Search this show’s transcripts

CyberWire Daily

en us
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

Episodes

Page 32 · 50 per page

Omer Singer, Lead Cybersecurity Strategist from Snowflake, sits down to share his experience getting into the cybersecurity field. Growing up, he knew he wanted to work with computers, but he just didn't know what he wanted to do within the field. His college gave him great hands-on experience to then transition into the workforce. He's played both on the offense and defense of cybersecurity, and he says that experience showed him and he "kind of saw firsthand, uh, what a well funded and motivated, uh, team of cybersecurity experts can do and it's pretty scary." In addition, Omer is a big advocate for encouraging other security professionals to learn data skills, and strongly stands by the belief that the future of cybersecurity is in borrowing from modern data analytics tools and techniques that enable consistent risk reduction. He also makes it a priority to invest in his people, believing that this unlocks intrinsic motivation that enables a ton of personal growth and accomplishment, and is a big believer in the OKR system for enabling security operations and avoiding burnout. We thank Omer for sharing his story.

Extract Knowledge

Larry Cashdollar, Principal Security Intelligence Response Engineer from Akamai Technologies, joins Dave to talk about their research on "KmsdBot: The Attack and Mine Malware." Akamai's Security Research team has found a new malware that infected their honeypot, which they have dubbed KmsdBot. 

The research states "The malware attacks using UDP, TCP, HTTP POST, and GET, along with a command and control infrastructure (C2), which communicates over TCP." The botnet targets weak login credentials and then infects systems via an SSH connection.

The research can be found here:

Extract Knowledge

CISA and its partners issue a Joint Advisory on the Hive ransomware-as-a-service operation. Ransomware continues to trouble governments, internationally and at all levels. The US Defense Department may see enhanced authority to conduct offensive cyber operations. Russian attacks on Ukrainian infrastructure remain kinetic, as missiles show up, but cyberattacks don’t. Kevin Magee from Microsoft about leveraging cybersecurity apprentices. Our guest is Paul Giorgi from XM Cyber describing creative attack path in enterprise networks.And, hey, glupost’ [GLUE-post]–don’t mess with Google’s lawyers.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/222


Selected reading.

CISA Alert AA22-321A – #StopRansomware: Hive Ransomware. (CyberWire)

#StopRansomware: Hive Ransomware (CISA)

Vanuatu: Hackers strand Pacific island government for over a week (BBC News)

Ransom attack cripples Vanuatu government systems, forces staff to use pen and paper (The Sydney Morning Herald)

Ransomware incidents now make up majority of British government’s crisis management COBRA meetings (The Record by Recorded Future)

Suffolk County, N.Y., Hack Shows Ransomware Threat to Municipalities (Wall Street Journal) 

Biden set to approve expansive authorities for Pentagon to carry out cyber operations (CyberScoop)

Red Lion Crimson (CISA)

Cradlepoint IBR600 (CISA)

A ruling in our legal case against the Glupteba botnet (Google)

Extract Knowledge

The FBI, CISA, and the Department of Health and Human Services are releasing this alert to disseminate known Hive Ransomware Group indicators of compromise and TTPs identified through FBI investigations.

AA22-321A Alert, Technical Details, and Mitigations

Stopransomware.gov is a whole-of-government approach that gives one central location for ransomware resources and alerts.

Resource to mitigate a ransomware attack: CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide.

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge

Meta employees, contractors compromised customer accounts. Nemesis Kitten found in US Government network. Unpatched Magento instances hit with "TrojanOrders." Emotet has returned after three quiet months. DDoS attacks in game servers by RapperBot. Carole Theriault looks at long term lessons learned from the 2019 Capital One breach. FBI Cyber Division AD Bryan Vorndran updates us on cyber threats. And an alleged "Zeus" cybercrime boss has been arrested in Switzerland.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/221


Selected reading.

Meta Employees, Security Guards Fired for Hijacking User Accounts (Wall Street Journal)

CISA Alert AA22-320A – Iranian government-sponsored APT actors compromise federal network, deploy crypto miner, credential harvester. (CyberWire)

Iranian Government-Sponsored APT Actors Compromise Federal Network, Deploy Crypto Miner, Credential Harvester (CISA)

Iranian government-linked hackers got into Merit Systems Protection Board’s network (Washington Post)

Iranian hackers compromise US government network in cryptocurrency generating scheme, officials say (CNN)

Magento stores targeted in massive surge of TrojanOrders attacks (BleepingComputer) 

A Comprehensive Look at Emotet’s Fall 2022 Return (Proofpoint) 

Notorious Emotet botnet returns after a few months off (Register) 

Updated RapperBot malware targets game servers in DDoS attacks (BleepingComputer) 

Russia’s cyber forces ‘underperformed expectations’ in Ukraine: senior US official (The Hill)

Suspected Zeus cybercrime ring leader ‘Tank’ arrested by Swiss police (BleepingComputer)

Extract Knowledge

Blockchains and cryptocurrency exchanges, and the risks they present. Vulnerabilities in Amazon RDS may expose PII. A study of the language of fraud. Tim Starks from Washington Post's Cybersecurity 202 on a lagging DHS cyber doomsday report. Our guest is Ashif Samnani of Cenovus Energy with insights from the world of OT cyber. And President Zelenskyy offers the benefit of Ukraine's experience with cyber warfare to the "G19”.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/220


Selected reading.

Cryptocurrency sector vulnerabilities. (CyberWire)

Oops, I Leaked It Again — How Mitiga Found PII in Exposed Amazon RDS Snapshots (Mitiga)

Amazon RDS may expose PII. (CyberWire)

The specious language of fraud. (CyberWire)

Zelensky offers G20 leaders to use Ukrainian experience in cyber defense (Ukrinform) 

Ukraine at D+265: A missile campaign punctuates diplomacy. (CyberWire)

Extract Knowledge

From mid-June through mid-July 2022, CISA conducted an incident response engagement at a Federal Civilian Executive Branch organization where CISA observed suspected advanced persistent threat activity. In the course of incident response activities, CISA determined that cyber threat actors exploited the Log4Shell vulnerability in an unpatched VMware Horizon server, installed XMRig crypto mining software, moved laterally to the domain controller, compromised credentials, and then implanted Ngrok reverse proxies on several hosts to maintain persistence.

AA22-320A Alert, Technical Details, and Mitigations

Malware Analysis Report MAR 10387061-1.v1

For more information on Iranian government-sponsored Iranian malicious cyber activity, see CISA’s Iran Cyber Threat Overview and Advisories webpage and FBI’s Iran Threats webpage.

CISA offers several no-cost scanning and testing services to help organizations reduce their exposure to threats by taking a proactive approach to mitigating attack vectors. See www.cisa.gov/cyber-hygiene-services

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge

Fangxiao works ad scams enroute to other compromises. Killnet claims to have defaced a US FBI site. CISA registers another Known Exploited Vulnerability. Difficulties with Twitter's SMS 2FA system. Zendesk vulnerability discovered. Joe Carrigan explains registration bombing for email addresses. Our guest is Miles Hutchinson from Jumio with insights on defense against sophisticated ransomware attackers. And Billbug romps through Asian government agencies.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/219


Selected reading.

