Talion Threat Set Radio: Recent Episodes

Talion Threat Intelligence Team

Talion Threat Set Radio is your weekly cyber threat intelligence bulletin. We cut through the noise to give you our honest opinion on the threat news that matters.

View Details

Evil Corp and LockBit members the target of global sanctions and arrests.
Quick fire topics.

View Details

Telegram in the spotlight, founder arrested, banned in Ukraine, and will now share user data on legal request.

Quick fire topics.

View Details

Explosions were a supply chain compromise, not a cyber attack.

Another Ivanti critical flaw exploited in the wild with public exploit.

View Details

Security giant Fortinet suffers data breach as 440GB of files stolen.

Quick fire lightning round.

View Details

Uncommon technique from 2017 resurrected to drop Cobalt Strike

Versa Director vulnerability leveraged by Volt Typhoon

New persistence technique allowed Linux malware to hide for years.

View Details

SolarWinds flaw exploited in the wild & hardcoded credentials.

Report indicates ransom payments will break last years record.

Lazarus exploit driver present on every Windows system.

View Details

In this weeks episode:
- Over 2 Billion Records of Personal Information Leaked.

  • Critical TCP/IP remote code execution vulnerability patched by Microsoft.

  • Ringleader of Ransom Cartel extradited to the US to face charges.

View Details

The legal challenges against CrowdStrike begin following update incident.

CISA re-issues seven year old warning over exploited Cisco install flaw.

Chinese group compromises ISP to push poisoned infostealer updates.

View Details

Microsoft vows less reliance on kernel drivers following CrowdStrike incident.

Cloudflare trial product increasingly abused for criminal obfuscation.

Black Basta sees success with in house tools following QBot takedown.

View Details

Repair documentation used to push malware after CrowdStrike incident.

New Linux variant of the prolific Play ransomware discovered.

New ICS malware FrostyGoop responsible for Ukraine attack.

View Details

Report highlights alarming speed PoC exploits are weaponized.

Kaspersky offers 6 months free service as farewell to US market.

Fin7 offers sophisticated evasion tool on underground markets.

CrowdStrike botched update causes global havoc.

View Details

Eldorado ransomware claims 16 victims in short timeframe.

Free decryptor released by Avast for DoNex ransomware strain.

Blast Radius attacks leverage MD5 collisions to gain admin.

View Details

"regreSSHion" SSH flaw leads to root on Linux servers.
GootLoader continues to deploy updated versions in new attacks.

View Details

Kaspersky software banned in US due to national security concerns.

LockBit misleadingly claims to hit US federal reserve.

TeamViewer compromised by Russian state sponsored APT group.

View Details

PoC exploit code available for heavily targeted Veeam backup solution.

New loader dubbed PhantomLoader delivers MaaS payloads.

Black Basta may have exploited flaw 3 months before fix issued, as 0 day.

View Details

Attackers target GitHub repos once again in Ransom-lite extortion.

Windows will finally depreciate NTLM, providing transition advice.

PoC chaining two flaws for Telerik report released.

View Details

In this week news:

  • Check Point Zero-day vulnerability.
  • Okta Credential Stuffing.
  • Operation Endgame Targets Botnets.

View Details

In this weeks episode, LockBit Ransomware group have had nothing but setbacks since “Operation Chronos”, GitHub alerts users to 2 high severity vulnerabilities and a significant uptick in Docusign phishing emails has been observed in May.

View Details

LockBit ransomware admin is named and sanctioned.

North Korean actors exploiting weak DMARC policies for spearphishing.

Ivanti flaws chained together to drop Mirai botnet.

View Details

Developers targeted with Python backdoor during false job interviews.

New UK law now in effect limits default passwords on smart devices.

New malware emerges targeting small office and home routers.

View Details

MITRE breached using two Ivanti zero days.

CrushFTP victim of targeted zero day exploitation.

ArcaneDoor campaign targets vulnerable Cisco devices.

View Details

Large scale exploitation of Palo Alto CVE following PoC disclosures.

Atlassian vulnerability leveraged to deploy Cerber ransomware.

PuTTY flaw can be used to obtain private cryptographic keys.

View Details

Warnings issued regarding 10/10 CVSS score Rust vulnerability.

Researchers speculate LLM wrote Powershell for malware strain.

Change Healthcare hit by ransom demand again following AlphV exit scam.

View Details

Sophisticated supply chain attack attempted against multiple Linux distros.

Linux false Sudo prompt flaw has persisted for over a decade.

DinodasRAT now targeting Linux servers with new variant.

View Details

Huge darknet marketplace seized by German takedown effort.

Muddywater group using legitimate RM tools for access.

APT31 members sanctioned following US infrastructure attacks.

View Details

Fujitsu discover malware compromised systems.

Russian actors may be targeting Ukrainian telecoms with new wiper malware.

New DoS technique discovered able to create infinite feedback loop.

View Details

Russian groups accesses Microsoft source code in follow up from January attack.

StopCrypt, the ransomware still targeting individuals over business has been upgraded.

DarkGate leverage recent SmartScreen vulnerability in attacks.

View Details

The Blackcat / AlphV ransomware operation fakes law enforcement takedown to steal from their own affiliate.

