Cyber threats are an all too common danger for companies in all critical infrastructure sectors. Historically, the threat of cyber-attack was thought to be largest against financial institutions, retail chains, and the medical sector. However, as manufacturing has become more reliant on data and technology, the threat of cyber-attacks on the industry has grown. This especially true for critical manfacturing, like aviation and the defense industrial base (DIB), but true for any manfacturing.
All Articles (3040)
Palo Alto Networks’ Unit 42 researchers have reported the emergence of a new Mirai botnet variant called MooBot. This variant is looking for unpatched D-Link devices to create its army of DDoS (distributed denial of service) bots. For compromising vulnerable D-Link routers, MooBot uses multiple exploits.
Re-Emergence of Notorious MooBot: The MooBot botnet was first discovered by Qihoo 360’s Netlab in Sep 2019, whereas the most recent wave of attacks involving MooBot, before the one detected b
Activity Summary - Week Ending on 9 September 2022:
- Red Sky Alliance identified 22,128 connections from new IP’s checking in with our Sinkholes
- storeiq[.]eu in Poland hit 24x
- Analysts identified 2,085 new IP addresses participating in various Botnets
- Samsung Hack
- Samsung’ Rebuttal
- SharkBot
- 3rd Party Vulnerabilities
- AI Lessons
- Eni in Italy
- US – LA School District Hit
Link to full report: IR-22-252-001_weekly252.pdf
A malicious campaign mounted by the North Korea-linked Lazarus Group targets energy providers worldwide, including those based in the United States, Canada, and Japan.
The campaign is meant to infiltrate organizations worldwide to establish long-term access and subsequently exfiltrate data of interest to the adversary's nation-state, according to investigators. Some elements of the espionage attacks have already been reported in the media.
The US National Security Agency’s No. 2 official said on 7 September that the US still outpaces foreign adversaries when it comes to cybersecurity and technology thanks to the country’s “open society.” The US and its democratic allies “enjoy things that cannot be replicated easily in autocratic societies,” the NSA’s deputy director, said during the Billington Cybersecurity Summit in Washington, DC.[1]
“The grist of that is innovation. Innovation sparks creativity and solutions. That puts us
A new Phishing-as-a-Service (PhaaS) named EvilProxy (also known as Moloch) was seen for sale in dark web forums, according to researchers. Moloch ransomware is a computer virus infection that encrypts all personal victim files on an affected device and demands a ransom for unlocking them. This file-locking parasite belongs to a relatively small Makop ransomware family compared to others, such as Djvu or Dharma.
EvilProxy actors are using reverse proxy and cookie injection methods to bypass 2FA
Artificial intelligence (AI) can be trained to recognize whether a tissue image contains a tumor. However, exactly how it makes its decision has remained a mystery until now. A team from the Research Center for Protein Diagnostics (PRODI) at Ruhr-Universität Bochum is developing a new approach that will render an AI’s decision transparent and thus trustworthy. The researchers describe the approach in their journal Medical Image Analysis.[1]
For the study, experts from the Ruhr-Universität’s S
This joint CISA - Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit stopransomware.gov to see all #StopRansomware advisories and to learn more about
According to recent studies, developers spend more time maintaining, testing and securing existing code than they do writing or improving code. Security vulnerabilities have a bad habit of popping up during the software development process, only to surface after an application has been deployed. The disappointing part is that many of these security flaws and bugs could have been resolved in an earlier stage and there are proper methods and tools to uncover them. Everyone makes mistakes, even
Just what is for sale on the Dark Web? According to a published report, the North Atlantic Treaty Organization (NATO) is investigating the leak of data reportedly stolen from a European missile systems firm, which hackers have put up for sale on the Dark Web. The leaked data includes blueprints of weapons used by Ukraine in its current war with Russia. Integrated defense company MBDA Missile Systems, headquartered in France, has acknowledged that data from its systems is a part of the cache b
Hacks tied to Russia and Ukraine war have had minor impact, researchers say. Although politicians and cybersecurity experts have warned about the potential for widespread hacks in the wake of Russia’s invasion of Ukraine, a new study finds that attacks linked to the conflict have had minor impact and are unlikely to escalate further.[1] This is some positive news for cyber security.
