Created by ChatGPT
The auction for some fabulous whisky is live at Unicorn Auctions until November 21, 2024. Proceeds go to the Innocent Lives Foundation.
You can view the live recording at the ExploreSec YouTube Channel. The audio version of the podcast will hit the podcast feed soon.
At Exploring Information Security, we’re passionate about all things cybersecurity, community, and—every now and then—a great bourbon adventure. In April 2024, I had the chance to join a unique charity experience: a barrel pick trip with the Innocent Lives Foundation (ILF). It was a memorable journey that not only deepened my appreciation for bourbon but also highlighted how a shared passion can turn into a powerful force for good.
The Origins of the ILF Barrel Pick ClubThe ILF Barrel Pick Club started with a simple idea: what if they could combine a love for whiskey with a mission to protect children? A few conversations later, this idea grew into a fully-fledged project, allowing whiskey enthusiasts to purchase exclusive barrels with all proceeds supporting ILF’s mission of identifying predators and protecting children. The club's purpose is to create a community where each sip makes a difference. However, getting to that first barrel wasn’t straightforward; with whiskey’s growing popularity, acquiring a quality barrel often requires invites, lotteries, and long waitlists.
An Exclusive Tour of Legendary DistilleriesOur journey led us to Louisville, Kentucky, where we visited some of the country’s most iconic distilleries, including Four Roses and the lesser-known gem Starlight Distillery. These aren’t just whiskey manufacturers—they are stewards of tradition, science, and innovation, each offering distinct qualities that make them unique.
At Four Roses, we were taken behind the scenes and introduced to their precise process, from single-story rickhouses to unique yeast strains. We learned that each barrel tells a story; the location, temperature, and aging process impart distinct flavors and profiles. Four Roses, renowned for its transparent labeling, even indicates barrel location details down to the warehouse tier and barrel direction.
Across the river, we discovered Starlight Distillery, a family-owned operation with a 200-year history in farming and a more recent venture into bourbon-making. Known for experimenting with unique finishes like Mizunara oak (a notoriously tricky Japanese wood), Starlight introduced us to a whole new world of flavors and finishes. It’s a place as much for bourbon as for families, complete with a fun park and farm tours.
Crafting the Perfect Barrel PickPicking a barrel is a blend of art and science—and more challenging than one might expect. With guidance from our hosts, we tasted everything from rich caramel to floral and smoky notes. A well-rounded tasting experience involves layers of flavor and aroma that evolve with each sip. This nuanced approach is essential when selecting barrels for auction because our picks aren’t just about finding what tastes good—they have to resonate with the community of experienced drinkers while supporting ILF’s mission.
At each stop, we were welcomed with enthusiasm, kindness, and yes, lots of whiskey. Starlight even donated a bottle of their premium Mizunara cask-aged bourbon to support the ILF auction. The generosity of these distilleries reflects their alignment with ILF’s purpose. It was humbling to see how eager they were to support a mission that matters deeply to us.
Bidding on a Purpose: The ILF Whiskey AuctionThe highlight of this journey is the ILF auction, hosted by Unicorn Auctions. Unicorn Auctions has gone above and beyond to support us by waiving all fees, ensuring that every dollar raised goes to ILF’s mission. The auction features exclusive bottles selected during our barrel pick trip, and each bottle represents a unique expression of craftsmanship and generosity.
These bottles aren’t just collectibles; they’re tokens of the ILF mission. Whether you’re an experienced bourbon enthusiast or a newcomer, bidding in the auction allows you to support ILF in a unique way. Proceeds from the auction directly fund ILF’s work in identifying and helping bring child predators to justice, one bottle at a time.
Memorable Moments and Tasting NotesThe trip was full of memorable (and hilarious) moments—like trying to keep our stomachs steady on bumpy Kentucky roads after too many tastings or debating flavor notes (shoutout to Chris for the “pine sol” descriptor!). The tasting process highlighted just how subjective and personal whiskey can be. The complexities of flavor brought out some spirited debates and even a few new friendships.
One of the favorites of the group was the Starlight Double Oak—a rich, complex bourbon with dark spice and caramel notes that had us all captivated. If you’re lucky enough to get your hands on a bottle, it’s worth savoring every sip. For those looking for a unique twist, the Starlight honey finish adds a hint of natural sweetness that’s both unusual and surprisingly smooth.
Raising a Glass to a CauseAt the end of the day, these bottles represent something bigger. Each auction, each barrel, and each sip brings us closer to funding ILF’s crucial work. As we continue to grow the Barrel Pick Club, we’re reminded of the power of community, generosity, and shared passion. This journey has shown us that even something as simple as whiskey can make a profound difference.
If you’re interested in supporting ILF or exploring our latest auction, visit Unicorn Auctions and place a bid. Let’s raise a glass to great bourbon, and an even greater cause.
Created with the help of ChatGPT; edited by Timothy De Block. This post original posted on exploresec.com.
Created using ChatGPT
This week, Exploring Information Security is excited to bring you a unique live recording that steps outside the digital world and into the heart of Kentucky and Indiana distilleries. We’re partnering with the Innocent Lives Foundation (ILF) for a special episode, where we dive into the art and experience of barrel picking. Our adventure took us to two iconic locations—Four Roses and Starlight Distillery—where we set out to find exceptional barrels and create a meaningful connection between the worlds of whiskey and cyber awareness.
Why a Barrel-Picking Adventure?While cybersecurity and barrel picking might seem worlds apart, this journey is about more than just tasting whiskey. It’s about discovering the unique stories, craftsmanship, and community that make each barrel something special. For this live recording, we’re blending our curiosity for great whiskey with our commitment to the Innocent Lives Foundation’s important mission: protecting children from online exploitation.
Our Trip to Four Roses and Starlight DistilleryOur barrel-picking journey began at Four Roses, known for its distinctive, rich flavor profiles, and continued to Starlight Distillery, where each barrel tells its own story. At each stop, we dove into the meticulous process of selecting barrels, learning how master distillers and their teams create diverse flavors and memorable experiences.
Each barrel pick wasn’t just about taste—it was a sensory experience that engaged sight, smell, and sound. We discovered how small variations in wood, weather, and aging environments can shape a barrel's character and flavor. Selecting a barrel that stood out from the rest required both intuition and collaboration—a bit like finding the right approach to solving cybersecurity challenges.
Behind the Scenes: The Art of Barrel PickingSo, how does one go about picking a barrel? It starts with identifying what makes each barrel unique. From the moment we began the tasting process, we immersed ourselves in a symphony of aromas, textures, and flavors that define each barrel’s character. Some barrels surprised us with unexpected hints of fruit or spice, while others stood out for their smooth, rich finish. These discoveries weren’t just thrilling—they were a reminder of the craftsmanship and care that goes into every bottle.
Memorable Moments and Incredible PeopleOne of the highlights of this journey was meeting the people behind the barrels. We heard stories from master distillers, learned about family traditions that have been passed down for generations, and saw firsthand the dedication it takes to produce high-quality spirits. These connections deepened our appreciation for the process and made each tasting session more meaningful.
Connecting the Dots: How This Adventure Supports ILF’s MissionWhile we tasted and shared stories, we kept the Innocent Lives Foundation’s mission at the heart of this journey. ILF is dedicated to protecting children from online predators by working behind the scenes to identify and support law enforcement in bringing these offenders to justice. Each barrel we picked represents a small way to support ILF’s efforts, as proceeds from the sales will go directly to support their work.
For us, this experience was about more than the whiskey—it was about using this adventure to make a difference.
If you’d like to grab your own bottle head over to Unicorn Auctions!
Join Us Live!Ready to dive into the world of barrel picking with us? Whether you’re a whiskey enthusiast, a cybersecurity pro, or a supporter of ILF’s mission, this episode promises to be packed with flavor, storytelling, and purpose.
🗓️ Tune in live around 6:30 PM ET on the ExploreSec YouTube channel: ExploreSec YouTube Channel. Join us for an unforgettable experience and discover the story behind each barrel we selected!
This is a monthly newsletter I put together for our executive team with a lean towards healthcare. Created with help from ChatGPT.
Ransomware Threats Surge Globally in 2023
Summary: The 2023 Global Ransomware Incident Map highlights a 73% rise in ransomware attacks, targeting sectors like healthcare and finance. Cybercriminals are increasingly using "big game hunting" tactics, exploiting vulnerabilities such as the MOVEit flaw. This trend underscores the urgent need for businesses to bolster cybersecurity defenses and improve incident response strategies.
Further reading: Institute for Security and Technology.
AI Risks in the Workplace
A recent study by CybSafe revealed that 38% of workers are sharing sensitive information with AI tools, often without their employer's knowledge. This raises significant security concerns, especially since over half of employees have not received training on safe AI use. With the growing reliance on AI, it's crucial for executives to implement clear guidelines and provide training on secure AI practices to mitigate the risk of data breaches and protect intellectual property.
Further reading: CybSafe - AI Security Risks.
North Korean IT Worker Incident Highlights Hiring Risks
A recent cyberattack on a company underscores the dangers of unknowingly hiring North Korean operatives. The organization accidentally hired a North Korean IT worker who accessed sensitive data and demanded a ransom. This highlights the need for stringent vetting in remote hiring practices, especially as North Korea increasingly infiltrates global companies.
Recommended Protections:
Further reading: GBHackers - North Korean IT Worker Incident.
Healthcare Supply Chain Attacks on the Rise
A recent Proofpoint report reveals that 68% of healthcare workers have faced a supply chain cyberattack, with 82% of these incidents affecting patient care.
Key Insights:
Further reading: Security Magazine - Supply Chain Attacks.
Change Healthcare Breach – Key Insights and Implications
In February 2024, Change Healthcare experienced a substantial ransomware attack, compromising the personal, financial, and medical information of approximately 100 million Americans. This incident highlights critical vulnerabilities within the healthcare sector and raises concerns about protecting patient data.
Key Insights:
Further Reading: Change Healthcare Breach Hits 100M Americans – Krebs on Security
This is a monthly newsletter I put together for our internal security team with a lean towards phishing and healthcare. Created with help from ChatGPT.
Fake Job Applications Deliver Dangerous Malware
Summary: A spear-phishing campaign is targeting HR professionals with fake job applications containing the More_eggs malware. Operated by the Golden Chickens group as part of a Malware-as-a-Service (MaaS) platform, More_eggs is a sophisticated backdoor used by multiple threat actors to infiltrate corporate networks.
Key Insights (Technical):
For further details, read the full article on The Hacker News.
New Ransomware Strain Targeting Healthcare
The U.S. Department of Health and Human Services (HHS) issued a warning about a new ransomware strain, Trinity, which is actively targeting the healthcare sector. Trinity uses techniques like encrypting data and demanding ransoms within 24 hours. It has connections to other ransomware families such as Venus and 2023Lock.
Technical Key Insights:
Further reading: The Record - Trinity Ransomware Alert.
Emerging Cybersecurity Threats Highlighted in HP Wolf Security Report
The September 2024 HP Wolf Security Threat Insights Report identifies key trends in cyberattacks, including a surge in document-based malware, with 61% of threats delivered via email attachments. Attackers are increasingly using malicious archives and PDFs to bypass detection, leveraging techniques like HTML smuggling and exploiting vulnerabilities in outdated software. Threat actors are also using Generative AI to write sophisticated malware, such as AsyncRAT.
Key Insights:
Further reading: HP Wolf Security Threat Insights Report.
North Korean IT Worker Incident Highlights Hiring Risks
A recent cyberattack on a company underscores the dangers of unknowingly hiring North Korean operatives. The organization accidentally hired a North Korean IT worker who accessed sensitive data and demanded a ransom. This highlights the need for stringent vetting in remote hiring practices, especially as North Korea increasingly infiltrates global companies.
Recommended Protections:
Further reading: GBHackers - North Korean IT Worker Incident.
User-Centric Security Design Inspired by Disney
A recent article from KnowBe4 discusses how organizations can improve security by observing how employees naturally work, similar to Disney’s strategy of observing guests before building paths. The concept of "desire paths" shows that security controls should be designed around actual workflows, reducing friction and improving compliance. By aligning security with user behavior, organizations can mitigate risky workarounds and foster a more secure environment.
Further reading: KnowBe4 - Security Highways.
Healthcare Supply Chain Attacks on the Rise
A recent Proofpoint report reveals that 68% of healthcare workers have faced a supply chain cyberattack, with 82% of these incidents affecting patient care.
Key Insights:
Further reading: Security Magazine - Supply Chain Attacks.
Microsoft’s Deceptive Honeypot Strategy Targets Phishers
Microsoft has launched a clever security strategy by creating fake Azure tenants to lure phishing attackers into honeypots. These realistic tenant environments mimic legitimate setups, tricking attackers into interacting with them. This allows Microsoft to gather valuable intelligence on phishing methods and infrastructure, which can be used to strengthen defenses and share with the wider security community. By engaging with these fake environments, phishers waste time while Microsoft gains crucial insights.
Further reading: BleepingComputer - Microsoft Honeypots.
Mobile-First Cyber Attacks on the Rise
Cyber attackers are increasingly adopting a "mobile-first" strategy, as highlighted by a new report from Zimperium. With 83% of phishing sites now targeting mobile devices and a 13% rise in mobile malware, employees’ personal devices pose a growing risk to organizations. As more employees use their smartphones for work-related tasks, organizations need to bolster mobile security and educate employees on safe practices through security awareness training.
Further reading: KnowBe4 - Mobile-First Attack Strategy.
Cybercriminals Exploiting Steam for Malware Distribution
A recent investigation highlights how cybercriminals are using Steam profiles to exploit a technique called Dead Drop Resolver (DDR) to hide Command and Control (C2) addresses within user profiles. Attackers have leveraged well-known infostealers like Vidar, Lumma, and MetaStealer to extract sensitive data from infected systems by using platforms like Steam and Telegram to evade detection.
Technical Key Insights:
Further reading: RT Solar Blog. <---- .ru site
Rise in Phishing Attacks with AI and Impersonation Tactics
A new report from KnowBe4 reveals a 28% rise in phishing attacks during Q2 2024, with 89% of attacks involving brand impersonation. Cybercriminals are increasingly using AI-powered phishing toolkits, making it easier for less-skilled attackers to execute sophisticated campaigns. Commodity phishing attacks, primarily using hyperlinks, have surged, overwhelming organizations' defenses. With impersonation tactics being a dominant trend, organizations must enhance defenses against these evolving threats.
Key Insights:
Further reading: KnowBe4 Report.
Phishing-as-a-Service Platform "Sniper Dz" Exposed
A recent investigation reveals the rise of the phishing-as-a-service (PhaaS) platform "Sniper Dz," which is responsible for over 140,000 phishing websites. The platform offers phishing templates targeting major brands and hides malicious content behind proxy servers to evade detection. Additionally, attackers can exfiltrate credentials to centralized servers controlled by Sniper Dz. This growing platform enables less-skilled attackers to launch sophisticated phishing attacks with ease.
Further reading: Unit 42 - Sniper Dz PhaaS.
Dark Angels Ransomware Group Exposed
A recent investigation uncovers the stealth tactics of the Dark Angels ransomware group, which targets high-value systems with Babuk and RagnarLocker-based ransomware. Their techniques include double extortion, data exfiltration, and selective ransomware deployment to minimize detection.
Technical Key Insights:
Further reading: Zscaler - Dark Angels Ransomware Group.
North Korean IT Worker Fraud
SecureWorks reports that North Korean IT workers are fraudulently obtaining remote jobs to access sensitive systems and generate revenue for the regime. These individuals disguise their identities, use VPNs to hide their location, and exploit company resources once hired.
Key Insights:
Further Reading: Fraudulent North Korean IT Worker Schemes
Health Care and Social Assistance Sector at Risk
Cyber threats in the Health Care and Social Assistance sector are intensifying, with phishing and social engineering attacks being the most prevalent. Organizations need to prioritize automation and Digital Risk Protection strategies to defend against these sophisticated threats.
Key Insights:
Further Reading: ReliaQuest Health Care Threat Landscape
AI-Driven Malware and Persistent Ransomware Threats
Check Point's Global Threat Index for September 2024 highlights the rising use of AI in malware creation, with AsyncRAT becoming one of the top threats. AI-powered scripts are being used to deliver malware like AsyncRAT through techniques such as HTML smuggling, showcasing how threat actors with limited technical skills can now leverage AI to create sophisticated attacks. This evolution underscores the need for organizations to adopt proactive security strategies.
In addition, RansomHub, a rebranded Ransomware-as-a-Service group, continues to dominate the ransomware scene, accounting for 17% of reported attacks. Other prominent malware families include FakeUpdates, targeting organizations worldwide, and Androxgh0st, which exploits vulnerabilities across platforms.
Key Insights:
Further Reading: Check Point Threat Intelligence Report
Trinity Ransomware Hits Healthcare Sector
The Trinity ransomware group is targeting healthcare organizations with double-extortion tactics, gaining access through phishing emails and software vulnerabilities. This ransomware not only encrypts data but also steals it, pressuring victims to pay or risk exposure of sensitive information. Two healthcare providers have already been attacked, with 330GB of data compromised from a U.S.-based provider.
Key Insights:
Further Reading: Trinity Ransomware Targets Healthcare
Threat Intelligence Update: Black Basta’s Social Engineering Tactics via Microsoft Teams
The Black Basta ransomware group has employed a sophisticated social engineering campaign targeting organizations through Microsoft Teams. By signing user emails up for multiple spam sources, Black Basta overwhelms the target with unwanted messages. Threat actors then contact the user, impersonating IT support and offering assistance with the email flood. During this call, the attacker convinces the user to install remote access software like Quick Assist or AnyDesk, providing them unauthorized access to the network. Once inside, the attackers can harvest credentials and potentially deploy ransomware.
Key Insights:
Further Reading: ReliaQuest Blog on Black Basta's Techniques
Q3 2024 Ransomware Trends
The ReliaQuest Q3 2024 ransomware report highlights significant shifts in the ransomware landscape, with new groups gaining prominence and using sophisticated tactics to escalate their attacks. RansomHub has overtaken LockBit as the most active group, experiencing an 800% rise in postings from Q1 to Q3. Their growth is attributed to aggressive recruiting and lucrative profit-sharing, which has drawn affiliates from other disrupted groups. This group, along with Play ransomware, continues to exploit vulnerabilities in VPNs and public-facing applications, demonstrating the persistent risk posed by unpatched systems.
Key Insights:
Further Reading: ReliaQuest Q3 Ransomware Report
Update: Q3 2024 Brand Phishing Trends
Check Point Research’s Q3 2024 report reveals that Microsoft continues as the most impersonated brand in phishing attacks, accounting for 61% of brand phishing attempts. Apple (12%) and Google (7%) follow, with new additions Alibaba and Adobe rounding out the top 10. These attacks commonly target the technology, social media, and banking sectors, as cybercriminals exploit brand familiarity to deceive users and capture credentials or payment information. Notably, new phishing sites targeting WhatsApp and Alibaba highlight the evolving strategies of threat actors seeking to exploit user trust.
Key Insights:
Further Reading: Check Point’s Q3 2024 Brand Phishing Report.
Global Surge in Cyber Attacks in Q3 2024
Check Point’s Q3 2024 report highlights a significant 75% increase in global cyber attacks compared to last year, with each organization facing an average of 1,876 weekly attacks. Sectors most impacted include Education/Research (3,828 weekly attacks), Government/Military (2,553), and Healthcare (2,434), reflecting the increased focus on these industries. Africa saw the highest regional attack rate, averaging 3,370 weekly, up 90% from 2023, while North America experienced the most ransomware attacks, making up 57% of incidents worldwide. Manufacturing was the top ransomware target, followed by Healthcare and Retail/Wholesale.
Key Insights:
Further Reading: Check Point Q3 2024 Report.
North Korean Cybercriminal Infiltrates UK Company
A UK-based organization recently suffered a breach after inadvertently hiring a North Korean cybercriminal posing as a remote IT worker. Once hired, the attacker used insider access to extract sensitive information and eventually demanded a ransom for its non-disclosure. This case highlights the importance of strict hiring processes for remote roles and enhanced security practices.
Key Insights:
Further Reading: KnowBe4 Article; KnowBe4 10 Hiring Updates
Partnership Between Scattered Spider and RansomHub
ReliaQuest reports a new collaboration between the Scattered Spider and RansomHub groups, merging advanced social engineering skills with network-compromising expertise to target enterprises globally. The partnership leverages RansomHub's effective 90/10 profit-sharing model, attracting experienced threat actors from disrupted groups. This collaboration allows attackers to target critical virtual infrastructures, such as ESXi servers, which host key applications, enabling high-impact ransomware attacks that pressure victims to pay swiftly.
Key Insights:
For more details, explore the full article at ReliaQuest.
Social Engineering Exploits Valid Accounts
Recent incidents highlight how threat actors are compromising legitimate accounts through social engineering tactics. By manipulating individuals into divulging sensitive information or performing specific actions, attackers gain unauthorized access to systems and data. This method often involves impersonating trusted entities or creating convincing scenarios to deceive targets.
Key Insights:
Further Reading: KnowBe4 Article on Social Engineering Exploits.
North Korean Group Adopts Play Ransomware
Unit 42 has identified that the North Korean state-sponsored threat group, Jumpy Pisces (also known as Andariel), has begun collaborating with the Play ransomware group, Fiddling Scorpius. This marks a significant shift in Jumpy Pisces' tactics, moving from traditional cyber espionage to active participation in ransomware operations. The group gained initial access to networks via compromised user accounts, deploying tools like Sliver and their custom malware, DTrack, to facilitate lateral movement and persistence. This collaboration underscores the evolving ransomware landscape, where nation-state actors are increasingly engaging in financially motivated cybercrime.
Key Insights:
Further Reading: Unit 42 Article on Jumpy Pisces and Play Ransomware.
Key Cyber Threat Actors in 2024
ReliaQuest's recent analysis identifies five prominent cyber threat actors significantly impacting the cybersecurity landscape in 2024:
Further Reading: ReliaQuest Article on Critical Threat Actors.
Halloween’s Digital Threats of 2024
Halloween brings tales of horror, but in 2024, some of the scariest threats come from the digital realm. Cybercriminals are increasingly using advanced tools to target individuals and organizations with new forms of AI-driven malware, IoT exploits, and social engineering tricks that play on our trust.
Key Insights:
Further Reading: Check Point’s guide on Halloween Cyber Threats.
This is a newsletter I share internally as part of our internal security awareness program. Feel free to take and use in your organization. Created with help from ChatGPT
Fake Job Applications Deliver Dangerous Malware
Summary: A spear-phishing campaign has been targeting HR professionals with malicious job applications. Attackers use fake resumes containing More_eggs malware, a backdoor designed to steal credentials. This malware, part of a Malware-as-a-Service (MaaS) platform operated by the Golden Chickens group, can be used by multiple threat actors. The attack chain involves malicious Windows shortcut (LNK) files that initiate the infection upon execution, allowing attackers to perform reconnaissance and drop additional payloads.
Key Insight: Be cautious when handling job applications, especially those involving downloadable files from unknown sources.
For further details, read the full article on The Hacker News.
Data Privacy Risks in Connected Cars
Modern connected vehicles collect vast amounts of data, including driving habits, location, and even biometric information like voice commands. A recent analysis by CHOICE reveals that many popular car brands share this data with third-party companies, raising privacy concerns. Brands like Kia, Hyundai, and Tesla collect and share voice and video data, while others gather driving behaviors. This highlights the importance of understanding your car’s data collection practices and opting out where possible.
Further reading: CHOICE - Connected Cars Tracking Your Data.
North Korean Hackers Targeting Job Seekers
A new campaign by North Korean hackers is targeting job seekers, particularly in the tech industry, according to a recent report. Hackers impersonate recruiters on platforms like LinkedIn, luring individuals into downloading malware disguised as video conferencing tools. The malware is designed to steal cryptocurrency and sensitive corporate data, posing risks to both individuals and organizations. Job seekers should remain cautious when interacting with unsolicited offers and recruiters.
Further reading: KnowBe4 - North Korean Hackers.
Election Season and Cybersecurity Concerns
As the 2024 election season progresses, a recent Malwarebytes survey reveals that 74% of respondents consider it a risky time for personal information. Fears of scams, privacy breaches, and cyber interference are high, with 52% of people expressing concern about falling prey to scams through political ads. Many are taking precautions, such as using two-factor authentication and password managers, to secure their data.
Key Insights:
Further reading: Malwarebytes - Election Season Raises Fears.
North Korean IT Worker Incident Highlights Hiring Risks
A recent cyberattack on a company underscores the dangers of unknowingly hiring North Korean operatives. The organization accidentally hired a North Korean IT worker who accessed sensitive data and demanded a ransom. This highlights the need for stringent vetting in remote hiring practices, especially as North Korea increasingly infiltrates global companies.
Recommended Protections:
Further reading: GBHackers - North Korean IT Worker Incident.
Mobile-First Cyber Attacks on the Rise
Cyber attackers are increasingly adopting a "mobile-first" strategy, as highlighted by a new report from Zimperium. With 83% of phishing sites now targeting mobile devices and a 13% rise in mobile malware, employees’ personal devices pose a growing risk to organizations. As more employees use their smartphones for work-related tasks, organizations need to bolster mobile security and educate employees on safe practices through security awareness training.
Further reading: KnowBe4 - Mobile-First Attack Strategy.
Microsoft Spoofing Threats on the Rise
A recent report from Harmony Email & Collaboration highlights over 5,000 fake Microsoft emails targeting organizations within a single month. These emails, often impersonating legitimate administrators, use sophisticated obfuscation techniques, making it difficult for users to detect. The risks include account takeovers, ransomware, and data theft.
Further reading: Check Point Blog.
New VPN Credential Attack Uses Sophisticated Social Engineering
A recent attack uncovered by security researchers targets organizations using VPNs through a combination of social engineering, fake login sites, and phone calls. Attackers impersonate a helpdesk, direct users to a spoofed VPN login page, and steal credentials. They also prompt users for multi-factor authentication (MFA) codes to gain access to corporate networks. This attack highlights the importance of user vigilance and strong security training.
Attack Chain:
Further reading: KnowBe4 - New VPN Credential Attack.
Operation Kaerb Takedown
Operation Kaerb successfully dismantled iServer, a Phishing-as-a-Service platform responsible for facilitating mobile credential theft targeting nearly half a million victims. iServer enabled low-skilled criminals to unlock stolen phones by phishing for user credentials. This takedown is a reminder of the evolving tactics cybercriminals use and underscores the importance of staying vigilant against mobile-focused phishing attacks.
Further Reading: Operation Kaerb on KnowBe4
Sextortion Scams on the Rise
Our team has recently been targeted by sextortion scams, where attackers use publicly available information to create threatening messages designed to elicit fear and urgency. These scams often appear more credible by including personal details. If you receive such a message, avoid engagement or payment—report it to our security team immediately by using the suspicious email button in Outlook.
Further Reading: KnowBe4 Article on Sextortion Scams.
Update: Q3 2024 Brand Phishing Trends
Check Point Research’s Q3 2024 report reveals that Microsoft continues as the most impersonated brand in phishing attacks, accounting for 61% of brand phishing attempts. Apple (12%) and Google (7%) follow, with new additions Alibaba and Adobe rounding out the top 10. These attacks commonly target the technology, social media, and banking sectors, as cybercriminals exploit brand familiarity to deceive users and capture credentials or payment information. Notably, new phishing sites targeting WhatsApp and Alibaba highlight the evolving strategies of threat actors seeking to exploit user trust.
Key Insights:
Further Reading: Check Point’s Q3 2024 Brand Phishing Report.
North Korean Cybercriminal Infiltrates UK Company
A UK-based organization recently suffered a breach after inadvertently hiring a North Korean cybercriminal posing as a remote IT worker. Once hired, the attacker used insider access to extract sensitive information and eventually demanded a ransom for its non-disclosure. This case highlights the importance of strict hiring processes for remote roles and enhanced security practices.
Key Insights:
Further Reading: KnowBe4 Article; KnowBe4 10 Hiring Updates
North Korean Threat Actors Pose as Recruiters to Target Job Seekers
Palo Alto Networks' Unit 42 recently uncovered a campaign in which North Korean threat actors pose as recruiters to lure tech job seekers into downloading malware disguised as legitimate communication tools. Known as the "Contagious Interview" campaign, this operation involves malware variants like BeaverTail and InvisibleFerret, which are capable of stealing credentials, exfiltrating sensitive files, and targeting cryptocurrency wallets. Victims are approached on professional platforms like LinkedIn, and then directed to install fake interview applications that serve as a conduit for malware.
Key Insights:
As remote work and digital hiring continue to rise, it’s critical to validate the legitimacy of recruiters and avoid downloading unverified software for job interviews.
Further Reading: Unit 42 Report on North Korean Recruitment Tactics
Pig Butchering Scams Target Job Seekers
Proofpoint has identified a new twist in cryptocurrency fraud, known as "Pig Butchering," targeting job seekers. Scammers posing as recruiters lure victims into fake job roles, eventually guiding them to invest in fraudulent cryptocurrency platforms. Victims see initial "profits" to build trust, but ultimately lose their entire investment. These scams often begin on social media, moving to platforms like WhatsApp or Telegram for further manipulation.
