Search this show’s transcripts

CyberWire Daily

en us
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

Episodes

Page 30 · 50 per page

Rachel Tobac, CEO from SocialProof Security sits down to share her amazing story on becoming what's known in the industry as an ethical hacker and CEO of a company. Rachel shares how she was always fascinated with spy movies and as she grew older that fascination turned into a real desire. Finding out she liked learning how the human brain works, she decided to start off in neuroscience. Wanting a change and with the help of her husband she was able to start getting more into hacking, finding she loved the fact that she was pretending to be someone to hack into a company and finding the weak spots. She shares how as a leader now she likes to be authentic with her team. She says "I think in the security world sometimes we take ourselves pretty seriously and a lot of times it's because we're dealing with really serious topics, and so in the moment we have to be extremely serious, but when you get a five minute break in between your crisis meetings, find a way to laugh if you can." We thank Rachel for sharing her story with us.

Extract Knowledge

Wendy Nather from Cisco sits down with Dave to discuss their work on "Cracking the Code to Security Resilience: Lessons from the Latest Cisco Security Outcomes Report." The report describes what security resilience is, while also going over how companies can achieve this resilience.

Wendy talks through some of the key findings based off of the report, and after surveying 4,751 active information security and privacy professionals from 26 countries, we find out some of the top priorities to achieving security resilience. From there the research goes on to explain from the findings which data-backed practices lead to the outcomes that can be implemented in cybersecurity strategies.

The research can be found here:

Extract Knowledge

The FBI is investigating incidents on its networks. Frebniis backdoors Microsoft servers. ProxyShell vulnerabilities are used to install a cryptominer. Havoc's post-exploitation framework. Atlassian discloses a data breach. German airports sustain a cyber incident. An Aspen Institute report concludes that cyber assistance benefits Ukraine. US announces "Disruptive Technology Strike Force." Robert M. Lee from Dragos on the value of capture the flag events. Our guests are Commander Brandon Campbell of US Navy Cyber Defense Operations Command and Captain Steve Correia, Commanding Officer of Naval Network Warfare Command. And CISA releases fifteen ICS advisories.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/33


Selected reading.

Exclusive: FBI says it has 'contained' cyber incident on bureau's computer network (CNN)

Frebniis: New Malware Abuses Microsoft IIS Feature to Establish Backdoor (Symantec, by Broadcom Software)

ProxyShellMiner Campaign Creating Dangerous Backdoors (Morphisec) 

Attacks with novel Havoc post-exploitation framework identified (SC Media)

Atlassian says recent data leak stems from third-party vendor hack (BleepingComputer) 

German airport websites down in possible hacker attack (Deutsche Welle) 

The Cyber Defense Assistance Imperative – Lessons from Ukraine (Aspen Institute)

U.S. launches 'disruptive technology' strike force to target national security threats (Reuters)

Justice Department to Increase Scrutiny of Technology Exports, Investments (Wall Street Journal)

ICS-CERT Advisories (CISA)

Extract Knowledge

North Korea's APT37 is distributing M2RAT. Multilingual BEC attacks, and how they happen. Assessing the cyber phase of Russia's war as the first anniversary of the invasion approaches. Killnet's attempt to rally hacktivists and criminals to the cause of Russia. Dinah Davis from Arctic Wolf describes continuous network scanning. Our guest is Dr. Inka Karppinen of CybSafe with a look at cyber security through the lens of a behavioral psychologist. And Grand Theft Auto is now also a TikTok challenge. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/32


Selected reading.

RedEyes hackers use new malware to steal data from Windows, phones (BleepingComputer) 

Multilingual Executive Impersonation Attacks (Abnormal Intelligence) 

Fog of War: How the Ukraine Conflict Transformed the Cyber Threat Landscape (Google Threat Analysis Group)

Following the Money: Killnet’s ‘Infinity Forum’ Wooing Likeminded Cybercriminals (Flashpoint) 

Hyundai, Kia patch bug allowing car thefts with a USB cable (BleepingComputer) 

Hyundai and Kia Launch Service Campaign to Prevent Theft of Millions of Vehicles Targeted by Social Media Challenge (NHTSA)

Extract Knowledge

SideWinder is an APT with possible origins in India. MortalKombat ransomware debuts. The GoAnywhere zero day was exploited in a data breach. Belarusian Cyber-Partisans release Russian data. Betsy Carmelite from Booz Allen Hamilton shares an overview of cyber deception. Our guest is Ashley Allocca from Flashpoint with a look at the Breaches and Malware Threat Landscape. And notes on Patch Tuesday.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/31


Selected reading.

Molted skin: APT SideWinder 2021 campaign that targeted over 60 companies in the Asia-Pacific (Group-IB)

New MortalKombat ransomware and Laplas Clipper malware threats deployed in financially motivated campaign (Cisco Talos Blog)

Tonga is the latest Pacific Island nation hit with ransomware (The Record from Recorded Future News) 

LockBit demanded £66mn from Royal Mail (Computing) 

City of Oakland declares state of emergency after ransomware attack (BleepingComputer) 

City of Oakland Targeted by Ransomware Attack, Work Continues to Secure and Restore Services Safely (City of Oakland)

Huge data dump from Russia’s censorship agency posted online (Cybersecurity Connect)

Russian system to scan internet for undesired content and dissent (Reuters)

Patch Tuesday: Three zero-days and nine 'Critical' RCE flaws fixed (Computing) 

Microsoft February 2023 Patch Tuesday fixes 3 exploited zero-days, 77 flaws (BleepingComputer)

Apple Releases Security Updates for Multiple Products (CISA) 

SAP Security Patch Day for February 2023 (Onapsis) 

Citrix Releases Security Updates for Workspace Apps, Virtual Apps and Desktops (CISA)

Adobe Releases Security Updates for Multiple Products (CISA)

The first national cyber director's last day is today (Washington Post)

Extract Knowledge

"Blender" reappears as "Sinbad." A Tonto Team cyberespionage attempt against Group-IB is thwarted. DarkBit claims responsibility for a ransomware attack on Technion University. An overview of ICS and OT security. Ben Yelin looks at surveillance oversight at the state level. Ann Johnson from Afternoon Cyber Tea speaks with Marene Allison about the CISO transformation. And it’s Valentine's Day, that annual holiday of love, chocolate, flowers, and online scams.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/30


Selected reading.

Has a Sanctioned Bitcoin Mixer Been Resurrected to Aid North Korea’s Lazarus Group? (Elliptic Connect)

Nice Try Tonto Team (Group-IB)

Hackers attack Israel’s Technion University, demand over $1.7 million in ransom (ARN)

Israel's top tech university postpones exams after ransomware attack (The Record from Recorded Future News)

Russian hackers ‘disrupt Turkey-Syria earthquake aid’ in cyber attack on Nato (The Independent) 

Killnet DDoS attacks disrupt Nato websites (ComputerWeekly.com)

Russian Hackers Disrupt NATO Earthquake Relief Operations (Dark Reading)

What Happened to #OpRussia? (Dark Reading)

Russian-linked malware was close to putting U.S. electric, gas facilities ‘offline’ last year (POLITICO)

2022 ICS/OT Cybersecurity Year in Review Executive Summary (Dragos)

What’s love got to do with it? 4 in 5 Valentine’s Day-themed spam emails are scams, Bitdefender Antispam Lab warns (Hot for Security)

Extract Knowledge

CISA adds to its Known Exploited Vulnerabilities Catalog. Cl0p claims responsibility for GoAnywhere exploitation. Victims mine for gold; attackers use pig butchering tactics. Hacktivists disrupt Iranian television during Revolution Day observances. Killnet claims a DDoS attack against NATO earthquake relief efforts. CyberWire UK Correspondent Carole Theriault asks what can we learn from the recent Roomba privacy snafu? Rick Howard looks at first principles we considered along the way. And can you name and shame the shameless?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/29


Selected reading.

