Cybersecurity News
- The US administration approved a 100-day plan to protect electrical infrastructure from cyber threats from adversaries. This is stated in a statement by the official representative of the National Security Council of the White House, Emily Horne.
- Microsoft has fixed a bug that could allow a threat actor to create specially crafted downloads that crash Windows 10 simply by opening the folder where they are downloaded. Microsoft has classified this bug as a DDoS vulnerability and is tracking it as CVE-2021-28312 with the title ‘Windows NTFS Denial of Service Vulnerability.’
- Nato holds Locked Shields 2021 – cyber war games with hackers targeting fictional island nation. The drills involving 30 countries are meant to test Nato’s defences during a global pandemic that is making the world more dependent on virtual systems. Hackers targeted vaccine developers during the Covid-19 crisis and the US government was the target of a major cyber attack, which was discovered last year.
- A joint advisory from the U.S. National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI) warn that the Russian Foreign Intelligence Service (SVR) is exploiting five vulnerabilities in attacks against U.S. organizations and interests.
- According to coordinated reports published by FireEye and Pulse Secure, two hacking groups have exploited a new zero-day vulnerability in Pulse Secure VPN equipment to break into the networks of US defense contractors and government organizations worldwide. The attacks were first discovered by the cybersecurity firm FireEye early this year. In all the intrusions, the attackers targeted Pulse Secure VPN appliances in the breached networks.
Cybersecurity Blog Posts
- Dan Simmons has shared his thoughts about what to expect from PCI DSS 4.0. He explains what PCI DSS is and describes the changes will occur in PCI DSS 4.0.
- Untangle have posted analysis about ransomware evolution in 2021. Ransomware cyberattacks exploded in 2020, taking advantage of the unique circumstances brought on by the pandemic. Cybercriminals particularly took aim at healthcare, educational institutions and local governments with ransomware.
- Kyndall Elliott in his article described 6 stages of risk and compliance program maturity and the opportunities for its automation. He explained what maturity means and how different levels of maturity apply to security posture.
- Ax Sharma wrote about important details of the Codecov Incident at Sonatype blog – the supply chain attack being undetected for 2 months.
Research and analytics
- Check Point Research’s latest Global Threat Index for March 2021 has revealed that the banking trojan IcedID has entered the Index for the first time, taking second place, while the established Dridex trojan was the most prevalent malware during March, up from seventh position in February.
- McAfee have published McAfee Labs Threat Report Q4 2021. The volume of malware threats observed by McAfee Labs averaged 588 threats per minute, an increase of 169 threats per minute (40%) in the third quarter of 2020. The fourth quarter volume averaged 648 threats per minute, an increase of 60 threats per minute (10%).
- Veracode has released Biggest Data Breaches 2020 Report. The data reveals that information leakage, CRLF injection, cryptographic issues, and code quality are the most common security vulnerabilities plaguing applications today.
- Threat Intelligence Executive Report 2021 Vol. 2 by Secureworks had reviewed the events and trends from the information security world from January through February 2021. You’ll learn about Emotet botnet disrupted by coordinated law enforcement action, compromised water treatment facility in Florida, USA and scan-and-exploit victims listed on ransomware leak site.
- Check Point Research issued Q1 Brand Phishing Report, highlighting the leading brands that hackers imitated in attempts to lure people into giving up personal data. In Q1, Microsoft was again the brand most frequently targeted by cybercriminals, as it was in Q4 2020. Thirty-nine percent of all brand phishing attempts were related to the technology giant (down slightly from 43% in Q4), as threat actors continued to try to capitalize on people working remotely during the Covid-19 pandemic.
- According to M-Trends 2021 Report performed by Fireeye, one of the most striking trends for the period of October 1st, 2019 to September 30th, 2020 was the significant reduction in the global median dwell time. This is the first time Mandiant has observed the global median dwell time dip below one month.
Major Cyber Incidents
- A ransomware attack against conditioned warehousing and transportation provider Bakker Logistiek has caused a cheese shortage in Dutch supermarkets. Bakker Logistiek is one of the largest logistics services providers in the Netherlands, offering air-conditioned warehousing and food transportation for Dutch supermarkets.
- A large BGP routing leak occurred recently disrupted the connectivity for thousands of major networks and websites around the world. Although the BGP routing leak occurred in Vodafone’s autonomous network (AS55410) based in India, it has impacted U.S. companies, including Google, according to sources.
- Leading French pharmaceutical group Pierre Fabre suffered a REvil ransomware attack where the threat actors initially demanded a $25 million ransom. As there has been no contact by the victim, and the time limit expired, the REvil ransom has doubled to $50 million.
- Days after scraped data from more than a billion Facebook and LinkedIn profiles, collectively speaking, was put for sale online, it looks like now it’s Clubhouse’s turn. The upstart platform seems to have experienced the same fate, with an SQL database containing 1.3 million scraped Clubhouse user records leaked for free on a popular hacker forum.
- The REvil ransomware gang asked Apple to buy back stolen product blueprints to avoid having them leaked on REvil’s leak site. The ransomware gang wants Apple to pay a ransom by May 1st and added that they are also “negotiating the sale of large quantities of confidential drawings and gigabytes of personal data with several major brands.”
- Group-IB has detected a large-scale scam campaign targeting Facebook Messenger users all over the world. Group-IB Digital Risk Protection analysts have found evidence proving that users in over 80 countries in Europe, Asia, the MEA region, North and South America might have been affected.