Further Reading: Proofpoint Article.
Foreign Disinformation on U.S. Hurricanes
Recent intelligence shows that operatives from Russia, China, and Cuba have spread false information about U.S. hurricanes to deepen political divides. AI-generated images and misleading posts claimed federal relief was denied or funds were diverted to foreign conflicts, aiming to erode trust in U.S. disaster response. Be cautious of divisive narratives or unverified disaster images on social media, as they may be part of coordinated disinformation efforts.
Further Reading: NBC News Article.
Social Engineering Exploits Valid Accounts
Recent incidents highlight how threat actors are compromising legitimate accounts through social engineering tactics. By manipulating individuals into divulging sensitive information or performing specific actions, attackers gain unauthorized access to systems and data. This method often involves impersonating trusted entities or creating convincing scenarios to deceive targets.
Key Insights:
Further Reading: KnowBe4 Article on Social Engineering Exploits.
Major Data Breach at Change Healthcare Affects 100 Million Americans
In February 2024, Change Healthcare, a leading U.S. healthcare technology company, experienced a significant ransomware attack that compromised the personal, financial, and medical information of approximately 100 million individuals. The breach disrupted healthcare services nationwide, highlighting vulnerabilities in the sector's cybersecurity defenses.
Key Insights:
Further Reading: Change Healthcare Breach Hits 100M Americans – Krebs on Security
Student Loan Phishing Scams Targeting Millions
Cybercriminals are exploiting confusion around student loan forgiveness with a surge in phishing emails targeting millions of Americans. These emails use advanced techniques to look legitimate and bypass email filters, making them harder to detect.
What You Can Do to Stay Safe:
Further Reading: Check Point Blog.
Created by ChatGPT
This is a newsletter I share internally as part of our internal security awareness program. Feel free to take and use in your organization. Created with help from ChatGPT
Spamouflage: State-Linked Influence Operations Target U.S. Elections Summary: A Chinese state-linked influence operation, Spamouflage, is ramping up efforts to sway U.S. political discourse ahead of the 2024 election. By posing as U.S. voters and using AI-generated content, they spread divisive narratives on social media about sensitive issues like gun control and racial inequality. These tactics highlight the importance of vigilance against foreign influence campaigns and fake online personas.
Key Insight: Verify online sources and stay aware of potential influence operations.
Further Reading: Graphika Report
Lazarus Hackers Target Job Seekers with Malware-Laden Job Offers Summary: The Lazarus Group is actively targeting job seekers, particularly those in blockchain-related fields, by disguising malware within fake job offers. The group utilizes platforms like LinkedIn, Upwork, and Telegram to distribute malicious software, including the "BeaverTail" malware, which steals credentials and cryptocurrency wallet data. Job seekers should be cautious of unsolicited job offers and avoid downloading unfamiliar files.
Key Insight: Always verify job offers and avoid downloading files from unknown sources.
Further Reading: GBHackers Article
Foreign Influence Operations Target U.S. 2024 Election Summary: U.S. intelligence officials warn of increased influence operations from Russia, China, and Iran aimed at U.S. voters ahead of the 2024 election. These operations, while not yet disrupting voting infrastructure, spread disinformation through media, PR firms, and American influencers. A recent U.S. indictment highlights Russia's attempts to covertly funnel pro-Russian narratives into right-wing media, signaling the need for heightened vigilance as the election approaches.
Key Insight: Stay alert to disinformation and foreign influence in political content.
Further Reading: CyberScoop Article
Lowe's Employees Targeted by Google Ads Phishing Campaign Summary: Lowe's employees were recently targeted by a phishing attack using fraudulent Google ads mimicking the MyLowesLife portal. Attackers designed fake login pages to steal employee credentials. This highlights the dangers of using search engines to access work-related sites. Employees should be reminded to avoid clicking on sponsored links and instead bookmark legitimate sites to protect against phishing attacks.
Tip: Always access work portals through bookmarks or trusted URLs, not through search engines.
Further Reading: Malwarebytes Blog
Email Breaches at Welcome Health & United Way of Connecticut Summary: Welcome Health and United Way of Connecticut reported email account breaches compromising sensitive data. At Welcome Health, patient information and contractor Social Security numbers were exposed, while a phishing attack on United Way's employee email compromised data of up to 8,039 patients. Both organizations have responded with enhanced security measures and offered credit monitoring to affected individuals.
Further Reading: HIPAA Journal
False Claims of Hacked Voter Data Intended to Undermine U.S. Elections Summary: The FBI and CISA have issued a joint public service announcement warning about false claims of hacked voter information. Foreign actors may spread disinformation to erode public confidence in U.S. elections, especially by exaggerating claims of compromised voter data. The agencies urge citizens to critically evaluate such claims and remind that much voter information is public.
Key Insight: Stay vigilant against disinformation campaigns designed to sow distrust in election processes.
Further Reading: CISA Announcement
Beware of Parking Payment Scams Involving Fake QR Codes Summary: Drivers in the UK are being targeted by scammers who place fake QR codes on parking machines. These codes lead to fraudulent websites designed to steal payment information. The RAC warns drivers to avoid using unfamiliar QR codes and instead rely on cash, card, or official apps for parking payments. This "quishing" scam has been reported across multiple UK regions, with an increasing number of incidents.
Key Insight: Be cautious when scanning QR codes, especially in public places like parking machines.
Further Reading: RAC News
Florida Healthcare Data Leak Exposes Thousands of Doctors and Hospitals Summary: A data breach at MNA Healthcare exposed sensitive information of over 14,000 healthcare workers and 10,000 hospitals, including encrypted Social Security Numbers, addresses, and job details. The breach, caused by a misconfigured database, increases risks of identity theft and fraud. Healthcare professionals and institutions are advised to enhance cybersecurity measures, monitor financial accounts, and consider identity theft protection.
Further Reading: Cybersecurity News
New Sextortion Scam Uses Photos of Victims' Homes Summary: A recent wave of sextortion scams has taken a more personalized approach, including photos of victims' homes in threatening emails. Scammers claim to have recorded compromising footage through malware and demand Bitcoin payments to avoid releasing the videos. The photos are often pulled from online mapping services to increase intimidation. To stay safe, avoid responding to such emails, keep webcams covered when not in use, and report incidents to law enforcement.
Further Reading: Krebs on Security
Google Password Manager Now Syncs Passkeys Across Devices Summary: Google Password Manager now automatically syncs passkeys across Windows, macOS, Linux, Android, and ChromeOS devices. Passkeys, which use biometrics like fingerprints and facial recognition, offer a more secure alternative to passwords. With this update, passkeys are encrypted and accessible on all devices, enhancing security and convenience for users. Google has also introduced a new PIN feature to ensure end-to-end encryption for synchronized data.
Further Reading: BleepingComputer Article
FTC Report Exposes Surveillance by Social Media and Streaming Giants Summary: The FTC has released a report revealing that major social media and video streaming platforms engage in extensive data collection and surveillance of users, including children and teens. The report highlights inadequate privacy protections and raises concerns about the use of data for targeted advertising. The FTC recommends stronger privacy laws, data minimization, and enhanced safeguards for younger users.
Key Insight: Ensure your social media use is mindful of privacy risks, and review settings to limit data sharing.
Further Reading: FTC Report
Operation Overload: A Disinformation Threat Targeting U.S. Elections Summary: Operation Overload, a Russia-linked disinformation campaign, is ramping up efforts targeting U.S. voters ahead of the 2024 presidential election. The operation uses AI-generated fake content, such as fabricated TikTok videos and doctored news articles, to spread false narratives. Recent emails aimed at smearing Vice President Kamala Harris highlight the evolving tactics. It's critical for newsrooms and voters to remain vigilant and fact-check claims.
Key Insight: Be cautious of AI-generated content that mimics legitimate sources to manipulate public opinion.
Further Reading: CheckFirst Report
Phishing Attack Uses Two-Step Approach to Evade Detection Summary: A new phishing attack leverages a two-step process, using legitimate platforms like Microsoft Office Forms as an intermediary to evade detection. After clicking the phishing email link, users are directed to a legitimate form before being redirected to a fake login page designed to steal credentials. This sophisticated approach helps attackers bypass security filters by exploiting trusted platforms.
Key Insight: Be cautious of phishing links that utilize legitimate services as intermediaries before redirecting to malicious sites.
Further Reading: KnowBe4 Blog
Investment Scam Losses Surge Six-Fold Since 2021 Summary: The Better Business Bureau reports a six-fold increase in losses from investment scams since 2021. Scammers frequently exploit dating platforms and hacked social media accounts to lure victims into fraudulent cryptocurrency schemes. Victims are often promised high returns on investments, only to lose significant amounts of money. Common red flags include promises of guaranteed returns, little-known cryptocurrencies, and requests to share wallet details.
Key Insight: Be cautious of unsolicited investment offers and avoid sharing cryptocurrency wallet details with unverified individuals.
Further Reading: KnowBe4 Blog
HR-Related Phishing Tactics on the Rise Summary: Threat actors are using HR-related phishing emails, posing as internal messages like "Updated Employee Handbook," to trick employees into clicking malicious links. These attacks often lead victims to fake login pages that steal their credentials. The emails appear legitimate, making it crucial for employees to be extra cautious with HR communications and verify any unusual requests directly with their HR department.
Key Insight: Always verify HR-related emails before clicking links or providing sensitive information.
Further Reading: Cofense Blog
Foreign Influence Operations Using AI to Target U.S. Elections Summary: According to a recent ODNI election security update, foreign actors—primarily Russia and Iran—are increasingly using AI-generated content to influence U.S. voters. These actors are deploying manipulated media across various formats, including text, images, audio, and video, to spread disinformation and fuel divisive political narratives. As Election Day approaches, U.S. citizens should be vigilant about AI-generated content and misinformation campaigns.
Key Insight: Verify sources and be cautious of sensationalized or divisive media, especially content that seems AI-generated.
Further Reading: ODNI Election Security Update
Expert Tips to Identify Phishing Links Summary: Phishing attacks are becoming more sophisticated, but there are key ways to spot phishing links. Security experts advise checking for suspicious URLs with complex characters, paying attention to redirect chains, and inspecting page titles or missing favicons. Attackers also abuse CAPTCHA and Cloudflare checks to mask phishing attempts. Tools like ANY.RUN’s Safebrowsing can help safely analyze suspicious links before engaging with them.
Key Insight: Always inspect URLs carefully and use tools to analyze suspicious links in a safe environment.
Further Reading: The Hacker News
The Dangerous Intersection Between Cybercrime and Harm Groups Summary: A recent investigation reveals that some cybercriminals involved in ransomware attacks are also tied to violent online communities. These groups, often targeting young people, manipulate victims into self-harm or harming others. They use platforms like Telegram and Discord to coordinate harassment and extortion, demonstrating the increasing overlap between cybercrime and real-world violence.
Key Insights:
Read more: Krebs on Security.
Cyber Predators Exploit Healthcare Vulnerabilities with Ransomware and Data Theft Summary: Cybercriminals are increasingly targeting healthcare organizations, exploiting weaknesses to steal patient data and extort hospitals via ransomware attacks. These criminals collaborate through darknet marketplaces, offering ransomware-as-a-service, and trading access to compromised healthcare systems. With attacks up 32% globally in 2024, healthcare remains a prime target due to its valuable data and often outdated security infrastructure.
Key Insights:
Read more: Checkpoint Research.
Beware of Funeral Streaming Scams on Facebook Summary: Scammers are exploiting Facebook by creating fake funeral streaming groups, tricking grieving families into providing credit card information to view a supposed service. These fraudulent groups use the deceased's images to appear legitimate and direct users to malicious websites requesting payment. This scheme preys on vulnerable people, often at their most emotional moments.
Key Insights:
Read more: Krebs on Security.
Phishing Campaign Exploits Google Apps Script for Sophisticated Attacks Summary: A new phishing campaign manipulates Google Apps Script macros to target users across multiple languages. The phishing emails falsely claim to provide “account details” and include links to malicious pages mimicking legitimate Google services. Victims are tricked into disclosing sensitive information, leading to data theft and operational disruption.
Key Insights:
For more details, visit Checkpoint Research.
New Windows PowerShell Phishing Campaign Highlights Serious Risks Summary: A recently discovered phishing campaign uses GitHub-themed emails to trick recipients into launching PowerShell commands, enabling the download of password-stealing malware. The attack uses social engineering techniques, disguising itself as a CAPTCHA verification process. By exploiting PowerShell’s automation capabilities, attackers gain unauthorized access to credentials stored on victims' systems.
Key Insights:
For more, visit Krebs on Security.
Phishing Attacks Exploit Content Creation and Collaboration Platforms Summary: A recent phishing campaign abuses popular content creation and collaboration tools to trick users into clicking malicious links. Cybercriminals use legitimate-looking posts and documents with embedded phishing URLs, leading to credential theft through fake login pages. These attacks have been seen in both business and educational environments.
Key Insights:
For more information, visit KnowBe4.
Scammers Exploit Virtual Shopping Lists to Target Walmart Customers Summary: Cybercriminals are using Walmart’s virtual shopping list feature to scam customers by embedding fake customer support numbers. Clicking these links, often promoted via malicious ads, leads users to scammers who impersonate law enforcement or bank employees. Victims are coerced into transferring funds, often under false threats of legal consequences.
Key Insights:
For more details, visit KnowBe4.
Cyber Threats Looming for the 2024 U.S. Election Summary: As the 2024 U.S. election approaches, cyber threats from nation-state actors, hacktivists, and cybercriminals are expected to rise. These include disinformation campaigns, phishing attacks, and attacks on electoral infrastructure. Businesses should brace for phishing campaigns and SEO poisoning targeting politically charged topics.
Key Insights:
For more details, visit ReliaQuest.
Timeshare Scam Linked to Mexican Drug Cartel Targets U.S. Owners Summary: The FBI has issued a warning about a telemarketing scam targeting timeshare owners, linked to the Jalisco New Generation drug cartel. Scammers posing as buyers lure victims into paying advance fees for fraudulent timeshare sales. The funds are used to finance other cartel activities. Victims are often reluctant to report the scam due to fear or embarrassment.
Key Insights:
For more details, visit Krebs on Security.
Created by ChatGPT
This is a monthly newsletter I put together for our internal security team with a lean towards phishing and healthcare. Created with help from ChatGPT.
Phishing via Google Ads Targets Lowe’s Employees Summary: Interesting technicque to watch. A recent malvertising campaign targeted Lowe’s employees by impersonating the company’s employee portal through fraudulent Google ads. Threat actors used phishing pages that closely resembled the legitimate MyLowesLife site to steal login credentials. These attacks underline the need for caution when clicking on sponsored links, especially for accessing internal portals.
Key Insight: Avoid using search engines to access internal portals—bookmark them instead to reduce exposure to phishing.
Further Reading: Malwarebytes Blog
Emerging Phishing Threats: Typosquatting and Brand Impersonation Trends Summary: Zscaler's research uncovers a growing trend in phishing attacks involving typosquatting and brand impersonation. Attackers are increasingly mimicking popular brands using lookalike domains to trick users into divulging sensitive information.
Key Insights:
For more details, visit Zscaler's blog.
Suspected Espionage Campaign Delivers “Voldemort” Malware Summary: Proofpoint researchers identified a sophisticated espionage campaign distributing custom malware named "Voldemort." This campaign used advanced techniques like abusing Google Sheets for command and control (C2) and targeting organizations globally by impersonating tax authorities. The malware, likely tied to an APT actor, has intelligence-gathering capabilities and is suspected of espionage rather than financial gain.
Key Insights:
For more details, visit Proofpoint's blog.
Scattered Spider Targets Insurance and Financial Sectors Using Cloud Ransomware Summary: The Scattered Spider group has intensified its ransomware attacks on the insurance and financial industries, leveraging cloud vulnerabilities and phishing campaigns to compromise high-privileged accounts. The group uses social engineering tactics, including SIM swapping, smishing, and cloud credential theft, to gain unauthorized access. Their advanced techniques, combined with partnerships like BlackCat, have made them a formidable threat to cloud-based infrastructures.
Further Reading: EclecticIQ Blog
Top Cyber Attacker Techniques: May-July 2024 Insights Summary: ReliaQuest’s report from May to July 2024 highlights the growing threat of phishing, accounting for 37% of incidents. The “SocGholish” malware, delivered via fake browser updates, remains widespread. Additionally, exposed credentials make up 88.75% of alerts, posing significant risks. Key sectors targeted by ransomware include manufacturing and tech. To defend against these threats, organizations should enhance multi-factor authentication, monitor user behavior, and deploy rapid response measures.
Key Insights:
Further Reading: ReliaQuest Blog
Unveiling RECORDSTEALER: A Persistent Infostealer Targeting Sensitive Data Summary: RECORDSTEALER (Raccoon Stealer V2) is a malware targeting sensitive information like passwords, payment data, and cryptocurrency wallets. It infects systems through malvertising and fake downloads, focusing on web browsers for data exfiltration. RECORDSTEALER’s infrastructure has been disrupted, but related malware such as VIDAR and STEALC are still active.
Key Insights:
Further Reading: Google Cloud Blog
Splinter: A New Post-Exploitation Red Team Tool Summary: Splinter, a post-exploitation tool developed in Rust, allows for remote command execution, file uploads, and process injection. It uses encrypted HTTPS for command-and-control (C2) communication, making it harder to detect. Initially built for red team operations, the tool's misuse poses significant risks to compromised systems.
Technical Key Insights:
Further Reading: Unit 42 Article
Supershell Malware Targeting Linux SSH Servers Summary: Supershell, a Go-based backdoor, is being deployed on Linux SSH servers through brute-force attacks. Once installed, it provides attackers with remote access via a reverse shell, enabling them to hijack systems and deploy additional payloads like cryptocurrency miners.
Key Insights:
Further Reading: AhnLab ASEC Report
Cybercriminals Exploit Legitimate Software with CAMO Techniques Summary: ReliaQuest's latest findings reveal the growing use of legitimate IT tools by cybercriminals in "Commercial Applications, Malicious Operations" (CAMO). These tools, such as PDQ Deploy and SoftPerfect, are used for spreading ransomware, exfiltrating data, and evading detection by blending into normal network operations. This trend complicates incident detection and response.
Key Insights:
Further Reading: ReliaQuest Blog
Phishing Attack Uses Two-Step Approach to Evade Detection Summary: A new phishing attack leverages a two-step process, using legitimate platforms like Microsoft Office Forms as an intermediary to evade detection. After clicking the phishing email link, users are directed to a legitimate form before being redirected to a fake login page designed to steal credentials. This sophisticated approach helps attackers bypass security filters by exploiting trusted platforms.
Key Insight: Be cautious of phishing links that utilize legitimate services as intermediaries before redirecting to malicious sites.
Further Reading: KnowBe4 Blog
Surge in Malicious Links Marks 133% Increase in Q1 2024 Summary: Phishing attacks using malicious links surged by 133% in the first quarter of 2024, as attackers shift away from traditional attachments to evade detection. Links allow attackers to obfuscate malicious content and use redirects, CAPTCHA, and legitimate services to conceal their payloads. This growing trend emphasizes the need for organizations to enhance email security and continuously train employees to spot suspicious links.
Further Reading: KnowBe4 Blog
HR-Related Phishing Tactics Grow More Sophisticated Summary: Threat actors are increasingly using HR-related phishing emails, disguised as official company communications, to trick employees into providing credentials. These phishing attacks often use urgent subjects like “Revised Employee Handbook,” leading victims to a fake Microsoft login page. Attackers use the stolen credentials for further exploitation. The campaign evades email security platforms by leveraging legitimate-looking content and psychological manipulation.
Further Reading: Cofense Blog
Inc Ransom Attack: Advanced Extortion Techniques Emerge Summary: The Inc Ransom group uses advanced techniques like data exfiltration without encryption, exploiting firewall vulnerabilities and hiding within legitimate network traffic using tools like Impacket and PowerShell. By deploying Rclone for data transfer, they evade detection while pressuring victims through extortion. The report includes details on a recent attack against a healthcare organization.
Technical Key Insights:
Further Reading: ReliaQuest Blog
RansomHub Reigns, Meow Ransomware Surges in August 2024 Summary: RansomHub leads ransomware threats, targeting Windows, macOS, Linux, and VMware ESXi systems using sophisticated encryption techniques. Meanwhile, Meow ransomware shifts focus from encryption to selling stolen data on leak marketplaces, employing the ChaCha20 encryption algorithm. Both groups aggressively target exposed RDP configurations and vulnerable systems.
Technical Analysis:
Further Reading: Checkpoint Blog
Phishing-as-a-Service Platform Sniper Dz Gains Traction with Unique Tactics Summary: The Sniper Dz Phishing-as-a-Service (PhaaS) platform has facilitated the creation of over 140,000 phishing websites. It offers pre-made phishing templates targeting major brands, leveraging public proxy servers and SaaS platforms to evade detection. Sniper Dz uses unique obfuscation techniques, enabling phishing campaigns to bypass traditional security measures while collecting stolen credentials.
Key Insights:
Further Reading: Unit42 Article
DragonForce Ransomware: Advanced Tactics and Affiliate Program Summary: DragonForce, using both LockBit and ContiV3 forks, targets critical sectors through its RaaS affiliate program. The ransomware employs sophisticated tactics like BYOVD to disable EDR/XDR systems, coupled with SystemBC for persistence and lateral movement. Affiliates can customize attacks using the builder to encrypt files, terminate security processes, and evade detection through advanced anti-analysis features. Mimikatz and Cobalt Strike are used for credential harvesting and system reconnaissance.
Key Technical Insights:
Further Reading: Group-IB Blog
RDP Brute-Force Attacks Summary: Remote Desktop Protocol (RDP) brute-force attacks remain a high-risk method for attackers to gain unauthorized access to networks. Cybercriminals exploit weak/default credentials and exposed RDP ports using automated tools, making it a preferred method for both nation-state and cybercriminal groups. Attackers can use compromised access for data theft, deploying ransomware, or selling credentials on dark web forums.
Technical Highlights:
Defense Recommendations:
For more details, you can visit ReliaQuest's article on RDP Brute-Force Attacks.
New Phishing Tactic Exploits HTTP Headers for Stealthy Redirects Summary: Attackers are using a new technique involving HTTP response headers to automatically redirect users to phishing pages. The tactic leverages compromised websites, making the phishing links appear legitimate. This technique is particularly challenging to detect and has been observed in phishing campaigns targeting various industries.
Key Insights:
For more details, visit KnowBe4.
Cyber Predators Exploit Healthcare Vulnerabilities with Ransomware and Data Theft Summary: Cybercriminals are increasingly targeting healthcare organizations, exploiting weaknesses to steal patient data and extort hospitals via ransomware attacks. These criminals collaborate through darknet marketplaces, offering ransomware-as-a-service, and trading access to compromised healthcare systems. With attacks up 32% globally in 2024, healthcare remains a prime target due to its valuable data and often outdated security infrastructure.
Key Insights:
Read more: Checkpoint Research.
Phishing Campaign Exploits Google Apps Script for Sophisticated Attacks Summary: A new phishing campaign manipulates Google Apps Script macros to target users across multiple languages. The phishing emails falsely claim to provide “account details” and include links to malicious pages mimicking legitimate Google services. Victims are tricked into disclosing sensitive information, leading to data theft and operational disruption.
Key Insights:
For more details, visit Checkpoint Research.
New Windows PowerShell Phishing Campaign Highlights Serious Risks Summary: A recently discovered phishing campaign uses GitHub-themed emails to trick recipients into launching PowerShell commands, enabling the download of password-stealing malware. The attack uses social engineering techniques, disguising itself as a CAPTCHA verification process. By exploiting PowerShell’s automation capabilities, attackers gain unauthorized access to credentials stored on victims' systems.
Key Insights:
For more, visit Krebs on Security.
Phishing Attacks Exploit Content Creation and Collaboration Platforms Summary: A recent phishing campaign abuses popular content creation and collaboration tools to trick users into clicking malicious links. Cybercriminals use legitimate-looking posts and documents with embedded phishing URLs, leading to credential theft through fake login pages. These attacks have been seen in both business and educational environments.
Key Insights:
For more information, visit KnowBe4.
Cyber Threats Looming for the 2024 U.S. Election Summary: As the 2024 U.S. election approaches, cyber threats from nation-state actors, hacktivists, and cybercriminals are expected to rise. These include disinformation campaigns, phishing attacks, and attacks on electoral infrastructure. Businesses should brace for phishing campaigns and SEO poisoning targeting politically charged topics.
Key Insights:
For more details, visit ReliaQuest.
Lanju Fotografie
@lanju_fotografie
I like to call them security assessments. A test you can flunk; an assessment tells you where you’re at.
-Dave Chronister founder of Parameter Security
In today's rapidly evolving cybersecurity landscape, penetration testing (pentesting) is a crucial practice for organizations aiming to protect their systems and data. Pentesting involves simulating cyberattacks to identify vulnerabilities in a company’s infrastructure, allowing businesses to fix potential weaknesses before malicious actors can exploit them. But how do you approach getting a pentest, and what should your organization consider? Here’s a step-by-step guide to help you navigate the process.
Why Should Your Organization Get a Pentest?Pentesting is essential for organizations of all sizes and industries. It provides a proactive approach to cybersecurity by identifying vulnerabilities and offering actionable solutions. Companies should consider scheduling a pentest if they are experiencing any of the following:
In short, a pentest is your best defense against unknown vulnerabilities that could put your business at risk of being compromised.
Common Misconceptions About PentestingMany businesses have misconceptions about pentesting when they first approach the process. Some think it's a one-time event or believe that only large enterprises need it. In reality, pentesting should be a continuous part of an organization’s cybersecurity efforts. Even small businesses and startups can be targets for cyberattacks, making it essential to stay vigilant.
Additionally, pentests do not guarantee total security; instead, they highlight risks and provide insights to improve overall security measures.
Preparing for a PentestBefore reaching out to a pentesting service, companies should take several steps to prepare:
Ensure cooperation: Make sure relevant teams are on board and ready to provide necessary information to the pentesters.
Proper preparation will not only streamline the process but also ensure the pentest delivers valuable results.
What Information Should You Provide to Pentesters?To get the most accurate and comprehensive results, your organization needs to share critical information with the pentesters, including:
How to Choose the Right Pentesting ProviderChoosing a pentesting provider can be daunting, but there are several factors to consider to ensure you're making the right decision:
The Pentesting Process: What to ExpectOnce you’ve chosen a provider and prepared your organization, the pentest begins. Here’s an overview of what you can expect during the process:
Different Types of Pentests: Black-Box, Gray-Box, and White-BoxNot all pentests are the same. Depending on your needs, you might choose between different types:
Each type offers different insights, and choosing the right one depends on your objectives and current security posture.
Understanding Pentesting ReportsA pentesting report is one of the most important deliverables of the process. It typically includes:
Your team should use the report as a roadmap to improve security, focusing first on high-severity issues.
What If No Vulnerabilities Are Found?If a pentest finds no major vulnerabilities, that’s great news! However, it doesn’t mean your company is fully secure forever. Cybersecurity is a continuous process, and as new threats emerge, regular pentests are necessary to stay ahead of potential risks.
Innovative Trends in PentestingAs cybersecurity threats evolve, so does the practice of pentesting. Organizations should stay aware of trends like:
By staying on top of these trends, businesses can ensure their security practices remain effective and up to date.
Conclusion: Why Pentesting is a Must for Every BusinessPentesting provides critical insights into your organization’s security and helps protect against evolving cyber threats. By understanding the process, preparing adequately, and choosing the right provider, businesses can significantly reduce their security risks.
Investing in regular pentests is not just a one-time event; it’s part of a continuous effort to keep your organization secure in a world where cyber threats are always changing.
Image created by ChatGPT.
These are news stories I’ve shared internally at my company. Feel free to take and use as part of your security awareness program.
Russia-linked Operations Target Paris 2024 Olympics In the lead-up to the 2024 Summer Olympics in Paris, Russian-linked actors launched a disinformation campaign to discredit France’s hosting capabilities and spread fear of terrorist attacks. These operations employed tactics like AI-generated videos, fake news reports, and social media hashtags to undermine confidence and create chaos. France's support for Ukraine has made it a target for these hybrid destabilization efforts. Stay vigilant against misinformation and verify sources before sharing content online.
Key Insights:
For more details, visit the DFRLab article.
Ransomware Attacks on Blood Suppliers In a concerning trend, blood suppliers have faced three ransomware attacks in the past three months. The latest victim, OneBlood, experienced a significant disruption, impacting over 350 hospitals and causing a critical shortage of blood supplies. This follows similar attacks on Synnovis and Octapharma, highlighting the growing threat to healthcare infrastructure. The American Hospital Association urges health systems to review their contingency plans to mitigate such risks.