View Details

LockBit claims swift recovery from takedown operation, downplaying severity and threatening leaks.
Lazarus exploit Windows zero day flaw with new improved Rootkit.

View Details

DoJ takes down botnet used by Russian state group.

LockBit ransomware operation gutted by the NCA.

ScreenConnect under active attack, Lockbit utilised.

View Details

Anydesk confirms cyberattack that allowed hackers to gain access to the company's production systems, Cloudflare publicly disclose its internal Atlassian server was breached by a suspected nation-state attacker and the FBI disrupt and neutralize KV-botnet.

View Details

Microsoft confirms details of recent Russian compromise.

Kasseika joins ransomware groups performing BYOVD attacks.

Trickbot browser injection developer jailed.

View Details

VMware critical flaw under active exploitation.

Critical vulnerability discovered in Juniper firewalls and switches.

Ivanti bypass flaw exploited in the wild.

View Details

Evasive Async RAT has targeted infrastructure for almost a year.

New FBot toolkit targets SaaS and cloud platforms.

Turkish group uses Mimic ransomware to target MSSQL servers.

View Details

Critical Invanti flaw allows compromise of enrolled devices.

Multiple malware strains use Google feature for persistence.

Microsoft disables MSIX after it is abused by malware again.

View Details

Rhadamanthys infostealer gains popularity with new features.

MongoDB confirms breach and theft of customer data.

FBI confirms it breached the Blackcat ransomware group.

View Details

AlphV ransomware outage rumored to be caused by FBI.

New "Pool Party" injection technique evades 5 leading EDR solutions.

Lazarus continues to abuse Log4J with 3 new malware strains.

View Details

NCSC warns of Russian state group social engineering activity.

Okta customers affected by recent attack revised from 1% to 100%.

Researchers discover Linux rootkit RAT undetected since 2021.

View Details

Ransomware group arrested in Ukraine following attacks against 71 countries.

Method discovered to passively extract RSA keys from SSH connections.

Chrome fixes its 6th zero day exploited in the wild this year.

View Details

Russian state USB malware spreads to unintended targets.

Qbot moves to Darkgate and Pikabot following takedown.

Criminals claim ability to reuse expired Google auth cookies.

View Details

CISA adds three flaws to its KEV

Google Workspace and Cloud highlighted as attack vector.

VMWare warns of critical VCD flaw.

View Details

Microsoft will soon begin moving towards mandatory full MFA adoption.

GootLoader variant moves to stealthier self developed bot.

BlazeStealer targets developers with malicious code repos.

View Details

Recent F5 Big IP flaws exploited in stealthy attacks.

Citrix bleed flaw leveraged against government targets.

Mozi dismantled by mysterious killswitch command.

View Details

Fake Corsair job offers pushing Darkgate malware strain.

Ragnar Locker operation dealt heavy blow by Europol.

Okta support system compromised, customers breached.

View Details

Another Citrix Netscaler flaw exploited as a zero day since August.

Microsoft will phase out NTLM with Windows 11, in favour of Kerberos.

Multiple nation state groups are exploiting a recent critical WinRAR flaw.

View Details

Genetic information stolen by credential stuffing attack.

New “rapid reset” zero day enables record breaking DDoS.

Microsoft will kill of VBScript in the near future.

View Details

New BunnyLoader MaaS becomes popular due to features and pricing.

Atlassian Confluence under active exploitation from new 0-day.

Looney Tunables vulnerability enables root on popular Linux distros.

View Details

Maximum severity CVE assigned to libwebp following Google error

New ShadowSyndicate group tied to several ransomware ops

View Details

VenomRAT dropped by fake PoC exploit for WinRAR flaw.

Newly observed Sandman group targets Telecoms.

BlackCat ransomware operation targets Azure storage.

View Details

Teams phishing techniques ignored by Microsoft used by ransomware enablers.

A new chain of Kubernetes vulnerabilities can lead to code execution.

Operators of the Redline and Vidar malware pivot to ransomware.

View Details

Cisco acknowledge VPN zero day exploited by ransomware actors.

North Korean threat actors target cyber security researchers.

New Blister malware updates drive quiet network infiltration.

View Details

PoC Exploit chain enables RCE attacks against Juniper firewalls.

Attacks against Citrix Netscaler devices linked to FIN8.

Qakbot botnet dismantled in aptly named “Operation Duck Hunt”

View Details

WinRAR flaw enables command execution by simply opening an archive.

Malware strain maps victims location in real time via Wi-Fi triangulation.

PoC exploit released for Ivanti vulnerability recently used in attacks.

View Details

Nearly 2000 Citrix NetScaler servers compromised in new campaign.

NoFilter, new stealthy privilege escalation technique discovered.

Raccoon returns with version 2.3 after 6 month hiatus.

View Details

AWS system manager can be leveraged as a remote access trojan.

CISA highlights the SUBMARINE backdoor used in Barracuda ESG attacks.

Google AMP links abused for stealthy phishing campaigns.

View Details

Compromised IIS servers used as malware delivery mechanism by Lazarus

Critical zero days in Atera platform could allow for privilege escalation.

Decoy Dog toolkit appears highly targeted and largely undetected.

