Talion Threat Set Radio is your weekly cyber threat intelligence bulletin. We cut through the noise to give you our honest opinion on the threat news that matters.
Evil Corp and LockBit members the target of global sanctions and arrests.
Quick fire topics.
Telegram in the spotlight, founder arrested, banned in Ukraine, and will now share user data on legal request.
Quick fire topics.
Explosions were a supply chain compromise, not a cyber attack.
Another Ivanti critical flaw exploited in the wild with public exploit.
Security giant Fortinet suffers data breach as 440GB of files stolen.
Quick fire lightning round.
Uncommon technique from 2017 resurrected to drop Cobalt Strike
Versa Director vulnerability leveraged by Volt Typhoon
New persistence technique allowed Linux malware to hide for years.
SolarWinds flaw exploited in the wild & hardcoded credentials.
Report indicates ransom payments will break last years record.
Lazarus exploit driver present on every Windows system.
In this weeks episode:
- Over 2 Billion Records of Personal Information Leaked.
Critical TCP/IP remote code execution vulnerability patched by Microsoft.
Ringleader of Ransom Cartel extradited to the US to face charges.
The legal challenges against CrowdStrike begin following update incident.
CISA re-issues seven year old warning over exploited Cisco install flaw.
Chinese group compromises ISP to push poisoned infostealer updates.
Microsoft vows less reliance on kernel drivers following CrowdStrike incident.
Cloudflare trial product increasingly abused for criminal obfuscation.
Black Basta sees success with in house tools following QBot takedown.
Repair documentation used to push malware after CrowdStrike incident.
New Linux variant of the prolific Play ransomware discovered.
New ICS malware FrostyGoop responsible for Ukraine attack.
Report highlights alarming speed PoC exploits are weaponized.
Kaspersky offers 6 months free service as farewell to US market.
Fin7 offers sophisticated evasion tool on underground markets.
CrowdStrike botched update causes global havoc.
Eldorado ransomware claims 16 victims in short timeframe.
Free decryptor released by Avast for DoNex ransomware strain.
Blast Radius attacks leverage MD5 collisions to gain admin.
"regreSSHion" SSH flaw leads to root on Linux servers.
GootLoader continues to deploy updated versions in new attacks.
Kaspersky software banned in US due to national security concerns.
LockBit misleadingly claims to hit US federal reserve.
TeamViewer compromised by Russian state sponsored APT group.
PoC exploit code available for heavily targeted Veeam backup solution.
New loader dubbed PhantomLoader delivers MaaS payloads.
Black Basta may have exploited flaw 3 months before fix issued, as 0 day.
Attackers target GitHub repos once again in Ransom-lite extortion.
Windows will finally depreciate NTLM, providing transition advice.
PoC chaining two flaws for Telerik report released.
In this week news:
In this weeks episode, LockBit Ransomware group have had nothing but setbacks since “Operation Chronos”, GitHub alerts users to 2 high severity vulnerabilities and a significant uptick in Docusign phishing emails has been observed in May.
LockBit ransomware admin is named and sanctioned.
North Korean actors exploiting weak DMARC policies for spearphishing.
Ivanti flaws chained together to drop Mirai botnet.
Developers targeted with Python backdoor during false job interviews.
New UK law now in effect limits default passwords on smart devices.
New malware emerges targeting small office and home routers.
MITRE breached using two Ivanti zero days.
CrushFTP victim of targeted zero day exploitation.
ArcaneDoor campaign targets vulnerable Cisco devices.
Large scale exploitation of Palo Alto CVE following PoC disclosures.
Atlassian vulnerability leveraged to deploy Cerber ransomware.
PuTTY flaw can be used to obtain private cryptographic keys.
Warnings issued regarding 10/10 CVSS score Rust vulnerability.
Researchers speculate LLM wrote Powershell for malware strain.
Change Healthcare hit by ransom demand again following AlphV exit scam.
Sophisticated supply chain attack attempted against multiple Linux distros.
Linux false Sudo prompt flaw has persisted for over a decade.
