Search this show’s transcripts

CyberWire Daily

en us
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

Episodes

Page 33 · 50 per page

A US Executive Order outlines US-EU data-sharing privacy safeguards. CISA, NSA, and the FBI list the top vulnerabilities currently being exploited by China. A look at election security and credit risk to US states. COVID-19-themed social engineering continues. Robert M. Lee from Dragos on securing the food and beverage industry. Carole Theriault interviews Joel Hollenbeck from Check Point Software on threat actors phishing school board meetings. Notes from the hybrid war: Killnet and US state government sites, the prospects of deterrence in cyberspace, and, finally, maybe the most motivated draft evaders in military history.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/194


Selected reading.

FACT SHEET: President Biden Signs Executive Order to Implement the European Union-U.S. Data Privacy Framework (The White House)

Top CVEs Actively Exploited By People’s Republic of China State-Sponsored Cyber Actors (CISA) 

Government credit risk associated with election risk (CyberWire)

Exploiting COVID-19: how threat actors hijacked a pandemic (Proofpoint)

Ukraine at D+125: Abandoned tanks and discontented hawks. (CyberWire) 

Department Press Briefing – October 6, 2022 - United States Department of State (United States Department of State) 

2 Russians fleeing military service reach remote Alaska island (Military Times)

Extract Knowledge

This joint Cybersecurity Advisory provides the top CVEs used by the People’s Republic of China state-sponsored cyber actors. PRC cyber actors continue to exploit these known vulnerabilities and use publicly available tools to target networks of interest. PRC state-sponsored cyber actors have actively targeted U.S. and allied networks as well as software and hardware companies to steal intellectual property and develop access into sensitive networks.

AA22-279A Alert, Technical Details, and Mitigations

For more information on PRC state-sponsored malicious cyber activity, see CISA’s China Cyber Threat Overview and Advisories webpage, FBI’s Industry Alerts, and NSA’s Cybersecurity Advisories & Guidance

People’s Republic of China State-Sponsored Cyber Actors Exploit Network Providers and Devices

CISA offers several no-cost scanning and testing services to help organizations reduce their exposure to threats by taking a proactive approach to mitigating attack vectors. See www.cisa.gov/cyber-hygiene-services

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System (PDNS) services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge

Microsoft updates mitigations for ProxyNotShell. Lloyd's of London investigates a suspected cyberattack. Killnet hits networks of US state governments. The FBI and CISA weigh in on election security. Credential theft in the name of Zoom. Tim Eades from Cyber Mentor Fund on the move to early-stage investing in times of war and recession. Our guest is Nick Lumsden of Tenacity Cloud on cloud infrastructure sprawl. The former security chief at Uber was found guilty in a case involving data breach cover-up.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/193


Selected reading.

Customer Guidance for Reported Zero-day Vulnerabilities in Microsoft Exchange Server (Microsoft Security Response Center)

Microsoft updates guidance for ‘ProxyNotShell’ bugs after researchers get around mitigations (The Record by Recorded Future)

Microsoft Updates Mitigation for Exchange Server Zero-Days (Dark Reading) 

Microsoft updates mitigation for ProxyNotShell Exchange zero days (BleepingComputer) 

Lloyd's of London investigates possible cyber attack (Reuters)

Insurance giant Lloyd’s of London investigating cyberattack (The Record by Recorded Future)

Russian-speaking hackers knock US state government websites offline (CNN) 

Malicious Cyber Activity Against Election Infrastructure Unlikely to Disrupt or Prevent Voting (FBI and CISA)

FBI: Cyberattacks targeting election systems unlikely to affect results (BleepingComputer) 

Zoom: 1 Phish, 2 Phish Email Attack (Armorblox)

Former Uber Security Chief Found Guilty of Obstructing FTC Probe (Wall Street Journal)

Former Uber security chief convicted of covering up 2016 data breach (Washington Post)

Uber’s Former Security Chief Convicted of Data Hack Coverup (Bloomberg)

Former Uber Security Chief Found Guilty of Hiding Hack From Authorities (New York Times)

Former Uber CISO Joe Sullivan Found Guilty Over Breach Cover Up (SecurityWeek)

Extract Knowledge

Data’s stolen from a US "Defense Industrial Base organization." Major sideloading cryptojacking campaign is in progress. Nord Stream and threats to critical infrastructure. US Cyber Command describes "hunt forward" missions in Ukraine. Andrew Hammond from SpyCast speaks with hacker Eric Escobar about the overlap of traditional intelligence and cybersecurity. Our guest is AJ Nash from ZeroFox with an update on the current threat landscape. Fraud meets romance.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/192


Selected reading.

Impacket and Exfiltration Tool Used to Steal Sensitive Information from Defense Industrial Base Organization (CISA)

CISA: Multiple government hacking groups had ‘long-term’ access to defense company (The Record by Recorded Future)

US Govt: Hackers stole data from US defense org using new malware (BleepingComputer) 

Side-Loading OneDrive for profit – Cryptojacking campaign detected in the wild (Bitdefender Labs)

Drone-loaded seabed ship is latest weapon in Royal Navy's arsenal to counter Russian threat (The Telegraph)

Opinion Undersea pipeline sabotage demands the West prepare for more attacks (Washington Post)

Ukraine Hasn’t Won the Cyber War Against Russia Yet (World Politics Review) 

USCYBERCOM Executive Director David Frederick Outlines Cyber Threats & Highlights Importance of Industry Partnerships (GovCon Wire) 

Romance scammer and BEC fraudster sent to prison for 25 years (Naked Security)

Extract Knowledge

From November 2021 through January 2022, the CISA responded to APT activity against a Defense Industrial Base organization’s enterprise network. During incident response activities, CISA discovered that multiple APT groups compromised the organization’s network, and some APT actors had long-term access to the environment. APT actors used an open-source toolkit called Impacket to gain their foothold within the environment and further compromise the network, and also used a custom data exfiltration tool, CovalentStealer, to steal the victim’s sensitive data.

AA22-277A Alert, Technical Details, and Mitigations

CISA Cyber Hygiene Services

Malware Analysis Report (MAR)-10365227-1.stix

MAR-10365227-2.stix

MAR-10365227-3.stix

CISA offers several no-cost scanning and testing services to help organizations reduce their exposure to threats by taking a proactive approach to mitigating attack vectors. See www.cisa.gov/cyber-hygiene-services

U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System (PDNS) services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov 

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge

CISA issues a Binding Operational Directive. An LA school district says ransomware operators missed most sensitive PII. An API protection report describes malicious transactions. Analysis of cyber risk in relation to SaaS applications. Joe Carrigan describes underground groups using stolen identities and deepfakes. Our guest is Eve Maler from ForgeRock on consumer identity breaches. And someone is making a nuisance of themself in Russia.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/191


Selected reading.

Binding Operational Directive 23-01 (CISA)

CISA Directs Federal Agencies to Improve Cybersecurity Asset Visibility and Vulnerability Detection (Cybersecurity and Infrastructure Security Agency) 

CISA aims to expand cyber defense service across fed agencies, potentially further (Federal News Network)

CISA directs federal agencies to track software and vulnerabilities (The Record by Recorded Future) 

Student, Teacher Data Not Affected in Los Angeles School District Hack (Wall Street Journal)

‘No evidence of widespread impact,’ LAUSD says of data released by hackers (KTLA) 

New API Threat Research Shows that Shadow APIs Are the Top Threat Vecto (Cequence Security)

Secureworks State of the Threat Report 2022: 52% of ransomware incidents over the past year started with compromise of unpatched remote services (Secureworks)

Russian Citizens Wage Cyberwar From Within (Kyiv Post)

Russian Hackers Take Aim at Kremlin Targets: Report (Infosecurity Magazine) Russian retail chain 'DNS' confirms hack after data leaked online (BleepingComputer)

Extract Knowledge

Two Microsoft Exchange zero-days exploited in the wild. A supply chain attack, possibly from Chinese intelligence services. There’s new Lazarus activity: bring-your-own-vulnerable-driver. The Mexican government falls victim to apparent hacktivism. Flying under partial mobilization’s radar. Betsy Carmelite from Booz Allen Hamilton talks about addressing the cyber workforce skills gap. Our guest Rachel Tobac from SocialProof Security brings a musical approach to security awareness training. How’s your off-boarding program working out?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/190


Selected reading.