View Details

Lazarus targets developers with malicious GitHub projects.

USB malware strains SOGU and SNOWYDRIVE drive huge infection vector increase.

Gamaredon campaign exfiltrating files mere 30 minutes after initial infection.

View Details

WormGPT, an AI tool which could make BEC attacks trivial.

Chinese hackers exploit flaw in Windows policy to load malicious kernel drivers.

View Details

BlackCat ransomware group uses WinSCP SEO poisoning to push cobalt strike.

New “StackRot” Linux vulnerability enables privilege escalation. 

View Details

New EarlyRAT malware attributed to Lazarus offshoot.

Microsoft issues warning on increased widespread credential theft activity.

New Mockingjay process injection technique could bypass EDR detection.

View Details

US Government offers $10m bounty for info on the Clop ransomware group following MOVEit attacks.

New “Mystic Stealer” malware as a service gaining traction in underground groups.

APT37 deploying new “Fadestealer” espionage malware.

View Details

Batcloak malware obfuscation engine tied to various successful malware strains.

Hackers impersonate cybersecurity experts and peddle poisoned PoC code.

View Details

PoC released for Win32K flaw actively exploited in attacks

Chinese group Camaro Dragon use new TinyNote backdoor for intel gathering.

The Clop threat actor claims responsibility for the MOVEit data theft attacks.

View Details

Gigabyte firmware vulnerability potentially affects 7 million devices.

Phishing toolkits develop new ticks using new .ZIP TLD.

New malware used to target and disrupt power grids discovered.

View Details

Tool which allows extraction of KeePass master password publicly available.

Geacon, an open source Cobalt Strike port usable on MacOS, sees spike in use.

Report outlines Microsoft Teams functions which can enable phishing and more.

View Details

ViperSoftX infostealer expands to target specific password managers.

DLL sideloading is so effective, attackers begin doubling up the technique.

North Korean Kimsuky group employing new Reconshark recon tool.

View Details

GhostToken flaw, which allowed invisible persistence, patched and visible.

AuKill tool used in attack pipeline to kill EDR processes.

PoC exploit code available for Papercut flaw, which allows server takeover.

View Details

Lazarus moves to distribute Linux malware via faux job offers.

Aurora distributed via YouTube, resulting in evasive loader payload.

Tangle of attackers as multiple groups collaborate with Domino malware.

View Details

Lazarus evolve their tactics and targeted industries.

Zero day from recent patch Tuesday under active Ransomware exploitation.

MuddyWater pairing with new splinter group to perform destructive attacks.

View Details

Wordpress plugin with over 11 million install base under active exploitation.
Western Digital hit by cyber attack, services impacted, cause unclear.
SFX archives can be used to run stealthy Powershell backdoors.

View Details

Malicious Python package avoids detection through use of Unicode Homoglyphs.

The well established IcedID malware shifts from banking to ransomware delivery.

Supply chain attack hits customers of 3CX VOIP application, including the NHS.

View Details

In this week’s episode we report on:
Fortinet zero-day vulnerability CVE-2022-42475 being exploited by a Chinese hacking group UNC3886, recent tactics from Russian state backed group Nobelium & Hitachi Energy confirmed as latest victim of Cl0ps exploitation of Fortra’s GoAnywhere MFT vulnerability.

View Details

New GoBruteforcer botnet in active development according to report.

AI videos are being used as an effective lure to drop malware.

Document signing services abused to deliver Redline stealer.

View Details

Emotet returns following 3 month break.

CISA issues advisory regarding new Royal ransomware capabilities.

Old UAC bypass technique used to drop Remcos.

View Details

Rig exploit kit going strong despite focusing on IE vulnerabilities.

PlugX seeing success posing as legitimate windows debug utility.

New advanced post exploitation framework linked to Lockbit affiliates.

View Details

North Korean trojan targets residents of specific cities.

GoDaddy reveals multi-year security breach.

New malware as a service circulated on the dark web.

View Details

In this weeks episode: Updates on Clop’s claims it breached 130 orgs using GoAnywhere zero-day, ESXiArgs Ransomware Hits Over 500 New Targets in European Countries, The Killnet DDoS Blocklist, Russia’s Ransomware Gangs Are Being Named and Shamed by UK & US and Patch Now: Apple's iOS, iPadOS, macOS, and Safari Under Attack with New Zero-Day Flaw.

View Details

New actor spotted utilising “screenshotter” in targeted attacks.

Gootkit continues to push SEO to target Healthcare and Finance

Lockbit claims responsibility for the Royal Mail ransomware attack.

View Details

Packer operation uncovered used in major attacks since 2016.

Lockbit green offers familiarity for displaced Conti affiliates.

Microsoft OneNote is the latest infiltration vector pivot.

View Details

Emotet tricks victims into moving malicious files to trusted locations.

Vice ransomware operation disrupted by international effort.

Invisible PlugX variant spreads across USB drives, steals documents.

View Details

More than 1 in 20 internet facing Sophos firewalls still vulnerable to RCE vulnerability.

CircleCI breach leads to the platform rotating many customer tokens due to severity.

Ransomware generates 40% less profit than previous 2 years, as victims refuse to pay.