DinodasRAT now targeting Linux servers with new variant.
Huge darknet marketplace seized by German takedown effort.
Muddywater group using legitimate RM tools for access.
APT31 members sanctioned following US infrastructure attacks.
Fujitsu discover malware compromised systems.
Russian actors may be targeting Ukrainian telecoms with new wiper malware.
New DoS technique discovered able to create infinite feedback loop.
Russian groups accesses Microsoft source code in follow up from January attack.
StopCrypt, the ransomware still targeting individuals over business has been upgraded.
DarkGate leverage recent SmartScreen vulnerability in attacks.
The Blackcat / AlphV ransomware operation fakes law enforcement takedown to steal from their own affiliate.
LockBit claims swift recovery from takedown operation, downplaying severity and threatening leaks.
Lazarus exploit Windows zero day flaw with new improved Rootkit.
DoJ takes down botnet used by Russian state group.
LockBit ransomware operation gutted by the NCA.
ScreenConnect under active attack, Lockbit utilised.
Anydesk confirms cyberattack that allowed hackers to gain access to the company's production systems, Cloudflare publicly disclose its internal Atlassian server was breached by a suspected nation-state attacker and the FBI disrupt and neutralize KV-botnet.
Microsoft confirms details of recent Russian compromise.
Kasseika joins ransomware groups performing BYOVD attacks.
Trickbot browser injection developer jailed.
VMware critical flaw under active exploitation.
Critical vulnerability discovered in Juniper firewalls and switches.
Ivanti bypass flaw exploited in the wild.
Evasive Async RAT has targeted infrastructure for almost a year.
New FBot toolkit targets SaaS and cloud platforms.
Turkish group uses Mimic ransomware to target MSSQL servers.
Critical Invanti flaw allows compromise of enrolled devices.
Multiple malware strains use Google feature for persistence.
Microsoft disables MSIX after it is abused by malware again.
Rhadamanthys infostealer gains popularity with new features.
MongoDB confirms breach and theft of customer data.
FBI confirms it breached the Blackcat ransomware group.
AlphV ransomware outage rumored to be caused by FBI.
New "Pool Party" injection technique evades 5 leading EDR solutions.
Lazarus continues to abuse Log4J with 3 new malware strains.
NCSC warns of Russian state group social engineering activity.
Okta customers affected by recent attack revised from 1% to 100%.
Researchers discover Linux rootkit RAT undetected since 2021.
Ransomware group arrested in Ukraine following attacks against 71 countries.
Method discovered to passively extract RSA keys from SSH connections.
Chrome fixes its 6th zero day exploited in the wild this year.
Russian state USB malware spreads to unintended targets.
Qbot moves to Darkgate and Pikabot following takedown.
Criminals claim ability to reuse expired Google auth cookies.
CISA adds three flaws to its KEV
Google Workspace and Cloud highlighted as attack vector.
VMWare warns of critical VCD flaw.
Microsoft will soon begin moving towards mandatory full MFA adoption.
GootLoader variant moves to stealthier self developed bot.
BlazeStealer targets developers with malicious code repos.
Recent F5 Big IP flaws exploited in stealthy attacks.
Citrix bleed flaw leveraged against government targets.
Mozi dismantled by mysterious killswitch command.
Fake Corsair job offers pushing Darkgate malware strain.
Ragnar Locker operation dealt heavy blow by Europol.
Okta support system compromised, customers breached.
Another Citrix Netscaler flaw exploited as a zero day since August.
Microsoft will phase out NTLM with Windows 11, in favour of Kerberos.
Multiple nation state groups are exploiting a recent critical WinRAR flaw.
Genetic information stolen by credential stuffing attack.
New “rapid reset” zero day enables record breaking DDoS.
Microsoft will kill of VBScript in the near future.
New BunnyLoader MaaS becomes popular due to features and pricing.
Atlassian Confluence under active exploitation from new 0-day.
Looney Tunables vulnerability enables root on popular Linux distros.
Maximum severity CVE assigned to libwebp following Google error
New ShadowSyndicate group tied to several ransomware ops
VenomRAT dropped by fake PoC exploit for WinRAR flaw.