Key Insights:
For more details, visit the Healthcare IT News article.
Surge in Data Breach Victims in 2024 In the first half of 2024, over 1 billion individuals were affected by data breaches, a staggering increase compared to 2023. The majority of breaches targeted financial services, healthcare, and manufacturing sectors. Alarmingly, there is a significant rise in attacks with unspecified vectors, highlighting a need for improved transparency and information sharing to bolster defense strategies. Phishing remains the primary attack method, underscoring the importance of robust security awareness training.
Key Insights:
For more details, visit the KnowBe4 article.
Foreign Influence Actors Adapting to U.S. Presidential Race U.S. intelligence agencies have identified that foreign influence actors are adapting their strategies in response to changes in the 2024 U.S. presidential race. These actors are leveraging social media, misinformation campaigns, and other digital tactics to sway public opinion and disrupt the electoral process. Key sources of influence include Russia, China, and Iran, each employing sophisticated techniques to achieve their objectives.
Key Insights:
For more details, visit the Reuters article.
$40 Million Recovered from International Email Scam Interpol's Global Rapid Intervention of Payments (I-GRIP) mechanism helped recover over $40 million from an international email scam targeting a Singapore-based commodity firm. The scam involved a fraudulent email from a fake supplier requesting payment to a new bank account. Swift action by Singapore and Timor Leste authorities led to the interception of funds and the arrest of seven suspects.
Key Insights:
For more details, visit the Interpol article.
Cyberattack on France's Grand Palais During Olympics France's Grand Palais suffered a ransomware cyberattack during the 2024 Olympic Games. The attack led to operational disruptions, particularly affecting museum bookstores and boutiques. Swift action was taken to prevent the spread of the attack, and temporary autonomous solutions were implemented to keep stores operational. Authorities, including ANSSI and CNIL, were informed, and preliminary investigations found no data exfiltration. This incident highlights the importance of robust cybersecurity measures, especially during major events.
Key Insights:
For more details, visit the Bleeping Computer article.
Rising Costs of Data Breaches in Healthcare A recent report by IBM and the Ponemon Institute revealed that the healthcare industry faces the highest average data breach costs at $10.93 million, significantly above the global average of $4.45 million. These breaches, often involving stolen credentials, can take up to 292 days to resolve. Healthcare organizations are urged to implement AI and automation in cybersecurity to reduce breach lifecycle and costs. Incident response planning and stringent data protection measures are essential to mitigate these risks.
For more details, visit the Security Intelligence article.
Enhanced Protection in Chrome Google has revamped the Chrome downloads experience to boost security and user awareness. The redesigned interface now offers detailed warnings, classifying files as either suspicious or dangerous, using AI-powered assessments. Enhanced Protection mode users benefit from automatic deep scans for suspicious files, providing extra layers of safety against new malware. Additionally, Chrome now tackles encrypted malicious files by prompting users to enter passwords for deep scans, enhancing protection even further. These updates aim to reduce user bypassing of warnings and improve overall safety when downloading files.
For more details, visit the Google Security Blog.
New Phishing Campaign Exploits Google Drawings and WhatsApp Menlo Security has uncovered a sophisticated phishing campaign that abuses Google Drawings and WhatsApp's URL shortener to deceive users. The attack redirects victims from what appears to be legitimate links to malicious sites mimicking trusted brands like Amazon. These tactics make it difficult for users and traditional security tools to detect the threat. Stay cautious of unexpected emails with links or attachments, even if they appear to be from familiar sources.
Key Insights:
For more details, visit the Menlo Security article.
Real Social Engineering Attack on KnowBe4 Employee Foiled KnowBe4 recently thwarted a social engineering attack targeting one of its employees. The attacker, posing as a customer support representative, attempted to gain unauthorized access to internal systems by exploiting trust and urgency. The employee recognized the signs of a phishing attempt and reported the incident immediately. This event underscores the importance of ongoing security awareness training and vigilance against social engineering tactics.
Key Insights:
For more details, visit the KnowBe4 article.
Beware of Misinformation on TikTok: Protect Yourself from Political Lies In today's digital age, social media platforms like TikTok are not just sources of entertainment—they have become powerful tools for spreading information, both true and false. A recent study revealed that a staggering 33% of young Americans have been exposed to political lies on TikTok. This statistic highlights a growing concern: the rapid spread of misinformation, particularly among younger generations.
Why This Matters: Misinformation, especially on social media, can influence opinions, sway elections, and even create social unrest. For cybercriminals, misinformation is a weapon. They can use false information to manipulate public perception, incite division, or even scam users by blending lies with phishing attacks.
How to Protect Yourself:
Conclusion: As we continue to navigate the complex world of social media, staying vigilant against misinformation is crucial. By adopting a skeptical mindset and verifying the content we encounter online, we can protect ourselves and our communities from the harmful effects of political lies and other forms of disinformation.
Exposed Passwords Highlight Risk A recent breach at National Public Data (NPD) underscores the critical need for strong security practices. NPD inadvertently published administrator passwords to their backend database, exposing sensitive information. This incident, coupled with a previous massive data leak, highlights the importance of securing credentials and regularly updating passwords. Users of similar services should take immediate steps to protect their personal information, including freezing their credit files and monitoring their accounts for suspicious activity.
Key Takeaway: Ensure your passwords are strong, unique, and updated regularly to avoid similar risks.
Read more
Unmasking Styx Stealer Checkpoint Research uncovered the Styx Stealer malware, designed to steal browser data, cryptocurrency, and instant messenger sessions. The developer's operational security mistakes, including leaking data during debugging, led to a treasure trove of intelligence. This discovery linked Styx Stealer to the Agent Tesla malware campaign, revealing details about the cybercriminals involved, including their identities and operations.
Key Insights:
For more details, visit the Checkpoint article.
AI Vishing Threats on the Rise Recent research by KnowBe4 has demonstrated that unsuspecting call recipients are highly vulnerable to AI-driven vishing (voice phishing) attacks. These attacks leverage AI to create highly convincing voice manipulations, often impersonating trusted individuals or authority figures. The study highlights the importance of being skeptical of unsolicited calls, even if the caller sounds familiar. Employees should verify the authenticity of any unexpected requests over the phone before taking action.
Key Insights:
For more details, visit the KnowBe4 article.
Employment Scams Targeting Job Seekers KnowBe4 reports a surge in employment scams targeting job seekers. Scammers pose as legitimate employers, often using fake job postings or direct outreach to collect personal information and money from victims. These scams exploit the urgency and desperation of job seekers, making them particularly effective. To protect yourself, always verify job offers through official channels, be cautious of unsolicited communications, and avoid sharing sensitive information without thorough verification.
Key Insights:
For more details, visit the KnowBe4 article.
Protect Yourself from File-Sharing Phishing Attacks Over the past year, file-sharing phishing attacks have surged by 350%, targeting employees through fake notifications from services like Google Drive or Dropbox. These attacks aim to steal sensitive information or infect your device with malware. To protect yourself, always verify the legitimacy of file-sharing requests, avoid clicking on suspicious links, and report any unusual emails to IT immediately. Staying vigilant is key to keeping our organization secure.
For more details, visit the KnowBe4 article.
Beware of Travel-Themed Spam Scams Bitdefender’s AntiSpam Lab warns that half of all travel-themed spam messages circulating worldwide are scams. Attackers are specifically targeting users of popular travel sites like Booking.com and Airbnb. These scams often involve fake booking confirmations and travel deals designed to steal personal information or deliver malware. With the travel season in full swing, it's essential to verify the authenticity of any travel-related emails and avoid clicking on suspicious links.
Key Insights:
For more details, visit the Bitdefender article.
Beware of Phishing Attacks Using URL Shorteners Phishing attacks are increasingly leveraging URL shorteners to obfuscate malicious links, making it harder for users to recognize potential threats. These shortened URLs often appear in emails or text messages, leading victims to fraudulent websites that steal personal information or deploy malware. To protect yourself, always hover over links to reveal their true destination, and avoid clicking on shortened URLs from unknown sources.
For more details, visit the KnowBe4 article.
Surge in Microsoft Brand Impersonation Attacks A recent report shows a 50% increase in phishing attacks impersonating Microsoft in just one quarter. These attacks target users by mimicking Microsoft’s branding to steal credentials or deploy malware. Given Microsoft’s widespread use in organizations, employees should be extra cautious when receiving emails claiming to be from Microsoft, especially those requesting login details or prompting downloads. Always verify the sender's address and report suspicious emails to IT.
For more details, visit the KnowBe4 article.
North Korean IT-Worker Scheme Exposed in Tennessee A Nashville resident, Matthew Isaac Knoot, was arrested for facilitating a scheme that funneled hundreds of thousands of dollars to North Korea’s illicit weapons program. Knoot allegedly helped North Korean IT workers secure remote jobs with U.S. and British companies by using stolen identities. The funds, earned through six-figure salaries, were laundered and funneled back to North Korea. This case underscores the growing threat of North Korean cyber operations targeting remote work environments.
For more details, visit the full article.
Cyber Threats Targeting US Elections 2024 As the US elections approach on November 5, 2024, cybercriminals are intensifying their efforts to exploit the event. From phishing campaigns using candidate names to fake websites and domains designed to mislead voters, these threats are aimed at manipulating voter sentiment and stealing personal information.
Key Insights:
For more information, visit BforeAI.
Beware of QR Code Phishing: Microsoft Sway Abused A new phishing campaign is leveraging QR codes in emails to trick users into visiting malicious websites hosted on Microsoft Sway. This attack is particularly dangerous because it bypasses traditional email security filters and targets users on mobile devices, where security controls are often weaker.
Key Insights:
Stay vigilant and educate your teams about this evolving threat. For more details, visit BleepingComputer.
Malvertising Campaign Impersonates Google Products A recent malvertising campaign has been detected, impersonating various Google products to lure users into tech support scams. These malicious ads, exploiting Google’s Looker Studio, redirect victims to fake Microsoft or Apple warning pages, urging them to call a fraudulent support number. This campaign serves as a reminder to be cautious of online ads, even those that appear to represent trusted brands.
Key Insights:
For more details, visit KnowBe4.
When Get-Out-The-Vote Efforts Resemble Phishing Scams As election season approaches, many citizens receive text messages urging them to get out and vote. While these messages often come from well-intentioned organizations, a recent campaign highlighted by KrebsOnSecurity shows how such efforts can closely resemble phishing scams.
In this case, a fake political consulting firm sent out mass texts linking to websites that requested personal information under the guise of verifying voter registration. The messages were a scam trying to get people to give up sensitive personal information.
Here’s how you can protect yourself:
While voter registration is crucial, ensuring the integrity of the process and protecting personal information is equally important. Stay informed and vigilant to avoid falling victim to phishing scams during election season.
For more details, visit KrebsOnSecurity.
GenAI and the Surge of AI-Driven Fraudulent Websites Cybercriminals are increasingly leveraging large language models (LLMs) to scale the creation of fraudulent websites, including phishing sites and fake online stores. Netcraft reports a significant rise in AI-generated content for scams, with a 3.95x increase in such websites from March to August 2024. These AI tools enhance the credibility of scams by improving text quality, making malicious content more convincing and harder to detect. Organizations must enhance their defenses to mitigate the risks posed by this emerging threat.
Key Insights:
Further Reading: Netcraft Blog
Scammers Exploit Fake Funeral Livestreams for Financial Gain Cybercriminals are using fake funeral livestreams on social media to exploit grieving families. These scams, often promoted through compromised accounts, lead victims to payment pages that charge excessive fees. This trend underscores the need for vigilance online, even during sensitive moments like a loved one's passing. Users should be cautious when encountering unexpected payment requests for livestreams and report suspicious activity.
Further Reading: KnowBe4 Blog
Originally posted on exploresec.com.
Image created with ChatGPT
These are news articles from August 2024. Feel free to take and share with your internal cybersecurity team. A mention of explores.com would be great!
Dismantling Smart App Control Elastic Security Labs recently uncovered multiple vulnerabilities in Windows Smart App Control (SAC) and SmartScreen. These weaknesses allow attackers to bypass security measures using techniques such as signed malware, reputation hijacking, and LNK stomping. These methods enable initial access without triggering security warnings, posing significant risks. Security teams should focus on detecting these evasive tactics and not rely solely on OS-native features.
Key Insights:
For more details, visit the Elastic Security Labs article.
Securing Domain Names from Takeover Recent research highlights vulnerabilities in domain name management that leave over a million domains susceptible to hijacking. This issue arises from weak authentication practices at several web hosting providers and domain registrars. Cybercriminals exploit these weaknesses to take control of domains, using them for phishing, spam, and malware distribution. To mitigate risks, it is crucial to ensure proper DNS configuration and use DNS providers with strong verification processes.
Key Insights:
For more details, visit the Krebs on Security article.
Exploitation of Google Drawings and WhatsApp A newly identified phishing campaign exploits Google Drawings and WhatsApp's URL shortener to create convincing redirects to malicious sites. This method allows attackers to bypass security filters and deceive users into thinking they are visiting legitimate sites like Amazon. These tactics highlight the increasing sophistication of phishing threats, emphasizing the need for heightened vigilance and advanced security measures.
Key Insights:
For more details, visit the Menlo Security article.
Concerns Over Cloudflare’s Anti-Abuse Posture Spamhaus has raised concerns about Cloudflare's anti-abuse policies, highlighting that cybercriminals are exploiting Cloudflare’s services to mask malicious activities. Despite numerous abuse reports, Cloudflare's current approach often shields the true location of harmful content, complicating efforts to combat cybercrime. This situation underscores the need for stronger abuse management practices to prevent cybercriminals from leveraging trusted services to conduct illegal activities.
Key Insights:
For more details, visit the Spamhaus article.
Royal Ransomware Rebrands as BlackSuit The ransomware group formerly known as Royal has rebranded as BlackSuit, increasing their ransom demands to over $500 million. This shift indicates a more aggressive approach, with the group targeting larger organizations across various sectors. BlackSuit continues to use sophisticated tactics, including double extortion, where they threaten to release stolen data if their demands are not met. Organizations should strengthen their defenses and ensure incident response plans are up-to-date.
Key Insights:
For more details, visit the KnowBe4 article.
New Phishing Scam Using Cross-Site Scripting A recent phishing scam uncovered by KnowBe4 employs cross-site scripting (XSS) attacks to harvest personal details from unsuspecting victims. Attackers use this method to inject malicious scripts into legitimate websites, tricking users into entering sensitive information like login credentials. This technique bypasses traditional security measures, making it a particularly dangerous threat. Users should be cautious when clicking on links in emails and ensure that websites they interact with are secure.
Key Insights:
For more details, visit the KnowBe4 article.
Surge in File-Sharing Phishing Attacks KnowBe4 reports a staggering 350% increase in file-sharing phishing attacks over the past year. These attacks often disguise themselves as notifications from popular file-sharing services, tricking users into revealing sensitive information or downloading malware. The rapid rise in these attacks highlights the need for enhanced email security and ongoing employee training.
Key Insights:
For more details, visit the KnowBe4 article.
Rising Use of URL Shorteners in Phishing Attacks Recent intelligence highlights a growing trend where cybercriminals use URL shorteners to obscure malicious links in phishing campaigns. This tactic effectively conceals the true destination of links, making it difficult for users and traditional security tools to detect threats. These shortened URLs often appear in seemingly legitimate emails or text messages, leading to fraudulent websites designed to steal credentials or deploy malware.
For more details, visit the KnowBe4 article.
Surge in Microsoft Brand Impersonation Attacks A recent report shows a 50% increase in phishing attacks impersonating Microsoft in just one quarter. These attacks target users by mimicking Microsoft’s branding to steal credentials or deploy malware. Given Microsoft’s widespread use in organizations, employees should be extra cautious when receiving emails claiming to be from Microsoft, especially those requesting login details or prompting downloads. Always verify the sender's address and report suspicious emails to IT.
For more details, visit the KnowBe4 article.
Dark Angels Ransomware Group Rakes in Record Ransoms The Dark Angels ransomware group has secured a record $75 million ransom payment from a fortune 50 company recently. Unlike other groups, Dark Angels avoid public leaks and minimize operational disruptions for their victims, making it easier to coerce payments quietly.
For more details, visit the Krebs on Security article.
Inc Ransom Attack Analysis Overview: In April 2024, the "Inc Ransom" group targeted a ReliaQuest customer, employing a double-extortion strategy without encrypting files. They exploited an unpatched Fortinet vulnerability to gain access, installed remote management tools like AnyDesk, and used techniques like pass-the-hash for lateral movement. Data was exfiltrated using unconventional tools such as Restic.
Key Insights:
Actionable Steps: Strengthen defenses by regularly updating and auditing systems, ensuring proper segmentation, and limiting privileges to essential accounts.
For a detailed analysis, visit the full report here.
URL Rewriting Exploited by Threat Actors Overview: Threat actors are increasingly abusing URL rewriting, a security feature intended to protect against phishing, to mask malicious links. By compromising legitimate email accounts and using URL rewriting, attackers can disguise phishing URLs as safe, often leveraging the security vendor's domain to gain trust.
Key Insights:
For a detailed analysis, visit the full report here.
Exfiltration Tools on the Rise A recent analysis by ReliaQuest highlights the growing use of advanced exfiltration tools by cybercriminals to steal sensitive data. Tools like Rclone, WinSCP, and FileZilla are increasingly being leveraged to exfiltrate data from compromised networks. These tools are difficult to detect as they mimic legitimate traffic, making traditional defenses less effective.
For more details, visit the ReliaQuest article.
North Korean IT-Worker Scheme Exposed in Tennessee A Nashville resident, Matthew Isaac Knoot, was arrested for facilitating a scheme that funneled hundreds of thousands of dollars to North Korea’s illicit weapons program. Knoot allegedly helped North Korean IT workers secure remote jobs with U.S. and British companies by using stolen identities. The funds, earned through six-figure salaries, were laundered and funneled back to North Korea. This case underscores the growing threat of North Korean cyber operations targeting remote work environments.
For more details, visit the full article.
Top Malware in July 2024: Remcos and RansomHub The July 2024 Threat Index highlights a surge in activity by the RansomHub ransomware group and a new Remcos malware campaign. RansomHub continues to dominate as the most prevalent ransomware, accounting for 11% of attacks, while LockBit3 and Akira follow closely behind. A critical security lapse led to the distribution of Remcos via a malicious ZIP file disguised as a CrowdStrike update. Additionally, FakeUpdates remains a persistent threat, utilizing fake browser updates to deploy RATs like AsyncRAT.
Key Insights:
For a deeper dive, visit Checkpoint’s Threat Index.
Focus on Malware Loaders: Evolving Threats in 2024 In 2024, nearly 40% of malware incidents involved advanced loaders like SocGholish, GootLoader, and Raspberry Robin. These loaders are pivotal in deploying ransomware and Remote Access Trojans (RATs). SocGholish has notably enhanced its tactics with Python scripts, making it harder to detect, while GootLoader and Raspberry Robin use sophisticated evasion techniques, posing significant threats to critical sectors.
Key Insights:
For more detailed insights, visit the full article here.
Emerging Malware Variants to Watch in 2024 In recent months, several malware variants have gained prominence in the cyber threat landscape. Notable among them are LummaC2, Rust-based stealers, SocGholish, AsyncRAT, and Oyster, each posing significant risks to organizations across all sectors.
Key Insights:
For more details, visit ReliaQuest.
Exploring the Abuse of Impacket: A Growing Threat Impacket, a versatile Python-based toolkit, has become a favored tool among threat actors for lateral movement, privilege escalation, and remote code execution in Windows environments. Threat actors commonly exploit Impacket scripts like psexec.py, smbexec.py, and wmiexec.py to perform these actions stealthily. The toolkit’s ability to mimic legitimate network activity complicates detection, making it a significant challenge for organizations to defend against.
Key Insights:
For more information, visit ReliaQuest.
Copybara Android Malware: A Rising Threat The latest variant of Copybara, an Android malware family, has evolved to use the MQTT protocol for command-and-control (C2) communication, enhancing its stealth. This malware exploits Android’s Accessibility Service for keylogging, screen capturing, and phishing attacks, particularly targeting cryptocurrency exchanges and financial institutions. Copybara’s ability to impersonate legitimate apps makes it especially dangerous.
Key Insights:
For more details, visit Zscaler.
Massive QR Code Phishing Campaign Abuses Microsoft Sway A significant phishing campaign has been detected, exploiting Microsoft Sway to host malicious landing pages targeting Microsoft 365 users. The campaign, identified by Netskope Threat Labs, saw a 2,000-fold increase in activity, primarily targeting sectors in Asia and North America. Attackers use QR codes embedded in phishing emails, redirecting victims to malicious sites. This method exploits the weaker security controls of mobile devices and evades email scanners, making it particularly effective and dangerous.
Key Insights:
For more details, visit BleepingComputer.
Malvertising Campaign Impersonates Google Products A recent malvertising campaign has been detected, impersonating various Google products to lure users into tech support scams. These malicious ads, exploiting Google’s Looker Studio, redirect victims to fake Microsoft or Apple warning pages, urging them to call a fraudulent support number. This campaign serves as a reminder to be cautious of online ads, even those that appear to represent trusted brands.
Key Insights:
For more details, visit KnowBe4.
Deceptive AI: A New Wave of Cyber Threats As AI technology advances, cybercriminals are increasingly using AI-generated content (AIGC) to deceive users on social media. This includes creating fake profiles, deepfake videos, and AI-crafted messages that are nearly indistinguishable from real content. A recent survey revealed that a significant portion of users struggle to identify these threats, which can lead to fraud, identity theft, and misinformation. It's crucial to be aware of these risks and stay vigilant online.
For more details, visit KnowBe4.
North Korean IT Workers Target U.S. Tech Companies North Korean IT workers are increasingly applying for remote jobs at U.S. tech firms using false identities. They employ AI-generated profile images and fake job histories, aiming to funnel earnings back to the North Korean regime, posing security risks and potential sanctions violations. Key insights include the importance of rigorous background checks and enhanced candidate verification processes to counter this threat. Collaboration with security experts and intelligence sharing is critical.
For more insights, visit Cinder.
Risks in Publicly Exposed GenAI Development Services A recent analysis highlights significant security risks in publicly exposed GenAI development services, particularly vector databases and low-code LLM tools. These platforms often handle sensitive data but can be misconfigured, leading to potential data leakage, data poisoning, and exploitation of vulnerabilities. To mitigate these risks, organizations should enforce strict access controls, monitor activity, and ensure all software is updated.
For a deeper dive, visit Legit Security.
How Attackers Exploit Digital Analytics Tools Cybercriminals are increasingly weaponizing digital analytics tools like link shorteners, IP geolocation services, and CAPTCHA challenges. These tools, often used for legitimate purposes, are repurposed to obscure malicious activity, evade detection, and tailor attacks to specific targets. Organizations should implement automated analysis and monitor suspicious patterns in these tools to mitigate risks.
Key Insights:
Further Reading: Google Cloud Blog
GenAI and the Surge of AI-Driven Fraudulent Websites Cybercriminals are increasingly leveraging large language models (LLMs) to scale the creation of fraudulent websites, including phishing sites and fake online stores. Netcraft reports a significant rise in AI-generated content for scams, with a 3.95x increase in such websites from March to August 2024. These AI tools enhance the credibility of scams by improving text quality, making malicious content more convincing and harder to detect. Organizations must enhance their defenses to mitigate the risks posed by this emerging threat.
Key Insights:
Further Reading: Netcraft Blog
So-Phish-ticated Attacks: A New Wave of Social Engineering A sophisticated threat actor is conducting targeted social engineering attacks against over 130 U.S. organizations. These attacks, which include phishing via SMS and direct phone calls, are designed to harvest credentials and one-time passcodes. The use of native English speakers and tactics that bypass traditional security tools makes these attacks particularly challenging to detect.
Key Insights:
Further Reading: GuidePoint Security Blog
Originally posted on exploresec.com
I created this blog post for distribution internally as part of our Security Awareness program. Feel free to grab and share internally at your own company.
As the November 5, 2024, US elections approach, cybercriminals are exploiting the event to carry out sophisticated phishing campaigns, financial fraud, and misinformation according to a report from BforeAI. These malicious actors often use the names of prominent candidates, like "Harris," "Trump," and "Biden," in fake domains to mislead the public. Websites mimicking legitimate voting resources aim to steal personal and financial information. Additionally, fraudulent ecommerce stores and cryptocurrency themed around the elections pose significant financial risks to unsuspecting voters.
The Threat LandscapePhishing and Fake Domains: Cybercriminals are creating fake domains and websites using candidate names and election-related terms like “vote” and “election” to increase their credibility. These sites are used to deceive voters into providing sensitive information, making donations to fraudulent campaigns, or spreading misinformation about voting dates and locations. For example, domains like "vote-no-sunnybailey[.]com" are designed to manipulate public opinion and suppress voter turnout through the dissemination of fake news and propaganda.
Financial Fraud: Many malicious websites are set up to collect personal and financial information from voters. Fraudulent donation sites mimic legitimate campaign fundraising efforts but are designed to steal credit card details and personally identifiable information (PII). This data is then sold on and used for future fraud and social engineering attacks. Furthermore, the emergence of meme coins themed around the elections is another avenue for financial exploitation, with these digital currencies often promoted on social media as quick investment opportunities, only to disappear after collecting funds from unsuspecting victims.
Misinformation Campaigns: Cybercriminals are also leveraging free web hosting platforms to quickly create and abandon malicious websites. These sites often contain misinformation about voting procedures, dates, and locations, aimed at confusing voters and reducing turnout. Additionally, unauthorized live streaming websites and other online platforms are being used to spread propaganda and manipulate voter behavior, further complicating the election process.
How to Protect Your VoteTo safeguard your vote and personal information during this election season, it’s essential to stay informed:
ConclusionThe 2024 US elections are a prime target for cybercriminals seeking to exploit voter emotions and manipulate election outcomes. By understanding the tactics used in these malicious campaigns, voters can better protect their identities and their votes. Staying informed and cautious is the best defense against these evolving threats.
Created with help from ChatGPT
This is a blog post I put together for distribution internally. Feel free to take and use as part of your own security awareness program. Created with help from ChatGPT
In the ever-evolving landscape of social media, TikTok has emerged as a dominant force, especially among younger generations. While the platform offers endless streams of creative content, it also harbors a growing concern: the spread of misinformation. Recent research has revealed that 33% of young Americans have encountered political lies on TikTok, highlighting the platform's significant role in shaping political perceptions.
As misinformation continues to proliferate across social media, it’s crucial to understand how it spreads, its potential impact, and the steps we can take to protect ourselves.
The Power of TikTok and the Rise of Misinformation TikTok’s algorithm is designed to keep users engaged by serving up content tailored to their interests. However, this algorithmic precision also makes it easier for misinformation to find its way into users’ feeds. Content that sparks strong emotional reactions—whether outrage, fear, or excitement—tends to spread rapidly, often without scrutiny.
Political misinformation can have far-reaching consequences. False narratives can skew public perception, influence voting behavior, and deepen societal divides. For young Americans, many of whom turn to social media as their primary news source, the risks are especially pronounced.
The Cybersecurity Implications of Misinformation While misinformation may seem like a mere nuisance, it poses serious cybersecurity risks. Cybercriminals can exploit false information to launch sophisticated social engineering attacks. For example, a fake news story might be used as bait in a phishing campaign, luring users to click on malicious links or download harmful software. Once trust is established through seemingly legitimate content, attackers can easily manipulate their targets.
Moreover, misinformation can be used to incite panic or distrust, leading to actions that compromise security. For instance, during elections, misinformation about voting procedures can confuse voters, leading to disenfranchisement or chaos at polling stations. In such scenarios, the lines between misinformation and cyber threats blur, creating a fertile ground for malicious activities.
Recognizing and Combating Misinformation Understanding how to identify and counter misinformation is crucial in today’s digital age. Here are some strategies to help you stay informed and secure:
The Broader Impact of Misinformation The dangers of misinformation extend beyond individual harm. On a larger scale, widespread misinformation can erode trust in institutions, polarize societies, and even threaten democratic processes. In an environment where misinformation thrives, it becomes increasingly difficult to have informed, rational discussions on critical issues.
Moreover, the spread of misinformation can contribute to the normalization of falsehoods. As false narratives become more prevalent, they can start to shape reality, influencing public opinion and policy in ways that are harmful or unjust.
Conclusion: Staying Vigilant in a Digital World In an age where information is at our fingertips, the responsibility to discern truth from falsehood rests on each of us. TikTok and other social media platforms offer immense value, but they also present risks that must be navigated carefully. By adopting a skeptical mindset, verifying the content we encounter, and educating ourselves and others, we can protect ourselves from the dangers of misinformation.
As we continue to interact with digital content, let’s commit to being informed and responsible consumers of information. In doing so, we not only safeguard our own security but also contribute to a more truthful and resilient digital community.
Created by ChatGPT
This is Security Awareness focused newsletter I put together for distribution internally at my company. Feel free to take and use for your own program.
