Cyber Security News


  • CISA Releases Four Industrial Control Systems Advisories

    October 28, 2022

    CISA has released four (4) Industrial Control Systems (ICS) advisories on October 27, 2022. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. CISA encourages users and administrators to review the newly released ICS advisory for technical details and mitigations: ICSA-22-300-01 Rockwell Automation FactoryTalk Alarm and Events Server ICSA-22-300-02 SAUTER Controls moduWeb ICSA-22-300-03 Rockwell ...

  • Defeating Guloader Anti-Analysis Technique

    October 28, 2022

    Unit 42 researchers recently discovered a Guloader variant that contains a shellcode payload protected by anti-analysis techniques, which are meant to slow human analysts and sandboxes processing this sample. To help speed analysis for this sample and others like it, we are providing a complete Python script to deobfuscate the Guloader sample that is available ...

  • Biden now wants to toughen up chemical sector’s cybersecurity

    October 27, 2022

    The White House is adding the chemical sector to a program launched last year to improve cybersecurity capabilities within America’s critical infrastructure industries. The addition makes chemical facilities and manufacturers the fourth sector under the Biden Administration’s Industrial Control Systems (ICS) Cybersecurity Initiative, which rolled out in July 2021 following the ransomware attack on Colonial Pipeline ...

  • Manufacturing Cybersecurity: Trends & Survey Response

    October 27, 2022

    Trend Micro conducted a study on the state of industrial cybersecurity in the oil and gas, manufacturing, and electricity/energy industries in 2022. Based on the results of a survey of over 900 ICS business and security leaders in the United States, Germany, and Japan, we will discuss the characteristics of each industry, the motivations and ...

  • Raspberry Robin worm part of larger ecosystem facilitating pre-ransomware activity

    October 27, 2022

    Microsoft has discovered recent activity indicating that the Raspberry Robin worm is part of a complex and interconnected malware ecosystem, with links to other malware families and alternate infection methods beyond its original USB drive spread. These infections lead to follow-on hands-on-keyboard attacks and human-operated ransomware activity. Microsoft continuous tracking of Raspberry Robin-related activity also ...

  • Attack Surface Management 2022 Midyear Review – Part 2

    October 27, 2022

    The cybersecurity landscape changed significantly in the first half of 2022. In our midyear roundup, Trend Micro researchers examine these changes and their effects on business operations as well as what you need to know about staying protected from online attacks. In part one of the series, Trend Micro researchers talked about the growing attack surface ...

  • DHS Announces New Cybersecurity Performance Goals for Critical Infrastructure  

    October 27, 2022

    WASHINGTON – Today, the Department of Homeland Security released the Cybersecurity Performance Goals (CPGs), voluntary practices that outline the highest-priority baseline measures businesses and critical infrastructure owners of all sizes can take to protect themselves against cyber threats. The CPGs were developed by DHS, through the Cybersecurity and Infrastructure Security Agency (CISA), at the direction of ...

  • Medibank now says hackers accessed all its customers’ personal data

    October 27, 2022

    Australian insurance firm Medibank has confirmed that hackers accessed all of its customers’ personal data and a large amount of health claims data during a recent ransomware attack. In an announcement published today, the companies warned that an internal investigation into the attack has shown that the threat actors had far greater access to customer data ...

  • Notorious ‘BestBuy’ hacker arraigned for running dark web market

    October 27, 2022

    A notorious British hacker was arraigned on Wednesday by the U.S. Department of Justice for allegedly running the now defunct ‘The Real Deal” dark web marketplace. The 34-year-old defendant Daniel Kaye (aka Bestbuy, Spdrman, Popopret, UserL0ser) allegedly ran the illicit services market between early 2015 and November 2016 when The Real Deal shut down. Threat actors used ...

  • Feds accuse Ukrainian of renting out PC-raiding Raccoon malware to fiends

    October 26, 2022

    Mark Sokolovsky, 26, a Ukrainian national, is being held in the Netherlands while he awaits extradition to America on cybercrime charges, the US Justice Department said on Tuesday. Sokolovsky, said to have used the online names Photix, Raccoon Stealer, and black21jack77777, was indicted on November 2, 2021 by a federal grand jury for his alleged role ...

  • NSA’s new ‘nerve center’ ready to scan the world for threats to America

    October 25, 2022

    The National Security Agency, which is in the middle of moving into a new “nerve center” on its Fort Meade campus, says it is still ready for whatever foreign threat may emerge against the Nov. 8 midterm elections. “We’re ready to go,” NSA Director Gen. Paul M. Nakasone said in an interview in the “battle bridge” ...