Newly observed Sandman group targets Telecoms.
BlackCat ransomware operation targets Azure storage.
Teams phishing techniques ignored by Microsoft used by ransomware enablers.
A new chain of Kubernetes vulnerabilities can lead to code execution.
Operators of the Redline and Vidar malware pivot to ransomware.
Cisco acknowledge VPN zero day exploited by ransomware actors.
North Korean threat actors target cyber security researchers.
New Blister malware updates drive quiet network infiltration.
PoC Exploit chain enables RCE attacks against Juniper firewalls.
Attacks against Citrix Netscaler devices linked to FIN8.
Qakbot botnet dismantled in aptly named “Operation Duck Hunt”
WinRAR flaw enables command execution by simply opening an archive.
Malware strain maps victims location in real time via Wi-Fi triangulation.
PoC exploit released for Ivanti vulnerability recently used in attacks.
Nearly 2000 Citrix NetScaler servers compromised in new campaign.
NoFilter, new stealthy privilege escalation technique discovered.
Raccoon returns with version 2.3 after 6 month hiatus.
AWS system manager can be leveraged as a remote access trojan.
CISA highlights the SUBMARINE backdoor used in Barracuda ESG attacks.
Google AMP links abused for stealthy phishing campaigns.
Compromised IIS servers used as malware delivery mechanism by Lazarus
Critical zero days in Atera platform could allow for privilege escalation.
Decoy Dog toolkit appears highly targeted and largely undetected.
Lazarus targets developers with malicious GitHub projects.
USB malware strains SOGU and SNOWYDRIVE drive huge infection vector increase.
Gamaredon campaign exfiltrating files mere 30 minutes after initial infection.
WormGPT, an AI tool which could make BEC attacks trivial.
Chinese hackers exploit flaw in Windows policy to load malicious kernel drivers.
BlackCat ransomware group uses WinSCP SEO poisoning to push cobalt strike.
New “StackRot” Linux vulnerability enables privilege escalation.
New EarlyRAT malware attributed to Lazarus offshoot.
Microsoft issues warning on increased widespread credential theft activity.
New Mockingjay process injection technique could bypass EDR detection.
US Government offers $10m bounty for info on the Clop ransomware group following MOVEit attacks.
New “Mystic Stealer” malware as a service gaining traction in underground groups.
APT37 deploying new “Fadestealer” espionage malware.
Batcloak malware obfuscation engine tied to various successful malware strains.
Hackers impersonate cybersecurity experts and peddle poisoned PoC code.
PoC released for Win32K flaw actively exploited in attacks
Chinese group Camaro Dragon use new TinyNote backdoor for intel gathering.
The Clop threat actor claims responsibility for the MOVEit data theft attacks.
Gigabyte firmware vulnerability potentially affects 7 million devices.
Phishing toolkits develop new ticks using new .ZIP TLD.
New malware used to target and disrupt power grids discovered.
Tool which allows extraction of KeePass master password publicly available.
Geacon, an open source Cobalt Strike port usable on MacOS, sees spike in use.
Report outlines Microsoft Teams functions which can enable phishing and more.
ViperSoftX infostealer expands to target specific password managers.
DLL sideloading is so effective, attackers begin doubling up the technique.
North Korean Kimsuky group employing new Reconshark recon tool.
GhostToken flaw, which allowed invisible persistence, patched and visible.
AuKill tool used in attack pipeline to kill EDR processes.
PoC exploit code available for Papercut flaw, which allows server takeover.
Lazarus moves to distribute Linux malware via faux job offers.
Aurora distributed via YouTube, resulting in evasive loader payload.
Tangle of attackers as multiple groups collaborate with Domino malware.
Lazarus evolve their tactics and targeted industries.
Zero day from recent patch Tuesday under active Ransomware exploitation.
MuddyWater pairing with new splinter group to perform destructive attacks.
Wordpress plugin with over 11 million install base under active exploitation.
Western Digital hit by cyber attack, services impacted, cause unclear.