View Details

Turla leverages decade old defunct Gamarue infrastructure to attack Ukraine

JWT security flaw could potentially lead to Remote Code Execution

Gootkit abusing VLC through SEO poisoning campaign targeting healthcare

View Details

Slack suffers theft of internal GitHub code repositories over the holidays.

Play confirmed as the ransomware operation behind the Rackspace breach.

View Details

Google Ads increasingly used to sideload malware alongside legitimate software.

APTs turn to XLL files following office macros being disabled by default.

View Details

Okta source code stolen following GitHub repo breach.

LastPass confirms customer password vaults stolen in earlier breach.

View Details

Fortinet SSL critical vulnerability exploited in attacks.

Citrix ADC & Gateway critical vulnerability exploited in attacks.

SVG image files used as infiltration vector by QBot malware.

View Details

MuddyWater leverage compromised accounts to drop legitimate admin tools.

Open source ransomware strain acts as a wiper due to poor coding.

Rackspace confirm outage is ransomware related, no attribution yet.

View Details

Acer laptops possess flaw which allows secure boot to be disabled.

NPM package naming quirk can bypass security checks.

LastPass suffers second security breach in 3 months as direct result of the first.

View Details

Another ransomware variant switches to the Rust programming language.

Several threat actors observed switching to new Go based Aurora infostealer.

Report suggests Nighthawk may soon be adopted as another Cobalt Strike alternative.

View Details

Chinese groups increasingly using Google drive and similar applications as infiltration vectors.

QBot leverages Control Panel to launch malware after previously abusing Calc.exe.

Lazarus employ updated version of DTrack as part of new wave of attacks.

View Details

Lockbit affiliate includes Amadey bot as part of new infection chain.

Experts warn URLscan integrations are leaking sensitive data.

15,000 sites, primarily WordPress, compromised as part of SEO campaign.

View Details

RAT campaign impersonates legitimate password and backup software as delivery method.

Chinese group using new quiet infection chain to drop LODEINFO.

Media company compromised and used to push SocGholish through US news sites.

View Details

Emotet becomes prime distributor of self extracting malicious archives

GitHub repositories claiming to be PoC code actually contain various malware.

Two flaws which directly target Windows event logs could result in DoS.

View Details

Microsoft sensitive data breach linked to over 65,000 entities.

Ursnif mirrors its peers, evolving from banking trojan to platform.

New Powershell backdoor bypasses AV detection, hits 60+ victims.

View Details

POC available for critical Forinet vulnerability

ProxyNotShell patches conspicuously missing from patch Tuesday

Microsoft Defender to add automatic C2 detection to its capabilities

View Details

BlackByte group abuses “bring your own driver” flaw in attacks.

Lazarus exploit existing Dell drivers to gut detection capabilities.

Updated mitigation actions for ProxyNotShell issued after original actions bypassed.

View Details

New zero day “similar to proxylogon” used in exchange attacks.

Brute Ratel has been cracked, and will likely replace Cobalt Strike imminently.

A new dropper unloads a dozen infections, some of which are droppers themselves.

View Details

Lockbit 3.0 toolkit leaked online by one or more angry developers.

15 year old unpatched Python flaw present in over 350,000 projects.

Emotet post Conti, now distributes Quantum and BlackCat.

View Details

Iranian group leverages bitlocker to perform encryption.

Intermittent encryption gains popularity among ransomware operators.

Bumblebee gains new post exploitation and stealth capabilities.

View Details

Twilio breach allowed attackers access to Okta single use sign on codes.

Raspberry Robin USB malware linked to EvilCorp via Dridex similarities.

Ransomware written in more obscure languages trend continues with Golang based “Agenda”

View Details

LastPass suffers breach, unknown amount of source code stolen.

APT29 and others leveraging dormant accounts to bypass MFA.

Lockbit victim Entrust appears to DDoS the ransomware operation in retaliation.

View Details

Electron, the backbone of Teams and Discord, has a one click RCE vulnerability uncovered.

POC for a 9.8 vulnerability targeting Realtek routers released online.

Callback phishing as an attack vector sees an alarming 625% spike from last quarter.

View Details

This week’s topics-

Twitter discloses a breach affecting 5.4 million accounts that could enable smishing, phishing and sim swapping attempts.

A suspected nation state cyberattack on NHS’s 111 service points speculation towards a Russian retaliation attack.

Killnet announced its operations shall soon turn lethal.

View Details

Lockbit switches to abusing Windows Defender as Cobalt Strike loader.

Raspberry Robin possibly linked to EvilCorp.

Gootkit reappears with new infection vectors.

Suspected Darkside rebrand BlackCat learns nothing, attacks gas pipeline. 

View Details

UEFI malware in development since 2016 discovered in Gigabyte and ASUS motherboards.

As Microsoft finally disables macros by default, container files emerge as replacement delivery mechanism.

QBot uses old version of Windows Calculator to facilitate DLL hijacking.

View Details

Atlassian issues fix for critical hardcoded credentials vulnerability

Two new ransomware strains are cross platform in nature

New modular “Lightning Framework” adds to fears of Linux malware surge

View Details

Impersonation of cybersecurity firms by threat actors as part of callback phishing attacks.