CISA Adds Three Known Exploited Vulnerabilities to Catalog (CISA) 

GoAnywhere MFT Zero-Day Exploitation Linked to Ransomware Attacks (SecurityWeek) 

Clop ransomware claims it breached 130 orgs using GoAnywhere zero-day (BleepingComputer) 

Fool’s Gold: dissecting a fake gold market pig-butchering scam (Sophos)

Iranian State TV Hacked During President's Speech on Revolution Day (HackRead) 

Russian hackers disrupt Turkey-Syria earthquake relief (The Telegraph)

Hacking marketplace emerges from Killnet partnership, seeks pro-Russia donations (SC Media)

Russian Government evaluates the immunity to hackers acting in the interests of Russia (Security Affairs)

Russia’s Ransomware Gangs Are Being Named and Shamed (WIRED)

Extract Knowledge

Jaden Dicks, a new intern at CyberVista, a company that merged with CyberWire to become N2K Networks, shares his story as a young man growing up trying to get into the cyber community. From a very young age, Jaden hoped to become part of the cybersecurity field, He recalls growing up constantly being surrounded by technology, and now with the help of Urban Alliance, Jaden was able to secure this internship with CyberVista. Urban Alliance is a nonprofit that connects young adults with paid work experiences, such as internships to help them bridge the gaps between education and the workforce. Jaden hopes that this internship will help him further advance his career and help him to pursue his goals of working in cyber. He also shares advice to younger people like him who are looking to branch out and start working toward your goals, even as a teenager, and what has helped him to find his rhythm. We thank Jaden for sharing his story with us.

Extract Knowledge

Pascal Ackerman, OT Security Strategist from Guidepoint Security, joins Dave to discuss his work on discovering a vulnerability in the integrity of common HMI client-server protocol. This research is a Proof of Concept (PoC) attack on the integrity of data flowing across the industrial network with the intention of intercepting, viewing, and even manipulating values sent to (and from) the HMI, ultimately trying to trick the user into making a wrong decision, ultimately affecting the proper operation of the process.

In this research, they are targeting Rockwell Automation’s FactoryTalk View SE products, trying to highlight the lack of integrity and confidentiality on the production network and the effect that has on the overall security of the production environment.

The research can be found here:

Extract Knowledge

US and Republic of Korea agencies outline the DPRK ransomware threat. Reddit is breached. CISA releases six ICS advisories. Flaws are found in IIoT devices. Dinah Davis from Arctic Wolf shares cybersecurity stats every IT professional should know. Our guest is Kayla Williams from Devo autonomous SOCs. And, it’s almost Valentine’s Day. Have you noticed? (The hoods have.)


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/28


Selected reading.

#StopRansomware - Ransomware Attacks on Critical Infrastructure Fund DPRK Espionage Activities (CISA)

#StopRansomware: Ransomware Attacks on Critical Infrastructure Fund DPRK Malicious Cyber Activities (CISA) 

U.S., South Korean Agencies Partner to #StopRansomware Threat from DPRK (National Security Agency/Central Security Service)

US and South Korea accuse North Korea of using hospital ransoms to fund more hacking (The Record from Recorded Future News)

North Korea using healthcare ransomware attacks to fund further cybercrime, feds say (SC Media) 

U.S., South Korea Warn of North Korean Ransomware Threats (Bank Info Security) 

r/reddit - We had a security incident. Here’s what we know. (reddit) 

Hackers breach Reddit to steal source code and internal data (BleepingComputer) 

Reddit Breached With Stolen Employee Credentials (Dark Reading) 

Reddit Says It Was Hacked But That You Don't Need to Worry. Probably. (Gizmodo)

Control By Web X-400, X-600M (CISA) 

LS ELECTRIC XBC-DN32U (CISA) 

Johnson Controls System Configuration Tool (SCT) (CISA)

Horner Automation Cscape Envision RV (CISA) 

Omron SYSMAC CS/CJ/CP Series and NJ/NX Series (CISA)

ARC Informatique PcVue (CISA)

Industrial Wireless IoT - The direct path to your Level 0 (Otorio)

Critical Infrastructure at Risk from New Vulnerabilities Found in Wireless IIoT Devices (The Hacker News)

Romance scammers’ favorite lies exposed (Federal Trade Commission)

New FTC Data Reveals Top Lies Told by Romance Scammers (Federal Trade Commission)

Romance scammers could cause unhappy Valentine’s Day (Washington Post)

Love Bytes (Georgia State News Hub)

As V-Day nears: Romance scams cost victims $1.3B last year (Register)

Michigan AG warns of cybersecurity risks after data breach of gaming sites (mlive)

Extract Knowledge

CISA, NSA, FBI, the US Department of Health and Human Services, the Republic of Korea National Intelligence Service, and the Republic of Korea Defense Security Agency are issuing this alert to highlight ongoing ransomware activity against Healthcare and Public Health Sector organizations and other critical infrastructure sector entities.

AA23-040A Alert, Technical Details, and Mitigations

CISA’s North Korea Cyber Threat Overview and Advisories webpage.

Stairwell provided a YARA rule to identify Maui ransomware, and a Proof of Concept public RSA key extractor at the following link: https://www.stairwell.com/news/threat-research-report-maui-ransomware/

See Stopransomware.gov, a whole-of-government approach, for ransomware resources and alerts.

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge

War-floating. A phishing campaign pursues Ukrainian and Polish targets. Pakistan's navy is under cyberattack. A new criminal threat-actor uses screenshots for recon. ESXiArgs is widespread, but its effects are still being assessed. The UK and US issue joint sanctions against Russian ransomware operators. Robert M. Lee from Dragos addresses attacks to electrical substations. Our guest is Denny LeCompte from Portnox discussing IoT security segmentation strategies. And is LockBit next on law enforcement’s wanted list?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/27


Selected reading.

Chinese Balloon Had Tools to Collect Communications Signals, U.S. Says (New York Times) 

UAC-0114 Campaign Targeting Ukrainian and Polish Gov Entitities (The State Cyber Protection Centre of the State Service of Special Communication and Information Protection of Ukraine)

NewsPenguin, a Previously Unknown Threat Actor, Targets Pakistan with Advanced Espionage Tool (BlackBerry)

Screentime: Sometimes It Feels Like Somebody's Watching Me (Proofpoint)

Florida state court system, US, EU universities hit by ransomware outbreak (Reuters).

No evidence global ransomware hack was by state entity, Italy says (Reuters)

Ransomware campaign stirs worry despite uncertain impact (Washington Post)

VMware Security Response Center (vSRC) Response to 'ESXiArgs' Ransomware Attacks (VMware Security Blog)

CISA and FBI Release ESXiArgs Ransomware Recovery Guidance (CISA)

United States and United Kingdom Sanction Members of Russia-Based Trickbot Cybercrime Gang (U.S. Department of the Treasury)

Ransomware criminals sanctioned in joint UK/US crackdown on international cyber crime (National Crime Agency)

Extract Knowledge

CISA and the FBI are releasing this alert in response to the ongoing ransomware campaign, known as “ESXiArgs.” Malicious actors are exploiting known vulnerabilities in VMware ESXi servers that are likely running unpatched and out-of-service or out-of-date versions of VMware ESXi software to gain access and deploy ransomware.

AA23-039A Alert, Technical Details, and Mitigations

CISA has released an ESXiArgs recovery script at github.com/cisagov/ESXiArgs-Recover

VMware Security Response Center (vSRC) Response to 'ESXiArgs' Ransomware Attack…

Enes Sonmez and Ahmet Aykac, YoreGroup Tech Team: decrypt your crypted files in…

See Stopransomware.gov, a whole-of-government approach, for ransomware resources and alerts.