Fangxiao: a Chinese threat actor (Cyjax)

Fangxiao: A Phishing Threat Actor (Tripwire) 

Russian hackers claim cyber attack on FBI website (Newsweek) 

CISA Has Added One Known Exploited Vulnerability to Catalog (CISA)

Twitter’s SMS Two-Factor Authentication Is Melting Down (WIRED)

Varonis Threat Labs Discovers SQLi and Access Flaws in Zendesk (Varonis)

Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries (Symantec)

Chinese hackers target government agencies and defense orgs (BleepingComputer) 

Researchers Say China State-backed Hackers Breached a Digital Certificate Authority (The Hacker News)

Extract Knowledge

Software supply chain risk. Cyber risk across sectors. CISA releases Stakeholder Specific Vulnerability Categorization (SSVC). Sandworm is back in Russia's hybrid war. Another wiper campaign from a Russian cyber auxiliary. Malek Ben Salem from Accenture shares thoughts on future-proofing cloud security. Rick Howard previews the latest CSO Perspectives show. And the Australian Federal Police say they know who hacked Medibank. (and the AFP says they have a good track record getting international criminals).


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/218


Selected reading.

Exclusive: Russian software disguised as American finds its way into U.S. Army, CDC apps (Reuters) 

Industries boost cyber defenses against growing number of attacks (Moodys) 

CISA Releases SSVC Methodology to Prioritize Vulnerabilities (CISA)

Transforming the Vulnerability Management Landscape (CISA)

Russian Sandworm hackers deployed malware in Ukraine and Poland (Washington Post)

New “Prestige” ransomware impacts organizations in Ukraine and Poland (Microsoft)

Microsoft links Russia’s military to cyberattacks in Poland and Ukraine (Ars Technica)

Microsoft attributes ‘Prestige’ ransomware attacks on Ukraine and Poland to Russian group (The Record by Recorded Future)

Wipe it or exfiltrate? How Russia exploits edge infrastructure to disrupt and spy during wartime (SC Media)

Russia’s New Cyberwarfare in Ukraine Is Fast, Dirty, and Relentless (WIRED)

Russian military hackers linked to ransomware attacks in Ukraine (BleepingComputer) 

Information on cyberattacks of the group UAC-0118 (FRwL) using the Somnia malware (CERT-UA#5185) (CERT-UA)

Ukraine says Russian hacktivists use new Somnia ransomware (BleepingComputer) 

Russian hacktivists hit Ukrainian orgs with ransomware - but no ransom demands (Help Net Security)

Development of the Ukrainian Cyber Counter-Offensive (Trustwave) 

Australian Federal Police say cybercriminals in Russia behind Medibank hack (The Record by Recorded Future)

Australia tells Medibank hackers: 'We know who you are' (TechCrunch)

Extract Knowledge

Lauren Campanara, a SOC Analyst from ThreatX shares her story as she made the decision to break into cybersecurity after spending twelve years in the cosmetology field. She worked her way through college in a job she did not enjoy and felt trapped in while competing her online degree. She found ThreatX and fell in love with the work she is doing now. Lauren hopes to inspire others, especially women, to consider a challenging and rewarding career in cybersecurity. She shares what it's like to be in a field she was not happy in and how she was the only one standing in her way to achieve her goals. She says "Another huge obstacle worth mentioning is learning to get out of my own way. You are your own worst critic. I learned to be more forgiving of myself." She hopes her story will inspire others to follow their dreams and stop holding themselves back.

Extract Knowledge

Deepen Desai from Zscaler sits down with Dave to talk about the Crytox ransomware family. First observed in 2020, Crytox is a ransomware family consisting of several stages of encrypted code that has fallen under the radar compared to other ransomware families. While other groups normally use double extortion attacks where data is both encrypted and held for ransom, Crytox does not perform this way.

The research says "The modus operandi of the group is to encrypt files on connected drives along with network drives, drop the uTox messenger application and then display a ransom note to the victim." It also shares how you may be compromised with this ransomware and goes through each stage in depth.

The research can be found here:

Extract Knowledge

There’s no sign that cyberattacks affected US vote counts. NATO meets to discuss the Atlantic Alliance’s Cyber Defense Pledge. A new APT41 subgroup has been identified. FSB phishing impersonates Ukraine's SSCIP. A look at Cozy Bear's use of credential roaming. Caleb Barlow shares tips on removing implicit bias from your hiring process. Our guests are Valerie Abend and Lisa O'Connor from Accenture with a look at the difference in how women and men pursue the top cyber leadership roles. And an update on Phishing trends and API threats.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/217


Selected reading.

Statement from CISA Director Easterly on the Security of the 2022 Elections (Cybersecurity and Infrastructure Security Agency):

No ‘Specific or Credible’ Cyber Threats Affected Integrity of Midterms, CISA Says (Nextgov.com)

U.S. vote counting unaffected by cyberattacks, officials say (PBS NewsHour) 

What's 'Putin's chef' cooking up with talk on US meddling? (AP NEWS)

NATO’s 2022 Cyber Defense Pledge Conference - United States Department of State (United States Department of State)

Japan joins NATO cyber defense centre (Telecoms Tech News)

China casts wary eye as Japan signs up for Nato cybersecurity platform (South China Morning Post) 

Hack the Real Box: APT41’s New Subgroup Earth Longzhi (Trend Micro)

New hacking group uses custom 'Symatic' Cobalt Strike loaders (BleepingComputer)

They See Me Roaming: Following APT29 by Taking a Deeper Look at Windows Credential Roaming (Mandiant)

APT29 Exploited a Windows Feature to Compromise European Diplomatic Entity Network (The Hacker News)

CAUTION‼️ russian hackers are sending emails with malicious links from the SSSCIP (State Service of Special Communications and Information Protection of Ukraine) 

Russian hackers send out emails under the name of Ukraine's State Service of Special Communications and Information Protection (Yahoo)

Research Report | The State of Email Security 2022 (Tessian) 

DevOps Tools & Infrastructure Under Attack (Wallarm)

Extract Knowledge

US midterm elections proceed without cyber disruption. Communications security lessons learned. CISA publishes new entries to its Known Exploited Vulnerabilities Catalog. Patch Tuesday notes. Carole Theriault examines cross border money laundering. The FBI’s Bryan Vorndran offers guidance on how companies should think about their exposure in china. And a recent study finds reasons to be concerned about off-boarding.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/216


Selected reading.