Luna Moth becomes the latest attack group to perform Ransomware style extortion without encryption.

Searchable data leak sites gain traction among threat actors as new leverage tool.

View Details

Ransomware affiliates spoof US companies to obtain new red team tools as they pivot away from Cobalt Strike.

Hive ransomware strain is completely re-written in Rust, gaining faster encryption among other benefits.

Microsoft reverses change popular among InfoSec community, no longer disabling document macros by default.

View Details

Mitel phone bug exploited to perform ransomware attack.

Lockbit 3.0 introduces first ransomware bug bounty program.

AMD reportedly suffers attack and data is currently held for ransom.

View Details

New variation of PetiPtoam flaw dubbed DFSCoerce can allow windows domain takeover.

Okta discusses Lapsus$ breach and how zero trust helped secure network from worse effects.

A collection of 56 flaws dubbed Icefall degrades security posture of thousands of OT devices.

View Details

New Symbiote Linux malware has several concerning stealth, obfuscation, and rootkit style techniques.

Emotet returns, featuring a similar codebase, but a host of new tricks.

Report highlights how non admin 0365 access could be used to sabotage/encrypt cloud files.

View Details

Two recent flaws can be combined to create very sophisticated phishing attacks.

Dridex authors EvilCorp become a LockBit affiliate, likely in another effort to evade sanctions.

POC code released for “trivial” to exploit Atlassian Confluence vulnerability.

View Details

New Chromeloader malware employs stealthy installation and persistence methods.

New MS Office zero day allows “no click” powershell exploitation even with macros disabled.

View Details

Information on a Russian botnet designed to manipulate social media trends and spread disinformation, facial recognition technology Clearview AI is fined by the UK government and an Iranian threat group target the port of London authority. 

View Details

New modular Eternity malware being offered via Telegram

Conti appears to encourage overthrowing the Costa Rican government

Conti reportedly shuts down, splintering into smaller cells and operations.

View Details

US sanctions crypto laundering service used by the North Korean Lazarus group.

Full featured Russian RAT DarkCrystal is selling perpetual licences for a mere $40.

US offers a $15,000,000 bounty for information leading to the Conti overlords.

View Details

Confirmation of REvils return as new sample is obtained and analysed.

New technique discovered involving hiding payload in Windows Event Logs.

Ukraine affiliated hacktivists target Russian alcohol production pipeline.

View Details

Bumblebee appears to replace BazarLoader as Conti’s delivery vector of choice.

Emotet returns to full operation, more than a year after coordinated takedown.

FBI circulates warning regarding new BlackCat ransomware strain.

View Details

No 10 suspected of being target of NSO spyware attack, U.S. offers $5 million for info on North Korean cyber operators & notorious cybercrime gang’s botnet ZLoader disrupted

View Details

Raidforums seized, owner and operator arrested after running the site since the age of 14.

Microsoft works with US government to dismantle operations targeting Ukraine.

In an act of poetic justice, Conti source code is repurposed to attack Russian targets.

View Details

Intel completely shuts down business in Russia, exacerbating component shortage fears.

German investigators shut down Hydra, the largest illegal Darkweb marketplace.

Borat remote access trojan, with ransomware and other capabilities, offered for sale.

View Details

Chinese security researcher accidentally releases spring framework PoC exploit.

Raccoon stealer malware operation suspended after key developer killed in Ukraine invasion.

Kaspersky pose “unacceptable risk” as the Russian security giant is removed from bug bounty programs.

Lapsus$ return from vacation, and take arrests in stride releasing 70gb of data stolen from Globant.

View Details

Open source software poisoned and turned into supply chain attack as anti war protest.

Much newer functional version of Conti leaked online as revenge by Ukrainian member.

Lapsus$ members arrested in London after more high profile hits over the last week.

View Details

In this weeks episode, the arrest and extradition of a NetWalker ransomware affiliate, the exploitation of unskilled Ukrainian hackers and finally, a campaign which suggests China may be helping Russia in their cyber efforts towards the conflict.

View Details

Hosted by Talion's in-house Threat Intelligence team, this special Threat Set Radio podcast episode covers some of the specific threats Higher Education is facing:

·         BotNet targeting Higher Education

·         Log4Shell exploit

·         Recent Ransomware attacks on Higher Education

View Details

Cybersecurity news regarding the ongoing Russian invasion of Ukraine rundown.

Certificates obtained from Nvidia leak used to sign malware.

Lapsus$ breaches Samsung shortly after the Nvidia attack.

View Details

Data wiper pointed at Ukraine appears to have been in development for months.

Ukranian researcher leaks Conti comms after they announce support for Russian invasion.

Trickbot developers appear to fold into Conti operation in act of cybercrime consolidation.

Nvidia hacked and employee data stolen, only to promptly hack the attackers back.

View Details

This week’s topics- Analysis of the DDoS Attacks against Ukrainian Websites, New Sandworm malware #Cyclops Blink replaces VPNFilter & a jammer used to stop kids going online, wipes out a town's internet by mistake.

View Details

Microsoft Defender to gain ability to block credential theft via Mimikatz and similar methods.

Kraken botnet spread using Smokeloader, and is observed dropping Redline.

Hackers using Microsoft Teams to perform extremely blatant internal attacks.

