Search this show’s transcripts

CyberWire Daily

en us
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

Episodes

Page 31 · 50 per page

Security vulnerabilities in automobiles. CircleCI customers should "rotate their secrets." CISA Director Easterly notes Russian failures, but warns that shields should stay up. Attempted cyberespionage against US National Laboratories. Turla effectively recycles some commodity malware infrastructure. Robert M. Lee from Dragos shares his outlook on ICS for the new year. Our CyberWire Space correspondent Maria Varmazis interviews Diane Janosek from NSA about her research on space-cyber. And the Guardian continues to recover from last month's ransomware attack.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/4


Selected reading.

Hitachi Energy UNEM (CISA)

Hitachi Energy FOXMAN-UN (CISA)

Hitachi Energy Lumada Asset Performance Management (CISA) 

Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More (Sam Curry)

Toyota, Mercedes, BMW API flaws exposed owners’ personal info (BleepingComputer)

16 Car Makers and Their Vehicles Hacked via Telematics, APIs, Infrastructure (SecurityWeek)

Ferrari, BMW, Rolls Royce, Porsche and more fix vulnerabilities giving car takeover capabilities (The Record by Recorded Future)

CircleCI security alert: Rotate any secrets stored in CircleCI (CircleCI).

CircleCI warns of security breach — rotate your secrets! (BleepingComputer)

CircleCI Urges Customers to Rotate Secrets Following Security Incident (The Hacker News)

CISA director: US needs to be vigilant, ‘keep our shields up’ against Russia (The Hill)

Exclusive-Russian Hackers Targeted U.S. Nuclear Scientists (Reuters via US News) 

Notorious Russian Spies Piggybacked on Other Hackers' USB Infections (WIRED) 

Turla: A Galaxy of Opportunity | Mandiant (Mandiant) 

Fallout from Guardian cyber attack to last at least a month (ComputerWeekly)

State of Ransomware Preparedness (Axio)

Extract Knowledge

The PurpleUrchin freejacking campaign. Bluebottle activity against banks in Francophone Africa. The PyTorch framework sustains a supply-chain attack. 2022's ransomware leaderboard. Cellphone traffic as a source of combat information. FBI Cyber Division AD Bryan Vorndran on the interaction and collaboration of federal agencies in the cyber realm. Our guest Jerry Caponera from ThreatConnect wonders if we need more "Carrots" Than "Sticks" In Cybersecurity Regulation. And two incommensurable views of information security.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/3


Selected reading.

An analysis of the PurpleUrchin campaign. (CyberWire)

PurpleUrchin Bypasses CAPTCHA and Steals Cloud Platform Resources (Unit 42)

Bluebottle observed in the wild. (CyberWire)

Bluebottle: Campaign Hits Banks in French-speaking Countries in Africa (Symantec)

PyTorch incident disclosed, assessed. (CyberWire)

PyTorch dependency poisoned with malicious code (Register)

Compromised PyTorch-nightly dependency chain between December 25th and December 30th, 2022. (PyTorch)

Most active, impactful ransomware groups of 2022. (CyberWire)

2022 Year in Review: Ransomware (Trustwave)

Russia says phone use allowed Ukraine to target its troops (AP NEWS)

For Russian Troops, Cellphone Use Is a Persistent, Lethal Danger (New York Times)

Kremlin blames own soldiers for Himars barracks strike as official death toll rises (The Telegraph) 

No Water’s Edge: Russia’s Information War and Regime Security (Carnegie Endowment for International Peace)

Extract Knowledge

Ad practices draw a large EU fine (and may set precedents for online advertising). Updates on the LastPass breach, and on Russian cyber activity against Poland. Malek Ben Salem from Accenture explains smart deepfakes. Our guest is Leslie Wiggins, Program Director for Data Security at IBM Security on the role of the security specialist. And cellphones, opsec, and the Makiivka strike.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/2


Selected reading.

Meta’s Ad Practices Ruled Illegal Under E.U. Law (New York Times)

Meta Fined More Than $400 Million in EU for Serving Ads Based on Online Activity (Wall Street Journal)

Meta's New Year kicks off with $410M+ in fresh EU privacy fines (TechCrunch)

LastPass data breach: notes and actions to take. (CyberWire)

Poland warns of attacks by Russia-linked Ghostwriter hacking group (BleepingComputer) 

Russia says phone use allowed Ukraine to target its troops (AP NEWS)

Russian soldier gave away his position with geotagged social media posts (Task & Purpose)

Russian commanders blamed for heavy losses in New Year’s Day strike (Washington Post)

Extract Knowledge

Recent DPRK cyber operations: spying and theft. Twitter’s data incident. 3Commas breached. Poland warns of increased Russian offensive cyber activity. Port of Lisbon hit by ransomware. DHS announces SBIR topics. New additions to the Known Exploited Vulnerabilities Catalog. Ben Yelin on the legal conundrum of AI generated code. Our guest is Tanya Janca from She Hacks Purple with insights on API security. And, news flash! LockBit says they have a conscience. (Yeah, right.)


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/1


Selected reading.

Recent DPRK cyber operations: spying and theft. (CyberWire)

Twitter targeted in extortion hack. (CyberWire)

3Commas' API compromised. (CyberWire)

Russian cyberattacks (Special Services) 

LockBit activity over the holidays. (CyberWire)

CISA Adds Two Known Exploited Vulnerabilities to Catalog (CISA) 

DHS Small Business Innovation Research (SBIR) Program FY23 Solicitation (SAM.gov)

The SBIR and STTR Programs. (SBIR/STTR)

Extract Knowledge

Between the emergence of sophisticated nation-state actors, the rise of ransomware-as-a-service, the increasing attack surface remote work presents, and much more, organizations today contend with more complex risk than ever. A “Secure-by-Design” approach can secure software environments, development processes and products. That approach includes increasing training for employees, adopting zero trust, leveraging Red Teams, and creating a unique triple-build software development process. SolarWinds calls its version of this process the "Next-Generation Build System," and offers it as a model for secure software development that will make supply chain attacks more difficult.

On this episode of CyberWire-X, host Rick Howard, N2K’s CSO, and CyberWire’s Chief Analyst and Senior Fellow, discusses software supply chain lessons learned from the SolarWinds attack of 2020 with Hash Table members Rick Doten, the CISO for Healthcare Enterprises and Centene, Steve Winterfeld, Akamai's Advisory CISO, and Dawn Cappelli, Director of OT-CERT at Dragos, and in the second half of the show, Rick speaks with our episode sponsor, SolarWinds, CISO Tim Brown.

