Dish continues to work toward recovery. OneNote attachments are used to distribute Qakbot. Ben Yelin has analysis on the Supreme Court’s hearing on a section 230 case. Mr Security Answer Person John Pescatore has thoughts on Chat GPT. And CISA Director Easterly urges vendors to make software secure-by-design.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/39


Selected reading.

U.S. Marshals Service investigating ransomware attack, data theft (BleepingComputer)

US Marshals says prisoners’ personal information taken in data breach (TechCrunch)

Blind Eagle Deploys Fake UUE Files and Fsociety to Target Colombia's Judiciary, Financial, Public, and Law Enforcement Entities (BlackBerry)

Dish hit by multiday outage after reported cyberattack (TechCrunch)

DISH says ‘system issue’ affecting internal servers, phone systems (The Record from Recorded Future News) 

Take Note: Armorblox Stops OneNote Malware Campaign (Armorblox) 

Ukraine & Intelligence: One Year on – with Shane Harris (SpyCast)

U.S. cyber official praises Apple security and suggests Microsoft, Twitter need to step it up (CNBC)

U.S. cyber chief warns tech companies to curb unsafe practices (CBS News)

Tech manufacturers are leaving the door open for Chinese hacking, Easterly warns (The Record from Recorded Future News)

CISA Director Calls Out Industry Using Consumers as Cyber 'Crash Test Dummies' (Nextgov.com)

The Designed-in Dangers of Technology and What We Can Do About It (Cybersecurity and Infrastructure Security Agency)

More description

The US Marshals Service sustains a data breach. Blind Eagle is a phish hawk. Dish continues to work toward recovery. OneNote attachments are used to distribute Qakbot. Ben Yelin has analysis on the Supreme Court’s hearing on a section 230 case. Mr Security Answer Person John Pescatore has thoughts on Chat GPT. And CISA Director Easterly urges vendors to make software secure-by-design.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/39


Selected reading.

U.S. Marshals Service investigating ransomware attack, data theft (BleepingComputer)

US Marshals says prisoners’ personal information taken in data breach (TechCrunch)

Blind Eagle Deploys Fake UUE Files and Fsociety to Target Colombia's Judiciary, Financial, Public, and Law Enforcement Entities (BlackBerry)

Dish hit by multiday outage after reported cyberattack (TechCrunch)

DISH says ‘system issue’ affecting internal servers, phone systems (The Record from Recorded Future News) 

Take Note: Armorblox Stops OneNote Malware Campaign (Armorblox) 

Ukraine & Intelligence: One Year on – with Shane Harris (SpyCast)

U.S. cyber official praises Apple security and suggests Microsoft, Twitter need to step it up (CNBC)

U.S. cyber chief warns tech companies to curb unsafe practices (CBS News)

Tech manufacturers are leaving the door open for Chinese hacking, Easterly warns (The Record from Recorded Future News)

CISA Director Calls Out Industry Using Consumers as Cyber 'Crash Test Dummies' (Nextgov.com)

The Designed-in Dangers of Technology and What We Can Do About It (Cybersecurity and Infrastructure Security Agency)

Extract Knowledge
Listen elsewhere

Social engineering with generative AI. Mylobot and BHProxies. PureCrypter is deployed against government organizations and staged through Discord. Dish Network reports disruption. Third-party app and software as a service risk. Further assessments of the cyber phase of Russia's war so far, with warnings to stay alert. Are tough times coming in gangland? Comments on NIST's revisions to its Cybersecurity Framework are due this Friday. AJ Nash from ZeroFox on Mis/Dis/and Malinformation. Rick Howard digs into Zero Trust. And get this—AI is writing science fiction!


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/38


Selected reading.

Social engineering with generative AI. (CyberWire)

Who’s Behind the Botnet-Based Service BHProxies? (KrebsOnSecurity)

Mylobot: Investigating a proxy botnet (Bitsight)

PureCrypter targets government entities through Discord (Menlo Security)

PureCrypter malware hits govt orgs with ransomware, info-stealers (BleepingComputer)

Uncovering the Risks & Realities of Third-Party Connected Apps: ‍2023 SaaS-to-SaaS Access Report (Adaptive Shield)

Ukraine war anniversary likely to bring ‘disruptive’ cyberattacks on West, agencies warn (Global News)

How the Ukraine War Has Changed Russia’s Cyberstrategy  (Foreign Policy) 

A year of wiper attacks in Ukraine (WeLiveSecurity)