SFX archives can be used to run stealthy Powershell backdoors.
Malicious Python package avoids detection through use of Unicode Homoglyphs.
The well established IcedID malware shifts from banking to ransomware delivery.
Supply chain attack hits customers of 3CX VOIP application, including the NHS.
In this week’s episode we report on:
Fortinet zero-day vulnerability CVE-2022-42475 being exploited by a Chinese hacking group UNC3886, recent tactics from Russian state backed group Nobelium & Hitachi Energy confirmed as latest victim of Cl0ps exploitation of Fortra’s GoAnywhere MFT vulnerability.
New GoBruteforcer botnet in active development according to report.
AI videos are being used as an effective lure to drop malware.
Document signing services abused to deliver Redline stealer.
Emotet returns following 3 month break.
CISA issues advisory regarding new Royal ransomware capabilities.
Old UAC bypass technique used to drop Remcos.
Rig exploit kit going strong despite focusing on IE vulnerabilities.
PlugX seeing success posing as legitimate windows debug utility.
New advanced post exploitation framework linked to Lockbit affiliates.
North Korean trojan targets residents of specific cities.
GoDaddy reveals multi-year security breach.
New malware as a service circulated on the dark web.
In this weeks episode: Updates on Clop’s claims it breached 130 orgs using GoAnywhere zero-day, ESXiArgs Ransomware Hits Over 500 New Targets in European Countries, The Killnet DDoS Blocklist, Russia’s Ransomware Gangs Are Being Named and Shamed by UK & US and Patch Now: Apple's iOS, iPadOS, macOS, and Safari Under Attack with New Zero-Day Flaw.
New actor spotted utilising “screenshotter” in targeted attacks.
Gootkit continues to push SEO to target Healthcare and Finance
Lockbit claims responsibility for the Royal Mail ransomware attack.
Packer operation uncovered used in major attacks since 2016.
Lockbit green offers familiarity for displaced Conti affiliates.
Microsoft OneNote is the latest infiltration vector pivot.
Emotet tricks victims into moving malicious files to trusted locations.
Vice ransomware operation disrupted by international effort.
Invisible PlugX variant spreads across USB drives, steals documents.
More than 1 in 20 internet facing Sophos firewalls still vulnerable to RCE vulnerability.
CircleCI breach leads to the platform rotating many customer tokens due to severity.
Ransomware generates 40% less profit than previous 2 years, as victims refuse to pay.
Turla leverages decade old defunct Gamarue infrastructure to attack Ukraine
JWT security flaw could potentially lead to Remote Code Execution
Gootkit abusing VLC through SEO poisoning campaign targeting healthcare
Slack suffers theft of internal GitHub code repositories over the holidays.
Play confirmed as the ransomware operation behind the Rackspace breach.
Google Ads increasingly used to sideload malware alongside legitimate software.
APTs turn to XLL files following office macros being disabled by default.
Okta source code stolen following GitHub repo breach.
LastPass confirms customer password vaults stolen in earlier breach.
Fortinet SSL critical vulnerability exploited in attacks.
Citrix ADC & Gateway critical vulnerability exploited in attacks.
SVG image files used as infiltration vector by QBot malware.
MuddyWater leverage compromised accounts to drop legitimate admin tools.
Open source ransomware strain acts as a wiper due to poor coding.
Rackspace confirm outage is ransomware related, no attribution yet.
Acer laptops possess flaw which allows secure boot to be disabled.
NPM package naming quirk can bypass security checks.
LastPass suffers second security breach in 3 months as direct result of the first.
Another ransomware variant switches to the Rust programming language.
Several threat actors observed switching to new Go based Aurora infostealer.
Report suggests Nighthawk may soon be adopted as another Cobalt Strike alternative.
Chinese groups increasingly using Google drive and similar applications as infiltration vectors.
QBot leverages Control Panel to launch malware after previously abusing Calc.exe.
Lazarus employ updated version of DTrack as part of new wave of attacks.
Lockbit affiliate includes Amadey bot as part of new infection chain.