Extract Knowledge

On Thursday October 20, 2022, the CyberWire was pleased to host the annual Women in Cybersecurity Reception at the International Spy Museum in Washington, DC. This annual event brought together almost 300 people to highlight and celebrate the value and successes of women in the cybersecurity industry. The reception included an industry-led panel discussion called “The Hidden Impact of Cybersecurity’s Talent Gap on the Cyber-Enabled Community,” discussing cyber-enabled professionals who aren’t usually included in conversations around the cybersecurity skills gap. The panel, moderated by Simone Petrella of CyberVista, included perspectives from experts including Davida Gray of MindPoint Group, Jennifer Walsmith of Northrop Grumman, Kyla Guru of Bits N’ Bytes, and Amy Mushahwar from Alston & Bird.

Extract Knowledge
Published 2022-12-31

Encore: LemonDucks evading detection.

15 min
View

Scott Fanning from CrowdStrike's research team, joins Dave to discuss their work on "LemonDuck Targets Docker for Cryptomining Operations." LemonDuck is a well-known cryptomining botnet, and the research suggests attackers are attracted to the monetary gain from the recent boom in cryptocurrency.

LemonDuck was caught trying to disguise its attack against Docker by running an anonymous mining operation by the use of proxy pools. Scott shares how its unknown which organizations have been targeted and just how much cryptocurrency has been stolen.

The research can be found here:

Extract Knowledge

SHOW NOTES

This interview from October 28th, 2022 originally aired as a shortened version on the CyberWire Daily Podcast. In this extended interview, Dave Bittner sits down with Nick Schneider of Arctic Wolf to discuss why he believes 2023 will see a resurgence of ransomware and why the decline of crypto will not deter future ransomware actors.

Extract Knowledge

Thanks for joining us again for another episode of fun project brought to you by the team of Hacking Humans, the CyberWire's social engineering podcast. Hacking Humans co-host Dave Bittner is joined by Rick Howard in this series where they view clips from their favorite movies and television shows with examples of the social engineering scams and schemes you hear Dave and co-host Joe Carrigan talk about on Hacking Humans. In this episode, Dave and Rick watch each of the selected scenes, describe the on-screen action for you, and then they deconstruct what they saw. Grab your bowl of popcorn and join us for some fantastic scams and frauds.

On this episode, Dave and Rick are joined by guest contributor Amanda Fennell. You can find Amanda on Twitter at @Chi_from_afar.

Links to this episode's clips if you'd like to watch along:

Extract Knowledge

This interview from September 30th, 2022 originally aired as a shortened version on the CyberWire Daily Podcast. In this extended interview, Dave Bittner sits down with MK Palmore from Google Cloud to talk about why collective cybersecurity ultimately depends on having a diverse, skilled workforce.

Extract Knowledge

Merry Christmas and Happy Holidays from the CyberWire and our friends! Enjoy our rendition of the 12 Days of Malware created by Dave Bittner and performed by Dave and friends: Rachel Tobac, Jayson Street, Ron Eddings & Chris Cochran, Ray [Redacted], Dinah Davis, Camille Stewart, Rick Howard, Michelle Dennedy, Jack Rhysider, Johannes Ullrich, and Charity Wright. Ba dum bum bum. Sing along if you are game! Check out our video for the full effect!


The 12 Days of Malware lyrics

On the first day of Christmas, my malware gave to me:

A keylogger logging my keys.


On the second day of Christmas, my malware gave to me:

2 Trojan Apps...

And a keylogger logging my keys.


On the third day of Christmas, my malware gave to me:

3 Web shells...

2 Trojan Apps...

And a keylogger logging my keys.


On the fourth day of Christmas, my malware gave to me:

4 Crypto scams...

3 Web shells...

2 Trojan Apps...

And a keylogger logging my keys.


On the fifth day of Christmas, my malware gave to me:

5 Zero Days!

4 Crypto scams...

3 Web shells...

2 Trojan Apps...

And a keylogger logging my keys.


On the sixth day of Christmas, my malware gave to me:

6 Passwords spraying...

5 Zero Days!

4 Crypto scams...

3 Web shells...

2 Trojan Apps...

And a keylogger logging my keys.


On the seventh day of Christmas, my malware gave to me:

7 Scripts a scraping...

6 Passwords spraying...

5 Zero Days!

4 Crypto scams...

3 Web shells...

2 Trojan Apps...

And a keylogger logging my keys.


On the eighth day of Christmas, my malware gave to me:

8 Worms a wiping...

7 Scripts a scraping...

6 Passwords spraying...

5 Zero Days!

4 Crypto scams...

3 Web shells...

2 Trojan Apps...

And a keylogger logging my keys.


On the ninth day of Christmas, my malware gave to me:

9 Rootkits rooting...

8 Worms a wiping...

7 Scripts a scraping...

6 Passwords spraying...

5 Zero Days!

4 Crypto scams...

3 Web shells...

2 Trojan Apps...

And a keylogger logging my keys.


On the tenth day of Christmas, my malware gave to me:

10 Darknet markets...

9 Rootkits rooting...

8 Worms a wiping...

7 Scripts a scraping...

6 Passwords spraying...

5 Zero Days! (Bah-dum-dum-dum!)

4 Crypto scams...

3 Web shells...

2 Trojan Apps...

And a keylogger logging my keys.


On the eleventh day of Christmas, my malware gave to me:

11 Phishers phishing...

10 Darknet markets...

9 Rootkits rooting...

8 Worms a wiping...

7 Scripts a scraping...

6 Passwords spraying...

5 Zero Days! (Bah-dum-dum-dum!)

4 Crypto scams...

3 Web shells...

2 Trojan Apps...

And a keylogger logging my keys.


On the twelfth day of Christmas, my malware gave to me:

12 Hackers hacking...

11 Phishers phishing...

10 Darknet markets...

9 Rootkits rooting...

8 Worms a wiping...

7 Scripts a scraping...

6 Passwords spraying...

5 Zero Days!

4 Crypto scams...

3 Web shells...

2 Trojan Apps...

And a keylogger logging my keys.

Extract Knowledge
Published 2022-12-24

Encore: Vulnerabilities in IoT devices.

22 min
View

Dr. May Wang, CTO of IoT Security at Palo Alto Networks, joins Dave Bittner to discuss their findings detailed in Unit 42's "Know Your Infusion Pump Vulnerabilities and Secure Your Healthcare Organization" research. Unit 42 recently set out to better understand how well hospitals and other healthcare providers are doing in securing smart infusion pumps, which are network-connected devices that deliver medications and fluids to patients. This topic is of critical concern because security lapses in these devices have the potential to put lives at risk or expose sensitive patient data.

Unit 42's discovery of security gaps in three out of four infusion pumps that they reviewed highlights the need for the healthcare industry to redouble efforts to protect against known vulnerabilities, while diligently following best practices for infusion pumps and hospital networks. May walks us through Unit 42's work.