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge

CISA releases an ICS security advisory affecting a smart facility system. LockBit threatens to release Royal Mail data tomorrow. Cl0p ransomware expands to Linux-based systems. A vulnerability is identified in Toyota's GSPIMS. There’s an ESXiArgs update: new trackers and mitigation tools are available. Russia is running two new cyberespionage campaigns against Ukraine. Our guest is Roya Gordon from Nozomi Networks discusses the ICS Threat Landscape. And The Washington Post’s Tim Starks provides analysis on last night’s State of the Union.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/26


Selected reading.

CISA Releases One Industrial Control Systems Advisory (CISA) 

LockBit group threatens to publish stolen Royal Mail data tomorrow (Computing) 

Cl0p Ransomware Targets Linux Systems with Flawed Encryption | Decryptor Available (SentinelOne)

Hacking into Toyota’s global supplier management network (Eaton Works)

Researcher breaches Toyota supplier portal with info on 14,000 partners (BleepingComputer)

Vulnerability Provided Access to Toyota Supplier Management Network (SecurityWeek)

CISA Releases ESXiArgs Ransomware Recovery Script (CISA)

ESXiArgs Ransomware Campaign Targets VMWare ESXi Vulnerability (SecurityScorecard)

Graphiron: New Russian Information Stealing Malware Deployed Against Ukraine (Symantec)

Remcos software deployed in spying attempt on Ukraine’s government, CERT says (The Record from Recorded Future News)

The State of the Union was light on cybersecurity (Washington Post)

Biden calls for action on privacy rights in State of the Union (CyberScoop)

Extract Knowledge

VMware ESXi exploitations. Super Bowl cyber risks. Scalping bots. The curious case of the Moscow billboards. Joe Carrigan tracks pig butchering apps in online app stores. Our guest is David Liebenberg from Cisco Talos, to discuss incident response trends. And, in sportsball, it’s gonna be the Chiefs by a couple of hat tricks, or something.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/25


Selected reading.

Ransomware Hits Unpatched VMware Systems: 'Send Money Within 3 Days' (Virtualization Review) 

Massive ransomware attack targets VMware ESXi servers worldwide (CSO Online) 

CISA steps up to help VMware ESXi ransomware victims (SC Media)

‘Massive’ new ESXiArgs ransomware campaign has compromised thousands of victims (The Record from Recorded Future News) 

Have you clicked “Report Junk” lately on your #mobile device? (Proofpoint) 

CyRC special report: Secure apps? Don’t bet on it (Synopsys)

DataDome’s Inaugural E-Commerce Holiday Bot & Online Fraud Report Reveals the US as the Top Source of Bot Attacks (DataDome)

Darknet drug market BlackSprut openly advertises on billboards in Moscow (The Record from Recorded Future News)

Extract Knowledge

New ransomware exploits a VMware ESXi vulnerability. Roasted 0ktapus squads up. LockBit says ION paid the ransom. Russian cyber auxiliaries continue attacks against healthcare organizations. Attribution on the Charlie Hebdo attack. Deepen Desai from Zscaler describes recent activity by Ducktail malware. Rick Howard looks at cyber threat intelligence. And the top US cyber diplomat says his Twitter account was hacked.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/24


Selected reading.

Ransomware Gang in Trading Hack Says Ransom Was Paid (Bloomberg)

Regulators weigh in on ION attack as LockBit takes credit (Register)

Russian hackers launch attack on City of London infrastructure (The Armchair Trader)

Ransomware attack on data firm ION could take days to fix -sources (Reuters)

Linux version of Royal Ransomware targets VMware ESXi servers (BleepingComputer)

Ransomware scum attack old VMWare ESXi vulnerability (Register)

Italy sounds alarm on large-scale computer hacking attack (Reuters)

Italy's TIM suffers internet connection problems (Reuters)

Italy sounds alarm on large-scale computer hacking attack (Jerusalem Post)

Italian National Cybersecurity Agency (ACN) warns of massive ransomware campaign targeting VMware ESXi servers (Security Affairs)

Campagne d’exploitation d’une vulnérabilité affectant VMware ESXi (CERT-FR)

VMSA-2021-0002 (VMware)

CERT-FR warns of a new wave of ransomware attacks targeting VMware ESXi servers (Security Affairs)

‘0ktapus’ hackers are back and targeting tech and gaming companies, says leaked report (TechCrunch)

Customizable new DDoS service already appears to have fans among pro-Russia hacking groups (The Record from Recorded Future News)

Russian Hackers Take Down At Least 17 U.S. Health System Websites (MedCity News)

Tallahassee Memorial HealthCare, Florida, has taken IT systems offline after cyberattack (Security Affairs)

Iran responsible for Charlie Hebdo attacks - Microsoft On the Issues (Microsoft On the Issues)

Piratage de « Charlie Hebdo » : un groupe iranien à la manœuvre, selon Microsoft (Le Monde)

Iran behind hack of French magazine Charlie Hebdo, Microsoft says (Reuters)

Microsoft attributes Charlie Hebdo data leak to Iran-linked NEPTUNIUM APT (Security Affairs

America's top cyber diplomat says his Twitter account was hacked (CNN)

Extract Knowledge

Yasmin Abdi, a Security Engineering Manager at Snapchat and the CEO and Founder of NoHack, sits down to share her story on how she got to be in her amazing current roles. From a young age, Yasmin was fascinated by the overlap of cybersecurity and crime and law. In her time in college, she was able to intern at big tech companies like Snapchat, Google, and Facebook. She decided to stick with Snapchat, which had the security aspect and security composure that she wanted. In her role at Snapchat, she gets to work with her team to help take down all kinds of bad content and keep up the platform’s integrity, and found she fell in love with the work along the way. Yasmin shares the sage advice to grow your community as much as you can, saying to"form a community of like-minded people. People that you can bounce ideas off of, people that can help support you when times are low. Find mentors, find people that you aspire to be like, and really find that community of people." We thank Yasmin for sharing her story.

Extract Knowledge

Penetration testing is a vital part of a robust security program, but the traditional pentesting model is in a rut. Assessments happen infrequently, the scope is often very broad, and the report is usually overwhelming. What if you could increase the overall ROI of your pentesting program and avoid these limitations? Every penetration test should have specific goals. Coverage of the MITRE ATT&CK framework or the OWASP Top Ten is a great start, but a pentest could provide exponential value by applying a more strategic approach.

In this episode of CyberWire-X, the CyberWire’s Rick Howard and Dave Bittner discuss what it means to "shift left" with your penetration testing by working on a threat-informed test plan with guests and Hash Table members Bob Turner, the Field CSO of Fortinet, Etay Maor, the Senior Director for Security Strategy at Cato Networks, and Dan DeCloss, the Founder and CEO of our episode sponsor PlexTrac. 

Extract Knowledge

Tom Bonner and Eoin Wickens from HiddenLayer's SAI Team to discuss their research on weaponizing machine learning models with ransomware. Researchers at HiddenLayer’s SAI Team have developed a proof-of-concept attack for surreptitiously deploying malware, such as ransomware or Cobalt Strike Beacon, via machine learning models.

The attack uses a technique currently undetected by many cybersecurity vendors and can serve as a launchpad for lateral movement, deployment of additional malware, or the theft of highly sensitive data. In this research the team raising awareness by demonstrate how easily an adversary can deploy malware through a pre-trained ML model.

The research can be found here:

Extract Knowledge

CISA has released six ICS Advisories. A look at a North Korean cyberespionage campaign. ChatGPT and its attack potential. A new Python-based supply chain attack. There’s traffic on the Static Expressway: ClickFunnels seen in use for redirection. KillNet continues its campaign against hospitals. Ransomware as misdirection for cyberespionage. Part two of my conversation with Kathleen Smith of ClearedJobs.Net discussing trends in the cleared space. Our guest is Eric Bassier of Quantum talking about the multi-layered approach to ransomware protection. And Russian surveillance extends to Telegram chats.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/23


Selected reading.