Researchers from the University of Cambridge, the University of Edinburgh and the University of Strathclyde exam
At its core, LastPass is a password manager. A password manager is a software service that allows users to store encrypted passwords so they can be accessed easily when they are needed. LastPass is indeed very popular, but it is only one of many widely known password managers, each with their own features, advantages, and disadvantages. Other commonly known password managers include BitWarden, Dashlane, 1Password.
The apparent necessity for password managers has been prompted by the fact that
Activity Summary - Week Ending on 2 September 2022:
- Red Sky Alliance identified 37,328 connections from new IP’s checking in with our Sinkholes
- capital hit 82x
- Analysts identified 1,905 new IP addresses participating in various Botnets
- Git Woes
- Chile SERNAC Cyber Attack
- LastPass
- Free Analytical Tools
- Burp Suite
- Gophish
- Snort
Link to full report: IR-22-245-001_weekly245.pdf
Data usage on commercial maritime vessels has jumped more than threefold since 2019, according to a new communications analysis by Inmarsat. The study found that the shipping industry’s reliance on digital connectivity to enhance operating efficiency and safeguard crew welfare has resulted in data usage among Inmarsat maritime customers rising almost 70 per cent in the 12 months to mid-2022. Analysis of data usage by vessel operators shows year-on-year demand for data was highest among contain
The Bolshevik Revolution was a rebellion against the banks, the state, the royals, the industrial class, entrepreneurship, and individualism. The Bolsheviks saw everything as a class struggle wherein the working class (small blockers would say “the pleb”) was innately moral while essentially everyone else was evil due to their class. Their worldview assumed that all people should be assumed malicious until vetted as an ally, and upon confirmation would typically adopt (typically red) regalia t
Black Hat USA 2022 https://www.blackhat.com/us-22 never fails to deliver exciting, enlightening, and distressing discussions about the state of cybersecurity. Analysts saw this at Black Hat impressed and worried us the most. If you could not make the trip, here is a summary of 14 Black Hat topics.
- A Quarter Century of Hacking: The Black Hat security conference turned 25 this year, and the relentless passage of time was enough to scare some of our reporters. The conference marked the o
The US Federal Bureau of Investigation (FBI) has issued a Private Industry Notification warning of malicious cyber actors using proxies and configurations for credential stuffing attacks on organizations within the United States.
See: https://www.ic3.gov/Media/News/2022/220818.pdf
Credential stuffing is a form of brute force attack and shares many of the same commonalities that exploit leaked user credentials or ones purchased on the Dark Web that takes advantage of the fact that many individua
Russian cyberespionage group APT29, responsible for the devastating SolarWinds supply chain attacks in 2020, is back in the news. In a technical report published by Microsoft, the APT29 cyber-spies have acquired authentication bypass of a new post-exploitation tactic. Microsoft previously tracked the actors as Nobelium (a), Cozy Bear (b), and the Dukes (C).
Findings Details: Microsoft wrote in its report that the hackers are targeting corporate networks with a new authentication bypassing tec
Our monthly Cyber Threats & Vulnerabilities Report is provided to our Red Sky Alliance Members to consolidate both prominent government and private cyber security reporting which include descriptions (TTPs), indicators of compromise (IoCs) and at times remediation directions.
Link to full report: IR-22-242-001_IntelSummary242.pdf
If you ever have the good fortune to be leaving your office on a well-deserved vacation, are you certain the security controls you have in place will let you rest easy while you are away? Equally important is do you have the right action plan in place for a happy vacation? As its name indicates, security validation is a process or a technology that validates assumptions made about the actual security posture of a given environment, structure, or infrastructure.[1]
In the digital world, there a