Microsoft Releases Guidance on Zero-Day Vulnerabilities in Microsoft Exchange Server (CISA) 

Customer Guidance for Reported Zero-day Vulnerabilities in Microsoft Exchange Server (Microsoft Security Response Center)

Warning: New attack campaign utilized a new 0-day RCE vulnerability on Microsoft Exchange Server (GTSC)

URGENT! Microsoft Exchange double zero-day – “like ProxyShell, only different” (Naked Security)

Microsoft confirms two Exchange Server zero days are being used in cyberattacks (The Record by Recorded Future)Microsoft confirms new Exchange zero-days are used in attacks (BleepingComputer) 

Two Microsoft Exchange zero-days exploited in the wild. (CyberWre) 

CISA Adds Three Known Exploited Vulnerabilities to Catalog (CISA)

Suspected Chinese hackers tampered with widely used customer chat program, researchers say (Reuters)

Report: Commercial chat provider hijacked to spread malware in supply chain attack (The Record by Recorded Future) 

CrowdStrike Falcon Platform Identifies Supply Chain Attack via a Trojanized Comm100 Chat Installer (crowdstrike.com)

Amazon‑themed campaigns of Lazarus in the Netherlands and Belgium (WeLiveSecurity)

Lazarus & BYOVD: evil to the Windows core (Virus Bulletin)

Lazarus hackers abuse Dell driver bug using new FudModule rootkit (BleepingComputer)

Mexican government suffers major data hack, president's health issues revealed (Reuters)

Mexican president confirms ‘Guacamaya’ hack targeting regional militaries (The Record by Recorded Future)

Analysis: Mexico data hack exposes government cybersecurity vulnerability (Reuters)

Russians dodging mobilization behind flourishing scam market (BleepingComputer) 

Honolulu Man Pleads Guilty to Sabotaging Former Employer’s Computer Network (US Department of Justice)

Extract Knowledge

On this episode of CyberWire-X, we dive into the essential role of open-source intelligence in identifying cyber and physical threats and reducing risk across your organization. The CyberWire's CSO, Chief Analyst, and Senior Fellow, Rick Howard, is joined in the first half by Hash Table members Dr. Georgianna Shea, CCTI and TCIL Chief Technologist at the Foundation for Defense of Democracies, and Bob Turner, Field CISO – Education at Fortinet. In the second half of the show, CyberWire podcast host Dave Bittner talks with our episode sponsor risk intelligence firm Flashpoint's Chief Intelligence Officer Tom Hofmann. They explore the foundational importance of open source intelligence, which includes social media platforms and geospatial data and insights. Plus, they explore real-life examples of how organizations, from governments to commercial enterprises, are leveraging open source intelligence and technology every day to protect their people, places, assets, and critical infrastructure.

Extract Knowledge

Kayla Williams, CISO of Devo, sits down to share her story, from graduating with a finance degree to rising to where she is now. She quickly learned that finance was not for her and changed paths, working towards gaining an information security certificate. From there she was able to excel and was offered the opportunity to move to England which changed her life. Working in her new role, she really enjoys thriving with her team. She says "We really try to be the department of no problem versus the department of no." She mentions how her and her team work on a day to day basis together solving issues and yet she says not everything related to cybersecurity needs to be a fire drill. She would rather her and her team build bridges in the face of adversity and in the face of people who may be naysayers. We thank Kayla for sharing her story.

Extract Knowledge

David Prefer from SANS sits down with Dave to discuss how a new covert channel exfiltrates data via a browser's built-in bookmark sync. David goes on to describe how this research will "describe how the ability to synchronize bookmarks across devices introduces a novel vector for data exfiltration and other misuses."

In the research, he shares how he tested his said hypothesis and goes on to describe how the interesting find was tested on multiple browsers including Chrome, Edge, Brave and Opera. In his research, he found that bookmarks are able to keep data and synchronize it, making it easier to infiltrate and extract data from. David shares the rest of his findings, as well as what organizations and browser developers can do to work on this new threat.

The research can be found here:

Extract Knowledge

North Korean operators "weaponize" open-source software. The SolarMarker info-stealer returns. A quick review of Fast Company's WordPress hijacking incident. Deepfakes, and their evolution into an underworld and influence ops tool. Kinetic sabotage in the Baltic raises concerns about threats to infrastructure in cyberspace. Chris Novak from Verizon with a mid-year check in. Our guest is MK Palmore of Google Cloud on why collective cybersecurity ultimately depends on having a diverse, skilled workforce. And the US arrests three in two alleged spying cases.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/189


Selected reading.

ZINC weaponizing open-source software (Microsoft Security Threat Intelligence | LinkedIn Threat Prevention and Defense)

Lazarus Group Affiliate Uses Trojanized Open Source Apps in New Campaigns (Decipher)

North Korea weaponizes open-source software. (CyberWire)

Info-Stealing Malware, SolarMarker, is Using Watering Hole Attacks… (eSentire) 

Fast Company hack causes obscene Apple News notifications. (CyberWire) 

The Future of Deepfakes. (CyberWire)

Fourth Nord Stream Leak Spotted, NATO Sees 'Sabotage' - The Moscow Times (The Moscow Times)

Russian spy chief: West was behind sabotage of Nord Stream (Reuters)

NATO Formally Blames Sabotage for Nord Stream Pipeline Damage (Wall Street Journal) 

NATO: Nord Stream pipeline leaks result of "sabotage" (Axios)

Pentagon chief: Too soon to say who might be behind Nord Stream pipeline attack (www.euractiv.com)

First on CNN: European security officials observed Russian Navy ships in vicinity of Nord Stream pipeline leaks (CNN)

Mysterious Blasts and Gas Leaks: What We Know About the Pipeline Breaks in Europe (New York Times)

NATO issues 'sabotage' warning after gas pipeline explosions (NBC News) 

Russia’s Purported Sabotage Of The Nord Stream Pipeline Marks A Point Of No Return (Forbes)

Nach Angriff auf Nord Stream 1 und 2: Ist Deutschland vor russischen Hackern sicher? (WirtschaftsWoche)

'We all have to be worried': War in Ukraine boosts energy cyberattack risks, says Petrobras executive (Upstream Online)

Finnish intelligence warns Russia ‘highly likely’ to turn to cyber in winter (The Record by Recorded Future)

Ukraine War Goes Hybrid (Energy Intelligence) 

New Warnings from Ukraine About Looming Russian Cyberattacks (VOA)a

Russian Cyber Efforts in Ukraine See Muted Results, Says Panel (USNI News)

Ukraine-Russia Conflict: Ukraine Alerts Energy Enterprises to Possible Cyberattack Escalation (Security Boulevard)

Ukraine is Winning the Cyber War (CEPA)

Hitachi Energy MicroSCADA Pro X SYS600 (CISA)

Hitachi Energy MicroSCADA Pro X SYS600 (CISA)

Baxter Sigma Spectrum Infusion Pump (CISA)

ARC Informatique PcVue (Update A) (CISA)

Delta Electronics DOPSoft (CISA)

Delta Electronics DOPSoft (Update B) (CISA) 

Former NSA Employee Arrested on Espionage-Related Charges (US Department of Justice) 

Major in the United States Army and a Maryland Doctor Facing Federal Indictment for Allegedly Providing Confidential Health Information to a Purported Russian Representative to Assist Russia Related to the Conflict In Ukraine (US Department of Justice)

Extract Knowledge

Gray-hat support for Iranian dissidents. Selling access wholesale in the C2C market. Novel malware’s discovered targeting VMware hypervisors. The Witchetty espionage group uses an updated toolkit. Deepen Desai from Zscaler has a Technical Analysis of Industrial Spy Ransomware. Ann Johnson of Afternoon Cyber Tea speaks with Michal Braverman-Blumenstyk, CTO for Microsoft Security, about Israel's cyber innovation. And Russian troops phone call revelations.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/188


Selected reading.