Delta Electronics DIAScreen (CISA)

Mitsubishi Electric GOT2000 Series and GT SoftGOT2000 (CISA)

Baicells Nova (CISA) 

Delta Electronics DVW-W02W2-E2 (CISA)

Delta Electronics DX-2100-L1-CN (CISA)

Mitsubishi Electric GT SoftGOT2000 (CISA)

No Pineapple! –DPRK Targeting of Medical Research and Technology Sector (WithSecure)

Hackers linked to North Korea targeted Indian medical org, energy sector (The Record from Recorded Future News)

North Korean hackers stole research data in two-month-long breach (BleepingComputer)

ChatGPT May Already Be Used in Nation State Cyberattacks, Say IT Decision Makers in BlackBerry Global Research (BlackBerry)

Supply Chain Attack by New Malicious Python Package, “web3-essential” ((Frotinet)

Leveraging ClickFunnels to Bypass Security Services (Avanan)

Report: 'KillNet' targeting hospitals in countries helping Ukraine in war efforts (Becker’s Hospital Review)

Intelligence agency says ransomware group with Russian ties poses 'an enduring threat' to Canada (CBC)  

Les ransomwares, couverture des groupes APT pour du cyber-espionnage (Le Monde Informatique)

The Kremlin Has Entered the Chat (WIRED)

Extract Knowledge

Cisco patches a command injection vulnerability. NIST issues antiphishing guidance. HeadCrab malware's worldwide distribution campaign. The Gamaredon APT is more interested in collection than destruction. Kathleen Smith of ClearedJobs.Net looks at hiring trends in the cleared community. Bennett from Signifyd describes the fraud ring that’s launched a war on commerce against U.S. merchants. And trends in cyberattacks by state-sponsored actors.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/22


Selected reading.

Command-Injection Bug in Cisco Industrial Gear Opens Devices to Complete Takeover (Dark Reading)

Phishing Resistance – Protecting the Keys to Your Kingdom (NIST) 

OneNote Documents Increasingly Used to Deliver Malware | Proofpoint UK (Proofpoint)

HeadCrab: A Novel State-of-the-Art Redis Malware in a Global Campaign (Aquasec) 

Another UAC-0010 Story (The State Cyber Protection Centre of the State Service of Special Communication and Information Protection of Ukraine)

Russia-backed hacker group Gamaredon attacking Ukraine with info-stealing malware (The Record from Recorded Future News)

City of London traders hit by Russia-linked cyber attack (The Telegraph)

ChristianaCare recovers from cyberattack, restores website service (6abc Philadelphia) 

Nation-State Threats and the Rise of Cyber Mercenaries: Exploring the Microsoft Digital Defense Report (CSO Online)

Microsoft Digital Defense Report 2022 (Microsoft Security)

Extract Knowledge

Microsoft tallies more than a hundred ransomware gangs. Sandworm's NikoWiper hits Ukraine's energy sector. Mobilizing cybercriminals in a hybrid war. Firebrick Ostrich and business email compromise. Telegram is used for sharing stolen data and selling malware. Crypto scams find their way into app stores. Bryan Vorndran of the FBI Cyber Division outlines the services the FBI provides during an incident response. Ann Johnson from Afternoon Cyber Tea speaks with actor producer Tim Murck about the intersection of cyber awareness and storytelling. And we are shocked - shocked! - that there are fraudulent cyber professional credentials circulating online.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/21


Selected reading.

Microsoft: Over 100 threat actors deploy ransomware in attacks (BleepingComputer) 

SocGholish: A Tale of FakeUpdates (Reliaquest)

ESET APT Activity Report T3 2022 (WeLiveSecurity) 

Pro-Russian DDoS attacks raise alarm in Denmark, U.S. (The Record from Recorded Future News)

ChristianaCare's website restored after attack; pro-Russia 'hacktivist' group takes credit (Delaware News Journal)

Univ. of Iowa Hospitals website possibly hit by cyberattack (KCRG)

Cyber attack causes problems with UM Health websites (The Detroit News)

How the war in Ukraine has strengthened the Kremlin's ties with cybercriminals (The Record from Recorded Future News)

Dark Covenant 2.0: Cybercrime, the Russian State, and War in Ukraine (Recored Future)

Russia’s cyberwar against Ukraine offers vital lessons for the West (Atlantic Council) 

BEC Group Uses Secondary Personas & Lookalike Domains in Third-Party… (Abnormal Intelligence)

Telegram's place in the cyber underworld. (CyberWire)

Crypto scams found in the App Store. (CyberWire)

Exposure to third-party risk. (CyberWire)

Cyber certification deceit. (CyberWire)

Extract Knowledge

Some perspective on the cybercriminal labor market. DocuSign is impersonated in a credential-harvesting campaign. Social engineering pursues financial advisors. Killnet is active against the US healthcare sector. Mr. Security Answer Person John Pescatore has thoughts on cryptocurrency. Ben Yelin and I debate the limits of section 230. And, hey, who’s the real victim in cyberspace? A hint: probably not you, Mr. Putin.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/20


Selected reading.

Perspectives on the cybercriminal labor market. (CyberWire).

IT specialists search and recruitment on the dark web (Securelist)

Cybercrime job ads on the dark web pay up to $20k per month (BleepingComputer) 

Report on hackers' salaries shows poor wages for developers (Register)

Cybercrime groups offer six-figure salaries, bonuses, paid time off to attract talent on dark web (CyberScoop)

Application security risks. (CyberWire)

Survey gives insight into new app security challenges (Cisco App Dynamics)

DocuSign impersonated in credential phishing attack. (CyberWIre)

Breaking the Impersonation: Armorblox Stops DocuSign Attack (Armorblox)

"Pig butchering" and financial advisor impersonation scams. (CyberWire)

No Blocking, No Issue: The Curious Ecosystem of Financial Advisor Impersonation Scams (Domain Tools)

Ukraine at D+341: Killnet hits US hospitals.(CyberWire)

HC3 TLP Clear Analyst Note: Pro-Russian Hacktivist Group Threat to HPH Sector (American Hospital Association)

HHS, AHA Warn of Surge in Russian DDoS Attacks on Hospitals (Gov Info Security) 

Russian hackers allegedly take down Duke University Hospital’s website (Carolina Journal)

The Evolution of DDoS: Return of the Hacktivist (FSISAC)

Russia becomes target of West’s coordinated aggression in cyberspace — MFA (TASS)

Extract Knowledge

Gootloader's evolution. Yandex source code leaked (and Yandex blames a rogue insider). New GRU wiper malware is active against Ukraine. Latvia reports cyberattacks by Gamaredon. Russia and the US trade accusations of malign cyber activity. A hacktivist auxiliary's social support system. Deepen Desai from Zscaler describes the Lilithbot malware. Rick Howard looks at chaotic simians. And wannabes can be a nuisance, too: LockBit impersonators are seen operating in northern Europe.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/19


Selected reading.