Experts warn URLscan integrations are leaking sensitive data.
15,000 sites, primarily WordPress, compromised as part of SEO campaign.
RAT campaign impersonates legitimate password and backup software as delivery method.
Chinese group using new quiet infection chain to drop LODEINFO.
Media company compromised and used to push SocGholish through US news sites.
Emotet becomes prime distributor of self extracting malicious archives
GitHub repositories claiming to be PoC code actually contain various malware.
Two flaws which directly target Windows event logs could result in DoS.
Microsoft sensitive data breach linked to over 65,000 entities.
Ursnif mirrors its peers, evolving from banking trojan to platform.
New Powershell backdoor bypasses AV detection, hits 60+ victims.
POC available for critical Forinet vulnerability
ProxyNotShell patches conspicuously missing from patch Tuesday
Microsoft Defender to add automatic C2 detection to its capabilities
BlackByte group abuses “bring your own driver” flaw in attacks.
Lazarus exploit existing Dell drivers to gut detection capabilities.
Updated mitigation actions for ProxyNotShell issued after original actions bypassed.
New zero day “similar to proxylogon” used in exchange attacks.
Brute Ratel has been cracked, and will likely replace Cobalt Strike imminently.
A new dropper unloads a dozen infections, some of which are droppers themselves.
Lockbit 3.0 toolkit leaked online by one or more angry developers.
15 year old unpatched Python flaw present in over 350,000 projects.
Emotet post Conti, now distributes Quantum and BlackCat.
Iranian group leverages bitlocker to perform encryption.
Intermittent encryption gains popularity among ransomware operators.
Bumblebee gains new post exploitation and stealth capabilities.
Twilio breach allowed attackers access to Okta single use sign on codes.
Raspberry Robin USB malware linked to EvilCorp via Dridex similarities.
Ransomware written in more obscure languages trend continues with Golang based “Agenda”
LastPass suffers breach, unknown amount of source code stolen.
APT29 and others leveraging dormant accounts to bypass MFA.
Lockbit victim Entrust appears to DDoS the ransomware operation in retaliation.
Electron, the backbone of Teams and Discord, has a one click RCE vulnerability uncovered.
POC for a 9.8 vulnerability targeting Realtek routers released online.
Callback phishing as an attack vector sees an alarming 625% spike from last quarter.
This week’s topics-
Twitter discloses a breach affecting 5.4 million accounts that could enable smishing, phishing and sim swapping attempts.
A suspected nation state cyberattack on NHS’s 111 service points speculation towards a Russian retaliation attack.
Killnet announced its operations shall soon turn lethal.
Lockbit switches to abusing Windows Defender as Cobalt Strike loader.
Raspberry Robin possibly linked to EvilCorp.
Gootkit reappears with new infection vectors.
Suspected Darkside rebrand BlackCat learns nothing, attacks gas pipeline.
UEFI malware in development since 2016 discovered in Gigabyte and ASUS motherboards.
As Microsoft finally disables macros by default, container files emerge as replacement delivery mechanism.
QBot uses old version of Windows Calculator to facilitate DLL hijacking.
Atlassian issues fix for critical hardcoded credentials vulnerability
Two new ransomware strains are cross platform in nature
New modular “Lightning Framework” adds to fears of Linux malware surge
Impersonation of cybersecurity firms by threat actors as part of callback phishing attacks.
Luna Moth becomes the latest attack group to perform Ransomware style extortion without encryption.
Searchable data leak sites gain traction among threat actors as new leverage tool.
Ransomware affiliates spoof US companies to obtain new red team tools as they pivot away from Cobalt Strike.
Hive ransomware strain is completely re-written in Rust, gaining faster encryption among other benefits.
Microsoft reverses change popular among InfoSec community, no longer disabling document macros by default.
Mitel phone bug exploited to perform ransomware attack.
Lockbit 3.0 introduces first ransomware bug bounty program.
AMD reportedly suffers attack and data is currently held for ransom.
New variation of PetiPtoam flaw dubbed DFSCoerce can allow windows domain takeover.