Russia's yearlong cyber focus on Ukraine (Axios)

A year after Russia's invasion, cyberdefenses have improved around the world (Washington Post)

One year on, how is the war playing out in cyberspace? (WeLiveSecurity) 

The Russia-Ukraine cyber war: one year later (IT World Canada) 

Russia launched large-scale operations in cyberspace alongside war (euronews)

WSJ News Exclusive | Hackers Extort Less Money, Are Laid Off as New Tactics Thwart More Ransomware Attacks (Wall Street Journal)

AI-generated fiction is flooding literary magazines — but not fooling anyone (The Verge)

More description

Social engineering with generative AI. Mylobot and BHProxies. PureCrypter is deployed against government organizations and staged through Discord. Dish Network reports disruption. Third-party app and software as a service risk. Further assessments of the cyber phase of Russia's war so far, with warnings to stay alert. Are tough times coming in gangland? Comments on NIST's revisions to its Cybersecurity Framework are due this Friday. AJ Nash from ZeroFox on Mis/Dis/and Malinformation. Rick Howard digs into Zero Trust. And get this—AI is writing science fiction!


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/38


Selected reading.

Social engineering with generative AI. (CyberWire)

Who’s Behind the Botnet-Based Service BHProxies? (KrebsOnSecurity)

Mylobot: Investigating a proxy botnet (Bitsight)

PureCrypter targets government entities through Discord (Menlo Security)

PureCrypter malware hits govt orgs with ransomware, info-stealers (BleepingComputer)

Uncovering the Risks & Realities of Third-Party Connected Apps: ‍2023 SaaS-to-SaaS Access Report (Adaptive Shield)

Ukraine war anniversary likely to bring ‘disruptive’ cyberattacks on West, agencies warn (Global News)

How the Ukraine War Has Changed Russia’s Cyberstrategy  (Foreign Policy) 

A year of wiper attacks in Ukraine (WeLiveSecurity)

Russia's yearlong cyber focus on Ukraine (Axios)

A year after Russia's invasion, cyberdefenses have improved around the world (Washington Post)

One year on, how is the war playing out in cyberspace? (WeLiveSecurity) 

The Russia-Ukraine cyber war: one year later (IT World Canada) 

Russia launched large-scale operations in cyberspace alongside war (euronews)

WSJ News Exclusive | Hackers Extort Less Money, Are Laid Off as New Tactics Thwart More Ransomware Attacks (Wall Street Journal)

AI-generated fiction is flooding literary magazines — but not fooling anyone (The Verge)

Extract Knowledge
Listen elsewhere

Mike Fey, CEO and co-founder of Island.io, joins to share his story, falling in love with technology and being fascinated by it at a young age. Mike quickly started working for companies where he grew in his role, becoming CTO of McAfee and then GM of the Enterprise business, stepping out to then become president and COO of Blue Coat, which was eventually acquired by Symantec, eventually wanting to get into his own business. He shares that being a small business owner is a lot of hard work and very tiring at times, he says "especially in a startup, the highs are very high and the lows are very low." Mike also mentions how easy it is to get knocked down when being in charge of your own business, but that teamwork is what helps to bring him back up. Mike says he wants to eventually help change the world and hopefully his legacy will help him to do that some day. We thank Mike for sharing his story with us.

More description

Mike Fey, CEO and co-founder of Island.io, joins to share his story, falling in love with technology and being fascinated by it at a young age. Mike quickly started working for companies where he grew in his role, becoming CTO of McAfee and then GM of the Enterprise business, stepping out to then become president and COO of Blue Coat, which was eventually acquired by Symantec, eventually wanting to get into his own business. He shares that being a small business owner is a lot of hard work and very tiring at times, he says "especially in a startup, the highs are very high and the lows are very low." Mike also mentions how easy it is to get knocked down when being in charge of your own business, but that teamwork is what helps to bring him back up. Mike says he wants to eventually help change the world and hopefully his legacy will help him to do that some day. We thank Mike for sharing his story with us.

Extract Knowledge
Listen elsewhere
Published 2023-02-25

The next hot AI scam. [Research Saturday]

25 min
View

Andy Patel from WithSecure Labs joins with Dave to discuss their study that demonstrates how GPT-3 can be misused through malicious and creative prompt engineering. The research looks at how this technology, GPT-3 and GPT-3.5, can be used to trick users into scams.