Welcome to Goot Camp: Tracking the Evolution of GOOTLOADER Operations (Mandiant) 

Yandex denies hack, blames source code leak on former employee (BleepingComputer) 

Hackers use new SwiftSlicer wiper to destroy Windows domains (BleepingComputer) 

Sandworm APT targets Ukraine with new SwiftSlicer wiper (Security Affairs) 

Ukraine: Sandworm hackers hit news agency with 5 data wipers (BleepingComputer)

Ukraine Links Media Center Attack to Russian Intelligence (BankInfoSecurity) 

Latvia confirms phishing attack on Ministry of Defense, linking it to Russian hacking group (The Record from Recorded Future News) 

Russia knows US recruits hackers, trains Ukrainian IT-army — Deputy Foreign Minister (TASS)

Taking down the Hive ransomware gang. (CyberWire)

US puts a $10m bounty on Hive while Russia shuts down access (Register) 

Exploring Killnet’s Social Circles (Radware)

Copycat Criminals mimicking Lockbit gang in northern Europe (Security Affairs)

Extract Knowledge

Our guest, Charlie Moore, is a recently retired USAF Lieutenant General who sits down to share his story from flying high in the air to becoming a bigwig in the cyber community. He was most recently the Deputy Commander of the United States Cyber Command, and also spent part of his career as a human factors engineer working on human interfaces for fighter aircraft. When he first began his Air Force career, he was a member of the last class entering into the Academy that was not issued desktop computers. Charlie discusses how this changed as the year went on and how that impacted his career both in and out of the military. Charlie worked for different companies over the years to further his career and his goals, and discusses how his flying career has helped him and says, "I was extremely passionate about the flying aspect of my career for 25 years and I became even more passionate about operating in this space." We thank Charlie for sharing his story with us.

Extract Knowledge
Cybersecurity interview with ChatGPT.

In part one of CyberWire’s Interview with the AI, Brandon Karpf interviews ChatGPT about topics related to cybersecurity. Rick Howard joins Brandon to analyze the conversation and discuss potential use cases for the cybersecurity community.

ChatGPT is a chatbot launched by OpenAI and built on top of OpenAI’s GPT-3 family of large language models.

Cyber questions answered by ChatGPT in part one of the interview.
  1. What were the most significant cybersecurity incidents up through 2021?
  2. What leads you to characterize these specific events as significant?
  3. What were the specific technical vulnerabilities associated with these incidents?
  4. Who were the cyber actors involved in each of these attacks?
  5. Do you think it's valuable to attribute cyber attacks to specific actors?
Extract Knowledge

Roya Gordon from Nozomi Networks sits down with Dave to discuss their research on "Vulnerabilities in BMC Firmware Affect OT/IoT Device Security." Researchers at Nozomi Networks has revealed that there are thirteen vulnerabilities that affect BMCs of Lanner devices based on the American Megatrends (AMI) MegaRAC SP-X.

The research states "By abusing these vulnerabilities, an unauthenticated attacker may achieve Remote Code Execution (RCE) with root privileges on the BMC, completely compromising it and gaining control of the managed host." As well as mentioning what patches could be in the future to help fix these vulnerabilities.

The research can be found here:

Extract Knowledge

An update on the takedown of the Hive ransomware gang, plus insights from CrowdStrike’s Adam Meyers. If you say you’re going to unleash the Leopards, expect a noisy call from Killnet. Our guest is ExtraHop CISO Jeff Costlow talking about nation-state attackers in light of ongoing Russian military operations. CISA has released eight ICS advisories, and the agency has also added an entry to its Known Exploited Vulnerabilities Catalog.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/18


Selected reading.

Cybercriminals stung as HIVE infrastructure shut down (Europol)

U.S. Department of Justice Disrupts Hive Ransomware Variant (U.S. Department of Justice)

Director Christopher Wray’s Remarks at Press Conference Announcing the Disruption of the Hive Ransomware Group (Federal Bureau of Investigation)

Taking down the Hive ransomware gang. (CyberWire)

US hacks back against Hive ransomware crew (BBC News)

Cyberattacks Target Websites of German Airports, Admin (SecurityWeek) 

Delta Electronics CNCSoft ScreenEditor (CISA) 

Econolite EOS (CISA) 

Snap One Wattbox WB-300-IP-3 (CISA) 

Sierra Wireless AirLink Router with ALEOS Software (CISA).

Mitsubishi Electric MELFA SD/SQ series and F-series Robot Controllers (CISA) 

Rockwell Automation products using GoAhead Web Server (CISA)

Landis+Gyr E850 (CISA) 

Mitsubishi Electric MELSEC iQ-F, iQ-R Series (CISA) 

CISA Has Added One Known Exploited Vulnerability to Catalog (CISA)

Extract Knowledge

Joint advisory warns of remote monitoring and management software abuse. Iranian threat actors reported active against a range of targets. UK's NCSC warns of increased risk of Russian and Iranian social engineering attacks. A look at trends, as seen by CIOs. Carole Theriault ponders health versus privacy with former BBC guru Rory Cellan Jones. Kyle McNulty, host of the Secure Ventures podcast shares lessons from the cybersecurity startup community. And the DRAGONBRIDGE spam network is disrupted.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/17


Selected reading.

CISA, NSA, and MS-ISAC Release Advisory on the Malicious Use of RMM Software (CISA)

Protecting Against Malicious Use of Remote Monitoring and Management Software (CISA)

CISA: Federal agencies hacked using legitimate remote desktop tools (BleepingComputer)

'Malicious' cyber attacks launched by groups connected to Iran's regime (ABC) 

Abraham's Ax Likely Linked to Moses Staff (Secureworks)

SEABORGIUM and TA453 continue their respective spear-phishing campaigns against targets of interest (NCSC)

NCSC: Russian and Iranian hackers targeting UK politicians, journalists (Computing)

State of the CIO Study 2023: CIOs cement leadership role (Foundry)

U.S. says it 'hacked the hackers' to bring down ransomware gang, helping 300 victims (Reuters)

Over 50,000 instances of DRAGONBRIDGE activity disrupted in 2022 (Google TAG)

Extract Knowledge

CISA, NSA, and the MS-ISAC are releasing this alert to warn network defenders about malicious use of legitimate remote monitoring and management software. 

AA23-025A Alert, Technical Details, and Mitigations

For a downloadable copy of IOCs, see AA23-025.stix

Silent Push uncovers a large trojan operation featuring Amazon, Microsoft, Geek Squad, McAfee, Norton, and Paypal domains

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge

How do the North Koreans get away with it? They do run their cyber ops like a creepy start-up business. A spoofing vulnerability is discovered in Windows CryptoAPI. Python-based malware is distributed via phishing. MacOS may have a reputation for threat-resistance, but users shouldn't get cocky. DevSecOps survey results show tension between innovation and security. Russian hacktivist auxiliaries hit German targets. Tim Starks from the Washington Post Cyber 202 shares insights from his interview with Senator Warner. Our guest is Keith McCammon of Red Canary to discuss cyber accessibility. And Private sector support for Ukraine's cyber defense.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/16


Selected reading.

TA444: The APT Startup Aimed at Acquisition (of Your Funds) (Proofpoint)

Exploiting a Critical Spoofing Vulnerability in Windows CryptoAPI (Akamai) 

Securonix Security Advisory: Python-Based PY#RATION Attack Campaign Leverages Fernet Encryption and Websockets to Avoid Detection (Securonix)

BlackBerry's Inaugural Quarterly Threat Intelligence Report Reveals Threat Actors Launch One Malicious Threat Every Minute (BlackBerry)

Global CIO Report Reveals Growing Urgency for Observability and Security to Converge (Dynatrace)

Russian 'hacktivists' briefly knock German websites offline (Reuters)

How Microsoft is helping Ukraine’s cyberwar against Russia (Computerworld)

CISA Releases Two Industrial Control Systems Advisories (CISA) 

Extract Knowledge

At the 2022 Cyber Marketing Con, the CyberWire presented a CISO Q&A panel session on how to help cyber marketers reach CISOs and other security executives in the industry. The panel included Rick Howard, CSO of N2K Networks, Jaclyn Miller, Head of InfoSec and IT at DispatchHealth, Ted Wagner, CISO of SAP NS2, and was moderated by board director & and operating partner, Michelle Perry.

Listen in as the panel discusses:

  • What works and doesn’t work in getting a security executive’s attention.
  • Message trust, message fatigue, and what you can do about it.
  • Trusted information sources and how security executives use them.
  • Positioning and messaging that is actually meaningful to decision makers.
  • The security executive’s purchasing behavior and why skepticism is the driving force.