Medusa Ransomware Analysis
In June 2024, ReliaQuest detected the Medusa ransomware, which encrypted multiple hosts in a customer environment. Medusa, active since 2022, exploits unpatched vulnerabilities and hijacks legitimate accounts. The attack lifecycle includes initial access via a compromised VPN account, credential access through NTDS dumps, and lateral movement using RDP. Medusa employs living-off-the-land techniques, PowerShell for credential dumping, and service installations for persistence. Enhanced VPN configurations, endpoint visibility, and automated responses are critical to mitigating such ransomware threats.
Key Takeaways:
For detailed insights, read the full report here.
Teen Sextortion on the Rise
Overview: Sextortion targeting teenagers is on the rise, exploiting their trust and vulnerabilities on social media. Criminals pose as peers or love interests to coerce explicit images, which they then use for blackmail.
Key Points:
Action Steps:
For more details, visit KnowBe4 Blog.
North Korean Fake IT Worker Infiltration Attempt
In a recent incident, KnowBe4's SOC detected suspicious activities from a newly hired software engineer, later revealed to be a North Korean fake IT worker using AI to generate a fake identity. Despite rigorous hiring processes, including background checks and multiple video interviews, the individual bypassed security measures and attempted to load malware upon receiving their workstation.
Key Takeaways:
This case underscores the importance of robust hiring and security processes to prevent similar infiltration attempts.
For a detailed account, visit the full article on KnowBe4's blog.
Phish-Friendly Domain Registry ".top" Put on Notice
The ".top" domain registry, managed by Jiangsu Bangning Science & Technology Co. Ltd., has been warned by ICANN for its failure to address phishing abuse. Findings revealed that over 4% of new ".top" domains from May 2023 to April 2024 were used for phishing. ICANN's notice demands immediate improvements, or the registry risks losing its license. This highlights the critical need for vigilant monitoring and prompt action against domain abuse to protect users from phishing threats.
For more information, read the full article on Krebs on Security.
CrowdStrike Phishing Attacks Appear in Record Time
Recent IT outages have led to a surge in phishing sites exploiting the chaos. Within hours, domains like crowdstriketoken[.]com and crowdstrikefix[.]com emerged, targeting those affected by the outages. Cybercriminals quickly capitalized on the situation, registering 28 domains by early morning. The US Cybersecurity and Infrastructure Security Agency (CISA) urges caution, advising users to avoid suspicious links and verify communications through official channels. Stay vigilant and only rely on trusted sources for updates.
Key Takeaways:
For more details, visit KnowBe4's blog.
Is Your Bank Really Calling? Protect Yourself from Financial Impersonation Fraud
Summary: With the rise of sophisticated scams, distinguishing between legitimate bank communications and fraudulent attempts is increasingly challenging. Cybercriminals use stolen personal details to make their scams appear genuine, often creating a sense of urgency to exploit victims.
Key Takeaways:
Recommendations: Stay vigilant and regularly update your security awareness to safeguard against financial fraud.
For more information, read the full article on KnowBe4 Blog.
Building Security into the Redesigned Chrome Downloads Experience
Google has revamped Chrome’s download interface, adding detailed warnings to protect users from malicious files. The new UI uses AI-powered verdicts from Google Safe Browsing to categorize files as "suspicious" or "dangerous," helping users make informed decisions.
Key Takeaways:
For more details, visit Google's Security Blog.
Olympics-Themed Scams: Stay Vigilant!
With the Paris 2024 Olympics approaching, cybercriminals are ramping up their efforts to exploit the excitement. Recent reports show an 80-90% increase in cybercrime targeting French organizations, with scam tactics including typosquatting domains (e.g., oympics[.]com) and Olympic-themed lottery scams impersonating brands like Coca-Cola and Microsoft. These scams target users worldwide, emphasizing the need for heightened vigilance. Always scrutinize unexpected emails and offers, especially those that seem too good to be true.
Key Takeaways:
Stay safe and informed to protect yourself and your organization from these threats.
For more details, visit KnowBe4's Blog.
Beware of Generative AI Tool Scams
Scammers are exploiting the growing interest in generative AI tools like ChatGPT. Researchers have observed a surge in suspicious domain registrations, especially around significant AI-related announcements. These domains often include keywords like "gpt" and "prompt engineering," and many are used for phishing and other malicious activities.
Key Takeaways:
Stay alert and informed to protect yourself from these evolving threats.
For more details, visit KnowBe4's Blog.
QR Code Phishing: An Ongoing Threat
QR code phishing, or "quishing," continues to rise as a significant cyber threat. Cybercriminals exploit QR codes to bypass email security filters and target users directly, often embedding malicious codes in PDFs or images. This method can deceive even vigilant users, leading to compromised personal and financial information.
Key Takeaways:
Stay informed and cautious to protect against these sophisticated phishing attacks.
For more details, visit KnowBe4's Blog.
New Phishing Tactic: Chat Support Scams
Cybercriminals are now using fake chat support to add credibility to phishing scams. By mimicking legitimate support chats on spoofed payment pages for platforms like Etsy and Upwork, scammers deceive users into providing sensitive information. These chat features, staffed by scammers posing as support agents, guide victims through the phishing process, making the scams more convincing and harder to detect.
Key Takeaways:
Stay informed and vigilant to protect against these sophisticated attacks.
For more details, visit KnowBe4's Blog.
OneDrive Pastejacking: A New Threat to Watch
A recent discovery highlights a new threat called "pastejacking" targeting OneDrive users. This technique exploits the copy-paste functionality to inject malicious commands into users' clipboards, potentially leading to unauthorized data access or malware installation. Attackers embed harmful code into seemingly innocuous text or files, posing a significant risk to personal and organizational security.
Key Takeaways:
Stay informed and cautious to protect against these evolving threats.
For more details, visit Trellix's Blog.
Fake Leaks of Crypto Wallet Seed Phrases: A Growing Threat
Scammers are leveraging fake leaks of passwords and seed phrases to target cryptocurrency users. These sophisticated scams involve presenting victims with seemingly real data leaks, enticing them to use malicious crypto management apps. Once installed, these apps steal sensitive information, leading to significant financial losses.
Key Insights:
For more details, visit Kaspersky's Blog.
Aveanna Healthcare Data Breach: Email Accounts Compromised
Aveanna Healthcare has experienced a data breach affecting 11 email accounts. The breach, discovered on May 9, 2023, potentially exposed the personal and protected health information (PHI) of patients, including names, Social Security numbers, and medical details. Aveanna has since secured the compromised accounts and is offering affected individuals complimentary credit monitoring and identity protection services.
Key Takeaways:
For more details, visit HIPAA Journal.
This is a monthly threat intelligence newsletter with a lean towards phishing and healthcare I put together for the team at my company. Feel free to grab and share with your own internal team.
Threat Intelligence Newsletter: Resurgence of Russia's Fin7
Overview: The notorious cybercrime group Fin7, previously thought to be dismantled, has re-emerged with increased activity. This resurgence is primarily facilitated by Stark Industries Solutions, a hosting provider linked to Russian cyberattacks.
Key Developments:
Implications: Organizations must heighten vigilance against phishing, regularly update security protocols, and monitor for suspicious domain activities.
For more details, visit Krebs on Security.
New Internet Explorer Zero-Day Spoofing Attack (CVE-2024-38112)
Overview: Check Point Research (CPR) has identified a new zero-day spoofing vulnerability in Internet Explorer, designated CVE-2024-38112. This vulnerability allows attackers to deceive users by displaying a fake website address in the browser's address bar, facilitating phishing and other malicious activities.
Key Details:
Recommendations:
For further information, visit the Check Point Blog.
Ransomware Attack Disrupts U.K. Health Service Laboratory
Overview: A ransomware attack on Synnovis, a laboratory partner for several major London hospitals, has significantly disrupted health services. The Qilin ransomware group, utilizing a Ransomware-as-a-Service model, is behind the attack and also targets U.S. based organizations. After failing to receive a ransom payment, Qilin released over 400GB of private healthcare data online.
Key Points:
Recommendations:
For more information, visit the KnowBe4 Blog.
Microsoft Links Scattered Spider Hackers to Qilin Ransomware Attacks
Microsoft has identified the Scattered Spider cybercrime group, also known as Octo Tempest, as responsible for recent Qilin ransomware attacks. This financially motivated group has been active since 2022, targeting over 130 high-profile organizations using tactics such as phishing, MFA bombing, and SIM swapping. The Qilin ransomware group, known for targeting VMware ESXi virtual machines, employs double-extortion attacks by threatening to release stolen data.
Key Takeaways:
For more details, read the full article from Bleeping Computer.
Social Media Job Scams: Don't Be the Target!
Hunting for your dream job online? Unfortunately, social media can be a breeding ground for scammers who target unsuspecting job seekers. But fear not! Here are some key takeaways to help you avoid falling victim to their schemes:
By following these tips, you can protect yourself from social media job scams and increase your chances of finding a legitimate and rewarding job opportunity. Remember, if it seems too good to be true, it probably is. So, be cautious, be smart, and happy hunting! For more details check out the KnowBe4 blog.
Phishing Alert: Microsoft Top Target, Social Media on the Rise
According to a recent Check Point Research report, Microsoft was the most imitated brand for phishing attacks in Q2 2024, accounting for over half of all attempts. This highlights the ongoing threat of brand phishing, where cybercriminals impersonate well-known companies to trick users into revealing personal information or clicking on malicious links.
The report also reveals new entries to the top 10 most impersonated brands, including Adidas, WhatsApp, and Instagram. This trend indicates a shift in cybercriminals' tactics, as they target social media and technology companies that hold valuable user data.
Top 10 Most Impersonated Brands in Q2 2024
Check out Check Point’s blog for more details.
New Backdoor Used by APT41: MoonWalk
A recent blog post by Zscaler details a new backdoor tool called MoonWalk المستخدمة من قبل مجموعة APT41 (used by the APT41 group). MoonWalk is a tool used by the APT41 threat group for espionage. The article discusses MoonWalk’s technical aspects, including its use of Google Drive for communication and Windows Fibers for evasion. MoonWalk also uses a modular design, allowing attackers to customize it for different situations.
Here are some key takeaways from a threat intelligence perspective:
Organizations should be aware of the MoonWalk backdoor and take steps to protect themselves, such as:
By following these steps, organizations can help to mitigate the risk of being targeted by APT41 and other threat groups.
You can read more about MoonWalk here.
Phish-Friendly Domain Registry ".top" Put on Notice
The ".top" domain registry, managed by Jiangsu Bangning Science & Technology Co. Ltd., has been warned by ICANN for its failure to address phishing abuse. Findings revealed that over 4% of new ".top" domains from May 2023 to April 2024 were used for phishing. ICANN's notice demands immediate improvements, or the registry risks losing its license. This highlights the critical need for vigilant monitoring and prompt action against domain abuse to protect users from phishing threats.
For more information, read the full article on Krebs on Security.
Over 3,000 GitHub Accounts Exploited in Malware Distribution Scheme
Summary: A new threat, dubbed 'Stargazers Ghost Network,' involves over 3,000 GitHub accounts used to distribute information-stealing malware via fake repositories. Discovered by Check Point Research, this Distribution-as-a-Service (DaaS) leverages GitHub’s reputation to spread infostealers like RedLine and Lumma Stealer. Despite GitHub's efforts, over 200 malicious repositories remain active.
Key Takeaway:
For more information, read the full article on BleepingComputer.
North Korean Operative Infiltrates KnowBe4 Using Stolen Identity
Summary: KnowBe4 recently revealed that a North Korean hacker, posing as a U.S. citizen, successfully got hired as an IT worker. Despite multiple rounds of interviews and background checks, the individual was detected attempting to install malware on their new workstation. No sensitive data was accessed due to robust security measures.
Key Takeaways:
Recommendations: Regularly review and update hiring and onboarding procedures to mitigate risks from sophisticated threat actors.
For more information, read the full article onKnowBe4 Blog.
Exploiting CrowdStrike Outage: Phishing, Fake Scripts, and Social Engineering
Summary: Following a recent CrowdStrike update that caused widespread blue screen of death (BSOD) errors, cybercriminals are capitalizing on the confusion. Fake PowerShell scripts, phishing domains, and social engineering attacks are proliferating, posing significant risks.
Key Takeaways:
Recommendations: Verify the authenticity of scripts and domains, and educate users on phishing and social engineering tactics.
For more information, read the full article on ReliaQuest Blog.
Huntress Foils a Medical Software Update Hack
Huntress recently uncovered a sophisticated phishing campaign targeting medical software updates. Cybercriminals created a fake version of a legitimate medical image viewer, embedding malicious code that established a secret connection back to the attackers. This attack highlights the critical need for vigilance even when dealing with trusted sources. Huntress's Security Operations Center (SOC) detected the anomaly and quickly isolated the threat, preventing potential data breaches.
Key Takeaways:
For more details, visit Huntress's blog.
TuDoor: Exploiting DNS Logic Vulnerabilities
A new DNS attack method, named TuDoor, has been identified, highlighting critical vulnerabilities in DNS response pre-processing. Attackers can use malformed DNS response packets to execute cache poisoning, denial-of-service, and resource exhaustion attacks. TuDoor impacts 24 mainstream DNS software and many public DNS services, potentially affecting millions of users.
Key Takeaways:
For more details, visit TuDoor's website.
Generative AI Tools: New Target for Scammers
Recent intelligence highlights a surge in cyber threats exploiting interest in generative AI tools, particularly ChatGPT. Scammers are registering suspicious domains containing keywords like "gpt" and "prompt engineering," aiming to deceive users with phishing schemes and malware distribution. This trend coincides with major AI-related announcements, increasing the risk to individuals and organizations exploring these technologies.
Key Insights:
For more details, visit KnowBe4's Blog.
OneDrive Pastejacking: A New Phishing Tactic
A new phishing threat, "pastejacking," targets OneDrive users by exploiting the copy-paste functionality. Attackers inject malicious commands into users' clipboards through seemingly benign text or files. This method can lead to unauthorized data access or malware installation when unsuspecting users paste the copied content.
Key Insights:
For more details, visit Trellix's Blog.
Created by ChatGPT
Getting this out a little late. This is a newsletter that I put together for our internal security awareness program. Feel free to grab and use within your own security awareness program. Created with help from ChatGPT.
Rising Threat of Business Email Compromise (BEC) Scams
The FBI’s Internet Crime Complaint Center (IC3) has warned about the growing threat of Business Email Compromise (BEC) scams targeting businesses and individuals to steal money through fraudulent emails.
Key Points:
Stay vigilant and protect your organization from BEC scams. For more details, visit the full PSA on the IC3 website: FBI IC3 PSA.
Arrests Made in Smishing Text Scam
The City of London Police has announced the arrest of two individuals connected to a sophisticated smishing campaign using a homemade mobile antenna. This operation involved sending thousands of fraudulent text messages to the public, aiming to steal personal and financial information.
Key Details:
Protect Yourself:
Stay Informed and Safe: For more details on this case and tips to protect yourself from smishing attacks, visit the City of London Police website: City of London Police Smishing Arrests.
Stay vigilant and keep your personal information secure!
Phishing Tactics Targeting Two-Factor Authentication (2FA)
Recent reports from Kaspersky highlight an emerging phishing technique targeting Two-Factor Authentication (2FA) mechanisms, increasing the risk of account compromise even for those using this added layer of security.
Key Findings:
How It Works:
Prevention Tips:
Stay Vigilant: Phishing attacks continue to grow in sophistication, posing significant risks even to those who use advanced security measures like 2FA. By staying informed and implementing robust security practices, you can protect yourself and your organization from these evolving threats.
For more detailed information, visit the full article on Kaspersky's blog: Phishing with Cloudflare Workers: Transparent Phishing and HTML Smuggling.
FTC’s Spring Scam Roundup
The FTC’s latest report highlights prevalent scams and their impact on consumers this spring.
Key Findings:
Most Impersonated Companies:
Common Contact Methods:
Payment Methods:
Protection Tips:
Stay Vigilant: Scams continue to evolve, posing significant risks. By staying informed and following these security tips, you can better protect yourself and your organization.
For more details, visit the FTC’s Spring Scam Roundup.
Stay safe and secure!
Beware of New Phishing Campaign Targeting Job Seekers
A recent phishing campaign has been discovered deploying the WARMCOOKIE backdoor, specifically targeting job seekers. Cybercriminals are using fake job offers to lure victims into opening malicious attachments or clicking on harmful links. Once activated, the WARMCOOKIE backdoor allows attackers to gain unauthorized access to the victim's system, compromising sensitive information.
Key Points:
Stay vigilant and protect your personal information!
For more details, visit the Hacker News article.
CISA Warns of Criminals Impersonating Its Employees
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about criminals impersonating its employees in phone calls. These scammers attempt to deceive victims into transferring money by posing as CISA representatives.
Key Points:
Impersonation Scams on the Rise: Last year, impersonation scams resulted in losses of $1.1 billion, highlighting the growing threat and the need for increased vigilance. Scammers posed as FTC staff as part of the scams.
“The FBI's 2023 Internet Crime Report revealed a 22% increase in reported losses to online crime compared to 2022, totaling a record $12.5 billion.”
Tips to Protect Yourself:
For more details, visit the Bleeping Computer article.
Beware of Fraudulent Olympics Ticketing Websites
Recently, Proofpoint uncovered fraudulent websites claiming to sell tickets for the Paris 2024 Summer Olympics. Notably, “paris24tickets[.]com” appeared as a top search result on Google. This site, designed to mimic legitimate ticketing platforms, aimed to steal money and personal information.
Key Findings
Stay Safe
Stay vigilant and share this information to help others avoid scams. For more details, visit the full article.
Social Engineering Scams via Mail
Social engineering scams aren't limited to digital channels; they can come through the mail too. KnowBe4 highlights a recent case where scammers sent fake refund checks via mail, tricking recipients into depositing them and sending a portion of the funds back. These checks appear realistic, but banks eventually discover they're fake, leaving the victim responsible for the amount.
Protection Tips:
For more details, visit KnowBe4's blog.
Beware of More_eggs Malware Targeting Hiring Managers
Attention Hiring Managers:
A new phishing campaign is using fake resume submissions to distribute the More_eggs malware. Cybercriminals target job listings on platforms like LinkedIn, directing recruiters to malicious websites that trigger a malware infection upon downloading a resume. This backdoor malware can steal sensitive data, deliver additional malicious payloads, and grant remote access to attackers.
Key Recommendations:
Stay vigilant and protect your organization from these sophisticated attacks.
For more details, visit the KnowBe4 blog.
Beware of Fraudulent Olympics Ticketing Websites
As the excitement for the Paris 2024 Summer Olympics builds, so do the efforts of scammers looking to exploit unsuspecting fans. Proofpoint recently discovered multiple fraudulent websites claiming to sell Olympics tickets, with one notably appearing as a top search result on Google. These sites mimic legitimate ticketing platforms, luring users into providing personal and payment information.
Key Points:
Stay Safe:
For more detailed information, read the full article on Proofpoint's blog here.
New Threat: "Paste and Run" Phishing
Overview A new phishing campaign exploits a unique user interaction by tricking users into pasting and executing malicious commands from their clipboard. This technique can install malware such as DarkGate on the victim’s system, bypassing conventional security measures.
Key Takeaways:
Stay vigilant and regularly update your security protocols. For more details, visit the KnowBe4 Blog.
AI-Driven Travel Scams on the Rise
Overview Booking.com warns that the rise of artificial intelligence (AI) is driving a significant increase in travel scams. According to Marnie Wilking, the firm's internet safety boss, there has been a 500 to 900% surge in scams over the past 18 months, particularly phishing attacks.
Key Takeaways:
For further details, refer to the BBC News Article.
Protect Yourself from Summer Vacation Scams
Overview As summer approaches, the excitement of planning vacations is in full swing. However, cybercriminals are also gearing up, exploiting this time to launch scams targeting travelers. Check Point Research (CPR) has observed a significant rise in phishing scams and malicious websites related to summer vacations.
Key Takeaways:
Stay informed and vigilant to protect yourself from these evolving cyber threats. For more detailed information, visit Check Point’s blog on staying safe during summer vacations.
Created using ChatGPT
Little behind getting this out but still wanted to get it out. This is a newsletter of articles I thought might be valuable for our security team and helped me plan this months simulated phish. Created with help from ChatGPT
New Execution Technique in ClearFake Campaign
ReliaQuest has identified a new execution technique used in the ClearFake campaign, a variant of the SocGholish malware family. This sophisticated method involves using JavaScript to trick users into executing malicious PowerShell commands, representing a significant evolution in attack tactics.
Key Findings:
Infection Chain:
Conclusion: The ClearFake campaign exemplifies the increasing sophistication of cyber threats, highlighting the need for robust security measures and continuous vigilance. By understanding and implementing the recommended defensive measures, organizations can better protect against these evolving threats.
For detailed information and technical analysis, visit ReliaQuest's blog on the ClearFake campaign. Stay informed and secure!
Phishing Campaigns Exploiting Cloudflare Workers
Netskope has identified sophisticated phishing campaigns leveraging Cloudflare Workers to deploy malicious content through two main techniques: HTML smuggling and transparent phishing. These methods are designed to evade detection and compromise user credentials.
Key Findings:
Campaign Details:
For detailed technical analysis and more information, visit Netskope's blog on the ClearFake campaign.
New Phishing Campaign Uses Malicious LNK Files
A sophisticated phishing campaign has been discovered, leveraging malicious LNK files to deliver malware. This technique bypasses traditional email security filters and lures victims into executing harmful payloads.
Phishing Lure:
For more details, visit The Hacker News.
New Phishing Campaign Deploys WARMCOOKIE Backdoor Targeting Job Seekers
A sophisticated phishing campaign has been identified, deploying the WARMCOOKIE backdoor to exploit job seekers. The attack involves sending fake job offers with malicious attachments or links, which, when executed, install the WARMCOOKIE backdoor. This malware provides attackers with remote access to compromised systems, allowing data exfiltration and further exploitation.
Attack Chain:
Key Indicators:
For further details, visit the Hacker News article.
RansomHub Strengthens Its Ransomware Arsenal with Scattered Spider Tactics
A recent alliance between RansomHub and Scattered Spider has significantly boosted RansomHub’s capabilities, making it one of the largest active Ransomware-as-a-Service (RaaS) operations.
Key Developments:
Indicators of Compromise (IOCs):
Recommendations:
For more details, visit Security Boulevard and Dark Reading.
Phorpiex Botnet and LockBit3 Ransomware Surge
In May 2024, the cybersecurity landscape was significantly impacted by two major threats: the Phorpiex botnet and the LockBit3 ransomware group.
Phorpiex Botnet's Phishing Campaign
Researchers identified a large-scale phishing campaign involving the Phorpiex botnet, which sent millions of emails containing ransomware. The Phorpiex botnet, which resurfaced as a variant called "Twizt" in December 2021, used deceptive .doc.scr files in ZIP attachments to trigger ransomware encryption. This campaign employed over 1,500 unique IP addresses, primarily from regions such as Kazakhstan, Uzbekistan, Iran, Russia, and China.
LockBit3 Ransomware Dominance
LockBit3, operating as a Ransomware-as-a-Service (RaaS), accounted for 33% of published ransomware attacks in May. Despite previous law enforcement actions that disrupted their operations, LockBit3 quickly rebounded. This group continues to target large enterprises and government entities, particularly in regions excluding Russia and the Commonwealth of Independent States (CIS).
Top Malware Families:
Top Exploited Vulnerabilities:
Top Mobile Malware:
Most Attacked Industries:
Top Ransomware Groups:
Organizations must stay vigilant and implement robust cybersecurity measures to defend against these evolving threats. For more detailed information, visit Check Point.
SmokeLoader Evolution and Impact
Zscaler's ThreatLabz provides an in-depth historical analysis of SmokeLoader, a modular malware family first advertised in 2011. Initially serving as a downloader, SmokeLoader has evolved to include functionalities for data theft, DDoS attacks, and cryptocurrency mining. Key features include advanced anti-analysis techniques, modular capabilities, and encrypted C2 communications. Notable developments include the introduction of a stager component in 2014 and sophisticated obfuscation methods. SmokeLoader remains a persistent threat due to its continuous evolution and adaptability.
Key Takeaways:
For detailed insights, visit the Zscaler Blog.
DarkGate Malware's Evolving Tactics
Cisco Talos has identified a significant increase in DarkGate malware activity through malicious email campaigns since March 2024. These campaigns use Remote Template Injection to bypass email security controls, deploying Excel attachments that trigger malware execution when opened. Notably, DarkGate has transitioned from using AutoIT to AutoHotKey scripts for its infection process, with the payload executing in-memory without being written to disk.
Key Takeaways:
For detailed insights, visit the Cisco Talos Blog.
Active Phishing Campaign: Yousign HR Lure
Agari has identified an active phishing campaign using the Yousign platform to distribute malicious emails posing as HR notifications. These emails prompt recipients to review an updated employee handbook, leading to credential harvesting. By leveraging the legitimacy of Yousign's domain, attackers bypass email security filters. The campaign employs Remote Template Injection and unique URLs to evade detection.
Key Takeaways:
For detailed insights, visit the Agari Blog.
FBI Alert: Healthcare Industry Phishing Campaign
The FBI and HHS have issued a warning about a sophisticated phishing campaign targeting the healthcare sector. Threat actors are using social engineering tactics to steal login credentials and redirect Automated Clearing House (ACH) payments to accounts they control. These attackers manipulate help desk staff to gain access and then use stealth techniques to divert payments. Healthcare organizations, due to their size and access to sensitive data, are prime targets. Enhance employee training to recognize and thwart social engineering attacks.
Key Takeaways:
For detailed information, visit the KnowBe4 blog.
New Threat: ASCII-Based QR Codes
QR code phishing, or "quishing," is evolving with attackers now using ASCII characters to create QR codes within HTML, bypassing traditional OCR-based security measures. These codes appear as legitimate QR codes to users but evade detection by security systems, leading to credential theft and malware deployment.
Key Takeaways:
Stay informed and update your security measures to guard against these sophisticated threats.
For more details, visit the Checkpoint Blog or read more on Techzine.
New Threat: Exploitation of Microsoft SmartScreen
Overview Hackers are actively exploiting a vulnerability in Microsoft SmartScreen (CVE-2024-21412) to deploy stealer malware such as Lumma and Meduza Stealer. Despite a patch released in February 2024, attackers continue to bypass SmartScreen using malicious internet shortcuts distributed via spam emails.
Key Takeaways:
For more details, visit the Cyber Security News.
New Threat: Volcano Demon Ransomware
Overview A new ransomware group named Volcano Demon is using phone calls to pressure victims into paying ransoms. This group deploys LukaLocker ransomware to encrypt files and uses double extortion tactics by exfiltrating data before encryption. Victims receive threatening phone calls from unidentified numbers, increasing the pressure to comply with ransom demands.
Key Takeaways:
For more details, visit the The Record.
Created with ChatGPT
This was written for security awareness and to be distributed to all of our employees. Feel free to grab and use as part of your own security awareness program. Created with help from ChatGPT.
Introduction In an era where data breaches have become increasingly common, it is crucial to stay informed about the latest incidents and understand their implications. On July 12, 2024, AT&T disclosed a significant data breach that affected a vast number of its cellular customers. This blog post aims to break down the incident, its impact, and the steps being taken to enhance security measures.
What Happened? On July 12, 2024, AT&T announced that a breach had occurred, involving the illegal download of customer data from a third-party cloud platform. The breach affected phone call and text message records of nearly all AT&T cellular customers from May to October 2022 and January 2023. The stolen data included phone numbers and call durations, detailing who contacted whom by phone or text. Importantly, no content of the calls or texts, nor personally identifiable information, was compromised.
How Did the Breach Occur? Between April 14 and April 25, 2024, attackers exploited a vulnerability in a third-party cloud service used by AT&T. This vulnerability allowed unauthorized access to customer data over two distinct periods: May to October 2022 and January 2023. The breach was only discovered and disclosed in July 2024, highlighting the sophisticated methods used by the attackers and the ongoing challenges in detecting such breaches promptly.
AT&T's Response Upon discovering the breach, AT&T took immediate action to secure the compromised access point and began notifying affected customers. The company is cooperating with law enforcement to investigate the incident and bring the perpetrators to justice. Additionally, AT&T is implementing enhanced security measures to prevent future breaches. These measures include strengthening the security of third-party services and conducting comprehensive security audits.
Timeline of Events * April 14 and April 25, 2024: Initial breach period where customer data From May 1, 2022, October 31, 2022, and January 2, 2023, was illegally accessed. * July 12, 2024: AT&T publicly disclosed the breach and began notifying affected customers. * Ongoing: AT&T is cooperating with law enforcement and implementing enhanced security measures to prevent future incidents.
What Should Customers Do? AT&T has set up a dedicated webpage to address questions and provide steps for customers to check if their information was compromised. Customers are advised to:
ConclusionThe July 2024 AT&T data breach serves as a reminder of the persistent threats to our personal information in the digital age. While AT&T is taking steps to enhance its security measures, customers must also remain vigilant and proactive in protecting their data. By staying informed and adopting best practices for data security, we can collectively reduce the risk and impact of such incidents.