Taking a look at election security on US midterm Election Day. (CyberWire)

Communications Security: Lessons Learned From Ukraine (BlackBerry)

CISA Adds Seven Known Exploited Vulnerabilities to Catalog (CISA)

Microsoft November 2022 Patch Tuesday (SANS Institute) 

November Patch Tuesday Updates | 2022 (Syxsense Inc) 

Microsoft Fixes Six Actively Exploited Flaws (Decipher) 

Microsoft fixes ProxyNotShell Exchange zero-days exploited in attacks (BleepingComputer)

Microsoft Scrambles to Thwart New Zero-Day Attacks (SecurityWeek) 

Infrastructure access and security. (CyberWire)

Extract Knowledge

Cybersecurity on US Election Day. Details on the OPERA1ER threat activity. Seasonal and secular trends in Insider threats. Hacktivist auxiliaries: influence operators in the hybrid war. Ben Yelin reviews election security and misinformation. Ann Johnson from Afternoon Cyber Tea speaks with Dr. Ryan Louie about the growing issue of mental illness among cybersecurity professionals. And, hey everybody, Mr. Hushpuppi is back in the news (and back in the slammer, the hoosgow, the big house…you get the picture…a sabbatical at Club Fed.)

Disclaimer: The content and views expressed do not constitute medical advice and are not a substitute for professional medical advice, diagnosis, or treatment. If you need help, please contact your medical provider. 


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/215


Selected reading.

Your Election Day cyber guide (Washington Post) 

Putin-linked businessman admits to US election meddling (AP NEWS)

OPERA1OR: Playing god without permission (Group-IB) 

DTEX i3 Team Insider Risk Stats for 2022 (DTEX Systems Inc) 

Killnet targets Eastern Bloc government sites, but fails to keep them offline (The Record by Recorded Future)

Ukrainian hacktivists claim to leak trove of documents from Russia’s central bank (The Record by Recorded Future)

Notorious Nigerian influencer ‘Billionaire Gucci Master’ sentenced to 11 years in jail in the U.S. for fraud (Forbes)

Hushpuppi: Notorious Nigerian fraudster jailed for 11 years in US (BBC)

Extract Knowledge

Election security on the eve of the US midterms. US FBI rates hacktivist contributions to Russia's war as unimportant. Microsoft accuses China of using vulnerability disclosure to develop zero-days. Andrea Little Limbago from Interos addresses accountability for breaches. Our guest is Michelle Amante from the Partnership for Public Service on their Cybersecurity Talent Initiative. And, finally, remember SIlk Road? The Feds do.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/214


Selected reading.

Hacktivists Use of DDoS Activity Causes Minor Impacts (FBI)

The government says it won’t flag election disinformation on Twitter and other social platforms (Washington Post)

What to Expect When You are Expecting an Election (CISA)

Hacktivists Use of DDoS Activity Causes Minor Impacts (FBI) 

Nation-state cyberattacks become more brazen as authoritarian leaders ramp up aggression (Microsoft On the Issues) 

U.S. Attorney Announces Historic $3.36 Billion Cryptocurrency Seizure And Conviction In Connection With Silk Road Dark Web Fraud (U.S. Attorney’s Office for the Southern District of New York)

Extract Knowledge

Gary Brickhouse, CISO from GuidePoint Security, sits down to share his story, looking back over the last 25 years of his career working for Fortune 100 companies, including Disney. He shares that every role he has had, he’s had to grow into and how each one was a pivotal point in his technical career. Gary ended up transitioning to a different organization and says how it was really compliance that was the transitional sort of moment for him as he grew into different roles. He says, “What I found was sort of just, riding the wave of growth and opportunity and trying to take advantage of it along the way." He shares some advice for new people entering the industry, saying that he wants to help shatter the myth that you have to be technical to get into this field. We thank Gary for sharing his story.

Extract Knowledge

Roya Gordon from Nozomi Networks sits down with Dave to discuss their work "UWB Real Time Locating Systems: How Secure Radio Communications May Fail in Practice." Ultra-wideband (UWB) is a rapidly-growing radio technology that, according to the UWB Alliance, is forecasted to drive sales volumes exceeding one billion devices annually by 2025.

In an effort to strengthen the security of devices utilizing UWB, Nozomi Networks Labs conducted a security assessment of two popular UWB RTLS solutions available on the market. Their research reveals 0-day vulnerabilities and other weaknesses that, if exploited, could allow an attacker to gain full access to all sensitive location data exchanged over-the-air.

The research can be found here:

Extract Knowledge

Flight-planning services are affected by cyberattack, as are Danish rail service. A BEC gang impersonates international law firms. Effects of the hybrid war on action in cyberspace. Deepen Desai from Zscaler examines the evolution of the X-FILES Stealer. CyberWire Space Correspondent Maria Varmazis has an analysis of the Starlink situation in Ukraine. And a sad, final farewell to Vitali Kremez, gone far too soon.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/213


Selected reading.

Boeing subsidiary Jeppesen's services impacted by cyber incident (Reuters)

BREAKING: Boeing's Jeppesen Subsidiary Hit With Potential Ransomware Attack (Live and Let's Fly)

Danish train standstill on Saturday caused by cyber attack (Reuters)

Cyber incident at Boeing subsidiary causes flight planning disruptions (The Record by Recorded Future)

Crimson Kingsnake: BEC Group Impersonates International Law Firms in… (Abnormal Security)

New Crimson Kingsnake gang impersonates law firms in BEC attacks (BleepingComputer) 

Ukraine war, geopolitics fuelling cybersecurity attacks -EU agency (Reuters) 

Microsoft Extends Aid for Ukraine's Wartime Tech Innovation (SecurityWeek) 

Evaluating the International Support to Ukrainian Cyber Defense (Carnegie Endowment for International Peace)

Cyber community mourns renowned researcher Vitali Kremez (The Record by Recorded Future)

Remembering Vitali Kremez, Threat Intelligence Researcher (Bank Info Security)

Extract Knowledge

Leveraging Microsoft Dynamics 365 Customer Voice for credential harvesting. Emotet is back. Black Basta ransomware linked to Fin7. A Russophone gang increases activity against Ukrainian targets. Betsy Carmelite from Booz Allen Hamilton on adversary-informed defense. Our guest is Tom Gorup of Alert Logic with a view on cybersecurity from a combat veteran. And Russia regrets that old US lack of cooperation in cyberspace–things would be so much better if the Anglo-Saxons didn’t think cyberspace was the property of the East India Company. Or something like that.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/212


Selected reading.

Abusing Microsoft Customer Voice to Send Phishing Links (Avanan) 

Emotet botnet starts blasting malware again after 5 month break (BleepingComputer) 

Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor (SentinelOne) 

RomCom Threat Actor Abuses KeePass and SolarWinds to Target Ukraine and Potentially the United Kingdom (BlackBerry) 

Russia cyber director warns no U.S. cooperation risks "mutual destruction" (Newsweek)

Extract Knowledge

OpenSSL patches two vulnerabilities. CISA and election security. Killnet attempted DDoS against the US Treasury. XDR data reveals threat trends. Business email compromise and gift cards. Tim Starks from the Washington Posts’ Cybersecurity 202 has the latest on election security. A visit to the CyberWire’s Women in Cyber Security event. And consequences for Raccoon Stealer from the war in Ukraine.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/211


Selected reading.