The research can be found here:

Extract Knowledge

The Vice Society may be upping its marketing game. Royal ransomware may have a connection to Conti. Royal delivers ransom note by hacked printer. KillNet goes after healthcare. CISA's Stakeholder Engagement Strategic Plan. Adam Meyers from CrowdStrike looks at cyber espionage. Giulia Porter from RoboKiller does not want to talk to you about your car’s extended warranty. And holiday wishes to all.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/245


Selected reading.

Custom-Branded Ransomware: The Vice Society Group and the Threat of Outsourced Development (SentinelOne)

Vice Society ransomware gang switches to new custom encryptor (BleepingComputer) 

Conti Team One Splinter Group Resurfaces as Royal Ransomware with Callback Phishing Attacks (Trend Micro)

Researchers Link Royal Ransomware to Conti Group (SecurityWeek)

Major Australian university dealing with suspected cybersecurity attack (7NEWS) 

Printers at Queensland's second-largest university spit out ransomware messages after cyber attack (ABC) 

Pro-Russian Hacktivist Group ‘KillNet’ Threat to HPH Sector (HC3)

HHS alert warns KillNet hacktivist group targeted US healthcare entity (SC Media) 

HC3 Analyst Note TLP Clear Pro-Russian Hacktivist Group Killnet Threat to HPH Sector December 22, 2022 | AHA (American Hospital Association)

 Strategic Plan for Stakeholder Engagement (CISA)

Extract Knowledge

The FBI warns of malicious advertising. A new gang makes an unwelcome appearance in the holiday season. Ukraine will receive more Starlink terminals after all. Cyber phases of the hybrid war: a view from Kyiv–the bears and their adjuncts are opportunistic agents of chaos. Caleb Barlow thinks boards of directors need to up their cyber security game. Our guest is AJ Nash from ZeroFox with a look at legislative restrictions on TikTok. And reports say that US National Cyber Director Chris Inglis is preparing to retire. We wish him the best of luck.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/244


Selected reading.

Cyber Criminals Impersonating Brands Using Search Engine Advertisement Services to Defraud Users (FBI)

A sophisticated fraud ring is waging war on commerce, using rapidly changing tactics (Signifyd)

Ukraine to Get Thousands More Starlink Antennas, Minister Says (Bloomberg)

Ukraine’s Cyber Units Aim to Retain Staff, Keep Services Stable as War Enters Year Two (Wall Street Journal)

Top Biden cybersecurity adviser to step down (CNN)

Chris Inglis to resign as national cyber director (CyberScoop).

First-ever national cyber director Chris Inglis set to retire in coming months: sources (Axios).

White House cyber adviser to resign  (The Hill)

Chris Inglis, Biden's top cyber adviser, plans to leave government in coming months (POLITICO).

White House Cyber Director Chris Inglis to Step Down (Bank Info Security)

Extract Knowledge

The Godfather banking Trojan has deep roots in older code. FuboTV was disrupted around its World Cup coverage. The Guardian has been hit with an apparent ransomware attack. A threat actor abuses AWS Elastic IP transfer. Moldova may be receiving more Russian attention in cyberspace. CISA releases six industrial control system advisories. Ben Yelin looks at legislation addressing health care security. Our guest is Hugh Njemanze of Anomali with advice on preparing for the holiday break. And criminals are impersonating other criminals' underworld souks.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/243


Selected reading.

Godfather: A banking Trojan that is impossible to refuse (Group-IB)

FuboTV outage during World Cup semifinal was caused by cyberattack (Record)

Guardian hit by serious IT incident believed to be ransomware attack (the Guardian) 

Elastic IP Hijacking — A New Attack Vector in AWS (Mitiga)

Telegram Hack Exposes Growing Russian Cyber Threat in Moldova (Balkan Insight)

Fuji Electric Tellus Lite V-Simulator (CISA)

Rockwell Automation GuardLogix and ControlLogix controllers (CISA)

ARC Informatique PcVue (CISA)

Rockwell Automation MicroLogix 1100 and 1400 (CISA)

Delta 4G Router DX-3021 (CISA)

Prosys OPC UA Simulation Server (CISA)

The scammers who scam scammers on cybercrime forums: Part 3 (Sophos News)

Extract Knowledge

SentinelSneak is out in the wild. XLLs for malware delivery. CERT-UA warns of attacks against the DELTA situational awareness system. FSB cyber operations against Ukraine. Trends in the cyber phases of Russia's hybrid war. Mr. Security Answer Person John Pescatore offers his sage wisdom. Microsoft’s Ann Johnson from Afternoon Cyber Tea speaks with Dr. Chenxi Wang from Rain Capital. And an unusually unpleasant sextortion campaign.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/242


Selected reading.

SentinelSneak is not a legitimate SDK. (CyberWire)

SentinelSneak: Malicious PyPI module poses as security software development kit (ReversingLabs)

Malicious Python Trojan Impersonates SentinelOne Security Client (Dark Reading)

Malicious ‘SentinelOne’ PyPI package steals data from developers (BleepingComputer)

Cisco research on XLL Abuse. (CyberWire)

Threat Spotlight: XLLing in Excel - threat actors using malicious add-ins (Cisco Talos Blog) 

Ukraine at D+299: Cyber operations 300 days into the war. (CyberWire)

Cyber Dimensions of the Armed Conflict in Ukraine (CyberPeace Institute)

Ukraine's DELTA military system users targeted by info-stealing malware (BleepingComputer)

Ukraine's Delta Military Intel System Hit by Attacks (Infosecurity Magazine)

Russia’s Trident Ursa (aka Gamaredon APT) Cyber Conflict Operations Unwavering Since Invasion of Ukraine (Unit 42)

FBI and Partners Issue National Public Safety Alert on Financial Sextortion Schemes | Federal Bureau of Investigation (Federal Bureau of Investigation)

HSI, federal partners issue national public safety alert on sextortion schemes (US Immigration and Customs Enforcement)

Extract Knowledge

BEC takes aim at physical goods (including food). BlackCat ransomware activity increases. Epic Games settles an FTC regulatory case. The InfraGard database was pulled from a dark web auction site. CISA releases forty-one ICS advisories. Rick Howard interviews author Andy Greenberg. Rob Boyce from Accenture examines holiday cyber threats. The growing value of open source intelligence. Twitter says vox populi, vox dei.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/241


Selected reading.

