Search this show’s transcripts

CyberWire Daily

en us
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

Episodes

Page 35 · 50 per page

In this extended interview, CyberWire Daily Podcast host Dave Bittner sits down with Cybersecurity and Infrastructure Security Agency (CISA) Director Jen Easterly to discuss her time at CISA and the work of her team. This interview from July 15, 2022 originally aired as a shortened version on the CyberWire Daily Podcast.

Extract Knowledge

An overview of the cyber phase of Russia's hybrid war. Smartphones as sources of targeting information. Lilith enters the ransomware game. ChromeLoader makes a fresh appearance. Honda acknowledges that Rolling-PWN is real (but says it's not as serious as some think). Part two of Carole Theriault’s conversation with Jen Caltrider from Mozilla's Privacy Not Included initiative. Our guest is Josh Yavor of Tessian to discuss Accidental Data Loss Over Email. A guilty verdict in the Vault 7 case.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/134


Selected reading.

Ukraine's Cyber Agency Reports Q2 Cyber-Attack Surge (Infosecurity Magazine)

2022 Q2 (SSSCIP)

The weaponizing of smartphone location data on the battlefield (Help Net Security) 

New Lilith ransomware emerges with extortion site, lists first victim (BleepingComputer) A new ransomware operation has been launched under the name 'Lilith,' and it has already posted its first victim on a data leak site created to support double-extortion attacks.

New Ransomware Groups on the Rise (Cyble) Cyble analyzes new ransomware families spotted in the wild led by notable examples such as LILITH, RedAlert, and 0Mega.

New Lilith ransomware emerges with extortion site, lists first victim (BleepingComputer)

New Ransomware Groups on the Rise (Cyble)

Researchers Uncover New Variants of the ChromeLoader Browser Hijacking Malware (The Hacker News)

ChromeLoader: New Stubborn Malware Campaign (Unit 42) 

Honda Admits Hackers Could Unlock Car Doors, Start Engines (SecurityWeek) Honda redesigning latest vehicles to address key fob vulnerabilities (The Record by Recorded Future) 

Statement Of U.S. Attorney Damian Williams On The Espionage Conviction Of Ex-CIA Programmer Joshua Adam Schulte (US Department of Justice) 

Ex-C.I.A. Engineer Convicted in Biggest Theft Ever of Agency Secrets (New York Times)

Former CIA Staffer Convicted For Massive Data Breach To WikiLeaks (Forbes)

Extract Knowledge

Adversary-in-the-middle sites support business email compromise. Silent validation carding bot discovered. Attempted social engineering at the European Central Bank. Germany puts its shields up. Carole Theriault speaks with Jen Caltrider about Mozilla's *Privacy Not Included initiative. Our guest is Lucia Milica on Proofpoint’s Voice of the CISO report. And Hacktivism in a hybrid war.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/133


Selected reading.

From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud (Microsoft Security Blog) 

PerimeterX Discovers New Silent Validation Carding Bot (PerimeterX)

Hackers posing as Merkel target ECB's Lagarde - German source (Reuters) 

European Central Bank head targeted in hacking attempt (AP NEWS)

Cyberangriff auf Spitzenpolitiker: Hacker nutzten Merkels Handynummer, um das Whatsapp-Konto von Lagarde zu knacken (Business Insider)

Germany bolsters defenses against Russian cyber threats (Deutsche Welle) 

Ukraine's cyber army hits Russian cinemas (CyberNews)

DDoS attacks surge in popularity in Ukraine — but are they more than a cheap thrill? (The Record by Recorded Future)

Microsoft Releases July 2022 Security Updates (CISA)

CISA orders agencies to patch new Windows zero-day used in attacks (BleepingComputer)

SAP Releases July 2022 Security Updates (CISA)

Schneider Electric Easergy P5 and P3 (CISA)

Dahua ASI7213X-T1 (CISA)

Extract Knowledge

High-end and low-end extortion. Vehicles from Honda may soon be rolling off the lot. Social media and open-source intelligence. Russian cyberattacks spread internationally. Joe Carrigan surveys items for sale in dark web markets. Our guest is Jonathan Wilson of AU10TIX to discuss consumer sentiment around data privacy. Preparing for cyber combat.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/132


Selected reading.

BlackCat (Aka ALPHV) Ransomware Is Increasing Stakes Up To $2,5M In Demands (Resecurity)

Ransomware gang now lets you search their stolen data (BleepingComputer)

Luna Moth: The Actors Behind the Recent False Subscription Scams (Sygnia)

'Luna Moth' Group Ransoms Data Without the Ransomware (Dark Reading)

Hackers can unlock Honda cars remotely in Rolling-PWN attacks (BleepingComputer)

Hackers Say They Can Unlock and Start Honda Cars Remotely (Vice)

Rolling PWN (PWN) 

Russia launches attack on Poland as hackers declare war on 10 countries, including UK (Express)

Vice Minister: cyber attacks are aimed at seeking publicity and raising tensions (DELFI)

How one Ukrainian ethical hacker is training 'cyber warriors' in the fight against Russia (The Record by Recorded Future)

The Biggest Threat to the Military May Not Be What You Think (ClearanceJobs)

Extract Knowledge

More deniable DDoS attacks strike countries friendly to Ukraine. Predatory Sparrow's assault on Iran's steel industry. A callback phishing campaign impersonates security companies. The Anubis Network is back. Thomas Etheridge from CrowdStrike on the importance of outside threat hunting. Rick Howard weighs in on sentient AI. And a ransomware gang ups the ante.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/131


Selected reading.

Pro-Russian cybercriminals briefly DDoS Congress.gov (CyberScoop)

Lithuania's state-owned energy group hit by 'biggest cyber attack in a decade' (lrt.lt)

Ignitis Group hit by DDoS attack as Killnet continues Lithuania campaign (Tech Monitor)

Russian ‘Hacktivists’ Are Causing Trouble Far Beyond Ukraine (Wired - 07-11-2022) 

Predatory Sparrow: Who are the hackers who say they started a fire in Iran? (BBC News)

Hacktivists claiming attack on Iranian steel facilities dump tranche of 'top secret documents' (CyberScoop)

Callback Phishing Campaigns Impersonate CrowdStrike, Other Cybersecurity Companies (CrowdStrike)

Anubis Networks is back with new C2 server (Security Affairs)

BlackCat (aka ALPHV) ransomware is increasing stakes up to $2.5 million in demands(Help Net Security)

Resecurity - BlackCat (aka ALPHV) Ransomware is Increasing Stakes up to $2,5M in Demands (Resecurity)

Extract Knowledge

Simone Petrella, CEO of cybersecurity training workforce firm CyberVista, spent her career in the Department of Defense as a threat intelligence analyst before founding CyberVista. She says that running a company has a new set of challenges each day thrown at you. She explains that the way she finds the most success is by letting her team contribute to each matter, and having a say in the decisions made as they pertain to each department. Simone says "I would say is I am a firm firm believer in the idea of empowering people to really own and kind of run with the things that they're passionate about." She notes that people will do amazing things when they are passionate and that faking it until you make it is true, because you will get where you're going by having that passion and that inspiration. We thank Simone for sharing her story.