Stay tuned until the end to hear us answer some additional bonus questions submitted by attendees.

Extract Knowledge

DragonSpark conducts "opportunistic" cyberattacks in East Asia. ProxyNotShell and OWASSRF exploit chains target Microsoft Exchange servers. The IoT supply chain is threatened by exploitation of Realtek Jungle SDK vulnerability. CISA adds an entry to its Known Exploited Vulnerabilities Catalog. A Cisco study finds organizations see positive returns from investment in privacy. What's the hacktivist's postwar future? Joe Carrigan tracks a romance scam targeting seniors. Our guest is Pete Lund of OPSWAT to discuss the security of removable media devices. And a retired G-Man is indicted on multiple charges.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/15


Selected reading.

DragonSpark | Attacks Evade Detection with SparkRAT and Golang Source Code Interpretation (SentinelOne)

Technical Advisory: Proxy*Hell Exploit Chains in the Wild  (Bitdefender)

Realtek SDK Vulnerability Attacks Highlight IoT Supply Chain Threats (Unit 42)

CISA Adds One Known Exploited Vulnerability to Catalog (CISA) 

 2023 Data Privacy Benchmark Study (Cicso)

Hacktivism Is a Risky Career Path (WIRED)

Retired FBI Executive Charged With Concealing $225,000 In Cash Received From An Outside Source (Department of Justice, U.S. Attorney’s Office, District of Columbia) 

Former Special Agent In Charge Of The New York FBI Counterintelligence Division Charged With Violating U.S. Sanctions On Russia (Department of Justice, U.S. Attorney’s Office, Southern District of New York)

Former Senior F.B.I. Official in New York Charged With Aiding Oligarch (New York Times)

Extract Knowledge

The FAA attributes its January NOTAM outage. Malicious OneNote attachments are appearing in phishing campaigns. The Vastflux ad campaign has been disrupted. Ukraine moves toward closer cybersecurity collaboration with NATO. Rick Howard considers the best of 2022. Deepen Desai from Zscaler looks at VPN Risk. And, finally, we’re betting you want alerts for sports book customers and online gamers.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/14


Selected reading.

FAA Says Contractor Unintentionally Caused Outage That Disrupted Flights (Wall Street Journal)

Not a cyberattack, but an IT failure: the FAA's NOTAM outage. (CyberWire)

Hackers now use Microsoft OneNote attachments to spread malware (BleepingComputer)

Traffic signals: The VASTFLUX Takedown (HUMAN Security)

Ukraine signs agreement to join NATO cyber defense center (The Record from Recorded Future News) 

FanDuels warns of data breach after customer info stolen in vendor hack (BleepingComputer)

Industry looks at the MailChimp data incident. (CyberWire)

PSA: Don’t play GTA Online on PC right now (Video Games)

You might not want to play GTA Online right now due to security vulnerabilities (RockPaperShotgun)

Riot Games hacked, delays game patches after security breach (BleepingComputer)

Riot hit by ‘social engineering attack’ that will affect patch cadence for multiple titles (Dot Esports)

Extract Knowledge

Miriam Wugmeister, co-chair of Morrison & Foerster’s Privacy and Data Security practice, sits down to share her in-depth experience and understanding of privacy and data security laws, obligations, and practices across a wide range of industries. She talks about how she grew up not knowing exactly what she wanted to get into as a profession, starting off as a chemical engineering major in college before switching to philosophy. She then got asked to work on a project relating to a company’s privacy and fell in love with the subject matter, deciding then to pursue it as a career. Miriam mentions how technology is not as complicated as tech people might have you think. She hopes she can advertise a tech degree for young women and men looking to get into the field, as well as making sure she "encourages women and diverse lawyers to, uh, come into this area to thrive." We thank Miriam for sharing her story with us.

Extract Knowledge

The public web data domain is a fancy way to say that there is a lot of information sitting on websites around the world that is freely available to anybody who has the initiative to collect it and use it for some purpose. When you do that collection, intelligence groups typically refer to it as open source intelligence, or OSINT. Intelligence groups have been conducting OSINT operations for over a century if you consider books and newspapers to be one source of this kind of information. In the modern day, hackers conduct OSINT operations in order to recon their potential victims by collecting email addresses, personal information, IP addresses, software versions, network configurations, and, if they are lucky, login credentials for websites and social media platforms. The question is, how can the good guys use these techniques to improve their security posture or maybe help the business in some kind of material way?

On this episode of CyberWire-X, the CyberWire’s Rick Howard and Dave Bittner discuss OSINT operations to improve your security posture with guests Steve Winterfeld, Hash Table member and Advisory CISO for Akamai, and Or Lenchner, CEO at our episode sponsor Bright Data. 

Extract Knowledge

Brigid O. Gorman from Symantec's Threat Hunter Team joins Dave to discuss their report "Billbug - State-sponsored Actor Targets Cert Authority and Government Agencies in Multiple Asian Countries." The team has discovered that state-sponsored actors compromised a digital certificate authority in an Asian country during a campaign in which multiple government agencies were also targeted.

The research states they believe Billbug, which is a long-established advanced persistent threat (APT) group has been active since about 2009. They say "In activity documented by Symantec in 2019, we detailed how the group was using a backdoor known as Hannotog (Backdoor.Hannotog) and another backdoor known as Sagerunex (Backdoor.Sagerunex). Both these tools were also seen in this more recent activity."

The research can be found here:

Extract Knowledge

Ransomware hits Costa Rican government systems, again. A Chinese threat actor deploys the BOLDMOVE backdoor against unpatched FortiOS. Credential stuffing afflicts PayPal users. T-Mobile discloses a data breach. A cyberattack hits a remote Canadian utility. The Wagner Group sponsors a hackathon. Malek Ben Salem from Accenture describes prompt injection for chatbots. Our guest is Paul Martini of iboss with insights on Zero Trust. And the FSB’s Gamaredon APT runs a hands-on Telegraph phishing campaign against Ukrainian targets.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/13


Selected reading.

Bolster Your Company Defenses With Zero Trust Edge (Forrester)

MICITT detecta incidente informático en el MOPT, el cual ya se encuentra contenido (MICITT)

MOPT mantiene habilitados todos los servicios de manera presencial (MICITT)

Costa Rica’s Ministry of Public Works and Transport crippled by ransomware attack (Record)

Suspected Chinese Threat Actors Exploiting FortiOS Vulnerability (CVE-2022-42475) (Mandiant) 

Attackers Crafted Custom Malware for Fortinet Zero-Day (Dark Reading)

Chinese hackers used recently patched FortiOS SSL-VPN flaw as a zero-day in October (Security Affairs) 

PayPal accounts breached in large-scale credential stuffing attack (BleepingComputer)

PayPal Confirms Over 34,000 Customer Accounts Were Breached (EcommerceBytes)

35,000 PayPal accounts hacked, and users could've prevented it (PCWorld)

Thousands Of PayPal Accounts Hacked—Is Yours One Of Them? (Forbes)

Nearly 35,000 PayPal users had SSNs, tax info leaked during December cyberattack (The Record from Recorded Future News)

T-Mobile Says Hacker Stole Data for 37 Million Customers (Bloomberg)

T-Mobile Says Hackers Stole Data on About 37 Million Customers (Wall Street Journal)

T-Mobile Says Hackers Used API to Steal Data on 37 Million Accounts (SecurityWeek)

Cyberattack hits Nunavut's Qulliq Energy Corp. (CBC News) 

Nunavut power utility’s servers hit by cyber attack | IT World Canada News (IT World Canada)

Russian War Report: Russian hacker wanted by the FBI reportedly wins Wagner hackathon prize  (Atlantic Council)

Gamaredon (Ab)uses Telegram to Target Ukrainian Organizations (Blackberry)

Gamaredon Group Launches Cyberattacks Against Ukraine Using Telegram (The Hacker News) 

Hitachi Energy PCU400 (CISA) 

Bolster Your Company Defenses With Zero Trust Edge (iBoss)

Extract Knowledge

A hostile takeover of the Solaris contraband market. Ukraine warns that Russian cyberattacks continue. An overview of 2H 2022 ICS vulnerabilities. Codespaces accounts can act as malware servers. Blank-image attacks. Campaigns leveraging HR policy themes. Dinah Davis from Arctic Wolf has tips for pros for security at home. Our guest is Gerry Gebel from Strata Identity describes a new open source standard that aims to unify cloud identity platforms. And travel-themed phishing increases.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/12


Selected reading.