FBI, FDA OCI, and USDA Release Joint Cybersecurity Advisory Regarding Business Email Compromise Schemes Used to Steal Food (CISA)

Colombian energy supplier EPM hit by BlackCat ransomware attack (BleepingComputer)

Events D.C. data published online in apparent ransomware attack (Washington Post) 

Fortnite Video Game Maker Epic Games to Pay More Than Half a Billion Dollars over FTC Allegations of Privacy Violations and Unwanted Charges (Federal Trade Commission) 

Hacker Halts Sale of FBI's High-Profile InfraGard Database (HackRead) 

CISA Releases Forty-One Industrial Control Systems Advisories (Cybersecurity and Infrastructure Security Agency) 

Russia’s Wartime Cyber Operations in Ukraine: Military Impacts, Influences, and Implications (Carnegie Endowment for International Peace) 

How open-source intelligence has shaped the Russia-Ukraine war (GOV.UK)

Front-line video makes Ukrainian combat some of history’s most watched (Washington Post) 

Elon Musk Polls Twitter Users, Asking Whether He Should Step Down (Wall Street Journal)

Musk asks: Should I stay as CEO? (Computing)

Elon Musk’s Twitter Poll Shows Users Want Him to Step Down (Wall Street Journal) 

Elon Musk’s Twitter poll: 10 million say he should step down (the Guardian)

Extract Knowledge

With a recession looming, many business leaders are looking for ways to cut spending wherever possible. And while tool bloat affects many security teams, it can be a challenging problem to tackle for a couple of reasons. First, there’s the fear that security will be lost if a tool is removed. Second, there’s the daunting task of unraveling complex systems. And finally, there’s the perennial talent shortage. Like all challenges in security, they’re made even worse by the fact that there’s not enough people able to tackle them. 

During this CyberWire-X episode, host Rick Howard, the CyberWire’s CISO, Chief Analyst and Senior Fellow, speaks with Hash Table member Ted Wagner, the CSO of SAP National Security Services, and host Dave Bittner speaks with sponsor ExtraHop Senior Technical Marketing Manager Jamie Moles. They discuss solutions to help business and security leaders to not just address these challenges, but to get more out of their tooling as they do. They discuss strategies for how to determine which tools you actually need and which you can get rid of, as well as the step-change benefits that can be realized when you consolidate, automate, and integrate your security solutions.  

Extract Knowledge

Don Pezet, CTO of ACI Learning, sits down to share his over 25 years of experience in the industry. Don previously spent time as a field engineer in the financial and insurance industries supporting networks around the world. He co-founded ITProTV in 2012 to help create the IT training that he wished he had when he got started in his IT career. He also shares insights for anyone else wishing to pursue IT, no matter their age or past experience. Don explains how important stepping stones are as you get into this field, stating "know that that first job you get is probably not going to be the job you want to have your whole life, but it's a stepping stone that leads to where you want to get." Don started teaching on the side as well as working in the IT field and explains how much his teaching skills come in handy to help him with his leadership skills, which in turn helps him to be a better CTO, helping his customers. We thank Don for sharing his story.

Extract Knowledge

Or Katz from Akamai sits down with Dave to discuss research on highly sophisticated phishing scams and how they are abusing holiday sentiment. This particular threat, most recently has focused on Halloween deals, enticing victims with the chance to win a free prize, including from Dick’s Sporting Goods or Tumi Backpacks. It then requests credit card details to cover the cost of shipment.

From mid-September to the end of October 2022, Akamai's research were able uncover and track this threat. This kit mimics well known retail stores in hopes to hijack credit card information, feeding off of people's holiday spirit.

The research can be found here:

Extract Knowledge

A predatory loan app is discovered embedded in mobile apps. Facebook phishing. GPS disruptions are reported in Russian cities. NSA warns against dismissing Russian offensive cyber capabilities. Farewell, SHA-1. Kevin Magee from Microsoft looks at cyber signals. Our guest is Jason Witty of USAA to discuss the growing risk from quantum computing. And welcome to the world, Leviathans.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/240


Selected reading.

Zimperium teams discover new malware in Flutter developed apps (SecurityBrief Asia) 

Meta-Phish: Facebook Infrastructure Used in Phishing Attack Chain (Trustwave)

GPS Signals Are Being Disrupted in Russian Cities (WIRED) 

NSA cyber director warns of Russian digital assaults on global energy sector (CyberScoop)

Russia's cyber war machine in Ukraine hasn't lived up to Western hype. Report analyses why (ThePrint)

NIST Retires SHA-1 Cryptographic Algorithm (NIST)

Historic activation of the U.S. Army’s 11th Cyber Battalion (DVIDS) 

Extract Knowledge

Trojanized Windows 10 installers are deployed against Ukraine. Alleged booters have been collared, and their sites disabled. A progress report on US anti-ransomware efforts. Suspicion in a cyberattack against India turns toward China. Bryan Vorndran from the FBI’s Cyber Division talks about deep fakes. Our guest is Lisa Plaggemier from the National Cybersecurity Alliance (NCA) on the launch of their Historically Black Colleges and Universities Career Program. And hybrid war and fissures in the underworld.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/239


Selected reading.

Trojanized Windows 10 Operating System Installers Targeted Ukrainian Government (Mandiant)

Federal Prosecutors in Los Angeles and Alaska Charge 6 Defendants with Operating Websites that Offered Computer Attack Services (US Department of Justice)

Global crackdown against DDoS services shuts down most popular platforms | Europol (Europol) 

Readout of Second Joint Ransomware Task Force Meeting (Cybersecurity and Infrastructure Security Agency)

US finds its ‘center of gravity’ in the fight against ransomware (The Record by Recorded Future) 

AIIMS cyber attack may have originated in China, Hong Kong (The Times of India) 

AIIMS Delhi Servers Were Hacked By Chinese, Damage Contained: Sources (NDTV.com)

Russia-Ukraine war reaches dark side of the internet (Al Jazeera)

Extract Knowledge

The FBI’s InfraGard user data shows up for sale. An update on Iranian cyber operations. NSA warns of Chinese cyber threats. Challenges in sharing data for threat detection and prevention. Legitimately signed drivers are used in targeted attacks. Patch Tuesday addressed a lot of actively exploited issues. Tim Starks from the Washington Post Cybersecurity 202 shares his reporting on ICS vulnerabilities. Our guest is Mike Fey from Island with an introduction to the enterprise browser space. And the US indicts five Russian nationals on sanctions-evasion charges.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/238


Selected reading.