Extract Knowledge

Alden Wahlstrom, senior analyst on Mandiant's Information Operations Team, shares a comprehensive overview and analysis of the various information operations activities they’ve seen while responding to the Russian invasion. While the full extent of the Russia-Ukraine war has yet to come to light, more than two months after the start of the invasion, Mandiant has identified activity that they believed to be information operations campaigns conducted by actors possibly in support of the political interests of nation-states such as Russia, Belarus, China, and Iran.

The research shares a chart with all of the known information operations events that have taken place so far dating back to January of 2022. It also states that following the beginning of the Russian attack they have seen concerning signs, including "incidents involving the deployment of wiper malware disguised as ransomware."

The research can be found here:

Extract Knowledge

An update on cyber operations in the hybrid war. NPM compromise updates. Free decryptors for AstraLocker and Yashma ransomware. Johannes Ullrich from SANS on attacks against Perimeter Security Devices. Our guest is Sonali Shah from Invicti Security with a look at DevSecOps anxiety. And who’s the villain who hijacked the Instagram account of Disneyland?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/130


Selected reading.

Russia-Ukraine war: List of key events, day 135 (Al Jazeera)

Russia-Ukraine war: Putin warns Moscow has 'barely started' its campaign (The Telegraph) 

Russian Cybercrime Trickbot Group is systematically attacking Ukraine (Security Affairs) 

US finance sector encouraged to stay vigilant against retaliatory Russian cyberattacks (SC Magazine) 

Someone may be prepping an NPM crypto-mining spree (Register) 

ICS CERT Advisories (CISA)

Free decryptor released for AstraLocker, Yashma ransomware victims (BleepingComputer) 

Disneyland’s Instagram Account Hacked With a Series of Profane, Racist Posts (Wall Street Journal)

Extract Knowledge

The FBI and MI-5 warn of Chinese industrial espionage. Revelations of Trickbot's privateering role. Russian influence operations target France, Germany, Poland, and Turkey. Chinese APTs target Russian organizations in a cyberespionage effort. Robert M. Lee from Dragos on CISA expanding the Joint Cyber Defense Collaborative. Ben Yelin speaks with Matt Kent from Public Citizen about the American Innovation and Online Choice Act. And who would guess it, but NFT scams are pestering Ukraine.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/129


Selected reading.

Heads of FBI, MI5 Issue Joint Warning on Chinese Spying (Wall Street Journal) 

FBI and MI5 leaders give unprecedented joint warning on Chinese spying (the Guardian)

FBI and MI5 bosses: China cheats and steals at massive scale (Register)

FBI director suggests China bracing for sanctions if it invades Taiwan (Washington Post) 

Unprecedented Shift: The Trickbot Group is Systematically Attacking Ukraine (Security Intelligence)

Trickbot may be carrying water for Russia (Washington Post)

Russia Info Ops Home In on Perceived Weak Links (VOA)

Targets of Interest | Russian Organizations Increasingly Under Attack By Chinese APTs (SentinelOne)

Chinese hackers targeting Russian government, telecoms: report (The Record by Recorded Future)

Near-undetectable malware linked to Russia's Cozy Bear (Register)

Russia's Cozy Bear linked to nearly undetectable malware (Computing)

When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors (Unit 42) 

NFT scammers see an opportunity in Ukraine donations (The Record by Recorded Future)

Extract Knowledge

The FBI, CISA, and the Department of the Treasury are releasing this joint Cybersecurity Advisory to provide information on Maui ransomware, which has been used by North Korean state-sponsored cyber actors since at least May 2021 to target Healthcare and Public Health Sector organizations.

AA22-187A Alert, Technical Details, and Mitigations

Stairwell Threat Report: Maui Ransomware

North Korea Cyber Threat Overview and Advisories

Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments

National Conference of State Legislatures: Security Breach Notification Laws

Health Breach Notification Rule

Protecting Sensitive and Personal Information from Ransomware-Caused Data Breaches

StopRansomware.gov

CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide


All organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at central@cisa.dhs.gov or (888) 282-0870 and to the FBI via your local FBI field office or the FBI’s 24/7 CyWatch at (855) 292-3937 or CyWatch@fbi.gov.

Extract Knowledge

Quantum computing and security standards. Notes on the cyber phases of a hybrid war, and how depressingly conventional cybercrime persists in wartime. Pyongyang operators are using Maui ransomware against healthcare targets. Malek Ben Salem from Accenture looks at the security risks of GPS. Our guest is Brian Kenyon of Island to discuss enterprise browser security. Shanghai's big data exposure.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/128


Selected reading.

NIST Announces First Four Quantum-Resistant Cryptographic Algorithms (NIST)

Winners of NIST's post-quantum cryptography competition announced (Computing) 

NIST unveils four algorithms that will underpin new 'quantum-proof' cryptography standards (SC magazine) 

NIST Identifies 4 Quantum-Resistant Encryption Algorithms (Nextgov.com)

Prepare for a New Cryptographic Standard to Protect Against Future Quantum-Based Threats (CISA)

Quantum-resistant encryption recommended for standardization (Register)

Keeping Phones Running in Wartime Pushes Kyivstar to the Limit (Bloomberg)

The Ukraine war could provide a cyberwarfare manual for Chinese generals eyeing Taiwan (CyberScoop)

Ukrainian police takes down phishing gang behind payments scam (ZDNet)

Cyber Police of Ukraine arrested 9 men behind phishing attacks on Ukrainians attempting to capitalize on the ongoing conflict (Security Affairs) 

North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector (CISA) 

Reports (Moody’s)

Clarion Housing ‘cyber incident’ affects thousands of tenants (Cambs Times) 

In a big potential breach, a hacker offers to sell a Chinese police database. (New York Times)

Nearly one billion people in China had their personal data leaked, and it's been online for more than a year (CNN) 

China data breach likely to fuel identity fraud, smishing attacks (ZDNet) 

China Tries to Censor What Could Be Biggest Data Hack in History (Gizmodo) 

Here are four big questions about the massive Shanghai police leak (Washington Post)

Shanghai Data Breach Exposes Dangers of China’s Trove (Bloomberg)

Extract Knowledge

Cyberattack hits a Ukrainian energy provider. NCSC updates its guidance on preparing for a long-term Russian cyber campaign. Royal Army accounts are hijacked. A hacktivist group claims to have hit Iranian sites. A very very large database of PII is for sale on the dark web. Chase Snyder from ExtraHop has a look back at WannaCry, 5 years on. Ben Yelin examines the constitutionality of keyword search warrants. And a rogue employee makes off with bug reports.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/127


Selected reading.