References * NPR Article on AT&T Data Breach * TechCrunch Report on AT&T Phone Records Theft * SEC Filing on AT&T Data Breach * AT&T Press Release on Customer Data Breach
By staying informed and understanding the nuances of such breaches, we can better prepare and protect ourselves against the ever-evolving landscape of cyber threats.
I pulled some information on the recently announced AT&T Data Breach, 12 July 2024, for leadership at my company. Feel free to take and use for your own reports or security awareness programs.
SummaryOn July 12, 2024, AT&T disclosed a significant data breach involving the illegal download of customer data from a third-party cloud platform. Attackers accessed a third-party cloud platform between April 14 and April 25, 2024. The breach affected phone call and text message records of nearly all AT&T cellular customers from May 1 to October 31, 2022, and January 2, 2023. The data included phone numbers and call durations, such as who contacted who by phone or text.
Per AT&T, no content of the calls or texts, nor personally identifiable information, was compromised. Attackers exploited a vulnerability in a third-party cloud service. AT&T has secured the access point, notified affected customers, and is cooperating with law enforcement. They are enhancing security measures to prevent future incidents.
Timeline of Events * April 14 and April 25, 2024: Initial breach period where customer data From May 1, 2022, October 31, 2022, and January 2, 2023, was illegally accessed. * July 12, 2024: AT&T publicly disclosed the breach and began notifying affected customers. * Ongoing: AT&T is cooperating with law enforcement and implementing enhanced security measures to prevent future incidents.
AT&T has set up a webpage to address questions and provide steps for checking if customer information is compromised.
This summary was written with help from the links below:
Created by ChatGPT
This is a security awareness newsletter meant for internal distribution. Feel free to grab and share with your company internally.
Steer Clear of Job Scams: Tips for New Graduates
Be cautious of job scams targeting new graduates. Here are some key takeaways to protect new graduates:
By following these tips, graduates can navigate a job search with confidence and avoid falling victim to scams. Remember, protecting your personal information and conducting thorough research are crucial steps towards landing a safe and rewarding job opportunity.
Love on the Rocks? Watch Out for Verification Scams!
Looking for love online? While dating apps can be a great way to meet someone special, be on the lookout for scammers trying to exploit your emotions. The FBI recently issued a warning about verification scams targeting dating app users.
Here's the lowdown:
Don't let love blind you! Here are some tips to stay safe:
Remember, online dating requires a healthy dose of skepticism. Trust your instincts, and prioritize your safety!
Shein Phishing Alert: Protect Your Fashion Finds and Login Info!
Calling all fashionistas! Watch out for phishing emails spoofing popular online retailer Shein. These emails aim to steal your login credentials and compromise your online shopping accounts.
Here's the Scheme:
Don't Fall for Fake Fashion Frenzy!
By staying vigilant, you can protect your hard-earned cash and sensitive information. Happy (and secure) shopping!
North Korean Threat Actors Targeting Developers with Fake Job Interviews
A new social engineering attack campaign is targeting software developers. This campaign is likely associated with North Korean threat actors. The attackers are sending fake job interviews that contain malicious software.
How the Attack Works
The attackers will send a seemingly legitimate job offer email to a software developer. The email will contain a link to a malicious website or a document that, when opened, will download malware onto the victim's computer. The malware is a Python-based RAT (Remote Access Trojan) that can steal information from the victim's computer, such as files, keystrokes, and browsing history.
How to Protect Yourself
Don't Let Ransomware Hit You Where It Hurts: Protecting Your Family From SIM Swapping
Cybercriminals are getting more personal in their attacks. A recent report from Mandiant highlights a disturbing trend: ransomware attackers targeting executives by SIM swapping their children's phones.
What is SIM Swapping?
SIM swapping is when a scammer takes control of your phone number by transferring it to a new SIM card. This allows them to receive your calls, texts, and potentially even two-factor authentication codes.
How Can You Protect Yourself?
For More Information:
Alert: Cybercriminals Exploiting Docusign with Sophisticated Phishing Scams
Summary: Cybercriminals are increasingly targeting Docusign users by distributing customizable phishing templates on cybercrime forums. These templates closely mimic legitimate Docusign emails, luring recipients into providing sensitive information or clicking malicious links. These attacks facilitate various malicious activities, including credential theft and business email compromise (BEC) scams.
Key Indicators of Docusign Phishing Emails:
Prevention Tips:
Growing Confidence Among CISOs Despite Rising Cyber Threats
Overview: According to Proofpoint's 2024 Voice of the CISO report, 70% of CISOs feel at risk of a cyber attack, yet only 43% feel unprepared—a significant improvement from previous years. Despite this growing confidence, human error remains a critical vulnerability, with 74% of CISOs identifying it as a top concern. Encouragingly, the adoption of AI-powered solutions and enhanced employee education are seen as key strategies to mitigate these risks. However, challenges such as ransomware, malware, and employee turnover continue to test cybersecurity resilience.
Key Points:
Takeaway: Continuous improvement in AI adoption and employee training is vital for bolstering cybersecurity defenses.
New Social Engineering Scheme by Black Basta Ransomware Group
Overview: The Black Basta ransomware group has launched a new mass spam and social engineering campaign, targeting various industries. The attackers flood users' emails with spam and then pose as IT support, convincing victims to download remote access tools like Quick Assist or AnyDesk. This grants the attackers initial access to deploy ransomware and steal credentials.
Key Points:
Takeaway: Stay vigilant against unsolicited IT support offers and ensure employees are aware of this tactic.
From Phish to Phish Phishing: How Email Scams Got Smart
Phishing scams have evolved dramatically over the years, becoming more sophisticated and harder to detect. Here are key points from Check Point's recent article on how email scams have become smarter:
Evolution of Phishing Tactics:
Techniques and Vectors:
Email and Attachments: Phishing emails often include links to fake websites or attachments that require personal information. These can lead to data theft or malware infections.
Common Scams:
Ransomware Delivery: A significant number of phishing emails now deliver ransomware, locking victims' files and demanding a ransom for their release.
Preventive Measures:
Stay Vigilant: Always verify the sender’s email address and look for signs of phishing, such as generic greetings and urgent requests for personal information.
By staying informed and cautious, you can protect yourself and your organization from falling victim to these increasingly sophisticated email scams.
Beware the Piano Scam
Cybercriminals are exploiting unsuspecting individuals with a new scheme known as the "Piano Scam." Victims receive emails offering a free piano due to a family death, but they are asked to pay shipping fees through fake shipping companies. These scammers also collect personal information. Protect yourself by verifying the sender, avoiding clicking on unknown links, and reporting suspicious emails.
Key Points:
Created by ChatGPT
This is a short blog post I wrote for our security awareness internal communication. Feel free to grab and use for your own program. Created with the help of ChatGPT.
Beware Advance Fee Fraud (AFF): The Piano Scam
Cyber threats are constantly evolving, and one of the latest scams targets unsuspecting individuals with a piano-themed fraud. This scheme, dubbed the "Piano Scam," preys on the goodwill of victims by offering a "free" piano, only to defraud them through advance fee payments for shipping.
This type of scam is targeting people in the education sector but other scams like this will target other industries such as healthcare or the food industry. Understanding these types of scams will help identify when similar scams are used against our company.
How the Scam Works
Recognizing the Scam
Prevention Tips
Understanding the tactics used in the Piano Scam can help you avoid becoming a victim. Stay vigilant and informed to protect yourself from these and other cyber threats.
For more detailed information on this scam, visit Proofpoint's Security Brief.
Created by ChatGPT
These are the articles and blogs I’ve read over the last month with a lean towards phishing and healthcare. I share this internally with the security team. Feel free to take and use for your own programs.
Unprecedented Surge in Proxy-Driven Credential Stuffing Attacks
Okta identified a substantial rise in credential stuffing attacks targeting online services in the past month. These attacks exploit widely available resources like stolen login credentials, residential proxies, and scripting tools to gain unauthorized access to user accounts. The attacks appear to originate from anonymizing services like Tor and leverage proxies to bypass security measures.
Key Takeaways:
Indicators of Compromise (IOCs):
Black Hat SEO Techniques Used to Distribute Malware
This report details a malware distribution campaign that leverages black hat SEO techniques. Attackers create malicious websites designed to look legitimate and rank high in search results. These websites are then used to trick users into clicking on them and downloading malware.
Technical Details:
Phishing Remains a Top Threat Despite Decline in Q4
Phishing attacks continue to be a major threat to organizations of all sizes. According to a recent report by the Anti-Phishing Working Group (APWG), 2023 saw a significant increase in phishing activity, making it the worst year on record. Over 5 million phishing attacks were detected in 2023, highlighting the prevalence of this cyber threat.
The report also details a decrease in phishing attacks during the fourth quarter of 2023. This decline is attributed to the takedown of Freenom, a service frequently abused by attackers to register domains that spoofed legitimate companies. While this is a positive development, it serves as a reminder that threat actors are constantly evolving their tactics.
Key Takeaways
New Technique for Detecting Malware Stealing Browser Data
A recent blog post by Google Security Blog details a new technique for detecting malware that steals browser data. The technique involves monitoring Windows Event Logs for signs of unauthorized access to browser data.
How Browser Data Theft Works
Many malware programs target browser data, such as cookies and saved credentials. This data can be valuable to attackers, as it can be used to gain access to online accounts, steal financial information, or launch other attacks.
Traditional Detection Methods
Traditional methods for detecting malware that steals browser data often rely on behavioral analysis or signature-based detection. However, these methods can be ineffective against new or sophisticated malware.
Detecting Browser Data Theft with Windows Event Logs
The new technique described by Google Security Blog involves monitoring Windows Event Logs for DPAPI events. DPAPI (Data Protection API) is a Windows API that is used to protect sensitive data. When an application attempts to decrypt data protected by DPAPI, a DPAPI event is generated in the Windows Event Log.
By monitoring DPAPI events, it is possible to identify unauthorized attempts to access browser data. This is because legitimate applications should not need to decrypt browser data unless the user is actively using the browser.
Benefits of This Technique
This technique has several benefits over traditional methods for detecting browser data theft. First, it is less reliant on signatures, making it more effective against new and unknown malware. Second, it can provide valuable forensic information, such as the time and process that attempted to access the data.
Security Implications
This technique highlights the importance of monitoring Windows Event Logs for security threats. By monitoring these logs, security professionals can gain valuable insights into the activities of applications running on their systems.
Recommendations
By following these recommendations, organizations can improve their ability to detect and prevent browser data theft.
Healthcare Organizations Targeted in Social Engineering Campaign with Deceptive Tactics
High Importance
A recent report by ReliaQuest exposes a cunning social engineering campaign targeting healthcare organizations' revenue cycle management (RCM) departments. Then attackers employed deceptive tactics to manipulate help desk staff into resetting multifactor authentication (MFA) credentials. This allowed them to infiltrate the system and steal funds by altering bank routing information for fraudulent money transfers.
Social Engineering Techniques Used:
The report details how attackers impersonated legitimate users, often healthcare staff, by leveraging readily available personal information. This information might have been obtained through various means, including phishing emails, data breaches, or even social media. Once impersonating a staff member, attackers would contact the help desk, feigning an issue with their MFA and requesting a reset. To heighten their legitimacy, they might provide seemingly valid personal details associated with the target user, such as the last four digits of their Social Security number, date of birth, or home address. By exploiting trust and creating a sense of urgency, attackers could potentially trick help desk personnel into resetting the MFA, compromising the account's security.
LockBit Black Ransomware Delivered via Phorpiex Botnet Spam Campaign
High Importance
A recent phishing campaign leveraged the Phorpiex botnet to distribute LockBit Black ransomware. Millions of malicious emails were sent, targeting a widespread audience.
Campaign Details:
LockBit Black Ransomware:
LockBit Black is a ransomware variant known for encrypting victim files and demanding a ransom payment for decryption. This iteration is likely derived from a leaked version of LockBit 3.0, raising concerns about potential widespread attacks.
Alert: Threat Actors Expand Malicious Use of DNS Tunneling
High Importance
Security researchers warn of a growing trend: threat actors are increasingly exploiting DNS tunneling for malicious purposes. DNS tunneling involves encoding data within legitimate DNS requests, creating covert communication channels that bypass traditional security measures.
Why is this concerning?
Cybercriminals Exploit Docusign Phishing Templates
Summary: Cybercriminals are increasingly targeting Docusign users by distributing customizable phishing templates on cybercrime forums. These templates closely mimic legitimate Docusign emails, luring recipients into providing sensitive information or clicking malicious links. These attacks facilitate various malicious activities, including credential theft and business email compromise (BEC) scams.
Rising Shadow AI Accounts Elevate Corporate Data Risks
Summary: Recent research by Cyberhaven Labs reveals a 485% surge in AI tool usage among workers, with 90% occurring through personal "shadow AI" accounts. This trend exposes sensitive corporate data to public AI models, posing significant security risks. Key findings highlight that tech workers are the highest contributors, with substantial portions of sensitive data like legal documents, source code, and HR records being inputted into non-corporate accounts. Companies must address these vulnerabilities to safeguard their data.
Action Points:
Image created by ChatGPT
In the past year, the field of AI has seen significant advancements and a greater focus on regulatory and ethical considerations. At ColaSec we will be talking about AI for our May meetup. This will be a group discussion like we had last year. We wanted to revisit AI and how our views and uses of it have changed. We have a virtual option available for those that can’t make it in person.
To prepare for the discussion I wanted to put this blog post together reviewing AI and how it’s impacted our society over the last year. Ironically, this post was created with help from ChatGPT.
ChatGPT weighs in Generative AI's Expansion: Generative AI technologies have experienced widespread adoption and development. Companies increasingly use these capabilities not just for enhancing existing products and services but also for innovating new business models (McKinsey & Company). * Ethics and Regulation: There has been a growing global movement towards regulating AI more stringently. For example, the European Union has been active in proposing comprehensive AI legislation, and the White House has introduced an executive order aimed at setting standards for AI development and deployment (MIT Technology Review) (Goodwin). * Technological Innovations: On the technical front, major advancements have been made in areas such as AI explainability, privacy, and safety. New tools have been developed to improve the transparency and accountability of AI models, such as watermarking technologies for identifying AI-generated content (Google DeepMind). * Application in Science and Healthcare: AI's application in scientific research and healthcare continues to grow, with new models enhancing our ability to design novel proteins and materials, potentially revolutionizing fields like drug discovery and environmental sustainability (Microsoft Cloud). * Public Discourse and Awareness: The public discourse around AI has matured, with more widespread discussions on the ethical implications, societal impacts, and long-term consequences of AI technologies. This includes concerns about AI-generated disinformation and the privacy implications of widespread surveillance technologies (CSIS) (Digital Watch Observatory). * Generative AI and Cybersecurity: AI technologies are playing an increasingly critical role in cybersecurity, automating tasks and enhancing threat detection and response capabilities. The dynamic nature of AI is likened to an arms race among companies, governments, and cybercriminals, emphasizing the need for vigilant cybersecurity practices (TechNewsWorld). * AI in Political Processes: The use of AI in political processes, such as elections, has become a significant concern. Issues like the generation and spread of political deepfakes are becoming more prevalent, complicating the political landscape and potentially influencing election outcomes. This underscores the urgent need for robust methods to detect and mitigate such AI-generated disinformation (MIT Technology Review) (AI Index)(Check Point). * Advancements in AI Applications: AI's capabilities continue to expand into more complex and nuanced areas, including multimodal interactions where AI systems can understand and generate outputs across text, image, video, and audio. This broadens AI's application in various fields but also raises concerns about privacy and the creation of synthetic content that can be difficult to distinguish from human-generated content (Tech Xplore). * Ethical Concerns and AI Bias*: The integration of AI in sectors like finance, healthcare, and public services brings benefits such as increased efficiency and new capabilities. However, it also brings risks such as biases in AI algorithms, which can perpetuate existing inequalities. There is a growing emphasis on developing responsible AI practices to address these issues (AI Index).
These developments reflect a dynamic field that is not only advancing rapidly in terms of technology but also becoming increasingly intertwined with broader societal and regulatory frameworks.
Tim weighs in Verizon DBIR: I recently read the latest Verizon DBIR and made a blog post about it. One of the takeaways was that AI hasn’t had a significant impact on attacks. It is helping with improving efficiencies of attacks but it’s not an action in itself yet. This may change or it may not. Attackers use the path of least resistance. Setup a scheme to attack people with deepfakes and voice impressions can be a bit more elaborate. Not to say that they aren’t out there. It’s just not as widespread. * Policy creation: One of the first things I did was create security policies for a small business. It took me just a few hours to create 10 security policies that the company was being required. They were concise and easy to read. I hope that security teams are paying attention as this will improve the quality of policies overall and make them much more consumable and easier to understand. * Building out ExploreSec.com: I’ve used AI to build out a large portion of this site. I’ve gotten a lot more done than I ever would have on my own. I can put up deep dives in less than an hour. I will go back and edit the initial output from ChatGPT. I’ve written a few blog posts with ChatGPT with varying results. I believe my better posts are going to be me and my stories and experiences. I did have one blog post get deleted accidentally after I wrote it. Instead of doing a full rewrite, I had ChatGPT write the article and I thought it came out very well. It’s been very useful for the podcast. I now use ChatGPT almost entirely to write my show notes. When I record I also transcript the conversation. I then take that transcript and have AI build show notes. It’s been an enhancement for show notes and streamlines my post editing process. * Creating Security Awareness Content: My new role is building out a security awareness program for a large healthcare organization. I’ve used ChatGPT to build out blog posts and create newsletter items. Smishing is my most recent blog post. Like the building out content on the site, I have it create the first draft and then make adjustments from there. This allows me to easily create regular content for our internal communication site while also educating people on different security topics. I’ve also started releasing a monthly newsletter for phishing threat intelligence and security awareness. I take articles I find online and have either ChatGPT or Gemini write a short newsletter item. With Gemini and Co-Pilot I could take the link and just feed it that instead of having to scrap the data. I found Co-Pilot to have the best repeatable format. Eventually I ran out of a free trial and it wanted me to login. It also got very uncomfortable when I was doing phishing research and it forced me off the topic. ChatGPT recently released 4o and it is now taking links and creating content out of it. * Scripting: I’ve found AI extremely useful for building out PowerShell scripts. One of the things I like to do in a new role is build out the metrics. This often means custom metrics that a platform doesn’t have reporting on. I’ve taken the raw data and created PowerShell scripts that massage the data into the metrics I want. The PowerShell created usually works the first time. If it doesn’t then I simply feed the AI the error. They usually start out being this simple script and quickly get more complicated as I think of more use cases for the script. I will be posting these scripts on my GitHub at some point. * Research: I’ve been using AI to help do research on topics. I still find that Google is better for some thing. AI is still several months behind on what it can provide but it’s getting better. Like creating content it’s a starting point for research. I’ve found in some of the topics I’ve explored in security it provides resources I’ve never heard of before but it can also be susceptible to marketing content. I would expect this will get worse as marketing teams figure out how to get their content into AI and a top result. Similar to how they figured out Google and other search platforms. * Image Generation: I’ve been extremely happy with the images generated by ChatGPT. I use it for blog posts where I can’t find images. Usually I feed it the content and ask it to make an accompanying image. I’ve also used it for my presentations when I can’t find a meme or visual that highlights the content. It’s not always great. It still struggles with words but I’ve seen it get better. The same prompt will give different results. Sometimes there’s one thing I don’t like and ask it remove it and it’ll create a whole new image. I’ve messed around with photoshop for a couple images but it usually ends up being more hassle than it’s worth. I just keep giving it prompts until I get something I want. Sometimes starting over and taking a different approach with the prompt is the best option. * Social Media: I’ve played around with AI for use on LinkedIn. Some of the posts it creates are cheesy. I primarily use it for podcast announcements. I need to play around with it more but I’ve started to move away from it. I have found that the view point for the prompt is big. It can get caught up creating words for a marketing team instead of someone with an idea or wants to comment on a blog post. This makes sense as I imagine marketing teams are using this to create social media posts on a more regular basis. * Presentations:* This year I used AI to help build my abstract, bio, and outline for my presentation. I haven’t had it build my slide deck yet, but I’m toying around with it. The abstract and bio alone are huge for me as I’m not a great self-promoter. I was able to build out all three in 30 minutes. This used to take me several hours to put together. I also believe I’ve been accepted to speak more because of it.
I’ve found AI to be a valuable tool for content and scripting. It’s helped me build content for ExploreSec.com. It’s helped me improve my presentations both from a submission and content standpoint. I’m excited to get back into scripting to see what sorts of automation I can build for doing regular tasks like metrics. Looking ahead, I’m continuing to come up with use cases. My next project is to understand how to use voice AI from an attackers standpoint but also from a podcasters standpoint. There are some use cases that I think will enhance the podcast.
What are your thoughts on AI and how have you used it over the past year?
Smishing - Image created by ChatGPT
This is an article I’ve put together for my internal Security Awareness program. Feel free to grab and use in your own program. Created with help from ChatGPT.
In today's digital age, cybersecurity threats are evolving rapidly, and one of the rising threats is "smishing." Smishing, a blend of "SMS" (short message services) and "phishing," is a form of phishing that involves sending fraudulent SMS messages designed to deceive recipients into revealing personal information or installing malware.
Understanding Smishing Smishing attacks typically involve a text message that appears to come from a legitimate source, such as a bank, a well-known retailer, or even government agencies. These messages may claim that there's an urgent issue requiring your immediate attention, such as a problem with your bank account, a missed delivery, or a tax refund opportunity. The message will usually include a link that you are urged to click to resolve the issue.
How Smishing Works The goal of smishing is to trick the recipient into providing sensitive information, such as login credentials, credit card details, or personal identification numbers. Alternatively, the link may download malware onto the recipient’s phone, which can lead to data theft or loss, financial loss, and sometimes even identity theft.
Examples of Smishing Attacks
Tips to Protect Yourself from Smishing * Be Skeptical of Unsolicited Messages: Always be wary of text messages that ask for personal information, especially if they convey a sense of urgency. * Verify the Source: If a message claims to be from an organization you do business with, verify its authenticity by contacting the organization directly using a phone number or email address from their official website—not the contact details provided in the message. * Avoid Clicking on Suspicious Links: Do not click on links in unsolicited texts or emails. Instead, go directly to the website by typing the URL into your browser. * Educate Yourself and Others: Awareness is your best defense. Learn about the latest smishing tactics and educate your family and friends on how to protect themselves.
Conclusion Smishing is a significant and growing threat in the realm of cyber scams. By staying informed and cautious, you can protect yourself from falling victim to these malicious attacks. Always remember that when it comes to protecting your personal information, vigilance is key. If you suspect you’re being targeted by a smishing attack please contact [INTERNAL SECURITY TEAM INBOX].
Exploring the Verizon DBIR - Image created by ChatGPT
The Verizon Data Breach Investigations Report (DBIR) for 2024 was recently released. It’s a must read of those in cybersecurity. It gives great insight into the overall threat landscape and then breaks it down by industry. Working in healthcare this is important because while ransomware grabs the news a bigger concern may actually be insider threat. This is highlighted even more this year with new requirements around reporting on security incidents and breaches insider threat and specifically the Miscellaneous Error category. My random thoughts from the report are below with a lean towards healthcare.
Insights and thoughts on the Verizon DBIRVulnerability exploitation on the riseExploitation of vulnerabilities tripled from last year. I’ve read similar numbers from other trend reports and it makes sense. As organizations get more controls in place such as Multi-Factor Authentication (MFA) and people get better at identifying phishing (later in the report) attackers will pivot to other ways of getting in. We’ve already seen a rash of vulnerabilities in network appliances over the last several months that could allow attackers into the network.
Human Element Calculation ChangePrivilege misuse was removed from the human element calculation which means the human element metric dropped to 68% instead of 76% if it were kept in this year. I’m a little torn because I still believe it’s human element misusing privilege. The idea is to align their security awareness recommendation better. From that angle I get it because privilege misuse is more intentional regardless of security awareness training.
Added third-party vendor and supply chain issuesThis is a good one to add. As organizations get better at defending attackers will look to get in via third-party vendor or supply chain issues. Which really isn’t a new concept see: Target breach or the Trojan War. A good third-party vendor risk management program is essentially to keeping organizational data secure.
Errors Increases due to mandatory breach notificationsErrors increased to 28% this year. Internal actors increased from 20% to 35%. Organizations that don’t have to report won’t. In healthcare if a breach is under 500 records then reporting doesn’t have to occur, so there’s even more Errors not being reported. I expect more regulation will make this number continue to grow for healthcare . This will hopefully highlight and shift focus to finding solutions to the insider threat problem. Yes, there’s Data Loss Prevention (DLP) but it’s a pain in the ass to get in place.
Meme created by ME!
Security Awareness is Improving20% of people are reporting simulated phishing emails and 11% are reporting after clicking. That’s positive improvement. I also really like that the report focused on report rates and not clicking. Click rates can fluctuate depending on the difficulty of the phish and the time of year. Too much focus is put on clicking when what’s really needed is an improvement in reporting.
Reporting gives the security team an opportunity to respond to an incident sooner. I always tell people that clicking doesn’t bother me. Did they report it? It’s much easier to respond now, than several weeks later when there’s a bigger issue. Encouraging reporting, even when a click happens, also helps build a more positive security culture. We’re all human and make mistakes. I’ve fallen for my own phish before.
Generative AI Not as much of an issue as we thinK It’s recognized that AI is helping attackers in writing phishing email and malware and being deployed in political campaigns but it’s not being used in way that is significantly contributing to breaches. This is why I love the Verizon DBIR. Despite the news headlines and play on social media AI and all the awful things it can do is not currently having a measurable impact. It’s certainly still something that needs to be discussed, understood, and controls put in place, but it may be better to focus on efforst that may make a more substantial impact such as vulnerability management and security awareness.
Distributed Denial of Service is the top action in incidentsThis is where understanding the verbiage of the report is important. Incident vs breach. Breach is a loss of data. An incident is a security incident that may not involve data being stolen. Hence, DDoS isn’t about taking the data it’s about taking the service offline for an extended period of time. This shocked me a little. DDoS is still happening and it’s impacting a lot of organizations. Having mitigating controls and a plan in place to respond is important for any organization.
Jen Easterly comments on vulnerabilities and the need to shift focus
“...recurring classes of software defects to inspire the development community to improve their tools, technologies, and processes and attack software quality problems at the root.”
Quality code is secure code is something I’ve been preaching for years. If the quality is there then the security will be there. It’s in the documentation. When developers don’t follow best practices and the documentation that’s when vulnerabilities get created. The reason why security folks have a job is because people aren’t developing, coding, or configuring things right in the first place.
I like that Jen is taking a more broad view and it’s not something I’ve thought about. Instead of focusing on individual vulnerabilities or bugs we should go a level up. Every organization is different and every development team is going to have different issues with certain quality issues. We need to be looking at the class of bugs and trying to solve for the large grouping of vulnerabilities. This will help the development community identify where they can make improvements in their tools, technologies, and most importantly processes.
Social Engineering SectionBEC attacks had a median transaction of $50,000. They have a great graph that shows most organizations can get their money back by reaching out to law enforcement. I had a great conversation with Jayson E. Street recently on the Exploring Information Security podcast on social engineering and he had a great idea to send everyone involved in financial transactions a card with a code word on it. If that code word wasn’t authenticated then it’s very likely a BEC attack. I love the simplicity of the solution and I think it can make a good impact.
WEB APPLICATION ATTACKS SECTIONCredential stuff and brute force attacks are the most common against APIs. Authentication and authorization are the biggest issues for APIs, not so much injection vulnerabilities. This improves security but also means permissions should be top of mind when developing APIs. Things like MFA and rate limiting also need to be in place to help mitigate the potential of a breach. 1000 credentials are available online daily for $10. Credentials are cheap and easy to come by.
Free gaming currency lures lead malicious NPM packages was not something on my radar. This is the younger generation looking to make a fast bUck in the gaming landscape. Unfortunately, they’re downloading malware. Typo squatting was second. From the report it talked about packages checking external repositories before internal. It’s always better to try and build an internal repo system that pulls updates from the known good repositories. This is easier said than done.
Miscellaneous ERrorsThis is often overlooked by organizations. Insider threat is the bigger concern in industries like healthcare where people are handling personal, health, and financial data. There’s a lot of data flying around. More than 50% was due to misdelivery which means people sent sensitive information to the wrong party and often non-malicious.
87% of users accounted for errors. System administrators go from 46% last year to 11% this year. System administrators largely accounted for internal threat issues due to misconfiguration. They’ve tightened up but it also highlights how under reported user errors were.
Data Loss Prevention (DLP) is huge to help prevent this. The problem is that DLP is a pain in the ass to implement. I hope that highlighting how big of an issue insider threat will encourage companies to try and tackle the problem in more creative ways.