OpenSSL patched today. (CyberWire)

OpenSSL Releases Security Update (CISA) 

OpenSSL releases fixes for two ‘high’ severity vulnerabilities (The Record by Recorded Future)

OpenSSL patches are out – CRITICAL bug downgraded to HIGH, but patch anyway! (Naked Security)

Threat Advisory: High Severity OpenSSL Vulnerabilities (Cisco Talos Blog)

OpenSSL Vulnerability Patch Released (Sectigo® Official)

Clearing the Fog Over the New OpenSSL Vulnerabilities (Rezilion)

OpenSSL vulnerability CVE-2022-3602 (Remote Code Execution) and CVE-2022-3786 (Denial of Service) Check Point Research Update (Check Point Software)

Undisclosed OpenSSL vulnerability: Free scripts for target scoping (Lightspin)

Discussions of CISA’s part in elections and the JCDC. (CyberWire)

U.S. Treasury thwarted attack by Russian hacker group last month-official (Reuters) 

XDR data reveals threat trends. (CyberWire)

What happens to a gift card given to a scammer? (CyberWire)

How Russia’s war in Ukraine helped the FBI crack one of the biggest cybercrime cases in years (MarketWatch)

Extract Knowledge

OpenSSL is patched today. The misconfiguration risk to US government networks' security and compliance. Hacking Ms Truss's phone. Assistance for Ukraine's cyber defense. Joe Carrigan looks at the latest round of apps pulled from the Google Play Store. Our guest is Matias Madou of Secure Code Warrior on why cultivating a positive culture among security and developer teams continues to fall short. And a quick look at DNS threats.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/210


Selected reading.

Effectively Preparing for the OpenSSL 3.x Vulnerability (Akamai) O

How The OpenSSL 3 Vulnerability Will Really Affect Your Environment (Nucleus Security) 

New Critical Flaw in OpenSSL: How to Know if You're at Risk (Rezilion)

Experts warn of critical security vulnerability discovered in OpenSSL (Application Security Blog)

The impact of exploitable misconfigurations on network security within US Federal organizations (Titania)

Liz Truss's personal phone hacked by Putin's spies (Mail Online) O

Truss phone was hacked by suspected Putin agents when she was foreign minister, the Daily Mail reports (Reuters) 

Liz Truss phone hack claim prompts calls for investigation (BBC News) 

Russian spies hacked Truss's personal phone (Computing)

Government urged to investigate report Liz Truss’s phone was hacked (the Guardian)

Ministers creating ‘wild west’ conditions with use of personal phones (the Guardian)

Suella Braverman admits sending official documents to personal email six times (The Telegraph) 

Ukraine War: UK reveals £6m package for cyber defence (BBC News)

DNS Threat Report — Q3 2022 (Akamai)

Extract Knowledge

Leading European metals producer is hit with malware. Cooperative defense in cyberspace. A Ukrainian ally describes its exposure to Russian cyberattacks. Former UK Prime Minister Truss's phone may have been compromised. CISA sees a complex threat environment, but no specific threat to US elections. The Australian Defence network sustains ransomware attack. The three finalists in the DataTribe Challenge share insights on the competition. Rick Howard previews the new season of CSO Perspectives. And a look at threat trends.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/209


Selected reading.

Aurubis says it was hit in wider cyberattack on metals industry (Reuters)

Copper Giant Aurubis Shuts Down Systems Due to Cyberattack (SecurityWeek)

Inside a US military cyber team’s defence of Ukraine (BBC News) 

Ukraine's cyber power shows value of public-private partnership (Nikkei Asia) 

Latvian President: Only the West’s Weakness Can Provoke Russia (Foreign Policy) 

Latvia’s cyberspace faces new challenges amid war in Ukraine (The Record by Recorded Future)

Worries build about winter cyber threats in Ukraine (POLITICO)

Liz Truss's personal phone hacked by Putin's spies (Mail Online)

Truss phone was hacked by suspected Putin agents when she was foreign minister, the Daily Mail reports (Reuters)

Liz Truss phone hack claim prompts calls for investigation (BBC News)

Russian spies hacked Truss's personal phone (Computing)

Government urged to investigate report Liz Truss’s phone was hacked (the Guardian)

Ministers creating ‘wild west’ conditions with use of personal phones (the Guardian)

'Complex threat environment' ahead of midterm elections, top cybersecurity official says (Reuters)

CISA chief sees no "specific or credible threats" to election infrastructure (CBS News)

For cyber experts, disinformation overshadows cyberthreats in midterms (Washington Post)

Australian Defence Department caught up in ransomware attack (ABC)

Cyber-attack on Australian defence contractor may have exposed private communications between ADF members (the Guardian)

Cyber Threat Reports (Deep Instinct)

Deep Instinct releases its 2022 Interim Cyber Threat Study. (CyberWire)

Extract Knowledge

Jenny Brinkley, Director of AWS Security at Amazon Web Services (AWS), sits down to share her empowering story working through the ranks, and even co-founding her own company. While she did not have a typical upbringing in the industry, she credits her parents for ending up where she is now, as they told her that she could do anything and she decided as she was growing up that she could. She had the opportunity to co-found a small startup before selling it to AWS. She says that working in her position is like a rollercoaster, as no one thing is like the other, saying her highs are high and her lows are low. Being a woman in cybersecurity, she is working to empower more women in the field, Jenny says, "I think that we're living in such an interesting time where empathy, kindness, compassion, honesty, partnership in the security space, I mean, heck for any industry, but really for security and cyber security roles today, it's, it's the life blood and to be underestimated, especially as a female or because, you know, my background doesn't follow a cookie cutter pattern of what individuals think of when they think of individuals in security roles." We thank Jenny for sharing her story.

Extract Knowledge

Fede Kirschbaum from Faraday Security sits down with Dave to discuss their research on "A vulnerability in Realtek's SDK for eCos OS: pwning thousands of routers." The team at Faraday found a vulnerability that made it to DEFCON 30, labeling it high severity. With more and more people working from home for their companies, the research team went looking for where there may be vulnerabilities as employees are working from home.

The research states that the team was "seeking and reporting security vulnerabilities in IoT devices, which led to the finding of an exploitable bug in a consumer-grade router popular in Argentina." They also stated in the research that it was escalating quickly and shares about how protecting home networks is important while working remotely.

The research can be found here:

Extract Knowledge

Cyberattacks against Poland’s and Slovakia’s parliaments. The US 2022 National Defense Strategy is out. Insights from SecurityWeek’s ICS Cyber Security Conference. The importance of zero-trust in industrial environments. Malek Ben Salem from Accenture on machine language security and safety. Our guest is Nick Schneider of Arctic Wolf to discuss why he believes 2023 will see a resurgence of ransomware. And CISA issues four more ICS Advisories.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/208


Selected reading.

