All Articles (2444)

Sort by

8910287276?profile=RESIZE_400xThe US Nation’s Capital police department has reportedly been hit by Russian-speaking ransomware threat actors who claim to have stolen sensitive information on informants.  If true, this is a very troubling cyber-attack.  If informants cannot keep their anonymity, they will never work with the police.  The Babuk group gave police three days to pay-up before it shares the data with local gangs, according to media sources.  The files were allegedly posted on a dark web forum. 

Babuk ransomware is

8902582475?profile=RESIZE_400xActivity Summary - Week Ending 7 May 2021:

  • Taleq Simeon needs a new Email Address
  • Red Sky Alliance identified 15,654 connections from new unique IP Addresses
  • Analysts identified 1,209 new IP addresses participating in various Botnets
  • Researchers observed 20 unique email accounts compromised with Keyloggers
  • FormBook Variant – Part III
  • Google Play Store
  • Oil and Gas getting SMART
  • Oil and Gas on the Rise, Finally
  • Cyber-Attack on Oil and Gas to ‘continue’ Rise
  • Angola’s National Oil, Gas and Biofuel’

8895965100?profile=RESIZE_400xThreat researchers have come across two new phishing scams targeting customers of JPMorgan Chase Bank.  Both attacks deployed social engineering and brand impersonation tactics to steal customers' login credentials.  While one scam involved an email that appeared to contain a credit card statement, the other impersonated a locked account workflow to falsely inform victims that access to their account had been blocked following the detection of unusual login activity.

Cyber threat researchers sai

8895950496?profile=RESIZE_400xThe current US administration is introducing a 100-day plan to improve cybersecurity and address cyber threats across the nation's electrical grid.  Officials state the program is part of a broader cybersecurity plan designed to address issues across the nation's critical infrastructure.

The 100-day initiative will involve government agencies that are responsible for the security of critical infrastructure as well as businesses and private utilities that oversee or own infrastructure, such as el

8892672262?profile=RESIZE_400xA specially crafted update created by Germany's Bundeskriminalamt (BKA) federal police agency created and pushed the uninstall update.  European law enforcement has triggered the process of removing the Emotet botnet malware from 1.6 million infected computers around the world.  Emotet was thought to be the world's largest botnet, known for spewing millions of malware-laden spam emails each day. Law enforcement in the US, Canada and Europe conducted a coordinated takedown of Emotet infrastructur

8892667262?profile=RESIZE_400xThe malware seems like nothing special at first, but further exploration shows it can wreak serious damage in follow-on attacks.  The NitroRansomware malware strain is changing the ransomware norm by demanding Discord Nitro gift codes from victims instead of actual money.  Discord is a VoIP, instant messaging and digital-distribution platform designed for creating communities. Users communicate with voice calls, video calls, text messaging, media and files in private chats or as part of communit

The FBI and the Cybersecurity and Infrastructure Security Agency are warning of continued cyber threats stemming from Russia's Foreign Intelligence Service, or SVR, which the Biden administration accused of carrying out the SolarWinds supply chain attack.

In a joint alert issued 26 April 2021, the agencies warn that despite economic and other sanctions against Russia announced by the White House on 15 April 2021, attackers associated with the SVR likely will continue to target government network

8889849660?profile=RESIZE_400xAre large organizations better when it comes to cyber security? There are areas in which small and midsize businesses achieve stronger outcomes.  Cisco recently released the 2021 Security Outcomes Study - Small and Midsize Business (SMB) Edition, which revealed a number of somewhat surprising findings about SMBs and how they compare to their larger counterparts.

The entire report can be viewed at:  2021 Security Outcomes Study for Small to Midsize Businesses (SMBs) (cisco.com)

The report found t

8875085260?profile=RESIZE_400xThe US Justice Department (DOJ) is creating a task force to tackle the growing threat of ransomware and related extortion schemes targeting school districts, hospitals and others, according to an internal department memo that began circulating the third week of April 2021.

The newly established Ransomware and Digital Extortion Task Force (RDE-TF) will include DOJ officials as well as representatives from the FBI and the Executive Office for US Attorneys.  The task force will target the "ransomwa

8874465853?profile=RESIZE_400xActivity Summary - Week Ending 30 April 2021:

  • Beware of emails and trophies from Crystal Time
  • Red Sky Alliance identified 40,298 connections from new unique IP addresses connected to Sinkholes
  • Analysts identified 1,209 new IP addresses participating in various Botnets
  • New FormBook Variant Delivered in Phishing Campaign
  • SMS Flubot campaign in Italy
  • Dear John: Farm Equipment
  • US Agriculture Sector
  • SickCodes
  • Taylors Wines – Hit
  • Kawasaki Heavy Equipment – Hit
  • Protesting the MoMA, huh?