Russian hackers allegedly target Ukraine's biggest private energy firm (CNN)

Proruskí hackeri opäť útočili. Ďalšia významná spoločnosť hlási, že čelila kybernetickým útokom (Vosveteit.sk)

Preparing for the long haul: the cyber threat from Russia (NCSC)

Official British Army Twitter and YouTube accounts hijacked by NFT scammers (Hot for Security)

British army confirms breach of its Twitter and YouTube accounts (the Guardian) 

British Army hit by cyberattack as Twitter and YouTube accounts hacked (The Telegraph) 

Iranians' Remote Access to Banking Services Cut Off Over 'Cyber Attacks' (IranWire) 

(Video) Iranian regime’s Islamic Culture and Communications Organization targeted in massive cyber offensive (EIN News)

Hackers Claim Theft of Police Info in China’s Largest Data Leak (Bloomberg) 

Hacker Selling Shanghai Police Database with Billions of Chinese Citizens Data (HackRead)

Giant data breach? Leaked personal data of one billion people has been spotted for sale on the dark web (ZDNet) 

Hacker claims to have stolen 1 bln records of Chinese citizens from police (Reuters) 

HackerOne disclosed on HackerOne: June 2022 Incident Report (HackerOne) 

HackerOne Employee Caught Stealing Vulnerability Reports for Personal Gains (The Hacker News)

Rogue HackerOne employee steals bug reports to sell on the side (BleepingComputer)

Extract Knowledge

In this episode, Marc and Patrick Morley, former CEO of Carbon Black, get nostalgic as they discuss Patrick's journey of coming up through the start up scene in the 90s—from working with VCs to taking companies public—and compare it to running cyber companies today. Along with the early career experience that helped form Patrick's leadership philosophy, he shares his experience of becoming CEO of Bit9, seeing the company through a breach, acquiring Carbon Black, bring the company public and later getting acquired by VMWare—this episode is filled to the brim.

You'll also learn about:

  • How build a criteria for joining a start up
  • Why cyber is the most mission-driven area of tech
  • What it's like to call 600 customers in 2 days after a breach and not lose a single one
  • Seven philosophies for running a cyber company
Extract Knowledge

Larry Cashdollar from Akamai, joins Dave to discuss their research on a DDoS campaign claiming to be REvil. The research shares that Akamai's team was notified last week of an attack on one of their hospitality customers that they called "Layer 7" by a group claiming to be associated with REvil. In the research, they dive into the attack, as well as comparing it to other similar attacks that have been made by the group.

The research states "The attacks so far target a site by sending a wave of HTTP/2 GET requests with some cache-busting techniques to overwhelm the website." It also stated that this is a smaller attack than they have seen by the group before, and notes that there seems to be more of a political agenda behind the attack, whereas in the past, REvil has been less political.

The research can be found here:

Extract Knowledge

An update on the DDoS attack against Norway. NATO's resolutions on cyber security. North Korea seems to be behind the Harmony cryptocurrency heist. MedusaLocker warninga. Microsoft sees improvements in a gang's technique. Google blocks underworld domains. The Israeli-Iranian conflict in cyberspace. Chris Novak from Verizon with his take on this year’s DBIR. Our guest is Jason Clark of Netskope on the dynamic challenges of a remote workforce.And Now among the FBI’s Ten Most Wanted: one Crypto Queen.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/126


Selected reading.

Pro-Russian hackers launched a massive DDoS attack against Norway (Security Affairs)

NATO establishes program to coordinate rapid response to cyberattacks (POLITICO) 

NATO to create cyber rapid response force, increase cyber defense aid to Ukraine (CyberScoop)

FACT SHEET: The 2022 NATO Summit in Madrid | The White House (The White House)

North Korean Lazarus hackers linked to Harmony bridge thef (TechCrunch) 

North Korea Suspected of Plundering Crypto to Fund Weapons Programs (Wall Street Journal)

Crypto crash threatens North Korea's stolen funds as it ramps up weapons tests (Reuters)

CISA Alert AA22-181A – #StopRansomware: MedusaLocker. (CISA Cybersecurity Alerts with the CyberWire)

#StopRansomware: MedusaLocker (CISA)

Microsoft warning: This malware that targets Linux just got a big update (ZDNet) 

Microsoft Warns of Cryptomining Malware Campaign Targeting Linux Servers (The Hacker News) 

Google blocked dozens of domains used by hack-for-hire groups (BleepingComputer)

Countering hack-for-hire groups (Google)

Gantz orders probe after TV reports hint IDF behind Iran steel plant cyberattack (Times of Israel)

Proofpoint: Zionist covert operation? (PressTV)

Zionist intelligence company cyberattacked by Iraqi hackers (Mehr)

FBI Offers $100,000 Reward for Capture of Ten Most Wanted Fugitive ‘Cryptoqueen’ (FBI)

Extract Knowledge

CISA, the FBI, the Department of the Treasury, and the Financial Crimes Enforcement Network are releasing this alert to provide information on MedusaLocker ransomware. Observed as recently as May 2022, MedusaLocker actors predominantly rely on vulnerabilities in Remote Desktop Protocol to access victims’ networks.

AA22-181A Alert, Technical Details, and Mitigations

Stop Ransomware

CISA Ransomware Guide

CISA No-cost Ransomware Services

All organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at central@cisa.dhs.gov or (888) 282-0870 and to the FBI via your local FBI field office or the FBI’s 24/7 CyWatch at (855) 292-3937 or CyWatch@fbi.gov.

Extract Knowledge

Killnet hits Norwegian websites. Hacktivists are tied to Russia's government. Amunet as a case study in C2C market differentiation. C2C commodification extends to script kiddies. Andrea Little Limbago from Interos examines borderless data. Rick Howard speaks with Cody Chamberlain from NetSPI on Breach Communication. Roscosmos publishes locations of Western defense facilities…and subsequently says it sustained a DDoS attack.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/125


Selected reading.

Pro-Russian hacker group says it attacked Norway (The Independent Barents Observer)

Cyberattack hits Norway, pro-Russian hacker group fingered (AP NEWS)

Norway blames "pro-Russian group" for cyber attack (Reuters)

Mandiant Finds Possible Link Between Kremlin, Pro-Russian ‘Hacktivists’ (Bloomberg)

Market Differentiation: Cybercriminal Forums’ Unusual Features Designed To Attract Users (Digital Shadows)

Minors Use Discord Servers to Earn Extra Pocket Money Through Spreading Malware (PR Newswire)

Russia publishes Pentagon coordinates, says Western satellites 'work for our enemy' (Reuters)

Russian Space Agency Targeted in Cyberattack (Wall Street Journal)

Cyberattack hits Russian space agency site after sharing NATO photos (Jerusalem Post)

Extract Knowledge

NATO's response to Killnet's cyberattacks on Lithuania. Influence operations in the interest of national market share. SOHO routers are under attack. YTStealer is out and active in the wild. RansomHouse hits AMD. CISA releases six ICS security advisories. The most dangerous software weaknesses. Betsy Carmelite from Booz Allen Hamilton takes a look back at Biden’s executive order on cyber. Our guest is Philippe Humeau of CrowdSec on taking a collaborative approach to security. And a guilty plea in the case of the NetWalker affiliate.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/124


Selected reading.

Could the Russian cyber attack on Lithuania draw a military response from NATO? (Sky News) 

Pro-PRC DRAGONBRIDGE Influence Campaign Targets Rare Earths Mining Companies in Attempt to Thwart Rivalry to PRC Market Dominance (Mandiant)

ZuoRAT Hijacks SOHO Routers to Silently Stalk Networks (Lumen) 

New YTStealer Malware Aims to Hijack Accounts of YouTube Content Creators (Hacker News)

RansomHouse Extortion Group Claims AMD as Latest Victim (RestorePrivacy) 

RansomHouse gang claims to have some stolen AMD data (Register)

CISA releases 6 Industrial Control Systems Advisories (Cybersecurity and Infrastructure Security Agency)

2022 CWE Top 25 Most Dangerous Software Weaknesses (CISA) 

Netwalker ransomware affiliate agrees to plead guilty to hacking charges (The Record by Recorded Future)

Extract Knowledge

Distributed denial-of-service attacks against Lithuania. Dark Crystal RAT described. Iranian steel mill suspends production due to cyberattack. Bumblebee rising. CISA adds to its Known Exploited Vulnerabilities Catalog. Music pirate sites brought down by US and Brazilian authorities. Joe Carrigan looks at Apple’s private access tokens. Mister Security Answer Person John Pescatore drops some sboms. And where do Russian intelligence officers go after they’ve been PNGed?