Okta discusses Lapsus$ breach and how zero trust helped secure network from worse effects.
A collection of 56 flaws dubbed Icefall degrades security posture of thousands of OT devices.
New Symbiote Linux malware has several concerning stealth, obfuscation, and rootkit style techniques.
Emotet returns, featuring a similar codebase, but a host of new tricks.
Report highlights how non admin 0365 access could be used to sabotage/encrypt cloud files.
Two recent flaws can be combined to create very sophisticated phishing attacks.
Dridex authors EvilCorp become a LockBit affiliate, likely in another effort to evade sanctions.
POC code released for “trivial” to exploit Atlassian Confluence vulnerability.
New Chromeloader malware employs stealthy installation and persistence methods.
New MS Office zero day allows “no click” powershell exploitation even with macros disabled.
Information on a Russian botnet designed to manipulate social media trends and spread disinformation, facial recognition technology Clearview AI is fined by the UK government and an Iranian threat group target the port of London authority.
New modular Eternity malware being offered via Telegram
Conti appears to encourage overthrowing the Costa Rican government
Conti reportedly shuts down, splintering into smaller cells and operations.
US sanctions crypto laundering service used by the North Korean Lazarus group.
Full featured Russian RAT DarkCrystal is selling perpetual licences for a mere $40.
US offers a $15,000,000 bounty for information leading to the Conti overlords.
Confirmation of REvils return as new sample is obtained and analysed.
New technique discovered involving hiding payload in Windows Event Logs.
Ukraine affiliated hacktivists target Russian alcohol production pipeline.
Bumblebee appears to replace BazarLoader as Conti’s delivery vector of choice.
Emotet returns to full operation, more than a year after coordinated takedown.
FBI circulates warning regarding new BlackCat ransomware strain.
No 10 suspected of being target of NSO spyware attack, U.S. offers $5 million for info on North Korean cyber operators & notorious cybercrime gang’s botnet ZLoader disrupted
Raidforums seized, owner and operator arrested after running the site since the age of 14.
Microsoft works with US government to dismantle operations targeting Ukraine.
In an act of poetic justice, Conti source code is repurposed to attack Russian targets.
Intel completely shuts down business in Russia, exacerbating component shortage fears.
German investigators shut down Hydra, the largest illegal Darkweb marketplace.
Borat remote access trojan, with ransomware and other capabilities, offered for sale.
Chinese security researcher accidentally releases spring framework PoC exploit.
Raccoon stealer malware operation suspended after key developer killed in Ukraine invasion.
Kaspersky pose “unacceptable risk” as the Russian security giant is removed from bug bounty programs.
Lapsus$ return from vacation, and take arrests in stride releasing 70gb of data stolen from Globant.
Open source software poisoned and turned into supply chain attack as anti war protest.
Much newer functional version of Conti leaked online as revenge by Ukrainian member.
Lapsus$ members arrested in London after more high profile hits over the last week.
In this weeks episode, the arrest and extradition of a NetWalker ransomware affiliate, the exploitation of unskilled Ukrainian hackers and finally, a campaign which suggests China may be helping Russia in their cyber efforts towards the conflict.
Hosted by Talion's in-house Threat Intelligence team, this special Threat Set Radio podcast episode covers some of the specific threats Higher Education is facing:
· BotNet targeting Higher Education
· Log4Shell exploit
· Recent Ransomware attacks on Higher Education
Cybersecurity news regarding the ongoing Russian invasion of Ukraine rundown.
Certificates obtained from Nvidia leak used to sign malware.
Lapsus$ breaches Samsung shortly after the Nvidia attack.
Data wiper pointed at Ukraine appears to have been in development for months.
Ukranian researcher leaks Conti comms after they announce support for Russian invasion.
Trickbot developers appear to fold into Conti operation in act of cybercrime consolidation.
Nvidia hacked and employee data stolen, only to promptly hack the attackers back.
This week’s topics- Analysis of the DDoS Attacks against Ukrainian Websites, New Sandworm malware #Cyclops Blink replaces VPNFilter & a jammer used to stop kids going online, wipes out a town's internet by mistake.
