timkmak, to random
@timkmak@journa.host avatar

Here’s what we are reading today:

The deputy head of military intelligence told the that the order has gone out for to “take something” before on May 9th, or a week later.

An offensive is expected in the and regions.

https://www.economist.com/europe/2024/05/02/ukraine-is-on-the-brink-says-a-senior-general?giftId=46801143-e035-4afa-b8f0-77d0fc1acdb9

timkmak,
@timkmak@journa.host avatar

has blamed for a on the ruling German party in 2023.

The German Foreign Minister said that a hacking group led by intelligence, was behind the attack and that it "will have consequences," the Kyiv Independent reports.

https://kyivindependent.com/germany-accuses-russia-of-cyberattack-against-governing-party-in-2023/

HonkHase, to random German
@HonkHase@chaos.social avatar
mttaggart, to random

This analysis of aka methodology is being reported all over as though it were special. And while it may be "unique" to the group, it's just...not that special.

Everything I see here should be detected by modern standard defenses. This attack chain doesn't even read like an APT to me; it reads like a cybercrime group.

What am I missing?

itnewsbot, to security
@itnewsbot@schleuss.online avatar

Hackers backed by Russia and China are infecting SOHO routers like yours, FBI warns - Enlarge (credit: Getty Images)

The FBI and partners from 10 ot... - https://arstechnica.com/?p=2006319

YourAnonRiots, to hacking Japanese
@YourAnonRiots@mstdn.social avatar

🔥 Russian group , known as Fancy Bear, is using NTLM relay attacks to breach high-value organizations worldwide, including foreign affairs, energy, defense and finance.

https://thehackernews.com/2024/02/russian-apt28-hackers-targeting-high.html

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

🚨 ALERT: Ukraine's CERT warns of a new campaign by Russia-linked .

They're deploying stealthy like MASEPIE and STEELHOOK to target government entities.

https://thehackernews.com/2023/12/cert-ua-uncovers-new-malware-wave.html

lsdm, to microsoft French
@lsdm@mamot.fr avatar

Le groupe russe APT 28 exploite la faille de relais NTLM Outlook.

Découverte en mars dernier, la faille CVE-2023-23397 débouchant sur du vol et de l'usurpation d'identifiants Outlook est toujours exploitée.

-2023-23397

https://lsdm.live/modules/news/article.php?storyid=4728

Freemind, to Cybersecurity
@Freemind@mastodon.online avatar

This backdoor was previously disclosed by CERT-UA in attacks targeting critical infrastructure in Ukraine.

https://cybersec84.wordpress.com/2023/12/13/apt28-cyber-espionage-escalates-russian-hackers-target-13-nations/

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

, a Russian threat actor, is using Israel-Hamas war-related lures to distribute the HeadLace backdoor. This targeted campaign affects 13 nations globally.

https://thehackernews.com/2023/12/russian-apt28-hackers-targeting-13.html

johnleonard, to microsoft
@johnleonard@mastodon.social avatar

Microsoft warns of Russian hackers targeting vulnerable Outlook email accounts

Uses a vulnerability that was patched in March

https://www.computing.co.uk/news/4153089/microsoft-warns-russian-hackers-targeting-vulnerable-outlook-email-accounts

simsus, to hacking German
@simsus@social.tchncs.de avatar
simontsui, to random

Cluster25: low-medium confidence that Russian state-sponsored APT28 Fancy Bear attributed to CVE-2023-38831 exploitation as part of a phishing campaign designed to harvest credentials from compromised systems. CVE2-2023-38831 is a 7.8 high severity vulnerability in WinRAR that was exploited as a Zero-Day by cybercriminals, and disclosed by Group-IB on 23 August 2023.
Link: https://blog.cluster25.duskrise.com/2023/10/12/cve-2023-38831-russian-attack

Tags:

0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

➝ 🇺🇸 ☁️ finally explains cause of breach: An engineer’s account was hacked
➝ 🎫 🔓 See Tickets says accessed customers’ payment data — again
➝ 🇳🇱 🔓 Chipmaker NXP Semiconductors confirms involving customers’ information
➝ 🇬🇧 🔓 election body failed cybersecurity test before hack
➝ 🚮 🔓 confirms massive data breach impacting 7 million users
➝ 🇦🇺 🔓 University of data breach impacts recent applicants
➝ 🇷🇺 🇺🇸 Wealthy Russian With Ties Gets 9 Years in for Hacking and Insider Trading Scheme
➝ 🇺🇸 ✈️ US Aeronautical Organization Hacked via , Vulnerabilities
➝ 🇮🇷 🎣 Alert: Campaigns Deliver New SideTwist Backdoor and Agent Tesla Variant
➝ 🇺🇦 🇷🇺 's CERT Thwarts 's Cyberattack on Critical Energy
➝ 🎰 💸 Stake.com loses $41 million to hot wallet hackers
➝ 🇺🇸 🇬🇧 US, UK take action against members of the Russian-linked hacker syndicate
➝ 🚗 👀 25 Major Car Brands Get Failing Marks From Mozilla for Security and Privacy
➝ 🇬🇧 👀 UK lawmakers back down on encryption-busting ‘spy clause’
➝ 🌏 Hundreds of thousands trafficked to work as online scammers in SE , says UN report
➝ 🇺🇸 ✍🏻 Hires @dotmudge to Work on Security-by-Design Principles
➝ 🇬🇧 🛒 Children's snack recalled after its website caught serving porn
➝ 🇸🇪 💰 Insurer fined $3M for exposing data of 650k clients for two years
➝ 🇷🇺 Elon Musk's erosion of safety standards at X is helping spread Russian propaganda, study finds
➝ 🇰🇵 North Korea-backed hackers target security researchers with 0-day
➝ 🎣 Researchers identify high-grade phishing kits attacking nearly 60,000 accounts
➝ 🇮🇳 🤖 warns of attacks targeting its users
➝ 🇨🇳 💬 Chinese-Speaking Cybercriminals Launch Large-Scale Smishing Campaign in U.S.
➝ 💸 💌 Fake extortion threatens to leak your sex tape
➝ 👤 Warns of Social Engineering Attacks Targeting Super Administrator Privileges
➝ 🎣 🛡️ is enabling real-time phishing protection for everyone
➝ 📱🧨 Hacking device can spam nearby with pop-ups
➝ 🩹 🍏 patches “clickless” 0-day image processing in ,
➝ 🩹 🔓 to Patch IP Leak Vulnerability After Public Disclosure

📚 This week's recommended reading is: "Blue Team Handbook: SOC, SIEM, and Threat Hunting (V1.02): A Condensed Guide for the Security Operations Team and Threat Hunter" by Don Murdoch GSE, MSISE, MBA

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-362023

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • kavyap
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • osvaldo12
  • mdbf
  • Youngstown
  • cisconetworking
  • slotface
  • rosin
  • thenastyranch
  • ngwrru68w68
  • khanakhh
  • megavids
  • ethstaker
  • tacticalgear
  • modclub
  • cubers
  • Leos
  • everett
  • GTA5RPClips
  • Durango
  • anitta
  • normalnudes
  • provamag3
  • tester
  • lostlight
  • All magazines