Masthash

#CyberSecurityNews

Pyrzout :vm:
2 hours ago

TA422 Hackers Attack Organizations Using Outlook & WinRAR Vulnerabilities https://gbhackers.com/ta422-hackers-attack-organizations/ #CyberSecurityNews #cybersecurity

Pyrzout :vm:
2 hours ago

TA422 Hackers Attack Organizations Using Outlook & WinRAR Vulnerabilities https://gbhackers.com/ta422-hackers-attack-organizations/ #CyberSecurityNews #cybersecurity

Pyrzout :vm:
9 hours ago
Pyrzout :vm:
9 hours ago
Simon
4 days ago

The Guardian reports that the UK's nuclear site Sellafield has been hacked into by cyber groups closely linked to Russia and China. They do not identify which groups.
🔗 https://www.theguardian.com/business/2023/dec/04/sellafield-nuclear-site-hacked-groups-russia-china

#Sellafield #Russia #China #nuclear #cyberespionage #cybersecuritynews

Pyrzout :vm:
6 days ago
Simon
1 week ago

The UK's NCSC concurs with CISA's security advisory "Exploitation of Unitronics PLCs used in Water and Wastewater Systems." This follows the 25 November 2023 reporting that Iran-backed Cyber Av3ngers compromised The Municipal Water Authority of Aliquippa, PA. If you own a Unitronics Vision PLC, please ensure that the default password "1111" is not in use.

🔗 https://www.ncsc.gov.uk/news/ncsc-statement-following-exploitation-of-unitronics-programmable-logic-controllers

#CISA #Unitronics #PLC #Aliquippa #CyberAv3ngers #Iran #cybersecuritynews

Simon
1 week ago

The Record: North Texas Municipal Water District (NTMWD), a water utility company serving 2 million, hit with cyberattack. Daixin Team claimed responsibility for the attack. This comes one day after the Municipal Water Authority of Aliquippa was attacked by the Iranian-backed hacking group Cyber Av3ngers.
🔗 https://therecord.media/north-texas-water-utility-cyberattack

#NTMWD #ransomware #DaixinTeam #cybersecuritynews

Simon
1 month ago

Apple warns Armenians of state-sponsored hacking attempts. The Record speculates that the spyware dropped is Pegasus and that the attacks are linked to Azerbaijan, which is a safe assumption given the ongoing Armenia-Azerbaijan conflicts.
Link: https://therecord.media/apple-warns-armenians-state-sponsored-hacking-attempts-azerbaijan

#Apple #Armenia #Azerbaijan #cybersecuritynews

Christina Lekati
1 month ago

Microsoft published a new blog with an analysis of the TTPs of the Octo Tempest group (also known as 0ktapus or Scattered Spider), a financially motivated threat actor that relies heavily on #socialengineering for initial access.

This group is reportedly the one behind the Okta, MGM Resorts & Caesars this year, as well as the MailChimp & Twilio attacks last year.

"Octo Tempest commonly launches social engineering attacks targeting technical administrators, such as support and help desk personnel, who have permissions that could enable the threat actor to gain initial access to accounts. The threat actor performs research on the organization & identifies targets to effectively impersonate victims, mimicking idiolect on phone calls & understanding personal identifiable information to trick technical administrators into performing password resets & resetting MFA"

"Octo Tempest leverages tradecraft that many organizations don’t have in their typical threat models, such as SMS phishing, SIM swapping, and advanced social engineering techniques."

In reality, most organizations don't have a social engineering security protocol for most types of social engineering attacks beyond #phishing and *some* vishing attacks/tactics. There is a lot of work to be done...

The blog:

https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/

#cybersecurity #cybersecuritynews #threatintelligence #scatteredspider #threatactors #infosec

Christina Lekati
2 months ago

🚨The ENISA Threat Landscape Report 2023 was released today!

It includes the top threats, major trends observed with respect to threats, threat actors & attack techniques, impact and motivation analysis.

It also describes relevant mitigation measures.

The top 3 threats that were identified and analyzed were:

🔹 Ransomware
🔹 Malware
🔹 Social Engineering

The report is a very insightful resource, especially for those who seek to make informed decisions for their cybersecurity strategy the coming year.

#cybersecurity #threatlandscape #cybersecurityawareness #cybersecuritynews #socialengineering #infosec #informationsecurity #ransomware #malware #enisa

https://www.enisa.europa.eu/topics/cyber-threats/threats-and-trends

Simon
2 months ago

Encrypted messaging app Signal has pushed back against "viral reports" of an alleged zero-day flaw in its software, stating it found no evidence to support the claim. "After responsible investigation *we have no evidence that suggests this vulnerability is real nor has any additional info been shared via our official reporting channels,"* it said in a series of messages posted on the deadbird site.
Link: https://thehackernews.com/2023/10/signal-debunks-zero-day-vulnerability.html

Tags: #Signal #zeroday #cybersecuritynews

crackerjack :fedora: :donor:
7 months ago

TBH I'm surprised this didn't happen sooner. Home routers are often thought of only when they fail in their purpose. APT and nationstate sponsored attacks can only be protected against only with concerted effort.