Friday the 13th on the Dark Web: $150 Million Russian Drug Market Solaris Hacked by Rival Market Kraken (Elliptic Connect) 

Russia-linked drug marketplace Solaris hacked by its rival (The Record from Recorded Future News) 

Cyber-attacks have tripled in past year, says Ukraine’s cybersecurity agency (the Guardian)

Ukraine: Russians Aim to Destroy Information Infrastructure (Gov Info Security) 

Ukraine says Russia is coordinating missile strikes, cyberattacks and information operations (The Record by Recorded Future)

ICS Vulnerabilities and CVEs: Second Half of 2022 (SynSaber)

Abusing a GitHub Codespaces Feature For Malware Delivery (Trend Micro)

The Blank Image Attack (Avanan)

Phishing Attacks Pose as Updated 2023 HR Policy Announcements (Abnormal Security)

Spammers phish eager vacationers with travel-themed lures, Bitdefender Antispam Lab warns (Bitdefender)

Extract Knowledge

CISA adds to its Known Exploited Vulnerability Catalog. Attacks against industrial systems. DNV is recovering from ransomware. Chinese cyberespionage is reported against Iran. The persistence of nuisance-level hacktivism. Robert M. Lee from Dragos outlines pipeline security. Our guest is Yasmin Abdi from Snap on bringing her team up to speed with zero trust. And a side-effect of Russia's war: a drop in paycard fraud.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/11


Selected reading.

Bolster Your Company Defenses With Zero Trust Edge (iBoss)

CISA Adds One Known Exploited Vulnerability to Catalog (CISA)

GE Digital Proficy Historian (CISA)

Mitsubishi Electric MELSEC iQ-F, iQ-R Series (CISA) 

Siemens SINEC INS (CISA)

Contec CONPROSYS HMI System (CHS) Update A (CISA)

Nozomi Networks Researchers Take a Deep Look into the ICS Threat Landscape (Nozomi Networks)

A look at IoT/ICS threats. (CyberWire)

DNV's fleet management software recovering from ransomware attack. (CyberWire)

DNV says up to 1,000 ships affected by ransomware attack (Computing)

Ransomware attack on maritime software impacts 1,000 ships (The Record from Recorded Future News)

Chinese Playful Taurus Activity in Iran (Unit 42)

Playful Taurus: a Chinese APT active against Iran. (CyberWire)

Russian hackers allegedly tried to disrupt a Ukrainian press briefing about cyberattacks (Axios)

Russia's Ukraine War Drives 62% Slump in Stolen Cards (Infosecurity Magazine)

Annual Payment Fraud Intelligence Report: 2022 (Recorded Future)

Extract Knowledge

A Phishing campaign impersonates DHL. Conscription and mobilization provide criminals with phishbait for Russian victims. Norton LifeLock advises customers that their accounts may have been compromised. Trends in data protection. Veracode's report on the state of software application security. Ben Yelin looks at NSO group’s attempt at state sovereignty. Ann Johnson from Afternoon Cyber Tea speaks with Microsoft’s Chris Young about the importance of the security ecosystem. And Ukraine calls for a "digital United Nations."


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/10


Selected reading.

Cloud 9: Top Cloud Penetration Testing Tools (Bishop Fox)

Our Top Favorite Fuzzer crowdsourcing pen testing tools (Bishop Fox)

DHL Phishing Attack. Simply Delivered. (ArmorBlox) 

Credential phishing campaign impersonates DHL. (CyberWire)

Phishing scam invites Russian Telegram users to check ‘conscription lists’ to see if they’ll be drafted in February (Meduza)

NortonLifeLock warns that hackers breached Password Manager accounts (BleepingComputer)

Norton LifeLock says thousands of customer accounts breached (TechCrunch).

NortonLifeLock notifies thousands of users about compromised Password Manager accounts (Computing) 

Data Protection Trends Report 2023 (Veeam)

Trends in data protection. (CyberWire)

How Orca Found Server-Side Request Forgery (SSRF) Vulnerabilities in Four Different Azure Services (Orca Security)

Orca describes four Azure vulnerabilities. (CyberWire)

State Of Software Security (Veracode) 

A look at the state of software security. (CyberWire)

Ukraine calls for ‘Cyber United Nations’ amid Russian attacks (POLITICO) 

Extract Knowledge

Gene Fay, CEO of ThreatX sits down to share his experience rising through the ranks to get to where he is today. He shares how even at a young age he wanted to work in an office and become a businessman, though at the time he did not understand what that entailed. After college he acquired a job that was revolutionizing video editing for post-production studios as well as TV stations, where he started to really learn about technology. Gene talks about leading from the front and how a good leader will always do so, even if he has to lead from two different fronts. He said "it's kind of the two fronts, sometimes you've gotta put on the leadership face, and believe it, that, that you can get, and we can get through any situation, cuz sometimes you're, your gut feelings are, might be wrong and, or it's a moment in time and if you can help the team grind through that situation, it does get better." We thank Gene for sharing his story with us.

Extract Knowledge

Mohammad Kazem Hassan Nejad from WithSecure joins Dave to discuss the team’s research, “DUCKTAIL returns - Underneath the ruffled feathers.” DUCKTAIL is a financially motivated malware operation that targets individuals and businesses operating on the Facebook Ads and Business platform.

The research states “The malware is designed to steal browser cookies and take advantage of authenticated Facebook sessions to steal information from the victim's Facebook account.” WithSecure has found that after a short hiatus, DUCKTAIL has returned with slight changes in their mode of operation.

The research can be found here:

Extract Knowledge

GitHub disables NoName accounts. Russia dismisses reports of cyberespionage attempts against US National Laboratories. The Royal Mail cyber incident is now identified as ransomware attack. An update on the NOTAM issues that interfered with civil aviation. A Citrix vulnerability is exploited by ransomware group. CISA publishes its annual report. Bryan Vorndran of the FBI Cyber Division calibrates expectations with regard to the IC3. Our guest is Kayne McGladrey with insights on 2023 from the IEEE. And Positive Hack Days and the growing isolation of Russia's cyber sector.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/9


Selected reading.

 Impact of Technology in 2023 and Beyond (IEEE)

Ukraine at D+323: Fighting in Soledar, and industrial mobilization. (CyberWire)

GitHub disables pro-Russian hacktivist DDoS pages (CyberScoop)

Russia criticises Reuters story on Russian hackers targeting U.S. nuclear scientists (Reuters)

Royal Mail cyber incident now identified as ransomware attack. (CyberWire)

Not a cyberattack, but an IT failure. (CyberWire)

The Guardian breach and news media as targets. (CyberWire)

Citrix vulnerability exploited by ransomware group. (CyberWire)

2022 Year In Review (CISA)

Russia’s largest hacking conference reflects isolated cyber ecosystem (Brookings)

Extract Knowledge

Iranian VPN users are afflicted by Trojanized installation apps. Phishing on the static expressway. NoName057(16) hacktivist auxiliaries target NATO. Yesterday’s flight outage appears not to have been caused by a cyberattack. Royal Mail is disrupted by a "cyber incident." Carole Theriault thinks Meta needs to step up their game when blocking financial scams. Our guest is Mark Sasson from Pinpoint Search Group to discuss why cybersecurity may no longer be a candidate-driven market. And HR phishbait dangles raises, and some employees bite.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/8


Selected reading.