Microsoft Defender to gain ability to block credential theft via Mimikatz and similar methods.
Kraken botnet spread using Smokeloader, and is observed dropping Redline.
Hackers using Microsoft Teams to perform extremely blatant internal attacks.
Russia performs third major cybercrime arrest as apparent crackdown continues.
Ransomware gangs adapt in effort to draw less attention and retaliation.
Smokeloader spearheads long list of malware strains using pay per install service to expand
Malicious CSV files used as Bazar malware infection vector.
Research compiled from 2021 shows most ransomware infections are self installed.
New publicly available Windows privilege escalation vulnerability as admins skip January patch.
Windows Update used by Lazarus as a living off the land tool to deploy malware.
Firmware level rootkits becoming more popular as 3rd to hide in SPI flash discovered.
Microsoft finally disables Excel XML macros by default in effort to block malware.
Russian authorities claim to dismantle the entire REvil ransomware operation, and seize assets.
Dark web card fraud platform shuts up shop after 8 years citing age of operators.
New ransomware strain dubbed White Rabbit linked to Fin8 group.
Google doc comments leveraged as highly convincing phishing lures.
Carbanak authors attempt ransomware infection by mailing disguised USBs to victims.
8 year old Microsoft Defender flaw highlighted by security researchers.
Microsoft sees in the new year with exchange server flaw dubbed Y22K, halting emails for affected organisations.
Purple Fox rootkit seeing increased distribution through trojanised versions of Telegram messenger.
Compromised version of Atera tools used to compromise organisations using decade old code signing oversight.
Rook, a new ransomware strain which appears to be created from the Babuk source code leak appears in the wild.
Researchers say Log4J flaw will take years to fully address owing to the sheer number of nested dependencies.
The ransomware gang which breached Gigabyte provides a free decryptor after realising they hit the US police.
New lightweight malware strain hides in the registry among other stealth techniques.
Two active directory bugs from November patch Tuesday abused in tandem by PoC to allow takeover.
Pysa ransomware strain experiences huge surge to become a top player as the year closes.
In this weeks episode the fallout from the Log4j discovery, new developments on the resurrection of Emotet & an accidental uncovering of Hello Kitty ransomware.
New Cerber ransomware impersonator targets Confluence and Gitlab servers.
Direct Cobalt Strike installation further suggests new Emotet infrastructure gearing up for Ransomware campaign.
Solarwinds attackers deploy new stealthy malware strain and search for new supply chain attack opportunities.
In this weeks episode, Trickbot adopt new evasion methods to avoid sandbox environments, nation state actors employ simple yet effective technique to perform post phishing exploitation, and an RCE vulnerability affecting over 150 distinct HP printer models has existed for over 8 years.
In this weeks episode proof of concept weaponised with alarming speed as windows installer zero day spotted in the wild, GoDaddy suffers breach affecting 1.2 million sites, ongoing since September and new strain of Linux malware hides in cron jobs scheduled for dates that don't exist.
This week’s Threat Intel news:
This week’s Threat Intel news:
This week’s Threat Intel news:
This week’s Threat Intel news:
This week’s Threat Intel news:
This week’s Threat Intel news:
This week's Threat Intel news:
This week's Threat Intel news:
In this week's episode:
This week's Threat Intel news in just 7 minutes:
This week's Threat Intel news in 6 minutes:
This week's Threat Intel news in 7 minutes:
This week's Threat Intel news in 7 minutes:
Some showstoppers this week, get the low down on:
This week we're discussing:
In this week's episode: Darkside returns, rebranding as Blackmatter following the Colonial Pipeline attack, disgruntled Conti ransomware affiliate leaks the groups playbook and training materials.
Also, ENISA concludes current defences will fold to supply chain based attacks based on recent examples.
In this weeks episode: Doppelpaymer looks to be performing a fairy obvious rebrand, The Babuk groups new ransomware forum ironically held to ransom, the no more ransom initiative saves over a billion in payments after 5 years in operation.