View Details

Russia performs third major cybercrime arrest as apparent crackdown continues.

Ransomware gangs adapt in effort to draw less attention and retaliation.

Smokeloader spearheads long list of malware strains using pay per install service to expand 

View Details

Malicious CSV files used as Bazar malware infection vector.

Research compiled from 2021 shows most ransomware infections are self installed.

New publicly available Windows privilege escalation vulnerability as admins skip January patch.

View Details

Windows Update used by Lazarus as a living off the land tool to deploy malware.

Firmware level rootkits becoming more popular as 3rd to hide in SPI flash discovered.

Microsoft finally disables Excel XML macros by default in effort to block malware.

View Details

Russian authorities claim to dismantle the entire REvil ransomware operation, and seize assets.

Dark web card fraud platform shuts up shop after 8 years citing age of operators.

New ransomware strain dubbed White Rabbit linked to Fin8 group.

View Details

Google doc comments leveraged as highly convincing phishing lures.

Carbanak authors attempt ransomware infection by mailing disguised USBs to victims.

8 year old Microsoft Defender flaw highlighted by security researchers.

View Details

Microsoft sees in the new year with exchange server flaw dubbed Y22K, halting emails for affected organisations.

Purple Fox rootkit seeing increased distribution through trojanised versions of Telegram messenger.

Compromised version of Atera tools used to compromise organisations using decade old code signing oversight.

View Details

Rook, a new ransomware strain which appears to be created from the Babuk source code leak appears in the wild.

Researchers say Log4J flaw will take years to fully address owing to the sheer number of nested dependencies.

The ransomware gang which breached Gigabyte provides a free decryptor after realising they hit the US police.

View Details

New lightweight malware strain hides in the registry among other stealth techniques.

Two active directory bugs from November patch Tuesday abused in tandem by PoC to allow takeover.

Pysa ransomware strain experiences huge surge to become a top player as the year closes.

View Details

In this weeks episode the fallout from the Log4j discovery, new developments on the resurrection of Emotet & an accidental uncovering of Hello Kitty ransomware.

View Details

New Cerber ransomware impersonator targets Confluence and Gitlab servers.

Direct Cobalt Strike installation further suggests new Emotet infrastructure gearing up for Ransomware campaign.

Solarwinds attackers deploy new stealthy malware strain and search for new supply chain attack opportunities.

View Details

In this weeks episode, Trickbot adopt new evasion methods to avoid sandbox environments, nation state actors employ simple yet effective technique to perform post phishing exploitation, and an RCE vulnerability affecting over 150 distinct HP printer models has existed for over 8 years. 

View Details

In this weeks episode proof of concept weaponised with alarming speed as windows installer zero day spotted in the wild, GoDaddy suffers breach affecting 1.2 million sites, ongoing since September and new strain of Linux malware hides in cron jobs scheduled for dates that don't exist.

View Details

This week’s Threat Intel news:

  • Emotet rises from the dead, uses its old payload Trickbot to rebuild itself.
  • North Korea state actors target security researchers with compromised analysis software.
  • Research highlights the TLDs favoured by attackers for different types of malicious activity.

View Details

This week’s Threat Intel news:

  • US charges 2 suspected major REvil ransomware operators
  • Conti ransomware gang make grovelling apology to Arab Royals over data leak
  • TeamTNT hackers target your poorly configured Docker server

View Details

This week’s Threat Intel news: 

  • Darkside hit with a $10m bounty as fallout of Colonial Pipeline attack continues.
  • Critical Linux kernel vulnerability disclosed.
  • FBI releases advisory stating ransomware gangs specifically target victims in financially sensitive negotiations.

View Details

This week’s Threat Intel news:

  • Avoslocker reportedly hits Gigabyte, possibly obtains files enabling supply chain attacks.
  • Conti begins selling access to non compliant victims networks.
  • Rootkit discovered bearing a valid Microsoft signature after evading vetting process.

View Details

This week’s Threat Intel news:

  • Macaw Locker is Evilcorps latest ransomware strain rebrand to evade sanctions.
  • Trickbot uses new tricks for distribution.
  • FIN7 creates fake English cybersecurity firm to hire pen-testers to perform criminal attacks.

View Details

This week’s Threat Intel news:

  • New EU legislation could ban anonymous domain registration, in an effort to curb cyber crime
  • FINN12 becomes the first ransomware affiliate to be elevated to threat actor level, targets healthcare
  • SnapMC skips the traditionally most important part of ransomware, and just plain extorts victims

View Details

This week's Threat Intel news: 

  • Ransomware operators arrested and ill gotten gains seized in Ukraine
  • Atom Silo ransomware strain targets Confluence servers and employs novel evasive measures
  • Apache Airflow vulnerability morphs into remote code execution as POC is released

View Details

This week's Threat Intel news:

  • Microsoft scrambles to register autodiscover domains exploited in flaw it was warned of years ago.
  • The Conti ransomware gang target new recruits with specific backup destruction experience.
  • FoggyWeb malware attributed to the group behind the infamous Solarwinds attack.