Healthcare IndustryI’ve already talked a lot about healthcare above. Miscellaneous Errors regained the top spot after being second to system intrusions last year. I would expect system intrusions to continue to decline in next year’s report due to law enforcements increased involvement in taking down ransomware gangs. Privilege misues was second. This is the more malicious actions internal threat actors are taking. System intrusions were third.
ConclusionThe 2024 Verizon Data Breach Investigations Report (DBIR) is a must read. It provides critical insights into the evolving threat landscape, particularly emphasizing the increasing complexity of cybersecurity challenges across various industries. It’s a good anchor point for challenging assumptions about the biggest risk to our own organization.
As cybersecurity environments become increasingly complex, the DBIR’s insights are invaluable for professionals seeking to bolster their defenses and anticipate potential threats. The report serves not only as a tool for understanding but also as a catalyst for implementing robust security measures tailored to specific industry needs. For those in cybersecurity, especially in sectors as sensitive as healthcare, the DBIR is an essential resource that supports ongoing efforts to protect sensitive information and systems from both external and internal threats.
Exploring the security awareness newsletter - Image created by ChatGPT
These are the stories I’ve been tracking that are of interest to people outside of security. Feel free to take this and use it as part of your own security awareness program. The items were created with the help of ChatGPT
Confirmed: AT&T Data Breach Exposes MillionsA large data leak containing personal information of millions of AT&T customers is being investigated. While AT&T denies the breach originated from their systems, this incident highlights the importance of protecting your personal information.
Here are some steps you can take to stay safe:
AI in Elections: Beware the Deepfakes!AI is shaking up elections! Check Point Research warns of deepfakes and voice cloning being used to mislead voters. They found evidence in 10 out of 36 recent elections. Stay informed - the future of voting might depend on it!
Heads Up, Gamers! Malware Lurks in YouTube Video Game CracksPhishing for free games can land you in hot water!
A recent report by Proofpoint discovered threat actors using YouTube to distribute malware disguised as popular video game cracks.
Here's the breakdown:
Alert on Privacy Risks in Dating Apps: Spotlight on HornetRecent investigations by Check Point Research have exposed critical privacy vulnerabilities in the popular dating app Hornet, affecting its 10+ million users. Despite Hornet's attempts to safeguard user locations by randomizing displayed distances, researchers found ways to determine users' exact locations within 10 meters using trilateration techniques. This finding poses a significant privacy risk, particularly in dating apps that rely on geolocation features to connect users.
Highlights:
The study illustrates the ongoing challenges and potential dangers of balancing app functionality with user privacy, urging both developers and users to remain vigilant.
Ransomware Scams Can Get CreativeRansomware gangs are constantly looking for new ways to pressure companies into paying up. A recent article on TechCrunch describes a hilarious (but ultimately unsuccessful) attempt by a hacker to extort a company through their front desk Ransomware gang's new extortion trick? Calling the front desk.
While this specific incident might be lighthearted, it serves as a reminder that ransomware attackers are always adapting their tactics. Here's what you should be aware of:
By staying vigilant and following these tips, we can all play a part in protecting our company from ransomware attacks. Remember, if you see something suspicious, report it!
FBI Alert: Increase in Social Engineering AttacksThe FBI has issued a warning about the rise in social engineering attacks targeting personal and corporate accounts. These attacks employ methods like impersonating employees, SIM swap attacks, call forwarding, simultaneous ringing, and phishing, which are designed to steal sensitive information.
Key Techniques:
How to Protect Yourself:
If Compromised:
Stay vigilant and implement these protective measures to defend against these sophisticated social engineering threats.
Smishing Scam Hits the Road!Beware of texts claiming unpaid tolls! Scammers are targeting drivers with smishing attacks. The texts claim that the recipient has unpaid tolls. Don't click links or give out info. Report scams to the FBI: https://www.ic3.gov/Home/ComplaintChoice. Stay safe!
Data Breach at Hospital: Ex-Employee Admits to Sharing Patient RecordsPatients at Jordan Valley Community Health Center in Missouri are being notified of a data breach involving over 2,500 individuals. The culprit? A former employee, Chante Falcon, who admitted to accessing and sharing patient records.
Facing federal charges for wrongful disclosure of patient information, Ms. Falcon pleaded guilty and awaits sentencing. The potential penalty? Up to 10 years in prison.
Tax Time Trouble: Don't Fall Victim to Tax Scams!It's tax season again! While you're busy gathering documents and filing your return, scammers are out in force trying to steal your money and personal information.
This year, security experts are seeing a rise in Artificial Intelligence (AI)-powered tax scams. These scams can look and feel more sophisticated than ever before, making them even trickier to spot.
Here are some red flags to watch out for:
Stay Safe This Tax Season:
By following these tips and staying vigilant, you can protect yourself from tax scams and ensure a smooth tax season!
Tracking AI's Influence in Global ElectionsRest of World, a news organization, has launched a new initiative to monitor and document the impact of artificial intelligence (AI) on global elections. This effort comes as generative AI tools become increasingly accessible, presenting both innovative uses and potential risks in political contexts.
Scope and Objective: The project tracks AI incidents across the globe, particularly focusing on regions outside the Western hemisphere. From the general elections in Bangladesh to those in Ghana, the tracker will compile AI-generated content related to elections, encompassing both positive applications and problematic issues like misinformation.
Noteworthy Incidents:
Comprehensive ChatGPT Risk AssessmentWalter Haydock from StackAware has conducted an exhaustive risk assessment of OpenAI's ChatGPT. This summary encapsulates the critical findings and documentation from the assessment, aiming to enhance your understanding and governance of AI tools.
Key Findings from the Assessment:
Deepfake Phishing Attempt Targets LastPass Employee: Audio Social Engineering on the RiseA recent incident reported by LastPass sheds light on a concerning trend: the use of audio deepfakes in social engineering attacks.
What Happened?
Why This Matters:
How LastPass Responded:
Change Healthcare Cyberattack: A Costly Reminder for Physicians
A recent cyberattack on Change Healthcare, a major healthcare IT provider, has had a significant impact on physicians across the country. According to a KnowBe4 article, a staggering 80% of physicians reported financial losses due to the attack. United Health announced the attack cost them $1.6 billion alone.
The High Cost of the Breach
The article details the financial strain placed on physician practices:
USPS Now the Most Impersonated Brand in Phishing AttacksPhishing attacks are one of the most common cyber threats. Criminals impersonate well-known brands to trick people into giving up personal information. According to a recent report, the United States Postal Service (USPS) has surged to the top spot on the list of most impersonated brands.
Here are some tips to avoid falling victim to a USPS phishing attack:
By following these tips, you can help protect yourself from phishing attacks.
Exploring phishing threat intelligence from April 2024 - Image created by ChatGPT
These are the phishing related stories I paid attention to in April 2024. Feel free to use these and share them with your own security teams.
The NaurLegal Campaign Unveiled
BlueVoyant's Threat Fusion Cell has exposed a new cyber attack campaign, dubbed ‘NaurLegal’, led by the notorious eCrime group Narwhal Spider. This campaign ingeniously exploits the trust in legal transactions by distributing malicious PDF files posing as invoices from reputable law firms. With filenames like "Invoice_[number]from[law firm name].pdf," these documents are crafted to bypass casual scrutiny and initiate malware infections.
Key Insights:
Google Ads Malware Alert for Security Professionals
In a recent discovery by AhnLab Security Intelligence Center (ASEC), a sophisticated malware distribution campaign has been identified exploiting Google Ads' tracking feature. Dubbed by ASEC, this campaign cleverly disguises malware as popular groupware installers like Notion, Slack, and Trello, leveraging Google Ads to reach a broad audience. The exploitation of the Ads platform's vast user base and complex targeting options presents a notable security concern, highlighting the innovative strategies of cybercriminals to breach defenses.
Key Campaign Insights:
Security Alert: New Loader and Agent Tesla Campaign Detected
SpiderLabs has identified a phishing campaign deploying Agent Tesla via a sophisticated new loader. Initiated via email attachments disguised as bank payment receipts, this campaign utilizes advanced obfuscation and encryption to deliver its malicious payload while evading detection.
Key Insights:
AI-Powered Malware Spreads Through Social Media Malvertising Campaigns
This article from Bitdefender highlights a recent surge in information-stealing malware campaigns targeting social media users.
Key Points:
Attention Security Teams: Malware Spreads Through YouTube Video Game Cracks
Threat actors are leveraging compromised YouTube accounts to distribute information stealers disguised as popular video game cracks. This campaign, detailed in a recent Proofpoint report, targets unsuspecting gamers, particularly younger audiences.
Security Implications:
For further investigation: The Proofpoint report provides Indicators of Compromise (IOCs) to assist in identifying these malicious videos.
ReliaQuest’s Annual Cyber-Threat Report: 2024
According to the report:
Android Malware Vultur Expands Its Capabilities
A recent report by Fox-IT details the evolving capabilities of the Android malware Vultur. Key takeaways:
These expanded capabilities pose a significant threat to Android users, as Vultur can now perform a wider range of malicious activities.
Agent Tesla Targets US and AU Organizations: A Newsletter for Security Professionals
A recent campaign by cyberespionage actors, nicknamed "Bignosa" and "Gods", has been targeting organizations in the United States and Australia. The attackers use phishing emails with topics related to purchasing goods and order delivery to distribute the Agent Tesla malware. Once installed, Agent Tesla can steal keystrokes and login credentials.
Key takeaways:
New Download Threat: Latrodectus Emerges
A new downloader malware called Latrodectus has emerged, posing a threat to system security. Two threat actors, TA577 and TA578, have been distributing Latrodectus, raising concerns about its potential reach.
This malware functions as a downloader, capable of not only information theft but also installing additional malware, potentially escalating the attack. Security experts believe Latrodectus might be linked to the creators of IcedID, another malicious software. Key takeaways:
New Malware Delivery Techniques on the Rise
New research from Check Point reveals that cybercriminals are developing new methods to deliver malware. These techniques involve novel infection chains designed to bypass common security measures and deliver Remcos, a powerful Remote Access Trojan (RAT).
The report also highlights the evolving tactics employed by attackers to exploit vulnerabilities. While Lockbit3 remains the most prevalent ransomware, Blackbasta has worryingly climbed the ranks, entering the top three.
Key takeaways:
Tycoon 2FA: Phishing As A Service Evolving to Bypass MFA
MFA Fatigue? Tycoon 2FA Raises Concerns
A new variant of the Tycoon 2FA phishing kit is making waves for its effectiveness in bypassing multi-factor authentication (MFA). This phishing-as-a-service (PhishingaaS) tool targets Microsoft 365 credentials and utilizes a technique known as adversary-in-the-middle (AiTM) to steal session cookies, granting access even with MFA enabled.
Key Points for Security Teams:
Alert: Cisco Duo's Multifactor Authentication Service Compromised
Cisco Duo has issued a warning to its customers following a breach involving a third-party telephony service provider. This incident, which unfolded on April 1, 2024, involved the unauthorized access of SMS logs due to a social engineering cyberattack.
Key Details:
Customer Advisory: Cisco Duo has advised all impacted users to notify individuals whose information was compromised and to stay alert for potential phishing attacks leveraging the stolen data.
Tech Giants Lead Phishing Charge: Microsoft, Google Top Q1 Brand Impersonation
Phishing remains a top threat, with technology brands the most impersonated.
A recent report by Check Point Research (CPR) paints a concerning picture of the evolving phishing landscape. Their analysis of brand phishing attempts in Q1 2024 reveals a worrying trend: technology giants are the most targeted sectors.
Key Findings:
Why Tech Brands?
Cybercriminals often target technology brands for several reasons:
Beware of Sophisticated Phishing Attacks Targeting Help Desks!
Alert! A recent report from the Department of Health and Human Services (HHS) warns of a rise in sophisticated social engineering attacks targeting IT help desks within the healthcare sector.
Here's what you need to know:
Malvertising Campaign Targets IT Teams with "MadMxShell" Backdoor
Threat actors are leveraging malvertising campaigns to distribute a previously unseen backdoor dubbed "MadMxShell." This campaign targets IT security and network administration teams by spoofing legitimate IP scanner software websites.
Key Details:
Technical Analysis:
Shift in Attack Tactics: Vulnerability Exploitation on the Rise
Phishing Declines, Zero-Days Soar
A recent report by Mandiant indicates a significant shift in cyberattacker tactics. Vulnerability exploitation has overtaken phishing as the primary method for gaining initial network access. Researchers found that in 2023, vulnerabilities were exploited in 38% of intrusions, a 6% increase over 2022. Phishing attempts, while still the second most common initial infection vector, dropped from 22% to 17% over the same period.
The report also highlights a sharp rise in the exploitation of zero-day vulnerabilities, previously unknown flaws in software, by 56% year-over-year. Chinese cyber espionage groups were found to be the most active users of zero-days, while financially motivated attackers continue to leverage these vulnerabilities to steal financial data.
Key Takeaways
Ransomware on the Rise: More Groups, More Victims
Ransomware is back with a vengeance. A GRIT report shows a worrying 20% increase in victims in Q1 2024 compared to the same period last year. This coincides with a surge in active ransomware groups, jumping from 29 to 45 (a 55% increase). BlackBasta and Play are new major players, joining the persistent LockBit.
Brutality and Distribution Mark New Era
These groups are targeting critical infrastructure like hospitals, highlighting a ruthless shift in tactics. Additionally, RaaS groups are recruiting affiliates, creating a more distributed threat landscape.
Key Takeaways:
Phishing Attacks on the Rise: AI-powered Threat Landscape
A recent report by AI-ThreatLabz highlights a significant increase in phishing attacks, with a staggering 58% rise observed in 2024 compared to the previous year. This surge is attributed to the growing adoption of Artificial Intelligence (AI) by attackers, enabling them to craft highly personalized and believable phishing campaigns.
Key Takeaways
FBI PSA on Social Engineering techniques - Create by ChatGPT
This is a timely article I put together for internal distribution as part of a Security Awareness program. Feel free to grab and use as part of your Security Awareness program.
Link: https://www.ic3.gov/Media/Y2024/PSA240411
The Federal Bureau of Investigation (FBI) has issued an alert regarding an increase in social engineering attacks that cybercriminals are using to compromise personal and corporate accounts. The techniques identified include impersonating employees, SIM swap attacks, call forwarding, simultaneous ringing, and phishing—each designed to manipulate victims into divulging sensitive information.
Social Engineering Techniques: * Employee Impersonation: Cybercriminals pose as company employees to trick IT or helpdesk staff into granting them network access. * SIM Swapping: Attackers deceive mobile carriers to transfer a victim’s phone number to a device they control, potentially bypassing multi-factor authentication to access financial and other secure accounts. * Call Forwarding and Simultaneous Ring: This method involves forwarding a victim’s calls to the attacker’s number, again potentially circumventing multi-factor authentication. * Phishing: Phishing emails mimic legitimate institutions to solicit sensitive information, such as login credentials and personal identification numbers.
Protection Recommendations: * Personal Security Measures: * Avoid responding to unsolicited requests for personal information. * Set unique passwords for voicemail and mobile accounts. * Contact your mobile carrier to block unauthorized SIM changes and call forwarding. * Regularly check your account activity for any unauthorized changes. * Use complex passwords and avoid posting personal data online. * Corporate Security Measures: * Pay attention to email banners for messages coming from external sources. * Use non-email based multi-factor authentication. * Report any phishing and social engineering attempts.
Reporting and Additional Actions: If you believe you are a victim of a social engineering attack:
This alert underscores the need for heightened vigilance and proactive measures to safeguard against sophisticated social engineering tactics that are increasingly prevalent in today’s digital landscape. We thank you for helping keep [COMPANY] secure.
AI security and healthcare - created by ChatGPT
This is an article I put together for internal communication on my companies intranet. I actually put two different articles together. Both are along the same lines just written different. I would love feedback on anything I may have missed. Otherwise feel free to use this as part of your company’s internal communication. This was most written by ChatGPT.
IntroductionIn the rapidly evolving world of healthcare, Artificial Intelligence (AI) has emerged as a beacon of hope and innovation. From improving patient outcomes to optimizing operational efficiencies, AI's potential is undeniable. However, as we integrate these powerful tools into our daily operations, it's imperative to approach AI with a blend of enthusiasm and caution.
The Power of AI in HealthcareAI's application within healthcare spans from predictive analytics in patient care to automating administrative tasks, allowing healthcare professionals to focus on what they do best—caring for patients. AI algorithms can analyze vast amounts of data to predict patient deterioration or optimize treatment plans. Additionally, AI-driven chatbots can enhance patient engagement and support, providing timely information and assistance.
Ethical Considerations and Patient PrivacyWhile AI can significantly improve efficiency and patient care, its implementation in healthcare comes with profound ethical implications, especially concerning patient privacy and data security. As stewards of sensitive health information, it's our collective responsibility to ensure that AI tools are used ethically and in compliance with all applicable laws and regulations, such as HIPAA.
Cybersecurity ImplicationsThe integration of AI into healthcare systems increases the complexity of our cybersecurity landscape. AI can both bolster our cybersecurity defenses and represent a novel vector for cyber threats. Therefore, a proactive and informed cybersecurity approach is essential.
Looking AheadAs we journey forward, integrating AI into our healthcare practices, let us do so with a vigilant eye on the ethical, privacy, and security implications. By fostering a culture of responsible AI use, we not only protect our patients and their data but also contribute to the advancement of healthcare, making it more accessible, efficient, and effective for all.
ConclusionThe integration of AI in healthcare represents a frontier of endless possibilities. Yet, as we harness these technologies, we must navigate this terrain thoughtfully and responsibly, ensuring that we remain steadfast in our commitment to patient care, privacy, and security. Together, we can create a future where AI empowers us to deliver better healthcare than ever before.
Exploring phishing March 2024
Tax Season Phishing Campaigns - Targeting New Tactics
Microsoft Threat Intelligence (MSTI) has uncovered a rise in phishing campaigns targeting taxpayers during the tax season. These campaigns leverage social engineering tactics to trick victims into revealing sensitive information or clicking on malicious links.
Targets and Techniques:
Iranian Threat Actor TA450 Shifts Tactics in Latest Campaign
Summary: A recent campaign by Iranian threat actor TA450 has been detected leveraging a new technique.
Previous Tactics: Historically, TA450 has targeted Israeli users via email campaigns containing malicious links directly embedded within the email body. These links typically led to file-sharing sites that, when clicked, downloaded remote access trojans (RATs).
New Development: Proofpoint researchers observed a shift in TA450's tactics. The latest campaign utilizes PDF attachments containing malicious links. The social engineering lure involves emails disguised as pay slips, likely designed to trick victims into opening the attachments.
Security Implications: This new delivery method makes TA450's emails appear more legitimate, potentially increasing the success rate of these phishing attacks. Security professionals should be aware of this evolving technique and update email security filters accordingly.
New Trojan: VCURMS Discovered by Fortinet
Fortinet researchers have uncovered a new trojan named VCURMS. This trojan leverages obfuscation techniques to bypass traditional antivirus detection and establish persistence on compromised systems.
VCURMS Capabilities:
Delivery Method:
VCURMS primarily spreads through phishing campaigns. Attackers target victims with emails containing malicious attachments. Once a user opens the attachment, the trojan infects the system.
Zscaler ThreatLabz Releases New Report on AI Security Trends and Risks
A recent Zscaler report, "New AI Insights: Exploring Key AI Trends and Risks ThreatLabz 2024 AI Security Report," delves into the evolving landscape of AI security. Key takeaways for security professionals include:
Exploring the newsletter below - Image created with the help of ChatGPT
This is a security newsletter I’ve put together as part of our security awareness program. This leans more towards healthcare and news items that are more general in nature. I’ll have a more technical focused newsletter later this week that’s targeted at security teams. Feel free to take this newsletter and use it internally as part of your security awareness program.
The Great Zoom-Skype-Google Masquerade: Beware of digital doppelgängers. Fake Zoom, Skype, and Google Meet sites are the latest traps set by cyber tricksters. These spoofed meetings can trick users into downloading harmful software that compromises their computer. Ensure you’re clicking on the real deal to keep those malware masqueraders at bay. Beware of QR codes that will try to steal credentials as part of this type of attack.
Beware of fake websites mimicking popular brands!: Typosquatting attacks are surging, and cybercriminals are exploiting user mistakes to steal login credentials and spread malware. Typosquatting is where an attacker registers a similar domain to one a person is familiar with. This increases the chance a malicious link will be clicked.
Small Businesses Hit Hard by Cybercrime: Some social engineering techniques highlighted in the article include: malicious ads; attackers starting a conversation before trying to get the person to take an action; and the move to PDF attachments. These types of attacks help launch ransomware against small businesses.
Beware of AI-Driven Voice Cloning in Vishing Scams: The Better Business Bureau (BBB) has issued a warning about the rise of voice phishing (vishing) scams utilizing AI-driven voice cloning technology. Scammers can now mimic voices convincingly with just a small audio sample, leading to fraudulent requests for money transfers or sensitive information. Tips to Stay Safe:
Update on Change Healthcare Cyberattack Recovery: Change Healthcare is on track to bring its systems back online by mid-March following a cyberattack that has caused widespread disruption since February 21. The cyberattack has significantly affected healthcare operations nationwide, with providers facing difficulties in payment processing, insurance verification, and clinical data exchange. This highlights why security awareness is so important. Identifying and reporting security threats to the organization is the responsibility of everyone.
Beware of Tax Season Scams Targeting SMBs and Self-Employed Individuals: As tax season unfolds, a new scam has surfaced targeting small business owners and self-employed individuals. Scammers are using emails to lure victims to a fraudulent site, claiming to offer IRS EIN/Federal tax ID number applications. However, this service is free through the IRS, and the scam site is designed to steal personal information, including social security numbers, creating a significant risk for identity theft and fraud. A Microsoft report identifies green card holders, small business owners, new taxpayers under 25, and older taxpayers over 60 as prime targets for these scams. Check Point has some example phishes in their tax scam article.
Apple Users Beware: "MFA Bombing" Phishing Attacks on the Rise: Leveraging Apple's password reset system attackers can bombard users with password reset prompts. If a person clicks "allow" on one of the prompts, the attackers can gain access to the user's account. The attackers may also call the person pretending to be Apple support. Some ways to protect yourself from this attack include not clicking on any of the prompts and contacting Apple directly if you receive a suspicious call.
This is a blog post I plan to submit to my companies intranet site as part of security awareness program. I wanted to post this here in case others would like to use it for their own internal programs. This was largely generated with ChatGPT. I have gone through and made my own edits and adjustments.
In today’s interconnected world, passwords are the gatekeepers to our digital existence. Whether it’s accessing your email, online banking, or social media accounts, a strong password is your first line of defense against cyber threats. In this blog post, we’ll explore essential practices for creating and managing secure passwords.
The Key to Your Account: Guard Your Passwords Your passwords are like the keys to your virtual kingdom. Treat them with utmost care and never share them with anyone. Remember, a password shared is a vulnerability exposed. Whether it’s your Netflix account or your corporate email, keep those keys close and confidential.
Password managers are great for both storing and creating passwords. Password managers generate and store complex, unique passwords for each of your accounts. Instead of remembering dozens (or even hundreds) of passwords, you only need to remember one master password. Password managers can auto-fill your login information on websites and apps, streamlining the login process. Below are some recommended password managers for personal use:
LastPass Features: LastPass offers a user-friendly interface, secure password storage, and strong password generation. It's accessible across various devices and browsers, making it convenient for users who need to manage their passwords on the go. LastPass also features secure sharing options, allowing users to safely share login information with trusted individuals.
1Password Features: 1Password is known for its strong security measures, including a unique security key for encryption, making it nearly impossible for unauthorized users to access your vault. It also offers a Travel Mode, which temporarily removes sensitive data from your devices when crossing borders. 1Password's user interface is clean and intuitive, with excellent organization features for managing passwords and documents.
Dashlane Features: Dashlane provides a robust set of features, including password management, a secure digital wallet, and a VPN for safe browsing. Its password changer feature can automatically update passwords on various sites, enhancing security with minimal user effort. Dashlane is suitable for individuals and businesses looking for a comprehensive security solution.
Bitwarden Features: Bitwarden stands out for being open-source, offering transparency in its security practices. It provides a secure vault for passwords and sensitive information, with options for self-hosting for users who prefer complete control over their data storage. Bitwarden's free version is feature-rich, making it an excellent choice for budget-conscious users seeking reliable security.
Keeper Features: Keeper is noted for its high-level security features, including biometric logins and a secure messaging vault. It offers flexible storage options for passwords, files, and private client data, making it a suitable option for both personal and professional use. Keeper also includes breach monitoring to alert users of potential security threats.
Browsers Browsers can be a good place to store passwords for users seeking convenience and simplicity, offering several features that facilitate better password practices. However, for those who require more robust security features, flexibility, and functionality, a dedicated password manager might be a more suitable option. As with any security tool, the best choice depends on your specific needs, habits, and the level of risk you're comfortable with.
Crafting Strong and Memorable Passwords Creating strong and memorable passwords is essential, especially for securing critical accounts like those for work, email, and finances. Here's how to craft passwords that are both robust and easy to remember:
Ensure Uniqueness for Each Account Distinguish your work and personal passwords to safeguard against potential breaches. Each account should have a unique password to prevent a security issue in one from affecting others. Websites like Have I Been Pwned offer valuable insights by letting you check if your email has been involved in any breaches, underscoring the importance of uniqueness.
My personal email shows up in the LinkedIn breach
Opt for Passphrases with Special Characters Early in my career, I learned the effectiveness of using multi-word passphrases with special characters interspersed. This strategy not only makes passwords more difficult for attackers to guess or crack but also helps in keeping them memorable. Despite witnessing 22-character passwords being compromised, it's clear that security isn't solely about length. Crafting your password—a mix of length, complexity, and unpredictability—is key.
Avoid common or popular phrases. Instead, draw inspiration from less obvious sources, like obscure quotes or unique phrases from your favorite media. This approach significantly lowers the risk of your password being easily cracked while ensuring it remains memorable to you.
By focusing on creating unique, complex passphrases that are personal and meaningful, you can significantly enhance the security of your online accounts while maintaining ease of recall.
Conclusion By adopting recommended practices—treating passwords as keys to our digital domains, leveraging password managers for enhanced security, and crafting strong, memorable passwords—we fortify our digital presence against unauthorized access.
Password managers like LastPass, 1Password, Dashlane, Bitwarden, and Keeper offer robust protection. For added simplicity, browser-stored passwords can also serve as a basic defense. Utilizing unique passphrases enriched with special characters further strengthens our security posture, as echoed by services like Have I Been Pwned, which emphasize the importance of password uniqueness.
In conclusion, secure password practices are not just about technical security; they're about empowering ourselves to navigate the digital space confidently and securely. Let's prioritize our digital safety by embracing these practices, ensuring our online presence is shielded from potential threats.
It’s dark on the “dark web”
I’m still adjusting to my new role as Sr Specialist of Security Awareness and Training at Acadia Healthcare, so things have gotten behind on this site. Behind the scenes I’m still recording and editing episodes and I’ve got some really good ones coming up. I still want to post content on this site and try to get one blog post out a week. I have some ideas to do that with the time allotted and one of those ideas is AI. This article was entirely written by AI.
I would love feedback in the comments below if you liked or didn’t like and if you feel there are any corrections that need to be made. I have read over it and thought it did a pretty good job but my experience is limited on the “Dark Web.”
The dark web is often portrayed as a shadowy underworld of the internet, a place where anonymity reigns supreme and illicit activities thrive. This portrayal has been popularized by media and folklore, painting a picture of a digital "no-man's-land" inaccessible to the average user and law enforcement alike. However, upon closer examination, the assertion that the "dark web doesn't exist" can be a provocative way to challenge misconceptions and misunderstandings about what the dark web truly is and what it represents.
Understanding the Internet's LayersTo debunk the myth, it's essential to understand the internet's structure, which is more nuanced than a binary division between the "surface web" and the "dark web." The internet is better described in layers, with the surface web comprising websites indexed by search engines. Beneath this lies the deep web, which contains unindexed content like private databases, academic journals, and secure personal accounts. The dark web is a small portion of the deep web, accessible only through specific, anonymizing networks like Tor.
The Dark Web: A Concept, Not a PlaceOne critical argument against the dark web's mythical status is the recognition of it as a concept rather than a physical or digital "place." The dark web refers to the use of anonymized networks to access content and services that are either intentionally hidden from the surface web or require specific software to access for privacy and security reasons. It is not a separate internet but part of the broader, intricate ecosystem that constitutes the web.
The Role of Anonymity and PrivacyThe dark web's existence is often justified by its role in protecting anonymity and privacy. Activists, whistleblowers, and those under oppressive regimes use it to communicate safely. This aspect challenges the notion that the dark web is solely a haven for illegal activities. It serves a crucial function in facilitating secure communication, underscoring that its existence is not inherently malevolent but rather a tool that can be used for good or ill.