Hacker Groups take to Telegram, Signal and Darkweb to assist Protestors in Iran (Check Point Software)

Hackers Use Telegram and Signal to Assist Protestors in Iran (Infosecurity Magazine)

Hackers Aid Protests Against Iranian Government with Proxies, Leaks and Hacks (The Hacker News)

Hackers seek to help — and profit from — Iran protests (The Record by Recorded Future)

Ransomware and Wholesale Access Markets: A $10 investment can lead to millions in profit (Cybersixgill)

Selling access wholesale in the C2C market. (CyberWire) 

Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors (Mandiant)

Bad VIB(E)s Part Two: Detection and Hardening within ESXi Hypervisors (Mandiant) 

Mandiant has identified new malware that targets VMware ESXi, Linux vCenter servers, and Windows virtual machines. (CyberWire)

Securonix Threat Labs Security Advisory: Detecting STEEP#MAVERICK: New Covert Attack Campaign Targeting Military Contractors (Securonix)

Steep#Maverick cyberespionage campaign. (CyberWire)

Witchetty: Group Uses Updated Toolset in Attacks on Governments in Middle East (Symantec)

Witchetty espionage group uses updated toolkit. (CyberWire)

‘Putin Is a Fool’: Intercepted Calls Reveal Russian Army in Disarray (New York Times) 

Cyber Warfare Rife in Ukraine, But Impact Stays in Shadows (SecurityWeek)

Russian hackers' lack of success against Ukraine shows that strong cyber defences work, says cybersecurity chief (ZDNET)

Failure of Russia’s cyber attacks on Ukraine is most important lesson for NCSC (ComputerWeekly)

Extract Knowledge

DDoS remains the most characteristic mode of cyber ops in Russia's hybrid war against Ukraine. A leaked LockBit 3.0 builder is being used in ransomware attacks. Meta takes down Russian disinformation networks. Lazarus Group is spearphishing with bogus job offers. Joe Carrigan looks at SNAP benefit scams. Our guest is Crane Hassold of Abnormal Security with the latest in advanced email attack trends. And the cloud…is complicated.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/187


Selected reading.

Adversaries Continue Cyberattack Onslaught with Greater Precision and Innovative Attack Methods According to 1H2022 NETSCOUT DDoS Threat Intelligence Report (NETSCOUT) 

Leaked LockBit 3.0 builder used by ‘Bl00dy’ ransomware gang in attacks (BleepingComputer) 

Removing Coordinated Inauthentic Behavior From China and Russia (Meta)

Russia is spoofing mainstream media to smear Ukraine, Meta says (Protocol)

Operation In(ter)ception: social engineering by the Lazarus Group. (CyberWire)

How cloud complexity affects security. (CyberWire)

Extract Knowledge

Ukraine's Defense Intelligence warns of coming Russian cyberattacks against infrastructure. Next moves for Lapsus$? We know it’s a bear market, but take a look at your wallet, crypto speculators, at least now and then. Mr Security Answer Person john Pescatore on next year's most over-hyped term. Ben Yelin explains a thirty five million dollar data privacy settlement. And, finally, developments in the Optus breach.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/186


Selected reading.

Invaders Preparing Mass Cyberattacks on Facilities of Critical Infrastructure of Ukraine and Its Allies (Defence Intelligence of the Ministry of Defence of Ukraine) 

Ukraine Says Russia Planning 'Massive Cyberattacks' on Critical Infrastructure (SecurityWeek)

Ukraine warns of Russian cyber attacks targeting critical infrastructure (Computing) 

Russia plans “massive cyberattacks” on critical infrastructure, Ukraine warns (Ars Technica)

Ukraine warns allies: Russia plans 'massive cyberattacks' (Register)

Hackers Working With Russia to Coordinate Cyberattacks, Google Says - Tech News Briefing - WSJ Podcasts (Wall Street Journal)

Viasat Hack "Did Not" Have Huge Impact on Ukrainian Military Communications, Official Says (Zero Day) 

Who’s next in Lapsus$’ crosshairs? (Digital Shadows)

Report: Sift Uncovers New Cashout Scam Targeting Forgotten Crypto Accounts (GlobeNewswire News Room)

Optus hacker releases 10,000 customers' details and issues new threat (Sky News)

‘Last thing I need’: Optus customer scrambles to protect himself (Australian Financial Review)

An alleged hacker has offered their 'deepest apologies' to Optus. Here's the latest on the data breach (ABC)

Singtel's Optus under further fire for cyber breach; purported hackers claim data deleted (The Straits Times)

‘Not feasible’ to crack properly encrypted data (Australian Financial Review)

Optus hack not 'sophisticated' as claims 10,000 customers have data publicly released (9News)

Everything Happening in This Optus Cyberattack Shitstorm, I Promise (Vice)

Australian cybersecurity minister lambasts Optus for ‘unprecedented' hack (The Record by Recorded Future)

FBI Working With Australian Authorities on Optus Cyberattack (MarketScreener) 

Extract Knowledge

Unrest in Iran finds expression in cyberspace. Albania explains its reasons for severing relations with Iran. Cybercrime in the hybrid war. Rick Howard on risk forecasting with data scientists. Dave Bittner sits down with Dr. Bilyana Lilly to discuss her new book: "Russian Information Warfare: Assault on Democracies in the Cyber Wild West."And there seems to have been an arrest in the Uber and Rockstar breaches.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/185


Selected reading.

Iran’s War Within (Foreign Affairs)

Iran’s Hijab Protests Have Lit a Fire the Regime Can’t Put Out (World Politics Review) 

‘Something big is happening’: the Iranians risking everything to protest (the Guardian)

Dissident: 'Iranian women are furious' over headscarf death (AP NEWS)

OpIran: Anonymous declares war on Teheran amid Mahsa Amini’s death (Security Affairs)

IDF official says military foiled ‘dozens’ of Iran cyberattacks on civilian sites (Times of Israel)

Analysis | 'Our Conflict With Iran Is Unparalleled', Say Israel's Elite Cyber Unit Commanders (Haaretz) 

US Issues License to Expand Internet Access for Iranians (VOA)

US Treasury carves out Iran sanctions exceptions for internet providers (The Record by Recorded Future) 

Iran and Albania: diplomacy and cyber operations (CyberWire)

Ukraine dismantles hacker gang that stole 30 million accounts (BleepingComputer) 

The SBU neutralized a hacker group that "hacked" almost 30 million accounts of Ukrainian and EU citizens (SSU)

Les détails personnels de stars, dont Sir David Attenborough et Sarah Ferguson, ont été divulgués après le piratage d'un magasin bio par des escrocs russes (News 24) 

London Police Arrested 17-Year-Old Hacker Suspected of Uber and GTA 6 Breaches (The Hacker News)

UK teen suspected of Uber and Rockstar hacks arrested (Computing) 

Extract Knowledge

Adam Marrè, CISO from Arctic Wolf sits down to share his story of rising through the ranks. After 9/11 he decided he wanted to make a difference in the world and so he chose to go into the FBI, there he learned the skills that got him to where he is today. In his time at the FBI, he was able to do what he loved which was working with computers while gaining more knowledge on cybersecurity and became computer forensic certified. Ultimately he needed a change in the end and decided to leave the FBI, He was able to learn the leadership skills he needed to move past that career path and follow a new dream. He is now able to share his passion with the world and help people understand security to help protect themselves as well as helping people finding success in their careers and in their lives. We thank Adam for sharing his story.

Extract Knowledge

Gafnit Amiga, Director of Security Research from Lightspin joins Dave to discuss her team's research "AWS RDS Vulnerability Leads to AWS Internal Service Credentials." The research describes how the vulnerability was caught and right after it was reported the AWS Security team applied an initial patch limited only to the recent Amazon Relational Database Service (RDS) and Aurora PostgreSQL engines, excluding older versions.

They followed by personally reaching out to the customers affected by the vulnerability and helped them through the update process. The research states "Lightspin's Research Team obtained credentials to an internal AWS service by exploiting a local file read vulnerability on the RDS EC2 instance using the log_fdw extension."

The research can be found here:

Extract Knowledge

The GRU's closely coordinating with cyber criminals. An unidentified threat actor deploys malicious NPM packets. Gootloader uses blogging and SEO poisoning to attract victims. Metador is a so-far unattributed threat actor. Johannes Ullrich from SANS on Resilient DNS Infrastructure. Maria Varmazis interviews Anthony Colangelo, host of spaceflight podcast Main Engine Cutoff, about the iPhone 14 “Emergency SOS via Satellite” feature. And having too much time on your hands while doing time is not a good thing.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/184


Selected reading.