FBI’s Vetted Info Sharing Network ‘InfraGard’ Hacked (KrebsOnSecurity)

Would’ve, Could’ve, Should’ve…Did: TA453 Refuses to be Bound by Expectations (Proofpoint) 

APT5: Citrix ADC Threat Hunting Guidance (NSA)

U.S. agency warns that hackers are going after Citrix networking gear (Reuters)

NSA Outs Chinese Hackers Exploiting Citrix Zero-Day (SecurityWeek) 

Effect of data on Federal agencies' policies. (CyberWire)

I Solemnly Swear My Driver Is Up to No Good: Hunting for Attestation Signed Malware (Mandiant)

Driving Through Defenses | Targeted Attacks Leverage Signed Malicious Microsoft Drivers (SentinelOne)

SAP Security Patch Day December 2022 (Onapsis)

December 2022 Security Updates (Microsoft Security Response Center)

December Patch Tuesday Updates | 2022 - Syxsense Inc (Syxsense Inc)

Microsoft December 2022 Patch Tuesday fixes 2 zero-days, 49 flaws (BleepingComputer)

Microsoft Squashes Zero-Day, Actively Exploited Bugs in Dec. Update (Dark Reading) 

Microsoft fixes exploited zero-day, revokes certificate used to sign malicious drivers (CVE-2022-44698) (Help Net Security)

Microsoft Releases December 2022 Security Updates (CISA)

Apple security updates (Apple Support)

We finally know why Apple pushed out that emergency 16.1.2 update (Macworld) 

Why You Should Enable Apple’s New Security Feature in iOS 16.2 Right Now (Wirecutter)

Apple Releases Security Updates for Multiple Products (CISA)

Citrix ADC and Citrix Gateway Security Bulletin for CVE-2022-27518 (Citrix)

State-sponsored attackers actively exploiting RCE in Citrix devices, patch ASAP! (CVE-2022-27518) (Help Net Security) 

Citrix Releases Security Updates for Citrix ADC, Citrix Gateway (CISA)

VMware Patches VM Escape Flaw Exploited at Geekpwn Event (SecurityWeek) 

Experts detailed a previously undetected VMware ESXi backdoor (Security Affairs)

VMware Releases Security Updates for Multiple products (CISA)

Mozilla Releases Security Updates for Thunderbird and Firefox (CISA)

Adobe Patches 38 Flaws in Enterprise Software Products (SecurityWeek)

CISA Releases Three Industrial Control Systems Advisories (CISA)

Five Russian Nationals, Including Suspected FSB Officer, and Two U.S. Nationals Charged with Helping the Russian Military and Intelligence Agencies Evade Sanctions (US Department of Justice)

Russian Military and Intelligence Agencies Procurement Network Indicted in Brooklyn Federal Court (US Department of Justice)

Extract Knowledge

Uber sustains a third-party breach. A phishing campaign hits Ukrainian in-boxes. The enduring riddle of why Russian offensive cyber operations have failed in Ukraine. Joe Carrigan on credit card skimming. Carole Theriault describes a UK food store chain that uses facial recognition technology to track those with criminal or antisocial behavior. And 2023’s ransomware-as-a-service leader board.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/237


Selected reading.

Uber suffers new data breach after attack on vendor, info leaked online (BleepingComputer)

Uber has been hacked yet again with code and employee data released online (SiliconANGLE)

Uber hit by new data breach — what you need to know (Tom's Guide)

Uber’s data breach. (CyberWire)

Ukrainian railway, state agencies allegedly targeted by DolphinCape malware (The Record by Recorded Future)

Cyber Operations in Ukraine: Russia’s Unmet Expectations (Carnegie Endowment for International Peace) 

The most prolific ransomware groups of 2022 (Searchlight Security)

Extract Knowledge

TrueBot found in Cl0p ransomware attacks. Royal ransomware targets the healthcare sector. Recent Iranian cyber activity. A night at the opera: an update on the cyberattack against the Metropolitan Opera. New Cloud Atlas activity reported. Europe looks to the cybersecurity of its power grid. Rob Boyce from Accenture describes Dark web actors diversifying their toolsets. Rick Howard explains fractional CISOs. And international support for Ukrainian cyber defense continues, more extensively and increasingly overt.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/236


Selected reading.

Breaking the silence - Recent Truebot activity (Cisco Talos Blog)

New TrueBot Malware Variant Leveraging Netwrix Auditor Bug and Raspberry Robin Worm (The Hacker News) 

TrueBot infections were observed in Clop ransomware attacks (Security Affairs) 

Clop ransomware uses TrueBot malware for access to networks (BleepingComputer) 

Royal Ransomware (US Department of Health and Human Services)

US Dept of Health warns of ‘increased’ Royal ransomware attacks on hospitals (The Record by Recorded Future) 

Iran-Backed MuddyWater's Latest Campaign Abuses Syncro Admin Tool (Dark Reading)

MuddyWater Hackers Target Asian and Middle East Countries with Updated Tactics (The Hacker News)

New MuddyWater Campaign Uses Legitimate Remote Administration Tools to Deploy Malware (Cyber Security News)

Shows will go on at Met Opera despite cyber-attack that crashed network (ABC7 New York)

Cyberattack disrupts Metropolitan Opera (SC Media)

Cloud Atlas targets entities in Russia and Belarus amid the ongoing war in Ukraine (Check Point Research)

APT Cloud Atlas: Unbroken Threat (Positive Technologies)

European Electricity Sector Lacks Cyber Experts as Ukraine War Raises Hacking Risks (Wall Street Journal)

How the US has helped counter destructive Russian cyberattacks amid Ukraine war (The Hill) 

The Australian company training Ukrainian veterans in cybersecurity (Australian Financial Review)

How Proton intends to thwart Russian cybercensorship with its VPN (HiTech Wiki) 

Cyber Lessons Learned from the War in Ukraine (YouTube) 

War in Ukraine Dominated Cybersecurity in 2022 (CNET)

Extract Knowledge

Jameeka Aaron, Chief Information Security Officer at Auth0, a product unit of Okta, sits down to share her story following two different paths that led her to where she is today. Jameeka has 20 years of IT and cybersecurity experience and has mitigated security risks at Nike, the U.S. Navy, and now Auth0. She joined the Navy not knowing what she wanted to do after high school and ended up becoming a Radioman, which is now titled IT. She shares her experiences of challenges she faced being the youngest, and the only woman, and the only woman of color in her group. She followed two different paths, getting an education as well as being in the Navy, and started her career at Lockheed Martin Mission Systems in San Diego. She eventually found her way to Auth0 in 2018. She says "I realized cybersecurity folks can do anything, everywhere. We're everywhere, we're in every industry and so I started to kind of say, I wanna work on programs that are fun for me." We thank Jameeka for sharing her story.

Extract Knowledge

Historically, the U.S. government has relied almost solely on its own intelligence analysis to inform strategic decisions. This has been especially true surrounding geopolitical events and nation-level cybersecurity situations.

However, the explosion of assets being connected to the internet, along with the fact that most critical infrastructure is owned by private sector organizations, means that commercially developed cyber threat intelligence is being generated at a faster pace than ever before.

In the Russia/Ukraine conflict, we saw how commercially generated satellite intelligence played a critical role in alerting the public and ensuring our allies were ready for an invasion. At LookingGlass, we believe commercial threat intelligence can provide similar anticipatory insight – and that it can be shared more easily and quickly than intelligence generated solely by the U.S. government.

Ultimately, the public and private sectors need to work together to protect the interests of the American people. Currently, both private industry and academia are targeted by foreign adversaries, just as are government agencies. This means that commercial entities also have access to adversary tactics, techniques, and procedures (TTPs) and indicators of compromise, and they have that access from a different perspective, which is valuable intelligence for the government.