Misconceptions and ExaggerationsThe sensationalization of the dark web contributes to its mythical status. Stories of nefarious activities and marketplaces often overshadow the less dramatic, yet equally important, uses of the dark web for privacy and security. By challenging the existence of the dark web as a singular, monolithic entity, we can shed light on the realities of digital anonymity and its implications for society.
ConclusionThe assertion that "the dark web doesn't exist" serves as a starting point for a more nuanced discussion about the internet's complexities and the importance of privacy and anonymity online. It invites us to reconsider our preconceptions and understand the dark web not as a hidden den of iniquity but as a component of the internet that reflects the diverse needs and ethical considerations of its users. In demystifying the dark web, we confront not just the technical realities of the internet, but also the broader questions of rights, freedoms, and responsibilities in the digital age.
Exploring the job market with my handy briefcase
A job search is workBelow you will find several log entries from me as I recently went through a job search. I wanted to do this to highlight how things have changed and show that even for someone who has several years of experience it’s tough. I started my search around the end of November and had it end in early March. The holiday’s certainly slowed things down but it still took a good three solid months. Getting hired at the end of a year is a rare thing because companies aren’t looking to add more to their books. Their focus is to close out the books and look as good as possible from a financial standpoint.
A lot more job posting went up at the beginning of the year and things seemed to pick up from a reach out and interviewing perspective. The job I eventually accepted had their posting up in early December but didn’t start talking to me until the beginning of the year.
I cater my resume to the role and despite all that I still got A LOT of rejection letters. In fact I just got another one yesterday. Prepare for baseball type of stats where it’s normal to bat .300 instead of .800. I did notice that it’s less likely a company will talk to you if their not in their city. Through my network I heard this quite a bit despite my willingness to relocate to certain parts of the country. Talking to some recruiters it was certainly a weird market with a lot of companies wanting to be back in office and with the layoffs last year it was harder to stand out.
Another factor is my background. I have a broad background and have successfully implemented programs in multiple disciplines. I have confidence I can adapt my skillset to any role. I’ve done it in just about every job I’ve had. Unfortunately, a lot of hiring managers are looking for a specific skillset and only that skillset. Recruiters are another layer where they often are just looking for keywords in a resume. I also found that AI was starting to play a part. I had a screening call that utilized AI. I tried to better understand how that worked on the backend but couldn’t find a lot of materials. I’d like to see how AI is impacting candidates both positively or negatively.
Last year I took some time to reflect on what I really wanted to do and where my background and skillset could really be useful. I found that security awareness was something I’ve done at all my previous jobs and that there were companies hiring and paying well enough for the role. That’s where I focused my job search and that’s where I’ve ended up. I’m excited for what’s ahead. Below is my journey to that role.
LogEntry 1: Willo and one-way video interviewing. This was an interesting experience because I was given a set of questions and asked to record my responses. I’ve never done this before and found it interesting. I had three minutes to record. I could save and continue or re-record. There was only one question I needed to re-record multiple times either because I ran out of time or screwed up. I thought it was a great way to do a screening. I also loved that the screening involved behavioral questions. Which I’m a big proponent of using.
Entry 2 (five days later): To this point I’ve applied to 16 roles: I’ve got one early stage interview setup; I’ve had one one-way video screening; and two, “we think you’re a great candidate but we don’t want to talk to you.” The last one I know one of them was due to pay because they reposted and took out the top part of the salary range and the other probably my resume. The one early stage interview I have is due to knowing someone at the company who put me in for a role. Which is why I always recommend networking to find a job.
I haven’t had to do a job search where I submitted blindly to companies for over 10 years. This is an experiment for me. Is my resume just not up to snuff anymore or is there some other factor. A couple factors I’m keeping in mind is that it’s the end of the year which means deadlines and goals. People outside of government work are usually pretty busy trying to wrap up the year and so hiring takes a back seat. Financially, people aren’t looking to add budget to their team at the end of the year.
It’s also been a tougher job market with the economy being down. I’ve talked to recruiters and they say it’s been a slow weird end of the year. There’s more competition for me in the job market so I’ll get less looks or get looked over. I’m also being more picky about the opportunities I apply for because I feel like I know what I want to do. My experience can be an issue because it’s a little all over the place. The closest I came to niching was application security but two years into that role I was promoted to manager over security engineers, pentesters, and application security.
Which brings me back to my resume. When I redid it over 10 years ago it was due to not getting call backs. It ended up taking 15 months to find a new job. Redoing it to the current format increased my interview opportunities by 50%. My resume format may be dated. My theory is that my resume may work for hiring managers but not for recruiters or talent acquisition people because they’re not in the field. They’re looking for those specific words and probably something more eye appealing. I’ve already started experimenting with different formats and I’ll provide the results here when it’s completed.
Entry 3 (Star Date -299052.05): The rejection emails have come in. I got two this morning and I expect more if I haven’t been reached out to by a recruiter. This means my resume is a problem and I need to work on that. I watched this talk from BSides San Francisco 2023 by Zach Strong on Hacking the Hiring Process. I think I need to simplify my resume and get it back down to under two pages. My master resume is currently at five pages. When I customize it to the job role it get’s down to four pages but I think I still need to cut that in half. Next role that I’m interested in, I’ll have to be brutal with my cuts. The last few I have added a new section called, “Applicable Qualifications” or “Applicable Experience” to try and highlight what makes me a potential candidate. We’ll see if that helps.
Ultimately, networking is still the best way to get in front of the hiring manager. I’ve gotten in front of one. Had the interview and then haven’t heard from them in about a week. This is unfortunately typical and disappointing. I’ve had enough of these that the behavior doesn’t bother me as much anymore. I’ve probably eliminated myself but it’d still be nice to be told that and given any feedback on what I’m lacking.
Entry 4 (some time later): More rejection letters have come in. I’ve gotten my resume down to two pages. I’m not sure the format is great but I like it and I’d like an organization that would want that kind of format. That’s me being naïve though and I’ll end up changing it. I want to make small tweaks just to see if I start getting more screening calls.
I did recently talk to someone else doing a job search and they said it was tough. They had read an article or something on reddit where someone had applied to 500 jobs. Got 20 call backs and two offers. I think it highlights the current state of the job market. It’s tough but I feel like I’m starting to see more posts go up and as people start ramping up for 2024.
To be continued…
Entry 5 (later): I got the rejection email from the place that had me do a one-way interview. I noticed it mentioned AI in the email and now I’m curious what that actually means for the hiring process.
Ignyte AI is the tool that was used for the screening. Looking it up there’s not a lot of information on it other than marketing material. Definitely something to explore in the future. Here are some links I found on it.
https://www.ignyteai.com/
https://huntscanlon.com/recruiting-platform-ignyte-ai-launches/
Entry 6 (Happy New Year!): I got a screening call setup for a position I applied for a few weeks ago. Hiring slows down during the holiday pretty significantly. Either the talent acquisition people are out or the hiring people are out or both. I’m hoping thinks pickup thought I expect I’ll continue to get rejection letters.
Entry 7 (busy): I’ve been focusing on getting podcast and blog posts produced and published so this has gone by the wayside a little bit. Screening call and interview with the hiring manager went well. I am setup for another interview with a panel of people and then a decision will be made. I have gotten more rejection letters, but I also recorded and published a really interesting podcast with Erin Barry from Code Red Partners.
I learned a couple things from the conversation. As I suspected it’s a weird time to be looking for a job. Networking is still king but there’s also some really crappy things that organizations do. They’ll put up a posting just to see what the market. There’s also people just looking for keyword searches and not getting anywhere near your resume. One of the key points she made was not getting down on yourself as part of the process. There’s a lot of factors that go into an opening that we just don’t see.
As part of another recording session I had, the guest pointed out to me that my LinkedIn page needed some work. I followed their recommendation around adding a banner and cleaning some other stuff up. Today I got a call from a recruiter for a director cybersecurity position in my area. Not sure it’s a great fit but the resume is off and we’ll see if we ever hear anything back.
Entry 8 (end of January): I just had a final interview for the one position that has progressed significantly. I’m still in for another position that I started the conversation in early December but it’s been very quiet. Talking with the hiring manager it sounds like a lot of internal politics and a question about remote work. The position is unfortunately up north and a region that is off limits for my family. I am still looking at job postings and applying to the ones I find interesting. I have also reached out to a recruiter about one position but haven’t heard back from them.
I like the idea of reaching out to recruiters and feel I should have done it before but I imagine some of them may not get back to me because they’re busy. I have seen encouraging signs though for the market with recruiters seeing there’s more jobs being posted. There are also more people getting back into the job market hunt so I would expect it’s still a competitive market. The place of my final interview is local. I have an advantage there because the discussion around relocation won’t be necessary.
Entry 9 (beginning of February): Shortly after my final interview for one position, I had another one start with a screening. That has progressed to another panel interview that I’m still waiting to hear back on. I still have not heard anything from the one I had a final interview on. I’m okay with that because I’m still in process on a couple other things and I continue to find security awareness positions being posted. It seems to be a position that a lot more companies are looking at and that hopefully means I can land in one. I haven’t really talked about it here but security awareness is where I want to head with my career. several years ago it was an addon to GRC or other roles. I did it as a passionate project but that were was never the thought of it being a full time gig. I’m happy to see this because I have the experience, knowledge, and desire to be successful in this discipline. It’s now just a matter of convincing someone else I’m right for the job.
I will say the waiting is a bit frustration. Even if things are being lined up a yes or not would be fine with me because it allows me to adjust and something I’ll talk about more in a future blog post. I did have some progression on the first position where I’ve had some conversations. That’s actually shifted to a discussion on being a contractor and would significantly help me with continuing down the self-employed path.
One other item I want to talk about is using AI to prepare for an interview. I took the job description and information I got from the recruiter and had ChatGPT create me some interview questions. I then wrote the questions on one side of a notecard and my answers on the other. Then I practiced the question and answering the question out loud. This is something I’ve always done for interviews but AI helped me create the questions a lot easier and made them applicable to the questions I get accessed. I had a technical assessment on the panel interview. I suck at technical questions in interviews. I always overthink them. I didn’t do great but the idea that came from that experience was to use AI practice for the technical assessment in an interview.
Entry 10 (later that week): Got a call this morning for one job and my salary requirements. Also got an email about not moving forward in another interview process because of the competitive talent pool. I’ll address both below.
Salary requirements are always an interesting thing for me. I am not a person that is motivated by money. I’ve reached all my financial goals and so the range I’m in now. I’ve been told I can go make 200k easily and have several peers that do. I don’t need that much money. The problem with telling people that though is that I get the sense they feel bad and then don’t give me the work I need to stay busy. So I’m in this weird balancing act of taking less money or making my requirements higher. I’m always willing to negotiate lower if it’s a position I’m interested in. I’m also very likely overthinking it.
It’s tough getting a notice that I won’t be moving on in a process or another candidate was selected. I got no feedback other than it was a competitive pool of candidates which I have no doubt there are. I was told salary was not a factor in the decision. This is the part where I need to remind myself that I may have interviewed well but the decision could have been any number of factors out of my control. Someone may have been referred. There may have been an internal candidate preferred. The process may have not been set up to allow me to shine properly. It could have been any number of things. I would have still liked to get more feedback because I want to improve but I’ve said the same thing to other candidates. I had multiple people and liked both and one just edged out the other for whatever reason. The one thing I knew I could have been better on was the technical assessment. I have played around with AI a bit and I think it would be very useful for practice for a technical assessment. I will have a future blog post on the topic.
Entry 11 (last one): I did get a job offer the next week and I’ve started the onboarding process, which is why I haven’t updated this post until now. I start next Monday and this post will be up shortly after I start. The onboarding process has been good. I think a lot of organizations have embraced automations and using platforms to onboard people. This is a good thing and it seems like I’m getting a lot of the stuff I need lined up ahead of time. I’ve also got my first day orientation schedule which is nice to have and know ahead of time.
I’m excited for this opportunity. I’ll be focusing on security awareness for my career which is a role that wasn’t around a few years ago. Organizations seem to be taking security awareness a lot more seriously instead of it being just a checkbox. I’ve been doing security awareness at organizations as a passion project for years, so it’s nice to have a role where I can just focus on that. I’ll be writing more about it more in other blog posts and probably talking about it on the podcast. While I have a full-time job now, I do plan to continue to producing content on this site.
Log log
This is a log of changes to the site over the last week.
Podcast posts:
Navigating the Currents of Open Source Intelligence: Insights From the Field - Micah Hoffman and Griffin Glynn join me to discuss OSINT.
ShowMeCon: Bypassing MFA with Shameer Amir - A ShowMeCon sponsored episode on bypassing MFA
Blog posts:
Charting a New Course Into Security Awareness at Acadia Healthcare - Thoughts on my new role
Other:
The podcast is now available on Spotify
Subscribe Sign up with your email address to receive news and updates.
Email Address Sign Up We respect your privacy.
Thank you!
Exploring Information Security now available on Spotify!
Exploring Information Security is now on Spotify.
If you have other preferred platforms you listen to podcasts on let me know and I’ll submit the RSS feed there.
Security explorer heading into the security awareness field - Created by ChatGPT
I have started a position as a Senior Specialist, Security Awareness and Training at Acadia Healthcare. I’m excited for this opportunity because it’s a role that’s only more recently started to get some traction. I’ve been doing security awareness activities at previous organizations as a part-time thing. I’m excited to get the opportunity to really focus on security awareness training. It’s something that has been seen as a checkbox for a lot of organizations. I think it can be more than that. I think it can help build a security culture and foster a security mindset at an organization which result in a more secure organization.
I’ve been in a bit of a career transition the last 2-3 years. I’m not looking to get super technical. I’ve been in management and would probably be okay going back but I don’t play the political game as well as other. Reflecting over these last few years, I discovered that I enjoyed educating others. It’s actually something I wanted to do since high school but the only path I saw then was a high school teacher and I wasn’t really interested in leaving high school only to return shortly thereafter.
In the Navy I got the opportunity to go through instructor training and do some training while being an electronics technician. That led to me getting into the information technology field and eventually into security. At previous roles I’ve always either created content for distribution or presented internally. This past fall, I started looking for security awareness roles and found that several organizations were hiring for security awareness roles. This fit well with my desire to educate and where I was at in my career. I have a generalist background so I can speak to a variety of different fields within security.
I want to make security awareness interesting and impactful for an organization. Not just a checkbox. In my view I am here to foster and improve the security culture at the organization. To do that I’ll have to be creative and identify what engages people to think more about security. I’m excited for this challenge. I see people as the most complex systems in an organization.
I am going to continue to run Exploring Information Security (EIS) with a focus on security awareness. I believe this new role and EIS will compliment each other well. Next week I am planning to post my job search log. As part of the job search I decided to put in entries documenting my progress and thoughts during the hiring process. I wanted to show others that the hiring process is stressful, even for someone with 22+ years of IT experience. It’s also changed significantly since I first got in the job market and I wanted to highlight some of those changes as well.
Logs somewhere cold
This is a log of changes to the site over the last week.
New pages:
Zero Trust - Deep Dive - Getting deeper into Zero Trust
Podcast posts:
What cybersecurity tools every organization should have - Hacker Historian Mubix joins me to discuss useful tools for security
Blog posts:
Impressions from the 2024 Palmetto Cybersecurity Summit - Thoughts from last weeks conference
7 Tips and Best Practices for Threat Modeling - Some of the tips and best practices I do to make threat modeling efficient and effective
Leveraging AI to Prepare for an Interview - My experience and some ideas around using AI to prepare for an interview
Subscribe Sign up with your email address to receive news and updates.
Email Address Sign Up We respect your privacy.
Thank you!
ChatGPT V4 - Image by D koi
In today's rapidly evolving job market, Artificial Intelligence (AI) has become more than just a buzzword—it's a tool that can provide a competitive edge in various aspects of life, including job hunting and interview preparation. As interviews become increasingly sophisticated, candidates are seeking innovative ways to prepare and stand out. I’ve recently gone through a few different interview processes and as part of that I leveraged AI to help do research and prepare for my interviews. Here's how AI can be your ally in acing your next job interview.
Understand the Role and CompanyBefore you even start preparing for the questions, it's crucial to have a deep understanding of the role you're applying for and the company behind it. AI-powered tools can analyze job descriptions, company websites, and news articles to provide a comprehensive overview of what the company values in its employees and what skills and experiences are critical for the role. This information can help tailor your interview responses to align with the company's culture and needs.
Personalized Practice SessionsAI-driven interview preparation tools can simulate realistic interview scenarios tailored to the job you're applying for. These platforms use natural language processing to evaluate your answers, providing feedback on content, tone, clarity, and even body language in video-based practice sessions. This personalized feedback can help identify strengths to highlight and weaknesses to improve upon, making your preparation more focused and efficient.
I’ve taken the job description and my resume and put them into ChatGPT to help identify how my experience aligns with the role. I’ve also taken the job description and any other information about the interview I’ve been provided and asked ChatGPT to create practice questions. I then take those questions and practice saying out loud my responses. I found the interview questions to be pretty close to the real questions I got asked. The questions allowed me to think through how I would answer questions and lean on past experiences. While not an exact match it did afford me an opportunity to think through my experiences and apply those to similar questions.
If there is a technical aspect to the interview AI can be used to prepare by getting quizzed on technical questions. Unfortunately, I didn’t think of this use case until after I had already gone through an interview that had technical questions in it. I struggled through those questions and did not move one. Had I prepared using AI I would have been better prepared to answer those questions and a better shot at moving on.
Enhancing Your AnswersAI doesn't just stop at practice; it can also help refine your answers. Tools like GPT (Generative Pre-trained Transformer) can suggest ways to structure your responses more effectively or creatively. Input your basic answer, and AI can enhance it, ensuring you communicate your thoughts coherently and compellingly. However, it's essential to keep your answers authentic to your experiences and voice; use AI as a tool for improvement, not a crutch. It’s also very important to say the responses out loud to understand how the responses will come off. Sometimes what’s in our head doesn’t sound as good when it’s said out loud.
Final ThoughtsAs AI continues to transform the job market, its role in interview preparation is undeniable. By offering personalized feedback, and enhancing response, AI can be a valuable asset in your job search toolkit. However, it's important to remember that AI is a supplement, not a substitute, for genuine preparation. The goal is to use AI to enhance your authentic self, showcasing your skills, experiences, and personality in the best possible light.
Embrace AI as part of your interview preparation strategy, but keep the focus on your unique contributions and how you can add value to the company. With the right preparation and mindset, you can use AI not just to prepare for interviews but to excel in them.
This blog post created with the help of ChatGPT
Threat Modeling an application
In the ever-evolving landscape of cybersecurity, threat modeling emerges as a crucial practice that helps organizations identify, assess, and mitigate potential security threats. It's a proactive approach that focuses on understanding the assets that need protection, identifying what threats those assets might face, and defining measures to mitigate those threats. Here are some essential tips and best practices for effective threat modeling:
Start Early and Integrate ContinuouslyBegin threat modeling at the earliest stages of system design and continue to integrate it throughout the development lifecycle. Early integration helps in identifying potential security issues when they are easier and less costly to resolve. Studies has shown the fixing issues later in development or IT project are more costly.
A chart showing the cost of fixing a bug throughout the development lifecycle
Involve a Cross-Functional TeamThreat modeling should not be the sole responsibility of the security team. It requires a collaborative effort involving developers, operations, architects, and business stakeholders. Each group brings a unique perspective that contributes to a comprehensive understanding of the system and its potential vulnerabilities.
There are other benefits to threat modeling outside of security. It get’s everyone involved in the project on the same page. Often development and infrastructure teams can be at odds about what needs to be done to complete the project. Threat modeling is an opportunity to bring everyone together to better understand and clarify what needs to get done.
Watch for scope creepIdentify what is being discussed at the start of the session. This will help setup boundaries for the discussion. People will want to dive into are other topics adjacent to the project. While they may need to be discussed at some point now is the time to discuss what was defined in the scope. I often will tell people let’s setup another session or move the discussion to later in the meeting if there’s time. This will help the meeting run more smoothly and ensure the topic of discussion get’s threat modeled.
Keep the Attacker's Perspective SimpleThinking like an attacker can provide invaluable insights into potential vulnerabilities and attack vectors. Understand the capabilities, motives, and methods of potential attackers to better anticipate and counteract their actions. Not everyone has an attacker mindset. Most people in an organization are builders. We as attackers are looking to tear things down and break them.
This can take some getting used to for people. It may take multiple sessions before they start getting into the attacker mindset. It’s a lot like exercise. It takes time to build up those security muscles but once it happens it will make the meeting run a lot more smoother. I often start with simple attacks such as offering someone a million dollars for their access.
Most people are uncomfortable in a group setting with silence. The facilitator of the session will need to get comfortable with silence. After a period of time someone will speak up with an idea. Don’t shoot down all ideas. Write them down like you would a brainstorming session. This will help encourage more people to speak up with their ideas.
threat modeling discussions are chaosIf it feels like chaos you’re likely doing it right. As you go through the session you may feel like you’re taking a step back and adding things to the diagram or the security profile. That’s okay. Keep your eraser tool handy because you may need to adjust different things on the diagram. I’ve been in sessions that I thought were going to take 20 minutes and they ended up taking three hours.
Meeting notes and action notesIdentify someone to help take notes. This will with more thoroughly document the meeting. Governance Risk and Compliance (GRC) folks are great at this. After the meeting ask for the notes to compare with your own. Virtual meetings can be recorded for later viewing and ensuring notes are complete.
After the meeting send the meeting notes, a picture or screenshot of the diagram, and action items. This will help document the meeting and allow anyone to make corrections on the notes. Action items are important for any follow up items that need to be addressed. Make sure to identify a person to follow up with and not a group. Also, it doesn’t hurt to document these in a central repository that everyone can access.
ConclusionThreat modeling is an essential practice in the toolkit of cybersecurity professionals. Threat modeling sessions can often feel like chaos and that’s okay. Make sure to start early and integrate into development and IT projects. Involve anyone that has work to be done as part of the process. Watch for scope creep and offer to set up another time to discuss. Use silence and keep the attacks simple to get people engaged in the conversation. Finally, remember to document each discussion, assign action items, and give people the opportunity to make corrections on the topic discussed.
Threat modeling is one of the low cost and most effective tools in your organization. These tips and best practices will ensure that threat modeling being performed at an organization will be efficient and effective. Leave a comment below if you have any tips or best practices for threat modeling.
Subscribe Sign up with your email address to receive news and updates.
Email Address Sign Up We respect your privacy.
Thank you!
The five stages of cybersecurity grief from Mathieu Gorge at the 2024 Palmetto Cybersecurity Summit
Last week I had the pleasure of attending the 2024 Palmetto Cybersecurity Summit in Columbia, SC. It was a great conference with a good venue and really great speakers. The keynote speakers brought a really great insight and of course the hot topics was artificial intelligence (AI). I’m hoping to attend again next year!
Prior to the conference I presented at ColaSec which is a local cybersecurity user group that I helped start about 10 years ago. I gave my threat modeling talk that I presented at the conference the next day. I like using ColaSec as a first run for my talks because I get a lot of really great feedback to refine the talk. You can watch the talk on ColaSec’s YouTube page. I adjusted the acronyms section and made some other minor adjustments to make the talk flow better. That helped for the conference the next day because I realized I had 10 less minutes for my presentation due to a reading error.
What I’m really excited about for this years conference is doing a demo of a live threat modeling session. I have about 20-25 mins of content and then we get into the demo. I like it because I want people to get a feel for how a threat modeling session should flow. I am planning to switch up the demo for each talk so that each version is a little different.
One of the things I rate conferences on is the drinks and food. I’m happy to report that the conference got an A in both regards. They had tea which is great because I’m not a coffee drinkers and the food was pretty good. Sometimes you go to a conference and the food is just meh or in a box. This was not the case for this conference. The other thing to call out is the chairs. Big comfy adjustable chairs. You could spend all day in those chairs.
The keynotes were really great. Mathieu Gorge talked about cybersecurity from a broader global level and the 5 Pillars of Security Framework. The picture above is the five stages of cybersecurity grief. William MacMillian was the former Chief Security Information Officer (CISO) at the Central Intelligence Agency (CIA) and he talked about his experience taking over there right before Solarwinds came out. He also talked about platform centric vs best-in-breed and how platform can provide simplicity to security teams that live in a world of complexity. Both provided some different perspectives and insights on the cybersecurity landscape and dropped some thought provoking ideas.
The majority of talks I attended were around AI. Before I get to that though I also went to Michael Holcomb’s talk on industrial control systems (ICS/OT). He gave some really good insights but more impressive he put together free ICS/OT courses on YouTube for people looking to get into the ICS/OT space.
The second day was filled with talks on AI. That will be a thing throughout this year and potentially for the next 2-3 years. I love that it’s something new to learn. A lot of the conferences I’ve attended in the last few years haven’t really provided me with the opportunity of learning new things. A lot of the talks just confirmed my own ideas and thoughts around security topics. Nothing really challenged those ideas either. There is value in confirming my knowledge and experiences but I want to continue to learn. AI is that current topic.
Dr. Sybil Rosado talked about the social engineering aspects of AI. While she talked about some of the malicious uses of AI she was a big proponent of using AI and learning how to work with it. She’s a professor at Benedict College in Columbia, SC, and has seen students using it. She actually likes that it’s making the writing better. Dr. Donnie Wendt talked about deepfakes and how they’re playing a role in the world today. It’s super easy to use and get started with. My own thought is that deepfakes are a great way to improve a security awareness program simply by talking about it and showing some examples. Plus there are already attacks where someone is using AI to imitate a voice and ask for money to be sent. Finally, Tom Scott talked about managing your security program with AI. One nugget that really stuck with me was that AI does not remember your interaction in a new chat. To continue to train it you need to keep the same chat.
The conference was a really great start to the year for conferences. I learned some new things, got to meet some new people, and catch up with some people I haven’t seen in a while. I’d definitely recommend checking it out for next year. Talking to one of the organizers it sounds like it’s going to get even bigger.
Logs somewhere warm
This is a log of changes to the site over the last week.
New pages:
Resources for Threat Modeling - A page I put together for my talk on threat modeling
Content From Threat Modeling Conference Talks - A place where I will drop videos and slides of my talks from my threat modeling talk
Podcast posts:
What is a Canary? - My conversation with Tyron Kemp of Thinkst Canary on canaries
ShowMeCon: Bypassing MFA with Brandon Potter - A sponsored podcast episode by ShowMeCon on bypassing MFA
Blog posts:
Tools and Resources for Effective Threat Modeling - I share tools and resources for threat modeling
Threat Modeling at BSides Nashville 2024 - I will be at BSides Nashville May 11, 2024, to give my threat modeling talk
How to Become a Cybersecurity Kevin Bacon - I talk about my tips and experiences networking in the infosec community
Subscribe Sign up with your email address to receive news and updates.
Email Address Sign Up We respect your privacy.
Thank you!
Be a cybersecurity Kevin Bacon - Image created with the help of ChatGPT
The Six Degrees of Kevin Bacon proposes that anyone in the Hollywood film industry is linked to Kevin Bacon within six steps. I’ve somehow had the title applied to me by a few different people. A large part of that is the networking I’ve done in the industry. I’ve hung out and talked to a lot of people. I don’t know everyone in the industry but I have meet people for the first time and we’ve known similar people. In this post I want to cover the networking that may have put me in the same breadth as Mr. Bacon.
My gamer tag is Jeditimmy
Attend ConferencesMy very first conference when I got into security was BSides Charleston in 2013. I went down with a buddy to the conference and meet a few people. One of those people that stood out was Evan Davison who goes by the hacker name Pentestfail. He gave a great talk on defense in-depth (this is the same talk at a ISSA local chapter). Evan and I would cross paths multiple times over the next 10 years. We would volunteer and get to know each other at BSides Augusta and the Social Engineering Village at DEF CON.
It’s not just about attending conferences it’s about getting involved and interacting with people. That could be meeting and talking to people, participating in capture the flag competitions, volunteering, or speaking. If you’re nervous about meeting people volunteering is a great way to meet and interact with people.
At one point I was going to 8-10 conferences a year. Most conferences were one day events within a a five hour driving distance so it was only a day or two. Still that’s a lot and it’s not something I’d necessarily recommend as I did get burned out and decided to tone back the conference attendance to three in 2019. There was also the cost. My company did always cover travel. I got maybe one a year. The rest was on my dime but I will say it was worth it for the connections I was able to build within the community.
Going to events allows for shared learning and job opportunities. I’ve learned a lot from just talking to people in the hallway at conferences. It’s a safe space for sharing interesting stories that you wouldn’t hear otherwise. If you’re the type that has a hard time starting a conversation, ask questions. People love talking about themselves and sharing their insights into the industry. I’ve had entire conversations with people who never asked a question or knew my name but I knew a ton about them and got some really great security stories.
Volunteer at events When I first started attending conferences I would volunteer. This forced me to meet people and as a bonus got me a free ticket into the conference. To get away from registration or door duty I started asking organizers if I could bring my camera and shoot pictures for them at the conference. This was great because I got to be more mobile and allowed me to meet and talk to a variety of people at the conference.