GRU: Rise of the (Telegram) MinIOns (Mandiant)

Void Balaur | The Sprawling Infrastructure of a Careless Mercenary (SentinelOne)

An unidentified threat actor deploys malicious NPM packets (CyberWire)

Threat analysis: Malicious npm package mimics Material Tailwind CSS tool (ReversingLabs)

A Multimillion Dollar Global Online Credit Card Scam Uncovered (ReasonLabs)

Gootloader Poisoned Blogs Uncovered by Deepwatch’s ATI Team (Deepwatch) 

The Mystery of Metador | An Unattributed Threat Hiding in Telcos, ISPs, and Universities (SentinelOne) 

SC inmate sentenced for ‘sextortion’ scheme that targeted military (Stars and Stripes)

Extract Knowledge

GRU operators masquerade as Ukrainian telecommunications providers. Another video game maker is compromised to spread malware. Noberus may be a successor to Darkside and BlackMatter ransomware. Robert M. Lee from Dragos explains Crown Jewel analysis. Our guest is Nathan Hunstad from Code42 with thoughts on insider risk events. Threat actors have their insider threats, too.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/183


Selected reading.

Russia-Nexus UAC-0113 Emulating Telecommunication Providers in Ukraine (Recorded Future)

Russian Cyberspies Targeting Ukraine Pose as Telecoms Providers (SecurityWeek)

Shadowy Russian Cell Phone Companies Are Cropping Up in Ukraine (WIRED)

CISA Alert AA22-264A – Iranian state actors conduct cyber operations against the government of Albania. (CyberWire)

Iranian State Actors Conduct Cyber Operations Against the Government of Albania (CISA)

2K Games says hacked help desk targeted players with malware (BleepingComputer)

2K Games helpdesk hacked to spread malware to players (TechRadar)

Rockstar parent company hacked again as 2K Support sends users malware (Dexerto)

‘Grand Theft Auto VI’ leak is Rockstar’s nightmare, YouTubers’ dream (Washington Post)

Noberus Ransomware: Darkside and BlackMatter Successor Continues to Evolve its Tactics (Symantec) 

LockBit ransomware builder leaked online by “angry developer” (BleepingComputer) 

Extract Knowledge

This alert builds on previous NSA and CISA guidance to stop malicious ICS activity and reduce OT exposure. The alert documentation linked in the show notes describes TTPs that malicious actors use to compromise OT/ICS assets. It also recommends mitigations that owners and operators can use to defend their systems from each of the listed TTPs. NSA and CISA encourage OT and ICS owners and operators to apply the recommendations in this documentation.

AA22-265A Alert, Technical Details, and Mitigations

NSA and CISA guidance to stop malicious ICS activity and reduce OT exposure

For NSA client requirements or general cybersecurity inquiries, contact Cybersecurity_Requests@nsa.gov. To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov.  

To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

Extract Knowledge

In July 2022, Iranian state cyber actors—identifying as “HomeLand Justice”—launched a destructive cyber attack against the Government of Albania which rendered websites and services unavailable. An FBI investigation indicates Iranian state cyber actors acquired initial access to the victim’s network approximately 14 months before launching the destructive cyber attack, which included a ransomware-style file encryptor and disk wiping malware.

AA22-264A Alert, Technical Details, and Mitigations

CISA’s free Cyber Hygiene Services (CyHy)

CISA’s zero–trust principles and architecture.

Iran Cyber Threat Overview and Advisories.

All organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at central@cisa.dhs.gov or (888) 282-0870 and to the FBI via your local FBI field office or the FBI’s 24/7 CyWatch at (855) 292-3937 or CyWatch@fbi.gov.

Extract Knowledge

It’s partial mobilization in Russia, and airline flights departing Russia are said to be sold out. Further notes on the IT Army's claimed hack of the Wagner Group. Leveraging Netflix for credential harvesting. Rockstar Games suffers a leak of new Grand Theft Auto footage. Ben Yelin has the latest on regulations targeting crypto. Our guest is Amy Williams from BlueVoyant discussing the value of feminine energy in the male dominated field of cybersecurity. CISA releases eight ICS Advisories.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/182


Selected reading.

Russia moves toward annexing Ukraine regions in a major escalation (Washington Post)

Four occupied Ukraine regions plan imminent ‘votes’ on joining Russia (the Guardian) 

Putin sets partial military call-up, won’t ‘bluff’ on nukes (AP NEWS)

Putin announces partial military mobilization for Russian citizens (Axios)

Pro-Ukraine Hacktivists Claim to Have Hacked Notorious Russian Mercenary Group (Vice) 

Fresh Phish: Netflix Bad Actors Go Behind the Scenes to Stage a Credential Harvesting Heist (INKY)

Leveraging Netflix for credential harvesting. (CyberWire)

Social Engineering: How A Teen Hacker Allegedly Managed To Breach Both Uber And Rockstar Games (Forbes)

Rockstar Games suffers leak of new Grand Theft Auto footage. (CyberWire) 

LastPass source code breach – incident response report released (Naked Security)

Notice of Recent Security Incident (The LastPass Blog)

The LastPass incident. (CyberWire)

Medtronic NGP 600 Series Insulin Pumps (CISA)

Hitachi Energy PROMOD IV (CISA) 

Hitachi Energy AFF660/665 Series (CISA) 

Dataprobe iBoot-PDU (CISA)

Host Engineering Communications Module (CISA)

AutomationDirect DirectLOGIC with Ethernet (CISA)

AutomationDirect DirectLOGIC with Serial Communication (CISA)

MiCODUS MV720 GPS tracker (Update A) (CISA)

Extract Knowledge

An overview of Russian cyber operations. The IT Army of Ukraine claims to have doxed the Wagner Group. Who dunnit? Lapsus$ dunnit. Emily Mossburg from Deloitte and Shelley Zalis of the Female Quotient on why gender equality is essential to the success of the cyber industry. We’ve got a special preview of the International Spy Museum's SpyCast's latest episode with host Andrew Hammond interviewing Robert Gates on the 75th anniversary of the CIA. And a look at the risk of stolen single sign-on credentials.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/181


Selected reading.

Ukraine's IT Army hacks Russia's Wagner Group (Computing)

Untangling the Russian web: Spies, proxies, and spectrums of Russian cyber behavior  (Atlantic Council)

Security update | Uber Newsroom (Uber Newsroom)

Tentative attribution in the Uber breach. (CyberWire)

Uber says Lapsus$-linked hacker responsible for breach (Reuters)

Uber blames security breach on Lapsus$, says it bought credentials on the dark web (ZDNET)

Uber's breach shows how hackers keep finding a way in (Protocol)

Uber attributes hack to Lapsus$, working with FBI and DOJ on investigation (The Record by Recorded Future)

Uber data breach spotlights need for enterprises to ‘get the basics right’, say experts (ITP.net)

"Keys to the Kingdom" at Risk: Analyzing Exposed SSO Credentials of Public Companies (Bitsight)

Extract Knowledge

An update on the Uber breach. Emotet and other malware delivery systems. Belarusian Cyber Partisans work against the regime in Minsk. Grayson Milbourne of OpenText Security Solutions on the arms race for vulnerabilities. Rick Howard continues his exploration of cyber risk. And risky piracy sites–that’s on the Internet, kids, not the high seas.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/180


Selected reading.