On this episode of CyberWire-X, host Rick Howard, the CyberWire’s CISO, Chief Analyst and Senior Fellow, speaks with Hash Table member Wayne Moore, CISO at Simply Business, and host Dave Bittner speaks with Bryan Ware, CEO at episode sponsor LookingGlass Cyber Solutions. They’ll discuss why the U.S. government needs commercial cyber threat intelligence now more than ever before and how both the public and private sectors will benefit from closer, trusted cyber partnerships. 

Extract Knowledge

AJ Nash from ZeroFox sits down with Dave to discuss Cybersecurity threats including social engineering attacks planned surrounding the Qatar 2022 World Cup. The research shares some of the key threats we might see while the World Cup is happening this year.

Researchers say "During the World Cup, there will likely be threat actors aiming to acquire personal information or monetary value through phishing and scams." In the research we can find how the venue host is preparing for these claims of attacks.

The research can be found here:

Extract Knowledge

Cobalt Mirage deploys Drokbk malware. Zombinder in the C2C market. Impersonation scams: that's not Ukraine’s Ministry of Digital Transformation. On the cyber front, nothing new. CISA releases three new ICS advisories. Caleb Barlow on attack surface management. Mike Hamilton from Critical Insight explains how state and local governments apply for the $1 billion allocated by the feds for cybersecurity funding. And criminals prey on other criminals.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/235


Selected reading.

Drokbk Malware Uses GitHub as Dead Drop Resolver (Secureworks)

Zombinder: new obfuscation service used by Ermac, now distributed next to desktop stealers (ThreatFabric)

Crypto Winter: Fraudsters Impersonate Ukraine’s Government to Steal NFTs and Cryptocurrency (DomainTools)

Danish defence ministry says its websites hit by cyberattack (Reuters)

Kela website hit by DoS attack (Yle)

Advantech iView (CISA) 

AVEVA InTouch Access Anywhere (CISA)

Rockwell Automation Logix controllers (CISA) 

The scammers who scam scammers on cybercrime forums: Part 1 (Sophos News) 

Cyber-criminals Scammed Each Other Out of Millions in 2022 (Infosecurity Magazine)

Extract Knowledge

The IT Army of Ukraine claims responsibility for DDoS against a Russian bank. North Korea exploits an Internet Explorer vulnerability. A new variant of Babuk ransomware has been reported. Blind spots in air-gapped networks. Rob Boyce from Accenture has insights on the most recent ransomware trends. Our guest is Nathan Howe from Zscaler with the latest on Zero Trust. And the hacking of cats and dogs.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/234


Selected reading.

IT Army of Ukraine Hit Russian Banking Giant with Crippling DDoS Attack (HackRead) 

Internet Explorer 0-day exploited by North Korean actor APT37 (Google)

Morphisec Discovers Brand New Babuk Ransomware Variant in Major Attack (PRWeb)

Bypassing air-gapped networks via DNS (Pentera) 

What to Know About an Unlikely Vector for Cyber Threats: Household Pets (Insurance Journal)

Extract Knowledge

Rackspace reacts to ransomware. Third-party incidents in New Zealand and the Netherlands. Russian intelligence goes phishing. Mustang Panda uses Russia's war as phishbait. A Malicious package is found in PyPi. Kevin Magee from Microsoft Canada shares thoughts on cybersecurity startups in an economic downturn. Our guest is IDology's Christina Luttrell to discuss how consumers feel about digital identity, fraud, security and data privacy. And a French-speaking investment scam.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/233


Selected reading.

Rackspace Technology Hosted Exchange Environment Update (Rackspace Technology) 

Multiple government departments in New Zealand affected by ransomware attack on IT provider (The Record by Recorded Future) 

Antwerp's city services down after hackers attack digital partner (BleepingComputer) 

Russian hacking group spoofed Microsoft login page of US military supplier: report (The Record by Recorded Future)

Mustang Panda Uses the Russian-Ukrainian War to Attack Europe and Asia Pacific Targets (BlackBerry) 

Inside the Face-Off Between Russia and a Small Internet Access Firm (New York Times) 

Apiiro’s AI engine detected a software supply chain attack in PyPI (Apiiro | Cloud-Native Application Security) 

Anatomizing CryptosLabs: a scam syndicate targeting French-speaking Europe for years (Group-IB)

Extract Knowledge

The FBI and CISA are releasing this alert to disseminate known Cuba Ransomware Group indicators of compromise and TTPs identified through FBI investigations.

FBI and CISA would like to thank BlackBerry, ESET, The National Cyber-Forensics and Training Alliance (NCFTA), and Palo Alto Networks for their contributions to this CSA.

AA22-335A Alert, Technical Details, and Mitigations

For a downloadable copy of IOCs, see AA22-335A.stix

Stopransomware.gov is a whole-of-government approach that gives one central location for ransomware resources and alerts.

Resource to mitigate a ransomware attack: CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide.

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge

A Chinese cyberespionage campaign is believed to be active in the Middle East. Poor quality control turns ransomware into a wiper, and a typo crashes a cryptojacker. A large DDoS attack is reported to have hit a Russian state-owned bank. Privateers compromise Western infrastructure to stage cyberattacks. Cyber operations against national morale. A look at the Vice Society. Ben Yelin on the growing concerns over TicTok. Ann Johnson from Afternoon Cyber Tea speaks with Charles Blauner about the evolution of the CISO role. And CISA has added an entry to its Known Exploited Vulnerabilities Catalog.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/232


Selected reading.

BackdoorDiplomacy Wields New Tools in Fresh Middle East Campaign (Bitdefender Labs) 

The Story of a Ransomware Turning into an Accidental Wiper | FortiGuard Labs (Fortinet Blog) 

Syntax errors are the doom of us all, including botnet authors (Ars Technica) 

Russia's No. 2 bank VTB suffers largest DDoS in history (Computing) 

Russia compromises major UK and US organisations to attack Ukraine (Lupovis) 

Russia’s online attacks target Ukrainians’ feelings (POLITICO) 

Vice Society: Profiling a Persistent Threat to the Education Sector (Unit 42)

CISA Adds One Known Exploited Vulnerability to Catalog (CISA)

Extract Knowledge

Wiper malware hits Russian targets. Microsoft sees an intensification of Russian cyber operations against Ukraine. State policy, privateering, or an APT side-hustle? The US Cyber Safety Review Board will investigate the Lapsu$ Group. Rackspace works to remediate a security incident. The Schoolyard Bully Trojan harvests credentials. Grayson Milbourne of OpenText Security Solutions on attacks on common open source dev libraries. Rick Howard looks at CISO career paths. And trends in ransomware: cybercrime succeeds when the gang runs like a business.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/231


Selected reading.

CryWiper: fake ransomware (Kaspersky).