This also opened the door for invitations to work other conferences where my travel expenses were covered. If you have an interest see if it fits into helping out with a conference. I know several people volunteer just to do video for a conference. I’ve also seen people contribute by providing a quilt that was auctioned off. Find something you feel can contribute to the conference. Working the registration desk is also fine.
Volunteering helped me get a really great job in Nashville, TN. I had been traveling to BSides Nashville since it’s inception. There was an opening at a company one of the organizers was working at. I didn’t know that organizer really well but when they were asked about me for the position they responded that I showed up and did my job. Not necessarily a glowing endorsement but it helps and you never know who you’re going to interact with while volunteering.
Attend Local User GroupsLocal user groups are great if you’re looking to network within your own city. If there’s not one I’d recommend starting one up. It’s definitely a lot of work but very rewarding. When people ask me my greatest accomplishment I often will tell them it’s starting a local user group in Columbia, South Carolina, that has 20-25 regular attendees. That’s massive for a local user group by the way. If you need guidance on starting a local user group there’s a couple podcasts for that.
How to Start a Successful CitySec Meetup - Part 1
How to Start a Successful CitySec Meetup - Part 2
Starting the local user group allowed me to meet a lot of people in town. You never know if you’ll meet your future employer or someone that starts their own company. I had both those experiences starting a user group. The first was switching to a different state department after meeting the South Carolina state CISO at a meetup and going to lunch with him.
The other is meeting Andrew Morris who is the founder of GreyNoise a company that’s starting to make waves in the cybersecurity community. I met him at a conference called Trends in 2015 where he told me about his idea for the company. I’ve had him on the podcast a couple of times to talk about being a pentester.
Start a blog or podcastSpeaking of podcasts, most people don’t know that I had a podcast prior to my security podcasts. I ran The Crawfish Boxes (TCB) podcast for the Houston Astros fan site on SB Nation. I gained some notoriety with the Houston Astros organization due to that podcast and blogging I did for TCB. It’s amazing how more accessible people become when you offer to interview them. I have a big leaguer or two in my cell phone and at one point had two baseball General Manager’s following me on Twitter.
I took the lessons and experience from covering baseball and brought it into the infosec community and it has really helped my career. I’ve gotten to meet and talk to a lot of great people in the field on my podcast. I’ve had a lot of success just reaching out and asking people if they’d be interested in talking about a topic they’re presenting on or have blogged about. There are people who never responded or responded and then stopped responding but more often than not I can get an interview set up with them.
One of the hardest things getting started is imposter syndrome, “Why would people want to listen or read me?” “Someone else is already doing what I would want to do.” I had those same thoughts but went ahead because I have my own unique perspective to offer. It’s still nerve-racking but the longer I did it the more I realized I have something to offer to the community. I love having a conversation with people and learning more about what they know. Which made podcasting a great fit.
Blogging, on the other hand, is the one I’ve struggled with. I was never good in English class and if I had concerns about podcasting and what people thought my writing is on a much higher level of imposter syndrome. But blogging isn’t about perfect English, it’s about sharing a unique viewpoint. English and grammar help but it’s more about the idea and finding my voice. Plus, the more I do it my writing is bound to improve, right? Right? AI is something I’m leveraging as an assistant. It’s not always great but it can help.
Summary To be a Kevin Bacon you gotta get out there. Attend conferences and local user groups. You’ll get to meet a lot of really great people. If you struggle with talking to people volunteer. It can force you to meet people and show your willingness to contribute to the community. Start a blog or podcast or vlog. Putting yourself out there can help you grow as a professional and open up doors. If blogging or podcast aren’t your thing that’s okay. Identify what you’re interested in and see how that can fit into the community. There’s a lot of ways to contribute. Contributing to an open source project or participating in a capture the flag event can do similar things for your career. Find ways to get involved.
This way to BSides Nashville - From BSides Nashville 2016.
I’m excited to announce that I will be speaking at BSides Nashville May 11, 2024. I will presenting my threat modeling talk which I’ve been blogging about the past couple of weeks. I’ll link the blog posts to the talk and pictures for past BSides events below. I’ve been going to BSides Nashville since it started in 2014. The first few years I attended I lived in Columbia, SC, which meant a seven hour drive to attend the conference. In 2016 I moved to Nashville and now consider it my home BSides conference.
It’s a really great event with a lot of great speakers and great spot. It’s also Nashville so getting into some fun (or trouble) is right around the corner. Prior to the pandemic they used to sell out 300 tickets very quickly. Post-pandemic they’ve struggled to get back to those number but so has every other local user group and conference. I’m expecting this year to be a big year for conference attendance not only for myself but the community. I believe people are ready to get back out there. More importantly the job market is influx and a lot of people are looking for jobs. The best way to do that is to get out and network with people at local user groups and conferences. If you’re planning to attend reach out and we can meet in person!
Threat modeling blog posts:
BSides Nashville Pictures:
BSides Nashville 2014 Bsides Nashville, TN, May 17, 2014.
BSides Nashville 2015 BSides Nashville, TN, April 11, 2015.
BSides Nashville 2016 BSides Nashville, TN, April 16, 2016
BSides Nashville 2017 Nashville, TN, April 22, 2017
BSides Nashville 2018 Nashville, TN, April 14, 2018
BSides Nashville 2019 Nashville, TN, April 13, 2019
Subscribe Sign up with your email address to receive news and updates.
Email Address Sign Up We respect your privacy.
Thank you!
Exploring tools and resources for threat modeling - Created with the help of ChatGPT
My presentation for this year is Threat Modeling. My first stop is the 2024 Palmetto Cybersecurity Summit Feb 21-22, 2024, in Columbia SC. I’ll also be speaking at BSides Nashville May 11, 2024, and ShowMeCon May 13-14, 2024.
Getting StartedWe’re going back to kindergarten people! We’ll get to draw shapes and lines and use different colored markers! To get started all one needs is a whiteboard and markers. Building out a diagram is the first step. As I mentioned in the Basics of Threat Modeling blog post having one prepared prior to the session will help expedite the process. Unfortunately, if there isn’t an existing diagram one will have to be done during the session. Adam Shostack has a description of the symbols and elements to use in a threat model on his GitHub page. They’re very simple and that’s the intention because threat modeling an application or process can get very complex.
Adam Shostack - DFD3 - https://github.com/adamshostack/DFD3
If the session is virtual and not in person the same principles applies. All popular video conferencing has a whiteboard feature on it that can be used for threat modeling. There are third-party options as well including:
The tools I’ve had experience with are Microsoft’s Whiteboard, Visio, and Threat Modeling Tool. Visio and the Threat Modeling Tool get into a lot of detail and can feel complex if you’re just getting started. The more important thing is learning the methodology and approach to threat modeling. Threat Dragon has a lot more simplicity. It is open-source so doesn’t have all the bells and whistles of other tools. It can take a little to get used to using. I’ve seen developers create diagrams with Draw.IO. It’s simple and easy to use but be mindful that if they build it on a third-party website they may be putting internal organization information on the internet. I have not used Miro, Lucidchart, MURAL, or Whimsical but they look similar to Draw.IO. Leave a comment below with your favorite white boarding tool.
Automated threat modeling toolsI have only used Microsoft Threat Modeling Tool and OWASP Threat Dragon for automating parts of the threat model process. Microsoft’s Threat Modeling Tool get’s very granular and tries to be exhaustive on attack scenarios. If you like digging into a lot of details it can be a very useful tool. OWASP Threat Dragon is a much lighter version of that which is why I used it a lot more. For me I wanted the group to come up with their own attack scenarios because it allowed them to exercise their security muscles and build a stronger security mindset. This impacts the other areas of their day-to-day work. As their working they’ll be thinking about security.
There are other commercial and open-source tools that promise one-click threat modeling. I have not had an opportunity to use them. Here are some popular ones I found:
If you have used one of these or another leave a comment below.
Educational ResourcesThe book I always recommend is Threat Modeling: Designing for Security by Adam Shostack. It is “THE” book on threat modeling. What I love about the book is that after the first chapter it says to just start threat modeling. It’s more of a companion book for learning and maturing the threat modeling program.
OWASP is another resource for threat modeling. They have an entire project on everything you need to know about Threat Modeling. The OWASP Cheat Sheet is also a great place to start and a good reference point while maturing the threat modeling practice. Finally, an exhaustive list of threat modeling resources can be found at Awesome Threat Modeling on GitHub.
Leave a comment below with resources or tools you recommend. If you’re interested in seeing a version of this talk check out the ColaSec Meetup page as I will be presenting on threat modeling at the February 20th, 2024, meetup. A virtual option for attending is available.
Subscribe Sign up with your email address to receive news and updates.
Email Address Sign Up We respect your privacy.
Thank you!
Logs somewhere cold
This is a log of changes to the site over the last week.
New pages:
Attack Tree Example - This is for my upcoming threat modeling talk.
Podcast posts:
How to Implement DAST - My conversation with Frank Catucci about implementing DAST
ShowMeCon: Kevin Johnson and whatever he wants to talk about - A sponsored episode by ShowMeCon with Kevin Johnson
Blog posts:
Basics of Threat Modeling - A blog post on threat modeling
Methodologies and Approaches for threat modeling - A blog post on threat modeling
Threat Modeling Risk Management - A blog post on threat modeling
Subscribe Sign up with your email address to receive news and updates.
Email Address Sign Up We respect your privacy.
Thank you!
Explore threat modeling risk management - Created with help from ChatGPT
My presentation for this year is Threat Modeling. My first stop is the 2024 Palmetto Cybersecurity Summit Feb 21-22, 2024, in Columbia SC. I’ll also be speaking at BSides Nashville May 11, 2024, and ShowMeCon May 13-14, 2024.
In this post I want to talk about rating and prioritizing the discovered threats from a threat modeling session. We’ll get into the different methodologies and talk about some of the nuances of them.
Methodologies for Risk ManagementCreated with help from ChatGPT
DREADDREAD, an acronym for Damage, Reproducibility, Exploitability, Affected users, and Discoverability, is a risk assessment model used to prioritize threats. Although its use has declined due to its subjective nature and lack of business context alignment, some organizations may still find it useful for quick, high-level risk assessments.
This is what I use for threat modeling. If you read Adam Shostack’s book he calls it obsolete and recommends SDL Bug Bar. The reason is that the different categories can be a bit ambiguous, lack granularity, and context. I think it’s great for getting started and keeps threat modeling simple. As threat modeling matures there may be a need to mature the risk management and switch to something that provides more scaleability.
Using DREAD we would rate the threat by each theat on a 1-3 scale. This allowed for prioritizing low, medium, and high. The final number will help prioritize the threats discovered for follow up. Again, when dealing with other groups it’s important to keep the bar to entry low. As the program matures and people get a better idea on threat modeling advancing to something a bit more technical can be useful.
SDL Bug Bar
The Security Development Lifecycle (SDL) Bug Bar is a concept and a set of criteria used within Microsoft's SDL framework to classify and prioritize the handling of software bugs based on their security implications. The "bug bar" establishes a baseline for the security severity that a bug must meet or exceed to be considered a priority for fix before software can be released. It helps teams make consistent, informed decisions about which security vulnerabilities to fix and when to fix them.
There’s not really a lot available online for implementing the Bug Bar. There are some blog posts and the SDL Bug Bar PDF which doesn’t exactly give instructions on how to implement. It can be loaded as a template into other Microsoft tooling so that can be helpful and will help with streamlining some of the threat modeling process. Leave a comment below if you’ve had experience implementing the SDL Bug Bar.
OWASP Risk Rating MethodologyThe Open Web Application Security Project (OWASP) offers a risk rating methodology that considers factors such as threat agents, attack vectors, technical impact, and business impact to prioritize vulnerabilities. This methodology is particularly useful for web application security and can be adapted to fit an organization's specific needs. This has more in-depth math and expanded categories for rating a threat. This could be another option for maturity.
CVSS (Common Vulnerability Scoring System)CVSS provides an open framework for rating the severity of security vulnerabilities in software. It offers a standardized way to capture the principal characteristics of a vulnerability and produce a numerical score reflecting its severity. CVSS scores can help organizations prioritize their response and remediation efforts based on the potential impact of each vulnerability. This is one of the standards for vulnerabilities.
FAIR (Factor Analysis of Information Risk)FAIR is a quantitative risk analysis methodology that helps organizations understand, analyze, and quantify information risk in financial terms. FAIR differs from other models by focusing on the financial impact of risks, making it particularly useful for making informed, data-driven decisions about cybersecurity investments and risk management strategies. This methodology was created by Jack Jones with the intent of providing risk in financial terms for organization.
TARA (Threat Agent Risk Assessment)TARA identifies potential threat agents and evaluates the risks they pose to an organization's critical assets. This methodology is useful for organizations that want to focus on the most likely sources of threats and tailor their defenses accordingly. Intel created TARA as part of its comprehensive security and risk management strategy to identify, assess, and prioritize risks based on the potential impact of various threat agents. This methodology was created by the Department of Defense (DoD) in 2010. It uses built in attacks to assist in the risk assessment process.
SummaryThere are multiple options for rating and prioritizing the threats identified in a threat modeling session. I like DREAD because it’s simple but that might not be feasible for larger organizations. If you’re a Microsoft shop the SDL Bug Bar may be a better fit. OWASP Risk Rating Methodology is also another option. If you really want to go deep CVSS or another framework may be the best option. FAIR and TARA are two methodologies that look to provide specific context to risk management. FAIR from a financial standpoint and TARA has a DoD lean. Choosing the best risk management methodology will depend on the organization and it’s needs. Try multiple and see what works best for your organization.
Next we’ll get into tools and resources for threat modeling.
Subscribe Sign up with your email address to receive news and updates.
Email Address Sign Up We respect your privacy.
Thank you!
Riccardo Annandale
@pavement_special
Mentorship is a big topic in the security industry. There are programs setup to connect a mentor with a mentee. I believe they’re great programs. I also believe mentorship is more than just a program. We can be mentored by people above us, below us, and within our peer group. I once said this to a friend and co-worker of mine. He responded that he saw mentorship as one way. I agreed that it is one way. I mentor him and he mentors me. There was a look of confusion and then a realization.
He’s a director and I’m a manager. At one point he was an analyst fresh out of the military. Within two years he went from analyst to manager to director. I’ve helped him along the way mentoring him on his hiring practices. He’s mentored me by encouraging me to climb the corporate ladder. At the time I wasn’t really interested in going higher than manager. We’ve confirmed each other's beliefs in management and also challenged each other.
I’ve done well for myself in my career. I’ve never really had a designated mentor. I’ve had to pick and choose lessons throughout my career from my managers and peers. I’ve asked mentee questions of several people because I like learning and gathering different perspectives on things.
They’re all ages and experience levels. The new generation has new ideas that could help us be better. The older generation has lessons from their own experiences that can help us avoid pitfalls or holes they fell into. There are peers that help us confirm or challenge our beliefs. They’re all around us. To me mentoring is organic. You can certainly have a designated mentor but don’t overlook the mentors right in front of you.
Jodie Cook
@jodiecook
I’ve stopped posting the daily stoic on my website. I am still doing them but it’s all in hand written form. I’ve enjoyed that process much more than coming here to post. It has helped to post them here. I remember getting feedback very early on that me doing it helped others pick it back up or start the Daily Stoic. That motivated me for a while. It’s a powerful tool for dealing with life’s struggles and improving ones life so I encourage those to still do it. The stoic I just read was about how we control are own thoughts and decisions. I like being inspirational to people but it’s still on them to do something with it and keep doing it.
When I take notes at work they’re hand written. I was doing this prior to the pandemic and its since been tested after the pandemic because I have my computer in front of me. It’s convenient. Handwriting is a skill that is going by the wayside and that’s unfortunate because it provides some benefits. It’s relaxing, it improves memory, and it gets us away from electronic devices that have invaded our lives. I want to use the Daily Stoic now as an opportunity to do a handwriting exercise everyday. This will also force me to come up with blog topics for the blog. I’d like to get back into blogging but I’ve yet to really commit to it. Some of that is having topics other is knowing what I want to do. Stoicism will help with that. Though I plan to blog about other topics.
Blogging about stoicism these past few years has been a great exercise. Like anything I think it’s time to evolve.
Nick Martin
@nickanthony
I am blogging everyday (or nearly everyday) on The Daily Stoic.
Friday - Protect The FlameI think this is talking about taking care of ones self and mindset. Studying stoicism. Learning and growing. Progressing towards being a better person. It’s hard work and requires lots and lots of patience. Also forgiveness. That’s something I have to remember or otherwise I’ll snuff my flame out with negativity.
Yesterday - No One Said It’s EasyI’m realizing this at work. I need to keep doing what I’m doing and how I’ve gone about doing it because I’ve had a lot of success. It’s when I bring in negativity or complaining when I don’t get the things I want that it hurts myself and the people around me. Instead I have to keep a positive attitude, especially in the tough times and realize that things will work itself out.
Today - Rise and ShineThis is something I’ve worked on. Getting up early verse sleeping in. Kids help with this as I no longer can sleep past 8 am. Regardless of when I went to bed. That means going to bed at 2 a.m. means I’m getting only six hours of sleep (if I’m lucky). It’s hard work to shift from being a self-professed night owl to an early riser but something I enjoy more.
Kevin Delvecchio
@kevindelvecchio
I am blogging everyday (or nearly everyday) on The Daily Stoic.
Flipping the script on perspective is important. Getting to do things is powerful and empowering. I’m trying to do that more at work. Instead of railing against a system, trying to find a way to do something important.
Nagesh Badu
@nagesh
I am blogging everyday (or nearly everyday) on The Daily Stoic.
I’ve felt like I can do my duty well. I often feel like I fail doing it though. I give in to impulses and pleasures more than I should. It feels like it’s harder when I do my duty more and more. I feel worn down and then give in. It’s a constant struggle and maybe that’s the point.
Letícia Pelissari
@leticiapelissari
I am blogging everyday (or nearly everyday) on The Daily Stoic.
Be good. I think I’m starting to realize that I’ve over thought stoicism. I tend to think a lot and that tends to make me put a lot of pressure on myself and hold myself to a high standard. Instead I need to go with the flow a bit more. Be aware of what I’m doing and make good decisions. That’s not always easy.
MARCIN CZERNIAWSKI
@marcin777
I am blogging everyday (or nearly everyday) on The Daily Stoic.
I’ve started to apply this more and more. When something doesn’t go my way or I need to adjust I see it as an opportunity to do something different than from what I planned. Getting upset about the inconvenience does very little for me.
Chris Mok || @cr.mok
@mokc
I am blogging everyday (or nearly everyday) on The Daily Stoic.
Excuses are not something I buy into. I can certainly be hard sometimes to use an excuse, especially when there’s motion involved. That has a tendency to not help the situation though. I try to remember that I can control what I can control and I can be better.
Aziz Acharki
@acharki95
I am blogging everyday (or nearly everyday) on The Daily Stoic.
Forgive myself is something I’ve been working on more. I know I hold myself to a higher standard. That can lead to self loathing when I don’t meet that high standard. I have learned to start forgiving myself and tell myself to do it better next time. I’ve made progress and I will continue to make progress.
Alex Haney
@alexhaney
I am blogging everyday (or nearly everyday) on The Daily Stoic.
I was out at dinner last night with some friends and service was taking for ever. I asked for my check and eventually got it when everyone else asked for theirs 20 mins later. I didn’t get upset. I patiently waited and enjoyed the company I was in even though I had planned to leave. Getting upset would have been a waste of energy.
Marek Piwnicki
@marekpiwnicki
I am blogging everyday (or nearly everyday) on The Daily Stoic.
Tuesday - The Truly Educated Aren’t QuarrelsomeThis is a good stoic to keep in mind. I don’t think I get upset a whole lot when I have disagreements when discussing topics. It’s nothing personal and I realize other people have different view points and experiences.
Yesterday - The Wise Don’t Have “Problems”I wonder if the talking also applies within my own head. I haven’t slept well recently. I’m waking up and the mind is running. Sometimes I can get back to sleep other times it’s harder.
Today - Try The OppositeBreaking the pattern is hard. Habits are so ingrained that it makes it tough to do something the opposite of what I want to do. Even if it’s bad. It takes energy and sometimes I don’t have the energy to do the opposite. That is of course me making excuses.
Alyssa Boobyer
@alyssab
I am blogging everyday (or nearly everyday) on The Daily Stoic.
This stoic is quite vague. The best I can take is that living in the present can often be the best way to acquire what we want. Enjoy the journey. Don’t over complicate things.
Javier Miranda
@nuvaproductions
I am blogging everyday (or nearly everyday) on The Daily Stoic.
May 23 - Plato’s ViewI haven’t had much success with taking the bird’s eye view. It puts things in perspective but it doesn’t necessarily change the problem. Both sides have to be willing to take this view. What has helped is reflecting on what I used to be upset about and realize how silly or small that thing really was.
May 24 - It Is Well To Be FlexibleGolf has a lot of practice to this stoic. I recently struggled with this using my driver. I was hitting high shots to the left. I tried one thing and it did it again. And another. I eventually did figure it out but only after several more tries. My scores suffered and there was a lot of frustration. It reminded me to stay humble
May 25 - This Is What We’re Here ForStruggle is a human objective. I recently had a conversation where I was told about all these negative things. I responded that things were better than they had been. This did not sit well. The house market was brought up as an example. I didn’t respond.
I do believe things are better. The housing market is the result of progress. Work in the office is being challenge and redefined. That’s progress in my view.
May 26 - Blow Your Own NoseIt can be difficult to move forward when it feels like the world is out to get me. I’ve had to remind myself it’s on step/day at a time. It sucks but progress is good.
May 27 - When To Stick And When To QuitI am the person always looking for the constant change. This is at the grocery store and driving on the road. I’ve worked to get better at being patient in my switches and accepting those outcomes.
May 28 - Finding The Right MentorsMentorship seems to be big right now in the tech field. I think it’s a good thing. I remind people though that mentorship isn’t always one way. We can learn from any type of person because we all have different experiences. Books are also a powerful way.
May 29 - Brick By Boring BrickI’ve gotten away from this in golf. No counting up the score on a hole or round until it’s done. I’ve found rounds much more enjoyable and less frustrating. Shots don’t matter until the end because each shot requires attention.
May 30 - Solve Problems EarlyI am working to better handle issues at the current moment. If it’s not critical I push it off. They often come around later.
May 31 - You Can Do ItI believe I can succeed at anything. This is something I try to instill in people around me.
June 1 - Just Don’t Make Things WorseAs I’ve improved at golf I find I’m getting more frustrated when things go bad. It’s ego and it ends up making things worse. I remind myself it’s part of the process and better swings are ahead.
June 2 - A Trained Mind Is Better Than Any Script Flexibility and adaptability are something I pride myself on. I love this quote from Billy Beane in the Moneyball movie.
“Adapt or die.”
June 3 - Life Is A BattlefieldI’m starting to figure out my own battlefield. It’s different from others because we all have different from others because we all have different priorities.
June 4 - Try The Other HandleI’ve struggled with trying the other handle. I don’t think I fully understand it. I do feel like being on vacation can be like grabbing the other handle because I’m in different scenarios. It gets us out of our day-to-day routine. I feel freer and more clear headed because I just have the essentials.
June 5 - Listening Accomplishes More Than SpeakingListening is something I try to do more than talking. Of course my father was a preacher so I can get out of listening more and get into chatty mode.
June 6 - No Shame In Needing HelpHelp is not something I always seek. I can be a bit stubborn in that regard. It’s not ego. It’s more wanting to help others.
June 7 - Offense Or DefenseOffense is exhausting but some times necessary. I believe there is a balance. I think the defense is better because it allows the other side to get worn down. The question is how to apply this in life.
June 8 - Prepared And ActiveI’ve struggled with this a lot at work. I’ve done a better job preparing for daily work. One realization I had after three years of management is that I was starting all over again. A lot like middle school to high school. I was a freshman barking at seniors. I have since accepted my position and strive for a more senior position.
June 9 - Stay Focused On The PresentWhen I golf I try to focus shot to shot. It takes a bit of practice. Some times I waiver and look at the overall score. That has a tendency to insight over confidence or worse frustration. My round of golf yesterday felt like a typical bad round. This time I was more focused on shot to shot. The outcome was much better than I expected when the round was complete
June 10 - Calm Is ContagiousI’ve had to learn to remain calm in my line of work. Things can easily get out of hand. Fear, uncertainty, and doubt is something that is rampant within the field. There are certainly times of urgency but only after all the info has been vetted.
Yesterday - Take A WalkI’ve incorporated more walks into my life. I still fill like I could do it more. It’s often hard to stop in the moment and go for a walk but when I can it is refreshing. I don’t necessarily solve all my problems. I know I’m on the right path though. +
Today - The Definition of InsanityProgress can be a small thing and easily overlooked. It’s hard to change habits by doing a 180. Some times there are motivation factors. Other times it’s the desire to improve and that takes patience and time. I’ve been working on not beating myself up and instead trying to identify what progress I did make. How I’ve changed this year verse last year. I am doing things better than a year ago and that’s because I’m making tweaks and trying to improve in different ways.
Aziz Acharki
@acharki95
I am blogging everyday (or nearly everyday) on The Daily Stoic.
The reverse clause is something I remember but I easily forget in my time of need. This year would be a good year to work to remember it more when things don’t go my way. I deployed it earlier this month when I had my ego takes some hits. Instead of ruminating over the hits I looked for insights about the other person and myself. It sucked but I like handling the situation with a reverse clause verses getting upset or angry.
Ankush Nath Sehgal
@ankushsehgal
I am blogging everyday (or nearly everyday) on The Daily Stoic.
Be a good human being. How do I strive towards that if I already feel good. I guess studying stoicism helps with that.
Simon Abrams
@flysi3000
I am blogging everyday (or nearly everyday) on The Daily Stoic.
I love this stoic because I feel like I’ve figured a good bit of what I’m working on it. I’m always questioning it’s usefulness. In life not so much. I still work. In fact I was just questioning if I do too much work because I’m always feeling a little exhausted at the end of the day. I used to power through it but now I’m paying attention to it. Am I doing the right thing?
Eddy Klaus
@eduardo_mekmuffin
I am blogging everyday (or nearly everyday) on The Daily Stoic.
I’ve struggled with this stoic because working to work is not something I want to do. I want to provide value. I also think it’s important to have down time. How much. I’m still trying to figure that out. I also always think so sometimes I just want that to shut off.
Francesco Ungaro
@francesco_ungaro
I am blogging everyday (or nearly everyday) on The Daily Stoic.
Monday - Stop Caring What People ThinkThis hits because at the moment I’m feeling a bit down about work. I feel like I’m not good enough based on things others have said. They’re not directed necessarily at me as a person but I’m taking them harsher than maybe I should. I am accomplished in my career and my decisions. I need to recognize that and feel full.
Yesterday - Sweat The Small StuffSmall steps towards better decisions. I have good days and bad days and everything in between. I have to remind myself of the progress I’ve made. I need to make smaller better decisions. Get those decisions ingrained and move onto the next small good decision.
Today - The First Two Things Before ActingDon’t get upset and do the right things. I’ve started to notice that when I have a rough day at work or get upset I tend to let that lead to poor decisions in the evening. I’m working on that and they have improved. I still have those nights though.
eberhard 🖐 grossgasteiger
@eberhardgross
I am blogging everyday (or nearly everyday) on The Daily Stoic.
Tuesday - Quality Over QuantityI love books. Both fiction and non-fiction. I have certain authors I follow while also enjoying discovering new authors. There are some books where I stop reading because I’m not getting much out of the experience.
Wednesday - What Kind Of Boxer Are You?I think about work for this stoic because I feel like I have started to give up at work. I get my work done but I’m not as drive as I once was. I wonder if this is because I’ve been beaten up too many times or becoming a smarter boxer.
Thursday - Today Is The DayI thought about doing this tomorrow but I knew I needed to do it today because I need to get this done and tomorrow is more distractions and things to do. I’m also behind a week and I’ve gotten into a habit of that.
Friday - Show Me How To LiveLiving a life to the fullest is subjective. I sometimes have a problem with the subjectivity of stoicism. Doing what I should do but what is that? A full life can’t be objective measured. People can do more but have not live a full life.
Yesterday - Making Your Own Good FortuneMore opportunities seem to come from the more I work at them. This brings luck.
Today - Where To Find JoyProper human work. This is something I’ve struggled with for several years. Doing things to do things is not what I want to do. I also think that can hold me back from find what my proper human work is.
Dan Burton
@dan__burton
I am blogging everyday (or nearly everyday) on The Daily Stoic.
I’ve realized this recently with how I’ve acted around people. I’ve said things negative when I’ve striven to be more positive. Or ask questions in conversations instead of talking. Practicing stoicism is also easy to forget. That’s why I like the book. I can practice it daily and I’m getting into the habit of practicing stoicism when things are challenge. I’m recognizing it’s not easy and that I have to let it work it’s course.