Developments in the case of the Uber breach. (CyberWire)

Preliminary lessons from the Uber breach. (CyberWire)

Uber says “no evidence” user accounts were compromised in hack (The Verge)

Uber Claims No Sensitive Data Exposed in Latest Breach… But There's More to This (The Hacker News)

Uber apparently hacked by teen, employees thought it was a joke (The Verge)

Uber hacker claims to have full control of company's cloud-based servers (9to5Mac)

The Uber Hack’s Devastation Is Just Starting to Reveal Itself (WIRED) 

Uber was breached to its core, purportedly by an 18-year-old. Here’s what’s known (Ars Technica)

Uber hacked by teen who annoyed employee into logging them in - report (Jerusalem Post)

18-year-old allegedly hacks Uber and sends employees messages on Slack (Interesting Engineering)

Uber Investigating Massive Security Breach by Alleged Teen Hacker (Gizmodo)

Uber cyber attack: protecting against social engineering (Information Age)

Threat actor breaches many of Uber’s critical systems (Cybersecurity Dive)

Uber hacker claims to have full control of company's cloud-based servers (9to5Mac)

Uber confirms hack in the the latest access and identity nightmare for corporate America (SC Media)

Uber hacked, attacker tears through the company's systems (Help Net Security)

Uber confirms it is investigating cybersecurity incident (The Record by Recorded Future)

UBER HAS BEEN HACKED, boasts hacker – how to stop it happening to you (Naked Security)

Emotet and other malware delivery systems. (CyberWire)

Emotet botnet now pushes Quantum and BlackCat ransomware (BleepingComputer)

AdvIntel's State of Emotet aka "SpmTools" Displays Over Million Compromised Machines Through 2022 (AdvIntel)

August’s Top Malware: Emotet Knocked off Top Spot by FormBook while GuLoader and Joker Disrupt the Index (Check Point Software)

How Belarusian hacktivists are using digital tools to fight back (The Record by Recorded Future)

Malvertising on piracy sites. (CyberWire)

Unholy Triangle (Digital Citizens' Alliance)

Piracy Advertising Researchers Fall Victim to Ransomware Attacks (TorrentFreak)

Extract Knowledge

Jaya Baloo, a Chief Information Security Officer from Avast sits down to share her story, sharing how she got into the technology field at a younger age with being introduced to computers and games on her PS 24. She started off going to college for political science and after not knowing what to do after that, she got her first start in cybersecurity. After falling in love with cybersecurity she kept moving up the ranks in different organizations before finding herself at Avast. She shares that at Avast she leans on her team quite a bit and you should never be afraid to bounce ideas off of your teammates. She says "The best ideas come from like bouncing ideas off of each other, sharing within the group and then if I can't figure it out myself, that's why I hire these amazing individuals it's to help me figure it out." We thank Jaya for sharing her story.

Extract Knowledge

Sam Crowther, CEO of Kasada join's Dave to discuss their work on "The New Way Fraudsters Bypass Bot Management." Kasada researchers recently discovered a new type of bot called Solver Services, which is used and created by bad actors to bypass the majority of bot management systems.

The research states "Now it’s easier than ever for mainstream bot operators to scrape content, take over accounts, hoard inventory, and commit other forms of automated fraud against organizations using legacy bot management solutions." Attackers are able to by these “Solver” bots, APIs, and services for less than $500 per month to make a profit.

The research can be found here:

Extract Knowledge

Uber suffers a data breach. Social media executives testify before Congress. A Large DDoS attack is thwarted in Eastern Europe. The FBI warns of increased cyberattacks against healthcare payment processors. Policy makers consider new OT security incentives. Malek Ben Salem from Accenture on future-proof cloud security. Our guest Diana Kelley from Cybrize discusses the need for innovation and entrepreneurship in cybersecurity. And if you’ve been hoping for a LockerGoga decryptor, you’re in luck.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/179


Selected reading.

Uber hacked, internal systems breached and vulnerability reports stolen (BleepingComputer) 

Uber suffers computer system breach, alerts authorities (Washington Post)

Uber Investigating Data Breach After Hacker Claims Extensive Compromise (SecurityWeek) 

Uber Investigating Breach of Its Computer Systems (New York Times)

Uber investigating "total compromise" of its internal systems (Computing) 

There’s No Honor Among Thieves: Carding Forum Staff Defraud Users in an ESCROW Scam (Digital Shadows) 

Social media hearings highlight lack of trust, transparency in sector (The Record by Recorded Future) 

Breaking the Boycott (Cybersixgill)

Record-Breaking DDoS Attack in Europe (Akamai)

Cyber Criminals Targeting Healthcare Payment Processors, Costing Victims Millions in Losses (FBI)

Siemens Mobility CoreShield OWG Software (CISA)

Siemens Simcenter Femap and Parasolid (CISA)

Siemens RUGGEDCOM ROS (CISA) 

Siemens Mendix SAML Module (CISA)

Siemens SINEC INS (CISA)

Siemens RUGGEDCOM ROS (Update A) (CISA)

Simcenter Femap and Parasolid (CISA) 

Siemens Industrial Products Intel CPUs (Update A) (CISA)

Siemens OpenSSL Affected Industrial Products (CISA) 

Siemens OpenSSL Vulnerability in Industrial Products (Update E) (CISA)

Siemens SCALANCE (CISA) 

CISA Adds Six Known Exploited Vulnerabilities to Catalog (CISA)

Building on our Baseline: Securing Industrial Control Systems Against Cyberattacks (House Committee on Homeland Security) 

Bitdefender Releases Universal LockerGoga Decryptor in Cooperation with Law Enforcement (Bitdefender Labs)

Extract Knowledge

This joint Cybersecurity Advisory highlights continued malicious cyber activity by advanced persistent threat actors affiliated with the Iranian Government’s Islamic Revolutionary Guard Corps. The IRGC-affiliated actors are actively targeting a broad range of entities, including entities across multiple U.S. critical infrastructure sectors as well as Australian, Canadian, and United Kingdom organizations. 

AA22-257A Alert, Technical Details, and Mitigations

AA22-257A.stix

CISA’s Iran Cyber Threat Overview and Advisories

FBI’s Iran Threat webpage.

Iranian Government-Sponsored APT Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities in Furtherance of Malicious Activities

Technical Approaches to Uncovering and Remediating Malicious Activity

All organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at central@cisa.dhs.gov or (888) 282-0870 and to the FBI via your local FBI field office or the FBI’s 24/7 CyWatch at (855) 292-3937 or CyWatch@fbi.gov.

Extract Knowledge

Nuisance-level DDoS and cyberespionage continue to mark Russia's cyber campaign in the hybrid war. There’s a US Presidential memorandum on software supply chain security. Webworm repurposes older RATs. Trends in cyber insurance claims. OriginLogger may be the new Agent Tesla. The SparklingGoblin APT described. Mathieu Gorge of VigiTrust describes cyber vulnerabilities in the hospitality industry. Dinah Davis from Arctic Wolf explains a PayPal phishing attack. And Royal funeral phishbait.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/178


Selected reading.

Pro-Russia hackers claim to have temporarily brought down Japanese govt websites (Asia News Network)

Gamaredon APT targets Ukrainian government agencies in new campaign (Cisco Talos)

Russia-linked Gamaredon APT target Ukraine with a new info-stealer (Security Affairs)

Fears grow of Russian spies turning to industrial espionage (The Record by Recorded Future)

Enhancing the Security of the Software Supply Chain through Secure Software Development Practices (The White House)

Enhancing the Security of the Software Supply Chain to Deliver a Secure Government Experience (The White House)

White House releases post-SolarWinds federal software security requirements (Federal News Network)

Webworm: Espionage Attackers Testing and Using Older Modified RATs (Threat Hunter Team Symantec)

Coalition Releases 2022 Cyber Claims Report: Mid-year Update (GlobeNewswire News Room)

OriginLogger: A Look at Agent Tesla’s Successor (Unit 42) 

You never walk alone: The SideWalk backdoor gets a Linux variant (WeLiveSecurity)

[Scam site harvests credentials] (Proofpoint)

Current, former social media execs address national security issues at Senate hearing (Fox Business)

Senators Have Stopped Embarrassing Themselves at Tech Hearings (Slate Magazine)

Extract Knowledge

Patch Tuesday notes. The US Senate Judiciary Committee hears from the Twitter whistleblower. Joint warning of IRGC cyber activity. Rob Boyce from Accenture on cybercriminals weaponizing leaked ransomware data. Chris Novak from Verizon describes his participation in the CISA Advisory Board. And Ukraine reiterates confidence in its resiliency.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/177


Selected reading.