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/123


Selected reading.

Lithuania targeted by massive Russian cyberattack over transit blockade (Newsweek)

Russia's Killnet hacker group says it attacked Lithuania (Reuters)

Killnet, Kaliningrad, and Lithuania’s Transport Standoff With Russia (Flashpoint)

Ukraine Targeted by Dark Crystal RAT (DCRat) | FortiGuard Labs (Fortinet Blog)

Cyberattack Forces Iran Steel Company to Halt Production (SecurityWeek)

Iran’s steel industry halted by cyberattack (Jerusalem Post)

Bumblebee: New Loader Rapidly Assuming Central Position in Cyber-crime Ecosystem (Broadcom Software Blogs)

CISA Adds Eight Known Exploited Vulnerabilities to Catalog (CISA) 

US, Brazil seize 272 websites used to illegally download music (BleepingComputer) 

Swiss intel service: Watch out for redeployed Russian spies (AP News)

Extract Knowledge

Lithuania sustains a major DDoS attack. Lessons from NotPetya. Conti's brand appears to have gone into hiding. Online extortion now tends to skip the ransomware proper. Josh Ray from Accenture on how social engineering is evolving for underground threat actors. Rick Howard looks at Chaos Engineering. US financial institutions conduct a coordinated cybersecurity exercise.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/122


Selected reading.

Russia's Killnet hacker group says it attacked Lithuania (Reuters)

The hacker group KillNet has published an ultimatum to the Lithuanian authorities (TDPel Media) 

5 years after NotPetya: Lessons learned (CSO Online) 

The cyber security impact of Operation Russia by Anonymous (ComputerWeekly)

Conti ransomware finally shuts down data leak, negotiation sites (BleepingComputer)

The Conti Enterprise: ransomware gang that published data belonging to 850 companies (Group-IB)

Fake copyright infringement emails install LockBit ransomware (BleepingComputer)

NCC Group Monthly Threat Pulse – May 2022 (NCC Group)

We're now truly in the era of ransomware as pure extortion without the encryption (Register)

Wall Street Banks Quietly Test Cyber Defenses at Treasury’s Direction (Bloomberg)

Extract Knowledge

Richard Melick, Director of Threat Reporting for Zimperium, talks about his journey, from working in the military to moving up to the big screens. He shares that he's been in the business of solving unique cybersecurity problems for so long that he has found his own path that works very well for him. He says, "if I go to a unique problem and try to solve it, I find that I'm solving it the same way that I would've solved it five years ago, because I found my pattern." Richard reflects on his time working in the industry, from moving away from the military and into different roles over the years. He notes that giving credit where credit is due, to those who deserve it, is how you keep the audience engaged as a storyteller. We thank Richard for sharing his story.

Extract Knowledge

Alan Neville, a Threat Intelligence Analyst from Symantec Broadcom, joins Dave to discuss their research "Lazarus Targets Chemical Sector." Symantec has observed the North Korea-linked threat group known as Lazarus conducting an espionage campaign targeting organizations operating within the chemical sector.

The campaign appears to be a continuation of the group's activity called Operation Dream Job, which Symantec first came across in August of 2020. The research states "evidence includes file hashes, file names, and tools that were observed in previous Dream Job campaigns."

The research can be found here:

Extract Knowledge

Lithuania's NKSC warns of increased DDoS threat. Limited Russian success in the cyber phases of its hybrid war. Another warning of spyware in use against targets in Italy and Kazakhstan. Hey, critical infrastructure operators: CISA’s got tabletop exercises for you. Kevin Magee from Microsoft has advice for recent grads. A look back the year since Colonial Pipeline with Padraic O'Reilly of CyberSaint. And sometimes ransomware is just a spy’s way of saying, “nothing up my sleeve…”


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/121


Selected reading.

Lithuania warns of rise in DDoS attacks against government sites (BleepingComputer) 

Defending Ukraine: Early Lessons from the Cyber War (Microsoft) 

Why think tanks are such juicy targets for cyberspies (The Record by Recorded Future)

The war in Ukraine is showing the limits of cyberattacks (Tech Monitor)

Spyware vendor targets users in Italy and Kazakhstan (Google Threat Analysis Group)

BRONZE STARLIGHT Ransomware Operations Use HUI Loader (SecureWorks)

CISA Tabletop Exercises Packages (CTEP) (CISA)

CISA Tabletop Exercise Package (CTEP) Workshop (Government Technology)

Extract Knowledge

CISA and the US Coast Guard Cyber Command are releasing this joint Cybersecurity Advisory to warn network defenders that cyber threat actors, including state-sponsored APT actors, have continued to exploit CVE-2021-44228 (Log4Shell) in VMware Horizon and Unified Access Gateway servers to obtain initial access to organizations that did not apply available patches or workarounds.

AA22-174A Alert, Technical Details, and Mitigations

Malware Analysis Report 10382254-1 stix

Malware Analysis Report 10382580-1 stix

CISA’s Apache Log4j Vulnerability Guidance webpage

Joint CSA Mitigating Log4Shell and Other Log4j-Related Vulnerabilities

CISA’s database of known vulnerable services on the CISA GitHub page

See National Security Agency (NSA) and Australian Signals Directorate (ASD) guidance Block and Defend Web Shell Malware for additional guidance on hardening internet-facing systems.

All organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at central@cisa.dhs.gov or (888) 282-0870 and to the FBI via your local FBI field office or the FBI’s 24/7 CyWatch at (855) 292-3937 or CyWatch@fbi.gov.

Extract Knowledge

Reviewing Russian cyber campaigns in the war against Ukraine, and the complexity of Ukraine's IT Army. ICEFALL advice and reactions. Carole Theriault looks at Hollywood’s relationship with VPNs. Podcast partner Robert M. Lee from Dragos provides a rundown on Pipedream. And CISA updates its Cloud Security Technical Reference Architecture.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/120


Selected reading.

[Blog] Defending Ukraine: Early Lessons from the Cyber War (Microsoft On the Issues)

[Report] Defending Ukraine: Early Lessons from the Cyber War (Microsoft)

Russian cyber spies attack Ukraine's allies, Microsoft says (Reuters) 

Research questions potentially dangerous implications of Ukraine's IT Army (CyberScoop)

The IT Army of Ukraine Structure, Tasking, and Ecosystem (Center for Security Studies) 

CISA Releases Security Advisories Related to OT:ICEFALL (Insecure by Design) Report (CISA)

Industry Reactions to 'OT:Icefall' Vulnerabilities Found in ICS Products (SecurityWeek) 

Cloud Security Technical Reference Architecture (CISA)

Extract Knowledge

Fancy Bear sighted in Ukrainian in-boxes. Why Russian cyberattacks against Ukraine have fallen short of expectations. ToddyCat APT is active in European and Asian networks. ICEFALL ICS vulnerabilities described. CISA issues ICS vulnerability advisories. Europol makes nine collars. Andrea Little Limbago from Interos on The global state of data protection and sharing. Rick Howard speaks with Michelangelo Sidagni from NopSec on the Future of Vulnerability Management. We are shocked, shocked, to hear of corruption in the FSB


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/119


Selected reading.