In this weeks episode, Kaseya obtains decryption master key, remaining quiet about its origin, the printer vulnerability nearly old enough to drive affects millions of machines, and Windows zero-day privilege escalation vulnerability affects even unreleased Windows 11.
This week we're discussing:
•Kaseya obtains decryption master key, but is remaining quiet about its origin
•Printer vulnerability nearly old enough to drive affects millions of machines
•Windows zero day privilege escalation vulnerability affects even unreleased Windows 11
This week we're discussing:
Kaseya made headings this week with a supply chain attack claiming approximately 1500 victims, and the largest ever ransom demand of $70m. Also, After OOB patch addressing PrintNightmare released by Microsoft, researchers discover a complete bypass.
In this week's bulletin we're discussing:
Ransomware is dominating the headlines again this week, we'll be discussing:
Avaddon, responsible for almost a quarter of all ransomware attacks in 2021, calls it quits.
EA reportedly breached via slack channel used to obtain MFA login token.
SITA, IT provider for 90% of the airline industry, hit by longform supply chain attack.
In this week's episode we're discussing:
In this week's episode we discuss:
This week we report on SolarWinds attackers NOBELIUM's latest campaign, 8 individuals arrested in connection with Royal Mail smishing campaign and a cheese-loving drug dealer sentenced to 13 years.
This week we report on New Zealand hospitals infected by ransomware, cancels surgeries, Colonial Pipeline CEO confirms $4.4 million payment & Qlocker ransomware shuts down after extorting hundreds of QNAP users.
This week we're focusing on the Colonial pipeline ransomware attack, the aftermath, and the potential long term consequences.
In this week's episode we're discussing:
In this week's episode - Another supply chain style attack, this time breaches an enterprise password manager, Babuk gets uncomfortably close to the plot of a bond film, threatening to expose informants if ransom goes unpaid and the “most reliable” UK rail network hit by ransomware as directors mail account hijacked.
This week we cover:
This week we cover FBI accesses exchange servers still affected by proxylogon without consent, Zoom RCE vulnerability requiring no user interaction debuted at Pwn2Own and US Government finally formally charges APT29 with Solarwinds breach.
In this week's episode we'll be discussing:
In this episode we'll be discussing:
In this week's episode we're discussing:
In this week's episode we discuss:
This week we report on:
In this week's episode we give you the lowdown on:
In this week's episode we discuss:
In this weeks episode we discuss the following news stories:
In this episode we discuss the following news items:
This week we report on remote Desktop Protocol Attacks surging by 768%, hacker modifying drinking water chemical levels in Florida and Cyperpunk 2077 creator CD Projekt Red hit with a ransomware attack.
This week we report on Malwarebytes joining the list of victims targeted by the SolarWinds attacker, attackers targeting cloud infrastructure more reliably bypassing MFA and the proof of concept code release, and public tool developed for CVSS 10 SAP vulnerability.
This week we report on suspected Lazarus attackers attempting to socially engineer security researcher to acquire zero days, legacy accounts of departed or deceased staff members being utilised for network compromise, and Emotet on the verge of collapse following infrastructure takedown.
In this episode you'll hear the latest threat intelligence for the week commencing 21 December 2020 and tactical advice to mitigate new threats.
This week we report on the SolarWinds attackers reportedly gaining some level of initial access via password spraying, similarities discovered between the malware used in SolarWinds attack and a Russian backdoor from 2017 and leak sites claiming to sell data obtained from recent SolarWinds compromise. Also the release of Microsoft tool updates to help detect process tampering type attacks and a Windows defender vulnerability being actively used in the wild patched.
This week we report on multiple US agencies have now officially attributed the SolarWinds breach to a Russian state group, Microsoft claim that the end goal of the Sunburst backdoor was to move into victims cloud infrastructure and hardcoded, stored in plaintext, admin level credentials discovered present on many Zyxel firewall and VPN products.
In this episode you'll hear the latest threat intelligence for the week commencing 14 December 2020 and tactical advice to mitigate new threats.