Adobe Patches 63 Security Flaws in Patch Tuesday Bundle (SecurityWeek)

Microsoft Releases September 2022 Security Updates (CISA)

Microsoft's September Patch Tuesday fixes five critical bugs (Computing)

Microsoft Raises Alert for Under-Attack Windows Flaw (SecurityWeek)

SAP Security Patch Day September 2022 (Onapsis) 

Apple Releases Security Updates for Multiple Products (CISA)

Apple fixes eighth zero-day used to hack iPhones and Macs this year (BleepingComputer) 

Apple Will Let You Remove Rapid Security Response Updates in iOS 16 (Mac Rumors)

Data Security at Risk: Testimony from a Twitter Whistleblower (United States Senate Committee on the Judiciary)

Twitter Employees Have Too Much Access to Data, Whistleblower Says (Wall Street Journal) 

Twitter whistleblower reveals employees concerned China agent could collect user data (Reuters)

Security failures cause ‘real harm to real people’ (Washington Post)

Twitter whistleblower testifies to Congress, calls for tech regulation reforms (The Record by Recorded Future)

The Search for Dirt on the Twitter Whistle-Blower (The New Yorker)

Whistle-Blower Says Twitter ‘Chose to Mislead’ on Security Flaws (New York Times) 

Twitter whistleblower says site put growth over security (Computing) 

Written Statement of Peiter (“Mudge”) Zatko United States Senate Judiciary Committee September 13, 2022 (Katz Banks Kumin) 

What we learned when Twitter whistleblower Mudge testified to Congress (TechCrunch) 

How China became big business for Twitter (Reuters)

Twitter whistleblower exposes limits of FTC’s power (Washington Post)

Twitter Whistle-Blower Testimony Spurs Calls for Tech Regulator (Bloomberg)

Iranian Islamic Revolutionary Guard Corps-Affiliated Cyber Actors Exploiting Vulnerabilities for Data Extortion and Disk Encryption for Ransom Operations (CISA)

Ukraine’s Cyberwar Chief Sounds Like He’s Winning (WIRED) 

DDoS attacks on financial sector surge during war in Ukraine, new FCA data reveals (PR Newswire)

Extract Knowledge

In this extended interview, CyberWire Daily Podcast host Dave Bittner sits down with members of the FBI's Baltimore field office: Special Agent in Charge, Tom Sobocinski, and Supervisory Special Agent for Cyber, Tom Breeden. As part of the FBI's cybersecurity awareness campaign, they discuss what the FBI can do to enhance and amplify cyber efforts in ways unlike any other public or private organization. This interview from August 30, 2022 originally aired as a shortened version on the CyberWire Daily Podcast.

Extract Knowledge

Apple patches its software. Reviewing the cyber phase of a hybrid war. The return of the (ShadowPad) alumni. Phishing from the Static Expressway. The state of cloud security. Overconfidence comes at a cost. Ann Johnson of Afternoon Cyber Tea speaks with Dr. Josephine Wolff from the Fletcher School about cyber insurance past. My conversation with FBI special agents Tom Sobocinski and Tom Breeden. And Charming Kitten and group-think in social engineering.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/176


Selected reading.

Apple security updates (Apple Support)

Ukraine Cyber War Update September 2022 (CyberCube)

New Wave of Espionage Activity Targets Asian Governments (Broadcom Software Blogs)

Chinese gov’t hackers using ‘diverse’ toolset to target Asian prime ministers, telecoms (The Record by Recorded Future)

Leveraging Facebook Ads to Send Credential Harvesting Links (Avanan)

Unpatched and Outdated Medical Devices Provide Cyber Attack Opportunities (FBI) 

CFO Cyber Security Survey: Over-Confidence is Costly (Kroll) 

Snyk’s State of Cloud Security Report Reveals 80% of Organizations Have Experienced a Severe Cloud Security Incident in Past Year (Snyk) 

Look What You Made Me Do: TA453 Uses Multi-Persona Impersonation to Capitalize on FOMO (Proofpoint)

Iranian military using spoofed personas to target nuclear security researchers (The Record by Recorded Future)

Alleged cyber commander of Iran’s Revolutionary Guard named by opposition outlet (Times of Israel)

Extract Knowledge

Albania reports additional cyberattacks from Iran over the weekend. RaidForums has a new successor. A look at threat actor reconnaissance in the contemporary Internet. Kinetic strikes hit Ukraine’s infrastructure. Rick Howard calculates risk with classic mathematical theorems. Tim Eades from Cyber Mentor Fund on the dynamic nature of the attack surface. And a look into the cyber phase of the hybrid war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/175


Selected reading.

Albania blames Iran for second cyberattack since July (CNN)

Treasury Sanctions Iranian Ministry of Intelligence and Minister for Malign Cyber Activities (US Department of the Treasury)

Iran strongly condemns US sanctions over Albania hacking (Al Arabiya)

Six months into Breached: The legacy of RaidForums? (KELA)

2022 State of the Internet Report (Censys)

Ukraine hails snowballing offensive, blames Russia for blackouts (Reuters)

Ukraine says Russia is retaliating by hitting critical infrastructure, causing blackouts. (New York Times)

Last reactor at Ukraine’s Zaporizhzhia nuclear plant stopped (Associated Press)

Ukraine Warns Russian Cyber Onslaught Is Coming (Voice of America)

Montenegro wrestles with massive cyberattack, Russia blamed (ABC News)

CyberCube: Russia’s Sovereign Internet Creates Security Risks With Implications for Cyber (Re)Insurance While War in Ukraine Develops (Associated Press)

Extract Knowledge

Mark Logan, CEO of One Identity, sits down to share his story, explaining how he fit into different roles growing up in different companies. Mark has nearly two decades of C-Suite experience at an array of different organizations, finally landing on his current position as the CEO at One Identity. Sharing his different roles, he also gives a quote from Steve Jobs, saying "it's not what I say yes to, it's what I say no to." He believes that's a key area for his workers because when he is able to make up his mind, his team and his customers have someone they can rely on. Mark says that as a CEO he wants to share the advice of always marching towards your goals, and identifying that different people have different goals because they work in different fields, but that's what makes a company work best. He says "I've found that the more you can delegate, provided you've got the right folks in place the better." We thank Mark for sharing his story.

Extract Knowledge

Deepen Desai from Zscaler ThreatLabz joins Dave to discuss their work on "Return of the Evilnum APT with updated TTPs and new targets." Zscaler’s ThreatLabz team recently caught a new Evilnum APT attack campaign that uses the document template on MS Office Word to inject malicious payload to the victim's machine. There are three new instances used of the campaign, including updated tactics, techniques, and procedures.

Researchers have been closely monitoring Evilnum APT’s activity. They ssay ThreatLabz identified several domains associated with the Evilnum APT group. Which has led them to discover that the "group has been successful at flying under the radar and has remained undetected for a long time."

The research can be found here:

Extract Knowledge

Nation-states are expected to target the US midterm elections. North Korea’s Lazarus Group is targeting energy companies. The Ukraine’s Ministry of Digital Transformation on cyber lessons learned from Russia’s hybrid war against Ukraine. CISA flags twelve known exploited vulnerabilities for attention and remediation. Vulnerable anti-cheat engines used for malicious purposes. Steve Carter from Nucleus Security has thoughts on AI in cybersecurity. Roland Cloutier, former CSO of TikTok, discusses working around the changing career field, needs, and how enterprise executives are developing and finding talent. And a look at top gaming-related malware lures.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/174


Selected reading.

Mandiant ‘highly confident’ foreign cyberspies will target US midterm elections (The Register)

What to Expect When You’re Electing: Preparing for Cyber Threats to the 2022 U.S. Midterm Elections (Mandiant)

North Korea’s Lazarus hackers are exploiting Log4j flaw to hack US energy companies (TechCrunch)

Lazarus and the tale of three RATs (Cisco Talos)

How Gaming Cheats Are Cashing in Below the Operating System (Eclypsium)

Good game, well played: an overview of gaming-related cyberthreats in 2022 (Securelist)

Cybercriminals target games popular with kids to distribute malware (The Register)

CISA Adds Twelve Known Exploited Vulnerabilities to Catalog  (CISA)

Extract Knowledge

Bronze President shows both enduring interests and adaptability. Iranian threat actor activity is reported. Cybersecurity and small-to-medium businesses. An initial access broker repurposes Conti's old playbook for use against Ukraine. Johannes Ullrich from SANS on Scanning for VoIP Servers. Our guest is Ian Smith from Chronosphere on observability. And Kyivstar as a case study in telco resiliency.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/173


Selected reading.