Computer networks of parliaments in Poland and Slovakia paralyzed by cyberattacks (Euro Weekly News)

Slovak, Polish Parliaments Hit By Cyber Attacks (Barron's)

Slovak parliament suspends voting due to suspected cyberattack (Reuters)

"Also from Russia" - cyber attack on parliaments in Poland and Slovakia - Today Times Live (Today Times Live)

2022 National Defense Strategy (US Department of Defense)

2022 NDS Fact Sheet | Integrated Deterrence (US Department of Defense) 

Discussing cyberattacks vs system failures. (CyberWire) 

Zero-trust in ICS environments. (CyberWire)

SANS 2022 Survey: The State of OT/ICS Cybersecurity in 2022 and Beyond | Nozomi Networks (Nozomi Networks)

CISA Releases Four Industrial Control Systems Advisories (CISA)

Extract Knowledge

CISA releases cross-sector cybersecurity performance goals. Trojans are spreading through scanners. Cyber seed rounds are an exception to a general downtrend in venture investment. Whistleblowing and corporate culture. Storing enterprise secrets. Robert M. Lee from Dragos explains the TSA Pipeline Security Directive. Our guests are Jenny Brinkley from Amazon AWS and Lisa Plaggemier from the National Cybersecurity Alliance with a collaborative educational project. Cyberattacks seen as opportunistic and disconnected from strategy.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/207


Selected reading.

Cross-Sector Cybersecurity Performance Goals (CISA)

CISA unveils voluntary cybersecurity performance goals (Federal News Network) 

Sending Trojans via Scanners (Avanan) 

DataTribe Insights - Q2 2022: Economic Storm Makes Landfall (DataTribe) 

Ukraine: Russian cyber attacks aimless and opportunistic (SearchSecurity)

Extract Knowledge

Sudan closes its Internet as the country sees protests on the first anniversary of a coup. A Chinese influence campaign targets US elections. A software supply chain security study, and a look at vulnerability scanning tools. Documenting cyber war crimes in Ukraine. CISA issues eight ICS Advisories. Andrea Little Limbago from Interos on the effects of water scarcity on data centers. And if you’ll indulge us, we’ve got some pretty exciting CyberWire news.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/206


Selected reading.

Internet is shut down in Sudan on anniversary of military coup (The Record by Recorded Future)

Pro-PRC DRAGONBRIDGE Influence Campaign Leverages New TTPs to Aggressively Target U.S. Interests, Including Midterm Elections (Mandiant)

Rezilion Vulnerability Scanner Benchmark Report Finds Top Scanners Only 73% Accurate (PR Newswire) 

Four in Five Software Supply Chains Exposed to Cyberattack in the Last 12 Months (BlackBerry)

Ukraine Documenting Russian Hacks, Eyeing International Charges (Bloomberg) 

CISA Releases Eight Industrial Control Systems Advisories (CISA)

Extract Knowledge

US Department of Justice unseals three indictments in PRC spying cases. CERT-UA warns of Cuba ransomware group phishing campaign. Varonis discovers two Windows vulnerabilities. Mr Security Answer Person John Pescatore on security through obscurity. Ben Yelin on the DOJ’s spying cases against China. CISA expands its Known Exploited Vulnerabilities Catalog with six new entries.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/205


Selected reading.

Two Arrested and 13 Charged in Three Separate Cases for Alleged Participation in Malign Schemes in the United States on Behalf of the Government of the People’s Republic of China (US Department of Justice)

U.S. Justice Department Fires Warning Shot at Chinese Spies (Foreign Policy)

Chinese spies charged with trying to thwart Huawei investigation (Quartz)

DOJ Charges 13 Over Chinese Interference In US Affairs (Law360) 

U.S. Says Chinese Tried to Obstruct Huawei Prosecution (Wall Street Journal)

U.S. charges Chinese nationals with schemes to steal info, punish critics and recruit spies (CBS News)

Cuba ransomware affiliate targets Ukrainian govt agencies (BleepingComputer)

Unattributed RomCom Threat Actor Spoofing Popular Apps Now Hits Ukrainian Militaries (BlackBerry)

The Logging Dead: Two Event Log Vulnerabilities Haunting Windows (Varonis) 

CISA Adds Six Known Exploited Vulnerabilities to Catalog (CISA)

Extract Knowledge

Breaking: US unseals three cases against Chinese intelligence officers. CISA says Daixin Team ransomware is an active threat. The FBI warns of Iranian threat group's activity. Meanwhile the Iranian nuclear agency says its email was hacked. Norway is concerned about threats to oil and gas infrastructure. A drop in ransomware correlates with Russia's hybrid war. Ann Johnson from Afternoon Cyber Tea speaks with AJ Yawn from ByteChek about breaking into the cybersecurity industry. Josh Ray from Accenture describes threats to the satellite industry. And cyber offense may be proving harder than thought.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/204


Selected reading.

CISA Alert AA22-294A – #StopRansomware: Daixin Team. (CyberWire)

#StopRansomware: Daixin Team (CISA)

CISA Warns of Daixin Team Hackers Targeting Health Organizations With Ransomware (The Hacker News)

Iranian Cyber Group Emennet Pasargad Conducting Hack-and-Leak Operations Using False-Flag Personas (FBI)

FBI warns Iranian hackers active ahead of the U.S. midterms (NBC News)

FBI Warns of Attacks From Iranian Threat Group Emennet Pasargad (Decipher)

Iran Hackers Behind Attempt on US Election Are Still Active (Gov Info Security)

FBI warns of ‘hack-and-leak’ operations from group based in Iran (The Record by Recorded Future)

Iran's Atomic Energy Agency Says Its E-Mail Server Was Hacked (RadioFreeEurope/RadioLiberty)

Iran says ‘specific foreign country’ behind hacktivist leak of atomic energy emails (The Record by Recorded Future)

Iran’s Top Nuclear Agency Says Its Email Servers Were Hacked (Bloomberg) 

Ukraine Could Still Face Cyberattacks, Experts Say (CNET)

Fears over Russian threat to Norway's energy infrastructure (AP NEWS)

Norway PM: Russia poses ‘real and serious’ cyber threat to oil and gas industry (The Record by Recorded Future) 

Ukraine war cuts ransomware as Kremlin co-opts hackers (The Telegraph) 

Q&A: Kenneth Geers on the cyber war between Ukraine and Russia (The Record by Recorded Future)

Extract Knowledge

FBI, CISA, and Department of Health and Human Services are releasing this joint advisory to provide information on the Daixin Team, a cybercrime group that is actively targeting U.S. businesses, predominantly in the Healthcare and Public Health Sector.

AA22-294A Alert, Technical Details, and Mitigations

Stopransomware.gov is a whole-of-government approach that gives one central location for ransomware resources and alerts.

Resource to mitigate a ransomware attack: CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide.

