- Lloyd’s of London reboots after dodgy network activity detected
October 7, 2022
Lloyd’s of London has reset its IT systems and is probing a possible cyberattack against it after detecting worrisome network behavior this week. “Lloyd’s has detected unusual activity on its network and we are investigating the issue,” a spokesperson told The Register on Thursday. “As a precautionary measure, we are resetting the Lloyd’s network and systems. ...
- TOP 10 unattributed APT mysteries
October 7, 2022
Targeted attack attribution is always a tricky thing, and in general, we believe that attribution is best left to law enforcement agencies. The reason is that, while in 90% of cases it is possible to understand a few things about the attackers, such as their native language or even location, the remaining 10% can lead ...
- Initial access broker repurposing techniques in targeted attacks against Ukraine
October 7, 2022
As the war in Ukraine continues, TAG is tracking an increasing number of financially motivated threat actors targeting Ukraine whose activities seem closely aligned with Russian government-backed attackers. This post provides details on five different campaigns conducted from April to August 2022 by a threat actor whose activities overlap with a group CERT-UA tracks as ...
- Fortinet warns admins to patch critical authentication bypass bug immediately
October 7, 2022
Fortinet has warned administrators to update FortiGate firewalls and FortiProxy web proxies to the latest versions, which address a critical severity vulnerability. The security flaw (tracked as CVE-2022-40684) is an authentication bypass on the administrative interface that could allow remote threat actors to log into unpatched devices. “An authentication bypass using an alternate path or channel ...
- CISA Releases Three Industrial Control Systems Advisories
October 7, 2022
CISA has released three Industrial Control Systems (ICS) advisories on October 11, 2022. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations: ICSA-22-284-01 Altair HyperView Player ICSA-22-284-02 Daikin SVMPC1 and SVMPC2 ICSA-22-284-03 Sensormatic Electronics C-CURE 9000 Read more… Source: ...
- Utility security is so bad, US DoE offers rate cuts to improve it
October 7, 2022
The US Department of Energy has proposed regulations to financially reward cybersecurity modernization at power plants by offering rate deals for everything from buying new hardware to paying for outside help. In a notice of proposed rulemaking published earlier this week (which nullified a similar 2021 plan), the DoE said the time was right “to establish ...
- Australian Federal Police arrest man suspected of exploiting Optus cyberattack
October 6, 2022
Aussie police have cuffed a 19-year-old Sydney resident accused of trying to extort money from victims of the recent cyberattack and digital burglary at national telecommunications provider Optus. The Australian Federal Police (AFP) said today it was alerted to the blackmail attempt when some Optus customers were told to transfer AU$2,000 ($1,300) to a bank account ...
- Nonprofit hospital network suffers IT meltdown after ‘security incident’
October 6, 2022
America’s second-largest nonprofit healthcare org is suffering a security “issue” that has diverted ambulances and shut down electronic records systems at hospitals around the country. CommonSpirit Health, a Chicago-based organization that has more than 1,000 facilities and 140 hospitals across 21 states, this week copped to an “IT security issue” affecting “some” of its locations. The ...
- Riyadh gears up for the ultimate hack fest as infosec heavyweights head to Black Hat MEA this November
October 6, 2022
Registrations now open for most awaited cybersecurity event in the region, taking place in Riyadh from 15 – 17 November 2022 Visitors to expect an action-packed agenda with 23 bespoke certified world-class cybersecurity trainings, exhilarating hacking competitions, and captivating sessions with leading international speakers Supported by Saudi Federation for Cyber Security and Programming (SAFCSP), Black Hat opens ...
- BlackByte ransomware abuses legit driver to disable security products
October 5, 2022
The BlackByte ransomware gang is using a new technique that researchers are calling “Bring Your Own Driver,” which enables bypassing protections by disabling more than 1,000 drivers used by various security solutions. Recent attacks attributed to this group involved a version of the MSI Afterburner RTCore64.sys driver, which is vulnerable to a privilege escalation and code ...
- Russian Hackers Reveal List of American Targets for Attack
October 5, 2022
A pro-Russian computer hacking cell announced it will be launching a series of cyber attacks on a number of United States government websites in an apparent response to escalating tensions between the country and the North Atlantic Treaty Organization (NATO). In a Telegram post Wednesday, Killnet, a notorious “hacktivist” group formed at the onset of the ...