CryWiper data wiper targets Russian courts and mayors' offices (Computing)

Never-before-seen malware is nuking data in Russia’s courts and mayors’ offices (Ars Technica)

Russian regions attacked by new wiper posing as ransomware (Cybernews)

Preparing for a Russian cyber offensive against Ukraine this winter (Microsoft On the Issues)

Russia coordinating Ukraine hacks with missiles, could increasingly target European allies, Microsoft warns (POLITICO)

Russia Is Boosting Its Cyber Attacks on Ukraine, Allies, Microsoft Says (Bloomberg.com) 

Hackers linked to Chinese government stole millions in Covid benefits (NBC News)

Cyber Safety Review Board to Conduct Second Review on Lapsus$ (US Department of Homeland Security)

Rackspace: Ongoing Exchange outage caused by security incident (BleepingComputer) 

Schoolyard Bully Trojan Facebook Credential Stealer (Zimperium)

The Professionalization of Ransomware: How Gangs Are Becoming Like Businesses (LookingGlass Cyber Solutions Inc.)

Extract Knowledge

Rohit Dhamankar from Fortra’s Alert Logic sits down with Dave Bittner to share his experiences as he navigates the industry. Rohit has over 15 years of security industry experience across product strategy, threat research, product management and development, and customer solutions. Before Alert Logic he served in Product roles for Live Oak Venture Capital at Infocyte and Razberi Technologies. He has previously worked in senior roles in several start-up companies in security analytics, intrusion detection/prevention, end-point protection, and security risk and compliance, including VP, Click Labs Solutions at Click Security, acquired by AlertLogic, and he was a Co-Founder of Jumpshot, acquired by Avast. Rohit shares the advise of never closing a door too prematurely, because you never know what could be behind the door waiting for you. We thank Rohit for sharing his story.

Extract Knowledge

Jeremy Kennelly and Sulian Lebegue from Mandiant sit down with Dave to discuss their research "From RM3 to LDR4: URSNIF Leaves Banking Fraud Behind? One of the oldest and most successful banking fraud malwares, URSNIF, which caused an estimated “tens of millions of dollars in losses”, has been discovered by researchers to have been re-tooled into a generic backdoor, dubbed “LDR4”.

This new varient was first observed in June 2022. Mandiant researchers believe that the same threat actors who operated the RM3 variant of URSNIF are likely behind LDR4. They say "given the success and sophistication RM3 previously had, LDR4 could be a significantly dangerous variant—capable of distributing ransomware—that should be watched closely."

The research can be found here:

Extract Knowledge

Cuba ransomware pulls in $60 million. CISA releases three ICS advisories. DDoSing the Vatican. Andrea Little Limbago from Interos on the implications of Albania cutting off diplomatic ties with Iran. Our space correspondent Maria Varmazis speaks with Brandon Bailey about Space Attack Research and Tactic Analysis matrix. And how Google supports Ukrainian startups in wartime.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/230


Selected reading.

Alert (AA22-335A) #StopRansomware: Cuba Ransomware (CISA)

Novel News on Cuba Ransomware: Greetings From Tropical Scorpius (Palo Alto Networks Unit 42)

New ways we're supporting Ukraine (Google)

25 new startup recipients of the Ukraine Support Fund (Google)

Vatican shuts down its website amid hacking attempts (Cybernews)

Extract Knowledge

A new backdoor, courtesy of the DPRK. The Medibank breach is all over but the shouting (or, all over but the suing and the arresting). Risks and opportunities in telecom’s shift to cloud. Cyber risk in healthcare. An assessment of Russian cyber warfare. Robert M. Lee from Dragos assesses the growing value of the ICS security market. Our guest is Cecilia Seiden of TransUnion to discuss their 2022 Consumer Holiday Shopping Report. And it’s December, which means…predictions.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/229


Selected reading.

Who’s swimming in South Korean waters? Meet ScarCruft’s Dolphin (ESET)

Medibank hackers announce ‘case closed’ and dump huge data file on dark web (the Guardian) 

New details on commercial spyware vendor Variston (Google)

Risks and opportunities in telecom’s shift to cloud. (CyberWire)

Moody’s discusses cyber risk in healthcare. (CyberWire)

'Do something:' Ukraine works to heal soldiers' mental scars (AP NEWS)

Reformed Russian Cybercriminal Warns That Hatred Spreads Hacktivism (Wall Street Journal)

Cybersecurity predictions for 2023. (CyberWire)

Extract Knowledge

Has LockBit 3.0 been reverse engineered? A COVID lure contains a Punisher hook. A Chinese cyberespionage campaign uses compromised USB drives. Lilac Wolverine exploits personal connections for BEC. Killnet claims to have counted coup against the White House. Tim Starks from the Washington Post has the FCC’s Huawei restrictions and ponders what congress might get done before the year end. Our guest is Tom Eston from Bishop Fox with a look Inside the Minds & Methods of Modern Adversaries. And, of course, scams, hacks, and other badness surrounding the World Cup.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/228


Selected reading.

LockBit 3.0 ‘Black’ attacks and leaks reveal wormable capabilities and tooling (Sophos News)

Punisher Ransomware Spreading Through Fake COVID Site (Cyble)

Always Another Secret: Lifting the Haze on China-nexus Espionage in Southeast Asia (Mandiant)

BEC Group Compromises Personal Accounts and Pulls Heartstrings to Launch Mass Gift Card Attacks (Abnormal Security)

Killnet Claims Attacks Against Starlink, Whitehouse.gov, and United Kingdom Websites (Trustwave)

Scammers on the pitch: Group-IB identifies online threats to fans at FIFA World Cup 2022 in Qatar (Group-IB)

Extract Knowledge

DDoS as a holiday-season threat to e-commerce. A TikTok challenge spreads malware. Meta's GDPR fine. Mr. Security Answer Person John Pescatore has thoughts on phishing resistant MFA. Joe Carrigan describes Intel’s latest efforts to thwart deepfakes. And US Cyber Command describes support for Ukraine's cyber defense.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/227


Selected reading.

Holiday DDoS Cyberattacks Can Hurt E-Commerce, Lack Legal Remedy (Bloomberg Law)

TikTok ‘Invisible Body’ challenge exploited to push malware (BleepingComputer) 

$275M Fine for Meta After Facebook Data Scrape (Dark Reading) 

Before the Invasion: Hunt Forward Operations in Ukraine (U.S. Cyber Command)

Extract Knowledge

Nighthawk’s at the diner (but maybe not on the crooks’ menu). Internet service in Ukraine and Moldova is interrupted by strikes against Ukraine's power grid. Sandworm renews ransomware activity against Ukrainian targets. Russian cyber-reconnaissance seen at a Netherlands LNG terminal. European Parliament votes to declare Russia a terrorist state (and Russia responds with cyberattacks and terroristic threats). Carole Theriault reports on where these kids today are getting their news. Malek Ben Salem from Accenture on digital identity in Web 3.0. And, hey, the new list of most commonly used passwords looks...depressingly familiar.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/226


Selected reading.