GPT-3 is a user-friendly tool that employs autoregressive language to generate versatile natural language text using a small amount of input that could inevitably interest cybercriminals. The research is looking for possible malpractice from this tool, such as phishing content, social opposition, social validation, style transfer, opinion transfer, prompt creation, and fake news.

The research can be found here:

More description

Andy Patel from WithSecure Labs joins with Dave to discuss their study that demonstrates how GPT-3 can be misused through malicious and creative prompt engineering. The research looks at how this technology, GPT-3 and GPT-3.5, can be used to trick users into scams.

GPT-3 is a user-friendly tool that employs autoregressive language to generate versatile natural language text using a small amount of input that could inevitably interest cybercriminals. The research is looking for possible malpractice from this tool, such as phishing content, social opposition, social validation, style transfer, opinion transfer, prompt creation, and fake news.

The research can be found here:

Extract Knowledge
Listen elsewhere

CISA advises increased vigilance on the first anniversary of Russia's war. CERT-UA reports current Russian cyberattacks were prepared in December 2021. How the war has changed the cyber underworld. Air raid alerts sound in nine Russian cities; Russia blames hacking. Our space correspondent Maria Varmazis speaks with Zhanna Malekos Smith at the Center for Strategic & International Studies about a new security agreement between Japan and the US. Kathleen Smith of ClearedJobs.Net clears misperceptions about the cleared space. And Dole continues recovery from ransomware. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/37


Selected reading.

CISA Urges Increased Vigilance One Year After Russia's Invasion of Ukraine (Cybersecurity and Infrastructure Security Agency | CISA)

Ukraine says Russian hackers backdoored govt websites in 2021 (BleepingComputer)

Ukraine suffered more data-wiping malware than anywhere, ever (Ars Technica) 

The First Crypto War? Assessing the Illicit Blockchain Ecosystem One Year Into Russia's Invasion of Ukraine (TRM Insights)

Ransomware Gang Conti Has Re-Surfaced and Now Operates as Three Groups: TRM Labs (CoinDesk).

Ukraine suffered more data-wiping malware than anywhere, ever (Ars Technica) 

Russia-Ukraine War: 3 Cyber Threat Effects, 1 Year In (ReliaQuest) 

Russian cybercrime alliances upended by Ukraine invasion (Register) Study: Old pacts ditched the moment Moscow moved in

How the Russia-Ukraine war has changed cyberspace (The Hill) 

Authorities blame hackers after air raid sirens sound over radio in multiple Russian cities (Meduza)

Russia blames 'hackers' for fake missile strike alerts (Register)

Fruit giant Dole suffers ransomware attack impacting operations (BleepingComputer)

Food giant Dole hit by ransomware (Computing) 

CISA Releases Three Industrial Control Systems Advisories (CISA)

More description

CISA advises increased vigilance on the first anniversary of Russia's war. CERT-UA reports current Russian cyberattacks were prepared in December 2021. How the war has changed the cyber underworld. Air raid alerts sound in nine Russian cities; Russia blames hacking. Our space correspondent Maria Varmazis speaks with Zhanna Malekos Smith at the Center for Strategic & International Studies about a new security agreement between Japan and the US. Kathleen Smith of ClearedJobs.Net clears misperceptions about the cleared space. And Dole continues recovery from ransomware. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/37


Selected reading.

CISA Urges Increased Vigilance One Year After Russia's Invasion of Ukraine (Cybersecurity and Infrastructure Security Agency | CISA)

Ukraine says Russian hackers backdoored govt websites in 2021 (BleepingComputer)

Ukraine suffered more data-wiping malware than anywhere, ever (Ars Technica) 

The First Crypto War? Assessing the Illicit Blockchain Ecosystem One Year Into Russia's Invasion of Ukraine (TRM Insights)

Ransomware Gang Conti Has Re-Surfaced and Now Operates as Three Groups: TRM Labs (CoinDesk).