Ukrainian cybersecurity officials disclose two new hacking campaigns (CyberScoop) 

Ukraine Warns of New Malware Campaign Tied to Russian Hackers (Bloomberg Law) 

Russian govt hackers hit Ukraine with Cobalt Strike, CredoMap malware (BleepingComputer) 

Opinion How Russia’s vaunted cyber capabilities were frustrated in Ukraine (Washington Post) 

New Toddycat APT Targets MS Exchange Servers in Europe and Asia (Infosecurity Magazine) 

Microsoft Exchange servers hacked by new ToddyCat APT gang (BleepingComputer)

OT:ICEFALL: 56 Vulnerabilities Caused by Insecure-by-Design Practices in OT (Forescout)

From Basecamp to Icefall: Secure by Design OT Makes Little Headway (SecurityWeek)

Dozens of vulnerabilities threaten major OT device makers (Cybersecurity Dive) 

CISA releases 6 Industrial Control Systems Advisories (Cybersecurity and Infrastructure Security Agency) 

Phishing gang behind several million euros worth of losses busted in Belgium and the Netherlands (Europol)

Подполковника УФСБ по Самарской области арестовали за кражу криптовалюты у хакера (TASS)

Extract Knowledge

A Cyberattack is suspected of causing false alarms in Israel. Risk surface assessments. Renewed warning of the potential security risks of fitness apps. Cyber options may grow more attractive to Russia as kinetic operations stall. DDoS in St. Petersburg. Ben Yeling details a Senate bill restricting the sale of location data. Our guest is Jon Check from Raytheon's Intelligence and Space Division discussing the National Collegiate Cyber Defense Competition. A conviction in the Capital One hacking case.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/118


Selected reading.

Suspected cyberattack triggers sirens in Jerusalem, Eilat (Israel Hayom)

Suspected Iranian Cyberattack on Israel Triggers Sirens (Haaretz)

Iranian cyberattack may be behind false rocket warning sirens in Jerusalem (Jerusalem Post) 

Israel suspects Iranian cyber-attack behind false siren alerts (Middle East Monitor) 

Strava fitness app used to spy on Israeli military officials (Computing) 

Treasury's Adeyemo sees elevated cyber threats in wake of Russia's war in Ukraine (Reuters)

More cyber warfare with Russia lies on the horizon (Interesting Engineering)

Prolonged war may make Russia more cyber aggressive, US official says (C4ISRNet) 

What the Russia-Ukraine war means for the future of cyber warfare (The Hill) 

Complex Russian cyber threat requires we go back to basics (ComputerWeekly.com) 

Vladimir Putin speech delayed 'because of cyber-attack' as he hits out at 'economic blitzkrieg' against Russia (Scotsman)

UPDATE 1-Putin's St Petersburg speech postponed by an hour after cyberattack (Yahoo)

Think of the Russia-Ukraine conflict as a microcosm of the cyber war  (SC Magazine)

The link between cyberattacks and war: Gartner (CRN Australia) 

Ex-Amazon Worker Convicted in Capital One Hacking (New York Times)

Jury Convicts Seattle Woman in Massive Capital One Hack (SecurityWeek)

Former Seattle tech worker convicted of wire fraud and computer intrusions (US Attorney’s Office, Western District of Washington)

Extract Knowledge

As we break to observe the Juneteenth holiday, our team thought you might like to try a sample of a CyberWire Pro podcast called Interview Selects. These podcasts are a series of extended interviews, exclusives, and a curated selection of our most engaging and informative interviews over the years, featuring cyber security professionals, journalists, authors and industry insiders. In this extended interview, Dave Bittner speaks with FBI Cyber Section Chief David Ring at RSAC discussing FBI cyber strategy/role in the cyber ecosystem and private sector engagement. Like what you hear? Consider subscribing to CyberWire Pro for $99/year. Learn more.

Extract Knowledge

Lauren Van Wazer, Vice President, Global Public Policy and Regulatory Affairs for Akamai Technologies, shares her story as she followed her own North Star and landed where she is today. She describes her career path, highlighting how she went from working at AT&T to being able to work in the White House. She shares how she is a coach and a leader to the team she works with now, saying "my view is I've got their back, if they make a mistake, it's my mistake, and if they do well, they've done well." Lauren hopes she's made an impact in the world by making it a little bit better than before, and discusses how she doesn't let anyone stop her from her goals. Lauren shares her outlook on her experiences, calling attention to different roles in her life that made her journey all the better. We thank Lauren for sharing.

Extract Knowledge

Edward Wu, senior principal data scientist at ExtraHop, joins Dave to discuss the company's research, "A Technical Analysis of How Spring4Shell Works." ExtraHop first noticed chatter from social media in March of 2022 on a new remote code execution (RCE) vulnerability and immediately started tracking the issue.

In the research, it describes how the exploit works and breaks down how the ExtraHop team came to identify the Spring4Shell vulnerability. The research describes the severity of the vulnerability, saying, "The impact of an RCE in this framework could have a serious impact similar to Log4Shell."

The research can be found here:

Extract Knowledge

Malibot is an info stealer masquerading as a coin miner. "Hermit" spyware is being used by nation-state security services. Fabricated evidence is planted in Indian computers. The US takes down a criminal botnet. The British Home Secretary signs the Assange extradition order. We wind up our series of RSA Conference interviews with David London from the Chertoff group and Hugh Njemanze from Anomali. And putting the Service into service learning.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/117


Selected reading.

'MaliBot' Android Malware Steals Financial, Personal Information (SecurityWeek)

F5 Labs Investigates MaliBot (F5 Labs)

Sophisticated Android Spyware 'Hermit' Used by Governments (SecurityWeek)

Lookout Uncovers Android Spyware Deployed in Kazakhstan (Lookout)

Police Linked to Hacking Campaign to Frame Indian Activists (Wired)

U.S., partners dismantle Russian hacking 'botnet,' Justice Dept says (Reuters)

Russian Botnet Disrupted in International Cyber Operation (US Attorney's Office, Southern District of California)

Julian Assange: Priti Patel signs US extradition order (The Telegraph)

AIVD disrupts activities of Russian intelligence officer targeting the International Criminal Court (AIVD)

Alleged Russian spy studied at Johns Hopkins, won ICC internship (Washington Post)

Extract Knowledge

Interpol coordinates international enforcement action against scammers. A new version of IceXLoader is observed. Exploiting versioning limits to render files inaccessible. Reflections on the first large-scale hybrid war. Kelly Shortridge from Fastly on why behavioral science and economics matters for InfoSec. Patrick Orzechowski from DeepWatch on Russian IoCs and critical infrastructure. And the possibility of cyber escalation in Russia’s hybrid war against Ukraine.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/116


Selected reading.