View Details

In this week's episode:

  • OS compatibility features abused to stealthily deliver malware.
  • VMware notifies customers of particularly concerning vulnerability prior to disclosure
  • US government poised to sanction Crypto exchanges which have dealt with cyber criminals

View Details

This week's Threat Intel news in just 7 minutes:

  • The recent Apple hack
  • Dark web forum Marketo making a name for themselves
  • Update on recent ransomware activity

View Details

This week's Threat Intel news in 6 minutes:

  • New malware technique observed using CLFS log files to evade detection.
  • REvil returns after 2 months of hiding, attacks UK based ITSP with DDoS attacks.
  • Babuk source code leaked by ransomware developer dying due to stage 4 lung cancer.

View Details

This week's Threat Intel news in 7 minutes:

  • Lockfile ransomware utilises intermittent file encryption to bypass defences.
  • Microsoft exchange flaw can enable remote theft of entire mailbox.
  • BazaLoader uses fake DMCA takedown and DDoS notices as lures to deliver malware.

View Details

This week's Threat Intel news in 7 minutes:

  • Details emerge on Fin8’s newly developed backdoor
  • Razer products allow alarmingly easy local privilege escalation
  • Proxyshell attacks on the rise despite patch issued months ago

View Details

Some showstoppers this week, get the low down on: 

  • Blackbaud in court battle over downplaying the severity of its 2020 ransomware attack
  • Almost half of US hospitals have shut down networks due to ransomware, new report shows
  • Possible terrorist suspect and no fly list exposed on Elasticsearch cluster with no password

View Details

This week we're discussing:

  • Gigabyte, and American Megatrends GIT breached by RansomEXX
  • Accenture hit by Lockbit RaaS operation in the wake of REvil and Darkside winding down
  • Vulnerability disclosed in Arcadyan router firmware present for over a decade

View Details

In this week's episode: Darkside returns, rebranding as Blackmatter following the Colonial Pipeline attack, disgruntled Conti ransomware affiliate leaks the groups playbook and training materials.

Also, ENISA concludes current defences will fold to supply chain based attacks based on recent examples.

View Details

In this weeks episode: Doppelpaymer looks to be performing a fairy obvious rebrand, The Babuk groups new ransomware forum ironically held to ransom, the no more ransom initiative saves over a billion in payments after 5 years in operation.

View Details

In this weeks episode, Kaseya obtains decryption master key, remaining quiet about its origin, the printer vulnerability nearly old enough to drive affects millions of machines, and Windows zero-day privilege escalation vulnerability affects even unreleased Windows 11.

View Details

This week we're discussing:

•Kaseya obtains decryption master key, but is remaining quiet about its origin

•Printer vulnerability nearly old enough to drive affects millions of machines

•Windows zero day privilege escalation vulnerability affects even unreleased Windows 11

View Details

This week we're discussing:

  • New Solarwinds vulnerability under active exploitation
  • REvil disappears from the face of the earth following Kaseya attack fallout
  • Trickbot resurgence with new capabilities

View Details

Kaseya made headings this week with a supply chain attack claiming approximately 1500 victims, and the largest ever ransom demand of $70m.  Also, After OOB patch addressing PrintNightmare released by Microsoft, researchers discover a complete bypass.

View Details

In this week's bulletin we're discussing:

  • Criminal VPN service taken down by law enforcement, who claim to have seized customer logs.
  • Code to exploit windows print spooler service accidentally released, disable ASAP.
  • Babuk ransomware building tool leaked to VT and immediately used by copycats.

View Details

Ransomware is dominating the headlines again this week, we'll be discussing:

  • Clop ransomware chugs onward despite arrests of multiple members and equipment seizures.
  • 700GB of ADATA files publicly released following refusal to pay ransom.
  • Data leak marketplace attempts to entice competitors into buying rivals compromised data.

View Details

Avaddon, responsible for almost a quarter of all ransomware attacks in 2021, calls it quits.

EA reportedly breached via slack channel used to obtain MFA login token.

SITA, IT provider for 90% of the airline industry, hit by longform supply chain attack.

View Details

In this week's episode we're discussing:

  • Evilcorp attempts to imitate other criminal group to evade sanctions
  • Attackers are actively looking to leverage new VMware vulnerability with working PoC code
  • Colonial ransomware incident attributed to old VPN password found in previous breaches
  • Largest stolen credentials market taken down by joint operation

View Details

In this week's episode we discuss:

  • HaveIBeenPwned partners with the FBI
  • Worlds largest meat producer hit by REvil ransomware attack
  • Group responsible for the Solarwinds nightmare begins new campaign
  • Babuk group moves away from encryption, toward data extortion model instead

View Details

This week we report on SolarWinds attackers NOBELIUM's latest campaign, 8 individuals arrested in connection with Royal Mail smishing campaign and a cheese-loving drug dealer sentenced to 13 years.

View Details

This week we report on New Zealand hospitals infected by ransomware, cancels surgeries, Colonial Pipeline CEO confirms $4.4 million payment & Qlocker ransomware shuts down after extorting hundreds of QNAP users.

View Details

This week we're focusing on the Colonial pipeline ransomware attack, the aftermath, and the potential long term consequences.