Ongoing Threat Alerts and Sector alerts are produced by the Health Sector Cybersecurity Coordination Center (HC3) and can be found at hhs.gov/HC3

For additional best practices for Healthcare cybersecurity issues see the HHS 405(d) Aligning Health Care Industry Security Approaches at 405d.hhs.gov 

CISA offers several no-cost scanning and testing services to help organizations reduce their exposure to threats by taking a proactive approach to mitigating attack vectors. See www.cisa.gov/cyber-hygiene-services

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge

Megan Doherty, a Technical Specialist from Microsoft Canada sits down to share her story of overcoming barriers in the workforce to get to where she is today in her career. Megan started out being a mechanical engineer before making the switch to do something with more creativity and problem solving. She shares about her passion of working with a group Microsoft created called "DigiGirlz." As well as just being able to work with her team who she says helps her face the world of adversity in her career. Megan said "There's so many barriers, just even mentally that we put on ourselves when it comes to looking for a career change or even thinking of cybersecurity as your next career path." She hopes that she leaves a legacy of kindness and compassion behind especially in the industry she is works in. We thank Megan for sharing her story with us.

Extract Knowledge

Dick O'Brien from Symantec's Threat Hunter team sits down with Dave to discuss their work on "Witchetty - Group Uses Updated Toolset in Attacks on Governments in Middle East." Their research has found that the group known as Witchetty aka LookingFrog, has been progressively updating its toolset, including the new tool, backdoor Trojan (Backdoor.Stegmap) to launch malware attacks on targets in the Middle East and Africa.

The research states "The attackers exploited the ProxyShell and ProxyLogon vulnerabilities to install web shells on public-facing servers before stealing credentials, moving laterally across networks, and installing malware on other computers. The researchers describe more on the new tool being used and why this new group is a threat.

The research can be found here:

Extract Knowledge

Blackbyte's new exfiltration tool. Hijacking student accounts for BEC. Zhora calls Russia's cyber campaigns a failure. Caleb Barlow explores new thinking for incident response. Our guest is Jon Hencinski of Expel, tracking the latest threat trends. OldGremlin ransomware is an outlier.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/203


Selected reading.

Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool (Symantec)

Hijacking Student Accounts to Launch BEC-Style Attacks (Avanan)

This sneaky kind of cybercrime rules them all (Washington Post)

Russia Failing to Reach Cyber War Goals, Ukrainian Official Says (Meritalk) 

EU supports cybersecurity in Ukraine with over €10 million - EU NEIGHBOURS east (EU NEIGHBOURS east) 

Gremlins’ prey, secrets, and dirty tricks: the ransomware gang OldGremlin set new records (Group-IB) 

OldGremlin hackers use Linux ransomware to attack Russian orgs (BleepingComputer)

OldGremlin, which targets Russia, debuts new Linux ransomware (Computing) It is one of the few ransomware groups in the world that prefer to target Russian organisations, but this may change experts advise

More Russian Organizations Feeling Ransomware Pain (Bank Info Security)

Extract Knowledge

DDoS as misdirection. NSA shares lessons learned from cyber operations observed in Russia's war against Ukraine. Advice from CISA on Zimbra.. A misconfigured Microsoft storage endpoint has been secured. Notes from a study on the Cybersecurity Workforce . The cost to businesses of phishing. Betsy Carmelite from Booz Allen Hamilton on managing mental health in the cyber workforce. Our guest is Ismael Valenzuela of Blackberry with insights on "The Cyber Insurance Gap". And updates to the ransomware leaderboard.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/202


Selected reading.

Bulgarian cyberattack: Sabotage as a cover for spying? (Deutsche Welle)

Bulgarian websites impacted by Killnet DDoS attack (SC Media) 

Lessons From Ukraine: NSA Cyber Chief Lauds Industry Intel (Meritalk)

NSA Cybersecurity Director's Six Takeaways From the War in Ukraine (Infosecurity Magazine) 

NSA cyber chief says Ukraine war is compelling more intelligence sharing with industry (CyberScoop) 

Investigation Regarding Misconfigured Microsoft Storage Location (Microsoft Security Response Center)

2019 Cybersecurity Workforce Study ((ISC)²) 

The Business Cost of Phishing (Ironscales)

Leading Ransomware Variants Q3 2022 (Intel471)

Extract Knowledge

Killnet explains its actions against Bulgaria's government. The National Republican Army claims successful attacks on Russian companies. The Director of Germany's BSI is out. A vulnerability in Azure, disclosed and patched. Trends in ransomware. Carole Theriault has a fresh look at the ransomware question - to pay or not to pay? Tim Eades from Cyber Mentor Fund considers cyber insurance for the small and medium sized businesses. Social Security phishing.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/201


Selected reading.

Cyberattack disrupts Bulgarian government websites over ‘betrayal to Russia’ (The Record by Recorded Future) 

Russians Against Putin: NRA Claims Massive Hack of Russian Government Contractors’ Computers - Kyiv Post - Ukraine's Global Voice (Kyiv Post)

Germany fires cybersecurity chief after reports of possible Russia ties (Reuters) 

German Cybersecurity Chief Sacked Over Alleged Russia Ties (SecurityWeek)

German cyber chief suspended following allegation he associated with Russian intelligence (The Record by Recorded Future) 

FabriXss (CVE-2022-35829): How We Managed to Abuse a Custom Role User Using CSTI and Stored XSS in Azure Fabric Explorer (Orca Security) 

Ransomware In Q3 2022 (Digital Shadows)

Fresh Phish: A New Social Security Phishing Scam Preys Upon Our Biggest Worries (INKY) 

Extract Knowledge

Mobilizing DDoS-as-a-service. Interpol takes down the Black Axe gang members. A look at phishing trends. Spyder Loader is active in Hong Kong. Joe Carrigan looks at Google’s launch of passwordless authentication. Our guest is Dr. Eman El-Sheikh from University of West Florida's Center for Cybersecurity on NSA-funded National Cybersecurity Workforce Development Programs. And Europol announces arrests in a case of keyless car hacking.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/200


Selected reading.

Project DDOSIA Russia's answer to disBalancer (Radwaare)

Russian DDOSIA Project Pays Volunteers to Participate in DDOS Attacks on Western Companies (Gridinsoft Blogs)

International crackdown on West-African financial crime rings (Interpol)

Giant online scamming syndicate 'Black Axe' destroyed in Interpol-led operation (teiss)

INTERPOL-led Operation Takes Down 'Black Axe' Cyber Crime Organization (The Hacker News)

Operation Jackal: Interpol arrests Black Axe fraud suspects (Register)

When the Black Axe falls: cybercrime suspects detained in global bust (Cybernews)

International Police Action Blunts Black Axe Criminal Group - HS Today (Hstoday)

Q3 2022 Cofense Phishing Intelligence Trends Review (Cofense)

Spyder Loader: Malware Seen in Recent Campaign Targeting Organizations in Hong Kong (Symantec)

Operation CuckooBees: Cybereason Uncovers Massive Chinese Intellectual Property Theft Operation (Cybereason)

31 arrested for stealing cars by hacking keyless tech | Europol (Europol)

European gang that sold car hacking tools to thieves arrested (The Record by Recorded Future)

Extract Knowledge

There’s been a Cyberattack against Tata Power. The FBI warns US state political parties of Chinese scanning. Russian influence ops play defense; China’s are on the offense. Ransom Cartel and a possible connection to REvil. "Prestige" ransomware is sighted in attacks on Polish and Ukrainian targets. Distributed denial-of-service attacks interfere with Bulgarian websites. Grayson Milbourne of OpenText Security Solutions on SBOMS. Our own Rick Howard checks in with Bryan Willett of Lexmark on implementation of Zero Trust. And Mr. Musk tweets his intention to continue to subsidize Starlink for Ukraine (probably).