Hundreds arrested and millions seized in global INTERPOL operation against social engineering scams (Interpol)

New IceXLoader 3.0 – Developers Warm Up to Nim (Fortinet Blog) 

Proofpoint Discovers Potentially Dangerous Microsoft Office 365 Functionality that can Ransom Files Stored on SharePoint and OneDrive (Proofpoint) 

Russia’s cyber fog in the Ukraine war (GIS Reports)

Russia Might Try Reckless Cyber Attacks as Ukraine War Drags On, US Warns (Defense One)

Cyber Attacks in Times of Conflict (CyberPeace Institute)

Vladimir Putin’s Ukraine invasion is the world’s first full-scale cyberwar (Atlantic Council)

Why Russia has refrained from a major cyber-attack against the West (Cyber Security Hub)

In modern war, we have as much to fear from cyber weapons as kinetics (Computing)

Extract Knowledge

The Hertzbleed side-channel issue affects Intel and AMD processors. An Iranian spearphishing campaign prospected former Israeli officials. Patch Tuesday notes. A look at software bills of materials. Russia routes occupied Ukraine's Internet traffic through Russia. Intercepts in the hybrid war: the odd and the ugly. Deepen Desai from ZScaler joins us with the latest numbers on ransomware. Rob Boyce from Accenture Security looks at cyber invisibility. And, finally, criminal wannabes and criminal publicity stunts.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/115


Selected reading.

A new vulnerability in Intel and AMD CPUs lets hackers steal encryption keys (Ars Technica) 

Iranian Spear-Phishing Operation Targets Former Israeli and US High-Ranking Officials (Check Point Research)

Microsoft June 2022 Patch Tuesday fixes 1 zero-day, 55 flaws (BleepingComputer) 

Microsoft Releases June 2022 Security Updates (CISA) 

Windows Updates Patch Actively Exploited 'Follina' Vulnerability (SecurityWeek) 

Adobe Plugs 46 Security Flaws on Patch Tuesday (SecurityWeek)

Citrix Releases Security Updates for Application Delivery Management (CISA)

SAP Releases June 2022 Security Updates (CISA) 

So long, Internet Explorer. The browser retires today (AP NEWS)

SBOM in Action: finding vulnerabilities with a Software Bill of Materials (Google Online Security Blog)

Russia Is Taking Over Ukraine’s Internet (Wired)

Belarusian hacktivist group releases purported Belarusian wiretapped audio of Russian embassy (CyberScoop) 

Intercepted call: Russian plan to send PoWs out into minefields (The Telegraph) 

Hacker Advertises ‘Crappy’ Ransomware on Instagram (Vice) 

LockBit Ransomware Compromise of Mandiant Not Supported by Any Evidence, May Be a PR Move by Cybercrime Gang (CPO Magazine)

Extract Knowledge

Dealing with the GRU's exploitation of the Follina vulnerabilities. SeaFlower uses stolen seed phrases to rifle cryptocurrency wallets. Ukraine moves sensitive data abroad. Anonymous claims to have hacked Russia's drone suppliers and to have hit sensitive targets in Belarus. Rick Howard reports on an NSA briefing at the RSA Conference. Our guest is Ricardo Amper from Incode with a look at biometrics in sports stadiums. And the effects of war on the cyber underworld.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/114


Selected reading.

Follina flaw being exploited by Russian hackers, info stealers (Computing) 

Chinese Hackers Adding Backdoor to iOS, Android Web3 Wallets in 'SeaFlower' Campaign (SecurityWeek)

How SeaFlower...installs backdoors in iOS/Android web3 wallets to steal your seed phrase (Medium) 

Ukraine Has Begun Moving Sensitive Data Outside Its Borders (Wall Street Journal) 

Anonymous claims hack on Russian drones (Computing) 

How the Cybercrime Landscape has been Changed following the Russia-Ukraine War (Kela)

Extract Knowledge

A Chinese APT deploys a new cyberespionage tool. Hacktivism roils India after a politician's remarks about the Prophet. Ukraine reports a "massive" spam campaign against the country's media organizations. A Russian court fines Wikimedia for "disinformation." From the NSA’s Cybersecurity Collaboration Center our guests are Morgan Adamski and Josh Zaritsky. Rick Howard sets the cyber sand table on Colonial Pipeline. And the Martians haven’t landed, and the Right Honorable Mr. Johnson is still PM.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/113


Selected reading.

CERT-UA warns of cyberattack on Ukrainian media (Interfax-Ukraine)

Russian hackers start targeting Ukraine with Follina exploits (BleepingComputer)

Massive cyber attack on media organizations of Ukraine using the malicious program CrescentImp (CERT-UA # 4797) (CERT-UA)

Wikimedia Foundation appeals Russian fine over Ukraine war articles (The Verge)

GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull Tool (Unit42)

Prophet remark: Slew of cyber attacks on Indian govt, private sites (The Times of India)

70 Indian government, private websites face international cyber attacks over Prophet row (The Times of India)

Channel 4 faces Ofcom probe over ’emergency news’ stunt to promote cyber attack drama The Undeclared War (INews)

Extract Knowledge

Deepen Desai, Global Chief Information Security Officer at Zscaler, shares his story as a doctor that treats computer viruses. He describes how he got into the security field and his work with Zscaler. He says what it's like learning and growing in this field and shares great advice for people who are up and coming in the field. Deepen describes working with an incredible team and how much joy it brings him to see his team learning and growing beyond their roles working with him. He says he want's to be remembered as a mentor among his colleagues. He says "I still remember my first team that I built, 15 years ago. Most of those guys are leading key technologies at many of the major security vendors, and some of them are still with me." We thank Deepen for sharing his story.

Extract Knowledge

Danny Adamitis from Lumen's Black Lotus Labs, joins Dave to discuss new developments in the WSL attack surface. Since September 2021, Black Lotus Labs have been monitoring malware repositories as a part of their proactive threat hunting process. Danny shares how researchers discovered a series of suspicious ELF files compiled for Debian Linux .

The research states how the team identified a series of samples that target the WSL environment, were uploaded every two to three weeks and that they started as early as May 3, 2021 and go until August 22, 20221.

The research can be found here:

Extract Knowledge

Looking at Russia's hybrid war as a cautionary example. Russia warns, again, that it will meet cyberattacks with appropriate retaliation. (China says "us too.") NSA and FBI warn of nation-state cyber threats. SentinelOne finds a Chinese APT that's been operating, quietly, for a decade. "Unpatchable" vulnerability in Apple chips reported. We’ve got more interviews from RSA Conference, including the FBI’s Cyber Section Chief David Ring, ExtraHop’s CEO, Patrick Dennis. And the overhead projector said, “Go Tigers.”


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/112


Selected reading.

Top Senate Democrats sound the alarm about Russian interference in the 2022 midterms (Business Insider) 

Russia says West risks ‘direct military clash’ over cyberattacks (NBC News)

Russia, China, oppose US cyber support of Ukraine (Register) 

#RSAC: NSA Outlines Threats from Russia, China and Ransomware (Infosecurity Magazine) 

FBI official: Chinese hackers boost recon efforts (The Record by Recorded Future) 

Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years (SentinelOne) 

MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips (TechCrunch)

New Jersey school district forced to cancel final exams amid ransomware recovery effort (The Record by Recorded Future)

Extract Knowledge

Another hacked broadcast in a hybrid war. Hunting forward as an exercise in threat intelligence collection and sharing. Cyber threats to the US midterm elections. Phishing for cryptocurrency. FakeCrack delivers a malicious payload to the unwary. Vacations are back. So is travel-themed phishbait. Ann Johnson from Microsoft shares insights on the trends she’s tracking here at RSA. Johannes Ullrich brings highlights from his RSA conference panel discussion. And Emotet returns, in the company of some old familiar criminal collaborators.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/111


Selected reading.