Resolving this problem is not simple. The ISP can't simply force updates to a wide array of devices that they may or may not own/control on the other end of the connection.

I haven't had consumer grade networking equipment in my house in years. The real issue with consumer grade tech, in my mind, is the lack of long term support. This leading to situations where updates aren't even flowing for those that take the time to periodically update!

#cybersecuritynews #homerouters #statesponsored #statesponsoredattack

https://arstechnica.com/information-technology/2023/05/malware-turns-home-routers-into-proxies-for-chinese-state-sponsored-hackers/

Erik Wynter
7 months ago

Does anyone know any cybersecurity reporters who'd be interested in a potential data leak at a European airline? My dms are open. #infosec #cybersecuritynews

crackerjack :fedora: :donor:
9 months ago

20 bits a second using high frequency audio. Clever way to target endpoints. The internal speaker seems almost pointless in a lot of machines... Perhaps buildings l vulnerabilities such as this will convince manufacturers to remove them?

#cybersecuritynews #casper #exfil #exfiltration

https://www.bleepingcomputer.com/news/security/casper-attack-steals-data-using-air-gapped-computers-internal-speaker/

crackerjack :fedora: :donor:
9 months ago

It's about time! Five years is a long, long time, where cybersecurity is concerned. Looking forward to seeing the updated framework, down the line.

#cybersecurity #cybersec #cybersecuritynews #nist #nistcsf

https://portswigger.net/daily-swig/nist-plots-biggest-ever-reform-of-cybersecurity-framework

CircleCityCon
10 months ago

Circle City Con crew has been busy! Visit our new website! Not only is it redesigned; it has a list of speakers and the general schedule for CircleCityCon 10.0 #WhoDunit!
Check it out! https://circlecitycon.org

#indianapolis #CybersecurityNews #infosec #midwest #Conferences

crackerjack :fedora: :donor:
10 months ago

Nice write-up and PoC for the "Not believed to be exploitable" recently patched double-free OpenSSH bug. Thanks jfrog!

#cybersecuritynews #PoC #doublefree #openssh #jfrog

https://jfrog.com/blog/openssh-pre-auth-double-free-cve-2023-25136-writeup-and-proof-of-concept/

crackerjack :fedora: :donor:
10 months ago

Glad most distros aren't enabling ksmbd by default! Another RCE has been discovered. Great breakdown of detection and mitigating here.

#cybersecuritynews #rce #KSMBD

https://sysdig.com/blog/cve-2023-0210-linux-kernel-unauthenticated-remote-heap-overflow/

crackerjack :fedora: :donor:
11 months ago

This is a fantastic dissection of the #EvilESP TCP/IP RCE vulnerability that was patched by Microsoft. I don't have time to finish reading or follow along myself currently, but I definitely plan on playing with this later today after work!

Understanding the mechanisms that are abused to achieve the exploit is what helps me fully grasp the implications of the vulnerability.

#cybersecuritynews #rce #tcpip

https://securityintelligence.com/posts/dissecting-exploiting-tcp-ip-rce-vulnerability-evilesp/

crackerjack :fedora: :donor:
11 months ago

Just another friendly reminder to not reuse credentials - ever! I use a self hosted instance of bitwarden, but there are plenty of tools to manage credentials.

#cybersecuritynews #paypal #credentialstuffing #credentialstuffingattack

https://www.bleepingcomputer.com/news/security/paypal-accounts-breached-in-large-scale-credential-stuffing-attack/

crackerjack :fedora: :donor:
11 months ago

I've heard about WiFi signal absorption being used to determine occupancy, but this is next level!

#cybersecuritynews #wifi #reconnaissance

https://www.tomshardware.com/news/wi-fi-routers-used-to-detect-human-locations-poses-within-a-room

crackerjack :fedora: :donor:
11 months ago

Five months between the foothold and the pivot. This is some serious long-game technique. More reason than ever to stay on top of patching!

#cybersecuritynews #ransomware

https://www.bleepingcomputer.com/news/security/lorenz-ransomware-gang-plants-backdoors-to-use-months-later/

crackerjack :fedora: :donor:
11 months ago

Well... I did it. I migrated (from https://nerfherders.io/@jack). Self-Hosting Mastodon was a blast but I'm changing roles professionally and won't have time for the work it takes. It's bittersweet. My old domain is currently dying a slow death, but trying to let the few users remaining migrate off of it.

I think I've found my new home though, this looks like an instance that is right up my alley.

Hi again, Fediverse! This is my re-#introduction post I suppose. I hope you're ready for more of my #cybersecuritynews and #cats posts!!

It's official! @seanmartin and I are covering #RSAC2023 - our 8th year in a row with @ITSPmagazine as official media partners for the event. Hope to see you all there! You can follow all of our shenanigans and adventures on the @ITSPmagazine coverage page at https://www.itspmagazine.com/rsac

Follow us and/or join us by sponsoring the coverage! There will be content created with organizers, keynotes, speakers, and all our many friends!

Let’s go! Is going to be a memorable adventure!
#infosec #conference #cybersecurity #cybersecuritynews #infosecjobs #podcasts #videos #livestream #tech #technology #society #ai #business #security