Ukraine suffered more data-wiping malware than anywhere, ever (Ars Technica) 

Russia-Ukraine War: 3 Cyber Threat Effects, 1 Year In (ReliaQuest) 

Russian cybercrime alliances upended by Ukraine invasion (Register) Study: Old pacts ditched the moment Moscow moved in

How the Russia-Ukraine war has changed cyberspace (The Hill) 

Authorities blame hackers after air raid sirens sound over radio in multiple Russian cities (Meduza)

Russia blames 'hackers' for fake missile strike alerts (Register)

Fruit giant Dole suffers ransomware attack impacting operations (BleepingComputer)

Food giant Dole hit by ransomware (Computing) 

CISA Releases Three Industrial Control Systems Advisories (CISA)

Extract Knowledge
Listen elsewhere

Cyberattacks in Russia's war so far, and their future prospects. The Lazarus Group may be employing a new backdoor. Clasiopa targets materials research organizations. Ransomware interferes with food production. Evernote is used in a BEC campaign to bypass security filters. Identity-based cyberattacks. Pirated versions of Final Cut Pro deliver cryptominers. Caleb Barlow has thoughts on Twitter, Mudge, and lessons learned. Marc Van Zadelhoff from Cyber CEOs Decoded podcast speaks with Amanda Renteria, CEO of Code for America, about attracting diverse talent. And what have the scalperbots been up to, lately.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/36


Selected reading.

A year into Ukraine, looking back at 5 prewar predictions (Breaking Defense)

Dutch intelligence: Many cyberattacks by Russia are not yet public knowledge (The Record from Recorded Future News)

WinorDLL64: A backdoor from the vast Lazarus arsenal? (WeLiveSecurity)

Clasiopa: New Group Targets Materials Research (Symantec)

Cyberattack on food giant Dole temporarily shuts down North America production, company memo says (CNN Business)

Business Email Compromise Scam Leads to Credential Harvesting Evernote Page (Avanan)

The 2023 State of Identity Security Report (Oort)

Beware of macOS cryptojacking malware. (Jamf Threat Labs) 

Quarterly Index: Top 5 Scalper Bot Targets of Q4 2022 (Netacea)

More description

Cyberattacks in Russia's war so far, and their future prospects. The Lazarus Group may be employing a new backdoor. Clasiopa targets materials research organizations. Ransomware interferes with food production. Evernote is used in a BEC campaign to bypass security filters. Identity-based cyberattacks. Pirated versions of Final Cut Pro deliver cryptominers. Caleb Barlow has thoughts on Twitter, Mudge, and lessons learned. Marc Van Zadelhoff from Cyber CEOs Decoded podcast speaks with Amanda Renteria, CEO of Code for America, about attracting diverse talent. And what have the scalperbots been up to, lately.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/36


Selected reading.

A year into Ukraine, looking back at 5 prewar predictions (Breaking Defense)

Dutch intelligence: Many cyberattacks by Russia are not yet public knowledge (The Record from Recorded Future News)

WinorDLL64: A backdoor from the vast Lazarus arsenal? (WeLiveSecurity)

Clasiopa: New Group Targets Materials Research (Symantec)

Cyberattack on food giant Dole temporarily shuts down North America production, company memo says (CNN Business)

Business Email Compromise Scam Leads to Credential Harvesting Evernote Page (Avanan)

The 2023 State of Identity Security Report (Oort)

Beware of macOS cryptojacking malware. (Jamf Threat Labs) 

Quarterly Index: Top 5 Scalper Bot Targets of Q4 2022 (Netacea)

Extract Knowledge
Listen elsewhere

CISA adds three entries to its Known Exploited Vulnerabilities Catalog. "Hydrochasma" is a new cyberespionage threat actor. IBM claims the biggest effect of cyberattacks in 2022 was extortion. Social network hijacking in the C2C market. A credential theft campaign against data centers. LockBit claims an attack on a water utility in Portugal. Tim Starks from the Washington Post describes calls to focus on harmonizing cyber regulations. Our guest is Luke Vander Linden, host of the RH-ISAC Podcast. Disrupting Mr. Putin's speech, online, and what the hybrid war suggests about the future of cyber auxiliaries.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/35


Selected reading.

CISA Adds Three Known Exploited Vulnerabilities to Catalog (CISA)

Hydrochasma: Previously Unknown Group Targets Medical and Shipping Organizations in Asia (Symantec)

IBM Security X-Force Threat Intelligence Index 2023 (IBM)

S1deload Stealer – Exploring the Economics of Social Network Account Hijacking (Bitdefender Labs) 

Cyber Attacks on Data Center Organizations (Resecurity)

Hackers Scored Data Center Logins for Some of the World's Biggest Companies (Bloomberg)

LockBit gang takes credit for attack on water utility in Portugal (The Record from Recorded Future News) 

Ukraine Suffered More Data-Wiping Malware Last Year Than Anywhere, Ever (WIRED) 

Ukrainian hackers claim disruption of Russian TV websites during Putin speech (The Record from Recorded Future News) 