Hacked Russian radio station broadcasts Ukrainian anthem (Washington Post) 

Ukraine Successfully Defends Its Cyberspace While Russia Leans Heavily on Guns, Bombs (CNET)

Ukraine war: US cyber chief on Kyiv's advantage over Russia (Sky News)

NSA Director Confirms Cyber Command 'Hunt Forward' Approach Applies to Russia (ClearanceJobs) 

Experts, NSA cyber director say ransomware could threaten campaigns in 2022 (CyberScoop)

Ransomware, botnets could plague 2022 midterms, NSA cyber director says (The Record by Recorded Future)

How Cyber Criminals Target Cryptocurrency (Proofpoint)

Crypto stealing campaign spread via fake cracked software (Avast)

Threat Actors Prepare Travel-Themed Phishing Lures for Summer Holidays (Hot for Security)

Emotet Malware Returns in 2022 (Deep Instinct)

Extract Knowledge

US officials continue to rate the threat of Russian cyberattack as high. Civilians in cyber war. Broadcast interference and propaganda. A Joint CISA/FBI warning of Chinese cyberespionage. What gets a vulnerability into the Known Exploited Vulnerabilities Catalog? Andrea Little Limbago from Interos and Mike Sentonas from Crowdstrike join us with previews of their RSA conference presentations. And, finally, some Jersey-based cyber campaigns (that’s the Bailiwick, not the Garden State).


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/110


Selected reading.

Russian Cyber Threat Remains High, U.S. Officials Say (Wall Street Journal)

Shields Up: The New Normal (CyberScoop)

Russian Government, Cybercriminal Cooperation a 'Force Multiplier' (Decipher) 

Opinion The U.S.-Russia conflict is heating up — in cyberspace (Washington Post) 

Smartphones Blur the Line Between Civilian and Combatant (Wired)

Russian Cyberattack Hits Wales-Ukraine Football Broadcast (Gov Info Security) 

People’s Republic of China State-Sponsored Cyber Actors Exploit Network Providers and Devices (CISA)

US agencies detail the digital ‘plumbing’ used by Chinese state-sponsored hackers (The Record by Recorded Future) 

CISA Provides Criteria and Process for Updates to the KEV Catalog (CISA)

Reducing the Significant Risk of Known Exploited Vulnerabilities (CISA)

Jersey computers used in international cyber-attacks (Jersey Evening Post)

Extract Knowledge

This joint Cybersecurity Advisory describes the ways in which People’s Republic of China state-sponsored cyber actors continue to exploit publicly known vulnerabilities in order to establish a broad network of compromised global infrastructure. These actors use the network to exploit a wide variety of targets worldwide, including public and private sector organizations.

AA22-158A Alert, Technical Details, and Mitigations

Refer to China Cyber Threat and Advisories, Internet Crime Complaint Center, and NSA Cybersecurity Guidance for previous reporting on People’s Republic of China state-sponsored malicious cyber activity.

US government and critical infrastructure organizations should consider signing up for CISA’s cyber hygiene services, including vulnerability scanning, to help reduce exposure to threats.

US Defense Industrial Base organizations should consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System (PDNS) services, vulnerability scanning, and threat intelligence collaboration. For more information on eligibility criteria and how to enroll in these services, email dib_defense@cyber.nsa.gov.

All organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at central@cisa.dhs.gov or (888) 282-0870 and to the FBI via your local FBI field office or the FBI’s 24/7 CyWatch at (855) 292-3937 or CyWatch@fbi.gov.

Extract Knowledge

DDoS as a weapon in a hybrid war. Resilience in the defense of critical infrastructure. Offensive cyber operations against Russia. LockBit claims to have hit Mandiant, but their claim looks baseless. Rick Howard joins us with thoughts on trends he’s tracking at the RSA conference. Our guest is Dr. Diane Janosek from NSA with insights on personal resilience. Effects of ransomware on businesses.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/109


Selected reading.

Ukraine at D+102: Ukraine's SSSCIP on cyber war. (The CyberWire) 

Major DDoS attacks increasing after invasion of Ukraine (SearchSecurity) 

The Russia–Ukraine War: Ukraine’s resistance in the face of hybrid warfare (Observer Research Foundation)

Ukraine Symposium - U.S. Offensive Cyber Operations in Support of Ukraine (Lieber Institute: Articles of War) 

Russia ready to cooperate with all states in cyber domain (UNI India)

LockBit 2.0 gang claims Mandiant as latest victim; Mandiant sees no evidence of it (CyberScoop)

Mandiant: “No evidence” we were hacked by LockBit ransomware (BleepingComputer) 

Cybereason Ransomware True Cost to Business Study Reveals Organizations Pay Multiple Ransom Demands (Cybereason)

Average Ransom Payment Up 71% This Year, Approaches $1 Million (Palo Alto Networks Blog)

Extract Knowledge

Ukraine offers an update on the cyber phases of Russia's hybrid war. Atlassian patches a Confluence critical vulnerability. CISA releases ICS advisory on voting systems. A "State-aligned" phishing campaign tried to exploit Follina. Is Electronic warfare a blunt instrument in the ether? Verizon’s Chris Novak stops by with thoughts on making the most of your trip to the RSA conference. Our guest is Tom Garrison from Intel with a look at hardware security. And a Russia-aligned group says they’re not just hacktivists; they’re "Cyber Spetsnaz."


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/108


Selected reading.

Remarks by Victor Zhorov, deputy head of SSSCIP. (SSSCIP)

US military hackers conducting offensive operations in support of Ukraine, says head of Cyber Command (Sky News)

Russian ministry website appears hacked; RIA reports users data protected (Reuters)

Confluence Security Advisory 2022-06-02 (Atlassian)

Atlassian Releases New Versions of Confluence Server and Data Center to Address CVE-2022-26134 (CISA) 

Patch released for exploited Atlassian zero-day vulnerability (The Record by Recorded Future) 

CISA Releases Security Advisory on Dominion Voting Systems Democracy Suite ImageCast X (CISA) 

State-Backed Hackers Exploit Microsoft 'Follina' Bug to Target Entities in Europe and U.S (The Hacker News)

Deadly secret: Electronic warfare shapes Russia-Ukraine war (AP NEWS) 

Exclusive: Pro-Russia group ‘Cyber Spetsnaz’ is attacking government agencies (Security Affairs)

Extract Knowledge

Executive Vice President at Concentric, Laura Hoffner shares her story about working as a Naval Intelligence Officer and supporting special operations around the globe for 12 years, to now, where she transitioned to the Naval Reserves and joined the Concentric team. Laura knew since she was in the seventh grade she wanted to work with SEALs and work in intelligence. She set her goals high and achieved them shortly after graduating college. She credits being a Naval Intelligence Officer to helping her get to where she is today and says how much she is enjoying working with Concentric, saying she's "ultimately just incredibly benefiting from unbelievable mentors at the company itself." We thank Laura for sharing her story.