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/199


Selected reading.

Hackers Attack Tata Power IT Systems: All You Need To Know (IndiaTimes)

Chinese hackers are scanning state political party headquarters, FBI says (Washington Post)

The Defender's Advantage Cyber Snapshot Issue 2 — More Insights From the Frontlines (Mandiant) 

Ransom Cartel Ransomware: A Possible Connection With REvil (Unit 42)

New “Prestige” ransomware impacts organizations in Ukraine and Poland (Microsoft Security Threat Intelligence)

Bulgarian Government Hit By Cyberattack Blamed On Russian Hacking Group (RadioFreeEurope/RadioLiberty)

'The hell with it': Elon Musk tweets SpaceX will 'keep funding Ukraine govt for free' amid Starlink controversy (CNBC)

Starlink isn't a charity, but the Ukraine war isn't a business opportunity (TechCrunch)

Extract Knowledge

Amanda Adams, VP of Americas Alliances at CrowdStrike sits down to share her story as she pivoted into the tech field. She started her career by wanted to be involved with sports, after getting her masters degree Amanda was faced with a difficult choice between working for The Golden State Warriors and Cisco. She ultimately chose Cisco as her path to move forward and has been working in technology ever since. Now she works for a team where she gets to prove her social skills and is focused on partnerships. She say's that working in technology doesn't just have to be working with technology, there are many other ways you can get involved with the field. Amanda says "you can always pivot into the technology industry and support the broader mission by doing that job function." We thank Amanda for sharing her story.

Extract Knowledge

Between multi-cloud deployments, more employees working remotely, and increasing use of SaaS applications, the number of entry points for attackers to infiltrate your systems has exploded. But gaining visibility into all these possible attack vectors is time-consuming and often incomplete or just a snapshot in time.

If the first rule of cyber is to “know what you have,” how can cyber professionals get a comprehensive, current picture of their assets? How can they feel confident that they understand which assets may be more vulnerable and prioritize defenses accordingly?

In the first half of this episode of Cyberwire-X, the CyberWire's CSO, Chief Analyst, and Senior Fellow, Rick Howard, is joined by Hash Table member Jaclyn Miller, the Head of InfoSec & IT at DispatchHealth. In the second half of the episode, Cody Pierce, Chief Product Officer at episode sponsor LookingGlass Cyber Solutions, talks with Dave Bittner. Listen to the discussions about answering the foundational cyber questions (What do I have? Is it protected?), why context is critical, and how an adversarial perspective helps you be a better defender.

Extract Knowledge

Brigid O Gorman from Symantec's Threat Hunter team joins Dave to discuss their research on "Noberus Ransomware - Darkside and BlackMatter Successor Continues to Evolve its Tactics." The research states that Noberus ransomware (aka BlackCat, ALPHV) is more dangerous than ever because attackers have been using new tactics, tools, and procedures in recent months.

In the research, Symantec says, "Among some of the more notable developments has been the use of a new version of the Exmatter data exfiltration tool, and the use of Eamfo, information-stealing malware that is designed to steal credentials stored by Veeam backup software." They go over an in-depth look at how its affiliate program operates.

The research can be found here:

Extract Knowledge

County election workers find themselves targets of phishing. Impersonating Intrusion Truth. The LDS Church discloses data compromise. SpaceX asks for Starlink funding. Does Killnet have potential to do more damage than it so far has? Deepen Desai from Zscaler on Joker, Facestealer and Coper banking malwares on the Google Play store. Our guest is Maxime Lamothe-Brassard of LimaCharlie to discuss how the cybersecurity is following in the footsteps of software engineering. And the Gamers’ attack surface? It’s big, big, really big, Noobs.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/198


Selected reading.

2022 Election Phishing Attacks Target Election Workers (Trellix)

Suspicious Twitter accounts impersonating research group try to blame the NSA for Chinese hacks (The Daily Dot)

Statement and FAQ on Church Account Data Incident (Church of Jesus Christ of Latter Day Saints)

Exclusive: Musk's SpaceX says it can no longer pay for critical satellite services in Ukraine, asks Pentagon to pick up the tab (CNN)

Killnet: don't underestimate the “script kiddies,” experts say (Cybernews)

Gaming Is Booming. That’s Catnip for Cybercriminals. (New York Times) 

Extract Knowledge

Emotet ups its game. COVID-19 small business grants as phishbait. Google Translate is spoofed for credential harvesting. Research on the Budworm espionage group. Kevin Magee from Microsoft shares why cybersecurity professionals should join company boards. Our guest is Chris Niggel from Okta with a look at identity shortfalls. And Internet outages during missile strikes, and the prospects of Russia’s hybrid war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/197


Selected reading.

Emotote’s evolution. (ESET)

Fresh Phish: Small Business COVID-19 Grants Designed for Disaster (INKY)

Spoofing Google Translate to Steal Credentials (Avanan) 

Budworm: Espionage Group Returns to Targeting U.S. Organizations (Symantec Blog) 

Internet outages hit Ukraine following Russian missile strikes (Bitdefender)

Starlink helped restore energy, communications infrastructure in parts of Ukraine - official (Reuters)

Ukraine’s Vice PM Thanks Starlink for Help to Restore Connections After Missile Attack from Russia (Tech Times)

We must tackle Europe’s winter cyber threats head-on (POLITICO)

The conflict in Ukraine makes us rethink cyberwar (The Japan Times)

Extract Knowledge

Refund fraud as a service. Costs of a nuisance. Remaining on alert during a hybrid war. Renewed activity by Polonium. Andrea Little Limbago from Interos discussing quantum computing policy. CyberWire Space Correspondent Maria Varmazis speaks with Dr. Gregory Falco on lessons learned from Russia’s attack on Viasat. Reflections on the Uber case's impact on security professionals. And when it comes to phishing-as-a-service, we’ll take decaf.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/196


Selected reading.