BRONZE PRESIDENT Targets Government Officials (Secureworks)

APT42: Crooked Charms, Cons, and Compromises (Mandiant)

Profiling DEV-0270: PHOSPHORUS’ ransomware operations (Microsoft)

Albania cuts diplomatic ties with Iran over July cyberattack (The Washington Post)

Initial access broker repurposing techniques in targeted attacks against Ukraine (Google)

Unprecedented Shift: The Trickbot Group is Systematically Attacking Ukraine (IBM SecurityIntelligence)

Ransomware gang's Cobalt Strike servers DDoSed with anti-Russia messages (BleepingComputer)

Ukraine’s largest telecom stands against Russian cyberattacks (POLITICO)

Extract Knowledge

The Albanian government attributes a disruptive cyber attack to Iran. TikTok says it’s found no evidence of a data breach. Researchers have discovered a new strain of Linux malware. US agencies warn of ransomware targeting the education sector. Finland prepares to increase its cybersecurity capacity. Deepen Desai from Zscaler on the latest updates to Raccoon Stealer. Our guest is Lance Spitzner from the SANS Institute with results of their recent Security Awareness Report. And a fond farewell to the father of Let’s Encrypt.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/172


Selected reading.

Albania cuts Iran ties over cyberattack, U.S. vows further action (Reuters)

Statement by NSC Spokesperson Adrienne Watson on Iran’s Cyberattack against Albania (The White House)

TikTok Data Breach Exposing 2B Records And Source Code May Not Have Happened After All (Hot Hardware)

TikTok Denies Data Breach Reportedly Exposing Over 2 Billion Users' Information (The Hacker News)

Shikitega - New stealthy malware targeting Linux (AT&T Alien Labs)

#StopRansomware: Vice Society (CISA)

Peter Eckersley, tech activist and founder of Let's Encrypt, dies at 43 (Techspot)

Honoring Peter Eckersley, Who Made the Internet a Safer Place for Everyone (Electronic Frontier Foundation)

Extract Knowledge

CISA, the FBI, and the Multi-State Information Sharing and Analysis Center, or MS ISAC, are releasing this advisory to disseminate indicators of compromise and TTPs associated with Vice Society actors and their ransomware campaigns. The FBI, CISA, and the MS-ISAC have recently observed Vice Society actors disproportionately targeting the education sector with ransomware attacks.

AA22-249A Alert, Technical Details, and Mitigations

Stopransomware.gov is a whole-of-government approach that gives one central location for ransomware resources and alerts.

Resource to mitigate a ransomware attack: CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide.

No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

All organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at central@cisa.dhs.gov or (888) 282-0870 and to the FBI via your local FBI field office or the FBI’s 24/7 CyWatch at (855) 292-3937 or CyWatch@fbi.gov.

Extract Knowledge

A Phishing-as-a-service offering on the dark web bypasses MFA. The Worok cyberespionage group is active in Central Asia and the Middle East. Prynt Stealer and the evolution of commodity malware. Sharkbot malware reemerged in Google Play. BlackCat/ALPHV claims credit for attack on the Italian energy sector. Joe Carrigan shares stats on social engineering. Our guest is Angela Redmond from BARR Advisory with six cybersecurity KPIs. And the Los Angeles Unified School District was hit with ransomware.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/171


Selected reading.

EvilProxy Phishing-As-A-Service With MFA Bypass Emerged In Dark Web (Resecurity)

Worok: The big picture (WeLiveSecurity) 

Dev backdoors own malware to steal data from other hackers (BleepingComputer) 

The Prynt Stealer malware contains a secret backdoor. Crooks steal data from other cybercriminals (Security Affairs)

Fake Antivirus and Cleaner Apps Caught Installing SharkBot Android Banking Trojan (The Hacker News)

SharkBot malware sneaks back on Google Play to steal your logins (BleepingComputer) 

BlackCat ransomware claims attack on Italian energy agency (BleepingComputer)

11.84GB of United States Military Contractor and Military Reserve data has been leaked. (vx-underground)

Hackers honeytrap Russian troops into sharing location, base bombed: Report (Newsweek) 

LAUSD hit by hackers in apparent cyber attack (FOX 11 Los Angeles)

Los Angeles Unified Targeted by Ransomware Atta (Los Angeles Unified School District)

Extract Knowledge

Anjali Hansen, a senior privacy counselor from Noname Security shares her story as she climbed through the ranks to get to where she is toady. When Anjali started she wanted to do international law. She started working for the International Trade Commission after law school which is where she was able to gain most of her experience and gain real world abilities. Working with online fraud and abuse, she shares, concerned her because it felt like governments could not protect organizations from threats occurring, which is how she got interested in cyber crime. From there, she moved to Noname Security and working there she found that she is working with every group in the organization, creating a cross team collaboration and how much she admires that type of model. She says "We have to help other departments protect the data because the data's throughout an organization, it's in HR, it's in sales and marketing, it's in IT, it's in finance. So you have to be able to work with all these teams." We thank Anjali for sharing her story.

Extract Knowledge

Ryan Kovar from Splunk sits down with Dave to discuss their findings in "Truth in Malvertising?" that contradict the LockBit group's encryption speed claims. Splunk's SURGe team recently released a whitepaper, blog, and video that outlined the encryption speeds of 10 different ransomware families. During their research they cam across Lockbit doing the same thing. After completing the research, the researchers came back to test the veracity of LockBit’s findings.

The research showed three interesting finds. The first find showed that LockBit’s fastest and slowest samples were closely aligned between the tests, but the other results were very different. They also found that LockBit continues to be the fastest ransomware, but LockBit 2.0 was more efficient yet slower than its previous counterpart, LockBit 1.0. Lastly, once ransomware gets to the point of encrypting your systems, it’s too late.

The research can be found here:

Extract Knowledge

REvil (or an impostor, or successor) may be back. A Paris-area medical center continues to work to recover from cyber extortion. An assessment of Russian failure (or disinclination) to mount effective cyber campaigns. Cyber criminals find wartime to be a tough time. Josh Ray from Accenture looks at cyber threats to the rail industry. Our guest is Dan Murphy of Invicti making the case that not all vulnerabilities are created equal. And Yandex Taxi’s app was hacked in a nuisance attack.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/170


Selected reading.

REvil says they breached electronics giant Midea Group (Cybernews)

Paralysed French hospital fights cyber attack as hackers lower ransom demand (RFI)

French hospital hit by $10M ransomware attack, sends patients elsewhere (BleepingComputer)

Hacks tied to Russia and Ukraine war have had minor impact, researchers say (The Record by Recorded Future) 

Getting Bored of Cyberwar: Exploring the Role of the Cybercrime Underground in the Russia-Ukraine Conflict (arXiv:2208.10629v2) 

Why Russia's cyber war in Ukraine hasn't played out as predicted (New Atlas)

Cyber key in Ukraine war, says spy chief (The Canberra Times) 

Montenegro Sent Back to Analog by Unprecedented Cyber Attacks (Balkan Insight)

Montenegro blames criminal gang for cyber attacks on government (EU Reporter)

Ransomware Attack Sends Montenegro Reaching Out to NATO Partners (Bloomberg) 

“I’m tired of living in poverty” – Russian-Speaking Cyber Criminals Feeling the Economic Pinch (Digital Shadows)

Yandex Taxi hack creates huge traffic jam in Moscow (Cybernews)

Anonymous hacked Russia's largest taxi firm and caused a massive traffic jam (Daily Star)

Extract Knowledge

The BianLian ransomware gang is better at coding than at the business of crime. The Attack on Montenegro seems to be ransomware. A look at Ragnar Locker's current interests. Recruiting for gangland gets allusive, but those who know, well, they know. Our guest is Dan Lanir of OPSWAT with insights on recent federal legislation supporting cyber jobs. Ben Yelin lexamines a lawsuit filed by the FTC against an online data broker. And it’s Insider Threat Month, so keep an eye on yourself.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/169


Selected reading.