Extract Knowledge

For this Cyberwire-X episode, we are talking about the failure of perimeter defense as an architecture where, since the 1990s when it was invented, the plan was to keep everything out. That model never really worked that well since we had to poke holes in the perimeter to allow employees, contractors, and partners to do legitimate business with us. Those same holes could be exploited by the bad guys, too. The question is, what are we doing instead? What is the security architecture, the strategy, and the tactics that we are all using today that is more secure than perimeter defense? In the first part of the show, Rick Howard, the CyberWire’s CSO, Chief Analyst, and Senior Fellow, talks with Jerry Archer, the Sallie Mae CSO and CyberWire Hash Table member, and, in the second half of the show, the CyberWire's podcast host Dave Bittner talks with Mike Ernst, episode sponsor ExtraHop’s Vice President of Sales Engineering, to discuss Software Defined Perimeter and intrusion kill chain prevention strategy.

Extract Knowledge

Scott Fanning from CrowdStrike's research team, joins Dave to discuss their work on "LemonDuck Targets Docker for Cryptomining Operations." LemonDuck is a well-known cryptomining botnet, and research suggests attackers are attracted to the monetary gain from the recent boom in cryptocurrency.

LemonDuck was caught trying to disguise it's attack against Docker by running an anonymous mining operation by the use of proxy pools. Scott shares how it’s unknown which organizations have been targeted and just how much cryptocurrency has been stolen.

The research can be found here:

Extract Knowledge

Moscow wants attention to be paid to its messengers. Western support for Ukraine in cyberspace. US remains on alert for Russian cyberattacks. Iran: anti-government hacktivism and Tehran-sponsored cyber ops. Rebranding as sanctions evasion. A gangland threat to firmware. Johannes Ullrich from SANS on security of browsers caching passwords. Dave Bittner sits down with Perry Carpenter to discuss his new book, "The Security Culture Playbook: An Executive Guide To Reducing Risk and Developing Your Human Defense Layer,''co-author was Kai Roer.. And CISA adds an Atlassian issue to its Known Exploited Vulnerabilities Catalog.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/107


Selected reading.

Russia summons heads of U.S. media outlets, warns of 'stringent measures' (Reuters)

US confirms military hackers have conducted cyber operations in support of Ukraine (CNN) 

Advancing security across Central and Eastern Europe (Google) 

US Justice Department Braces for More Russian Cyberattacks (VOA)

Russia, backed by ransomware gangs, actively targeting US, FBI director says (Cybersecurity Dive) 

Exiled Iran Group Claims Tehran Hacking Attack (SecurityWeek)

Exposing POLONIUM activity and infrastructure targeting Israeli organizations (Microsoft Security) 

To HADES and Back: UNC2165 Shifts to LOCKBIT to Evade Sanctions (Mandiant)

Russia-Linked Ransomware Groups Are Changing Tactics to Dodge Crackdowns (Wall Street Journal) 

Conti Targets Critical Firmware (Eclypsium)

Atlassian: Unpatched critical Confluence flaw under attack (Register) 

CISA Adds One Known Exploited Vulnerability (CVE-2022-26134) to Catalog (CISA)

Extract Knowledge

Russian government agencies are buying VPNs. CISA and its partners warn about the Karakurt extortion group. Clipminer is out in the wild. GootLoader expands its payloads and targeting. Carole Theriault has the latest on fraudsters imitating law enforcement. Kevin Magee from Microsoft on security incentives by way of insurance. And leak brokers and booters shut down.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/106


Selected reading.

White House: cyber activity not against Russia policy (Reuters) 

Some see cyberwar in Ukraine. Others see just thwarted attacks. (Washington Post) 

ESET Threat Report details targeted attacks connected to the Russian invasion of Ukraine and how the war changed the threat landscape (ESET) 

Ukraine - 100 days of war in cyberspace (CyberPeace Institute) 

Russian VPN Spending (Top 10 VPN)

Karakurt Data Extortion Group (CISA)

Karakurt Data Extortion Group (CISA) 

US Agencies: Karakurt extortion group demanding up to $13 million in attacks (The Record by Recorded Future)

Clipminer Botnet Makes Operators at Least $1.7 Million (Symantec Enterprise Blog)

GootLoader Expands its Payloads Infecting a Law Firm with IcedID (eSentire) 

WeLeakInfo.to and Related Domain Names Seized (US Department of Justice)

Extract Knowledge

The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Department of the Treasury (Treasury), and the Financial Crimes Enforcement Network (FinCEN) are releasing this joint Cybersecurity Advisory to provide information about the Karakurt data extortion group, also known as the Karakurt Team and Karakurt Lair. Karakurt actors have employed a variety of TTPs, creating significant challenges for defense and mitigation. Karakurt victims have not reported encryption of compromised machines or files; rather, Karakurt actors claim to steal data and threaten to auction it or release it to the public unless they receive payment.

AA22-152A Alert, Technical Details, and Mitigations

CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide

Data Integrity: Detecting and Responding to Ransomware and Other Destructive Events. Stopransomware.gov 

CISA's Ransomware Readiness Assessment

CISA's cyber hygiene services

FinCEN Advisory to Financial Institutions on Cyber-Events and Cyber-Enabled Crime

FinCEN Advisory on Ransomware and the Use of the Financial System to Facilitate Ransom Payments

All organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at central@cisa.dhs.gov or (888) 282-0870 and to the FBI via your local FBI field office or the FBI’s 24/7 CyWatch at (855) 292-3937 or CyWatch@fbi.gov.

Extract Knowledge

Costa Rica's healthcare system comes under renewed ransomware attack. Cyber phases of the hybrid war. Charity fraud exploits sympathy for Ukraine. US FBI attributes last year's attack on Boston Children's Hospital to Iran. CISOs surveyed on their challenges (and they're particularly worried about exposure to 3rd-party risk). Robert M. Lee joins us for the launch of the new Control Loop podcast. Josh Ray from Accenture looks at ransomware trends. Razzlekhan and Dutch: a cryptocurrency love song.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/11/105


Selected reading.

Latest cyberattack in Costa Rica targets hospital system (Reuters)

Costa Rica’s public health agency hit by Hive ransomware (BleepingComputer)

Costa Rican Social Security Fund hit with ransomware attack (The Record by Recorded Future)

Costa Rica May Be Pawn in Conti Ransomware Group’s Bid to Rebrand, Evade Sanctions (KrebsOnSecurity)

Ukraine joins its first NATO cyber defense center meeting (TheHill)

US military hackers conducting offensive operations in support of Ukraine, says head of Cyber Command (Sky News)

The FBI Warns of Scammers Soliciting Donations Related to the Crisis in Ukraine (Internet Crime Complaint Center (IC3))

FBI director blames Iran for ‘despicable’ attempted cyberattack on Boston Children’s Hospital (CNN)

Hackers ransom 1,200 exposed Elasticsearch databases (TechTarget)

The CISOs Report (Security Current)

New York couple accused of laundering $4.5 bln in crypto still in plea talks (Reuters)

Extract Knowledge
Show details
Episodes
3784
Transcripts
68
2% coverage
Missing transcripts
3716
With chapters
0