Sec firm MDSec slams Proofpoint for post on pen-testing framework (iTWire) 

Nighthawk: With Great Power Comes Great Responsibility - MDSec 

Cyberattack Hits Iran's Fars News Agency (RadioFreeEurope/RadioLiberty)

Iran’s Fars news agency is hit by cyberattacks, blames Israel (Times of Israel) 

Ukraine and Moldova suffer internet disruptions after Russian missile strikes (The Record by Recorded Future)

New ransomware attacks in Ukraine linked to Russian Sandworm hackers (BleepingComputer)

Russian hackers targeting Dutch gas terminal: report (NL Times) 

Russia labelled state sponsor of terrorism as missile strikes leave Ukraine without power (The Telegraph)

Killnet Group Claims Responsibility for European Parliament Cyber Attack (Digit)

European Parliament hit by 'sophisticated' cyberattack (Deutsche Welle)

European Parliament website suffers 'sophisticated' cyber attack after Russia terrorism vote (Computing)

Hackers Temporarily Take Down European Parliament Website (Wall Street Journal)

Guess the most common password. Hint: We just told you (Register)

Extract Knowledge

Laura Whitt-Winyard, CISO from Malwarebytes, sits down to share her story, beginning with a desire to be a pediatric oncologist that she later discovered was not the path for her. Laura was bouncing around from job to job until she bought her first computer, and a light bulb went off in her head. She set out to make it her goal to learn about this new, interesting field and grow within it. Now as a successful CISO, she wants to make the world more secure and goes from company to company to complete her goal. She considers herself a servant leader whose goal is the greater good. She compares her role to football, explaining that she is not the quarterback, but the center for the team. She believes she is the center that paves the path for the quarterbacks on her team to reduce the noise, to give the quarterback all the tools that they need to do their jobs and do their jobs well. We thank Laura for sharing her story.

Extract Knowledge
Published 2022-11-26

Encore: The secrets behind Docker.

20 min
View

Alon Zahavi from CyberArk, joins Dave Bittner on this episode to discuss CyberArk's work in conjunction with Patch Tuesday. CyberArk published about how Docker inadvertently created a new vulnerability and what happens when it's exploited.

CyberArk's research concluded that an attacker may execute files with capabilities or setuid files in order to escalate its privileges up to root level. CyberArk found the new vuln in some of Microsoft’s Docker images, caused by misuse of Linux capabilities, a powerful additional layer of security that gives admins the ability to assign capabilities and privileges to processes and files in the Linux system

The research can be found here:

Extract Knowledge

This interview is from June 3rd, 2022 originally aired as a shortened version on the CyberWire Daily Podcast. In this extended interview, Dave Bittner sits down Perry Carpenter, host of 8th Layer Insights to discuss his new book "The Security Culture Playbook: An Executive Guide To Reducing Risk and Developing Your Human Defense Layer."

Extract Knowledge

Another pentesting tool may soon be abused by threat actors. Cyberattack disrupts Guadeloupe. Ducktail evolves and expands. Warning of the potential disruption cyberattacks might work against European ports. CISA releases eight industrial control system advisories. Patrick Tiquet, VP of Security and Architecture at Keeper Security, talks about the FedRAMP authorization process. Bryan Vorndran of the FBI Cyber Division with reflections on ransomware. And stay safe on Black Friday (and Cyber Monday, and Panic Saturday, and…you get the picture.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/225


Selected reading.

Nighthawk: An Up-and-Coming Pentest Tool Likely to Gain Threat Actor Notice (Proofpoint)

Making Cobalt Strike harder for threat actors to abuse (Google Cloud Blog)

Guadeloupe government fights 'large-scale' cyberattack (AP NEWS)

Vietnam-Based Ducktail Cybercrime Operation Evolving, Expanding (SecurityWeek)

Cyber as important as missile defences - ex-NATO general (Reuters)

CISA Releases Eight Industrial Control Systems Advisories (CISA) 

Black Friday and Cyber Monday risks. (CyberWire)

Extract Knowledge

Daixin Team claims ransomware attack against AirAsia. DraftKings users suffer credential harvesting and paycard theft. Assessing cyber risk in the US pharmaceutical industry. Killnet claims successes few others can discern. In Ukraine, kinetic attacks on IT infrastructure eclipse cyberattacks. Carole Theriault on digital echo chambers and what's in it for us. Nancy Wang from Forta's Alert Logic discusses how she is helping more young women get into the STEM field and leadership positions. Google seeks to render Cobalt Strike less useful to threat actors.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/224


Selected reading.

Daixin Team claims AirAsia ransomware attack with five million customer records leaked (Tech Monitor)

Daixin Ransomware Gang Steals 5 Million AirAsia Passengers' and Employees' Data (The Hacker News)

DraftKings Users Hacked, Money In Account "Cashed Out" (Action Network)

DraftKings says no evidence systems were breached following report of a hack (CNBC)

Assessing cyber risk in the US pharmaceutical industry. (CyberWire)

Killnet DDoS hacktivists target Royal Family and others (ComputerWeekly.com) 

Ukraine Data Centers Became Physical Targets When Cyber Attacks Failed (Meritalk)

Making Cobalt Strike harder for threat actors to abuse (Google Cloud Blog)

Google seeks to make Cobalt Strike useless to attackers (Help Net Security) 

Google Releases YARA Rules to Disrupt Cobalt Strike Abuse (Dark Reading)

Google releases 165 YARA rules to detect Cobalt Strike attacks (BleepingComputer)

Extract Knowledge

Luna Moth's callback phishing offers an unpleasant and less familiar form of social engineering. New activity by China's Mustang Panda is reported. DEV0569 is using malvertising to distribute Royal ransomware. US indicts 10 in a business email compromise case. Developing a cyber auxiliary. Dave Bittner sits down with AJ Nash from ZeroFox to discuss holiday scams. Our own Rick Howard speaks with us about cloud security. And beware of Black Friday scams.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/223


Selected reading.

Threat Assessment: Luna Moth Callback Phishing Campaign (Unit 42) 

DEV-0569 finds new ways to deliver Royal ransomware, various payloads (Microsoft Security) 

Earth Preta Spear-Phishing Governments Worldwide (Trend Micro) 

EXCLUSIVE: Rounding up a cyber posse for Ukraine (The Record by Recorded Future) 

Tech for good: How the IT industry is helping Ukraine (Computing) 

10 Charged in Business Email Compromise and Money Laundering Schemes Targeting Medicare, Medicaid, and Other Victims (US Department of Justice) 

Black Friday and Cyber Monday risks. (CyberWire)

Extract Knowledge
Show details
Episodes
3784
Transcripts
68
2% coverage
Missing transcripts
3716
With chapters
0