BianLian Ransomware Gang Gives It a Go! ([redacted]) 

Montenegro blames criminal gang for cyber attacks on government (Reuters) 

FBI's team to investigate massive cyberattack in Montenegro (AP NEWS) 

US issues rare security alert as Montenegro battles ransomware (TechCrunch) 

Cuba ransomware group claims attack on Montenegro government (IT PRO) 

Cuba Ransomware Team claims credit for attack on Montenegro (Databreaches.net) 

Montenegro blames Cuba ransomware for cyberattack (Cybernews) 

Cybercriminals Apparently Involved in Russia-Linked Attack on Montenegro Government (SecurityWeek)

THREAT ANALYSIS REPORT: Ragnar Locker Ransomware Targeting the Energy Sector (Cybereason)

Behind the News: The Ragnar Locker Attack on Greek Natural Gas Supplier DESFA - Radiflow (Radiflow)

Mobile App Supply Chain Vulnerabilities Could Endanger Sensitive Business Information (Broadcom Software Blogs / Threat Intelligence) 

“Looking for pentesters”: How Forum Life Has Conformed to the Ransomware Ban (Digital Shadows) 

NCSC and Federal Partners Focus on Countering Risk in Digital Spaces during National Insider Threat Awareness Month 2022 (ODNI)

Extract Knowledge

While multi-cloud brings significant benefits, it also poses serious security risks. And identity is the reason. Each cloud platform, such as Azure, Google, and AWS, uses proprietary identity systems, and the lack of interoperability makes it unruly to manage. These disparate systems can’t talk to each other resulting in a fragmented environment full of identity silos — the perfect way for an attacker to get in and cause destruction.

In this episode of CyberWire-X, the CyberWire's CSO, Chief Analyst, and Senior Fellow, Rick Howard, is joined in the first half by Hash Table member Rick Doten, the CISO for Healthcare Enterprises and Centene. In the second half of the show, CyberWire podcast host Dave Bittner talks with our episode sponsor Strata Identity's CEO and Co-founder Eric Olden. Both sets of discussions center around the challenges to identity management caused by the rapid shift to multi-cloud. 

Extract Knowledge

Chrome extensions steal browser data. A business email compromise attack is under investigation in Kentucky. Belarusian Cyber Partisans claim to have a complete Belarusian passport database. Organizing a cyber militia. CISA releases twelve ICS security advisories. Our guest is Asaf Kochan of Sentra on overemphasizing “the big one.” Carole Theriault cautions against getting ahead of yourself in the cryptocurrency supply chain. Cosplaying" hardware. And Canada welcomes a new SIGINT boss.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/168


Selected reading.

Chrome extensions with 1.4 million installs steal browsing data (BleepingComputer) 

Malicious Cookie Stuffing Chrome Extensions with 1.4 Million Users (McAfee Blog) 

Police investigate electronic theft of federal funds (City of Lexington) 

FBI, Secret Service join Kentucky investigation into $4 million cybercrime theft (The Record by Recorded Future)

Russian hackers blamed for ongoing Montenegro cyberattack (Tech Monitor)

“For the 1st time in human history a #hacktivist collective obtained passport info of the ALL country's citizens.” (Cyber Partisans)

Inside the IT Army of Ukraine, ‘A Hub for Digital Resistance’ (The Record by Recorded Future) 

Ukraine takes down cybercrime group hitting crypto fraud victims (BleepingComputer) 

Hitachi Energy FACTS Control Platform (FCP) Product (CISA)

Hitachi Energy Gateway Station (GWS) Product (CISA)

Hitachi Energy MSM Product (CISA).

Hitachi Energy RTU500 series (CISA)

Fuji Electric D300win (CISA)

Honeywell ControlEdge (CISA)

Honeywell Experion LX (CISA)

Honeywell Trend Controls Inter-Controller Protocol (CISA)

Omron CX-Programmer (CISA)

PTC Kepware KEPServerEX (CISA)

Sensormatic Electronics iSTAR (CISA)

Mitsubishi Electric GT SoftGOT2000 (CISA)

Walmart Sells Fake 30TB Hard Drive That’s Actually Two Small SD Cards in a Trench Coat (Vice)

Extract Knowledge

Cyberespionage around the South China Sea. Oktapus and the Twilio compromise. Montenegro works to recover from a Russian cyber offensive. A big Russian streaming platform sustains a data leak. Ann Johnson of the Afternoon Cyber Tea podcast speaks with Dave DeWalt of NightDragon and Jay Leek of both Syn Ventures and Clear Sky Security about cyber capital investment. Mr. Security Answer Person John Pescatore examines the allure of the healthcare industry for ransomware operators. And the LockBit gang looks beyond double extortion.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/167


Selected reading.

Rising Tide: Chasing the Currents of Espionage in the South China Sea (Proofpoint) 

Why the Twilio Breach Cuts So Deep (WIRED)

Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms (Threatpost)

Hackers used Twilio breach to intercept Okta onetime passwords (SiliconANGLE)

Okta Impersonation Technique Could be Utilized by Attackers (SecurityWeek)

Ukraine launches counter-offensive to retake Kherson from Russia (The Telegraph)

Russia-Ukraine war: Kremlin insists invasion going to plan despite counterattacks; first grain ship docks in Africa – live (the Guardian)

Montenegro says Russian cyberattacks threaten key state functions (BleepingComputer)

Montenegro struggles to recover from cyberattack that officials blame on Russia (The Record by Recorded Future)

Leading Russian streaming platform suffers data leak allegedly impacting 44 million users (The Record by Recorded Future) 

LockBit ransomware mulls triple extortion following DDoS attack (SC Media)

Extract Knowledge

Russian cyber operations in Southeastern Europe. The challenge of containing the cyber phases of a hybrid war. Russian and Chinese cyber activity in Latin America. Greenwashing influence operations. Rick Howard looks at risk probabilities. Dinah Davis from Arctic Wolf looks at ransomware payment myths. And an Iranian threat actor exploits Log4j vulnerabilities against Israeli targets.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/166


Selected reading.

Russia blamed for wave of hacker attacks in Southeast Europe (BNE)

Montenegro declares it is in 'hybrid war' with Russia after massive cyber attack (Metro)

Montenegro reports massive Russian cyberattack against govt (ABC News)

Montenegro Reports Massive Russian Cyberattack Against Govt (AP via SecurityWeek)

Montenegro's state infrastructure hit by cyber attack -officials (Reuters) 

Cyber Element in the Russia-Ukraine War & its Global Implications (Modern Diplomacy)

Swiss secret service worried about Russian cyber operations (SWI swissinfo.ch)

China and Russia Step Up Cyber Presence in Latin America (Diálogo Américas)

Dominican Republic refuses to pay ransom after attack on agrarian institute (The Record by Recorded Future) 

China-Linked Bots Attacking Rare Earths Producer ‘Every Day’ (Bloomberg) 

Iranian Hackers Exploiting Unpatched Log4j 2 Bugs to Target Israeli Organizations (The Hacker News)

MERCURY leveraging Log4j 2 vulnerabilities in unpatched systems to target Israeli organizations (Microsoft Threat Intelligence Center)

Iran exploiting Log4j 2 weakness to attack Israel, says Microsoft (Israel Defense)

Extract Knowledge

David Nosibor, Product Lead for SafeCyber at UL Solutions, started his career in a unique way by not letting himself be pigeonholed. Within his company, David was able to grow to the position he is in now and says that his position feels like a lot of roles tied into one. He says that on any given day he is tackling all sorts of elements, such as marketing, operations, working with the engineering team, figuring out ways to acquire customers, retain them, and also working on sales and business development capabilities. He also says that constantly learning and getting new opportunities was how he ended up being where he is today. David states that staying focused and being on the lookout for ways to accomplish the mission is the best way for him in his company to democratize product security. He quotes the famous singer Sean Carter in saying that he firmly believes in taking calculated risks to get where you need to be going. We thank David for sharing his story.

Extract Knowledge

Nick Ascoli from ForeTrace in a partnership with PIXM sits down with Dave to provide insight on their team's work on "Phishing tactics: how a threat actor stole 1 million credentials in 4 months." During routine analysis, researchers discovered the connection between the pages using PIXM’s deep html analysis feature, which enabled them to view and analyze the underlying code on the pages after they were flagged as phishing. This led to the ensuing investigation, which was led by PIXM’s threat research team with assistance from Nick Ascoli.

The research states "we uncovered a campaign whose scale has potentially impacted hundreds of millions of facebook users, and whose complexity offer insight into the evolving nature of phishing operations, especially from a technical perspective."

The research can be found here:

Extract Knowledge
Show details
Episodes
3784
Transcripts
68
2% coverage
Missing transcripts
3716
With chapters
0