View Details

In this week's episode we're discussing:

  • Dell kernel bugs have the potential to be used against an install base of hundreds of millions
  • New spectre flaw surfaces, bypasses all current protections
  • A student delivers Ryuk onto research institute estate after downloading cracked software

View Details

In this week's episode - Another supply chain style attack, this time breaches an enterprise password manager, Babuk gets uncomfortably close to the plot of a bond film, threatening to expose informants if ransom goes unpaid and the “most reliable” UK rail network hit by ransomware as directors mail account hijacked.

View Details

This week we cover:

  • Codecov compromised in another large supply chain attack
  • Ryuk updates its techniques to include novel evasion methods
  • The Bazarloader campaign uses collaboration platforms to increase infection rate

View Details

This week we cover FBI accesses exchange servers still affected by proxylogon without consent, Zoom RCE vulnerability requiring no user interaction debuted at Pwn2Own and US Government finally formally charges APT29 with Solarwinds breach.

View Details

In this week's episode we'll be discussing:

  • LinkedIn job offer phishing delivers more_eggs
  • VMWare suffers another critical vulnerability, this time in security platform
  • SAP issues advisory on how quickly attackers reverse engineer their own patches

View Details

In this episode we'll be discussing:

  • Insurance Giant CNA hit by new ransomware strain tied to Evilcorp
  • Official PHP Git server appears to have been compromised, and a supply chain attack attempted.
  • Ransomware group pledges to return payments, after pocketing a tidy profit due to Bitcoin inflation.

View Details

In this week's episode we're discussing:

  • Multiple high profile hackers charged, after targeting multiple companies including Tesla.
  • Acer hit by ransomware demanding largest known ransom demand to date, 50 million USD
  • Evil corp reportedly creates Wastedlocker spinoff to evade sanctions on ransom payment.

View Details

In this week's episode we discuss:

  • 6 Distinct APTs leveraged the exchange 0-day prior to patch, indicating previously unseen co-operation.
  • Ransomware joins the list of post exchange exploit activity with the new strain “Dearcry”
  • Trickbot takes the crown once held by Emotet prior to its takedown.

View Details

This week we report on:

  • the Hafnium hack, posing a new long-term threat for already overtaxed cyber workers,
  • operators of REvil ransomware threatening DDoS attacks and increase intimidation techniques by threatening Journalists and Business Partners over the phone,
  • and the breach of 150,000 Verkada surveillance camera feeds for the NHS, Tesla and numerous other large organisations.

View Details

In this week's episode we give you the lowdown on:

  • Ryuk develops self propagation capabilities, possibly due to Emotet takedown.
  • Four exchange vulnerabilities cause Microsoft to fear a repeat of the past.
  • Maza, infamous and exclusive Russian cybercriminal forum, suffers breach.

View Details

In this week's episode we discuss:

  • Critical VMware vulnerability discovered, present in the default install of the majority of enterprise data centers.
  • Tool previously believed to be made by Chinese APT group appears to be cloned stolen NSA tool.
  • New details emerge regarding browser zero day used to target security researchers.

View Details

In this weeks episode we discuss the following news stories:

  • Google patches the Chrome zero day suspected of use in targeted attacks against security researchers
  • Windows installer vulnerability is now exploitable for a 6th time as yet another bypass method is released
  • Trickbot continues to evolve and adapt following takedown attempt, this time adding a MassScan module

View Details

In this episode we discuss the following news items: 

  • Jones Day law firm files released after the company refuses to pay ransom
  • Accelion product responsible for data breach is retired after decades of operation
  • Kia Motors America fall afoul of a Doppelpaymer ransomware attack
  • Microsoft claims the Solarwinds Orion compromise was the work of over 1000 engineers

View Details

This week we report on remote Desktop Protocol Attacks surging by 768%, hacker modifying drinking water chemical levels in Florida and Cyperpunk 2077 creator CD Projekt Red hit with a ransomware attack.

View Details

This week we report on Malwarebytes joining the list of victims targeted by the SolarWinds attacker, attackers targeting cloud infrastructure more reliably bypassing MFA and the proof of concept code release, and public tool developed for CVSS 10 SAP vulnerability.

View Details

This week we report on suspected Lazarus attackers attempting to socially engineer security researcher to acquire zero days, legacy accounts of departed or deceased staff members being utilised for network compromise, and Emotet on the verge of collapse following infrastructure takedown.

View Details

In this episode you'll hear the latest threat intelligence for the week commencing 21 December 2020 and tactical advice to mitigate new threats. 

View Details

This week we report on the SolarWinds attackers reportedly gaining some level of initial access via password spraying, similarities discovered between the malware used in SolarWinds attack and a Russian backdoor from 2017 and leak sites claiming to sell data obtained from recent SolarWinds compromise. Also the release of Microsoft tool updates to help detect process tampering type attacks and a Windows defender vulnerability being actively used in the wild patched.

View Details

This week we report on multiple US agencies have now officially attributed the SolarWinds breach to a Russian state group, Microsoft claim that the end goal of the Sunburst backdoor was to move into victims cloud infrastructure and hardcoded, stored in plaintext, admin level credentials discovered present on many Zyxel firewall and VPN products. 

View Details

In this episode you'll hear the latest threat intelligence for the week commencing 14 December 2020 and tactical advice to mitigate new threats.