Ukraine's volunteer cyber army could be model for other nations: experts (Newsweek) 

Ukraine's largest charity wants to raise $1.3 million for ‘cyber offensive’ (The Record from Recorded Future News)

More description

CISA adds three entries to its Known Exploited Vulnerabilities Catalog. "Hydrochasma" is a new cyberespionage threat actor. IBM claims the biggest effect of cyberattacks in 2022 was extortion. Social network hijacking in the C2C market. A credential theft campaign against data centers. LockBit claims an attack on a water utility in Portugal. Tim Starks from the Washington Post describes calls to focus on harmonizing cyber regulations. Our guest is Luke Vander Linden, host of the RH-ISAC Podcast. Disrupting Mr. Putin's speech, online, and what the hybrid war suggests about the future of cyber auxiliaries.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/35


Selected reading.

CISA Adds Three Known Exploited Vulnerabilities to Catalog (CISA)

Hydrochasma: Previously Unknown Group Targets Medical and Shipping Organizations in Asia (Symantec)

IBM Security X-Force Threat Intelligence Index 2023 (IBM)

S1deload Stealer – Exploring the Economics of Social Network Account Hijacking (Bitdefender Labs) 

Cyber Attacks on Data Center Organizations (Resecurity)

Hackers Scored Data Center Logins for Some of the World's Biggest Companies (Bloomberg)

LockBit gang takes credit for attack on water utility in Portugal (The Record from Recorded Future News) 

Ukraine Suffered More Data-Wiping Malware Last Year Than Anywhere, Ever (WIRED) 

Ukrainian hackers claim disruption of Russian TV websites during Putin speech (The Record from Recorded Future News) 

Ukraine's volunteer cyber army could be model for other nations: experts (Newsweek) 

Ukraine's largest charity wants to raise $1.3 million for ‘cyber offensive’ (The Record from Recorded Future News)

Extract Knowledge
Listen elsewhere

GoDaddy has discovered a compromise of its systems. Twitter disables SMS authentication for those not subscribed to Twitter Blue. Last week’s cyber incident impacting German airports was confirmed to be DDoS. The consequences of cyber irregular participation in cyber wars. Semiconductor tech giant Applied Materials sees significant financial losses from a cyberattack. Joe Carrigan on scammers dangling fake job offers to students. Our guests are Max Shuftan & Monisha Bush from the SANS Institute, on the reopening of their HBCU Cyber Academy application window. And is Bing channeling Tay?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/34


Selected reading.

GoDaddy Inc. - Statement on recent website redirect issues (GoDaddy)

GoDaddy: Hackers stole source code, installed malware in multi-year breach (Bleeping Computer)

GoDaddy SEC Filing (SEC)

An update on two-factor authentication using SMS on Twitter(Twitter)

Twitter Limits SMS-Based 2-Factor Authentication to Blue Subscribers Only (The Hacker News)

SMS-Based 2FA Will Be Limited to Twitter Blue Users (HackRead)

Twitter will limit uses of SMS 2-factor authentication. What does this mean for users? (NPR)

Twitter's Two-Factor Authentication Change 'Doesn't Make Sense' (WIRED)

Twitter Shuts Off Text-Based 2FA for Non-Subscribers (SecurityWeek)

Official: Twitter will now charge for SMS two-factor authentication (The Verge)

German airport websites downed by DDoS attacks (Register)

German airports hit by DDoS attack, ‘Anonymous Russia’ claims responsibility (The Record from Recorded Future)

Russian phishing attacks flooded Ukraine, tripled against NATO nations in 2022: Report (Breaking Defense)

Civilian hackers could become military targets, Red Cross warns (The Record from Recorded Future News)

I helped create a 'cyber army' to help Ukraine defeat Russia. We can't fight with guns, but we can fight with our laptops. (Business Insider)

How Uncle Sam enlisted Big Tech to thwart Russia from launching catastrophic cyberwar (The Washington Times)

Big Tech Descends on Munich Conference in Support of Ukraine (Bloomberg)

Applied Materials will take a $250M hit to sales this quarter, thanks to a cyberattack at one of its suppliers (Silicon Valley Business Journal)

Semiconductor industry giant says ransomware attack on supplier will cost it $250 million (The Record by Recorded Future)

How should AI systems behave, and who should decide? (OpenAI)

Why Bing Is Being Creepy (Intelligencer)

Microsoft's new chatbot is a liar. And it says it's ready to call the cops. (Mother Jones)

After AI chatbot goes a bit loopy, Microsoft tightens its leash (Washington Post).