EyeSpy - Iranian Spyware Delivered in VPN Installers (Bitdefender Labs)

Phishing on the Static Expressway. (CyberWire)

NoName057(16) - The Pro-Russian Hacktivist Group Targeting NATO (SentinelOne) 

Not a cyberattack, but an IT failure. (CyberWire)

FAA NOTAM Statement (FAA)

Canadian Pilot-Alert System Reports Outage Hours After U.S. Grounding Order (Wall Street Journal)

US air travel resumes but thousands of flights delayed after planes grounded - live updates (The Telegraph) 

US Flights Latest: Departures Resume After FAA Lifts Ground Stop (Bloomberg)

Royal Mail suffers ‘severe service disruption’ after cyber incident (Glasgow Times)

Royal Mail issues major disruption warning after 'cyber incident' (Computing) 

Parcels and letters stuck in limbo as Royal Mail is hit by a suspected hack (The Telegraph) 

Cyber Incident Hits UK Postal Service, Halts Overseas Mail (SecurityWeek)

Extract Knowledge

Patch Tuesday. CISA releases two ICS Advisories and makes some additions to its Known Exploited Vulnerabilities Catalog. Dark Pink APT is active against Asian targets. Kinsing cryptojacking targets Kubernetes instances. Ukrainian hacktivists conduct DDoS against Iranian sites. Risk exposure and a hospital's experience with ransomware. The Health3PT initiative seeks to manage 3rd-party risk. Tim Starks from the Washington Post’s Cyber 202 on cyber rising to the level of war crime. Our guest is Connie Stack, CEO of Next DLP, on the path to leadership within cyber for women. And phishing with Pokémon NFTs.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/7


Selected reading.

The Daily 202 (Latest Cybersecurity 202)

Microsoft Releases January 2023 Security Updates (CISA) >

Adobe Releases Security Updates for Multiple Products (CISA) 

Black Box KVM (CISA)

Delta Electronics InfraSuite Device Master (CISA)

Known Exploited Vulnerabilities Catalog (CISA)

Dark Pink (Group-IB)

New Dark Pink APT group targets govt and military with custom malware (BleepingComputer)

Kinsing cryptojacking. (CyberWire)

Ukraine at D+321: "Difficult in places." (CyberWire)

Iranian websites impacted by pro-Ukraine DDoS attacks (SC Media) 

Ransomware attack against SickKids said to be unusual. (CyberWire)

Health3PT seeks a uniform approach to healthcare supply chain issues. (CyberWire)

Breaking the glass ceiling: My journey to close the leadership gap. (CyberWire, Creating Connections)

Pokémon NFTs used as malware vectors. (CyberWire)

Extract Knowledge

A look back at ransomware in 2022. Lessons from Russia's war: crooks, hacktivists, and auxiliaries. Cyberattacks as war crimes. The state of SSE adoption. RSA Conference 2023 opens applications for the Launch Pad and the Innovation Sandbox. Joe Carrigan looks at online scams targeting military members. Our guest is Richard Caralli from Axio on the State of Ransomware Preparedness. And the most common known exploited vulnerabilities affecting the financial sector.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/6


Selected reading.

Ransomware trends: 2022. (CyberWire)

State of Ransomware Preparedness Research Study: 2022 (Axio)

Kyiv argues Russian cyberattacks could be war crimes (POLITICO)

Ukraine official says Russian cyberattacks on its energy network could equate to war crimes (Yahoo)

Ukraine war and geopolitics fuelling cybersecurity attacks - EU agency (EU Reporter)

Industry-first research from Axis Security finds 65% percent of organizations plan to adopt a Security Service Edge platform within next two years (Axis Security)

RSAC Launch Pad is Back! (RSA Conference 2023)

The Best in Innovation Programs Starts Here (RSA Conference 2023)

Top KEVs in the U.S. Financial Services Sector (LookingGlass)

Extract Knowledge

Telegram impersonation affects a cryptocurrency firm. Phishing with Facebook termination notices. Russian phishing continues to target Moldova. The IEEE on the impact of technology in 2023. Glass ceilings in tech leadership. Seattle Schools sue social media platforms. Malek Ben Salem from Accenture explains coding models. Our guest is Julie Smith, identity security leader and executive director at IDSA, with insights on identity and security strategies. And dealing with the implications of ChatGPT. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/5


Selected reading.

Impact of Technology in 2023 and Beyond (IEEE)

Telegram insider server access offered to Dark Web customers (SafetyDetectives)

Moldovaʼs government hit by flood of phishing attacks (The Record from Recorded Future News) 

OPWNAI : Cybercriminals Starting to Use ChatGPT (Check Point Research)

Hackers exploiting ChatGPT to write malicious codes to steal your data (Business Standard)

Armed With ChatGPT, Cybercriminals Build Malware And Plot Fake Girl Bots (Forbes) 

Hackers Exploiting OpenAI’s ChatGPT to Deploy Malware (HackRead)

Cybercriminals are already using ChatGPT to own you (SC Media)

Threat Report: Impersonation Detected in Telegram Chats to Deliver Malware (Safeguard Cyber) 

Seattle schools sue tech giants over social media harm (ABC News) 

Seattle Public Schools sues TikTok, YouTube, Instagram and others, seeking compensation for youth mental health crisis (GeekWire)

Ghost Writer: Microsoft Looks to Add OpenAI’s Chatbot Technology to Word, Email (The Information)

Microsoft plans to use ChatGPT in Bing. Here's why it could be a threat to Google. (Freethink) 

ChatGPT Hits Ethical Roadblock; Blocked (Analytics India Magazine)

A College Kid Built an App That Sniffs Out Text Penned by AI (The Daily Beast) 

A Princeton student built an app which can detect if ChatGPT wrote an essay to combat AI-based plagiarism (Business Insider)

Extract Knowledge

Teresa Rothaar, a governance, risk, and compliance (GRC) analyst at Keeper Security sits down to share her story, from performer to cyber. She fell in love with writing as a young girl, she experimented with writing fanfiction which made her want to grow up to be in the arts. After attending college she found that she was good at math, lighting the way for her to start her cyber career. Teresa moved to being a writer at Keeper, finding she wanted to spread out and try more, so she ended up becoming an analyst while still doing writing on the side. She quotes David Duchovny in an interview once, explaining how sometimes you need to keep your head down and outwork others. Teresa said this resonated with her, saying, "that's how I went from a foreclosure box on the porch to where I am now. I have a good job and, and I have a career and I have a really good career and I absolutely love it." We thank Teresa for sharing her story.

Extract Knowledge

Marisa Atkinson, an analyst from Flashpoint, joins Dave to discuss a new blog post from Flashpoint’s research team about “RisePro” Stealer, malware from Russia, and Pay-Per-Install Malware “PrivateLoader.” “RisePro” is written in C++ and appears to possess similar functionality to the stealer malware “Vidar.” It's also a newly identified stealer, that began appearing as a stealer source for log credentials on the illicit log shop Russian Market on December 13, 2022.

The research states, "Samples that Flashpoint analysts identified indicate that RisePro may have been dropped or downloaded by the pay-per-install malware downloader service “PrivateLoader” in the past year." Analysts identified several sets of logs uploaded to the illicit underground Russian Market, which listed their source as “RisePro.”

The research can be found here:

Extract Knowledge
Show details
Episodes
3784
Transcripts
68
2% coverage
Missing transcripts
3716
With chapters
0