- British spies playing key role in defending Kyiv from Russian cyber attacks
November 1, 2022
British cyber spies have been playing a key role in defending Ukraine from widespread Russian cyber attacks since the start of the invasion, it has been confirmed. The damage caused by Russian hackers would have been “very significant” without the British assistance, Leo Docherty, a junior foreign office minister, said. He told Sky News the UK has ...
- APT10: Tracking down LODEINFO 2022, part I
October 31, 2022
Kaspersky has been tracking activities involving the LODEINFO malware family since 2019, looking for new modifications and thoroughly investigating any attacks utilizing those new variants. LODEINFO is sophisticated fileless malware first named in a blogpost from JPCERT/CC in February 2020. The malware was regularly modified and upgraded by the developers to target media, diplomatic, governmental and ...
- CISA Releases Guidance on Phishing-Resistant and Numbers Matching Multifactor Authentication
October 31, 2022
CISA has released two fact sheets to highlight threats against accounts and systems using certain forms of multifactor authentication (MFA). CISA strongly urges all organizations to implement phishing-resistant MFA to protect against phishing and other known cyber threats. If an organization using mobile push-notification-based MFA is unable to implement phishing-resistant MFA, CISA recommends using number ...
- Banking Trojan Techniques: How Financially Motivated Malware Became Infrastructure
October 31, 2022
While advanced persistent threats get the most breathless coverage in the news, many threat actors have money on their mind rather than espionage. You can learn a lot about the innovations used by these financially motivated groups by watching banking Trojans. Because attackers constantly create new techniques to evade detection and perform malicious acts, studying monetarily ...
- Actively exploited Windows MoTW zero-day gets unofficial patch
October 30, 2022
A free unofficial patch has been released for an actively exploited zero-day that allows files signed with malformed signatures to bypass Mark-of-the-Web security warnings in Windows 10 and Windows 11. Last weekend, BleepingComputer reported that threat actors were using stand-alone JavaScript files to install the Magniber ransomware on victims’ devices. When a user downloads a file from ...
- New Azov data wiper tries to frame researchers and BleepingComputer
October 30, 2022
A new and destructive ‘Azov Ransomware’ data wiper is being heavily distributed through pirated software, key generators, and adware bundles, trying to frame well-known security researchers by claiming they are behind the attack. The Azov Ransomware falsely claims to have been created by a well-known security researcher named Hasherazade and lists other researchers, myself, and BleepingComputer, ...
- Russian spies ‘hacked Liz Truss’s phone and stole sensitive messages’
October 29, 2022
Liz Truss had her phone hacked by Kremlin spies while she was working as foreign secretary, according to a report. The former prime minister’s personal messages with former chancellor Kwasi Kwarteng were raided, as well as sensitive details of international negotiations, it is claimed. Security services discovered the major security breach during the summer Tory leadership election, ...
- Largest EU copper producer Aurubis suffers cyberattack, IT outage
October 28, 2022
German copper producer Aurubis has announced that it suffered a cyberattack that forced it to shut down IT systems to prevent the attack’s spread. Aurubis is Europe’s largest copper producer and the second largest in the world, with 6,900 employees worldwide, and produces one million tonnes of copper cathodes yearly. In an announcement published on their website, ...
- Cranefly: Threat Actor Uses Previously Unseen Techniques and Tools in Stealthy Campaign
October 28, 2022
Symantec, by Broadcom Software, has discovered a previously undocumented dropper that is being used to install a new backdoor and other tools using the novel technique of reading commands from seemingly innocuous Internet Information Services (IIS) logs. The dropper (Trojan.Geppei) is being used by an actor Symantec calls Cranefly (aka UNC3524), to install another piece of ...
- Malaysia to champion global cyber security agenda through the inaugural CyberDSA
October 28, 2022
Set to debut in 2023, the annual event was officiated by the Minister of Communications and Multimedia Kuala Lumpur, 28 October 2022: – Malaysia is set to host the inaugural Cyber Defence and Security Asia Expo and Conference (CyberDSA) which will be held annually from next year. The event will take place over three days from ...
- Joint CISA FBI MS-ISAC Guide on Responding to DDoS Attacks and DDoS Guidance for Federal Agencies
October 28, 2022
The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) are releasing this joint guide to provide organizations proactive steps to reduce the likelihood and impact of distributed denial-of-service (DDoS) attacks. These attacks can cost an organization time and money and may impose ...