My Week of Being Gaslit and Lied to by the New Bin (Information)

More description

GoDaddy has discovered a compromise of its systems. Twitter disables SMS authentication for those not subscribed to Twitter Blue. Last week’s cyber incident impacting German airports was confirmed to be DDoS. The consequences of cyber irregular participation in cyber wars. Semiconductor tech giant Applied Materials sees significant financial losses from a cyberattack. Joe Carrigan on scammers dangling fake job offers to students. Our guests are Max Shuftan & Monisha Bush from the SANS Institute, on the reopening of their HBCU Cyber Academy application window. And is Bing channeling Tay?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/34


Selected reading.

GoDaddy Inc. - Statement on recent website redirect issues (GoDaddy)

GoDaddy: Hackers stole source code, installed malware in multi-year breach (Bleeping Computer)

GoDaddy SEC Filing (SEC)

An update on two-factor authentication using SMS on Twitter(Twitter)

Twitter Limits SMS-Based 2-Factor Authentication to Blue Subscribers Only (The Hacker News)

SMS-Based 2FA Will Be Limited to Twitter Blue Users (HackRead)

Twitter will limit uses of SMS 2-factor authentication. What does this mean for users? (NPR)

Twitter's Two-Factor Authentication Change 'Doesn't Make Sense' (WIRED)

Twitter Shuts Off Text-Based 2FA for Non-Subscribers (SecurityWeek)

Official: Twitter will now charge for SMS two-factor authentication (The Verge)

German airport websites downed by DDoS attacks (Register)

German airports hit by DDoS attack, ‘Anonymous Russia’ claims responsibility (The Record from Recorded Future)

Russian phishing attacks flooded Ukraine, tripled against NATO nations in 2022: Report (Breaking Defense)

Civilian hackers could become military targets, Red Cross warns (The Record from Recorded Future News)

I helped create a 'cyber army' to help Ukraine defeat Russia. We can't fight with guns, but we can fight with our laptops. (Business Insider)

How Uncle Sam enlisted Big Tech to thwart Russia from launching catastrophic cyberwar (The Washington Times)

Big Tech Descends on Munich Conference in Support of Ukraine (Bloomberg)

Applied Materials will take a $250M hit to sales this quarter, thanks to a cyberattack at one of its suppliers (Silicon Valley Business Journal)

Semiconductor industry giant says ransomware attack on supplier will cost it $250 million (The Record by Recorded Future)

How should AI systems behave, and who should decide? (OpenAI)

Why Bing Is Being Creepy (Intelligencer)

Microsoft's new chatbot is a liar. And it says it's ready to call the cops. (Mother Jones)

After AI chatbot goes a bit loopy, Microsoft tightens its leash (Washington Post).

My Week of Being Gaslit and Lied to by the New Bin (Information)

Extract Knowledge
Listen elsewhere

Dave Bittner had a conversation with Commander Brandon Campbell of US Navy Cyber Defense Operations Command and Captain Steve Correia, Commanding Officer of Naval Network Warfare Command. They discussed the Navy’s cybersecurity advances and how they have implemented them.

Commander Brandon Campbell is the former Operations Director at Navy Cyber Defense Operations Command and Task Force 1020 where they protect, detect, and respond to global cyber threats against Navy networks.

Captain J. Steve Correia is the Commanding Officer of Naval Network Warfare Command and the Commander of Task Force 1010 under the U.S. Navy’s Fleet Cyber Command where they execute tactical-level command and control to direct, operate, maintain and secure Navy communication and network systems.

More description

Dave Bittner had a conversation with Commander Brandon Campbell of US Navy Cyber Defense Operations Command and Captain Steve Correia, Commanding Officer of Naval Network Warfare Command. They discussed the Navy’s cybersecurity advances and how they have implemented them.

Commander Brandon Campbell is the former Operations Director at Navy Cyber Defense Operations Command and Task Force 1020 where they protect, detect, and respond to global cyber threats against Navy networks.

Captain J. Steve Correia is the Commanding Officer of Naval Network Warfare Command and the Commander of Task Force 1010 under the U.S. Navy’s Fleet Cyber Command where they execute tactical-level command and control to direct, operate, maintain and secure Navy communication and network systems.

Extract Knowledge
Listen elsewhere
Show details
Episodes
3784
Transcripts
67
2% coverage
Missing transcripts
3717
With chapters
0