Link to full

8872398281?profile=RESIZE_400xAs more web merchants accept cryptocurrencies, the possibilities for theft and fraud will increase.  There will no protections that consumers and businesses have enjoyed that are standard for purchases via credit card.  Hackers with apparent ties to North Korea that hit e-commerce shops in 2019 and 2020 to steal payment card data also tested functionality for stealing cryptocurrency, according to the cybersecurity firm Group-IB.  Group-IB's new report builds on findings published in July 2020 by

8872293089?profile=RESIZE_400xChina, Russia, North Korea, and Iran continue to pose significant cybersecurity threats to the US, because each is capable of launching disruptive attacks, according to a report published 13 April 2021 by the Office of the Director of National Intelligence.

Threats include disinformation campaigns that target elections and try to undermine democratic institutions as well as aggressive hacking campaigns, such as the SolarWinds supply chain attack, according to the report. In many cases, criminal

8857017055?profile=RESIZE_400xTechRadar is reporting that the personal data of about 500 million LinkedIn users is being sold on a popular hacking forum.  Cyber security analysts discovered this evidence, which includes LinkedIn IDs, full names, email addresses, phone numbers, genders, links to LinkedIn profiles, links to other social media profiles, and professional titles, and other work-related data.  On a good note, no associated passwords or payment data appear to have been affected.

LinkedIn boasts of nearly 740 millio

8837932068?profile=RESIZE_400xCostco Wholesale Corporation is warning American internet users to be wary of more than a dozen digital scams targeting its customer base.   On its website,  HERE the American multinational corporation has published screenshots of 14 "prominent fraudulent emails, texts, and posts" in which cyber-criminals are impersonating Costco  The majority of the traps use financial benefits to lure victims, promising free products, financial reimbursements, exclusive offers, cash-back rewards, and gift card

8837807256?profile=RESIZE_400xFollowing the recent sanctions announced by the U.S. Department of the Treasury, Russian cyber-security firm Positive Technologies says the accusations are groundless.  The sanctions were announced against six Russian companies and 32 individuals and entities who the U.S. believes help Russian intelligence to conduct cyberespionage and election interference activities. The Biden administration also expelled 10 Russian diplomats.

Positive Technologiesptsecurity.com/ww-en/  - one of the sanctio

8837471697?profile=RESIZE_400xThe new cooperation agreement between Russia and Iran on cybersecurity and information technology is likely to create new hurdles for the United States and its allies in the Middle East. In January 2021, Russian Foreign Minister Sergey Lavrov and his Iranian counterpart Javad Zarif signed a cooperation agreement on cybersecurity and information and communications technology (ICT).

The agreement includes cybersecurity cooperation, technology transfer, combined training, and coordination at multil

8837253898?profile=RESIZE_400xUS insurance leader Geico says hackers stole driver's license numbers from its website after they supplied personal information that they had acquired elsewhere.   The driver's license numbers are believed to have been used "to fraudulently apply for unemployment benefits," Geico reported.  Unemployment fraud has skyrocketed since Covid.

The US Labor Department's Office of the Inspector General estimated that between April and September 2020, as much as 10% of the $360 billion spent as part of t

8826872876?profile=RESIZE_400xActivity Summary - Week Ending 23 April 2021:

  • Analysts identified 2,512 new IP addresses participating in various Botnets
  • Red Sky Alliance identified 51,165 connections from new unique IP Addresses
  • 33 new unique email accounts Compromised with Keyloggers were Observed
  • Rocke Group Leverages SSH Keys
  • To Whitelist, or Not to Whitelist - Packity Networks
  • Cars Driving Themselves
  • The UN and Cars
  • Digital Twin
  • Miami FL Auto Dealer Hit
  • GND gaining Speed in Governments

Link to full report: IR-21-113-001

8824223077?profile=RESIZE_400xThe US government is working to draw attention to supply chain vulnerabilities, an issue that received particular attention late last year after suspected Russian hackers gained access to federal agencies and private corporations by sneaking malicious code into widely used software. 

The US National Counterintelligence and Security Center (NCSC) recently warned that foreign hackers are increasingly targeting vendors and suppliers that work with the government to compromise their products in an e

8824008491?profile=RESIZE_400xPopular TCP/IP stacks are affected by a series of Domain Name System (DNS) vulnerabilities that could be exploited to take control of impacted devices, researchers with IoT security firm Forescout recently reported.  Collectively called NAME:WRECK and identified in the DNS implementations of FreeBSD, Nucleus NET, IPnet, and NetX, the flaws could also be abused to perform denial of service (DoS) attacks, to execute code remotely, or take devices offline.

Devices ranging from smartphones, aircraft