The Fresh Phish Market: Behind the Scenes of the Caffeine Phishing-as-a-Service Platform (Mandiant) 

Caffeine phishing. (CyberWire)

Refund Fraud as a Service (Netacea)

Amid reports of JP Morgan cyberattack, experts call Killnet unsophisticated, ‘media hungry’ (SC Media)

Hacktivists Force Companies to Respond to Low-Level Cyberattacks (Wall Street Journal) 

Nato warns Russian sabotage on Western targets 'could trigger Article 5' (The Telegraph)

US Not Ruling Out Russian Cyber Offensive (VOA)

Ukraine at D+230: Escalation, but unlikely to be sustainable. (CyberWire)

POLONIUM targets Israel with Creepy malware (WeLiveSecurity)

Hacking group POLONIUM uses ‘Creepy’ malware against Israel (BleepingComputer)

Security chiefs fear ‘CISO scapegoating’ following Uber-Sullivan verdict (The Record)

Sullivan verdict sends shockwaves through the security industry (Security Info Watch)

Reflections on the Uber case's impact on security. (CyberWire)

Extract Knowledge

Russia's Killnet suspected in DDoS attack on major US airports. Starlink service interruptions reported. Bundesbahn communications network sabotaged in northern Germany. Germany's cybersecurity chief faces scrutiny over alleged ties to Russia. Ben Yelin on the FCC's crackdown on robocalls. Ann Johnson from Afternoon Cyber Tea talking with Sounil Yu from JupiterOne about the importance and evolution of cyber resilience. Overworked CISOs may be a security risk, but in an encouraging counterpoint, another study shows a record of CISO success during the pandemic.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/195


Selected reading.

US Airport Websites Hit by Suspected Pro-Russian Cyberattacks (SecurityWeek) 

Hackers knock some U.S. airport websites offline (Washington Post)

Hackers took down U.S. airport web sites, Department of Homeland Security confirms (USA TODAY)

Pro-Russian hackers claim responsibility for taking down US airport websites (Computing) 

US airports' sites taken down in DDoS attacks by pro-Russian hackers (BleepingComputer) 

Pro-Putin goons target US airport websites with DDoS flood (Register) 

Russian Sanctions Instigator Lloyd’s Possibly Hit by Cyber-Attack (Infosecurity Magazine)

Lloyd's of London reboots network after suspicious activity (Register)

Colorado.gov Back Online After Cyber Attack (GovTech)

Defending Ukraine: SecTor session probes a complex cyber war (IT World Canada)

Ukrainian officials reportedly say there have been 'catastrophic' Starlink outages in recent weeks (Business Insider)

Frontline Ukraine troops are reportedly enduring Starlink outages (Engadget).

Elon Musk’s foray into geopolitics has Ukraine worried (The Economist)

Elon Musk needs to clarify Ukraine's reported Starlink outages: Kinzinger (Newsweek) 

Attack on German Rail Network ‘Targeted, Professional,’ Police Say (Bloomberg)

An act of sabotage shut down parts of Germany's rail system for hours this weekend (NPR.org)

Germany rail chaos could have been caused by Russia, says MP (The Telegraph) 

Sabotage blamed for major disruption on Germany’s rail network (The Telegraph) 

No sign that foreign state was behind German rail sabotage, police say (Reuters)

Germany Won’t Rule Out Foreign Country Role in Rail Sabotage (Bloomberg)

Germany's cybersecurity chief faces dismissal, reports say (Reuters)

German cybersecurity chief investigated over Russia ties (ABC News)

German Cybersecurity Chief to be Sacked Over Alleged Russia Ties: Sources (SecurityWeek)

„Wir müssen wachsam bleiben“ (Tagesspiegel) 

1 in 5 Chief Information Security Officers (CISOs) Work More Than 25 Extra Hours Per Week (Tessian) 

2022 Devo SOC Performance Report (Devo)

2022 Deloitte-NASCIO Cybersecurity Study (Deloitte Insights)

Cybersecurity Survey of State CISOs Identifies Many Positive Trends (PR Newswire)

Extract Knowledge

This interview from September 23rd, 2022 originally aired as a shortened version on the CyberWire Daily Podcast. In this extended interview, CyberWire’s space correspondent, Maria Varmazis, interviews host of spaceflight podcast “Main Engine Cutoff,” Anthony Colangelo about the upcoming Apple iPhone 14 “Emergency SOS via Satellite” feature & what it means for satellite communications in the consumer sector.

Extract Knowledge

In today’s episode, our sandbox heads to the deployment pipeline for a conversation on the who/what/when/and why of a DevSecOps program and how it adds value to your business. And your main questions- – how you can encourage buy-in and adoption. Joining me today are Marcin Swiety, Relativity’s Senior Director of Global Security and IT, and Raphael Theberge - Director of Security Integrations. So, grab your DORA metrics, your source controls, and staging environments, and let’s dive in. 

Extract Knowledge

Payal Chakravarty, Head of Product for Security and Risk from Coalition, sits down to share her story of working at several different organizations, including interning for IBM and Microsoft. After obtaining her master's degree, she worked with IBM a bit more closely and fell in love with one of the projects she was working on. Payal had a very interesting career path going from physical to virtual, virtual to cloud now, cloud to containers. She says that there is still some bias she has dealt with as a woman in her field, she says, "I think the way you handle it is you negotiate or you kind of calmly handle the situation, there's no ego involved." Payal shares that in working in this field you need to be in love with it, giving the advice that don't just choose a job because of the money or because it's cool, but because you feel connected to it as a profession. We thank Payal for sharing her story.

Extract Knowledge

The age-old battle between offensive and defensive security practitioners is most often played out in the penetration testing cycle. Pentesters ask, “Is it our fault if they don’t fix things?” While defenders drown in a sea of unprioritized findings and legacy issues wondering where to even start.

But the real battle shouldn’t be between the teams; it should be against the real adversaries. So why do pentesters routinely come back and find the same things they reported a year ago? Do the defenders just not care or does the onus fall on the report? Everyone really wants the same thing: better security. To get there, the primary communication tool between consultant and client, offensive and defensive teams — the pentest report — must be consumable and actionable and tailored to the audience who receives it.

In the first half of this episode of Cyberwire-X, the CyberWire's CSO, Chief Analyst, and Senior Fellow, Rick Howard, is joined by Hash Table members Amanda Fennell, the CIO and CSO of Relativity, and William MacMillan, the SVP of Security Product and Program Management at Salesforce. In the second half of the episode, Dan DeCloss, the Founder and CEO of episode sponsor PlexTrac, joins Dave Bittner discuss the politics around pentest reporting and how better reports can support real progress.

Extract Knowledge

Jen Miller-Osborn from Palo Alto Networks' Unit 42 joins Dave to discuss their recent work on "Russian APT29 Hackers Use Online Storage Services, DropBox and Google Drive." The research shares the insight into an active campaign from Russia’s Foreign Intelligence Service, that is leveraging the use of trusted, legitimate cloud services including Google Drive as a staging platform to deliver malware.

The research states that when these tactics are used, it is extremely difficult for organizations to detect the malicious activity in connection with the campaign. These tactics are used to collect victim information, evade detection, and deliver Cobalt Strike.

The research can be found here:

Extract Knowledge
Show details
Episodes
3784
Transcripts
68
2% coverage
Missing transcripts
3716
With chapters
0